Chapter 11: Compliance Management Flashcards
1
Q
What does compliance management ensure?
A
- all applicable laws and regulations are identified; and
- the implications of these laws and regulations for an organisation’s decisions and processes are assessed and understood.
2
Q
What does compliance management include?
A
- putting mechanisms in place to assess whether the risk-management policies, procedures and practices within an organisation are compliant with applicable laws and regulations; and
- designing and implementing controls which monitor and maintain compliance.
3
Q
Outline examples of compliance risk
A
- An organisation does not realise that a law or regulation exists or applies to it.
- An organisation is aware of the existence of a law or regulation, but there is a lack of certainty concerning how to comply with the law or regulation
- Uncertainties may exist over when or how a law or regulation may apply to different contexts.
- An organisation’s management makes a conscious decision not to comply with a law or regulation
- Staff members take decisions or actions that cause the organisation to breach a law or regulation.
- Complexities and conflicting priorities within processes and procedures may make it hard to design them to ensure full compliance while at the same time achieve organisational objectives.
4
Q
Outline some compliance-management tools
A
- compliance policies and procedures – e.g. RM policies and procedures may include elements that relate to compliance with relevant risk-management laws and regulations
- **compliance codes of conduct **– specify the type of conduct expected of staff – rules and guidance
- **compliance reviews and audits **- internal audit that review and report on the effectiveness of compliance-related controls.
- compliance impact analysis - form of risk assessment that investigates the impact of a compliance breach
- gap analysis and action planning - helps an organisation to assess whether its existing policies, processes, procedures and compliance controls are sufficient to comply with relevant laws and regulations
- **compliance reporting **– output from a range of other compliance activities
- HR-related controls
- whistleblowing procedures - might include reporting criminal activities, observed breaches of policies and procedures and poor behaviour such as workplace bullying or discrimination
- **establishing an appropriate compliance culture **