At a Glance
- Tasks: Lead compliance operations in a fast-growing AI company, ensuring data protection and information security.
- Company: Join CourtCorrect, a market leader in AI software for complaints resolution.
- Benefits: Enjoy hybrid working, EMI share options, and direct mentorship from industry experts.
- Other info: Opportunity for career growth and influence in a dynamic, collaborative environment.
- Why this job: Make a real impact on compliance in the exciting intersection of AI and data protection.
- Qualifications: 3+ years in compliance roles with strong knowledge of GDPR and experience with continuous compliance platforms.
The predicted salary is between 60000 - 75000 β¬ per year.
About CourtCorrect
CourtCorrect is the market-leading AI software for complaints resolution in regulated industries. We support businesses across the UK to identify, respond to and learn from complaints. Founded at the University of Cambridge, we are a team of engineers, designers, scientists and commercial operators. Following a Β£2m+ Seed round, we are scaling rapidly across financial services and other regulated sectors.
The Role
We are hiring a Compliance Manager to join our Legal & Compliance function, reporting directly to the Head of Legal & Compliance. This is a specialist compliance role with deep ownership of CourtCorrect's data protection, information security and AI compliance operations β supporting a fast-growing AI company through complex enterprise client engagements and an evolving regulatory landscape.
You will take meaningful ownership from day one of compliance frameworks, GDPR operations, third-party risk, due diligence responses, NDA review, contract operations and continuous compliance tooling β with scope to grow into independent ownership of CourtCorrect's compliance function.
What You Will Do
- GDPR & Data Protection Operations
- Owning day-to-day GDPR compliance: records of processing (ROPAs), DPIAs, legitimate interest assessments, transfer risk assessments (TRAs), and data subject rights handling
- Maintaining the data protection register and ensuring all processing activities are accurately documented under UK GDPR and EU GDPR
- Supporting the DPO on regulatory matters, breach assessments and ICO correspondence
- Operationalising international data transfer mechanisms (SCCs, IDTA, TRAs)
- Third-Party & Sub-Processor Risk
- Conducting and documenting sub-processor risk assessments (including AI/LLM vendors such as OpenAI), maintaining the sub-processor register, and supporting customer notification obligations under DPAs
- Running vendor risk assessments across data protection, information security and AI risk dimensions
- Maintaining the third-party risk register and ensuring periodic re-assessment of critical vendors
- Information Security & ISO 27001
- Operating CourtCorrect's continuous compliance platform (Vanta), including evidence uploads, control monitoring, and remediation tracking for ISO 27001 and related frameworks
- Coordinating with the Information Security Team Lead on control implementation, audit preparation, and surveillance reviews
- Maintaining the ISMS documentation suite, risk register and policy register
- Due Diligence & Regulatory Questionnaires
- Leading end-to-end responses to client and vendor due diligence, including data protection, information security, AI risk and financial services regulatory questionnaires
- Producing high-quality, commercially aware responses that present CourtCorrect's controls clearly and accurately, with appropriate supporting evidence and consistent positioning across questionnaires
- Coordinating with Engineering, Security and Product to gather evidence; escalating complex matters with clear analysis
- Building and maintaining a reusable DD response library to improve efficiency and consistency over time
- NDA & Contract Operations
- Reviewing and negotiating NDAs against CourtCorrect's playbook, handling end-to-end from receipt to execution
- Coordinating signature workflows on DocuSign (or equivalent): preparing envelopes, routing for signature, managing signing order, chasing counter-signatures and ensuring fully executed copies are correctly filed
- Supporting contract lifecycle management: tracking obligations, renewals, variations and notice deadlines across the customer and vendor portfolio
- Flagging contractual compliance obligations (audit rights, sub-processor notifications, security commitments) to the Head of Legal & Compliance for action
- Escalating substantive contract matters (MSAs, DPAs, complex amendments) to the Head of Legal & Compliance with a clear summary of the key points
- Compliance Policies & Attestations
- Operationalising and maintaining internal compliance policies across UK and EU GDPR, AI governance, information security, anti-bribery and ethics
- Running regular internal compliance checks, policy attestations and evidence collection across the business
- Escalating issues to the Head of Legal & Compliance with clear analysis and proposed actions
- AI Governance
- Maintaining CourtCorrect's AI governance documentation, including model risk records, EU AI Act classification evidence and human-in-the-loop control documentation
- Tracking AI regulatory developments (EU AI Act, ICO AI guidance, sector-specific AI rules) and preparing concise summaries with recommendations
- Documentation & Information Management
- Owning CourtCorrect's legal and compliance document infrastructure: structuring, organising and maintaining contract repositories, compliance evidence libraries and policy registers
- Managing day-to-day document operations: filing executed contracts, NDAs and compliance records in the appropriate repositories; retrieving documents promptly on request from internal stakeholders or external auditors
- Maintaining GDPR records, DPIAs, risk logs, policy attestations, audit trails and evidence repositories to audit-ready standard
- Operating retention schedules and conducting periodic clean-up of legal and compliance records
- Ensuring file naming, version control and access permissions remain consistent and well-governed as the business scales
