Job Details

Business Analyst, CLORA (Malaysia, India)
Job Description
Requisition Number:  63338
Job Location:  Bukit Jalil KL, MYS | Bukit Jalil, MYS | Chennai, IND
Global Grade:  Band 5
Work Type:  Office Working
Employment Type:  Permanent
Posting Start Date:  07/10/2026
Posting End Date:  30/10/2026
Job Description: 

Job Summary

This role could be based in Malaysia and India. When you start the application process you will be presented with a drop down menu showing all countries, please ensure that you select a country where the role is based.

The role holder will provide integrated business analysis support for the continued enhancement of CLORA, the Bank’s Tableau-based Control Library and Regulatory Obligations Analytics capability. The role will translate risk, control, regulatory and user needs into a governed delivery roadmap, requirements and releases that expand CLORA with new data sources, simplify and redesign visual journeys, and improve the underlying data model so dashboards load reliably and efficiently. The role will work across Business, Risk, Data, Technology and GRC teams to connect information from M7, ORHS and other approved sources, including regulatory obligations, policies and standards, processes, risks, controls, metrics and metric definitions, as well as events, issues, findings, control testing and related remediation data where approved and available.

The role will also support alignment and rationalisation across CLORA, the Standards Coverage and Effectiveness Dashboard, the Risk and Control Library Report, and other GRC list reports and dashboards. It will maintain clear distinctions between lineage and definition views and performance or effectiveness views, protect golden-source ownership, improve data quality and traceability, and deliver an intuitive, persona-based experience for senior management, Process Owners, Risk Managers, Policy and Standard Owners, Control Owners, Control Testing, Internal Audit and other stakeholders across the three lines of defence.

Key Responsibilities

Develop and Maintain Control Library & Obligations Register Analytics (CLORA) Tool Governance:

•    Requirements Governance: Establish and maintain an end-to-end requirements framework for CLORA enhancements, covering business, functional, data, integration, visualisation, performance, security, access, auditability and operational requirements.
•    Use Case Definition: Facilitate workshops and interviews to define persona-based questions and decision journeys, including regulatory traceability, standards and control coverage, risk-to-control lineage, issue and finding oversight, event analysis, impact assessment, gap identification and remediation prioritisation.
•    Lineage Integrity: Define requirements for reliable lineage across Regulatory Obligations, Policy Statements, Control Objectives, Control Requirements, Processes, Risks, Library Controls, Control Instances, Metrics and approved downstream records, while distinguishing current, future, expired and historical relationships.
•    Integrated Assurance View: Enable users to navigate seamlessly from regulatory obligations, policy statements and control requirements through to controls, metrics, testing outcomes, issues and events, providing a consolidated view of both coverage and control effectiveness.
•    Governance Artefacts: Maintain the business requirements document, use cases, user stories, acceptance criteria, process and data-flow diagrams, data dictionary, source-to-target mappings, lineage rules, decision log and requirements traceability matrix.
•    Simplification: Identify overlapping or duplicative dashboard content and recommend a coherent target-state information architecture across CLORA, SCE, the Risk and Control Library Report and related GRC dashboards.

Service Expansion & Onboarding Execution:

•    Data Source Onboarding: Lead discovery, assessment and onboarding of approved sources for events, issues, findings, control testing, regulatory obligations, policies, standards, processes, risks, controls, metric definitions and other relevant GRC entities.
•    Source Assessment: Document each source’s ownership, authority, granularity, keys, refresh cycle, history, status fields, effective dating, access restrictions, data-quality limitations and reconciliation requirements before integration.
•    Business Rules: Define joining, filtering, deduplication, aggregation, effective-dating and exception rules, including treatment of orphan records, expired relationships, many-to-many relationships, nulls and records not mapped to a process.
•    Incremental Delivery: Sequence new source integration through proof of concept, controlled UAT and production releases, ensuring existing lineage and dashboard journeys are not disrupted.
•    BAU Transition: Define operating procedures for refreshes, reconciliations, issue handling, release support, ownership and continuous improvement, and ensure these are accepted by the relevant product, data and support teams.

Tooling and Reporting:

•    Tableau Visual Redesign: Lead a user-centered redesign of landing pages, summaries, drill-downs, filters, tooltips, legends, downloads and navigation. Reduce visual clutter, remove redundant objects and use consistent terminology, colours and interaction patterns.
•    Performance and Data Model: Work with Tableau developers, data engineers and architects to redesign the logical and physical data model for efficient querying. Define performance requirements and address row multiplication, inefficient joins, excessive calculations, high-cardinality fields, duplicated extracts and visual objects that adversely affect load times.

Project Planning & Delivery Management:

•    Own the integrated delivery plan, scope, milestones, dependencies, resources, budget inputs, release calendar and critical path across business analysis, data engineering, Tableau development, testing, governance and deployment.
•    Build and manage a prioritised backlog based on regulatory and control urgency, user value, data readiness, technical dependency, delivery effort, risk reduction and expected benefits.
•    Apply disciplined change control, assessing impacts to scope, timeline, data lineage, controls, architecture, performance, support and expected benefits before recommending decisions.
•    Maintain RAID, dependency, assumption, decision and action logs; escalate blockers with clear options, impacts and recommended actions.
•    Coordinate agile ceremonies and delivery governance, including discovery, backlog refinement, sprint planning, demonstrations, retrospectives, stage gates and release readiness.
•    Ensure releases have named owners, documented support arrangements, rollback or recovery considerations, communications and training materials.

Testing, Governance and Production Readiness:

•    Define and coordinate functional, integration, regression, lineage, reconciliation, performance, usability, security and user acceptance testing.
•    Create test scenarios that validate source-to-dashboard traceability, relationship logic, filters, aggregations, data-as-of dates, status and effective-date treatment, and prevention of misleading duplicate or historical mappings.
•    Coordinate test data and business testers across relevant personas. Maintain evidence of test execution, defects, retests, acceptance decisions and residual risks.
•    Lead defect triage, prioritisation and resolution, ensuring data correctness and material performance defects are resolved or formally accepted before release.
•    Prepare production-readiness packs and support go/no-go decisions, including approvals, reconciliations, operational procedures, support ownership, release notes, communications and training.

CLORA Lifecycle Ownership:

•    Support the Product Owner in maintaining the product vision, target-state architecture, roadmap, release plan, benefits framework and lifecycle governance for CLORA.
•    Maintain a controlled inventory of data sources, dashboards, views, calculations, business rules, owners, consumers and dependencies.
•    Establish user-feedback, idea-intake, issue-management and enhancement processes and convert operational insights into a transparent, prioritised backlog.
•    Define success measures covering adoption, usability, data quality, lineage completeness, refresh reliability, load performance, defect leakage, auditability and realised business outcomes.
•    Ensure changes to sources, mappings, calculations, visualisations, access or refresh schedules are assessed, tested, approved, documented and communicated.

Training, Awareness and Stakeholder Enablement:

•    Develop supporting guidance and educational materials that promote consistent interpretation of control lineage, control coverage and assurance information in alignment with the Group Control Standard and Group Control Testing Methodology.
•    Deliver training, workshops and awareness sessions to support stakeholder understanding and adoption of the solution.
•    Act as a trusted advisor to stakeholders on the application of the Group Control Standard and Group Control Testing Methodology within the solution ecosystem.

Stakeholder Collaboration:
•    Partner with Process Owners, Group Process Owners, Risk Managers, Risk Framework Owners, Policy and Standard Owners, Control Owners, Control Testing, Operational Risk, ICS, Technology, Regulatory Alignment, Data & Analytics, GRC, Architecture, Information Security, and other users across the three lines of defence.
•    Translate complex GRC and data topics into clear executive decisions, options and trade-offs, without losing the detail required by developers, testers and data owners.
•    Facilitate agreement on definitions, source authority, lineage, coverage logic, data-quality thresholds, performance targets and acceptance criteria.
•    Serve as a trusted adviser within the team, providing evidence-based recommendations and transparent status, impact and dependency assessments.

Strategy
•    Support the evolution of CLORA from a set of dashboard views into a governed, scalable and reusable risk intelligence capability that can incorporate additional risk and control domains over time.
•    Develop a pragmatic roadmap that balances strategic data architecture with near-term delivery, reuse of existing GRC reporting assets and measurable user outcomes.
•    Promote common definitions, reusable data products and consistent persona journeys across CLORA to integrate SCE and related GRC data sources.

Business
•    Understand senior-management and user decisions supported by each dashboard and ensure features are designed around those decisions rather than around source-system structures.
•    Articulate the business value of improved traceability, coverage visibility, data quality, impact analysis and timely risk information.
•    Ensure requirements and prioritisation reflect the needs of global, business and functions as well as country stakeholders and the practical operating model of the three lines of defence.

Processes
•    Define and improve the end-to-end processes for idea intake, requirements, design, data onboarding, development, testing, approval, release, refresh, incident handling and BAU support.
•    Embed traceability from business objective to requirement, user story, data rule, visual, test evidence and release outcome.
•    Standardise documentation and hand-offs while simplifying unnecessary controls, duplicate approvals and manual data preparation.

People & Talent
•    Create clear ways of working across business analysts, project managers, developers, data engineers, testers and subject matter experts.
•    Coach contributors on good requirements, test evidence, GRC data concepts, visual storytelling and disciplined delivery practices.
•    Promote an inclusive, collaborative culture that encourages constructive challenge, accountability and continuous learning

Risk Management
•    Identify and manage delivery, data, model, lineage, performance, availability, access, privacy, security, change and adoption risks throughout the project lifecycle.
•    Prevent misleading reporting by ensuring active and historical relationships, metric definitions and metric results, and coverage and effectiveness measures are clearly separated and labelled.
•    Ensure reconciliations and controls detect stale data, failed loads, missing records, duplicate relationships, broken joins, orphan data and unexplained variances.
•    Maintain audit-ready evidence of requirements, data rules, approvals, testing, decisions, exceptions and production releases.

Governance
•    Operate within the Bank’s project, architecture, data, model, information security, privacy, GRC and change-governance requirements.
•    Establish clear accountabilities for business ownership, technical ownership, data ownership, calculation ownership, access approval and production support.
•    Provide timely, decision-oriented reporting to governance forums and escalate material risks, unresolved design choices and data limitations.

Regulatory & Business Conduct

•    Display exemplary conduct and live by the Group’s Values and Code of Conduct. 
•    Take personal responsibility for embedding the highest standards of ethics, including regulatory and business conduct, across Standard Chartered Bank. This includes understanding and ensuring compliance with, in letter and spirit, all applicable laws, regulations, guidelines and the Group Code of Conduct.
•    Support the team to achieve the outcomes set out in the Bank’s Conduct Principles: The Right Environment. 
•    Effectively and collaboratively identify, escalate, and resolve conduct and compliance matters.
•    Provide timely and accurate risk & control information to support regulatory meetings and RFIs. 

Skills and Experience

•    Project and Programme Management
•    Business Analysis and Requirements Management
•    Data Visualisation and Tableau
•    Data Modelling, Lineage and Data Quality
•    Operational Risk and Internal Controls
•    GRC Platforms and Risk Reporting
•    Internal Controls
•    Risk Management
•    Operational Risk
•    Process Management
•    Regulatory Environment - Financial Services
•    Standard Operating Procedures 

Qualifications

•    Bachelor’s or Master’s degree in Business Administration, Information Systems, Data, Engineering, Finance, Risk Management or another relevant discipline.
•    Professional certification in project management or agile delivery, such as PMP, PRINCE2, SAFe, Scrum or equivalent, is desirable.
•    Business-analysis certification, such as IIBA CBAP/CCBA or equivalent, is desirable.
•    Tableau certification or demonstrable advanced Tableau delivery experience is desirable.
•    Risk, controls, data or technology certifications, such as CRISC, CISM, CISA, DAMA/CDMP or equivalent, are advantageous.
•    12+ years’ experience and strong expertise in Operational & Technology risk management and governance in a Bank of global scale, with a focus on standards and controls, risk management, and regulatory compliance or equivalent, are advantageous. 
•    Strong leadership, communication, and interpersonal skills. Demonstrated ability to work effectively with diverse teams and stakeholders. 
•    Strong communication skills, both written and verbal, with ability to influence business management, other stakeholders and peers.
•    Responds enthusiastically to tasks allocated, accepts responsibility readily and demonstrates business professionalism.
•    Proven track record of performing work independently with minimal supervision and meeting stretch timelines; comfortable to deal with ambiguity and solve problems in large organisations.
•    Good time management, well-organised with the ability to prioritise and plan workload to ensure delivery to timescales, with a good track record of delivery large-scale and complex projects

About Standard Chartered

We're an international bank, nimble enough to act, big enough for impact. For more than 170 years, we've worked to make a positive difference for our clients, communities, and each other. We question the status quo, love a challenge and enjoy finding new opportunities to grow and do better than before. If you're looking for a career with purpose and you want to work for a bank making a difference, we want to hear from you. You can count on us to celebrate your unique talents and we can't wait to see the talents you can bring us.

Our purpose, to drive commerce and prosperity through our unique diversity, together with our brand promise, to be here for good are achieved by how we each live our valued behaviours. When you work with us, you'll see how we value difference and advocate inclusion.

Together we:

  • Do the right thing and are assertive, challenge one another, and live with integrity, while putting the client at the heart of what we do
  • Never settle, continuously striving to improve and innovate, keeping things simple and learning from doing well, and not so well
  • Are better together, we can be ourselves, be inclusive, see more good in others, and work collectively to build for the long term

What we offer

In line with our Fair Pay Charter, we offer a competitive salary and benefits to support your mental, physical, financial and social wellbeing.

  • Core bank funding for retirement savings, medical and life insurance, with flexible and voluntary benefits available in some locations.
  • Time-off including annual leave, parental/maternity (20 weeks), sabbatical (12 months maximum) and volunteering leave (3 days), along with minimum global standards for annual and public holiday, which is combined to 30 days minimum.
  • Flexible working options based around home and office locations, with flexible working patterns.
  • Proactive wellbeing support through Unmind, a market-leading digital wellbeing platform, development courses for resilience and other human skills, global Employee Assistance Programme, sick leave, mental health first-aiders and all sorts of self-help toolkits
  • A continuous learning culture to support your growth, with opportunities to reskill and upskill and access to physical, virtual and digital learning.
  • Being part of an inclusive and values driven organisation, one that embraces and celebrates our unique diversity, across our teams, business functions and geographies - everyone feels respected and can realise their full potential.
Information at a Glance