Framework
What a Compliance Officer is for, where the function sits in the Three Lines Model, and which roles EU law now expressly requires.
The compliance function ensures that an organisation knows the rules that apply to it, translates them into internal policies and controls, and can demonstrate, at any moment, that those controls work. It does not replace management, legal counsel or internal audit. It gives the management body an independent and reasoned view of compliance risk, so that decisions are taken with full knowledge of their regulatory consequences.
In the European Union this function is no longer a matter of good practice alone. A growing number of EU instruments require specific roles, documented programmes and the personal accountability of management bodies.
The Three Lines Model of the Institute of Internal Auditors (2020) remains the reference for positioning the function:
first line: operational management owns and manages risk in day-to-day activity;
second line: the compliance and risk functions provide expertise, monitoring and challenge, and report independently to the management body;
third line: internal audit gives independent assurance on the effectiveness of governance, risk management and control.
The Compliance Officer belongs to the second line. Independence, direct access to the management body and adequate resources are the conditions that make the role credible to supervisors.
Data Protection Officer: mandatory for public authorities and for organisations whose core activities involve large-scale monitoring or large-scale processing of special categories of data (GDPR, Article 37);
AML compliance manager and compliance officer: a member of the management body responsible for compliance, and a compliance officer of sufficient seniority, from 10 July 2027 (Regulation (EU) 2024/1624, Article 11);
accountable management bodies for cybersecurity: management bodies approve and oversee cybersecurity risk-management measures, can be held liable and must follow training (NIS2, Article 20);
ICT risk control function: financial entities must have an independent function for managing and overseeing ICT risk (DORA, Article 6);
whistleblowing channel managers: impartial persons or departments to receive and follow up reports (Directive (EU) 2019/1937, Article 9);
national compliance officers: for example, Portugal's general regime for preventing corruption requires a person responsible for regulatory compliance in entities with 50 or more workers.
ISO 37301:2021: compliance management systems;
ISO 37001: anti-bribery management systems;
ISO/IEC 27001:2022: information security management systems.
Certification is voluntary, but these standards give the compliance programme a recognised structure and make it easier to evidence before supervisors and in public procurement.
EU Legal Order: the instruments, their legal nature and their authorities;
Regulation and national transposition: the current status of each instrument;
Authorities: EU and national supervisors;
Services and products: how we support the function in practice.
This page provides general information and does not constitute legal advice. EU instruments and their national implementation evolve; confirm the applicable requirements with the competent authorities.