Blackstone Alternative Credit Advisors did not lack for legal talent when the SEC came calling in January 2025. It lacked, along with eleven other firms swept up in the same enforcement action, adequate recordkeeping controls. The result was over $63 million in combined penalties across the group. None of those firms decided that month to finally build out a compliance function. They decided it the month before, when the exam letter arrived, which is to say: too late to matter for the fine, and just in time to matter for the next one.
This is the pattern. A company runs lean on compliance because compliance produces no revenue and no product. Then something breaks: a whistleblower, an exam, a subpoena. Only then does the board authorize a Chief Compliance Officer search, at exactly the moment when the company has the least leverage to negotiate salary, the least time to vet candidates, and the most exposure if the hire goes wrong.
The cost of getting it wrong is not symmetrical with the cost of getting it right
A mid-size company hiring a competent CCO will pay somewhere between $140,000 and $220,000 a year. A company that hires the wrong one, or hires too late and then has to unwind the mess, faces a different number entirely: failed CCO hires cost 2.5 to 15 times annual salary, which puts the downside at $350,000 to $3.3 million per bad hire. That range includes severance, remediation, regulatory penalties, and the cost of running a second search under worse conditions than the first.
The asymmetry is the whole argument. Nobody budgets for a $3.3 million failure. Everybody budgets, reluctantly, for a $180,000 salary line. The math only looks expensive if you stop at the salary and never price the alternative.
And the alternative is not hypothetical. Individual compliance officers are now personally exposed. In July 2025, two CCOs faced personal fines and multi-year industry bars for falsifying and backdating compliance records. That is not a company absorbing a fine and moving on. That is a named individual, barred from the industry, for a decision made under pressure to make the paperwork match the promise. Regulators are not just fining the firm anymore. They are ending careers, which changes who is willing to take the job and under what terms.
The hiring market is not cooperating
Even a company that decides, today, to hire proactively runs into a supply problem. The average CCO search takes approximately 105 days, more than three months of a board hoping nothing goes wrong while the seat sits empty. That timeline assumes the company is searching from a position of calm. Searches that start after an enforcement action move faster and worse: candidates know they're walking into a cleanup job, and price accordingly, or decline.
The pipeline itself is thin. The U.S. Bureau of Labor Statistics projects 33,300 compliance officer openings a year on average from 2024 to 2034, and the senior-level pipeline, the people actually qualified to sit in the CCO chair and answer to a board, is nowhere near sufficient to fill those slots, according to the Ncontracts 2026 Future of Compliance Survey of more than 180 banks, credit unions, and mortgage companies cited in that same reporting.
Pedigree drives price sharply in this market. Compliance officers from Top 50 law schools earn 55% more than those from schools ranked 100 or below, and candidates with Am Law Top 50 law firm experience earn 85% more in total compensation. That is the market pricing scarcity, not necessarily competence. It also means the qualified candidates know their leverage. Companies that wait to hire until after a failure are negotiating against candidates who have seen this movie before and know the desperate buyer pays more.
And the people already in the seat are not staying. 56% of current CCOs are considering a job change in the coming year, according to the BarkerGilmore 2025 CCO Compensation Report. A role with over 50,000 incumbents nationally, per Bright Defense's count of currently employed chief compliance officers, and more than half of them looking for the exit, is not a role you can staff on short notice. It is a role you staff early, or you compete for scraps later.
The case against hiring one, stated plainly
The strongest argument against all of this is that most companies do not need a standalone CCO at all. Below a certain revenue or regulatory-risk threshold, the workload does not justify a dedicated C-suite seat. A senior compliance director reporting into the General Counsel or the COO can carry the load at a fraction of the cost, and plenty of large, publicly traded companies run this way successfully. Cisco is the standing example: Mark Chandler has held both the General Counsel and Chief Compliance Officer titles simultaneously, and Cisco has not suffered for it.
There is a cost argument buried in here too. Firms consolidating compliance under the legal function are, in part, betting that the CCO labor market is overheated, that the compensation premiums described above (the 55% law school bump, the 85% Am Law premium) reflect scarcity pricing rather than genuine value, and that a company can get 80% of the function for 50% of the price by folding it into an existing legal hire. This is not a fringe position. 28% of organizations still assign compliance oversight to their Chief Risk Officer rather than building a standalone CCO role, according to the Hyperproof IT Risk and Compliance Benchmark Report cited by Bright Defense.
This case is strongest for companies that are privately held, operate in a single lightly regulated jurisdiction, and have no history of examination findings. For a fifty-person software company with no broker-dealer registration, no health data, and no government contracts, a standalone CCO is very likely a wasted seat. The compliance workload for that company is a Tuesday for a good legal director.
Where the case against breaks down
The Cisco model works because Cisco built it deliberately and staffed it with someone capable of running both functions at scale, not because combining the roles is free of tradeoffs. The model fails at exactly the moment described at the top of this piece: when the regulatory exposure grows faster than the org chart does. The Hyperproof data that shows 28% of firms still routing compliance through the CRO is paired with a harder number from the same report: 38% of risk and compliance leaders identified expanded responsibilities without additional resources as an increasing internal challenge in 2026. That is not a stable equilibrium. That is a function being asked to do more with a structure built for less, and it is exactly the condition under which recordkeeping lapses happen, exam findings pile up, and boards suddenly discover they need a CCO by Friday.
There is also a detection problem that the consolidation argument does not answer well. SEC examiners are not finding these gaps at the margins. They identified employment screening violations in 23% of investment adviser examinations conducted in 2024. Nearly one in four exams turned up a failure in a category that a dedicated compliance function exists specifically to catch. A General Counsel splitting attention between litigation strategy and compliance monitoring is structurally more likely to miss the kind of finding that shows up in a screening audit than a compliance officer whose entire job is that audit.
The condition that decides it
The honest answer is that this is a threshold question, not a universal rule. A company with no regulatory examinations in its future, no broker-dealer registration, no fiduciary duty to third-party capital, and a General Counsel with real bandwidth can run combined for years without incident. The moment any one of those conditions changes, registered investment adviser status, a banking charter, a government contract requiring FAR compliance, the math flips, and it flips fast, because the 105-day search clock does not start until the board admits it needs to.
The founders and boards who benefit from waiting are the ones optimizing this year's budget over next year's liability. The ones who benefit from hiring early are everyone downstream: the shareholders who do not want a $3.3 million write-down, the employees who do not want their company's name in an SEC release, and, not incidentally, the General Counsel who does not want to be doing two demanding jobs badly instead of one job well.
The decision is not whether compliance costs money. It always does. The decision is whether you pay for it as a line item you chose, or a penalty you didn't see coming.