A requirement becomes manageable when someone owns the decision, operates the control and can show that it works.
Start with the decision, not the spreadsheet
A regulatory update lands in the compliance inbox. It is logged, circulated and marked as reviewed. Yet the business continues working in exactly the same way. The information has moved; the organisation has not. This is a useful place to begin when examining the strength of a compliance programme.
Regulatory compliance involves understanding applicable requirements and translating them into business practice. Integrity risk management asks a related question: where might pressure, opportunity or accepted habits lead people to act against the organisation’s commitments? The two perspectives belong together. A legal register may identify a duty, while conversations with operations reveal why following it is difficult.
Our proposed starting point is a decision map. Identify the moments that matter: accepting a customer, selecting an intermediary, approving an expense or releasing a product. For each moment, connect the relevant obligation with the person who makes the decision and the information they need. This gives the register a practical purpose.
Translate the requirement into a control
Avoid treating every new publication as an immediate instruction for every employee. First establish its status, jurisdiction, scope and relevance to the organisation. Distinguish binding requirements from guidance and voluntary commitments. Where applicability is uncertain, obtain an interpretation from someone qualified to make it and record the reasoning.
Then define the required change in observable terms. “Improve due diligence” is difficult to implement. “The relationship owner must resolve unexplained beneficial ownership before approval” creates a decision that can be reviewed. Specify who operates the control, when it is triggered, what evidence is retained and who can resolve an exception.
An obligation can require several controls across a process. Equally, one well-designed control can support several obligations. Keep those relationships visible so a change in the rule does not leave an outdated procedure operating unnoticed.
Bring integrity risk into the conversation
Ask the people doing the work what makes the right action inconvenient. A procurement team may understand a conflict-of-interest rule while believing that challenging a favoured supplier is professionally dangerous. A control design that ignores that pressure will miss an important part of the exposure.
Use a short scenario rather than an abstract label. Describe the decision, the potential misconduct, the conditions that enable it and the people who could be harmed. Separate existing safeguards from proposed improvements. Record uncertainty where evidence is weak instead of giving every risk a confident numerical score.
The September 2024 US Department of Justice guidance discusses risk-based programme design and adaptation to changing circumstances. It is a prosecutorial evaluation framework, not a universal legal checklist. Its contextual approach provides a useful reference point for this exercise.
Reference: DOJ evaluation guidance (September 2024).
Look for evidence that changes your judgement
A completed action does not automatically mean a risk has fallen. Sample actual decisions after a control changes. Can reviewers reconstruct what happened? Were exceptions challenged? Did people seek advice early enough for it to matter?
Combine records with conversations. A high number of questions might indicate confusion, or it might show that employees trust the advice channel. A low number of reported incidents might indicate effective prevention, or silence. Interpret the pattern alongside workload, business changes and the ability to speak openly.
Review the map when the business enters a market, changes its delivery model or identifies misconduct. The useful output is a prioritised set of decisions and controls to improve, with a named owner and evidence needed to close each action.
Put it into practice
- Select one important business decision and identify its applicable obligations.
- Interview its operator about pressure, workarounds and escalation.
- Trace three recent cases from request to approval, including an exception.
- Agree one improvement and the evidence that will show whether it works.
Sources and scope
US Department of Justice — Evaluation of Corporate Compliance Programs, September 2024
Compliance House’s practical analysis, with illustrative scenarios. Framework references are identified above. Apply the approach to your organisation and confirm the legal requirements relevant to its jurisdictions and activities. References checked 15 September 2026.