Rules and scope
A maintained obligations map connects sources of law with products, countries, customers and process owners. A new service or rule change triggers a fresh applicability review.
A compliance function helps a regulated firm meet its obligations in day-to-day business. It identifies risks, advises management and checks whether procedures and controls actually work.
Management is responsible for sound organisation. Compliance promotes effective procedures and controls, identifies material regulatory risks and advises management. It needs a clear mandate, resources, information access and a direct reporting line. Its design follows the firm’s risk profile.
A maintained obligations map connects sources of law with products, countries, customers and process owners. A new service or rule change triggers a fresh applicability review.
Compliance must be involved before product and process launches while remaining free from sales conflicts. Securities services are also subject to the specific MaComp requirements.
A compliance risk assessment connects obligations with real workflows: what may fail, how severe is the impact, what controls exist, and what gap remains? A documented, risk-based monitoring programme follows from that assessment.
Examples include customer disclosures, suitability, target markets, conflicts, advertising, complaints, outsourcing and records. Control frequency and depth reflect the risk.
Samples, system rules, exceptions and complaints provide evidence. Findings need an owner, deadline, action and effectiveness review.
The function reviews new products, agreements, digital customer journeys and major process changes before launch. It translates requirements into instructions and relevant training. Repeated breaches and serious deficiencies need management decisions.
A CFD onboarding journey may raise questions about appropriateness, risk warnings, target-market restrictions and records. Compliance examines the control logic using real cases.
Reports should show risk trends, findings, causes and open actions. Banking MaRisk requires at least annual and event-driven management reports, also passed to internal audit.
Business owners run their processes and controls. Compliance monitors and advises within its remit; internal audit independently assesses the effectiveness of compliance too. Outsourcing tasks does not transfer management responsibility.
Mandate, obligations map, risk assessment, monitoring plan, samples, advice records, training, reports and action log.
A plan without testing, late involvement in product launches, reports without decisions or overdue actions point to a gap between policy and operations.
Duties depend on firm type and activity. MaComp, banking MaRisk and WpI MaRisk have different addressees; this overview does not replace an applicability assessment.
Did you know?
How an app can become an activity that requires permission.
Have you explored?
Prepare management profiles and collective suitability reviews.
International market entry / Germany
Considering a local office, a branch or a standalone authorisation in Germany? The appropriate route depends on your home jurisdiction, activities and operating model. 3RMCN combines experience from complex supervisory projects with product, technology and delivery expertise: from entry strategy and key interfaces through to operational readiness.
Discuss your plans ↗Supervisory perspectives
Experience in the context of CySEC (Cyprus), MFSA (Malta), FCA (United Kingdom), the European ESMA framework and MAS (Singapore). ESMA is not a national licensing authority.
International structuring
For incorporation in offshore jurisdictions, relevant specialists from the network can be involved. Jurisdiction, activities and regulatory obligations need to be considered for each project.