SlideShare une entreprise Scribd logo
1  sur  56
Télécharger pour lire hors ligne
State of Compliance 2021
Survey Results
by Nimonik
Compliance is a moving target. No organization is ever fully compliant with all of its obligations.
“Obligations are any mandatory or voluntary requirement that your company needs to comply
with. You can separate obligations into two broad categories - Internal and External. Internal
obligations come from corporate documents, while external obligations come from
government regulators and industry bodies.”
In addition to changing obligations, organizations are constantly changing due to mergers,
acquisitions and management change. These changes are a constant struggle for any organization.
This survey of over 150 industry professionals paints a portrait of compliance in 2021. We hope you
will find some insights worth sharing with your colleagues.
What is this survey?
The survey
In 2021, Nimonik surveyed 100 compliance and risk
professionals at mid-size businesses or business units
of larger organizations. The aim is to better understand
how they are managing compliance and how they see
the compliance landscape evolving in the next year.
When results from Chinese companies differed
substantially, we broke out their data in the charts.
Executive Summary
Most organizations surveyed feel their compliance burden will increase in
the years to come, but they are relatively well equipped to tackle it.
Chinese companies have more concerns around fines, penalties and
sanctions than North American or European companies.
Most organizations feel they could use more resources to tackle
compliance; this is especially true in China.
All organizations indicated that they lost substantial time and money on
“surprises”. These losses were often in the often thousands of hours and
millions of dollars. This is perhaps the single biggest issue organizations
are facing: how to reduce or avoid unwanted events?
Survey
Participants
Survey Results
Perception of compliance burden
Most organizations feel they have over 2,500 obligations with about 4% changing every year.
This lines up with observations at Nimonik. Our data of over 450,000 regulatory documents
shows that about 3.5% or over 15,750 documents are repealed, replaced, introduced or
amended every year.
Internal obligations from contracts, permits, supplier agreements and stakeholder
engagements form at least 30% of obligations. These are generally not being managed
effectively, as demonstrated by our 2020 survey on Internal Obligations.
Organizations have a high level of confidence they are “mostly” in compliance; whether they
have the data to support this is another question entirely.
Management systems
Most organizations have some form of a compliance program in place.
Chinese companies rely much more on management systems than North American
companies.
Technology for managing compliance is still not widespread in the industry, with nearly 50% of
organizations still reliant on pen, paper, Word and Excel.
North American and European companies are mostly satisfied with their systems, whereas
Chinese companies are less satisfied.
In terms of prioritization, risk ranking is popular across the board, but Chinese companies rely
more heavily on potential fines and on government inspections.
It seems that many organizations are still audit driven - meaning they rely on external and
internal audits to drive their compliance priorities, which is not ideal.
Perception of compliance
The survey participants indicated their companies are generally in favor of compliance
programs and view proactive compliance as an investment. It is likely that the sample for this
survey consisted of people and organizations who are further along in their organizational
maturity.
Most participants felt that compliance is part of operational excellence, which is a good sign
that more and more organizations are taking action on compliance programs.
Many organizations feel they still lack resources to tackle compliance; the shortage is
particularly acute amongst Chinese companies.
“Surprises”
Nearly all participants indicated they had substantial compliance “Surprises” which indicates
there is still room for improvement.
Some participants indicated they could not quantify the amount of time spent on unplanned
events, but “it was a heck of a lot of time”. Time is money and as such, it is critical that
organizations quantify time spent on unplanned events to help further justify investments in
proactive compliance.
Organizations indicated that they could have avoided a substantial portion of these surprises
with better systems and planning.
Emerging Trends
The vast majority of organizations see their regulatory and compliance burden increasing in the
years to come.
Organizations feel they mostly have the tools in place to tackle this increasing work, but that
they will continue to invest in programs, systems and software across their organization.
Environmental, Social and Governance (ESG) are becoming an increasingly important part of
their compliance programs and many organizations plan to further integrate ESG with their
compliance systems.
Comments from
compliance and
risk professionals
The most thorough response we received was, “A systematic approach to building a compliance function
allows you to structure and create an effective compliance function in an organization. In this case, the
following questions are key: an approach to identifying compliance areas and a methodology for
constructing a compliance function; structuring the compliance function (centralized and decentralized
compliance function; separation of areas of responsibility with the function of risk management, internal
control, internal audit); external assessment of the compliance function (who and for what evaluates the
compliance function; what actions should be taken in the company in this regard).”
However, the majority of participants indicated that the compliance responsibilities remain highly
decentralized and fragmented.
At a high level, how is your compliance program structured?
