Overview
The Director of Compliance and Enterprise Risk Management provides enterprise-level leadership, governance oversight, coordination, and strategic guidance for the System's risk and compliance framework. Reporting to the Chief Financial Officer, this role develops and maintains the System-wide Enterprise Risk Management (ERM) program, methodologies, governance processes, and reporting practices that support informed decision-making, organizational resilience, and Board oversight.
The Director serves as a strategic advisor to executive leadership by monitoring the evolving regulatory and risk landscape, facilitating enterprise risk assessments, providing executive-level reporting and analysis, and promoting consistent risk management practices across the System.
Operational responsibility for identifying, assessing, mitigating, and managing risks remains with institutional leadership and functional executives. The Director provides the governance framework, enterprise coordination, and executive visibility necessary to support consistent risk management while respecting institutional authority and accountability.
Enterprise Risk Oversight
- •Develop, implement, and continuously enhance the System-wide ERM framework, methodologies, tools, and reporting standards.
- •Guide institutions in conducting risk assessments and maintaining institutional risk registers using consistent enterprise methodologies.
- •Aggregate and analyze institutional risk information to develop and maintain the System's enterprise risk profile.
- •Identify and elevate cross-cutting, systemic, and emerging risks requiring executive leadership or Board consideration.
- •Facilitate the development and periodic review of the System's risk appetite and risk tolerance in partnership with executive leadership and the Board.
- •Develop and maintain enterprise risk escalation protocols for material or emerging risks.
- •Lead the System Risk and Compliance Committee and other cross-functional governance committees.
- •Develop enterprise dashboards, key risk indicators (KRIs), and executive reports that support governance and strategic decision making.
Regulatory and Compliance Intelligence
- •Monitor the evolving federal, state, accreditation, and industry regulatory landscape affecting higher education.
- •Partner with executive leaders and functional subject matter experts to evaluate enterprise impacts of significant regulatory developments.
- •Provide executive leadership and institutional leaders with strategic regulatory briefings, trend analyses, and enterprise impact assessments.
- •Facilitate cross-functional coordination related to significant regulatory changes and emerging compliance risks.
- •Conduct proactive regulatory horizon scanning to support strategic planning and organizational preparedness.
- •Promote consistent enterprise communication regarding significant regulatory developments.
Board Engagement
- •Prepare and present risk reports, dashboards, and emerging risk updates for executive leadership and Board committees.
- •Advise executive leadership and the Board regarding enterprise risks, regulatory developments, governance trends, and leading practices.
- •Support the Board's enterprise risk governance responsibilities through education, strategic reporting, and periodic review of the System's enterprise risk profile.
Risk Framework and Control Alignment
- •Establish and maintain enterprise risk assessment methodologies, documentation standards, and risk reporting practices.
- •Collaborate with Internal Audit, Legal Affairs, Compliance, and other functional leaders to provide enterprise risk insights that inform risk-based audit planning and compliance monitoring while maintaining the independence of assurance functions.
- •Facilitate periodic enterprise risk reviews to evaluate aggregate risk exposure, organizational resilience, and mitigation effectiveness.
- •Monitor trends in significant audit, compliance, and risk findings to identify recurring systemic issues and opportunities to strengthen governance and internal controls.
- •Develop and monitor enterprise key risk indicators (KRIs) and other metrics that measure changes in the System's risk profile.
Culture and Capacity Building
- •Provide strategic guidance and consultation to institutions in advancing ERM maturity.
- •Develop and maintain enterprise methodologies, tools, guidance, and educational resources that promote consistent risk management practices and compliance awareness.
- •Foster a culture of risk awareness, ethical decision making, and shared accountability throughout the System.
- •Promote the integration of enterprise risk management into strategic planning and executive decision making.
Risk Domain Scope
The Director provides enterprise-level coordination, governance oversight, and reporting across the following major risk domains:
- •Financial sustainability and liquidity
- •Enrollment, admissions, and revenue concentration
- •Title IV compliance and federal regulatory compliance
- •Accreditation, licensure, and state authorization
- •Information security, cybersecurity, data privacy, and technology resilience
- •Reputational and strategic communications
- •Business continuity, emergency management, and crisis response
- •Third-party, vendor, and strategic partner risk
Crisis Management and Business Continuity
- •Support executive leadership through enterprise crisis governance, cross-functional coordination, and post-incident reviews.
- •Coordinate enterprise risk assessments with institutional business continuity, disaster recovery, and organizational resilience planning.
- •Develop and maintain enterprise incident reporting and risk escalation protocols.
- •Facilitate post-incident lessons learned reviews to identify systemic issues and strengthen enterprise resilience.
Performance Indicators
- •The ERM program demonstrates measurable improvement in organizational maturity, consistency, and effectiveness.
- •Executive leadership and the Board receive meaningful, timely risk intelligence that supports governance and strategic decision making.
- •Enterprise risks are proactively identified, escalated, and monitored through established governance processes.
- •Institutional risk management practices demonstrate increasing consistency with System-wide ERM methodologies and reporting standards.
- •Recurring systemic risk themes decrease over time through strengthened governance and cross-functional collaboration.
- •Enterprise risk management is effectively integrated into strategic planning, governance, and major organizational initiatives.
Compensation and Benefits
This opportunity is budgeted at $140,000 to $150,000 base compensation. Additional compensation factors may impact total compensation. Benefits include generous paid time-off, medical and dental insurance coverage, life and disability insurance, retirement plan with employer contribution, multiple flexible spending accounts, and tuition reimbursement.