Skip to content
RiskTemplates · The Daily Brief Friday, August 28, 2026
Wire SEC False Form ADV Cases: 38 Fake Advisers Turned a Public Filing Into a Trust Signal AUG 27

Feature Compliance Strategy

CCO Personal Liability in 2026: What the SEC and FINRA Are Now Charging Compliance Officers With

SEC and FINRA enforcement against individual compliance officers is accelerating in 2025–2026. Here's what the three-part personal liability test actually means, what recent cases look like, and how to build a compliance function that protects the institution and the person running it.

By Rebecca Leung · August 28, 2026 ·
Table of Contents

TL;DR

  • The SEC charged multiple CCOs personally in 2025, including for falsifying compliance records, inadequate supervision, and failing to maintain adequate compliance policies
  • FINRA settled two enforcement actions against CCOs in 2026, both tied to dually-hatted compliance officers who held supervisory responsibilities
  • The SEC’s three-part personal liability test — affirmative misconduct, obstruction, or wholesale failure — creates real exposure for CCOs who don’t document escalation and challenge
  • The most defensible compliance programs are the ones where the CCO’s actions are visible: escalation records, board reports, testing calendars, and written challenge of management decisions

The SEC charge didn’t go to the firm. It went to the compliance officer.

That’s the sentence that changes how you read every SEC enforcement notice from now on. Not “the firm was charged” — “the compliance officer was charged, in their personal capacity, for failing to do the job.”

It happened in March 2025. It happened in January 2025. It happened in July 2025. FINRA settled two enforcement actions against CCOs in the first quarter of 2026. The pattern is consistent enough now that “CCO personal liability” has moved from an edge case to a legitimate planning consideration for every compliance officer in financial services.

Here is what you need to know about how this happens and how to make sure it doesn’t happen to you.


The Three-Part Test

The SEC has been candid about when it will charge a CCO personally. In public statements and enforcement actions over the past several years, the agency has identified three circumstances:

1. Affirmative involvement in the misconduct. The CCO wasn’t just aware of the problem — they actively participated. This is the clearest case: the CCO falsified records, directed the violation, or executed the transaction themselves. There’s no ambiguity here, and the defense is limited.

2. Obstruction or misleading the SEC. The CCO provided inaccurate information during an examination, altered documents to conceal violations, or impeded the agency’s ability to conduct its review. In July 2025, the SEC settled charges against the CCO of a formerly registered investment adviser who had altered approximately 170 pre-clearance trading forms. That’s a document falsification case, and the personal charge was the predictable result.

3. Wholesale failure to carry out responsibilities. This is the least well-defined and the most concerning of the three. A CCO who had the authority and resources to implement an effective compliance program, and failed to do so in a way that contributed to widespread violations, can face personal liability — even without being involved in the violations themselves.

The first two categories are, in a meaningful sense, personal misconduct. The third is a failure to prevent someone else’s misconduct. That distinction matters for how compliance officers think about their own risk.


What the 2025–2026 Cases Actually Look Like

Three cases from the recent enforcement record are worth understanding in detail.

The pre-clearance falsification case (July 2025). The SEC charged the CCO of a formerly registered investment adviser for altering pre-clearance trading forms — approximately 170 of them. The alteration was designed to make the firm’s compliance records appear more complete or accurate than they were. This is the clearest case: document falsification by the compliance officer is both a substantive violation and an obstruction of the SEC’s ability to evaluate the firm’s compliance program. The charge was in the CCO’s personal capacity.

The supervisory failure case (March 2025). The SEC charged a private fund adviser and its former CCO after misuse of portfolio company debit cards for personal expenses. The CCO’s charge was for failing to reasonably supervise the partner responsible for the misconduct. The result: an $80,000 penalty and a one-year suspension from acting in a supervisory capacity. Note the structure — the CCO wasn’t accused of taking the money. They were accused of failing to prevent it when the tools to do so were available.

The recordkeeping and policies failure (January 2025). The SEC charged Arete Wealth Management and its General Counsel and CCO, UnBo (Bob) Chung, alongside several sales representatives, for failing to comply with compliance and recordkeeping requirements and failing to maintain adequate compliance policies and procedures. This case spans the line between the second and third prongs: inadequate policies (wholesale failure) plus inadequate records (obstruction risk).

None of these CCOs committed the underlying fraud. In most cases, they failed to prevent someone else’s fraud — and the SEC concluded that failure was chargeable.


FINRA’s Approach: The Dually-Hatted Problem

FINRA takes a different analytical approach to CCO liability, but the 2026 enforcement actions show the agency is still actively pursuing individuals.

FINRA’s formal position is that a CCO’s role is “advisory, not supervisory.” The CCO is not a supervisor by virtue of the title alone. Personal liability for supervisory failures only arises when the firm has expressly or impliedly designated the CCO as having supervisory authority — typically through the firm’s written supervisory procedures.

The problem is structural at many smaller firms: the compliance officer is also a supervisor. Wearing two hats. Managing a team, running compliance, and technically holding supervisory authority over business line activity — often because headcount is limited and someone has to do it.

FINRA settled two enforcement actions against dually-hatted CCOs in early 2026. In one of the settled cases, the CCO was suspended for three months, fined $5,000, and required to complete 20 hours of continuing education related to Regulation Best Interest. The finding wasn’t that the CCO failed to perform their compliance function — it was that they held supervisory authority, had supervisory responsibility for the Reg BI failure, and didn’t exercise it adequately.

If you are a CCO who also supervises people, you are exposed on both tracks. The compliance track for failing to build or operate an adequate compliance function. The supervisory track for failing to oversee the people you manage.


”Wholesale Failure”: What It Means in Practice

The SEC has never formally defined “wholesale failure,” which creates legitimate ambiguity and significant personal risk for CCOs who can’t be sure where the line is.

What the enforcement record and SEC staff statements suggest:

A CCO who had warning signs and did nothing is at maximum risk. If a compliance officer received a complaint, saw a red flag in a report, or was present in a meeting where a concern was raised — and then took no action, generated no record, and conducted no review — the wholesale failure framing fits.

A CCO who escalated and was overruled is substantially better positioned. The act of putting the concern in writing, sending it to senior management or the board, and documenting the response creates a record that shifts accountability. The CCO’s job is to identify and raise compliance risks. A CCO who identifies the problem and loses the argument — but documents having identified and raised it — has done what the role requires, even if the firm subsequently fails.

Lack of resources is a defense, but a limited one. CCOs at understaffed firms have argued that they couldn’t build an adequate program because they didn’t have the headcount or budget. That defense is more credible when the CCO repeatedly asked for resources and was denied in writing. It is less credible when the request was never made or was verbal only.

The practical implication: escalation and documentation are not just good compliance practice. They are personal liability protection.


Building a Defensible Compliance Function

What does “defensible” actually look like in the current enforcement environment?

Maintain your own paper trail. Every material compliance concern you identify should generate a written record: a memo, an email, a board report, a risk log entry. If the firm later has a problem in an area where you raised concerns, you need to be able to show the date you raised them and the response you received.

Formalize your escalation path. Know who you escalate to, on what timeline, and what happens if escalation doesn’t produce action. If you escalate to a CEO who doesn’t act, do you go to the board? Is there a process for that? Having a written escalation procedure protects the function — and the officer.

Test what you assert. If your compliance program says vendors are reviewed annually, those reviews need to be documented. If your program says transaction monitoring thresholds are calibrated quarterly, the calibration records need to exist. RCSA testing and controls documentation are how you prove that your compliance program functions rather than just exists.

Document management’s decisions, not just your own. When management overrules your compliance recommendation, document the overrule. “Management decided to proceed” is not documentation. “On [date], I raised [concern] to [name and title]. [Name] responded that [position] and the firm would proceed. I documented my disagreement in the attached memo.” That is documentation.

Separate your supervisory and compliance roles if possible. If you are wearing two hats at a smaller firm, understand that you’re exposing yourself on both tracks. The FINRA cases in 2026 show that the dually-hatted structure creates enforcement risk that is distinct from ordinary CCO liability. If headcount allows, separate the roles.


The Conduct Risk KRI Gap

One of the indicators that a compliance function is operating — rather than existing — is whether it tracks conduct-related metrics: employee complaints, unusual trading patterns, escalation volumes, whistleblower submissions, exception frequencies. These conduct risk indicators are the early warning system that a CCO is supposed to operate.

