Compliance officers

Outsourced compliance support
Without carrying it alone.

Interpret obligations, keep policies current, and evidence controls, without carrying the whole compliance burden alone.

Is your compliance function stretched?

Usually you are the whole function, or most of it. We give you the capacity, the second opinion and the evidence trail, without taking the role off you.

  • You're a one-person (or stretched) compliance function
  • You need to evidence Consumer Duty, SM&CR and financial crime controls
  • Regulatory change is outpacing your capacity

Why having a compliance function is not the test

What you are personally accountable for

Most obligations land on the firm. These land on the individual holding the function.

SYSC 6.1

The test is effectiveness, not existence

SYSC 6.1 requires adequate policies and procedures to detect the risk of failing to meet regulatory obligations. In a smaller firm the compliance function can be a named individual rather than a department — but it has to have authority, resources and independence. A compliance officer who is routinely overruled or under-resourced does not satisfy SYSC.

What the FCA expects from a compliance monitoring programme

Having the artefact is rarely the issue. These are the qualities that survive challenge.

The monitoring plan

Risk-based and actually executed. A plan showing twelve reviews a year with four completed is worse evidence than a plan showing four and completing them, because it documents your own assessment of what mattered and then shows you did not do it.

Testing that can fail

Sample sizes, the criteria applied, and findings including the negative ones. Monitoring that has never produced an adverse finding is not reassuring — it reads as monitoring designed not to find anything.

Breach and action log

Owners, dates and closure evidence, with overdue items visible rather than quietly re-dated. Root cause recorded, not just the fix, so recurrence is detectable.

Board reporting

Enough for the board to govern rather than be reassured: what is off track, what you are not sighted on, and what you need. A pack with no bad news invites the question of what is being filtered and by whom.

Your own independenceSYSC 6.1

Demonstrable through budget, direct board access, and a record of escalations that were acted on. Where you were overruled, the record of you having raised it is the thing that protects both you and the firm.

Regulatory change tracking

A live log from publication through to implementation and evidence, with owners. Horizon scanning that produces a reading list rather than a set of actions is the version supervisors discount.

Outsourced compliance support and monitoring

See the Stay Compliant process
  • An external compliance function with monitoring and MI
  • Policy reviews, regulatory horizon scanning and action logs
  • Consumer Duty, SM&CR and financial crime evidence
  • Board-ready reporting
100+
Firms authorised
11
FCA sectors covered
10+
Years regulatory experience
Since 2019
Led by ex-FCA regulators

Questions compliance officers ask us

Does SYSC require a separate compliance function?

SYSC 6.1 requires adequate policies and procedures to detect the risk of failing to comply with regulatory obligations. For most firms that means an identifiable compliance function, though the FCA accepts this may be a named individual rather than a dedicated department in a smaller firm. What matters is that the function has sufficient authority, resources and independence to be effective — a compliance officer who is routinely overruled or under-resourced does not satisfy SYSC.

Can we outsource compliance to a third party?

You can outsource the work, not the responsibility. Firms remain responsible and accountable for regulatory obligations that apply to outsourcing and third-party arrangements, and oversight remains with the firm. External support can provide expertise, monitoring or capacity, but you should retain decision ownership, enough knowledge to challenge the work, and genuine access to what is being done in your name.

Is spreadsheet-based monitoring defensible for a small firm?

It can be. The rules require effective monitoring, not particular software, and a well-run spreadsheet in a small firm can be adequate. The risks are practical rather than regulatory: version control, no audit trail of who changed what, and key-person dependency if you are the only person who understands it. The question to test is whether you could hand it to someone else tomorrow and whether it would survive a supervisory request for evidence.

For the full detail, read SYSC systems and controls: the full explainer.

Talk to a regulatory specialist

Book a scoping call to discuss your situation and the right next step.