From the Regulatory Map to an Operational Compliance System
(obligations, risk assessment, roles and control mechanisms)

Compliance begins before policies

A business that decides to organise its compliance framework often starts with what is most visible: it asks for policies, codes and manuals. This order is usually wrong. Before drafting any such document, the business must know which obligations bind it. It must also know where material risk arises and who controls the day-to-day implementation of the relevant rules.

The decision to treat compliance as a business investment creates value only when it is transformed into an operational system.

A compliance management system should not be a library of documents. It is an organised capacity to identify, assess, allocate and monitor regulatory risks. It connects the rule with a specific process, the risk with a specific owner and a deviation with a specific response.

It also connects every critical control with the evidence confirming its implementation. Without this link, even legally impeccable documents remain detached from the actual operation of the business.

The starting point: the Regulatory Compliance Map

The first step is to map the business’s “regulatory universe”. This does not consist solely of laws and, more broadly, the applicable regulatory framework. It also includes operating licences, supervisory decisions and the terms of public or private contracts. It further includes commitments towards financiers and insurers, as well as policies adopted and announced by the business itself.

The mapping exercise must follow the business model. A manufacturing facility, a technology company and a service provider face different risks. The exposure of a public-sector supplier is also different. Likewise, the environment of a company operating only in Greece differs from that of a company operating across several jurisdictions.

A list of rules is not yet a system. Each material obligation must be linked to an activity, an owner, a deadline, supporting evidence and the consequences of non-compliance. It must also identify which process implements the obligation and which control prevents or detects deviation.

In this way, the legal rule is converted into management and operational information. Management can see what needs to be protected, rather than merely which regulatory obligation applies.

From the obligation to the actual risk

Not all obligations carry the same weight. Some are associated with significant fines or loss of credibility. Others may result in interruption of operations, loss of licence or exclusion from a tender. They may also lead to termination of an important contract. Finally, certain risks directly affect employees, customers, other individuals or the environment.

The assessment must take into account probability, the severity of the potential harm and the ability to detect the problem in time. It must also consider how rapidly an incident may develop. The business’s dependence on third parties is equally important.

A low-probability risk may still require priority where its consequences would be catastrophic or irreversible.

A compliance risk assessment is not a mathematical pretence of precision. It is a disciplined method of prioritisation. It forces management to decide where people, time and budget should be allocated.

It also distinguishes inherent risk from the risk remaining after controls have been implemented. In this way, the residual risk that is accepted can be recorded, rather than being assumed unconsciously.

From mapping to gap analysis and an action plan

Mapping and risk assessment show where the business currently stands. They are not, however, sufficient to bring it to where it needs to be.

A gap analysis is required: a comparison between the applicable requirements and the existing procedures, available controls and their actual implementation.

The gap may consist of an absent policy, unclear ownership or inadequate documentation. It may also involve a control that has been designed but does not operate effectively, or a process that is systematically bypassed. The assessment must distinguish between the complete absence of a mechanism and its limited effectiveness.

Every material gap should result in an action plan. The plan needs an owner, a deadline, the required resources and a completion criterion. It must also determine who verifies that the action has been implemented and has genuinely reduced the risk.

Simply marking an item as “completed” is not sufficient where the outcome has not been tested.

It is neither possible nor realistic to close every gap at the same time. Priorities must follow risk, rather than the ease with which an action can be completed. A business that corrects only the easy findings may appear to be making progress while leaving its most serious exposure unresolved.

Proportionality: neither a luxury nor a shortcut

A compliance system must be proportionate to the size, sector and geographical presence of the business. It must also correspond to its actual risk profile.

An SME does not need to replicate the structure of a multinational group. It must, however, understand its critical risks and have stable control mechanisms in place.

Proportionality does not mean leniency. A small company processing sensitive data may require a stricter framework than a larger, lower-risk business. The same applies where it provides a critical digital service. Size is a criterion, but it is not the only one.

A useful system is one that can actually be implemented. Excessively complex approvals, endless forms and policies detached from day-to-day work lead to circumvention.

Simplification is legitimate where it does not remove the substantive control. At the same time, it must leave a clear and adequate audit trail.

Roles, ownership and lines of responsibility

Every critical obligation must have an owner. That owner is not always the legal counsel or the compliance function. In most cases, it is the business function carrying out the activity that creates the risk.

HR applies the regulatory framework governing employment relations and IT implements security measures. Procurement controls suppliers, while production must comply with technical or environmental requirements.

The legal function identifies the requirement, assesses the consequences and contributes to the design of the procedure. It cannot, however, replace the operational owner. When everything “belongs to Legal” — through lack of clarity, habit or established practice — compliance moves away from the point at which the risk actually arises.

There must also be a clear distinction between execution, monitoring and independent assurance. The same function should not design a control, perform it and independently certify its effectiveness.

This distinction must be adapted to the capabilities of each business, but it should not disappear.

Allocation of roles must be understandable and workable. A complex responsibility chart has no value where the people involved either ignore it altogether or do not understand key aspects of it: who decides, who performs and who must be informed. In critical processes, a simple project-management matrix, such as a RACI matrix, may be useful.

