OP is 100% correct. The problem is in the process/approach rather than the headcount. My experience is that over 50% of compliance related processes seem to exist solely so that certain teams and executives can justify their own salary/job security/political capital without actually taking any “risk” of the table.
It leads to much wasted time and inefficiency across the entire org as every business line has to deal with all of the red tape and smoke and mirrors. Identifying these redundant and worthless processes would go a long way towards reducing headcount and making the entire organization more efficient.
Unfortunately, this has only become worse as risk and compliance teams have been emboldened by the regulatory scrutiny the company is facing. With the state that things are in now, hard to see that turning around anytime soon as it seems like it would be nearly impossible for anyone in charge to figure out exactly what the he-l all of these teams are doing and why.