Head of Risk, Compliance & Legal
Description
Mission:
Skip is on a mission to fast-track Australians into homeownership by building a fairer, faster path to buying a home.
We are a fintech lender in a period of rapid growth, with an established risk and compliance framework, an active Risk Committee, and institutional funding relationships that hold us to a high standard. Responsibility for risk, compliance and legal currently sits with our COO.
This role exists to take that framework to its next level of maturity - deeper, more automated, and scalable. It is a genuine build opportunity on a strong baseline, not a caretaker role.
About the role:
This is a role for someone who wants to build – not just manage.
Risk, compliance and legal currently sits with our COO. The framework is in place and functioning: we hold an Australian Credit License, our policies and registers are established, and our partners review us on a regular cycle. What the next stage of growth calls for is a dedicated owner who can continue to uplift our capabilities- deepening the monitoring and assurance program, automating what is still manual, and extending the framework as our volumes, channels and regulatory surface all expand.
We are explicit about the kind of function we want. Risk and compliance should enable growth, not create a queue. In practice, that means you will own the risk appetite so the business can operate inside pre-agreed boundaries without asking permission, publish a service standard for the reviews you own, and be accountable for work going live compliantly rather than for flagging that it might not. It also means you will hold an absolute veto on anything that genuinely threatens our brand and business, and we will back you when you use it. Enabler on ninety-five per cent of decisions; immovable on five.
You will report to the COO with a hard line to the Board Risk Committee. Your objectives are set there, you will have standing time with the Risk Committee, and you will have a documented right to escalate directly to the Board. We have designed the role this way deliberately - genuine second-line independence is what makes the function credible to our Board, partners and our regulators.
You will not be our General Counsel. External counsel handle our securitisation programme and our principal funding agreements and will continue to. You will own the commercial contracting layer around them, and the relationship with those firms.
Over time this role has a clear path. As the business scales it becomes a Chief Risk Officer reporting to the CEO or the Board. If you perform, that opportunity will be on the table.
What this role owns - and what it does not:
Owns. Regulatory compliance, operational and enterprise risk, privacy and Consumer Data Right obligations, and second-line assurance over credit process - whether policy was followed. Plus the commercial contracting layer, the contract register, and the management of external counsel.
Does not own. Credit appetite - whether the policy itself is right - which sits with Credit and Operations. Nor securitisation and funding documentation, contentious matters, or formal legal opinions, which remain with external firms.
Key Responsibilities:
Own and continue to uplift the framework
- Own and deepen the compliance obligations register, mapped across the NCCP Act and National Credit Code, the relevant ASIC regulatory guides, the AML/CTF Act, the Privacy Act, the Consumer Data Right regime and our AFCA obligations - and own the process that keeps it current, not just the document that records it
- Own the enterprise risk register and lift it to the next standard - named first-line owners, assessed control effectiveness and tracked remediation, reviewed on a rhythm rather than before a board meeting
- Own Skip’s risk appetite statement, expressed so that an operations or product lead can tell whether a decision sits inside it without asking you
- Design and run a rolling compliance monitoring and testing plan across origination, servicing, collections and hardship
- Own the compliance calendar and the policy suite - complaints, breach reporting, AML/CTF, privacy, CDR, hardship, conflicts and outsourcing
Product governance, DDO and target market determinations
- Own TMD and DDO review processes and ensure our products align with regulatory requirements
- Own the reasonable steps obligation - making sure distribution across our broker, aggregator, white-label and direct channels is consistent with each TMD, and that we can evidence it rather than assert it
- Bring market feedback into those reviews as evidence - complaints and AFCA themes, distributor and broker reporting, arrears and hardship experience, and product outcome data - so that a TMD review changes something when the evidence says it should
- Sit in the product development process early enough to shape design - not so late that saying no is the only option left
Complaints, AFCA and dispute resolution
- Own our internal dispute resolution framework under RG 271, including response timeframes, decision quality and the systemic issues process
- Own our AFCA membership obligations and the six-monthly IDR data reporting to ASIC, and use what the data shows us about root causes rather than simply filing it
- Own our hardship obligations and the associated regulatory reporting, and make sure the volume of hardship cases informs product and policy rather than sitting in a queue
Breaches and incidents and resilience
- Own the incident and breach register end to end, including root cause analysis, remediation tracking and reportable situations assessment under RG 78
- Own and mature the operational risk framework - control design and testing, incident themes and emerging risk
- Own the outsourcing and third-party register and the risk assessment of material service providers, including their subcontractors
- Own business continuity and disaster recovery planning and, more importantly, the evidence it has been tested - and meet the operational risk expectations that flow down to us from our ADI funders
- Meet the operational risk expectations that flow down to us from our ADI funders, who assess us as a material service provider
Financial crime, privacy and data
- Own Skip’s AML/CTF program - the transition to the reformed obligations, customer due diligence oversight, transaction monitoring and AUSTRAC reporting - and commission the independent evaluation, then close what it finds
- Own Skip’s Consumer Data Right position and requirements, including the compliance and reporting relationship with the ACCC and the OAIC, and keep us current with the Consumer Data Standards
- Own privacy compliance - the Privacy Act and Australian Privacy Principles, our privacy policy and collection notices, third-party data flows, and eligible data breach assessment and notification
Legal and contracting
- Own the contract register, our template agreements, and a contracting playbook that lets the business self-serve on routine agreements
- Select, brief and manage external counsel, and own the legal budget
- Track conditions subsequent and ongoing obligations arising under our funding and partnership agreements
- Escalate anything contentious, novel, or bearing on our funding structure to external counsel - and know exactly where that line sits
Governance and reporting
- Own the Risk Committee pack and the risk section of board reporting - material risks, emerging themes, control weaknesses and overdue remediation, said plainly
- Support the operation of the Risk Committee, including action registers tracked through to completion
- Be our point of contact for funder, rating agency and auditor due diligence on the risk and compliance framework
Ways of working
- We do not accept compliance processes that scale linearly with volume. You will have the full support of our product and engineering team, and we expect you to use it
- Push policy checks into the origination flow rathe