Fitness Requirements for Key Roles: The Regulator Screens Before You Do
In a regulated entity, certain positions carry qualification requirements, so the first filter in hiring is not your job description but the fitness standard attached to the office. These requirements typically reach directors, senior officers and specific compliance functions, and they look in three directions: relevant experience and years in the field; integrity and record; and relationships that could compromise independent judgement. Which offices are caught, how demanding the standard is, and whether prior notification or approval is needed all depend on the licence you hold and on the regulator's current rules, which differ substantially between business categories. Do not copy another company's org chart on the assumption that the same requirements apply.
The effect on hiring lead time is structural rather than incidental. An ordinary vacancy runs search, interview, offer, start. A key position adds two further stages: assembling documentation — curriculum vitae, supporting certificates, clearance-type records, declarations — and the regulator's own processing time. Key roles therefore have to be planned backwards from the launch date, with a reserve candidate identified in advance, because if the office is a precondition to operating then a failed appointment is a stopped business rather than a delayed one.
The second overlooked point is concurrent office-holding. Certain functions are expected to be independent, and doubling up erodes that directly. A finance head who also serves as compliance officer, a business head who also owns risk, one person responsible for both operations and internal audit — these are difficult to explain during an examination. Three practical controls: write each regulated office's qualification, reporting line and incompatible roles into the job description; update the org chart and any filed particulars whenever a personnel change occurs; and name a deputy for every key office who has enough live exposure to step in.
When a foreign national holds a key role, two sets of requirements stack. One is the regulator's fitness standard for the office; the other is the permission to work in the Philippines — the sequence of employment permit and work visa, the processing rhythm, and localisation expectations, set out in employing foreign nationals and the alien employment permit. Some positions carry an obligation to train a local understudy; see foreign worker ratios and understudies. The two timelines do not align themselves; put them on one chart. The same backward-planning discipline appears in BPO ramp planning; see BPO staffing. Take advice on your own facts; this is not legal advice.
Compliance and AML Roles Are Licence Conditions, Not Deferrable Headcount
In regulated financial activity, the compliance and anti-money-laundering functions are usually part of the conditions of entry — not something to add once volume justifies it, but something without which the business should not launch. Three characteristics recur: a named accountable officer, a reporting line independent of the business, and duties to report both to the regulator and to the governing body. Recruiting for these as ordinary back-office vacancies is the most expensive misjudgement in the sector.
Independence is the core of this line, and independence is produced by structure, not by attitude. Three arrangements damage it immediately: a compliance head reporting to the business head; compliance performance measured against commercial targets; and compliance opinions that the business can override unilaterally with no record. The minimum workable structure routes the compliance reporting line past the business to the governing body, separates compliance appraisal criteria from commercial metrics, and requires every overridden compliance opinion to be documented in writing with the decision-maker and the basis recorded.
People alone are not the requirement; people plus policy plus records are. This function usually has to produce four artefacts on demand: written terms of reference for the role, training records covering induction and periodic refreshers, an internal escalation route for suspicious matters with the handling record, and periodic self-assessment and reporting. Training records are the item most often missing — many companies deliver the training but keep no attendance sheet, no version of the material and no assessment result, which during an examination is indistinguishable from not having done it. General record-keeping practice is in keeping employment records, and the boundaries for handling personal data are in data privacy basics for companies.
On team size, the only honest answer is that it scales with business complexity, not with a percentage of headcount. What drives the requirement is the number of product lines and channels, the customer mix, transaction volume and the degree of automation — not how many people the company employs. Three symptoms of an under-resourced function: compliance staff working sustained overtime on routine checks; a growing backlog of unresolved escalations; and compliance staff simultaneously carrying day-to-day support or operations duties. When those appear, the options are to add people or to reduce complexity; there is no third route. Outsourcing boundaries are covered further below. Keeping compliance role definitions and records for several entities or licences in one managed set of books is routine compliance management work. Take advice on your own facts; this is not legal advice.
Screening and Conflict Declarations: A Continuing Duty, Not a One-Off Check at Hiring
Personnel vetting in fintech runs on two lines — pre-employment screening, and conflict-of-interest declarations during employment — and the second is the one most companies are missing. Screening answers what this person's record is. Declarations answer who this person is connected to now. The first happens once; the second must repeat on a cycle and update immediately when circumstances change.
