SD-14.2 — Corporate Compliance & Conduct
Business Domain: BD-14 Enterprise Risk, Control & Assurance (Cross-cutting — corporate) · Applies: BOTH
Purpose
Runs the firm’s compliance as a licensed entity, and governs the conduct of its people. SD-14.2 is the Chief Compliance Officer’s function: it operates the firm’s compliance programme, runs the regulator relationship’s compliance dimension, scans the regulatory horizon for change, and governs employee conduct — the code of ethics, personal-account dealing, conflicts of interest, gifts and entertainment, and outside business interests. The personal-account-dealing and conflicts capability monitors the employee, not the portfolio. It is not investment compliance — BD-10 checks the portfolio against the rules it must obey — and it is not financial crime, which is SD-14.3; corporate compliance and financial crime are run by different officers (the CCO and the MLRO) and are distinct second-line functions.
For an in-house asset owner that is not an authorised firm — a DB pension, sovereign wealth fund or endowment managing only its own money — the licensed-adviser thread of this Service Domain (the compliance programme of a regulated adviser, the regulator relationship’s compliance dimension) is light or dormant; the conduct thread (the code of ethics, personal-account dealing, conflicts of interest, senior-accountability mapping) still applies.
Service Operations
- Operate the compliance programme — maintain and run the firm’s compliance programme and the compliance monitoring plan, as a licensed entity.
- Scan the regulatory horizon — monitor for regulatory change firm-wide, and route the investment-rule-affecting subset to SD-10.3 and the SD-10.2 rule library.
- Govern employee conduct — maintain and enforce the code of ethics, and run conflicts-of-interest, gifts-and-entertainment and outside-business-interest management.
- Run personal-account dealing — operate the personal-account-dealing pre-clearance and monitoring of employees’ personal trading.
- Manage senior-accountability and attestations — maintain the senior-managers accountability mapping and run the firm’s conduct attestations.
Inputs and outputs
- Inputs: the conduct regulation and the firm’s licence conditions; employee trading and conduct activity; the certification record from SD-17.6; regulatory developments; compliance-breach reporting from SD-10.8.
- Outputs: the compliance programme, the regulatory-change horizon-scan, the conduct and personal-account-dealing record — consumed by SD-10.3 (the investment-rule-affecting regulatory change), SD-06.5 (the conflict-of-interest discipline), the governing bodies and the regulators.
Entities
- Consumes: the firm’s employee, conduct and licence records; the SD-10.8 compliance-breach reporting; the SD-17.6 certification record; E-35 Complaint Record (from SD-15.16 — the complaints MI, the root-cause findings and the systemic-finding flags that feed the conduct-and-outcomes evidence picture).
- Owns: the compliance programme, the conduct register and the personal-account-dealing record — a process artefact.
Standards
- FCA SYSC, the SMCR and the Consumer Duty; the SEC Advisers Act — the Compliance Rule (206(4)-7) and the Code of Ethics rule (204A-1).
- The CFA Institute Asset Manager Code — the requirement for an empowered, independent compliance function.
- The Three Lines Model — corporate compliance and conduct as a second-line function.
Open extensions
- The compliance-programme and regulatory-change-management sub-model.
- The personal-account-dealing workflow.
- The boundary with BD-10 — corporate compliance versus investment compliance.