Skip to main content
Shufti logo

Head of Legal, Compliance & Privacy

Shufti
1 hour ago
Full-time
On-site
United Kingdom
Manager

To lead Shufti’s Legal, Compliance & Privacy department for a global identity-verification and AML business (KYC, KYB, AML screening). The role owns commercial and corporate legal, compliance and regulatory affairs, and data protection, holds Shufti demonstrably compliant with its own obligations while providing assurance over the screening product Shufti sells, keeps the business audit-ready at all times, and builds the function and the team to do so.

The role is expected to design and run the function end-to-end: set the operating model, stand up the registers and controls, represent the function to the executive, customers and regulators, and grow and lead a multi-disciplinary team across the three pillars.

2.  Scope — three pillars

Pillar

Coverage

Commercial & Corporate Legal

MSAs, DPAs, NDAs, contract governance, signing authority, renewals; corporate governance & company-secretarial; employment & ER; disputes; US gaming licences; product-related legal.

Compliance & Regulatory Affairs

Obligations & controls registers, control design & testing, audit readiness & remediation, regulatory change, training; AML / screening (sanctions, PEP, CDD/EDD); product compliance; certification portfolio incl. UK DVS/DIATF; enterprise DDQ / RFI / RFP & security questionnaires.

Privacy & Data Protection

ROPA, DPIA, DSAR, ICO engagement, international transfers (SCC / IDTA), vendor DPAs, privacy-by-design.

Legal Operations (cross-cutting)

Intake, registers/repositories and the KPI dashboard across all three pillars.

Incident & breach response is owned by the Security department and is outside this role’s remit.

3.  Key responsibilities

Leadership & function-building

  • Own the department’s operating model, structure and ways of working; build and lead the team across all three pillars.

  • Represent Legal, Compliance & Privacy to the executive and Board, and to customers, partners, auditors and regulators.

  • Set the governance cadence (weekly RAG, monthly memo, quarterly QBR) and report on function performance.

  • Recruit and develop the team to a consistent bar (ghSMART A-Method); set scorecards, manage performance and succession.

Commercial & corporate legal

  • Own the contract lifecycle — repository, turnaround SLAs, signing-authority matrix, renewals and self-serve playbooks (NDA, customer, vendor, DPA).

  • Run corporate governance and company-secretarial matters; support fundraising, M&A and other strategic transactions with clean documentation and external-counsel coordination.

  • Oversee employment/ER matters and manage disputes and the US gaming-licence portfolio.

Compliance & regulatory affairs

  • Build and maintain the obligations register, controls inventory and testing schedule, and the audit-readiness evidence pack.

  • Own AML / screening controls (sanctions, PEP, adverse-media, CDD/EDD) covering both Shufti’s own obligations and assurance over the screening product.

  • Track regulatory change and emerging regimes (DORA, NIS2, EU AI Act); drive the certification portfolio, including UK DVS/DIATF, and enterprise DDQ / security-questionnaire responses.

Privacy & data protection

  • Oversee the privacy programme — ROPA, DPIA, DSAR, international transfers (SCC/IDTA), vendor DPAs and privacy-by-design — and manage ICO engagement and remediation.

4.  How the role is measured

Performance is measured against the department KPI framework, once each underlying register or system is live (development goal until then):

  • Legal — contract turnaround, review quality/rework, renewal capture, contract governance & control, legal risk/disputes/cost.

  • Compliance — sanctions & anti-bribery, screening-service integrity, audit readiness & records, controls effectiveness, obligations & regulatory change, training, DDQ/query timeliness.

  • Privacy — regulator remediation, DSAR timeliness, records maturity (ROPA/DPIA), data lifecycle & vendor compliance, privacy incidents/risk/training.

5.  Person specification

Essential

  • Qualified lawyer with substantial in-house experience leading legal and/or compliance in a regulated, multi-jurisdiction environment.

  • Strong commercial and corporate contracting, and corporate governance / company-secretarial capability.

  • Genuine cross-border experience and the ability to coordinate external counsel across jurisdictions.

  • Compliance / AML depth — obligations and controls, audit readiness, and screening (sanctions/PEP/CDD-EDD).

  • Data-protection literacy (GDPR/ICO) and the judgement to partner privacy effectively.

  • Evidence of building or materially improving a function, and of leading and developing a team.

  • Clear, pragmatic stakeholder management — an enabler to the business, not a blocker.

Desirable

  • RegTech / fintech / identity-verification domain exposure.

  • Fundraising and/or M&A transaction leadership.

  • Experience with certifications/assurance (e.g. UK DVS/DIATF, ISO/IEC 27001, SOC 2) and AI-regulatory change (EU AI Act).

  • Additional qualification/jurisdiction (e.g. dual-qualified).

6.  What success looks like

Horizon

Indicative outcomes

First 90 days

Function operating model and team structure agreed; core registers designed; contract engine and screening SOPs taking shape; hiring underway; a clear DVS/DIATF plan.

6 months

Registers live and KPIs being RAG-scored; audit-readiness evidence pack maintained; certifications progressing; team on cadence.

12 months

A demonstrably audit-ready, well-run function across all three pillars; commercial legal protecting revenue; compliance and privacy operating to plan; a capable, developing team.

This role description is indicative and may be refined as the department structure is finalised. It is a candidate-neutral job description; no appointment has been made.