The compliance wheel: how to make compliance work effectively

"The wheel that does not need to be reinvented." For many organisations, compliance feels like a treadmill. You work hard, yet the finishing line never seems to get any closer. A new piece of legislation? Start another project. Applying for certification? A new folder on SharePoint. Where are our biggest risks? Are we in control? Who is supposed to do what?

In my previous blog series, I described how to build a sustainable compliance ecosystem using an integrated risk and control framework and the PDCA cycle. That series was about laying the foundation and keeping it in good repair. This new series goes a step further: how do you organise compliance in a way that actually works? It is intended as a starting point rather than an exhaustive guide, and there is a good reason why billions are spent worldwide on compliance teams, tools and consultants.

To answer that question, I use the compliance wheel as my guide. Not as a theoretical model, but as a practical instrument for setting up compliance effectively. Four quadrants that together form the complete picture:

  1. Vision & Governance; vision, values, roles and risk appetite
  2. Policies & Procedures; from requirement or standard to workable control
  3. Culture; from written policy to behaviour in practice
  4. Monitoring & Reporting; from execution to insight and demonstrability

At the centre of the wheel, as the hub that holds everything together and maintains quality through change, sits People, Process & Technology. I will dedicate a separate blog to that.

The wheel is not new. The four building blocks can be traced back to the US Sentencing Guidelines of 1991, ISO 37301 and the IIA's Three Lines Model. The movement is always the same: leadership → planning and policy → awareness and execution → evaluation and improvement. The Deming cycle in different clothing. The PDCA cycle as the flywheel process at the centre.

What is new is the urgency, complexity and scale. In the era of the GDPR, NIS2, the AI Act and DORA, a compliant-on-paper framework is no longer sufficient. The stakeholders in the outer ring reflect the interplay. Legislation provides rules but also uncertainty. Regulators want evidence and issue instructions. Society can shift its expectations seemingly overnight. On top of that, the board wants comfort. And clients and employees need clarity. Setting up compliance effectively means serving all of those needs, with as little duplication as possible and as much coherence as possible.

 

Compliance wheel

Figuur 1. The compliance wheel

Compliance has a historical context, and that matters

The history of compliance is one of responses to societal crises. From Watergate and the oil crisis in the 1970s, through Enron and WorldCom in the early 2000s, to the financial crisis of 2008, every major shock led to tighter regulation and the further professionalisation of the field. The movement progressed from rule-based (follow the letter of the law) through principle-based (understand the spirit of the law) to today's risk-based approach: make your own justified choices and demonstrate how.

The fourth industrial revolution, with AI as its central driver, is the next trigger. The EU's Digital Decade legislation is the direct response. An organisation that starts a separate project for every new law will drown. An organisation that integrates them all into one effectively organised wheel keeps its head above water.

AI is introducing a new dynamic into the threat landscape. Following the next AI-driven crisis, legislators will undoubtedly respond swiftly with new regulation. In line with the pattern above, that could well become value-based, with human values playing a more prominent role in the interests to be protected. This is still too distant to have a direct impact on your current compliance organisation, but it is certainly worth bearing in mind for those who want to learn from the past and look ahead.

In the next blog

Now that the wheel has been introduced, it is time for the spokes. In the next blog, we will explore Quadrant 1: Vision & Governance. What role does the organisation's vision, norms and values play in setting up compliance effectively? And how do you give meaningful substance to a catch-all concept such as 'governance' in the context of compliance?

Would you like an early insight into the maturity of your organisation on specific compliance topics? We would be happy to help with a practical maturity assessment, a clear first step before your regulator does it for you.

Contact us

Back to overview