Skip to main content

Basel Consolidated Guidelines

This page sets out the guidelines and sound practices issued by the Basel Committee on Banking Supervision (BCBS). The application page outlines the implementation expectations for guidelines and sound practices, and their scope of application.

The consolidated guidelines and sound practices comprise the 13 modules listed below. Each module is divided into chapters. Each chapter includes links to the original source publications from which the contents of the chapter are based, related standards, related guidelines or sound practices, and other publications that are relevant to a particular topic.

Please provide first name.
Looks good!
IAC20

Compliance functions

This chapter describes compliance risk and the compliance function in banks.
  • Published: 01 Jan 2026

Guidelines

This chapter describes compliance risk and the compliance function in banks.

The contents of this chapter are based on:

Related standards

Related guidelines

  • CGO10 Corporate governance
  • ORR30 Third-party risk management

Foreword

20.1

Compliance starts at the top. It will be most effective in a corporate culture that emphasises standards of honesty and integrity and in which the board and senior management lead by example. Compliance concerns everyone within the bank and should be viewed as an integral part of the bank’s business activities. A bank should hold itself to high standards when conducting business, and always strive to observe the spirit as well as the letter of the law. Failure to consider the impact of its actions on its shareholders, customers, employees and the markets may result in significant adverse publicity and reputational damage, even if no law has been broken.

20.2

Compliance should be part of the culture of the organisation; it is not just the responsibility of specialist compliance staff. There are significant differences between banks regarding the organisation of the compliance function. In larger banks, compliance staff may be located within operating business lines, and internationally active banks may also have group and local compliance officers. In smaller banks, compliance function staff may be centralised in one unit. Separate units have been established in some banks for specialist areas such as data protection and the prevention of money laundering and terrorist financing.

Key terms

20.3

The following terms are used throughout this chapter and have the meaning given below:

  1. Bank: is used in this chapter to refer generally to banks, banking groups, and to holding companies whose subsidiaries are predominantly banks.
  2. Compliance function: refers to staff carrying out compliance responsibilities; it is not intended to prescribe a particular organisational structure.
  3. Compliance laws, rules and standards: generally cover matters such as observing proper standards of market conduct, managing conflicts of interest, treating customers fairly, and ensuring the suitability of customer advice. They typically include specific areas such as the prevention of money laundering and terrorist financing, and may extend to tax laws that are relevant to the structuring of banking products or customer advice. A bank that knowingly participates in transactions intended to be used by customers to avoid regulatory or financial reporting requirements, evade tax liabilities or facilitate illegal conduct will be exposing itself to significant compliance risk. Compliance laws, rules and standards have various sources, including primary legislation, rules and standards issued by legislators and supervisors, market conventions, codes of practice promoted by industry associations, and internal codes of conduct applicable to the staff members of the bank. These are likely to go beyond what is legally binding and embrace broader standards of integrity and ethical conduct.
  4. Compliance risk: refers to the risk of legal or regulatory sanctions, material financial loss, or reputational harm a bank may suffer as a result of its failure to comply with laws, regulations, rules, related self-regulatory organisation standards, and applicable codes of conduct.
  5. Head of compliance: refers to an executive or senior staff member with overall responsibility for co-ordinating the identification and management of the bank’s compliance risk and for supervising the activities of other compliance function staff. In some banks, the head of compliance has the title “chief compliance officer”.

Principles for compliance risk management

20.4

A bank should organise its compliance function and prioritise the management of its compliance risk in a way that is consistent with its own risk management strategy and structures. Regardless of organisation, the compliance function should be independent and sufficiently resourced, its responsibilities should be clearly specified, and its activities should be subject to periodic and independent review by the internal audit function. An independent compliance function is a key component of the bank’s second line of defence.

20.5

These principles are applicable to all banks, although it is for individual banks to determine how best they should be implemented. Implementation will depend on factors such as the bank’s size, the nature, complexity and geographical extent of its business, and the legal and regulatory framework within which it operates.

20.6

These principles assume a governance structure composed of a board and senior management. The legislative and regulatory frameworks differ across countries and types of entities as regards the functions of the board and senior management. Therefore, the principles set out in this chapter should be applied in accordance with the corporate governance structure of each country and type of entity.1

1

See CGO10.10 and CGO10.11.

Responsibilities of the board of directors for compliance

20.7

Principle 1 – The bank’s board of directors (hereafter, the board) is responsible for overseeing the management of the bank’s compliance risk. The board should approve the bank’s compliance policy, including a formal document establishing a permanent and effective compliance function. At least once a year, the board or a committee of the board should assess the extent to which the bank is managing its compliance risk effectively.

