Chapter 2 · The Compliance Function

24 of 100 exam questions (HEAVIEST) · 3 lines of defence · independence · CCO · monitoring · reporting · SMCR
← Back to quiz
Why this chapter matters. 24 of 100 exam questions (24%) — the SINGLE HEAVIEST chapter. Trap zones: compliance is 2nd line, not 1st (business OWNS the risk, compliance oversees), business owns compliance — not the compliance function, disclosure alone doesn't manage conflicts (avoid > manage > disclose), SMCR duty of responsibility — "should have known" can be enough, tipping off is a separate criminal offence from failure to disclose. Post-2019 to note: FCA Consumer Duty (2023), WhatsApp/off-channel fine wave ($2bn+), SMCR expansion, EU DORA (2025).

2.1 Purpose of the compliance function

What compliance is for syllabus 2.1

Purpose: protect the firm from regulatory / legal breaches (and the fines, licence loss, and reputational damage that follow) by identifying, assessing, monitoring, advising on, and reporting compliance risk.

Compliance is a control function. It does NOT replace management's ownership of compliance risk — every business unit remains responsible for its own compliance; compliance provides oversight, advice, and challenge.

Common exam trap: "who is responsible for compliance in the business?" — the BUSINESS UNIT (line management), NOT the compliance function. This is the foundational principle of modern GRC.

2.2 Three lines of defence

The industry-standard model syllabus 1.1

LineWhoRole
1st lineBusiness unitsOWN and MANAGE the risks — accountable for compliance in their own area
2nd lineCompliance + Risk ManagementOVERSEE, advise, challenge, monitor
3rd lineInternal AuditINDEPENDENT assurance over all controls including the compliance function itself

Compliance sits in the 2nd line. This is why compliance must be independent of revenue-generating business units — a compliance officer reporting to the head of sales cannot credibly challenge sales practices.

Memorise this structure. It underpins every question about roles, responsibilities, and reporting lines.

2.3 Independence + reporting lines

To whom does compliance report? syllabus 2.1

To preserve independence, the head of compliance should typically report to:

  • The BOARD (or a board committee — often audit or risk committee)
  • And/or the CEO directly
  • NOT a revenue-generating business unit

The head of compliance should have direct access to the board — enabling independent escalation of significant compliance risks, breaches, or disagreements with executive management, WITHOUT filtering through the CEO.

Direct board access is a control against executive management suppressing concerns. Regulators often meet privately with the head of compliance to test whether this actually happens.

Adequate resourcing syllabus 2.2

A compliance function must be adequately resourced (headcount, skill, seniority, technology, budget) proportionate to the firm's size, complexity, risk profile, and regulatory environment.

Under-resourced compliance is a common regulatory finding. Head of compliance should have (and use) the ability to raise concerns to the board if they believe resources are inadequate. Regulators may ask "did you request more resources? Were you refused?"

2.4 The CCO — responsibilities + fit & proper

Chief Compliance Officer responsibilities syllabus 3.1

Core responsibilities of a CCO:

  • Setting the compliance strategy
  • Maintaining the compliance policy framework
  • Running the compliance monitoring programme
  • Providing advice to the business
  • Ensuring training
  • Liaising with regulators
  • Reporting to the board
  • Managing the compliance team

Under regimes like the UK SMCR, the CCO is a Senior Manager with personal regulatory accountability — meaning they can be personally fined or banned for failures within their remit.

"Fit and proper" — three pillars syllabus 3.2

Approved persons must meet a fit and proper standard covering:

  1. HONESTY, INTEGRITY, and REPUTATION
  2. COMPETENCE and CAPABILITY (technical knowledge, experience)
  3. FINANCIAL SOUNDNESS

Assessed by the firm and (in many jurisdictions) tested by the regulator before approval. Failures (undisclosed criminal record, bankruptcy, prior regulatory action) can bar someone from senior compliance roles.

2.5 Compliance culture

Tone from the top syllabus 4.1

Culture is established by tone from the top — visible, consistent leadership commitment from the board and senior executives, backed by aligned incentives, HR consequences for breaches, and rewards for compliance-supportive behaviour.

What leaders SAY matters less than what they DO — who they promote, who they fire, what they tolerate, how they handle a whistleblowing case.

Positive vs warning indicators syllabus 4.2

Positive indicators: employees speaking up without fear · near-miss reporting valued · timely breach reporting · consistent discipline regardless of seniority · compliance concerns addressed (not deferred) · board engagement on culture.

Warning signs: ZERO breach reports (usually means people are hiding them) · rainmakers get away with things ordinary staff would be fired for · policies exist but not lived.

Culture "eats" controls. Every major misconduct case — Wells Fargo, Wirecard, LIBOR / FX, WhatsApp — had a culture failure at its heart, not absent policies.

2.6 Compliance monitoring programme (CMP)

What a CMP is and does syllabus 5.1

Compliance Monitoring Programme (CMP) = a risk-based, planned programme of activities designed to give the compliance function ongoing assurance that regulatory / policy requirements are being met.

