Vice President- Legal, Risk & Compliance (Gurugram)

Vice President- Legal, Risk & Compliance (Gurugram)

29 Aug
|
CIMET
|
Gurugram

29 Aug

CIMET

Gurugram

1. About CIMET

CIMET Group is one of Australias fastest-growing comparison and connection platforms. Through CIMET Sales Pty Ltd and its related entities, we help Australian households and small businesses compare, choose and switch across four verticals: energy, broadband, personal loans and credit cards, and private health insurance.

We operate through our own digital comparison journeys and through a national network of referral, white-label, co-brand and marketing partners. We contract directly with Australias largest energy retailers, lenders, telecommunications providers and health funds, and we operate under their compliance regimes as well as our own licenses and authorizations.

CIMETs India operations in Gurgaon and Jaipur are not a back office. They carry substantive ownership of technology, operations, quality assurance, legal and compliance for the Australian business. This role sits at the top of that legal, risk and compliance capability.

Our stated ambition (BHAG) is to build a $1 billion enterprise by 2030. That ambition depends entirely on being the most trusted operator in our category. Legal, risk and compliance is therefore a core commercial capability at CIMET, not a support function and it is being elevated accordingly.

2. Why this role exists

This is a newly created executive role. CIMET is consolidating Legal, Risk and Compliance into a single accountable function reporting directly to the Chief Financial Officer & Director. The Compliance function, which currently reports through Operations, will transition into this function, and compliance coverage will be organised product-by-product alongside legal.

The Vice President Legal, Risk & Compliance will:

- own the operating framework that keeps CIMET compliant with its Australian legal, licence, code and contractual obligations across all four product verticals;
- act as a genuine second line of defence, with the standing and the authority to challenge, condition, pause or reject activity where controls or evidence are inadequate;
- build and embed an enterprise risk management framework, and the risk and compliance reporting that goes to the Executive and the Board;
- provide legal, risk and compliance oversight of CIMETs group entities in Australia, India and the Philippines, working with external counsel and corporate secretarial providers in each jurisdiction;
- support CIMETs growth agenda capital raising, mergers and acquisitions, joint ventures, strategic partnerships and new geographic expansion from a legal, risk and compliance perspective;
- lead, develop and scale a product-aligned legal and compliance team across Gurgaon and Jaipur; and
- keep CIMETs commercial engine partner channels, retailer and provider agreements, digital journeys and new product launches moving at pace inside defensible controls.

We are looking for a commercially fluent operator who has built and run a function not a purely advisory or transactional lawyer. 2.1 A note on the operating model

This role is based in India and is accountable for a business regulated in Australia. Australian licence holdings and any Responsible Manager appointments remain with CIMETs Australian officers; the Vice President supports those appointments rather than holding them, and works with Australian external counsel where a local practising opinion is required. Everything else the obligations register, the control environment, the evidence, the monitoring, the reporting and the remediation sits with this role.

The successful candidate does not need to arrive holding Australian regulatory knowledge. They do need to demonstrate that they have learned an unfamiliar regulatory regime from primary sources before, and built a working control environment on top of it.

3. Team and structure The Vice President will lead a product-aligned structure. Legal and compliance accountability is paired within each vertical grouping so that a single leader owns both the advice and the controls for their products.

Role-

Vice President Legal, Risk & Compliance

Reports to

CFO & Director (Sydney)

Product scope

All verticals; enterprise risk; board and committee reporting; obligations and license support; commercial contracting; India entity legal

Role-

Legal & Compliance Teams Energy, Personal Loans & Credit Cards

Reports to

VP Legal, Risk & Compliance

Product scope

Energy; personal loans and credit cards legal advice plus compliance framework, monitoring and remediation

Role-

Legal & Compliance Teams Broadband & Private Health Insurance

Reports to

VP Legal, Risk & Compliance

Product scope

Broadband; private health insurance legal advice plus compliance framework, monitoring and remediation

