Team Lead — Compliance Monitoring, Assurance & Testing (CMAT)
About the role
Responsibilities
Compliance Monitoring & Testing Programme
Own and maintain a risk-based annual Compliance Monitoring & Assurance Plan (CMAP), refreshed on risk assessment outcomes, FSRA thematic reviews, and changes in regulatory posture.
Design and execute control testing across AML/CFT, sanctions, market abuse, client-asset safeguarding, complaint handling, outsourcing, and technology/cyber governance.
Apply full-cycle assurance methodology: scoping → walkthroughs → sampling → testing → root-cause analysis → findings rating → remediation tracking → closure validation.
Deliver thematic deep-dives aligned to FSRA supervisory priorities (e.g., transaction monitoring effectiveness, Travel Rule compliance, EDD for high-risk clients, market abuse surveillance).
Ensure monitoring activities map to the FSRA AML/CFT Rulebook, Conduct of Business (COBS), General (GEN), Prudential (PRU), and Virtual Asset framework obligations.
Support the Compliance Officer and MLRO in demonstrating effective oversight under FSRA's risk-based supervision model.
Maintain evidence trails that satisfy FSRA information requests, on-site inspections, and thematic reviews.
Monitor regulatory change (FSRA consultations, ADGM notices, UAE Federal Decree-Law 20/2018 and its Executive Regulations, MoE/EO AML guidance) and reflect updates in the plan.
Produce clear, board-ready assurance reports with quantified findings, severity ratings, and management action plans.
Operate a robust issue-management and remediation-tracking framework with escalation protocols for overdue or high-risk items.
Present monitoring results to Risk Committees, Compliance Committees, and where required the Board/Audit Committee.
Liaise with Internal Audit and external auditors to ensure complementary (non-duplicative) coverage.
Test the effectiveness of CDD/EDD, KYC onboarding, periodic review, PEP/sanctions screening, transaction monitoring, and SAR/STR escalation processes.
Assess suspicious activity identification and reporting effectiveness, including FIU-UAE submission quality.
Verify Targeted Financial Sanctions (TFS) and asset-freeze controls.
Build, mentor, and lead a high-performing assurance team — setting testing standards, quality review, and coaching.
Foster a culture of challenge, professional scepticism, and integrity, consistent with SMCR conduct expectations.
Manage resource allocation against the CMAP and ensure delivery within agreed SLAs.
Maintain CMAT policies, methodologies, and documentation to an auditable standard.
Drive automation and data analytics to strengthen monitoring coverage and efficiency.
Embed lessons learned into first- and second-line processes and training.
Regulatory Alignment (FSRA)
Findings, Reporting & Escalation
AML/CFT & Financial Crime Assurance
Leadership & Team Management
Governance & Continuous Improvement
Requirements
Essential
7–10+ years in compliance, assurance, internal audit, or regulatory supervision within financial services, fintech, preferably within crypto/VASP environments.
3+ years leading teams or workstreams in a second-line or audit function.
Strong working knowledge of ADGM FSRA rulebooks and the UAE AML/CFT landscape; comparable MAS, HKMA, FCA, or DIFC/DFSA experience will be considered.
Proven track record designing and executing risk-based compliance monitoring/testing programmes.
Depth in AML/CFT, sanctions, and financial-crime control testing.
Excellent written and verbal English; strong report-writing and stakeholder-presentation skills.
CAMS, CGSS, CRMA, CIA, ACCA/ACA, ICA, or equivalent certification
Prior experience in a regulated crypto/VASP or high-growth fintech.
Data analytics, SQL, or audit-automation tooling skills.
Arabic language proficiency (advantageous, not required).
Desirable