Various comments spoke about the challenge for resource allocation
“COVID was very influential, because the impact of a covid exposure in the workplace is very rapid and
has a very high cost to the organization.”
“COVID has led to funding cuts for certain departments due to increased investment on PPE.”
“COVID reassured the company that all compliance processes are necessary.”
In general, most participants felt that COVID reinforced the importance of proactive compliance and
the value of getting ahead of surprises.
Impacts of COVID on compliance functions
Various comments spoke about the change in perception
“I personally think COVID has raised awareness to the importance of
compliance. Employees are more conscious of safety and health risks
associated with non-compliance.”
It also pushed organizations to go digital faster: “COVID forced us to move from
paper based to electronic paperless system.”
COVID and the perception of compliance
Various comments spoke about the needs to better centralize and organize
compliance data and for management to lead the effort
“A holistic system where you can manage all of your compliance needs would
be beneficial in the industry. We currently need numerous systems to track the
data related to HSE management.”
“Top level management involvement cardinal for any compliance system to
succeed.”
“It requires an enterprise-wide commitment for all levels of the organization.”
General thoughts on compliance?
Participants spoke about increasing burden from their customers and investors.
Nearly everyone anticipates greater regulation across the board.
“"Obligations" in the form of customer demand: we expect more sustainability
demands over and above regulatory obligations from customers.”
“ESG will take on a greater and greater role”
“We anticipate a significant increase in both state and federal regulations”
Emerging trends
Nimonik offers a framework and
solutions for management of
obligations
Comprehensive
Compliance
approach
Successful Compliance
Programs
Successful compliance programs
require three key elements:
Software solution
Centrally managed
compliance
Minimal
Management
Supervisor led
Systems are in place and training is
mandated. Most of the issues are
pushed by supervisors and reports
identify problematic areas. General staff
do not feel a strong responsibility for
compliance.
Integrated
Team based compliance
All members of the organization
believe that compliance to
standards and regulations is
good business. Strong
comprehension by all of policies
and procedures. Easy access to
data and software that empower
teams.
Reactive
Focus on putting out fires
Organization reacts to
EHS, Quality and
Compliance issues as they
arise. People and teams
respond only when there is
an immediate problem.
Inconsistent
Piecemeal approach
Some processes and
systems are in place.
Most facilities or
business units are
independent and do not
share best practices or
systems.
Compliance Maturity
Proactive
Forward thinking
Meet with stakeholders
and regulators. Conduct
continuous improvement
of compliance program.
Most organisations do not
know all of their obligations,
leading to “surprises”...
A typical Facility has 3,000
Compliance Obligations and
200 new ones per year.
Product
Testing
Repurchase materials and support
Even higher cost to purchase new
materials and make changes to
equipment and systems.
Production
Disruption to production
Interrupt regular production,
replace staff, equipment or
systems, potentially halt
production or slow it down.
Project
Planning
Solve early!
Adjust plans well before
you invest money and
time!
Implementation
Re-Engineering
Higher costs to re-train
and redesign system
When do you discover surprises?
Deadline
Ouch!
Rework projects, materials
and people. Major cost
overruns and lost
revenues.
Comprehensive
Compliance
approach
A key factor for success is a
‘Comprehensive Compliance’ approach
Software solution
Centrally managed
Compliance
Successful Compliance
Programs
Modern organizations eliminate
surprises with Comprehensive
Compliance
A Comprehensive Compliance program captures all of
your Obligations across your areas of compliance:
Quality, environmental, safety, HR, OHS, product...
...and Sources:
Regulatory, standards, contracts, permits, stakeholders, customers,...
...and enables timely management of Actions and
Audits.
Comprehensive
Obligations
Comprehensive
Assurance
Business
Outcomes
01 02 03
• 360° Coverage
• Mandatory and Voluntary
• Obligations Mapping
• Always Audit Ready
• Comprehensive Audit
• Performance Assessments
• Increased Trust
• Reduced Risk
• Fewer Surprises
Path to Resilience
Traditional Compliance Approaches
In-house
- Inconsistency
- Loss of institutional
knowledge
- Time consuming
Consultants
- Compliance gaps
- Variability in work
- Expensive
Software +
content +
consultants
- Integration is complex
- Expensive to build &
maintain
Clause Level
Compliance Obligations
150,000 specific
Obligations
Extracted
obligations from
your documents
Web & Mobile Audits
Inspect & collect
evidence
Actions taken?
Actions effective?
Document Level
Compliance Obligations
400,000 Laws,
Regulations
and Standards
Your internal
documents
Nimonik Solution Architecture
Actions Dashboard
Actions when
obligations change
Actions you create
Actions from your
documents
Audits
Obligations Actions
Continuous Comprehensive Compliance - Nimonik Implementation
Select obligations &
personalize the system
Map responsible
people
Establish your process
Monitor for changes
Follow-up on
Non-Compliance and
OFI
Identify Obligations with
Questionnaire & Workshop
Audit compliance on a
regular basis
Continuous
Improvement
Plan
Do
Check
Act
Centralize your internal &
external compliance
obligations and
personalize the system
Facilitate collaboration
across the business
Create essential compliance
records to prove Due Care
Process
Rapidly report to
management and
colleagues
Four Key Benefits of Compliance with Nimonik
Book a free consultation
Nimonik can help you achieve
Comprehensive Compliance for
Internal and External obligations.
nimonik.com | +1-888-608-7511 | info@nimonik.com

