AirBorneo→
Senior Manager/Manager, IT Governance &… at AirBorneo · Sarawak
Job Description
Senior Manager/Manager, IT Governance & Compliance
Location: Sarawak, Malaysia
| A. RESPONSIBILITIES |
1. IT Governance Framework and Policy Management
- Maintain the Technology governance framework, governance principles, decision rights, control structure and related governance documentation in accordance with approved organisational requirements.
- Coordinate the development, review, approval, publication and periodic refresh of Technology policies, standards, procedures and control requirements.
- Maintain the Technology governance document register, ownership matrix, review cycle and version-control requirements, ensuring obsolete or superseded documents are appropriately controlled.
- Assess governance gaps, overlaps or inconsistencies across Technology functions and recommend practical improvements to clarify accountability and strengthen control effectiveness.
- Provide guidance to Technology teams on the interpretation and application of approved governance requirements and ensure material exceptions are formally managed.
2. Compliance Monitoring and Assurance
- Develop and operate a risk-based Technology compliance monitoring programme covering approved policies, standards, procedures, governance controls and management requirements.
- Conduct periodic compliance reviews, control checks, self-assessments or evidence-based assurance activities and document findings in a consistent and auditable manner.
- Maintain the IT governance and compliance register, including control status, non-compliance, exceptions, remediation actions, accountable owners, target dates and supporting evidence.
- Challenge unsupported compliance declarations or incomplete evidence and require responsible owners to provide corrective information or remediation plans within agreed timelines.
- Escalate repeated, overdue, high-risk or high-impact non-compliance in accordance with approved governance and management escalation requirements.
3. Project, Change and Technology Process Governance Compliance
- Monitor adherence to approved Technology project governance requirements, including project onboarding, lifecycle controls, stage/gate reviews, mandatory approvals, documentation and closure obligations.
- Monitor compliance with approved Technology change management governance, including classification, risk assessment, approval, implementation evidence, emergency change controls and post-implementation requirements where applicable.
- Perform governance quality checks on material submissions before they are tabled to Technology leadership or relevant governance forums, focusing on completeness, required approvals and supporting evidence.
- Track governance obligations and exceptions arising from projects, changes and other Technology processes, ensuring overdue actions are followed up with accountable owners.
- Identify recurring governance failures or control breakdowns and recommend systemic corrective actions rather than relying solely on individual issue remediation.
4. Risk, Audit and Regulatory Coordination
- Coordinate Technology inputs, evidence and management responses for internal audit, external audit, risk reviews, compliance reviews and other assurance activities within the scope of the department.
- Track Technology audit findings, risk treatment actions and compliance remediation commitments to closure, ensuring accountable owners, due dates and evidence of completion are maintained.
- Support Technology risk and control assessments by ensuring identified governance or compliance weaknesses are documented, assessed and routed to the appropriate accountable function.
- Maintain readiness for assurance activities by ensuring key governance records, approvals, control evidence and compliance documentation can be retrieved efficiently and are appropriately retained.
- Coordinate with relevant corporate functions where Technology requirements intersect with cybersecurity, data protection, financial controls, procurement, records management, operational continuity or aviation-related obligations.
5. Governance Reporting and Management Information
- Produce regular Technology governance and compliance dashboards, summaries and management reports for the Head of Technology, Technology leadership and relevant governance forums.
- Provide clear analysis of compliance status, material control gaps, overdue remediation, audit findings, exceptions, recurring issues, decisions required and areas requiring management attention.
- Establish consistent compliance status definitions, evidence expectations, escalation criteria and reporting thresholds to improve transparency and comparability across Technology functions.
- Prepare governance and compliance information for leadership, Steering Committee, audit, risk, budget, management review and other governance discussions as required.
- Maintain auditable records of key governance decisions, approved exceptions, management directions, corrective actions and formal escalations.
6. Governance Exceptions, Remediation and Continuous Improvement
- Administer the Technology governance exception process, ensuring requests include clear rationale, risk assessment, compensating controls, accountable approval and defined expiry or review dates.
- Monitor remediation plans for governance and compliance findings, challenge overdue or ineffective actions and escalate matters where agreed corrective action is not progressing.
- Analyse trends in findings, exceptions, audit observations and non-compliance to identify root causes and recommend improvements to governance design, training, processes or control implementation.
7. Stakeholder and Team Management
- Set work priorities and maintain appropriate quality and documentation standards.
- Act as the principal operational point of contact for Technology governance and compliance matters, providing practical guidance to Technology managers, project teams and control owners.
- Facilitate governance reviews, compliance working sessions and remediation follow-ups, ensuring actions, decisions, owners and target dates are clearly recorded and monitored.
- Build a culture of accountability, evidence-based compliance and proactive control ownership across Technology, emphasising that governance requirements support reliable and safe airline operations rather than being treated as administrative exercises.
