Fractional Compliance Officer
Context
In most small organisations compliance is a secondary responsibility, attended to ahead of an audit, funder review or supplier questionnaire and left thereafter. Policies exist; whether they are followed is not known.
Scope
Ownership of the compliance framework as a whole: identification of applicable obligations, the policies and procedures that meet them, the registers that evidence them, the training that embeds them, and the reporting that keeps leadership informed. Scope is agreed at onboarding and typically covers data protection (with or in place of the DPO service), AI use, information security governance, whistleblowing and complaints handling, supplier and contract compliance, and sector-specific requirements — for FCA-authorised firms, SM&CR, conduct rules, financial promotions and regulatory reporting.
Month to month
A standing review cadence. Registers maintained and reviewed. Policy review dates diarised and met. Training assigned, completed and recorded. Breaches, complaints and incidents logged, assessed and closed with root cause recorded. Regulatory change monitored and assessed for relevance. A quarterly compliance report to the board.
Delivery
All of the above is maintained in the Xelvio Toolkit: breach register, risk register, policy library with version control, training tracker, complaints and gifts-and-hospitality logs, regulatory intelligence feed and, for regulated firms, SM&CR responsibilities mapping and a financial promotions log.
Terms
Retainer by day-equivalent per month (for example two or four days), twelve-month minimum. Onboarding at a fixed fee, including a compliance framework review. [Insert figures.]