What is Compliance Oversight?
Compliance oversight involves the Board of Directors' top-down responsibility to establish, maintain, and review a Compliance Management System (CMS) that ensures an organization adheres to evolving regulatory requirements through documented policies, risk management, employee training, audits, and corrective actions to protect the organization from enforcement actions and regulatory risks across sectors like healthcare, finance, and cybersecurity.
Regulatory compliance is continuously evolving, making it imperative that everyone involved in the Compliance Management System (CMS) understands their responsibilities. Various sectors mandate oversight, including healthcare, finance, and cybersecurity. Compliance management is a top-down system, established and maintained through the Board of Directors’ oversight, ensuring the regulatory process is fully functional within the organization.
Reviewing the CMS: What’s Required?
The core functions of a CMS are to protect the organization and to follow the rules that impact the business and its consumers. An effective CMS prevents enforcement actions, such as penalties and litigation, manages regulatory risks, and ensures that threats are identified and mitigated.
A CMS is how an entity:
- Acquires information about compliance responsibilities
- Conveys compliance responsibilities to employees, vendors, and the public
- Incorporates compliance requirements into business processes
- Evaluates processes to confirm responsibilities are implemented and requirements are achieved
- Performs updates and corrective actions
Regulatory institutions each have specific requirements. At a minimum, compliance audits, risk assessments, a written compliance program, and oversight of the Board of Directors apply to all.
The CMS is instituted through a documented program, which includes written requirements for risk management and compliance issues. Formal policies within the program establish methods to guide the organization’s regulatory steps. The CMS policies outline employee training. For staff and employees, the written CMS is also a valuable reference tool and provides a dedicated method to interact with the public and provide services that meet regulatory requirements.
Role of the Board of Directors
Implementing and sustaining an effective CMS are chief oversight responsibilities for the Board of Directors. The FDIC states: “The Board of Directors is ultimately responsible for developing and administering a CMS that ensures compliance with federal consumer protection laws and regulations.”
Board oversight includes:
- Identifying compliance expectations for the institution and impacted vendors and providers
- Developing organizational statements that unequivocally convey regulatory requirements
- Selecting a compliance officer and understanding the duties of the officer
- Ensuring the compliance officer can conduct tasks with proper authority and accountability
- Appropriating financial resources toward compliance functions based on the organization’s requirements
- Requiring and reviewing compliance audits
- Providing a system to receive regular reports from the compliance officer
- Applying or approving corrective measures to regulatory risks and providing follow-up to ensure these are satisfactorily completed
One of the most important areas for the Board to understand is the role of the compliance officer. An adequate flow of information from the compliance officer is essential to oversight.
The compliance officer represents the operational lead for the regulatory needs of the organization. They may develop operational policies or procedures, which must meet the compliance requirements of the organization. Employee and management training, instituted or delivered by the compliance officer, should align with the organization’s regulatory goals. The compliance officer should report on these areas to the Board periodically.
If applicable laws or regulations evolve or a new risk is identified, necessitating a change in institutional policy statements, the compliance officer should be aware and inform the Board. This means the compliance officer should regularly review policies, as well as emerging trends or potential liabilities, and deliver these findings to the Board.
To perform duties of compliance management, the Board must allow the compliance officer the authority to function in duties. As the FDIC states, the compliance officer should have sufficient authority to:
- Cross-departmental lines
- Have access to all areas of the institution’s operations
- Effect corrective action
The Board’s oversight may include assessing the compliance officer’s authority and offering additional leadership support. For example, a compliance committee may be necessary to assist the compliance officer in directing the CMS.
Oversight is Proactive and Engaging
Board of Directors oversight must extend beyond digesting reports from compliance officers. Properly implemented compliance oversight is proactive and regularly monitors and evaluates the organization’s CMS with the emerging regulatory landscape.
Boards are expected to put forth a meaningful effort to review the adequacy of existing compliance systems and functions. Board Members should know the organization’s CMS well enough to ask the right questions. The correct questions produce a useful compliance framework for the organization.
Questions to consider include:
- Are departments sharing pertinent compliance information with each other and with the Board?
- If the legal department discovers a potential area of regulatory risk or possible fraud, what is the reporting process?
- How are corrective measures applied to the organizational level?
- Is the Board engaged in reviewing these corrections?
- What is the purpose of this rule or regulation?
- How are we fulfilling those requirements to the affected parties?
The Board should periodically examine the responsibilities and roles of legal, quality, and audit departments. Each of these is central to compliance—yet independent.
The Office of Inspector General (OIG) believes an organization’s compliance officer “should neither be counsel for the provider nor be subordinate in function or position to counsel or the legal department, in any manner.” In other words, the compliance officer should collaborate as an equal with other departments to enact the CMS. Oversight ensures this is achieved.
While oversight depends on the influx of information and expert input, striking a balance between too little or too much compliance information can be difficult. Some boards use dashboards or similar tools that contain key operational, fiscal, or strategic plans to moderate information. Risk-reporting and compliance can be integrated into these tools to provide an overview of the pertinent CMS information to the Board. However, methods or policies should be established to ensure prompt reporting to the Board if specific risk-based criteria are triggered.
Organizational accountability is another area directed by Board oversight. Incentives for accountability, as well as maintaining an appropriate level of corporate transparency, stem from policies the Board enacts.
Oversight is a Process
It’s a tall order for Boards to stay on top of all this and still function in other organizational leadership roles. But engaging and effective Board oversight is an ongoing process, not a destination. Just as the regulatory environment is continuously evolving, oversight needs to be consistently developing and changing to meet those demands.