Grade screening depth by how much data and money the role touches, rather than applying one standard to everyone. Roles that can view customer records, execute transactions, change parameters or approve disbursements warrant deeper checks and a more senior approver; purely functional roles do not need the same depth. Screening has legal limits: written consent is required, verifiable scope is narrow, and former employers commonly confirm only dates and position — see lawful background checking. The results are themselves personal data, so retention period, access list and disposal method must be settled at the same time; see company obligations under the data privacy framework.
Conflict declarations need a form and a cadence; an instruction to disclose voluntarily is not a control. Five categories recur: the employee or a close relative employed by or holding an interest in a competitor, vendor, channel partner or major client; outside employment or a personal business related to the company's activity; gifts and hospitality beyond ordinary business courtesy; participation in approving or pricing anything involving a related party; and personal account activity that could be misread against company business. Practical design: declare on joining, review at least annually, update on change, collect through compliance rather than the line manager, and define in advance what happens after a declaration — recusal, a different approver, or a change of duties.
Finally, the purpose is risk management, not identity screening. Collecting personal information unrelated to the role is both non-compliant and protectively worthless. Three disciplines: collect only what relates to the role's risk; state the reason in the consent form; and where something surfaces, give the person an opportunity to explain before deciding, because an immediate exclusion often manufactures an avoidable dispute. The correct sequence when misconduct is discovered is in handling suspected employee misconduct. The same logic of a qualification attaching to the individual appears in property, where it takes the form of a salesperson's licence; see property developer staffing. Take advice on your own facts; this is not legal advice.
Segregation of Duties: One Person Cannot Initiate and Approve — Access Design Is Organisation Design
Split who can initiate, who can approve, who can change parameters and who can read data into four distinct entitlements, and make sure they do not land on one person. This is an organisational decision, not an IT one. Most losses and data incidents in fintech are not external breaches; they happen where one role accumulated entitlements that should never have combined. An org chart drawn wrongly is an internal control drawn wrongly.
Build a role-to-entitlement matrix with four separation lines that each hold on their own. First, initiation from approval: whoever submits a transaction, changes a settlement account or adjusts a limit cannot be the person approving it. Second, data rights from money rights: a role that can export customer records in bulk should not also move funds. Third, production from development: developer and tester access to production must be controlled, temporary and logged. Fourth, execution from review: nobody audits their own records. These are obvious, and the usual failure is a temporary grant nobody revoked, which is why every exception must carry automatic expiry.
What a small team does about this is the sector's most honest question. Early on there are not enough people for strict separation. The answer is not to abandon it but to substitute three controls: dual control instead of two departments, so critical actions require two named people acting together; system limits that keep what one person can complete alone inside a low-risk band, with anything above the threshold forced into review; and a higher frequency of after-the-fact review, recorded, for roles that genuinely cannot be split. Write down who may deviate, under what conditions, and what record the deviation leaves, rather than assuming nobody will.
Three moments must be wired into HR process: grant on hire, change on transfer, revoke on exit. Transfer is where it usually breaks — the new entitlements are added, the old ones are never removed, and after a few moves that individual holds more access than anyone intended. Two controls work: define entitlements against roles rather than individuals so a move recalculates access automatically; and run a full quarterly review in which each role owner confirms line by line. The same role-based approach is a contractual requirement in BPO work; see BPO staffing. Policies also have to be published to employees to be usable; what makes a handbook effective is in writing an enforceable employee handbook. Take advice on your own facts; this is not legal advice.
Outsourced Support and Third-Party Seats: You Can Outsource the Work, Not the Responsibility
Support, collections, parts of operations and development can be outsourced, but responsibility towards customers and the regulator stays with you — so the outsourcing contract must carry people clauses, not only service levels. The supply-side view is already covered in the fintech supply chain; this section covers only what the people clauses must say and how to verify them.
