Skip to content
JOH Partners
Engage
Perspective · Financial ServicesFrom:Board Pulse

Chief Compliance Officer: Who Answers in a Gulf Group

Gulf compliance functions are built to satisfy the regulators a group raises money from, and few boards ask which jurisdiction wins when the two disagree.

Oliver Helvin· Founder and Managing Director
18 September 202610 min read
Chief Compliance Officer: Who Answers in a Gulf Group
-- Subscribe

Subscribe to our newsletter

A standing brief on the executive search and leadership market across the Gulf.

Research, market notes and pay benchmarks, direct to your inbox. Every two weeks. No marketing. Unsubscribe anytime.

Gulf groups have built chief compliance officer functions at pace over the past several years, and the single largest difficulty-zero search term in JOH Partners' current keyword programme, chief compliance officer at roughly 9,900 searches a month in the UK alone, confirms the appetite for board-level guidance on the seat has outpaced the settled thinking behind it. JOH's reading across its financial-services and group-holdings governance mandates finds a structural pattern boards rarely name directly: the function has usually been built to satisfy the regulator the group is most visibly exposed to, typically its home listing venue or banking licence, rather than the regulator with the most actual leverage over the group's access to capital. The two are not always the same, and a board that has not asked which one wins when they disagree is carrying an exposure the org chart does not show.

A chief compliance officer is not answering to a regulator in the abstract. They are answering to whichever regulator can most credibly threaten the group's access to capital, and that is not always the one whose logo is on the licence framed in reception.
Oliver Helvin, Founder and Managing Director, JOH Partners, September 2026

Why the seat is regulator-facing before it is board-facing

Every other function in this series' control layer, the chief audit executive most directly, is built primarily to serve the board: independent assurance whose client is, in the end, the audit committee. A chief compliance officer serves a more divided set of masters. The regulator sets the substantive standard the function must meet, on pain of licence conditions, fines or, at the extreme, the withdrawal of the group's ability to operate in that market at all. The board sets the seat's reporting line and resourcing, and increasingly expects a standing view of regulatory exposure rather than a report only when something has already gone wrong. When those two demands pull in different directions, which happens more often in a fast-growing Gulf group than a settled Western one, the compliance function's actual behaviour reveals which master it was really built to serve.

This matters because Gulf groups have historically built compliance capability reactively, in response to a specific licensing requirement, a listing prospectus, or a co-investment covenant, rather than as a deliberately scoped governance function from the outset. JOH's earlier reading of the control layer beneath the Gulf CEO found this same reactive pattern across the wider assurance set: formal structure arrives quickly once a mandatory disclosure requires it, and practised independence behind that structure takes considerably longer to build, if it is built deliberately at all.

The jurisdiction question boards rarely ask

A Gulf industrial group with a Nasdaq-listed instrument, a Dubai International Financial Centre holding structure and a sovereign co-investor with its own compliance covenants can find itself answering, in practice, to at least three separate regulatory expectations at once, and JOH's observation across its own compliance and governance search mandates is that boards default to prioritising whichever regulator is most locally visible, usually the group's home exchange or central bank, rather than the one with the most actual leverage over the group's continued access to capital. A regional regulator can issue a fine the group can absorb. An international capital-markets regulator, or a sovereign co-investor reconsidering a relationship, can close a door the group cannot easily reopen, and that asymmetry is precisely what a chief compliance officer's reporting line and escalation protocol should be built around, rather than defaulting to whichever jurisdiction feels closest to home.

