← Back to blog

Building a compliance program: your 2026 step-by-step guide

July 23, 2026
Building a compliance program: your 2026 step-by-step guide

A compliance programme is an organisational framework of policies, controls, training, and oversight mechanisms that keeps a business operating within its legal, regulatory, and ethical obligations. Done well, it moves an organisation from reactive firefighting to proactive risk management. Done poorly, it produces a binder nobody reads and a false sense of security that collapses the moment a regulator arrives.

The most effective programmes share a common architecture, regardless of sector. The DOJ Evaluation of Corporate Compliance Programs frames this around three fundamental questions: is the programme well designed, is it applied in good faith, and does it actually work? Those three questions should sit above every decision you make when building yours.

The core elements of any credible compliance programme include:

  • Written policies and procedures that map to specific regulatory obligations
  • Leadership oversight with genuine board and executive sponsorship
  • Risk assessments that drive prioritisation rather than follow it
  • Training and communication tailored by role, not delivered as a single annual event
  • Internal monitoring and independent auditing as distinct, scheduled activities
  • Reporting mechanisms including protected whistleblowing channels
  • Corrective action procedures with named owners and deadlines
  • Continuous improvement governance with documented lessons learned

The steps below follow a deliberate sequence. Building policies before you have a risk assessment produces policies nobody follows. Building controls before you have policies produces workflows that cannot be audited. The order is the method.


Infographic showing step-by-step compliance program process

1. Define clear policies and standards for compliant operations

Policies are the backbone of any compliance programme. Without them, every decision about what is and is not acceptable behaviour becomes a matter of individual interpretation, which is precisely what regulators penalise.

A formal, written compliance programme serves two purposes simultaneously: it guides day-to-day behaviour and it functions as a reference document during audits and regulatory reviews. Every policy should state its objective, the specific regulatory obligation it addresses, the steps required to meet that obligation, and who is accountable for each step. Vague aspiration is not policy.

When mapping policies to regulatory frameworks, UK-based organisations typically need to address the Financial Conduct Authority (FCA) rules, the UK General Data Protection Regulation (UK GDPR), sector-specific requirements such as the Care Quality Commission (CQC) standards in healthcare, and the Building Safety Act 2022 in construction. The policy set should reflect the actual regulatory landscape the organisation operates within, not a generic template borrowed from another sector.

Key considerations for building your policy framework:

  • Map each policy to a named regulatory source so that updates to legislation trigger automatic policy reviews
  • Assign a named owner to every policy, responsible for annual review and interim updates when regulations change
  • Version-control all documents with approval dates, reviewer names, and change logs
  • Write for the reader who will use the policy, not the regulator who will audit it; plain language reduces misapplication
  • Build in delegation of authority so that staff know exactly what decisions they can make independently and what requires escalation
  • Structure policies to support audit readiness by cross-referencing the controls that implement them

Policies should be reviewed at least annually, and more frequently when the regulatory environment shifts or the organisation changes its products, markets, or operating model.


2. Conduct thorough risk assessments to inform programme priorities

Risk assessment is the document that drives every prioritisation decision in a compliance programme. It must come before the policy set, not after. Organisations that skip this step end up with policies that address theoretical risks while genuine exposures go unmanaged.

Colleagues discussing risk assessment reports

The purpose of a compliance risk assessment is to identify where the organisation is most likely to breach its obligations, estimate the likelihood and impact of each breach, and rank risks so that resources go to the areas of greatest exposure. A risk register built on the NIST SP 800-30 framework provides a structured, auditable output that regulators and auditors recognise as credible.

Identifying compliance risks requires looking across three dimensions: legal obligations (statutes, regulations, licences), operational processes (where human error or system failure could cause a breach), and third-party relationships (where your obligations extend to suppliers, contractors, and service providers). In UK healthcare and construction, third-party risk is consistently underestimated. A contractor who mishandles personal data or a subcontractor who ignores safety protocols creates liability for the commissioning organisation, not just for themselves.

Practical steps for an effective risk assessment process:

  • Scope the assessment by business unit, data type, geography, and regulatory framework before starting
  • Involve operational staff, not just legal and compliance teams; the people doing the work know where the real gaps are
  • Build a risk register with columns for risk description, likelihood, impact, inherent risk score, existing controls, residual risk score, and owner
  • Approve the register at committee level and update it quarterly; a stale risk register is treated by auditors as evidence of programme neglect
  • Use the outputs to shape your control design, training priorities, and audit schedule rather than treating the assessment as a standalone exercise
  • Reassess when the organisation changes its products, enters new markets, or adopts new technologies, because a programme that was effective three years ago may be inadequate today

3. Establish governance structures and secure leadership commitment

Visible and vocal leadership support is the single most important factor in whether a compliance programme actually works. Regulators increasingly focus on individual executive responsibility alongside corporate accountability, which means the days of treating compliance as a back-office function are over.

