Compliance Officer
A compliance officer is the individual a regulated firm formally designates as responsible for its anti-money-laundering program — the person named on a licensing application, asked for by a bank during onboarding, and interviewed by an examiner. In the United States the role is often called the BSA officer.
Also called: BSA officer · chief compliance officer · CCO
Every regulated firm has to name someone. The compliance officer is the individual a firm formally designates as responsible for its AML program: the single point of accountability for whether the controls exist, work, and are followed.
The title varies and so do the duties. In the United States the financial-crime role is often the BSA officer, and in larger firms the chief compliance officer, whose remit extends past financial crime into conduct, licensing and consumer rules. In the United Kingdom the job is split in two: the regulations require a member of the board or of senior management to be the officer responsible for the firm’s compliance, and separately require a nominated officer — in practice the money laundering reporting officer, the MLRO — to receive internal suspicion reports and decide whether to report them onward. Both appointments have to be notified to the supervisor. Do not assume two titles in two countries cover the same job.
The work itself is unglamorous. Owning the risk assessment. Keeping policies current as products change. Running or overseeing transaction monitoring and escalation. Making reporting decisions and defending them. Arranging training. Handling examinations and bank due diligence questionnaires. Commissioning the independent AML review and closing its findings. Designating an officer does not move responsibility off the board — in most regimes senior management remains accountable for the program regardless of who runs it day to day.
In practice
How senior the appointment has to be depends on the regime, so name it. The UK requires the compliance officer, where appropriate to the size and nature of the business, to be a member of the board or of senior management, and the EU requires a compliance officer at management level — a requirement that becomes unconditional across the EU from 10 July 2027, when a compliance manager drawn from the management body will also be mandatory. The US money services business rule sets no rank at all: it asks only that a person be designated to assure day-to-day compliance. Whatever the rule says about seniority, a nominal appointment — a name on an organization chart who cannot escalate, exit a customer or stop a product — remains one of the most common examination findings there is.
Example
A startup appoints its head of operations as compliance officer. She also carries the revenue target for the customer segment she is meant to police. When she recommends exiting a large account, the CEO overrules her and nothing is minuted. The appointment is real; the authority is not, and the authority is what an examiner tests.
Commonly confused with
| Term | How it differs |
|---|---|
| MLRO | MLRO is a defined United Kingdom role centred on receiving and deciding internal suspicion reports; a US BSA officer’s duties are set out differently and are not a straight translation. |
| Control Person | A control person is identified by ownership or the power to direct a firm and matters for licensing approval; a compliance officer is an appointed functional role. |
See also
- MLROThe Money Laundering Reporting Officer is the named individual an FCA-regulated firm appoints to oversee its anti-money-laundering systems and controls. In most firms the same person is also the firm’s nominated officer, the separate appointment that receives internal suspicion reports and decides what is reported onward. The responsibility attaches to the person, not to a department.
- AML ProgramAn AML program is the documented set of controls a regulated firm must maintain to detect and deter money laundering. In the United States it is conventionally described as four pillars: written policies and procedures, a designated compliance officer, staff training, and independent review. Other regimes frame the same components differently.
- Independent AML ReviewAn independent AML review is the periodic examination of a firm’s anti-money-laundering program by someone who is not responsible for running it. In the United States it is a mandatory element of the program; in the United Kingdom and European Union it is required where the size and nature of the business make it appropriate.
- Anti-Money LaunderingAnti-money laundering, usually shortened to AML, is the body of law, regulation and internal controls requiring financial firms to detect, prevent and report attempts to disguise the origin of criminal proceeds. It is an obligation placed on the firm, not a product the firm can buy.
