Why RIAs are turning to outsourced compliance chiefs

SEC

ACA’s outsourced chief compliance officer (OCCO) service is being positioned as a way for registered investment advisers (RIAs) to close compliance gaps before they escalate into SEC deficiency letters or enforcement referrals, according to ACA OCCO Shoshana Thoma-Isgur.

Thoma-Isgur, who has worked as an SEC enforcement attorney, an in-house CCO and now an ACA OCCO, argues that firms strengthen their regulatory standing when compliance is treated as a core business function rather than a box-ticking exercise.

She notes that many of the shortcomings she encountered during her time at the SEC did not stem from misconduct, but from compliance programmes lacking structure, documentation or adequate resourcing to keep pace with business growth. Those gaps, she says, tend to trigger longer examinations and unwanted regulatory attention.

The OCCO model is gaining traction among advisers whose compliance demands have outgrown internal capacity but who are not yet ready to hire a full-time CCO. This includes firms scaling quickly, entering new markets, launching new products or seeking greater assurance ahead of an SEC review.

An OCCO offers experienced compliance leadership and an independent perspective without the cost of a full-time executive hire.

ACA positions its OCCO offering as backed by a wider consulting bench spanning regulatory reporting, cybersecurity, private funds, marketing compliance and ESG, meaning clients are not reliant on a single adviser but on a broader specialist team.

The firm’s OCCOs work alongside executive leadership to embed compliance into daily operations, aiming to build controls that scale with the business rather than adding unnecessary complexity.

This is particularly relevant given that SEC examinations assess whether policies and procedures are reasonably designed, effectively implemented, reviewed annually and adapted to a firm’s evolving risk profile. ACA says its OCCOs support this through risk assessments, compliance testing, annual reviews, regulatory filings and documentation aimed at examination readiness.

Independent oversight is another selling point, with ACA arguing that an external compliance leader can flag emerging risks without being swayed by competing internal business priorities. As firms grow, additional investors, new strategies and expanding operations raise the bar for compliance infrastructure, often stretching executives already juggling investment, operations and finance duties.

ACA maintains that examination readiness is built well before regulators arrive, through consistent implementation, testing and review, and that firms with dedicated compliance leadership and a compliance-first culture are best placed to navigate SEC scrutiny successfully.

To read the full ACA post, click here. 

Read the daily FinTech news

Copyright © 2026 FinTech Global

Enjoying the stories?

Subscribe to our daily FinTech newsletter and get the latest industry news & research

Investors

The following investor(s) were tagged in this article.