What Is Compliance Management?
The process that turns an obligation into policy, controls and evidence: who is responsible, how it differs from internal audit, what a programme contains.
Compliance management is the work of identifying the legal and regulatory obligations that bind an organisation, translating them into internal rules, supervising how they are applied, and making all of that provable. The last word is the decisive one: compliance is shown, not described. The question in an examination is not "did you do it" but "how do you show that you did".
The three lines of defence
In regulated organisations responsibility is commonly split across three lines. The split explains why compliance sits apart from both the business and internal audit.
| Line | Who | Responsibility |
|---|---|---|
| First | Business units | Own and manage the risk inside the daily work |
| Second | Compliance and risk management | Build the framework, oversee it, guide the first line |
| Third | Internal audit | Independently test whether the first two lines work |
A common mistake is running compliance as though it were the third line. Compliance does not audit; it builds and oversees. Auditing the arrangement it designed itself removes the independence the third line exists to provide.
What a compliance function does
The work reduces to four steps. Detect: catch the new or amended obligation — this step is regulatory tracking. Interpret: assess whether it binds the organisation and what it requires. Apply: update policy, procedure and control, and set an owner and a deadline. Evidence: document what was done and keep it ready for examination.
In regulated sectors the existence, independence and reporting line of the compliance function are set out in the rules governing that sector, and where the function reports is the most concrete indicator of its independence.
What a compliance programme contains
An obligation inventory, written policies and procedures, a control library with periodic assessment, training and awareness, a breach reporting channel, evidence retention and an audit trail, and regular reporting. None of these is compliance on its own; the programme is the connection between them. It must be traceable which control satisfies which obligation, and when that control was last assessed.
Where software comes in
Two of the four steps automate by their nature. QRegu covers the detect step by watching 26+ regulators and official sources, and the apply step by turning a change into tasks with RACI roles, owners, deadlines and evidence upload; on the control side it stays traceable which control satisfies which obligation. The interpret step stays with people, and should.