Routiqo

Internal Audit Manager (Enterprise Risk Management)

PayNet

  • Malaysia
  • Full-time

Why PayNet / Why Now

  • Build trust in the platforms Malaysians use every day, including DuitNow, FPX, MyDebit and JomPAY.
  • Shape assurance that strengthens governance, controls and organisational resilience across a national payments institution.
  • Challenge how enterprise risks are identified, treated, monitored and reported before they become material exposures.
  • Influence risk-informed decisions by turning audit insight into clear priorities for Management and the Board.
  • Join a values-led environment built on Aspiration, Curiosity, Grit and Integrity.

##

TL;DR

  • Own risk-based operational audits, with a strong focus on Enterprise Risk Management and risk governance.
  • Decide where assurance effort matters most by applying professional judgement to complex and emerging risks.
  • Lead reviews independently or through audit teams, from scoping and fieldwork to reporting and remediation validation.
  • Deliver practical, evidence-based recommendations that strengthen accountability, oversight and resilience.

##

Why This Role Matters

  • Provide independent assurance that risk governance supports effective decisions and sustainable organisational resilience.
  • Test whether accountabilities, oversight, escalation and independent challenge work as intended.
  • Surface gaps in how strategic, emerging, systemic, ecosystem and third-party risks are understood and managed.
  • Give Management and the Board clearer insight into material risks, trends and escalating exposures.
  • Raise the quality of remediation by identifying root causes and validating that actions are sustainable.

##

What You Will Actually Do

  • Lead or independently execute risk-based operational audits across business processes, ERM and the Risk Management function.
  • Assess governance and operating models for clear accountability, effective oversight, structured escalation and robust challenge.
  • Evaluate horizon scanning, scenario analysis and RCSA across emerging, concentration, dependency and interdependency risks.
  • Test KRIs, thresholds and risk treatment decisions, including acceptance, exemptions, mitigation, contingency and exit strategies.
  • Shape concise audit reports and working papers supported by evidence, root-cause analysis, benchmarks and leading practices.
  • Drive closure by validating whether agreed remediation addresses the underlying risk sustainably.

##

Examples of This Role in Practice

  • A business accepts a material risk: decide whether the rationale, authority, mitigation and escalation are sufficiently robust.
  • A KRI remains within threshold while exposure is rising: challenge whether the indicator still gives timely and meaningful warning.
  • A critical service depends on a concentrated third party: test whether dependency, contingency, workaround and exit risks are understood.
  • A scenario analysis identifies a severe event: assess whether the response translates into clear ownership and management action.
  • A recurring audit issue is marked complete: validate the root cause, evidence and sustainability before supporting closure.

##

What Will Help You Succeed

  • Bring internal audit experience across business or operational processes, combined with hands-on ERM experience or assurance over an enterprise risk function.
  • Apply strong knowledge of risk governance, ERM frameworks, RCSA, emerging risk assessment, KRIs, thresholds and risk reporting.
  • Use critical thinking, analytical rigour and sound professional judgement to reach clear, defensible conclusions.
  • Engage stakeholders confidently, provide constructive independent challenge and explain complex risk matters clearly.
  • Add value through experience in financial institutions, regulated payments, operational resilience or comparative ERM benchmarking.
  • Extend audit insight through IT general controls, artificial intelligence or data analytics capabilities.

APPLY

Skills

  • Ai
  • Analytical
  • Business continuity
  • Critical thinking
  • Financial reporting
  • Risk assessment