The compliance function that answers convincingly to the local regulator and quietly under-resources the international one has priced the wrong risk. The international relationship is usually the one that is hardest to repair once it is damaged.
Oliver Helvin, Founder and Managing Director, JOH Partners, September 2026

9,900/mo. UK monthly search volume on the term chief compliance officer, at the lowest measurable keyword difficulty (DataForSEO, September 2026)

1,000+. Senior mandates JOH Partners has closed across the Gulf, the UK and Singapore since 2014

The boundary against chief risk officer and chief audit executive

The assurance and control cluster now has four distinct seats, and a board that collapses the distinctions between them tends to mis-scope and mis-resource all four. The chief risk officer owns risk identification and management inside the first line, working alongside the executives running the business. The chief audit executive independently tests whether the first and second lines, compliance included, are actually functioning as their charters describe. The chief compliance officer sits between the two: a second-line function that sets and monitors conformance with external regulatory standards, distinct from risk management's broader remit and distinct from audit's independent testing role. A board that routes all three through a single reporting line, most often by folding compliance under the chief risk officer, has removed the separation that makes each seat's assurance value legible on its own terms, and has made it materially harder for an audit finding to surface a compliance failure without the same function that owns the failure also owning the response to it.

Financial-services platforms carry this boundary question with particular weight, because regulators such as the DFSA and the UAE Central Bank increasingly expect to see it drawn clearly in a licensed institution's governance disclosure. JOH's search building senior technology leadership for a tier-one GCC universal bank illustrates the wider discipline at financial-services scale: appointing senior functions inside heavily regulated institutions where multiple regulatory reporting lines are the operating default, not the exception, and where the seat's charter has to survive contact with more than one supervisor's expectations at once.

What a functioning mandate actually requires

A chief compliance officer mandate built with genuine intent, in JOH's reading across its own placements, names its full set of applicable regulatory regimes explicitly at the outset rather than discovering a new one when a transaction or co-investment brings it into scope. It sets an escalation protocol that identifies, in advance, which regulator's expectation governs when two disagree, rather than leaving that judgement to be made under time pressure during an actual conflict. It reports on regulatory exposure to the board or audit committee on a standing cycle, not only when a specific matter has already become a problem. And its remuneration and tenure are set at genuine distance from the chief executive's direct influence, for the same reason that protection matters for the chief audit executive: a compliance function whose continued employment depends on the goodwill of the person most exposed by an unfavourable finding has a structural incentive to soften what it reports, however capable the individual holding the seat.

JOH's earlier work on the AI governance readiness gap in Gulf boardrooms documents an adjacent version of this same structural challenge: boards adopting new capability faster than they build the oversight function meant to govern it, and discovering the gap only once something has already gone wrong rather than through a deliberate readiness review. The compliance function faces the same dynamic in miniature every time a Gulf group adds a new capital-raising relationship or cross-border structure without pausing to ask which regulatory regime now governs it.

The practical consequence of that dynamic is a compliance calendar built around whichever regime last made itself felt, rather than one that anticipates the regimes a group's own growth plan will bring into scope. A group planning a Nasdaq or London listing within two years is already, in JOH's reading, a candidate for a compliance function scoped to that future regulatory footprint, not only its present one, because the lead time to build genuine conformance capability against an unfamiliar regime is measured in years, not months, and a board that waits until the prospectus process has begun to ask the question has already left it too late to answer well.

Who should hold the seat, and what boards get wrong hiring for it

JOH's search work across the region finds boards defaulting to two candidate profiles for the chief compliance officer seat, a regulator alumnus with deep knowledge of one specific regime, or a Big Four advisory background with broad exposure but no lived experience of holding the seat inside an operating company. Both profiles can succeed, but each carries a predictable blind spot the board should test for explicitly at interview rather than discovering afterward. The regulator alumnus tends to build the function around the regime they know best, sometimes under-weighting a newer or less familiar jurisdiction the group has since grown into. The advisory-background candidate tends to design a comprehensive framework on paper that has never been stress-tested against a genuine internal conflict, where the finding implicates a colleague the chief executive personally recruited. Neither gap disqualifies a candidate; both are answerable with the right structural support once named, and a board that names them at hire rather than discovering them in year two gets a materially stronger appointment.

