12 Sep
|
Community First
|
New South Wales
12 Sep
Community First
New South Wales
Community First Bank is one of Australia's leading customer-owned banks, proudly serving members and communities since 1959. With more than 80,000 members, over $2.4 billion in assets, and a strong presence across Sydney, the Illawarra, Sutherland Shire, Western Sydney and the Hunter region, Community First Bank is built on a simple philosophy: people helping people. As a member-owned organisation, we reinvest in delivering exceptional service, competitive products, and meaningful community support rather than generating profits for external shareholders. Our purpose is to help our members achieve their financial goals through trusted relationships, innovation, and a genuine commitment to the communities where we live and work.
For careers at Community First Bank, you'll join a values-driven organisation that puts people first, celebrates collaboration, and empowers employees to make a real difference in the lives of members and local communities.
About the role
Community First distributes financial products and services across a range of channels Australia wide. Our store locations stretch from the Sutherland Shire, the Hunter Region, Western Sydney and in between. Community First is member owned and run for the benefit of members, not for external shareholder profit. Our mission is to help members achieve their financial goals by building relationships for mutual benefit. Community First therefore strives to offer members something different to traditional banking institutions and puts members first in the delivery of products and services which help them achieve their personal financial goals. Community First also owns Easy Street – an online only provider of savings and loan products that offer simple value and appeal to people who prefer to do their banking online themselves.
The Legal & Compliance Manager is the Bank’s principal internal legal advisor and compliance leader within the Line 2 function. The role provides independent oversight, challenge and guidance on the Bank’s legal, regulatory, compliance, privacy and governance obligations—while ensuring that Line 1 owns and manages legal and compliance risks and controls.
As a newly merged mutual bank with uplifted prudential expectations (including CPS 230 operational resilience, CPS 234 cybersecurity, CPS 220 risk management, AML/CTF obligations and enhanced ASIC regimes), the role ensures the Bank operates safely, ethically and in compliance with all relevant laws and regulations.
This role leads the design, maintenance and embedding of the Bank’s Legal Risk Management Framework and Compliance Management Framework, including the obligations register, policy governance, compliance monitoring, breach oversight, horizon scanning and regulatory change implementation. It also strengthens organisational capability, fosters integrity and supports safe strategic growth.
What you'll do
Legal Advisory & Leadership (Internal Legal Function)
- Act as the Bank’s principal internal legal advisor, delivering timely and practical legal advice on corporate, regulatory, privacy, consumer, lending, contracts, commercial, property, banking and governance matters.
- Lead and maintain the Legal Risk Management Framework, including legal risk identification,
contract governance, legal risk assessments and legal incident management.
- Partner with business units on reviews of current products, digital initiatives, contracts, third-party arrangements, technology solutions and outsourcing arrangements.
- Oversee internal and external dispute resolution including oversight of AFCA matters.
- Support governance frameworks including conflicts of interest, delegations, document execution, and powers of attorney (as required).
- Manage relationships with external legal service providers and the internal legal budget.
- Monitor and interpret changes to legislation, case law, industry standards and codes with Bank-wide impact.
- Act as spokesperson or regulatory point of contact on legal matters where appropriate.
Compliance Framework & Governance
- Own and maintain the Compliance Management Framework, ensuring alignment with APRA, ASIC, AUSTRAC, OAIC and industry standards.
- Maintain the obligations register / obligations library, ensuring obligations are accurately interpreted, mapped to controls, assigned to Line 1 owners and kept current.
- Oversee compliance monitoring, thematic reviews, compliance assurance and Line 1 control attestation processes.
- Drive clear accountability for compliance obligations within Line 1, ensuring policy, control and process ownership is understood and discharged.
- Ensure the Bank complies with all relevant obligations, including:
- APRA Prudential Standards (CPS 220, CPS 230, CPS 234, CPS 510, CPS 520)
- AML/CTF Act and Rules
- ASIC Act, Corporations Act, RG 78, DDO, consumer protection requirements
- Privacy Act and APPs
- Customer Owned Banking Code of Practice
- Promote a strong compliance culture and uplift in regulatory understanding across Line 1.
