We’re Hiring: Head of Compliance
2 days ago
Newcastle upon Tyne
Noggin HQ (Noggin) is a 6-person start-up based in the Newcastle upon Tyne. Having recently secured our Credit Referencing and AISP permissions, as well as a new round of institutional funding, we are looking for an exceptional Head of Compliance to support our next phase of growth. Our core products are built using Open Banking data, e.g., transaction categorisation, income verification models and credit risk scores, which exist to serve our core mission: making access to credit equitable. We are early stage with big, exciting challenges to tackle as a team. We are a half in-person / half remote team with offices in Ouseburn (Newcastle upon Tyne). Our working environment suits people who are proactive, are comfortable working with processes that are in their infancy & need evolution, own their area(s) of responsibility and can push things forward, make their work visible, and have a clear passion for what they do. For this role, flexible working arrangements can be agreed up-front. As the only compliance hire at Noggin, you will be responsible for our entire compliance function, taking over from our COO. You will also act as our designated Data Protection Officer. In this pivotal role, you will ensure Noggin meets its obligations across multiple FCA permissions, including Account Information Services (AISP), Credit Referencing, Credit Information Services, and Credit Broking, while helping us progress toward full Credit Reference Agency certification and supporting our ISO 27001 (ISMS) accreditation. In particular, you will: • Act as Noggin's named Data Protection Officer, overseeing compliance with UK GDPR across the business., • Lead on DPIAs for novel processing, including Article 22 considerations for our automated credit scoring products, and handle data subject rights requests in a financial data context., • Own our regulatory obligations as an Account Information Service Provider (AISP), ensuring our data use stays within FCA and Open Banking conduct requirements., • Maintain compliance across our Credit Referencing, Credit Information Services, and Credit Broking permissions, meeting the reporting and conduct obligations attached to each., • Build our understanding of the credit-data reciprocity ecosystem (SCOR/CRAIN) as we grow toward becoming an Open Banking credit bureau., • Support compliance management of our ISMS (ISO 27001) programme during a planned handover, through regulatory and certification body audits., • Shape our data governance strategy through a GDPR lens, applying privacy by design and a commercial view of lawful data use to both current activity and future ambitions., • Own our partner and third-party due diligence, including checks on lender partners ahead of pilot 'Retros'., • Reduce the burden on the wider team of completing inbound due diligence questionnaires (DDQs) from lenders., • Mature our existing policy and procedure suite, and design and deliver a compliance training regime that meets regulatory and GDPR standards., • Take ownership of our Compliance Monitoring Programme (CMP)., • Manage our relationship with the FCA, including preparing accurate monthly updates under our current Oversight regime., • Help build the evidence base needed to progress toward full Credit Reference Agency certification, and own ICO registration and renewal., • Act as a proactive regulatory adviser as we develop product-market fit, shaping what's feasible early in product development rather than reviewing decisions after the fact., • Deliver a compliance update to the Board every two months., • Support a monthly Risk Committee cycle, including preparing and circulating agendas and papers in advance, and circulating minutes afterward., • Has held a formally designated DPO role, or clear functional equivalent, and can speak concretely to Article 22 automated decisioning and DPIAs on novel processing, ideally in financial services., • Solid working knowledge of AISP and the Payment Services Regulations 2017., • Solid working knowledge of Credit Reference Agency regulation (Consumer Credit Act 1974, CONC), Credit Broking conduct rules, and the credit-data reciprocity ecosystem (SCOR/CRAIN)., • Has directly contributed to an ISO 27001 (or equivalent ISMS) certification project, or has a strong working understanding of what one entails., • Experience directing strategy around data storage and collection for use in product development, with a genuinely commercial understanding of lawful data use., • Experience designing and running a risk-based due diligence framework, ideally including managing inbound partner due diligence questionnaires efficiently., • Experience personally owning a Compliance Monitoring Programme and designing and delivering compliance training., • Experience personally preparing and submitting FCA and ICO regulatory returns, including operating under an active FCA Oversight or Requirement regime., • A track record of giving proactive regulatory input early in product development, and shaping decisions through direct working relationships rather than formal process., • Experience delivering board-level compliance reporting and supporting a risk or compliance committee cycle, including agendas, papers, and minutes. #J-18808-Ljbffr