Executive leader addressing compliance governance

The board of directors carries ultimate responsibility for the compliance management system. That responsibility is discharged through clear policy statements, the appointment of a compliance officer with genuine authority, and the allocation of resources proportionate to the organisation's size, risk profile, and complexity. A compliance officer who lacks the authority to cross departmental lines or access all areas of operations cannot do the job.

Governance structure typically includes three layers: board-level oversight (setting expectations and reviewing outcomes), an executive compliance committee (approving policy changes, reviewing risk registers, and authorising corrective action), and operational compliance ownership (named individuals responsible for specific controls and processes). Each layer needs defined responsibilities, a meeting cadence, and documented minutes. Those minutes are audit evidence.

Building effective governance requires:

  • A programme charter signed by the chief executive or equivalent, establishing scope, accountability, and authority
  • A compliance officer with sufficient independence to report directly to the board or a board committee
  • Executive sponsorship that is visible to the workforce, not just stated in a policy document
  • Clear escalation paths so that staff know how to raise concerns and what happens when they do
  • Third-party oversight mechanisms that extend compliance expectations to suppliers and contractors, not just internal staff
  • Regular board reporting on compliance metrics, audit findings, and open corrective actions

Flat organisational structures need to evolve with dedicated roles and clear ownership as the business scales. Giving the compliance officer title to whoever is available, rather than whoever has the expertise, is one of the most common and costly governance mistakes.


4. Develop effective training and communication programmes

An organisation can have the finest written policies in the world, but if its employees do not understand them, they are just words on paper. Effective compliance training must be current, comprehensive, role-specific, and continuously updated to address emerging risks and operational realities.

The distinction between onboarding training, role-specific training, and annual refreshers matters more than most organisations acknowledge. A new joiner needs foundational awareness of the organisation's compliance obligations and reporting channels. A procurement manager needs detailed training on third-party due diligence and anti-bribery requirements. A data processor needs specific instruction on UK GDPR obligations. Delivering the same generic module to all three is not training; it is a tick-box exercise.

Micro-learning approaches, where training is delivered in short, targeted modules tied to specific job functions, consistently outperform annual all-staff sessions in both retention and behaviour change. The key is to connect training directly to the risks identified in the risk assessment, so that staff understand not just what the rules are but why they exist and what happens when they are breached.

Building a training and communication programme that works:

  • Segment your audience by role, risk exposure, and existing knowledge before designing any content
  • Tie training content directly to the risk register so that high-risk areas receive proportionate attention
  • Establish confidential reporting channels and communicate them clearly during onboarding and at regular intervals
  • Promote a non-retaliation culture explicitly, not just in policy; staff who fear consequences for raising concerns will stay silent
  • Track completion rates and assessment scores as programme metrics, and investigate low completion rates rather than accepting them
  • Update training content when regulations change, when incidents occur, or when audit findings reveal knowledge gaps

Communication about compliance should not be limited to training events. Policy updates, regulatory changes, and lessons learned from incidents all warrant proactive communication to affected staff. A culture of compliance is built through consistent, honest communication, not through annual reminders.


5. Implement internal monitoring, auditing, and continuous improvement

Monitoring and auditing are related but distinct functions, and conflating them is a common programme weakness. Monitoring is proactive and frequent: it identifies procedural or training weaknesses before they become regulatory violations. Auditing is independent and periodic: it tests whether the compliance programme is actually working as designed.

An effective monitoring system includes regularly scheduled reviews of disclosures, calculations, document retention, marketing materials, third-party operations, and internal communication systems. The compliance officer should be involved in the planning and development of new business activities, not just reviewing them after the fact. Early involvement is what makes monitoring genuinely preventive rather than retrospective.

Audit evidence must be generated at the time the control runs and stored in a centralised, tamper-proof location. Retroactive documentation rarely passes auditor scrutiny. If a control ran but was not documented contemporaneously, auditors treat it as if it did not run at all. This is not a technicality; it is the operating principle that determines whether a programme is credible or not.

Continuous improvement requires a governance committee with executive and operational stakeholders that meets at least quarterly to review the risk register, incident log, audit findings, and metric dashboards. Every finding, incident, and near-miss should generate a lessons-learned entry with a named owner, a deadline, and a verification step.

