03/31/2025 | News release | Distributed by Public on 04/01/2025 06:08
Chief Compliance Officers ("CCOs") are facing uncertain times due to a combination of factors that challenge the stability and predictability of their operating environments. These factors include geopolitical tensions; rapidly shifting political and regulatory agendas that are resulting in less uniform approaches across the globe; budget and headcount restraints; evolving business models; the speed and impact of innovation; and, in some companies, waning board and management support stemming from the belief that regulatory pressures may be lessening.
The US may be the most extreme example of regulatory unpredictability. A series of Supreme Court decisions in 2024 upended the regulatory rulemaking process,[1] leading to the expectation that more regulations would be subject to challenge and litigation. While many financial institutions welcomed what was expected to be a less regulated environment and recent administration pronouncements and leadership changes continue to signal an easing of regulation and enforcement, the uncertainty has made it difficult for CCOs to plan. Questions also remain around whether some regulatory agencies will be merged or even eliminated outright, what the administration means when it says there is the need for a "fundamental refocusing" of how the nation's regulators supervise . . . banks" and what this all implies for regulatory compliance, supervision and enforcement. But it's not just CCOs in the US who are facing uncertainty.
As a result of signals that the US is less inclined to strive for international coordination on issues as diverse as capital adequacy and economic sanctions, multinational banks are concerned about a growing divergence of regulatory requirements, which will complicate compliance efforts.
In addition, CCOs are facing challenges in their own countries and regions. In the United Kingdom, the Prudential Regulation Authority ("PRA") and the Financial Conduct Authority ("FCA") in January reiterated their support for "the Government's focus on delivering a higher rate of sustainable economic growth in the UK, and on encouraging responsible risk-taking in support of that goal." The U.K. Chancellor and HM Treasury have also announced plans to review the U.K. regulatory framework, provide challenge on how regulators are enabling growth and have already announced the closure of the Payments Services Regulator as part of this review. Further changes to the regulatory framework and an expected reduction in regulatory "burdens" are expected in the U.K.
The EU has committed to a simplification agenda designed to enhance European competitiveness, attract investment and reduce regulatory fragmentation across member states and has appointed a new Commissioner for Implementation and Simplification, tasked with coordinating the Commission's response and ensuring that regulatory changes reflect the needs of businesses. A recent example includes the proposal for an Omnibus simplification package in respect of sustainability reporting.
Australian Securities and Investments Commission ("ASIC") chair Joe Longo in a March 2025 speech said that businesses and regulators alike face increasing challenges due to complex and overlapping regulations. ASIC has formed a Simplification Consultative Group to advance the goal of developing recommendations for making regulatory guidance more accessible and practical for businesses and directors. The goal of this initiative was not to deregulate but to "refine regulatory processes to ensure they remain effective and proportionate," according to Longo.
CCOs must find a way to navigate these and many other challenges to survive in an increasingly challenging environment. No doubt seasoned CCOs have faced similar circumstances before, but the magnitude and pace of change today have ushered in a degree of turmoil that seems extraordinary and may require unusual effort to manage.
For CCOs who work in organizations that have strong and immutable cultures of compliance, the period ahead may be chaotic, but they can take comfort in knowing their boards of directors and senior management will support them throughout and make clear that compliance remains a priority.
For those CCOs who are not sure what to expect or for any CCO who expects to encounter institutional challenges, this paper aims to equip you with information for navigating the complexities of your role during uncertain times.
Imagine that you are heading out on a trek through the wilderness; what are the important things that you would want to include in your survival kit? They would include items such as:
You might not think that the risk of getting lost in the wilderness has much to do with a CCO's surviving a stressful operating environment nor do we intend to suggest that a CCO's challenges are comparable to the life and death situations other survivors may face, but we do think there are some parallels in the way all survivors prepare for and manage their challenges.
Ask a CCO what she needs to survive in uncertain times, and the response you get will likely point to three basic necessities, namely:
Knowing when and how to progress when the road ahead is less clear may test a CCO's navigation skills. CCOs are used to having to make decisions based on less than perfect information. But conflicting or frequently changing views from politicians, regulators, the market and customers make that more challenging. When changes to the regulatory landscape render existing maps ineffective, CCOs will need to draw on their ethical and moral compass and consider the risks and impacts of potential changes, knowing that these form effective guardrails for many regulatory decisions. It will be important for CCOs to have as full a view of the environment as possible, and regular discussions with peers, industry groups and regulators will provide helpful directions, warnings and information as to when and how others are responding.
CCOs know the importance of compliance culture in responding to uncertainties. The CCO will want to report to senior management and the Board on how the organization is dealing with uncertainty, noting the specific regulatory changes, emerging risks and the additional help and support, whether budgetary, strategic or moral, that may be required to deal with the changes. While it may be harder to get management's attention due to an increased need for financial or business focus, the CCO will need to signal for help by being persistent, providing clear direction of the way forward and risks, and by raising concerns in a variety of fora. Keeping management aware of emerging risks and uncertainties may help prepare the ground for when leadership, decisions and support are required.
