3.1 Role & Function of the Compliance Officer

Key Takeaways

  • FAIS section 17(1)(a) requires an authorised FSP with more than one key individual or one or more representatives to appoint one or more compliance officers to oversee the compliance function, monitor FAIS compliance, and liaise with the Authority.
  • A sole proprietor (or other FSP) with only one approved key individual and no representatives is generally not required to appoint a CO, but must still establish compliance procedures and submit compliance reports.
  • Regulation 5 requires every FSP to have a compliance function inside its risk-management framework, exercised with diligence, care and reasonable competence.
  • The CO monitors compliance with the FAIS Act and codes such as the GCOC (including specific provider duties under GCOC section 3(1)); the CO does not replace the key individual’s management responsibility.
  • Representatives do not “report to” the CO as their line manager for sales targets — they must still understand the CO’s monitoring role because their files, disclosures and conduct are the subject of that monitoring.
Last updated: August 2026

3.1 Role & Function of the Compliance Officer

Quick Answer: Under FAIS section 17, an authorised FSP with more than one key individual or one or more representatives must appoint one or more compliance officers (COs) to oversee the provider’s compliance function, monitor compliance with the Act by the provider and those representatives, and take responsibility for liaison with the Authority. A sole proprietor (or similar) with one KI and no representatives generally need not appoint a CO — but still must run a compliance function and submit reports. The CO monitors; key individuals manage.

Why Task 1 QC4 matters for representatives

RE5 is the representatives’ exam, so you might ask why you need a whole chapter on compliance officers. The answer is practical: almost every multi-person FSP you will work for has (or must have) an approved CO. That person’s monitoring work looks at your advice files, disclosures, register details, supervision status, and complaints. Incomplete records, obstructed monitoring, or treating the CO as optional create firm-level and personal risk.

Chapter 1 introduced the CO as a role-player. This section deepens role and function under section 17, Regulation 5, and the link to the General Code of Conduct (GCOC) — especially the everyday duties providers and representatives must meet when rendering financial services (GCOC section 3(1) and related provisions).

Statutory starting point — FAIS section 17(1)(a)

Section 17 is titled “Compliance officers and compliance arrangements.” The core appointment rule in section 17(1)(a) can be stated as follows:

Any authorised financial services provider with more than one key individual or one or more representatives must, subject to the Act’s regulation-making powers and the approval rules, appoint one or more compliance officers to:

  1. Oversee the provider’s compliance function;
  2. Monitor compliance with this Act by the provider and such representative(s), particularly in line with the compliance procedures the provider must maintain; and
  3. Take responsibility for liaison with the registrar/Authority.

Two reading points matter for exam accuracy:

  • The trigger is disjunctive — more than one KI or any representatives. You do not need both conditions at once.
  • The CO’s monitoring target is the Act (which includes subordinate instruments that form part of “this Act” in FAIS language — codes of conduct, regulations, determinations as applicable). In practice that means FAIS licensing/conduct rules and the GCOC duties that shape client-facing work.

Fit and proper for the CO (high level)

Section 17(1)(b) requires the compliance officer to comply with fit and proper requirements. Section 17(1)(bA) applies the ongoing fit-and-proper continuation duties of section 8A with the necessary changes. In plain language: a CO is not a casual admin title; the person must meet honesty/integrity and competence standards determined for compliance officers and keep meeting them.

When a CO is required — and the sole-proprietor style exception

Training materials and regulator guidance commonly illustrate the rule with simple firm structures. Use the following high-level map for RE5 (always apply the statutory wording if a question quotes it):

FSP structureCO appointment generally required?
Sole proprietor; one approved KI; no representativesNo
Sole proprietor with one or more representativesYes
Close corporation / company with one KI and no representativesNo
Close corporation / company with one KI and one or more representativesYes
Company with two or more approved KIs (even with no representatives)Yes
Any FSP with both multiple KIs and representativesYes

Why the “no CO required” cases still matter

Section 17(5) is critical exam material: the duties to establish and maintain compliance procedures (section 17(3)) and to submit compliance reports (section 17(4)) apply with the necessary changes even to an authorised FSP that carries on business with only one key individual or without any representative.

So a sole-prop-style FSP that is not forced to appoint a CO is not free of compliance arrangements. In those cases:

  • The key individual / provider remains responsible for ensuring compliance with the Act and subordinate legislation;
  • The KI typically establishes the compliance function and completes and submits the annual compliance report to the Authority;
  • The FSP may still choose to appoint an approved CO voluntarily to assist.

Exam trap: “No CO required” does not mean “no compliance function, no procedures, no report.”

What the compliance function is (Regulation 5)

The FAIS Regulations (made under section 35) contain Regulation 5 on establishment of the compliance function. High-level content of Reg 5:

  1. Reg 5(1) — Subject to the Act, an authorised FSP must ensure that a compliance function exists or is established as part of the risk management framework of the business, supervised by an approved compliance officer (where required), or otherwise managed under the control and responsibility of the provider alone.
  2. Reg 5(2) — The compliance function must be exercised with such diligence, care and degree of competency as may reasonably be expected of a person responsible for that function.
  3. Reg 5(3) — An approved CO (where required) must give the provider written reports on the course of and progress with compliance-monitoring duties, and make recommendations on any aspect of the required compliance or monitoring functions.

Together, section 17 and Reg 5 create a two-layer picture:

LayerWho owns itEssence
Compliance functionThe FSP (always)Procedures and risk-framework arrangements so FAIS duties are met
Compliance officerAppointed & approved person (when required)Oversees the function, monitors, reports, liaises

Core functions of the CO — support, monitor, report, liaise

Industry teaching often groups CO work into practical themes. Map those themes back to the statute so you do not invent extra duties on the exam:

1. Oversee the compliance function

The CO does not invent the business strategy. The CO helps ensure the firm has workable procedures (section 17(3)) so the provider and representatives can comply with the Act in day-to-day rendering of financial services.

