2.1 Purpose of the compliance function
▼What compliance is for syllabus 2.1
Purpose: protect the firm from regulatory / legal breaches (and the fines, licence loss, and reputational damage that follow) by identifying, assessing, monitoring, advising on, and reporting compliance risk.
Compliance is a control function. It does NOT replace management's ownership of compliance risk — every business unit remains responsible for its own compliance; compliance provides oversight, advice, and challenge.
2.2 Three lines of defence
▼The industry-standard model syllabus 1.1
| Line | Who | Role |
|---|---|---|
| 1st line | Business units | OWN and MANAGE the risks — accountable for compliance in their own area |
| 2nd line | Compliance + Risk Management | OVERSEE, advise, challenge, monitor |
| 3rd line | Internal Audit | INDEPENDENT assurance over all controls including the compliance function itself |
Compliance sits in the 2nd line. This is why compliance must be independent of revenue-generating business units — a compliance officer reporting to the head of sales cannot credibly challenge sales practices.
2.3 Independence + reporting lines
▼To whom does compliance report? syllabus 2.1
To preserve independence, the head of compliance should typically report to:
- The BOARD (or a board committee — often audit or risk committee)
- And/or the CEO directly
- NOT a revenue-generating business unit
The head of compliance should have direct access to the board — enabling independent escalation of significant compliance risks, breaches, or disagreements with executive management, WITHOUT filtering through the CEO.
Adequate resourcing syllabus 2.2
A compliance function must be adequately resourced (headcount, skill, seniority, technology, budget) proportionate to the firm's size, complexity, risk profile, and regulatory environment.
Under-resourced compliance is a common regulatory finding. Head of compliance should have (and use) the ability to raise concerns to the board if they believe resources are inadequate. Regulators may ask "did you request more resources? Were you refused?"
2.4 The CCO — responsibilities + fit & proper
▼Chief Compliance Officer responsibilities syllabus 3.1
Core responsibilities of a CCO:
- Setting the compliance strategy
- Maintaining the compliance policy framework
- Running the compliance monitoring programme
- Providing advice to the business
- Ensuring training
- Liaising with regulators
- Reporting to the board
- Managing the compliance team
Under regimes like the UK SMCR, the CCO is a Senior Manager with personal regulatory accountability — meaning they can be personally fined or banned for failures within their remit.
"Fit and proper" — three pillars syllabus 3.2
Approved persons must meet a fit and proper standard covering:
- HONESTY, INTEGRITY, and REPUTATION
- COMPETENCE and CAPABILITY (technical knowledge, experience)
- FINANCIAL SOUNDNESS
Assessed by the firm and (in many jurisdictions) tested by the regulator before approval. Failures (undisclosed criminal record, bankruptcy, prior regulatory action) can bar someone from senior compliance roles.
2.5 Compliance culture
▼Tone from the top syllabus 4.1
Culture is established by tone from the top — visible, consistent leadership commitment from the board and senior executives, backed by aligned incentives, HR consequences for breaches, and rewards for compliance-supportive behaviour.
What leaders SAY matters less than what they DO — who they promote, who they fire, what they tolerate, how they handle a whistleblowing case.
Positive vs warning indicators syllabus 4.2
Positive indicators: employees speaking up without fear · near-miss reporting valued · timely breach reporting · consistent discipline regardless of seniority · compliance concerns addressed (not deferred) · board engagement on culture.
Warning signs: ZERO breach reports (usually means people are hiding them) · rainmakers get away with things ordinary staff would be fired for · policies exist but not lived.
2.6 Compliance monitoring programme (CMP)
▼What a CMP is and does syllabus 5.1
Compliance Monitoring Programme (CMP) = a risk-based, planned programme of activities designed to give the compliance function ongoing assurance that regulatory / policy requirements are being met.
Distinct from internal audit's periodic assurance — CMP is CONTINUOUS 2nd-line testing, not periodic 3rd-line testing.
Elements:
- Risk-based prioritisation (informed by the compliance risk assessment)
- Sample testing, thematic reviews, deep-dives
- Documented findings + ratings + agreed actions
- Tracked to CLOSURE
- MI to senior management + board on trends
Risk-based approach syllabus 5.2
Higher-risk areas (large volumes · sensitive customers · high-fine regulations · past breach history · new business · new regulation) receive PROPORTIONATELY MORE monitoring than lower-risk areas.
