Strata
Group AI Governance, Risk and Compliance Manager (DPO)

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Job Title: Group AI Governance, Risk and Compliance Manager (DPO)
Department: Group IT
Location: London – Hybrid (plus multi-site travel as required)
We are Strata!
Strata Group is a collective of award-winning specialist agencies, united by one ambition: to help people and brands on a mission create meaningful, memorable and measurable experiences.
Across the Group, we bring together expertise spanning strategy, creative, experiential, events, production, technical delivery, audience engagement, incentives and specialist services. Together, we offer clients one partner, uniting experts – giving them access to the right combination of people and capabilities for every challenge.
Job Overview
The Group AI Governance, Risk & Compliance Manager is responsible for establishing, maintaining and continuously improving the Group's governance, compliance, information security, data protection and AI governance frameworks.
Acting as the Group's Data Protection Officer (DPO), the role will ensure compliance with UK GDPR, Data Protection legislation, Cyber Essentials, ISO certifications (including ISO 9001, 14001, 20121, 27001 and future ISO standards), and internal policies and procedures.
The role will work across all Strata Group businesses to promote a culture of security, privacy, responsible AI use and compliance, ensuring that employees understand their responsibilities and that appropriate controls, policies and processes are consistently applied.
This position will serve as the primary advisor to senior management on governance, risk, compliance, privacy, information security and AI governance matters.
Key Responsibilities
Governance & Compliance
- Develop, implement and maintain the Group Governance, Risk and Compliance (GRC) framework.
- Own the governance roadmap and compliance programme across all Group companies.
- Monitor changes to legislation, regulations and industry standards and assess impact on the business.
- Ensure compliance with relevant legal, contractual and regulatory obligations.
- Conduct regular compliance reviews, audits and control assessments.
- Maintain compliance registers, risk registers, ROPA and remediation plans.
- Provide governance reporting and assurance updates to Executive Leadership and the Board.
Data Protection Officer (DPO) Responsibilities
- Act as the Group's appointed Data Protection Officer.
- Serve as the primary point of contact for the Information Commissioner's Office (ICO).
- Maintain and oversee Records of Processing Activities (ROPA).
- Conduct Data Protection Impact Assessments (DPIAs).
- Ensure GDPR and privacy requirements are embedded into business processes.
- Manage data subject access requests, data retention compliance and privacy governance.
- Lead investigations into data protection incidents and breaches.
- Provide expert guidance on international data transfers and data-sharing arrangements.
- Oversee privacy-by-design and privacy-by-default practices across all business systems and projects.
AI Governance
- Develop, implement and maintain a Group AI governance framework covering the responsible assessment, approval, deployment and use of AI systems and services.
- Maintain a central inventory of approved AI tools, systems and use cases, with defined business ownership, purpose, data classification, risk rating and review arrangements.
- Establish policies, standards and guidance for responsible AI use, including acceptable use, human oversight, transparency, record keeping, data protection, information security and intellectual property.
- Coordinate proportionate AI risk and impact assessments for new use cases and material changes, including privacy, security, legal, ethical, reputational, operational and client risks.
- Define approval and assurance controls for AI-generated outputs, ensuring appropriate human review, validation and accountability before internal, client or public use.
- Set due diligence, contractual and ongoing assurance requirements for AI suppliers and third-party AI services, including data use, model training, confidentiality, ownership, security and incident notification.
- Monitor relevant AI legislation, regulatory guidance and recognised standards, and translate changes into practical Group policies, controls and operating requirements.
- Establish processes for reporting, investigating and learning from AI-related incidents, misuse, inaccurate or unintended outcomes, policy breaches and control failures.
- Develop AI literacy and role-based awareness so employees understand approved tools, permitted uses, limitations, risks, human-review responsibilities and escalation routes.
- Provide regular reporting to Executive Leadership and the Board on AI adoption, material risks, policy compliance, incidents, exceptions and remediation actions.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Information Security & ISO Management
- Own and maintain ISO certification programmes including ISO 9001, 14001, 20121, 27001 and other relevant standards.
- Coordinate internal and external audits.
- Manage corrective actions and continuous improvement plans.
- Ensure security policies, standards and procedures remain current and effective.
- Support Cyber Essentials and Cyber Essentials Plus certification activities.
- Develop security governance controls aligned to recognised best practices.
- Work alongside internal IT teams and third-party providers to ensure compliance with security requirements.
