Standish Compliance
Standish Compliance is a private-fund specialist offering customized program administration, reviews, surveillance, ethics and AML/KYC operations, regulatory reporting, SEC registration, examination support, outsourced deputy CCO service, training, special projects, and cybersecurity work. Engagements are designed around the manager's structure, risks, internal resources, and investor expectations.
Overview
Standish Compliance is a specialist serving private-fund managers, including private-equity, hedge, venture-capital, real-estate, energy, credit, and other alternative strategies. Its offering ranges from construction and administration of an RIA compliance program to independent reviews, surveillance, regulatory reporting, examinations, outsourced deputy CCO work, AML/KYC, and cybersecurity.
The firm was previously known as Core CCO and now operates within Standish Management. Its compliance pages describe a dedicated client team and continuing relationships tailored to the manager’s business, conflicts, culture, personnel, and registration status.
Who it may suit
Standish may suit an emerging private-fund adviser building its SEC framework or an established manager seeking more external operating capacity. The service menu can support an internal CCO through administration or a deputy CCO, while preserving the need to define the named CCO’s authority and the responsibilities retained by management.
It may also fit managers with strong in-house resources that need a targeted annual review, mock exam, marketing or communications surveillance, cybersecurity assessment, or another high-risk project. The company says it accepts a selective group of clients, so mutual fit and available capacity are threshold questions.
RIA compliance services
Program work includes risk-based manuals, ethics codes, policies, controls, disclosures, calendars, checklists, meetings, and recurring task administration. Review services cover marketing and investor communications, email and social channels, portfolio or trading activity, best execution, proxy voting, vendors, employee personal activity, gifts, political contributions, and other conflicts.
Standish offers annual Rule 206(4)-7 reviews, staff and CCO training, AML/KYC design and operation, sanctions screening, due diligence, regulatory-reporting analysis, registrations, and filings through IARD and EDGAR. Examination services include preparation, document production, interviews, regulator interaction, deficiency responses, and remediation. The menu also includes mock exams, policy projects, SEC registration, outsourced deputy CCO support, and cybersecurity governance and technical testing.
How the engagement works
Each client receives a consistent team that learns the business and assembles a customized service package. Managed assignments may include regular meetings and hands-on completion of program tasks; project clients can purchase independent testing, registration, cybersecurity, or another defined review.
The public pages do not give prices, package boundaries, service levels, staff allocation, or technology costs. Counsel is mentioned in connection with some filings, so the scope should state when Standish advises, administers, or coordinates with separately engaged lawyers.
What stands out
Private-fund specialization is the central distinction. The service inventory addresses fund-specific operational areas and investor scrutiny alongside baseline Advisers Act obligations.
The combination of ethics administration, financial-crime controls, communications surveillance, deputy CCO support, and technical cyber testing could reduce the number of providers involved. Buyers should still test whether integration produces clear accountability rather than overlapping roles.
What to clarify before contacting
Outline every adviser and fund entity, exemption, strategy, regulator, service provider, jurisdiction, and reporting obligation. Request a responsibility matrix for the CCO, deputy, management, counsel, administrator, internal technology team, and Standish personnel, including approvals and regulator communications.
Confirm meeting cadence, staff continuity, submission authority, testing methods, findings, remediation, records, response standards, on-site work, and termination assistance. Separately identify platform licenses, AML data sources, surveillance tools, penetration testing, vendor access, incident work, travel, special projects, insurance, confidentiality, and fees.