Group Control Assurance Lead

Payhawk

Greater London

On-site

GBP 90,000 - 130,000

Full time

12 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Paid time off
Work-from-anywhere days
Office exchange policy
Health membership
On-site days
Commuting allowance

Job summary

Payhawk in London seeks a senior second-line controls assurance specialist to lead independent testing across two electronic money entities and the full regulatory framework. You will own end-to-end control testing for regulatory compliance, financial crime, outsourcing, and governance, reporting to the Risk Committee and the Boards, with scope to shape the programme and drive remediation.

This role requires strong data fluency, executive presence, and the ability to challenge control owners

Qualifications

  • Experience in compliance monitoring or assurance within a regulated framework.
  • Second-line or third-line testing across multiple risk domains.
  • Strong knowledge of FCA expectations for the compliance function.
  • Ability to drive remediation to closure and run programmes across entities.

Responsibilities

  • Build and own the Board-approved control assurance and monitoring plan for both entities.
  • Design and run risk-based control testing across the risk register.
  • Test operational resilience, ICT controls and governance across entities.
  • Test regulatory reporting controls and data accuracy for returns.
  • Lead remediation and stakeholder engagement to achieve closure.
  • Provide credible challenge with written findings and owner accountability.

Skills

Test strategy design
Data analysis
Independent thinking
Board communication

Education

BA/BS in Finance, Risk or related field

Tools

SQL
Python
Tableau/Power BI

Job description

Payhawk is a leading global spend management solution for scaling businesses. Headquartered in London and combining company cards, reimbursable expenses and accounts payable into a single product; its future-facing technology enables finance teams to control and automate company spending at scale.

The Payhawk customer base includes fast-growing and mature multinational companies in 32 countries including LuxAir and Wagestream. With offices in New York, London, Berlin, Munich , Barcelona, Paris, Amsterdam, Vilnius and Sofia; Payhawk is backed by renowned investors such as Lightspeed Venture Partners, Greenoaks, QED Investors, Bek Ventures and Eleven Ventures.

Our values include supporting flat hierarchies, taking ownership and responsibility, seeking and providing feedback, managing constructive critique, and speaking our minds. We understand that the best ideas don’t all come from the same place, so we encourage diversity and inclusion in all areas of our work.

We’re also on a journey to measure and improve our environmental and social impact.From virtual cards to digital subscriptions, our software and automation help take paper out of the equation for our customers, too.

We’re changing the world of payments, and we’re looking for an exceptional team to help us.

About the Role

This is a senior second-line role with a wide mandate: independent control testing across two licensed entities and the full regulatory framework, reporting into the Risk Committee and both Boards, with the latitude to design the programme the way you think it should work.

Payhawk operates two electronic money institution licences, one in the UK supervised by the Financial Conduct Authority and one in Lithuania supervised by the Bank of Lithuania. You will cover both, reporting to the Director of Risk and Outsourcing, independent of the teams you review.

In plain terms: you test whether our controls work, and whether they would catch what they are designed to catch. That means testing systems rather than case files, and populations rather than hand-picked samples. The questions look different in every domain. Does a safeguarding reconciliation actually prove what it claims to prove. Would we know promptly if a critical outsourced provider stopped meeting its obligations. Is a regulatory return built on data that reconciles. Would a resilience control hold in the scenario it was designed for. Are the alerts a screening or monitoring tool should be raising being raised at all. It takes someone comfortable with data, confident forming their own view, and senior enough to be heard when the answer is unwelcome.

Your mandate is the whole control framework across both entities: regulatory compliance and conduct, regulatory reporting, financial crime and sanctions, operational resilience and ICT under the Digital Operational Resilience Act, safeguarding, capital adequacy, outsourcing and third‑party management, and governance. You will agree risk‑based priorities with the Risk Committee each cycle rather than testing everything at once.

You will own the programme end to end and shape how it develops: the plan, the testing, the findings, the credible challenge to control owners, the remediation through to closure, and the reporting into both Boards. Identifying a gap is the easy half, so this role is as much programme management as testing: convening the right stakeholders, setting clear expectations and dates, keeping the work moving, escalating where it stalls, securing the approvals it needs, and validating independently that the fix holds before anything is marked complete.

How we work with AI. Payhawk builds automation for a living, and we build our control functions the same way. Good assurance at our scale means testing whole populations rather than handle‑picked samples, so we want someone fluent with AI as a working tool: pulling your own data from connected systems, prompting well enough to get reliable answers out of large document sets, and turning a test into something repeatable that produces its own evidence. We will give you the tooling, the data access and the mandate to build the programme around it, and any recurring manual check is yours to automate.

