
The compliance officer is part of the firm’s governance, not a personal guarantee that nothing will go wrong. Effective role holders need authority, information, time, training, evidence and protection.
The COLP or COFA may be one individual, but compliance is not a solo activity. The role only works when the firm around it provides the information, authority, time and support needed to make sound decisions.
That is the central lesson from the SRA’s thematic review of compliance officers and from the practical experience of role holders across the profession. Many compliance officers are conscientious and technically capable. Too many are still expected to carry responsibility without the architecture that makes meaningful oversight possible.
In 2026, a firm should be asking more than whether it has the right names on the SRA record. It should be asking whether those people can see risk early, challenge decisions effectively and show how the firm responded.
A governance role, not a guarantee
The COLP and COFA roles were introduced as part of the move towards outcomes-focused regulation in 2012. The 2019 Standards and Regulations shortened the rulebook and placed still greater weight on judgement. Prescriptive detail reduced; the need to understand the firm, assess risk and explain decisions increased.
Against that background, a compliance officer cannot sensibly be treated as the person who personally prevents every breach. Firms are complex systems. Client work, finance, people, technology, complaints, insurance and management decisions all generate information that may have regulatory significance.
The compliance officer’s job is to help the firm establish effective arrangements, maintain oversight, identify serious issues and ensure the right response. The firm’s job is to enable that role. The SRA Code of Conduct for Firms makes this a firm-wide management obligation.
Compliance officers cannot be expected to know everything. When something goes wrong, the relevant questions are:
- What information should have reached the compliance officer?
- Who was responsible for passing it on?
- Did the role holder have the authority and time to act?
- How was the decision recorded and followed through?
Those questions move the discussion away from personal blame and towards governance.
What the SRA found
The SRA’s compliance officer thematic review, published in December 2025, involved 25 firms and 36 role holders.
Only one COLP could outline every material regulatory requirement explored during the review. Just 44 per cent of role holders felt that the role was acknowledged and valued within the firm. Compliance officers spent, on average, 26 per cent of their working time on compliance, while nearly half cited insufficient time or resources as a challenge.
Training was also uneven. Only 44 per cent could demonstrate relevant training during the previous year. The same proportion of firms had no deputy. Decision records were partial in 41 per cent of cases.
These technical gaps describe roles that may become fragile under pressure. If key knowledge sits in one person’s head, the function weakens when that person is busy, ill or away. If the board receives little compliance information, it may mistake silence for control. If decisions are not recorded, the firm loses both organisational memory and the opportunity to learn.
A blank breach register is not necessarily evidence of a healthy firm. It may mean that people are not recognising concerns, do not know how to raise them or believe the safest course is to keep quiet.
Independence is not the same as influence
The SRA’s proposed eligibility reform would prevent individuals with overwhelming control or unilateral power from holding the COLP or COFA role. The intention is understandable: a compliance officer should be able to assess and challenge the conduct of those who run the business as part of the checks and balances.
Formal independence, however, does not guarantee practical authority. A salaried partner may look independent on an organisation chart but still lack the influence to challenge a dominant owner. Conversely, a senior leader may have the commercial standing to secure change, provided conflicts are recognised and decisions are subject to proper governance.
Firms should therefore look beyond status. Can the compliance officer:
- obtain information without unnecessary gatekeeping;
- attend the meetings where material decisions are made;
- require remedial action or escalate delay;
- reach the managing partner, board or owners directly; and
- obtain independent advice where their interests may diverge from the firm’s?
A written role mandate can help. It should set out access, reporting lines, escalation rights, decision-making boundaries, deputy arrangements and the resources available. It should also explain what happens when management disagrees with the compliance officer’s recommendation.
The aim is not to make the role holder unaccountable. It is to prevent important regulatory judgements being neutralised by hierarchy or commercial pressure.
The COFA needs continuous oversight
The COFA role illustrates the difference between real oversight and a periodic check.
An external accountant’s report is valuable, but it is not a substitute for the firm’s own controls. The COFA needs information that can reveal a problem while it is still manageable: reconciliations, shortages, residual balances, office-to-client transfers, suspense items, interest, bills, authorisations and unusual payment activity.
Reconciliation paperwork should be read intelligently. Warning signs may include different ledger and bank dates, outstanding lodgements or stale cheques, repeated adjusting items, unexplained suspense entries and residual balances that remain unmanaged. A technically balanced reconciliation can still contain a control problem.
