CySEC Advanced · Chapter 3 · Topic 2 of 12

What must an investment firm's compliance function do, and how independent must it be?

The four tasks of the MiFID II compliance function, the conditions that keep it independent, when two of them can be relaxed, and what ESMA and CySEC add.

By the ExamPass CY editorial teamLast reviewed 6 min read

Short answer

Every investment firm needs a permanent, effective and independent compliance function. It monitors permanently and assesses regularly whether the firm's compliance measures work, advises and assists staff, oversees complaints handling and reports to the management body at least annually, and directly and ad hoc when it finds a significant risk. The management body appoints and replaces the compliance officer. Compliance staff may not take part in what they monitor and their pay must not undermine their objectivity, unless the firm shows these two conditions are disproportionate and the function stays effective.

The compliance function at a glance

PurposeDetect the risk that the firm fails to meet its obligations and minimise that risk
TasksMonitor permanently and assess regularly; advise and assist relevant persons; report to the management body at least annually; monitor complaints handling
Monitoring programmeBuilt on a compliance risk assessment, covering all areas of the business and prioritised by risk
Independence conditionsAuthority, resources, expertise and access to information; the management body appoints and replaces the officer; direct ad hoc reports on significant risks; staff not involved in what they monitor; pay that does not compromise objectivity
Relaxing two conditionsNon-involvement and pay only, if the firm shows they are disproportionate and the function stays effective; the assessment is reviewed regularly
BudgetWhere the firm sets budgets for its functions: consistent with the level of compliance risk; officer consulted beforehand; significant cuts documented in writing with detailed reasons
Combining functionsPossible with other control functions if effectiveness and independence are not compromised, documented with its reasons; never with internal audit
In CyprusA CIF's regulatory compliance officer must have passed CySEC's Advanced examination and be on CySEC's public register; CySEC may approve an unregistered appointee, who then has six months (two exam sittings) to qualify

Source: Delegated Regulation (EU) 2017/565, Articles 22 and 25; ESMA Guidelines on the MiFID II compliance function (ESMA35-36-1952); CySEC Directive on the certification of persons and the certification registers.

What does the compliance function do?

A firm must have policies and procedures aimed at spotting any risk of failing to meet its obligations, and measures to keep that risk low, scaled to the size and complexity of its business. To run them it needs a permanent and effective compliance function that operates independently.

The function has four tasks. It monitors on a permanent basis, and assesses on a regular basis, whether the firm's measures and the actions taken to address deficiencies are adequate and effective. It advises and assists the people responsible for investment services. It reports to the management body at least once a year on the control environment for investment services, the risks identified and complaints handling, including remedies taken or to be taken. And it monitors how the complaints-handling process works.

Its work follows a compliance risk assessment, which leads to a risk-based monitoring programme covering all areas of the firm's investment and ancillary services, with priorities set by the level of risk so that compliance risk is monitored comprehensively. Risk-based means every area is covered, with more attention where the risk is higher.

Terms used in this note

Compliance risk
The risk that the firm fails to meet its obligations under MiFID II and the national law that transposes it.
Management body
The firm's board of directors, which appoints and replaces the compliance officer and receives the compliance reports.
Monitoring programme
The plan of compliance reviews, built on a risk assessment, that covers every area of the business with priorities set by risk.

How is its independence protected?

Five conditions apply. The function needs sufficient authority, resources and expertise, and access to every piece of relevant information. The management body appoints and replaces the compliance officer, who is responsible for the function and its reports. Whenever the function finds a significant risk that the firm may fail to comply, it reports directly to the management body, without waiting for the annual cycle. Its staff must not be involved in performing the services or activities they monitor. And the way they are paid must not compromise, or be likely to compromise, their objectivity.

The last two conditions can be disapplied, but only if the firm can demonstrate that, given its business, they would be disproportionate and that the function still works effectively. The firm must then assess whether effectiveness is compromised, and review that assessment regularly. Senior management also receives written reports on compliance at least annually.

What do ESMA's guidelines and CySEC add?

ESMA's guidelines on the compliance function, which replaced the 2012 version in 2021, expand on the Delegated Regulation. Where the firm sets budgets for specific functions, the budget for compliance should match the level of compliance risk; the compliance officer should be consulted before it is set, and any decision to cut it significantly should be documented in writing with detailed reasons. The compliance officer needs sufficiently broad knowledge and experience and a high level of expertise, including knowledge of MiFID II and national law. Combining compliance with other control functions of the same level, such as money laundering prevention, may be acceptable if it does not compromise the function's effectiveness and independence and is documented with its reasons, but an internal audit function may never be combined with compliance.

In Cyprus a CIF may appoint someone as its regulatory compliance officer only if that person has passed CySEC's Advanced examination and is entered in CySEC's public register. As an exception, CySEC may approve, on prior written notice from the firm, a person who is not yet registered; that person must then qualify and register within six months, with two examination sittings to do so. CySEC may extend the six months only if no examination slot is available or there is another serious impediment. The officer who monitors money laundering controls is a separate role under the AML/CFT Law, described in What does the AML compliance officer do?

How to think about it

Remember the verbs and the audience. Compliance monitors all the time and assesses from time to time; it advises and assists; it reports to the board at least once a year and at once when something serious turns up. Independence rests on five legs, and only two of them, not being involved in the work and not being paid in a way that skews judgement, can be removed, and only with proof that the function still works.

Common mistakes

  1. Swapping 'permanent' and 'regular'. Monitoring is permanent; assessment of effectiveness is regular.

  2. Letting the CEO appoint the compliance officer. The management body appoints and replaces the officer.

  3. Relying only on the annual report. Significant risks are reported directly and ad hoc, not saved for the annual report.

  4. Reading 'risk-based' as 'high-risk areas only'. All areas are covered; risk sets the priorities and depth.

  5. Combining compliance with internal audit. That combination is never acceptable.

Practise this topic

Test what you just read

The Chapter 3 pack has 155 exam-style questions, 20 of them on this topic. Every question has a hint before you answer and a full explanation after.

Try the free demo

Or revise the numbers first with 53 free Chapter 3 flashcards →

Last reviewed on by the ExamPass CY editorial team against the law in force on that date. Study notes help you prepare for the CySEC exams; they are not legal advice. ExamPass CY is not affiliated with CySEC.

How we write study notesReport an error