Get told when a verified record lands on this occupation →
Compliance officer
Works out what a rule requires this company to actually do, checks whether it is being done, and is the person who has to say no to the business.
This is not a probability of losing your job. It combines how much of the role's task load is exposed to automation with how far adoption has actually gone — useful for comparing occupations on one consistent basis, and for nothing else.
Covers second-line compliance in regulated industries — financial services, healthcare, data protection. It does not cover legal advice, which is a separate occupation here, and it does not cover audit, which looks backwards at what happened rather than forwards at what is allowed. Whether your role has the authority to stop a transaction changes this job more than any tool does.
The evidence base holds verified records for other occupations, but not one for this one yet. Until it does, the analysis below is reasoning about task structure and known technical capability — for this job in particular it is not backed by traceable sources, and we would rather say so than cite things we have not verified. An empty section here is a gap in our coverage, not a finding about the work.
What is actually changing#
The unit of analysis is the task, not the job title. A role is not replaced — its task mix shifts.
Is this your job? Say so and this page narrows to your share of it.
A job title is a bundle of tasks bought together, and no two people hold the same bundle. Nothing is sent anywhere — it stays in this browser.
Reading the rule
Being augmented≈ Platform inferenceGetting through a new regulation, a consultation response and three guidance notes, and extracting what actually changes for this company.
Reading long documents and summarising them is squarely what models do well, and the volume of regulatory text is the reason this job has grown. What does not transfer is the second half: knowing which of this company's actual processes the clause lands on, which requires knowing the processes rather than the clause.
Faster reading raises the expected scope rather than reducing the work: once summarising is free, the question becomes why you have not assessed every jurisdiction. The hours move from reading to defending an interpretation, which is a meeting rather than a document.
Working the alerts
Automating≈ Platform inferenceTransaction monitoring, sanctions screening, the flagged payment — deciding which of hundreds is worth investigating.
This is the same task as the SOC analyst's queue and the security guard's camera wall, and it fails the same way: the true-positive rate is very low, human vigilance collapses, and correlation is machine-checkable. Financial crime monitoring is one of the most heavily automated alert pipelines anywhere for exactly that reason.
The queue is where this profession hires and where the pattern recognition is learned, so automating it removes the training ground. And the regulator's expectation is that alerts are investigated, not that they are closed — a system that closes more of them faster produces a metric that improves while the risk does not.
Saying no to the business
Still human-led≈ Platform inferenceBlocking a deal, a client or a product launch, and holding the position when the revenue owner escalates.
The mechanism here is organisational, not analytical: the refusal works because a named person with standing will be the one questioned if it turns out to have been wrong, and because they can be overruled in a way that is recorded. Neither property exists for a system, which is why no institution delegates it.
Held in place by structure, not by difficulty, and structure is cheap to change: a compliance function that reports into the business it polices has this task on paper and not in practice. The question to ask is not whether a tool could do it but who you report to, and that answer changes without any technology involved.
Proving it was done
Automating≈ Platform inferenceKeeping the record that shows a control operated, a decision was reviewed and a policy was followed — for a regulator who will arrive later.
Evidence collection is structured logging with a known format, and it is the part of compliance work that everyone agrees should not require a person. The outcome is checkable — the record exists and is complete, or it is not — which is the property that allows unattended operation.
Automating the evidence does not automate the judgement it evidences, and it creates a specific new risk: a complete record of a control that was not actually effective is worse than an incomplete one, because it is harder to challenge. Auditors have begun asking how the record was produced, which is a question the tooling was not designed to answer.
Which technologies matter here#
Four separate signals. They are deliberately not added together — a job exposed to two technologies is not twice as exposed.
How it got here#
The index is not a static number. This is where it would have sat at each capability checkpoint since ChatGPT — reconstructed, and labelled as such.
The rise is the alert queue, which is the same task as a security analyst's and a guard's: very low true-positive rate, human vigilance collapsing within about twenty minutes, and correlation that a machine can check. Financial crime monitoring is among the most heavily automated alert pipelines anywhere for exactly that reason, and evidence logging follows the same path. It flattens because reading a rule is only augmented — the hard half is knowing which of this company's processes a clause lands on — and because refusing the business is held in place by organisational structure rather than by difficulty. The curve cannot see the thing that most decides this job: who the function reports to.
A flat line is not a forecast of safety. It says which tasks automation has reached so far — the occupations that moved least here are the ones where the constraint is physical or regulatory, and both of those can change.
Recent changes#
No verified events recorded yet.
This section will fill from the monitoring pipeline as events are collected, de-duplicated, graded and linked to the tasks above. An empty list here means we have not verified anything — it does not mean nothing is happening.
"We found no news" is not the same as "you are safe."
What this means for you#
This profession grew because regulatory text grew, and the alert queue is how people get in. That rung is the one being automated, and the pattern recognition senior officers rely on was built there. Aim at a specific regime early — one you know deeply — because depth in one regulation is what survives cheap reading of all of them.
Two things decide your position and neither is a tool: who you report to, and whether your refusals are recorded when they are overruled. If the second does not happen, the task exists on paper only, and no amount of technology caused that.
Your options#
Four directions, each with its real constraints and one thing you can test this week. Continuing as you are is a legitimate choice — it just has to be a chosen one.
Go deep in one regime
Cheap reading makes breadth free and depth scarce: the value is in knowing which of this company's processes a clause actually lands on, which requires knowing the processes.
Depth in one regime is less portable between employers than general compliance experience.
Pick one obligation and trace it to the specific system and person that satisfies it. If the trail breaks, that break is your finding.
Own oversight of the automated decisions
Regulation in several markets now requires a named person with competence and authority to oversee a high-risk automated system, and most institutions have not assigned it.
It requires enough technical literacy to challenge a model owner, which most compliance training does not provide.
List the automated decisions in your firm that affect a customer. Then find who is named as accountable for each. The gaps are the job.
Common questions#
The alert queue is the exposed part, and it is the same task as a security analyst's queue and a guard's camera wall — very low true-positive rate, collapsing human vigilance, machine-checkable correlation. Reading regulation is augmented rather than replaced, because the hard half is knowing which of this company's processes a clause lands on. Saying no to the business is held in place by organisational structure, which is why no institution delegates it — and also why it can be removed without any technology.
No date. The two signals that matter are organisational: who your function reports to, and whether a refusal that gets overruled is recorded as such. If compliance reports into the business it polices, the task that looks most durable on paper is the one least real in practice — and that arrangement changes by reorganisation, which is faster than any technology and is announced in a meeting.
For the collection itself, clearly — it is structured logging with a checkable outcome, and nobody thinks a person should be doing it. The risk it creates is specific and worth naming: a complete record of a control that was not actually effective is worse than an incomplete one, because it is harder to challenge. Auditors have begun asking how the record was produced, which is a question the tooling was not designed to answer.
It is creating duties, which is not the same thing until somebody is paid to hold them. Several markets now require a named person with the competence and authority to oversee a high-risk automated system — a real obligation attached to a real person. What this site sees repeatedly is that such duties arrive assigned to nobody and land on whoever already understands both the system and the business consequence. Whether that becomes a post or an unpaid addition to one is decided locally.
Method and sources#
- Assessment date
- 2026-09-14
- Basis of the task judgements
- 0 evidence-backed · 4 platform inference · 0 not enough evidence
- Verified events
- 0