CIBI Information Inc.
Be part of CIBI Information Inc. , a purpose-driven company at the forefront of enabling better credit decisions in the Philippines and beyond. Role Overview The GRC Manager will be responsible for the design, implementation, and operationalization of CIBI’s integrated governance, risk, and compliance frameworks. This is a high-impact, individual contributor-plus role focused on ensuring that CIBI’s operations remain resilient, audit-ready, and fully aligned with the mandates of the Credit Information Corporation (CIC), the Data Privacy Act (DPA), and international standards (ISO/SOC 2). Duties AND RESPONSIBILITIES: Governance Framework & Strategy Operationalize the Enterprise Risk Management (ERM) and Governance frameworks to align with CIBI’s mission and vision and strategic objectives; Advisory on best industry practice in governance and regulatory compliance; Draft and maintain the repository of corporate policies, ensuring they are not merely documented but functionally embedded into departmental workflows. Evaluate the effectiveness of internal controls and provide technical recommendations to the Board and Senior Management on daily operations towards promotion of a culture of integrity, accountability and compliance by design. Enterprise Risk & Internal Controls Assist in the assessment, and prioritization of potential risks, including operational, compliance, financial, reputational, and strategic risks and the creation of risk mitigation plans through deep-dive risk assessments across all business units (Operational, Financial, Reputational, and Strategic). Develop and monitor Key Risk Indicators (KRIs) and control metrics to provide early-warning signals to the Risk Management Committee. Audit and test the efficacy of internal controls, ensuring the safeguarding of CIBI’s data assets and the reliability of reporting. Regulatory Compliance Management Monitor adherence to all relevant laws pertinent to the operations of CIBI and internal policies, including the Data Privacy Act of 2012, BSP regulations, Anti-Money Laundering (AML) and CIC Circulars, serving as a primary point of contact for regulatory inquiries. Conduct regular compliance "health checks" and gap analyses to ensure the organization maintains its "Advanced Tier" standing. Manage the end-to-back compliance lifecycle, from detection of potential non-compliance to the implementation of remedial actions. Technical Collaboration (ISO & SOC 2) Serve as the GRC lead in partnership with Internal Audit for ISO 27001 and SOC 2 Type 2 certifications and collaboration in all governance and compliance audit Map GRC requirements against technical security controls, ensuring that governance documentation matches technical implementation. Work with Lead Internal Auditor in remediating findings from ISO/SOC 2 audits by redesigning processes to meet international security and availability standards. Incident Response & Institutional Resilience Lead the GRC component of the Incident Response Plan, ensuring that compliance breaches are detected, reported, and mitigated within statutory timelines. Design Business Continuity and Crisis Management protocols focused on maintaining the integrity of CIBI’s credit database during unforeseen events. Coordinate with other departments, including Internal Audit and IT, for incident investigations and risk assessments. Reporting, Documentation & Training Document and maintain a centralized repository for all GRC policies, procedures, risk registers, and compliance reports. Ensure all GRC documentation aligns with regulatory and organizational standards, facilitating easy access for audits and regulatory reviews. Assist in the development and delivery of GRC training programs on compliance, risks and governance policies and the creation of awareness initiatives to promote ethical and compliance by design practices. Maintain up-to-date training materials that reflect regulatory changes and align with CIBI’s policies and procedures. JOB SPECIFICATIONS Educational Background Bachelor’s degree in Finance, Accounting, Law, Business Administration, or a related field. Master’s degree or equivalent preferred. Professional certifications (e.g., Certified Risk Manager, Certified Compliance Professional, or Certified Internal Auditor) are highly desirable. Experience 2-3 years of experience in governance, risk, compliance, or audit functions, with at least 1 year in a supervisorial or managerial role, preferably in financial services, banking, or credit bureau, audit compliance industries. Strong knowledge of relevant regulatory frameworks, particularly BSP and CIC regulations, Anti-Money Laundering (AML) laws, data privacy laws (e.g., Data Privacy Act of the Philippines). Key skills Deep understanding of governance, risk management, and compliance frameworks. Proven leadership and team management skills, with the ability to foster a collaborative and ethical work environment. Excellent analytical and problem-solving abilities, with a strategic mindset and attention to detail. Effective communication and interpersonal skills, with the ability to engage and influence stakeholders at all levels. Strong organizational and project management skills, with the ability to prioritize and manage multiple tasks. High ethical standards and integrity, with a commitment to upholding the company’s values and promoting a compliance-oriented culture. Ability to handle sensitive and confidential information with discretion. Proactive, resourceful, and self-motivated with a results-oriented approach.
CIBI Information Inc.