At a Glance
- Tasks: Lead compliance operations in a fast-growing AI company, ensuring data protection and regulatory adherence.
- Company: Join CourtCorrect, a market leader in AI software for complaints resolution.
- Benefits: Enjoy hybrid working, direct mentorship, and participation in an EMI share option scheme.
- Other info: Opportunity for career growth and influence in shaping compliance functions.
- Why this job: Make a real impact on compliance in the exciting intersection of AI and data protection.
- Qualifications: 3+ years in data protection or compliance roles, with hands-on experience in SaaS environments.
The predicted salary is between 80000 - 100000 € per year.
About CourtCorrect
CourtCorrect is the market-leading AI software for complaints resolution in regulated industries. We support businesses across the UK to identify, respond to and learn from complaints. Founded at the University of Cambridge, we are a team of engineers, designers, scientists and commercial operators. Following a £2m+ Seed round, we are scaling rapidly across financial services and other regulated sectors.
We are hiring a Compliance Manager to join our Legal & Compliance function, reporting directly to the Head of Legal & Compliance. This is a specialist compliance role with deep ownership of CourtCorrect's data protection, information security and AI compliance operations — supporting a fast-growing AI company through complex enterprise client engagements and an evolving regulatory landscape.
You will take meaningful ownership from day one of compliance frameworks, GDPR operations, third-party risk, due diligence responses, NDA review, contract operations and continuous compliance tooling — with scope to grow into independent ownership of CourtCorrect's compliance function.
GDPR & Data Protection Operations- Owning day-to-day GDPR compliance: records of processing (ROPAs), DPIAs, legitimate interest assessments, transfer risk assessments (TRAs), and data subject rights handling
- Maintaining the data protection register and ensuring all processing activities are accurately documented under UK GDPR and EU GDPR
- Supporting the DPO on regulatory matters, breach assessments and ICO correspondence
- Operationalising international data transfer mechanisms (SCCs, IDTA, TRAs)
- Conducting and documenting sub-processor risk assessments (including AI/LLM vendors such as OpenAI), maintaining the sub-processor register, and supporting customer notification obligations under DPAs
- Running vendor risk assessments across data protection, information security and AI risk dimensions
- Maintaining the third-party risk register and ensuring periodic re-assessment of critical vendors
- Operating CourtCorrect's continuous compliance platform (Vanta), including evidence uploads, control monitoring, and remediation tracking for ISO 27001 and related frameworks
- Coordinating with the Information Security Team Lead on control implementation, audit preparation, and surveillance reviews
- Maintaining the ISMS documentation suite, risk register and policy register
- Leading end-to-end responses to client and vendor due diligence, including data protection, information security, AI risk and financial services regulatory questionnaires
- Producing high-quality, commercially aware responses that present CourtCorrect's controls clearly and accurately, with appropriate supporting evidence and consistent positioning across questionnaires
- Escalating complex matters with clear analysis
- Building and maintaining a reusable DD response library to improve efficiency and consistency over time
- Flagging contractual compliance obligations (audit rights, sub-processor notifications, security commitments) to the Head of Legal & Compliance for action
- Escalating substantive contract matters (MSAs, DPAs, complex amendments) to the Head of Legal & Compliance with a clear summary of the key points
- Operationalising and maintaining internal compliance policies across UK and EU GDPR, AI governance, information security, anti-bribery and ethics
- Running regular internal compliance checks, policy attestations and evidence collection across the business
- Escalating issues to the Head of Legal & Compliance with clear analysis and proposed actions
- Maintaining CourtCorrect's AI governance documentation, including model risk records, EU AI Act classification evidence and human-in-the-loop control documentation
- Tracking AI regulatory developments (EU AI Act, ICO AI guidance, sector-specific AI rules) and preparing concise summaries with recommendations
- Owning CourtCorrect's legal and compliance document infrastructure: structuring, organising and maintaining contract repositories, compliance evidence libraries and policy registers
- Managing day-to-day document operations: filing executed contracts, NDAs and compliance records in the appropriate repositories; Maintaining GDPR records, DPIAs, risk logs, policy attestations, audit trails and evidence repositories to audit-ready standard
- Operating retention schedules and conducting periodic clean-up of legal and compliance records
- Ensuring file naming, version control and access permissions remain consistent and well-governed as the business scales
3+ years of dedicated experience in data protection, privacy or compliance roles at SaaS, technology or regulated businesses
