What is compliance?

In short

  • Compliance means adherence: your organisation follows laws, rules and its own policy, and can demonstrate that it does.
  • In financial services it is mainly about integrity: preventing money laundering, terrorist financing, sanctions breaches, corruption and conflicts of interest.
  • The compliance officer advises, drafts policy, monitors adherence and reports to the board. That role must be independent.
  • A good approach starts with a risk analysis, such as the SIRA, and translates it into policy, processes such as KYC, and record keeping.

Compliance means adherence. An organisation follows the laws and rules that apply to it and its own policy, and can demonstrate that it does. In financial services it is mainly about rules that protect the integrity of the organisation and of the financial system, such as the Wwft, the Dutch Anti-Money Laundering and Anti-Terrorist Financing Act, and sanctions rules. Compliance is therefore both a goal and a function within the organisation.

The meaning of compliance

The word comes from to comply with: to conform to. In a general sense, compliance covers every rule that applies to an organisation. Think of privacy rules, competition law or employment law.

Compliance is more than knowing the rules. It is about three things:

  • knowing which rules apply to your organisation
  • setting up processes that make you follow those rules
  • recording and checking that this actually happens

Compliance in financial services

Banks, insurers, payment institutions, investment firms and trust offices are supervised by DNB and the AFM. For them, compliance is a fixed part of their operations. The supervisors expect sound and ethical business operations.

Important topics are:

  • preventing money laundering and terrorist financing under the Wwft (see What is the Wwft?)
  • complying with sanctions rules
  • preventing conflicts of interest, corruption and fraud
  • treating customers with due care
  • the integrity of staff and board members

Compliance is not only a matter for financial institutions. Accountants, tax advisers, notaries, lawyers and estate agents also have obligations under the Wwft. They fall under other supervisors, such as the Bureau Financieel Toezicht and the Dienst Financieel-Economische Integriteit (DFEI).

The role of the compliance officer

The compliance officer oversees whether the organisation follows the rules. The tasks differ per organisation, but usually include:

  • advising the board and staff on rules and risks
  • drafting policies and procedures and keeping them up to date
  • checking whether the policy is followed in practice
  • training staff
  • reporting to the board and maintaining contact with the supervisor
  • reviewing high-risk customers or transactions

A compliance officer must be able to work independently. Many organisations use the three lines of defence model for this. The first line is the business itself, which takes on customers and carries out the customer due diligence. The second line is compliance and risk management, which advises and monitors. The third line is internal audit, which assesses the whole.

Compliance, the Wwft and KYC

For institutions subject to the Wwft, preventing money laundering is a large part of compliance work. Among other things, the Wwft requires:

  • customer due diligence for every customer, also called KYC or CDD (see What is KYC?)
  • identifying the UBO, the ultimate beneficial owner (see What is a UBO?)
  • additional measures where the risk is higher, for example with a PEP (see What is a PEP? and Enhanced due diligence)
  • reporting unusual transactions to FIU-Nederland, the Dutch Financial Intelligence Unit
  • recording and retaining data

Where appropriate given the nature and size of the organisation, the Wwft also requires an independent compliance function. Compliance drafts the policy and monitors. The day-to-day investigation of customers often takes place in the first line, by analysts (see What does a CDD analyst do?).

Integrity risks and the SIRA

Good compliance starts with insight into risks. Financial institutions use the SIRA for this: the systematic integrity risk analysis. DNB expects institutions under its supervision to carry out such an analysis and keep it up to date.

In broad terms, a SIRA involves the following:

  1. You map out which integrity risks your organisation faces, such as money laundering, terrorist financing, sanctions breaches, corruption and fraud.
  2. You assess how large the likelihood and the impact are.
  3. You describe which measures you already take.
  4. You determine which risk remains and whether that is acceptable.

In addition, the Wwft requires every institution to identify and assess its risks of money laundering and terrorist financing. The outcome drives the policy: which customers you do and do not accept, and when enhanced due diligence is needed.

Organising compliance

How you set up compliance depends on the size and risk profile of your organisation. A few fixed building blocks:

  • responsibility at management level: a board member who is accountable for adherence
  • policies and procedures that follow from the risk analysis
  • sufficient knowledge and capacity, including during peaks
  • record keeping, so that you can show the supervisor what you do and why
  • periodic evaluation, for example when new rules arrive, such as the AMLR that applies from 10 July 2027 (see AMLR 2027)

Doing it yourself or bringing in support

Many organisations set up compliance entirely by themselves. That works well when there is enough knowledge and capacity. Sometimes outside support is useful, for example when drafting a SIRA, revising policy or running a remediation project on customer files. The organisation remains responsible and makes its own decisions. An external party can think along, carry out part of the work or take a fresh look at the processes.

Frequently asked questions

What does compliance mean?

Compliance means adherence. An organisation is compliant when it follows the laws and rules that apply to it and its own internal policy, and can demonstrate that it does.

What does a compliance officer do?

A compliance officer oversees whether the organisation follows the rules. They advise the board and staff, draft policies and procedures, monitor adherence, provide training and report to the board.

Is a compliance function mandatory?

For many financial institutions it is. The Wwft also requires an independent compliance function where this is appropriate given the nature and size of the organisation. Your supervisor can tell you what applies to your organisation.

What is a SIRA?

SIRA stands for systematic integrity risk analysis (systematische integriteitsrisicoanalyse). In it, a financial institution maps out which integrity risks it faces, how large they are and which measures it takes. DNB expects such an analysis from institutions under its supervision.

What is the difference between compliance and risk management?

Compliance focuses on adherence to laws, rules and integrity standards. Risk management looks more broadly at all risks to the organisation, including financial and operational ones. Both belong to the second line of defence.

Support with your compliance?

BlueMonks helps you think through KYC and customer due diligence, based on practical work for organisations subject to the Wwft. You stay in control of every decision.