External compliance function

We design independent external compliance functions that strengthen governance, regulatory resilience and board oversight

External compliance function for firms under financial supervision

View as Markdown
9 mins read • Vilgot Sahlholm • FINANCIAL REGULATION • 16 July 2026

Many financial firms know that the compliance function must be independent, competent and embedded in the business on an ongoing basis. The difficult question is often how the function should be organised in a way that works in practice and meets the applicable regulatory requirements.

For firms under financial supervision, compliance is not merely a formal control function. The function must be able to identify regulatory risks, review the business, provide advice, follow up on measures and report to management and the board. This requires legal understanding, commercial judgement and the ability to act independently.

In practice, this requires a clear allocation of roles. The person responsible for compliance work must be able to interpret regulations, support the business and follow up on whether internal procedures work. This is also why the role of the compliance lawyer is often central in financial services.

In small and medium-sized financial firms, this can be difficult to resolve internally. Organisations are often lean, key individuals hold several roles, and building a senior compliance function from the ground up can be costly. An external compliance function can then be a practical and strategic alternative, both on an interim basis and over time.

Why the interim compliance officer model can be effective

The issue is rarely just about finding someone who “knows compliance”. A functioning compliance function must understand relevant financial regulation, make independent assessments, communicate with management and the board, and understand the firm’s business model.

The function must also operate continuously. Compliance becomes weaker if the work is only carried out at specific points before board meetings, authorisation processes or external reviews. Regulatory risks often arise in everyday decisions: new products, changed processes, customer flows, outsourcing, marketing, personal data processing or internal incentive models.

A common challenge is that compliance responsibility is assigned to a person who already has an operational role, for example in finance, legal, product, operations or business development. This may work in some organisations, but it can also create conflicts of role. A person who helps design or operate a process may find it harder to review that same process later with sufficient distance. Many regulated firms are therefore required to maintain an independent compliance function.

Independence is therefore not just a matter of what is stated in a policy. It is affected by organisational structure, reporting lines, workload, access to information and the actual ability to raise difficult issues without being too close to the decisions being reviewed.

An external interim compliance officer can strengthen independence

An external compliance function can create clearer distance between day-to-day business operations and the control function. This can be particularly valuable in firms where it is otherwise difficult to separate roles internally.

In a simplified model, this is often described as three lines of defence. The first line owns and manages risks in the business. The second line, which includes compliance, supports, controls and follows up. The third line, internal audit, reviews governance and control.

Compliance in the second line must therefore be close enough to the business to understand the risks, but not so close that the function becomes part of the decisions it will later review. An external or outsourced compliance function can help achieve that balance, particularly where the internal organisation is small or the same individuals would otherwise have to hold several roles.

At the same time, outsourcing does not automatically resolve the question of independence. An external function needs a clear mandate, the right authority, access to information and a direct reporting line to management and the board. If the engagement is framed only as sporadic advice when needed, the function risks becoming too reactive and too weakly integrated into the firm’s governance. Such an arrangement will also not meet the requirements placed on an outsourced function unless the model is structured properly to deliver the right result and withstand supervisory scrutiny.

Access to senior expertise without internal training costs

One of the key advantages of an external compliance function is that the firm can access senior regulatory expertise without first having to build the entire function internally. For many financial firms, this is critical. Regulation is extensive, changes over time and often requires experience of how requirements can be translated into practical ways of working.

This does not mean that internal expertise becomes unimportant. On the contrary, there must always be internal ownership, accountability and understanding of compliance matters. The board and management cannot abdicate their responsibility simply because the function is outsourced. However, specialist expertise does not always need to sit within the firm as an employed resource.

An external compliance function can provide established working methods, experience from comparable businesses, methods for risk assessment and follow-up, and practical experience of reporting to management and the board. It can also identify gaps in governance documents, processes, controls or allocation of responsibilities more quickly.

For firms that are growing, applying for authorisation, changing their business model or facing higher regulatory expectations, support with financial regulation can therefore reduce the time required to become operational. Instead of first recruiting, training and building methods internally, the firm can put a functioning structure in place earlier.

