Head of Risk, Compliance & Legal

Skip LoansSydney, New South WalesHybridFull-timeSenior, 5–8 yearsListed 1 hour ago

Apply now

About this role

Mission:

Skip is on a mission to fast-track Australians into homeownership by building a fairer, faster path to buying a home.

We are a fintech lender in a period of rapid growth, with an established risk and compliance framework, an active Risk Committee, and institutional funding relationships that hold us to a high standard. Responsibility for risk, compliance and legal currently sits with our COO.

This role exists to take that framework to its next level of maturity - deeper, more automated, and scalable. It is a genuine build opportunity on a strong baseline, not a caretaker role.

About the role:

This is a role for someone who wants to build – not just manage.

Risk, compliance and legal currently sits with our COO. The framework is in place and functioning: we hold an Australian Credit License, our policies and registers are established, and our partners review us on a regular cycle. What the next stage of growth calls for is a dedicated owner who can continue to uplift our capabilities- deepening the monitoring and assurance program, automating what is still manual, and extending the framework as our volumes, channels and regulatory surface all expand.

We are explicit about the kind of function we want. Risk and compliance should enable growth, not create a queue. In practice, that means you will own the risk appetite so the business can operate inside pre-agreed boundaries without asking permission, publish a service standard for the reviews you own, and be accountable for work going live compliantly rather than for flagging that it might not. It also means you will hold an absolute veto on anything that genuinely threatens our brand and business, and we will back you when you use it. Enabler on ninety-five per cent of decisions; immovable on five.

You will report to the COO with a hard line to the Board Risk Committee. Your objectives are set there, you will have standing time with the Risk Committee, and you will have a documented right to escalate directly to the Board. We have designed the role this way deliberately - genuine second-line independence is what makes the function credible to our Board, partners and our regulators.

You will not be our General Counsel. External counsel handle our securitisation programme and our principal funding agreements and will continue to. You will own the commercial contracting layer around them, and the relationship with those firms.

Over time this role has a clear path. As the business scales it becomes a Chief Risk Officer reporting to the CEO or the Board. If you perform, that opportunity will be on the table.

What this role owns - and what it does not:

Owns. Regulatory compliance, operational and enterprise risk, privacy and Consumer Data Right obligations, and second-line assurance over credit process - whether policy was followed. Plus the commercial contracting layer, the contract register, and the management of external counsel.

Does not own. Credit appetite - whether the policy itself is right - which sits with Credit and Operations. Nor securitisation and funding documentation, contentious matters, or formal legal opinions, which remain with external firms.

Key Responsibilities:

Own and continue to uplift the framework

- Own and deepen the compliance obligations register, mapped across the NCCP Act and National Credit Code, the relevant ASIC regulatory guides, the AML/CTF Act, the Privacy Act, the Consumer Data Right regime and our AFCA obligations - and own the process that keeps it current, not just the document that records it
- Own the enterprise risk register and lift it to the next standard - named first-line owners, assessed control effectiveness and tracked remediation, reviewed on a rhythm rather than before a board meeting
- Own Skip’s risk appetite statement, expressed so that an operations or product lead can tell whether a decision sits inside it without asking you
- Design and run a rolling compliance monitoring and testing plan across origination, servicing, collections and hardship
- Own the compliance calendar and the policy suite - complaints, breach reporting, AML/CTF, privacy, CDR, hardship, conflicts and outsourcing

Product governance, DDO and target market determinations

- Own TMD and DDO review processes and ensure our products align with regulatory requirements
- Own the reasonable steps obligation - making sure distribution across our broker, aggregator, white-label and direct channels is consistent with each TMD, and that we can evidence it rather than assert it
- Bring market feedback into those reviews as evidence - complaints and AFCA themes, distributor and broker reporting, arrears and hardship experience, and product outcome data - so that a TMD review changes something when the evidence says it should
- Sit in the product development process early enough to shape design - not so late that saying no is the only option left

Complaints, AFCA and dispute resolution

- Own our internal dispute resolution framework under RG 271, including response timeframes, decision quality and the systemic issues process
- Own our AFCA membership obligations and the six-monthly IDR data reporting to ASIC, and use what the data shows us about root causes rather than simply filing it
- Own our hardship obligations and the associated regulatory reporting, and make sure the volume of hardship cases informs product and policy rather than sitting in a queue

