Governance
Compliance Roles and Accountability
How boards, executives, managers, compliance staff, control owners and assurance functions share responsibility.
Why this matters
How boards, executives, managers, compliance staff, control owners and assurance functions share responsibility.
Accountability starts with operations
The people who run a process usually own its compliance outcomes. A compliance function can interpret requirements, advise, challenge and monitor, but it cannot operate every control on behalf of the business.
Leadership responsibilities
Boards and senior leaders set expectations, approve risk appetite, provide resources, review significant issues and challenge overdue corrective actions. Their records should show meaningful oversight rather than ceremonial approval.
Control owners
A control owner is responsible for the design, operation, evidence and remediation of a control. Ownership should be assigned to a role with authority and access to the process, not merely to the person who writes the policy.
Independent challenge
Second-line compliance or risk teams may monitor and challenge. Internal audit or other assurance functions may independently test governance and control effectiveness. The exact structure varies, but independence should be clear.
Delegation and backup
Named backups, documented handoffs and escalation thresholds reduce key-person dependency. Delegation does not remove accountability from the responsible leader.
Questions to document
- Which obligations and processes are in scope?
- Who owns the activity and who independently reviews it?
- What record demonstrates that the activity operated?
- What happens when the control fails or circumstances change?
Related planning tools
Use the local planning tools to turn the concepts into a structured working note.