The 4 Biggest Mistakes in Compliance Management

  • by gcarroll@fasttrackaust.com (Greg Carroll)
  • 03 Jul, 2015
Mere compliance with a Framework is an insufficient audit approach; it is critical to assess whether it is current, timely, communicated broadly, and meets the needs of the business. 
focusing compliance on opportunities not threats
The 4 biggest mistakes are:
  1.      Not being Outcome focused
  2.      Not using Risk base targeting
  3.      Not Value Adding
  4.      Not being timely

In a recent article on Auditing Risk Appetite Norman Marks commented: “What I especially like about the FSB list of questions (and reflected in mine) is that it recognizes that mere compliance with a Framework is an insufficient audit approach; it is critical to assess whether it is current, timely, communicated broadly, and meets the needs of the business.”

Although speaking about auditing Risk Appetite I believe these issues apply equally to Audit and Inspection in general.  A comprehensive checklist of several hundred items assessed as complying or not is neither effective nor beneficial, and only serves to chew up limited Compliance funds from the corporate budget.  If done well, corporate health reports become an eagerly awaited strategy document for boards.

 

1.     Not Outcome focused

Merely auditing the existence of corporate goals and objectives doesn’t make auditing Outcome focused.  The Audit Plan has to be based on the corporate objectives understanding the opportunities and threats inherent in those objectives.  Any compliance management framework is a comprehensive inventory of compliance items not a roadmap.   This is where good compliance management software comes in, letting you map your Audit Plan back to the framework to ensure comprehensive coverage, while allowing you to concentrate on Compliance Assurance of the corporate objectives.  When looked at from this perspective improvement and performance become the aim of compliance not the systematic enforcement of controls.

 

2.     Not Risk base targeting

Once focused on opportunities and threats, a risk based approach (see "Does anyone really understand Emerging Risks?") coupled with targeted activities is inevitable.  Risk based is more that checking for known issues first. Setting surveillance levels and frequencies based on risk not only produces more results by concentrating on the areas that can produce the greatest returns, it allows for more efficient uses of the limited compliance budget resources. 

Audit and Inspection are expensive services and in low risk areas have little benefit and are not the only methods of assuring compliance.  Online self-audits with appropriate evidence or periodic reporting of key indicators is just as effective, and sometimes more timely, in low risk areas. Obviously, this needs to be backed by occasional unscheduled audits/inspections.

 

3.     Not Value Adding

Identifying & issuing corrective actions, although necessary, is not value adding in the eyes of the operation staff responsible.  If they saw it as a problem they would have fixed it before being assessed (yes a bad word, but if you’re not value adding that is all it is!).  What can be done to value add?  Well you have the unique opportunity to educate operation management in circumstances where they are likely to listen and act – PRIOR TO THE AUDIT.  Use it. 

 

Compliance is more than just Audit & Inspection

With a properly developed compliance management system, and not just a pool of word/excel documents, you can compile a targeted reviews based on areas of importance.  Developing checklists based on objectives and risks, weightings can be allocated to individual questions as to their effect to objectives (see 2 above), allows assessment of effectiness not just compliance.

Previous history, lessons learnt in related fields, and current industry trends should be the purview of the Compliance department and their duty to disseminate as part of the pre-audit activity.  Finally, in the final report include business cases for improvements in target areas. Relating those back to corporate objectives is a good way to garner support for the audit/inspection process from operational management.  In time they will look forward to, and prepare for, the opportunity to press their own objectives.

 

4.     Not being timely

Board/Management review of summaries audit findings is both an opportunity and entrenchment of value of Compliance Management to the organisation.  Regurgitating conformance information of problems fixed and administrative observations reinforces the negative regulatory role of the compliance department as a necessary overhead.  Releasing regular health reports on the organisation’s progress to achieving its objectives not only gives interest to compliance reports but the opportunity to push expanding the department’s capability. 

