Compliance Monitoring Program & Assessment in 2026

Compliance Monitoring Program and Assessment in 2026

Compliance Monitoring Program & Assessment in 2026

An effective Compliance Monitoring Program (CMP) is essential for every investment firm seeking to meet national and European regulatory expectations. More than a compliance requirement, the CMP provides continuous oversight of the firm’s operations and helps identify weaknesses before they develop into significant regulatory concerns. 

Its effectiveness relies on a well-structured Compliance Risk Assessment (CRA), which identifies the firm’s key compliance risks and helps prioritize monitoring activities. Together, the CRA and CMP support the identification, assessment, monitoring, and mitigation of compliance risks across the firm. 

In this article, the SALVUS Regulatory Compliance team explores the key components of an effective Compliance Monitoring Program (CMP) and how firms can implement a robust monitoring framework. 

1. What is Compliance Monitoring & Assessment?
2. Purpose and Objectives of the Compliance Risk Assessment
3. What does the Compliance and Risk Management Function do?
4. CySEC Circular C553 – Organisational Requirements of the Compliance Function
5. Departmental Inspection Areas
6. CySEC Circular C441 – CySEC Desk-based review

We regularly share bite-sized insights on LinkedIn such as those found in this article

1. What is Compliance Monitoring & Assessment? 

Compliance monitoring is a structured process that helps regulated firms maintain compliance with legal and regulatory obligations. It includes assessing compliance risks, implementing a Compliance Monitoring Program (CMP), and conducting periodic reviews to identify potential breaches. 

The Compliance Function (CF) operates independently, reports its findings to senior management, and provides ongoing guidance and annual reporting. This supports transparency, accountability, and a strong compliance culture within the firm. 

2. Purpose and Objectives of the Compliance Risk Assessment (CRA)

The purpose of the Compliance Risk Assessment (CRA) is to support the effective allocation of Compliance Function resources and ensure that compliance risks across the firm are systematically identified, assessed, prioritised, and monitored. 

The CRA evaluates compliance risk by taking into account: 

  • the firm’s obligations under the applicable legal and regulatory framework; 
  • the policies and procedures in place; 
  • the systems and controls applied within the investment services activities; 
  • the outcomes of compliance monitoring activities; and 
  • the findings arising from internal and external audits. 

A well-documented CRA enables the Compliance Function to develop a proportionate and risk-based Compliance Monitoring Programme (CMP), including the appropriate nature, frequency, and scope of monitoring activities. 

3. What does the Compliance and Risk Management Function do?

Within an investment firm’s governance structure, the Compliance and Risk Management Functions form part of the second line of defence. 

The Compliance Function, headed by the designated Compliance Officer and supported by relevant personnel where appropriate, plays an important role in maintaining the firm’s regulatory compliance and governance standards. In this capacity, the Compliance Function serves as a key regulatory safeguard and is actively involved in: 

  • The development and review of policies and procedures relating to investment and ancillary services  
  • Providing compliance expertise and advice on strategic decisions, new business models, and marketing strategies  
  • Participating in organisational changes, new product approvals, and remuneration policy discussions   
  • Being involved in product approval processes for manufacturers and distributors  
  • Handling material and non-material correspondence with CySEC and other competent authorities 

To fulfil its obligations, the Compliance Function implements a risk-based monitoring program that includes: 

  • Reviewing internal policies and procedures,  
  • Performing onsite inspections of operational departments,  
  • Carrying out monitoring activities at appropriate intervals,  
  • Reporting findings to the Board of Directors via the Annual Compliance Report. 

4. CySEC Circular C553 – Organisational Requirements of the Compliance Function

Circular C533 provides guidance to investment firms on implementing the requirements of the Compliance Function, including: 

Guidelines 1–4: Responsibilities of the Compliance Function 

  • Compliance Risk Assessment – Identify and assess regulatory risks to determine monitoring priorities.  
  • Monitoring Obligations – Establish a risk-based monitoring programme to ensure compliance with legal and internal requirements.  
  • Reporting Obligations – Prepare an annual compliance report for the Board of Directors covering relevant business areas.  
  • Advisory and Assistance – Support management and staff through training, policy development, and regulatory guidance. 

Guidelines 5–11: Organisational Requirements

  • Effectiveness – The function must operate effectively and fulfil its responsibilities.  
  • Skills and Authority – Compliance staff must have sufficient expertise, knowledge, and authority.  
  • Permanence – The Compliance Function must be a permanent part of the firm.  
  • Independence – It must operate independently and avoid conflicts of interest.  
  • Proportionality – Resources should reflect the firm’s size, complexity, and risk profile.  
  • Combination with Other Functions – Appropriate safeguards must preserve independence and effectiveness.  
  • Outsourcing – Outsourced activities must meet regulatory requirements without reducing the firm’s responsibility.  

Guideline 12: Competent Authority Review

  • CySEC Review – CySEC assesses the structure, resources, reporting lines, and effectiveness of the Compliance Function during licensing and ongoing supervision. 

5. Departmental Inspection Areas

A well-structured CMP should include periodic reviews of all operational departments. The scope of these reviews depends on the firm’s business model and risk profile, although certain areas remain a key supervisory focus. 

Departmental inspections typically cover Back Office, AML/CFT, Accounting and Finance, Provision of Services, Business Development and Marketing, Customer Support, and IT. The Compliance Function reviews whether internal policies and procedures are properly applied and whether employees comply with regulatory requirements in their daily activities. 

Key areas of review generally include the accuracy and timely submission of information through the CySEC portal, notification of changes in key personnel, organisational effectiveness, staff training, conflicts of interest, complaints handling, and the implementation of the Compliance Risk Assessment. 

Attention is also given to governance arrangements, including oversight by Senior Management and the Board of Directors, as well as coordination between Compliance, Risk Management, and Internal Audit. 

Regular departmental inspections help firms identify weaknesses, address deficiencies promptly, and strengthen the overall control framework. 

6. CySEC Circular C441 – CySEC Desk-based review

CySEC Circular C441 introduced desk-based reviews, allowing CySEC to carry out thematic and targeted assessments using information and documentation submitted by regulated entities. 

These reviews generally focus on specific regulatory areas and aim to identify common weaknesses in firms’ compliance frameworks. Key areas include the Compliance Monitoring Program, Compliance Risk Assessment, governance arrangements, conflicts of interest, and client protection. 

Circular C441 identified recurring deficiencies such as insufficiently documented risk assessments, weak monitoring methodologies, ineffective reporting lines, and delays in implementing corrective actions. It also highlighted good practices, encouraging firms to adopt more structured, risk-based, and properly documented compliance processes. 

Firms should consider the findings of CySEC’s desk-based reviews when developing and improving their Compliance Monitoring Program, helping them address supervisory expectations and reduce potential findings during inspections. 

In this context, SALVUS Funds, in cooperation with the Institute for Professional Excellence (IforPE), developed the self-study CPD course “Compliance Monitoring Program & Assessment in 2026.” The course covers the main features, inspection areas, and methodology of the CMP, while providing practical compliance guidance based on Circulars C441 and C553. 

The online course provides 5 Continuous Professional Development (CPD) units toward the annual requirements for CySEC Basic and Advanced certification holders. 

Contact us at compliance@salvusfunds.com if you need support with your Compliance Monitoring Program, Compliance Risk Assessment, or other CySEC compliance obligations, or if you would like to learn more about relevant CPD training with IforPE. 

#StayAhead

The information provided in this article is for general information purposes only. You should always seek professional advice suitable to your needs.

Share this post