For many investment firms, the answer to a seemingly straightforward question can reveal a much larger governance issue:
Where do your compliance rules actually live?
Ask different teams and you may get different answers.
Some rules live in policies and procedures, while others exist in spreadsheets maintained by compliance. The order management system (OMS) may contain another set of rules, with additional logic residing inside portfolio management, trading, or surveillance platforms. Meanwhile, institutional knowledge may fill the gaps.
For many firms, the OMS has gradually become the closest thing they have to a central repository for investment compliance rules.
There are understandable reasons for this.
Order management systems sit at the center of critical trading workflows. They can evaluate transactions against investment guidelines, flag potential violations, support pre-trade and post-trade controls, and provide compliance professionals with visibility into trading activity.
Those capabilities are essential.
However, they raise a different question:
Should a system designed primarily to facilitate investment and trading operations also serve as the firm’s system of record for compliance governance?
For many CCOs and COOs, the answer deserves closer examination.
An OMS may be extremely good at performing the functions it was designed to perform. That doesn’t necessarily make it the right architecture for governing the complete universe of compliance rules a modern investment organization needs to understand, document, own, change, test, and defend.
The issue isn’t whether firms should stop using their trading systems.
It’s whether compliance should be dependent on them.
An OMS and a Compliance Governance Platform Solve Different Problems
Order management systems are critical infrastructure for investment managers.
Their primary purpose is operational: helping investment teams manage orders and supporting the trading process.
Over time, these systems have also developed sophisticated compliance capabilities. For example, firms can configure rules to identify restricted securities, concentration limits, investment guideline violations, exposure thresholds, and other conditions relevant to the investment process.
That’s valuable.
However, investment compliance extends far beyond transaction-level monitoring.
A CCO may be responsible for regulatory requirements involving:
- Personal trading
- Marketing and advertising
- Books and records
- Conflicts of interest
- Gifts and entertainment
- Political contributions
- Code of ethics requirements
- Cybersecurity
- Privacy
- Vendor oversight
- Business continuity
- Regulatory reporting
- Valuation
- Custody
- Employee certifications
- Policies and procedures
- Supervisory processes
- Regulatory change management
Only a subset of that universe naturally belongs within a trading platform.
That creates a fundamental architectural question:
Should the firm’s compliance framework be organized around the boundaries of its trading technology, or should compliance have infrastructure designed around its own responsibilities?
For sophisticated firms, those are increasingly different things.
The Difference Between Executing a Rule and Governing a Rule
A trading system may be capable of executing compliance logic extraordinarily well.
For example:
If security X appears on a restricted list, prevent the trade.
Or:
If this transaction would cause the portfolio to exceed a concentration threshold, generate an alert.
Those are clear, executable rules.
But the CCO’s responsibility doesn’t necessarily begin or end with whether the rule fired correctly.
Compliance may also need to know:
- Why does this rule exist?
- Which regulatory, contractual, or internal requirement does it support?
- Who approved the interpretation?
- Which portfolios or entities does it apply to?
- Who owns the rule?
- When did someone last review it?
- Has its logic changed?
- Who authorized that change?
- How did the firm test it?
- What exceptions have occurred?
- What documentation supports the firm’s current interpretation?
Those are governance questions, not trading questions.
And that distinction matters.
The SEC’s Compliance Rule, Rule 206(4)-7, requires registered investment advisers to adopt and implement written policies and procedures reasonably designed to prevent violations of the Advisers Act and its rules and to review the adequacy and effectiveness of those policies and procedures at least annually.
That responsibility is much broader than maintaining automated trading restrictions.
Instead, it requires firms to think about compliance as a governance framework.
Your Trading System Shouldn’t Define Your Compliance Universe
One of the risks of relying heavily on an OMS for compliance management is subtle.
Over time, the technology can begin defining the boundaries of the compliance program.
If teams can configure a requirement within the OMS, it becomes highly visible. If they can’t, they may manage it somewhere else.
As a result, the firm can develop a fragmented compliance architecture.
Trading restrictions may live in the OMS, while policies reside in a document management system. Compliance teams may track regulatory obligations in spreadsheets and testing in yet another platform. Meanwhile, exceptions may move through email or ticketing systems, with institutional knowledge connecting everything together.
Each individual system may work.
The challenge is understanding the relationships between them.
For a CCO, the important question isn’t simply:
“Did the trade pass the compliance check?”
It is also:
“Can I demonstrate how our rules, policies, controls, ownership, testing, and evidence fit together?”
An independent compliance system of record is designed to answer the second question.
Independence Creates Governance Resilience
There is another reason CCOs and COOs should think carefully about where compliance rules reside: technology independence.
Trading platforms change over time. Firms migrate between systems, organizations merge, and business units consolidate. In addition, new asset classes may require different technology. A firm might acquire another manager with a completely different trading stack, or an OMS vendor may change its product architecture or strategic direction.
