Job Title: Risk and Compliance Manager
Organisation: Dfcu Bank
Duty Station: Kampala, Uganda
About Organisation:
dfcu Bank is part of dfcu Group, a Ugandan financial services firm. The Group comprises dfcu Bank and dfcu Investment Management. dfcu Bank offers a wide range of products and services in personal banking, business banking, and corporate banking.
Job Summary: Reporting to Chief Executive Officer, dfcu Limited, the role is responsible for leading, designing, implementing and maintaining the risk management and compliance framework for the parent company and its non-bank entities, ensuring the holding company discharges obligations to the Bank of Uganda, the Capital Markets Authority, the Uganda Securities Exchange and other regulators, and providing the Board and its Audit and Risk Committees with an independent, consolidated view of the Group risk and compliance profile.
Key Duties and Responsibilities:
Risk Management and Governance
- Develop, maintain and obtain Board approval for the risk management framework, risk taxonomy, risk appetite statement and supporting policy suite, and ensure proportionate adoption by each non-bank entity.
- Maintain the risk register and top and emerging risk profile across strategic, financial, operational, conduct, financial crime, technology, legal and reputational risk.
- Facilitate risk and control self-assessments, monitor adherence to approved appetite and internal control standards, and track agreed mitigation actions to closure.
- Embed a sound risk culture and support first line ownership of risk across the parent and non-bank entities.
- Prepare and present risk exposure reports, trend analysis, and mitigation recommendations to the Board and Management Committees.
Compliance Monitoring and Regulatory Oversight
- Maintain the regulatory obligations register, mapping every applicable statute, regulation, guideline, licence condition and reporting obligation to a named owner, a control and a monitoring frequency.
- Operate horizon scanning, impact assessment and implementation tracking for regulatory change across BoU, CMA, USE, FIA, PDPO, the NGO Bureau and URA.
- Design and execute a risk-based compliance monitoring and testing programme, with documented findings, agreed actions and follow-up to closure.
- Maintain the breach, incident and regulatory correspondence registers; manage notification of reportable breaches within prescribed timelines; and support licensing applications and ongoing licence conditions for new entities and activities.
- Oversee compliance with the Data Protection and Privacy Act, including registration with the Personal Data Protection Office, records of processing, data subject requests and personal data breach management.
- Oversee sanctions, PEP and adverse media screening of counterparties, investee companies, donors, grantees, suppliers and staff.
- Own the anti-bribery and corruption, gifts and hospitality, conflicts of interest and whistleblowing arrangements for the parent and non-bank entities.
- To act as the Money Laundering Control Officer and Data Privacy Officer for Limited & non bank subsidiaries
Risk Identification and Control Effectiveness
- Conduct risk identification and assessment exercises across departments and operational areas.
- Review and evaluate the adequacy and effectiveness of internal controls and risk mitigation measures.
- Provide guidance to management and staff on corrective actions required to address identified risk and compliance gaps.
- Conduct follow-up reviews to ensure timely implementation of agreed action plans.
Risk Awareness and Capacity Building
- Promote awareness of risk management and compliance requirements through training, workshops, guidance notes, and stakeholder engagement.
- Support staff and management in understanding and implementing the company’s risk management methodologies, frameworks, policies, and procedures.
- Encourage a culture of accountability, compliance, and proactive risk management across the organization.
Reporting and Risk Analytics
- Prepare periodic risk and compliance reports, dashboards, and analytics for Management, Board Committees, and regulators.
- Compile and analyse operational risk data, key risk indicators (KRIs), incident reports, and loss event data.
- Reporting on operational risk, financial risk, compliance, and AML/CFT activities.
Professional Development and Continuous Improvement
- Maintain up-to-date knowledge of risk management, compliance, governance, and regulatory developments.
- Participate in continuous professional development initiatives to enhance technical and professional competence.
- Contribute to the continuous improvement of risk management tools, frameworks, methodologies, and reporting processes.
Qualifications, Skills and Experience:
Education and Certification
- A degree in law, finance, accounting, economics, business administration, risk management or related discipline; a relevant postgraduate qualification is an added advantage.
- At least one relevant professional certification, held or obtained within an agreed period of appointment – for example CAMS, the ICA Diploma in Governance, Risk and Compliance, CRMA, CIA, CRISC, CGRC, PRM, FRM, CPA(U), ACCA, or admission as an Advocate of the High Court of Uganda.
Experience
- A minimum of 3 to 5 years’ experience in risk management, compliance, regulatory affairs, internal audit or financial services legal practice.
- Demonstrable experience of direct engagement with financial sector regulators and of preparing and presenting reporting to a board or board committee.
- Experience in a group, multi-entity or holding company environment, or in capital markets, asset management or the donor-funded sector, is a distinct advantage.
Technical Knowledge
- Working knowledge of the Ugandan regulatory framework, including the Financial Institutions Act and its regulations, the Bank of Uganda Corporate Governance Guidelines, the Anti-Money Laundering Act, the Capital Markets Authority Act and USE Listing Rules, the Data Protection and Privacy Act, the Companies Act and the Non-Governmental Organizations Act.
- Familiarity with the FATF 40 Recommendations, Basel Committee corporate governance principles, COSO ERM, ISO 31000, ISO 37301 and the IIA Three Lines Model.
- Competence in risk assessment methodology, control design and testing, key risk indicator development and risk reporting; proficiency in Excel, Word and PowerPoint.
- Excellent written and spoken English, including the ability to write concise, decision-ready board papers.
- Strong analytical and organizational skills, with the ability to interpret complex regulatory text and translate it into practical, proportionate controls.
- Personal integrity and the courage to raise and escalate difficult issues, including where this places the role holder in disagreement with executive management.
- Strong influencing and stakeholder management skills, with the ability to secure outcomes across entities where the role holder has no direct line authority.
How to Apply:
All suitably qualified and Interested applicants should apply online at the link below.
Opens the employer’s application pageApply Now →
Deadline: 28th August 2026
NB: Only shortlisted candidates will be contacted.
For more of the latest jobs, please visit https://www.theugandanjobline.com or find us on our facebook page https://www.facebook.com/UgandanJobline
Level of Education: bachelor degree
Work Hours: 8
Experience in Months: 36