Risk, compliance and operational policies · 02

Compliance policy and regulatory universe

Identifies every statute and regulator that binds the organisation, and who owns each obligation.

What it does

Identifies every statute and regulator that binds the organisation, and who owns each obligation.

How it is drafted

Build the regulatory universe first: each Act and subordinate instrument, the obligations it creates, the owner, the control, the evidence and the frequency. Then the policy around it — how the universe is maintained, how legislative change is monitored, the compliance calendar, breach reporting and remediation, and reporting to the board.

What to look out for

The perimeter question is usually answered by the product roadmap rather than the current product — a feature six months away can bring an entire licensing regime with it, and the time to know is before it is built. A universe that lists statutes without naming an owner for each obligation cannot be used, and will not be.

The law it sits under

What governs this instrument.

A compliance policy is the instrument that allocates ownership of statutory obligations. For a public entity the accounting authority’s general responsibilities under section 51 of the PFMA are the anchor; for a company, the directors’ duties under section 76 of the Companies Act. The policy’s value is the register behind it, not the statement of intent in front of it.

Related pages, tools and documents

Where this instrument sits in the wider set, and the engagement that produces it.

Start here

Tell us the decision your organisation needs to make.

The first conversation is thirty minutes, confidential and free. You will leave it knowing which of our services you need and which you do not.