Study: Non-Compliance Problems Cost 3X More Than a Strong Compliance Program

  • by gcarroll@fasttrackaust.com (Greg Carroll)
  • 21 Jan, 2013
Study shows that non-compliance problems cost nearly three times as much as doing it properly from the start

Many companies view compliance programs as a headache -- something they're required to invest time and money in, but which produces little. A benchmark report from the United States shows that the opposite is the case. Investing in strong compliance programs saves money in the long run.

The research report by Ponemon Institute LLC in Traverse City, Michigan, examines the real costs, both of setting up a proper compliance program and of cleaning up the damage when proper programs have not been put in place. The study looked at 46 multinational organisations and interviewed 160 leaders.

The cost of compliance worked out to only about $222 per employee, while noncompliance costs averaged about $820 per employee.

"We learned that while the average cost of compliance for the organizations in our study is $3.5 million, the cost of non-compliance is much greater," the report said. Cleaning up non-compliance problems averaged nearly $9.4 million.

Study cites 10 attributes of a strong compliance structure

The report also looked at the 10 attributes that lend the greatest support to a strong compliance structure. Many of them pertain to governance and oversight of the organization's security initiatives.

Organizations need to anticipate how changing threats will affect their ability to comply with external, internal and contractual demands, the report said. "The implication for an organization that does not manage compliance risks with the right integrated and holistic response to data security and related compliance challenges are a decrease in revenue that results from both the loss of customer trust and loyalty and the inability to deliver services and products," the report said.

The study, "The True Cost of Compliance," is available online at Tripwire.com.

Doing more than keeping authorities at bay

Fast Track has long held that a good compliance program can be a strategic tool rather than merely a way to keep governing authorities at bay. That's why we offer 11 different modules covering everything from documents to equipment inventories.

Why spend $820 per employee cleaning up a mess when it's much cheaper to prevent the mess in the first place?

by gcarroll@fasttrackaust.com (Greg Carroll) 05 Apr, 2017
The benefits of SharePoint as a content management system and information portal tool are indisputable.  With great search functionality and user definable portal pages SharePoint is now the leading Content Management solution chosen by most IT departments. But what if your business demands strict document controls protocols, not just because it’s good practice but life depends on it?  Unfortunately there is generally a poor appreciation by IT departments of the importance of document control in mission critical business. 
by gcarroll@fasttrackaust.com (Greg Carroll) 11 Oct, 2016
It is not uncommon for laboratories to be saddled with maintaining both ISO 17025 and ISO 9001 certification. Although it is simpler to create and implement two QMS – and to "merge" those activities which can be merged – this approach is arduous, inefficient, and prone to mistakes.
by gcarroll@fasttrackaust.com (Greg Carroll) 15 Sept, 2016
Senior management have to come to grips with the fact that Digital Transformation is not an Event but rather the operating environment of 21st century business. 
by gcarroll@fasttrackaust.com (Greg Carroll) 22 Aug, 2016
Last week saw the latest in misguided innovation talkfests, the AFR Innovation Summit #Innovation16.  For several days academics, public servants, journalists, and corporate employees put forward their insights into how Australia can develop an Innovation culture. 
by gcarroll@fasttrackaust.com (Greg Carroll) 25 Jul, 2016
Effectiveness is the holy grail of Compliance Management.  Whether regulatory or ERM, ensuring business is conducted as intended is the base requirement to optimising your organization’s performance.
by gcarroll@fasttrackaust.com (Greg Carroll) 17 Jun, 2016
2016 has seen a virtual tsunami of compliance failures involving some of our largest companies. From Mitsubishi to VW, from ANZ to Target, almost weekly there have been media reports about some company employees having run amok – unbeknownst to their executives and boards. People are asking: “What happened to the compliance management systems that are supposed to monitor and prevent such abuses?” Executives and boards are naturally starting to question the entire compliance management function. 
by gcarroll@fasttrackaust.com (Greg Carroll) 07 Sept, 2015
The Compliance Manager’s role in the modern organization is to enable/empower decision makers to take action and leave the building defensive walls to the Risk Manager with his heat maps. So how can compliance managers start realising their value adding role?
by gcarroll@fasttrackaust.com (Greg Carroll) 18 Jul, 2015
With the release of the Final Draft of ISO9001:2015 this week and its focus on risk-based Compliance Management, I thought I would share our approach to Risk-Based Auditing from our experience with the likes of Defence Aviation and the Australian Quarantine Inspection Service, both leaders in the field.
by gcarroll@fasttrackaust.com (Greg Carroll) 03 Jul, 2015
Mere compliance with a Framework is an insufficient audit approach; it is critical to assess whether it is current, timely, communicated broadly, and meets the needs of the business. The 4 biggest mistakes are:       Not being Outcome focused      Not using Risk base targeting      Not Value Adding      Not being timely
by gcarroll@fasttrackaust.com (Greg Carroll) 28 May, 2015
Why, with the number of fertile minds that exist in our field, is it still a case of an irresistible force meeting an immovable object.  The paradox I believe, like our would-be entrepreneurs, is one of approach.
Show More
Share by: