NHS Business Services Authority

Director of Risk

The closing date is 30 January 2026

Job summary

Job Overview

Are you ready to lead risk management at a national scale and make a real difference to the NHS?We're looking for a dynamic and forward-thinker to join our Senior Leadership Team and act as Chief Risk Officer at NHS Business Services Authority (NHSBSA). This is a unique opportunity to shape the future of risk and assurance across a complex, high-impact organisation that touches millions of lives every day.

You'll play a pivotal role in embedding a culture of resilience, governance and innovation, ensuring we operate with confidence and foresight. You'll bring an enterprise-wide perspective on risk, understanding the consequences of decisions and ensuring effective mitigations are in place to protect the organisation and enable progress as we navigate a challenging landscape. If you're passionate about strategic leadership, influencing at the highest level, and driving transformation, this could be the role for you.

What do we offer?

  • 27 days annual leave, rising to 29 days after five years' service and 33 days after ten years' service + public holidays
  • Excellent pension, 23.7% employer contribution
  • Flexible working
  • Active wellbeing and inclusion networks
  • NHS Car Lease Scheme
  • Access to a wide range of benefits and high-street discounts

Main duties of the job

Main duties of the job

As Director of Risk, you'll lead the development and delivery of NHSBSA's enterprise-wide risk and assurance strategy. You'll:

  • Define and embed our risk management framework, ensuring compliance with NHS and UK Government standards.
  • Chair the Executive Risk Committee, providing assurance to the Board and Executive Team.
  • Drive cultural change, building risk capability and confidence across the organisation.
  • Oversee integrated assurance and internal audit planning, ensuring governance remains robust and fit for purpose.
  • Lead and inspire a high-performing team, fostering collaboration and continuous improvement.
  • Influence senior stakeholders, regulators and system partners to strengthen trust and transparency.

We welcome conversations about this opportunity, so please don't hesitate to reach out for a more detailed breakdown of the role and responsibilities.

About us

Working for your organisation

Here at the NHS Business Services Authority (NHSBSA), what we do matters. We manage the NHS Pension scheme, process prescription payments and much more. Our services are used by NHS organisations, contractors and the public: we're proud to be part of something meaningful, that touches millions of lives. We design our services around customer needs and place people at the heart of our organisation.

That's why when you join us, you'll be empowered and supported to help your career grow. As one of the UK's Best Big Companies to work for, we're connected to our values: Collaborative, Adventurous, Reliable and Energetic. We care about our people, our purpose, and your progress.

We strive to offer a fantastic colleague experience, where every colleague is heard, supported and respected. Wellbeing, diversity and inclusion is at the centre of this, and you can join our Lived Experience Networks who help us bring our authentic selves to work.

We're committed to being a flexible employer and we try to offer a working pattern that suits you where possible, through hybrid working, flexible hours and more. Alongside a competitive salary with pay progression, we offer a people-centric benefits package, connecting you to the rewards and benefits you value most!

Ready to join us in delivering business service excellence to the NHS, helping people live longer, healthier lives? Apply today and see where the NHSBSA can take you. We are people connected to care.

Details

Date posted

20 January 2026

Pay scheme

Agenda for change

Band

Band 9

Salary

£109,179 to £125,637 a year

Contract

Permanent

Working pattern

Full-time

Reference number

914-BSA7746463

Job locations

Stella House

Newcastle upon Tyne

NE15 8NY


Job description

Job responsibilities

Job Purpose

NHS Business Services Authority (NHSBSA) is a unique Special Health Authority with over 4,000 colleagues, an Arms Length Body of the Department of Health. The NHSBSA is a forward thinking, innovative organisation. We help the NHS to run efficiently by delivering platforms and services to support the entire NHS Workforce, Primary Care, and millions of UK citizens.

We are responsible for providing a complex range of critical services to support the priorities for the NHS, Government and local heath economies. Our platforms, systems and services touch countless lives, facilitating the flow of around £100 billion in NHS funds annually and supporting over three million present, past and future NHS colleagues throughout their careers and beyond The NHSBSAs vision is to be the provider of national, at scale business services for the health and social care system, transforming and delivering these services to maximise efficiency to meet customer expectations. The NHSBSA provides platforms and services at scale and nationally, utilising leading-edge technology so that we deliver great taxpayer value and provide huge savings for the NHS which can be reinvested in frontline care.

