Regulatory compliance is not limited to having a policy document on file. An organization also needs clear responsibilities, practical procedures, appropriate oversight and a way to identify matters that require attention.
Global Screenings provides regulatory compliance support for corporate and financial organizations reviewing their governance arrangements, risk-management approach, internal procedures and wider compliance responsibilities. The scope is defined around the organization’s activities, industry, jurisdictions and areas of concern.
Compliance Support for Corporate and Financial Organizations
Different industries face different operational and regulatory expectations. A financial institution, investment business, stockbroker, insurer, securities company or international trade supplier may each require a different compliance structure.
Our regulatory compliance support may be relevant to:
- Banks and financial institutions
- Investment businesses
- International stockbrokers
- Insurance companies
- Securities companies
- Trade suppliers
- Corporate organizations operating across several jurisdictions
- Businesses reviewing their governance, policies or risk controls
The purpose is to help the organization examine its existing arrangements and identify areas where further review, clarification or improvement may be required.
Corporate Integrity and Structure Review
A compliance review may begin with the organization’s legal and operational structure. This can help establish how responsibilities are divided, who exercises control and where important decisions are made.
Depending on the agreed scope, the review may consider:
- Corporate structure
- Ownership and management information
- Roles and responsibilities
- Business divisions and reporting lines
- Administrative and operational controls
- Relationships with subsidiaries, branches or associated businesses
- Relevant licences, permits or registrations included in the review
Where the review concerns a business partner, customer, investor or other external party, it may also be supported through Third-Party Integrity Due Diligence.
Administrative Governance
Administrative governance determines how responsibilities are assigned, decisions are approved and important matters are reported within the organization.
A governance review may examine:
- Management responsibilities
- Decision-making authority
- Internal reporting lines
- Oversight and approval procedures
- Escalation of compliance concerns
- Recordkeeping responsibilities
- Internal accountability
- Communication between management and operational teams
Clear governance can help reduce uncertainty over who is responsible for identifying, reviewing and responding to a compliance issue.
Risk Assessment and Management
Risk management involves identifying the matters that may affect the organization, considering their significance and deciding how they should be controlled or monitored.
Depending on the business, the review may consider risks connected with:
- Customers and business partners
- Vendors, suppliers and intermediaries
- Financial transactions
- Corporate structure and ownership
- Regulatory responsibilities
- Internal procedures
- Geographic or cross-border activity
- Reputation and business conduct
- Operational weaknesses
The assessment can help the organization distinguish between routine matters and areas that may require stronger controls, additional screening or management attention.
Where a wider business-risk review is required, the work may also be supported through Global Risk Consulting.
Compliance Policies and Procedures
A policy explains the organization’s intended approach. A procedure explains how that approach should operate in practice. Both need to reflect the organization’s actual activities and responsibilities.
A review may consider whether existing policies and procedures clearly address:
- Responsibilities and approvals
- Customer or third-party review
- Internal reporting
- Recordkeeping
- Risk assessment
- Escalation of concerns
- Management oversight
- Review and update responsibilities
The review may identify unclear wording, gaps between policy and practice, inconsistent responsibilities or procedures that no longer reflect the way the organization operates.
Corporate and Compliance Track Record
An organization’s previous business and compliance history may provide useful context when reviewing its current structure and responsibilities.
Depending on the information available and the agreed scope, a track-record review may consider:
- Corporate history
- Previous business activities
- Management and ownership changes
- Available regulatory information
- Litigation or dispute history
- Public records
- Reputation and media information
- Other matters relevant to the compliance review
A previous issue should be considered in context. The date, source, current status and action taken by the organization may all affect its relevance.
Compliance Outsourcing Support
Some organizations require external support for selected compliance tasks, particularly when internal resources are limited or when a matter involves several countries or third parties.
Compliance outsourcing support may include agreed activities such as:
- Collection and organization of relevant information
- Corporate and public record research
- Background screening of selected third parties
- Review of documents included in the agreed scope
- Follow-up on missing or incomplete information
- Preparation of research findings
- Support for periodic review requirements
- Reporting matters requiring internal consideration
Where vendors or suppliers are part of the compliance concern, the work may also include Vendor Screening.
External support does not transfer the organization’s regulatory or management responsibilities. The client remains responsible for its compliance decisions, approvals and required actions.
Reviewing Organizational Objectives
An organization’s commercial objectives should be considered alongside its risk controls and compliance responsibilities. A growth plan, new market, investment activity or wider supplier network can create new requirements that were not relevant when the existing procedures were introduced.
An organizational review may consider:
- The stated business objectives
- The activities required to achieve those objectives
- The countries and markets involved
- The customers, suppliers or partners concerned
- The current governance and approval structure
- The risks created by the planned activity
- Whether existing policies and procedures remain suitable
This can help management understand whether the organization’s current compliance arrangements continue to reflect the way the business is developing.
Defining a Compliance Review
A useful compliance review begins with a clear understanding of the organization and the reason for the instruction.
The initial scope may consider:
- The industry and type of business
- The jurisdictions in which the organization operates
- The regulatory or operational concern
- The existing governance structure
- The policies and procedures available for review
- The customers, vendors or transactions involved
- The outcome the organization needs from the review
A defined scope helps keep the review focused on the matters that are relevant to the organization rather than applying the same process to every business.
Reporting and Follow-Up
The completed review may identify:
- Information that appears consistent with the organization’s stated procedures
- Responsibilities that require clarification
- Missing or incomplete records
- Policies or processes that may need further review
- Risks requiring management attention
- Third parties or transactions that may require additional due diligence
The findings should distinguish between a confirmed issue, an area requiring clarification and a recommendation for further professional review.
International Compliance Considerations
Regulatory and compliance requirements vary between countries and industries. A process used in one jurisdiction may not satisfy the requirements of another.
Cross-border organizations may also need to consider differences in:
- Corporate and financial regulation
- Licensing and registration
- Privacy and data protection
- Customer and third-party screening
- Reporting and recordkeeping
- Industry-specific responsibilities
The jurisdictions and activities involved should therefore be identified before the expected scope and applicable areas of review are confirmed.
Important Limitations
Global Screenings provides research, review and compliance-support findings from the agreed scope. The service does not issue regulatory approval, certify that an organization is fully compliant or replace advice from qualified legal, regulatory, accounting or compliance professionals.
Final responsibility for policies, controls, regulatory submissions, management decisions and compliance obligations remains with the client and its appointed advisers.