Equal pay as an example of operational compliance

The requirements relating to equal pay and pay transparency provide a characteristic example. Compliance is not exhausted by an equal-treatment policy. Nor is it exhausted by the preparation of reports.

It requires mapping actual roles, identifying work of equal value and consistently recording total remuneration. It also requires objective criteria for recruitment, salary increases, bonuses, promotions and deviations from approved pay ranges.

For the system to function, management, HR, payroll and finance must work together. Appropriate involvement of Legal or external legal counsel is also required. The processing of remuneration data additionally requires the necessary support of the data protection function.

The obligations are thus converted into role ownership, reliable data and request-handling procedures. Deviation controls and corrective actions are also required.

A rule of employment law is therefore transformed into a mechanism of corporate information, control and evidential accountability.

Policies must produce controls

A policy has value when it leads to a controlled action. A conflict-of-interest policy should provide for declaration, assessment, recusal and record-keeping. A supplier policy should lead to categorisation, due diligence, contractual commitments and periodic review.

An incident policy should define who must be informed, who decides and which records must be retained.

Controls may be preventive, detective or corrective. Approval before a payment is made is a preventive control. Periodic sampling of contracts already entered into is a detective control. Revoking access and retraining following a breach are corrective measures.

A mature system does not rely solely on prohibitions. It creates points at which an error can be prevented or detected in time.

In processes that depend on human judgement, training and clear communication are also substantive control mechanisms. They must have a defined audience, subject matter and frequency.

Every critical control needs a clear purpose, frequency, owner and failure criterion. Otherwise, its effectiveness cannot be assessed.

Every critical control must also leave an audit trail. Approvals, checks, exceptions and corrective action require documentation proportionate to the risk. The evidential function is not a subsequent addition. It is part of the design.

Changes, exceptions and reassessment of risk

A compliance system should not be activated only when the law or, as the case may be, the regulatory framework changes. A new product, new market, acquisition, organisational change or implementation of a new system may materially alter the business’s risk exposure.

The same applies when a critical function is outsourced to a third party or the use of data and technology is expanded.

Such changes should trigger reassessment. Before implementation, the business needs to assess the new obligations, roles, contracts and required controls.

Involving Legal only after the business decision has been finalised significantly limits the available solutions.

Likewise, the business needs a controlled exceptions process. An exception from a policy may be justified where a genuine business need exists. It must, however, be approved by the appropriate person, be time-limited and be accompanied by compensating controls.

Repeated exceptions often indicate that the policy or process does not correspond to actual operations. Informal circumvention is not flexibility. It is a loss of control and, frequently, the starting point of formal rather than substantive compliance.

Reporting and escalation to management

The system fails when information remains at operational level. Management does not need to know every detail. It does, however, need to be informed of serious deviations, recurring weaknesses and the expiry of critical licences.

It must also know about significant incidents and overdue corrective actions.

Escalation requires predefined criteria. What level of financial or operational impact makes an issue material? When does a deviation threaten reputation or become a systemic risk? When is external legal advice or a decision of a corporate body required?

These questions should not be answered for the first time while a crisis is already unfolding.

A concise compliance dashboard is generally more useful than a voluminous report. It may present the main risks, outstanding corrective actions and critical deadlines. It should also show which decisions are required.

The dashboard should not create a false sense of security through generic green indicators. Delays, repeated exceptions and controls that have not been tested must be clearly visible.

Good information is not measured by the number of pages. It is measured by whether it enables timely and informed decision-making.

Audit, learning and continuous improvement

Compliance does not end with initial implementation. Rules change, businesses grow and processes drift.

Periodic review of the regulatory map, testing of controls and monitoring of corrective actions are required.

Audits should seek to understand reality, rather than merely verify the existence of documents and records. Interviews, file sampling, scenario testing and data review reveal whether a policy is actually being implemented. Exceptions and cases in which the formal procedure was bypassed or failed must also be examined.

Findings do not constitute failure of the system. Failure consists in concealing them or allowing them to recur without remediation.

Every material finding should lead to a root-cause analysis. Otherwise, the business corrects the symptom rather than the mechanism that produced it.

ISO 37301 can provide a useful architecture for the development, assessment and improvement of a compliance management system. It does not replace the law, nor does it impose a uniform model on all businesses.

It does, however, reinforce a fundamental principle: compliance requires governance, proportionality, documentation and continuous improvement.

In summary: practical significance and value

An operational compliance system does not promise that no breach will ever occur. It ensures something more realistic: that the business understands its critical risks and has defined who manages them. It also knows which controls apply, which gaps remain open and who verifies completion of corrective actions.

For management, the practical objective is specific: to receive timely and reliable information without replacing the operational functions. For legal counsel, the objective is to translate the rule into an applicable procedure and clear control points. At that point, compliance ceases to be a collection of legal obligations and becomes a method of management.

Ultimately, the quality of the system will be judged by the way management uses that information. What must it know, decide and supervise? When is delegation sufficient and when does inaction create exposure? These are the questions addressed in the next article of the series.

Stavros Koumentakis

Managing Partner

Koumentakis and Associates Law Firm

Note: This article forms part of a broader series of articles by our Law Firm on regulatory compliance, consistently approached from a business perspective. Appropriate legal advice should always be sought from a suitably qualified lawyer.