The NHSBSA has an ambitious vision for the future and strong values that drive our commitment tohigh quality and efficient services delivered by compassionate and caring people. Our values of Collaborative, Adventurous, Reliable and Energetic (CARE) are at the heart of who we are, and we are proud these are at the heart of every role in our organisation.

Risk management is at the heart of NHSBSAs decision making, enabling the organisation to operate with confidence, resilience, and foresight. The postholder will act as Chief Risk Officer to provide strategic leadership for risk and integrated assurance, embedding frameworks and processes that safeguard services, strengthen organisational resilience, and support innovation and efficient delivery.

You will champion the integration of risk management and assurance across the organisation, shaping NHSBSAs risk culture and governance approach, and enhancing the maturity of the organisations risk capability. As a Senior Leader and member of the Leadership Team, you will define and deliver an ambitious strategy for risk and resilience, influencing the organisations strategic position within the broader health and care system and ensuring long-term sustainability, agility, and trust.

Job summary:

This role will provide strategic, technical and professional expertise to deliver a comprehensive and forward-looking Risk Management agenda. You will be responsible for setting and implementing the NHSBSAs enterprise-wide approach to risk, resilience and assurance, ensuring that the organisation anticipates, understands and effectively manages strategic, operational, financial and compliance risks. You will maximise the use of resources within your remit, set and achieve key performance indicators and break-even budgets, and ensure value is delivered through proportionate, well-designed controls and governance frameworks. Alongside this, you will identify and deliver significant improvements to the organisations risk maturity, embedding an integrated approach to risk that enhances decision-making, strengthens accountability and supports the achievement of NHSBSAs strategic objectives.

You will operate confidently in ambiguity, creating clarity where needed and shaping the organisations approach to risk management and assurance. You will define and refine the vision, scope and operating model for the function, embedding the frameworks and behaviours needed for a mature, enterprise-wide risk environment.

As a member of the NHSBSA Senior Leadership Team, you will play a key role in shaping the organisations culture and direction, maintaining world-class levels of engagement across your teams and influencing positive behaviours across the wider organisation. Leading a diverse and high-performing workforce, you will inspire, develop and empower colleagues to build capability in risk management and assurance, ensuring consistency, confidence and professionalism in how risk is understood and managed across all areas of the business. You will also foster strong, trusted relationships with internal and external stakeholders, including regulators, auditors and system partners, to enhance transparency, confidence and collaboration.

As Chair of the Executive Risk Committee (ERC), you will oversee the organisations key risks, ensuring operations remain within the Board-approved Risk Appetite. Independent of the first line of defence, you will work closely with the Chief People Officer, CEO, Executive Directors, and wider leadership team to ensure that risks are well-understood, monitored, and managed. The postholder will report directly to the Chief People Officer, with a dotted reporting line to the CEO, and will also maintain an independent reporting line to the Chair of the Board Audit & Risk Management Committee (ARMC), thereby safeguarding independence. The post holder will use risk insights and analysis to provide direct assurance to the Executive and the Board, forming and communicating clear, evidence-based opinions on key strategic decisions at the highest levels of the organisation.

As the NHSBSAs Director responsible for the second line of defence, you will oversee the design and delivery of strategies, frameworks, and policies that uphold high standards of governance and compliance with government and NHS requirements. You will lead risk assurance activity, providing professional oversight and constructive challenge to strengthen control environments across all functions.

With a forward-thinking, commercially astute, and collaborative approach, you will define and deliver an ambitious strategy for risk management and assurance that enhances the organisations resilience, performance, and reputation. Acting with autonomy and integrity, you will make significant decisions to safeguard NHSBSAs governance, compliance, and long-term sustainability, ensuring that excellence in risk management is achieved and maintained.

In this role you are accountable for

Strategic Leadership

1. Shared accountability for supporting the overall organisation to achieve its vision and contribute to the development of the organisations strategic and annual business plans, leading and driving operational performance improvement across NHSBSA Services to deliver high-quality, cost-effective services.

2. Providing strategic leadership to a department of risk management professionals who provide risk consultancy, governance, and assurance, you will ensure the development and implementation of the departments strategy and associated business plans to enable the delivery of the NHSBSA strategy whilst supporting the Chief People Officer in the development of vision and strategic direction.

