The first condition for any compliance programme is leadership support. If senior management bypasses the rules, no structure or policy, however well drafted, will help.
1 The six components
Tone from the top
Board and senior management support
Policy and mandate
An approved document and clear authority
Risk assessment
Where is the likelihood of breach highest?
Training and awareness
So every employee knows their limits
Whistleblowing
A safe channel for early warning
Monitoring and reporting
Periodic testing and reporting to the committee
Six complementary components — a weakness in one weakens the whole programme
2 Independence of the compliance function
For a compliance officer to do the job, three things are needed: access rights to information and people, an independent reporting line to a committee or board rather than to the person being monitored, and job protection, so that an uncomfortable report is not punished.
A conflict to avoid
Assigning compliance to whoever runs the activity itself — for instance making the sales director responsible for monitoring sales compliance. The result: reassuring reports, every time.
3 Compliance risk assessment
Effort is not spread evenly; it follows the risk. So each compliance area is assessed on two criteria: the impact of a breach and its likelihood — exactly as in risk management.
| Area | Impact of breach | Likelihood | Level of monitoring |
|---|---|---|---|
| Returns and their deadlines | High | Medium | Monthly tracking + alerts |
| Employee contracts and wages | High | Low | Quarterly sample check |
| Protection of customer data | Very high | Medium | Semi-annual control testing |
| Gifts and hospitality | Medium | High | Gift register + periodic reminder |
4 Training and awareness
- General, for all staff: code of conduct, conflicts of interest, whistleblowing, data protection.
- Role-specific: finance on tax, HR on labour law, sales on conduct in dealings.
- At hiring and before taking on sensitive duties — not a year later.
- With real examples rather than dry legal text — people remember the case, not the article number.
- With a short assessment that demonstrates understanding and serves as documented evidence.
An organisation with twenty-five employees does not need a full compliance department, but it needs the same programme on a smaller scale:
| Component | The form that fits its size |
|---|---|
| Responsibility | Assigned part-time to a qualified administrative manager reporting to the CEO and the owner |
| Policies | Three short policies: conduct, conflicts of interest, whistleblowing |
| Requirements register | A single table with twenty to thirty obligations |
| Training | A two-hour annual session + a quarterly email reminder |
| Whistleblowing | A dedicated mailbox reaching the owner directly |
| Reporting | A one-page quarterly report: what was done, what is late, what needs a decision |
The principle of proportionality
The programme is built to the scale of the activity and its risks. Copying a large bank’s programme into a small workshop produces paperwork nobody reads — and that is failure wearing the costume of compliance.
Lesson summary
- The programme has six components, beginning with leadership commitment and ending with reporting.
- The compliance function needs access, an independent reporting line and job protection.
- Effort is allocated by compliance risk assessment, not spread evenly.
- Training happens at hiring, uses real examples, and leaves documented evidence.
- Proportionality: the size of the programme matches the size of the organisation and its risks.
5 Test your understanding
Three quick questions
Pick the answer you believe is correct and you will see the result immediately.
1. What is the most important condition for a compliance programme to succeed?
When leadership bypasses the rules, everyone understands the rules are for show, and no structure helps after that.
2. Whom should the compliance officer report to?
An independent reporting line protects the report from being filtered and protects the officer from pressure.
3. A small organisation copied a large bank’s compliance programme. What is wrong?
A programme is tailored to the activity and its risks; otherwise it becomes paperwork that is never applied.