Contenu connexe

Tendances

Reimagining Minnesota State Emerging Themes
Reimagining Minnesota State Emerging ThemesReimagining Minnesota State Emerging Themes
Reimagining Minnesota State Emerging ThemesMSCSA
 
Key Steps to Creating a Strong Compliance Culture Through Effective Leadership
Key Steps to Creating a Strong Compliance Culture Through Effective LeadershipKey Steps to Creating a Strong Compliance Culture Through Effective Leadership
Key Steps to Creating a Strong Compliance Culture Through Effective LeadershipEthisphere
 
SolarWinds IT Trends Report 2015: Business at the Speed of IT (North America)
SolarWinds IT Trends Report 2015: Business at the Speed of IT (North America)SolarWinds IT Trends Report 2015: Business at the Speed of IT (North America)
SolarWinds IT Trends Report 2015: Business at the Speed of IT (North America)SolarWinds
 
AFCEA Cybersecurity through Continuous Monitoring: SolarWinds Survey Results ...
AFCEA Cybersecurity through Continuous Monitoring: SolarWinds Survey Results ...AFCEA Cybersecurity through Continuous Monitoring: SolarWinds Survey Results ...
AFCEA Cybersecurity through Continuous Monitoring: SolarWinds Survey Results ...SolarWinds
 
Managing Risks in Document Preservation and E-Discovery
Managing Risks in Document Preservation and E-DiscoveryManaging Risks in Document Preservation and E-Discovery
Managing Risks in Document Preservation and E-DiscoverySeth Row
 
Building on the Foundation of Ethics and Compliance to Achieve Sustainability
Building on the Foundation of Ethics and Compliance to Achieve SustainabilityBuilding on the Foundation of Ethics and Compliance to Achieve Sustainability
Building on the Foundation of Ethics and Compliance to Achieve SustainabilityEthisphere
 
8 common brick walls that slow down not-for-profits
8 common brick walls that slow down not-for-profits8 common brick walls that slow down not-for-profits
8 common brick walls that slow down not-for-profitsGreentree International
 
Sure Fire Ways to Succeed with Data Analytics
Sure Fire Ways to Succeed with Data AnalyticsSure Fire Ways to Succeed with Data Analytics
Sure Fire Ways to Succeed with Data AnalyticsJim Kaplan CIA CFE
 
Implementing and Auditing GDPR Series (9 of 10)
Implementing and Auditing GDPR Series (9 of 10) Implementing and Auditing GDPR Series (9 of 10)
Implementing and Auditing GDPR Series (9 of 10) Jim Kaplan CIA CFE
 
AI Use Expected to Increase in Risk and Compliance Efforts, But Few Have Ethi...
AI Use Expected to Increase in Risk and Compliance Efforts, But Few Have Ethi...AI Use Expected to Increase in Risk and Compliance Efforts, But Few Have Ethi...
AI Use Expected to Increase in Risk and Compliance Efforts, But Few Have Ethi...Deloitte United States
 
Accenture lean six_sigma 65pages
Accenture lean six_sigma 65pagesAccenture lean six_sigma 65pages
Accenture lean six_sigma 65pagestrongctm2011
 
The Next 10 Years of EHS - Canada & LATAM - Alex Lima - Feb 2016
The Next 10 Years of EHS - Canada & LATAM - Alex Lima  - Feb 2016The Next 10 Years of EHS - Canada & LATAM - Alex Lima  - Feb 2016
The Next 10 Years of EHS - Canada & LATAM - Alex Lima - Feb 2016Alex Lima
 
IT Trends Report 2015: Business at the Speed of IT, Public Sector Results
IT Trends Report 2015: Business at the Speed of IT, Public Sector ResultsIT Trends Report 2015: Business at the Speed of IT, Public Sector Results
IT Trends Report 2015: Business at the Speed of IT, Public Sector ResultsSolarWinds
 
Adding internal audit value: Strategically leveraging compliance activities
Adding internal audit value: Strategically leveraging compliance activitiesAdding internal audit value: Strategically leveraging compliance activities
Adding internal audit value: Strategically leveraging compliance activitiesGrant Thornton LLP
 
HFMA Navigant 2019 RCM Survey
HFMA Navigant 2019 RCM SurveyHFMA Navigant 2019 RCM Survey
HFMA Navigant 2019 RCM SurveyGuidehouse
 
Webinar: Information Governance - Where is the Healthcare Industry and Where ...
Webinar: Information Governance - Where is the Healthcare Industry and Where ...Webinar: Information Governance - Where is the Healthcare Industry and Where ...
Webinar: Information Governance - Where is the Healthcare Industry and Where ...Modern Healthcare
 

Tendances (20)

Reimagining Minnesota State Emerging Themes
Reimagining Minnesota State Emerging ThemesReimagining Minnesota State Emerging Themes
Reimagining Minnesota State Emerging Themes
 
Key Steps to Creating a Strong Compliance Culture Through Effective Leadership
Key Steps to Creating a Strong Compliance Culture Through Effective LeadershipKey Steps to Creating a Strong Compliance Culture Through Effective Leadership
Key Steps to Creating a Strong Compliance Culture Through Effective Leadership
 
SolarWinds IT Trends Report 2015: Business at the Speed of IT (North America)
SolarWinds IT Trends Report 2015: Business at the Speed of IT (North America)SolarWinds IT Trends Report 2015: Business at the Speed of IT (North America)
SolarWinds IT Trends Report 2015: Business at the Speed of IT (North America)
 
Takeaways from a Simulated Cyber Attack
Takeaways from a Simulated Cyber AttackTakeaways from a Simulated Cyber Attack
Takeaways from a Simulated Cyber Attack
 
EDI 2009 Controlling E-Discovery Costs through Records Management
EDI 2009 Controlling E-Discovery Costs through Records ManagementEDI 2009 Controlling E-Discovery Costs through Records Management
EDI 2009 Controlling E-Discovery Costs through Records Management
 
AFCEA Cybersecurity through Continuous Monitoring: SolarWinds Survey Results ...
AFCEA Cybersecurity through Continuous Monitoring: SolarWinds Survey Results ...AFCEA Cybersecurity through Continuous Monitoring: SolarWinds Survey Results ...
AFCEA Cybersecurity through Continuous Monitoring: SolarWinds Survey Results ...
 
