jobmarket.pro
All articles
Interviews

What do compliance officer interviews actually test?

Who sits on the panel, what the case study exercise looks like, and the questions that expose whether you've actually done the job.

Published 21 Sept 2026 · 6 min read

Who actually interviews you

For most compliance roles in financial services, you won't get a generic HR screen and call it done. Expect at least one round with the Head of Compliance or the MLRO directly, because they're the person who has to trust you with decisions that carry personal regulatory exposure under SMCR. If the role is embedded in a business line — say, a compliance monitoring officer covering a trading desk — a desk head or COO from that business often sits in too, partly to check you can hold your ground with revenue-generating staff who don't want to hear the answer is no.

Senior hires (SMF16/SMF17-adjacent roles, or anyone who'll be a certified person under the Certification Regime) sometimes meet a Non-Executive Director or a member of the Risk Committee, because the firm needs to document that the appointment was properly scrutinised — that scrutiny is itself part of what the FCA expects to see if it ever asks how the firm satisfied itself on fitness and propriety.

HR is usually in the process but rarely the one asking the technical questions. If HR is the only person you speak to before an offer, that's unusual for anything above an entry-level KYC analyst role, and worth asking about directly.

The technical or practical assessment

The case study is where most candidates either show they've actually done the work or reveal they've only read about it. Common formats:

  • A scenario walk-through. You're given a client file, a transaction pattern, or a marketing document and asked to identify what's wrong and what you'd do next. A common version: an onboarding file for a client linked to a jurisdiction on the FATF grey list, or a payment pattern that looks like structuring. You're expected to talk through customer due diligence versus enhanced due diligence, when a PEP check should have triggered EDD, and at what point you'd consider a SAR to the NCA rather than just noting it on file.
  • A written exercise. Draft a short breach notification, summarise a policy gap, or turn a piece of regulatory guidance (an FCA Policy Statement, a Consumer Duty update) into a one-page instruction for the front office. This tests whether you can write for a business audience, not just for a file note that never gets read.
  • A mock escalation. You're told a trader has breached a personal account dealing rule, or a suspicious activity has been flagged, and asked to role-play telling the business the outcome isn't negotiable. This is less about knowing the rule and more about whether you visibly flinch under pushback.

Some firms skip the live exercise and instead probe your CV for specifics: which monitoring tools have you actually used — Actimize, NICE Actimize surveillance, World-Check or Dow Jones for screening, a case management system for SARs — and what did you do with the output, not just whether you had access to it.

The questions that are actually testing something

A few questions come up in almost every serious compliance interview in this sector, and they're not small talk — they're checking for specific things.

"Talk me through a SAR you filed where the business disagreed with your decision." This checks independence. A weak answer describes the mechanics of filing. A strong answer describes the conversation with the relationship manager who wanted the client kept, what you said, and what you did when they pushed back — because that tension is the actual job.

"How would you explain risk-based versus rule-based compliance to a new joiner?" This checks whether you understand proportionality or just apply checklists. The FCA has moved firms towards outcomes-focused regulation for years, and an answer that treats every client the same regardless of risk profile suggests someone who's never actually run a monitoring programme with limited resource.

"Describe a time you had to interpret an ambiguous piece of guidance." Regulation is frequently not a clear yes or no — Consumer Duty is a good current example, since it's principles-based rather than prescriptive. This question checks whether you can reason from first principles (treating customers fairly, foreseeable harm) or whether you need a rule written down before you can act.

"What's in your current monitoring plan, and how did you prioritise it?" This checks whether you've actually built or owned a compliance monitoring programme, or whether you've only executed someone else's. Being able to name the thematic areas — financial promotions, complaints handling, conduct risk indicators, CASS if client money is involved — and explain why they were prioritised that way, based on the firm's risk assessment, is the difference between having done the job and having sat near it.

"How do you stay current with regulatory change?" Nearly everyone says they read FCA publications. The question is really asking whether you can name something specific you changed in a policy or process because of a recent development — a Policy Statement, a Dear CEO letter, a Handbook update — rather than a general claim to being informed.

What a shallow answer sounds like

To someone who's actually done this job, a few patterns give away a candidate who hasn't:

  • Reciting the rulebook instead of applying it. "I ensure the firm complies with all applicable FCA regulations" is not an answer to anything. Every candidate is supposed to do that; it says nothing about how.
  • No tension in any story. Real compliance work involves telling people things they don't want to hear. If every anecdote ends with the business happily agreeing, either the candidate has never done the hard part of the job or they're smoothing the story for the interview. Interviewers who've been in the room for actual escalations notice this.
  • Confusing having a policy with the policy working. Saying "we had a policy on X" isn't the same as being able to say how you tested whether it was followed, what the breach register showed, or what you did when monitoring found a gap.
  • Not knowing the difference between reporting lines. A candidate who can't clearly explain who they'd escalate to — line manager, MLRO, board, or directly to the regulator in extreme cases — hasn't internalised how accountability actually works under SMCR, and that's a structural gap, not a minor one.
  • Treating a SAR as paperwork. Describing a suspicious activity report purely as a form to submit, without any account of the judgement call about tipping off, timing, or continuing the relationship in the meantime, tells an experienced interviewer the candidate has processed SARs rather than owned the decision to file one.

What to do before you walk in

Go back through your own casework and find two or three situations where you disagreed with the business and had to hold your position — not situations where compliance and commercial interest happened to align. Be ready to say what you actually did, not just what the policy said you should do.

Know the current live issues for your sector cold: where Consumer Duty implementation actually stands for firms like the one you're interviewing with, any recent FCA enforcement action in a comparable business line, and anything specific to their permissions (CASS, MiFID, e-money) that would shape their monitoring priorities. Generic knowledge of the FCA Handbook is table stakes; knowing what's live for this firm is what separates candidates.

If you're short on interviews rather than short on substance — sending applications into roles that never reply — that's usually a matching problem before it's an interview problem: jobmarket.pro reads the advert in full and prepares the application from your actual casework rather than a generic template, so the fit is visible before you get to the room.

Or stop doing this by hand

An agent that reads each advert in full, tells you where you fit and where you do not, and prepares the application from a profile it cannot invent experience into. Free to start, no card.