SardineCon SF/2026

Learn More
AML programs4 min read

What is Chief Compliance Officer (CCO)?

SUBSCRIBE

The Chief Compliance Officer is the senior executive accountable for a firm's entire compliance function, financial crime included. They set the compliance agenda, report to the board, own risk appetite and resourcing at the top, and increasingly carry personal liability under individual-accountability rules.

What is a CCO, in plain English?

The Chief Compliance Officer is the most senior person responsible for compliance across the whole firm. Their remit is broader than AML: it spans conduct, regulatory compliance, and financial crime. Within financial crime, the CCO is usually the escalation point sitting above the BSA Officer or MLRO.

What makes the role distinct is that it owns risk appetite and resourcing at the top. The CCO sets the compliance agenda, decides how much risk the firm is willing to tolerate, and reports directly to the board on where the program stands. They are the bridge between the day-to-day compliance function and the people who control the budget.

Increasingly the CCO also carries personal liability under individual-accountability regimes. Regulators want a named senior executive they can hold responsible, so the role is not just organizational; it can put the individual's own standing on the line when a program fails.

What sits under the CCO

The compliance function the CCO owns typically breaks into a few pillars:

  1. Financial crime — AML, sanctions, fraud oversight. The BSA Officer or MLRO and their teams report up through this line.
  2. Regulatory — Conduct and rule compliance. Making sure the firm meets its licensing, disclosure, and market-conduct obligations.
  3. Governance — Board and risk appetite. Setting how much risk the firm accepts and reporting the true picture upward.
  4. Resourcing — Budget and headcount. Owning the decisions on staffing and tooling that determine whether the program can actually work.

CCO vs the officers below them

Who

Their role

Chief Compliance Officer

Owns the whole compliance function, risk appetite, and board reporting; carries top-level accountability.

BSA Officer / MLRO

Owns the specifics of AML compliance and filing decisions; escalates to the CCO.

Investigators and analysts

Do the case and alert work; feel resourcing decisions most directly.

Board

Receives the CCO's reporting and holds ultimate governance responsibility.

What it looks like in practice

In practice

Investigators at a growing payments firm are drowning: alert volume has doubled but headcount has not, and cases sit open past internal deadlines. The team keeps asking their manager for more people and keeps hearing there is no budget.

The real fix is not on the queue floor. Whether the function gets more investigators is a decision that lives with the CCO, who owns resourcing and reports the risk to the board. Framing the backlog as a CCO-level governance issue, rather than a team gripe, is what finally moves it, because it points the problem at the person with authority to solve it.

Why the CCO owns resourcing problems

For front-line teams, the important takeaway is that chronic under-resourcing of investigations is a CCO-level governance problem, not just a team gripe. If cases pile up because there are never enough investigators, the fix sits above the queue, with the person who owns budget, headcount, and the firm's risk appetite.

This matters because pointing the issue at the wrong level wastes time. A team lead cannot conjure headcount, and repeatedly asking them for it changes nothing. Escalating the same problem as a governance risk to be reported to the board puts it in front of the decision authority that can actually act, and it creates a record that the risk was raised, which protects both the team and the firm.

What to watch for

  • Persistent backlog. A queue that never clears is usually a resourcing decision, and that decision belongs to the CCO.
  • Risk appetite drift. When the business keeps onboarding higher-risk customers, someone at the CCO level has set or tolerated that appetite.
  • Board reporting gaps. If material risks never reach the board, the CCO's core function is not working.
  • Compliance overruled. Revenue teams routinely overriding compliance signals a weak CCO position in the firm's power structure.
  • Unfilled or revolving role. A vacant or churning CCO seat is a governance red flag and often precedes enforcement.

Quick questions

Is the CCO the same as the BSA Officer or MLRO?

No. The CCO owns the entire compliance function and usually sits above the BSA Officer or MLRO, who handle the specifics of AML compliance and filing decisions. The CCO is the escalation and governance layer.

Does the CCO handle only AML?

No. AML and financial crime are part of the remit, but the CCO also owns conduct, regulatory, and broader compliance obligations across the firm.

Can the CCO be held personally liable?

Increasingly yes. Individual-accountability regimes are designed to name a senior executive who can be held responsible when a program fails, which raises the stakes for the person in the seat.

Why should front-line teams care who the CCO is?

Because the decisions that shape their working conditions, like headcount and tooling, live at the CCO level. Chronic under-resourcing is a governance problem to escalate upward, not a queue problem to grind through.

Who does the CCO report to?

The board or a board committee, and often the CEO. That direct line to governance is a defining feature of the role and part of what gives it independence.

What is the sign of a weak CCO function?

Compliance being routinely overruled by revenue teams, material risks not reaching the board, and persistent backlogs that management simply tolerates. These point to a role without real authority.

Go deeper

  • FFIEC BSA/AML Examination Manual ↗ — The manual US examiners use to assess BSA and AML programs.
  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.

What to know alongside Chief Compliance Officer (CCO)