Managing Risks in Document Preservation and E-Discovery
Managing Risks in Document Preservation and E-DiscoveryManaging Risks in Document Preservation and E-Discovery
Managing Risks in Document Preservation and E-Discovery
 
Building on the Foundation of Ethics and Compliance to Achieve Sustainability
Building on the Foundation of Ethics and Compliance to Achieve SustainabilityBuilding on the Foundation of Ethics and Compliance to Achieve Sustainability
Building on the Foundation of Ethics and Compliance to Achieve Sustainability
 
8 common brick walls that slow down not-for-profits
8 common brick walls that slow down not-for-profits8 common brick walls that slow down not-for-profits
8 common brick walls that slow down not-for-profits
 
Managing Corporate Memory: The Impact of Disruptive Forces in the Workplace
Managing Corporate Memory: The Impact of Disruptive Forces in the WorkplaceManaging Corporate Memory: The Impact of Disruptive Forces in the Workplace
Managing Corporate Memory: The Impact of Disruptive Forces in the Workplace
 
Sure Fire Ways to Succeed with Data Analytics
Sure Fire Ways to Succeed with Data AnalyticsSure Fire Ways to Succeed with Data Analytics
Sure Fire Ways to Succeed with Data Analytics
 
Implementing and Auditing GDPR Series (9 of 10)
Implementing and Auditing GDPR Series (9 of 10) Implementing and Auditing GDPR Series (9 of 10)
Implementing and Auditing GDPR Series (9 of 10)
 
AI Use Expected to Increase in Risk and Compliance Efforts, But Few Have Ethi...
AI Use Expected to Increase in Risk and Compliance Efforts, But Few Have Ethi...AI Use Expected to Increase in Risk and Compliance Efforts, But Few Have Ethi...
AI Use Expected to Increase in Risk and Compliance Efforts, But Few Have Ethi...
 
Accenture lean six_sigma 65pages
Accenture lean six_sigma 65pagesAccenture lean six_sigma 65pages
Accenture lean six_sigma 65pages
 
The Next 10 Years of EHS - Canada & LATAM - Alex Lima - Feb 2016
The Next 10 Years of EHS - Canada & LATAM - Alex Lima  - Feb 2016The Next 10 Years of EHS - Canada & LATAM - Alex Lima  - Feb 2016
The Next 10 Years of EHS - Canada & LATAM - Alex Lima - Feb 2016
 
IT Trends Report 2015: Business at the Speed of IT, Public Sector Results
IT Trends Report 2015: Business at the Speed of IT, Public Sector ResultsIT Trends Report 2015: Business at the Speed of IT, Public Sector Results
IT Trends Report 2015: Business at the Speed of IT, Public Sector Results
 
Adding internal audit value: Strategically leveraging compliance activities
Adding internal audit value: Strategically leveraging compliance activitiesAdding internal audit value: Strategically leveraging compliance activities
Adding internal audit value: Strategically leveraging compliance activities
 
HFMA Navigant 2019 RCM Survey
HFMA Navigant 2019 RCM SurveyHFMA Navigant 2019 RCM Survey
HFMA Navigant 2019 RCM Survey
 
Consumer privacy in retail
Consumer privacy in retailConsumer privacy in retail
Consumer privacy in retail
 
Webinar: Information Governance - Where is the Healthcare Industry and Where ...
Webinar: Information Governance - Where is the Healthcare Industry and Where ...Webinar: Information Governance - Where is the Healthcare Industry and Where ...
Webinar: Information Governance - Where is the Healthcare Industry and Where ...
 

Similaire à State of Compliance 2021 at Mid-Market Firms - Nimonik

ESG and Compliance: Where do we go from here?
ESG and Compliance: Where do we go from here?ESG and Compliance: Where do we go from here?
ESG and Compliance: Where do we go from here?Nimonik
 
Uma devi discuss the purpose of the capability maturity model.c
Uma devi discuss the purpose of the capability maturity model.cUma devi discuss the purpose of the capability maturity model.c
Uma devi discuss the purpose of the capability maturity model.craju957290
 
2015 Tackling This Year's Audit Hot Spots
2015 Tackling This Year's Audit Hot Spots2015 Tackling This Year's Audit Hot Spots
2015 Tackling This Year's Audit Hot SpotsRon Steinkamp
 
POSITION OF INTERNAL AUDIT IN THE CORPORATE FRAMEWORK
POSITION OF INTERNAL AUDIT IN THE CORPORATE FRAMEWORKPOSITION OF INTERNAL AUDIT IN THE CORPORATE FRAMEWORK
POSITION OF INTERNAL AUDIT IN THE CORPORATE FRAMEWORKHaresh Lalwani
 
Lets understand the GRC market well with Ponemon analysis- FixNix
Lets understand the GRC market well with Ponemon analysis- FixNixLets understand the GRC market well with Ponemon analysis- FixNix
Lets understand the GRC market well with Ponemon analysis- FixNixFixNix Inc.,
 
Compliance in Manufacturing: A Very Personal Affair (2013)
Compliance in Manufacturing: A Very Personal Affair (2013)Compliance in Manufacturing: A Very Personal Affair (2013)
Compliance in Manufacturing: A Very Personal Affair (2013)Melih ÖZCANLI
 
Risk & Compliance Outlook 2011
Risk & Compliance Outlook 2011Risk & Compliance Outlook 2011
Risk & Compliance Outlook 2011Hiten Sethi
 
CAEs speak out: Cybersecurity seen as key threat to growth
CAEs speak out: Cybersecurity seen as key threat to growthCAEs speak out: Cybersecurity seen as key threat to growth
CAEs speak out: Cybersecurity seen as key threat to growthGrant Thornton LLP
 
How to integrate risk into your compliance-only approach
 How to integrate risk into your compliance-only approach How to integrate risk into your compliance-only approach
How to integrate risk into your compliance-only approachAbhishek Sood
 
The Changing Role of Compliance | Accenture
The Changing Role of Compliance | AccentureThe Changing Role of Compliance | Accenture
The Changing Role of Compliance | AccentureAccenture Operations
 
Compliance at a Crossroads: One Step Forward, Two Steps Back?
Compliance at a Crossroads: One Step Forward, Two Steps Back?Compliance at a Crossroads: One Step Forward, Two Steps Back?
Compliance at a Crossroads: One Step Forward, Two Steps Back?Accenture Insurance
 
Introduction to IT compliance program and Discuss the challenges IT .pdf
Introduction to IT compliance program and Discuss the challenges IT .pdfIntroduction to IT compliance program and Discuss the challenges IT .pdf
Introduction to IT compliance program and Discuss the challenges IT .pdfSALES97
 
The Changing Role of Compliance | Accenture
The Changing Role of Compliance | AccentureThe Changing Role of Compliance | Accenture
The Changing Role of Compliance | AccentureAccenture Operations
 
True Cost of Compliance
True Cost of ComplianceTrue Cost of Compliance
True Cost of ComplianceTripwire
 
Chief Audit Executive Survey 2011 - perspectives and trends from internal aud...
Chief Audit Executive Survey 2011 - perspectives and trends from internal aud...Chief Audit Executive Survey 2011 - perspectives and trends from internal aud...
Chief Audit Executive Survey 2011 - perspectives and trends from internal aud...Grant Thornton
 

Similaire à State of Compliance 2021 at Mid-Market Firms - Nimonik (20)

ESG and Compliance: Where do we go from here?
ESG and Compliance: Where do we go from here?ESG and Compliance: Where do we go from here?
ESG and Compliance: Where do we go from here?
 
NEMEA Compliance Automation
NEMEA Compliance AutomationNEMEA Compliance Automation
NEMEA Compliance Automation
 
Memo to CEOs
Memo to CEOsMemo to CEOs
Memo to CEOs
 
Uma devi discuss the purpose of the capability maturity model.c
Uma devi discuss the purpose of the capability maturity model.cUma devi discuss the purpose of the capability maturity model.c
Uma devi discuss the purpose of the capability maturity model.c
 
2015 Tackling This Year's Audit Hot Spots
2015 Tackling This Year's Audit Hot Spots2015 Tackling This Year's Audit Hot Spots
2015 Tackling This Year's Audit Hot Spots
 
POSITION OF INTERNAL AUDIT IN THE CORPORATE FRAMEWORK
POSITION OF INTERNAL AUDIT IN THE CORPORATE FRAMEWORKPOSITION OF INTERNAL AUDIT IN THE CORPORATE FRAMEWORK
POSITION OF INTERNAL AUDIT IN THE CORPORATE FRAMEWORK
 
Survive an Impending Audit
Survive an Impending AuditSurvive an Impending Audit
Survive an Impending Audit
 
Lets understand the GRC market well with Ponemon analysis- FixNix
Lets understand the GRC market well with Ponemon analysis- FixNixLets understand the GRC market well with Ponemon analysis- FixNix
Lets understand the GRC market well with Ponemon analysis- FixNix
 
Deloitte India Survey
 Deloitte India Survey Deloitte India Survey
Deloitte India Survey
 
Compliance in Manufacturing: A Very Personal Affair (2013)
Compliance in Manufacturing: A Very Personal Affair (2013)Compliance in Manufacturing: A Very Personal Affair (2013)
Compliance in Manufacturing: A Very Personal Affair (2013)
 
Risk & Compliance Outlook 2011
Risk & Compliance Outlook 2011Risk & Compliance Outlook 2011
Risk & Compliance Outlook 2011
 
CAEs speak out: Cybersecurity seen as key threat to growth
CAEs speak out: Cybersecurity seen as key threat to growthCAEs speak out: Cybersecurity seen as key threat to growth
CAEs speak out: Cybersecurity seen as key threat to growth
 
How to integrate risk into your compliance-only approach
 How to integrate risk into your compliance-only approach How to integrate risk into your compliance-only approach
How to integrate risk into your compliance-only approach
 
The Changing Role of Compliance | Accenture
The Changing Role of Compliance | AccentureThe Changing Role of Compliance | Accenture
The Changing Role of Compliance | Accenture
 
Compliance at a Crossroads: One Step Forward, Two Steps Back?
Compliance at a Crossroads: One Step Forward, Two Steps Back?Compliance at a Crossroads: One Step Forward, Two Steps Back?
Compliance at a Crossroads: One Step Forward, Two Steps Back?
 
