Get accounting insights delivered directly to your inbox!
As regulatory standards change, CFOs must ensure that accounting teams are able to meet their compliance responsibilities by practising effective compliance management.
In Deloitte’s State of Compliance Survey 2022, 57% of respondents identified regulatory change as their key compliance challenge - up from 49% in 2020. Of those respondents, only 7% said that their companies were actually prepared to meet their new compliance challenges. In 2022, survey respondents also revealed a lack of confidence in the effectiveness of their compliance management function, with almost 50% saying that their risk management frameworks were integrated only with second-line compliance functions or not integrated at all.
The complexity of existing, and incoming, financial regulations makes compliance management too important to ignore - and a critical risk consideration. With that in mind, CFOs should understand how to implement a compliance management system (CMS) within their organisation, and how to leverage technology to make the compliance process easier.
Compliance management is the practice of ensuring that a company’s financial systems and processes conform to all applicable laws, and meet all industry regulations and contractual obligations.
Central to the compliance management process is the need to develop a company-specific framework of policies and procedures that facilitate compliance - typically through the application of internal controls. However, compliance management goes beyond the day-to-day activities of teams and individual employees, and extends to C-suite executives, who must understand the regulatory risks that their company faces in order to shape compliance policy and develop effective controls.
With that in mind, companies should seek to build their compliance management framework around these principle considerations:
The primary aim of compliance management is to ensure that companies mitigate risk and build a deep-rooted internal culture of compliance.
However, specific compliance management objectives may be more complex, and differ by company. In the EU, for example, tax law is different in each of the 27 member states, meaning that companies must train their accountants to manage finances for each jurisdiction in which they operate, and take that diversity into account during the month-end close.
Accordingly, an effective compliance management framework should enable accounting teams to keep pace with an increasingly complex, and rapidly changing, regulatory landscape - where failing to do so would expose them to unprecedented levels of legal risk and damaging financial penalties.
The rate of regulatory change is a significant compliance priority: in PWC’s 2022 Global Risk Survey, four out of five respondents stated that keeping pace with the speed of digital and other transformations was a major risk management challenge. Similarly, the 2023 Global Risk Survey revealed that 57% of respondents viewed technology investment as the “biggest motivating factor” in prompting a review of their risk landscape.
Beyond affirming regulatory compliance and creating a culture of compliance, a compliance management framework serves to help companies avoid costly non-compliance penalties.
Failure to comply with regulatory requirements, knowingly or unknowingly, may lead to serious consequences, including:
The consequences of non-compliance can seriously damage a company’s brand, restrict operational capacity, and wipe out financial resources. For example, in the EU, member states typically set their own financial penalty rates, however, collective fines for General Data Protection Regulation (GDPR) violations alone reached a record €2.1 billion in 2023.
Compliance risk exposure varies based on a range of factors, such as company size, industry, and geographic location. However, certain industries are more heavily regulated than others, such as those in the banking and financial services industries, and accordingly, need to dedicate more resources and administrative focus to compliance. Broadly, all companies should be aware of the legal requirements and regulatory frameworks that apply to their operations, and implement an appropriate compliance management solution.
Examples of prominent compliance regulations include:
The evolving regulatory landscape means that companies should conduct horizon scanning to anticipate emerging risks and possible vulnerabilities in their compliance solutions. In 2024, emerging regulatory compliance concerns include:
Having set out compliance objectives, companies must develop a CMS - sometimes referred to as compliance management framework, capable of fulfilling them. An effective CMS typically includes the following elements:
The practical details of CMS implementation will differ by company, but should typically involve the following steps:
Ideally, companies should seek to integrate their compliance management framework with as little disruption as possible to products and services. This means facilitating communication between departments and stakeholders both during the development of policies and procedures and then on an ongoing basis after CMS deployment.
Companies should lean-in to process automation during the integration process since the interface of technology and compliance workflows will determine the effective execution of policies and procedures. Automated software can not only add speed and accuracy to the application of controls, but minimise the chance of human error, enable real-time communication, and centralise access to critical resources.
Compliance management is not just a question of regulatory box-ticking. Effective implementation typically brings meaningful operational benefits, including:
The risk assessment is one of the most important components of compliance. Most regulators require a risk-based approach to compliance, which means that companies must deploy mitigation measures commensurate with the risk they face. With that in mind, the risk assessment process might include the following elements:
The compliance management framework should go beyond the identification and assessment of risk, and include consideration of mitigation strategies. The primary mitigation mechanism is the effective application of controls - as part of critical financial processes such as the monthly close. With the benefit of compliance software, CFOs can assign control responsibilities to accounting teams, track their application, and automatically escalate alerts to the compliance officer so that reports can be made to the relevant authorities.
Corporate ethics is a critical foundation of healthy compliance. Recent regulations, such as the EU CSRD and the UK’s Corporate Governance Code, reflect an increasing global focus on ESG and corporate compliance culture, and the public expectation that businesses contribute to important social issues, such as climate change, and labour equality.
Senior management employees set the standards by which their teams operate. Accordingly, CFOs should build a compliance culture on accountability and transparency, encouraging close communication and collaboration and investing in technology that facilitates the fulfilment of compliance tasks, such as reporting and record-keeping. Similarly, companies should seek to provide ongoing training for their compliance employees to prepare them for both changes on the compliance landscape, and emerging risks.
The changing risk landscape, and the increasing complexity of compliance regulations, mean that CFOs must seek to create compliance management frameworks that are robust and flexible. The best way to achieve that goal is to automate compliance wherever possible by integrating software tools.
Compliance automation is not just about efficiency. Deployed effectively, software tools help companies focus on, and build, their internal compliance culture.
FloQast Compliance Management, for example, is designed to make the compliance process smoother from end to end, enabling accounting teams to embed controls into daily financial workflows, retain and retrieve critical data, and are always ready for audit requests. Similarly, FloQast increases visibility and accountability of compliance tasks, enabling team members to take ownership of their control responsibilities, access resources remotely, track progress accurately, and ultimately, deliver the standard of compliance performance that their company needs.
Learn more about effective compliance management, contact FloQast today.