Compliance is the process of identifying applicable obligations, assigning ownership, operating controls, detecting breaches, and documenting remediation.
Compliance is the process of identifying the laws, regulations, licence conditions, contractual duties, professional standards, and internal commitments that apply to an organization and then designing, operating, monitoring, and improving controls to meet them. In finance, this can cover market conduct, financial reporting, prudential requirements, anti-money laundering, sanctions, consumer protection, data handling, tax reporting, and fiduciary duties.
Compliance is not proved by having a policy manual or avoiding enforcement action. A credible program connects each applicable obligation to risks, owners, procedures, data, escalation, testing, and evidence that the process works in practice.
| Component | Core question | Evidence |
|---|---|---|
| Obligation inventory | Which requirements apply to each entity, product, activity, and location? | Laws, rules, licences, contracts, interpretations, and mapped owners |
| Risk assessment | How could the organization fail to comply, and with what impact? | Risk scenarios, inherent risk, controls, residual risk, and approvals |
| Policies and procedures | What conduct and decisions are required or prohibited? | Current documents, version history, accessibility, and exceptions |
| Governance and resources | Who owns, challenges, escalates, and funds the program? | Mandates, reporting lines, budgets, skills, and committee records |
| Controls | What prevents, detects, or corrects noncompliance? | Approvals, screening, restrictions, reconciliations, alerts, and logs |
| Training and communication | Who needs which knowledge before acting? | Role-based curriculum, completion, assessment, and targeted updates |
| Monitoring and testing | Does the process operate and remain effective? | Samples, metrics, exceptions, root causes, and independent testing |
| Investigation and remediation | How are concerns resolved and repeated failures prevented? | Case files, findings, discipline, control changes, and validation |
The program should reflect actual operations. Copying another firm’s policy can miss different products, systems, customers, incentives, and legal obligations.
Legal counsel interprets law, advises on rights and obligations, and manages specified legal matters. Compliance translates requirements into ongoing business processes, monitoring, escalation, and evidence. The functions often collaborate but are not interchangeable.
Risk management provides methods for identifying, measuring, treating, and aggregating risk. Compliance applies those methods to legal, regulatory, conduct, and policy obligations while recognizing that some requirements cannot be accepted merely because the expected penalty appears low.
Compliance owns or oversees parts of the program and may conduct monitoring. Internal audit provides independent assurance under its mandate. If internal audit designs or operates a control, its later assurance over that same control can be impaired.
Business leaders remain responsible for compliant activity. The compliance function advises and challenges; it should not become the sole owner of every transaction performed by the first line.
This is a cycle, not an annual certification exercise.
Assume a financial company plans a mobile service that lets small businesses send payments into three new countries. The commercial proposal describes features and revenue but does not yet identify the compliance perimeter.
A defensible launch review could map:
| Risk area | Questions before launch | Illustrative evidence |
|---|---|---|
| Licensing | Which entity provides each service, and where? | Legal analysis, licence conditions, regulator correspondence |
| Customer due diligence | Which customers, owners, and purposes require verification? | Procedures, data fields, test cases, approval rules |
| Sanctions | Which parties, locations, banks, and payment messages are screened? | List sources, matching logic, alert cases, disposition logs |
| Consumer or business disclosures | What fees, rates, timing, and error rights must be communicated? | Approved screens, agreements, version records, testing |
| Funds and settlement | How are customer funds held, reconciled, and protected? | Account structure, daily reconciliation, exception reports |
| Data | Where does information travel and who can access it? | Data map, permissions, retention, vendor terms, incident plan |
| Monitoring | Which transactions or behaviors trigger review? | Scenarios, thresholds, tuning, cases, quality assurance |
If the sanctions-screening test environment uses incomplete country and ownership data, a signed policy and completed training do not make the control effective. The launch decision should record the gap, interim restriction, accountable owner, evidence required, and approval authority. Applicable law determines whether launch can proceed; a risk rating cannot waive a legal prohibition.
A control description should identify:
“Management reviews compliance” is too vague to test. “The regional compliance officer reviews every high-risk onboarding exception before account activation, records the evidence and rationale in the case system, and escalates unresolved sanctions matches” is more testable.
Automation does not remove ownership. Rules, models, artificial intelligence, and vendor systems require approved inputs, access controls, versioning, validation, monitoring, explainability appropriate to use, and a process for errors and overrides.
Monitoring is ongoing or frequent review of activity, such as transaction alerts or approval exceptions. Compliance testing samples or re-performs controls to assess design and operation. Internal audit independently evaluates governance, risk management, and controls under its mandate. Regulatory examination applies the authority’s own scope and standards.
One activity cannot automatically substitute for another. A dashboard showing low exception counts may indicate effective prevention, missing data, an overly permissive rule, or underreporting. Review denominators, data completeness, false negatives, aging, and outcome quality.
| Metric | Useful question | Misleading interpretation |
|---|---|---|
| Training completion | Did assigned personnel complete required modules? | Completion proves understanding or compliant conduct |
| Alert volume | What activity meets configured scenarios? | More alerts mean more misconduct |
| Case aging | Are reviews and escalations timely? | Fast closure means high-quality decisions |
| Repeat findings | Are root causes and remediation effective? | Every repeat issue has the same severity |
| Exception rate | How often does a process depart from policy? | A low rate proves controls are effective |
| Speak-up reports | Are concerns reaching the organization? | More reports mean culture is worse |
| Remediation closure | Were planned actions completed? | Closure proves sustained operating effectiveness |
Metrics should connect volume, severity, timeliness, outcome, population, and data quality. Incentives based on one count can encourage superficial closure or nonreporting.
When a concern arises, determine who can investigate independently, which information must be preserved, what legal or privilege issues apply, and which governance or authorities require notice. Protect against retaliation and restrict information only as necessary for a fair process.
Remediation should address the immediate issue and root cause. Possible causes include unclear ownership, weak incentives, missing data, override access, poor vendor design, inadequate staffing, conflicting targets, or ineffective supervision. Validate the new control after enough transactions or time have passed to observe its operation.
The U.S. Department of Justice’s compliance guidance is designed for prosecutorial evaluation, not as a universal legal safe harbor. Its three broad questions are nevertheless useful analytical prompts:
Evidence should be proportional to the organization’s risks and circumstances. A program can fail to prevent one violation and still contain meaningful controls; conversely, absence of a detected violation does not prove the program is effective.
Treating compliance as policy publication. Controls, data, decisions, monitoring, and remediation matter more than document count.
Using generic training for every role. Front-line sales, finance, engineers, directors, and investigators face different decisions.
Assigning all risk to compliance staff. Business owners remain accountable for the activity they perform.
Counting alerts instead of testing outcomes. Poor data or thresholds can make a quiet dashboard dangerous.
Closing remediation when a procedure is written. Design, implementation, and sustained operation are separate stages.
Applying one jurisdiction’s rules globally. Product, entity, customer, location, and licence determine the obligations.
This article provides general financial-compliance education, not legal, regulatory, enforcement, employment, privacy, tax, or investment advice. Obtain current advice for the relevant entity, activity, and jurisdiction.