Rule 3.3 is another recurring risk. Client account must not be used as a banking facility. The fact that a payment is convenient for the client, connected loosely with the matter or historically accepted does not answer whether it is part of the delivery of regulated legal services. Recent enforcement action shows the cost of allowing payment handling to drift away from the legal work.
Useful COFA reporting should be selective, and should help management see trends, exceptions and unresolved actions. A short monthly dashboard may be more effective than a large finance pack nobody discusses.
Oversight depends on information flows
Neither the COLP nor the COFA can oversee information they never receive. Compliance reporting should not depend on somebody remembering to mention an issue in the corridor.
The firm should define what flows into the compliance function from:
- finance, including reconciliations, shortages, residual balances and unusual transactions;
- HR, including disciplinary issues, capability concerns and changes affecting suitability;
- complaints and claims, including repeated causes and emerging service problems;
- supervision and file review, including overdue actions and recurring weaknesses;
- IT and cyber security, including incidents, access failures and data loss; and
- management, including acquisitions, new work types, financial stress and strategic decisions.
It also needs a reporting rhythm. Depending on the firm, that may include a dashboard, a regular risk meeting and a standing board agenda item. The purpose is not to create bureaucracy. It is to make sure regulatory information reaches somebody able to assess it and that agreed action is followed through.
The distinction between the internal breach record and SRA-reportable matters is important. Firms should record concerns and decisions without assuming that every entry will be reported. A useful record identifies the facts known at the time, the rules and risks considered, the people consulted, the decision, the rationale and any action or review date.
Reasonable reliance on competent colleagues is part of operating a firm. Blind reliance is not. The record should show what assurance the compliance officer sought and why it was reasonable to accept it.
Time, training and continuity
Compliance time should be planned rather than donated from the edges of another full-time role. The thematic review’s average of 26 per cent does not create a benchmark: the right allocation depends on the size, work, structure and risk of the firm. It does show why boards need an honest discussion about capacity.
Protected time is most useful when tied to defined activity: reviewing management information, following up audit actions, considering reports, updating risk assessments, training, horizon scanning and meeting management. Without that structure, “one day a week” can disappear into client and operational work.
Training should include more than an annual legal update. Compliance officers need the technical rules, but also skills in investigation, judgement, data interpretation, challenge, board communication and record keeping. Deputies need enough exposure to act confidently when required.
Continuity deserves particular attention. A deputy needs access to relevant systems and people, clarity about their authority and a route for urgent escalation. The very act of developing deputies may also provide a succession route, so that the same compliance officer isn’t stuck in the role indefinitely.
Protecting the role holder
Personal responsibility can make compliance roles feel exposed. Firms should address that directly rather than relying on goodwill.
The role mandate should distinguish the officer’s responsibilities from the firm’s. The officer should have access to appropriate training, budget and independent legal advice. The firm should also understand the protection available through indemnities and its professional indemnity, management liability or directors’ and officers’ insurance. Policy wording and exclusions need checking.
Protection does not remove accountability for the officer’s own conduct. It creates an environment in which concerns can be raised and advice sought without fear that doing so will leave one person isolated.
Boards should be especially alert where the compliance officer is asked to approve a course they have advised against, where owners are implicated, or where the firm’s financial position creates pressure to delay remedial action or reporting.
Six questions for the next board meeting
An effective framework can be tested through six headings:
- Authority: Can the compliance officer challenge decisions and escalate unresolved action?
- Access: Do they receive the information and management data needed to spot risk?
- Time: Is enough protected capacity allocated to the actual work of the role?
- Training: Are the role holder and deputy keeping both technical and practical skills current?
- Evidence: Do records show the concerns considered, decisions reached and actions completed?
- Protection: Can the role holder obtain support, independent advice and appropriate insurance protection?
If the answer to any of these is “only when the right people are available”, the arrangement is not yet resilient.
Make risk visible early
The strongest compliance officers are not those who claim certainty about everything. They ask good questions, understand where information comes from, recognise the limits of their knowledge and bring difficult issues to the right forum while there is still time to act.
Firms support them by treating compliance as part of governance rather than as an individual’s additional duty. That means functioning information flows, clear authority, protected time, capable deputies, thoughtful records and a board willing to hear unwelcome news.
A good compliance officer does not make risk disappear. A good compliance officer makes risk visible early enough for the firm to do something about it.
Read the SRA compliance officers thematic review and the JBL Compliance analysis of the SRA client money and compliance officer proposals.