Role-

Compliance leadership

Reports to

Both Teams of Legal & Compliance, on a transitional basis

Product scope

Operational compliance across all verticals during the transition period

Role-

Operational compliance team

Reports to

Allocated product-wise beneath the two Teams

Product scope

Quality assurance and consent auditing, partner oversight, complaints, incidents, training and attestations, reporting inputs

4. Key accountabilities

4.1 Commercial and transactional legal

- Own CIMETs commercial contracting end to end: retailer and provider channel and distribution agreements, referral, white-label, co-brand, marketing and lead-supply agreements, technology and SaaS terms, data-sharing and processing arrangements, procurement and vendor terms.
- Negotiate directly with the legal and commercial teams of large Australian counterparties on service definitions, approved channels, audit and inspection rights, subcontracting and sub-affiliate approval requirements, data protection, liability and indemnity, suspension and termination.
- Build and maintain the contract playbook, template suite, negotiation parameters, delegated authority and approval matrix, contract register and renewal calendar driving cycle time down without lowering the floor on risk terms.
- Manage disputes, notices, demands and contentious matters, including instruction, scoping and cost management of Australian and Indian external counsel.
- Support corporate activity capital raising, mergers and acquisitions, joint ventures, new entities and new vertical launches including diligence readiness, disclosure and warranty work, and post-transaction integration of legal and compliance obligations.
- Advise on intellectual property and brand, marketing and advertising claims, corporate governance and entity housekeeping; partner with People & Culture on employment and workplace matters.

4.2 Australian regulatory and product compliance

- Licence and authorisation support: own the obligations, controls and evidence that sit beneath CIMETs Australian authorisations, including Australian Credit Licence obligations under the National Consumer Credit Protection Act organisational competence and responsible manager arrangements, credit representative and referral arrangements, general conduct obligations, annual compliance certification and the reportable situations (breach reporting) regime.
- Australian Consumer Law: own compliance across misleading or deceptive conduct, unsolicited consumer agreements, unfair contract terms, unconscionable conduct and consumer guarantees as they apply to comparison, lead generation, telesales and partner-assisted sales activity.
- Energy: National Energy Retail Law, Rules and Code, AER guidelines and pricing information requirements, the Victorian Energy Retail Code of Practice and other jurisdictional requirements; retailer compliance regimes covering approved channels, scripts, disclosures and consent.
- Consumer credit: credit assistance and responsible lending obligations, design and distribution obligations, ASIC regulatory guidance, and disclosure and comparison standards for credit products.
- Broadband: Telecommunications Consumer Protections Code, ACMA requirements, and Telecommunications Industry Ombudsman processes.
- Private health insurance: Private Health Insurance Act and Code of Conduct obligations, fund distribution arrangements, and the basis on which CIMETs activities sit within or outside the financial services licensing regime.
- Cross-cutting: the Australian Privacy Act and Australian Privacy Principles, notifiable data breaches, cross-border disclosure of personal information, the Spam Act, the Do Not Call Register Act, and the consent-capture and record-retention standards that evidence compliance with all of the above.
- Regulatory change: own horizon scanning, impact assessment, implementation planning and evidenced closure of regulatory and code change across all verticals.

4.3 Compliance framework and operations

- Own the compliance management framework: an obligations register and control library mapped to law, license, industry code and contract, with named control owners, testing frequency and defined evidence standards.
- Own the three lines of defence model and the decision authorities within it including second-line authority to condition, pause or reject activity, approve time-bound exceptions, and determine external notifications.
- Own gate controls: no partner, campaign, brand, website journey, script, sales process or material system change goes live without the required approvals evidenced.
- Own monitoring and assurance: pre-submission sales quality assurance, call and consent audits, website and digital journey audits, system control testing, and risk-based thematic reviews.
- Own complaints governance: identification, logging, investigation, remediation of customer outcomes, root cause analysis, systemic issue detection, and the handling of vulnerable customer and family and domestic violence matters through safe, restricted and documented processes.
- Own incident and breach management: containment, investigation, notification assessment (regulator, retailer or provider, Ombudsman, affected customers), corrective and preventive action, and effectiveness testing.
- Own training, competency and attestation: onboarding and refresher training, competency records, code of conduct, and periodic attestations from staff, agents and partners.




