Brief
In-house, outsourced or co-sourced compliance: a governance comparison
A comparison of compliance resourcing models through accountability, capability, information access, provider oversight, continuity and exit planning.
Michaela Clarke
Operations & Compliance Coordinator

At a Glance
This article compares in-house, outsourced, and co-sourced compliance models for FCA-regulated firms, focusing on governance aspects such as accountability, capability, information access, provider oversight, continuity, and exit planning. It is aimed at founders, boards, MLROs, and operations leads considering compliance resourcing. The FCA’s updated outsourcing and operational resilience guidance and new third-party reporting rules effective from March 2027 are key contextual drivers.
The FCA's outsourcing and operational-resilience page, updated in July 2026, clarifies that firms retain full responsibility for risks arising from outsourced or third-party services. This includes lifecycle risk management, dependency assessment, and operational resilience oversight. Boards and senior management remain accountable regardless of whether compliance functions are in-house or outsourced. This underscores the importance of clear governance arrangements and robust oversight mechanisms.
From March 2027, firms in scope of the FCA’s new material third-party arrangements reporting regime must notify the FCA about significant outsourcing or non-outsourcing arrangements and maintain an annual register. This regime supplements existing obligations and does not reduce firms’ accountability for managing outsourced compliance or other third-party services. Firms should therefore carefully consider the governance and operational implications when choosing or evolving their compliance delivery model.
Who Needs to Choose
The FCA’s outsourcing and operational resilience guidance primarily affects regulated firms that use third-party services for critical functions, including compliance. Founders, boards, MLROs, and operations leads involved in compliance resourcing decisions should consider the FCA’s expectations on accountability and risk management when choosing between in-house, outsourced, or co-sourced compliance models.
From 18 March 2027, specified in-scope firms must notify the FCA when entering or materially changing a material third-party arrangement and submit an annual register. Firms outside that reporting perimeter continue to meet their existing applicable obligations, including Principle 11 and relevant outsourcing notifications. A compliance-support arrangement should not be labelled reportable without testing the firm and arrangement against the FCA's perimeter and materiality criteria.
Compare the operating models against the same risks
An in-house team offers direct access and business context but can create key-person and specialist-capability gaps. Outsourcing can add breadth and variable capacity, but only if the firm retains enough knowledge, information and authority to challenge the provider. Co-sourcing can combine internal ownership with specialist support, although unclear interfaces can leave each side assuming the other owns the decision.
The board should define the outcomes, non-delegable decisions, information rights, service evidence, escalation path and exit plan before comparing cost. Where the 2027 material third-party reporting regime may apply, the firm should separately test its own perimeter and the arrangement's materiality rather than assuming every compliance provider belongs in the register.
| Decision factor | In-house | Outsourced | Co-sourced |
|---|---|---|---|
| Decision ownership | Direct, provided roles are clear | Must remain with the firm | Needs an explicit responsibility map |
| Specialist depth | Depends on team size and recruitment | Potentially broad, but test named-resource access | Targeted depth alongside internal knowledge |
| Information and challenge | Fast access, with independence risk to manage | Contract, access rights and internal challenge capability are critical | Strong when interfaces and escalation are designed |
| Continuity and exit | Key-person and succession exposure | Provider dependency and exit-transfer exposure | Shared continuity, but hand-offs need testing |
| Best fit | Stable scale with sufficient internal breadth | Defined needs with a capable internal owner | Internal ownership plus variable specialist support |
What the FCA evidence establishes
FCA outsourcing accountability and lifecycle risk management
The FCA’s July 2026 update on outsourcing and operational resilience reiterates that firms remain fully responsible for risks from outsourced services, including compliance functions. Firms must manage risks throughout the lifecycle of arrangements and increase oversight as dependency grows. Boards and senior management retain accountability for operational resilience and regulatory compliance, regardless of outsourcing status. Firms should assess whether arrangements meet the FCA’s outsourcing definition and apply relevant rules accordingly, ensuring governance structures support ongoing risk management.
FCA guidance on compliance support from external providers
The FCA’s February 2023 guidance on compliance and other support emphasises that firms must define the scope and objectives of any external compliance service clearly. The firm cannot transfer regulatory responsibility by outsourcing compliance functions and must actively monitor the quality and appropriateness of the service. This requires firms to drive the relationship with providers and maintain oversight, ensuring that external support aligns with the firm’s regulatory obligations and risk appetite.
New FCA reporting regime for material third-party arrangements
Effective from 18 March 2027, the FCA requires specified in-scope firms to notify it when entering or materially changing material third-party arrangements that meet the regime's perimeter and materiality tests. Firms must also submit an annual register of material arrangements. This regime covers both outsourcing and non-outsourcing arrangements for listed firm types but does not alter the firm’s responsibility for managing these arrangements. Firms should review their third-party mapping and governance frameworks to ensure compliance with these new reporting requirements.
Implementation Priorities
| Action | Owner | Status | Timing | Evidence |
|---|---|---|---|---|
| MEMA recommends comparing in-house, outsourced and co-sourced models against the firm's risk profile, required capability, decision rights, information access and expected challenge. | Board / SMF16 | MEMA recommended action | before selecting or renewing the operating model | RISK MANAGEMENT OF OUTSOURCING - Outsourcing and operational resilience |
