- KPJ HEALTHCARE UNIVERSITY _NILAI Nilai Negeri Sembilan Malaysia
Working Location
Job Description
Responsibilities
1. Risk Management
• Perform biannual risk assessments to identify strategic, operational, financial, compliance, and reputational risks and ensure adherence to internal controls and external regulations.
• Assist and update the risk register, ensuring risks are identified, analysed, and mitigated effectively through quarterly reviews.
• Support risk owners in developing risk treatment plans and monitor their implementation.
• Assist and update the KPJU top risk registered in the CURA system and submit it to GM for approval by quarterly reporting.
• Collaborate with cross-functional teams to ensure risk management practices are integrated into business processes.
2. Compliance Management
• Ensure compliance with ISO 9001, ISO 21001, OSHA, PDPA, MACC Act, and other relevant regulations.
• Assist in regulatory and compliance audits by preparing documentation and coordinating responses.
• Assist in developing, reviewing, and updating compliance policies, SOPs, and guidelines in line with legal and regulatory requirements.
• Conduct internal compliance audits and self-assessments to identify potential gaps and recommend improvements.
• Assist and update the KPJU compliance registered in the CURA system and submit it to GM for approval through monthly reporting.
• Keep abreast of regulatory changes and recommend necessary updates to policies and practices.
• Maintain records of licenses, permits, certifications, and regulatory submissions.
3. Incident Reporting and Investigation
• Oversee the detection, reporting, and tracking of workplace incidents, accidents, and near-misses.
• Facilitate incident investigations and root cause analysis (RCA) to determine contributing factors and recommend corrective actions.
• Manage the Incident Reporting System (Q-Radar) to collect, analyze, and report data on incidents (with 24 hours for sentinel/major events and 48 hours for minor events).
• Manage the incident reporting through WhatsApp immediately to Group Risk, Compliance and Integrity (GRCI), KPJ Healthcare Berhad.
• Develop and maintain incident reporting metrics, ensuring accurate reporting and trend analysis to identify areas for improvement. (with 24 hours for sentinel/major events & 48 hours for minor events).
• Work closely with internal teams and regulatory bodies to ensure timely and effective incident resolution.
• Submit the declaration of non-clinical incidents to GRCI through monthly reporting.
4. Training & Awareness
• Organize training sessions for academic and administrative staff on risk management, compliance, PDPA, and integrity governance.
• Assist in providing compliance guidance to schools and professional services.
5. Others
• Oversee documentation and minutes as the secretary for the ISO certification Management Review Meeting (MRM).
• Work collaboratively with the Quality team to exchange ideas and enhance operations by proposing, supporting, and implementing continuous improvement initiatives, as well as refining processes and
procedures to optimize results and improve service quality, in alignment with quality standards, university requirements, and customer expectations.
• Communicate with personnel at all levels, internally and externally to the university in relation to quality matters.
Education:
1. Bachelor’s degree in finance, Law, Risk Management or a related field.
2. Professional certifications such as Certified Risk Management (CRM) and ISO 31000 Risk Management System are an advantage.
Knowledge and Experiences:
1. 2-3 years of experience in risk management, compliance, governance, or internal audit.
2. Strong knowledge of ISO 21001, ISO 9001, OSHA, PDPA, MACC Act, and Malaysian higher education regulations.
3. Experience in conducting compliance audits, risk assessments, and investigations.
4. Familiarity with Enterprise Risk Management (ERM) frameworks, MQA accreditation, and governance policies.
Skills & Competencies:
1. Analytical and problem-solving skills to identify compliance gaps and risk exposures.
2. Excellent communication and report-writing skills for internal and external reporting.
3. Strong ethical judgment and attention to detail in handling sensitive information.
Technical skills required
1. Proficiency in risk and compliance management software (e.g., GRC tools).
2. Familiarity with PDPA regulations and university data protection practices.
3. Ability to interpret legal and regulatory documents and translate them into organisational policies.
Special skills required
1. Strong analytical and problem-solving skills.
2. Detail-oriented with a focus on accuracy.
3. Effective project management skills to handle multiple tasks simultaneously.
4. Proficiency in Microsoft Excel and PowerPoint.
Personal attributes
1. Managing People & Performance
2. Results-oriented mindset, with the ability to work under pressure to meet deadlines.
3. Self-motivated and able to work independently.
4. Strong ethics and integrity.
5. Openness to learning and adapting to change.
6. A collaborative and team-oriented approach.
Important Information
Never provide your bank or credit card details when applying for jobs. Do not transfer any money or complete unrelated online surveys. If you see something suspicious, Report this Job ad.