What the function is for
A compliance function exists to ensure that the business meets its obligations, which sounds obvious and is frequently interpreted in two unhelpful ways.
The first treats it as a documentation function: maintaining policies, completing returns, responding to regulator queries and producing evidence when asked. This is necessary and, on its own, produces the operators that appear in enforcement material with excellent policies and inadequate practice.
The second treats it as a veto function: reviewing proposals and declining those that breach requirements. This is also necessary and, on its own, produces an adversarial relationship in which the business routes around compliance rather than using it.
The function that works does both and adds a third thing, which is finding out whether the controls actually operate. That is where the difference between a documented framework and a functioning one is established, and it is the activity most often absent.
Structure
The arrangement depends on scale and market footprint, and the principles are consistent.
Central ownership of standards, policy, aggregate risk view, regulatory relationships and the board interface. This is required because obligations interact across markets, because conduct in one jurisdiction affects licences in others, and because someone must hold the group picture.
Local expertise in each significant market, since obligations differ in detail that matters and generalist knowledge produces confident errors.
Reporting lines running to the centre, not into local commercial management. This is the point on which the function's viability depends.
Specialist areas within the function, typically covering financial crime, responsible gambling, regulatory affairs and, depending on the operator, data protection.
Embedded support where compliance staff work alongside the functions they support, which improves relevance at the cost of independence if reporting lines follow the embedding.
The three lines model is the common framing: the business owns and operates controls, compliance provides oversight and challenge, and internal audit provides independent assurance. It works where the distinctions are real, and degrades where compliance is doing the business's job because the business has not taken ownership, which is a common condition and is worth naming when it occurs.
Independence
The single structural requirement without which nothing else matters.
A compliance officer reporting to a commercial director whose revenue targets compliance decisions constrain is in the same position as a VIP account manager paid on their customers' losses, or an analyst reporting to the person whose proposals they assess. The arrangement does not guarantee a bad outcome; it makes the good outcome depend on individual courage, which is not a control.
The practical requirements are a reporting line to the chief executive, the board or a board committee rather than into the commercial structure; direct access to the board and to non-executive directors, exercisable without going through management; protection for the individual, which personal licensing partly provides by giving them regulatory accountability that outranks their employment relationship; budget that is not at the discretion of the functions being overseen; and the ability to escalate externally, ultimately to the regulator, which is a genuine backstop and one that licensed individuals may have obligations to use.
An operator unwilling to provide these has told its compliance function what its role actually is.
Assurance
The activity that distinguishes functioning compliance from documented compliance.
A compliance monitoring plan schedules testing across the obligations the operator holds, prioritised by risk, so that every significant control is examined on a defined cycle rather than when something goes wrong.
The testing must be testing rather than review. The difference is concrete.
Policy review asks whether a deposit limit policy exists. Assurance attempts to exceed a deposit limit through every payment route and every brand.
Policy review asks whether a self-exclusion procedure is documented. Assurance attempts to deposit as a self-excluded customer and checks whether marketing reaches one.
Policy review asks whether an interaction policy exists. Assurance takes ten accounts that displayed indicators and traces what was identified, what was done, what changed and what followed.
Policy review asks whether affiliate terms require compliance. Assurance looks at live affiliate content.
Policy review asks whether source of funds procedures exist. Assurance examines whether the highest-spending customers were actually assessed and what evidence was accepted.
The second column is what a regulator does. An operator that has done it first knows what will be found.
Findings must produce remediation with owners and deadlines, and follow-up verifying that the remediation occurred. Findings recorded and not closed are a record of known problems, which is worse than not having looked.
Standing
The informal dimension, and the one that determines whether the function is effective in practice.
A compliance function with standing is consulted at design, when a proposal can still be shaped cheaply. One without standing is consulted at approval, when the work is done and the answer is either yes or an expensive no.
Standing is earned rather than granted, and the behaviours that build it are consistent.
Answer quickly. A function that takes three weeks to respond to routine questions will be routed around.
Distinguish requirements from preferences. A compliance officer who presents every view as a legal requirement loses the ability to signal when something actually is one.
Offer routes rather than only refusals. The useful answer to a proposal that breaches a rule is frequently what would work instead.
Be right. Credibility is spent by confident wrong answers, and this area is complex enough that they happen.
Understand the business. A compliance function that cannot describe how the operator makes money will give impractical advice and be treated accordingly.
Hold the line where it matters. Standing built by agreeableness is worth nothing at the moment it is needed. The function's reputation depends on the business knowing that a compliance no is genuine.
Measuring effectiveness
Activity measures are easy and largely uninformative. Policies maintained, training completed, queries answered and returns filed all measure effort.
The measures that indicate whether the function works are different.
What has it found? A function with no findings is usually not looking. Businesses have problems, and an assurance programme that never identifies one is not testing.
What has changed as a result? Findings that produced remediation demonstrate influence. Findings recorded and unresolved demonstrate the opposite.
Is it consulted before or after? The proportion of significant decisions where compliance was involved at design rather than at approval.
Do people raise things? The volume and quality of concerns coming from the business voluntarily, which indicates whether raising them is safe.
How did the last incident go? Whether it was identified internally, escalated promptly, reported where required and remediated, or whether it surfaced through a regulator or a complaint.
What do external reviews find? Independent assessment, which is the only way to know whether the function's own view of itself is accurate.
Regulatory relationship quality, which is subjective and is nonetheless known to anyone who has one.
Culture
The final and most consequential thing a compliance function builds, and the one it cannot build alone.
