Chief Compliance Officer (Saint Paul)
ROLE OF THE ASSOCIATE VICE PRESIDENT AND CHIEF COMPLIANCE OFFICER Reporting directly to the Executive Vice President for Finance and Operations, the CCO leads the Office of Institutional Compliance and serves in an advisory role to senior leadership and the Board of Regents. The CCO will be a trusted partner to campus and unit leaders, providing consultation and judgment on complex or cross‑functional compliance issues. The CCO will oversee compliance activities, align policy and prioritize risks across the University. The CCO will establish a central function to assess new laws and regulations, determine impact and resource needs, and guide implementation. The CCO will oversee a newly consolidated Privacy Office within the OIC and recruit and onboard a dedicated Chief Privacy Officer to manage HIPAA, FERPA, GDPR and other privacy programs. KEY OPPORTUNITIES AND CHALLENGES Strategic Leadership & Compliance Infrastructure Modernization The CCO will provide strategic leadership to advance a modern, enterprise‑wide compliance function that reflects and supports the scale and complexity of the University. The CCO will serve as the key architect and leader of the University of Minnesota’s institutional compliance framework across the highly decentralized, five‑campus system, partnering closely with Chancellors, Vice Presidents, and senior leaders to align compliance strategy with institutional priorities and best practices. They will champion a proactive approach to compliance and risk management that emphasizes early identification, coordinated response, clarity of responsibility, and continuous improvement, underscoring a culture of integrity, accountability, and ethical decision‑making across the University. To modernize the compliance infrastructure, the CCO will strategically develop systems, tools, and technologies that support training, reporting, policy management, and overall coordination. Beginning with a comprehensive review of existing structures across the University, the CCO will identify gaps, redundancies, and opportunities for greater alignment and use these findings to develop a prioritized multi‑year compliance investment roadmap. The CCO will also establish a data framework that ensures protection, integrity, and accessibility of compliance‑related data to support timely execution of compliance and reporting functions. Governance & Institutional Coordination Lead the Board of Regents Audit and Compliance Committee and participate directly in the newly re‑chartered leadership governance committee and the President’s Policy Committee. Formally lead and chair the Institutional Strategic Risk and Compliance Group, coordinating legal, risk, audit, and information security leaders to address emerging enterprise risks. Guide the systemwide Compliance Partner network, leveraging a decentralized, collaborative model to share information and scale best practices across all five campuses. Formalize cross‑functional affinity groups organized around key areas of risk and compliance, such as international activities, research, clinical care, student services, athletics, and data/privacy. Enterprise Integration & Network Leadership The CCO will strengthen the University’s Compliance Partner network, establishing mechanisms for information sharing, escalation, and coordination across compliance areas. The CCO will ensure that compliance risks are identified and addressed collaboratively across organizational boundaries. Privacy & Regulatory Oversight The CCO will recruit and onboard a Chief Privacy Officer to oversee a newly established Privacy Office within OIC. In partnership with the CPO, the CCO will guide a unified privacy governance framework that defines principles, assigns decision‑making authority, and coordinates privacy‑related efforts across IT, research, healthcare, and administrative units. The CCO will strengthen the University’s approach to privacy and data protection, ensuring compliance with HIPAA, FERPA, GDPR, and other privacy laws and regulations. The Health Information Privacy & Compliance Office (HIPCO) will transition from the Office of Academic Clinical Affairs to the Privacy Office within OIC. Core Compliance Program Leadership Provide oversight and strategic direction for OIC’s core compliance programs, including institutional compliance coordination, conflict of interest, University policy, delegations of authority, and suspected misconduct reporting and investigations through the UReport system. Continuously review and strengthen these programs to reflect constantly evolving best practices and regulatory requirements. Training, Onboarding & Role Clarity Review and strengthen a comprehensive, role‑based compliance education framework to enhance awareness and accountability across the University. In partnership with Human Resources, implement a curriculum tailored by job function and a corresponding tracking system that ensures completion and identifies areas of non‑compliance. Create a comprehensive inventory of compliance responsibilities, mapping roles across academic, administrative, research, and operational units to clarify ownership, reduce duplication, and strengthen coordination. Risk Identification, Reporting & Communication Collaborate with Internal Audit, Office of the General Counsel, Enterprise Risk Management, and other key partners to identify, assess, and manage compliance risks. Enhance institutional visibility into compliance trends and emerging areas of concern by harnessing data, reporting, and analytics. Develop and implement a comprehensive communication and training strategy that reaches constituents across the University community. Leadership & Team Management The incoming CCO will lead a dedicated, collaborative, and stable team within the Office of Institutional Compliance. The office has maintained high performance and strong operational continuity. The CCO will provide direction for staff, resources, and program priorities, cultivate a high‑performing, collaborative culture that strives for continuous improvement, and motivate the team to develop strong partnerships and provide high‑level support and service across the University. COMPENSATION AND LOCATION The Associate Vice President and Chief Compliance Officer position is a 100-percent time, 12‑month, professional and administrative appointment based in Minneapolis. Salary is commensurate with education and experience, with an anticipated salary range of $273,395 to $325,545. PAY AND BENEFITS Salary range: $273,395 to $325,545; depending on education, qualifications, experience. Time appointment: 100% Appointment. Position type: Faculty and P&A Staff. The University offers a comprehensive benefits package that includes competitive wages, paid holidays, and generous time off; continuous learning opportunities through professional training and degree‑seeking programs supported by the Regents Tuition Benefit Program; low‑cost medical, dental, and pharmacy plans; healthcare and dependent care flexible spending accounts; HSA contributions; disability and employer‑paid life insurance; employee wellbeing program; excellent retirement plans with employer contribution; Public Service Loan Forgiveness opportunity; financial counseling services; Employee Assistance Program with eight sessions of counseling at no cost; Employee Transit Pass with free or reduced rates in the Twin Cities metro area. DIVERSITY The University of Minnesota provides equal access to and opportunity in its programs, facilities, and employment without regard to race, color, creed, religion, national origin, gender, age, marital status, disability, public assistance status, veteran status, sexual orientation, gender identity, or gender expression. We are committed to attracting and retaining employees with varying identities and backgrounds. QUALIFICATIONS Required Qualifications Minimum 15 years of progressively responsible experience, including at least five years in compliance, privacy, risk, legal, audit, regulatory, or a closely related function. Demonstrated success leading, designing, and implementing enterprise compliance or risk management programs in complex organizations. Exceptional leadership, communication, and relationship‑building skills. Strong analytical and strategic thinking capabilities. Preferred Qualifications Advanced degree (JD, Master's, etc.). Experience in higher education or other large, decentralized organization. Experience working with governing boards and senior leadership. Experience leading an institutional compliance, enterprise risk, privacy, regulatory, legal, audit, or related function in a complex organization. Experience managing privacy regulations at a complex institution that includes healthcare operations. Key Leadership Competencies Strong collaboration and relationship‑building skills. Strategic and enterprise mindset. Integrity and sound judgment. Ability to lead through influence in a decentralized environment. Capacity to translate complex risks into clear, actionable insights. Commitment to continuous improvement and institutional excellence. EMPLOYMENT REQUIREMENTS Background check required. The University presumes prospective employees are eligible to work here. Criminal convictions do not automatically disqualify finalists from employment. J-18808-Ljbffr