Compliance risk assessment (CRA) → heat map → CMP prioritisation. Don't spread butter thinly across everything.
2.7 Advisory role + regulator interaction
▼The advisory role syllabus 6.1
Compliance advises the business on the compliance implications of new products, new business lines, transactions, marketing material, client relationships, and regulatory change. Early involvement matters — being asked "is X compliant?" AFTER launch is much worse than being asked BEFORE.
Give objective, independent advice — even when unwelcome. Document material advice. Escalate where compliance disagrees but is overruled.
Open and cooperative syllabus 8.1
General regulatory expectation (formal rule in many jurisdictions e.g. FCA Principle 11): firms must deal with regulators OPENLY AND COOPERATIVELY — proactively disclosing significant issues, responding promptly to information requests, not misleading the regulator.
Compliance ensures the firm makes required NOTIFICATIONS: regular reports (returns, transaction reports, financial data) + ad-hoc event-driven (material breaches, senior appointments/departures, litigation, IT incidents affecting clients, whistleblowing referrals). Timing is critical.
2.8 SMCR + individual accountability
▼Senior Managers & Certification Regime syllabus 13.1
UK SMCR (2016 → expanded 2023+) is the current UK model of individual accountability. Features:
- Named INDIVIDUALS accountable for specified prescribed responsibilities (via statements of responsibility)
- Personal regulatory approval for Senior Managers
- Annual certification of "significant harm" staff as fit & proper
- Individual Conduct Rules applying across most staff
- Duty of responsibility — Senior Manager can be sanctioned for failures in their area, regardless of whether they knew
Similar regimes globally: Hong Kong Manager-in-Charge (2017), Singapore MAS senior management guidelines, Australia FAR (2024 for banking/insurance/super).
The Duty of Responsibility syllabus 13.2
Under SMCR's Duty of Responsibility, a Senior Manager can be personally sanctioned by the regulator where:
- There has been a regulatory breach in an area they were responsible for, AND
- They did NOT take "such steps as a person in their position could reasonably have been expected to take" to prevent it
Note: "I didn't know" is not automatically a defence. The question is: SHOULD you have known, and DID you take reasonable steps?
2.9 Handling breaches + outsourcing
▼Standard breach playbook syllabus 15.1
- Containment — stop the harm continuing
- Investigation — facts, scope, root cause
- Notification where required (regulator, affected clients)
- Remediation (customer redress, control fix)
- Discipline where individuals culpable
- Documentation
- Tracked to closure
Outsourcing — accountability retained syllabus 14.1
Universal principle: you can outsource the OPERATION, not the RESPONSIBILITY.
Even for outsourced compliance operations, the firm:
- Retains FULL regulatory accountability
- Must due-diligence the provider
- Must contract clearly (SLAs, access rights, exit)
- Must monitor performance
- Must retain sufficient in-house knowledge to oversee
- Typically requires an internal accountable individual (Senior Manager)
Conflicts — avoid > manage > disclose syllabus 11.1
Response hierarchy for identified conflicts:
- AVOID the conflict where possible
- If not avoidable, MANAGE via controls (info barriers / Chinese walls, separation of duties, restricted lists, PAD rules)
- DISCLOSE to the client as a LAST resort, and only where management is sufficient to protect the client
Disclosure alone is NOT a fix for a genuine ongoing conflict.
2.10 All the numbers (cheat sheet)
▼Ch 2 quick-reference
| Item | Answer |
|---|---|
| Compliance = which line? | 2nd |
| Internal audit = which line? | 3rd |
| Business = which line? | 1st (owns risk) |
| Head of compliance reports to | Board / audit or risk committee / CEO (NOT sales/trading) |
| Fit & proper pillars | Honesty · Competence · Financial soundness |
| Conflicts hierarchy | Avoid > Manage > Disclose |
| FCA Principle 11 | Open and cooperative with regulators |
| Duty of responsibility test | "Reasonable steps a person in their position would have taken" |
| Outsourcing rule | Firm retains full regulatory accountability |
| UK SMCR started | 2016 (expanded 2023+) |
| Australia FAR started | 2024 (banking / insurance / super) |
| HK MIC started | 2017 |