Most firms do not buy compliance support because they lack a compliance officer. They buy it because the regulatory perimeter around their business has moved faster than the internal function can absorb, and because a supervisory letter, an authorisation application or a growth plan has exposed a gap that must be closed before it is found by someone else.
This article sets out what retained FCA compliance support properly covers, what it can never cover, and how a board should structure and supervise the arrangement so that it strengthens rather than dilutes accountability.
What "compliance support" means in practice
The term covers four distinct types of work that are often conflated in proposals and priced as if they were one thing.
Advisory support. Interpretation of FCA rules and guidance as applied to specific products, distribution arrangements and customer segments. This is question-driven and episodic.
Operational compliance support. Delivery of a defined compliance function activity: the compliance monitoring programme, board and committee reporting, breach and complaints oversight, horizon scanning and policy maintenance.
Assurance and review. Independent testing of the framework: financial crime reviews, safeguarding reviews, Consumer Duty outcome testing, permissions reviews and readiness assessments ahead of a skilled person review.
Project and remediation work. Authorisation and variation of permission applications, remediation following supervisory contact, and implementation of new regimes such as the interim safeguarding regime under CASS 15.
A retainer that does not state which of these four it includes will produce disagreement in month three.
| Work type | Typical trigger | Usual pricing model | Who owns the output |
|---|---|---|---|
| Advisory | Product launch, new market, rule change | Retainer hours or day rate | Firm, on the record of advice |
| Operational | Capacity gap in the compliance function | Monthly retainer | Firm's Compliance Oversight function |
| Assurance | Board request, supervisory contact, audit | Fixed fee per review | Board or audit committee |
| Remediation | Dear CEO letter, s166, breach | Fixed fee or milestone | Named senior manager |
What cannot be outsourced
SYSC 8 permits outsourcing of critical or important operational functions, subject to conditions. It does not permit outsourcing of responsibility. Three principles govern the arrangement.
The firm remains accountable
The firm must not outsource in a way that impairs the quality of its internal control or the ability of the FCA to supervise it. In practice that means the firm must retain enough internal capability to challenge the provider, to understand the output, and to act on it.
A senior manager must own the obligation
Under SM&CR, prescribed responsibilities sit with approved individuals inside the firm. The Compliance Oversight function and the MLRO are firm roles. An external provider can support the holder of those functions but cannot hold them. Where a provider is described as performing a controlled function, the arrangement is defective.
Reasonable steps must be evidenced
A senior manager relying on an external provider must be able to show what they did to oversee that reliance: what they commissioned, what they received, what they challenged and what they did with the findings. Reliance without oversight is the position the FCA has repeatedly criticised.
How to scope a retained arrangement
A defensible scope document answers seven questions.
- Which regulatory obligations are in scope, by rule reference rather than by theme.
- What is expressly out of scope, and who covers it instead.
- What deliverables are produced, at what frequency, and in what format.
- Who personally performs the work, and what happens if they are unavailable.
- What the escalation route is when the provider identifies a potential breach.
- How records and work product are held, and what happens on exit.
- What the annual review process is, and against what measures.
Firms frequently omit the fifth point. The provider identifies an issue, raises it informally, and no record exists of when the firm was put on notice. If that issue later becomes a reportable breach under Principle 11 or SUP 15, the absence of an escalation record is itself a governance finding.
Where retained support earns its fee
The regimes that consume the most internal capacity are those where the rules change continuously and the evidential standard is high.
Safeguarding. The interim regime introduced by PS25/12 and delivered through CASS 15 raised the standard on records, reconciliation and audit evidence for payment institutions and e-money institutions. Our PS25/12 safeguarding compliance checklist sets out the underlying obligations.
Financial crime. Transaction monitoring calibration, sanctions screening effectiveness and the annual MLRO report are areas where supervisory expectations have risen faster than most firms' systems. See our guidance on FCA financial crime compliance.
Consumer Duty. The annual board report requires outcomes evidence, not process description. Firms that report on activity rather than outcomes are the ones that attract follow-up.
Regulatory reporting. Late or inaccurate REP returns remain one of the most common sources of supervisory contact, and one of the easiest to prevent.
How boards should test the arrangement
Once a year, the board or audit committee should be able to answer four questions from documents rather than from assurance given verbally.
- Did we receive everything the scope said we would receive?
- What did the provider find, and what did we do about each finding?
- Where the provider identified a control weakness, is it closed, and who verified closure?
- Would this arrangement withstand a skilled person review of governance?
If the answer to the fourth question is uncertain, the arrangement needs restructuring before it is renewed.
About Regulatory Counsel
Regulatory Counsel advises UK and international financial services firms on authorisation, prudential and conduct requirements, governance, financial crime and regulator engagement.
Our retained compliance support covers compliance monitoring programmes, board and committee reporting, policy framework design and maintenance, horizon scanning, financial crime and safeguarding reviews, Consumer Duty implementation and outcomes testing, regulatory reporting oversight and regulator correspondence.
Contact our regulatory team at info@regulatorycounsel.co.uk.
This article is provided for general information and does not constitute legal or regulatory advice. Firms should confirm the current position against FCA publications and take advice on their specific circumstances.
Frequently Asked Questions
It typically covers advisory work on rule interpretation, operational delivery such as compliance monitoring and board reporting, independent assurance reviews, and project work including authorisation applications and remediation following supervisory contact.
A firm can outsource compliance activity but not accountability. SYSC 8 requires that outsourcing does not impair internal control or FCA supervision, and the Compliance Oversight and MLRO functions must be held by approved individuals within the firm.
Most arrangements use a monthly retainer against an agreed hour allocation, with fixed fees for defined projects such as authorisation applications or independent reviews. Scope definition affects total cost far more than the headline rate.
The obligations in scope by rule reference, express exclusions, deliverables and frequency, named personnel, the escalation route where a potential breach is identified, record retention and exit terms, and the annual review process.
By retaining records of what was commissioned, what was delivered, what challenge was applied, and what action followed each finding. Reliance on a provider without a documented oversight trail does not satisfy the reasonable steps standard.
