Compliance program management: running the function, not just the controls
Compliance program management covers the charter, the annual plan, resourcing, training, reporting lines and how effectiveness is measured. What a programme needs to be credible rather than decorative.
MI
Maria I.Sept 29, 2026 · 3 min read
Share
How-toC
Compliance program management is the layer above individual controls: what the function is mandated to do, who it reports to, how it decides where to spend a limited year, and how anyone can tell whether it works. Regulators assess this directly. When a breach is investigated, the questions are about the programme — was it resourced, was it independent, did it escalate, and did anybody act on what it found — far more than about the specific control that failed.
What a compliance program management framework contains
A charter approved at board level, stating mandate, scope, independence and reporting line.
A periodic compliance risk assessment that determines the annual plan, rather than a plan repeated from last year.
An annual plan with named deliverables, so unfinished work is visible instead of absorbed.
Resourcing measured against that plan, including the parts deliberately not covered.
Training targeted by role and risk, with completion tracked and content refreshed.
Reporting to a committee on a fixed cycle, with issues named rather than aggregated away.
A route to escalate past management to the board or its committee, used at least once without career consequences.
Effectiveness measures agreed in advance, not selected afterwards from whatever looks good.
Measuring whether it works
Weak programmes report activity: sessions delivered, policies published, reviews completed. Those are inputs. Better measures look at outcomes — how many issues were found internally before an external party found them, how long issues stay open, whether reporting rates through the speak-up channel are rising, and whether business decisions were changed by compliance input in ways somebody can point to. A function that has never caused a decision to change is not influencing risk, regardless of how much it produces.
Independence is structural, not personal. If the compliance lead's objectives and bonus are set by the executive whose business they assess, no amount of individual integrity fixes the incentive, and a regulator will identify that arrangement immediately.
Standing one up
Get the charter written and approved, however short, before building anything else.
Run a risk assessment across obligations and business lines, and rank by consequence.
Publish an annual plan with what is in scope and, explicitly, what is not.
Fix the reporting cycle and the committee that receives it.
Track issues centrally with owners and dates, and report the overdue ones every time.
Agree three or four effectiveness measures at the start of the year and report them unchanged.
Ettex Records holds the operating record: the annual plan with deliverables and status, the risk assessment with scores per business line, a training completion log, and an issue register with owners and due dates. Those four views produce a committee pack without anyone rebuilding numbers in slides the week before.
Frequently asked
Who should the compliance function report to?
Administratively to the chief executive or general counsel is common; substantively there should be a direct line to a board committee, with private access to it. Reporting only into the business being assessed compromises the function.
What makes a compliance programme "effective" to a regulator?
Broadly: it is risk-based, adequately resourced, independent, produces evidence of issues being found and fixed, and shows senior accountability. Published guidance in several jurisdictions follows that structure closely.
How big should a compliance team be?
There is no ratio worth quoting. The defensible approach is to size it against the annual plan and state plainly which risks are uncovered at current resourcing.
MI
Written by Maria I.
Part of the Ettex team — writing about product, engineering and the future of work.