3. Responsibility for major policy interpretation, implementation and policy or service development, which impacts across the organisation.

4. Working in collaboration with colleagues from the wider organisation, you will develop robust internal performance management systems which enable NHSBSA to adhere to or exceed strategic plans, standards, and targets, developing a culture of performance management, improvement, and appraisal for excellent organisational performance.

5. Delivering NHS-wide benefits and savings through embedding Government Functional Standards in NHSBSA operations.

Risk & Assurance Leadership

6. This role will ensure strategic alignment of the organisations approach to risk, assurance and resilience and ensure a culture of accountability, transparency and continuous improvement is embedded. Youll champion proportionate and effective risk management that balances innovation with governance ensuring value for money and optimising resources while maintaining a strong compliance environment across all areas of service delivery

7. Shape and embed the organisations risk function, setting clear vision, standards and expectations, and establishing the structures, behaviours and capabilities needed for a mature and integrated risk environment

8. Define, implement and maintain the NHSBSAs enterprise risk management framework, ensuring compliance with NHS and UK Government standards. The postholder will ensure that appropriate governance structures, policies and procedures are in place to identify, assess and manage risk effectively, enabling informed decision-making and delivery of the organisations strategic objectives.

9. Continuously evolve the NHSBSAs Integrated Assurance Framework, ensuring that governance structures, policies, and tools remain fit for purpose and compliant with Government Functional Standards. Drive innovation and improvement in risk and assurance processes to enhance organisational resilience and accountability.

10. Embed an integrated approach to assurance across all directorates, overseeing the mapping and assessment of key controls and assurance mechanisms. Ensure that assurance activity is risk-based, proportionate, and delivers confidence in the organisations ability to meet strategic objectives.

11. Chair the Executive Risk Committee (ERC), ensuring the organisations key risks are monitored, including risk appetite, limit breaches, tolerances, and key risk indicators. Provide assurance to the Board, ensuring that risk exposure is understood, communicated, and actively managed.

12. Manage the monitoring and reporting of strategic and operational risk and assurance positions, ensuring that emerging risks and trends are identified, assessed and communicated promptly to the Executive team and Board. Youll ensure risk insights and analysis are used to drive better performance, enhance governance and inform strategic decision-making at the highest level.

Job description

Job responsibilities

Job Purpose

NHS Business Services Authority (NHSBSA) is a unique Special Health Authority with over 4,000 colleagues, an Arms Length Body of the Department of Health. The NHSBSA is a forward thinking, innovative organisation. We help the NHS to run efficiently by delivering platforms and services to support the entire NHS Workforce, Primary Care, and millions of UK citizens.

We are responsible for providing a complex range of critical services to support the priorities for the NHS, Government and local heath economies. Our platforms, systems and services touch countless lives, facilitating the flow of around £100 billion in NHS funds annually and supporting over three million present, past and future NHS colleagues throughout their careers and beyond The NHSBSAs vision is to be the provider of national, at scale business services for the health and social care system, transforming and delivering these services to maximise efficiency to meet customer expectations. The NHSBSA provides platforms and services at scale and nationally, utilising leading-edge technology so that we deliver great taxpayer value and provide huge savings for the NHS which can be reinvested in frontline care.

The NHSBSA has an ambitious vision for the future and strong values that drive our commitment tohigh quality and efficient services delivered by compassionate and caring people. Our values of Collaborative, Adventurous, Reliable and Energetic (CARE) are at the heart of who we are, and we are proud these are at the heart of every role in our organisation.

Risk management is at the heart of NHSBSAs decision making, enabling the organisation to operate with confidence, resilience, and foresight. The postholder will act as Chief Risk Officer to provide strategic leadership for risk and integrated assurance, embedding frameworks and processes that safeguard services, strengthen organisational resilience, and support innovation and efficient delivery.

You will champion the integration of risk management and assurance across the organisation, shaping NHSBSAs risk culture and governance approach, and enhancing the maturity of the organisations risk capability. As a Senior Leader and member of the Leadership Team, you will define and deliver an ambitious strategy for risk and resilience, influencing the organisations strategic position within the broader health and care system and ensuring long-term sustainability, agility, and trust.

Job summary:

This role will provide strategic, technical and professional expertise to deliver a comprehensive and forward-looking Risk Management agenda. You will be responsible for setting and implementing the NHSBSAs enterprise-wide approach to risk, resilience and assurance, ensuring that the organisation anticipates, understands and effectively manages strategic, operational, financial and compliance risks. You will maximise the use of resources within your remit, set and achieve key performance indicators and break-even budgets, and ensure value is delivered through proportionate, well-designed controls and governance frameworks. Alongside this, you will identify and deliver significant improvements to the organisations risk maturity, embedding an integrated approach to risk that enhances decision-making, strengthens accountability and supports the achievement of NHSBSAs strategic objectives.

You will operate confidently in ambiguity, creating clarity where needed and shaping the organisations approach to risk management and assurance. You will define and refine the vision, scope and operating model for the function, embedding the frameworks and behaviours needed for a mature, enterprise-wide risk environment.

As a member of the NHSBSA Senior Leadership Team, you will play a key role in shaping the organisations culture and direction, maintaining world-class levels of engagement across your teams and influencing positive behaviours across the wider organisation. Leading a diverse and high-performing workforce, you will inspire, develop and empower colleagues to build capability in risk management and assurance, ensuring consistency, confidence and professionalism in how risk is understood and managed across all areas of the business. You will also foster strong, trusted relationships with internal and external stakeholders, including regulators, auditors and system partners, to enhance transparency, confidence and collaboration.

As Chair of the Executive Risk Committee (ERC), you will oversee the organisations key risks, ensuring operations remain within the Board-approved Risk Appetite. Independent of the first line of defence, you will work closely with the Chief People Officer, CEO, Executive Directors, and wider leadership team to ensure that risks are well-understood, monitored, and managed. The postholder will report directly to the Chief People Officer, with a dotted reporting line to the CEO, and will also maintain an independent reporting line to the Chair of the Board Audit & Risk Management Committee (ARMC), thereby safeguarding independence. The post holder will use risk insights and analysis to provide direct assurance to the Executive and the Board, forming and communicating clear, evidence-based opinions on key strategic decisions at the highest levels of the organisation.

As the NHSBSAs Director responsible for the second line of defence, you will oversee the design and delivery of strategies, frameworks, and policies that uphold high standards of governance and compliance with government and NHS requirements. You will lead risk assurance activity, providing professional oversight and constructive challenge to strengthen control environments across all functions.

With a forward-thinking, commercially astute, and collaborative approach, you will define and deliver an ambitious strategy for risk management and assurance that enhances the organisations resilience, performance, and reputation. Acting with autonomy and integrity, you will make significant decisions to safeguard NHSBSAs governance, compliance, and long-term sustainability, ensuring that excellence in risk management is achieved and maintained.

In this role you are accountable for

Strategic Leadership

1. Shared accountability for supporting the overall organisation to achieve its vision and contribute to the development of the organisations strategic and annual business plans, leading and driving operational performance improvement across NHSBSA Services to deliver high-quality, cost-effective services.

2. Providing strategic leadership to a department of risk management professionals who provide risk consultancy, governance, and assurance, you will ensure the development and implementation of the departments strategy and associated business plans to enable the delivery of the NHSBSA strategy whilst supporting the Chief People Officer in the development of vision and strategic direction.

3. Responsibility for major policy interpretation, implementation and policy or service development, which impacts across the organisation.

4. Working in collaboration with colleagues from the wider organisation, you will develop robust internal performance management systems which enable NHSBSA to adhere to or exceed strategic plans, standards, and targets, developing a culture of performance management, improvement, and appraisal for excellent organisational performance.

5. Delivering NHS-wide benefits and savings through embedding Government Functional Standards in NHSBSA operations.

Risk & Assurance Leadership

6. This role will ensure strategic alignment of the organisations approach to risk, assurance and resilience and ensure a culture of accountability, transparency and continuous improvement is embedded. Youll champion proportionate and effective risk management that balances innovation with governance ensuring value for money and optimising resources while maintaining a strong compliance environment across all areas of service delivery

7. Shape and embed the organisations risk function, setting clear vision, standards and expectations, and establishing the structures, behaviours and capabilities needed for a mature and integrated risk environment

8. Define, implement and maintain the NHSBSAs enterprise risk management framework, ensuring compliance with NHS and UK Government standards. The postholder will ensure that appropriate governance structures, policies and procedures are in place to identify, assess and manage risk effectively, enabling informed decision-making and delivery of the organisations strategic objectives.

