What Does an Outsourced CCO Do?

For registered investment advisers and broker-dealers, the need for experienced compliance leadership is obvious. The harder question is whether that leadership needs to, or in some cases, can come from a full-time internal Chief Compliance Officer.

For smaller firms, newly registered firms, and firms with relatively focused business models, hiring a full-time CCO may not make practical or economic sense. For many start-ups, the founding members may know their business very well, but no one in the group may have the commensurate compliance knowledge. In those circumstances, an experienced outside professional serving as the firm’s designated CCO and administering its compliance program on an outsourced basis may be an excellent option to explore.

An outsourced individual serving in the Chief Compliance Officer role must understand the firm’s business, know how the regulatory framework applies to it, have appropriate access to management and firm information, and be able to administer a compliance program that reflects what the firm actually does.

If you are exploring this option, it’s crucial to understand that the firm does not outsource its regulatory responsibilities. The regulators have been clear in reminding firms that internal management remains responsible for operating the business in compliance with applicable requirements. The outsourced CCO provides the compliance leadership, knowledge, judgment, testing, advice and administration necessary to help the firm meet those responsibilities.

What Do All Good CCOs Do?

Broker-dealers and investment advisers operate under different regulatory frameworks, but much of what separates a good CCO from an average one has very little to do with whether the firm is a broker-dealer or an investment adviser.

In either setting, maintaining manuals and regulatory calendars is only a small part of the job.

Understand the Business

If the CCO does not really understand how the firm operates, the compliance program will eventually show it.

That means understanding how the firm makes money, the products and services it offers, the types of clients or customers it serves, how personnel perform their jobs, where important decisions are made, and where conflicts or regulatory risks can arise.

A manual can be perfectly organized and still miss the risks created by the way the firm actually conducts its business.

A good CCO starts with the firm’s business and builds the compliance program around it.

Translate Regulation Into Practical Requirements

The rules are only part of the analysis. Regulatory guidance, examination priorities, enforcement history, interpretations and the details of the firm’s business all affect how a requirement should be handled in practice.

Knowing what a rule says is one thing. Figuring out what it means for a particular firm, and turning that into a process people can actually follow, takes both regulatory knowledge and practical experience.

Identify and Prioritize Risk

A strong CCO continually evaluates where the firm’s most significant exposures are and devotes attention accordingly. Those risks can change when the firm introduces a new product, changes a business process, hires personnel, opens an office, enters a new state, changes technology, engages a new vendor or encounters regulatory development. Accordingly, an effective compliance program cannot remain static.

The question is not simply whether there is a policy on the books. It is whether that policy still makes sense for the business and the risk it is supposed to address.

Have Access to Management, Personnel and Information

Technical knowledge does not help much if the CCO is kept at arm’s length from the business.

Whether internal or outsourced, the CCO needs access to the people, records, systems and information necessary to understand what is occurring within the firm. Just as important, the CCO must be able to communicate directly with senior management when an issue requires attention.

For an outsourced CCO, that requires more than periodic document reviews or showing up for an annual compliance exercise.

The CCO has to stay close enough to the organization to know when the business, the people or the risks are changing.

Test Whether the Program Actually Works

Written policies are just the starting point.

The CCO should be looking for evidence that required processes are actually happening and that the controls work the way the procedures say they do. Depending on the firm, that may involve transactional testing, books and records reviews, personal trading reviews, marketing reviews, supervisory testing, fee testing, communications reviews, branch inspections, privacy testing and other forms of compliance monitoring.

Testing often exposes the gaps between the manual and what is actually happening.

Once found, those gaps need to be understood and addressed, not simply put on a list.

Exercise Judgment and Know When to Escalate

There will be questions where the answer is not obvious from the rulebook.

A good CCO knows when the issue can be handled through the normal compliance process, when more facts are needed, when legal or other specialized expertise should be brought in, and when management needs to be involved.

Knowing that something is outside your expertise can be just as important as knowing the answer.

At that point, the job is to figure out who needs to be involved, get to a supportable answer and make sure the firm follows through.

Communicate Effectively

A CCO has to explain regulatory requirements to people who do not spend their day reading securities rules. The ability to communicate clearly, professionally and credibly is therefore an important part of the job.

In practice, that may mean explaining to senior management why a business practice creates risk, helping an employee understand what a procedure requires, working with operations to develop a workable control, or explaining the firm’s process to a regulator.

Follow Issues Through to Resolution

Finding a problem is not the same as fixing it.

