What Is Compliance Management?

The process that turns an obligation into policy, controls and evidence: who is responsible, how it differs from internal audit, what a programme contains.

Compliance management is the work of identifying the legal and regulatory obligations that bind an organisation, translating them into internal rules, supervising how they are applied, and making all of that provable. The last word is the decisive one: compliance is shown, not described. The question in an examination is not "did you do it" but "how do you show that you did".

The three lines of defence

In regulated organisations responsibility is commonly split across three lines. The split explains why compliance sits apart from both the business and internal audit.

LineWhoResponsibility
FirstBusiness unitsOwn and manage the risk inside the daily work
SecondCompliance and risk managementBuild the framework, oversee it, guide the first line
ThirdInternal auditIndependently test whether the first two lines work

A common mistake is running compliance as though it were the third line. Compliance does not audit; it builds and oversees. Auditing the arrangement it designed itself removes the independence the third line exists to provide.

What a compliance function does

The work reduces to four steps. Detect: catch the new or amended obligation — this step is regulatory tracking. Interpret: assess whether it binds the organisation and what it requires. Apply: update policy, procedure and control, and set an owner and a deadline. Evidence: document what was done and keep it ready for examination.

In regulated sectors the existence, independence and reporting line of the compliance function are set out in the rules governing that sector, and where the function reports is the most concrete indicator of its independence.

What a compliance programme contains

An obligation inventory, written policies and procedures, a control library with periodic assessment, training and awareness, a breach reporting channel, evidence retention and an audit trail, and regular reporting. None of these is compliance on its own; the programme is the connection between them. It must be traceable which control satisfies which obligation, and when that control was last assessed.

Where software comes in

Two of the four steps automate by their nature. QRegu covers the detect step by watching 26+ regulators and official sources, and the apply step by turning a change into tasks with RACI roles, owners, deadlines and evidence upload; on the control side it stays traceable which control satisfies which obligation. The interpret step stays with people, and should.

Frequently Asked Questions

Compliance is the second line of defence: it builds the compliance framework, defines policy and controls, and oversees the business units. Internal audit is the third line and independently tests whether the first two work. Compliance auditing the arrangement it designed itself would remove that independence.
What does a compliance programme contain?
An obligation inventory, written policies and procedures, a control library with periodic assessment, training and awareness, a breach reporting channel, evidence retention with an audit trail, and regular reporting. What matters is not that these exist but that the connections between them are traceable.
Is compliance management the same as regulatory tracking?
No. Regulatory tracking is the detection step, which is the first stage of compliance management. Compliance management adds interpretation, translation into policy and controls, application and proof on top of it.

Sources