8. Regular Activities and Reporting Cadence
- Weekly: review material non-compliance, overdue remediation, governance exceptions, project/change governance breaches and matters requiring escalation; follow up accountable owners.
- Monthly: issue consolidated Technology governance and compliance reporting, including compliance status, audit/remediation progress, control exceptions, trends and management attention items.
- Quarterly or as required: coordinate targeted compliance reviews, policy/control attestations, governance maturity reviews, risk/control updates and management assurance activities.
- Annually: coordinate the Technology policy and governance document review cycle, refresh the compliance monitoring plan and support annual risk, audit and governance planning activities.
- Ad hoc: support audits, regulatory or management requests, investigate material governance concerns, prepare decision papers and coordinate urgent remediation activities.
Key Performance Measures / KPIs
| Governance document control | Technology governance documents have clear owners, approvals, current versions and review dates; overdue reviews and obsolete documents are identified and addressed. |
| Compliance monitoring | Planned compliance reviews and attestations are completed to the agreed schedule, with findings supported by appropriate evidence and consistent assessment criteria. |
| Remediation discipline | Audit findings, compliance gaps and corrective actions are assigned, monitored and closed or formally accepted within agreed timelines; overdue material items are escalated. |
| Project/change governance compliance | Required project and change governance controls, approvals and documentation are monitored, with repeated or high-impact breaches identified and addressed. |
| Audit and assurance readiness | Governance records, approvals, exceptions and control evidence are complete, traceable and retrievable to support internal/external assurance activities. |
| Exception management | Governance exceptions are formally documented, risk-assessed, approved by the appropriate authority, time-bound where applicable and reviewed through to closure. |
| Management reporting | Governance and compliance reporting is timely, accurate and decision-oriented, clearly identifying material gaps, trends, overdue actions and management attention items. |
| Stakeholder service | Technology teams receive practical governance guidance and clear compliance expectations, while accountable owners remain responsible for implementing and operating required controls. |
| B. ACCOUNTABILITIES |
- Ownership and integrity of the Technology governance framework, governance document register, compliance register, exception register and associated assurance records.
- Timely completion of planned governance reviews, compliance assessments, policy/control attestations and management reporting activities.
- Effective monitoring and follow-up of Technology policy, project, change and process governance requirements, with material non-compliance escalated in accordance with approved criteria.
- Timely closure or formal risk acceptance of audit findings, compliance gaps, governance exceptions and remediation actions within agreed management timelines.
- Quality, traceability and retrievability of compliance evidence, approvals, exceptions, corrective actions and governance decisions for audit and assurance purposes.
- Early identification of recurring control weaknesses, systemic governance gaps and material compliance risks, supported by practical recommendations for improvement.
- Performance, development and work quality of assigned IT Governance / Compliance team members and the effectiveness of governance guidance provided to Technology stakeholders.
The role is accountable for the quality of Technology governance and compliance oversight, monitoring and escalation. It does not replace the accountability of individual control owners, Technology managers, Information Security, Enterprise Risk/Compliance, Internal Audit or other formally designated assurance and approving authorities.
| C. AUTHORITY |
Decisions the Role May Make Independently
- Administer approved Technology governance and compliance processes, reporting calendars, templates, evidence standards, registers and routine assurance activities.
- Require Technology teams and control owners to provide compliance information, governance documentation, supporting evidence and corrective updates within agreed timelines.
- Return incomplete, inconsistent or unsupported governance/compliance submissions for correction before onward review or formal assessment.
- Classify and record compliance findings, exceptions, remediation status and governance observations in accordance with approved definitions and assessment criteria.
- Assign routine governance, compliance monitoring, evidence review and reporting responsibilities to assigned team members within approved role boundaries.
Approvals / Recommendations Within the Role
- Endorse the completeness and readiness of routine governance or compliance submissions for onward review by the Head or relevant approving authority.
- Recommend corrective actions, control enhancements, policy/process changes, governance exceptions, escalation, targeted assurance reviews or other remediation based on evidence and risk.
- Recommend updates to Technology governance frameworks, policies, standards, procedures, controls and compliance monitoring requirements based on operational findings and assurance results.
Budget, Resources and Assets
- Manage departmental resources, governance/compliance tools and approved operating expenditure assigned to the role within the organisation's Delegation of Authority (DoA).
- Monitor expenditure related to assigned governance, assurance, audit-support or compliance activities; procurement commitments, contractual awards, unbudgeted expenditure and other financial approvals remain subject to the applicable DoA and authorised approving authority.
Matters Requiring Escalation or Higher Approval
- Critical or high-risk non-compliance, significant control failure, repeated governance breaches or overdue remediation that could materially affect operations, security, regulatory obligations, financial integrity or management assurance.
- Policy or control exceptions that exceed delegated thresholds, materially alter risk exposure or require acceptance by a designated risk owner or higher approving authority.
