Compliance is the system through which an organisation identifies the obligations that apply, translates them into procedures, checks that they are followed, and preserves evidence. The rules depend on who is acting, what activity is performed, which product and client are involved, and in which jurisdiction.
In plain terms — First identify the rule, then build a control, and finally retain evidence that the control worked.
Three levels that should not be confused
Legal and regulatory obligations. These may concern authorisation, organisation, conflicts, communications, suitability or appropriateness, records, client asset protection, market integrity, and resilience. They are not identical for every firm or client.
Contractual duties and internal controls. Contracts, policies, and procedures determine who approves an activity, which exceptions are allowed, which data is retained, and how a problem is handled. They must remain consistent with the higher-level rules that apply.
A trader's personal discipline. Following a playbook, risk limit, or journal matters, but it does not turn private rules into “regulatory compliance”. Operational documentation and personal audit address this layer.
The control cycle
Scope
Identify the entity, role, activity, instruments, clients, and countries involved. A European rule for an investment firm should not automatically be applied to every trader or service worldwide.
Rule
Use the current legal text and guidance from the competent authority. A summary can provide orientation, but the current authentic text prevails.
Procedure and control
Assign responsibility and design an observable control: approval, blocking, reconciliation, sampling, surveillance, or review. A document without execution is not evidence of compliance.
Evidence and exception
Retain the rule version, inputs, outcome, owner, date, and any exception. The evidence makes it possible to reconstruct what happened and correct the process.
Review
Update the system for regulatory change, new products, incidents, complaints, and control results. Compliance is not a one-off certification.
Example: communications to clients
Within the European Union, MiFID II requires investment firms to act honestly, fairly, and professionally in accordance with the best interests of their clients, and requires information to be fair, clear, and not misleading. A control does not stop at the sentence “returns are not guaranteed”: it checks the audience, product, risks, costs, conflicts, and channel in the version that was actually published.
This example describes a principle for firms within the MiFID II perimeter; it does not assign the same obligation to every author, trader, or platform. To assess an intermediary as a user, follow the due diligence process.
Common mistake — Calling every personal trading rule “compliance”, or copying a checklist from another jurisdiction without checking the entity, service, and date.
Professional reading
A mature programme maps every obligation to a risk, control, owner, frequency, and item of evidence. It also measures effectiveness: a completed control may still fail to detect the risk it was designed to address. Conflicts, continuity, outsourcing, systems security, and client asset protection require clear ownership throughout the operating chain.
Sources
- ESMA — MiFID II, Article 16: organisational requirements — policies, conflicts, continuity, records, and safeguarding of client assets.
- ESMA — MiFID II, Article 24: general principles and information to clients — clients' best interests and fair, clear, and not misleading communications.
- ESMA — MiFID II, Article 25: suitability and appropriateness — assessments linked to the service and client.
- ESMA — MiCA, Article 14 — conduct, conflicts, and systems obligations for offerors within its perimeter.
- IOSCO — Objectives and Principles of Securities Regulation — investor protection, fair and efficient markets, and reduction of systemic risk.
- EUR-Lex — Regulation (EU) 2022/2554, DORA — digital operational resilience for financial entities within its scope.
This page is educational and does not determine the obligations in a specific case. Current law, the relevant jurisdiction, and the competent authority prevail.