Of course, there are times when it's all gone wrong, and an emergency response is required! An early warning system of risk identification can help identify when course correction is needed and the CCO applying first aid will need to reassess the corrective action required, advise management and potentially discuss with regulators. Strong and trusted relationships and effective communication will make this process much easier.
What essential gear will a CCO need in her kit? We suggest that horizon scanning capabilities come into their own in periods of uncertainty or rapid and sometimes contradictory changes. Being able to identify new and emerging trends, changes or regulatory expectations is critical. The move from peripheral vision to central vision has been very rapid on topics such as deregulation, potential sanction changes and reduction in consumer protection. A robust risk assessment methodology is also essential kit to enable rapid analysis and determination of how to respond.
Just having a survival kit does not guarantee a positive outcome. Other factors such as physical health, and even luck, can play important roles, especially for someone trapped in the wilderness.
But if you are facing a survival crisis, no matter the type, having mental fortitude - a survivor's mentality - can also significantly enhance your ability to confront and overcome challenges.
A survivor's mentality is characterized by the following:
And finally, the characteristic that many would suggest is most critical to success:
As important as empathy is to the survival process, you shouldn't excuse people's behavior simply because you understand their motivation; it doesn't change the damage they are doing. Within that context, there may come a time when a CCO should give up the fight. The circumstances that might give rise to such a decision would include a CCO finding herself in a situation where the organization ignores her advice or warnings and engages in unethical practices or illegal activities, or the organization's non-compliance or illegal activities expose the CCO to personal liability. Under these conditions, resignation and even whistleblowing could be options, though these actions should be a last resort and should come only after careful consideration and consultation with trusted advisors and legal counsel. In some jurisdictions, CCOs who resign can expect to be contacted by the organization's regulator who will want to understand the circumstances.
Talk to CCOs who have managed through uncertain and challenging times and they will tell you that they learned a lot from the experience, including:
CCOs who have managed through periods of lighter touch supervision and regulation - and those of us who have witnessed them - will also tell you that such periods are often marked by increased risk-taking and weakening of an organization's compliance culture, which lead to unacceptable and sometimes systemic risk, followed by market volatility, loss of customer and market confidence, regulatory backlash and reforms, and an increased volume of enforcement actions. Individual institutions that take their eye off compliance by reducing investments in necessary resources and tools and otherwise deemphasizing the importance of a culture of compliance follow a similar path of increased risk-taking followed by regulatory and customer repercussions.
Sharing this history, however, is an inconvenient truth that many people do not want to hear because it requires a change in their outlook and behavior. But that doesn't mean that you shouldn't explain this pattern to decision-makers in your organization.
While the immediate environment is fraught with uncertainty, we expect that greater clarity of the new regulatory expectations will eventually emerge. When it does, CCOs will want to take advantage by taking stock of how the business and the compliance function are responding to the new world. For example:
Even the most experienced CCO can benefit from preparing for a survival challenge by:
For boards and senior management, it's important to remember that the CCO's role extends beyond mere compliance; it is about ensuring that the organization operates in a manner that builds and sustains trust with all of its stakeholders. In doing so, CCOs contribute significantly to the long-term success and sustainability of the organizations. But a CCO can only be effective with your steadfast support.
Carol Beaumier is a senior managing director in Protiviti's Risk and Compliance practice. Based in Washington, D.C., she has more than 30 years of experience in a wide range of regulatory issues across multiple industries. Before joining Protiviti, Beaumier was a partner in Arthur Andersen's Regulatory Risk Services practice and a managing director and founding partner of The Secura Group, where she headed the Risk Management practice. Before consulting, Beaumier spent 11 years with the U.S. Office of the Comptroller of the Currency (OCC), where she was an examiner with a focus on multinational and international banks. She also served as executive assistant to the comptroller, as a member of the OCC's senior management team and as liaison for the comptroller inside and outside of the agency. Beaumier is a frequent author and speaker on regulatory and other risk issues.
Bernadine Reese is a managing director in Protiviti's Risk and Compliance practice. Based in London, Reese joined Protiviti in 2007 from KPMG's Regulatory Services practice. Reese has more than 30 years' experience working with a variety of financial services clients to enhance their business performance by successfully implementing risk, compliance and governance change and optimizing their risk and compliance arrangements. She is a Certified Climate Risk Professional.
There's a better way to manage the burden of regulatory compliance. Imagine if functions were aligned to business objectives, processes were optimized, and procedures were automated and enabled by data and technology. Regulatory requirements would be met with efficiency. Controls become predictive instead of reactive. Employees derive more value from their roles. The business can take comfort that their reputation is protected, allowing for greater focus on growth and innovation.
Protiviti helps organizations integrate compliance into agile risk management teams, leverage analytics for forward-looking, predictive controls, apply regulatory compliance expertise and utilize automated workflow tools for more efficient remediation of compliance enforcement actions or issues, translate customer and compliance needs into design requirements for new products or services, and establish routines for monitoring regulatory compliance performance.
1. US Supreme Court reshapes the regulatory landscape, Protiviti, July 8, 2024: https://www.protiviti.com/us-en/in-focus/us-supreme-court-reshapes-regulatory-landscape.