Est.

Building a Compliance Operations Function in a Tax Firm

Reporter · · 12 min read
Cover illustration for “Building a Compliance Operations Function in a Tax Firm”
Compliance Operations · August 3, 2026 · 12 min read · 2,792 words

The compliance workload isn't static, and any operating model built on the assumption that it is will eventually buckle. The OECD BEPS Pillar Two global minimum tax framework, now active in more than 50 jurisdictions as of early 2025 per KPMG, illustrates how fast the rules can move and how far their reach extends. Pillar Two formally targets multinationals with annual turnover above EUR 750 million, but the compliance tail stretches well into the mid-market. Advisers to those companies need to understand the mechanics, smaller firms with international structures are increasingly in scope as jurisdictions expand coverage, and the precedent of transnational compliance coordination is now embedded in the regulatory architecture whether firms are ready for it or not.

The cost is documented. A ZEW study cited by Tax Foundation Europe in October 2024 estimated total recurring annual compliance costs for EU-headquartered multinationals at EUR 517 million. Top-Up Tax mechanics require effective tax rate calculations across every in-scope jurisdiction regardless of whether any additional tax is ultimately owed. For firms advising clients in this space, that distinction matters concretely. It means ongoing data collection, documentation, and reporting across multiple jurisdictions, every year, compounding on itself even in years when no additional liability materializes.

U.S.-based practices carry additional weight. Holland & Knight reported in January 2025 that U.S. firms must still comply with the full Pillar Two Model Rules for 2024 and 2025 before the G7 "Side-by-Side" package takes effect for fiscal years beginning January 1, 2026. TCJA provisions expiring at the end of 2025, the Corporate Alternative Minimum Tax, proliferating state and local nexus rules, and the emerging transfer mechanics for renewable energy credits each represent a discrete obligation requiring monitoring, interpretation, and execution. Bloomberg Tax noted in September 2024 that mid-market businesses are increasingly being pulled into international compliance frameworks designed for large multinationals, without the staffing or systems to absorb them.

Those demands fall disproportionately on whoever is executing routine compliance. The execution layer must be built to absorb regulatory growth without routing every new requirement straight to senior practitioners who are already stretched thin.

Why Hiring Your Way Out of This Isn't Possible

The accounting profession's talent contraction is well-documented, but the scale of it still warrants direct statement. The profession has lost more than 300,000 accountants and auditors over the past three years, a roughly 17% decline since 2020, with an estimated 190,000 to 200,000 open positions across the U.S., according to Madras Accountancy as of April 2025. CPA exam participation is at its lowest level since 2006; the number of candidates sitting for the exam has fallen more than 30% since 2016, per Talentfoot's 2025 reporting. This isn't a cyclical trough. The pipeline has narrowed structurally, and anyone who has tried to staff a mid-size practice over the past two years already knows what that looks like from the inside.

The AICPA has reported that 75% of current CPAs are approaching retirement age, creating an estimated 136,400 annual job openings through 2034. Supply won't recover quickly enough to offset retirement attrition even if exam participation rebounded immediately, which it shows no signs of doing. Finance roles requiring CPA credentials now take an average of 73 days to fill, 41% longer than comparable non-credentialed positions, per Talentfoot. EY's decision to implement a more than 10% salary increase for accountants as part of a $1 billion, three-year talent investment, reported by Auxis in February 2025, signals where compensation pressure is heading across the industry.

The internal consequences are already visible. Public accounting firms were running 15% to 22% annual turnover in 2024. Twelve percent of firms scaled back their client base simply because they didn't have the workforce to serve it, per Rightworks' January 2025 reporting. Academic research cited in CPA Journal in April 2025 connects audit-employee turnover directly to measurable declines in accounting quality — more financial misstatements, more internal control weaknesses. The talent crisis doesn't just create operational strain; it creates downstream quality exposure that clients eventually notice.

Seventy-seven percent of accounting firms are already considering or employing accountants working remotely from other countries, per CFO Dive, as a workaround for domestic supply constraints. A growth strategy built primarily on adding credentialed headcount to absorb compliance volume is slow, expensive, increasingly unreliable, and fragile in ways that don't announce themselves until a filing season goes sideways. The operating model itself must do work that headcount can't.

What a Compliance Operations Function Actually Is. And What It Isn't

The language of "compliance team" already exists in most firms and describes something categorically different from what's needed. A compliance team is a group of practitioners who handle compliance work, typically assembled around seniority and availability, with throughput determined largely by individual effort and whoever happens to be free. A compliance operations function is something else — a deliberate organizational layer with explicit inputs, outputs, service level agreements, quality gates, and role boundaries, one that separates the execution of routine compliance from the judgment-intensive advisory work that requires senior practitioner capacity.

The structural shift is treating compliance execution as a managed workflow rather than as ad hoc work absorbed by whoever is closest to it. Deloitte's framing is useful here — the move from entity-by-entity return preparation toward a unified, process-driven approach, where standardization enables throughput and throughput enables scale without proportional headcount growth.

