A compliance officer is the person responsible for making sure a firm follows the laws and regulations that apply to it. In financial services, that includes anti-money laundering, sanctions, and conduct rules. The role overlaps with, but is broader than, the money laundering reporting officer.
Key takeaways
- A compliance officer keeps a firm on the right side of the rules that apply to it.
- In finance, the role centers on anti-money laundering, sanctions, and conduct.
- It is broader than the MLRO, which is focused on money laundering.
- The role needs independence and a direct line to the board.
- A senior version is the Chief Compliance Officer, who leads the function.
- Regulators increasingly hold compliance officers personally accountable.
On this page
What it isWhat they doOfficer vs MLROIn financial servicesSkills neededWhere the role sitsThe Chief Compliance OfficerChallengesFAQsRead more
1989
Year the FATF set the standard compliance officers work within
Source: FATF
$3B
Paid by TD Bank in 2024 after compliance failures
Source: US Department of Justice
$800B to $2T
Laundered worldwide each year that compliance aims to stop
Source: UNODC
What is a compliance officer?
A compliance officer is the person a firm relies on to follow the rules that govern it. They translate laws and regulations into practices the firm can actually run, and they check that it does.
The role exists in many industries, but it is especially central in financial services, where the rules are dense and the penalties for breaking them are severe.
At its heart, the job is about keeping the firm and its people out of trouble. Read more: in AML, the closely related role is the money laundering reporting officer.
What does a compliance officer do?
A compliance officer carries a broad remit that runs from writing rules to catching problems. The core duties are consistent across firms.
- Know the rules. Track the laws and regulations that apply to the firm.
- Write policies. Turn those rules into clear internal procedures.
- Advise the business. Guide teams on how to stay compliant.
- Monitor and test. Check that controls work and spot gaps.
- Handle reporting. Report issues to leadership and to regulators.
- Train staff. Build awareness of the rules across the firm.
The exact mix depends on the firm, but the thread is the same: prevent, detect, and correct compliance failures.
Compliance officer vs MLRO vs BSA officer
These roles overlap, which causes confusion. The difference is scope and, in some places, a legal title.
A compliance officer covers all the rules that apply to a firm. An MLRO, the UK term, is focused specifically on anti-money laundering. The BSA officer is the US equivalent of the MLRO, designated under the Bank Secrecy Act.
| Role | Scope | Where used |
|---|---|---|
| Compliance officer | All applicable rules | General |
| MLRO | Anti-money laundering | UK and aligned regimes |
| BSA or AML officer | Anti-money laundering | United States |
In a small firm, one person may hold all of these at once. In a large bank, they are separate roles within a wider team.
Start your compliance policy in minutes
Generate a tailored AML policy draft that sets out roles and controls, ready for your compliance officer to adapt.
The compliance officer in financial services
In a bank or payment firm, compliance work leans heavily on financial crime. That is where the biggest risks and the biggest penalties sit.
The compliance officer oversees anti-money laundering, sanctions screening, and conduct rules, often alongside a dedicated MLRO. They make sure the firm knows its customers, watches transactions, and reports suspicion, and they answer to the regulator when asked.
The stakes are shown by enforcement. In 2024, TD Bank agreed to about $3 billion after compliance and monitoring failures (US Department of Justice, 2024).
Give your compliance team a screening tool
Run one search across sanctions, PEP, and adverse media data as part of your compliance checks.
Skills a compliance officer needs
The role calls for a mix of knowledge and character. Technical skill alone is not enough.
- Knowledge of the rules. A sound grasp of the laws that apply to the firm.
- Judgment. The ability to weigh risk and make a call.
- Communication. Explaining rules clearly to the business.
- Independence. The nerve to challenge the business and say no.
- Attention to detail. Spotting the gap that others miss.
Where the compliance role sits
For compliance to work, it has to be independent of the business it checks. Structure is what protects that independence.
In the common three lines of defense model, compliance is the second line: separate from the business, which is the first line, and from internal audit, which is the third. A strong compliance officer reports high in the firm, often with a direct line to the board, so they cannot simply be overruled.
The Chief Compliance Officer
In larger firms, the compliance function is led by a Chief Compliance Officer, or CCO. The CCO sits at the top of the compliance structure.
The CCO sets the firm’s compliance strategy, owns the relationship with regulators, and reports to senior management and the board. Beneath them sits a team that may include the MLRO, sanctions specialists, and compliance analysts. The role carries real weight and real accountability.
Get an indicative AML risk rating
See where your money laundering risk is concentrated so your compliance function can focus where it matters.
