Summary
Overview
Work History
Education
Skills
Keywords
Timeline
Generic

Sandra Moses

Houston

Summary

Experienced Regulatory Compliance and Risk Management professional with over 4 years of experience in banking and highly regulated environments. Skilled in risk assessment, regulatory compliance, and enterprise risk management (ERM), with hands-on experience interpreting and applying banking regulations such as BSA, AML, and OFAC. Adept at collaborating with cross-functional teams to implement compliance solutions, ensuring audit readiness, and supporting privacy protections (e.g., CCPA, COPPA). Proficient in analyzing regulatory data, preparing compliance documentation, and maintaining strong internal controls.

Overview

9
9
years of professional experience

Work History

Compliance Analyst

Sunflower Bank, N.A.
01.2023 - Current
  • Conducted comprehensive risk assessments across banking operations, identifying vulnerabilities and recommending actionable solutions to mitigate risks.
  • Administered and maintained the Enterprise Risk Management (ERM) system, ensuring alignment with organizational goals and regulatory requirements.
  • Reviewed and ensured compliance with key regulations, including BSA, AML, CCPA/CPRA, and COPPA, collaborating with internal teams to ensure audit readiness.
  • Analyzed regulatory developments and supported updates to internal policies, procedures, and compliance guidance.
  • Maintained and organized regulatory tracking logs and compliance documentation, ensuring the bank was audit-ready.

Compliance Analyst

Indigo Flex Consulting – Questrade Financial Group
Chicago
11.2020 - 09.2022
  • Evaluated internal controls and business processes for adherence to financial services regulations and internal policies.
  • Conducted compliance risk assessments, identifying gaps and proposing remediation actions to senior leadership.
  • Applied PCI DSS, SOX, and NIST regulations and facilitated ISO 27001 recertification.
  • Collaborated with IT and Audit teams to support compliance with SOX and ISO 27001 frameworks.
  • Provided advisory support on privacy regulations like CCPA/CPRA and FISMA, ensuring organizational alignment with these frameworks.

Compliance Analyst

Indigo Flex Consulting – World Financial Group (WFG)
Chicago
04.2018 - 07.2020
  • Managed compliance activities related to PCI DSS, SOC 1/2, and ISO 27001 frameworks, ensuring alignment with regulatory standards.
  • Developed and implemented compliance metrics and dashboards, effectively communicating compliance posture to senior leadership.
  • Supported remediation efforts for identified compliance gaps, ensuring full control validation for financial and regulatory processes.
  • Assisted with compliance training and maintained documentation for internal policy reviews.

Risk Analyst

Indigo Flex Consulting – INOAC Exterior Systems
Chicago
02.2017 - 03.2018
  • Designed and implemented risk assessment frameworks addressing financial, operational, cybersecurity, and third-party risks.
  • Conducted compliance reviews aligned with Canadian regulations (FERC, NERC, PIPEDA).
  • Collaborated with business and technical teams to align risk management activities with regulatory and organizational objectives.

Education

LLB - Law

London Metropolitan University
United Kingdom

Skills

  • Risk Assessment & Analysis
  • Enterprise Risk Management (ERM)
  • Regulatory Compliance (BSA, AML, CIP, OFAC)
  • Data Monitoring & Reporting
  • Risk Data Visualization & Modeling
  • Policy & Procedure Development
  • Cross-Functional Collaboration
  • Vendor & Third-Party Risk Management
  • Privacy & Consumer Protection (CCPA/CPRA, COPPA)
  • Compliance Documentation & Reporting
  • Internal Controls & Compliance Testing
  • ISO 27001 & NIST 800-53 Frameworks
  • Risk Management Software: ServiceNow, AuditBoard
  • Data Analysis Tools: Microsoft Excel (Advanced), Risk Modeling Tools
  • Regulatory Frameworks: ISO 27001, NIST 800-53, PCI DSS, SOC 1/2, FISMA
  • Compliance Tracking Systems: AuditBoard, SOX Compliance Tools
  • Privacy Tools: Data Tracking and Reporting Systems for CCPA/CPRA, COPPA
  • Banking Software: MSP, LASERFICHE, nCINO, Desktop Teller, TENA

Keywords

  • Risk Assessment
  • Enterprise Risk Management
  • Regulatory Compliance
  • BSA
  • AML
  • CIP
  • OFAC
  • Compliance Documentation
  • Cross-Functional Collaboration
  • Risk Data Analysis
  • Privacy & Consumer Protection
  • Compliance Training
  • Audit-Ready
  • Vendor & Third-Party Risk
  • ISO 27001
  • NIST 800-53

Timeline

Compliance Analyst

Sunflower Bank, N.A.
01.2023 - Current

Compliance Analyst

Indigo Flex Consulting – Questrade Financial Group
11.2020 - 09.2022

Compliance Analyst

Indigo Flex Consulting – World Financial Group (WFG)
04.2018 - 07.2020

Risk Analyst

Indigo Flex Consulting – INOAC Exterior Systems
02.2017 - 03.2018

LLB - Law

London Metropolitan University
Sandra Moses