Internal Controls
- Execute the daily operational activities of the internal control framework across HQ corporate functions and preschool centres.
- Conduct regular control testing and compliance assurance reviews to evaluate control designs and operating effectiveness (e.g., centre fee collections, decentralized procurement workflows, government grant/subsidy reconciliations, vendor management).
- Identify operational gaps and process vulnerabilities, offering pragmatic recommendations for control enhancements that consider the challenges of frontline educators.
- Monitor, log, and track the remediation of identified control deficiencies internally and by independent auditors, collaborating closely with business unit process owners to ensure timely resolution.
- Support coordination efforts with internal and external auditors to streamline regulatory, compliance, and financial statement audits.
Enterprise Risk Management (ERM)
- Facilitate the ongoing operationalisation of the Enterprise Risk Management framework across all corporate functions and business units.
- Maintain and systematically update enterprise and department-level risk registers, ensuring emerging risks (e.g child safety hazards, operational data leaks, and macroeconomic shifts) are accurately captured.
- Perform risk assessments and analyse residual risk levels against established corporate risk appetites and tolerances.
- Conduct root-cause analyses on key operational risk incidents, tracking the implementation and progress of management action plans.
Control Self-Assessment (CSA)
- Drive and execute the annual Control Self-Assessment (CSA) framework rolled out across various business units and departments to ensure robust management control attestations.
- Review, validate, and critically challenge the completeness and accuracy of CSA submissions provided by HQ teams and center leaders.
- Identify systemic control gaps from CSA data and partner with business unit process owners to establish and track formal remediation plans.
Business Continuity Planning (BCP)
- Design, maintain, and own the documentation of the organisation's Business Continuity Planning (BCP) framework and operational resilience strategies.
- Plan, lead, and execute BCP tabletop exercises and crisis simulation programmes, proactively identifying and logging operational bottlenecks or recovery gaps.
- Lead fact finding, report drafting, and operational coordination during crisis management activation as a core executor of the organisation's Crisis Management Plan.
Data Governance
- Maintain the Data Governance framework, ensuring alignment with ethical guidelines, applicable data privacy laws, and NFC's corporate values.
- Maintain the enterprise-wide data inventory
- Provide oversight of NFC's Data Governance Committee and provide regular trainings and updates to Data Champions
- Lead investigations and draft reports on data-related (including personal data) incidents.
Stakeholder Engagement & Reporting
- Assist in compiling high-quality data insights, metrics, and progress materials for executive reporting to the Risk Management Committee and Audit & Risk Committee.
- Collaborate closely with business units and functional teams to build risk culture, operational compliance, and awareness across all levels.
- Conduct localised briefings and assist in updating training materials related to internal controls, ERM, data protection, CSA and BCP protocols.
- And other duties where required.
Experience & Education
- Bachelor's degree in Accounting, Finance, Business Administration or a related discipline.
- Minimum 6 to 10 years of professional experience in internal controls, risk management, internal/external audit, or operational compliance roles.
- Prior experience working within a professional services firm or the education/preschool sector is highly advantageous.
Technical Knowledge
- Strong understanding of internal control frameworks (e.g., COSO) and Enterprise Risk Management guidelines (e.g., ISO 31000).
- Familiarity with the regulatory landscapes impacting social enterprises and the education sector in Singapore, including the Personal Data Protection Act (PDPA) and Early Childhood Development Agency (ECDA) operational parameters.
- Basic understanding of GRC (Governance, Risk, and Compliance) platforms or structured digital tracking workflows.
- Ability to interpret regulatory changes and translate risks into clear, center-appropriate business documentation and control requirements.
Key Competencies
- Analytical Rigor: Ability to analyze diverse operational workflows, identify underlying control gaps, and map them to business risk scenarios.
- Collaborative Problem Solving: Strong capability to drive the adoption of risk policies while maintaining supportive, constructive, and effective relationships with cross-functional business units.
- Clear Communication: Ability to articulate risk impacts and control parameters in simple, accessible, and non-technical narratives to non-financial operators and center staff.
Certification Preference
- Professional qualifications such as Certified Internal Auditor (CIA), Certified Public Accountant (CPA / CA), Certified Information Systems Auditor (CISA), or foundational business continuity certifications (e.g., ABCP / AMBCI) are a plus.
Desired Skills, Experience And Qualities
- High EQ & De-escalation: Exceptional emotional intelligence to handle stakeholder resistance smoothly during control rollouts, compliance tracking, and policy updates.
- The Enabling Mindset: A functional focus on being an enabler of innovation—providing the clear guardrails that allow operational and center teams to move fast safely, rather than acting as an administrative roadblock.