Mason: "My Board hired me to “keep the firm compliant”."
I am Head of Compliance.
My Board hired me to “keep the firm compliant”.
The reality: I can’t do that unless certain conversations happen at Board level.
Not “nice to have” – the non-negotiables.
As CCO, these are the Board discussions I’d fight to have regularly:
1 Risk appetite vs growth – in plain language
I’d want a real conversation, not just a document, about:
where we are prepared to take risk to grow, and
where we’re not, even if it costs revenue.
So that, day-to-day, I can say:
“This isn’t my line in the sand. This is the line our Board has drawn.”
2 “Known non-compliance” and trade-offs
Every firm has gaps and legacy issues. Once or twice a year, I’d want the Board to see a clear list of:
where we know we’re not where we should be,
the customer / regulatory / reputational impact,
what we’re fixing now – and what we’re consciously living with (for a time), and why.
If those trade-offs never reach the Board, they sit silently on me and the exec.
3 Customer outcomes, not just legal minimums
Whether your regime talks about “fair treatment”, “duty”, or something else, the direction of travel is the same: Regulators want Boards to own real outcomes, not just technical compliance.
I’d want a regular discussion that answers:
where we are clearly delivering good outcomes,
where price, value, vulnerability or support look uncomfortable,
and what we’ve actually changed as a result.
4 Culture, incentives and behaviour
Dashboards don’t always tell you what people are really doing.
I’d want time to discuss:
what people are actually rewarded for,
where process is being bent to hit numbers,
what we’re hearing from the front line, HR, whistleblowing, audit.
That’s often where the next enforcement case is hiding.
Ben Mason is on LinkedIn
5 “Where we make our money” vs financial crime and conduct risk
Rather than a technical AML or conduct update, I’d want the Board to see:
where the firm really makes money,
where that overlaps with higher financial crime / conduct risk,
and whether we’re genuinely comfortable with that trade-off.
It’s easier to defend those choices when they’ve been made consciously.
For me, these aren’t “compliance agenda items”.
They’re the conversations that let me say – to myself, my Board and my regulator:
“We saw the real picture. The hard choices were made at the right level. I’m not carrying this alone.”
If you’re a Head of Compliance, CRO or NED:
Which of these conversations are locked into your Board calendar?
Which are still missing?

