Skip to main content

Compliance Director

HitPay
SG, Singapore
Full Time
Compensation
$10,000–$15,000/month

Job Description

ABOUT THE ROLE

We're looking for a Compliance Director to own group compliance across every

regulated entity we operate - setting the framework, holding the regulatory

relationships, and making sure not a single obligation or deadline is missed

anywhere in the group.

You will oversee the MLROs and local compliance leads in each licensed entity,

functionally rather than by title alone: you set the standard they work to, you

review what they produce, and you are accountable to the CEO for the group's

overall compliance posture.

This is a senior role for someone who has already been the accountable person -

a Head of Compliance or MLRO at a regulated payments business - and knows exactly

what a regulator expects to see when they ask.

WHAT YOU'LL OWN

Group compliance framework

- Own the group-wide AML/CFT, sanctions and regulatory compliance framework, and

translate it into what each entity must do locally.

- Set the standard, the minimum controls and the reporting cadence that every

regulated entity works to.

- Design and maintain the compliance and risk structure itself - how the

function is organised across entities, where accountability sits, what

escalates and to whom.

- Advise the CEO and the business on compliance and risk structure decisions:

new products, new markets, new partners, changes to the licensing footprint.

Oversight of MLROs and local compliance

- Provide functional oversight of the MLRO and compliance lead in each regulated

entity.

- Review and challenge their risk assessments, alert handling, SAR/STR

decisions, and regulatory filings before they go out.

- Run a regular oversight cadence - reporting lines, escalation paths, group

compliance committee, and a consolidated view of risk across entities.

- Coach and develop the local compliance leads. Where an entity is

under-resourced or a control is weak, you say so early and fix it.

Regulatory obligations and deadlines - non-negotiable

- Own a complete, live inventory of every regulatory obligation across every

entity and jurisdiction: what is due, to whom, when, and who prepares it.

- Own on-time, accurate delivery of all periodic regulatory reporting and

submissions across the group.

- Own incident, breach and material-change notifications to regulators, filed

within the required window.

- NO MISSED REGULATORY DEADLINES. This is the hard line of the role. You build

the tracking, the buffers and the escalation that make missing one

structurally difficult.

Regulatory relationships

- Be the group's primary point of contact for regulators.

- Handle regulator queries, information requests, thematic reviews and

inspections directly - draft the responses, manage the timeline, close them

out.

- Track regulatory change across all our jurisdictions and translate it into

concrete action before it becomes a compliance gap.

- Prepare the CEO and the board for regulatory engagement, and represent the

company credibly on your own.

Policy

- Own the full compliance policy suite - AML/CFT, sanctions, KYC/KYB and CDD,

transaction monitoring, merchant acceptance and prohibited activity,

complaints, outsourcing, safeguarding-adjacent controls.

- Keep policies current against regulatory change, and make sure changes

actually land in operational procedure and system configuration, not just in

the document.

- Run the annual review and approval cycle, with a clear audit trail of what

changed, why and when.

Audit and assurance

- Own the independent AML/CFT audit and any other compliance audits or external

reviews - scope, timeline, evidence, and the auditor relationship.

- Manage external auditors, consultants and assurance providers across entities.

- Own remediation of audit and regulator findings end to end. Findings get

closed with evidence, on the committed date.

- Maintain the control testing and evidence trail that makes the framework

defensible under examination.

Guidance to the business

- Be the person the CEO, Sales, Risk and Product come to before they do

something, not after.

- Give clear, commercially aware answers - what we can do, what we can't, and

what conditions make a "no" into a "yes".

WHAT WE'RE LOOKING FOR

Required

- Prior experience as Head of Compliance, MLRO, or Compliance Officer of record

at a regulated payments, e-money or financial institution. This is not a first

accountable-person role.

- Deep working knowledge of AML/CFT and payments regulation, with real depth in

at least one major regime and demonstrated ability to get up to speed on

others.

- Track record of owning a regulatory reporting calendar across multiple

obligations without misses.

- Direct experience handling regulator engagement - queries, inspections,

thematic reviews - as the named contact.

- Experience managing external auditors and closing out audit and regulator

findings.

- Experience overseeing or managing compliance staff, ideally across more than

one entity or jurisdiction.

- Has personally written and defended compliance policy, not just inherited it.

- Hands-on and detailed. You read the alerts, the filings and the audit evidence

yourself.

- Based in Singapore with existing right to work.

Strongly preferred

- Experience across more than one of: MAS (Payment Services Act), BNM, BSP,

AUSTRAC, HKMA/CSP, US state MTL or FinCEN MSB.

- Experience in a group structure where local entities operate under different

licences or through acquirer/partner arrangements.

- Fitness-and-propriety approval history with a regulator, or clear ability to

obtain it.

- ICA, CAMS, or equivalent professional certification.

- Merchant-acquiring or marketplace payments background - merchant onboarding

risk, prohibited MCCs, transaction monitoring at merchant level.

- Comfortable with data. You can interrogate monitoring output and merchant

portfolios yourself rather than waiting for a report.

How you work

- Deadlines are absolute. You build in buffer and escalate early rather than

explaining a miss afterwards.

- You bring a position, not just a risk. "No" comes with a route to "yes"

wherever one legitimately exists.

- You are direct with the CEO and with regulators, and you don't soften a real

problem.

- You are comfortable building the function while running it.

