Compliance Programme
What is Compliance Programme?
A structured set of internal policies, procedures, training, and monitoring activities designed to ensure an organisation adheres to applicable laws, regulations, and industry standards.
Terms that appear alongside compliance programme
Each of these is named in at least one of the same controls as compliance programme. The number is how many controls name both.
- compliance 17 shared controls
- audit 6 shared controls
- governance 5 shared controls
- due diligence 4 shared controls
- corporate compliance 3 shared controls
- policy 2 shared controls
- information sharing 2 shared controls
- internal audit 2 shared controls
Frameworks that govern compliance programme
What the standards actually require on compliance programme
Requirements naming compliance programme across 6 standards, quoted from the control text.
Per FCPA Resource Guide + DOJ Evaluation of Corporate Compliance Programs: compliance programme + risk-based DD on third parties + agents + JV partners + M&A + training.
USFCPA-4 · Compliance Programme and Due Diligence →Financial institutions shall establish a written AML compliance programme approved by the board, with policies, procedures, internal controls and ongoing oversight under 31 CFR 1020.210.
BSA-AML-01 · AML Compliance Programme →KVKK Board Decision 2019/10 requires periodic internal audits as part of adequate measures. Audits cover processing inventory accuracy, lawful basis assessment, security controls, processor compliance, DSR handling, and training effectiveness.
KVKK-Audit · Internal Audit and Compliance Programme →Governments work to harmonize cross-border control measures, which may include mutual recognition of control measures and compliance programmes, sharing of resources and techniques, and accepting clearance carried out by the other party.
SAFE-P3-S10 · Harmonization of cross-border control measures →Counterparty VASP Due Diligence (CVDD): VASPs must conduct due diligence on counterparty VASPs (the VASP on the other side of a virtual asset transfer) BEFORE establishing a counterparty relationship + on an ongoing basis.
R.16-VATR.CVDD · Counterparty VASP Due Diligence (CVDD) →Runs the privacy compliance programme, including the assessments and records that show personal information is handled lawfully.
NICE-OG-WRL-008 · Privacy Compliance →Questions people ask about compliance programme
What is Compliance Programme?
Why is Compliance Programme important for compliance?
Which compliance frameworks address Compliance Programme?
Where can I learn more about Compliance Programme?
See how Compliance Programme applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.