Breaches and incidents and resilience

- Own the incident and breach register end to end, including root cause analysis, remediation tracking and reportable situations assessment under RG 78
- Own and mature the operational risk framework - control design and testing, incident themes and emerging risk
- Own the outsourcing and third-party register and the risk assessment of material service providers, including their subcontractors
- Own business continuity and disaster recovery planning and, more importantly, the evidence it has been tested - and meet the operational risk expectations that flow down to us from our ADI funders
- Meet the operational risk expectations that flow down to us from our ADI funders, who assess us as a material service provider

Financial crime, privacy and data

- Own Skip’s AML/CTF program - the transition to the reformed obligations, customer due diligence oversight, transaction monitoring and AUSTRAC reporting - and commission the independent evaluation, then close what it finds
- Own Skip’s Consumer Data Right position and requirements, including the compliance and reporting relationship with the ACCC and the OAIC, and keep us current with the Consumer Data Standards
- Own privacy compliance - the Privacy Act and Australian Privacy Principles, our privacy policy and collection notices, third-party data flows, and eligible data breach assessment and notification

Legal and contracting

- Own the contract register, our template agreements, and a contracting playbook that lets the business self-serve on routine agreements
- Select, brief and manage external counsel, and own the legal budget
- Track conditions subsequent and ongoing obligations arising under our funding and partnership agreements
- Escalate anything contentious, novel, or bearing on our funding structure to external counsel - and know exactly where that line sits

Governance and reporting

- Own the Risk Committee pack and the risk section of board reporting - material risks, emerging themes, control weaknesses and overdue remediation, said plainly
- Support the operation of the Risk Committee, including action registers tracked through to completion
- Be our point of contact for funder, rating agency and auditor due diligence on the risk and compliance framework

Ways of working

- We do not accept compliance processes that scale linearly with volume. You will have the full support of our product and engineering team, and we expect you to use it
- Push policy checks into the origination flow rather than onto a checklist, build automated exception and breach detection, and design the function so compliance headcount grows sub-linearly with settlements
- Design and deliver role-based compliance training across credit operations, sales, broker distribution and customer teams - and be the accessible, trusted point of contact for anyone raising a concern

What you will bring:

- 8+ years across risk, compliance or financial services regulation, including time inside an Australian credit licensee. You have personally owned a compliance and risk framework - owned it, not advised on it
- Working knowledge of the NCCP Act and National Credit Code, the relevant ASIC regulatory guides, the AML/CTF Act and the Privacy Act as they apply to a credit provider
- You have worked in a business under about 150 people. You know a framework designed for a bank does not transplant, and that adding process is usually the wrong answer
- Experience identifying, assessing and monitoring operational risks and controls - registers, incidents, remediation, emerging risk - and translating obligations into controls people will actually follow
- Commercial judgment. You can tell the difference between a risk that threatens the licence and a risk that is merely untidy, and you treat them differently
- A collaborative, pragmatic style - able to build trust with frontline, sales and product teams without diluting the independence of the second line
- Excellent written communication. You can write a board paper a director reads once and understands

Helpful, not required

- A law degree and post-qualification experience at a firm with a financial services, credit or securitisation practice.

We are not hiring a General Counsel, but this role manages our commercial contracting and our external counsel, and a legal background makes that materially easier. It is a strong plus, not a filter - we would take a compliance operator who has built a framework over a lawyer who has not

- Experience with warehouse facilities, servicing agreements or securitisation
- Consumer Data Right or open banking experience - as a data holder, an accredited data recipient, or through an intermediary arrangement
- Broker channel or third-party distribution conduct risk
- AML/CTF depth, particularly under the reformed obligations
- Evidence you have specified software or worked closely with engineers

Why join us:

- Build, don’t babysit. You inherit a functioning framework and a credible baseline - and the mandate to take it from solid to best-in-class. Real ownership from day one, not a delegated slice of someone else’s job
- Real independence. A hard line to the Risk Committee, your objectives set there and a documented right of escalation to the Board
- A clear path up. As the business scales this becomes a CRO role reporting to the CEO or the Board. If you perform, that will be explicitly on the table
- Engineering leverage. Full support of an internal product and engineering team, so you automate the function rather than staff it
- Serious company, serious scale. Backed by leading US venture funds, global credit partners and prominent Australian investors, Skip is in a true hyper-growth phase with major distribution partnerships already live
- A positive impact. Your work helps hard working Australians Skip to home ownership sooner
- A team that backs you. We move fast, we take ownership, and we back each other to do the best work of our careers