Challenges and accountability
The compliance role has grown harder as rules multiply and regulators pursue individuals. The pressure is real.
Common challenges include heavy workloads, tension between compliance and commercial goals, and the risk of personal liability. In the UK, the Senior Managers and Certification Regime ties named individuals to specific responsibilities, so a compliance officer can be held personally accountable for failures.
That accountability makes independence and firm support more than a nicety. They protect the person in the role as much as the firm.
None of this means the role is thankless. A compliance officer who is trusted, resourced, and properly heard has real influence over how a firm behaves. The best ones are seen as partners to the business rather than a brake on it, which is also the surest way to keep a firm out of the trouble that ends careers.
Frequently asked questions
What is a compliance officer?
A compliance officer is the person responsible for making sure a firm follows the laws and regulations that apply to it. They turn rules into internal procedures, advise the business, monitor controls, and report issues. In financial services the role centers on anti-money laundering, sanctions, and conduct, and it is broader than the MLRO.
What does a compliance officer do?
A compliance officer tracks the rules that apply to the firm, writes policies to meet them, advises teams on staying compliant, monitors and tests controls, reports issues to leadership and regulators, and trains staff. The exact mix varies by firm, but the thread is the same: to prevent, detect, and correct compliance failures.
What is the difference between a compliance officer and an MLRO?
A compliance officer covers all the rules that apply to a firm, while an MLRO is focused specifically on anti-money laundering. MLRO is the UK term, and the BSA or AML officer is the US equivalent. In a small firm, one person may hold both roles, while a large bank keeps them separate within a wider team.
What is a Chief Compliance Officer?
A Chief Compliance Officer, or CCO, leads the compliance function in a larger firm. The CCO sets compliance strategy, owns the relationship with regulators, and reports to senior management and the board. Beneath them sits a team that may include the MLRO, sanctions specialists, and analysts. The role carries significant weight and accountability.
What skills does a compliance officer need?
A compliance officer needs sound knowledge of the rules, good judgment to weigh risk, clear communication to explain rules to the business, independence to challenge and say no, and attention to detail to spot gaps. Technical knowledge alone is not enough, because much of the role is about influence and judgment.
Does a compliance officer need to be independent?
Yes. For compliance to work, the role must be independent of the business it checks. In the three lines of defense model, compliance is the second line, separate from the business and from internal audit. A strong compliance officer reports high in the firm, often with a direct line to the board, so they cannot simply be overruled.
Can a compliance officer be held personally liable?
Yes. Regulators increasingly hold individuals accountable as well as firms. In the UK, the Senior Managers and Certification Regime ties named individuals to specific responsibilities, so a compliance officer can be held personally responsible for failures. This is why genuine independence and firm support matter, as they protect the person as well as the firm.
Where does the compliance officer sit in a firm?
The compliance officer sits in the second line of defense, independent of the business, which is the first line, and of internal audit, which is the third. To protect that independence, the role usually reports high in the firm, often with a direct line to the board, so compliance decisions cannot easily be overridden by the business.
What is the difference between a compliance officer and a BSA officer?
A BSA officer is a compliance role focused specifically on the US Bank Secrecy Act and anti-money laundering, designated as a program requirement. A compliance officer is broader, covering all the rules that apply to a firm. In practice, a firm may have a compliance officer who also serves as, or oversees, the BSA officer.
Is a compliance officer required by law?
In regulated firms, a designated compliance role is effectively required. US anti-money laundering rules require a designated BSA or AML compliance officer, and UK rules require an MLRO. Broader compliance responsibilities may sit with the same person. The law focuses on having a named, accountable person, whatever the exact title.
What industries employ compliance officers?
Compliance officers work across many regulated industries, including banking, payments, insurance, investment, healthcare, and energy. The role is especially central in financial services, where rules are dense and penalties are severe. Any organization facing significant regulation is likely to need someone responsible for meeting those rules.
What is the compliance function?
The compliance function is the team and structure responsible for meeting a firm’s regulatory duties. In a large firm it is led by a Chief Compliance Officer and may include the MLRO, sanctions specialists, and analysts. It sits in the second line of defense, setting rules, advising the business, and checking that controls work.
Read more: our ultimate guides, whitepapers and templates
Related guides and resources to help you act on what you just read.
Last reviewed July 12, 2026 · 10 min read · Written for compliance and risk professionals · By the WhoWiki editorial team
Key takeaway: a compliance officer makes sure a firm follows the laws that apply to it, a role that in financial services centers on anti-money laundering and sanctions.