How do you approach regulatory compliance (APRA, ASIC, PCI-DSS) in fintech product work?
Compliance in fintech is not a constraint on product — it is a product requirement like any other, and it needs to be sequenced into the roadmap with the same rigour as a feature. I map the applicable regulatory obligations early in discovery: APRA prudential standards if you are operating in the deposit-taking or insurance space, ASIC licensing and disclosure requirements for financial product issuers, and PCI-DSS scope for anything touching card data. The output is a compliance requirements register that feeds directly into acceptance criteria on stories. I also help teams design compliance-forward UX — disclosure flows, consent mechanisms, dispute resolution — that satisfies the regulator without destroying conversion.