Skip to main content
Category: Compliance Programs

Ethics and Compliance Function

Also known as: E&C, Ethics and Compliance Program, Compliance Function, Ethics and Compliance Office
Simply put

The ethics and compliance function is the part of an organization responsible for helping the business follow applicable laws and rules while also promoting values-driven, ethical behavior among its people. Compliance generally focuses on adhering to external legal requirements, whereas ethics focuses on internal values and doing the right thing; the two are related but distinct. Although a dedicated team typically coordinates these efforts, ethics and compliance are often described as responsibilities shared across every employee.

Formal definition

The ethics and compliance function refers, in general terms, to the staff and organizational arrangements charged with carrying out an entity's compliance responsibilities, typically including efforts to deter and detect potential legal and regulatory violations, alongside activities that foster an ethical, values-based culture. As reflected in guidance from the Basel Committee, the term 'compliance function' describes the personnel performing compliance responsibilities and is not intended to prescribe a particular organizational structure; entities may configure the function differently depending on their size, sector, and jurisdiction. Practitioners generally distinguish compliance (adherence to binding laws, regulations, and rules) from ethics (values-driven conduct that is internally motivated), while treating the two as complementary. The precise scope, reporting lines, and accountability of the function vary by jurisdiction, sector, and entity type, and the distribution of responsibility between a dedicated function, management, and the broader workforce is a matter of organizational design and professional judgment. This entry is educational and not legal, audit, or compliance advice.

Why it matters

The ethics and compliance function sits at the intersection of two related but distinct objectives: helping an organization adhere to the binding laws, regulations, and rules that apply to it, and fostering a values-driven culture in which people are internally motivated to do the right thing. Keeping these objectives visibly connected matters because compliance alone, treated as a checklist of external requirements, rarely produces durable good conduct, while ethics without attention to legal obligations can leave an organization exposed. A well-designed function generally works to both deter and detect potential legal and regulatory violations while reinforcing the shared expectation that ethical behavior is part of everyone's role.

A recurring theme in practitioner guidance is that ethics and compliance are often described as responsibilities shared across every employee rather than the sole province of a dedicated team. Where an organization treats compliance as something owned only by a specialist office, the culture that ultimately drives behavior can drift out of alignment with stated policies. Framing these as everyone's responsibility, while still relying on a coordinating function, helps embed expectations into day-to-day decisions rather than confining them to formal controls.

Because the precise scope, reporting lines, and accountability of the function vary by jurisdiction, sector, and entity type, boards and senior leaders should be careful not to assume a single model fits all organizations. Guidance from the Basel Committee, for example, describes the 'compliance function' as the staff carrying out compliance responsibilities and expressly does not prescribe a particular organizational structure. How responsibility is distributed among a dedicated function, line management, and the wider workforce remains a matter of organizational design and professional judgment.

Who it's relevant to

Chief Compliance and Ethics Officers
Those who lead the function are typically responsible for coordinating efforts to deter and detect potential legal and regulatory violations while promoting a values-driven culture. Because guidance such as the Basel Committee's does not prescribe a particular structure, these leaders exercise judgment over how the function is organized and how responsibility is shared with management and the wider workforce.
Boards and Board Committees
Directors generally exercise oversight of the ethics and compliance function rather than running it day to day. Their interest lies in understanding how the organization distinguishes and connects compliance (adherence to binding rules) and ethics (internally motivated conduct), and in satisfying themselves that reporting lines and accountability are appropriate for the entity's size, sector, and jurisdiction.
General Counsel and Legal Teams
Legal functions often work closely with, and in some organizations house, ethics and compliance responsibilities. Roles such as ethics and compliance counsel help ensure the organization adheres to legal standards while supporting ethical practices, though how the legal and compliance responsibilities are divided varies by organization.
Line Management and Employees
Because ethics and compliance are frequently described as responsibilities shared across every employee, managers and staff play a central role in translating policies into everyday conduct. A dedicated function typically coordinates and supports these efforts, but the culture that drives behavior depends on the broader workforce, not the specialist team alone.
Internal Auditors and Assurance Functions
Assurance providers may evaluate how the ethics and compliance function operates and whether its activities are designed and functioning as intended. Their role is generally to provide independent assurance rather than to own compliance responsibilities, keeping the distinction between the function's operational duties and independent assurance intact.

Inside E&C

Standards and Code of Conduct
A documented set of ethical expectations and behavioral standards, typically anchored by a code of conduct and supporting policies. These articulate the organization's values and translate legal and regulatory obligations into practical guidance for employees, though the specific content varies by jurisdiction, sector, and entity type.
Governance and Reporting Lines
The structural arrangements that establish where the function sits and to whom it reports. In many organizations the head of the function (for example, a chief compliance or chief ethics officer) has a reporting line to senior management for operational matters and access to the board or a board committee for independence. The precise arrangement depends on the entity and applicable frameworks or listing rules.
Training and Communication
Programs that build awareness of standards and legal obligations across the workforce, typically including onboarding, periodic refreshers, and targeted training for higher-risk roles. The scope generally reflects the risks the organization faces rather than a single mandated curriculum.
Speak-Up and Reporting Channels
Mechanisms allowing employees and, in some cases, third parties to raise concerns, often including confidential or anonymous options and protections against retaliation. Legal requirements for such channels and whistleblower protections vary significantly by jurisdiction.
Investigations and Case Management
Processes for triaging, investigating, and resolving reported concerns, along with tracking of outcomes and remediation. Accountability for consistent, documented handling typically rests with the function, though decisions on discipline usually involve management and other stakeholders.
Risk Assessment and Monitoring
Activities to identify compliance and ethics risks and to monitor whether controls are designed appropriately and operating effectively. This is generally distinct from enterprise risk management ownership and focuses on the compliance risk domain; monitoring assesses ongoing conduct rather than a one-time control design review.
Oversight and Reporting to the Board
Periodic reporting to the board or a designated committee on program effectiveness, significant matters, and emerging risks. The board or committee typically holds an oversight role, while day-to-day operation of the program sits with management and the function.

Common questions

Answers to the questions practitioners most commonly ask about E&C.

Is the ethics and compliance function the same as internal audit?
No. Although both are often described as assurance or oversight-related activities, they are distinct functions. Under the widely referenced three lines model, a compliance function typically operates as a second-line activity that helps design controls, sets policy, monitors adherence to laws and internal standards, and advises management on compliance risk. Internal audit generally operates as a third-line function providing independent assurance over the adequacy and effectiveness of governance, risk management, and controls, including the work of the compliance function itself. Treating them as interchangeable can undermine the independence that internal audit is expected to maintain. The precise structure varies by jurisdiction, sector, and entity type, and some organizations combine or separate responsibilities differently.
Does having an ethics and compliance function mean the board has discharged its oversight duty?
Not on its own. The existence of a compliance function is generally a mechanism through which management operates the compliance program day to day, but oversight of that program typically remains a board or board committee responsibility in many governance frameworks. Boards generally retain a duty to oversee whether the program is reasonably designed, resourced, and functioning, rather than to run it. Delegating operation to a compliance function does not transfer the board's oversight accountability. What satisfies an oversight duty depends on the applicable legal regime, jurisdiction, and facts, and this entry is educational rather than legal advice.
Where should the ethics and compliance function report, and does the chief compliance officer need access to the board?
Reporting lines vary by jurisdiction, sector, and entity type, so there is no single required model. In many frameworks, the chief compliance officer reports functionally to a board committee, such as an audit or compliance committee, while reporting administratively to a member of senior management. A common design goal is to preserve sufficient independence and stature for the compliance function while giving it a direct line of communication to the board or a committee, often including access without management present. Whether any of this is mandatory depends on applicable law, listing rules, and sector-specific requirements, and organizations should assess their own facts and obtain professional advice.
How can an organization assess whether its compliance program is effective rather than merely documented?
Effectiveness generally depends on more than the existence of policies. Organizations commonly distinguish between whether controls are well designed and whether they operate effectively over time. Assessment approaches may include monitoring and testing of key controls, tracking issues such as reported concerns and their resolution, evaluating training reach and comprehension, and considering culture indicators. Independent assurance, often from internal audit, can help evaluate the program separately from those who run it. The appropriate depth of assessment depends on the organization's risk profile, resources, and applicable expectations, and this entry does not prescribe a specific methodology.
How does the ethics and compliance function typically coordinate with risk management and legal?
These functions are related but distinct, and clear allocation of responsibility helps avoid gaps or duplication. Compliance generally focuses on adherence to laws, regulations, and internal standards and on compliance risk specifically, while enterprise risk management typically addresses a broader range of risks across the organization. Legal generally provides advice on legal rights, obligations, and privileged matters. In practice, organizations often define ownership of specific activities, share risk information, and agree on escalation paths so that accountability sits clearly with one function. The optimal coordination model depends on the organization's structure, size, and sector.
How should resourcing and independence of the compliance function be approached?
Adequate resourcing and appropriate independence are commonly viewed as important to a function's ability to operate objectively, though what is adequate depends on the organization's size, complexity, and risk exposure. Considerations often include sufficient budget, staffing, expertise, and authority, as well as structural safeguards that reduce conflicts of interest, such as reporting arrangements and protection of the compliance leader's position. Some regulated sectors impose specific requirements on independence and resourcing, while for other entities these are matters of governance judgment guided by non-binding frameworks. Organizations should assess their own circumstances and applicable requirements rather than rely on a fixed standard.

Common misconceptions

The ethics and compliance function is the same as internal audit or the risk management function.
These are related but distinct disciplines. The ethics and compliance function generally owns the design and operation of the compliance program as a management activity, often positioned within the second line. Internal audit typically provides independent assurance over that program from the third line, and enterprise risk management addresses a broader risk universe. Conflating them obscures where accountability and independent assurance actually sit.
Having a written code of conduct and policies means the organization has an effective compliance program.
Documented standards address control design, but effectiveness also depends on operating effectiveness, meaning the controls work in practice over time. Training, functioning speak-up channels, consistent investigations, monitoring, and remediation are generally needed for a program to be more than a paper exercise.
The board runs the ethics and compliance program.
In most models the board or a board committee provides oversight and challenge, while management and the function are responsible for building and operating the program. Attributing operational execution to the board, or attributing oversight solely to management, misstates the typical allocation of roles.

Best practices

Clarify and document reporting lines so the head of the function has operational access to senior management and independent access to the board or a designated committee, reflecting the organization's structure and any applicable listing or regulatory requirements.
Base training, monitoring, and control priorities on a periodic compliance risk assessment rather than a generic checklist, focusing resources on the areas of greatest inherent and residual risk.
Distinguish clearly between the function's ownership of program design and operation and internal audit's independent assurance role, avoiding overlap that could compromise the independence of assurance.
Maintain confidential speak-up channels with clear anti-retaliation protections, and follow a consistent, documented process for triaging, investigating, and remediating reported concerns.
Report periodically to the board or its committee on program effectiveness, significant matters, and emerging risks, distinguishing control design from evidence of operating effectiveness.
Treat program materials as educational governance tools and confirm specific legal obligations against applicable law, regulation, and jurisdiction, drawing on qualified legal, audit, or compliance advice where facts and judgment are decisive.