- Matters involving suspected misconduct, fraud, deliberate circumvention of controls, legal/regulatory exposure or issues requiring independent investigation by Security, Compliance, Legal, Internal Audit or another authorised function.
- Material changes to approved governance requirements, policy waivers, risk acceptance, major audit commitments or decisions reserved under the company DoA or formal governance charters.
| D. DELEGATION OF DUTIES |
Acting / Backup Arrangement
During temporary absence, routine operational responsibilities may be assigned to a designated team member formally nominated by the role holder and acknowledged by the Head, IT PMO, Governance & Admin Support. For extended absence, an acting appointment should be confirmed by the Head in accordance with company practice.
Responsibilities That May Be Delegated
- Routine compliance evidence collection, register maintenance, document administration, meeting coordination, action tracking and preparation of standard governance or compliance reports.
- Follow-up with Technology teams and control owners on overdue attestations, remediation actions, governance documentation and supporting evidence.
- Preparation of compliance analysis, assurance working papers, policy review inputs and management reporting for review by the role holder or acting authority.
Limitations on Delegated Authority
- Delegation does not transfer the role holder's accountability for the quality and integrity of governance and compliance oversight unless a formal acting appointment is made.
- Formal risk acceptance, material policy exceptions, high-risk findings, investigation decisions, commitments of funds and approvals reserved under the DoA or another governance authority may not be delegated beyond the authority granted to the acting officer.
- Material decisions taken during an acting period must be documented and reported to the Head and, where appropriate, to the returning role holder.
| E. MINIMUM QUALIFICATIONS |
Education
- Bachelor's degree in Information Technology, Computer Science, Information Systems, Engineering, Risk Management, Business, Management or a related discipline.
- Postgraduate qualification in technology management, governance, risk, compliance, business or a related discipline is an advantage for the Senior Manager level.
Professional Certifications
- Professional certification in IT governance, audit, risk, compliance, security or service management is preferred, such as COBIT, CGEIT, CISA, CRISC, ITIL, ISO/IEC 27001 Lead Implementer/Auditor or equivalent.
- Project/change governance, quality management, internal audit or other risk/control-related certifications are an advantage depending on the assigned scope.
Relevant Experience
- Manager level: typically at least 8 years of relevant experience in IT governance, technology risk, compliance, assurance, audit, IT controls, PMO governance or a related Technology management environment.
- Senior Manager level: typically at least 10 years of relevant experience, with demonstrated leadership of enterprise Technology governance, risk/compliance, assurance or control improvement activities across multiple Technology domains.
- Experience in aviation, airline operations, transport, financial services, telecommunications or another regulated / operationally critical industry is strongly preferred.
- Demonstrated experience in policy and control governance, compliance monitoring, audit coordination, remediation tracking, management reporting, stakeholder challenge and governance improvement.
Technical Skills and Knowledge
- Strong knowledge of IT governance, risk and control principles, including practical application of frameworks and standards such as COBIT, ITIL and ISO/IEC 27001.
- Strong understanding of policy lifecycle management, compliance monitoring, control design and assessment, audit evidence, issue remediation, exception management and risk-based assurance.
- Working knowledge of project governance, change management controls, third-party/vendor governance, information security, business continuity and data protection requirements relevant to Technology operations.
- High proficiency in governance and reporting tools such as Microsoft Excel, Power BI, PowerPoint, SharePoint / Microsoft Lists, document repositories, GRC platforms or equivalent workflow and evidence-management tools.
- Ability to translate complex governance, risk, audit and compliance information into concise management insights, clear obligations, practical remediation actions and evidence-based recommendations.
Competencies and Behaviours
- High integrity, independence of judgement and objectivity, with the confidence to challenge unsupported assertions, weak controls or persistent non-compliance.
- Strong analytical thinking and attention to detail, with the ability to distinguish isolated issues from systemic governance or control weaknesses.
- Strong stakeholder management, facilitation and influencing skills, including the ability to work constructively with accountable owners while maintaining appropriate governance discipline.
- Persistent and structured follow-through on overdue actions, remediation commitments, exceptions and audit findings, with timely escalation where required.
- Ability to manage sensitive governance and compliance matters with appropriate confidentiality, professionalism and sound judgement.
- Leadership capability to coach team members, build governance awareness and progressively improve Technology governance and compliance maturity.
Regulatory / Industry-Specific Requirements
- Must comply with AirBorneo policies, Technology governance requirements, information security controls, records management requirements, corporate compliance obligations and applicable laws or regulations relevant to assigned duties.
- Must understand that Technology governance and control failures may affect airline operational continuity, aviation safety, cybersecurity, data protection, financial integrity and regulatory compliance; potential impacts must be identified and escalated through the appropriate accountable functions without assuming responsibilities reserved for specialist safety, security, legal, risk or audit authorities.