Compliance Function in Banks and the Chief Compliance Officer
Compliance used to be the department nobody wanted. It cleared circulars, chased branches for confirmations and got remembered only when an inspection went badly. Then in September 2020 the Reserve Bank of India put out a circular that changed the job description entirely - and made the chief compliance officer one of the most protected, and most exposed, roles in an Indian bank.
Compliance Functions & Chief Compliance Officer in Banks · Watch on YouTube
If you are writing the IIBF certificate course in compliance in banks, this circular is not background reading. It is the syllabus. Nearly every question on governance of the compliance function traces back to it, and the numbers in it are precise enough to be tested directly.
What the compliance function is supposed to do
The compliance function exists to make sure the bank obeys everything that binds it: statutes, RBI directions, internal codes of conduct, fair practice codes and the standards of the markets it operates in. It is not the audit function. Audit checks, after the fact, whether controls worked. Compliance sits ahead of that - identifying the obligation, translating it into a control, and testing whether the business is actually following it.
The standard framing is three lines of defence. The business unit owns its risk and is the first line. The compliance and risk functions form the second line, setting standards and independently testing them. Internal audit is the third, assuring the board that the first two are working. The moment the second line reports to the first, the model collapses - which is exactly what the independence requirements around the chief compliance officer are designed to prevent.

The 2020 circular, in numbers
The circular of 11 September 2020 on compliance functions in banks and the role of the chief compliance officer laid down hard, checkable criteria. These are the ones that come up in question papers.
| Requirement | RBI stipulation |
|---|---|
| Seniority | A senior executive, preferably in the rank of General Manager or equivalent - not below two levels from the CEO |
| Minimum fixed tenure | Not less than 3 years |
| Maximum age at appointment | Not more than 55 years |
| Overall experience | At least 15 years in banking or financial services |
| Specialist experience | Minimum 5 years in audit, finance, compliance, legal or risk management |
| Reporting | Direct line to the MD and CEO and/or the Board or Audit Committee of the Board |
| Dual hatting | Not permitted - no role carrying a conflict of interest, especially business roles |
Read the tenure clause carefully, because it is the one candidates misremember. Three years is a floor on how long the officer stays, not a ceiling. Its purpose is protection: someone who can be moved out in six months for raising an uncomfortable finding is not independent in any meaningful sense. Premature transfer or removal requires prior intimation to the Reserve Bank.
The circular also requires the audit committee to meet the officer separately, on a one-to-one basis, at least quarterly and without senior management present. That single provision does more for candour than any amount of policy drafting.
Why no dual hatting matters more than it sounds
In many mid-sized banks the same executive once handled compliance alongside operations, or compliance alongside a business vertical. The conflict is obvious once stated: the person judging whether a product breaches a regulation should not also be the person whose bonus depends on selling it. The prohibition on dual hatting closes that door.
It has a practical consequence too. Because the chief compliance officer cannot carry business targets, the role needs its own budget, its own staff and its own authority to access any record in the bank without asking permission from the unit being examined. Banks that treat the appointment as a title change rather than a structural change tend to get pulled up on exactly this point.
How the function runs day to day

A working compliance department maintains a live inventory of every obligation that applies to the bank, mapped to an owner and a control. New circulars are dissected within days and pushed to the affected verticals with a dated action point. High-risk areas - KYC and anti-money laundering, customer protection, interest rate and fee disclosures, related-party dealings, outsourcing - get tested on a defined cycle rather than on suspicion.
Findings go into a compliance risk assessment that ranks units by residual risk, and into a report that reaches the board committee at least quarterly. The board approves the compliance policy annually. None of this is optional decoration; each element is traceable to a specific expectation in the circular, and each is a fair target for a question.
For candidates, the honest advice is to study the framework the way a practitioner would. Read the actual circular on the RBI website once, end to end - it is short. Then attempt questions until the numbers are automatic. The certification mock tests cover this module in full, and the blog archive tracks fresh RBI circulars as they land. If compliance is part of a wider promotion plan, the CAIIB course and the study planner will help you slot it in without abandoning the main papers.
Whatever your reason for studying it, the shift is worth understanding on its own terms. A decade ago the compliance head was an internal record-keeper. Today the chief compliance officer is a board-facing officer with a protected tenure, a defined rank and a statutory relationship with the regulator - and that is a genuinely different job.
Frequently asked questions
What is the minimum tenure prescribed for a chief compliance officer?
Not less than three years. Removal or transfer before that period requires prior intimation to the Reserve Bank, which is what makes the tenure a protection rather than a formality.
What rank must the officer hold?
A senior executive, preferably General Manager or equivalent, and in no case below two levels from the CEO. The seniority requirement exists so that findings cannot simply be overruled.
Can the compliance head also handle a business portfolio?
No. RBI expressly bars dual hatting - any responsibility carrying a conflict of interest, particularly business roles, is not permitted alongside the compliance mandate.
How is compliance different from internal audit?
Compliance is the second line of defence and works ahead of the event, converting obligations into controls and testing them. Internal audit is the third line and independently assures the board that both the business and compliance are functioning.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.