JobRaahGet matched free

Jobs

Group Control Assurance Lead

Payhawk · London · United Kingdom · On-site

Posted Sep 2, 2026

Apply with JobRaah

Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.

Company Mission Payhawk is one AI-powered spend management platform for scaling businesses — corporate cards, expense management, procurement, and accounts payable, unified in one place. We serve finance teams across 32+ countries, cutting month-end close time and reconciling 99.7% of transactions with zero manual touch. AI runs through the platform as core infrastructure, not a bolted-on feature — and we hire the top 1% of talent in every function to keep building it that way. Why Payhawk Payhawk, where the bold builders make an impact. We're not a family, we're a high-performance team — and that's deliberate. We debate, ideate, and push each other to be better, because the best ideas come from direct feedback. We've already made history as Bulgaria's first unicorn, but the ambition doesn't stop there: if you want to grow fast - own it; do not wait for it. Give : Honest opinions, real ownership, a focus on outcomes. Get : A front-row seat to a market leader in one of the fastest-moving industries. The role, in one line You will independently test whether the controls across Payhawk's two e-money institutions, in the UK and Lithuania, actually work, and drive the gaps you find through to closure. What you will own Build and own the Board-approved group control assurance and monitoring plan for both licensed entities, with priorities set by the risk assessment and agreed with the Risk Committee. Design and run risk-based control testing across the group risk register, assessing both design effectiveness and operating effectiveness. Test operational resilience and ICT controls under the Digital Operational Resilience Act, and governance and conduct controls across both entities. Test safeguarding and capital adequacy controls, including whether reconciliations and calculations evidence what they are relied on to evidence. Test regulatory reporting controls, including whether the data behind each regulatory return is complete and accurate. Test outsourcing and third-party controls, including whether we would detect a critical provider falling below its obligations. Test detection controls independently and end to end. This covers sanctions and politically exposed person screening effectiveness, and transaction monitoring coverage and calibration, including the population that never generated an alert. Lead the remediation of the gaps you identify as programme manager for closure. You will convene the relevant stakeholders, agree scope, owners and dates, track progress, escalate where work stalls, and secure the governance approvals required. Validate independently that a remediated control works before the finding is closed, and reopen it where the fix does not hold. Provide credible challenge to control owners, with written findings, severity ratings, agreed actions, and owners. Report testing results, remediation status, coverage against plan, and thematic findings to the Risk Committee and to the Boards of…