When the firm’s compliance knowledge is deeply embedded within a particular trading platform, those changes become compliance events as much as technology events.
The organization must then determine what rules exist, why they exist, which configurations matter, and how teams should recreate them elsewhere.
That creates unnecessary dependency.
An independent compliance system of record changes the architecture.
Instead of:
Compliance framework → trading platform
the model becomes:
Compliance framework → systems that execute relevant controls
Under this model, compliance retains ownership of the framework.
Trading systems, meanwhile, become execution environments for the subset of rules they are best suited to enforce.
That separation can make the compliance program more resilient as technology changes.
Compliance Rules Are Enterprise Assets
One of the most important mindset shifts for CCOs and COOs is recognizing that compliance rules aren’t simply configurations.
They’re institutional knowledge.
Consider an investment restriction implemented years ago.
The logic embedded in the OMS may tell you what the system currently checks.
But does it tell you why?
Perhaps the restriction came from a regulatory requirement or reflects a client mandate. Maybe it resulted from a previous examination finding. In other cases, the compliance committee may have adopted a more conservative interpretation than strictly required, or a previous CCO may have made a risk-based decision after consulting outside counsel.
That context matters.
Without it, the firm possesses the rule but risks losing the reasoning behind it.
Over time, that can create significant key-person risk.
For example, the people who originally implemented the control may leave. A new compliance professional might see the configuration without understanding why it exists. Later, someone could modify the logic without understanding the original rationale.
Eventually, the institutional knowledge disappears even though the rule itself remains.
A compliance system of record should preserve both.
The CCO Needs a Different View Than the Trader
This is another area where “fit for purpose” matters.
Different users need different views of compliance.
A trader needs to know whether an order can proceed. A portfolio manager may need to understand a restriction affecting a particular mandate, while an operations team may need to resolve an exception.
The CCO, however, needs a much broader view.
Compliance leadership needs visibility into:
- What obligations apply across the firm
- Where those obligations originate
- How the firm has interpreted requirements
- Which controls support them
- Which systems execute those controls
- Who owns them
- Whether teams have tested them
- Which issues remain unresolved
- What has changed
- Where evidence exists
A trading platform naturally organizes information around portfolios, orders, transactions, and investment activity.
By contrast, a compliance governance platform should organize information around obligations, rules, controls, ownership, evidence, and accountability.
Neither model is inherently better.
They’re designed to solve different problems.
Rule Ownership Should Belong to Compliance
For CCOs, there is also a governance principle at stake.
Compliance should understand and maintain ownership over the firm’s compliance framework, even when technology teams or third-party platforms implement portions of it.
That doesn’t mean compliance professionals need to configure every technical rule themselves.
Rather, the firm should maintain an authoritative record independent of the systems performing individual controls.
Imagine that the OMS contains 800 configured rules.
A CCO should be able to determine:
- How many are currently active?
- Which regulatory or contractual obligations do they support?
- Which have changed during the past year?
- Who reviewed those changes?
- Which rules have generated repeated exceptions?
- Which rules have not triggered in three years?
- Which were inherited through an acquisition?
- Which should be retired?
If answering those questions requires extracting data from the trading system and manually reconstructing the context, the firm may have rule execution without true rule governance.
Change Management Exposes the Difference
The distinction becomes particularly obvious when something changes.
Suppose a new regulatory interpretation affects an existing investment compliance requirement.
A trading-centric workflow might look like:
Identify change → modify OMS rule → test configuration → deploy
However, a governance-centric workflow is broader:
Identify regulatory change → assess applicability → document interpretation → identify affected rules → identify related policies and controls → assign ownership → modify relevant systems → test → approve → document evidence → monitor
The OMS remains important.
It simply becomes one component within a larger governance process.
This distinction aligns with the SEC’s broader expectations for adviser compliance programs. In its 2026 Examination Priorities, the Division of Examinations continues to focus on whether adviser policies and procedures are reasonably designed for firms’ operations and whether firms actually implement and enforce them.
For a CCO, therefore, demonstrating the governance surrounding a control can be just as important as showing that the control exists.
What Happens During an Examination?
Consider the difference from an examination perspective.
An examiner asks about a particular compliance requirement.
A firm relying primarily on its trading system might demonstrate:
“Here is the rule configured in our OMS.”
That’s useful evidence.
However, the next questions may be harder:
- Why is the rule configured this way?
- Which requirement does it address?
- When did the firm last review the interpretation?
- Who owns it?
- When did the logic last change?
- Who approved the change?
- How did the firm test it?
- Does the same requirement affect any other systems or policies?
- Did the firm identify exceptions?
- How did teams resolve them?
An independent compliance governance system creates the possibility of answering those questions from a connected record.