Risk Management
- Develop and maintain the Group information security risk management framework.
- Facilitate risk assessments across business functions.
- Maintain risk treatment and mitigation plans.
- Track remediation actions and provide visibility to leadership.
- Support business continuity and disaster recovery governance activities.
Training & Employee Awareness
- Develop and deliver security, compliance, privacy and responsible AI awareness programmes.
- Ensure mandatory compliance training is completed and tracked.
- Create engaging awareness campaigns addressing cyber security, phishing, GDPR, information governance and responsible AI use.
- Promote a positive culture of accountability for data protection and security.
- Provide guidance and coaching to managers and employees on compliance responsibilities.
Policy & Process Management
- Maintain ownership of all security, privacy, AI governance and wider governance policies.
- Establish consistent standards across all Strata Group companies.
- Ensure policies are regularly reviewed, approved and communicated.
- Drive policy adoption and compliance throughout the organisation.
- Maintain evidence repositories to support audits and certification activities.
Key Stakeholders
- Board of Directors
- Group Head of IT
- Managing Directors
- HR Team
- Finance Team
- Legal Advisors
- Third-Party Auditors
- Managed Service Providers
- Employees across all Strata Group companies
The successful candidate will be able to demonstrate the following:
- Proven experience in Governance, Risk and Compliance (GRC).
- Experience acting as a Data Protection Officer or privacy lead.
- Strong working knowledge of UK GDPR and Data Protection legislation.
- Experience managing ISO 9001, 14001, 20121, 27001 certification and audit programmes.
- Experience conducting risk assessments and compliance reviews.
- Experience developing policies, standards and governance frameworks.
- Experience delivering security awareness and training programmes.
- Strong stakeholder management and communication skills.
- Practical knowledge of responsible AI principles, organisational AI risks and emerging AI regulation and standards.
- Experience developing AI policies, AI risk or impact assessments, approved-use registers, or third-party AI assurance controls.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Desirable Qualifications
- Certified Data Protection Officer (DPO)
- ISO 9001, 14001, 20121, 27001 Lead Implementer or Lead Auditor
- CIPP/E
- CIPM
- CISSP
- CISM
- CRISC
- Cyber Essentials Assessor (desirable)
Success Measures
Within the first 12 months the role will:
- Establish a Group-wide Governance, Risk and Compliance framework.
- Successfully maintain and expand ISO certification programmes.
- Demonstrate measurable improvements in security and privacy compliance.
- Establish an approved AI inventory, proportionate risk-assessment process and clear governance reporting for material AI use cases.
- Increase employee completion rates for compliance training.
- Reduce audit findings and compliance risks.
- Establish clear governance reporting for Executive Leadership and the Board.
- Create a culture where security, privacy, compliance and responsible AI are embedded into day-to-day operations.
Employee Benefits
- 25 days annual leave, plus usual Bank Holidays
- Birthday day off
- Private Health Insurance* (Upon successful completion of a 6-month probation period)
- Workplace pension scheme
- Death in service scheme
- Cycle to work scheme
- Hybrid working arrangement
- Regular social events
Our Principles
A win for the client
Client success is at the forefront of everything we do. We measure our success by the impact we make for our clients. We strive to exceed your expectations, delivering moments that matter with results that matter.
A win for the company
We believe in long-term partnerships and sustainable growth. When your business prospers, so does ours. Our commitment to excellence and innovation means we’re always ahead of the curve, offering you the best brand experiences.
A win for the team
Our team is the lifeblood of our agency. We celebrate diversity, promote collaboration, and foster an inclusive culture where every team member feels valued and empowered. When our team thrives, their passion and dedication is reflected in everything we deliver.
A win for you
Whether you’re engaging us for your events, already fostering a career at Strata, or considering one, our goal is to create a win for you. We’re dedicated to providing our employees with an enriching workplace that supports their growth and well-being. For our clients, a win means achieving your objectives and making your brand shine.
A win for the planet
We are committed to making environmentally responsible choices in our work. We recognise our responsibility to minimise our impact on the planet and contribute to a sustainable future. From eco-friendly event practices to conscious resource management, we aim to create events that are a win for the environment.
Diversity at Strata
At Strata, people are at the heart of who we are.
We recognise and value the diverse and unique perspectives, experiences, and backgrounds that each individual brings.
We are committed to fostering a workplace where
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location