Risk & compliance
What a compliance job actually involves
How compliance is organised, the difference between advisory, monitoring and regulatory-change work, and what makes someone good at it.
The short answer: Compliance is three distinct jobs sharing a department name. Advisory compliance answers questions from the business before something happens and is fast, conversational and judgement-based. Monitoring and testing checks after the fact whether what should have happened did, and is methodical, evidence-driven and closest in shape to audit. Regulatory change reads what is coming, works out what it means for the firm, and drives the implementation — the most strategic of the three and the hardest to enter without experience. Most people are much better suited to one than the others, and the label on the job posting frequently does not say which one it is.
Key points
- Advisory, monitoring and regulatory change are different jobs with different temperaments, all posted as "compliance".
- Advisory work is judgement under time pressure with incomplete information; monitoring is evidence and method.
- The valuable skill across all three is translating a rule into what someone must actually do differently on Monday.
- Financial crime compliance is usually a separate function and the largest single entry route — see the AML topic.
Three jobs, one department name
The three compliance disciplines| Discipline | When it acts | Suits someone who |
|---|
| Advisory | Before — the business asks, you answer | Decides quickly with incomplete information and is comfortable being wrong occasionally |
| Monitoring and testing | After — you check what happened | Is methodical, evidence-driven, and untroubled by delivering unwelcome findings |
| Regulatory change | Ahead — you read what is coming | Reads closely, thinks in programmes, and can drive work across functions |
The temperaments genuinely differ. Someone who needs to be certain before answering finds advisory work uncomfortable, because the business needs an answer this afternoon and the perfect one arrives on Friday. Someone who prefers momentum finds monitoring slow. Neither is a deficiency, but a mismatch makes for a long two years.
The skill that carries all three
Rules are written to be precise and complete. Nobody in the business has time to read one, and if they did they would still need to know what to do differently. The core compliance skill is closing that gap: turning an obligation into a specific instruction that a person with a deadline can act on.
The same obligation, at three levels of usefulness
- The rule, restated
- The firm must ensure adequate records are maintained of client communications.
- A better version
- Client conversations that affect an order need to be recorded and kept.
- The useful version
- If a client changes an instruction by phone, log it in the system before you act on it — same call, not end of day.
All three are accurate. Only the third one changes what anybody does, and producing the third consistently is what distinguishes a compliance professional from a person who has read the handbook.
Routes in
- Financial crime. The largest entry route by volume in most large banks, and a genuine foundation — the frameworks and escalation habits transfer directly. See what an AML analyst does.
- From the business. Someone who has worked in operations, onboarding or a product area brings knowledge of how the process actually runs, which is scarce and valued in monitoring and advisory work alike.
- Monitoring and testing. Often the most accessible of the three directly, because the work is methodical and can be learned on structured cases with supervision.
- Graduate programmes. Several large banks run risk-and-compliance streams that rotate across the disciplines, which solves the choosing problem — see graduate programmes.
One further thing to establish before accepting a compliance role is how the function is positioned internally, because it varies enormously between firms and it determines what the job feels like day to day. In some organisations compliance is consulted early and its view carries weight; in others it is asked to sign off on decisions already taken, which is a materially worse job with the same title.
It is a difficult thing to ask about directly, and there are two questions that get at it obliquely. "At what point in a product decision does compliance usually get involved?" — early is a good sign, at approval is not. And "when was the last time compliance changed the shape of something?" A team that cannot produce an example has an answer, whether or not anyone says it.
Frequently asked questions
Is compliance a good long-term career?
It has been a structurally growing function for years and it is unusually portable — the framework skills transfer between firms and between sectors, which is not true of most banking specialisms. The honest counterweight is that it is a cost function, which shapes how it is resourced in a downturn, and that some roles become narrow if you stay in one process too long.
What is the difference between compliance and internal audit?
Compliance is second line: it sets policy, advises the business and monitors adherence, and it is accountable for the framework working. Internal audit is third line: it independently assures both the business and compliance, and reports to the audit committee rather than to management. Auditors examine whether compliance is doing its job, which is why the two are deliberately separate.
Do I need a law degree?
No, and most compliance professionals do not have one. It helps in regulatory change and in interpretation-heavy roles. What matters more broadly is the ability to read a rule, work out what it requires in practice, and explain that to someone who has a deadline and no interest in the rule — a skill that is closer to translation than to law.
Published 2026-08-01 · Updated 2026-08-01