Not only an interim compliance officer, but a long-term model

External compliance can be a temporary solution. This is relevant in connection with recruitment, parental leave, sickness absence, authorisation applications, organisational change or work before or after supervisory review. In such situations, an interim compliance officer can create continuity when the firm would otherwise risk losing momentum.

But the model does not need to be temporary. For some firms, an external compliance function is a deliberate long-term choice. It can suit businesses that want to keep the internal organisation lean while still ensuring that the compliance function has the right expertise, sufficient independence and a clear annual cycle.

This is particularly relevant for firms where the need for compliance is qualified but does not necessarily justify a full-time senior function. An external model can then provide a better match between need, risk profile and resources.

Even large and established organisations may sometimes choose to keep certain specialist functions external or partly external. This can be relevant where it provides increased flexibility, clearer independence or access to expertise that is not needed internally on a full-time basis. For other firms, an internal function is the right route. The central question is not whether the model is internal or external, but which model delivers the best practical effect.

What is required for an outsourced compliance function to work

An outsourced compliance function must be established with clear parameters and expectations. It should not operate as general advice on demand, but as an integrated part of the firm’s control environment.

Above all, this requires clarity. The firm must define what the function is to do, what responsibility it has, which matters must be escalated and how reporting is to take place. It must also be clear what remains within the first line and what belongs to other control functions, such as risk control.

  • Clear mandate and defined responsibility.
  • Sufficient authority and access to relevant information.
  • Reporting line to management and the board.
  • Ongoing meeting structure and documented annual cycle.
  • Risk-based planning, follow-up and reporting.
  • Procedures for regulatory change, incidents and escalation.
  • Clear boundary between the first line and other control functions.

When these elements are in place, an external compliance function can work more proactively. The function can plan controls, follow up on measures, participate in relevant forums and help ensure that regulatory risks are managed before they become larger problems.

When an external compliance function is particularly suitable

An external compliance function is not suitable for every firm, but the model can be particularly relevant in certain situations.

  • The firm is facing an authorisation application, a change to its authorisation or a new regulatory phase.
  • The business has grown faster than the control environment.
  • The compliance function is highly dependent on one individual.
  • The current allocation of roles creates a risk of insufficient independence.
  • The firm needs senior expertise but not a full-time compliance function.
  • The board or management wants clearer follow-up and reporting.
  • The firm is entering a new market, product area or business model.

In these cases, an external or outsourced compliance function can create structure, continuity and regulatory resilience without requiring the firm to build a larger internal organisation than the business needs.

When an internal function may be better

There are also situations where an internal compliance function may be more appropriate. This applies, for example, where the business is very large and complex, where compliance needs to be operationally present every day, or where the firm has many parallel regulatory matters requiring continuous internal coordination.

An internal function may also be right where the firm already has a mature second line organisation and regards internal knowledge-building as a strategic priority. In such cases, external advice may still be valuable, but perhaps as specialist support rather than as the compliance function itself.

For some firms, the best solution is a hybrid model. In that model, there is internal ownership and an internal point of contact, while parts of the specialist expertise, review work or reporting are handled externally. Such a model can provide both internal anchoring and flexibility.

A strategic solution, not only a cost question

External compliance should not primarily be viewed as a way to reduce costs. Cost control can be an important part of the calculation, but the strategic value often lies in the combination of flexibility, experience, independence, continuity and rapid implementation.

When the engagement is organised as an ongoing function with a clear scope, the cost structure can also become more predictable. This is often preferable to multiple separate interventions that only arise once a problem has already become urgent.

For financial firms operating across Europe, an external compliance function can therefore be a practical way to strengthen the control environment without building a larger internal organisation than the business needs. Properly structured, the model can work both as an interim compliance officer solution and as a long-term organisational model.

At Morling Consulting, our financial regulation lawyers help financial firms organise and develop compliance functions tailored to the size, risk profile and regulatory requirements of the business.

Speak to a compliance lawyer

Do you need an external compliance function for your regulated business? Contact us and we will assess your governance model

"*" indicates required fields