9. Continuously evolve the NHSBSAs Integrated Assurance Framework, ensuring that governance structures, policies, and tools remain fit for purpose and compliant with Government Functional Standards. Drive innovation and improvement in risk and assurance processes to enhance organisational resilience and accountability.

10. Embed an integrated approach to assurance across all directorates, overseeing the mapping and assessment of key controls and assurance mechanisms. Ensure that assurance activity is risk-based, proportionate, and delivers confidence in the organisations ability to meet strategic objectives.

11. Chair the Executive Risk Committee (ERC), ensuring the organisations key risks are monitored, including risk appetite, limit breaches, tolerances, and key risk indicators. Provide assurance to the Board, ensuring that risk exposure is understood, communicated, and actively managed.

12. Manage the monitoring and reporting of strategic and operational risk and assurance positions, ensuring that emerging risks and trends are identified, assessed and communicated promptly to the Executive team and Board. Youll ensure risk insights and analysis are used to drive better performance, enhance governance and inform strategic decision-making at the highest level.

Person Specification

Personal Qualities, Knowledge and Skills - Application form

Essential

  • Political awareness and awareness of broader aspects which may impact on the area of expertise.

Desirable

  • Coaching and mentoring at leadership level

Experience - Application form

Essential

  • Managing a highly complex budget.

Desirable

  • Previous experience working at similar level in a relevant role within Public Sector

Qualifications - Application Form

Essential

  • Degree level in a relevant subject area (such as Business, Finance, Risk Management) or equivalent experience
  • Post graduate governance/ risk/ assurance qualification in related discipline (e.g. CIPFA Diploma, PRINCE2, AMP, Agile PM)

Desirable

  • Masters degree in relevant subject area
  • Postgraduate or executive-level qualification in leadership or public-sector management (e.g., MBA, MSc, or equivalent).

Personal Qualities, Knowledge and Skills - Application form and interview

Essential

  • Significant expertise in risk management and assurance, with a successful track record of delivering strategic outcomes using industry-leading methodologies
  • Experience of benefits realisation at strategic scale, ensuring alignment of investment decisions to organisational objectives and taxpayer value.
  • Highly comfortable operating in ambiguity, with the ability to shape and define a organisational risk function--establishing frameworks, culture, processes and expectations from the ground up
  • Seeing the big picture to steer day-day delivery focusing on risk and optimising outcomes for organisation, customers and taxpayer.

Desirable

  • In-depth knowledge of UK Government financial controls and risk governance standards, with ability to interpret and apply these at organisational level
  • Experience of product and service innovation, leveraging technology and data to enhance governance and assurance capability
  • Project planning and management techniques/in depth knowledge and experience of managing projects
  • Political awareness and awareness of broader aspects which may impact on the area of expertise.

Experience - Application form and Interview

Essential

  • Strategic leadership in risk management, integrated assurance, audit and/or compliance functions in a complex organisation.
  • Leading the development and implementation of enterprise risk management frameworks, policies, and strategies that align with organisational objectives.
  • Delivering cultural change and embedding a risk-aware culture across an organisation.
  • Managing change and being a catalyst and leader in a changing environment, harnessing others to embrace transformation.
  • Strategic leadership experience in designing and implementing organisational scale frameworks

Desirable

  • Knowledge of relevant government, NHS, and regulatory risk and governance standards

Personal Qualities, Knowledge and Skills - Interview

Essential

  • Uses enterprise-wide thinking to break down silos, fostering collaboration and accountability at all levels.
  • Effective relationships enabling collaborative delivery of shared accountabilities working with and through partners and peers.
  • An engaging leader, championing the strategic importance of people, talent management, development and wellbeing through setting and maintaining direction, clear requirements and performance standards, building a culture of diversity and inclusion and continuous learning and improvement
  • Excellent communication and engagement skills, ability to articulate complex situations clearly in order to influence and inform decisions.

Desirable

  • Capable of and experience of working outside normal professional and own comfort boundaries

Experience - Interview Stage

Essential

  • Influencing and engaging with senior leaders, Boards, regulators, and external stakeholders to provide risk insight and drive organisational improvement.
  • Motivating, enabling and empowering teams to deliver
Person Specification

Personal Qualities, Knowledge and Skills - Application form

Essential

  • Political awareness and awareness of broader aspects which may impact on the area of expertise.

Desirable

  • Coaching and mentoring at leadership level

Experience - Application form

Essential

  • Managing a highly complex budget.

Desirable

  • Previous experience working at similar level in a relevant role within Public Sector

Qualifications - Application Form

Essential

  • Degree level in a relevant subject area (such as Business, Finance, Risk Management) or equivalent experience
  • Post graduate governance/ risk/ assurance qualification in related discipline (e.g. CIPFA Diploma, PRINCE2, AMP, Agile PM)

Desirable

  • Masters degree in relevant subject area
  • Postgraduate or executive-level qualification in leadership or public-sector management (e.g., MBA, MSc, or equivalent).

Personal Qualities, Knowledge and Skills - Application form and interview

Essential

  • Significant expertise in risk management and assurance, with a successful track record of delivering strategic outcomes using industry-leading methodologies
  • Experience of benefits realisation at strategic scale, ensuring alignment of investment decisions to organisational objectives and taxpayer value.
  • Highly comfortable operating in ambiguity, with the ability to shape and define a organisational risk function--establishing frameworks, culture, processes and expectations from the ground up
  • Seeing the big picture to steer day-day delivery focusing on risk and optimising outcomes for organisation, customers and taxpayer.

Desirable

  • In-depth knowledge of UK Government financial controls and risk governance standards, with ability to interpret and apply these at organisational level
  • Experience of product and service innovation, leveraging technology and data to enhance governance and assurance capability
  • Project planning and management techniques/in depth knowledge and experience of managing projects
  • Political awareness and awareness of broader aspects which may impact on the area of expertise.

Experience - Application form and Interview

Essential

  • Strategic leadership in risk management, integrated assurance, audit and/or compliance functions in a complex organisation.
  • Leading the development and implementation of enterprise risk management frameworks, policies, and strategies that align with organisational objectives.
  • Delivering cultural change and embedding a risk-aware culture across an organisation.
  • Managing change and being a catalyst and leader in a changing environment, harnessing others to embrace transformation.
  • Strategic leadership experience in designing and implementing organisational scale frameworks

Desirable

  • Knowledge of relevant government, NHS, and regulatory risk and governance standards

Personal Qualities, Knowledge and Skills - Interview

Essential

  • Uses enterprise-wide thinking to break down silos, fostering collaboration and accountability at all levels.
  • Effective relationships enabling collaborative delivery of shared accountabilities working with and through partners and peers.
  • An engaging leader, championing the strategic importance of people, talent management, development and wellbeing through setting and maintaining direction, clear requirements and performance standards, building a culture of diversity and inclusion and continuous learning and improvement
  • Excellent communication and engagement skills, ability to articulate complex situations clearly in order to influence and inform decisions.

Desirable

  • Capable of and experience of working outside normal professional and own comfort boundaries

Experience - Interview Stage

Essential

  • Influencing and engaging with senior leaders, Boards, regulators, and external stakeholders to provide risk insight and drive organisational improvement.
  • Motivating, enabling and empowering teams to deliver

Employer details

Employer name

NHS Business Services Authority

Address

Stella House

Newcastle upon Tyne

NE15 8NY


Employer's website

https://careers.nhsbsa.nhs.uk/ (Opens in a new tab)


Employer details

Employer name

NHS Business Services Authority

Address

Stella House

Newcastle upon Tyne

NE15 8NY


Employer's website

https://careers.nhsbsa.nhs.uk/ (Opens in a new tab)


Employer contact details

For questions about the job, contact:

Talent |Acquisition Advisor

Bryony Breadmore

bryony.breadmore@nhsbsa.nhs.uk

Details

Date posted

20 January 2026

Pay scheme

Agenda for change

Band

Band 9

Salary

£109,179 to £125,637 a year

Contract

Permanent

Working pattern

Full-time

Reference number

914-BSA7746463

Job locations

Stella House

Newcastle upon Tyne

NE15 8NY


Supporting documents

Privacy notice

NHS Business Services Authority's privacy notice (opens in a new tab)