The Compliance Wheel: Quadrant 1, Vision & Governance

The axle of the wheel: from introduction to the first quadrant

In the previous blog, I introduced the compliance wheel as a practical instrument for setting up compliance effectively. Now it is time for the first quadrant: Vision & Governance. Not as an abstract administrative concept, but as the foundation on which all other arrangements rest. Vision and Governance are the axle of the wheel. Without an axle, the wheel cannot turn, no matter how elegant the spokes.

Governance starts with an uncomfortable question

Is it truly clear to every employee in your organisation who may decide on which risks?

That question sounds simple. In practice, the answer rarely is. Compliance ownership ends up with the second line in many organisations (including CO, AICO, DPO, CISO and PRRC), while it belongs in the first line. As soon as that division of roles blurs, the second line ends up reviewing its own work. And that is precisely where the independence required for effective compliance disappears. It also undermines ownership of responsibilities, execution, monitoring and accountability for non-compliance.

Governance, however, goes beyond role allocation. Effective governance starts with clarity about behaviour: which risks does the organisation accept, and which does it not? Some organisations permit gifts up to €200 without a registration requirement; others draw the line at €10, and yet others have no policy at all. All these choices are defensible, provided the boundaries are clear to everyone and fit the organisation's culture. Transparency and accountability are the key words here.

Four building blocks for effective governance design

1. Vision, standards and values: the compass before the structure

Governance begins with the question: what does the organisation want to be? That vision translates into standards and values that guide everyday behaviour. The code of conduct is the most visible expression of this, but a code that is only signed on the first day of employment is not a governance instrument. It is a reference document. Effective governance requires standards and values to come alive: managers refer to them in concrete decisions, and employees know where the boundary lies and why.

2. Clear roles, mandates and independence

The Three Lines Model provides the structure: the first line executes and owns, the second line monitors and advises independently, the third line audits independently and reports to the board. The most common pitfall is that the second line gets absorbed into the first: the second-line role drafts the policy it then has to assess.

The AFM (Netherlands Authority for the Financial Markets) noted in its report "Design of the Compliance and Internal Audit Functions" (September 2026) that this still occurs regularly in practice. The AFM is also clear on mandate: the compliance officer must have direct access to the board and relevant committees. Without that access, the function is structurally weak, regardless of how well the procedures look on paper.

Proportionality fully applies here. An SME does not need a compliance department of twenty people, but even a small organisation needs clear arrangements. The capacity can be sourced externally; the steering remains with the organisation itself.

In the AI era, alongside the traditional roles, the AI Compliance Officer (AICO) is gaining importance: the professional who brings AI governance and legal compliance together at the intersection of law, ethics, risk management and technology.

3. Risk appetite: the governance agreement that sets priorities

Risk appetite defines how much risk the organisation is willing to take per risk type. Describe this in concrete statements per risk category and illustrate them with scenarios. Without such an agreement, prioritisation becomes a matter of opinion. With a defined appetite it becomes a decision: this is where we invest, this is where we consciously accept the risk, and this is the owner who can justify it. Use a single methodology so you can compare risks more effectively, and apply it consistently.

It is also the compass for employees in practice: clear boundaries ensure people know when to pause and consult internally.

4. The role of managers: governance becomes concrete behaviour

Governance only works if managers carry it. They are risk owners themselves and the link between the organisation's vision and their team's behaviour. That requires transparency in their decision-making: when is it time to push ahead, and when is it wiser to pause and consult internally?

Good governance helps managers with clear boundaries and concrete scenarios. What are the most common red flags in your organisation? Sending personal data to a private email address, unsupervised use of AI tools for client-related tasks, contacts with competitors outside the regulated framework. Employees who recognise these situations as moments to pause, and who know whom to approach, are the strongest link in the governance chain.

Sovereignty starts in this quadrant

A theme landing on the compliance professional's desk more and more often: digital sovereignty. Under which jurisdiction do we, or do we not, want which data? Who actually has access, and under what law?

This is not a procurement detail; it is a governance decision. Assign ownership of the sovereignty question explicitly, preferably at board level. Establish a classification that pre-structures decisions, so that each new cloud contract does not become a matter of principle. And report periodically on concentration and dependency: what percentage of critical processes relies on a single supplier or a single jurisdiction?

AI as accelerator and as governance object

AI makes it possible to shift the governance cycle from annual to continuous. Think of a regulatory radar: an agent that tracks official gazettes and supervisory authority communications and, for each change, suggests which risks and controls are affected. Or a tool that places charters, job profiles and mandates side by side and flags inconsistencies (mind-numbing work for people, trivial for a model).

But watch out for the flip side: AI output containing a wrong article number or mismatching a requirement quickly becomes your legal justification. Treat the output as a junior colleague's draft, and record who validated it and when. That record is itself an audit object.

And do not forget: an AI application is itself a compliance object. The AI Act imposes requirements on governance, quality management and human oversight. The AICO role therefore becomes not only a governance instrument for AI, but also a governance obligation arising from AI.

From documented to effective: the lesson from the AFM

The AFM report's central message fits this quadrant perfectly: a well-documented compliance function is not yet an effective compliance function. The AFM identifies three recurring shortcomings:

  • Documentation that does not live: a list of laws and regulations is not enough; it must be translated into the organisation's own activities, processes and risks.
  • Lack of coherence in the cycle: if planned activities do not reappear in reports, the cycle loses its steering effect.
  • Compliance assessing its own work: the second line must advise, monitor and assess, not execute. Guarding that boundary is a governance responsibility.

The question is not just whether compliance has been set up, but whether the function has the position, mandate and capacity to act as an independent counterweight.

Legal anchors in this quadrant

Digital Decade legislation enshrines governance ever more explicitly: the Cybersecurity Act obliges the board to approve measures and to complete mandatory training; DORA places ultimate responsibility for the ICT risk framework with the management body; the AI Act requires demonstrable AI literacy; the Corporate Governance Code identifies risk management (including cyber, supplier and AI risks) as a board responsibility.

What you can do this week

One A4, one law. Answer the five governance questions for the law that currently occupies you most: who is the owner, who may make the trade-off, where is independence safeguarded, where does the reporting land, what if things go wrong?

Three risks, three names. Describe three risks you see frequently. No name equals your first finding.

Put the training obligation on the agenda. Use the Cybersecurity Act as an entry point to the board for one concrete question: how do we organise knowledge-building, and who records that it has been completed?

In the next blog

Now that the axle of the wheel is in place, it is time for the spokes. In third blog, we dive into Quadrant 2: Policy & Procedures. How do you translate the growing stack of Digital Decade legislation into concrete, workable controls?

Do you want to know how effectively the governance aspect is set up within your organisation? We would be happy to assist you with a practical maturity assessment or any other services.

Contact us

Back to overview