hirq
← All jobs

Strata

Group AI Governance, Risk and Compliance Manager (DPO)

London, Greater London, United Kingdom · Hybrid · fulltime_permanent · Operations

Apply well, not just fast

Create a free account and upload your resume to get a match score, keyword gaps, a tailored resume, a cover letter and interview prep for this job.

About the role

CybersecurityComplianceRisk ManagementLeadership
Job Title: Group AI Governance, Risk and Compliance Manager (DPO) Department: Group IT Location: London – Hybrid (plus multi-site travel as required) We are Strata! Strata Group is a collective of award-winning specialist agencies, united by one ambition: to help people and brands on a mission create meaningful, memorable and measurable experiences. Across the Group, we bring together expertise spanning strategy, creative, experiential, events, production, technical delivery, audience engagement, incentives and specialist services. Together, we offer clients one partner, uniting experts – giving them access to the right combination of people and capabilities for every challenge. Job Overview The Group AI Governance, Risk & Compliance Manager is responsible for establishing, maintaining and continuously improving the Group's governance, compliance, information security, data protection and AI governance frameworks. Acting as the Group's Data Protection Officer (DPO), the role will ensure compliance with UK GDPR, Data Protection legislation, Cyber Essentials, ISO certifications (including ISO 9001, 14001, 20121, 27001 and future ISO standards), and internal policies and procedures. The role will work across all Strata Group businesses to promote a culture of security, privacy, responsible AI use and compliance, ensuring that employees understand their responsibilities and that appropriate controls, policies and processes are consistently applied. This position will serve as the primary advisor to senior management on governance, risk, compliance, privacy, information security and AI governance matters. Key Responsibilities Governance & Compliance - Develop, implement and maintain the Group Governance, Risk and Compliance (GRC) framework. - Own the governance roadmap and compliance programme across all Group companies. - Monitor changes to legislation, regulations and industry standards and assess impact on the business. - Ensure compliance with relevant legal, contractual and regulatory obligations. - Conduct regular compliance reviews, audits and control assessments. - Maintain compliance registers, risk registers, ROPA and remediation plans. - Provide governance reporting and assurance updates to Executive Leadership and the Board. Data Protection Officer (DPO) Responsibilities - Act as the Group's appointed Data Protection Officer. - Serve as the primary point of contact for the Information Commissioner's Office (ICO). - Maintain and oversee Records of Processing Activities (ROPA). - Conduct Data Protection Impact Assessments (DPIAs). - Ensure GDPR and privacy requirements are embedded into business processes. - Manage data subject access requests, data retention compliance and privacy governance. - Lead investigations into data protection incidents and breaches. - Provide expert guidance on international data transfers and data-sharing arrangements. - Oversee privacy-by-design and privacy-by-default practices across all business systems and projects. AI Governance - Develop, implement and maintain a Group AI governance framework covering the responsible assessment, approval, deployment and use of AI systems and services. - Maintain a central inventory of approved AI tools, systems and use cases, with defined business ownership, purpose, data classification, risk rating and review arrangements. - Establish policies, standards and guidance for responsible AI use, including acceptable use, human oversight, transparency, record keeping, data protection, information security and intellectual property. - Coordinate proportionate AI risk and impact assessments for new use cases and material changes, including privacy, security, legal, ethical, reputational, operational and client risks. - Define approval and assurance controls for AI-generated outputs, ensuring appropriate human review, validation and accountability before internal, client or public use. - Set due diligence, contractual and ongoing assurance requirements for AI suppliers and third-party AI services, including data use, model training, confidentiality, ownership, security and incident notification. - Monitor relevant AI legislation, regulatory guidance and recognised standards, and translate changes into practical Group policies, controls and operating requirements. - Establish processes for reporting, investigating and learning from AI-related incidents, misuse, inaccurate or unintended outcomes, policy breaches and control failures. - Develop AI literacy and role-based awareness so employees understand approved tools, permitted uses, limitations, risks, human-review responsibilities and escalation routes. - Provide regular reporting to Executive Leadership and the Board on AI adoption, material risks, policy compliance, incidents, exceptions and remediation actions. Information Security & ISO Management - Own and maintain ISO certification programmes including ISO 9001, 14001, 20121, 27001 and other relevant standards. - Coordinate internal and external audits. - Manage corrective actions and continuous improvement plans. - Ensure security policies, standards and procedures remain current and effective. - Support Cyber Essentials and Cyber Essentials Plus certification activités. - Develop security governance controls aligned to recognised best practices. - Work alongside internal IT teams and third-party providers to ensure compliance with security requirements. Risk Management - Develop and maintain the Group information security risk management framework. - Facilitate risk assessments across business functions. - Maintain risk treatment and mitigation plans. - Track remediation actions and provide visibility to leadership. - Support business continuity and disaster recovery governance activities. Training & Employee Awareness - Develop and deliver security, compliance, privacy and responsible AI awareness programmes. - Ensure mandatory compliance training is completed and tracked. - Create engaging awareness campaigns addressing cyber security, phishing, GDPR, information governance and responsible AI use. - Promote a positive culture of accountability for data protection and security. - Provide guidance and coaching to managers and employees on compliance responsibilities. Policy & Process Management - Maintain ownership of all security, privacy, AI governance and wider governance policies. - Establish consistent standards across all Strata Group companies. - Ensure policies are regularly reviewed, approved and communicated. - Drive policy adoption and compliance throughout the organisation. - Maintain evidence repositories to support audits and certification activities. Key Stakeholders - Board of Directors - Group Head of IT - Managing Directors - HR Team - Finance Team - Legal Advisors - Third-Party Auditors - Managed Service Providers - Employees across all Strata Group companies