Risk And Compliance Manager job at DFCU Bank
Posted by: great-volunteer
Posted date: 2026-Aug-19
Location: Kampala
Risk And Compliance Manager 2026-08-19T15:05:03+00:00 DFCU Bank https://cdn.ugashare.com/jsjobsdata/data/employer/comp_7435/logo/dfcu%20Bank.jpeg https://www.dfcugroup.com/ FULL_TIME Kampala Kampala 00256 Uganda Banking Management, Accounting & Finance, Business Operations, Legal 2026-08-28T17:00:00+00:00 8 DFCU Bank Uganda is hiring a Risk And Compliance Manager responsible for leading, designing, implementing and maintaining the risk management and compliance framework for the parent company and its non-bank entities, ensuring the holding company discharges obligations to the Bank of Uganda, the Capital Markets Authority, the Uganda Securities Exchange and other regulators, and providing the Board and its Audit and Risk Committees with an independent, consolidated view of the Group risk and compliance profile. Reporting to Chief Executive Officer, KEY ACCOUNTABILITIES: Risk Management and Governance - Develop, maintain and obtain Board approval for the risk management framework, risk taxonomy, risk appetite statement and supporting policy suite, and ensure proportionate adoption by each non-bank entity.
- Maintain the risk register and top and emerging risk profile across strategic, financial, operational, conduct, financial crime, technology, legal and reputational risk.
- Facilitate risk and control self-assessments, monitor adherence to approved appetite and internal control standards, and track agreed mitigation actions to closure.
- Embed a sound risk culture and support first line ownership of risk across the parent and non-bank entities.
- Prepare and present risk exposure reports, trend analysis, and mitigation recommendations to the Board and Management Committees.
Compliance Monitoring and Regulatory Oversight - Maintain the regulatory obligations register, mapping every applicable statute, regulation, guideline, licence condition and reporting obligation to a named owner, a control and a monitoring frequency.
- Operate horizon scanning, impact assessment and implementation tracking for regulatory change across BoU, CMA, USE, FIA, PDPO, the NGO Bureau and URA.
- Design and execute a risk-based compliance monitoring and testing programme, with documented findings, agreed actions and follow-up to closure.
- Maintain the breach, incident and regulatory correspondence registers; manage notification of reportable breaches within prescribed timelines; and support licensing applications and ongoing licence conditions for new entities and activities.
- Oversee compliance with the Data Protection and Privacy Act, including registration with the Personal Data Protection Office, records of processing, data subject requests and personal data breach management.
- Oversee sanctions, PEP and adverse media screening of counterparties, investee companies, donors, grantees, suppliers and staff.
- Own the anti-bribery and corruption, gifts and hospitality, conflicts of interest and whistleblowing arrangements for the parent and non-bank entities.
- To act as the Money Laundering Control Officer and Data Privacy Officer for Limited & non bank subsidiaries
Risk Identification and Control Effectiveness - Conduct risk identification and assessment exercises across departments and operational areas.
- Review and evaluate the adequacy and effectiveness of internal controls and risk mitigation measures.
- Provide guidance to management and staff on corrective actions required to address identified risk and compliance gaps.
- Conduct follow-up reviews to ensure timely implementation of agreed action plans.
Risk Awareness and Capacity Building - Promote awareness of risk management and compliance requirements through training, workshops, guidance notes, and stakeholder engagement.
- Support staff and management in understanding and implementing the companyâs risk management methodologies, frameworks, policies, and procedures.
- Encourage a culture of accountability, compliance, and proactive risk management across the organization.
Reporting and Risk Analytics - Prepare periodic risk and compliance reports, dashboards, and analytics for Management, Board Committees, and regulators.
- Compile and analyse operational risk data, key risk indicators (KRIs), incident reports, and loss event data.
- Reporting on operational risk, financial risk, compliance, and AML/CFT activities.
Professional Development and Continuous Improvement - Maintain up-to-date knowledge of risk management, compliance, governance, and regulatory developments.