WHY THIS ROLE

You'll own group compliance for a licensed payments business operating across

multiple regulated markets, reporting directly to the CEO with a seat in the

decisions that shape the licensing footprint and product roadmap. The scope -

multiple regimes, multiple entities, direct regulator ownership - is broader

than an equivalent title at a single-market institution.


Interview Process

ROLE CONTEXT

We are a regulated payments company operating multiple licensed entities across

several markets. This Compliance Director role reports to the CEO and owns group

compliance: the group-wide AML/CFT and regulatory framework, functional

oversight of the MLROs and compliance leads in each regulated entity, every

regulatory submission and deadline across all jurisdictions, direct handling of

regulator conversations and inspections, the full compliance policy suite,

management of external and AML audits, and guidance to the business on

compliance and risk structure. Missing a regulatory deadline is the single worst

failure mode of this role.

HARD REQUIREMENTS - score low if any are missing

1. Has already held an accountable compliance position at a REGULATED payments,

e-money, remittance, banking or financial institution - Head of Compliance,

Chief Compliance Officer, MLRO, Money Laundering Reporting Officer, Nominated

Officer, or named Compliance Officer of record. This must be a role they have

already held; this is not a step-up-into-first-accountable-role hire.

2. Prior experience in payments or financial services specifically. Compliance

experience from an unregulated industry does not qualify.

3. Direct, personal experience dealing with a financial regulator - responding

to queries, information requests, thematic reviews, inspections or

examinations as the named or primary contact.

4. Ownership of periodic regulatory reporting and filing calendars, with

evidence of consistent on-time submission.

5. Experience managing external auditors, independent AML audits, or regulatory

examinations, and closing out the resulting findings.

6. Has written, updated and defended compliance policies themselves.

7. Currently based in Singapore, or clearly relocating, with existing right to

work in Singapore. This role cannot be done remotely.

STRONG POSITIVE SIGNALS - rank these candidates highest

- Has been Head of Compliance or MLRO at a payments institution, EMI, major

payment institution, digital bank, remittance business or acquirer -

especially one with merchant-facing volume rather than only consumer.

- Group or regional scope: has overseen, supervised or set standards for

compliance officers or MLROs in more than one legal entity or country, even

where the reporting line was functional rather than solid.

- Multi-regime exposure. MAS Payment Services Act is the most relevant; also

valuable are BNM (Malaysia), BSP (Philippines), AUSTRAC (Australia), HKMA or

Hong Kong MSO/SVF, US state money transmitter licensing or FinCEN MSB, FCA or

EU EMI regimes.

- Has held or been approved for a regulator-notified or fit-and-proper approved

role.

- Merchant acquiring or marketplace context: merchant onboarding and KYB,

prohibited and high-risk MCC policy, merchant-level transaction monitoring,

sanctions screening, STR/SAR filing.

- Has built or materially rebuilt a compliance framework - risk assessment

methodology, policy suite, monitoring rules, governance committee structure -

rather than only operating an inherited one.

- Evidence of successful licence applications, licence variations, or market

entry from the compliance side.

- Comfortable with data and systems - can interrogate transaction monitoring

output, alert quality, and merchant portfolios directly.

- ICA Diploma, CAMS/ACAMS, or an equivalent professional compliance

certification.

- Has worked in a smaller or scaling company where they were hands-on, not only

in a large institution with a deep support function beneath them.

NEGATIVE SIGNALS - score down

- Never held an accountable compliance role - only compliance analyst, AML

analyst, KYC operations, or compliance manager reporting into a Head of

Compliance, with no ownership of the regulatory relationship.

- Compliance experience only in unregulated sectors, or corporate/legal

compliance (ethics, SOX, data privacy, ESG) with no financial regulatory

content.

- Purely operational AML background - alert clearing, case queues, onboarding

reviews - without framework, policy or regulator ownership.

- No evidence of direct regulator interaction. Someone who only prepared

material for others to submit is not a fit.

- Purely legal profile (lawyer or in-house counsel) without operational

compliance ownership.

- Wants a supervisory, strategic-only role and would not personally draft a

policy, review a filing or handle a regulator response.

- Pattern of very short tenures (under about 12 months) in recent accountable

roles without a clear explanation, given how long regulatory credibility takes

to build.

- Requires full remote or is not able to work in Singapore.

HOW TO SCORE

The single most important filter is whether the candidate has ALREADY BEEN the

accountable compliance person at a regulated payments or financial institution.

Weight that above title seniority or company size. A Head of Compliance from a

mid-sized payments company with direct MAS or equivalent regulator ownership is

a stronger fit than a senior compliance manager from a global bank who never

owned the regulatory relationship.

Prioritise, in order: (1) prior Head of Compliance / MLRO / Compliance Officer

of record at a regulated payments firm, (2) direct regulator engagement

ownership, (3) multi-entity or multi-jurisdiction oversight of other compliance

officers or MLROs, (4) proven on-time regulatory reporting discipline, (5) audit

management and findings remediation, (6) policy authorship and framework design,

(7) merchant acquiring or marketplace payments context.

Do not infer or use any protected characteristic. Assess only demonstrated

experience, qualifications, certifications, skills and work authorisation.

Optimize Your Resume for This Job

Get a match score and see exactly which keywords you're missing

Optimize Resume

Job Details

Category
Legal & Compliance
Employment Type
Full Time
Location
SG, Singapore
Posted
Compensation
$10,000 - $15,000 per month

About HitPay

Payments infrastructure for businesses scaling in APAC

Found this role interesting?

Compliance Director
HitPay
Apply