1. Own the E2E merchant risk framework
Own the merchant risk management framework end-to-end - KYB/KYC/AML, fraud and quasi-merchant detection, ongoing monitoring, and the feedback loop that connects QC findings back to policy and model.
Set and maintain risk rules, thresholds and merchant risk tiers; define what gets auto-approved, what goes to Watch, and what must reach a human - and own the consequences of where those lines are drawn.
Build the policy and escalation architecture: decision rights, escalation paths by severity, SLA per tier, and the audit trail that evidences control effectiveness to Compliance, Legal and regulators.
Own risk outcomes, not just process compliance: risk control kept under x% while merchant base and manual-review reduction both scale.
2. Lead the QC organisation (Back-office & Field) at scale
Lead -36 people across two QC arms: Back-office QC (6) for profile and case review, and Field Operations QC (30) for on-site verification, POSM and merchant-facing checks - through Team Leaders and Supervisors.
Standardise how QC is done: SOPs, sampling logic, decision playbooks, calibration sessions, and a shared QC quality bar so two reviewers reach the same verdict on the same case.
Build the levelling, competency and coaching system that lets the team grow without diluting judgement; develop successors so escalation does not bottleneck on one person.
Manage productivity and quality together - never one at the expense of the other - through KPIs, calibration, and root-cause review of QC misses.
3. Data-driven decision making
Define the metric set for risk QC - risk rate, false positive / false negative, manual-review ratio, QC accuracy, turnaround time, escalation volume - and own the dashboards behind them.
Read and interrogate data directly (SQL/BI): segment risk by merchant type, industry, geography and channel; find where controls over- or under-fire before someone else does.
Translate analysis into decisions: rule changes, threshold moves, sampling reallocation, or a case for more automation - each with a stated expected impact and a follow-up measurement.
Bring evidence, not anecdote, to leadership: quantify residual risk (missed cases, wrongly-flagged cases) and the cost of each control choice.
4. Product thinking, without being a
product ownerThink in systems and flows rather than tickets: understand how a rule change ripples into onboarding conversion, field workload, merchant experience and complaint volume.
Write clear problem statements and requirements for internal tooling (QC workbench, case queue, escalation workflow, dashboards) and prioritise them against risk impact.
Balance automation against judgement: decide deliberately where a human must stay in the loop, and defend that boundary with data.
5. Stakeholder management & risk culture
Partner with Cell team (Product, AI, Risk) and Cross team (Legal, Tech ...) so controls are embedded in the flow instead of bolted on afterwards.
Represent risk in leadership forums: report control health, escalate systemic exposure early, and make trade-offs explicit rather than absorbing them silently.
Raise the organisation's risk literacy - typology briefings, case reviews, post-incident learning - so risk thinking is shared, not centralised in one team.