Enterprise Risk & Governance
• Own and maintain the enterprise risk framework: risk register, risk appetite statement, risk taxonomy, and escalation policy
• Drive the risk reporting cycle — structured risk updates to the CEO and senior leadership; regulatory risk reporting to Latvijas Banka, FCA, and FinCEN as applicable
• Chair or co-chair the risk committee: agenda, cadence, participants, and decision authority
• Build risk ownership culture across business units — risk is not only the risk function's responsibility
DORA & Operational Resilience
• Own the DORA ICT risk management framework and lead the Register of Information workstream to meet the January 2027 hard regulatory deadline
• Own business continuity and disaster recovery planning — documented recovery objectives and tested plans for critical services
• Own third-party and vendor risk management: risk assessment of critical service providers, concentration risk, and exit planning
• Own the PSD2 operational resilience framework: 4-hour major incident reporting to Latvijas Banka, important business services definition, and impact tolerances
• Partner with the CTO and Head of Security on technology and cloud risk
EMI & Regulatory Risk
• Lead the operational risk framework and capital adequacy/safeguarding design for two parallel EMI applications (Latvia hub + UK EMI)
• Own ongoing capital adequacy monitoring under MiCA and PSD2 PI — maintain required buffers and escalate breaches
• Own risk-focused regulatory examination preparation and serve as the primary internal contact for risk-related regulator queries
• Coordinate with the VP of Legal on regulatory legal obligations and with the Global Chief of Compliance on AML/CTF risk appetite and financial crime risk thresholds
B2B Partner & Counterparty Risk
• Design and own the B2B partner risk assessment framework — onboarding risk scoring, ongoing due diligence, risk-tiered monitoring
• Own risk sign-off on material B2B partnerships — define thresholds beyond which CEO approval is required, and ensure high-risk review is fast and credible — a commercial enabler, not a friction point
• Define the risk-based conditions for which partner industries, geographies, and business models Paybis will and will not serve
• Manage partner concentration risk and delegated-compliance liability as B2B volume scales
Fraud & Financial Crime Risk
• Establish a unified fraud risk framework and appetite across the relevant business functions — creating clear ownership, consistent thresholds, and a single escalation path
• Set fraud risk appetite by channel, product, and geography — and own the decision when escalations breach threshold
• Coordinate with the Global Chief of Compliance on the fraud-AML/CTF intersection: typologies, SAR referrals, and financial crime risk appetite
• Own the sanctions screening risk framework and escalation policy for high-risk jurisdictions and counterparties
Product & Financial Risk
• Own product-launch risk gating for new products and markets — new products, geographies, and business lines as they enter the pipeline
• Manage crypto price volatility exposure on open positions: conversion timing, settlement risk, and liquidity buffers
• Own counterparty credit risk: liquidity providers, banking partners, card scheme exposure, and B2B client credit risk
• Oversee treasury risk: fiat and crypto balance management, currency exposure, and concentration risk