A compliance function that has no conduct metrics, or that generates the metrics but doesn’t use them to trigger investigation, is exactly the profile that fits the “wholesale failure” framing. The indicators existed. Nobody acted on them.

The examination question regulators now ask isn’t just “do you have a compliance program?” It’s “how would you have known?” If your answer is “we would have caught it when someone complained,” that’s the wrong answer. The right answer is a monitoring system with thresholds, escalation procedures, and records of the times the system triggered a response.


So What?

Personal liability is not inevitable for compliance officers who do their jobs. It is a risk that grows when the job is performed without documentation, when escalation is verbal instead of written, when testing is asserted but not conducted, and when the CCO holds supervisory authority without managing the exposure that comes with it.

The three-part test gives you the map. Affirmative misconduct is obvious. Obstruction is intentional. Wholesale failure is the category to manage: identify compliance risks, escalate them in writing, document the response, and test that your program operates rather than sits on paper.

That is a compliance function that can defend itself. Build it now, before the examination arrives.


If you’re building or rebuilding your compliance control environment, the RCSA (Risk & Control Self-Assessment) provides pre-built control assessments across 141 fintech risk areas, evidence-based scoring, and board reporting — the documented control environment that makes your compliance function visible when regulators ask to see it.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What are the three circumstances where the SEC will charge a CCO personally?
The SEC has stated that it will pursue individual CCO liability in three circumstances: (1) when the CCO is affirmatively involved in the misconduct itself; (2) when the CCO engages in efforts to obstruct or mislead the SEC during an examination or investigation; or (3) when the CCO exhibits a wholesale failure to carry out their compliance responsibilities. The first two are straightforward. The third is the one that keeps CCOs up at night — because 'wholesale failure' is not clearly defined and has been applied inconsistently.
What does 'wholesale failure' actually mean in practice?
'Wholesale failure' has been described as a situation where the CCO had the authority and resources to prevent compliance breakdowns but failed to exercise either. Courts and SEC staff have signaled that a CCO who had early warning signs, did not escalate, and did not document their escalation attempts is the highest-risk profile. A CCO who identifies the problem, escalates in writing, gets overruled by senior management, and documents the overrule has substantially more protection — even if the firm ultimately fails.
When does FINRA charge a CCO personally, and what triggers supervisory liability?
FINRA's position is that CCO liability for supervisory failures only arises when the firm has expressly or impliedly designated the CCO as having supervisory authority — typically through the firm's written supervisory procedures (WSPs). FINRA confirmed in guidance that a CCO's role is 'advisory, not supervisory' by default. The risk arises when a CCO is 'dually hatted' — holding both the CCO title and explicit supervisory responsibility for a business line or function. Both roles can create disciplinary exposure independently.
What happened in the 2026 FINRA CCO enforcement actions?
FINRA settled two enforcement actions against CCOs in early 2026, both focusing on dually-hatted compliance officers who held supervisory as well as compliance responsibilities. In one of the settled cases, the CCO was suspended for three months, fined $5,000, and required to complete 20 hours of continuing education related to Regulation Best Interest. Both cases were cited by industry observers as evidence that FINRA was continuing to pursue individual CCO discipline even after issuing guidance meant to clarify the boundaries of CCO liability.
What documentation should a CCO maintain to protect themselves from personal liability?
The most important documentation categories are: written escalation records (capturing when the CCO raised a concern, to whom, and the response); board and management reports showing what the compliance function disclosed and when; testing records demonstrating that the compliance program was actually operationalized, not just documented; and any evidence that the CCO sought independent legal or compliance counsel when the situation warranted it. A CCO who can show a paper trail of escalation and challenge has substantially stronger protection than one who relied on verbal conversations and status quo approval.
What's the difference between how the SEC and FINRA approach CCO liability?
The SEC's personal liability framework is primarily based on whether the CCO committed misconduct, obstructed regulators, or failed wholesale. The SEC can pursue a CCO as a control person or for their own independent violations. FINRA's framework is more specific: the CCO faces supervisory liability only when designated as a supervisor, and compliance liability when they fail to reasonably perform their defined compliance function. A CCO at a dually-regulated firm (registered broker-dealer and investment adviser) may face both frameworks simultaneously.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

RCSA (Risk & Control Self-Assessment)

141 pre-populated fintech risks with control assessments, questionnaire framework, and testing calendar.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.