
Job Description
ABOUT THE ROLE
We're looking for a Compliance Director to own group compliance across every
regulated entity we operate - setting the framework, holding the regulatory
relationships, and making sure not a single obligation or deadline is missed
anywhere in the group.
You will oversee the MLROs and local compliance leads in each licensed entity,
functionally rather than by title alone: you set the standard they work to, you
review what they produce, and you are accountable to the CEO for the group's
overall compliance posture.
This is a senior role for someone who has already been the accountable person -
a Head of Compliance or MLRO at a regulated payments business - and knows exactly
what a regulator expects to see when they ask.
WHAT YOU'LL OWN
Group compliance framework
- Own the group-wide AML/CFT, sanctions and regulatory compliance framework, and
translate it into what each entity must do locally.
- Set the standard, the minimum controls and the reporting cadence that every
regulated entity works to.
- Design and maintain the compliance and risk structure itself - how the
function is organised across entities, where accountability sits, what
escalates and to whom.
- Advise the CEO and the business on compliance and risk structure decisions:
new products, new markets, new partners, changes to the licensing footprint.
Oversight of MLROs and local compliance
- Provide functional oversight of the MLRO and compliance lead in each regulated
entity.
- Review and challenge their risk assessments, alert handling, SAR/STR
decisions, and regulatory filings before they go out.
- Run a regular oversight cadence - reporting lines, escalation paths, group
compliance committee, and a consolidated view of risk across entities.
- Coach and develop the local compliance leads. Where an entity is
under-resourced or a control is weak, you say so early and fix it.
Regulatory obligations and deadlines - non-negotiable
- Own a complete, live inventory of every regulatory obligation across every
entity and jurisdiction: what is due, to whom, when, and who prepares it.
- Own on-time, accurate delivery of all periodic regulatory reporting and
submissions across the group.
- Own incident, breach and material-change notifications to regulators, filed
within the required window.
- NO MISSED REGULATORY DEADLINES. This is the hard line of the role. You build
the tracking, the buffers and the escalation that make missing one
structurally difficult.
Regulatory relationships
- Be the group's primary point of contact for regulators.
- Handle regulator queries, information requests, thematic reviews and
inspections directly - draft the responses, manage the timeline, close them
out.
- Track regulatory change across all our jurisdictions and translate it into
concrete action before it becomes a compliance gap.
- Prepare the CEO and the board for regulatory engagement, and represent the
company credibly on your own.
Policy
- Own the full compliance policy suite - AML/CFT, sanctions, KYC/KYB and CDD,
transaction monitoring, merchant acceptance and prohibited activity,
complaints, outsourcing, safeguarding-adjacent controls.
- Keep policies current against regulatory change, and make sure changes
actually land in operational procedure and system configuration, not just in
the document.
- Run the annual review and approval cycle, with a clear audit trail of what
changed, why and when.
Audit and assurance
- Own the independent AML/CFT audit and any other compliance audits or external
reviews - scope, timeline, evidence, and the auditor relationship.
- Manage external auditors, consultants and assurance providers across entities.
- Own remediation of audit and regulator findings end to end. Findings get
closed with evidence, on the committed date.
- Maintain the control testing and evidence trail that makes the framework
defensible under examination.
Guidance to the business
- Be the person the CEO, Sales, Risk and Product come to before they do
something, not after.
- Give clear, commercially aware answers - what we can do, what we can't, and
what conditions make a "no" into a "yes".
WHAT WE'RE LOOKING FOR
Required
- Prior experience as Head of Compliance, MLRO, or Compliance Officer of record
at a regulated payments, e-money or financial institution. This is not a first
accountable-person role.
- Deep working knowledge of AML/CFT and payments regulation, with real depth in
at least one major regime and demonstrated ability to get up to speed on
others.
- Track record of owning a regulatory reporting calendar across multiple
obligations without misses.
- Direct experience handling regulator engagement - queries, inspections,
thematic reviews - as the named contact.
- Experience managing external auditors and closing out audit and regulator
findings.
- Experience overseeing or managing compliance staff, ideally across more than
one entity or jurisdiction.
- Has personally written and defended compliance policy, not just inherited it.
- Hands-on and detailed. You read the alerts, the filings and the audit evidence
yourself.
- Based in Singapore with existing right to work.
Strongly preferred
- Experience across more than one of: MAS (Payment Services Act), BNM, BSP,
AUSTRAC, HKMA/CSP, US state MTL or FinCEN MSB.
- Experience in a group structure where local entities operate under different
licences or through acquirer/partner arrangements.
- Fitness-and-propriety approval history with a regulator, or clear ability to
obtain it.
- ICA, CAMS, or equivalent professional certification.
- Merchant-acquiring or marketplace payments background - merchant onboarding
risk, prohibited MCCs, transaction monitoring at merchant level.
- Comfortable with data. You can interrogate monitoring output and merchant
portfolios yourself rather than waiting for a report.
How you work
- Deadlines are absolute. You build in buffer and escalate early rather than
explaining a miss afterwards.
- You bring a position, not just a risk. "No" comes with a route to "yes"
wherever one legitimately exists.
- You are direct with the CEO and with regulators, and you don't soften a real
problem.
- You are comfortable building the function while running it.
WHY THIS ROLE
You'll own group compliance for a licensed payments business operating across
multiple regulated markets, reporting directly to the CEO with a seat in the
decisions that shape the licensing footprint and product roadmap. The scope -
multiple regimes, multiple entities, direct regulator ownership - is broader
than an equivalent title at a single-market institution.