Practical elements of a monitoring, auditing, and improvement framework:

  • Distinguish monitoring from auditing in your programme documentation, with separate schedules, owners, and reporting lines
  • Develop a published audit calendar with named owners for each audit area and defined scope
  • Store all evidence centrally with timestamps, version control, and access restrictions; compliance automation platforms replace fragile manual processes and improve audit readiness
  • Define KPIs including mean time to remediate audit findings, policy exception counts, training completion rates, and access review completion rates
  • Establish corrective action procedures with named owners, deadlines, and escalation triggers for overdue items
  • Report compliance metrics to the board quarterly, not just when something goes wrong

Complaint trends deserve specific attention. Individual complaints are data points, but when considered in aggregate, patterns emerge that reveal systemic issues with products, processes, or disclosures. Treating each complaint as an isolated event misses the signal entirely.


6. Advanced best practices: testable controls and the human factors that determine success

The difference between a compliance programme that passes an audit and one that actually reduces risk comes down to two things: the design of individual controls, and the culture in which those controls operate.

A testable control has five required attributes: a named owner, a defined cadence, a trigger event, a documented procedure, and a verifiable evidence artefact. Without all five, the control cannot be tested, which means it cannot be relied upon. Informal compliance fails the moment an auditor arrives, because informality means no evidence trail and no way to demonstrate that the control ran consistently over time.

The efficiency gain from well-designed controls is significant. A single quarterly user access review, properly documented, can simultaneously satisfy multiple framework requirements across SOC 2, HIPAA, ISO 27001, and PCI DSS. Mapping controls across multiple regulatory frameworks maximises organisational efficiency and compliance coverage. One well-run control satisfying several obligations is always preferable to several poorly-run controls each satisfying one.

Pro Tip: Build a defensible operating rhythm before expanding your control scope. Organisations that attempt to cover multiple compliance frameworks simultaneously in their first year consistently produce weaker programmes than those that master one primary framework first and layer additional requirements once the operating cadence is established.

Technology accelerates compliance but does not substitute for human expertise. Workflow automation handles evidence collection, escalation routing, and audit trail generation. Human judgement handles the interpretation of ambiguous situations, the assessment of emerging risks, and the cultural work of making compliance feel like a shared responsibility rather than an external imposition. The balance between automation and expertise is one of the most consequential decisions in programme design.

Documentation capability is a skill that not every hire possesses. Insufficient documentation consistently compromises compliance audits and regulatory confidence, regardless of how well the underlying controls actually run. When building or scaling a compliance function, treat documentation as a core competency requirement, not an administrative afterthought.

Common pitfalls that undermine otherwise well-designed programmes:

  • Over-scoping frameworks in year one, leading to shallow coverage across many areas rather than deep, testable coverage in the areas that matter most
  • Underestimating documentation rigour, particularly for manual controls where evidence is generated by people rather than systems
  • Treating compliance as a legal task rather than a management and culture issue; genuine buy-in at every level requires leadership that models the behaviour, not just mandates it
  • Separating compliance from operations, so that the compliance function reviews what the business does rather than participating in how it is designed
  • Neglecting third-party oversight, particularly in sectors like construction and facilities management where supply chains are long and liability transfers are complex

Compliance must be approached as a management and culture issue rather than purely a legal task. Organisations that treat it as a legal obligation to be managed at arm's length consistently underperform those that embed it in how decisions are made and how performance is measured.

Keystoneconsulting's Videra platform addresses several of the most persistent failure points in compliance programme delivery: mapped workflows that make control ownership visible, AI-powered reporting that surfaces exceptions before they become findings, and stage-gated project governance that builds audit readiness into operational processes rather than retrofitting it at year-end. For organisations in healthcare, construction, and facilities management, where governance failures and reporting bottlenecks are endemic, that kind of structural integration makes a material difference.


Key takeaways

A well-built compliance programme requires a deliberate sequence: risk assessment before policies, policies before controls, and governance that meets regularly enough to actually improve the programme over time.

PointDetails
Sequence the build correctlyRisk assessment must precede policy development; controls must follow policies, not lead them.
Leadership commitment is structuralBoard oversight, a compliance officer with real authority, and visible executive sponsorship are prerequisites, not enhancements.
Testable controls require five attributesEvery control needs a named owner, cadence, trigger, documented procedure, and verifiable evidence artefact.
Training must be role-specificGeneric annual training does not change behaviour; targeted, risk-linked modules tied to specific job functions do.
Continuous improvement needs governanceA quarterly committee reviewing the risk register, incident log, and audit findings is what separates a living programme from a static one.

https://keystoneconsulting.uk

Keystoneconsulting works with organisations across healthcare, construction, and facilities management to design and implement compliance programmes that hold up under scrutiny. The Videra platform maps workflows, automates reporting, and generates the audit-ready evidence trails that manual processes consistently fail to produce. If your current programme relies on spreadsheets, shared drives, and annual reviews, explore what Videra delivers before your next audit cycle begins.