Internal Audit Manager (Enterprise Risk Management)
PayNet
Why PayNet / Why Now
- Build trust in the platforms Malaysians use every day, including DuitNow, FPX, MyDebit and JomPAY.
- Shape assurance that strengthens governance, controls and organisational resilience across a national payments institution.
- Challenge how enterprise risks are identified, treated, monitored and reported before they become material exposures.
- Influence risk-informed decisions by turning audit insight into clear priorities for Management and the Board.
- Join a values-led environment built on Aspiration, Curiosity, Grit and Integrity.
##
TL;DR
- Own risk-based operational audits, with a strong focus on Enterprise Risk Management and risk governance.
- Decide where assurance effort matters most by applying professional judgement to complex and emerging risks.
- Lead reviews independently or through audit teams, from scoping and fieldwork to reporting and remediation validation.
- Deliver practical, evidence-based recommendations that strengthen accountability, oversight and resilience.
##
Why This Role Matters
- Provide independent assurance that risk governance supports effective decisions and sustainable organisational resilience.
- Test whether accountabilities, oversight, escalation and independent challenge work as intended.
- Surface gaps in how strategic, emerging, systemic, ecosystem and third-party risks are understood and managed.
- Give Management and the Board clearer insight into material risks, trends and escalating exposures.
- Raise the quality of remediation by identifying root causes and validating that actions are sustainable.
##
What You Will Actually Do
- Lead or independently execute risk-based operational audits across business processes, ERM and the Risk Management function.
- Assess governance and operating models for clear accountability, effective oversight, structured escalation and robust challenge.
- Evaluate horizon scanning, scenario analysis and RCSA across emerging, concentration, dependency and interdependency risks.
- Test KRIs, thresholds and risk treatment decisions, including acceptance, exemptions, mitigation, contingency and exit strategies.
- Shape concise audit reports and working papers supported by evidence, root-cause analysis, benchmarks and leading practices.
- Drive closure by validating whether agreed remediation addresses the underlying risk sustainably.
##
Examples of This Role in Practice
- A business accepts a material risk: decide whether the rationale, authority, mitigation and escalation are sufficiently robust.
- A KRI remains within threshold while exposure is rising: challenge whether the indicator still gives timely and meaningful warning.
- A critical service depends on a concentrated third party: test whether dependency, contingency, workaround and exit risks are understood.
- A scenario analysis identifies a severe event: assess whether the response translates into clear ownership and management action.
- A recurring audit issue is marked complete: validate the root cause, evidence and sustainability before supporting closure.
##
What Will Help You Succeed
- Bring internal audit experience across business or operational processes, combined with hands-on ERM experience or assurance over an enterprise risk function.
- Apply strong knowledge of risk governance, ERM frameworks, RCSA, emerging risk assessment, KRIs, thresholds and risk reporting.
- Use critical thinking, analytical rigour and sound professional judgement to reach clear, defensible conclusions.
- Engage stakeholders confidently, provide constructive independent challenge and explain complex risk matters clearly.
- Add value through experience in financial institutions, regulated payments, operational resilience or comparative ERM benchmarking.
- Extend audit insight through IT general controls, artificial intelligence or data analytics capabilities.
Skills
- Ai
- Analytical
- Business continuity
- Critical thinking
- Financial reporting
- Risk assessment