Distinct from internal audit's periodic assurance — CMP is CONTINUOUS 2nd-line testing, not periodic 3rd-line testing.

Elements:

  • Risk-based prioritisation (informed by the compliance risk assessment)
  • Sample testing, thematic reviews, deep-dives
  • Documented findings + ratings + agreed actions
  • Tracked to CLOSURE
  • MI to senior management + board on trends
Common trap: "who does 2nd-line testing?" Compliance (via CMP). Internal audit is 3rd line and audits the CMP itself.

Risk-based approach syllabus 5.2

Higher-risk areas (large volumes · sensitive customers · high-fine regulations · past breach history · new business · new regulation) receive PROPORTIONATELY MORE monitoring than lower-risk areas.

Compliance risk assessment (CRA) → heat map → CMP prioritisation. Don't spread butter thinly across everything.

2.7 Advisory role + regulator interaction

The advisory role syllabus 6.1

Compliance advises the business on the compliance implications of new products, new business lines, transactions, marketing material, client relationships, and regulatory change. Early involvement matters — being asked "is X compliant?" AFTER launch is much worse than being asked BEFORE.

Give objective, independent advice — even when unwelcome. Document material advice. Escalate where compliance disagrees but is overruled.

Open and cooperative syllabus 8.1

General regulatory expectation (formal rule in many jurisdictions e.g. FCA Principle 11): firms must deal with regulators OPENLY AND COOPERATIVELY — proactively disclosing significant issues, responding promptly to information requests, not misleading the regulator.

Compliance ensures the firm makes required NOTIFICATIONS: regular reports (returns, transaction reports, financial data) + ad-hoc event-driven (material breaches, senior appointments/departures, litigation, IT incidents affecting clients, whistleblowing referrals). Timing is critical.

Being caught concealing a breach usually leads to a MUCH larger fine than the underlying issue. Self-reporting is nearly always the better outcome.

2.8 SMCR + individual accountability

Senior Managers & Certification Regime syllabus 13.1

UK SMCR (2016 → expanded 2023+) is the current UK model of individual accountability. Features:

  • Named INDIVIDUALS accountable for specified prescribed responsibilities (via statements of responsibility)
  • Personal regulatory approval for Senior Managers
  • Annual certification of "significant harm" staff as fit & proper
  • Individual Conduct Rules applying across most staff
  • Duty of responsibility — Senior Manager can be sanctioned for failures in their area, regardless of whether they knew

Similar regimes globally: Hong Kong Manager-in-Charge (2017), Singapore MAS senior management guidelines, Australia FAR (2024 for banking/insurance/super).

The Duty of Responsibility syllabus 13.2

Under SMCR's Duty of Responsibility, a Senior Manager can be personally sanctioned by the regulator where:

  1. There has been a regulatory breach in an area they were responsible for, AND
  2. They did NOT take "such steps as a person in their position could reasonably have been expected to take" to prevent it

Note: "I didn't know" is not automatically a defence. The question is: SHOULD you have known, and DID you take reasonable steps?

This shifts the incentive: managers must actively engage with their area, not delegate-and-forget.

2.9 Handling breaches + outsourcing

Standard breach playbook syllabus 15.1

  1. Containment — stop the harm continuing
  2. Investigation — facts, scope, root cause
  3. Notification where required (regulator, affected clients)
  4. Remediation (customer redress, control fix)
  5. Discipline where individuals culpable
  6. Documentation
  7. Tracked to closure

Outsourcing — accountability retained syllabus 14.1

Universal principle: you can outsource the OPERATION, not the RESPONSIBILITY.

Even for outsourced compliance operations, the firm:

  • Retains FULL regulatory accountability
  • Must due-diligence the provider
  • Must contract clearly (SLAs, access rights, exit)
  • Must monitor performance
  • Must retain sufficient in-house knowledge to oversee
  • Typically requires an internal accountable individual (Senior Manager)
"It was the outsourcer's fault" is not a defence. Regulators expect the firm to be a "smart client" of its providers.

Conflicts — avoid > manage > disclose syllabus 11.1

Response hierarchy for identified conflicts:

  1. AVOID the conflict where possible
  2. If not avoidable, MANAGE via controls (info barriers / Chinese walls, separation of duties, restricted lists, PAD rules)
  3. DISCLOSE to the client as a LAST resort, and only where management is sufficient to protect the client

Disclosure alone is NOT a fix for a genuine ongoing conflict.

2.10 All the numbers (cheat sheet)

Ch 2 quick-reference

ItemAnswer
Compliance = which line?2nd
Internal audit = which line?3rd
Business = which line?1st (owns risk)
Head of compliance reports toBoard / audit or risk committee / CEO (NOT sales/trading)
Fit & proper pillarsHonesty · Competence · Financial soundness
Conflicts hierarchyAvoid > Manage > Disclose
FCA Principle 11Open and cooperative with regulators
Duty of responsibility test"Reasonable steps a person in their position would have taken"
Outsourcing ruleFirm retains full regulatory accountability
UK SMCR started2016 (expanded 2023+)
Australia FAR started2024 (banking / insurance / super)
HK MIC started2017