← All open jobs

Legal and Compliance · Not stated

Direct employer

Senior Risk Management Officer

TVET Council Uganda

KampalaSenior · Not statedCloses Wednesday, 21 October 2026, 23:59 EATChecked 9 Oct 2026
Illustration of an office desk with a laptop and notebook.

Published by employer

About this role

Role overview

Reports to: Manager Internal Audit and Risk Management (MIAR)

Organizational Unit: Internal Audit and Risk Management

Read full role

Location: TVET Head Office, Kampala

Basic Function

The Senior Risk Management Officer continuously strengthens enterprise risk management (ERM) across the TVET Council. The incumbent is responsible for coordinating risk identification, assessment, monitoring, and reporting processes, and for promoting a proactive risk-aware culture that advances the Council's mandate under the TVET Act 2025 and the TVET Policy Implementation Standards, 2019.

Enterprise Risk Management Coordination

a) Initiate the development and implementation of the Council's Enterprise Risk Management Framework and Policy.

b) Facilitate the periodic review of the Council's risk management framework including an assessment of the Council’s risk appetite.

c) Coordinate risk identification, assessment, and profiling exercises across departments, divisions, units, and projects.

d) Maintain and regularly update the Council's risk register, ensuring risks are properly categorized, rated, and assigned risk owners.

e) Track changes in the risk profile over time and flag emerging or escalating risks to the Manager Internal Audit and Risk Management.

f) Integrate and align departmental and project risk assessments with the Council's strategic and annual work plans.

Risk Mitigation and Control Monitoring

a) Support the risk owners/champions across departments to design and document appropriate risk mitigation strategies and action plans.

b) Monitor the implementation status and effectiveness of agreed risk mitigation measures and internal controls.

c) Recommend enhancements to policies, procedures, and controls in response to identified or emerging risks.

d) Conduct periodic risk-based reviews/spot checks of key processes to assess control effectiveness in collaboration with the team of Internal Audit section.

Risk Reporting

a) Prepare periodic risk management reports, e.g., quarterly risk registers, heat maps, key risk indicator dashboards for review by the Manager IARM.

b) Contribute risk analysis and advisory input for presentation to the Executive Director/Senior Management and the Audit, Risk Regulatory Committee.

c) Track and report on the status of risk incidents, near-misses, and lessons learned.

Training and Awareness

a) Coordinate risk management training, sensitization, and awareness sessions for staff and Council members.

b) Build departmental capacity for self-identification and reporting of risks.

c) Promote a proactive, risk-aware culture across the Council through communication and engagement activities.

Advisory Services

a) Provide advisory input to management on risk considerations in new projects, policies, and major decisions.

b) Conduct scenario analysis and stress-testing of key risks affecting the Council's mandate and service delivery.

c) Liaise with process owners/champions to ensure risk appetite and tolerance levels set by the Council are understood and applied.

d) Perform any other duties as may be assigned from time to time by the department leadership team.

Supervision Received: The Senior Internal Auditor (Risk Management) is directly supervised by Manager Internal Audit and Risk Management.

Supervision Exercised: None

Education requirements.

a) Bachelor's degree in Finance, Accounting, Business Administration, Technical & Vocational Education and Training or a related field.

b) Post graduate qualification in Risk Management, Business Administration, or a related field

c) Professional qualification or certification in risk management (e.g., CRMA, ISO 31000 Risk Management, or equivalent) is required.

d) Master's degree in accounting, finance, auditing, business administration, Information Systems, Technical & Vocational Education and Training or related field is an added advantage.

e) Additional certification such as COSO ERM, CIA, or CISA is an added advantage.

f) Membership with other professional bodies such as ICPAU, IIA, Corporate Governance, among other bodies.

Experience

a) At least Six (6) years relevant audit/risk management experience, with 3 years at a middle management level in a reputable organization, donor funded organizations or public institution.

b) Experience developing or implementing risk management frameworks in a public sector or regulatory agency is an added advantage.

Knowledge and Skills

a) Sound knowledge of enterprise risk management principles and frameworks (e.g., ISO 31000, COSO ERM).

b) Strong analytical skills, with the ability to translate risk data into practical insights and reports.

c) Excellent report-writing, presentation, and communication skills.

d) Strong stakeholder engagement and facilitation skills, with the ability to build a risk-aware culture across departments.

e) High integrity, objectivity, and sound judgment.

f) Familiarity with TVET sector issues is an added advantage.

Physical Demands: None

Travel requirements: Limited travel within/out of the country for official work

View advert & apply