Newport, Wales, United Kingdom
As Head of Operational Assurance at Homeprotect my leadership has been dedicated to advancing a comprehensive operational assurance strategy. This role gives oversight to Business Continuity Management, Operational Resilience, Risk Management (including TPRM), Fraud and Incident Management to ensure a robust business and continuous services to customer can be provided. Previous leadership roles in resilience, audit, governance, risk, and compliance have strengthened cross-departmental and cross 3 lines of defence collaboration and regulatory alignment across the organisations I have worked at. Committed to continuous improvement, development of true and full governance practices, delivery of end to end assurance schedules and commitment to services to the customer.
As Head of Operational Assurance at Homeprotect my leadership has been dedicated to advancing a comprehensive operational assurance strategy. This role gives oversight to Business Continuity Management, Operational Resilience, Risk Management (including TPRM), Fraud and Incident Management to ensure a robust business and continuous services to customer can be provided.
Continuing the delivery of the Operational Resilience but now an all-embracing concept of Business Resilience; this is a concept derived from encompassing all resilience focused workstreams to create a streamlined and consistent approach across EUI. This is encompassing specifically the concepts of: Operational Resilience, Business Continuity Management, Technology and Cyber Resilience, Third-party Resilience Risk, and Business Incident and Crisis Management. The focus is for the organisational capability to prevent, adapt, respond to, recover and learn from operational disruption that impact the delivery of all business services across EUI, and in more depth, the recovery of our Important Business Services (IBS) as defined by the FCA and PRA under the UK Operational Resilience regulations. IBSs are defined as services that, if disrupted or made unavailable, could cause intolerance harm to our customers, or pose a risk to the soundness of the UK financial system. The benefit of having all these elements together, means we can access, manage, and mitigate potential flaws in the areas before they cause detrimental damage to our business and therefore customer and financial market. Enhancing our work in this area I am responsible for directing the continuous development, embedding and management of Business Resilience within EUI; FCA Certified and charged with an annual fit and proper assessment to ensure I can continue delivering the role to the highest standard. Leading a team of 15 to facilitate all works within these areas, reporting to the CIO as part of Admiral’s Tech Leadership Team alongside the CISO and Head of First Line Risk but spanning across all business areas. Key stakeholders include all SMFs (CRO, CFO, and Directors of Depts), Chair of the EUI Resilience Committee and reporting to the Board on a regular basis.
FCA Certified and fundamentally responsible for creating a resilient organisation across business, technology, people, process and third parties. Accountable for transitioning all Operational Resilience Programme output (processes, procedures, policies, frameworks, and output from IBS Steps 1-8) into BAU. Currently working towards developing a full governance framework which includes an effective department, committee structure and escalation processes. Facilitating communications across EUI and developing training for staff across the business. Attendance at multiple meetings to ensure operational resilience is considered in process such as change management, risk management, business continuity and procurement / third party. Presenting at Board meetings to ensure all levels of the business are involved and up to date with the resilience status of the business. Enhancing process mapping to ensure all areas of IBS are considered and further increasing the complexity of scenario testing, tracking all vulnerabilities identified within remediation plans and ensuring the self-assessment is maintained up to date, relevant and ready for the regulation when requested. Day to day activity includes owning and operating an annual plan of works as follows: -IBS review and updates -Testing of IBS and tolerance levels -Resilience assessments -Managing remediation plans to completion -Reporting of operational resilience progress and status -Effective risk management of identified resilience risks across the business and IBS departments -Maintenance of policies, procedures, and frameworks Working across departments within Admiral such as Procurement / third parties, BCM / Facilities and Risk to provide support in operational resilience related activities, including supplier management, business impact assessment and risk management processes.
Responsible for managing the Governance & Reporting team within the Customer and Conduct area of the UK business, responsible for all reporting regarding customer, and conduct of the business as a result. Reporting on all products (Motor, HH, Van, Pet, Travel) in areas such as complaints, FOS, call answer rate and fair outcomes; in addition to cultural areas such as staff engagement, attrition, and absence. Also addressing a large area of risk within the customer conduct area and applying and testing of KRIs, GMS and CRMI. Governance duties span the development of policies and procedures, terms of reference and management of working groups and committees. Secretariat duties for the Conduct Risk Working Group (CRWG) and Customer Committee (CC) and forward reporting to RMC, GRC and EUI Board. Attendee duties where necessary.
