Risk And Compliance Manager Job
Work Hours: Full-time, 08 hours per day
Salary:
Attractive
Job Deadline: 28 August 2026
Number of Jobs: 01
Hiring Entity: DFCU Bank
| DFCU Bank |
Location: In Uganda
Job Details:
Description
Reporting to Chief Executive Officer, dfcu Limited, the role is responsible for leading, designing, implementing and maintaining the risk management and compliance framework for the parent company and its non-bank entities, ensuring the holding company discharges obligations to the Bank of Uganda, the Capital Markets Authority, the Uganda Securities Exchange and other regulators, and providing the Board and its Audit and Risk Committees with an independent, consolidated view of the Group risk and compliance profile.
KEY ACCOUNTABILITIES:
Risk Management and Governance
Develop, maintain and obtain Board approval for the risk management framework, risk taxonomy, risk appetite statement and supporting policy suite, and ensure proportionate adoption by each non-bank entity.
Maintain the risk register and top and emerging risk profile across strategic, financial, operational, conduct, financial crime, technology, legal and reputational risk.
Facilitate risk and control self-assessments, monitor adherence to approved appetite and internal control standards, and track agreed mitigation actions to closure.
Embed a sound risk culture and support first line ownership of risk across the parent and non-bank entities.
Prepare and present risk exposure reports, trend analysis, and mitigation recommendations to the Board and Management Committees.
Compliance Monitoring and Regulatory Oversight
Maintain the regulatory obligations register, mapping every applicable statute, regulation, guideline, licence condition and reporting obligation to a named owner, a control and a monitoring frequency.
Operate horizon scanning, impact assessment and implementation tracking for regulatory change across BoU, CMA, USE, FIA, PDPO, the NGO Bureau and URA.
Design and execute a risk-based compliance monitoring and testing programme, with documented findings, agreed actions and follow-up to closure.
Maintain the breach, incident and regulatory correspondence registers; manage notification of reportable breaches within prescribed timelines; and support licensing applications and ongoing licence conditions for new entities and activities.
Oversee compliance with the Data Protection and Privacy Act, including registration with the Personal Data Protection Office, records of processing, data subject requests and personal data breach management.
Oversee sanctions, PEP and adverse media screening of counterparties, investee companies, donors, grantees, suppliers and staff.
Own the anti-bribery and corruption, gifts and hospitality, conflicts of interest and whistleblowing arrangements for the parent and non-bank entities.
To act as the Money Laundering Control Officer and Data Privacy Officer for Limited & non bank subsidiaries
Risk Identification and Control Effectiveness
Conduct risk identification and assessment exercises across departments and operational areas.
Review and evaluate the adequacy and effectiveness of internal controls and risk mitigation measures.
Provide guidance to management and staff on corrective actions required to address identified risk and compliance gaps.
Conduct follow-up reviews to ensure timely implementation of agreed action plans.
Risk Awareness and Capacity Building
Promote awareness of risk management and compliance requirements through training, workshops, guidance notes, and stakeholder engagement.
Support staff and management in understanding and implementing the company’s risk management methodologies, frameworks, policies, and procedures.
Encourage a culture of accountability, compliance, and proactive risk management across the organization.
Reporting and Risk Analytics
Prepare periodic risk and compliance reports, dashboards, and analytics for Management, Board Committees, and regulators.
Compile and analyse operational risk data, key risk indicators (KRIs), incident reports, and loss event data.
Reporting on operational risk, financial risk, compliance, and AML/CFT activities.
Professional Development and Continuous Improvement
Maintain up-to-date knowledge of risk management, compliance, governance, and regulatory developments.
Participate in continuous professional development initiatives to enhance technical and professional competence.
Contribute to the continuous improvement of risk management tools, frameworks, methodologies, and reporting processes.
KNOWLEDGE, SKILLS, AND EXPERIENCE REQUIRED:
Education and Certification
A degree in law, finance, accounting, economics, business administration, risk management or related discipline; a relevant postgraduate qualification is an added advantage.
At least one relevant professional certification, held or obtained within an agreed period of appointment – for example CAMS, the ICA Diploma in Governance, Risk and Compliance, CRMA, CIA, CRISC, CGRC, PRM, FRM, CPA(U), ACCA, or admission as an Advocate of the High Court of Uganda.
Experience
A minimum of 3 to 5 years’ experience in risk management, compliance, regulatory affairs, internal audit or financial services legal practice.
Demonstrable experience of direct engagement with financial sector regulators and of preparing and presenting reporting to a board or board committee.
Experience in a group, multi-entity or holding company environment, or in capital markets, asset management or the donor-funded sector, is a distinct advantage.
Technical Knowledge
Working knowledge of the Ugandan regulatory framework, including the Financial Institutions Act and its regulations, the Bank of Uganda Corporate Governance Guidelines, the Anti-Money Laundering Act, the Capital Markets Authority Act and USE Listing Rules, the Data Protection and Privacy Act, the Companies Act and the Non-Governmental Organizations Act.
Familiarity with the FATF 40 Recommendations, Basel Committee corporate governance principles, COSO ERM, ISO 31000, ISO 37301 and the IIA Three Lines Model.
Competence in risk assessment methodology, control design and testing, key risk indicator development and risk reporting; proficiency in Excel, Word and PowerPoint.
Behavioural Competencies
Excellent written and spoken English, including the ability to write concise, decision-ready board papers.
Strong analytical and organizational skills, with the ability to interpret complex regulatory text and translate it into practical, proportionate controls.
Personal integrity and the courage to raise and escalate difficult issues, including where this places the role holder in disagreement with executive management.
Strong influencing and stakeholder management skills, with the ability to secure outcomes across entities where the role holder has no direct line authority.
Application procedure
If you believe you meet the requirements as noted above, please use the link below to apply;
Once there, click on “Career Opportunities” to get started. (We recommend using Google Chrome for the best experience.)
Deadline: Friday 28th August 2026
Only short-listed candidates will be contacted.
Posting Date: 2026-07-19