A CCO has to make sure the issue goes somewhere: what needs to be fixed, who owns it, what the timing is, and whether the corrective action actually happened.

How Does the CCO Role Differ Between an RIA and a Broker-Dealer?

The core skills do not change much, but the work does. The regulatory framework determines what the CCO is responsible for and where the firm’s risk tends to sit.

The RIA CCO

For an SEC-registered investment adviser, Rule 206(4)-7 under the Investment Advisers Act requires the adviser to adopt and implement written policies and procedures reasonably designed to prevent violations of the Advisers Act and its rules, review those policies and procedures at least annually, and designate a Chief Compliance Officer to administer them.

For an RIA CCO, much of the job therefore centers on administering the compliance program and evaluating whether it still fits the adviser’s business.

Depending on the adviser’s business, that can include areas such as:

  • Fiduciary obligations and conflicts of interest
  • Form ADV and regulatory disclosures
  • The firm’s Code of Ethics and personal securities transactions
  • Marketing and advertising
  • Advisory agreements and client disclosures
  • Fee billing
  • Custody and safeguarding considerations
  • Books and records
  • Privacy and protection of customer information
  • Business continuity and cybersecurity-related compliance issues
  • Regulatory filings
  • Annual compliance reviews
  • Preparation for SEC or state examinations

The annual compliance review should be a real look at the program, not a confirmation that a manual exists. It should consider whether the firm’s procedures remain adequate, whether they are being implemented effectively, what compliance issues arose during the year, and whether changes to the business or applicable regulation require the program to be revised.

For state-registered advisers, specific requirements vary by jurisdiction, but the same need for an experienced CCO who understands the adviser’s business and applicable regulatory obligations remains.

The Broker-Dealer CCO

The broker-dealer framework is different. FINRA’s rules tend to be more prescriptive than the principles-based approach of the Investment Adviser’s Act of 1940, and the SEC’s subsequent interpretations and guidance.

FINRA Rule 3130 requires a member firm to designate one or more appropriately qualified principals as Chief Compliance Officer and establishes an annual certification process involving the firm’s CEO and CCO.

In practice, the broker-dealer CCO has to understand the firm’s products and activities, know which regulatory requirements attach to them, help build the compliance processes around those requirements, evaluate whether those processes are actually working, and stay close enough to management to know when something changes.

That job also sits alongside a separate supervisory framework.

FINRA Rule 3110 requires the firm to establish and maintain a supervisory system and written supervisory procedures reasonably designed to achieve compliance with applicable securities laws and FINRA rules. Importantly, the CCO does not automatically become the supervisor of every activity simply by serving as CCO. Supervisory responsibilities are assigned to appropriately registered individuals within the firm’s supervisory structure, and final responsibility for proper supervision rests with the member firm.

The CCO may help design and test the firm’s compliance processes, advise management and supervisors, and push corrective action when something is not working. But the people assigned supervisory responsibilities still have to carry them out.

Broker-dealer compliance responsibilities can include:

  • Written Supervisory Procedures
  • Supervisory systems and controls
  • FINRA Rule 3120 supervisory control testing and reporting
  • FINRA Rule 3130 compliance and supervisory-process certification
  • Communications with the public
  • Registration and licensing
  • Branch office and supervisory-location requirements
  • Customer complaints
  • Books and records
  • Anti-money laundering requirements
  • Regulatory filings
  • Sales-practice requirements
  • Annual Compliance Meeting requirements
  • Regulatory examinations and inquiries
  • Changes in FINRA, SEC and state requirements

That means a broker-dealer CCO needs to understand more than the rulebook. The CCO also has to understand the supervisory structure—who is responsible for what, how the procedures allocate that responsibility, and where the compliance function intersects with supervision.

What Does a Good Outsourced CCO Relationship Look Like?

The CCO may be outside the firm, but the role cannot be performed at arm’s length.

The person still needs enough access and enough familiarity with the business to make informed compliance judgments.

In practice, that means regular interaction with management, access to the people and records that matter, involvement when the business is changing, and a workable path for escalating issues.

And that familiarity should show up in the compliance program itself.

A limited-purpose broker-dealer conducting a narrow range of investment banking activity should not have the same compliance program as a larger retail brokerage firm. An investment adviser managing private funds may present different risks from an adviser serving individual wealth-management clients.

If the same compliance program could be handed to five unrelated firms with little more than the name changed, something is wrong. The program should look like the business it is supposed to cover.

The Advantage of a Team Behind the CCO

An outsourced model can also provide something that can be difficult for a smaller firm to create internally: access to a broader compliance team. No individual CCO knows everything.

