Job Description:
Shadow IT (eg. IT outside the IT governance) is a risk for any organization and even worse for regulated companies like banks. The role for BNP Paribas CIB EMEA Risk officer for Shadow IT is to ensure this risk is properly managed, contributing for Governance, Risk and Compliance Frameworks, within BNPP CIB EMEA.
To do so, there is a need to manage a global inventory referencing all shadow IT usage with their resulting IT risks and for this portfolio the shadow IT risk officer is in charge of liaising with business teams to identify new or evolving Shadow IT situations, challenge content declared, data completeness and consistency but also provide support and coordination during assessment and validation. Finally, he/she will ensure follow-up of related KPI and KRI to be able to perform the reporting about these risks to the top management.
Main Tasks:
- Management of the Risk Register:
- Update regularly IT risks criteria over time (risk category, owner, impact…)
- Initiate & support the annual review of all IT risks in the Risk Register
- Support risk assessment:
- Organize with relevant stakeholders the assessment/analysis about identified IT risks (e.g.: impact, mitigation…)
- Organize the validation of IT risks assessment
- Organize the compliance with the BNPP Risk Management process
- Collect new risk cards and challenge them with relevant stakeholders (e.g.: mitigation suggested)
- Reporting:
- Gather feedback regarding formalization of risk cards & ongoing mitigation measures from risk owners
- Follow KPI defined in risk cards (mitigation, impact…)
- Perform a reporting about risks and risks mitigation to the top management, raise alerts if needed
- Participate to the Business Line Risk committee to share inputs about risks (risks stored in Risk Register, level of risks, impact…)