Cadence refers to a regular, rhythmic flow of activity.

The cadence of compliance refers to compliance infrastructure and the information and data that flows through the infrastructure. The cadence of compliance is critical to ensure that a firm’s compliance measures are adequate and documented, enabling self-regulation and self-reporting.

A compliance cadence, importantly, enables the firm’s compliance measures to evolve and adapt through business growth, innovation, use of automation, and the development of new products, services, distribution channels and partnerships.

Compliance infrastructure

Think of a pipeline infrastructure in the energy sector. The network of pipelines, compressor stations, valves, and monitoring systems used to transport crude oil, natural gas, and refined products.

Similarily, the pipeline infrastructure for compliance is the network of governance, IT systems, people and processes used to transport risk and compliance information and data flows.

The components of compliance infrastructure

Governance

Including:

  • roles and responsibilities, based on the 3 lines of defence accountability model;
  • delegated authority for risk-decision making, based on the firm’s risk appetite statement;
  • risk and compliance committees including sub-committees such as the breach management committee;
  • monitoring and supervision including of the compliance system and of staff, authorised representatives, distributors and service suppliers;
  • training and competency mechanisms;
  • regulatory change management;
  • product governance (design and distribution obligations);
  • reporting to business operations, management, board, business partners, stakeholders and regulators; and
  • record keeping.

Licence management

This includes those things that must be done to maintain an AFSL/APRA licence/authorisation such as:

  • annual regulatory returns;
  • ASIC IDR data reporting;
  • notifying regulators of change of details including changes in responsibilities (such as responsibile managers);
  • administrative matters; and
  • changes to licence authorisations and conditions

Risk management processes

This includes how risks and complance obligations are managed:

  • identification;
  • analysis;
  • evaluation;
  • treatment; and
  • monitoring

Frameworks and sub-frameworks

Aligned to governance however it is important to ensure that there is an overarching framework (enterprise risk management framework (ERMF)) and sub-frameworks such as obligations management, incidents , complaints, monitoring, product governance etc that align with and are connected to the ERMF.

Information and data flows

With the compliance pipeline infrastructure in place the test of the adequacy of the system is the information and data that flows through the infrastructure.

Data and information enables risk decision-makers to self-regulate and self-report.

Data and information

This includes and is not limited to:

  • incidents including regulatory/code incidents, operational risk incidents, cybersecurity incidents, people incidents and financial incidents;
  • complaints
  • conflicts of interest
  • quality assurance, audits, and file reviews (underwriting, claims and broking)
  • control testing outcomes
  • risk profiling
  • obligation management
  • remediation and rectification activities
  • training
  • risk committee meetings
  • business operational data
  • attestations

The cadence of compliance must be documented

Documentation helps you demonstrate whether or not you are complying with the general obligations. When you document your measures, we [ASIC] expect this will include details of who is responsible, the timeframes involved and associated record keeping and reporting. (ASIC RG 104.26)

In addition a documented cadence of compliance:

  • supports training and education for staff, authorised representatives and service suppliers;
  • provides assurance to management, board, partners and regulators that risk and compliance is being adequately managed;
  • enables obligations to be met;
  • enables material risks to be managed;
  • provides evidence of compliance; and
  • supports change management.

Disclaimer: Reproduction of statements made in this article by media outlets, whether in full or in part, is strictly prohibited without the written express consent of the author. The views, opinions, and positions expressed within this article are those solely of the author and Compliance Advocacy Solutions Pty Ltd and not the views of other individuals, companies or organisations they may be affiliated with. The author and Compliance Advocacy Solutions Pty Ltd make no representations as to accuracy, completeness, currency, suitability, or validity of any information in this article and will not be liable for any errors or omissions or any loss or damage arising from its use or reliance. This article is intended for educational and informational purposes only and should not be relied upon as professional legal advice.