20.8

A bank’s compliance policy will not be effective unless the board promotes the values of honesty and integrity throughout the organisation. Compliance with applicable laws, rules and standards should be viewed as an essential means to this end. The board is responsible for ensuring that an appropriate policy is in place to manage the bank’s compliance risk. The board should oversee the implementation of the policy, including ensuring that compliance issues are resolved effectively and expeditiously by senior management with the assistance of the compliance function. The board may delegate these tasks to an appropriate board level committee (eg its audit committee).

Responsibilities of senior management for compliance

20.9

Principle 2 – The bank’s senior management is responsible for establishing and communicating a compliance policy, for ensuring that it is observed, and for reporting to the board on the management of the bank’s compliance risk. The bank’s senior management is responsible for establishing a permanent and effective compliance function as part of the bank’s compliance policy.

20.10

The bank’s senior management is responsible for establishing a written compliance policy that contains the basic principles to be followed by management and staff, and explains the main processes by which compliance risks are to be identified and managed through all levels of the organisation. Clarity and transparency may be promoted by distinguishing between general standards for all staff members and rules that only apply to specific groups of staff.

20.11

Senior management is responsible for ensuring that appropriate remedial or disciplinary action is taken if breaches of the compliance policy are identified.

20.12

Senior management should, with the assistance of the compliance function:

  1. at least once a year, identify and assess the main compliance risk issues facing the bank and the plans to manage them. Such plans should address any shortfalls (policy, procedures, implementation or execution) related to how effectively existing compliance risks have been managed, as well as the need for any additional policies or procedures to deal with new compliance risks identified as part of the annual compliance risk assessment;
  2. at least once a year, report to the board or a committee of the board on the bank’s management of its compliance risk, in a manner that assists board members to make an informed judgment on whether the bank is managing its compliance risk effectively; and
  3. report promptly to the board or a committee of the board on any material compliance failures (eg failures that may attract significant legal or regulatory sanctions, material financial loss, or reputational loss).

Independence

20.13

Principle 3 – The bank’s compliance function should be independent.

20.14

The concept of independence does not mean that the compliance function cannot work closely with management and staff in the various business units. A co-operative working relationship between compliance function and business units should help to identify and manage compliance risks at an early stage. Rather, the various elements described below should be viewed as safeguards to help ensure the effectiveness of the compliance function. The way in which the safeguards are implemented will depend to some extent on the specific responsibilities of individual compliance function staff.

Status
20.15

The compliance function should have formal status within the bank to ensure appropriate standing, authority and independence. This may be set out in the bank’s compliance policy or in any other formal document, which should be communicated to all staff.

20.16

The compliance policy (or other formal document) should address the following issues with respect to the compliance function:

  1. role and responsibilities;
  2. measures to ensure its independence;
  3. relationship with other risk management functions and with the internal audit function;
  4. allocation of responsibilities across departments (in cases where compliance responsibilities are carried out by staff in different departments);
  5. right to obtain access to information necessary to carry out its responsibilities, and the corresponding duty of bank staff to co-operate in supplying this information;
  6. right to conduct investigations of possible breaches of the compliance policy and to appoint outside experts to perform this task, if appropriate;
  7. right to be able to express and disclose freely its findings to senior management, and if necessary, the board or a committee of the board;
  8. formal reporting obligations to senior management; and
  9. right of direct access to the board or relevant board committee.
Head of compliance
20.17

Each bank should have a head of compliance.

20.18

The reporting line for compliance staff will depend on how the bank has organised its compliance function. Compliance function staff in operating business units or in local subsidiaries may report to operating business unit management or local management. This is acceptable provided such staff also report to the head of compliance for their compliance responsibilities. Separate reporting to the head of compliance may not be necessary where compliance function staff are in independent support units (eg legal, financial control, risk management). However, these units should co-operate closely with the head of compliance to ensure that they can perform their responsibilities effectively. However, these units should co-operate closely with the head of compliance to ensure that the latter can perform their responsibilities effectively.

20.19

If the head of compliance is a member of senior management, they should not have direct business line responsibilities. If they are not a member of senior management, they should report directly to a member of senior management without direct business line responsibilities.

20.20

The bank should inform the supervisor and the board when the head of compliance takes up or leaves that position, including reasons for their departure. For internationally active banks with local compliance officers, the host country supervisor should be similarly informed of the arrival or departure of the local head of compliance.

Conflicts of interest
20.21

The independence of the head of compliance and any other staff having compliance responsibilities may be undermined if there is a real or potential conflict between their compliance responsibilities and their other responsibilities. Ideally, compliance function staff should perform only compliance responsibilities. However, that this may not be practicable in smaller banks, smaller business units or in local subsidiaries. In these cases, compliance function staff may perform non-compliance tasks, provided potential conflicts of interest are avoided.

20.22

Independence may also be undermined if the remuneration of compliance staff is related to the financial performance of the business line they oversee. However, remuneration related to the financial performance of the bank as a whole should generally be acceptable.

