Independent Director
Gladwin International & Company
Why the Board is appointing
The company enables consent-driven exchange of financial information among authorised participants. Its responsibility is not to own customer data or broaden its use, but to ensure that a valid individual has given specific, informed and revocable permission for defined information to move securely between entitled parties.
The Board seeks an Independent Director with Audit Committee depth who can examine whether consent, identity, data flow, billing and reported activity describe the same underlying event. A technically successful transfer can still be improper if the consent was unclear, the scope was excessive, the requesting party was misrepresented or revocation failed.
Control domains
- Consent validity. Govern purpose, data type, source, recipient, frequency, duration, revocation and user comprehension. Consent must not be bundled or designed to make refusal materially harder than acceptance.
- Identity and authorisation. Review user authentication, participant credentials, delegated access, device or account changes and suspicious consent creation. High-risk changes require enhanced verification and alerting.
- Purpose and minimisation. Ensure the information requested is proportionate to the stated use and that participants cannot silently expand scope, frequency or retention.
- Data-flow evidence. Maintain immutable records of request, consent, fetch, transfer, failure, revocation and deletion without exposing the underlying data unnecessarily. Activity metrics must reconcile to this evidence.
- Participant governance. Examine onboarding, continuing eligibility, certificates or credentials, security posture, complaint history, misuse, suspension and offboarding. Commercial importance cannot create lower control standards.
- Security and tenant separation. Oversee encryption, key management, privileged access, vulnerability management, interfaces, denial-of-service protection and incident containment. Sensitive financial data must not persist beyond permitted technical necessity.
- Complaint and harm detection. Track unauthorised access, incorrect source data, inability to revoke, repeated requests, deceptive journeys and adverse downstream outcomes. Resolution should include affected populations, not only complainants.
- Revenue and related-party integrity. Review participant fees, transaction or subscription measures, incentives, pass-throughs, connected entities, credits and side arrangements. Commercial models should not reward excessive data requests.
- Resilience and regulated reporting. Test participant outage, certificate failure, cyberattack, corrupted requests, clock or timestamp error, dependency loss and peak traffic. Regulatory metrics must share definitions with operational source systems.
Audit Committee evidence
The Committee should receive consent success and failure by reason; revocation latency; participant exceptions; anomalous requests; unauthorised or disputed transfers; data-retention exceptions; privileged access; incidents; complaints and remediation; service availability; revenue reconciled to activity; related-party transactions; audit issues; and regulatory commitments.
Assurance should reproduce selected consent journeys from customer interface through data transfer and revocation, testing whether the purpose, scope, participant, evidence and billing agree. Serious consent manipulation, unauthorised persistence or participant misconduct must reach the Committee Chair directly.
Candidate profile and conditions
Candidates should bring at least 22 years of leadership across regulated FinTech, banking technology, data protection, payments, digital identity, audit, cybersecurity or financial-services boards. Former CFOs, chief risk officers, CISOs, data-governance executives, audit partners and Audit Committee Chairs may be suitable.
Active IICA registration is mandatory, together with applicable fit-and-proper, independence and disclosure requirements. Connections with banks, financial-data users, regulated participants, technology providers, auditors or investors must be declared. The appointment may not be used to obtain software, security, audit or consulting business.