As the Compliance, Risk and Internal Controls Manager I sit as the second line of defence and manage risk and control environments for Tata Steel Europe, I audit and assess ‘As Is’ processes, procedures and policies and recommend changes contributing into a ‘To Be’ operating model or functional end to end delivery cycle for financial control environments and report directly to senior management on the results. The role focus is ‘process and documentation’ (including but not limited to companywide Risk and Control Matrices, business process narratives and Internal Control and Compliance Manual), line managing a team and an annual plan of works in line with compliance and internal controls remits laid out below working closely with the Risk Management Team. Day to day development of a risk based approach to all internal controls and compliance work we currently undertake, with the aim to be fully aligned to business risks and approaches, assisting with meeting strategic business needs and objectives. From a compliance perspective, I manage a number of activities which include but are not limited to: IT access and segregation of duty, mandatory e-learning completion, expenses and credit card activities, monitoring internal audit activity and following up on implementation of financial recommendations, updating and writing policies for all areas of the business, HMRC SAO tax (VAT/PAYE) testing and maintaining an understanding of regulatory requirements. Key contact for the General Data Protection Regulation (GDPR) for the Finance function in Europe and India, which sees me sit on the working group committee and continually assess risks; I then implement changes and controls to areas of weakness to ensure compliance with the regulation. I consult with the project team for the outsourcing of business processes (HR, Finance and Procurement) from a controls, compliance and GDPR perspective, providing assurance that robust controls and governance are in place.
Tata Steel is one of the largest providers of Steel in the World and as the Compliance and Internal Controls Analyst I sit as the second line of defence and manage risk and control environments for Tata Steel Europe consisting of approx. 50 business entities, I test and examine the financial control environments providing advice on effectiveness and efficiency. I report directly to senior management on the results and produce annual reports by business entity, which then feed into the financial statement, this confirms that any results we publish are accurate from a control environment viewpoint. I review at all business cycles including but not limited to, sales, purchasing, stock, fixed assets, information technology, HR & payroll and reporting. My work also sees me as the main contact and facilitator of quarterly and annual external audits from a financial controls perspective. From a compliance perspective, I manage a number of activities which include but are not limited to: IT access and segregation of duty, mandatory e-learning completion, expenses and credit card activities, monitoring internal audit activity and following up on implementation of financial recommendations, updating and writing policies for all areas of the business, HMRC SAO tax (VAT/PAYE) testing.
PwC is part of the ‘Big 4’ accountancy and audit practices and working in the realms of Internal Audit and Controls Assurance (including Information Technology General Controls (ITGCs)) as a Senior Associate, I assessed and reviewed business processes and controls aiming to mitigate risks across the business. I developed risk and control frameworks for organisations in an attempt to assist them with the management of risks. I managed clients and projects across both public and private sectors in multiple organisations across England and Wales as follows: Private Sector – Insurance (Aviva, Friends Life, LV, Zurich), Defence (Babcock); Public Sector – NHS (Wales), Local Government (Incl. Police), Education (Schools, Colleges & Examining Bodies). I managed client portfolios and undertook meetings with clients and executives from across these businesses and liaise to arrange audit fieldwork, reporting and the development of risk and control frameworks. Along with people management I also undertook reviews of financial aspects of audit and project work, including budget and time monitoring. I led teams of varying numbers and this aspect of the role includes general supervision, guidance, review time, sharing knowledge and more. I also provided tutoring / teaching sessions to newer members of the organisation on a national basis. I was awarded the additional role of Internal Audit Champion Role for South Wales; this role included being a point of contact for Internal Audit related queries, providing tutoring and coaching to members of staff and attending national events as the face of Internal Audit for South Wales.
Baker Tilly is an international accountancy firm, currently within the Mid-Tier Accountancy firms in the UK. The South West and Wales department operates with a team of 10 internal auditors working across the region in providing essential advice and assurance to public sector organisations and institutions in relation to all aspects of risk and the mitigation of risk designed to add value. On a daily basis I would engage with employees from various Public Sector institutions across financial and non-financial areas of the business and the development of key risk and control frameworks and with the aim of providing assurance to operational business systems. I was involved in all aspects of the audit process from scoping meetings, planning engagements, undertaking audits, debriefing clients and follow up. I also undertook the task of training all new employees to the office in the full audit process.