- Hands-on experience reviewing and negotiating NDAs against a playbook, with sound commercial judgment on routine variations
- Demonstrable experience leading client due diligence responses end-to-end, including information security and AI risk questionnaires
- Hands-on experience with continuous compliance platforms (Vanta, Drata, Secureframe or equivalent) and ISO 27001 evidence management
- Experience with financial services client environments (FCA-regulated firms as customers or counterparties)
- Experience supporting SOC 2 audits or other compliance frameworks beyond ISO 27001
- Experience reviewing DPAs and other privacy-related contractual annexes against compliance checklists
Direct mentorship from the Head of Legal & Compliance, with a clear path to independent ownership of CourtCorrect's compliance function
Deep, specialist work at the intersection of AI, data protection and information security — at one of the UK's leading AI legal-tech companies
Real influence on how a scaling AI company builds its compliance function
EMI share option scheme participation
Hybrid working and a collaborative team
Director, Regulatory Affairs & Quality in City of London employer: CourtCorrect
CourtCorrect is an exceptional employer, offering a dynamic work environment at the forefront of AI technology in the UK. With a strong focus on employee growth, you will receive direct mentorship from the Head of Legal & Compliance and have the opportunity to take meaningful ownership of compliance functions, all while enjoying the benefits of hybrid working and participation in an EMI share option scheme. Join a collaborative team that values innovation and provides a unique chance to influence the compliance landscape in a rapidly scaling company.
StudySmarter Expert Advice🤫
We think this is how you could land Director, Regulatory Affairs & Quality in City of London
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the industry. Attend events, join online forums, and don’t be shy about reaching out on LinkedIn. You never know who might have the inside scoop on job openings!
✨Tip Number 2
Prepare for interviews by researching the company and its culture. Understand their products and services, especially how they relate to compliance and data protection. This will help you tailor your answers and show that you're genuinely interested in CourtCorrect.
✨Tip Number 3
Practice makes perfect! Do mock interviews with friends or use online resources to get comfortable with common questions. Focus on articulating your experience in GDPR compliance and risk management clearly and confidently.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, it shows you’re serious about joining the team at CourtCorrect and ready to dive into the exciting world of AI compliance.
We think you need these skills to ace Director, Regulatory Affairs & Quality in City of London
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter for the Compliance Manager role. Highlight your experience in GDPR compliance and data protection, as well as any relevant projects you've worked on that align with our needs at CourtCorrect.
Showcase Your Experience:We want to see your hands-on experience! Be specific about your previous roles in compliance, especially around due diligence responses and vendor risk assessments. Use examples that demonstrate your ability to manage complex compliance frameworks.
Be Clear and Concise:When writing your application, keep it straightforward. Use clear language and avoid jargon where possible. We appreciate a well-structured response that gets straight to the point, especially when discussing your achievements and skills.
Apply Through Our Website:Don’t forget to submit your application through our website! It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it shows you’re keen to join our team at CourtCorrect!
How to prepare for a job interview at CourtCorrect
✨Know Your GDPR Inside Out
Make sure you brush up on your knowledge of GDPR and data protection regulations. Be prepared to discuss how you've handled compliance in previous roles, especially in relation to records of processing and data subject rights. This will show that you’re not just familiar with the theory but have practical experience.
✨Showcase Your Risk Assessment Skills
Be ready to talk about your experience with third-party risk assessments and how you’ve managed vendor relationships. Bring examples of how you’ve documented and maintained risk registers, as this is crucial for the role. Highlight any specific tools or platforms you've used, like Vanta, to demonstrate your hands-on experience.
✨Prepare for Due Diligence Questions
Since you'll be leading end-to-end responses to client and vendor due diligence, think of examples where you’ve successfully navigated complex questionnaires. Practice articulating how you produced high-quality responses and built reusable libraries for efficiency. This will show your strategic thinking and attention to detail.
✨Understand the AI Compliance Landscape
Given the focus on AI compliance, make sure you’re up to speed with current regulations like the EU AI Act. Be prepared to discuss how you would track regulatory developments and implement necessary changes. Showing that you can keep pace with evolving regulations will set you apart as a candidate who’s proactive and forward-thinking.