There is a cost attached to senior compliance roles that does not appear in job descriptions, is rarely discussed in appraisals, and is absent from careers talks given to people entering the profession. Not workload and stress in the general sense that every senior role has. This is something more specific: the personal price of having a job that the organization needs and values, but does not fully understand.

I have spent over 20 years in and around this profession and, over that time, I have come to believe that the most senior people in compliance are carrying a set of costs they rarely speak about.

Why the silence exists

Ben Mason

The silence is not modesty, and it is not stoicism. It is structural.

The senior compliance or risk professional in an organization is likely to have a line manager who does not fully understand how compliance works. Even in an organization with a positive and pro-compliance culture, the line manager may value the output and the security it gives and admire the professionalism of the leader and the function. However, they are unlikely to understand what it takes to deliver it.

Now add into the mix professional pride. Compliance officers are careful, capable people who chose a demanding job and do not want to be heard complaining about it. The only fully safe audience may be a peer at another firm. The result is a profession that talks constantly about risk and almost never about what carrying that risk costs the person at the top of the function.

Here are the five costs I see most consistently:

  • The independence that is meant to be central is often theoretical only

The compliance function’s independence is written into the governance framework and dictated by regulation. That is the theory. In practice, it has to be asserted, defended and re-earned each time it matters. The framework does not make that happen on its own. The individual in the firing line does.

Each time a CCO reasserts their independence it costs something such as goodwill, political capital, sometimes a relationship. The framework says “independent,โ€ yet the lived experience can be different.

  • Doing the job properly is what puts the job at risk

Doing the job properly can put a CCO’s job and reputation at risk. The moment they are most needed, when they stand fast when the business doesn’t want them to, is the moment their position is least secure. Every compliance leader has experienced this or knows someone who has. Compliance Week’s own recent survey on retaliation against compliance officers confirms the reality of this.

  • Doubts cannot be voiced to anyone else in the company

A compliance leader who voices a doubt downwards unsettles their team. One who voices it upwards turns a private worry into a formal issue before they are sure it is one. That is the challenge, and it is a personal cost in its own right.

Carrying unresolved concerns alone, sometimes for months, in the end becomes stressful for most people. This is not a failure of resilience but a natural human reaction. It is also what the role’s position in the organization produces.

  • The best work is invisible, even to the people who value it

Most other functions’ good years have numbers attached, such as revenue, growth, deals closed. A compliance team’s good year is a list of things that did not happen. The fine received by competitors but not by us, the scandal that never broke, the client harm that never occurred, the complaints resolved without fuss.

Most careers are built on the evidence of high performance, but effective compliance does not naturally create that evidence. The lack of noise, dearth of excitement, and absence of trouble don’t prove how successful someone is in the traditional way.

  • There is little leadership support from above

A CFO reports to people who understand finance. A sales director reports to people who have been salespeople. Many compliance officers report to boards and executives who value the function. But few have ever done the role themselves. That makes it difficult for them to mentor, coach, or develop the person leading it.

It is possible to be well regarded and entirely unsupported at the same time. Building and managing the skills to thrive in this environment is something the most successful compliance leaders do deliberately. But it is challenging and takes personal commitment. I wrote about these costs on LinkedIn recently. Across industries and jurisdictions, the response from compliance officers was not disagreement. It was relief. In many cases, people responded, “Someone has finally said it.”

What should be done?

The response should not be sympathy. Every role has its challenges, and most compliance leaders I know accept them willingly. They simply wish some of those challenges were less demanding.

I think these challenges can be structural, meaning a change in structure by design can reduce them. Boards and CEOs can give compliance a genuine reporting line and genuine access, not just a documented one. They can make explicit, in advance, that holding a difficult line will be protected rather than punished and then honor it when it is tested. And boards can agree in advance how prevention will be valued, so that a year in which nothing went wrong is recognized as an achievement rather than an absence.  They can also put someone senior in the compliance officer’s corner who understands the function well enough to support the person doing it.

Unfortunately, in some organizations, that seems to be a lot to ask.

One caution on that last point. Former compliance or risk leaders who become non-executive directors can sometimes challenge the CCO in ways that are more performative than supportive. The result can be to make the role even harder. This is not a universal position, but I have seen it on multiple occasions.

If you sit on a board or an executive committee, ask which of these costs your compliance officer is carrying right now. They probably will not raise it with you, and that is rather the point.

If you are a senior compliance leader now, and expecting a future portfolio or non-executive career, maybe bear these points in mind as you change sides.


Ben Mason is the founder and CEO of My Compliance Centre, a compliance technology company. Ben acts as a board adviser to Turkish Bank and is chair of Katalysys, the prudential risk consultancy.  He previously founded and led Compliancy Services (now Cosegic), a financial services compliance consultancy.