1
Formulate and implement Information Security and Cyber security risk management policies
2
Provide relevant information to CRO regarding the information Security and Cyber risks
3
For the relevant functional risks, identify, analyze and report and escalate the following to the CRO and CEO along with recommended action plan for Early warning signals, Emerging risks, Major findings, Near miss and loss events and fraud incidents.
4
Ensure adherence to the guidelines pertinent to SEBI in respect of RMF and relevant principles thereunder including risk identification, risk management, risk reporting (both periodic and escalation of material incident) and corrective actions taken.
5
Formulate and review the RCSA for key risks and controls and periodically provide inputs to update the RCSA for the Information security area.
6
Responsible for the governance (incl. reputation and conduct risk associated for the respective function)
7
Maintaining risk level as per the risk metric
8
Define specific responsibilities regarding risk management of key personnel reporting to CISO
9
Undertake immediate corrective action for non-compliance or major finding post approval from CEO as per DoP and shall report to CRO regarding the risk reports.
10
Perform adequate due diligence of outsourced vendors prior to onboarding
11
Ensure periodic assessment of outsourced vendors considering following elements:
- Review of vendors' people, systems and processes
- Documentation and communication of error tolerance and code of conduct and monitoring breaches
- Monitor fraud vulnerabilities in the outsourced process
- Report SLA breaches
Key Result Areas
- Adherence to Risk Management Framework
- Risks and inconsistencies identified and reported to CEO / CRO
- Timely reporting of identified risks and outliers to CEO / CRO
- Timely implementation of corrective actions for the risks and deviations
- Reporting of Risk incidents / events