Sign up free to see how well your resume matches this role.
The Head of Governance, Risk & Compliance builds and runs the governance backbone of the organisation — the policy suite, the compliance calendar, the risk register, and the OKR system that holds every department accountable to measurable targets. This is a founding mandate, not a maintenance one: the incumbent stands up policies, processes and SOPs largely from scratch, gets them adopted across departments that don't report to them, and reports progress directly to the MD every quarter. The role suits someone who is equally comfortable drafting a board-ready policy, running a root-cause investigation, and pushing a reluctant department head to close an overdue audit finding.
• Own and maintain the company's core policy suite — insurance (zero-expiry rule), delegation of authority / signature matrix, related-party and intercompany transactions, regulatory compliance, contract approval and execution, client money / escrow handling, incident reporting and escalation, procurement and vendor engagement, vendor prequalification, risk management, workforce capacity and resource allocation, data protection and privacy (UAE PDPL), conflict of interest, whistleblowing, document retention and records, HSE, code of conduct, and business continuity
• Build and keep live the regulatory compliance calendar covering RERA, Mollak, escrow, owners association elections, and statutory audits, with proactive escalation of upcoming deadlines
• Run insurance renewal tracking with 90/60/30-day alerts to maintain a zero-expiry position across all company assets
• Own contract lifecycle management — review, approval, renewal and expiry alerting — and maintain the contract review checklist used across departments
• Oversee intercompany billing, commissions and settlement, ensuring related-party and intercompany transactions are documented, reconciled and audit-ready
• Run incident investigation and root cause analysis (5-why / fishbone), classify and log incidents on intake, and track corrective actions from finding to verified closure
• Lead the internal audit cycle on a quarterly, rotating basis, from fieldwork through reporting, driving findings to closure against a defined target rate
• Administer the mobilization compliance gate, ensuring every new project or mandate receives sign-off before go-live
• Maintain the risk register, score and review risks on a quarterly cycle, and deliver quarterly risk reports to senior management
• Run vendor prequalification and onboarding, including annual revalidation and document verification, and own the procurement and vendor engagement policy
• Lead quarterly workload analysis (priced versus actual allocation) and monitor capacity utilization, escalating hiring or resourcing triggers at the 85% utilization threshold
• Maintain the diligence file with a quarterly refresh cadence, and lead the UAE PDPL programme — personal data handling, breach response, and data subject request procedures
Requirements
Benefits