2. Monitor compliance with FAIS and the GCOC

Monitoring is the heart of the role. Typical monitoring themes that affect representatives include:

  • Whether advice and intermediary services stay inside the FSP’s licence categories/subcategories and the rep’s appointment scope;
  • Whether disclosures, suitability steps, records of advice, and conflict management match the GCOC;
  • Whether GCOC section 3(1)-type specific duties are met when a financial service is rendered — for example that representations and information given to clients are factually correct, in plain language, adequate and appropriate, and given timeously so the client can make an informed decision (alongside the Code’s related duties on conflicts, disclosures and fair treatment);
  • Whether register, supervision, and competence arrangements for representatives are accurate;
  • Whether complaints and record-keeping themes (including section 18 record categories discussed in the next section) are being handled lawfully.

3. Report to FSP management

Reg 5(3) requires written reports to the provider on monitoring progress and recommendations. A CO finding is not merely a polite suggestion: it is a formal compliance signal that KIs and the provider must take seriously in managing the business.

4. Report to / liaise with the Authority

Section 17(1)(a) assigns liaison with the registrar/Authority to the CO. Section 17(4) requires the CO (or, if there is no CO, the provider) to submit reports to the Authority in the manner and on the matters determined for different categories. The FSP must ensure those reports are in fact submitted (section 17(4)(b)).

5. Support competence culture (practical)

While the Act’s text emphasises monitoring, liaison and procedures, good practice CO work often includes training support and gap analysis. For RE5, do not claim the CO “replaces CPD” or “signs off product advice for every client.” Competence and advice quality remain KI oversight and representative personal duties.

CO vs key individual vs representative — keep the roles separate

RolePrimary legal job
Key individualManage and oversee the rendering of financial services for the FSP
Compliance officerOversee compliance function; monitor FAIS compliance; report and liaise
RepresentativeRender advice and/or intermediary services on behalf of the FSP within appointment scope
FSP (provider)Holds the licence; accountable for systems, many firm duties, and services rendered by its reps

Hard boundary for RE5

The CO is not a substitute for KI management responsibility. If a KI fails to oversee product limits, supervision of junior reps, or fair treatment systems, “we have a CO” is not a defence. Conversely, a CO finding that disclosures are incomplete does not erase the representative’s personal duty to act honestly and with due skill, care and diligence.

Internal vs external compliance officers (high level)

Where a CO is required, the FSP may typically appoint:

  • An internal (in-house) CO employed by that FSP; or
  • An external (outsourced) CO / compliance practice approved to render compliance services for FSPs.

Either route still requires Authority approval of the officer for the role (detail in section 3.2). Approval and independence rules exist so monitoring is meaningful, not captured by sales pressure.

Worked scenarios

Scenario 1 — Sole prop without reps
Thandi is a sole-proprietor Category I FSP, the only KI, with no representatives. She tells a client she need not worry about compliance because “section 17 does not apply to me.”
Correction: She may not be required to appoint a CO, but section 17(5) still requires procedures and reporting. She remains fully bound by the GCOC when she renders services.

Scenario 2 — First representative hired
A one-KI company appoints its first representative.
Effect: The “one or more representatives” trigger in section 17(1)(a) is met. The FSP must appoint an approved CO (unless a specific legal exception applies under the Act’s regulation framework — do not invent exemptions on the exam).

Scenario 3 — Rep assumes CO “approved” the product
A representative tells a client the CO “approved this product for you.”
Correction: Product suitability and advice quality are advice-process / KI oversight issues. The CO monitors systems and compliance; the CO does not replace the advice process or become the client’s adviser.

Scenario 4 — Ignoring GCOC because “compliance will catch it later”
A rep rushes oral product claims that are not factually correct, planning to “fix the file if compliance asks.”
Correction: GCOC section 3(1)-type duties apply when the service is rendered. Monitoring may detect the failure later, but the duty was already breached — and false information to a CO is a separate serious problem (section 3.2).

How this section connects to the rest of RE5

  • Task 2 (licence maintenance) — compliance arrangements and reports form part of how the FSP keeps its house in order.
  • Task 3 (key individuals) — KIs manage; COs monitor; do not merge the roles.
  • Task 4 (GCOC) — CO monitoring often tests the same disclosure, conflict, and fair-treatment duties you study as a rep.
  • Task 5 (records) — section 18 records are raw material for monitoring (next section).
  • Task 8 (representatives) — your register status, supervision, and conduct are CO monitoring subjects.

Exam focus checklist

  • Quote the appointment trigger accurately: more than one KI or one or more representatives.
  • Name the three headline CO jobs: oversee compliance function, monitor, liaise/report.
  • Know that no-CO FSPs still need procedures + reports (section 17(5)).
  • Keep KI management ≠ CO monitoring.
  • Connect monitoring to GCOC client-facing duties, not only to “licence paperwork.”
Test Your Knowledge

Under FAIS section 17(1)(a), which FSP must appoint one or more compliance officers?

A
B
C
D
Test Your Knowledge

A sole-proprietor FSP has one approved key individual and no representatives. Which statement is most accurate?

A
B
C
D
Test Your Knowledge

Which statement best captures the high-level function of a compliance officer under FAIS?

A
B
C
D
Test Your Knowledge

Regulation 5 of the FAIS Regulations primarily requires that:

A
B
C
D