Vice President- Legal, Risk & Compliance
CIMET · Jaipur, Rajasthan, India
Apply & track with Apply EdgeKey accountabilitiesCommercial and transactional legalOwn CIMETs commercial contracting end to end: retailer and provider channel and distribution agreements, referral, white-label, co-brand, marketing and lead-supply agreements, technology and SaaS terms, data-sharing and processing arrangements, procurement and vendor terms.Negotiate directly with the legal and commercial teams of large Australian counterparties on service definitions, approved channels, audit and inspection rights, subcontracting and sub-affiliate approval requirements, data protection, liability and indemnity, suspension and termination.Build and maintain the contract playbook, template suite, negotiation parameters, delegated authority and approval matrix, contract register and renewal calendar driving cycle time down without lowering the floor on risk terms.Manage disputes, notices, demands and contentious matters, including instruction, scoping and cost management of Australian and Indian external counsel.Support corporate activity capital raising, mergers and acquisitions, joint ventures, new entities and new vertical launches including diligence readiness, disclosure and warranty work, and post-transaction integration of legal and compliance obligations.Advise on intellectual property and brand, marketing and advertising claims, corporate governance and entity housekeeping; partner with People & Culture on employment and workplace matters.Australian regulatory and product complianceLicense and authorization support: own the obligations, controls and evidence that sit beneath CIMETs Australian authorizations, including Australian Credit License obligations under the National Consumer Credit Protection Act organizational competence and responsible manager arrangements, credit representative and referral arrangements, general conduct obligations, annual compliance certification and the reportable situations (breach reporting) regime.Australian Consumer Law: own compliance across misleading or deceptive conduct, unsolicited consumer agreements, unfair contract terms, unconscionable conduct and consumer guarantees as they apply to comparison, lead generation, tele-sales and partner-assisted sales activity.Energy: National Energy Retail Law, Rules and Code, AER guidelines and pricing information requirements, the Victorian Energy Retail Code of Practice and other jurisdictional requirements; retailer compliance regimes covering approved channels, scripts, disclosures and consent.Consumer credit: credit assistance and responsible lending obligations, design and distribution obligations, ASIC regulatory guidance, and disclosure and comparison standards for credit products.Broadband: Telecommunications Consumer Protections Code, ACMA requirements, and Telecommunications Industry Ombudsman processes.Private health insurance: Private Health Insurance Act and Code of Conduct obligations, fund distribution arrangements, and the basis on which CIMETs activities sit within or outside the financial services licensing regime.Cross-cutting: the Australian Privacy Act and Australian Privacy Principles, notifiable data breaches, cross-border disclosure of personal information, the Spam Act, the Do Not Call Register Act, and the consent-capture and record-retention standards that evidence compliance with all of the above.Regulatory change: own horizon scanning, impact assessment, implementation planning and evidenced closure of regulatory and code change across all verticals.Compliance framework and operationsOwn the compliance management framework: an obligations register and control library mapped to law, license, industry code and contract, with named control owners, testing frequency and defined evidence standards.Own the three lines of defence model and the decision authorities within it including second-line authority to condition, pause or reject activity, approve time-bound exceptions, and determine external notifications.Own gate controls: no partner, campaign, brand, website journey, script, sales process or material system change goes live without the required approvals evidenced.Own monitoring and assurance: pre-submission sales quality assurance, call and consent audits, website and digital journey audits, system control testing, and risk-based thematic reviews.Own complaints governance: identification, logging, investigation, remediation of customer outcomes, root cause analysis, systemic issue detection, and the handling of vulnerable customer and family and domestic violence matters through safe, restricted and documented processes.Own incident and breach management: containment, investigation, notification assessment (regulator, retailer or provider, Ombudsman, affected customers), corrective and preventive action, and effectiveness testing.Own training, competency and attestation: onboarding and refresher training, competency records, code of conduct, and periodic attestations from staff, agents and partners.Lead the transition of Compliance from Operations into Legal and the product-wise allocation of the compliance team, without any loss of coverage during the change.Risk management and risk reportingDesign, implement and embed CIMETs enterprise risk management framework: risk taxonomy, risk appetite statement and tolerances, risk and control self-assessment, key risk indicators, and a live risk register with named owners and treatment plans.Maintain and report the enterprise risk profile across compliance, conduct, privacy, information security, third-party and outsourcing, fraud, operational, financial-crime and regulatory risk and challenge residual risk acceptance at the correct authority.Own the exception and waiver regime time-bound, with compensating control, owner and expiry and ensure expired, failed or bypassed exceptions are treated as incidents.Partner with Information Security and Technology on the information security management system, ISO 27001 alignment, security incident response and partner security assessments.Work with the CFO on insurance strategy, placement and renewals (professional indemnity, cyber, directors and officers, public liability) and manage claim notifications.Own business continuity, crisis management and the escalation, communications and media protocol for regulatory, conduct or security events.Board, committee and executive reportingPrepare and present the Legal, Risk and Compliance report to the Board and to the product compliance and management risk committees, covering risk profile movement, appetite breaches, incidents and breaches, complaints and conduct trends, partner and third-party risk, remediation status, licence and regulatory obligations, litigation and material contracts.Establish and run the committee architecture: charters, membership, cadence, papers, minutes, action tracking, and documented residual-risk decisions.Give the CFO, the Executive and the Board early, unvarnished escalation of material matters. No surprises.Keep the function permanently ready for external scrutiny retailer and provider audits, regulator or Ombudsman enquiries, investor and acquirer due diligence, and independent or internal assurance reviews.Partner, channel and third-party riskOwn the partner onboarding gate end to end: business due diligence, security and privacy assessment, compliance risk assessment, legal and contractual review, operational readiness, and the go-live decision.Maintain a complete, current and accurate register of partners, sub-affiliates, subcontractors and trading brands, and ensure every required counterparty approval or consent is obtained and evidenced before activity commences.Own ongoing oversight: attestations, risk-based audits and site inspections, quality assurance and consent testing, corrective action plans tracked to verified closure, and suspension or termination where risk is not controlled.Set and enforce the rules of engagement for partner and agent sales conduct approved channels and brands, scripts, mandatory disclosures, consent capture, contact preferences and record retention.Be the escalation point for partner conduct issues, and lead the notification, remediation and relationship conversations with affected retailers and providers.Group entity oversight Australia, India and the PhilippinesMaintain a consolidated group entity register and statutory compliance calendar covering every jurisdiction filings, registrations, licenses, resolutions, registered offices, directorships and secretarial obligations with visible status and no reliance on any single providers memory.Australia: work with Australian external counsel and the corporate secretary on Corporations Act obligations, board and shareholder resolutions, ASIC filings, director appointments and entity housekeeping for CIMET Sales Pty Ltd and related entities.Philippines: work with Philippine external counsel and corporate secretarial providers on SEC and regulatory filings, entity registrations and incentives arrangements where applicable, local statutory obligations and the Data Privacy Act.India: own the statutory and corporate compliance calendar under the Companies Act 2013 directly, working with the company secretary, statutory auditors and Finance; and own obligations under the Digital Personal Data Protection Act 2023.Own intra-group arrangements across all three jurisdictions services agreements, data processing and cross-border transfer arrangements, intellectual property and licensing arrangements between entities, and the legal documentation supporting transfer pricing positions, in conjunction with Finance.Ensure Australian customer personal information is handled consistently with Australian Privacy Principle requirements for cross-border disclosure wherever in the group it is processed.Manage litigation, notices and regulatory correspondence in each jurisdiction, and the external counsel handling it.