3.2 CO Duties, Approval, Independence & Reporting

Key Takeaways

  • A compliance officer must be approved by the Authority under section 17(2) against determined criteria and guidelines; the Authority may withdraw approval for Act contraventions, fit-and-proper failure, or criteria non-compliance.
  • Independence and avoidance of conflicts are essential so monitoring is objective — a CO cannot effectively monitor if sales pressure or dual roles compromise diligence, care and competence under Regulation 5.
  • COs provide written monitoring reports and recommendations to the FSP (Reg 5(3)) and must submit prescribed compliance reports to the Authority (section 17(4)); the FSP must ensure those reports go in.
  • Representatives must cooperate with monitoring: give access to records and information, not obstruct reviews, and never give false, misleading or incomplete information to a CO (an offence under the Act).
  • Section 18 record-keeping (five-year themes including complaints, non-compliance cases, and representative fitness) feeds CO monitoring; the CO still does not take over KI management accountability.
Last updated: August 2026

3.2 CO Duties, Approval, Independence & Reporting

Quick Answer: A CO must be approved by the Authority (section 17(2)), meet fit and proper standards on an ongoing basis, and perform monitoring with diligence, care and competence (Reg 5). The CO gives the FSP written monitoring reports and recommendations, submits prescribed reports to the Authority, and must act with meaningful independence. Approval can be withdrawn. Representatives must cooperate — provide access to records (supported by section 18 record duties) and must not supply false or misleading information.

From role to operating rules

Section 3.1 answered who the CO is and when appointment is required. This section covers how the role is authorised and performed: approval, withdrawal, independence, reporting lines, record access, and the representative’s duties when the compliance function examines their work.

Approval by the Authority — section 17(2)

Section 17(2)(a)(i) states that a compliance officer must be approved by the registrar/Authority in accordance with the criteria and guidelines determined by the Authority. Those criteria are a regulatory instrument under the FAIS/FSR framework (see section 1B of the Act).

Practical implications for RE5:

  • The FSP appoints a person or practice, but the person cannot lawfully function as the FSP’s CO without Authority approval of that appointment.
  • Approval is not automatic: qualification, experience, and capacity to perform section 17 functions for the relevant business type are tested against the published criteria.
  • The Authority may amend criteria and guidelines; an already approved CO must meet the amended standards within the period the Authority sets (section 17(2)(a)(ii)).

Application steps (conceptual)

Regulation 4 (FAIS Regulations) requires the authorised provider to submit an application for approval of a CO under section 17(2) in writing on the form determined by the Authority, with all required information. Two related ideas often appear in practice materials:

  1. The individual/practice must be capable of approval under the CO criteria; and
  2. The appointment to a specific FSP must also be processed/approved so the CO is linked to that licence holder.

You do not need form numbers for RE5, but you must know that approval is a regulatory gate, not a private job title the FSP invents.

Withdrawal of approval — section 17(2)(b)–(d)

The Authority may at any time withdraw CO approval if satisfied, on available facts and information, that the compliance officer:

  1. Has contravened or failed to comply with any provision of the Act; or
  2. Does not meet or no longer meets fit and proper requirements; or
  3. Does not comply or no longer complies with the approval criteria and guidelines.

Procedural fairness themes from section 9 (licence suspension/withdrawal) apply with the necessary changes to withdrawal of CO approval (excluding certain period/terms provisions). The Authority may publish withdrawal of approval and the reasons on its official website or other appropriate public media.

Exam angle: Approval is conditional and ongoing. Passing an approval process years ago is not a lifetime shield if honesty, competence, or criteria compliance collapses.

Independence and conflicts — why monitoring must be real

The Act’s architecture only works if monitoring is objective. Independence is therefore a recurring theme in CO criteria, regulator guidance, and good governance:

  • A CO who is financially or operationally captured by the sales desk cannot credibly report breaches of GCOC section 3(1)-type duties (incorrect representations, inadequate disclosures, unmanaged conflicts).
  • Dual roles that mix line management of production with independent compliance sign-off create conflict risk. Where structures combine functions, firms must still show that monitoring is exercised with the diligence, care and competence Regulation 5(2) demands.
  • External COs must still understand the FSP’s product and process risks enough to monitor effectively; internal COs must still be able to escalate findings without retaliation.

