What must an investment firm's compliance function do, and how independent must it be?
The four tasks of the MiFID II compliance function, the conditions that keep it independent, when two of them can be relaxed, and what ESMA and CySEC add.
By the ExamPass CY editorial teamLast reviewed 6 min read
Topic 2 of 12 · all topics in this chapter
Short answer
Every investment firm needs a permanent, effective and independent compliance function. It monitors permanently and assesses regularly whether the firm's compliance measures work, advises and assists staff, oversees complaints handling and reports to the management body at least annually, and directly and ad hoc when it finds a significant risk. The management body appoints and replaces the compliance officer. Compliance staff may not take part in what they monitor and their pay must not undermine their objectivity, unless the firm shows these two conditions are disproportionate and the function stays effective.
The compliance function at a glance
| Point | Rule |
|---|---|
| Purpose | Detect the risk that the firm fails to meet its obligations and minimise that risk |
| Tasks | Monitor permanently and assess regularly; advise and assist relevant persons; report to the management body at least annually; monitor complaints handling |
| Monitoring programme | Built on a compliance risk assessment, covering all areas of the business and prioritised by risk |
| Independence conditions | Authority, resources, expertise and access to information; the management body appoints and replaces the officer; direct ad hoc reports on significant risks; staff not involved in what they monitor; pay that does not compromise objectivity |
| Relaxing two conditions | Non-involvement and pay only, if the firm shows they are disproportionate and the function stays effective; the assessment is reviewed regularly |
| Budget | Where the firm sets budgets for its functions: consistent with the level of compliance risk; officer consulted beforehand; significant cuts documented in writing with detailed reasons |
| Combining functions | Possible with other control functions if effectiveness and independence are not compromised, documented with its reasons; never with internal audit |
| In Cyprus | A CIF's regulatory compliance officer must have passed CySEC's Advanced examination and be on CySEC's public register; CySEC may approve an unregistered appointee, who then has six months (two exam sittings) to qualify |
Source: Delegated Regulation (EU) 2017/565, Articles 22 and 25; ESMA Guidelines on the MiFID II compliance function (ESMA35-36-1952); CySEC Directive on the certification of persons and the certification registers.
What does the compliance function do?
A firm must have policies and procedures aimed at spotting any risk of failing to meet its obligations, and measures to keep that risk low, scaled to the size and complexity of its business. To run them it needs a permanent and effective compliance function that operates independently.
The function has four tasks. It monitors on a permanent basis, and assesses on a regular basis, whether the firm's measures and the actions taken to address deficiencies are adequate and effective. It advises and assists the people responsible for investment services. It reports to the management body at least once a year on the control environment for investment services, the risks identified and complaints handling, including remedies taken or to be taken. And it monitors how the complaints-handling process works.
Its work follows a compliance risk assessment, which leads to a risk-based monitoring programme covering all areas of the firm's investment and ancillary services, with priorities set by the level of risk so that compliance risk is monitored comprehensively. Risk-based means every area is covered, with more attention where the risk is higher.
Terms used in this note
- Compliance risk
- The risk that the firm fails to meet its obligations under MiFID II and the national law that transposes it.
- Management body
- The firm's board of directors, which appoints and replaces the compliance officer and receives the compliance reports.
- Monitoring programme
- The plan of compliance reviews, built on a risk assessment, that covers every area of the business with priorities set by risk.
How is its independence protected?
Five conditions apply. The function needs sufficient authority, resources and expertise, and access to every piece of relevant information. The management body appoints and replaces the compliance officer, who is responsible for the function and its reports. Whenever the function finds a significant risk that the firm may fail to comply, it reports directly to the management body, without waiting for the annual cycle. Its staff must not be involved in performing the services or activities they monitor. And the way they are paid must not compromise, or be likely to compromise, their objectivity.
The last two conditions can be disapplied, but only if the firm can demonstrate that, given its business, they would be disproportionate and that the function still works effectively. The firm must then assess whether effectiveness is compromised, and review that assessment regularly. Senior management also receives written reports on compliance at least annually.
What do ESMA's guidelines and CySEC add?
ESMA's guidelines on the compliance function, which replaced the 2012 version in 2021, expand on the Delegated Regulation. Where the firm sets budgets for specific functions, the budget for compliance should match the level of compliance risk; the compliance officer should be consulted before it is set, and any decision to cut it significantly should be documented in writing with detailed reasons. The compliance officer needs sufficiently broad knowledge and experience and a high level of expertise, including knowledge of MiFID II and national law. Combining compliance with other control functions of the same level, such as money laundering prevention, may be acceptable if it does not compromise the function's effectiveness and independence and is documented with its reasons, but an internal audit function may never be combined with compliance.
In Cyprus a CIF may appoint someone as its regulatory compliance officer only if that person has passed CySEC's Advanced examination and is entered in CySEC's public register. As an exception, CySEC may approve, on prior written notice from the firm, a person who is not yet registered; that person must then qualify and register within six months, with two examination sittings to do so. CySEC may extend the six months only if no examination slot is available or there is another serious impediment. The officer who monitors money laundering controls is a separate role under the AML/CFT Law, described in What does the AML compliance officer do?
How to think about it
Remember the verbs and the audience. Compliance monitors all the time and assesses from time to time; it advises and assists; it reports to the board at least once a year and at once when something serious turns up. Independence rests on five legs, and only two of them, not being involved in the work and not being paid in a way that skews judgement, can be removed, and only with proof that the function still works.
Common mistakes
Swapping 'permanent' and 'regular'. Monitoring is permanent; assessment of effectiveness is regular.
Letting the CEO appoint the compliance officer. The management body appoints and replaces the officer.
Relying only on the annual report. Significant risks are reported directly and ad hoc, not saved for the annual report.
Reading 'risk-based' as 'high-risk areas only'. All areas are covered; risk sets the priorities and depth.
Combining compliance with internal audit. That combination is never acceptable.
Legal references
- Commission Delegated Regulation (EU) 2017/565 (MiFID II organisational requirements and operating conditions), as amended (opens in a new tab)
Article 22 (compliance) · Article 25(2) (reports to senior management)
- ESMA Guidelines on certain aspects of the MiFID II compliance function requirements (ESMA35-36-1952) (opens in a new tab)
- CySEC Directive on the certification of persons and the certification registers, consolidated (opens in a new tab)
Paragraph 5(6) and 5(11)
- The Investment Services and Activities and Regulated Markets Law of 2017 (Law 87(I)/2017), consolidated Greek text on CyLaw (amendments up to Law 183(I)/2025) (opens in a new tab)
Article 17(2) (compliance policies and procedures)
Practise this topic
Test what you just read
The Chapter 3 pack has 155 exam-style questions, 20 of them on this topic. Every question has a hint before you answer and a full explanation after.
Or revise the numbers first with 53 free Chapter 3 flashcards →