Interview Process
ROLE CONTEXT
We are a regulated payments company operating multiple licensed entities across
several markets. This Compliance Director role reports to the CEO and owns group
compliance: the group-wide AML/CFT and regulatory framework, functional
oversight of the MLROs and compliance leads in each regulated entity, every
regulatory submission and deadline across all jurisdictions, direct handling of
regulator conversations and inspections, the full compliance policy suite,
management of external and AML audits, and guidance to the business on
compliance and risk structure. Missing a regulatory deadline is the single worst
failure mode of this role.
HARD REQUIREMENTS - score low if any are missing
1. Has already held an accountable compliance position at a REGULATED payments,
e-money, remittance, banking or financial institution - Head of Compliance,
Chief Compliance Officer, MLRO, Money Laundering Reporting Officer, Nominated
Officer, or named Compliance Officer of record. This must be a role they have
already held; this is not a step-up-into-first-accountable-role hire.
2. Prior experience in payments or financial services specifically. Compliance
experience from an unregulated industry does not qualify.
3. Direct, personal experience dealing with a financial regulator - responding
to queries, information requests, thematic reviews, inspections or
examinations as the named or primary contact.
4. Ownership of periodic regulatory reporting and filing calendars, with
evidence of consistent on-time submission.
5. Experience managing external auditors, independent AML audits, or regulatory
examinations, and closing out the resulting findings.
6. Has written, updated and defended compliance policies themselves.
7. Currently based in Singapore, or clearly relocating, with existing right to
work in Singapore. This role cannot be done remotely.
STRONG POSITIVE SIGNALS - rank these candidates highest
- Has been Head of Compliance or MLRO at a payments institution, EMI, major
payment institution, digital bank, remittance business or acquirer -
especially one with merchant-facing volume rather than only consumer.
- Group or regional scope: has overseen, supervised or set standards for
compliance officers or MLROs in more than one legal entity or country, even
where the reporting line was functional rather than solid.
- Multi-regime exposure. MAS Payment Services Act is the most relevant; also
valuable are BNM (Malaysia), BSP (Philippines), AUSTRAC (Australia), HKMA or
Hong Kong MSO/SVF, US state money transmitter licensing or FinCEN MSB, FCA or
EU EMI regimes.
- Has held or been approved for a regulator-notified or fit-and-proper approved
role.
- Merchant acquiring or marketplace context: merchant onboarding and KYB,
prohibited and high-risk MCC policy, merchant-level transaction monitoring,
sanctions screening, STR/SAR filing.
- Has built or materially rebuilt a compliance framework - risk assessment
methodology, policy suite, monitoring rules, governance committee structure -
rather than only operating an inherited one.
- Evidence of successful licence applications, licence variations, or market
entry from the compliance side.
- Comfortable with data and systems - can interrogate transaction monitoring
output, alert quality, and merchant portfolios directly.
- ICA Diploma, CAMS/ACAMS, or an equivalent professional compliance
certification.
- Has worked in a smaller or scaling company where they were hands-on, not only
in a large institution with a deep support function beneath them.
NEGATIVE SIGNALS - score down
- Never held an accountable compliance role - only compliance analyst, AML
analyst, KYC operations, or compliance manager reporting into a Head of
Compliance, with no ownership of the regulatory relationship.
- Compliance experience only in unregulated sectors, or corporate/legal
compliance (ethics, SOX, data privacy, ESG) with no financial regulatory
content.
- Purely operational AML background - alert clearing, case queues, onboarding
reviews - without framework, policy or regulator ownership.
- No evidence of direct regulator interaction. Someone who only prepared
material for others to submit is not a fit.
- Purely legal profile (lawyer or in-house counsel) without operational
compliance ownership.
- Wants a supervisory, strategic-only role and would not personally draft a
policy, review a filing or handle a regulator response.
- Pattern of very short tenures (under about 12 months) in recent accountable
roles without a clear explanation, given how long regulatory credibility takes
to build.
- Requires full remote or is not able to work in Singapore.
HOW TO SCORE
The single most important filter is whether the candidate has ALREADY BEEN the
accountable compliance person at a regulated payments or financial institution.
Weight that above title seniority or company size. A Head of Compliance from a
mid-sized payments company with direct MAS or equivalent regulator ownership is
a stronger fit than a senior compliance manager from a global bank who never
owned the regulatory relationship.
Prioritise, in order: (1) prior Head of Compliance / MLRO / Compliance Officer
of record at a regulated payments firm, (2) direct regulator engagement
ownership, (3) multi-entity or multi-jurisdiction oversight of other compliance
officers or MLROs, (4) proven on-time regulatory reporting discipline, (5) audit
management and findings remediation, (6) policy authorship and framework design,
(7) merchant acquiring or marketplace payments context.
Do not infer or use any protected characteristic. Assess only demonstrated
experience, qualifications, certifications, skills and work authorisation.
Optimize Your Resume for This Job
Get a match score and see exactly which keywords you're missing
Job Details
- Category
- Legal & Compliance
- Employment Type
- Full Time
- Location
- SG, Singapore
- Posted
- Compensation
- $10,000 - $15,000 per month
About HitPay
Payments infrastructure for businesses scaling in APAC
More Roles at HitPay





Similar Legal & Compliance Roles



Found this role interesting?