Skip to content

Open nowPosted 11 hours ago

Group AI Governance, Risk and Compliance Manager (DPO)

Strata18 open roles

Where
London, Greater London, United Kingdom
Work mode
Hybrid
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowGroup AI Governance, Risk and Compliance Manager (DPO)Strata · London, Greater London, United Kingdom
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Strata's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. Strata postings stay open a median of 23 days.

Share of postings closed within
  1. 1.9%1 day
  2. 3.8%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.1%30 days
This job: posted 11 hours ago

Strata median: 23 days open

The posting

Job Title: Group AI Governance, Risk and Compliance Manager (DPO)

Department: Group IT

Location: London – Hybrid (plus multi-site travel as required)

We are Strata!

Strata Group is a collective of award-winning specialist agencies, united by one ambition: to help people and brands on a mission create meaningful, memorable and measurable experiences.

Across the Group, we bring together expertise spanning strategy, creative, experiential, events, production, technical delivery, audience engagement, incentives and specialist services. Together, we offer clients one partner, uniting experts – giving them access to the right combination of people and capabilities for every challenge.

Job Overview

The Group AI Governance, Risk & Compliance Manager is responsible for establishing, maintaining and continuously improving the Group's governance, compliance, information security, data protection and AI governance frameworks.

Acting as the Group's Data Protection Officer (DPO), the role will ensure compliance with UK GDPR, Data Protection legislation, Cyber Essentials, ISO certifications (including ISO 9001, 14001, 20121, 27001 and future ISO standards), and internal policies and procedures.

The role will work across all Strata Group businesses to promote a culture of security, privacy, responsible AI use and compliance, ensuring that employees understand their responsibilities and that appropriate controls, policies and processes are consistently applied.

This position will serve as the primary advisor to senior management on governance, risk, compliance, privacy, information security and AI governance matters.

Key Responsibilities

Governance & Compliance

  • Develop, implement and maintain the Group Governance, Risk and Compliance (GRC) framework.
  • Own the governance roadmap and compliance programme across all Group companies.
  • Monitor changes to legislation, regulations and industry standards and assess impact on the business.
  • Ensure compliance with relevant legal, contractual and regulatory obligations.
  • Conduct regular compliance reviews, audits and control assessments.
  • Maintain compliance registers, risk registers, ROPA and remediation plans.
  • Provide governance reporting and assurance updates to Executive Leadership and the Board.

Data Protection Officer (DPO) Responsibilities

  • Act as the Group's appointed Data Protection Officer.
  • Serve as the primary point of contact for the Information Commissioner's Office (ICO).
  • Maintain and oversee Records of Processing Activities (ROPA).
  • Conduct Data Protection Impact Assessments (DPIAs).
  • Ensure GDPR and privacy requirements are embedded into business processes.
  • Manage data subject access requests, data retention compliance and privacy governance.
  • Lead investigations into data protection incidents and breaches.
  • Provide expert guidance on international data transfers and data-sharing arrangements.
  • Oversee privacy-by-design and privacy-by-default practices across all business systems and projects.

AI Governance

  • Develop, implement and maintain a Group AI governance framework covering the responsible assessment, approval, deployment and use of AI systems and services.
  • Maintain a central inventory of approved AI tools, systems and use cases, with defined business ownership, purpose, data classification, risk rating and review arrangements.
  • Establish policies, standards and guidance for responsible AI use, including acceptable use, human oversight, transparency, record keeping, data protection, information security and intellectual property.
  • Coordinate proportionate AI risk and impact assessments for new use cases and material changes, including privacy, security, legal, ethical, reputational, operational and client risks.
  • Define approval and assurance controls for AI-generated outputs, ensuring appropriate human review, validation and accountability before internal, client or public use.
  • Set due diligence, contractual and ongoing assurance requirements for AI suppliers and third-party AI services, including data use, model training, confidentiality, ownership, security and incident notification.
  • Monitor relevant AI legislation, regulatory guidance and recognised standards, and translate changes into practical Group policies, controls and operating requirements.
  • Establish processes for reporting, investigating and learning from AI-related incidents, misuse, inaccurate or unintended outcomes, policy breaches and control failures.
  • Develop AI literacy and role-based awareness so employees understand approved tools, permitted uses, limitations, risks, human-review responsibilities and escalation routes.
  • Provide regular reporting to Executive Leadership and the Board on AI adoption, material risks, policy compliance, incidents, exceptions and remediation actions.

Information Security & ISO Management

  • Own and maintain ISO certification programmes including ISO 9001, 14001, 20121, 27001 and other relevant standards.
  • Coordinate internal and external audits.
  • Manage corrective actions and continuous improvement plans.
  • Ensure security policies, standards and procedures remain current and effective.
  • Support Cyber Essentials and Cyber Essentials Plus certification activités.
  • Develop security governance controls aligned to recognised best practices.
  • Work alongside internal IT teams and third-party providers to ensure compliance with security requirements.

Risk Management

  • Develop and maintain the Group information security risk management framework.
  • Facilitate risk assessments across business functions.
  • Maintain risk treatment and mitigation plans.
  • Track remediation actions and provide visibility to leadership.
  • Support business continuity and disaster recovery governance activities.

