Regulated function · EU and national law
The compliance function that EU and national rules increasingly require, performed on retainer where the law allows it and supported where it must be held internally.
Key facts
The AMLR requires obliged entities to appoint a compliance officer, and the DSA and DMA require compliance functions for very large platforms and gatekeepers.
Entities with 50 or more workers must adopt a regulatory compliance programme and designate a person responsible for regulatory compliance.
These rules expect the officer to have sufficient hierarchical standing, adequate resources and direct access to the management body.
Some regimes require the role to be held internally; elsewhere the function can be performed by an external provider under a service contract.
The first question is always whether the law allows the role to be held by an external provider. The answer determines the model.
we perform the function: where it may be outsourced, an experienced Compliance Officer works for the organisation on a part-time, recurring basis, as a Fractional Compliance Officer;
we support the internal officer: where the law requires an internal holder, such as the person responsible for regulatory compliance under Portugal's RGPC or the compliance officer under the AMLR, we give that person the methodology, documentation, monitoring and training needed to perform the role.
programme management: the compliance programme, its risk assessment and its annual plan;
advice: day-to-day guidance to management and staff on applicable rules;
monitoring: controls, indicators and periodic reviews of the programme's effectiveness;
board reporting: regular reports to the management body on risks, incidents and actions;
supervisor liaison: preparation of communications to the competent authorities;
evidence: records and minutes kept through the Compliance Secretariat.
Essential: programme management, advice and quarterly reporting;
Advanced: adds monitoring, training and supervisor liaison;
Mentoring: support and mentoring for an internally designated officer.
Fees are set in a tailored proposal, according to the size of the organisation, its regulatory exposure and the roles involved.
Related: Anti-Corruption · Anti-Money Laundering · Data Protection Officer · Information Security Officer · Whistleblowing Officer
General information as at October 2026; it does not constitute legal advice.
Request a proposal for the officer role on retainer or for support to your internal officer.