The pattern in this sector's enforcement record, restated once more, is that the information was available and nothing effective followed. That is rarely because nobody knew. It is because the person who knew did not raise it, or raised it and was not heard, or raised it and the commercial answer prevailed.
The conditions that change this are cultural rather than procedural. Raising a problem must be safe, demonstrated by how the last person who did it was treated. Escalation must be routine rather than exceptional. Concerns about valuable customers must carry no penalty for the person raising them. Self-reporting a mistake must be better for the individual than concealing it. And senior people must have visibly declined things that would have made money, because that is the only evidence anyone believes.
A compliance function can advocate for these and cannot create them. They are established by what leadership actually does, which is the subject of the final course in this programme.
Closing the course
This course has covered the regulatory architecture, licensing, financial crime, responsible gambling obligations, advertising and consumer protection, data protection, and the function that holds it together.
The recurring finding across every area is the same. Operators facing enforcement generally had policies. What they lacked was evidence that the controls operated on the cases where it mattered, and the gap between those two things is where this sector's enforcement record sits.
Closing it is not a matter of better documents. It is a matter of testing, of independence, of standing, and of a culture in which the information that was always available reaches someone empowered to act on it and that person does. Everything technical in this course serves that, and an operator that gets the technical detail right and the culture wrong will find the technical detail did not save it.
Resourcing and capability
A practical dimension, since compliance functions are frequently under-resourced in ways that are invisible until they matter.
The capability required in this sector is specific. Gambling regulatory knowledge, market by market. Financial crime expertise. Responsible gambling practice, which is a genuine discipline rather than a policy area. Data analysis, since assurance depends on interrogating data rather than reading documents. And enough understanding of the operating business to give advice that can be acted on.
These skills are developed largely within the industry, which means the pool is small, as the Operations Strategy course noted. Hiring alone will not fill a function, and development is therefore part of the plan rather than an afterthought.
The sizing question has no formula, and the useful test is whether the function can actually complete its monitoring plan. A function whose assurance programme is perpetually behind is not adequately resourced, regardless of how its headcount compares to peers. That test is more informative than benchmarks, which as elsewhere in these courses are constructed on inconsistent bases.
The interaction and safer gambling teams deserve separate mention. A queue larger than the team can work properly is not a resourcing inconvenience; it is a documented failure to act, and it appears as such in enforcement findings.
Technology matters more than in most compliance functions, because assurance in this sector means querying transaction and behavioural data rather than reviewing files. A compliance function without data access and the capability to use it is limited to reviewing documents, which is precisely the mode this lesson has argued against.
The relationship with the regulator
A capability that sits with the compliance function and shapes the operator's position materially.
Continuity. Regulators value knowing who they are dealing with, and a relationship maintained by the same people over time accumulates credibility.
Proactivity. Raising matters before being asked, including matters that reflect poorly, builds a position that is available when something serious occurs.
Accuracy. Nothing damages standing faster than a submission that turns out to be incomplete. The information a regulator receives should be right the first time.
Constructive engagement on rules. Operators that respond to consultations with analysis rather than opposition are listened to more. Submissions arguing that every proposal threatens channelisation are discounted, which weakens the argument in the cases where it is genuinely strong.
Understanding their position. Regulators are supervising a sector with a poor conduct record under political scrutiny. An operator that engages as though its regulator is an obstacle rather than a supervisor with a job to do misreads the relationship.
The value of this becomes apparent at the moment something goes wrong, when the regulator's prior view of the operator affects how the matter is approached. That view is formed over years of routine interaction.
Stages of maturity
Compliance functions develop through recognisable stages, and knowing which one an operator is in indicates what to work on next.
Reactive. The function responds to requirements as they arrive and to problems as they surface. Policies exist because they were required. There is no monitoring plan and no systematic view of obligations. Most small operators start here and some remain.
Documented. Obligations are mapped, policies are comprehensive and current, returns are filed correctly and the regulator receives what it asks for. This looks like compliance and is the stage at which operators are most likely to be surprised, because nothing yet tests whether controls operate.
Assured. A monitoring plan exists and is executed, findings are raised and remediated, and the function knows where the weaknesses are. This is the stage at which enforcement becomes considerably less likely, because problems are found internally.
Embedded. Compliance is consulted at design, the business owns its own controls, escalation happens without prompting, and the function spends its time on genuinely difficult questions rather than on catching failures. Few operators reach this.
The progression is not automatic and the gap between the second and third stages is the significant one. It requires the function to move from producing documents to testing outcomes, which requires data access, capability and the standing to require remediation when it finds problems.
An operator wanting to know which stage it occupies can answer one question: when did we last identify a significant control failure ourselves, before anyone external raised it? A function that cannot recall one is at the second stage regardless of how comprehensive its documentation is.
Working with the rest of the business
A closing point about positioning, since effectiveness depends on relationships the function does not control.
Commercial needs compliance early enough to shape proposals rather than late enough to block them.
Product needs the constraints as design inputs, as the Product Innovation course argued.
Marketing needs approved building blocks and fast answers, or it will route around the function.
Payments needs joint working, since payment changes can defeat compliance controls without anyone intending it.
Customer operations needs training, escalation routes and approved language, and provides in return the human observations no system generates.
Technology builds the controls and the assurance capability, and a compliance function without technical partnership is limited to reading documents.
Finance owns the resourcing and understands the cost of the alternative better than most, since the enforcement penalties in this sector are financial statements items.
The board provides the independence and the standing, without which none of the above is reliably available.
The function that works is connected to all of these. The function that fails is the one that owns compliance while everyone else owns the business, because in that arrangement the controls sit outside the processes they are meant to govern and the failures happen in the gaps.