Introduction to IT compliance program and Discuss the challenges IT .pdf
Introduction to IT compliance program and Discuss the challenges IT .pdfIntroduction to IT compliance program and Discuss the challenges IT .pdf
Introduction to IT compliance program and Discuss the challenges IT .pdf
 
How Audit Committees Can Help with Third-Party Risks
How Audit Committees Can Help with Third-Party RisksHow Audit Committees Can Help with Third-Party Risks
How Audit Committees Can Help with Third-Party Risks
 
The Changing Role of Compliance | Accenture
The Changing Role of Compliance | AccentureThe Changing Role of Compliance | Accenture
The Changing Role of Compliance | Accenture
 
True Cost of Compliance
True Cost of ComplianceTrue Cost of Compliance
True Cost of Compliance
 
Chief Audit Executive Survey 2011 - perspectives and trends from internal aud...
Chief Audit Executive Survey 2011 - perspectives and trends from internal aud...Chief Audit Executive Survey 2011 - perspectives and trends from internal aud...
Chief Audit Executive Survey 2011 - perspectives and trends from internal aud...
 

Plus de Nimonik

Generative AI for Regulatory Analysis
Generative AI for Regulatory AnalysisGenerative AI for Regulatory Analysis
Generative AI for Regulatory AnalysisNimonik
 
Nimonik Brochure
Nimonik BrochureNimonik Brochure
Nimonik BrochureNimonik
 
ISO 37301 Compliance Management Systems
ISO 37301 Compliance Management SystemsISO 37301 Compliance Management Systems
ISO 37301 Compliance Management SystemsNimonik
 
Calgary Oil & Gas Regulatory and Standards Day January 18th 2023
Calgary Oil & Gas Regulatory and Standards Day January 18th 2023Calgary Oil & Gas Regulatory and Standards Day January 18th 2023
Calgary Oil & Gas Regulatory and Standards Day January 18th 2023Nimonik
 
Best Practices for Regulatory Change Management
Best Practices for Regulatory Change ManagementBest Practices for Regulatory Change Management
Best Practices for Regulatory Change ManagementNimonik
 
Build a business case for compliance March 2022
Build a business case for compliance March 2022Build a business case for compliance March 2022
Build a business case for compliance March 2022Nimonik
 
ISO 19600 Section 4.5 - Know your Obligations
ISO 19600 Section 4.5 - Know your ObligationsISO 19600 Section 4.5 - Know your Obligations
ISO 19600 Section 4.5 - Know your ObligationsNimonik
 
COVID-19 Biological Risk Assessment Webinar
COVID-19 Biological Risk Assessment WebinarCOVID-19 Biological Risk Assessment Webinar
COVID-19 Biological Risk Assessment WebinarNimonik
 
Preparing for a Post Covid World
Preparing for a Post Covid WorldPreparing for a Post Covid World
Preparing for a Post Covid WorldNimonik
 
Identify Applicable EHS Regulatory Documents
Identify Applicable EHS Regulatory DocumentsIdentify Applicable EHS Regulatory Documents
Identify Applicable EHS Regulatory DocumentsNimonik
 
19600 Compliance Management System Guidelines
19600 Compliance Management System Guidelines19600 Compliance Management System Guidelines
19600 Compliance Management System GuidelinesNimonik
 
19600 compliance management system guidelines
19600   compliance management system guidelines19600   compliance management system guidelines
19600 compliance management system guidelinesNimonik
 
Survey results - Centrally vs Locally managed compliance
Survey results - Centrally vs Locally managed complianceSurvey results - Centrally vs Locally managed compliance
Survey results - Centrally vs Locally managed complianceNimonik
 
Continous compliance october 2019 webinar (2)
Continous compliance   october 2019 webinar (2)Continous compliance   october 2019 webinar (2)
Continous compliance october 2019 webinar (2)Nimonik
 
The not so hidden costs of non-compliance
The not so hidden costs of non-complianceThe not so hidden costs of non-compliance
The not so hidden costs of non-complianceNimonik
 
The 4 key types of regulations and how to comply (3)
The 4 key types of regulations and how to comply (3)The 4 key types of regulations and how to comply (3)
The 4 key types of regulations and how to comply (3)Nimonik
 
Comprehensive Compliance for Environmental, Safety, Quality Requirements in C...
Comprehensive Compliance for Environmental, Safety, Quality Requirements in C...Comprehensive Compliance for Environmental, Safety, Quality Requirements in C...
Comprehensive Compliance for Environmental, Safety, Quality Requirements in C...Nimonik
 
Process Area Site Assessments techniques for the Management
Process Area Site Assessments techniques for the ManagementProcess Area Site Assessments techniques for the Management
Process Area Site Assessments techniques for the ManagementNimonik
 
Air monitoring presentation
Air monitoring presentationAir monitoring presentation
Air monitoring presentationNimonik
 
Legal Register / Compliance Obligations ISO 14001
Legal Register / Compliance Obligations ISO 14001Legal Register / Compliance Obligations ISO 14001
Legal Register / Compliance Obligations ISO 14001Nimonik
 

Plus de Nimonik (20)