- Lead the transition of Compliance from Operations into Legal and the product-wise allocation of the compliance team, without any loss of coverage during the change.

4.4 Risk management and risk reporting

- Design, implement and embed CIMETs enterprise risk management framework: risk taxonomy, risk appetite statement and tolerances, risk and control self-assessment, key risk indicators, and a live risk register with named owners and treatment plans.
- Maintain and report the enterprise risk profile across compliance, conduct, privacy, information security, third-party and outsourcing, fraud, operational, financial-crime and regulatory risk and challenge residual risk acceptance at the correct authority.
- Own the exception and waiver regime time-bound, with compensating control, owner and expiry and ensure expired, failed or bypassed exceptions are treated as incidents.
- Partner with Information Security and Technology on the information security management system, ISO 27001 alignment, security incident response and partner security assessments.
- Work with the CFO on insurance strategy, placement and renewals (professional indemnity, cyber, directors and officers, public liability) and manage claim notifications.
- Own business continuity, crisis management and the escalation, communications and media protocol for regulatory, conduct or security events.

4.5 Board, committee and executive reporting

- Prepare and present the Legal, Risk and Compliance report to the Board and to the product compliance and management risk committees, covering risk profile movement, appetite breaches, incidents and breaches, complaints and conduct trends, partner and third-party risk, remediation status, licence and regulatory obligations, litigation and material contracts.
- Establish and run the committee architecture: charters, membership, cadence, papers, minutes, action tracking, and documented residual-risk decisions.
- Give the CFO, the Executive and the Board early, unvarnished escalation of material matters. No surprises.
- Keep the function permanently ready for external scrutiny retailer and provider audits, regulator or Ombudsman enquiries, investor and acquirer due diligence, and independent or internal assurance reviews.

4.6 Partner, channel and third-party risk

- Own the partner onboarding gate end to end: business due diligence, security and privacy assessment, compliance risk assessment, legal and contractual review, operational readiness, and the go-live decision.
- Maintain a complete, current and accurate register of partners, sub-affiliates, subcontractors and trading brands, and ensure every required counterparty approval or consent is obtained and evidenced before activity commences.
- Own ongoing oversight: attestations, risk-based audits and site inspections, quality assurance and consent testing, corrective action plans tracked to verified closure, and suspension or termination where risk is not controlled.
- Set and enforce the rules of engagement for partner and agent sales conduct approved channels and brands, scripts, mandatory disclosures, consent capture, contact preferences and record retention.
- Be the escalation point for partner conduct issues, and lead the notification, remediation and relationship conversations with affected retailers and providers.

4.7 Group entity oversight Australia, India and the Philippines CIMET operates through entities in Australia, India and the Philippines. The Vice President holds single-point visibility of the legal, corporate and compliance health of every group entity, and is the person who knows what is outstanding, where, and by when,

- Maintain a consolidated group entity register and statutory compliance calendar covering every jurisdiction filings, registrations, licenses, resolutions, registered offices, directorships and secretarial obligations with visible status and no reliance on any single providers memory.
- Own the relationship with, and the quality of work from, external legal counsel and corporate secretarial providers in each jurisdiction: instruct clearly, scope tightly, manage cost, review output, and escalate where advice is late, thin or inconsistent.
- Australia: work with Australian external counsel and the corporate secretary on Corporations Act obligations, board and shareholder resolutions, ASIC filings, director appointments and entity housekeeping for CIMET Sales Pty Ltd and related entities.
- Philippines: work with Philippine external counsel and corporate secretarial providers on SEC and regulatory filings, entity registrations and incentives arrangements where applicable, local statutory obligations and the Data Privacy Act.
- India: own the statutory and corporate compliance calendar under the Companies Act 2013 directly, working with the company secretary, statutory auditors and Finance; and own obligations under the Digital Personal Data Protection Act 2023.
- Own intra-group arrangements across all three jurisdictions services agreements, data processing and cross-border transfer arrangements, intellectual property and licensing arrangements between entities, and the legal documentation supporting transfer pricing positions, in conjunction with Finance.
- Ensure Australian customer personal information is handled consistently with Australian Privacy Principle requirements for cross-border disclosure wherever in the group it is processed.
- Manage litigation, notices and regulatory correspondence in each jurisdiction, and the external counsel handling it.
- Report group entity compliance status to the CFO and the Board as a standing item, with exceptions and overdue items named.

