Skip to main content
Category: Compliance Programs

Compliance Function

Also known as: Compliance Department
Simply put

The compliance function is the part of an organization responsible for helping ensure that employees and others associated with the firm follow the rules that apply to it. It works to prevent, detect, and respond to conduct that could violate applicable laws, regulations, or internal standards. Its structure and scope vary by organization, sector, and jurisdiction.

Formal definition

The compliance function typically comprises the organizational efforts undertaken to ensure that employees and other associated persons do not violate applicable rules, whether external legal and regulatory requirements or internal policies. In financial institutions it is generally oriented toward managing compliance risk, which the Basel Committee defines as the risk of legal or regulatory sanctions, financial loss, or reputational loss that an institution may suffer as a result of failing to comply with applicable rules. The function is commonly positioned within a broader enterprise risk management framework, though its structure, degree of independence, and reporting lines depend on the entity's size, sector, and jurisdiction; this entry is educational and not legal, audit, or compliance advice.

Why it matters

The compliance function is central to how an organization manages the risk that its people fail to follow the rules that apply to it. In financial institutions, the Basel Committee frames this in terms of compliance risk: the risk of legal or regulatory sanctions, financial loss, or reputational loss that an institution may suffer as a result of failing to comply with applicable rules. Because these consequences can be severe and can arise from the conduct of individual employees or associated persons, a dedicated function that works to prevent, detect, and respond to potential violations is generally regarded as a foundational element of organizational integrity.

The function's importance also stems from its position within a broader enterprise risk management framework. It is not the only line of assurance an organization relies on, and its accountability, independence, and reporting lines depend heavily on the entity's size, sector, and jurisdiction. Some commentary characterizes compliance as playing a distinctive, elevated role among an organization's control and assurance activities, but the precise weight given to the function varies by organization and regulatory context. Boards and senior management typically retain oversight responsibility, while the compliance function itself performs the day-to-day work of monitoring adherence to rules and internal standards.

This matters because the design of the compliance function is itself a governance choice with real consequences. A structure that is well suited to one institution's risk profile may be inadequate for another's, and getting that structure right is generally treated as crucial rather than merely administrative. This entry is educational and not legal, audit, or compliance advice; how a specific organization should structure and resource its compliance function depends on its facts, sector, and applicable jurisdictional requirements.

Who it's relevant to

Chief Compliance Officers and Compliance Teams
These professionals own the design and operation of the compliance function, including the efforts to prevent, detect, and respond to potential rule violations. Decisions about the function's structure, independence, and reporting lines fall squarely within their remit, though these decisions are shaped by the organization's size, sector, and jurisdiction.
Board Members and Senior Management
The board and senior management typically retain oversight responsibility for how the organization manages compliance risk, even though day-to-day compliance activities sit with the function itself. The choice of an appropriate compliance structure and its position within the enterprise risk management framework is a governance matter in which they generally have an interest.
Risk Officers
Because the compliance function is commonly positioned within a broader enterprise risk management framework, risk officers have reason to understand how compliance risk, defined by the Basel Committee as the risk of legal or regulatory sanctions, financial loss, or reputational loss from failing to comply with applicable rules, relates to the organization's wider risk activities.
General Counsel and Legal Teams
Legal teams are concerned with the applicable laws, regulations, and internal standards that the compliance function works to uphold, and with the legal and regulatory sanctions that can follow from non-compliance. The precise requirements vary by jurisdiction and sector, and this entry is not a substitute for legal advice.

Inside Compliance Function

Compliance Program Design
The framework of policies, procedures, and standards through which an organization seeks to conform to applicable laws, regulations, and, where adopted, voluntary codes. Design typically reflects the entity's regulatory environment, sector, and risk profile, and forms the documented basis against which conformity is assessed.
Compliance Risk Assessment
A process to identify and prioritize the legal and regulatory obligations most relevant to the organization and the areas where non-conformity is most likely or most consequential. This is generally distinct from enterprise risk management owned more broadly, though the two often coordinate.
Policies, Procedures, and Controls
The documented requirements and control activities intended to operationalize compliance obligations. A distinction is generally drawn between control design (whether a control is capable of achieving its objective) and operating effectiveness (whether it functions as intended over time).
Monitoring and Testing
Ongoing activities by which the compliance function checks whether controls and behaviors align with obligations. This is typically a second-line activity, separate from independent assurance provided by internal audit as a third line.
Training and Communication
Efforts to convey obligations, expected conduct, and reporting channels to relevant personnel. Scope and frequency generally depend on role, risk exposure, and applicable requirements, which vary by jurisdiction and sector.
Reporting and Escalation
Mechanisms, including whistleblowing or speak-up channels where applicable, through which concerns are raised and material issues escalated to management, relevant committees, and the board. Reporting lines are typically structured to preserve the function's independence.
Governance and Reporting Lines
The positioning of the compliance function within the organization, commonly with a chief compliance officer who has access to senior management and, in many structures, a direct or dotted reporting line to a board committee such as audit or a dedicated risk or compliance committee.

