Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Does Your Compliance Officer Report to Legal?Regulatory Obligations Management
5 min readFor Compliance Officers

Does Your Compliance Officer Report to Legal?

The U.S. Department of Health and Human Services' Office of the Inspector General (OIG) has made a clear statement: compliance officers shouldn't report to legal or finance. They should report directly to the CEO or board, focusing solely on compliance.

This directive isn't hidden away. It's prominently featured on page 39 of their healthcare compliance guidelines.

For compliance officers in any sector, this presents both an opportunity and a challenge. You now have regulatory support for independence, but you might face resistance from executives who currently oversee your work.

Assessing Your Compliance Function

Use this checklist to evaluate whether your compliance function meets the independence standard set by the OIG and to identify necessary organizational changes. While OIG's guidelines target healthcare, the principle of independence is relevant across all sectors where compliance officers must deliver uncomfortable truths without fear of retaliation.

Preparation

Before using this checklist, ensure you have:

  • A current organizational chart showing where compliance reports today
  • A job description for your compliance officer role
  • Access to board or audit committee calendars to verify direct reporting relationships
  • A list of all functions the compliance officer currently manages or supervises

Independence Assessment Checklist

Reporting Structure

1. The compliance officer reports directly to the CEO or board of directors

This means not reporting to the general counsel, CFO, or other C-suite executives. "Reports to" implies that performance reviews, compensation decisions, and strategic priorities are managed through this relationship.

What good looks like: The compliance officer has a regular agenda slot at board meetings and submits reports directly to the audit committee without legal department review.

2. The compliance officer does not lead or report to the legal function

This means no dual roles like deputy general counsel, no dotted-line reporting to legal, and no requirement for compliance findings to go through legal before reaching the board.

What good looks like: When the compliance officer identifies a control deficiency, they can report it directly to stakeholders without waiting for legal's approval.

3. The compliance officer does not lead or report to the finance function

The compliance officer shouldn't report to the CFO or manage functions like internal audit or financial reporting.

What good looks like: The compliance officer can escalate financial control issues without those concerns being filtered through the finance department.

4. The compliance officer does not provide legal or financial advice

Compliance interprets regulatory obligations and assesses control effectiveness. Legal handles contracts and litigation, while finance manages the books.

What good looks like: When asked about contract terms, the compliance officer directs inquiries to legal. For questions about bribery risk under the Foreign Corrupt Practices Act, the compliance officer responds directly.

5. The compliance officer does not supervise anyone who provides legal or financial advice

Independence is compromised if you manage those whose work you're supposed to oversee. This includes not managing in-house counsel, paralegals, accountants, or financial analysts.

What good looks like: The compliance team includes risk analysts and compliance coordinators. Legal and finance are separate departments with their own leadership.

Operational Independence

6. Compliance is the officer's sole responsibility

Avoid split roles like "VP of Legal and Compliance." OIG recommends that the compliance officer focus exclusively on compliance whenever possible.

What good looks like: The compliance officer's job description lists compliance program management as the primary duty, without responsibility for legal strategy or other functions.

7. The compliance officer is not responsible for operational functions they must oversee

In healthcare, OIG specifically mentions billing and contracting. In other sectors, this extends to sales operations, procurement, or HR administration.

What good looks like: The compliance officer reviews sales compensation plans for risks but doesn't design or administer them. Operations owns the process; compliance owns the oversight.

8. The compliance officer has unrestricted access to all personnel and records

Independence requires information access. If the compliance officer needs permission to review records or interview employees, they're not truly independent.

What good looks like: The compliance officer can request transaction details, interview employees, and review board materials without needing approval from legal or HR.

Common Mistakes

Treating independence as a reporting-line exercise only. You can report to the CEO and still lack independence if the general counsel controls your budget or performance reviews.

Assuming the GC will embrace the change. Some general counsels support compliance officer independence, while others may see it as a loss of control. Don't assume your current relationship with legal means they'll support your push for independence.

Confusing independence with isolation. Independence doesn't mean working in a silo. You still collaborate with legal on regulatory interpretation and with finance on control testing. You just don't report to them.

Ignoring the board's appetite for change. OIG's guidelines are voluntary. Your board might not see the value in restructuring if they believe the current setup works. Build a business case before demanding changes.

Next Steps

If you're a compliance officer seeking greater independence:

Document the current state. Map where compliance sits today, who you report to, what non-compliance functions you manage, and where your access is restricted. Compare these against the checklist.

Build the business case. Lead with how independence improves risk detection and strengthens board oversight. Use OIG as regulatory validation.

Negotiate the transition. If you report to the general counsel, propose a phased approach: direct board reporting first, then separation of duties, then full operational independence.

Define the new relationship with legal. Clarify who handles regulatory inquiries and manages government investigations. Ensure mutual support when delivering bad news to leadership.

If you're a board member or CEO, ask your compliance officer to complete this checklist. Then consider whether your current structure allows them to share insights that might not align with what your general counsel or CFO prefers.

That's what independence is for.

Promotional banner for the Pentest Readiness checklist download

You Might Also Like