I started on the bank side — HSBC, J.P. Morgan, BTMU — then spent years with EY, Protiviti and Genpact being flown in when something was broken: a remediation programme, a licence application, a control framework nobody trusted. You learn fast what regulators actually care about, and how much of a compliance function is theatre.
Then I moved to fintech and had to build the thing myself. At Hnry I stood up Risk, Compliance and InfoSec from nothing across Australia, New Zealand and the UK, and got the card and e-money licences over the line. At Mint Payments I run the same function across Asia-Pacific, Europe and North America — with a fraction of the headcount that used to imply.
That last part is most of what I do now. Compliance is full of work that is repetitive but not simple: onboarding and KYB checks, screening alerts, transaction monitoring reviews, evidence collection, regulatory reporting, policy upkeep. I redesign those processes around AI and automation — models and agents doing the first pass, humans deciding the things that actually need judgement — and the cost curve stops tracking transaction growth. At Mint that took roughly 60% out of operational cost while the control environment got stronger, not weaker. At Westpac the same instinct cut manual controls testing by over 40% across 5,000+ controls.
My bias: compliance should make the roadmap possible, not shorter — and it should not be the line item that scales fastest. That means saying yes with conditions instead of no, designing controls a product team can actually run, automating everything that does not need a person, and knowing which regulator conversation is worth having early.