What is Compliance Management?
What is compliance management, described as work rather than as a function? It comes down to three questions you should be able to answer at any time.
Which obligations apply to us? Legislation, regulation, modern awards, standards, customer contracts and licence conditions. Most organisations have never written that list down anywhere, which makes everything that follows it guesswork.
Who owns each one? A named person rather than a department. An obligation owned by everyone in general is owned by nobody in particular.
How would we show we met it? Which record proves it, held where, and retained for how long.
An organisation that can answer all three of those is managing compliance. One that has policies and training in place but no obligations register underneath them is managing activity instead.
ASIC publishes governance guidance. This is general information rather than legal advice, and obligations vary by state and territory.
See Sentrient’s workplace compliance system and GRC system.
Compliance Management System: What It Is, And What It Is Not
Quick Answer: A compliance management system, or CMS, is the structure an organisation uses to meet its obligations and prove that it did. Australia has a published definition: AS ISO 37301:2023, which identically adopts ISO 37301:2021 and covers establishing, developing, implementing, evaluating, maintaining and improving one. The distinction that matters is that compliance management is […]
