Source: OJ L 277, 27/10/2022, p. 1–102

Current language: EN

Article 41 Compliance function


Summary What does Article 41 of the DSA regulation say?

This article establishes the internal compliance structure that providers of very large online platforms and very large online search engines must put in place.

It requires these providers to create a dedicated compliance function, staffed by qualified compliance officers and led by a senior independent head, that sits apart from operational functions.

The article ties closely to Article 34, which covers systemic risk assessment, as the compliance function is central to ensuring those risks are identified, reported on, and mitigated.

It also connects to Articles 35, 37, 45, 46, and 48, as compliance officers are responsible for overseeing activities under those provisions.

Crucially, accountability for the compliance function rests squarely with the management body, which must actively engage with risk management decisions and maintain the independence of the compliance structure.

Important points:

  • Establish an independent compliance function, led by a senior manager who reports directly to the management body and cannot be removed without its prior approval.
  • Compliance officers are responsible for a defined set of tasks, including cooperating with the Digital Services Coordinator and the Commission, overseeing audits, and monitoring adherence to codes of conduct and crisis protocols.
  • The management body is accountable for the governance arrangements underpinning the compliance function and must review risk strategies at least once a year.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Providers of very large online platforms or of very large online search engines shall establish a compliance function, which is independent from their operational functions and composed of one or more compliance officers, including the head of the compliance function. That compliance function shall have sufficient authority, stature and resources, as well as access to the management body of the provider of the very large online platform or of the very large online search engine to monitor the compliance of that provider with this Regulation.

    1. The management body of the provider of the very large online platform or of the very large online search engine shall ensure that compliance officers have the professional qualifications, knowledge, experience and ability necessary to fulfil the tasks referred to in paragraph 3.

    2. The management body of the provider of the very large online platform or of the very large online search engine shall ensure that the head of the compliance function is an independent senior manager with distinct responsibility for the compliance function.

    3. The head of the compliance function shall report directly to the management body of the provider of the very large online platform or of the very large online search engine, and may raise concerns and warn that body where risks referred to in Article 34 or non-compliance with this Regulation affect or may affect the provider of the very large online platform or of the very large online search engine concerned, without prejudice to the responsibilities of the management body in its supervisory and managerial functions.

    4. The head of the compliance function shall not be removed without prior approval of the management body of the provider of the very large online platform or of the very large online search engine.

    1. Compliance officers shall have the following tasks:

      1. cooperating with the Digital Services Coordinator of establishment and the Commission for the purpose of this Regulation;

      2. ensuring that all risks referred to in Article 34 are identified and properly reported on and that reasonable, proportionate and effective risk-mitigation measures are taken pursuant to Article 35;

      3. organising and supervising the activities of the provider of the very large online platform or of the very large online search engine relating to the independent audit pursuant to Article 37;

      4. informing and advising the management and employees of the provider of the very large online platform or of the very large online search engine about relevant obligations under this Regulation;

      5. monitoring the compliance of the provider of the very large online platform or of the very large online search engine with its obligations under this Regulation;

      6. where applicable, monitoring the compliance of the provider of the very large online platform or of the very large online search engine with commitments made under the codes of conduct pursuant to Articles 45 and 46 or the crisis protocols pursuant to Article 48.

    1. Providers of very large online platforms or of very large online search engines shall communicate the name and contact details of the head of the compliance function to the Digital Services Coordinator of establishment and to the Commission.

    1. The management body of the provider of the very large online platform or of the very large online search engine shall define, oversee and be accountable for the implementation of the provider's governance arrangements that ensure the independence of the compliance function, including the division of responsibilities within the organisation of the provider of very large online platform or of very large online search engine, the prevention of conflicts of interest, and sound management of systemic risks identified pursuant to Article 34.

    1. The management body shall approve and review periodically, at least once a year, the strategies and policies for taking up, managing, monitoring and mitigating the risks identified pursuant to Article 34 to which the very large online platform or the very large online search engine is or might be exposed to.

    1. The management body shall devote sufficient time to the consideration of the measures related to risk management. It shall be actively involved in the decisions related to risk management, and shall ensure that adequate resources are allocated to the management of the risks identified in accordance with Article 34.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod