Compliance · Integrity · Culture
Compliance: acting with integrity
Compliance is often reduced to respecting applicable texts. This is necessary, but partial. The third dimension of GRC covers more broadly the fact of acting with integrity: respecting legal and regulatory obligations, and complying with the values the organisation has set for itself.
The first register is that of applicable obligations laws, regulations, circulars, industry standards. It is objectifiable — we can draw up an inventory of them, monitor their developments and demonstrate compliance. This is the usual territory of the compliance function.
Two registers
Applicable obligations and specific commitments
Culture
What happens when nobody is looking
Upstream
Integrated into processes rather than added as an afterthought
Two registers, not just one
The second is that of clean commitments values, code of conduct, internal policies, promises made to customers. Nothing legally binds the organisation to these, other than itself. Yet this register is crucial: it is what determines behaviour in the areas that texts do not cover — and those areas are vast.
Beyond formal compliance
A compliance programme can be comprehensive on paper and inoperative in practice. The signs are recognisable: exhaustive policies that no one consults, training courses taken for the certificate they issue, and checks carried out without their findings changing anything.
This device produces documentary evidence — and a deceptive assurance. It costs, it occupies, and it does not protect. Moving to an effective system requires verifying not that procedures exist, but that they produce the expected behaviours.
Culture: the determining factor
The compliance culture refers to what happens when no controls are in place. It is measured less by statements than by observable signals:
- Do employees flag up difficulties, or do they learn that it is better to keep quiet?
- Is a breach dealt with in the same way regardless of the hierarchical level involved?
- Is compliance consulted ahead of projects, or afterwards for validation?
- Do commercial objectives and compliance requirements conflict without explicit arbitration?
Management behaviour carries more weight than any set of documentation. An exception granted to a senior executive effectively cancels out the impact of several training sessions.
The interface with risks
Compliance and risk management deal with related subjects using distinct rationales — hence frequent friction. Compliance reasons in terms of obligations: they apply or they do not. Risk management reasons in terms of probability and impact: it prioritises.
The two approaches can be reconciled. Compliance with an obligation is not negotiable; however, the'level of checks deployed to ensure this is a matter of risk assessment. A failure with major consequences justifies a reinforced mechanism; a low-stakes obligation does not merit the same effort. Making this connection explicit avoids two symmetrical pitfalls: uniform, costly and demotivating control, and the neglect of obligations deemed minor.
The Luxembourgish context
For regulated financial entities, the compliance function — often headed by a compliance officer (RC) and, where applicable, a member of senior management — must meet specific requirements: independence, direct access to management and the board, proportionate resources, and regular reporting.
Two main areas focus the supervisor's attention: the fight against money laundering and the financing of terrorism (AML/CFT), with its customer due diligence, monitoring and reporting obligations; and the protection of personal data. In both cases, the expected proof concerns not only the existence of procedures, but their effective and traceable application — the subject of the next article.
This requirement for effectiveness also implies being able to link what was planned to what was actually executed. Centralising control plans, completed works, findings, recommendations and their follow-up helps to maintain a clearer overview of the framework — and above all, to demonstrate how it operates over time.
Common pitfalls
- Reduce compliance to the formal observance of texts, while neglecting actual commitments.
- Accumulating policies without ensuring their dissemination, understanding, or updating.
- Positioning compliance at the end of the process, as a validation body.
- Apply a uniform level of control, without prioritising by stakes.
- Tolerate exceptions at the top, which ruin the credibility of the whole.
The ARCAD approach
ARCAD examines compliance frameworks from the perspective of their effectiveness: are obligations identified and monitored, are controls calibrated to the actual risks, are findings followed up with action, and is the function consulted prior to decisions being made? The firm also acts on AML/CFT mandates and provides training, notably on anti-money laundering and terrorist financing.
Assess the effectiveness of your compliance programme.
ARCAD conducts compliance audits, compliance officer mandates and training, including in the area of AML/CFT.