- Participate in continuous professional development initiatives to enhance technical and professional competence.
- Contribute to the continuous improvement of risk management tools, frameworks, methodologies, and reporting processes.
KNOWLEDGE, SKILLS, AND EXPERIENCE REQUIRED: Education and Certification - A degree in law, finance, accounting, economics, business administration, risk management or related discipline; a relevant postgraduate qualification is an added advantage.
- At least one relevant professional certification, held or obtained within an agreed period of appointment â for example CAMS, the ICA Diploma in Governance, Risk and Compliance, CRMA, CIA, CRISC, CGRC, PRM, FRM, CPA(U), ACCA, or admission as an Advocate of the High Court of Uganda.
Experience A minimum of 3 to 5 yearsâ experience in risk management, compliance, regulatory affairs, internal audit or financial services legal practice. Demonstrable experience of direct engagement with financial sector regulators and of preparing and presenting reporting to a board or board committee. Experience in a group, multi-entity or holding company environment, or in capital markets, asset management or the donor-funded sector, is a distinct advantage. Technical Knowledge Working knowledge of the Ugandan regulatory framework, including the Financial Institutions Act and its regulations, the Bank of Uganda Corporate Governance Guidelines, the Anti-Money Laundering Act, the Capital Markets Authority Act and USE Listing Rules, the Data Protection and Privacy Act, the Companies Act and the Non-Governmental Organizations Act. Familiarity with the FATF 40 Recommendations, Basel Committee corporate governance principles, COSO ERM, ISO 31000, ISO 37301 and the IIA Three Lines Model. Competence in risk assessment methodology, control design and testing, key risk indicator development and risk reporting; proficiency in Excel, Word and PowerPoint. Behavioural Competencies Excellent written and spoken English, including the ability to write concise, decision-ready board papers. Strong analytical and organizational skills, with the ability to interpret complex regulatory text and translate it into practical, proportionate controls. Personal integrity and the courage to raise and escalate difficult issues, including where this places the role holder in disagreement with executive management. Strong influencing and stakeholder management skills, with the ability to secure outcomes across entities where the role holder has no direct line authority. * Develop, maintain and obtain Board approval for the risk management framework, risk taxonomy, risk appetite statement and supporting policy suite, and ensure proportionate adoption by each non-bank entity. * Maintain the risk register and top and emerging risk profile across strategic, financial, operational, conduct, financial crime, technology, legal and reputational risk. * Facilitate risk and control self-assessments, monitor adherence to approved appetite and internal control standards, and track agreed mitigation actions to closure. * Embed a sound risk culture and support first line ownership of risk across the parent and non-bank entities. * Prepare and present risk exposure reports, trend analysis, and mitigation recommendations to the Board and Management Committees. * Maintain the regulatory obligations register, mapping every applicable statute, regulation, guideline, licence condition and reporting obligation to a named owner, a control and a monitoring frequency. * Operate horizon scanning, impact assessment and implementation tracking for regulatory change across BoU, CMA, USE, FIA, PDPO, the NGO Bureau and URA. * Design and execute a risk-based compliance monitoring and testing programme, with documented findings, agreed actions and follow-up to closure. * Maintain the breach, incident and regulatory correspondence registers; manage notification of reportable breaches within prescribed timelines; and support licensing applications and ongoing licence conditions for new entities and activities. * Oversee compliance with the Data Protection and Privacy Act, including registration with the Personal Data Protection Office, records of processing, data subject requests and personal data breach management. * Oversee sanctions, PEP and adverse media screening of counterparties, investee companies, donors, grantees, suppliers and staff. * Own the anti-bribery and corruption, gifts and hospitality, conflicts of interest and whistleblowing arrangements for the parent and non-bank entities. * To act as the Money Laundering Control Officer and Data Privacy Officer for Limited & non bank subsidiaries * Conduct risk identification and assessment exercises across departments and operational areas. * Review and evaluate the adequacy and effectiveness of internal controls and risk mitigation measures. * Provide guidance to management and staff on corrective actions required to address identified risk and compliance gaps. * Conduct follow-up reviews to ensure timely implementation of agreed action plans. * Promote awareness of risk management and compliance requirements through training, workshops, guidance notes, and stakeholder engagement. * Support staff and management in understanding and implementing the companyâs risk management methodologies, frameworks, policies, and procedures. * Encourage a culture of accountability, compliance, and proactive risk management across the organization. * Prepare periodic risk and compliance reports, dashboards, and analytics for Management, Board Committees, and regulators. * Compile and analyse operational risk data, key risk indicators (KRIs), incident reports, and loss event data. * Reporting on operational risk, financial risk, compliance, and AML/CFT activities. * Maintain up-to-date knowledge of risk management, compliance, governance, and regulatory developments. * Participate in continuous professional development initiatives to enhance technical and professional competence. * Contribute to the continuous improvement of risk management tools, frameworks, methodologies, and reporting processes. * Excellent written and spoken English * Ability to write concise, decision-ready board papers * Strong analytical and organizational skills * Ability to interpret complex regulatory text and translate it into practical, proportionate controls * Personal integrity * Courage to raise and escalate difficult issues * Strong influencing and stakeholder management skills * Ability to secure outcomes across entities where the role holder has no direct line authority * Working knowledge of the Ugandan regulatory framework * Familiarity with FATF 40 Recommendations, Basel Committee corporate governance principles, COSO ERM, ISO 31000, ISO 37301 and the IIA Three Lines Model * Competence in risk assessment methodology, control design and testing, key risk indicator development and risk reporting * Proficiency in Excel, Word and PowerPoint * A degree in law, finance, accounting, economics, business administration, risk management or related discipline * A relevant postgraduate qualification is an added advantage * At least one relevant professional certification, held or obtained within an agreed period of appointment â for example CAMS, the ICA Diploma in Governance, Risk and Compliance, CRMA, CIA, CRISC, CGRC, PRM, FRM, CPA(U), ACCA, or admission as an Advocate of the High Court of Uganda. JOB-6a85c61f16d4d Vacancy title: Risk And Compliance Manager Jobs at: DFCU Bank Deadline of this Job: Friday, August 28 2026 Duty Station: Kampala | Kampala Summary Date Posted: Wednesday, August 19 2026, Base Salary: Not Disclosed JOB DETAILS:
DFCU Bank Uganda is hiring a Risk And Compliance Manager responsible for leading, designing, implementing and maintaining the risk management and compliance framework for the parent company and its non-bank entities, ensuring the holding company discharges obligations to the Bank of Uganda, the Capital Markets Authority, the Uganda Securities Exchange and other regulators, and providing the Board and its Audit and Risk Committees with an independent, consolidated view of the Group risk and compliance profile. Reporting to Chief Executive Officer, KEY ACCOUNTABILITIES: Risk Management and Governance - Develop, maintain and obtain Board approval for the risk management framework, risk taxonomy, risk appetite statement and supporting policy suite, and ensure proportionate adoption by each non-bank entity.
- Maintain the risk register and top and emerging risk profile across strategic, financial, operational, conduct, financial crime, technology, legal and reputational risk.
- Facilitate risk and control self-assessments, monitor adherence to approved appetite and internal control standards, and track agreed mitigation actions to closure.
- Embed a sound risk culture and support first line ownership of risk across the parent and non-bank entities.
- Prepare and present risk exposure reports, trend analysis, and mitigation recommendations to the Board and Management Committees.
Compliance Monitoring and Regulatory Oversight - Maintain the regulatory obligations register, mapping every applicable statute, regulation, guideline, licence condition and reporting obligation to a named owner, a control and a monitoring frequency.
- Operate horizon scanning, impact assessment and implementation tracking for regulatory change across BoU, CMA, USE, FIA, PDPO, the NGO Bureau and URA.
- Design and execute a risk-based compliance monitoring and testing programme, with documented findings, agreed actions and follow-up to closure.
- Maintain the breach, incident and regulatory correspondence registers; manage notification of reportable breaches within prescribed timelines; and support licensing applications and ongoing licence conditions for new entities and activities.
- Oversee compliance with the Data Protection and Privacy Act, including registration with the Personal Data Protection Office, records of processing, data subject requests and personal data breach management.
- Oversee sanctions, PEP and adverse media screening of counterparties, investee companies, donors, grantees, suppliers and staff.
- Own the anti-bribery and corruption, gifts and hospitality, conflicts of interest and whistleblowing arrangements for the parent and non-bank entities.
- To act as the Money Laundering Control Officer and Data Privacy Officer for Limited & non bank subsidiaries
Risk Identification and Control Effectiveness - Conduct risk identification and assessment exercises across departments and operational areas.
- Review and evaluate the adequacy and effectiveness of internal controls and risk mitigation measures.
- Provide guidance to management and staff on corrective actions required to address identified risk and compliance gaps.
- Conduct follow-up reviews to ensure timely implementation of agreed action plans.
Risk Awareness and Capacity Building - Promote awareness of risk management and compliance requirements through training, workshops, guidance notes, and stakeholder engagement.
- Support staff and management in understanding and implementing the companyâs risk management methodologies, frameworks, policies, and procedures.
- Encourage a culture of accountability, compliance, and proactive risk management across the organization.
Reporting and Risk Analytics - Prepare periodic risk and compliance reports, dashboards, and analytics for Management, Board Committees, and regulators.
- Compile and analyse operational risk data, key risk indicators (KRIs), incident reports, and loss event data.
- Reporting on operational risk, financial risk, compliance, and AML/CFT activities.
Professional Development and Continuous Improvement - Maintain up-to-date knowledge of risk management, compliance, governance, and regulatory developments.
- Participate in continuous professional development initiatives to enhance technical and professional competence.
- Contribute to the continuous improvement of risk management tools, frameworks, methodologies, and reporting processes.
KNOWLEDGE, SKILLS, AND EXPERIENCE REQUIRED: Education and Certification - A degree in law, finance, accounting, economics, business administration, risk management or related discipline; a relevant postgraduate qualification is an added advantage.
- At least one relevant professional certification, held or obtained within an agreed period of appointment â for example CAMS, the ICA Diploma in Governance, Risk and Compliance, CRMA, CIA, CRISC, CGRC, PRM, FRM, CPA(U), ACCA, or admission as an Advocate of the High Court of Uganda.
Experience A minimum of 3 to 5 yearsâ experience in risk management, compliance, regulatory affairs, internal audit or financial services legal practice. Demonstrable experience of direct engagement with financial sector regulators and of preparing and presenting reporting to a board or board committee. Experience in a group, multi-entity or holding company environment, or in capital markets, asset management or the donor-funded sector, is a distinct advantage. Technical Knowledge Working knowledge of the Ugandan regulatory framework, including the Financial Institutions Act and its regulations, the Bank of Uganda Corporate Governance Guidelines, the Anti-Money Laundering Act, the Capital Markets Authority Act and USE Listing Rules, the Data Protection and Privacy Act, the Companies Act and the Non-Governmental Organizations Act. Familiarity with the FATF 40 Recommendations, Basel Committee corporate governance principles, COSO ERM, ISO 31000, ISO 37301 and the IIA Three Lines Model. Competence in risk assessment methodology, control design and testing, key risk indicator development and risk reporting; proficiency in Excel, Word and PowerPoint. Behavioural Competencies Excellent written and spoken English, including the ability to write concise, decision-ready board papers. Strong analytical and organizational skills, with the ability to interpret complex regulatory text and translate it into practical, proportionate controls. Personal integrity and the courage to raise and escalate difficult issues, including where this places the role holder in disagreement with executive management. Strong influencing and stakeholder management skills, with the ability to secure outcomes across entities where the role holder has no direct line authority. Work Hours: 8 Experience in Months: 36 Level of Education: bachelor degree Job application procedure
Application Link:Click Here to Apply Now
|