About the Role
The Operational Risk Manager (Section Manager) supports the department in implementing and maintaining the hospital's risk management framework. This role involves assisting in Enterprise Risk Management (ERM) activities, conducting departmental and project-level risk assessments, monitoring risks and mitigation strategies, and promoting a strong risk-aware culture.
Responsibilities
A. Enterprise Risk Management (ERM)
- Assist the ORM Department Head in the development, implementation, and maintenance of the hospital's Operational Risk Management (ORM) framework, ensuring alignment with strategic goals, regulatory standards, and hospital objectives.
- Assist in ensuring all risk management activities adhere to relevant regulatory frameworks and internal policies.
- Collate and prepare status reports on top risks of the hospital's current risk posture and mitigation efforts.
B. Department Level Risk Assessment (DRA), Proactive, and Focused Risk Assessment
- Assist in organizing the yearly initiation of department level risk assessment activities.
- Monitor and track the timely submission of risk assessment reports from various departments.
- Aggregate and analyze data from departmental risk assessments and report to the ORM Department Head any identified common trends, potential risks, and areas requiring attention.
- Address questions and provide clarifications to departments regarding the risk assessment process, tools, and methodologies to promote understanding and compliance.
- Organize and lead sessions to guide departments through the risk assessment process.
- Conduct risk assessments for various operational areas, including but not limited to facility, clinical/patient safety, information security, and vendors, ensuring comprehensive risk coverage.
- Provide subject matter expertise on Information security and vendor risk management, contributing to the refinement and improvement of policies and procedures within the ORM framework.
C. Project Risk Assessment
- Consolidate departmental and project-level risk reports into a comprehensive risk report for the ORM Department Head, ensuring transparency and timely updates.
D. Risk Registry Review and Feedback
- Conduct thorough reviews of departmental risk registers to ensure accuracy and completeness.
- Provide feedback and recommendation to address any gaps, enhance risk mitigation strategies, and improve overall risk documentation practices.
E. Risk Treatment Plan Implementation Validation Activity
- Support the ongoing evaluation and validation of risk mitigation strategies, ensuring continuous improvement in risk management practices.
F. Data Review and Analysis
- Assist the ORM Department Head in utilizing data and analytics to track the effectiveness of risk mitigation strategies.
- Provide support in ensuring that risk management metrics are reviewed regularly, making recommendations to adjust strategies and ensure ongoing risk management success.
G. Trainings, Awareness, and Communications
- Support the ORM Department Head in building a risk-aware culture within the hospital by assisting in training, awareness campaigns, and communication efforts.
- Help foster a culture where risk management is embedded in decision-making, operational practices, and daily activities.
- Provide guidance and training sessions on risk management concepts and best practices to staff, executives, and other stakeholders.
H. Risk Management
- Collaborate with Business Continuity Management to ensure coverage on risks related to financial posture and business resiliency.
- Coordinate with Finance Risk Management in establishing financial risk controls and identifying trends in claims submissions.
- Participate in risk management projects and programs, particularly in information security and vendor risk assessment.
- Contribute to conducting gap analyses to identify areas for improvement in risk management practices and support ongoing alignment with regulatory and industry standards.
- Provide support to the ORM Head in strengthening its risk management practices which may involve recommending additional training, refining risk assessment methodologies, or implementing new tools to support risk identification and mitigation.
I. Administrative
- Maintaining the orderliness and cleanliness of the Risk Management Group office in compliance with Environment of Care (EOC) standards and practices.
- Managing departmental tools, documentation, and repositories, ensuring all materials are organized, up-to-date, and easily accessible.
- Safeguarding and monitoring all assigned equipment, materials, and supplies, ensuring proper storage, maintenance, and accountability in accordance with hospital policies and EOC requirements.
- Participating in and supporting the promotion of the Culture of Care program at St. Luke's Medical Center (SLMC).
J. Act as the team's representative in internal committees and meetings as assigned.
K. Engage in hospital events and activities as directed by the immediate superior.
L. Carry out other duties relevant to the position as assigned.
Qualifications
- Graduate of any four year course.
- Advanced training or relevant certifications in information security and compliance, vendor risk management is preferred.
- Minimum of 3 years of experience in risk management.
- Experience in enterprise risk management, vendor risk management, and information security management is an advantage.
- Proven experience in risk assessment methodologies, regulatory compliance, and risk reporting.
Required Skills
- High level of awareness and orientation of the hospital's organizational unit structures, policies, procedures, products, services, facilities and culture.
- Strong expertise in identifying, assessing, and managing operational risks.
- Proficiency with risk management tools and software.
- Analytical skills to track, monitor, and report on risks and mitigation efforts.
- Excellent written and verbal communication skills, with the ability to present risk reports to leadership.
Work Set-up
- Onsite
- Willing to work in Global City, Taguig City, E-Rodriguez, Quezon City and site visit to its subsidiaries and affiliates (shall have schedules in each site every week).