Source: OJ L 265, 12.10.2022, pp. 1–66Consolidated text

Current language: EN

Article 28 Compliance function


Summary What does Article 28 of the DMA regulation say?

This article establishes a mandatory internal compliance structure that gatekeepers must put in place to ensure adherence to the regulation.

It requires gatekeepers to set up a dedicated compliance function, staffed by qualified compliance officers and led by a senior independent head, who reports directly to the management body.

The article places significant weight on the management body's accountability, requiring it to actively oversee, resource, and engage with compliance on an ongoing basis rather than delegate it away entirely.

Important points:

  • Gatekeepers must establish an independent compliance function, composed of one or more compliance officers, with sufficient authority, resources, and direct access to the management body.
  • The head of the compliance function must be an independent senior manager who reports directly to the management body and cannot be removed without its prior approval.
  • The management body bears ultimate accountability for governance of the compliance function, including approving strategies and policies at least once a year and actively participating in compliance decisions.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Gatekeepers shall introduce a compliance function, which is independent from the operational functions of the gatekeeper and composed of one or more compliance officers, including the head of the compliance function.

    1. The gatekeeper shall ensure that the compliance function referred to in paragraph 1 has sufficient authority, stature and resources, as well as access to the management body of the gatekeeper to monitor the compliance of the gatekeeper with this Regulation.

    1. The management body of the gatekeeper shall ensure that compliance officers appointed pursuant to paragraph 1 have the professional qualifications, knowledge, experience and ability necessary to fulfil the tasks referred to in paragraph 5.

    2. The management body of the gatekeeper shall also ensure that such head of the compliance function is an independent senior manager with distinct responsibility for the compliance function.

    1. The head of the compliance function shall report directly to the management body of the gatekeeper and may raise concerns and warn that body where risks of non-compliance with this Regulation arise, without prejudice to the responsibilities of the management body in its supervisory and managerial functions.

    2. The head of the compliance function shall not be removed without prior approval of the management body of the gatekeeper.

    1. Compliance officers appointed by the gatekeeper pursuant to paragraph 1 shall have the following tasks:

      1. organising, monitoring and supervising the measures and activities of the gatekeepers that aim to ensure compliance with this Regulation;

      2. informing and advising the management and employees of the gatekeeper on compliance with this Regulation;

      3. where applicable, monitoring compliance with commitments made binding pursuant to Article 25, without prejudice to the Commission being able to appoint independent external experts pursuant to Article 26(2);

      4. cooperating with the Commission for the purpose of this Regulation.

    1. Gatekeepers shall communicate the name and contact details of the head of the compliance function to the Commission.

    1. The management body of the gatekeeper shall define, oversee and be accountable for the implementation of the governance arrangements of the gatekeeper that ensure the independence of the compliance function, including the division of responsibilities in the organisation of the gatekeeper and the prevention of conflicts of interest.

    1. The management body shall approve and review periodically, at least once a year, the strategies and policies for taking up, managing and monitoring the compliance with this Regulation.

    1. The management body shall devote sufficient time to the management and monitoring of compliance with this Regulation. It shall actively participate in decisions relating to the management and enforcement of this Regulation and ensure that adequate resources are allocated to it.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod