· Contribute to identification and initiation of risk mitigation projects addressing significant risks impacting the product tower, leveraging D&T Risk Assessments (DTRA).
· Facilitate risk identification and discussions within the business unit, covering operational, product/project, and strategic risks. · Conduct Digital & Tech Risk Assessments for new tech products, End User Developed (EUD) solutions, and RPA bots, including approvals. · Provide ad-hoc controls consultancy, support RFP activities for new Tech products, and review DTRA documentation deliverables. · Approve findings and remediation plans, ensuring timely closure and effective risk reduction. · Monitor deliverable quality and ensure standards are met for products, projects, programmes, and operations within remit, following a risk-based approach aligned with ITMS, D&T Risk Assessments, local SOPs, and project PQPs. · Execute self-inspection programmes through management monitoring and independent business monitoring, when required. · Support implementation of management monitoring programmes for processes not owned by GRC. · Contribute to maintenance of product tower delivery and operational frameworks (activities, deliverables, roles, and responsibilities) ensuring alignment with the Digital & Tech Management System (DTMS). · Support readiness for external inspections (FDA, EMEA, tax authorities), external audits, and internal audits. · Manage inspection readiness activities and Corrective and Preventative Actions (CAPAs) in liaison with the business. · Attend and actively support Architect Review Board sessions for relevant projects, ensuring that architectural decisions align with security, compliance, and risk management principles. · Participate in Cyber Risk Assessment meetings, providing expert input on risk identification, mitigation strategies, and control design. · Ensure robust documentation and evidence is maintained to demonstrate compliance with internal standards (D&T Written Standards, DTMS) and external regulatory requirements (FDA, EMEA, tax authorities). · Validate that project deliverables meet quality and compliance expectations, supporting audit readiness and inspection preparedness. · Lead initiatives to simplify and streamline key risk and compliance processes, including D&T Risk Assessments, control requirements, and compliance workflows. · Reduce complexity and duplication across frameworks, ensuring processes are efficient, user-friendly, tech-enabled via the Enterprise GRC platform, and aligned with governance standards. · Champion standardization and automation opportunities to improve consistency, accelerate delivery, and enhance overall risk management effectiveness.