The GRC Lead role is a key leadership position responsible for overseeing governance, risk, compliance, certification, and continuous improvement across multiple management systems. This position ensures the maintenance of an integrated framework that aligns with standards such as ISO 9001, ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 42001, as well as other relevant legal, regulatory, contractual, client, and compliance requirements. The GRC Lead acts as the single point of accountability, driving effective management and continual enhancement of organizational controls and processes.
Key Responsibilities
- Maintain a robust governance framework with clearly defined roles, responsibilities, and decision-making authority.
- Oversee an integrated management system encompassing Quality Management System (QMS), Information Security Management System (ISMS), Privacy Information Management System (PIMS), AI Management System (AIMS), and other adopted standards.
- Manage the risk methodology and organizational risk registers, ensuring risk ownership, treatment plans, and target dates are up to date.
- Maintain and monitor registers of legal, regulatory, contractual, client, and internal compliance obligations.
- Supervise document control processes, including controlled-document and record registers, retention policies, and management system change impacts.
- Plan and execute a risk-based audit program on a quarterly and annual basis, utilizing competent and impartial auditors with objective evidence.
- Coordinate certification, surveillance, recertification, transition, client, and other external assurance audits.
- Oversee corrective actions from initial containment and root cause analysis through to closure and effectiveness review.
- Provide compliance oversight for significant nonconformities, security or privacy incidents, breaches, and control failures.
- Define and monitor compliance requirements for suppliers, vendors, contractors, and service providers.
- Provide governance oversight for business continuity, disaster recovery, and resilience testing.
- Plan and deliver annual competence and awareness training programs, maintaining related records.
- Facilitate management reviews and maintain clear GRC metrics, dashboards, and reports for senior leadership.
- Prepare gap assessments, business cases, resource estimates, and roadmaps for emerging standards and certifications.
- Coordinate AI governance risks, controls, and obligations, supporting the responsible use of AI technologies.
- Respond to client assurance requests, coordinate accurate evidence, and maintain constructive stakeholder relationships.
- Exercise independent access, challenge, approval, recommendation, and escalation authority within approved confidentiality and access-control guidelines.
Required Qualifications
- Lead Auditor or Lead Implementer certification for at least one management system standard relevant to the organization.
- A minimum of five years’ experience in management systems, risk, compliance, or assurance, preferably within a software or IT services environment.
- Proven ability to interpret standards and compliance obligations independently and apply them practically and proportionately.
- Experience planning and leading audits, with the ability to communicate findings clearly using objective evidence.
- Strong skills in designing and maintaining governance, risk, and compliance frameworks.
- Proficiency in structured root cause analysis and corrective action effectiveness reviews.
- Capability to assess controls related to quality, information security, privacy, business continuity, and AI governance.
- Experience facilitating management reviews, risk workshops, and cross-functional decision-making.
- Ability to build cooperation and influence stakeholders without direct reporting authority.
- Strong written and verbal communication skills in English, with the ability to prepare clear, objective reports for senior management.
Preferred Qualifications and Benefits
- Additional certifications or formal training in risk management, privacy, information security, business continuity, AI governance, or GRC are highly desirable.
- Experience coordinating certification or client audits is an advantage.
This role offers the opportunity to lead governance, risk, and compliance initiatives in a dynamic environment, ensuring that the organization meets evolving standards and regulatory requirements while supporting responsible AI use and business resilience.