An authorised firm has a set of obligations written into its permissions. Somebody has to know what those obligations are, test whether the business is meeting them, and produce evidence of the testing. That is the compliance function, and in most jurisdictions the person who owns it is named on the licence application and approved individually.
The misconception is that compliance stops things. Most of the work is documentation and monitoring, and the stopping happens once or twice a year. Firms that treat the function as a veto queue end up with a compliance officer who is out of the loop until the day something is already live.
Second line, not the police
The standard model puts three lines between a firm and a regulatory failure. The first line is the business: the sales team that onboards a client, the dealing desk that fills an order, the finance team that reconciles client money, the support agent who logs a complaint. They own the controls in their own processes.
The second line is compliance and risk. It sets the policy, tests whether the first line is following it, and reports what it finds to the board. The third line is independent audit, internal or external, checking that the second line is doing its job.
The distinction matters commercially. If compliance performs first line tasks, such as approving every client file personally, it has no independence left to test the process, and the testing is where the regulatory value sits. A small firm with three staff can combine roles, but it should still separate the act from the review.
The calendar the job actually runs on
Ask a working compliance officer what they do and the answer is a schedule. The monitoring programme is the core artefact: a list of tests against the firm's real obligations, each with an owner, a frequency, a sample size and a written outcome.
| Frequency | Typical work | Output |
|---|---|---|
| Daily | Transaction and alert review, onboarding exceptions, complaint intake | Case notes and escalations |
| Weekly | Marketing and promotion approvals, sample file checks | Approval log with versions and dates |
| Monthly | Client money reconciliation review, execution quality sampling, breach register update | Management information pack |
| Quarterly | Monitoring programme tests, training completion, policy reviews | Board report with findings and deadlines |
| Annually | Risk assessment refresh, regulatory returns, audit support | Filed returns and an updated risk register |
Marketing approval is the piece that surprises new firms most. In many regimes a financial promotion has to be approved before it is published, retained in the approved form, and withdrawn if it stops being fair and clear. That covers landing pages, affiliate creatives, email campaigns and social posts, which is why the restrictions described in CFD marketing rules land on the compliance queue rather than on the marketing team's own judgement.
MLRO and compliance officer are not the same job
The money laundering reporting officer owns the anti-money-laundering programme: the risk assessment, the customer due diligence standards, ongoing monitoring, and the decision to file a suspicious activity report. That last one is personal. In most regimes the MLRO decides, and the decision is recorded with reasons whether or not a report is filed.
A compliance officer covers conduct obligations more broadly: client categorisation, disclosures, complaints, best execution, record keeping, reporting. The two roles overlap at onboarding, where the verification level applied to a client is both an AML control and a conduct one, and the underlying programme is set out in AML basics for trading firms.
Many small firms appoint one person to both roles and that is usually permitted. What is not workable is appointing one person to both roles and giving them ten hours a month, because the daily alert review alone will consume more than that once client numbers pass a few thousand.
The breach register is the document nobody wants to start and everybody needs. Every rule breach, near miss and control failure, with date, cause, remediation and owner. A firm that presents a supervisor with an honest register and evidence of fixes is in a much stronger position than one that presents an empty one, because an empty register in a real business reads as a monitoring failure rather than as perfection.
Where the role fails
Four failure patterns show up repeatedly. Reporting lines: a compliance officer who reports to the head of sales cannot stop a campaign the head of sales wants. The line should run to the board or to a non-executive. Second, no systems access: an officer who has to ask the technology team for a client list cannot perform monitoring, and the audit trails described in compliance audit trails only help if the officer can read them directly.
Third, the nominee. A named individual in the licensing jurisdiction who has never logged into the CRM, appointed to satisfy a local presence requirement. Regulators look for evidence of actual activity, and an approved person with no footprint in the firm's records is a finding in itself. Fourth, no budget: a monitoring programme with no tooling becomes a spreadsheet that is updated the week before a board meeting.
Outsourcing, and what cannot be outsourced
Buying compliance support is normal and sensible for a firm of ten people. Consultants draft policies, run periodic testing, prepare returns and track rule changes. That work is genuinely better done by people who see thirty firms a year.
Accountability does not travel with the invoice. The approved individual and the board remain responsible, and an outsourced provider without system access performs no monitoring worth the name. The practical arrangement is a named internal owner with real authority and real access, supported by an external firm for testing and drafting. Anything else produces a policy library nobody in the business has read, which is a different problem from the one the licence was granted to solve. It also connects back to what the permission actually allows, which is the distinction drawn in licence versus registration.
"If your compliance officer finds out about a campaign when a client complains about it, you do not have a compliance function. You have someone who writes apologies."
— Roman Onta, Executive Director, SINGUARD
Key Takeaways
- Compliance is a second line function: it sets policy and tests the business, while the controls themselves belong to the teams doing the work.
- The monitoring programme, the promotion approval log and the breach register are the three artefacts a supervisor will ask for first.
- The MLRO role carries a personal decision on suspicious activity reporting and is distinct from the general compliance mandate even when one person holds both.
- Outsourcing testing and drafting is normal; outsourcing accountability is not, and a nominee with no system access is a finding waiting to happen.
Frequently Asked Questions
Is the compliance officer the same person as the MLRO?
Often in a small firm, rarely in a large one, and the two roles have different duties. The compliance officer owns the firm's adherence to conduct and regulatory obligations generally. The money laundering reporting officer owns the anti-money-laundering programme specifically, including the decision to file suspicious activity reports. Many regimes allow one person to hold both, and some require the roles to be approved individually.
Can a firm outsource its compliance function?
Parts of it, yes. Monitoring testing, policy drafting, training material and regulatory horizon scanning are commonly bought from consultants. What cannot be outsourced is accountability: the regulator holds the approved individual and the board responsible, and an outsourced provider with no access to the firm's systems cannot perform monitoring in any meaningful sense.
What does a compliance monitoring programme contain?
A schedule of tests against the firm's actual obligations, each with an owner, a frequency, a sample size and a written result. Typical items include client onboarding file reviews, marketing material approvals, execution quality checks, complaint handling timelines, client money reconciliations and staff training completion. The output is a report to the board with findings, actions and deadlines.