Singuard Home Blog Contact eTrader eTrader for Businesses eTrader for Traders Broker Broker CRM Live Demo Prop Firm Prop Firm CRM Live Demo
Licenses & Regulation

What Goes in a Compliance Manual.

A manual copied from another firm is worse than no manual. It commits you to controls you do not run, and the first reviewer who compares the document to the records will find the gap.

Roman Onta, Executive Director, SINGUARD By August 28, 2026 7 min read

The compliance manual is the document a supervisor reads first and measures everything else against. It is not a summary of the rulebook. It is the firm's own description of how it will meet the rulebook, with named owners, stated frequencies and a record produced at the end of each control. Generic manuals fail on that last point: they describe an ideal firm rather than this one.

Governance, roles and delegation

The opening section sets out who is responsible for what. Board composition and the matters reserved to it. Committees where they exist. The compliance function's reporting line, its access to the board and its independence from commercial pressure. The money laundering reporting officer, named. Deputies for both, because the rules do not pause when someone is on leave.

Delegation is where this section earns its place. Where a function sits with a group company or a service provider, the manual says so, states what has been delegated and confirms that accountability remains with the licensed entity. The scope of each control function is set out in the compliance officer role.

Conflicts of interest, written for the actual model

Conflicts are the section that most exposes a copied manual, because the real conflicts depend on the business model. A firm that internalises client flow has a structural conflict between its trading result and its clients' results, and the manual has to name it, describe the controls, and state how the firm decides which flow is internalised. A firm paying introducing brokers a share of spread has a volume incentive conflict. A firm running its own copy trading has an allocation conflict.

Controls belong here in concrete form: information barriers, remuneration structures that do not pay dealing staff on client losses, approval requirements for staff personal trading, and a conflicts register that is reviewed and dated. The underlying model choice decides which of these apply.

Client facing obligations

This is the largest block and it tracks the client relationship in order. Client categorisation and what each category is entitled to. Onboarding, identification and appropriateness assessment where the regime requires one. Disclosure and risk warnings. Order handling and execution policy, including the factors used, the venues or counterparties, and how execution quality is monitored, expanded in best execution rules.

Complaints deserve their own procedure with a defined intake point, an acknowledgment timeframe, an escalation path away from the person complained about, a final response, and information about any external redress scheme. Complaints are also a supervisory sample: examiners ask for the log and check that what is in it matches the emails and chats the firm holds.

Every control in the manual should produce a dated record with an identifiable owner. If a control cannot be evidenced, either change the system so it can be, or change the manual so it promises something the firm actually does.

Financial crime, marketing and outsourcing

Financial crime usually sits in its own document because it is long, and the manual cross references it. Marketing needs an approval procedure: who reviews material before publication, against which restrictions, how affiliate and influencer content is controlled, and where approved versions are stored. Retail derivatives marketing is heavily restricted in many regimes and the practicalities are in the marketing approval process.

Outsourcing gets a register of material providers, the due diligence performed, monitoring, and exit arrangements. Data protection, records retention, business continuity and information security each need a section or a referenced policy. The public facing documents that sit alongside all of this are covered in terms and policies for trading firms.

Breaches, monitoring and training

Three registers do most of the work in a supervisory visit. The breach register records what went wrong, when it was found, the root cause, the remediation and whether it was notified. An empty breach register after a year of operation is not a good sign; it reads as a firm that does not detect problems.

The compliance monitoring programme is a calendar of the checks compliance will run, with frequencies, samples and outputs. It is what turns the manual from a statement into an operating cycle, and it is the document that shows a reviewer the firm is testing itself. The training register records who was trained, on what, when, and how understanding was assessed, including new joiners and refreshers.

The manual should also state its own review cycle and version control, with each version dated and approved. Rules change, models change, and a manual that still describes the launch business two years later tells a reviewer that nobody has read it. Practical reality is that a manual is only as good as the systems underneath it, which is why record capture, approvals and logs should be settled when the platform and portal are chosen rather than bolted on.

This describes common structure and is not legal advice. Content requirements are jurisdiction specific and should be drafted against the applicable rulebook with local counsel.

"Write the manual around what your systems can actually evidence. A promise you cannot show a record for is a finding waiting to happen."

— Roman Onta, Executive Director, SINGUARD

Key Takeaways

Frequently Asked Questions

Should the AML policy sit inside the compliance manual?

Most firms keep financial crime as a separate document because of its length and because it needs its own approval and review cycle, then cross reference it from the manual. Either structure works provided nothing is duplicated with conflicting wording.

How often does a compliance manual need updating?

At a stated review cycle, typically annual, and immediately on any material change to the business model, permissions, systems or the applicable rules. Each version should be dated, approved and retained.

Can a firm use a template manual from a consultant?

A template is a reasonable starting structure, but it has to be rewritten against the firm's own model, systems and records. Reviewers compare the document to the evidence, and a control the firm never ran becomes a finding.


About the Author

Roman Onta, Executive Director, SINGUARD
Roman Onta Executive Director, SINGUARD

Roman Onta is an Executive Director at SINGUARD. He builds the Prop Firm CRM, the Broker CRM, Scalegram and CopySignals side by side with his brother Alex Onta, and he helped on the design of eTrader, the division Alex built and leads. His ground is worldwide payment processing, AML compliance and the corporate structures brokers are built on, work the two of them carry together, shaped by executive roles in the UAE and international corporates. He lives and works in Dubai for most of the year. Meet the executive duo leading Singuard's five divisions.

Your Own Trading Firm, Live in 24 Hours.

SINGUARD builds the technology behind brokers and prop firms: trading platform, CRM, client portal and payment rails, one bundle, one predictable price. Book a call and see it working, or keep reading the guides.

More in Licenses & Regulation