4.8 New market entry and geographic expansion

- Provide the legal, risk and regulatory assessment for any new geography CIMET considers entering: licensing and authorisation requirements, consumer protection and marketing rules, data protection and data localisation, foreign investment and entity structuring, employment and engagement models, and the practical cost and timeline of becoming compliant.
- Recommend and stand up the entity, licensing and governance structure for a new market, including selection and onboarding of local counsel and corporate secretarial providers.
- Extend CIMETs obligations register, control library, policies and reporting to each new market so that a new geography enters the existing framework rather than running on its own arrangements.
- Give the CFO and the Board a clear, early view of whether a market is viable from a regulatory and risk standpoint including when the answer is no, or not yet.

4.9 Capital raising, M&A;, joint ventures and partnerships

- Act as the legal and risk lead on CIMETs corporate development agenda: capital raising, mergers and acquisitions, joint ventures, strategic partnerships and material commercial alliances.
- Support transaction execution end to end term sheets, confidentiality and exclusivity arrangements, structuring input with Finance and advisers, transaction documentation, conditions precedent, completion mechanics and post-completion obligations.
- Lead buy-side due diligence on targets: scope the legal, regulatory, licensing, contractual, data protection, employment and litigation workstreams; instruct and manage advisers; and translate findings into deal issues, price and warranty implications, conditions, and integration actions rather than an undigested issues list.
- Own sell-side and investor-side readiness on CIMET itself: maintain the corporate, contract, license, compliance, privacy, employment and litigation record in a state that can be opened to a counterparty at short notice; run the data room; prepare disclosure schedules; and manage the diligence response process across the group.
- Advise on warranties, indemnities, disclosure and, where applicable, warranty and indemnity insurance; and ensure obligations surviving completion are tracked and honored.
- Lead legal and compliance integration of acquired businesses or joint ventures obligations mapping, control alignment, contract novation and remediation of inherited issues.
- Ensure that diligence findings on CIMET are fed back into the risk register and the remediation plan, so that each process leaves the group in better shape than it found it.

4.10 Employment law across the group

- Own India employment and workplace legal compliance directly, in partnership with People & Culture: employment and contractor arrangements, Shops and Establishments and applicable labour law registrations, statutory benefits, disciplinary and separation processes, and the Sexual Harassment of Women at Workplace (Prevention, Prohibition and Redressal) Act 2013, including Internal Committee constitution, training and annual reporting.
- Instruct and manage Australian external counsel and advisers on Australian employment matters Fair Work Act obligations, awards and classifications, contractor and engagement models, performance and termination, and workplace complaints.
- Instruct and manage Philippine external counsel and advisers on Philippine employment matters, including Labor Code obligations, engagement models, statutory benefits, and termination and dispute processes.
- Maintain consistent group-wide standards for employment contracting, confidentiality, intellectual property assignment, restraint provisions and code of conduct, adapted to what is enforceable in each jurisdiction.
- Advise on workplace investigations, grievances and whistleblower matters, and ensure a protected and properly documented process in every jurisdiction.
- Support People & Culture on organizational change, workforce structuring and cross-border mobility, including the legal implications of moving roles or teams between jurisdictions.

4.11 Leadership

- Lead, coach and develop two product-aligned Teams of Legal & Compliance and, through them, the wider legal and compliance team across Gurgaon and Jaipur.




