Ricardo Maifrino

Portfolio

Fifteen projects, from licence applications to bank remediation.

Each one has the context I walked into, what I actually did, and what came out of it. Filter by the kind of problem — or read the lot.

Showing 15 of 15

Fintech · current

Mint Payments — multi-market payments

The situation

Mint needed a Risk & Compliance function that could keep pace with growth across Asia-Pacific, Europe and North America — licensing, product controls and lean operations, not a cost-centre afterthought.

What I did

Built the function from the ground up as Head of Risk & Compliance and MLRO: frameworks, licensing pathways, AI- and automation-led operations, and controls designed to unlock products and markets rather than block them.

A$1B+ transaction volume supported · ~60% lower operational cost · standing MLRO capability across three regions

Fintech

Hnry — Risk & Compliance from zero

The situation

Hnry needed Risk, Compliance and InfoSec stood up from scratch across Australia, New Zealand and the UK as payments scaled — a real governance backbone, not a slide pack.

What I did

Designed risk appetite statements, multi-jurisdiction compliance frameworks, incident response and privacy plans, and worked with the executive team and Board to keep risk strategy tied to growth.

One resilient function scaling across three markets, with board-aligned risk strategy instead of bolted-on policies

Licensing

Hnry — debit card licences

The situation

Debit cards were a growth bet — but only if the AFSL, UK e-money, Visa and Mastercard pathways cleared without a late regulatory blocker.

What I did

Coordinated with ASIC and the FCA, integrated risk controls with issuing partners, and implemented Strong Customer Authentication under PSD2 so the launch stayed secure and compliant.

Licences secured and card operations launched, with monitoring and reporting ready to run

Expansion · UK

Hnry — UK market launch

The situation

Opening the UK meant a compliant, scalable risk framework aligned to the FCA — governance, SCA/PSD2 and GDPR — not a copy-paste of the AU/NZ model.

What I did

Built UK-specific governance and operational controls, designed the SCA processes for PSD2, and implemented privacy frameworks and GDPR measures for customer data.

Successful UK go-live, regulator relationships built for the long term, and a framework ready for further product launches

ADI · APRA

GoBank — Restricted ADI licence

The situation

GoBank needed a Restricted ADI application that would stand up to APRA — governance, risk management and operational readiness as the foundation for a full banking licence.

What I did

Gap-assessed processes against APRA requirements, designed the policies and procedures, and built the business plan, governance model, Risk Appetite Statement and Risk Management Strategy, with leadership workshops on licensing strategy.

A well-structured RADI application, accountability aligned to BEAR and CPS 510, and a clear roadmap to unrestricted ADI status

Payments

PayPal Brazil — operational risk

The situation

PayPal Brazil wanted a stronger operational risk framework across governance, payments, procurement, vendor management and data protection — local Central Bank rules plus global PayPal standards.

What I did

Partnered with PayPal stakeholders to map and test processes, risks and controls; recommended automation, formalised local policies, and ran workshops on regulatory and data-protection awareness.

Formal local governance and committees, automation of key processes, and global policy aligned with Brazilian Central Bank requirements

AML/CTF

ANZ Wealth — AML/CTF risk assessment refresh

The situation

ANZ Wealth needed its AML/CTF Product Risk Assessment refreshed for Pensions & Investments — closing gaps against AUSTRAC guidance and internal audit findings, with MLRO alignment.

What I did

Reviewed AML/CTF controls against AUSTRAC guidance and audit findings, ran workshops with Product, Compliance and the MLRO team, and assessed transaction monitoring, screening and customer due diligence.

A health-check dashboard with prioritised risks, and stronger AML/CTF accountability across the product lifecycle

Tax · compliance

HSBC Brazil — FATCA

The situation

HSBC Brazil needed to meet US FATCA obligations — automated reporting, lower regulatory risk, and a framework that could travel beyond one market.

What I did

Mapped existing reporting to FATCA requirements, closed compliance gaps with controls, built automated data collection and reporting tools, and trained the team to run and maintain the regime.

FATCA reporting automated and embedded, with around 30 people trained to keep it running

Transformation

Westpac — controls at scale

The situation

Westpac needed its control framework transformed — testing, incident management and reporting — across more than 5,000 key controls, with digital solutions in the loop.

What I did

Led a cross-functional team of 70+ through Genpact: created a risk playbook for controls testing and incidents, implemented analytics dashboards, and aligned technical controls with APRA and ASIC expectations.

5,000+ controls covered, manual testing effort cut by over 40%, and stronger incident tracking and reporting

Governance

OFX — Three Lines of Defence

The situation

OFX had inconsistent risk accountability, incomplete risk-appetite integration and board oversight that needed an uplift against global practice and ERM expectations.

What I did

Interviewed senior management and the board, maturity-assessed the Three Lines of Defence against global benchmarks, and recommended integrating risk appetite with ERM and performance, with a better balance of preventative and detective controls.

Clearer accountability across all three lines, stronger board reporting with KRIs and emerging-risk trends

APRA

Macquarie — target operating model & audit review

The situation

Macquarie needed a Target Operating Model and an internal audit review against APRA prudential standards — sharper governance and risk practice after Royal Commission and APRA scrutiny.

What I did

Designed a TOM blueprint for prudential compliance, reviewed past internal audits for coverage gaps, facilitated alignment workshops and prepared an implementation roadmap.

Gaps closed across risk and governance, internal audit aligned to APRA expectations, and a roadmap to embed prudential compliance in BAU

Internal audit

Bank of Sydney — internal audit co-source

The situation

Bank of Sydney wanted co-sourced internal audit support to deepen APRA Prudential Standards compliance and strengthen controls across governance, risk and operations.

What I did

Ran risk-based reviews of control design and effectiveness, tested compliance against APRA standards, documented findings with the in-house audit team and shared emerging-risk insights.

Key compliance risks identified and resolved, with stronger internal audit methodology left behind

Internal audit

State Bank of India, Sydney — audit framework

The situation

The Sydney branch needed an enhanced internal audit framework across governance, risk and compliance, with actionable recommendations on key risks and controls.

What I did

Ran a risk-based assessment and prioritisation, built an audit plan covering governance, credit, compliance and operations, brought in specialists for IT, AML/CTF and financial controls, and delivered quarterly audits.

Quarterly risk-rated audits, clearer risk accountability and closer alignment with APRA Prudential Standards

Banking technology

BTMU Brazil — front office system

The situation

Banco de Tokyo-Mitsubishi UFJ Brazil needed a new front office system for fixed-income products — better efficiency, data integration and regulatory compliance.

What I did

Led analysis and design of the product requirements, coordinated integration across DMA portfolios and swap instruments, phased the Calypso configuration through UAT, and built contingency plans as risks appeared.

Fixed-income operations streamlined with less manual intervention and stronger reporting and reconciliation

Remediation

Newcastle Permanent — mortgage offset remediation

The situation

A customer remediation programme for mislinked mortgage offset accounts and overcharges needed a quality review of its methodology, governance and regulatory alignment.

What I did

Reviewed customer identification, calculation and communication processes, evaluated steering and working-group governance, root-caused manual errors and prioritisation flaws, and recommended control and customer-comms uplifts.

Fairer, more accurate remediation for affected customers and stronger oversight of the programme

Got a licence, a market or a mess like one of these?

Based in Sydney, working across US, European and Asia-Pacific time zones.