Compliance is an organisation’s adherence to the laws, regulations and instructions that apply to it, and to the policies, contracts and professional standards it has committed itself to — together with the ability to prove that adherence with evidence.
1 The two kinds of compliance
| Mandatory compliance | Voluntary compliance | |
|---|---|---|
| Source | Laws, regulations and regulator instructions | The organisation’s own policies, contracts and professional standards |
| Effect of breach | Fine, suspension or legal liability | Contractual or disciplinary breach, or loss of accreditation |
| Examples | Tax returns · labour law · data protection | Code of conduct · client requirements · ISO certification |
2 Where does compliance sit among its siblings?
Governance
Sets the rules and who decides
Risk
Surfaces what could obstruct the objectives
Compliance
Turns the requirement into daily practice
Audit
Independently verifies that the above works
Four complementary functions — the first three are known worldwide as GRC, with audit as an independent line of assurance
The difference in one line
Risk asks: what could happen? · Compliance asks: what does the law require of us? · Audit asks: is what we said we do actually happening?
3 The cost of non-compliance
- Direct financial: fines, penalties and late-payment interest.
- Operational: a service or licence suspended, or an activity frozen until corrected.
- Contractual: losing clients who require documented compliance.
- Reputational: a single news story can cost many times the fine.
- Personal: liability that may reach board members or the responsible officer.
An organisation files a return late because the responsible employee was tied up elsewhere. The fine may look like “an amount you pay and move on”, but the real effect is wider: the organisation’s rating with the regulator is affected, it may face closer scrutiny later, and additional disclosure may be demanded when seeking financing or bidding for tenders.
The simple control that would have been enough: an obligations calendar carrying every statutory deadline with its date, an alert two weeks ahead, and a named backup for every task.
4 Who is responsible for compliance?
The compliance function builds the framework, monitors and reports, but execution is the responsibility of every department in its own area. Finance owns tax compliance, HR owns labour law, and IT owns data protection. Compliance enables, verifies and escalates — it does not act on their behalf.
A common misconception
“Compliance slows the business down.” In truth it is late compliance that slows things down: an activity suspended, work redone, or a retrospective fix. Early compliance is built into the process and is barely noticed.
Lesson summary
- Compliance: adherence to what the law requires of the organisation and to what it has voluntarily committed to, with the ability to prove it.
- Two kinds: mandatory, sourced from legislation, and voluntary, sourced from the organisation’s own policies and contracts.
- Governance sets the rules, risk surfaces the possibilities, compliance translates the requirements, and audit verifies.
- The cost of non-compliance is financial, operational and reputational — and can be personal.
- Execution belongs to each department; the compliance function builds, monitors and escalates.
5 Test your understanding
Three quick questions
Pick the answer you believe is correct and you will see the result immediately.
1. An internal code of conduct the organisation wrote for itself. Which kind of compliance?
What an organisation commits to voluntarily becomes internally binding, and adherence to it is measured just as statutory adherence is.
2. Who is responsible for adhering to labour law inside the organisation?
Execution belongs to the area owner; compliance sets the framework, verifies, and escalates when there is a breach.
3. Which question belongs specifically to the audit function?
Audit provides independent assurance that what was said to be in place is in fact in place and effective.