Access to information and personnel
20.23

The compliance function should have the authority to communicate with any staff member and access any records or files necessary to enable it to carry out its responsibilities.

20.24

The compliance function should be able to carry out its responsibilities in all departments of the bank in which compliance risk exists. It should have the right to conduct investigations of possible breaches of the compliance policy and to request assistance from specialists within the bank (eg legal or internal audit) or engage outside specialists to perform this task if appropriate.

20.25

The compliance function should be free to report to senior management any irregularities or possible breaches disclosed by its investigations, without fear of retaliation or disfavour from management or other staff members. Although its normal reporting line should be to senior management, the compliance function should also have direct access to the board or to a board committee, when necessary. It may also be useful for the board or board committee to meet with the head of compliance at least annually, as this will help the board or board committee assess whether the bank is managing its compliance risk effectively.

Resources
20.26

Principle 4 – The bank’s compliance function should have the resources to carry out its responsibilities effectively.

20.27

The resources of the compliance function should be both sufficient and appropriate to ensure that compliance risk within the bank is managed effectively. Compliance function staff should have the necessary qualifications, experience and professional and personal qualities to enable them to carry out their specific duties. They should also have a sound understanding of compliance laws, rules and standards and their practical impact on the bank’s operations. The professional skills of compliance function staff should be maintained through regular and systematic education and training.

Compliance function responsibilities
20.28

Principle 5 – The compliance function’s responsibilities should include assisting senior management in managing effectively the bank’s compliance risks If some of these responsibilities are carried out by staff in different departments, the allocation of responsibilities to each department should be clear.

20.29

Compliance responsibilities may not always be centralised within a “compliance department” or “compliance unit”, and may be exercised by staff in different departments. In some banks, for example, legal and compliance may be separate departments; the legal department may be responsible for advising management on the compliance laws, rules and standards and for preparing guidance to staff, while the compliance department may be responsible for monitoring compliance with the policies and procedures and reporting to management. In other banks, parts of the compliance function may be located within the operational risk group or within a more general risk management group. If there is a division of responsibilities between departments, the allocation of responsibilities to each department should be clear. There should also be appropriate mechanisms for co-operation among each department and with the head of compliance (eg with respect to the provision and exchange of relevant advice and information). These mechanisms should be sufficient to ensure that the head of compliance can perform their responsibilities effectively.

Advice
20.30

The compliance function should advise senior management on compliance laws, rules and standards, including keeping them informed on developments in the area.

Guidance and education
20.31

The compliance function should assist senior management in:

  1. educating staff on compliance issues, and acting as a contact point within the bank for compliance queries from staff members; and
  2. establishing written guidance to staff on the appropriate implementation of compliance laws, rules and standards through policies and procedures and other documents such as compliance manuals, internal codes of conduct and practice guidelines.
Identification, measurement and assessment of compliance risk
20.32

The compliance function should pro-actively identify, document and assess the compliance risks associated with the bank’s business activities, including the development of new products and business practices, the proposed establishment of new types of business or customer relationships, or material changes in such relationships. If the bank has a new products committee, compliance function staff should be represented on the committee.

20.33

The compliance function should consider ways to measure compliance risk (eg by using performance indicators) and use such measurements to enhance compliance risk assessment. Technology can aid in developing performance indicators by aggregating or filtering data that may be indicative of potential compliance problems (eg an increase in customer complaints, irregular trading or payments activity, etc).

20.34

The compliance function should assess the appropriateness of the bank’s compliance procedures and guidelines, promptly follow up any identified deficiencies, and, where necessary, formulate proposals for amendments.

Monitoring, testing and reporting
20.35

The compliance function should monitor and test compliance by performing sufficient and representative compliance testing. The results of this testing should be reported through the compliance function reporting line in accordance with the bank’s internal risk management procedures.

20.36

The head of compliance should report on a regular basis to senior management on compliance matters. These reports should:

  1. refer to the compliance risk assessment conducted during the reporting period (including any changes in the compliance risk profile based on relevant measurements such as performance indicators);
  2. summarise any identified breaches and/or deficiencies and the corrective measures recommended to address them; and
  3. report on corrective measures already taken.
The reporting format should align with the bank’s compliance risk profile and activities.
Statutory responsibilities and liaison
20.37

The compliance function may have specific statutory responsibilities (eg fulfilling the role of anti-money laundering officer). It may also liaise with relevant external bodies, including regulators, standard setters and external experts.

Compliance programme
20.38

The responsibilities of the compliance function should be carried out under a compliance programme that sets out its planned activities, such as the implementation and review of specific policies and procedures, compliance risk assessment, compliance testing, and educating staff on compliance matters. The compliance programme should be risk- based and subject to oversight by the head of compliance to ensure appropriate coverage across businesses and co-ordination among risk management functions.