 

Making Compliance Relevant

The key to this is not just relevance but timeliness.  Knowing the emerging issues at a time they can be acted on is of benefit to the board.  Historically knowing what happened last year is not.  This requires moving away from an annual (or periodic) audit/inspection regime to a continuous monitoring approach, backed up by periodic audit/inspection.  Sending out regular, specifically targeted questionnaires for self-assessment, with automated submission and analysis reduces the overhead and workload to the compliance dept while allowing them to adjust the risk targeting and produce timely health reports for management.

 

Effective Compliance Management

An effective compliance management methodology must not only deliver the right information and training, it must be delivered at the right time, in a consistent and controlled manner. The information delivered must be accurate and up to date. And, there must be validation that the information has been received and understood, with a complete audit trail.  Automating these processes with best practice Compliance Management software frees up Compliance expertise to perform their true role monitoring and assisting the organisation in achieving its corporate objectives.

Next Week:  How to Implement Risk Based Audits & Inspections

Other Related articles

by gcarroll@fasttrackaust.com (Greg Carroll) 05 Apr, 2017
The benefits of SharePoint as a content management system and information portal tool are indisputable.  With great search functionality and user definable portal pages SharePoint is now the leading Content Management solution chosen by most IT departments. But what if your business demands strict document controls protocols, not just because it’s good practice but life depends on it?  Unfortunately there is generally a poor appreciation by IT departments of the importance of document control in mission critical business. 
by gcarroll@fasttrackaust.com (Greg Carroll) 11 Oct, 2016
It is not uncommon for laboratories to be saddled with maintaining both ISO 17025 and ISO 9001 certification. Although it is simpler to create and implement two QMS – and to "merge" those activities which can be merged – this approach is arduous, inefficient, and prone to mistakes.
by gcarroll@fasttrackaust.com (Greg Carroll) 15 Sept, 2016
Senior management have to come to grips with the fact that Digital Transformation is not an Event but rather the operating environment of 21st century business. 
by gcarroll@fasttrackaust.com (Greg Carroll) 22 Aug, 2016
Last week saw the latest in misguided innovation talkfests, the AFR Innovation Summit #Innovation16.  For several days academics, public servants, journalists, and corporate employees put forward their insights into how Australia can develop an Innovation culture. 
by gcarroll@fasttrackaust.com (Greg Carroll) 25 Jul, 2016
Effectiveness is the holy grail of Compliance Management.  Whether regulatory or ERM, ensuring business is conducted as intended is the base requirement to optimising your organization’s performance.
by gcarroll@fasttrackaust.com (Greg Carroll) 17 Jun, 2016
2016 has seen a virtual tsunami of compliance failures involving some of our largest companies. From Mitsubishi to VW, from ANZ to Target, almost weekly there have been media reports about some company employees having run amok – unbeknownst to their executives and boards. People are asking: “What happened to the compliance management systems that are supposed to monitor and prevent such abuses?” Executives and boards are naturally starting to question the entire compliance management function. 
by gcarroll@fasttrackaust.com (Greg Carroll) 07 Sept, 2015
The Compliance Manager’s role in the modern organization is to enable/empower decision makers to take action and leave the building defensive walls to the Risk Manager with his heat maps. So how can compliance managers start realising their value adding role?
by gcarroll@fasttrackaust.com (Greg Carroll) 18 Jul, 2015
With the release of the Final Draft of ISO9001:2015 this week and its focus on risk-based Compliance Management, I thought I would share our approach to Risk-Based Auditing from our experience with the likes of Defence Aviation and the Australian Quarantine Inspection Service, both leaders in the field.
by gcarroll@fasttrackaust.com (Greg Carroll) 28 May, 2015
Why, with the number of fertile minds that exist in our field, is it still a case of an irresistible force meeting an immovable object.  The paradox I believe, like our would-be entrepreneurs, is one of approach.
by gcarroll@fasttrackaust.com (Greg Carroll) 22 Apr, 2015
Return of Investment (ROI) does not come for automating a process but from using it to add value.  Value adding comes from targeting time and resources, risk based thinking, and Business Intelligence where they can deliver the greatest benefit to achieving the organisation’s strategic goals. 
Show More
Share by: