The BMO Legal Business Unit is seeking a highly organized Risk Manager to help manage, document, and strengthen its risk and control environment.
This role supports how the Legal team identifies risks, maintains controls, tracks remediation, and prepares governance risk reporting for senior Legal leaders.
The Risk Administration Manager will also provide administrative support to the Legal risk specialty area - BMO's lawyers are the independent oversight team responsible for reviewing and challenging how legal risk is assessed and managed.
This oversight function provides legal risk effective challenge across roughly 280 business units enterprisewide.
Legal Business Unit relies on this manager role to coordinate and monitor that effective challenge process.
This role is ideal for someone who enjoys structured governance work, working with senior Legal leaders, and translating enterprise risk expectations into clear, actionable steps.
A background in Legal Risk from a financial institution is preferred.
What You Will DoRisk & Control Management- Maintain and update the Legal Business Unit's inventory of risks, controls, and internal processes within the enterprise governance system
- Monitor new enterprisewide risk and control requirements and identify which apply to the Legal Business Unit
- Design new risk controls and recommend practical updates to existing controls based on control testing results. Coordinate review with internal stakeholders
- Draft updates for Legal owned process documents, guides and job aids
Support for the Legal Risk Specialty Area (Independent Risk Oversight)- Support the update and stakeholder review of the Legal Risk Directive
- Serve as the primary point of coordination with the legal risk specialty area that provides effective challenge to Business Unit's assessment of Legal Risk in their processes
- Manage effectivechallenge workflows, including responding to inquiries, clarifying the definition of legal risk, and addressing or escalating disagreements to resolution
- Provide clear explanations to senior leaders about the rationale behind challenge points and how they impact Legal's risk profile
- Ensure that alignment of legal risk ratings, control descriptions, and documentation meet oversight expectations and support the Legal Risk Directive.
Issue Tracking & Remediation- Record issues identified by legal teams, internal audit, or risk partners.
- Working with legal stakeholders, draft action plans, monitor remediation progress, coordinate validation, and follow through to closure
- Support improvements to internal controls when remediation requires redesign or process changes
Testing & Quality Assurance- Partner with enterprise testing teams to support scheduled reviews of Legal Business Unit controls
- Review and challenge test scripts and results where appropriate
- Conduct quarterly quality checks of selected Legal Business Unit processes and prepare clear documentation of results
Annual Risk Assessment & Leadership Support- Lead the annual risk assessment process for the Legal Business Unit.
- Update risk ratings, coordinate internal challenge and review steps, and summarize the results
- Prepare the yearend summary for Legal leadership that outlines Legal's overall risk assessment, key changes, and any untested or ineffective controls.
Quarterly Risk Reporting- Develop and manage the quarterly reporting calendar for the Legal Business Unit
- Prepare consolidated quarterly summaries that highlight testing outcomes, risk assessment updates, and outstanding issues
- Send communications to stakeholders to keep risk activities on track and ensure deadlines are met
Legal Risk Stakeholder Support & Training- Risk related policy review
- Provide practical guidance to lawyers on completing riskrelated tasks, understanding system workflows, and interpreting reports
- Maintain stakeholder contact lists for riskrelated responsibilities
- Create or update training materials that explain legal risk responsibilities in clear, approachable terms
- Attend internal Risk team working and training sessions.
What You Bring- 5-7 years of experience in risk management, compliance, audit, or legal operations, ideally from a consulting firm
- Strong understanding of risk frameworks, control development, control testing practices, and issue management
- Excellent communication skills, with the ability to explain risk concepts to nontechnical audiences
- Strong organization and documentation skills with comfort managing quarterly and annual cycles
- Experience summarizing complex governance information for senior leadership
The above represents BMO Financial Group's pay range and type.
Salaries will vary based on factors such as location, skills, experience, education, and qualifications for the role, and may