A regulatory issue may involve an unfamiliar business activity, an unusual registration question, a complex supervisory issue, cybersecurity, financial responsibility requirements or an area where legal advice is appropriate.

One advantage of the outsourced model is that the designated CCO can draw on colleagues with different regulatory backgrounds and experience instead of having to solve every issue alone.

The same team model is useful when regulations change. Professionals working across multiple firms and business models see how regulatory developments affect different parts of the industry and can bring that perspective back to the individual client.

Breadth of experience is valuable only if the designated CCO remains sufficiently engaged with each firm to understand its particular business and risks.

When Should a Firm Consider an Outsourced CCO?

Outsourcing tends to work best when the firm genuinely needs CCO-level leadership but a full-time internal hire would be more than the business needs.

Common circumstances include:

  • A newly registering broker-dealer or investment adviser that needs an experienced CCO from the outset
  • A smaller or limited-purpose firm for which a full-time CCO would be inefficient
  • A firm whose owner or senior executive is serving as CCO but no longer has sufficient time to administer the compliance program
  • A firm experiencing the departure or retirement of an existing CCO
  • A growing firm whose compliance requirements have become more complex
  • A firm that wants access to a larger team of regulatory professionals rather than relying on a single internal resource

Cost will always be part of the conversation. But an inexpensive arrangement is not a good one if the person filling the CCO role lacks the regulatory knowledge, judgment, access or time the firm actually needs.

Choosing an Outsourced CCO

A service list tells you very little about whether an outsourced CCO arrangement will actually work.

You should ask yourself:

  • Who will actually serve as our designated CCO?
  • What experience does that person have with firms like ours?
  • How will the CCO learn our business?
  • How frequently will the CCO interact with management and personnel?
  • Will the CCO have sufficient access to our records, systems and decision-makers?
  • What resources support the designated CCO?
  • How are regulatory changes evaluated and incorporated into the program?
  • How are compliance issues documented, escalated and followed through to resolution?
  • How does the provider tailor its compliance program to different business models?
  • What happens when an issue falls outside the designated CCO’s individual expertise?

How DFP Partners Can Help

DFP Partners serves as outsourced Chief Compliance Officer for broker-dealers and registered investment advisers, responsible for administering the compliance program.

Our people do not work in isolation. Our CCOs can draw on our entire teams’ experience across broker-dealer and investment adviser compliance, regulatory examinations, registrations, supervisory systems, annual reviews, regulatory filings and other compliance matters.

We start with the business: what the firm does, where its regulatory risks arise, how responsibilities are divided, and what compliance processes actually make sense for its size, structure and activities.

Our goal is not to add compliance infrastructure for its own sake. It is to give the firm experienced support that fits the business and the regulatory obligations it actually has.

Frequently Asked Questions

What is an outsourced CCO?

An outsourced CCO is an outside compliance professional who actually serves as the firm’s designated Chief Compliance Officer. The CCO administers the firm’s compliance program and performs the responsibilities of the role without being a traditional full-time employee.

Is an outsourced CCO the same as a compliance consultant?

No. An outsourced CCO actually occupies the firm’s designated CCO role. A compliance consultant supports a firm that retains its own CCO or compliance leadership and may provide testing, annual reviews, examination support, policy development, registrations, filings or other compliance work.

Does outsourcing the CCO role transfer the firm’s regulatory responsibility to the provider?

No. The broker-dealer or investment adviser still owns its regulatory obligations. The outsourced CCO administers the compliance program and provides compliance leadership, but management and the firm retain the underlying responsibility.

Is the role of an RIA CCO different from a broker-dealer CCO?

Yes. The core skills are similar, but the regulatory frameworks are not. Investment adviser CCO responsibilities arise primarily from the Advisers Act and applicable SEC or state requirements, while broker-dealer CCOs operate within the Securities Exchange Act, FINRA rules and a separate supervisory structure.

Can an outsourced CCO support a firm during a regulatory examination?

Yes. Because the outsourced CCO is already responsible for administering the firm’s compliance program, that person will play a significant role in preparing for and responding to SEC, FINRA or state examinations, including coordinating document production, responding to questions, preparing personnel and addressing issues identified during the examination.

Is outsourcing a CCO appropriate only for startup firms?

No. Startups commonly use outsourced CCOs, but established firms may also outsource the role because of their size, business model, a CCO departure, succession planning, growth or a desire to access broader compliance resources without maintaining a full-time internal compliance department.

More from the blog