Senior Manager, Audit & Compliance
NTUC LearningHub- Posted an hour ago
- Be among the first 10 applicants
Job Description
The ideal candidate will drive the NTUC LearningHub's (LHUB) overarching governance, internal controls, and data protection architecture. The core focus is to maintain a comprehensive coverage matrix for policies and standard operating procedures (SOPs) across all departments. While functional department heads (process owners) retain ownership and maintenance of their daily SOPs, this role holds ultimate accountability for the completeness of the coverage, identifying regulatory blind spots, and executing rigorous, independent internal audits.
Additionally, this candidate will also cover the role of the Data Protection Officer (DPO), serving as the enterprise-wide single reference point for all data protection, process controls, and breach-reporting mandates under Singapore's Personal Data Protection Act (PDPA).
Key Responsibilities for the candidate include:
- Coverage Completeness: Build and maintain an enterprise-wide SOP Mapping Matrix to guarantee that all business units possess comprehensive and compliant SOPs.
- Framework Architecture: Establish and scale the overarching organisational standards, templates, and frameworks for how SOPs are drafted, validated, and updated.
- Stakeholder Advisory: Act as an internal consultant to respective process owners, ensuring that internal process are reviewed and revised in accordance to changes from key funding agencies and stakeholders including funding criteria, process and audit requirements, and administration guidelines.
- Regulatory Watch: Continuously track updates from relevant statutory bodies to pre-emptively flag necessary adjustments to operational procedures before non-compliance risks manifest.
- Risk-Based Audit Plan: Formulate and execute an Annual Internal Audit Plan approved by the management, prioritizing high-risk regulatory and operational areas.
- Regular Auditing Cycles: Conduct routine and surprise audits on operational processes to verify that practices align with documented SOPs and funding criteria
- Deficiency Reporting & Remediation: Author formal audit reports highlighting control deficiencies, process gaps, or inefficiencies. Track corrective action plans with business and process heads to resolve issues promptly.
- Statutory DPO Designation: ready to be deployed as a registered Data Protection Officer with the ACRA / PDPC, acting as the primary point of contact for regulators and internal stakeholders on all personal data matters.
- PDPA Compliance Management: Develop and operationalize LHUB's Data Protection Management Programme (DPMP).
- Data Incident Response: Oversee LHUB's Data Breach Management Plan. Lead immediate triage, investigation, containment, and statutory reporting to the PDPC and affected individuals within the mandatory 3-day notification window if a reportable breach occurs.
Key Competencies:
- CET Regulatory Domain Knowledge: In-depth, working familiarity with Singapore's CET ecosystem, specifically SWDA funding mechanics, CPE standards, training provider quality frameworks, and auditing guidelines.
- Audit Methodologies: Proven expertise in applying internal audit standards ( ISO 9001:2015, ISO 45001:2018, and ISO 29993:2017) to non-financial, operational, and administrative processes.
- PDPA Legislation Mastery: Comprehensive command of Singapore's Personal Data Protection Act (PDPA), including data mapping, breach management, and cross-border data transfer policies.
- Influencing Without Authority: Exceptional ability to drive accountability and process ownership across department heads who do not report to you directly.
- Rigorous Attention to Detail: Capable of scanning voluminous policies and operations to uncover latent governance deficiencies.
- Strategic & Objective Perspective: Capable of balancing commercial realities (the speed of running a business) with strict compliance margins.
- Crisis Management & Communication: Highly calm under pressure; clear, concise verbal and written reporting capabilities to the C-Suite, Board, and state regulators.
Preferred Qualifications:
- Education: Bachelor's Degree in Accountancy, Law, Business Administration or relevant disciplined field.
- Audit/Compliance: Certified Internal Auditor (CIA), Certified Compliance Specialist, or equivalent.
- Data Protection: Certified Information Privacy Professional/Asia (CIPP/A), Practitioner Certificate in Personal Data Protection (Singapore), or PDPC-recogniaed DPO qualifications.
- A minimum of 8–10 years of progressive experience in internal audit, operational compliance, or risk management.
- At least 2–3 years in a dedicated team leadership/head-of-department capacity.
- Prior experience within a reputable CET Centre, Private Education Institution (PEI Registered under CPE), or an institute of higher learning (IHL) in Singapore is highly advantageous.
More Info
Key Skills
SOP Mapping Matrix
Data Breach Management
Audit Methodologies
Stakeholder Advisory