Common questions

Answers to the questions practitioners most commonly ask about Compliance Function.

Is the compliance function the same as the internal audit function?
No. Although both are commonly described as assurance-related functions, they typically occupy different positions and roles. Under the widely referenced three lines model, the compliance function is generally treated as a second-line function that helps management identify, manage, and monitor compliance risk, while internal audit is generally positioned as a third-line function providing independent assurance over the effectiveness of first- and second-line activities, including compliance. Conflating the two can obscure where accountability sits. That said, the precise structure varies by jurisdiction, sector, entity type, and organizational design, and this distinction is a general framing rather than a universal legal rule.
Does having a compliance function mean the compliance officer is responsible for the organization's compliance?
Not typically. The existence of a compliance function does not usually transfer ownership of compliance obligations away from the business and management. In many governance models, first-line management owns and manages compliance risk in day-to-day operations, the compliance function provides oversight, advice, monitoring, and challenge, and the board or a relevant committee exercises oversight. The compliance officer generally facilitates and monitors rather than absorbing accountability for every compliance outcome. How responsibilities are formally allocated depends on the applicable legal regime, sector expectations, and the entity's own arrangements, so this should not be read as legal advice.
Where should the compliance function report to preserve its independence?
Reporting arrangements vary by jurisdiction, sector, and entity type, and there is no single mandated structure across all contexts. A common approach in many organizations is to give the head of compliance a reporting line that supports independence, often including access to the board or a board committee alongside an administrative line into senior management. The aim is generally to allow the function to raise concerns without undue influence from the areas it monitors. The appropriate structure depends on applicable rules and the organization's own judgment, and specific regulatory requirements may apply in certain regulated sectors.
How does the compliance function typically coordinate with risk management and internal audit?
Coordination is generally designed to avoid both gaps and unnecessary duplication of effort. In many organizations, the risk management function provides frameworks and methodologies for identifying and assessing risk across categories, the compliance function focuses on compliance risk and monitoring against applicable obligations, and internal audit provides independent assurance over the design and operating effectiveness of these arrangements. Clear mandates, shared taxonomies, and defined escalation paths are commonly used to align these functions. The exact division of labor depends on the entity's structure and any applicable requirements, and this is a general description rather than a prescribed model.
What activities does a compliance function commonly perform?
Activities vary by organization, but a compliance function commonly performs some combination of the following: identifying and interpreting applicable legal and regulatory obligations, advising the business on compliance risk, developing policies and procedures, delivering training and awareness, monitoring and testing for adherence to obligations, and reporting on compliance matters to management and the board or a relevant committee. The precise remit depends on jurisdiction, sector, entity type, and how the organization allocates responsibilities. This is an educational overview and not a definitive checklist of required activities.
How can the effectiveness of a compliance function be assessed?
Effectiveness is generally assessed against the function's defined mandate and the compliance risks it is intended to help manage, rather than by a single universal metric. Common considerations include whether the function has an adequate mandate, sufficient resources and access, appropriate independence, and whether its monitoring and reporting reach the board or relevant committee in a timely and candid way. Independent assurance, such as from internal audit, is often used to evaluate design and operating effectiveness. Suitable indicators depend on the organization's context and professional judgment, and this entry is educational and not audit, legal, or compliance advice.

Common misconceptions

Compliance, risk management, and internal audit are essentially the same function performing overlapping work.
These are related but distinct disciplines with different accountabilities. Compliance and operational risk management typically sit in the second line, owning and overseeing risk within their remit, while internal audit provides independent assurance from the third line. Conflating them undermines the separation that gives assurance its value.
A documented compliance program is sufficient to demonstrate the organization is compliant.
Documentation reflects control design, but a program must also operate effectively in practice. A well-designed policy that is not followed, monitored, or tested does not by itself evidence conformity. The distinction between design and operating effectiveness is central to evaluating a program.
The board is responsible for running the compliance function day to day.
The board and its committees typically exercise oversight of compliance, satisfying themselves that an adequate program exists and receiving reporting on material matters. Management generally owns the operation of the program. Attributing operational execution to the board, or oversight to management alone, misstates where accountability sits.

Best practices

Clarify and document reporting lines so the compliance function has sufficient independence, access to senior management, and a route to the relevant board committee for escalating material issues.
Base the program on a periodic compliance risk assessment that prioritizes the obligations most relevant to the organization's jurisdictions, sector, and risk profile, rather than applying a generic checklist.
Distinguish and separately evaluate control design and operating effectiveness, since a sound policy that is not consistently followed does not evidence conformity.
Coordinate with, but do not merge, the responsibilities of risk management and internal audit, preserving the separation of duties across the lines of defense.
Maintain accessible reporting and escalation channels, including speak-up mechanisms where applicable, and ensure concerns are triaged and escalated to the appropriate level.
Tailor training and communication to role and risk exposure, and confirm through monitoring and testing that expected behaviors and controls are actually occurring.