- Set clear accountabilities, service standards, quality benchmarks and development plans; build bench strength and succession in a function that has previously been thinly resourced.
- Build the functions credibility with Operations, Sales, Partnerships, Product, Technology, Information Security and Finance across two countries and two time zones so that legal and compliance is engaged early in the design of activity, not at the gate.
- Represent CIMET credibly to Australian retailers, providers and their compliance and legal teams, and to Australian external counsel.
- Manage the functions budget, external legal spend, and its technology and tooling roadmap.

5. What success looks like

Horizon

First 90 days

Outcomes

Structure stood up: Compliance transitioned into Legal, product-wise allocation planned and underway, accountabilities documented. Australian obligations, licence conditions and contract inventory independently verified. Top enterprise risks and control gaps identified, ranked and socialised with the CFO and Executive. Working relationships established with key Australian retailer and provider counterparts.

Horizon

3 to 6 months

Outcomes

Enterprise risk management framework and risk appetite statement approved by the Board. Risk register live with named owners and treatment plans. Committee architecture and a standing reporting pack operating to a fixed cadence.

Contract playbook, templates and delegated authority matrix in force. Consolidated group entity register and statutory calendar current and clean across Australia, India and the Philippines, with external counsel and corporate secretarial relationships under active management.

Horizon

6 to 12 months

Outcomes

Compliance team reporting cleanly into the two product-aligned Teams. Partner, sub-affiliate and brand register complete, current, and approved wherever counterparty approval is required. Monitoring and assurance plan executing to schedule with evidenced results.

Incident, complaint and breach handling demonstrably timely and documented. Measurable reduction in contract cycle time. Transaction readiness established the corporate, contract, licence, compliance and employment record can be opened to an investor or acquirer at short notice.

A function that can withstand a retailer audit, a regulator enquiry or a counterpartys due diligence without a remediation scramble.

6. Selection criteria

6.1 Essential

- Law graduate (LLB or equivalent), with enrolment with a State Bar Council in India or an equivalent qualification in another common-law jurisdiction.
- At least 12 years post-qualification experience, including a minimum of four to five years leading a legal and/or compliance function with direct reports.
- Substantial experience supporting a business regulated in a common-law jurisdiction outside India Australia, the United Kingdom, New Zealand, Canada or the United States in a consumer-facing financial services, energy, telecommunications, insurance or comparison business.
- Demonstrated ability to learn an unfamiliar regulatory regime from primary sources legislation, regulator guidance, industry codes and counterparty contracts and to convert it into a working obligations register and control workplace.
- Proven experience designing, implementing and operating a compliance management framework and a three lines of defence model in a fast-moving commercial business evidenced by controls that were actually tested, not a framework that only existed on paper.
- Enterprise risk management experience: risk appetite, risk register, key risk indicators, risk and control self-assessment, and exception management.
- Board and committee reporting experience has personally authored and presented papers to a board, board risk committee or the executive of an overseas parent.
- Solid commercial contracting capability, with a track record of negotiating distribution, channel, referral, white-label or outsourcing agreements directly with large corporate counterparties, in English, under foreign governing law.
- Third-party and outsourcing risk experience: due diligence, contractual controls, audit and inspection, remediation, suspension and termination.
- Privacy and data protection capability, including cross-border data transfer arrangements between group entities.
- Experience overseeing legal and corporate compliance for entities in more than one country, including instructing, scoping, cost-managing and quality-reviewing external counsel and corporate secretarial providers in jurisdictions where the candidate is not personally qualified.
- Demonstrated experience on corporate transactions capital raising, mergers and acquisitions, joint ventures or strategic partnerships including running or leading workstreams on both buy-side due diligence of a target and the companys own diligence response, data room and disclosure process.
- Working knowledge of India entity corporate, employment and data protection compliance, including Companies Act statutory compliance and the POSH Act.
- Employment law capability: direct ownership of employment matters in at least one jurisdiction, and demonstrated ability to manage employment issues in others through external advisers including terminations, investigations and organisational change.
- Experience managing incidents, complaints, disputes, regulator or ombudsman engagement, and external counsel.
- Evidence of building something from a low base, at pace, with constrained resources a framework, a function, or a team.
- Excellent written and spoken English, and the presence to hold a difficult conversation with an Australian counterpartys legal or compliance leadership over video.

