Classification: Fixed Term (Full Time)
Reporting To: Executive Director
Department Executive Director’s Office
Location Kampala, Uganda
ROLE DEFINITION
The Risk Manager is responsible for enhancing, implementing, and continuously improving the Infectious Diseases Institute’s Enterprise Risk Management (ERM) framework. The role provides operational oversight of institutional risk, strategic oversight remains the responsibility of the Board, delegated to the Executive Director and the Senior Management Team, supports evidence-based decision-making across the organization, and ensures IDI operates within acceptable risk tolerance levels.
The Risk Manager supports risk identification, assessment, monitoring, and reporting; institutional compliance; and business continuity planning. The role works in close collaboration with the Internal Audit team, maintaining a clear and complementary division of responsibilities: The Risk Manager focuses on forward-looking risk prevention and compliance, while Internal Audit retains full ownership of the whistleblower mechanism, fraud detection, investigation, and audit assurance.
KEY RESPONSIBILITIES
1. Enterprise Risk Management Framework
• Enhance, maintain, and continuously improve IDI’s ERM framework, policies, and procedures in line with international best practice (e.g., ISO 31000, COSO ERM) and the NGO operating context in Uganda.
• Establish and embed a consistent risk management methodology across all departments, programs, and projects.
• Maintain and regularly update the institutional risk register, ensuring all risk categories are accurately assessed, assigned to appropriate risk owners, and actively mitigated, with risks falling within Internal Audit’s mandate captured in coordination with that function.
• Coordinate periodic risk assessment exercises at both the institutional and program levels, facilitating risk workshops with departmental heads and the Senior Management Team.
• Prepare and present comprehensive risk reports to the Executive Director, Senior Management Team, and the Board, as required.
• Monitor the external risk environment, including regulatory, political, financial, and reputational risks relevant to IDI’s operations and donor-funded programs.
• Advise management on reputational risk considerations arising from program activities, partnerships, communications, or external developments.
2. Risk Culture and Capacity Building
• Champion a risk-aware culture across IDI by providing training, guidance, and practical tools that embed risk thinking at all levels of the organization.
• Develop and maintain risk management guidance documents, toolkits, and templates for use by program and departmental teams.
• Provide advisory support to project teams on risk identification and mitigation as part of project planning and implementation cycles.
• Design and deliver periodic risk management training for risk owners, departmental heads, and project teams, and monitor the uptake and effectiveness of these initiatives.
3. Compliance
• Serve as IDI’s institutional lead for regulatory and donor compliance, ensuring operations remain aligned with applicable Ugandan legal and regulatory requirements, donor requirements, and internal policies. This role is distinct from the fraud-related Compliance Officer function designated to the Senior Manager, Internal Audit under the Anti-Fraud and Whistle-blower Policy.
• Monitor and report on compliance with donor requirements, working closely with the Grants and Contracts team to identify and escalate compliance risks promptly.
• Coordinate with relevant teams to ensure IDI’s policies are current, communicated effectively, and consistently applied across the organization.
• Identify and monitor safeguarding-related compliance risks, ensuring IDI’s safeguarding policy and procedures are embedded across all operations and partner engagements.
• Support the development and periodic review of IDI’s data protection and privacy risk controls in line with applicable requirements.
• In collaboration with Internal Audit, lead staff awareness and training initiatives on compliance obligations, IDI’s Code of Conduct, and relevant institutional policies, including fraud prevention awareness, which remains distinct from fraud investigation.
4. Business Continuity Planning (BCP)
• Lead the regular review and updating of IDI’s BCP and Disaster Recovery Plan (DRP), ensuring alignment with operational realities and emerging risks.
• Conduct business impact analyses and facilitate BCP testing exercises, documenting outcomes and driving timely improvement actions.
• Report periodically to management on implementation and compliance status of the BCP/DRP.
5. Coordination and Stakeholder Engagement
• Maintain a close and collaborative working relationship with the Internal Audit team through regular information sharing, joint risk intelligence, and a coordinated assurance approach — while respecting the independence and distinct mandate of each function.
• Engage with external auditors, regulators, and donor representatives on risk and compliance matters, as required.
• Participate in relevant internal committees and management forums to provide risk and compliance advisory input.
PERSON SPECIFICATIONS
Qualifications
• Bachelor’s degree in Finance, Accounting, Business Administration, Law, or a related field from a recognized university.
• A professional qualification in risk management (e.g., IRM, CRMA, RIMS-CRMP) or a closely related compliance or governance field is required.
• A postgraduate qualification (MBA or Master’s in Risk, Compliance, or a related discipline) will be a distinct advantage.
Experience
• A minimum of seven (7) years’ progressive experience in enterprise risk management, compliance, or a related function within a sizeable and reputable organization, of which at least three (3) years are at a managerial level.
• Demonstrable experience working within or alongside NGOs, donor-funded programs, or international development organizations is strongly preferred.
• Experience developing and managing institutional compliance frameworks and grievance mechanisms.
• Experience developing and implementing BCP/DRP frameworks.
• Prior exposure to major donor accountability requirements (e.g., PEPFAR, USAID, Global Fund, DFID/FCDO) is a distinct advantage.
Technical Skills
• Strong knowledge of enterprise risk management frameworks (e.g., ISO 31000, COSO ERM).
• Understanding of Ugandan regulatory and legal requirements relevant to NGO operations.
• Proficiency in risk management tools, reporting systems, and MS Office applications.
• Knowledge of safeguarding principles and data protection frameworks applicable in Uganda.
Core Competencies
• Analytical thinking with the ability to interpret complex risk environments and present findings clearly to both technical and non-technical audiences.
• High levels of integrity, confidentiality, and professional ethics.
• Excellent report writing and presentation skills.
• Strong interpersonal and influencing skills, with the ability to engage credibly at senior management and Board level.
• Ability to work independently, manage multiple priorities, and meet deadlines in a dynamic environment.
• Sound judgment, discretion, and attention to detail, particularly in handling sensitive compliance matters.
How to Apply:
All applications will be received and reviewed through the BrighterMonday Portal by clicking on the 'Apply Here' section