Reference: GILA/ID/TECH-037/PAY
Board seat: Independent Director, Non-Executive
Primary board location: Mumbai and Bengaluru operations centres
Meeting model: Six board meetings, six technology-risk sessions and one live exercise
Mandate type: Risk, Cybersecurity, Technology & AI Director
Status: Confidential live-search specification; client identity released only after conflict clearance and NDA.
The anonymised enterprise
A regulated digital payment-aggregation company serving online merchants and platforms through cards, UPI and net-banking orchestration, without taking lending risk.
Annual processed value exceeds ₹4 lakh crore. Growth in enterprise merchants and tokenised payments has increased dependency on banks, networks, cloud services and high-volume fraud controls.
The board problem and strategic reason for appointment
The board needs an independent technology-risk director who can connect uptime, settlement integrity, merchant due diligence, fraud loss and regulatory reporting. The mandate is not for a product evangelist.
The board is not buying a credential. It is appointing an independent decision-maker who can convert this problem into a governed sequence of choices, evidence and accountability. Success will be judged by the quality of decisions and control improvement, not by the number of recommendations made.
Board position, authority and interfaces
Chair of Technology & Risk; Audit member for ITGCs, settlement and reconciliation; direct private sessions with CISO, CRO, compliance and internal audit.
The appointee will have direct, unfiltered access to the Company Secretary and to the relevant control-function leaders. Any advisory support requested by the board must remain management-executed: the director sets questions, tolerances and evidence standards, but does not become an executive or consultant.
First 12–18 month strategic charter
- Set tolerances for settlement breaks, fraud losses, service outage and unreconciled balances; independently test cloud/processor failure and manual settlement continuity; review merchant onboarding, prohibited-business and mule-account analytics; govern tokenisation, privileged access and incident evidence across bank/network dependencies
- Translate technical risk into board decisions: risk appetite, investment priorities, accountable owners, recovery tolerances and customer consequences—not dashboards of vulnerabilities or model counts.
- Require independent testing of the severe-but-plausible scenario, including executive decision rehearsal, evidence preservation, regulatory/customer communication and recovery of critical services.
Decision profile sought
Essential evidence
- Payments, banking technology, cyber, fraud or operational-resilience executive with board judgement; regulated-control familiarity; high-volume transaction depth
Differentiators
- Major incident command, red-team oversight or payment reconciliation assurance; regulator-facing experience
GILA will assess board-level technology judgement, operational resilience, adversarial questioning and enough technical depth to challenge management without becoming a shadow CIO or CISO. Candidates should expect a case discussion based on an ambiguous board decision from this mandate, not a career-history interview alone.
Independence, suitability and downside diligence
The search will apply Section 149(6), Sections 164–165, Schedule IV and the applicable listing or sector rules to the entity’s legally verified status at the appointment date. Databank/proficiency status, listed-entity directorship and committee ceilings, pecuniary relationships, relatives’ interests, recent audit/advisory work and interlocking directorships will be checked. The appointment is subject to formal legal and secretarial confirmation; this posting is not a substitute for that determination.
Mandate-specific screens: Current ties to sponsor banks, card networks, cloud/security vendors or major merchants; competing payment board; any operating role that blurs oversight.
Before accepting the seat, the candidate will receive under NDA the latest board composition, committee charters, material litigation/regulatory schedule, related-party map, last audited accounts, current D&O policy and the specific risk papers necessary to make an informed liability assessment.
Twelve-month outcomes
The board expects a board that knows which digital failures can threaten the enterprise, what tolerances apply and whether recovery claims have been independently tested. For this particular seat, the evidence will be:
- Settlement/reconciliation breaks remain within explicit tolerance; severe scenario is rehearsed end to end; merchant and fraud risk produce demonstrable control actions
Commitment, protection and economics
- Expected load: 26–32 days annually plus incident availability.
- Terms: Five-year term subject to regulator/company approvals; chair fee; cyber/crime and D&O protection.
- Protection: Appointment letter, deed of indemnity where legally available, appropriate D&O cover including discovery/run-off terms, access to independent advice under the board-approved protocol, and complete minuting of dissent.
- Equity: No stock options where the appointment is legally an independent-director seat subject to Section 149(9). Any private-company structure outside that perimeter will be expressly classified and separately advised; no equity is implied by this posting.
Search process
Conflict pre-clearance → GILA/SYMPHONY™ board-fit interview → mandate case → document-led diligence under NDA → references from board peers and control functions → NRC/owner interviews → statutory, regulatory and reputation checks → board recommendation. Candidate consent, disclosures and appointment approvals will follow the law and the entity’s constitutional documents.