Six items belong in the contract when third parties touch your customers. One, the population of people permitted to access customer data and how that roster is managed. Two, the screening standard and whether you may inspect evidence of its execution. Three, training obligations — particularly on data handling, complaint handling and the boundaries of scripted communication — and retention of the training records. Four, timelines for granting and revoking access, with confirmations returned. Five, restrictions and notice obligations on sub-contracting by the provider. Six, your audit right: whether you may attend, sample records and at what frequency. Without the sixth, the first five are paper.
There is a hard line between lawful contracting and labour-only contracting, and crossing it makes you the real employer. The tests look at whether the provider has substantial capital and an independent business, where control actually sits, and whether the work contracted out is your core activity; the full framework is in agency and contracting rules, and the wider menu of engagement models is in HR outsourcing options. Two points are specific to fintech: where outsourced agents work inside your systems, communicate under your name and are managed against your metrics, the outsourced form is difficult to sustain; and outsourcing a regulated core function — compliance judgement itself, for example — is a different order of question that is often not permitted or requires prior arrangement, subject to the regulator's current rules.
Collections is the outsourced activity that fails most publicly, and when it fails, reputational and regulatory attention usually arrive together. Whether in-house or outsourced, settle four things in advance: who may be contacted and within what hours; the permitted script and the list of prohibited conduct; retention of call and message records; and a complaint intake and review mechanism. Put the prohibited conduct into the breach provisions of the contract rather than only into the training deck — that is the only version with teeth. Take advice on your own facts; this is not legal advice. Consolidating provider people clauses, audit records and compliance files into one managed set of books is standard compliance management work.
Exit and Transfer: Revoke Access, Capture the Handover, and Make Post-Employment Restrictions Real
A fintech exit process has to achieve three things at once: access revoked immediately, duties genuinely picked up by someone, and post-employment restrictions that are actually workable. Miss any one and the exposure stays with the company. Departure here is not a headcount event; it is a question of whether an access chain closed and whether an accountability was handed over.
First, revocation with a timestamp and a confirmation. The fixed actions are: disable every system account; withdraw production and administrative console access; rotate shared credentials; unbind multi-factor devices; replace the person's role in every approval workflow — the item most often missed, where someone has left but still sits in the chain; recover equipment and access cards; and record completion. On sequence, the gap between notice and disablement is the largest window of exposure, so key roles should lose sensitive access at the moment notice is given. Where clearance itself stalls is covered in resignation and clearance.
Second, a handover that leaves verifiable artefacts rather than a conversation. This matters most for regulated offices. A compliance, risk or finance handover should produce at minimum: a list of open matters and their status; unresolved escalations and any external correspondence in progress; tasks sitting in systems under that person's name; and an index of dealings with regulators or external bodies. Succession and notification for key offices: where an office carries a qualification requirement or a filing obligation, the departure itself may trigger a notification and a succession arrangement, subject to the regulator's current rules — so the leaving date cannot live only in the HR system.
Third, distinguish three different post-employment instruments instead of merging them into one clause. Confidentiality restrains information and ordinarily continues after the relationship ends. A non-competition restraint restrains where the person may go, and whether it will be recognised in the Philippines depends on scope, duration, territory and consideration — see are non-compete clauses enforceable. Reassigning duties during the notice period, so that a departing employee no longer touches sensitive systems, is a management arrangement that only works if the contract and policy provide for it. All three depend on a contract that holds; general drafting is in employment contracts that hold up. Enforceability turns on your facts — take legal advice; this is not legal advice. For contrast, the same person-level qualification logic appears as licences and age verification in property developer staffing and agricultural staffing. The regulatory frame for crypto-asset activity is in crypto rules in the Philippines.
Frequently Asked Questions
Which fintech roles are not ours to fill freely?
Can compliance and AML hiring wait until the business is bigger?
How large should the compliance team be — is there a ratio?
How should conflict-of-interest declarations work?
Our team is too small to separate initiation from approval — what then?
If support is outsourced, is a failure still ours?
A key officer is leaving — beyond paperwork, what matters?
Let’s talk through your situation — free
Every company is different. Leave your details and a Chinese-speaking advisor will get back within 1 business day with practical, industry-specific guidance and a transparent quote.
Get help with Compliance → Free consultation