Relationship with internal audit
20.39

Principle 6 – The scope and breadth of the activities of the compliance function should be subject to periodic review by the internal audit function.

20.40

Compliance risk should be included in the risk assessment methodology of the internal audit function, and an audit programme that covers the adequacy and effectiveness of the bank’s compliance function should be established, including testing of controls commensurate with the perceived level of risk.

20.41

The compliance function and the audit function should be separate, to ensure that the activities of the compliance function are subject to independent review. It is important that there is a clear understanding within the bank as to how risk assessment and testing activities are divided between the two functions, and that this is documented (eg in the bank’s compliance policy or in a related document such as a protocol). The audit function should keep the head of compliance informed of any audit findings relating to compliance.

Cross-border issues
20.42

Principle 7 – Banks should comply with applicable laws and regulations in all jurisdictions in which they conduct business, and the organisation and structure of the compliance function and its responsibilities should be consistent with local legal and regulatory requirements.

20.43

Banks that conduct business in a particular jurisdiction should comply with local laws and regulations. For example, banks operating in subsidiary form must satisfy the legal and regulatory requirements of the host jurisdiction. Certain jurisdictions may also have special requirements in the case of foreign bank branches. Local offices must ensure that compliance responsibilities specific to each jurisdiction are carried out by individuals with the appropriate local knowledge and expertise, with oversight from the head of compliance in co-operation with the bank’s other risk management functions.

20.44

Procedures should be in place to identify and assess the possible increased reputational risk to a bank if it offers products or carries out activities in certain jurisdictions that would not be permitted in its home jurisdiction.

Outsourcing
20.45

Principle 8 – Compliance should be regarded as a core risk management activity within the bank. Specific tasks of the compliance function may be outsourced, but they must remain subject to appropriate oversight by the head of compliance.

20.46

A bank should ensure that any outsourcing arrangements do not impede effective supervision by its supervisors. Regardless of the extent to which specific tasks of the compliance function are outsourced, the board and senior management remain responsible for compliance by the bank with all applicable laws, rules and standards.2

2

See also ORR30.

Application of the guidelines and sound practices

  1. The Basel Framework is the full set of standards of the BCBS. The membership of the BCBS has agreed to fully implement these standards and apply them to the internationally active banks in their jurisdiction.1 For other banks, BCBS members may adopt a proportional approach to implementing specific rules and principles under the given standard.
  2. Guidelines elaborate the standards in areas where they are considered desirable for the prudential regulation and supervision of banks, in particular internationally active banks. They generally supplement BCBS standards by providing additional guidance for the purpose of their implementation.
  3. Sound practices generally describe actual observed practices, with the goal of promoting common understanding and improving supervisory or banking practices. BCBS members are encouraged to compare these practices with those applied by themselves and their supervised institutions to identify potential areas for improvement.
  4. The BCBS also publishes various other documents, including implementation reports and newsletters. These documents do not constitute standards, guidelines or sound practices.
  5. The Committee's standards (ie those set out in the Basel Framework) are subject to monitoring and assessment of their adoption by jurisdictions through the Regulatory Consistency Assessment Programme (RCAP). The Basel Core Principles are used in assessing the effectiveness of countries' regulatory and supervisory regimes, generally under the Financial Sector Assessment Program (FSAP). Guidelines, sound practices and other publications are not subject to RCAPs or FSAPs.
  6. The Committee periodically reviews its guidelines and sound practices as standards, supervisory practices and the financial system evolve. The consolidated guidelines and sound practices are intended to be a living document, which will be updated when the Committee publishes new materials.
  7. Unless otherwise indicated, the guidelines have been developed with a view towards application to: (i) large, internationally active banks; and (ii) supervisory and other relevant financial authorities in Basel Committee member jurisdictions. However, smaller banks and authorities in all jurisdictions may benefit from considering the guidelines and applying them on a proportionate basis, depending on the size, complexity and risk profile of the bank or banking sector for which the authority is responsible.

1 The Core Principles for effective banking supervision (Basel Core Principles) are also a standard and form part of the Basel Framework but are applicable to all jurisdictions and all banks.

This module describes expectations to combat money laundering and terrorist financing.

This module describes expectations and practices relating to capital adequacy.

This module describes expectations for corporate governance.

This module describes expectations for credit risk and counterparty credit risk management.

This module describes expectations for external audit and sets out references related to public disclosure.

This module describes expectations for banks’ internal audit and compliance functions.

This module describes expectations for liquidity risk management.

This module sets out references related to market risk and interest rate risk.

This module describes expectations for the management of operational risk and operational resilience.

This module describes expectations for the management of problem assets and expected credit losses.

This module describes the application of proportionality in prudential regulation and supervision.

This module describes expectations for risk management.

This module describes the nature and application of prudential supervision.

You might also be interested in