6.2 Desirable

- Direct exposure to Australian consumer regulation the Australian Consumer Law, National Energy Retail Law and Rules, the National Consumer Credit Protection Act, the Telecommunications Consumer Protections Code, or the Australian Privacy Principles.
- Experience in a global capability centre or captive supporting an Australian, UK or US regulated parent, with genuine ownership rather than process execution.
- Experience in a comparison, aggregator, marketplace, broking, lead generation or affiliate-channel business model.
- Experience in Indian financial services, insurance distribution, non-banking financial companies or consumer internet businesses with a regulated product set.
- Information security governance exposure, including ISO 27001 environments.
- Exposure to Philippine corporate, data protection or employment requirements, or to South-East Asian entity structures more generally.
- Experience assessing and standing up a new geographic market licensing, entity structure, local advisers and extension of an existing control framework.
- Experience on an initial public offering, a private equity or venture funding round, or a trade sale process.
- Company secretarial qualification (ACS) or a post-graduate qualification in risk, compliance or governance.
- Experience leading teams across more than one Indian location.

7. Capabilities and behaviors

Capability

Commercial judgement

What we mean

Understands the revenue model and the deal, and finds the compliant path to the commercial outcome rather than simply cataloguing the risk.

Capability

Independence and courage

What we mean

Will hold a position under commercial pressure, escalate without hesitation, and say no when no is the right answer and has done so.

Capability

Evidence discipline

What we mean

Treats a control as real only when the evidence exists, is retained and would survive an audit or a regulators file request.

Capability

Operator, not adviser

What we mean

Comfortable in process, systems, registers, audits and remediation not only in advice and negotiation.

Capability

Learns a regime fast

What we mean

Can go from unfamiliar legislation to a mapped obligation set and a working control in weeks, and knows when to buy a local opinion instead of guessing.

Capability

Clarity

What we mean

Writes and speaks plainly. Board papers, partner notices and internal requirements are unambiguous and decision-ready.

Capability

Distance leadership

What we mean

Runs a function whose stakeholders sit in another country and time zone, without becoming invisible or becoming a bottleneck.

Capability

Manages advisers well

What we mean

Instructs external counsel with a clear question and a scope, tests the answer rather than forwarding it, and holds providers to cost and quality across several jurisdictions.

Capability

Pace

What we mean

Delivers at the speed of a scaling business, and knows which controls must never be traded for speed.

Capability

Integrity

What we mean

Non-negotiable. Consumer outcomes and honest reporting come before convenience.

8. Key relationships

Internal

Chief Financial Officer & Director, Sydney (manager); Chief Executive Officer; VP Operations; Sales and Partnerships leadership; Product and Technology; Information Security; People & Culture; Finance; the Board and its committees.

External

Australian energy retailers, lenders and credit providers, telecommunications providers and health funds; Australian regulators and schemes including ASIC, the AER and state energy regulators, ACMA, the ACCC, the OAIC, the TIO, the state energy and water ombudsman schemes and the Private Health Insurance Ombudsman; external legal counsel and corporate secretarial providers in Australia, India and the Philippines; statutory auditors and independent assurance providers; corporate finance advisers, investors, acquirers and joint venture counterparties; insurers and brokers.

9. Other information

- Location: Gurgaon or Jaipur. Working arrangements to be discussed; core overlap with Australian business hours is required.
- Travel: periodic travel to Sydney, Philippines and between CIMETs India locations. Candidates must be able to obtain the necessary travel documentation.
- Pre-employment checks: identity and address verification, education and Bar Council enrolment verification, employment and reference checks, criminal record check, and database and directorship checks appropriate to a senior legal and compliance appointment.
- CIMET is an equal opportunity employer. We welcome applications from candidates of all backgrounds and are happy to discuss flexible and accessible working arrangements.

📌 Vice President- Legal, Risk & Compliance (Gurugram)
🏢 CIMET
📍 Gurugram

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: vice president- legal, risk & compliance (gurugram) / gurugram