About the Role
We are seeking an experienced VP Compliance to lead compliance, governance, privacy and technology risk across our AI platform and intellectual property portfolio.
The role will ensure the IP owner entity provides legal defensibility and economic substance, acting as the central point for product governance, security, privacy, compliance, IP protection and commercialisation.
Working closely with Legal, Product, Engineering, Security, Tax and Finance, you will establish robust governance frameworks that protect client data and intellectual property while supporting commercial growth.
Key Responsibilities
AI Platform Governance
-
Define the operating framework for multi-agent AI systems, including agent classifications, permissions, tools, escalation rules and human-in-the-loop controls.
-
Establish policy-driven orchestration based on data type, client restrictions, geography and purpose.
-
Implement segregation of duties across AI agents, including drafting, approval, analysis, decision-making, retrieval and export.
-
Govern agent access to data, models and external tools.
Data Privacy & Governance
-
Own the privacy architecture for the AI platform, including data classification, minimisation, purpose limitation, retention and deletion controls.
-
Ensure compliance with relevant regulations, including UK GDPR, EU GDPR, India DPDP and applicable US state privacy laws.
-
Establish appropriate controls for cross-border data processing, model selection and data handling.
-
Oversee DPIAs and privacy assessments for new products and use cases.
Compliance & Assurance
-
Translate legal, regulatory and contractual requirements into practical, auditable technical controls.
-
Establish compliance testing, control validation and periodic assurance programmes.
-
Lead red-team exercises and adversarial AI/prompt testing.
-
Maintain a central evidence library supporting client audits, SOC 2, ISO 27001, regulatory enquiries and investor diligence.
Risk & Incident Management
-
Develop and maintain an AI-specific incident response framework.
-
Establish controls and response procedures for data leakage, unauthorised tool calls, AI-related client harm and cross-jurisdictional data misrouting.
-
Work with the CISO and Security teams on monitoring, logging, anomaly detection and kill-switch mechanisms.
-
Lead significant compliance and AI-related incidents through to resolution.
IP Protection & Contractual Governance
-
Partner with Legal on DPAs, SCCs, audit rights, subcontractor agreements and IP provisions.
-
Establish appropriate restrictions around the use of client data for model training and secondary purposes.
-
Develop platform usage policies for internal teams and subcontractors.
-
Ensure outsourced development and third-party arrangements protect the IP owner entity.
Commercialisation & Client Support
-
Develop client-facing governance and trust materials, including AI governance statements, model/tool inventories, data handling frameworks, audit trail examples, RACI models and DPIA summaries.
-
Support Sales and Delivery with security questionnaires, RFPs and client due diligence.
-
Provide clear and commercially practical responses to client AI, privacy, security and compliance requirements.
DEMPE, Transfer Pricing & Economic Substance
-
Maintain evidence demonstrating the IP owner entity's control over Development, Enhancement, Maintenance, Protection and Exploitation (DEMPE) activities.
-
Document roadmap decisions, product approvals, release sign-offs, budget ownership, vendor contracting, risk decisions and incident leadership.
-
Evidence appropriate oversight of outsourced development and enhancement work.
-
Partner with Tax and Finance on intercompany licensing, cost contribution/recharge frameworks and transfer pricing documentation.
Required Skills & Experience
-
10+ years' experience across data privacy, compliance, security governance, technology risk or related disciplines.
-
Experience within B2B technology, SaaS, professional services or complex technology environments.
-
Strong understanding of privacy by design, DPIAs, data retention, minimisation and cross-border transfers.
-
Experience developing governance frameworks for AI, automated decision-making or ML systems.
-
Ability to translate legal and regulatory requirements into practical technical controls.
-
Strong understanding of technology risk, compliance assurance and information governance.
-
Excellent executive communication skills with experience producing board- and client-ready materials.
Preferred Experience
-
Microsoft security and compliance technologies, including Purview, DLP and identity management.
-
SOC 2 and ISO 27001 frameworks and audit evidence.
-
Transfer pricing, DEMPE and economic substance relating to IP.
-
AI/LLM governance, AI assurance or multi-agent systems.
-
Experience in regulated environments such as financial services, healthcare or publicly listed organisations.
Similar Jobs
Senior Data Engineer
- Employment Type: Contract
- Location: EU Remote
Data Engineer
- Employment Type: Permanent
- Location: Romania/Remote
Azure Integration Architect
- Employment Type: Permanent
- Location: Stockholm