Generative AI for Regulatory Analysis
Generative AI for Regulatory AnalysisGenerative AI for Regulatory Analysis
Generative AI for Regulatory Analysis
 
Nimonik Brochure
Nimonik BrochureNimonik Brochure
Nimonik Brochure
 
ISO 37301 Compliance Management Systems
ISO 37301 Compliance Management SystemsISO 37301 Compliance Management Systems
ISO 37301 Compliance Management Systems
 
Calgary Oil & Gas Regulatory and Standards Day January 18th 2023
Calgary Oil & Gas Regulatory and Standards Day January 18th 2023Calgary Oil & Gas Regulatory and Standards Day January 18th 2023
Calgary Oil & Gas Regulatory and Standards Day January 18th 2023
 
Best Practices for Regulatory Change Management
Best Practices for Regulatory Change ManagementBest Practices for Regulatory Change Management
Best Practices for Regulatory Change Management
 
Build a business case for compliance March 2022
Build a business case for compliance March 2022Build a business case for compliance March 2022
Build a business case for compliance March 2022
 
ISO 19600 Section 4.5 - Know your Obligations
ISO 19600 Section 4.5 - Know your ObligationsISO 19600 Section 4.5 - Know your Obligations
ISO 19600 Section 4.5 - Know your Obligations
 
COVID-19 Biological Risk Assessment Webinar
COVID-19 Biological Risk Assessment WebinarCOVID-19 Biological Risk Assessment Webinar
COVID-19 Biological Risk Assessment Webinar
 
Preparing for a Post Covid World
Preparing for a Post Covid WorldPreparing for a Post Covid World
Preparing for a Post Covid World
 
Identify Applicable EHS Regulatory Documents
Identify Applicable EHS Regulatory DocumentsIdentify Applicable EHS Regulatory Documents
Identify Applicable EHS Regulatory Documents
 
19600 Compliance Management System Guidelines
19600 Compliance Management System Guidelines19600 Compliance Management System Guidelines
19600 Compliance Management System Guidelines
 
19600 compliance management system guidelines
19600   compliance management system guidelines19600   compliance management system guidelines
19600 compliance management system guidelines
 
Survey results - Centrally vs Locally managed compliance
Survey results - Centrally vs Locally managed complianceSurvey results - Centrally vs Locally managed compliance
Survey results - Centrally vs Locally managed compliance
 
Continous compliance october 2019 webinar (2)
Continous compliance   october 2019 webinar (2)Continous compliance   october 2019 webinar (2)
Continous compliance october 2019 webinar (2)
 
The not so hidden costs of non-compliance
The not so hidden costs of non-complianceThe not so hidden costs of non-compliance
The not so hidden costs of non-compliance
 
The 4 key types of regulations and how to comply (3)
The 4 key types of regulations and how to comply (3)The 4 key types of regulations and how to comply (3)
The 4 key types of regulations and how to comply (3)
 
Comprehensive Compliance for Environmental, Safety, Quality Requirements in C...
Comprehensive Compliance for Environmental, Safety, Quality Requirements in C...Comprehensive Compliance for Environmental, Safety, Quality Requirements in C...
Comprehensive Compliance for Environmental, Safety, Quality Requirements in C...
 
Process Area Site Assessments techniques for the Management
Process Area Site Assessments techniques for the ManagementProcess Area Site Assessments techniques for the Management
Process Area Site Assessments techniques for the Management
 
Air monitoring presentation
Air monitoring presentationAir monitoring presentation
Air monitoring presentation
 
Legal Register / Compliance Obligations ISO 14001
Legal Register / Compliance Obligations ISO 14001Legal Register / Compliance Obligations ISO 14001
Legal Register / Compliance Obligations ISO 14001
 

Dernier

Early Modern Spain. All about this period
Early Modern Spain. All about this periodEarly Modern Spain. All about this period
Early Modern Spain. All about this periodSaraIsabelJimenez
 
PHYSICS PROJECT BY MSC - NANOTECHNOLOGY
PHYSICS PROJECT BY MSC  - NANOTECHNOLOGYPHYSICS PROJECT BY MSC  - NANOTECHNOLOGY
PHYSICS PROJECT BY MSC - NANOTECHNOLOGYpruthirajnayak525
 
SBFT Tool Competition 2024 -- Python Test Case Generation Track
SBFT Tool Competition 2024 -- Python Test Case Generation TrackSBFT Tool Competition 2024 -- Python Test Case Generation Track
SBFT Tool Competition 2024 -- Python Test Case Generation TrackSebastiano Panichella
 
Mathan flower ppt.pptx slide orchids ✨🌸
Mathan flower ppt.pptx slide orchids ✨🌸Mathan flower ppt.pptx slide orchids ✨🌸
Mathan flower ppt.pptx slide orchids ✨🌸mathanramanathan2005
 
Call Girls In Aerocity 🤳 Call Us +919599264170
Call Girls In Aerocity 🤳 Call Us +919599264170Call Girls In Aerocity 🤳 Call Us +919599264170
Call Girls In Aerocity 🤳 Call Us +919599264170Escort Service
 
