The Compliance, Enterprise Risk Management and Data Privacy Department supports Tubulis with the following tasks:
Data Privacy:
- Serve as the primary point of contact for addressing inquiries to the External DPO.
- Develop, implement, and maintain data protection policies across the organization and supporting systems.
- Promote and oversee the implementation of recommendations issued by the External DPO.
- Support data privacy assessments, reviews, and audits to ensure ongoing compliance.
Healthcare Compliance:
- Establishment, implementation, oversight, and continuous enhancement of the Compliance Management System (CMS).
- Strategic compliance support to Tubulis’ business operations, including global policy development, compliance risk assessments, and compliance monitoring activities, in close collaboration with the Management Board, C-level executives, department heads, and other relevant functions.
- Establishment of compliance governance.
- Design, implementation, and oversight of an effective system for raising concerns, including a whistleblowing mechanism, and ensuring reported concerns are appropriately addressed.
- Development, implementation, and supervision of a comprehensive compliance training program.
- Ongoing compliance monitoring and effectiveness assessments.
- Conduct of internal investigations.
Enterprise Risk Management
- Managing and overseeing quarterly and ad-hoc risk updates prepared by designated risk owners.
- Facilitate risk identification and validation workshops across the organization.
- Own and maintain the Enterprise Risk Management (ERM) Policy, ensuring its ongoing relevance and effectiveness.
- Assess the effectiveness of risk management processes and ensure compliance with the Tubulis ERM Policy.
- Conduct ongoing review and monitoring of ERM activities to support continuous improvement.
