Actively Interviewing
This organisation is scheduling interviews as applications come in. They're ready to hire as soon as they find the right person. Don't miss your opportunity, apply now!
Director of Compliance - (Voluntary)
Status: Voluntary (expenses reimbursed)
Reports to: Board (via the Chair)
Works with: Managing Director, Company Secretary, Head of Programmes, Director of HR, Finance & Compliance Officer
Location: Hybrid (South of England preferred), with occasional site visits
Time commitment: c. 6–8 hours per month, with peaks during audits/incidents
Screening: Enhanced DBS required
Role purpose
To ensure ThriveSpark operates safely, lawfully, and to a consistently high standard by providing independent oversight of safeguarding, data protection, quality assurance, and organisational risk. The Director of Compliance sets proportionate guardrails that enable delivery, maintains the core compliance framework, and advises the Board with clear, evidence-led judgement.
Key responsibilities
1) Compliance framework & policy governance
-
Maintain and periodically review the suite of core policies: Safeguarding, Data Protection (UK GDPR), Health & Safety, Quality Assurance, Complaints, Whistleblowing, and related procedures.
-
Establish an annual compliance calendar covering policy review, training refreshers, audits, and filings; monitor adherence and report variances.
-
Ensure documents are version-controlled, accessible, and aligned across the CIC and (where relevant) the CIO charity arm.
2) Risk management & assurance
-
Own the organisational risk register: define risk owners, review quarterly, and ensure mitigations are tracked to closure.
-
Design proportionate internal assurance (spot checks, observations, sample reviews) to test policy effectiveness without impeding delivery.
-
Produce concise compliance dashboards and narrative reports for the Board, escalating material issues promptly.
3) Safeguarding oversight
-
Ensure safeguarding policy and practice meet statutory and sector standards, with clear reporting/ escalation routes and post-incident learning.
-
Confirm coverage and currency of safeguarding training for all relevant staff/associates; monitor DBS status and safer-recruitment controls.
-
Chair or contribute to incident reviews (including “near misses”) to identify root causes and corrective actions.
4) Data protection & information governance
-
Serve as the lead for UK GDPR compliance (or work closely with an appointed DPO as applicable).
-
Lead Data Protection Impact Assessments (DPIAs) for new systems, platforms, or data flows; ensure data minimisation, access control, and retention schedules.
-
Oversee privacy notices, subject access processes, data breach response, and ICO registration/renewal.
5) Quality assurance (QA) of delivery
-
Codify QA standards for programmes (planning, observation, feedback, supervision, reflective practice).
-
Coordinate periodic QA reviews with the Head of Programmes; verify that quality actions are implemented and evidenced.
-
Support the publication of proportionate impact and compliance statements to clients and stakeholders.
6) External compliance & partner due diligence
-
Ensure statutory filings and insurances remain current (e.g., ICO, relevant regulator reporting).
-
Oversee due diligence for key suppliers/partners (safeguarding, data protection, insurance, references) and ensure appropriate clauses in contracts.
-
Advise on procurement and proportionate contract-management controls.
7) Complaints, concerns & whistleblowing
-
Maintain accessible routes for complaints/concerns; ensure timely, fair handling and learning capture.
-
Safeguard whistleblowers and assure the Board that concerns are investigated and addressed without detriment.
Success measures (illustrative)
-
Risk register reviewed quarterly with actions closed to schedule; Board receives clear, timely assurance.
-
100% completion and currency of mandatory training (safeguarding, data protection) for staff and associates.
-
All relevant programmes observed/assured against QA standards at agreed cadence; corrective actions implemented.
-
DPIAs completed before any new data processing; zero material data breaches; ICO registration current.
-
Safeguarding incidents reported promptly; root-cause analysis and learning actions evidenced.
-
Annual policy audit completed; filings and insurances up to date; no missed statutory deadlines.
Person specification
Essential
-
Substantial experience in compliance, safeguarding, quality, or risk within education, health, or the social-impact sector.
-
Practical command of UK GDPR (including DPIAs, retention schedules, breach management) and confident policy drafting.
-
Proven ability to design proportionate assurance, interpret evidence, and communicate concise, actionable findings to Boards.
-
Calm, independent judgement; able to balance risk with operational realities and maintain confidentiality.
-
Strong written/oral communication; skilled at turning complex requirements into usable guidance for busy teams.
-
Commitment to inclusion, ethical practice, and the safety and dignity of beneficiaries.
Desirable
-
Experience overseeing mixed workforces (staff, associates, volunteers) and multi-site delivery.
-
Familiarity with sector regulators and reporting (e.g., CIC Regulator/Charity Commission context).
-
Exposure to ISO-aligned approaches or equivalent quality systems.
-
Relevant credentials (e.g., safeguarding lead, information governance, risk/assurance).
Safeguarding, data protection & H&S
This role is subject to an Enhanced DBS check and ongoing safeguarding refresher training. All activity must comply with ThriveSpark policies and legal duties, including UK GDPR, Health & Safety, and sector standards for safeguarding. The director ensures safer-recruitment, data minimisation, and lawful processing are embedded in everyday practice.
Terms of appointment
This is a voluntary position during the current phase. Reasonable expenses will be reimbursed in line with policy. Time commitment averages 6–8 hours per month with additional time during audits or incidents. The Board will periodically review leadership requirements as the organisation scales.
At ThriveSpark Southampton, our mission is to empower, support, and celebrate people with ADHD across Southampton and the surrounding community.
Who are Guts UK Charity?
Guts UK Charity is committed to a world where digestive conditions are better understood, better treated and everyone who lives with one gets the support they need. Too many people are suffering or dying in silence or alone. They don’t know where to turn for information or support, diagnosis takes too long for many, and treatment can often come too late.
We are the only UK charity that covers the entire digestive system. We raise vital awareness of digestive conditions, fund life-saving research, and provide patients and loved ones with expert information and support – we are informed by evidence and expertise, our community, and the patient voice.
Our mission is simple: to improve the lives of millions of people affected by digestive conditions
Who are we looking for?
We are seeking an experienced treasurer who has a comprehensive understanding of charity finances, requirements and regulations and will actively support other board members to fulfil their collective responsibilities around finance.
You will play a pivotal role in ensuring the Gut UK’s ambitious growth plans are achievable, and sustainable for the long term. As a charity we need to do more, fund more, and support more people and we need a treasurer who shares our passion in achieving this.
As treasurer, you will play a vital role in ensuring our financial health, sustainability, and transparency. You guide and advise the Board on financial strategy, budgeting, and risk management, Chair the Finance, Fundraising, Audit & Risk Committee, ensuring robust oversight of financial and operational matters, support the CEO and COO, offering expert insight and challenge on financial planning and reporting, and champion good governance, transparency, and accountability across the organisation.
Our vision is of a world where digestive disorders are better understood, better treated and everyone who lives with one gets the support they need



The client requests no contact from agencies or media sales.