Home › Blog › Compliance

What Is a Compliance Officer? The Role, the Legal Duties and When You Need One

What is a compliance officer? In short, the person responsible for making sure an organisation follows the laws, regulations and internal rules that apply to it, and for spotting and reporting when it does not. In some sectors the role is a legal requirement: firms regulated by the Financial Conduct Authority must have a senior manager responsible for compliance oversight, and businesses covered by the Money Laundering Regulations need a nominated officer for suspicious activity. Elsewhere it is a choice, but an increasingly common one since the failure to prevent fraud offence came into force on 1 September 2025. This page explains what the job involves, where it sits, which roles are required by law and how to set one up in a smaller business.

Where a compliance officer sits The three lines model, a common way to split risk responsibilities First line: Operational managers Own the risks and run the controls day to day Second line: Compliance and risk Set policy, advise, monitor and challenge Third line: Internal audit Independent assurance to the board The board and audit committee oversee all three lines. Graphic by e-Business Ethics
The three lines model. A compliance officer sits in the second line, setting policy and checking the first line, while internal audit provides independent assurance. Graphic by e-Business Ethics.

The job: know the rules, write the policies, train people, monitor, investigate and report to the board.

Required by law in some sectors: FCA firms (Compliance Oversight, SMF16, and Money Laundering Reporting Officer, SMF17), and businesses under the Money Laundering Regulations 2017 (a nominated officer).

Not the same as: a Data Protection Officer, which UK GDPR requires only in certain cases, or a company secretary.

What a compliance officer does

The detail varies by sector, but the job has the same core in almost every organisation:

  1. Map the obligations. Work out which laws and rules apply: sector regulation, anti-bribery, anti-money laundering, data protection, consumer law, health and safety, modern slavery reporting and so on. Keep a register and track changes.
  2. Assess the risks. Decide where the business is most exposed, by activity, country, product or customer type, and focus effort there.
  3. Write and maintain policies. A code of conduct, gifts and hospitality rules, a whistleblowing policy, conflicts of interest, and the procedures that make them real.
  4. Train people. Make sure staff know the rules that apply to their job, and keep records of who was trained on what.
  5. Monitor and test. Check that controls are working: sample transactions, review approvals, run audits of high-risk areas.
  6. Investigate and report. Look into concerns and breaches, report to senior management and the board, and where the law requires it, to regulators.
  7. Advise. Be the person managers ask before they do something new, not after.

Our guide to building a compliance programme goes through these steps as a project plan.

Where the role sits

Many organisations organise risk responsibilities using the three lines model shown above. Operational managers are the first line: they own the risks in their area and run the controls. Compliance and risk functions are the second line: they set the framework, advise and challenge. Internal audit is the third line, giving the board independent assurance that the first two are working.

Two features matter for a compliance officer to be effective: independence from the people they check, and direct access to the board or audit committee. A compliance officer who reports only to the sales director they are meant to challenge cannot do the job properly. See our page on governance versus management for how this fits board oversight.

When the law requires one

FCA-regulated firms

Under the Senior Managers and Certification Regime, many firms regulated by the FCA must allocate the Compliance Oversight function (SMF16) to an approved senior manager, responsible for the firm's compliance with FCA rules, and the Money Laundering Reporting Officer function (SMF17). In smaller firms one person may hold both. These are personal, approved roles: the individual can be held accountable by the regulator.

Businesses under the Money Laundering Regulations

Accountants, tax advisers, estate and letting agents, high-value dealers, solicitors and other businesses supervised under the Money Laundering Regulations 2017 must appoint a nominated officer to receive internal reports of suspicion and decide whether to report to the National Crime Agency. Where it is appropriate to the size and nature of the business, the Regulations also require a board member, or equivalent, to be responsible for compliance with them.

Data protection

UK GDPR requires a Data Protection Officer only for public authorities and for organisations whose core activities involve large-scale regular monitoring of individuals or large-scale processing of special category or criminal offence data. A DPO is a distinct role with protected independence; it is not automatically the compliance officer. Our UK GDPR guide covers when you need one.

When there is no legal requirement

Most companies are not obliged to appoint a compliance officer, but the law increasingly rewards those that can show they had proper procedures. Two examples:

  • Bribery Act 2010. A company commits the section 7 offence if someone associated with it bribes to win business for it. The only defence is to show it had adequate procedures to prevent bribery. See our Bribery Act compliance guide.
  • Failure to prevent fraud. Since 1 September 2025, large organisations, those meeting two of more than 250 employees, more than £36 million turnover and more than £18 million in total assets, can be liable if an employee or agent commits fraud intending to benefit them, unless they had reasonable prevention procedures. Our page on failure to prevent fraud explains the offence.

In both cases, a named person who owns the procedures, keeps them up to date and can evidence training and monitoring is the practical heart of the defence.

Setting up the role in a smaller business

A business with a few dozen staff rarely needs a full-time compliance officer. Common, workable set-ups are:

  • A named director who holds compliance as a formal responsibility alongside other duties, with time set aside for it and an annual report to the board.
  • A part-time or outsourced compliance consultant who builds the framework and reviews it periodically, with an internal owner for day-to-day questions.
  • A compliance lead in a related role, such as finance, legal or HR, as long as they are not checking their own work in high-risk areas.

Whatever the model, write the role down: what the person is responsible for, who they report to, how often they report, and their right to raise concerns directly with the board. Pair it with a whistleblowing policy, so staff can raise concerns without going through their line manager.

Skills and qualifications

There is no single licence to be a compliance officer outside the regulated roles above, where the FCA assesses fitness and propriety. Employers usually look for knowledge of the relevant regulation, judgement, clear writing, and the confidence to challenge senior people. Professional bodies such as the International Compliance Association offer certificates and diplomas in compliance and anti-money laundering, and many compliance officers come from legal, audit or operational backgrounds in the same sector.

Frequently Asked Questions

What does a compliance officer do?

They identify the laws and rules that apply to the organisation, write policies, train staff, monitor whether controls work, investigate concerns and report to senior management, the board and, where required, regulators.

Is a compliance officer a legal requirement in the UK?

Only in some sectors. FCA-regulated firms must allocate compliance oversight and MLRO functions to senior managers, and businesses under the Money Laundering Regulations need a nominated officer. Most other companies are not required to appoint one.

What is the difference between a compliance officer and a Data Protection Officer?

A compliance officer covers the organisation's obligations broadly. A Data Protection Officer is a specific role under UK GDPR, required only in certain cases, with duties limited to data protection and a protected independent position.

Who should a compliance officer report to?

To senior management, with direct access to the board or audit committee. They should be independent of the business areas they monitor.

Does a small business need a compliance officer?

Not usually as a full-time post, but naming a director or manager as responsible for compliance, with time and a reporting line to the board, helps show adequate procedures under the Bribery Act and similar laws.