Responsibilities
  • Build and own the Board‑approved group control assurance and monitoring plan covering both licensed entities, with priorities set by the risk assessment and agreed with the Risk Committee
  • Design and run risk‑based control testing across the group risk register, assessing both design effectiveness and operating effectiveness
  • Test operational resilience and ICT controls under the Digital Operational Resilience Act, and governance and conduct controls across both entities
  • Test safeguarding and capital adequacy controls, including whether reconciliations and calculations evidence what they are relied on to evidence
  • Test regulatory reporting controls, including the completeness and accuracy of the data behind regulatory returns
  • Test outsourcing and third‑party controls, including whether we would detect a critical provider falling below its obligations
  • Independently test detection controls end to end, including sanctions and politically exposed person screening effectiveness and transaction monitoring coverage and calibration, including the population that never generated an alert
  • Lead the remediation of the gaps you identify, acting as programme manager for closure: convene the relevant stakeholders, agree scope, owners and dates, track progress, and secure the governance approvals required
  • Independently validate that a remediated control works before the finding is closed, and reopen it where the fix does not hold
  • Provide credible challenge to control owners, with written findings, severity ratings, agreed actions and owners
  • Report testing results, remediation status, coverage against plan and thematic findings to the Risk Committee and to the Boards of both entities
  • Own the relationship with external assurance providers, and progressively bring recurring testing in‑house to reduce cost and dependency
  • Build the testing as tooling: automated, repeatable, population‑level tests that generate their own evidence rather than one‑off manual exercises
  • Support supervisory engagement and internal audit by producing evidence of control effectiveness on demand
  • Provide independent assurance over significant change, so that new systems and processes are tested before they become business as usual
Requirements
  • Genuine fluency with AI in your day‑to‑day work. You can pull your own data and reports from connected systems, prompt well enough to get reliable answers out of large document sets and datasets, and build a repeatable workflow from a few chained steps. You have built something yourself, whether a workflow, a set of prompts, a report or a small automation that saved you real time, and you can walk us through it
  • Compliance monitoring, control testing or assurance experience across a regulated framework, in a second‑line or third‑line capacity, covering more than one risk domain rather than a single specialism
  • Strong knowledge of Financial Conduct Authority expectations on the compliance function and its monitoring programme, and of equivalent EEA expectations
  • Real depth in at least two of the risk domains above, and the appetite to build it in the others
  • The ability to distinguish control design from control execution, and to test a system rather than a case file
  • A track record of driving remediation to closure, not only reporting findings. You can run a programme without owning the resources: convene stakeholders across functions, hold them to dates, escalates proportionately, and get decisions made
  • Comfortable working with data at population level rather than relying only on manual samples, and able to get to an answer in a dataset with the tooling available to you
  • Independence and spine. You can tell a senior control owner that their control does not work, evidence it, and make the finding stick
  • Written English to Board standard, and the judgement to rate findings proportionately rather than escalating everything
  • Fluent written and spoken English, and the right to work in the United Kingdom
Nice to have
  • A Big Four or specialist consultancy assurance, audit or regulatory advisory background
  • Experience in a payments, e‑money or banking institution, and familiarity with how these frameworks apply to an electronic money institution
  • Testing exposure to operational resilience and ICT risk, safeguarding, capital adequacy or regulatory reporting
  • Experience testing screening or transaction monitoring effectiveness, including matching behaviour, list coverage and scenario back‑testing
  • SQL, Python or similar, and practical use of data testing frameworks
  • A relevant qualification such as IIA, ICA, ACAMS or equivalent
  • Experience of a multi‑entity or multi‑jurisdiction group structure, and of intragroup outsourcing oversight
Company Benefits
  • 30 days of paid time off + 12 work‑from‑anywhere days
  • Exchange policy to another Payhawk office (Amsterdam, Paris, Barcelona, Berlin, Sofia)
  • Health and fitness membership
  • Two company on‑sites per year
  • Opportunity to use the Payhawk product, with a monthly commuting allowance of £150

Payhawk is an Equal Employment Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Content & AI Enablement Team Lead
Content & AI Enablement Team Lead

Payhawk • Greater London

On-site
GBP 90,000 - 120,000
30 days holiday paid leave
Exchange policy to Payhawk offices
Sports card fully funded
+1
Business Development Representative
Business Development Representative

Payhawk • Greater London

Hybrid
GBP 30,000 - 60,000
4 days in the office per week
30 days paid time off + 12 work-from-?
Health and fitness membership
+2
Global Content & AI Enablement Lead
Global Content & AI Enablement Lead

Payhawk • Greater London

On-site
GBP 90,000 - 120,000
30 days holiday paid leave
Exchange policy to Payhawk offices
Sports card fully funded
+1
Quality Assurance Executive
Quality Assurance Executive

OpenPayd Ltd • Greater London

Hybrid
GBP 40,000 - 65,000
Personal training budget
Cycle to Work
Gym membership discount
+8
Assurance Manager EU/UK
Assurance Manager EU/UK

United States Digital Space LLC • Greater London

On-site
GBP 80,000 - 110,000
Holiday entitlement 20–30 days
Team outings allowance
Parental leave support
+1
Assurance Manager EU/UK
Assurance Manager EU/UK

Trustly, Inc. • Greater London

Hybrid
GBP 90,000 - 120,000
20 to 30 days of holiday
Monthly team outing allowance
Parental leave top-up
+3
Assurance Manager EU/UK
Assurance Manager EU/UK

Trustly • Greater London

On-site
GBP 90,000 - 120,000
20 to 30 days of holiday
Monthly team outing allowance
Parental leave top-up
+3
Technology Assurance & Operational Risk Specialist
Technology Assurance & Operational Risk Specialist

LHV Bank • Greater London

On-site
GBP 70,000 - 100,000
Vitality Health Plan
Life assurance – 4 x salary
Income protection insurance – 75%
+2
KYC Associate
KYC Associate

B4B Payments - A Banking Circle Group Company • Greater London

On-site
GBP 52,000 - 68,000
25 days annual leave
Annual wellness day off
Employee Assistance Programme counsell
+3
Global Demand Generation Manager London
Global Demand Generation Manager London

Payhawk • Greater London

On-site
GBP 70,000 - 90,000
30 days of paid time off + 12 work-from-anywhere days
Health and fitness membership
Exchange policy to another Payhawk office