How to Build and Scale a Compliance Team | Lithic
How to Build and Scale a Compliance Team
June 17, 2022
Matt Janiga
General Counsel and Compliance Officer
.png)
Reggie Young
Senior Product Counsel
Table of Contents
- Founder TL;DR
- Compliance in a nutshell
- The role of compliance in your organization
- The four pillars of a compliance function
- How to structure your compliance function by stage
- Hiring tips as you build your compliance team
- Using technology to cut down headcount
- Tips for founders and compliance leaders
In this guide, we provide guidance on how to build a compliance team from scratch, covering everything from staffing to responsibilities.
It also contains tips on how to scale your compliance organization across each company stage and tackles a few topics like the difference between compliance and legal, whether or not to give your general counsel the chief compliance officer title, and how to use technology to cut down headcount.
Founder TL;DR
- Fintech compliance teams tend to focus on anti-money laundering (AML), sanctions, and conduct. This means helping detect and report suspicious financial activity, avoiding business relationships with prohibited people and entities, and ensuring business and customers are compliant with various regulations.
- Your compliance program should be commensurate with your company’s risks and resources. Many consultants and compliance professionals want to go straight to the battleship of compliance functions, but that’s not practical or necessary for most fintechs.
- Don’t over-hire or hire too early. Compliance professionals are highly skilled and expensive, so you probably want to use tools and consultants before you hit product-market fit.
- At scale, your compliance organization will typically be structured around four key areas: compliance, risk, financial partnerships, and vendor management.
- Documentation is a skill, and not everyone has it. Keep that in mind as you build your compliance function and staff your teams.
- Square, PayPal, Stripe, and others spent millions building internal systems and staffing teams. Today you can build a similar setup using technology from Alloy, Hummingbird, and Persona.
Compliance in a nutshell
Compliance is a broad term that encompasses second-line teams in a company’s control function. It’s really critical to make them independent from the business units, and also give them the agency to correct errors and issues.
In fintech, compliance tends to focus on anti-money laundering (AML), sanctions, and conduct.
Legal vs. Compliance
Legal helps interpret guidance and navigate gray areas to figure out what the company needs to do. It also helps with contract negotiations, employment issues, and others.
Compliance focuses on implementing and running the day-to-day operations. This can include confirming customers aren’t on sanction watchlists or that they’ve provided the right KYC elements.
But there’s often overlap. Good compliance professionals often help do some of the legal work, especially at early companies.
The role of compliance in your organization
- Governance: setting the rules for what you focus on and how you operate. This includes documenting and updating the policies, procedures, and playbooks.
- Operations: building and running operations to honor the policies and procedures. This includes running queues for AML tasks like KYC escalations, sanction hits, transaction monitoring, and SAR/UAR filing.
- External Requests: sometimes driven when the bank wants more information to help fill in their compliance files or to check controls. More established fintech sponsors will also have monthly, quarterly, and annual oversight requests. You’ll need someone staffed to block and tackle these when you’re smaller and automate reporting over time to keep your headcount low.
This list of responsibilities can also expand based on your product and regulatory type.
The four pillars of a compliance function
At scale, your compliance organization will typically be structured around four key areas: compliance, risk, financial partnerships, and vendor management.
How to structure your compliance function by stage
Before product-market fit
At this stage, I probably wouldn’t over-invest in an in-house compliance function.
Your bank or infrastructure partners will often have a policy. Our bank sends us their updated policy once a year and we review it to see if we’re meeting their expectations.
Instead, tap a business person to read the policy and make sure your product blocks and tackles key requirements. If you get stuck, there are a bunch of great consultants that can help you identify policy requirements and design processes and operations to drive compliance forward.
Series A - B
After you find product-market fit, you should consider investing in compliance if you’ve built a good customer base, you’re scaling, and have raised a healthy round of financing. Your first compliance hires should depend on your existing team’s capabilities.
If you have seasoned founders or an in-house attorney who understands compliance needs, you can use your budget to bring in a mid-level manager who can take direction, manage analysts and help you scale.
Series C or later
One of the key things for this stage is to have your functional lines broken down. I lived through this at Stripe and now we’re in the middle of this at Lithic.
Hiring tips as you build your compliance team
Here are a few particular skills and considerations for you to think about as you’re hiring a compliance team.
First compliance hire
Your first compliance team member should be a policy person who can drive the “what” and “how” on AML, sanctions, and any other regulations you need.
- This person should have a good balance between enabling the business and keeping the organization safe. Ideally, this means having sufficient sales skills to get your partners comfortable with your program.
- They should also know not to sweat the small stuff. Early on, there will be a lot of missing parts and/or areas that need fixing so it’s important they don’t get concerned over every little thing.
Operations leader
Unicorn hires will have both substantive knowledge and key operational experience.
Compliance team members
- Banks will want you to share data and sample various queues and process results to prove your system is working. A junior person can be trained to manage these lower-level tasks.
- Your junior folks will also need to review KYC and sanctions queues, and eventually do AML monitoring for suspicious transactions and SAR filings.
General Counsel vs. Chief Compliance Officer (or both)
Other good considerations:
- Reporting lines and how many direct reports go to your CEO/COO
- Whether your General Counsel can be a good mentor/manager for the CCO
Using technology to cut down headcount
Square, PayPal, Stripe, and others spent millions building internal systems and staffing teams. You can build a similar setup using technology from Alloy, Hummingbird, and Persona.
There’s a handful of things you should weigh when considering a technology vendor:
- How easy is it to integrate with the vendor? Six to twelve months is too long.
- How do the vendor’s features fit your business needs?
- Can they scale?
- How much do they cost?
Tips for founders and compliance leaders
- Don’t let compliance be a dumping ground for things that don’t have a home.
- Don’t over-hire or hire too early.
- When you need to give away a title, start small.
- Don’t just give your compliance officer title to your in-house counsel.