What the compliance operations function owns is concrete: client intake, document collection and classification, return preparation, data validation, filing coordination, deadline tracking across the portfolio, and the documentation infrastructure that supports audit readiness. Tax strategy, planning advice, effective tax rate forecasting, controversy management, and client relationship decisions stay with senior practitioners. The line between these two layers is governed by the nature of judgment required, not the seniority of whoever is currently doing the work. Without that principle explicitly stated and enforced, every engagement defaults to senior practitioner time, because ambiguity always resolves toward over-caution.

The compliance ops function requires explicit decisions on roles, process handoffs, technology selection, and governance. It doesn't emerge on its own, and firms that expect it to are still waiting.

Venn diagram: Compliance Operations vs. Advisory Work. Compares Compliance Ops and Senior Advisory; overlap: Shared Boundary.

The Role Structure Inside a Compliance Operations Function

The standard hierarchy running from director through managers, officers, and junior staff is a reasonable scaffold, but the compliance ops framing redefines what each level is actually doing rather than merely organizing it by seniority.

The junior layer handles defined, proceduralized tasks: document intake, data entry, preliminary return preparation for standard entity types, checklist-based completeness checks. Clear right and wrong outputs, assignable to staff without extensive experience, reviewable efficiently, and progressively automatable as the function matures. The officer and specialist layer, typically requiring three to five years of experience and ideally holding CPA or EA credentials, owns quality review of outputs from the junior layer, flags exceptions that can't be resolved against the defined standard, and maintains the process documentation that keeps the function consistent as staff turns over. The manager layer oversees preparation and filing across a portfolio, owns process improvement, and monitors legislative changes for their execution implications. The director sets standards, manages risk exposure across the function as a whole, and interfaces with the advisory side of the firm on resourcing and escalation.

The Tax Manager role, typically reflecting seven to ten years of experience and often holding an advanced degree in taxation per Umbrex, sits at the boundary between compliance ops and advisory. This is the role that decides when a matter escalates and who takes ownership on the advisory side. The escalation criteria need to be written down, tested against real engagements, and updated as the regulatory environment shifts. Firms consistently defer this governance work. They consistently regret it.

Two structural advantages follow from this design. Junior and mid-level roles absorb volume, protecting senior practitioner time for matters that genuinely require it. Many specialist and officer roles can also be filled without CPA credentials, which matters considerably in a market where credentialed staff are difficult to recruit and expensive to retain. Co-sourcing and offshore arrangements fit naturally into this architecture, but only when the compliance ops function has processes defined clearly enough to manage remote execution reliably.

How Workflow Design Turns the Role Structure Into Actual Throughput

Role structure alone doesn't produce throughput. In most firms without deliberate workflow design, compliance work arrives unevenly, gets routed to whoever is available, changes hands without defined handoff criteria, and clears no quality gates that are structurally enforced. Throughput becomes a function of system design when workflow is engineered — something that can be optimized, monitored, and scaled regardless of who occupies a given seat.

The workflow begins at intake. Every engagement enters through a standardized process with defined document requirements, a defined completeness checklist, and a defined initial classification before any practitioner touches substantive work. This single structural decision eliminates a significant category of inefficiency — work arriving incomplete, work being touched multiple times before it's ready to process, senior practitioners spending time on document retrieval that belongs in the junior layer. These aren't hypothetical failure modes; they're what compliance workflows look like before someone has actually engineered them.

The stages requiring explicit design include:

  • intake and document collection with defined client-facing deliverables and deadlines
  • document classification and completeness checking, which can be handled by the junior layer or automated against a defined standard
  • return preparation assigned by entity type and complexity rather than by practitioner availability
  • internal quality review structured as a gate with defined criteria rather than open-ended senior oversight
  • filing and deadline management tracked at the portfolio level rather than at the individual engagement level
  • post-filing documentation maintained continuously as an audit-readiness output, not assembled reactively when the need arises

Internal service level agreements, covering handoffs between stages and not only client-facing deadlines, convert a role structure into a functional system. Each stage has a defined completion standard and a defined next recipient. Exception handling requires the same discipline — the workflow needs a documented path for matters that can't be resolved at the current layer, with defined escalation criteria. Without it, exceptions default to senior practitioner time by necessity, and the entire structure starts to leak.

Because filing deadlines and extension periods are known well in advance, the function can model staffing and volume requirements against a calendar in ways that ad hoc compliance teams genuinely can't. Capacity planning becomes a management activity rather than a recurring crisis.

Where Technology Fits. And What It Can Realistically Automate

Technology without process design produces faster chaos. The workflow architecture is the precondition; automation belongs inside a well-defined workflow, not in front of one.

With that precondition in place, several stages of compliance ops work are strong automation candidates. Document intake and classification, including AI-assisted extraction, categorization, and completeness flagging, removes significant mechanical effort from the junior layer and accelerates the time between client submission and work-ready status. Data validation, cross-referencing extracted data against prior-year returns and flagging anomalies before human review, reduces the error rate at the data-handling stage before any practitioner has spent time on the file. Deadline and filing tracking, including extension triggers and jurisdiction-specific requirement monitoring, is calendar and rules-based work that technology handles more reliably than manual tracking across a large portfolio. Regulatory change monitoring can surface relevant legislative developments to the manager layer automatically rather than depending on someone remembering to check.

