The uncomfortable position of financial institutions’ internal defence under the EU law of investment services
摘要
This article examines the Compliance Function (CF) in EU investment-services law as a legally mandated internal control function with public-law effects. The argument is functional rather than institutional: CF is not a public authority and does not possess public enforcement powers. Rather, EU law uses CF to operationalise investor-protection standards inside the firm through policies, risk-based monitoring, complaints-handling, reporting, remediation, and escalation. The article first maps the public and private enforcement landscape for investor protection, then analyses CF under Basel/IOSCO standards, MiFID, the MiFID II Delegated Regulation, and ESMA/EBA guidance. It situates CF within new-governance and controlled internal self-regulation, and explains how hard law, soft law, and supervisory expectations interact in shaping CF’s role. The article argues that CF’s position is uncomfortable because EU law relies on a private, firm-financed, internally embedded function to support public-law outcomes, while leaving it outside the coercive powers, judicial-review framework, and accountability architecture attached to public authorities.