Our clients regularly tell us that developing and maintaining an effective compliance programme is one of the most challenging areas they face. Not only is a raft of new legislation making it difficult to keep abreast of changes, but the increase in regulation and legislation targeting corporate governance and corporate behaviour is adding to the pressure of getting it right.
The focus and the regulations that govern your business will vary depending on your operations and industry sector. The framework to determine and implement the necessary measures to ensure compliance, however, are highly transferable across different sectors and industries. With that in mind, we developed our Compliance Blueprint to bring clarity and shape to the compliance process, so the businesses we support can have confidence that they are operating ethically and within the law.
In this blog, we will give you more information about our Compliance Blueprint, what it covers, how the process works and what outcomes you can expect. If you would like to book an appointment to find out more about how it could work in your business, please complete the enquiry form on our Compliance Blueprint page or give us a call on 020 3056 8538.
How the risk assessment workflow works
This risk assessment workflow sets out the procedure that a Client Legal Director follows to produce a Compliance Blueprint report.
Following the steps gives valuable, actionable insights, providing an overview of a business’s current situation, helping to bring focus on the potential impact of non-compliance and to prioritise the most urgent enhancements.
Step one: Begin Assessment
The first step in the process is to decide the scope of the assessment. Compliance requirements focus on the internal controls, but also the external rules that govern how a business should operate. It is therefore necessary to consider any required risk assessments by any external agencies when determining the scope.
You may decide to concentrate on a particular area or areas in your assessment. Broadly speaking, they fall under: corporate governance & oversight, regulatory compliance, financial compliance, HR compliance, IT compliance and health & safety compliance.
Step two: Assess inherent exposure to risk for the business without any controls
In this second stage of the assessment, a Client Legal Director would assess the risk driven purely by the nature of your business, the markets you operate in, the rules and regulations that apply, and the clients/suppliers you engage with. How likely is a violation of any applicable legislation in the normal course of your business operations with no controls in place, and if a violation does occur how severe will the impact on your business be?
These considerations will then be charted on a matrix to produce an inherent risk of either high, medium or low.
Step three: Assess the strength of the controls currently deployed
Understanding the current status of your compliance is key to developing a sound compliance programme. So, at this stage, the Client Legal Director will assess your current controls and, employing a scoring system, rate each control as either high, medium or low.
Your control assessment may consider, amongst other elements, how comprehensive and up to date your documented policies and procedures are, what training is in place and any documented violations you may have.
Step four: Calculate the residual risk to the business, using the inherent risk and control strength scores
By cross referencing the inherent risk and strength of current controls, the Client Legal Director can now calculate the residual risk to which your business is ultimately exposed.
Step five: Report to management
A report of their findings with recommendations for enhancements will now be delivered to management. Management will need to consider whether the risks identified fall within risk tolerances that are acceptable to them. They will also consider whether the scope of the initial risk assessment was sufficient.
Based on these considerations, management will decide if they want to proceed with the recommended enhancements. As part of the Compliance Blueprint, the Client Legal Director will support management in these decisions and record any conclusions and actions in writing so they can be kept in accordance with the record retention requirements.
Step six: Improve controls
After reporting the findings, the Client Legal Director will then devise a plan to implement the recommendations based on the priorities identified and the feedback from management.
Each Compliance Blueprint undertaken is bespoke. And if you require help implementing the plan, we can offer that support on an ongoing basis too.
Establish a policy management framework
To support regular review and a consistent approach to ongoing compliance matters, the Compliance Blueprint service can include the development and maintenance of a policy management framework.
Setting down a standard and principles for policy development, approval, implementation and review across a business, it includes information about the process for assigning a senior manager with ownership of the policy, preparing or updating policy documents, engaging in stakeholder consultation and ensuring appropriate oversight and approval.
Get in touch
If you are interested in knowing more about our Compliance Blueprint or would like us to give you a quote for the work you need, please give us a ring on 020 3056 8538, fill in the enquiry form on our Compliance Blueprint page or send us an email.
Related Posts
-
An overview of the current status of your compliance and information on the scope of the future engagement required to maintain a robust and comprehensive compliance programme.
-
The increase in regulation and legislation targeting corporate governance and corporate behaviour makes it more important than ever to get governance right and to develop and maintain a robust compliance programme.

