About the Role
In this role as Head of Compliance you will own, manage and directly deliver Netzon's Compliance programme across the Group globally.
You will establish and maintain the frameworks, policies, management systems, controls and governance processes needed to support legal, regulatory, contractual, certification and business requirements. This includes privacy and data protection, information security governance, quality management, artificial intelligence governance, corporate ethics, risk management and wider regulatory compliance.
Reporting directly to the Chief Operating Officer, and accountable to the Board, the role combines strategic leadership with hands-on management and execution. It is accountable for the design, management and day-to-day operation of the compliance function.
Responsibilities
Governance, Risk & Compliance
- Own, develop, implement, maintain and continually improve Netzon's Governance, Risk & Compliance framework.
- Provide advice and guidance to senior management and the Board on governance, compliance, regulatory, privacy, security, quality and ethical matters.
- Monitor legal, regulatory, contractual and certification requirements and coordinate implementation of relevant controls.
- Prepare governance reporting, management information, roadmaps and improvement plans.
- Promote a culture of integrity, accountability, transparency and continual improvement.
Privacy & Data Protection
- Own, develop, implement, maintain and continually improve the privacy and data protection programme.
- Own and implement privacy risk assessments, data protection impact assessments, records of processing, international transfer assessments and related governance activities.
- Own and implement data subject rights requests processes and manage privacy incident assessment and response.
- Develop and maintain privacy notices, policies, procedures, guidance and controls.
- Act as the primary advisor for privacy and data protection matters.
Information Security Governance
- Own governance activities supporting ISO 27001, PCI-DSS, client security requirements and other applicable information security frameworks.
- Develop and maintain information security policies, standards, procedures and governance controls.
- Coordinate audits, assessments, penetration testing activities, remediation programmes and evidence collection.
- Support security risk management and continuous improvement activities with technology and operational teams.
- Manage security incident assessment and response.
Artificial Intelligence Governance
- Develop and maintain the organisation's artificial intelligence governance framework.
- Assess artificial intelligence tools, vendors, technologies and use cases for legal, privacy, security, ethical and contractual compliance.
- Develop artificial intelligence policies, standards, procedures, controls and training materials.
- Monitor evolving artificial intelligence regulatory requirements and promote responsible adoption across the business.
Corporate Compliance & Ethics
- Own and maintain the broader ethics and corporate compliance framework.
- Develop and maintain policies and controls covering anti-bribery and corruption, whistleblowing, code of conduct, conflicts of interest, gifts and hospitality, environmental and sustainability compliance, and ethical business conduct.
- Manage investigations relating to compliance concerns, misconduct allegations and whistleblowing reports.
- Promote ethical decision-making and practical compliance across the organisation.
Client, Supplier & Contract Compliance
- Review and negotiate privacy, security, governance and compliance provisions in client, supplier and subcontractor agreements.
- Own and implement due diligence, supplier reviews, client audits, compliance questionnaires and governance assessment processes.
- Translate contractual requirements into practical operational controls and ongoing compliance activities.
- Advise commercial, operational and procurement teams on compliance implications of new services, technologies, suppliers and business opportunities.
Policy, Training, Incident Management & Records
- Draft, review, publish and maintain policies, standards, procedures and governance documentation.
- Design, develop and deliver compliance, privacy, quality, security, artificial intelligence governance and ethics training programmes.
- Lead or coordinate privacy, security, compliance and governance investigations and remediation activities.
- Maintain evidence repositories and records required for audits, certifications, client reviews and regulatory enquiries.
- Undertake any other responsibility considered a reasonable business requirement within the scope of the role as directed by the Chief Operating Officer or Board.
Skills, Know-how and Experience
Must have:
- Strong knowledge of governance, risk management, compliance, privacy, information security, quality management and regulatory frameworks.
- Experience designing, implementing and operating compliance programmes and management systems.
- Experience supporting or maintaining ISO 27001 and/or ISO 9001 certification programmes.
- Experience reviewing contracts, supplier arrangements and regulatory obligations.
- Strong policy drafting, documentation and governance skills.
- Strong analytical, project management and problem-solving capability.
- Excellent written and verbal communication skills in English.
- Ability to influence stakeholders at all levels, including senior management.
- Ability to operate independently with minimal supervision in a broad multidisciplinary role.
- High level of integrity, discretion and professional judgement.
Preferred:
- Experience supporting PCI-DSS compliance programmes.
- Experience in a multinational services, outsourcing, technology or contact centre environment.
- Experience implementing artificial intelligence governance programmes.
- Experience working directly with executive leadership teams and Boards.
Technical / Professional Certifications
Preferred:
- Privacy certifications such as CIPP/E, CIPM, CIPT or equivalent.
- ISO 27001 Lead Implementer, Lead Auditor or Internal Auditor certification.
- ISO 9001 Lead Implementer, Lead Auditor or Internal Auditor certification.
- Compliance, risk management, governance or artificial intelligence governance certification.
Reporting & Structure
- Reports to: CEO/Board.
- Direct Reports: None initially. The role may supervise future compliance resources as organisational needs develop.