An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Private Advertiser is seeking a senior leader to head AML, regulatory compliance and data protection. The role combines MLRO and DPO responsibilities to build scalable, risk-based programs across onboarding, monitoring, and reporting.
The candidate will engage with senior management and regulators, embedding a strong compliance culture while supporting rapid digital growth in financial services.
A rapidly growing, digitally focused financial institution is seeking a Head of AML, Compliance & Data Protection to lead and establish its Anti-Money Laundering (AML), regulatory compliance, and data privacy frameworks.
This is a senior, dual-hatted leadership role combining Money Laundering Reporting Officer (MLRO) and Data Protection Officer (DPO) responsibilities. The successful candidate will build scalable compliance and privacy programs, ensure regulatory readiness, and embed a strong risk and compliance culture across the organization.
The role will work closely with senior management, the Board, and key regulators while balancing regulatory requirements with the needs of a fast-growing digital financial services business.
Serve as the designated MLRO, with overall accountability for the organization's AML/CFT framework and regulatory engagement with the AMLC and BSP.
Develop, implement, and continuously enhance the AML/CFT program, including customer risk-rating, KYC/CDD/EDD, transaction monitoring, sanctions screening, and suspicious transaction reporting.
Establish appropriate AML controls for digital onboarding and eKYC, including customer identification, beneficial ownership verification, and risk-based customer acceptance.
Oversee transaction monitoring frameworks, including typologies, scenarios, thresholds, alert management, investigation procedures, and escalation protocols.
Lead the preparation, review, and filing of STRs and CTRs, ensuring accuracy, timeliness, appropriate documentation, and regulatory defensibility.
Establish and oversee sanctions compliance covering relevant international and Philippine sanctions requirements across customer onboarding, payments, and other applicable activities.
Develop the broader regulatory compliance framework covering consumer protection, lending disclosures, interest rate requirements, and product-level regulatory obligations.
Lead AML-related BSP examinations and AMLC engagements, including regulatory submissions, examination preparation, issue remediation, and follow-through.
Deliver AML and compliance training across the organization and provide regular reporting to senior management and relevant Board committees on compliance risks, trends, and program effectiveness.
Serve as the organization's Data Protection Officer (DPO) and oversee compliance with the Data Privacy Act of 2012 (RA 10173) and applicable NPC regulations and issuances.
Develop and maintain the organization's data privacy framework, including privacy policies, consent management, data subject rights, retention and disposal requirements, and privacy impact assessments.
Lead privacy-by-design reviews for new products, services, technologies, and data-processing activities.
Review and govern data-sharing, outsourcing, and data-processing arrangements with third-party providers, technology partners, and affiliated entities.
Oversee personal data breach response, including assessment, containment, regulatory notification, investigation, and remediation, in coordination with Information Security and other relevant functions.
Ensure applicable BSP data governance and technology risk requirements are integrated into data architecture, operational processes, and third-party arrangements.
Maintain the organization's Records of Processing Activities (ROPA) and oversee Privacy Impact Assessments for high-risk processing activities, including AI-enabled decisioning and analytics.
Promote organization-wide awareness of privacy requirements and responsible handling of personal and sensitive information.
Advise the CEO, senior leadership, and Board on emerging AML, regulatory compliance, and data privacy risks, particularly where these areas intersect.
Partner with Information Security, Risk, Legal, Technology, Product, and Operations teams on regulatory and control matters.
Coordinate regulatory responses and incident management involving potential AML, privacy, cybersecurity, or data governance implications.
Serve as a key regulatory contact with the BSP, AMLC, NPC, and other relevant authorities.
Establish a proactive compliance culture that supports business growth while maintaining strong regulatory and risk discipline.
12–18 years of relevant experience in AML, regulatory compliance, data privacy, or related functions, preferably within a Philippine bank, digital bank, fintech, payments company, or other highly regulated financial institution.
Proven experience serving as an MLRO, Deputy MLRO, or senior AML leader, with direct accountability for STR/CTR reporting, AMLC engagement, and BSP examinations.
Strong practical experience managing or serving as a Data Protection Officer, including privacy governance, PIAs, data subject rights, and personal data breach management.
Deep knowledge of Philippine AML/CFT requirements, including AMLA (RA 9160, as amended), AMLC regulations, and applicable BSP issuances.
Strong working knowledge of RA 10173 (Data Privacy Act), NPC regulations, and applicable BSP data governance requirements.
Experience with digital onboarding, eKYC, transaction monitoring, sanctions screening, and technology-enabled financial services.
Understanding of privacy and regulatory considerations surrounding AI-driven data processing, analytics, credit decisioning, and customer profiling.
Strong understanding of the FATF risk-based approach and its application within financial institutions.
CAMS certification required; DPO certification, CIPM, CIPP, or equivalent privacy credentials are advantageous.
Legal, CPA, or other relevant professional background is an advantage.
Strong executive presence with the ability to communicate complex regulatory matters clearly to senior management and Board-level stakeholders.
This is a high-impact leadership opportunity to shape AML, regulatory compliance, and data privacy frameworks within a rapidly growing digital financial institution.
The successful candidate will have the opportunity to build scalable programs from the ground up, work directly with senior leadership and regulators, and establish a strong risk-based and privacy-by-design culture as the organization expands its products, customer base, and digital capabilities.