Compliance means adherence. An organisation follows the laws and rules that apply to it and its own policy, and can demonstrate that it does. In financial services it is mainly about rules that protect the integrity of the organisation and of the financial system, such as the Wwft, the Dutch Anti-Money Laundering and Anti-Terrorist Financing Act, and sanctions rules. Compliance is therefore both a goal and a function within the organisation.
The meaning of compliance
The word comes from to comply with: to conform to. In a general sense, compliance covers every rule that applies to an organisation. Think of privacy rules, competition law or employment law.
Compliance is more than knowing the rules. It is about three things:
- knowing which rules apply to your organisation
- setting up processes that make you follow those rules
- recording and checking that this actually happens
Compliance in financial services
Banks, insurers, payment institutions, investment firms and trust offices are supervised by DNB and the AFM. For them, compliance is a fixed part of their operations. The supervisors expect sound and ethical business operations.
Important topics are:
- preventing money laundering and terrorist financing under the Wwft (see What is the Wwft?)
- complying with sanctions rules
- preventing conflicts of interest, corruption and fraud
- treating customers with due care
- the integrity of staff and board members
Compliance is not only a matter for financial institutions. Accountants, tax advisers, notaries, lawyers and estate agents also have obligations under the Wwft. They fall under other supervisors, such as the Bureau Financieel Toezicht and the Dienst Financieel-Economische Integriteit (DFEI).
The role of the compliance officer
The compliance officer oversees whether the organisation follows the rules. The tasks differ per organisation, but usually include:
- advising the board and staff on rules and risks
- drafting policies and procedures and keeping them up to date
- checking whether the policy is followed in practice
- training staff
- reporting to the board and maintaining contact with the supervisor
- reviewing high-risk customers or transactions
A compliance officer must be able to work independently. Many organisations use the three lines of defence model for this. The first line is the business itself, which takes on customers and carries out the customer due diligence. The second line is compliance and risk management, which advises and monitors. The third line is internal audit, which assesses the whole.
Compliance, the Wwft and KYC
For institutions subject to the Wwft, preventing money laundering is a large part of compliance work. Among other things, the Wwft requires:
- customer due diligence for every customer, also called KYC or CDD (see What is KYC?)
- identifying the UBO, the ultimate beneficial owner (see What is a UBO?)
- additional measures where the risk is higher, for example with a PEP (see What is a PEP? and Enhanced due diligence)
- reporting unusual transactions to FIU-Nederland, the Dutch Financial Intelligence Unit
- recording and retaining data
Where appropriate given the nature and size of the organisation, the Wwft also requires an independent compliance function. Compliance drafts the policy and monitors. The day-to-day investigation of customers often takes place in the first line, by analysts (see What does a CDD analyst do?).
Integrity risks and the SIRA
Good compliance starts with insight into risks. Financial institutions use the SIRA for this: the systematic integrity risk analysis. DNB expects institutions under its supervision to carry out such an analysis and keep it up to date.
In broad terms, a SIRA involves the following:
- You map out which integrity risks your organisation faces, such as money laundering, terrorist financing, sanctions breaches, corruption and fraud.
- You assess how large the likelihood and the impact are.
- You describe which measures you already take.
- You determine which risk remains and whether that is acceptable.
In addition, the Wwft requires every institution to identify and assess its risks of money laundering and terrorist financing. The outcome drives the policy: which customers you do and do not accept, and when enhanced due diligence is needed.
Organising compliance
How you set up compliance depends on the size and risk profile of your organisation. A few fixed building blocks:
- responsibility at management level: a board member who is accountable for adherence
- policies and procedures that follow from the risk analysis
- sufficient knowledge and capacity, including during peaks
- record keeping, so that you can show the supervisor what you do and why
- periodic evaluation, for example when new rules arrive, such as the AMLR that applies from 10 July 2027 (see AMLR 2027)
Doing it yourself or bringing in support
Many organisations set up compliance entirely by themselves. That works well when there is enough knowledge and capacity. Sometimes outside support is useful, for example when drafting a SIRA, revising policy or running a remediation project on customer files. The organisation remains responsible and makes its own decisions. An external party can think along, carry out part of the work or take a fresh look at the processes.