What We Are Looking For
Essential
- 3+ years of dedicated experience in data protection, privacy or compliance roles at SaaS, technology or regulated businesses
- Recognised privacy certification: CIPP/E, CIPM, or equivalent
- Deep working knowledge of UK GDPR and EU GDPR, including practical experience drafting DPIAs, ROPAs, TRAs and legitimate interest assessments
- Hands-on experience reviewing and negotiating NDAs against a playbook, with sound commercial judgment on routine variations
- Demonstrable experience leading client due diligence responses end-to-end, including information security and AI risk questionnaires
- Hands-on experience with continuous compliance platforms (Vanta, Drata, Secureframe or equivalent) and ISO 27001 evidence management
- Practical experience with DocuSign and managing contract lifecycle workflows
- Strong document management discipline: file structure, version control, retention, access governance
- Working knowledge of information security frameworks (ISO 27001 in particular) and the ability to engage credibly with technical teams
- Exceptional attention to detail and written communication
- Comfortable managing multiple workstreams independently with sound prioritisation
Desirable
- Additional certifications: ISO 27001 Lead Implementer, CISA, CRISC, or equivalent
- Exposure to the EU AI Act and AI governance frameworks
- Experience with financial services client environments (FCA-regulated firms as customers or counterparties)
- Experience supporting SOC 2 audits or other compliance frameworks beyond ISO 27001
- Experience reviewing DPAs and other privacy-related contractual annexes against compliance checklists
What We Offer
- Direct mentorship from the Head of Legal & Compliance, with a clear path to independent ownership of CourtCorrect's compliance function
- Deep, specialist work at the intersection of AI, data protection and information security β at one of the UK's leading AI legal-tech companies
- Real influence on how a scaling AI company builds its compliance function
- EMI share option scheme participation
- Hybrid working and a collaborative team
Compliance Manager in Slough employer: CourtCorrect
At CourtCorrect, we pride ourselves on being a leading employer in the AI legal-tech sector, offering our Compliance Manager a unique opportunity to shape compliance frameworks in a fast-paced environment. Our collaborative work culture fosters innovation and personal growth, with direct mentorship from experienced leaders and a clear path to independent ownership of compliance functions. Enjoy the benefits of hybrid working, participation in our EMI share option scheme, and the chance to make a real impact in a company that values your expertise and contributions.
StudySmarter Expert Adviceπ€«
We think this is how you could land Compliance Manager in Slough
β¨Tip Number 1
Network like a pro! Get out there and connect with folks in the compliance field. Attend industry events, webinars, or even local meetups. You never know who might have the inside scoop on job openings or can put in a good word for you.
β¨Tip Number 2
Show off your skills! Prepare a portfolio that highlights your experience with GDPR operations, risk assessments, and compliance frameworks. Bring it along to interviews or share it during networking chats to demonstrate your expertise.
β¨Tip Number 3
Practice makes perfect! Mock interviews can help you nail down your responses to common compliance questions. Get a friend to grill you on your knowledge of data protection laws and compliance tools like Vanta or ISO 27001.
β¨Tip Number 4
Apply through our website! We love seeing candidates who are genuinely interested in joining us at CourtCorrect. Tailor your application to highlight how your experience aligns with our needs, especially in AI compliance and data protection.
We think you need these skills to ace Compliance Manager in Slough
Some tips for your application π«‘
Tailor Your CV:Make sure your CV is tailored to the Compliance Manager role. Highlight your experience with GDPR, data protection, and compliance frameworks. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about compliance and how your background makes you a perfect fit for CourtCorrect. Keep it concise but impactful!
Showcase Relevant Experience:When detailing your experience, focus on specific projects or roles where you've managed compliance tasks. We love seeing concrete examples of how you've handled GDPR operations or vendor risk assessments.
Apply Through Our Website:We encourage you to apply directly through our website. Itβs the best way to ensure your application gets into the right hands. Plus, it shows us you're keen on joining our team at CourtCorrect!
How to prepare for a job interview at CourtCorrect
β¨Know Your GDPR Inside Out
Make sure you brush up on your knowledge of UK and EU GDPR regulations. Be prepared to discuss specific compliance frameworks, like DPIAs and ROPAs, and how you've applied them in previous roles. This will show that youβre not just familiar with the theory but have practical experience too.
β¨Showcase Your Document Management Skills
Since this role involves a lot of document management, be ready to talk about your experience with file structures, version control, and retention policies. Bring examples of how you've maintained compliance records or managed contract workflows in the past to demonstrate your attention to detail.
β¨Prepare for Scenario-Based Questions
Expect questions that put you in hypothetical situations related to compliance challenges. Think about how you would handle vendor risk assessments or respond to a data breach. Practising these scenarios can help you articulate your thought process clearly during the interview.
β¨Connect with the Team's Vision
Research CourtCorrectβs mission and values, especially their focus on AI and compliance. Be ready to discuss how your background aligns with their goals and how you can contribute to building a robust compliance function as they scale. Showing genuine interest in their work will set you apart.