Role Summary
You will own compliance across our global delivery operations, covering client contractual obligations, information security and privacy, industry regulations, and labor and statutory requirements. Our clients (in [BFSI, healthcare, telecom, retail, etc.]) audit us constantly and expect bank-grade controls, so this leader ensures we pass those audits and turn compliance into a reason clients choose and stay with us.
Key Responsibilities
Compliance framework and certifications
- Own the compliance framework across all delivery centers, including work-from-home and hybrid delivery
- Maintain and renew certifications and attestations: ISO 27001, ISO 27701, SOC 1 / SOC 2 Type II, PCI-DSS, and HIPAA readiness
- Run the compliance risk assessment, control testing, and continuous monitoring across sites and programs
Client audits and contractual compliance
- Serve as the primary contact for client audits, due diligence questionnaires, and regulator-driven client assessments, including those from banks under outsourcing rules such as the RBI outsourcing directions
- Review and negotiate compliance, data protection, and audit clauses in MSAs, SOWs, and DPAs with Legal and Sales
- Track obligations by client and ensure delivery teams follow them, such as call recording, data retention, and access restrictions
- Own audit findings through closure with clear remediation ownership and timelines
Data privacy and protection
- Lead the privacy program under GDPR, India's DPDP Act, and other applicable laws, including data mapping, cross-border transfer controls, breach response, and data subject requests
- Govern handling of sensitive data in voice and non-voice processes: PII, PCI, PHI, and financial data
- Partner with the CISO and IT on access controls, DLP, clean-desk and secure-floor policies, BYOD, and remote-work security
Industry and process compliance
- Ensure adherence to customer-facing regulations relevant to our client mix, such as TCPA and telemarketing rules, FDCPA / Reg F for collections, consumer protection norms, and fair-treatment requirements
- Oversee quality and conduct monitoring: call and chat compliance scoring, script adherence, mis-selling, and complaint handling
- Embed AML/KYC and fraud controls in financial-services processes, where applicable
People, vendor, and statutory compliance
- Oversee background verification standards, training and certification requirements, and employee conduct policies
- Ensure compliance with labor and statutory requirements (Shops & Establishments, POSH, night-shift and transport rules, SEZ/STPI conditions) working with HR and Admin
- Run third-party and subcontractor risk management for technology vendors, staffing partners, and sub-processors
AI and emerging risk
- Establish governance for AI, GenAI, speech analytics, and automation in delivery, covering client approval, data use, model risk, and human oversight
Governance, reporting, and team
- Report compliance posture, incidents, and audit outcomes to the executive team, Board, and key clients
- Own the code of conduct, whistleblower and ethics mechanism, and investigations
- Build and lead a compliance, audit, and privacy team, with site-level compliance leads
- Manage the compliance budget and GRC tooling (e.g., ServiceNow GRC or equivalent)
Qualifications
Required
- Bachelor's degree in Engineering, Law, Commerce, or a related field; MBA or postgraduate qualification preferred
- [1215] years of experience in compliance, risk, information security governance, or audit, with [5+] years leading teams
- Hands‑on experience managing external audits and attestations (SOC 2, ISO 27001, PCI-DSS) end to end
- Working knowledge of data privacy laws (GDPR, DPDP Act) and information security frameworks (NIST, ISO)
- Experience handling client audits in a services, BPO, IT-ITeS, or outsourcing environment
Preferred
- Certifications such as CISSP, CISA, CISM, ISO 27001 Lead Implementer/Auditor, CIPP/CIPM, CAMS, or CCEP
- Experience in BFSI, healthcare, or telecom BPO
- Exposure to multi-site, multi-geography operations and large-scale hiring and attrition environments
- Experience with GRC platforms, RCSA design, and AI governance
Skills and Attributes
- Business‑minded and able to say "yes, if" rather than just "no"
- Credible with clients, auditors, and regulators, and able to hold firm with operations leaders under delivery pressure
- Strong at translating complex requirements into simple floor‑level controls
- Excellent communication, from the ops floor to the Board room
- High integrity and sound judgment
Success Measures (first 12 months)
- Complete a compliance gap assessment across all sites and programs, with a prioritized roadmap
- Clean renewals of ISO 27001, SOC 2, and PCI-DSS, with no major client audit findings
- Consolidated obligations register by client, with control ownership assigned
- Reduced audit‑finding closure time and fewer repeat findings
- DPDP Act readiness and an AI governance framework in place
- Regular, decision‑useful reporting to the Board and key clients