- Salary
- $12k – $16k/yr
- Location
- Singapore, SG
- Workplace
- Onsite
- Type
- Full-time
- Department
- Legal
- Source
- Y Combinator
Description
HEAD OF COMPLIANCE
Singapore | Full-time | On-site | Reports to the CEO
ABOUT THE ROLE
We're looking for a Head of Compliance to own group compliance across every
regulated entity and licensed market we operate in - setting the framework,
personally holding each of our regulator relationships, and making sure no
obligation or deadline is missed anywhere in the group. You will oversee the
MLROs and compliance leads in each licensed entity, and own our new licence
acquisition efforts as we enter new markets.
This is a senior role for someone who has already been the accountable person -
a Head of Compliance or MLRO at a regulated payments business - and knows what a
regulator expects to see when they ask.
WHAT YOU'LL OWN
Regulatory relationships in every licensed market
- Be the group's primary point of contact with every regulator we are licensed
or registered with - Singapore, Malaysia, the Philippines, Australia, Hong
Kong and the United States.
- Own those relationships personally and continuously, not only when something
goes wrong. Our regulators should never be surprised by us.
- Handle queries, information requests, thematic reviews and on-site inspections
directly in every market - scope the response, draft it, manage the timeline,
close it out.
- Maintain a group-level view of our licensing footprint: every licence we hold,
its conditions, obligations and renewal timeline.
- File incident, breach, material-change and key-person notifications within the
required window in each jurisdiction.
- Track regulatory change across every market and turn it into action before it
becomes a gap.
- Prepare the CEO and board for regulatory engagement, and represent the company
in front of any of our regulators on your own.
New licence acquisition
- Own our new licence acquisition end to end. When we decide to enter a market
or upgrade a licence, you run it.
- Scope each target market: which licence we need, what it permits, capital and
local presence requirements, cost, and a realistic timeline to approval.
- Select and manage local law firms, licensing consultants and corporate service
providers. Brief them, hold them to timelines, and challenge their advice
rather than accepting it at face value.
- Compile the application pack - business plan, financial projections,
governance structure, flow of funds, risk assessments - and write the full
policy suite the regulator requires, so it reflects how we actually operate.
- Manage the regulator through the process: clarifications, requests for further
information, meetings and interviews, through to approval.
- Own the licence conditions and stand up local compliance arrangements - MLRO
appointment, governance, reporting - so the entity operates from day one.
- Own licence variations, upgrades and renewals on the same basis.
New products, flow of funds and proactive gap assessment
- Own regulatory compliance for every new product, feature and market launch.
Nothing ships without a compliance assessment, and you are the person who does
it.
- Assess and sign off the flow of funds for every product and payment
arrangement - who holds the money at each step, in which entity, under which
licence, and what that triggers for safeguarding, licensing scope, outsourcing
and reporting.
- Review new partners, acquirers, banking arrangements and payment methods for
regulatory and AML risk before we commit.
- Work proactively with the front line - Sales, Merchant Operations, Risk,
Support, Product - to find gaps in how the business actually operates rather
than how the policy says it does. Walk the process; surface what the
documentation misses.
- Run periodic gap assessments against each licence's obligations and keep a
live register with owners and target dates.
- Drive gaps to closure with the teams that own them - Product, Engineering,
Operations, Finance, Legal. You don't log a gap and hand it over; you follow
it through, escalate when it stalls, and confirm the fix landed.
- Be the person people come to before they act, not after - with clear,
commercially aware answers on what turns a "no" into a "yes".
Regulatory obligations and deadlines - non-negotiable
- Own a live inventory of every regulatory obligation across every entity and
jurisdiction: what is due, to whom, when, and who prepares it.
- Own on-time, accurate delivery of all periodic reporting and submissions.
- NO MISSED REGULATORY DEADLINES. This is the hard line of the role. You build
the tracking, buffers and escalation that make missing one structurally
difficult.
Internal and external audit
- Own both internal and external audit across every entity, and be the single
point of contact for auditors in every market.
- External: the independent AML/CFT audit, statutory compliance audits, partner
and acquirer due diligence, and any regulator-mandated review - scope,
timeline, evidence pack and the auditor relationship.
- Internal: the compliance monitoring and internal audit programme - annual
testing plan, control testing, thematic entity reviews, and reporting to the
CEO and board.
- Own remediation of all audit and regulator findings. Findings close with
evidence, on the committed date, not rolled forward.
Framework, oversight and policy
- Own the group AML/CFT, sanctions and regulatory compliance framework, and the
minimum controls and reporting cadence every entity works to.
- Design the compliance and risk structure - how the function is organised,
where accountability sits, what escalates and to whom - and advise the CEO and
board on what it needs to keep pace with the business.
- Provide functional oversight of the MLRO and compliance lead in each entity:
review and challenge their risk assessments, alert handling, SAR/STR decisions
and filings before they go out.
- Run the oversight cadence - escalation paths, group compliance committee, a
consolidated view of risk across entities - and coach the local leads.
- Own the full policy suite - AML/CFT, sanctions, KYC/KYB and CDD, transaction
monitoring, merchant acceptance and prohibited activity, complaints,
outsourcing - and make sure changes land in procedure and system
configuration, not just in the document.
WHAT WE'RE LOOKING FOR
Required
- Prior experience as Head of Compliance, MLRO or Compliance Officer of record
at a regulated payments, e-money or financial institution. This is not a first
accountable-person role.
- Deep working knowledge of AML/CFT and payments regulation, with real depth in
at least one major regime.
- Direct ownership of the regulator relationship as the named contact - not
preparing material for someone else to submit.
- Experience managing both internal and external auditors, and closing findings
out with evidence.
- Has led or played a substantive role in a payments or financial services
licence application - business plan, policy suite, external counsel, and
regulator engagement through to approval.
- Track record of owning a regulatory reporting calendar without misses.
- Experience advising on new product launches and flow-of-funds structures, and
driving the resulting gaps to closure with business and technology teams.
- Experience overseeing or managing compliance staff, ideally across more than
one entity or jurisdiction.
- Has personally written and defended compliance policy.
- Hands-on and detailed. You read the alerts, filings and audit evidence
yourself.
- Based in Singapore with existing right to work.
Strongly preferred
- Experience across more than one of: MAS (Payment Services Act), BNM, BSP,
AUSTRAC, HKMA/CSP, US state MTL or FinCEN MSB.
- A licence application taken to approval in more than one market, or in a
market we are targeting.
- A group structure where entities operate under different licences or through
acquirer/partner arrangements.
- Has run a compliance monitoring or internal audit testing programme.
- Fitness-and-propriety approval history with a regulator, or the ability to
obtain it.
- ICA, CAMS or equivalent certification.
- Merchant acquiring or marketplace payments - onboarding risk, prohibited MCCs,
merchant-level transaction monitoring.
- Comfortable with data. You can interrogate monitoring output and merchant
portfolios yourself.
How you work
- Deadlines are absolute. You build in buffer and escalate early rather than
explaining a miss afterwards.
- You bring a position, not just a risk. "No" comes with a route to "yes"
wherever one legitimately exists.
- You are direct with the CEO and with regulators, and don't soften a real
problem.
- You are comfortable building the function while running it.
WHY THIS ROLE
You'll own group compliance for a licensed payments business across multiple
regulated markets, holding every regulator relationship directly and reporting
to the CEO. You won't just maintain the licensing footprint - you'll extend it.
The scope is broader than an equivalent title at a single-market institution.