The Risk & Compliance Analyst is responsible for supporting the Head of Risk & Compliance (& Data Protection Officer - DPO) in updating, implementing, and overseeing OUB's risk and compliance framework.
We are a tech business that bundle household bills into one fixed monthly payment. One payment means easier finances, less time on the phone to suppliers, and less admin. It’s a game changer.
It’s also a gorgeous place to work. Everybody gets stuck in to make things work, the team will make you feel welcome from day one, and the office is near some pretty great pubs.
As a Risk & Compliance Analyst, you will support the Head of Risk & Compliance (& DPO) with a range of regulatory and compliance matters, contributing to a culture of proportionate and realistic compliance combined with continuous improvement. The role ensures that OUB meets the minimum requirements of relevant regulations, industry standards, and internal policies in line with risk appetite to protect the business from regulatory and compliance risks.
Our team manages risk while also supporting the growth ambitions of the business by following these principles:
-
When something goes wrong, we will support you to fix it and record what we did
-
Raise issues and problems before they become an incident so we can solve them together
-
We will support you to identify risks and give you ways and ideas to manage them
-
If compliance gets in the way of progress, let’s discuss and adjust if we can
Day to day, you will be working on a combination of these goals:
-
Ensuring that process and procedures are aligned to the OUB regulatory compliance framework that aligns with strategic objectives and risk appetite.
-
Supporting the DPO in ensuring compliance with UK GDPR and the Privacy and Electronic Communications Regulations (PECR).
-
Actioning Data Subject Access Requests (DSARs) and data deletion processes in line with regulatory timescales.
-
Supporting the process of product changes to protect customers from detriment and ensure sales process compliance standards prevent mis-selling.
-
Reviewing Root Cause Analysis (RCA) completed on all complaints to identify and address systemic issues.
-
Supporting or completing assessments of the security and compliance of all suppliers and partners to mitigate information security risks.
-
Ensuring adherence to industry certifications like ISO 27001.
-
Seeking opportunities to support leaders to be confident and independent when dealing with any regulatory or compliance issues.
-
Supporting team members to manage the impact and resolution of data and operational risk incidents to a suitable outcome.
-
Creating and producing analysis and reporting
-
An Operational Risk Management certification or progress towards one.
-
Experience in a consumer-facing sector (e.g., energy, telecoms, financial services).
-
Knowledge of UK GDPR, PECR, and consumer protection legislation.
-
Understanding of relevant compliance frameworks such as ICOB, ISO 27001, Cyber Essentials, and GDPR.
-
Excellent communication skills and a proven ability to influence and engage with stakeholders at all levels.
-
A pragmatic, solutions-oriented approach to problem-solving, with a focus on commercial outcomes.
-
A project management qualification (desired but not essential).
As well as all of the great perks listed below, here’s what you can expect to gain financially from this role…
An annual salary of £32,000 - £36,000
£2000 per year in bonuses paid to the full company if we achieve our shared objectives
The shift pattern for this role is Monday to Friday, 9am until 5pm.
This is an office-based role for the first 6 months, following a successful probation period there is potential for hybrid working, 2 days per week.
Be Fiercely You isn't just a value, it's how we thrive! We believe our strength comes from a truly diverse team where everyone feels valued and respected. If you're passionate about what you do, we want to hear from you, no matter your background