Back to Glossary

Entry · Business

Compliance Program

A compliance programme is the documented set of policies, training, monitoring and reporting a company puts in place to prevent and detect breaches of law or regulation. Regulators judge whether the programme is genuinely operating rather than merely written down, and that judgement often decides how harshly a breach is punished.

From the Money Master HQ dictionary, founded by Shihan Sheriff (FCMA, VP of Finance at Nomod, CFO at Esanjo Ventures). How these definitions are written.

What it means

A recognisable programme has seven parts: a risk assessment, written policies, training, monitoring and testing, a confidential reporting channel, consistent discipline when rules are broken, and periodic review. Miss any one of them and the programme tends to fail at exactly the moment it is needed.

The economics turn on penalty mitigation. Enforcement outcomes routinely distinguish between a company that had no controls and one whose controls were bypassed by a determined individual, and the difference in penalty can be larger than the entire cost of the programme.

There is a commercial angle too. Large customers, public bodies and insurers increasingly require evidence of an anti-bribery or data protection programme before awarding contracts, so the programme becomes a condition of bidding rather than an internal nicety.

Effectiveness is assessed on behaviour, not paperwork. Reviewers look at training completion, whether the reporting line is actually used, whether senior people have ever been disciplined under the policy, and whether the risk assessment has been refreshed since the business changed.

The most common weak point is third parties. Agents, distributors and outsourced providers can create liability for the company that hired them, so a credible programme extends due diligence, contract terms and audit rights across the supply chain rather than stopping at the office door.

In practice

Real-world examples.

1

Example

A construction firm bidding for government work builds a formal anti-bribery programme because the tender documents require evidence of one. Policies, gift registers, third-party due diligence and annual training are documented, and the certification becomes a prerequisite for bidding rather than an optional extra.

2

Example

A medical device distributor rolls out a programme covering interactions with clinicians, including pre-approval of hospitality and a register of consultancy payments. When an audit finds a regional team booking educational events that never took place, the reporting channel catches it internally and the company self-reports before a regulator finds it.

3

Example

An online marketplace establishes a data protection programme after expanding into new markets, appointing an owner, mapping data flows and setting retention limits. The first real test comes when a supplier suffers a breach, and the mapping lets the company identify affected customers within days rather than months.

Formula

Calculation

Expected annual cost of non-compliance = probability of a breach event x financial impact of that event. Net benefit of the programme = (expected cost before - expected cost after) - annual programme cost. A distributor assesses its exposure to a bribery or sanctions breach at $9,000,000 once penalties, legal fees and contract loss are combined. Without a formal programme it judges the annual probability of such an event at 12%. With screening, training, third-party due diligence and monitoring in place, it judges the probability falls to 3%. The programme costs $450,000 a year to run. Expected cost before = 0.12 x $9,000,000 = $1,080,000 Expected cost after = 0.03 x $9,000,000 = $270,000 Risk reduction = $1,080,000 - $270,000 = $810,000 Net benefit = $810,000 - $450,000 = $360,000 Return on the programme spend = $360,000 / $450,000 = 80% The probabilities are judgements rather than measurements, so the sensible use of this calculation is to test how far they would have to move before the programme stopped paying for itself.

Case study

Seen in the real world.

Tallow and Finch Logistics is an illustrative, fictional freight forwarder with $64,000,000 of revenue, moving cargo through a dozen jurisdictions with no formal sanctions or export controls programme. Screening was done informally by whichever operations clerk happened to handle the booking.

After a near miss on a shipment routed through a high-risk intermediary, the board approved a programme costing $320,000 to set up and $180,000 a year to run, making first-year spend $500,000, or 0.78% of revenue. It covered a documented risk assessment, automated counterparty screening, mandatory training for the 90 staff who touch bookings, an anonymous reporting line and quarterly sample testing of completed shipments.

In the first eighteen months the screening stopped three shipments involving restricted end users, any one of which could have cost the company its customs authorisations. The finance director noted that the programme never generated a dollar of revenue and was still the best-value line in the budget, because the cheapest breach the company might have suffered would have cost several times its annual running cost.

Watch out

Common mistakes.

  • Writing the policy and calling the job done. A programme that exists only as a document offers almost no mitigation, because regulators test whether it operated in practice.
  • Training everyone identically once a year. Generic annual training satisfies a checkbox but does little for the specific roles, such as sales and procurement, where the real exposure sits.
  • Excluding agents, distributors and outsourced providers. Third parties are the most common route to liability, so a programme that stops at your own employees leaves the biggest gap open.

Questions

People also ask.

How is a compliance programme different from a compliance department?

The department is the people; the programme is the system of policies, training, monitoring and reporting they operate, and a small company can run a programme without a dedicated department.

How often should the programme be reviewed?

At least annually, and immediately after any material change such as entering a new market, launching a new product line or completing an acquisition.

Does having a programme guarantee lower penalties?

No, but a demonstrably operating programme is consistently treated as a mitigating factor, whereas a paper-only one can be treated as an aggravating one.

Was this explanation helpful?

From the founder's library

Accounting Fundamentals: A Non-Finance Manager's Guide to Finance and Accounting, by Shihan Sheriff

Take it further with the book.

Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.

US$2.24US$2.99

25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.

View the book and save 25%
Last updated · October 8, 2026
Browse all terms →

Disclaimer

The information provided in this finance dictionary is for educational and informational purposes only. It should not be construed as financial, investment, legal, or tax advice. Always consult with a qualified professional before making any financial decisions. Money Master HQ makes no representations or warranties about the accuracy, completeness, or suitability of this information. Use of this content is at your own risk.