Boards wanting continuous, standing visibility into regulatory and control-layer exposure between formal review cycles increasingly use platforms such as Board Pulse to track those signals on an ongoing basis, rather than reconstructing the picture only once a regulator has already raised a finding. David Daly's account of finance transformation, tax compliance and radical honesty inside a UAE business turnaround is a useful companion listen for boards thinking through what a genuinely honest compliance function sounds like under pressure, distinct from one built primarily to keep the most visible regulator satisfied.

Where this leaves a board scoping the seat

The chief compliance officer question a board should be asking is not whether it has one; nearly every group of scale now does. It is whether the function was built against the regulator with the most actual leverage over the group's future, or against the one that happened to be first in the door when the seat was created. Boards that name every applicable regime explicitly, resolve the escalation question in advance, and price the seat's independence at genuine distance from the chief executive get a function capable of catching a conflict while it is still manageable. Boards that leave the question implicit discover, at the least convenient possible moment, which regulator the function was actually built to satisfy.


Key takeaways


JOH Partners is an executive search and senior executive recruitment firm advising boards, family groups and regulated financial institutions on chief compliance officer, chief risk officer and wider control-layer appointments across the GCC, the UK and Singapore. Boards wanting continuous visibility of how the control layer is actually functioning can request a Board Pulse demo, or engage a partner for a confidential conversation about structuring or filling a chief compliance officer mandate.

-- Frequently asked questions

Questions about this topic.

What does a chief compliance officer own that a chief audit executive does not?

A chief compliance officer owns regulatory conformance: making sure the group's activity satisfies the licensing, disclosure and conduct rules of every regulator it answers to. A chief audit executive independently tests whether the group's controls, including the compliance function itself, are working as designed. The two are frequently confused because both sit close to the regulatory perimeter, but a chief compliance officer who also audits their own function has quietly removed the independent check the audit seat exists to provide.

Why would a Gulf group's compliance function answer to a regulator it does not actually operate under day to day?

Because raising capital, listing, or accepting investment frequently brings a group under a regulator's jurisdiction that its operating business does not otherwise touch. A Gulf industrial group with a Nasdaq-listed bond, a DIFC-domiciled holding structure, or a sovereign co-investor with its own compliance expectations can find itself answering to two or three regulatory regimes simultaneously, and the one with the most capital-raising leverage over the group often has the most practical pull, whatever the operating footprint suggests.

Should the chief compliance officer report to the chief executive or the board?

JOH's reading of Gulf financial-services and group-holdings governance disclosure finds the formal answer increasingly converging on a board or audit-committee reporting line for regulatory matters, mirroring the independence protection built into the chief audit executive seat. In practice, administrative reporting to the chief executive remains common, and the two lines coexist; the substantive question a board should ask is which line actually governs when a regulatory finding implicates the chief executive personally.

Is chief compliance officer only relevant to banks and regulated financial institutions?

No. The seat has grown fastest in financial services because the regulatory density is highest there, but any Gulf group that lists, raises international capital, or takes on a sovereign or institutional co-investor with its own compliance covenants now carries a genuine multi-jurisdiction conformance question, whatever sector it operates in. JOH's mandate book increasingly includes compliance leadership searches for industrial and group-holdings platforms with no banking licence at all.

What is the biggest structural mistake boards make when creating the seat?

Appointing a chief compliance officer against the regulator the group is most publicly exposed to, usually its home listing venue, without deciding which regulator actually has the most leverage over the group's access to capital. JOH's observation is that the regulator with the least visible profile locally is sometimes the one whose displeasure carries the highest practical cost, because it controls a listing, a credit facility or a co-investment relationship the group cannot easily replace.

-- Author

Oliver Helvin

Founder and Managing Director

Oliver Helvin is the Founder and Managing Director of JOH Partners. He writes on the GCC executive market, leadership transitions in family-controlled businesses, and the discipline of senior search.

LinkedIn ↗
Engage a partner

Tell us about the seat.
We’ll tell you who’s right.

Confidential conversations with the partner leading the practice you need. We respond within one business day.