Business Risk VP, Business Risk, BRR

Brand:  HSBC
Area of Interest: 
Location: 

Colombo, LK, 00600

Work style:  Hybrid Worker
Date:  16 Jan 2026

Why Join us:

This is a key role within Business Risk (BR) Function that directly supports the Group’s Chief Operating Office (GCOO) within HSBC, one of the world’s largest banking and financial services organizations. Key Responsibilities include:

  • Enforcing robust risk governance and ensuring all stakeholders have visibility of key risks and remediation activity.
  • Setting, communicating and monitoring risk appetite in line with business requirements.
  • Conducting high quality and efficient reviews of our control performance.
  • Facilitating controls remediation where required.
  • Raising awareness and understanding of risks, controls and risk management.
  • Continuously improving the control and monitoring of risk, including behaviors.

Some Careers grow faster than others.

If you’re looking for further opportunities to develop your career, take the next step in fulfilling your potential right here at HSBC.

Accountabilities will include:

The role is part of the BRR function in GSCs.  The purpose of the role is to enable colleagues within GSCs to deliver safe and secure services to all our customers, colleagues and the Bank itself. This will be achieved by:

  • Implementing robust risk governance and ensuring all stakeholders have visibility of key risks and remediation activity.
  • Monitoring risk appetite in line with business requirements.
  • Conducting high quality and efficient reviews of GSC control performance.
  • Facilitating controls remediation where required.
  • Raising awareness and understanding of risks, controls and risk management.
  • Continuously improving the control and monitoring of risk, including behaviors.
  • This role will work with other Business Service Risk professionals/SMEs to drive these objectives to improve the risk and control management within GSCs.
  • The role requires the job holder to provide guidance and advice to key senior GSC stakeholders, challenge senior leaders on the control performance and escalate risk and issues as appropriate to GSC Exco.
  • The role is expected to support the GSC Head of BR to:
    1. Provide control expertise and opine on the end to end health of the Risk and Control environment within GSC Entity.
    2. Implement improvements to the GSC Control Environment.
    3. Manage internal and external audit requirements for GSCs.

What you’ll do:

Principal Accountabilities:  Key activities and decision making areas

Impact on the Business

Protect the Bank:

  • Identify and proactively manage current and emerging risks related to changes to services, processes and systems delivered by or impacting GSCs. 
  • Implement and oversee governance processes, intervening in GSC Operations activities where necessary and agreeing subsequent actions with key GSC senior managers. 
  • Deliver robust controls testing, risk reviews to mitigate GSC Risks.
  • Ensure current and emerging entity risks are identified and proactively managed.

Enable the Bank:

  •  Implement enhancements across GSCs, and sharing best practices with colleagues and stakeholders.
  • Increase awareness and engagement, and ensure risk is considered proactively in all GSC Operations activities. 
  • Educate GSC Leadership teams on the end to end health of the Risk and control environment, identify and communicate the need for intervention to ensure suitable controls are in place.
  • Execute risk communication and engagement plans across GSCs. Drive the Risk Culture agenda.

Typical Targets and Measures

  • Evidence of proactive identification of risk exposure and intervention to resolve threats.
  • Evidence of challenge, intervention and escalation of significant risks. 
  • Feedback from BR and GSC leadership teams.
  • Evidence of early, proactive identification and execution of control and risk interventions within GSCs
  • Successful implementation of risk and control governance and reporting across GSCs
  • Timely provision of relevant information to stakeholders.
  • Strategic risk projects, where involved, delivered on time and within budget, delivering sustainable improvements. 
  • Evidence of challenge, intervention and escalation of significant risk issues. 

Customers / Stakeholders

  • Represent operations controls management to GSC Executive Management.
  • Partner with and appropriately challenge Risk oversight functions and Internal / External Audit to ensure a holistic view of risk profile.
  • Ensure that all BR function deliverables to stakeholders are concise, precise and impactful.

Typical Targets and Measures

  • Customer / stakeholder feedback.
  • Demonstrate awareness of all Audit and Regulatory engagements for area.
  • GSC ExCo understanding of reporting and execution of subsequent actions.
  • Testing / Reviews delivered according to agreed plans.

Leadership & Teamwork

  • Assess and build the right capabilities needed to set and execute the strategy to improve the risk and control environment within GSCs.
  •  Manage the relationship with the Head of Global Service Centre’s / Center Directors, the GSC leadership team, and the BR leadership team.
  • Agree responsibilities within formal and informal network, providing context, direction and confidence to deliver results.
  • Role model a positive internal risk and control culture across GSCs and shape the climate, tone and environment in which people work.
  •  Make considered decisions that protect and enhance HSBC values, reputation and business
  • Demonstrate leadership on the execution of thematic reviews / investigations  in response to internal or external events within GSC’s.

