The compliance function is the part of ISO 37301:2021 that organisations most often meet on paper and fail in substance. The standard defines it as the “person or group of persons with responsibility and authority for the operation of the compliance management system” (3.23), adds that “preferably one individual will be assigned to the oversight of the compliance management system”, and places it in a governance triangle with top management and the governing body — the body “to which top management reports and by which top management is held accountable” (3.21). The requirement that trips implementations is independence: a compliance function that reports to the commercial leadership whose decisions it must question has responsibility without authority, and an auditor reading the org chart will say so. This guide sets out what ISO 37301 requires of the function, the four tests of independence, how to size and staff it proportionately, what it owns and what it must never own, how it reports to the governing body, and the five findings auditors raise.

What ISO 37301 requires of the compliance function
| Requirement area | What the standard expects | Evidence |
|---|---|---|
| Existence and assignment | A function with responsibility and authority for the operation of the CMS; preferably one individual assigned to oversight | Charter or terms of reference; appointment record |
| Authority | Able to require information, escalate, stop or challenge activity that creates compliance risk, and report noncompliance | Delegations; mandate approved by the governing body |
| Independence | Free from conflicts with the activities it oversees; not subordinate to the functions whose compliance it assesses | Reporting line; conflict-of-interest arrangements |
| Access to the governing body | Direct and unimpeded access to report | Governing-body agenda; minutes of compliance reports |
| Resources and competence | Adequate resources (7.1); competence to operate the CMS (7.2) | Budget; headcount; competence records |
| Role boundaries | Management remains responsible for compliance in its own areas; personnel comply; the function operates the system | Roles matrix under 5.3 |
The last row is the one that keeps the function honest. ISO 37301 makes compliance everyone’s job — top management demonstrates commitment, managers ensure compliance in their areas, personnel comply — and gives the function the system, not the compliance. A function that owns compliance itself becomes the place accountability goes to die. Our guide to ISO 37301 covers the wider standard.
Four tests of compliance function independence
- Reporting line. To whom does the head of the function report administratively, and to whom functionally? Functional reporting to the CEO or the governing body with a direct line to the board or its audit or risk committee passes; reporting to a sales, operations or finance leader whose decisions the function assesses fails.
- Remuneration and appraisal. Who sets the function’s objectives and bonus? If the answer is the leadership it oversees, independence is compromised however the org chart reads.
- Appointment and removal. Can the head of compliance be removed by a manager it has reported on? The governing body should approve appointment and removal.
- Operational roles. Does anyone in the function also run an activity it assesses — a compliance manager who is also the sales director, or a DPO who runs the marketing database? Dual roles need documented conflict handling or separation.
Sizing and staffing it proportionately
| Organisation | Typical model | Where independence comes from |
|---|---|---|
| Small firm (≤50 staff, few regulated activities) | One named compliance officer, often part-time, possibly the company secretary or a senior manager outside the exposed activities | Direct access to the owner or board; documented conflict handling; external adviser for areas of specialism |
| Mid-size company (100–500 staff) | A compliance lead with one or two specialists; DPO and anti-bribery roles may sit inside | Functional reporting to the CEO; board or committee reporting quarterly; appraisal by the CEO or board |
| Regulated group | Chief compliance officer, central team, business-line compliance officers, regional roles | Second line of defence; independent from first-line management; charter approved by the board; direct committee access |
| Outsourced or shared | External compliance provider under contract for defined scope | Contract terms on access and independence; internal owner of the CMS retained |
The standard says implementation “can differ depending on the size and level of maturity of an organization’s compliance management system and on the context, nature and complexity of the organization’s activities and objectives”. A one-person team is compliant if it has the authority, the access and the competence; a twenty-person function is not if it reports to the wrong place.
What the function owns
| Owns | ISO 37301 clause | Does not own |
|---|---|---|
| The obligations register and its currency | 4.5 | Compliance with each obligation — that stays with the operational owner |
| The compliance risk assessment | 4.6 | The decision to accept residual risk — that is management’s |
| Advice on and design of controls | 8.2 | Operating the controls in the business |
| The raising-concerns mechanism | 8.3 | Every investigation — HR, legal or specialists may lead under 8.4 |
| Monitoring and reporting | 9.1 | Internal audit — which must be independent of the function too (9.2) |
| Training and awareness design | 7.2, 7.3 | Managers’ duty to ensure their people comply |
| Reporting to the governing body | 5 | The governing body’s accountability |
Our guides to the compliance obligations register and compliance risk assessment cover the two artefacts the function owns outright.
The compliance function and the governing body
- A standing agenda item, at least quarterly, with the compliance function presenting in its own name.
- Content: the residual risk profile from 4.6, changes to obligations, monitoring results and trends, concerns raised and investigations, noncompliance and corrective action, resourcing, and the function’s own independence.
- A private session without executive management at least annually, so the function can speak about the executives.
- Minutes that record decisions and actions — the 9.3 and 5.1 evidence.
- An escalation route outside the normal cycle for serious matters.
Five findings auditors raise
- Reports to the function it oversees. The most common and the most serious; the org chart is the evidence.
- Named but not resourced. A title with no time, budget or competence behind it (7.1, 7.2).
- Owns compliance instead of the system. Managers point to the team when asked who is responsible.
- Never reached the board. No minutes show the function reporting to the governing body.
- Dual roles without conflict handling. The compliance lead also runs a regulated activity and no one wrote down how that conflict is managed.
Frequently asked questions
What is the compliance function under ISO 37301?
The person or group with responsibility and authority for the operation of the compliance management system (3.23), preferably with one individual assigned to oversight, resourced and competent, independent of the activities it oversees, and with direct access to the governing body.
Does the function have to be independent?
In substance, yes. It must be able to challenge and report on the activities it oversees, which it cannot do if it reports to, is appraised by or can be removed by the management of those activities.
Can a small company have a one-person compliance function?
Yes. The standard is explicitly adaptable to size and complexity. One named person with authority, access to the board and adequate competence — supported by external advice where needed — meets the requirement.
Is the compliance function the same as internal audit?
No. Internal audit (9.2) must be independent of the team as well as of the business, because it audits the CMS the function operates.
Who is accountable for compliance?
The governing body and top management are accountable; managers are responsible in their areas; personnel comply; the compliance function operates the system that makes all of that visible and evidenced.
Where this leaves you
Give the compliance function a charter the governing body approves, a reporting line that does not run through the activities it oversees, an appraisal and removal route that management cannot control, the resources and competence the standard requires, and a standing place on the board’s agenda. Then keep it in its lane — it owns the system, the register, the assessment and the reporting; the business owns compliance — because that division is what ISO 37301 means by responsibility and authority.
References
- ISO 37301:2021 — Compliance management systems — Requirements with guidance for use — First edition, April 2021; the definitions of compliance function (3.23), governing body (3.21) and personnel (3.22) and the introduction’s adaptability statement are readable on the ISO Online Browsing Platform.
- ISO 37000:2021 — Governance of organizations — Guidance — The governance frame the compliance function reports into.
More on ISO 37301
- The compliance function — you are here
- ISO 37301 explained
- Compliance culture
- Compliance risk assessment: clause 4.6
- Compliance monitoring
- ISO 37301 vs ISO 19600
The Compliance Function Charter, the roles and responsibilities matrix, the governing-body reporting template, the conflict-of-interest procedure and the competence framework are in the ISO 37301 Compliance Management Toolkit, or start with the free templates.