The firm can move from:
Requirement → interpretation → rule → control → system → owner → testing → exception → remediation → evidence
The OMS can still demonstrate that the trading control operated.
The compliance platform, however, demonstrates why that control exists and how the firm governs it.
The Same Principle Applies to Annual Reviews
This distinction becomes especially valuable during annual compliance reviews.
The SEC has emphasized that advisers’ annual reviews should consider the adequacy and effectiveness of their policies and procedures, including changes in business activities and regulatory developments. SEC guidance on annual review requirements has also highlighted the importance of reviewing how compliance programs operate in practice.
For a CCO, the annual review shouldn’t require reconstructing the compliance environment from multiple operational platforms.
Instead, an independent compliance system of record can provide visibility into what changed throughout the year, including:
- New regulatory requirements
- New or modified rules
- Changes in ownership
- Control updates
- Testing results
- Exceptions
- Remediation
- Policy revisions
- Business changes
- Technology changes
Rather than asking, “What happened this year?”
Compliance already has the record.
When the OMS Changes, Compliance Shouldn’t Have to Start Over
For COOs in particular, this is an important operational consideration.
Technology architecture evolves.
An investment firm may eventually replace its OMS, consolidate platforms after an acquisition, adopt a specialized system for a new asset class, or move certain investment operations to another provider.
Those projects are already complex.
Moreover, they become even more difficult if the firm’s compliance knowledge is inseparable from the legacy system.
An independent compliance system of record creates continuity.
The firm can maintain its authoritative rule inventory, regulatory rationale, ownership, history, and governance outside the execution platform.
Then, when technology changes, the question becomes:
“How do we implement our compliance framework in the new system?”
rather than:
“What exactly was our compliance framework in the old system?”
That is a significant difference.
What Should a Fit-for-Purpose Compliance Platform Provide?
For CCOs and COOs evaluating their current architecture, the question shouldn’t necessarily be whether the OMS has compliance functionality.
Most sophisticated trading platforms do.
Instead, the better question is whether the firm has a compliance governance environment independent of any single operational platform.
A fit-for-purpose compliance management platform should help the organization:
- Maintain an authoritative inventory of compliance rules and obligations
- Document the source and rationale behind each rule
- Map rules to policies, controls, portfolios, entities, and systems
- Assign clear ownership
- Maintain change history
- Track approvals
- Connect testing and evidence
- Identify exceptions and remediation
- Understand downstream impact when requirements change
- Preserve institutional knowledge
- Support annual reviews and examinations
- Maintain continuity when operational technology changes
Most importantly, it should give compliance its own view of the organization.
Not a trading view with compliance added.
A compliance view by design.
Independence Doesn’t Mean Isolation
An independent compliance platform shouldn’t become another silo.
Quite the opposite.
Its value comes from connecting the compliance framework to the systems that execute it.
The OMS remains part of that architecture. In addition, surveillance tools, portfolio management systems, document repositories, HR platforms, risk systems, regulatory intelligence tools, and other enterprise technology may all play important roles.
The goal isn’t to duplicate everything those systems do.
Instead, the goal is to establish an authoritative governance layer above them.
Think of it this way:
Operational systems execute.
Compliance governance explains, connects, and evidences.
Large investment organizations need both.
Ask a Better Question About Your Compliance Technology
For years, firms have asked:
“Does our OMS support compliance?”
For CCOs and COOs thinking about the next generation of compliance architecture, however, there may be a more important question:
“Does compliance have a system of its own?”
A trading platform can be excellent at enforcing investment restrictions and still not be the appropriate system of record for the firm’s entire compliance framework.
That’s not a failure of the OMS.
Rather, it’s a recognition that the responsibilities of modern compliance have expanded beyond the boundaries of the trading workflow.
Compliance rules need context, ownership, and history. They also need clear relationships to policies and regulatory obligations, along with testing and evidence.
Furthermore, the compliance framework needs to survive technology changes, personnel changes, acquisitions, and organizational restructuring.
Most importantly, compliance rules need to remain owned by the compliance organization responsible for defending them.
For CCOs and COOs, that is what fit for purpose should mean.
Give Compliance a System of Its Own
Your OMS plays a critical role in your investment operations. It shouldn’t have to serve as your entire compliance governance infrastructure too.
TillieStar gives investment compliance teams an independent environment for managing the rules, obligations, ownership, documentation, and governance that sit behind their compliance program.
By separating the compliance system of record from the systems that execute individual controls, firms can preserve institutional knowledge, strengthen traceability, improve change management, and maintain greater control over their compliance framework as technology and regulatory requirements evolve.
Your trading system was built to manage trading. Your compliance team deserves technology built for compliance.
Ready to evaluate whether your current compliance architecture is still fit for purpose?
Contact TillieStar at sales@tilliestar.com or (617) 865-3550 to start the conversation.