Independence does not mean the CO is above the FSP or replaces the board/KI. It means the CO can see, test, and report without improper interference.

What independence is not

MythReality
“Independent CO means the FSP has no responsibility”The provider remains accountable for compliance arrangements and for ensuring reports are submitted
“Independent CO can ignore KI instructions on business strategy”The CO monitors legal compliance, not commercial ownership of the firm
“If the CO is independent, representatives need not keep records”Section 18 record duties still sit with the FSP; reps create the evidence trail

Duties in action — monitoring, written reports, recommendations

Written reports to the provider (Reg 5(3))

An approved CO (where required) must provide the provider with written reports on:

  • The course of compliance-monitoring duties; and
  • The progress achieved with those duties;

and must make recommendations on any aspect of the required compliance or monitoring functions.

For a representative, this is why file reviews, sample testing, and follow-up action plans appear in firm calendars. A CO recommendation to fix disclosure templates or supervision logs is part of the statutory monitoring loop — not optional “nice to have” consulting.

Reports to the Authority (section 17(4))

Section 17(4)(a): a compliance officer or, in the absence of such officer, the authorised FSP, must submit reports to the Authority in the manner and regarding the matters determined by the Authority for different categories of compliance officers.

Section 17(4)(b): the authorised FSP must ensure those reports are submitted.

High-level practical points used in industry guidance:

  • All authorised FSPs have compliance-reporting obligations — including sole-prop and dormant firms in the sense that a report is still required and dormancy is disclosed on the report.
  • Where a CO is appointed, the CO typically completes and submits the compliance report; a KI is still expected to review and sign the related declaration as the firm’s management attestation practice requires.
  • Where no CO is appointed (lawfully), the provider/KI submits the report.

Do not memorise outdated portal URLs or historic FSB email addresses for RE5. Know the legal duty and who submits.

Link to section 18 — records the CO needs

Section 18 requires an authorised FSP (except to the extent exempted) to maintain records for a minimum of five years regarding, among other themes:

  • Known premature cancellations of transactions or financial products by clients;
  • Complaints received and whether resolved;
  • Continued compliance with section 8 authorisation/fit themes as applicable;
  • Cases of non-compliance with the Act and the reasons; and
  • Continued compliance by representatives with section 13(1) and (2) requirements.

Why this appears in the CO chapter: monitoring without records is empty. Section 17 monitoring of the provider and representatives depends on the firm actually creating and keeping the evidence trail that section 18 (and the GCOC’s record-keeping duties) demand. Representatives who “work off the books,” delete emails, or refuse to complete advice records sabotage both the FSP’s statutory duties and the CO’s ability to monitor.

What representatives must know — cooperate, do not obstruct

RE5 expects you to know your practical duties toward the compliance function even though you are not the CO.

1. Provide access to records and information

When the CO (or KI running the compliance function) requests client files, call notes, disclosure packs, mandate documents, register details, or complaint correspondence, you must produce what the firm’s procedures require. Hiding incomplete files until “after the visit” is a non-compliance culture problem.

2. Do not obstruct monitoring

Obstruction includes delaying access without good reason, coaching clients to give false feedback, destroying drafts that form part of the advice record, or refusing to attend required compliance interviews. Section 17 assumes the CO can actually monitor “in accordance with the procedures” the provider must maintain.

3. Never give false, misleading, or incomplete material information to a CO

Section 36 of the FAIS Act makes it an offence, among other things, for a person who in the execution of duties imposed by the Act gives an appointed auditor or compliance officer information that is false, misleading, or conceals any material fact. That is not a soft internal rule — it is a criminal-offence pathway alongside other FAIS offences.

4. Understand that CO findings can escalate

CO findings may lead to internal remediation, KI management action, update of registers, debarment investigations where honesty/integrity is implicated, or regulatory reporting. Treating a monitoring finding as “HR noise” is a professional error.

