Feature Compliance Strategy
CCO Personal Liability in 2026: What the SEC and FINRA Are Now Charging Compliance Officers With
SEC and FINRA enforcement against individual compliance officers is accelerating in 2025–2026. Here's what the three-part personal liability test actually means, what recent cases look like, and how to build a compliance function that protects the institution and the person running it.
Table of Contents
TL;DR
- The SEC charged multiple CCOs personally in 2025, including for falsifying compliance records, inadequate supervision, and failing to maintain adequate compliance policies
- FINRA settled two enforcement actions against CCOs in 2026, both tied to dually-hatted compliance officers who held supervisory responsibilities
- The SEC’s three-part personal liability test — affirmative misconduct, obstruction, or wholesale failure — creates real exposure for CCOs who don’t document escalation and challenge
- The most defensible compliance programs are the ones where the CCO’s actions are visible: escalation records, board reports, testing calendars, and written challenge of management decisions
The SEC charge didn’t go to the firm. It went to the compliance officer.
That’s the sentence that changes how you read every SEC enforcement notice from now on. Not “the firm was charged” — “the compliance officer was charged, in their personal capacity, for failing to do the job.”
It happened in March 2025. It happened in January 2025. It happened in July 2025. FINRA settled two enforcement actions against CCOs in the first quarter of 2026. The pattern is consistent enough now that “CCO personal liability” has moved from an edge case to a legitimate planning consideration for every compliance officer in financial services.
Here is what you need to know about how this happens and how to make sure it doesn’t happen to you.
The Three-Part Test
The SEC has been candid about when it will charge a CCO personally. In public statements and enforcement actions over the past several years, the agency has identified three circumstances:
1. Affirmative involvement in the misconduct. The CCO wasn’t just aware of the problem — they actively participated. This is the clearest case: the CCO falsified records, directed the violation, or executed the transaction themselves. There’s no ambiguity here, and the defense is limited.
2. Obstruction or misleading the SEC. The CCO provided inaccurate information during an examination, altered documents to conceal violations, or impeded the agency’s ability to conduct its review. In July 2025, the SEC settled charges against the CCO of a formerly registered investment adviser who had altered approximately 170 pre-clearance trading forms. That’s a document falsification case, and the personal charge was the predictable result.
3. Wholesale failure to carry out responsibilities. This is the least well-defined and the most concerning of the three. A CCO who had the authority and resources to implement an effective compliance program, and failed to do so in a way that contributed to widespread violations, can face personal liability — even without being involved in the violations themselves.
The first two categories are, in a meaningful sense, personal misconduct. The third is a failure to prevent someone else’s misconduct. That distinction matters for how compliance officers think about their own risk.
What the 2025–2026 Cases Actually Look Like
Three cases from the recent enforcement record are worth understanding in detail.
The pre-clearance falsification case (July 2025). The SEC charged the CCO of a formerly registered investment adviser for altering pre-clearance trading forms — approximately 170 of them. The alteration was designed to make the firm’s compliance records appear more complete or accurate than they were. This is the clearest case: document falsification by the compliance officer is both a substantive violation and an obstruction of the SEC’s ability to evaluate the firm’s compliance program. The charge was in the CCO’s personal capacity.
The supervisory failure case (March 2025). The SEC charged a private fund adviser and its former CCO after misuse of portfolio company debit cards for personal expenses. The CCO’s charge was for failing to reasonably supervise the partner responsible for the misconduct. The result: an $80,000 penalty and a one-year suspension from acting in a supervisory capacity. Note the structure — the CCO wasn’t accused of taking the money. They were accused of failing to prevent it when the tools to do so were available.
The recordkeeping and policies failure (January 2025). The SEC charged Arete Wealth Management and its General Counsel and CCO, UnBo (Bob) Chung, alongside several sales representatives, for failing to comply with compliance and recordkeeping requirements and failing to maintain adequate compliance policies and procedures. This case spans the line between the second and third prongs: inadequate policies (wholesale failure) plus inadequate records (obstruction risk).
None of these CCOs committed the underlying fraud. In most cases, they failed to prevent someone else’s fraud — and the SEC concluded that failure was chargeable.
FINRA’s Approach: The Dually-Hatted Problem
FINRA takes a different analytical approach to CCO liability, but the 2026 enforcement actions show the agency is still actively pursuing individuals.
FINRA’s formal position is that a CCO’s role is “advisory, not supervisory.” The CCO is not a supervisor by virtue of the title alone. Personal liability for supervisory failures only arises when the firm has expressly or impliedly designated the CCO as having supervisory authority — typically through the firm’s written supervisory procedures.
The problem is structural at many smaller firms: the compliance officer is also a supervisor. Wearing two hats. Managing a team, running compliance, and technically holding supervisory authority over business line activity — often because headcount is limited and someone has to do it.
FINRA settled two enforcement actions against dually-hatted CCOs in early 2026. In one of the settled cases, the CCO was suspended for three months, fined $5,000, and required to complete 20 hours of continuing education related to Regulation Best Interest. The finding wasn’t that the CCO failed to perform their compliance function — it was that they held supervisory authority, had supervisory responsibility for the Reg BI failure, and didn’t exercise it adequately.
If you are a CCO who also supervises people, you are exposed on both tracks. The compliance track for failing to build or operate an adequate compliance function. The supervisory track for failing to oversee the people you manage.
”Wholesale Failure”: What It Means in Practice
The SEC has never formally defined “wholesale failure,” which creates legitimate ambiguity and significant personal risk for CCOs who can’t be sure where the line is.
What the enforcement record and SEC staff statements suggest:
A CCO who had warning signs and did nothing is at maximum risk. If a compliance officer received a complaint, saw a red flag in a report, or was present in a meeting where a concern was raised — and then took no action, generated no record, and conducted no review — the wholesale failure framing fits.
A CCO who escalated and was overruled is substantially better positioned. The act of putting the concern in writing, sending it to senior management or the board, and documenting the response creates a record that shifts accountability. The CCO’s job is to identify and raise compliance risks. A CCO who identifies the problem and loses the argument — but documents having identified and raised it — has done what the role requires, even if the firm subsequently fails.
Lack of resources is a defense, but a limited one. CCOs at understaffed firms have argued that they couldn’t build an adequate program because they didn’t have the headcount or budget. That defense is more credible when the CCO repeatedly asked for resources and was denied in writing. It is less credible when the request was never made or was verbal only.
The practical implication: escalation and documentation are not just good compliance practice. They are personal liability protection.
Building a Defensible Compliance Function
What does “defensible” actually look like in the current enforcement environment?
Maintain your own paper trail. Every material compliance concern you identify should generate a written record: a memo, an email, a board report, a risk log entry. If the firm later has a problem in an area where you raised concerns, you need to be able to show the date you raised them and the response you received.
Formalize your escalation path. Know who you escalate to, on what timeline, and what happens if escalation doesn’t produce action. If you escalate to a CEO who doesn’t act, do you go to the board? Is there a process for that? Having a written escalation procedure protects the function — and the officer.
Test what you assert. If your compliance program says vendors are reviewed annually, those reviews need to be documented. If your program says transaction monitoring thresholds are calibrated quarterly, the calibration records need to exist. RCSA testing and controls documentation are how you prove that your compliance program functions rather than just exists.
Document management’s decisions, not just your own. When management overrules your compliance recommendation, document the overrule. “Management decided to proceed” is not documentation. “On [date], I raised [concern] to [name and title]. [Name] responded that [position] and the firm would proceed. I documented my disagreement in the attached memo.” That is documentation.
Separate your supervisory and compliance roles if possible. If you are wearing two hats at a smaller firm, understand that you’re exposing yourself on both tracks. The FINRA cases in 2026 show that the dually-hatted structure creates enforcement risk that is distinct from ordinary CCO liability. If headcount allows, separate the roles.
The Conduct Risk KRI Gap
One of the indicators that a compliance function is operating — rather than existing — is whether it tracks conduct-related metrics: employee complaints, unusual trading patterns, escalation volumes, whistleblower submissions, exception frequencies. These conduct risk indicators are the early warning system that a CCO is supposed to operate.
A compliance function that has no conduct metrics, or that generates the metrics but doesn’t use them to trigger investigation, is exactly the profile that fits the “wholesale failure” framing. The indicators existed. Nobody acted on them.
The examination question regulators now ask isn’t just “do you have a compliance program?” It’s “how would you have known?” If your answer is “we would have caught it when someone complained,” that’s the wrong answer. The right answer is a monitoring system with thresholds, escalation procedures, and records of the times the system triggered a response.
So What?
Personal liability is not inevitable for compliance officers who do their jobs. It is a risk that grows when the job is performed without documentation, when escalation is verbal instead of written, when testing is asserted but not conducted, and when the CCO holds supervisory authority without managing the exposure that comes with it.
The three-part test gives you the map. Affirmative misconduct is obvious. Obstruction is intentional. Wholesale failure is the category to manage: identify compliance risks, escalate them in writing, document the response, and test that your program operates rather than sits on paper.
That is a compliance function that can defend itself. Build it now, before the examination arrives.
If you’re building or rebuilding your compliance control environment, the RCSA (Risk & Control Self-Assessment) provides pre-built control assessments across 141 fintech risk areas, evidence-based scoring, and board reporting — the documented control environment that makes your compliance function visible when regulators ask to see it.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
RCSA (Risk & Control Self-Assessment)
141 pre-populated fintech risks with control assessments, questionnaire framework, and testing calendar.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What are the three circumstances where the SEC will charge a CCO personally?
What does 'wholesale failure' actually mean in practice?
When does FINRA charge a CCO personally, and what triggers supervisory liability?
What happened in the 2026 FINRA CCO enforcement actions?
What documentation should a CCO maintain to protect themselves from personal liability?
What's the difference between how the SEC and FINRA approach CCO liability?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
RCSA (Risk & Control Self-Assessment)
141 pre-populated fintech risks with control assessments, questionnaire framework, and testing calendar.
◆ Keep reading
Related posts.
Compliance Strategy
FINRA's First Significant CAT Enforcement: What Instinet's $3.8 Million Fine Means for Your Consolidated Audit Trail Compliance Program
On August 16, 2026, FINRA settled its first significant Consolidated Audit Trail enforcement action — a $3.8M fine against Instinet plus a mandatory independent consultant review. Here's what the red-flag failure pattern means for your firm's CAT reporting program.
Aug 27, 2026
Compliance Strategy
What the SEC's Conflicts of Interest Risk Alert Found — and What Examiners Will Look for at Your Firm
The SEC's June 2026 Risk Alert identified recurring deficiencies in how investment advisers identify, disclose, and manage economic conflicts of interest. Here are the five categories examinations staff flagged — and what your Form ADV and compliance program need to address before the next exam cycle.
Aug 26, 2026
Compliance Strategy
FINRA's Low-Priced Securities AML Trap: What the Pictet and Blue Ocean Fines Mean for Your Surveillance Program
FINRA fined Pictet Overseas ($610K) and Blue Ocean ATS ($550K) for AML failures on low-priced securities in 2026. One firm missed $300M in transactions routed through an affiliate's omnibus account. The other had one employee reviewing two reports. Here's the five-part compliance trap these cases expose.
Aug 25, 2026