Training & Employee Awareness

  • Develop and deliver security, compliance, privacy and responsible AI awareness programmes.
  • Ensure mandatory compliance training is completed and tracked.
  • Create engaging awareness campaigns addressing cyber security, phishing, GDPR, information governance and responsible AI use.
  • Promote a positive culture of accountability for data protection and security.
  • Provide guidance and coaching to managers and employees on compliance responsibilities.

Policy & Process Management

  • Maintain ownership of all security, privacy, AI governance and wider governance policies.
  • Establish consistent standards across all Strata Group companies.
  • Ensure policies are regularly reviewed, approved and communicated.
  • Drive policy adoption and compliance throughout the organisation.
  • Maintain evidence repositories to support audits and certification activities.

Key Stakeholders

  • Board of Directors
  • Group Head of IT
  • Managing Directors
  • HR Team
  • Finance Team
  • Legal Advisors
  • Third-Party Auditors
  • Managed Service Providers
  • Employees across all Strata Group companies

The successful candidate will be able to demonstrate the following:

  • Proven experience in Governance, Risk and Compliance (GRC).
  • Experience acting as a Data Protection Officer or privacy lead.
  • Strong working knowledge of UK GDPR and Data Protection legislation.
  • Experience managing ISO 9001, 14001, 20121, 27001 certification and audit programmes.
  • Experience conducting risk assessments and compliance reviews.
  • Experience developing policies, standards and governance frameworks.
  • Experience delivering security awareness and training programmes.
  • Strong stakeholder management and communication skills.
  • Practical knowledge of responsible AI principles, organisational AI risks and emerging AI regulation and standards.
  • Experience developing AI policies, AI risk or impact assessments, approved-use registers, or third-party AI assurance controls.

Desirable Qualifications

  • Certified Data Protection Officer (DPO)
  • ISO 9001, 14001, 20121, 27001 Lead Implementer or Lead Auditor
  • CIPP/E
  • CIPM
  • CISSP
  • CISM
  • CRISC
  • Cyber Essentials Assessor (desirable)

Success Measures

Within the first 12 months the role will:

  • Establish a Group-wide Governance, Risk and Compliance framework.
  • Successfully maintain and expand ISO certification programmes.
  • Demonstrate measurable improvements in security and privacy compliance.
  • Establish an approved AI inventory, proportionate risk-assessment process and clear governance reporting for material AI use cases.
  • Increase employee completion rates for compliance training.
  • Reduce audit findings and compliance risks.
  • Establish clear governance reporting for Executive Leadership and the Board.
  • Create a culture where security, privacy, compliance and responsible AI are embedded into day-to-day operations.

Employee Benefits

  • 25 days annual leave, plus usual Bank Holidays
  • Birthday day off
  • Private Health Insurance*
  • Workplace pension scheme
  • Death in service scheme
  • Cycle to work scheme
  • Hybrid working arrangement
  • Regular social events

*Upon successful completion of a 6-month probation period

Our Principles

We are a people-first brand experience agency with a set of core principles that guide our every action by measuring:

A win for the client Client success is at the forefront of everything we do. We measure our success by the impact we make for our clients. We strive to exceed your expectations, delivering moments that matter with results that matter.

A win for the company We believe in long-term partnerships and sustainable growth. When your business prospers, so does ours. Our commitment to excellence and innovation means we’re always ahead of the curve, offering you the best brand experiences.

A win for the team Our team is the lifeblood of our agency. We celebrate diversity, promote collaboration, and foster an inclusive culture where every team member feels valued and empowered. When our team thrives, their passion and dedication is reflected in everything we deliver.

A win for you Whether you’re engaging us for your events, already fostering a career at Strata, or considering one, our goal is to create a win for you. We’re dedicated to providing our employees with an enriching workplace that supports their growth and well-being. For our clients, a win means achieving your objectives and making your brand shine.

A win for the planet We are committed to making environmentally responsible choices in our work. We recognise our responsibility to minimise our impact on the planet and contribute to a sustainable future. From eco-friendly event practices to conscious resource management, we aim to create events that are a win for the environment.

Diversity at Strata

At Strata, people are at the heart of who we are.

We recognise and value the diverse and unique perspectives, experiences, and backgrounds that each individual brings.

We are committed to fostering a workplace where everyone feels respected, heard, valued, and empowered. We strive to create an innovative, creative, and inclusive environment where all employees and applicants can thrive.

We welcome applications from all suitably qualified individuals, regardless of age, disability, gender reassignment, marital or civil partnership status, pregnancy or maternity, race, religion or belief, sex, or sexual orientation. Recruitment decisions are based solely on merit, qualifications, and business needs.

Embracing diversity isn't just our goal, it's our strength, driving us towards a more inclusive future.

At Strata, we are proud to be a Disability Confident employer, committed to creating an inclusive and accessible workplace where everyone can thrive. We actively promote equal opportunities and support individuals with disabilities throughout their careers. As part of our recruitment process, we encourage candidates to let us know if they require any reasonable adjustments - our team is committed to ensuring a fair, supportive, and inclusive experience from application through to employment.

https://stratacreate.com/

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Strata's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Strata's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Strata's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.