5. Remember personal GCOC duties still apply

Even while a CO reviews your book, you remain bound by honesty, skill, care, diligence, and GCOC section 3(1)-type rules on accurate, plain, adequate, timeous client information. Compliance monitoring detects breaches; it does not authorise them in advance.

Auditor-style duties applied to COs (section 17(1)(c))

Section 17(1)(c) applies sections 19(4), (5) and (6) — the auditor irregularity-reporting and related provisions — with the necessary changes to a compliance officer. At RE5 level, take the policy message:

  • Material irregularities in the conduct or affairs of the FSP of which the CO becomes aware in performing the role are not something to bury quietly if the Act requires escalation pathways analogous to auditor duties;
  • Termination of appointment and Authority powers to require termination in defined circumstances form part of the integrity of the external assurance/monitoring architecture.

You are not examined as if you were an IRBA auditor. You are examined on the idea that COs have serious reporting responsibilities, not only internal coaching roles.

CO duties vs KI management — final boundary check

IssueCO contributionStill the KI/FSP’s job
Representative under supervision fails competence planMonitor, report, recommendManage the supervision arrangement and consequences
Disclosure template outdatedIdentify gap; recommend fixApprove new process; train staff; enforce use
Possible honesty breach by a repEscalate through monitoring/reporting channelsRun fair debarment process if grounds exist; notify Authority as required
Annual compliance reportComplete/submit where appointedEnsure submission; own management declarations; remediate findings

The CO is never a substitute for KI management responsibility. If the exam offers an option that says the CO “takes over management of financial services” or “holds the FSP licence,” reject it.

Worked scenarios

Scenario 1 — Unapproved “compliance person”
An FSP with twelve representatives asks a senior sales manager to “act as CO” without Authority approval because “she knows the products.”
Problem: Section 17 requires an approved compliance officer meeting CO criteria. Product knowledge alone does not equal section 17 approval.

Scenario 2 — File dump refused
During a monitoring review, a representative refuses to hand over records of advice, saying clients are “confidential from compliance.”
Problem: Confidentiality to third parties is not a licence to block the FSP’s own compliance function. Section 18 record themes and section 17 monitoring assume internal access. Refusal is obstruction.

Scenario 3 — Misleading the CO
A representative alters dates on disclosure documents after the CO requests a sample, then claims the originals always looked like that.
Problem: Providing false or misleading information to a CO engages the section 36 offence pathway and is a severe honesty/integrity event — debarment risk sits close behind.

Scenario 4 — Approval withdrawn
The Authority withdraws a CO’s approval for fit-and-proper failure. The FSP continues using that person as CO for six months “while we look for someone else.”
Problem: Once approval is withdrawn, that person is no longer an approved CO for section 17 purposes. The FSP must restore a lawful compliance arrangement promptly; section 17(4) reporting still must occur.

Scenario 5 — KI hides behind the CO
After a poor FSCA interaction, a KI says, “Compliance signed the report, so management has no further duty.”
Problem: Section 17(4)(b) requires the provider to ensure reports are submitted; KIs still manage and oversee the business. A CO report does not absorb KI accountability.

RE5 exam habits for this section

  1. Approval first — if the person is not approved, they are not the statutory CO.
  2. Two report directions — written reports to the FSP (Reg 5(3)) and prescribed reports to the Authority (section 17(4)).
  3. Independence = objective monitoring, not absence of an FSP.
  4. Rep cooperation — access, honesty, no obstruction; section 18 records fuel monitoring.
  5. Boundary — CO monitors and reports; KI manages; rep renders services lawfully.

With appointment triggers (3.1) and operating rules (3.2) in place, you can place the compliance officer correctly in every multi-role RE5 scenario — including licence-maintenance, GCOC, record-keeping, and debarment questions later in the guide.

Test Your Knowledge

Which statement correctly describes approval of a compliance officer under FAIS section 17(2)?

A
B
C
D
Test Your Knowledge

The Authority may withdraw a compliance officer’s approval if, among other grounds, the CO:

A
B
C
D
Test Your Knowledge

Under Regulation 5(3), an approved compliance officer (where required) must:

A
B
C
D
Test Your Knowledge

Which conduct by a representative is most consistent with lawful cooperation with the compliance function?

A
B
C
D