Regulatory Change, Horizon Scanning & Emerging Regulation
- Lead horizon scanning for legislative, regulatory, prudential and industry changes, including upcoming reforms and regulatory expectations.
- Maintain the Regulatory Change Register, capturing impacts, interpretation, responsible owners, implementation milestones and deadlines.
- Conduct regulatory impact assessments and partner with Line 1 to implement required changes sustainably and on time.
- Provide concise, forward-looking insights to ELT, Risk Committee and Board on emerging legal, compliance, privacy, industry and prudential risks.
- Ensure the Bank remains prepared for and compliant with major regulatory developments such as CPS 230, CPS 234 uplift, Privacy Act reforms, anti-scam obligations, FAR, DDO and AML/CTF enhancements.
Incident Management & Regulatory Breach Oversight
- Own and oversee the Bank’s Legal, Compliance, Privacy and Regulatory Incident Management Frameworks.
- Provide Line 2 oversight of compliance incidents, legal incidents, privacy incidents, AML/CTF breaches, regulatory incidents,
and reportable situations, ensuring Line 1 owns investigation, remediation and controls.
- Review incident classification and severity assessments, ensuring accuracy and consistency across the Bank.
- Ensure timely and accurate notifications to regulators including:
- ASIC Reportable Situations (RG 78)
- APRA breach notifications (CPS )
- AUSTRAC SMRs and TTRs
- OAIC Notifiable Data Breach (NDB) notifications
- Oversee quality of root cause analysis, remedial actions and customer remediation.
- Maintain the Compliance Incident and Breach Register and ensure reporting to ELT, Risk Committee, Audit Committee and the Board.
- Analyse incident themes, systemic issues and forward indicators to support continuous improvement.
- Challenge Line 1 compliance assessments, breach investigations, control effectiveness assessments and proposed remediation plans.
- Review the quality and completeness of Line 1 compliance controls, operationalisation of legal requirements and adherence to policies.
- Oversee compliance attestations, Line 1 obligations self‑assessments and thematic reviews.
- Ensure Line 1 appropriately escalates legal, compliance and regulatory risks in accordance with governance expectations.
Policy Management & Governance
- Lead the Bank’s policy governance framework, ensuring policies and standards are current, aligned, consistent and accessible.
- Maintain a central policy register and support Line 1 policy owners with interpretation and implementation advice.
- Ensure policies reflect regulatory, prudential and legal changes and drive consistent policy governance across the Bank.
Regulatory Engagement & Reporting
- Act as primary or delegated regulator contact for legal, compliance, AML/CTF and privacy matters.
- Maintain a central Regulatory Engagement Register, including all regulatory interactions, notices, requests, reviews and commitments.
- Coordinate high-quality responses to regulatory notices, inquiries, data requests, thematic reviews and consultations.
- Prepare clear and concise reports for ELT, Risk Committee, Audit Committee and the Board covering:
- breaches and incidents
- legal risks and disputes
- emerging regulatory risks
- compliance maturity and trends
- regulatory change status
Training, Capability & Culture Uplift
- Develop and deliver training on legal obligations, compliance risk, privacy, AML/CTF, incident management, breach reporting and governance requirements.
- Uplift Line 1 capability and understanding of their legal and compliance responsibilities.
- Promote a solid culture of ethical conduct, transparency and regulatory accountability.
Qualifications
- Bachelor of Laws (LLB) or equivalent.
- 8 years' experience in legal, compliance or regulatory roles within financial services or a regulated environment.
- APRA Prudential Standards (CPS 220, CPS 230, CPS 234, CPS 510, CPS 520)
- Experience overseeing compliance, legal, privacy or regulatory incidents and breach reporting.
- Experience drafting, reviewing and negotiating commercial and financial services contracts.
- Experience engaging with regulators (APRA, ASIC, AUSTRAC, OAIC) and preparing regulatory submissions or responses.
#J-18808-Ljbffr
📌 Legal Compliance Manager (New South Wales)
🏢 Community First
📍 New South Wales