Typical Targets and Measures

  • Evidence of progress against strategy.
  • Stakeholder feedback, 1:1 meetings, objectives & performance reviews output.
  • Evidence of appropriate seniority of Risk and Control ownership

Operational Effectiveness & Control

  • Partner with the GSC Leadership Team to identify, measure, mitigate, monitor and report risk. 
  • Facilitate the execution of the 3 Lines of Defence model by ensuring audits are planned, executed and reported effectively.
  • Facilitate issues and actions management processes and ensure remediation activities are completed on time.
  • Enhance the GSC Operations control framework through periodic review, including consolidation of key controls and removal of redundant controls. 
  • Ensure complete end to end risk and control coverage by managing the effective implementation and development of the 3LoD framework in GSCs.
  • Implement audit recommendations and maintain satisfactory level of audits across GSC operations

Typical Targets and Measures

  • Evidence of identification and mitigation of significant risks. 
  • Evidence of improvements made to GSC processes, systems, ways of working and Transformation activities. 
  • Feedback from GSC stakeholders. 
  • Delivery of objectives within agreed KPIs and KRIs. 
  • Evidence of continuous control framework improvement. 
  • Successful, timely implementation of audit recommendations

Role Context

  • Close working relationship with GSC senior leadership team to escalate risks and issues as appropriate.
  • Not subject to close supervision.
  • Need to perform a proactive, collaborative role across GSCs and also externally with a comprehensive understanding of the Regulatory environment and emerging risk as well as regulatory issues.
  • You will be expected to implement Group Risk policies and framework for Risk management and the Operational Risk Transformation Framework across GSCs.
  • The Group has adopted a risk management and internal control structure, referred to as the Three Lines of Defense, to ensure it achieves its commercial aims while meeting regulatory and legal requirements and its responsibilities to shareholders, customers and staff. All staff must familiarize themselves and adhere at all times with the roles and supporting responsibilities they play in the Three Lines of Defense.

 

Qualifications

 

What you will need to succeed in the role:

  • Bachelors degree (or equivalent) in any discipline with strong academic background
  • Previous experience in Risk Management within a global organization, working across cultures. 
  • Ability to present complex issues confidently and concisely to Executives, Non-Executives and Regulators, using simple language. 
  • Comprehensive knowledge of the external environment (risk, regulatory, political, competitors etc.). 
  • Outstanding relationship management, collaboration and influencing skills with experience of positive, challenging interactions with senior executives across multiple functions.
  • Thorough understanding of HSBC organization structure and ability to adapt to fact paced changes in the organization. 

Technical Competence

  • Risk & Control subject matter expertise. 
  • Ability to distil complex and varied information into useful, insightful and concise recommendations. 
  • Ability to identify, assess and communicate the need for risk management intervention in complex, fast paced environments.
  • Skilled decision-maker, making considered and timely decisions, particularly when under high pressure. 

Focus & Energy

  • Proactive and delivery focused to ensure individual and team tasks are completed on time and to the required levels of quality. 
  • Ability to prioritize workload effectively, across multiple businesses and countries, in line with business and controls priorities and work with other resource owners to agree timely provision of services
  • High level of drive and self-motivation to ensure delivery of a broad range of outputs simultaneously in a matrix environment. 
  • Committed to personal and professional development both for self and team.

Relationships

  • Ability to build senior relationships by communicating, influencing and negotiating effectively with senior executives, non-executives, regulators, third parties and internal management teams. 
  • Ability to use initiative to resolve issues, whilst dealing with a diverse range of stakeholders and team members, distributed across functions and locations. 
  • Experience of building and maintaining strong working relationships across a globally distributed matrix organization. 
  • Outstanding interpersonal and communication skills with a proven ability to communicate effectively and confidently at all levels across the Group. 
  • Proven capability in building globally distributed, high performing teams of experienced professionals. 
  • Ability to leverage expertise of CoE team in implementing initiatives and governance without direct line management responsibility for all staff. 

Leadership Capabilities

  • Navigating: understand and translate strategy into own Function, aligning directions accordingly
  • Aspiring: be ambitious about providing the highest standards of delivery and embedding them in the team
  • Driving: set stretching goals for self and deliver them with courage and tenacity
  • Mobilising: authentically engage with team, colleagues and business partners to deliver at pace
  • Sustaining: make considered decisions that protect and enhance HSBC values, reputation and business