Risk, compliance and operational policies · 02
Compliance policy and regulatory universe
Identifies every statute and regulator that binds the organisation, and who owns each obligation.
Identifies every statute and regulator that binds the organisation, and who owns each obligation.
Build the regulatory universe first: each Act and subordinate instrument, the obligations it creates, the owner, the control, the evidence and the frequency. Then the policy around it — how the universe is maintained, how legislative change is monitored, the compliance calendar, breach reporting and remediation, and reporting to the board.
The perimeter question is usually answered by the product roadmap rather than the current product — a feature six months away can bring an entire licensing regime with it, and the time to know is before it is built. A universe that lists statutes without naming an owner for each obligation cannot be used, and will not be.
The law it sits under
What governs this instrument.
A compliance policy is the instrument that allocates ownership of statutory obligations. For a public entity the accounting authority’s general responsibilities under section 51 of the PFMA are the anchor; for a company, the directors’ duties under section 76 of the Companies Act. The policy’s value is the register behind it, not the statement of intent in front of it.
Related pages, tools and documents
Where this instrument sits in the wider set, and the engagement that produces it.
Start here
Tell us the decision your organisation needs to make.
The first conversation is thirty minutes, confidential and free. You will leave it knowing which of our services you need and which you do not.
