Compliance · Integrity · Culture

Compliance: acting with integrity

Compliance is often reduced to respecting applicable texts. This is necessary, but partial. The third dimension of GRC covers more broadly the fact of acting with integrity: respecting legal and regulatory obligations, and complying with the values the organisation has set for itself.

Category: Compliance Reading time: 7 minutes

The first register is that of applicable obligations laws, regulations, circulars, industry standards. It is objectifiable — we can draw up an inventory of them, monitor their developments and demonstrate compliance. This is the usual territory of the compliance function.

Two registers

Applicable obligations and specific commitments

Culture

What happens when nobody is looking

Upstream

Integrated into processes rather than added as an afterthought

01

Two registers, not just one

The second is that of clean commitments values, code of conduct, internal policies, promises made to customers. Nothing legally binds the organisation to these, other than itself. Yet this register is crucial: it is what determines behaviour in the areas that texts do not cover — and those areas are vast.

Why both matter: The most reputationally costly failures rarely result from a clear-cut breach. They most often stem from practices that are formally compliant, but contrary to what the organisation claimed to stand for.
02

Beyond formal compliance

A compliance programme can be comprehensive on paper and inoperative in practice. The signs are recognisable: exhaustive policies that no one consults, training courses taken for the certificate they issue, and checks carried out without their findings changing anything.

This device produces documentary evidence — and a deceptive assurance. It costs, it occupies, and it does not protect. Moving to an effective system requires verifying not that procedures exist, but that they produce the expected behaviours.

03

Culture: the determining factor

The compliance culture refers to what happens when no controls are in place. It is measured less by statements than by observable signals:

  • Do employees flag up difficulties, or do they learn that it is better to keep quiet?
  • Is a breach dealt with in the same way regardless of the hierarchical level involved?
  • Is compliance consulted ahead of projects, or afterwards for validation?
  • Do commercial objectives and compliance requirements conflict without explicit arbitration?

Management behaviour carries more weight than any set of documentation. An exception granted to a senior executive effectively cancels out the impact of several training sessions.

04

The interface with risks

Compliance and risk management deal with related subjects using distinct rationales — hence frequent friction. Compliance reasons in terms of obligations: they apply or they do not. Risk management reasons in terms of probability and impact: it prioritises.

The two approaches can be reconciled. Compliance with an obligation is not negotiable; however, the'level of checks deployed to ensure this is a matter of risk assessment. A failure with major consequences justifies a reinforced mechanism; a low-stakes obligation does not merit the same effort. Making this connection explicit avoids two symmetrical pitfalls: uniform, costly and demotivating control, and the neglect of obligations deemed minor.

05

The Luxembourgish context

For regulated financial entities, the compliance function — often headed by a compliance officer (RC) and, where applicable, a member of senior management — must meet specific requirements: independence, direct access to management and the board, proportionate resources, and regular reporting.

Two main areas focus the supervisor's attention: the fight against money laundering and the financing of terrorism (AML/CFT), with its customer due diligence, monitoring and reporting obligations; and the protection of personal data. In both cases, the expected proof concerns not only the existence of procedures, but their effective and traceable application — the subject of the next article.

This requirement for effectiveness also implies being able to link what was planned to what was actually executed. Centralising control plans, completed works, findings, recommendations and their follow-up helps to maintain a clearer overview of the framework — and above all, to demonstrate how it operates over time.

06

Common pitfalls

  • Reduce compliance to the formal observance of texts, while neglecting actual commitments.
  • Accumulating policies without ensuring their dissemination, understanding, or updating.
  • Positioning compliance at the end of the process, as a validation body.
  • Apply a uniform level of control, without prioritising by stakes.
  • Tolerate exceptions at the top, which ruin the credibility of the whole.
07

The ARCAD approach

ARCAD examines compliance frameworks from the perspective of their effectiveness: are obligations identified and monitored, are controls calibrated to the actual risks, are findings followed up with action, and is the function consulted prior to decisions being made? The firm also acts on AML/CFT mandates and provides training, notably on anti-money laundering and terrorist financing.

Assess the effectiveness of your compliance programme.

ARCAD conducts compliance audits, compliance officer mandates and training, including in the area of AML/CFT.

Schedule an exchange →

References & further reading

  • OCEG works (Open Compliance and Ethics Group) on the compliance dimension of GRC.
  • Financial Action Task Force (FATF) Recommendations on AML/CFT.
  • Requirements applicable to the compliance function of entities regulated by the CSSF.

Note: good practice to be adapted to the profile, size and regulatory framework specific to each organisation; does not constitute legal advice.