The EY Tax and Finance Operations survey from 2024 found 54% of tax department leaders rethinking their operating models, with technology cited alongside co-sourcing as a primary driver. The direction of the market isn't ambiguous.

The practical distinction between purpose-built tax workflow tools and generic accounting software matters at volume. Generic tools require customization to handle the entity types, jurisdiction logic, and document structures that are routine in tax compliance. That gap shows up in implementation time, in the brittleness of custom configurations as requirements change, and in the daily friction of working around a tool's limitations. Purpose-built tools carry higher acquisition cost but lower total operational friction over a multi-year horizon. Infrastructure decisions made on shorter timeframes get revisited expensively, usually at the worst possible moment.

What technology doesn't replace is judgment — complex position decisions, client communication, escalation determinations, strategy. The realistic near-term gains from automation are in time-to-completion on routine tasks and in error reduction at the data-handling stages. Technology also makes remote and co-sourced arrangements viable, because standardized digital workflows create the location-independence that paper-based or ad hoc processes never could.

The Operating Model Decision: What to Keep In-House and What to Co-Source

The EY 2024 Tax and Finance Operations survey finding that 54% of tax department leaders are actively reconsidering their operating models, with co-sourcing as the most prominent change under consideration, reflects where market practice is converging. Firms that treat this as a fringe consideration are misreading the environment.

The co-sourcing model, properly structured, works as follows: the firm retains strategy, policy, accountability, and client relationships. A managed services partner handles execution of defined compliance tasks. The compliance ops function is the management layer that makes the arrangement coherent, providing the workflow standards, quality gates, and escalation criteria that allow external execution to be monitored and controlled. Without a well-defined internal compliance ops function, co-sourcing creates a governance gap — the firm has delegated execution without the infrastructure to manage what it's delegated. That gap surfaces under deadline pressure, which is precisely the worst moment to discover it.

The decision isn't co-source versus in-house as a binary. The real question is which stages of the compliance ops workflow are candidates for external execution given the firm's volume, margin, and quality requirements. High-volume, well-defined tasks — data entry, document processing, preliminary return preparation for standard entity types — are strong co-source candidates. Quality review, exception handling, client communication, and anything requiring firm-specific context or judgment stays in-house. Offshore and near-shore staffing arrangements operate under the same logic, with the same dependency on process clarity.

Co-sourcing trades fixed headcount costs for variable delivery costs and introduces third-party risk that the risk management framework must govern. A firm running 15% to 22% annual turnover can't build a sustainable operating model on stable, fully-staffed internal delivery. The model must absorb attrition without service disruption, which means comprehensive process documentation, defined role coverage, and managed external capacity that scales with demand rather than with hiring cycles.

Risk Controls the Compliance Operations Function Needs to Own

The compliance ops function is not only a throughput mechanism. It's the organizational layer where the firm's exposure to filing errors, deadline failures, data handling breaches, and regulatory non-compliance is either managed or quietly compounded.

Data integrity is the foundation. The function handles large volumes of client financial data across multiple stages and multiple handlers, including potentially remote or co-sourced staff. Access controls, data handling protocols, and audit trails are structural requirements. A co-sourced delivery model that hasn't addressed data handling rigorously exposes the firm to regulatory liability and client trust damage simultaneously.

Quality gate enforcement is equally central. The workflow design establishes quality gates, but those gates only control risk if they have defined criteria and are consistently applied. A quality gate bypassed under deadline pressure isn't a control; it's documentation of what should have happened. The function needs clear standards for what passes each gate, who has authority to approve exceptions, and how exceptions are logged and reviewed.

Deadline management at the portfolio level requires systematic tracking. As jurisdiction count and entity volume grow, the failure modes of manual deadline tracking multiply. The function needs a system of record for filing obligations, extension elections, and deadline status, updated in real time and reviewed at defined intervals by the manager layer.

Regulatory change monitoring must feed into the workflow directly. New requirements that are identified but not incorporated into execution checklists, data collection templates, or review criteria represent a genuine risk gap. Identifying a new requirement is only the first step; embedding it into the process is the actual control. The manager layer owns that connection.

The escalation protocol is a risk control as much as it is an operational feature. When a matter requires judgment that exceeds the compliance ops function's defined scope, the escalation path determines whether it receives appropriate practitioner attention or gets handled at the wrong level. Escalation criteria should be explicit, documented, and reviewed periodically against actual escalation patterns. If escalations are implausibly rare, the criteria are too permissive. If they're frequent, the criteria are too conservative or the junior layer doesn't have sufficient training.

A compliance operations function built with these controls makes risk visible, assigns ownership of each risk category to a defined layer of the function, and creates the governance infrastructure to detect and respond to failures before they become client-level problems. Review the escalation criteria and quality gates before peak season, against actual engagement data.

Sources

  1. deloitte.com

More in Compliance Operations