| MEMA recommends documenting the responsibilities retained by the firm and the activities performed by each provider, including conflicts, escalation and access to records. | Compliance Officer / COO | MEMA recommended action | before contract approval | OUTSIDE SUPPORT - Outsourcing and operational resilience |
| MEMA recommends defining service evidence, quality measures, meeting cadence, exception handling and the internal capability needed to challenge the provider. | Provider Owner / Assurance | MEMA recommended action | before service commencement and at each formal review | NEW RULES FROM 18 MARCH 2027 - Outsourcing and operational resilience |
| MEMA recommends testing continuity and exit arrangements and determine whether the 2027 material third-party reporting rules apply to the firm and arrangement. | Operational Resilience Lead / Legal | MEMA recommended action | before a material arrangement begins or changes | RISK MANAGEMENT OF OUTSOURCING - Outsourcing and operational resilience |
MEMA Perspective
Boards should critically assess whether governance arrangements provide sufficient transparency and control over outsourced or co-sourced compliance functions. Key questions include whether senior management has unfettered access to relevant information and whether provider oversight processes are robust and documented. Boards should seek assurance that lifecycle risk management is embedded and that operational resilience plans are tested and updated regularly. Evidence to support these judgements might include board papers detailing compliance oversight, risk registers showing lifecycle management, and reports on provider performance and incident response capabilities.
MEMA recommends that boards thoroughly understand the scope and perimeter of the FCA’s new material third-party arrangements reporting regime and ensure the firm’s readiness to comply. Boards should review the firm’s third-party mapping and reporting processes to confirm that all material arrangements are identified and that any required notification and register submissions will be accurate and timely. They should also verify that senior management is fully briefed on these requirements and that continuity and exit plans for outsourced compliance services are comprehensive and tested. Assurance evidence could include documented third-party registers, internal audit reports on reporting processes, and scenario testing outcomes for continuity plans. This oversight ensures the firm maintains control and meets FCA expectations, reducing regulatory and operational risks.
MEMA helps firms apply regulatory developments through its compliance governance and resourcing support.
Further reading: the FCA's 2026 compliance priorities.
Source Evidence
| Source | Document type | Published | Why it matters |
|---|---|---|---|
| Outsourcing and operational resilience | FCA firm guidance (Risk management of outsourcing) | Updated 14 July 2026 | Current FCA explanation of outsourcing accountability, lifecycle risk management, third-party mapping and operational-resilience expectations. |
| Compliance and other support | FCA firm guidance (Outside support) | Updated 10 February 2023 | Primary FCA statement that outside compliance support must match the firm's needs and does not transfer regulatory responsibility. |
| Reporting material third party arrangements | FCA implementation guidance (New rules from 18 March 2027) | 18 March 2026 | Primary FCA implementation page for the in-scope firms and arrangements covered by the 2027 notification and register requirements. |
Disclaimer
This article is for general information only and does not constitute legal or regulatory advice. Firms should assess the application of regulatory requirements by reference to their permissions, products, customers and operating model.
How MEMA Can Help
MEMA can help firms translate regulatory change into practical controls, policies, monitoring activity and board evidence. Book a free scoping call to discuss what this development means for your firm.
Frequently asked questions
Can a firm outsource regulatory responsibility to a compliance provider?
No. The FCA's Outsourcing and operational resilience page says firms remain responsible and accountable for regulatory obligations applying to outsourcing and third-party arrangements. Its Compliance and other support page also says responsibility for oversight remains with the firm. External support can provide expertise, monitoring or capacity, but the firm should retain decision ownership, enough knowledge to challenge the work, access to relevant information and evidence that provider performance is monitored and acted upon.
Is in-house compliance always better than an outsourced model?
No single model is automatically better. MEMA recommends comparing capability, independence, business knowledge, scalability, continuity, information access, oversight effort and cost variability against the firm's actual risk profile. Outsourcing and operational resilience explains that risk management should be proportionate and should increase with dependence on third parties. A co-sourced model may combine internal ownership with specialist support, but its interfaces and decision rights still need to be explicit and testable.
What evidence should a firm retain for an outsourced compliance arrangement?
MEMA recommends retaining the needs assessment, due diligence, approved scope, responsibility map, conflicts review, access rights, service measures, meeting and challenge record, exceptions, remediation and continuity or exit plan. Outsourcing and operational resilience emphasises lifecycle risk management and continuing firm accountability. Where the 2027 material third-party reporting regime applies, the firm should also identify the notification and register evidence needed without assuming that every compliance-support arrangement falls within that specific reporting perimeter.
Need expert regulatory guidance?
Our ex-regulator team helps firms navigate complex requirements and evidence compliance with confidence.
Book a Free Scoping CallRelated insights
View all insights →
Consumer Duty scope decisions need a documented wholesale boundary
CP26/23 proposes targeted changes to Consumer Duty scope. Mixed retail and wholesale firms should separate the live Duty from changes still under consultation.

FCA advice survey 2025: growth needs a capacity evidence trail
The FCA's April 2026 survey reports around 5,500 advice firms, 31,000 advisers and widespread outsourcing. Sector averages are context, not staffing standards.

Crypto prudential risk assessments need a board-owned evidence trail
GC26/5 closed on 30 July 2026. Firms can now use the proposed CRYPTOPRU 7 guidance to test readiness while monitoring the FCA's final position.