Risk & Assurance Program Lead
MORROW · Singapore · Not Specified
Quick Summary
- Build, operate, and improve governance functions to ensure patient safety.
- Maintain evidence quality and completeness for compliance and controls.
- Produce monthly assurance reports on risks, actions, and exceptions.
Full Description
MORROW MEDICAL
MORROW Medical is a physician-led longevity and lifestyle medicine clinic in Singapore, focused on helping individuals understand, optimise, and protect their long-term health. We combine comprehensive health screening, preventive care, and evidence-based lifestyle medicine to identify early signs of metabolic, cardiovascular, and functional change—often before disease develops. Our fully licensed doctors diagnose conditions, prescribe medication, and manage chronic disease where required, while also guiding patients through personalised lifestyle interventions that support sustainable improvement. From preventive screening to ongoing medical management, MORROW Medical delivers integrated care designed to strengthen function, resilience, and long-term health outcomes.
⸻
MORROW HEALTH
MORROW Health is Singapore’s largest integrated fitness and recovery destination, designed to help individuals build healthier, more resilient lives through intentional daily habits. Grounded in lifestyle medicine, MORROW Health brings together physical activity, nutrition, restorative sleep, stress management, avoidance of risky substances, and social connection through structured programmes and purpose-built environments that make sustainable lifestyle change achievable. Supported by evidence-informed practice and data from wearables and lifestyle inputs, MORROW Health helps members recognise patterns, build consistency, and stay accountable—turning insight into everyday action that supports long-term vitality, strength, and clarity, without medical diagnosis or treatment.
Role Overview:
Build, operate, and continuously improve MORROW’s control layer, the set of governance functions that keep patients safe, protect data, comply with healthcare rules, and keep services running. The role ensures trust is earned through evidence, not intent, by maintaining concise policies, simple cadences, and auditable artefacts that demonstrate controls work in practice.
Group Context and Scope:
MORROW operates as a group with multiple entities, and will incorporate new operating entities over time, each with its own Board. This role establishes a consistent Group control-layer operating model while maintaining entity-specific compliance and evidence requirements.
Reporting Line and Independence:
- Primary reporting: Reports to the Board of the respective entities within the Group (or a delegated Board committee, for example Audit and Risk), for assurance matters.
- Administrative coordination: Works day to day with the CEO, COO and EXCO members to run cadences, maintain artefacts, and drive closure.
- Standing access and escalation: Has standing access to EXCO and Boards for material issues, including escalations supported by evidence, recommended actions, owners, and timelines.
What You Are Accountable For:
You are accountable for the system and evidence:
- single source of truth for artefacts (SharePoint, Files channel),
- cadence execution (reviews, audits, drills),
- evidence quality and completeness,
- control testing and verification,
- issues tracking and action closure discipline,
- independent assurance reporting to EXCO and Boards.
You are not the accountable “Owner” of each control function domain, those owners remain as defined in the Control Layer.
Control Layer Coverage:
You will operate the framework across these seven functions, ensuring each has current artefacts, a working cadence, and validated evidence signals:
1. Enterprise Risk Management (ERM)
Operate the ERM system so scattered concerns become owned risks with actions, dates, and owners; maintain the risk register and reporting packs; enforce escalation rules.
2. Legal, Compliance and Licensing
Run the intake and tracking system, maintain DOA and template libraries, track cycle times and exceptions, and evidence “zero out of policy signatures”.
3. Health, Safety and Quality (HSQ)
Coordinate HSQ evidence, audit readiness, incident and near-miss logs, CAPA tracking, and verification that practice matches policy.
4. Data Privacy and Cybersecurity
Support and evidence the minimum standards, acknowledgement rates, MFA coverage, access reviews, and breach drill readiness.
5. Internal Audit and Controls
Maintain the internal controls framework artefacts and evidence folders, support regular testing, and drive remediation of exceptions to reduce recurrence.
6. Insurance and Risk Financing
Maintain insurance artefacts, claims SOPs, incident-to-claim checklists, coverage gap tracking, and post-incident claim reviews with evidence of timely notifications.
7. Business Continuity and Crisis Management
Maintain BCP artefacts (call tree, scripts, evacuation checklist), run tabletop and evacuation drills, and track improvements and tested RTOs.
Key Responsibilities
A. Run the cadence
Plan, schedule, run, and document the recurring beats that prove controls work:
- ERM: risk review committee, plus escalation within 24 hours for red risks per scoring rules.
- Legal, Compliance and Licensing: weekly intake triage, monthly compliance check-in, annual licensing reviews.
- HSQ: monthly safety walk, quarterly HSQ audit.
- Privacy and Cyber: quarterly DPO and IT reviews, annual breach drill.
- Internal Controls: quarterly control testing with evidence folders.
- Insurance: annual broker review and post-incident claim reviews.
- BCP: semi-annual tabletop exercises, annual evacuation drill.
B. Maintain core artefacts and single source of truth
- Keep “policy on a page” artefacts current, link to living SOPs and templates, maintain registers and logs as the source of truth.
- Maintain evidence folders that are inspection-ready at all times.
C. Independent assurance and control testing
- Design and execute a risk-based assurance plan across all seven functions, including spot checks, evidence verification, and control effectiveness testing.
- Report findings with owners and due dates, and confirm remediation is effective, not cosmetic.
D. Issue management and remediation to closure
- Operate an issues register (incidents, audit findings, control exceptions, compliance gaps), severity triage, owner assignment, due dates, and verification of closure.
- Reduce repeat failures by ensuring root cause is addressed and evidence signals improve (for example fewer repeat incidents, lower exception rates).
E. Board and EXCO reporting
- Produce a concise monthly assurance pack: top risks, overdue actions, exceptions, drill readiness, insurance gaps, and trend movement.
- Escalate material issues with evidence, recommended actions, and timelines.
KPIs
Track and report the cross-control KPIs defined in the control layer:
- Policy acknowledgement rate and on-time reviews
- Red risk escalation within 24 hours
- Action closure by due date
- Quarterly control exception rate
- Drill and audit completion rate
- Count and age of insurance coverage gaps