The Compliance Manager holds primary responsibility for ensuring the Company’s efficient and effective compliance with regulatory requirements set by the Bangko Sentral ng Pilipinas (BSP), Anti-Money Laundering Council (AMLC), Data Privacy Act (DPA), National Telecommunications Commission (NTC), and other governing bodies. The role collaborates closely with Legal and Compliance functions to align processes, reporting obligations, and governance standards with Group Risk.
Beyond regulatory compliance, the position also encompasses oversight of risk management across the broader fintech and payments industry. This includes analyzing current (as-is) processes and policies, researching emerging trends and technologies, and documenting assessments for review by senior leadership. The Compliance Manager is further tasked with producing clear, non-technical reports tailored for C-level executives and board members, ensuring that complex regulatory and risk issues are communicated in a concise and actionable manner.
DUTIES AND RESPONSIBILITIES
- Regulatory Compliance - Ensure timely submissions and implement governance policies, processes, and procedures in compliance with BSP, AMLC, DPA, PCI DSS, NTC, and other relevant governing bodies.
- Regulatory Updates - Continuously update the company on evolving requirements and compliance obligations across the fintech and payments industry.
- Internal Audit - Conduct internal audits of company processes, communications, and reporting to verify adherence to compliance standards.
- Document Reviews - Review, evaluate, and provide compliance input on NDAs, agreements, contracts, and other legal or operational documents to ensure alignment with regulatory and risk frameworks.
- Risk Frameworks - Establish and maintain security, disaster recovery, IT risk, and broader fintech risk policies and frameworks.
- Risk Register Management - Oversee the risk management process, including maintaining a comprehensive Risk Register that covers technology, operational, financial, and compliance risks.
- Employee Adherence - Ensure employees comply with all established procedures, frameworks, and risk management protocols.
- Risk Collaboration - Collaborate with teams to classify and manage risks across technology resources, payment systems, merchant operations, and customer data.
- AML Training: Conduct regular refresher training on AMLA requirements for existing employees and deliver structured compliance training for new hires to strengthen awareness and adherence to anti-money laundering standards.
JOB QUALIFICATION
- Bachelor’s degree in Business Administration, Financial Management, Accountancy, Economics, Management, Marketing, Legal Management, Political Science, or Information
- Technology/Computer Science (with specialization or exposure to compliance, risk, or regulatory frameworks).
- 3–5 years of experience in a compliance role involving BSP, AMLC, DPA, PCI DSS, and other governing bodies relevant to the payments industry.
- Prior work experience in a fintech or payment company, with exposure to operational, financial, and technology risk management.
- Demonstrated ability to review, evaluate, and provide compliance input on NDAs, agreements, contracts, and other legal or operational documents.
- Experience in conducting AMLA refresher training for existing employees and delivering structured compliance training for new hires.
- Strong organizational skills with the ability to design and document test processes to support compliance analysis and audits.
- Understanding of basic security principles including firewalls, SIEM, EDR, patching, and vulnerability management.
- Knowledge of industry standards and frameworks such as PCI DSS, ISO 27001:2013, NIST CSF, NIST 800-53, CSA CCM, ISO 27017, and ISO 22301.
- Excellent communication skills, with the ability to prepare non-technical reports and present compliance and risk issues effectively to C-level executives and board members.