THE COUNTRY WHO SOLVED THE WORLD_HOW CHINA LAUNCHED THE CIVILIZATION REVOLUTI...
THE COUNTRY WHO SOLVED THE WORLD_HOW CHINA LAUNCHED THE CIVILIZATION REVOLUTI...THE COUNTRY WHO SOLVED THE WORLD_HOW CHINA LAUNCHED THE CIVILIZATION REVOLUTI...
THE COUNTRY WHO SOLVED THE WORLD_HOW CHINA LAUNCHED THE CIVILIZATION REVOLUTI...漢銘 謝
 
Dutch Power - 26 maart 2024 - Henk Kras - Circular Plastics
Dutch Power - 26 maart 2024 - Henk Kras - Circular PlasticsDutch Power - 26 maart 2024 - Henk Kras - Circular Plastics
Dutch Power - 26 maart 2024 - Henk Kras - Circular PlasticsDutch Power
 
RACHEL-ANN M. TENIBRO PRODUCT RESEARCH PRESENTATION
RACHEL-ANN M. TENIBRO PRODUCT RESEARCH PRESENTATIONRACHEL-ANN M. TENIBRO PRODUCT RESEARCH PRESENTATION
RACHEL-ANN M. TENIBRO PRODUCT RESEARCH PRESENTATIONRachelAnnTenibroAmaz
 
Work Remotely with Confluence ACE 2.pptx
Work Remotely with Confluence ACE 2.pptxWork Remotely with Confluence ACE 2.pptx
Work Remotely with Confluence ACE 2.pptxmavinoikein
 
miladyskindiseases-200705210221 2.!!pptx
miladyskindiseases-200705210221 2.!!pptxmiladyskindiseases-200705210221 2.!!pptx
miladyskindiseases-200705210221 2.!!pptxCarrieButtitta
 
The Ten Facts About People With Autism Presentation
The Ten Facts About People With Autism PresentationThe Ten Facts About People With Autism Presentation
The Ten Facts About People With Autism PresentationNathan Young
 
Quality by design.. ppt for RA (1ST SEM
Quality by design.. ppt for  RA (1ST SEMQuality by design.. ppt for  RA (1ST SEM
Quality by design.. ppt for RA (1ST SEMCharmi13
 
PAG-UNLAD NG EKONOMIYA na dapat isaalang alang sa pag-aaral.
PAG-UNLAD NG EKONOMIYA na dapat isaalang alang sa pag-aaral.PAG-UNLAD NG EKONOMIYA na dapat isaalang alang sa pag-aaral.
PAG-UNLAD NG EKONOMIYA na dapat isaalang alang sa pag-aaral.KathleenAnnCordero2
 
The 3rd Intl. Workshop on NL-based Software Engineering
The 3rd Intl. Workshop on NL-based Software EngineeringThe 3rd Intl. Workshop on NL-based Software Engineering
The 3rd Intl. Workshop on NL-based Software EngineeringSebastiano Panichella
 
Simulation-based Testing of Unmanned Aerial Vehicles with Aerialist
Simulation-based Testing of Unmanned Aerial Vehicles with AerialistSimulation-based Testing of Unmanned Aerial Vehicles with Aerialist
Simulation-based Testing of Unmanned Aerial Vehicles with AerialistSebastiano Panichella
 
Genshin Impact PPT Template by EaTemp.pptx
Genshin Impact PPT Template by EaTemp.pptxGenshin Impact PPT Template by EaTemp.pptx
Genshin Impact PPT Template by EaTemp.pptxJohnree4
 
Event 4 Introduction to Open Source.pptx
Event 4 Introduction to Open Source.pptxEvent 4 Introduction to Open Source.pptx
Event 4 Introduction to Open Source.pptxaryanv1753
 
Engaging Eid Ul Fitr Presentation for Kindergartners.pptx
Engaging Eid Ul Fitr Presentation for Kindergartners.pptxEngaging Eid Ul Fitr Presentation for Kindergartners.pptx
Engaging Eid Ul Fitr Presentation for Kindergartners.pptxAsifArshad8
 
DGT @ CTAC 2024 Valencia: Most crucial invest to digitalisation_Sven Zoelle_v...
DGT @ CTAC 2024 Valencia: Most crucial invest to digitalisation_Sven Zoelle_v...DGT @ CTAC 2024 Valencia: Most crucial invest to digitalisation_Sven Zoelle_v...
DGT @ CTAC 2024 Valencia: Most crucial invest to digitalisation_Sven Zoelle_v...Henrik Hanke
 
SaaStr Workshop Wednesday w/ Kyle Norton, Owner.com
SaaStr Workshop Wednesday w/ Kyle Norton, Owner.comSaaStr Workshop Wednesday w/ Kyle Norton, Owner.com
SaaStr Workshop Wednesday w/ Kyle Norton, Owner.comsaastr
 

Dernier (20)

Early Modern Spain. All about this period
Early Modern Spain. All about this periodEarly Modern Spain. All about this period
Early Modern Spain. All about this period
 
PHYSICS PROJECT BY MSC - NANOTECHNOLOGY
PHYSICS PROJECT BY MSC  - NANOTECHNOLOGYPHYSICS PROJECT BY MSC  - NANOTECHNOLOGY
PHYSICS PROJECT BY MSC - NANOTECHNOLOGY
 
SBFT Tool Competition 2024 -- Python Test Case Generation Track
SBFT Tool Competition 2024 -- Python Test Case Generation TrackSBFT Tool Competition 2024 -- Python Test Case Generation Track
SBFT Tool Competition 2024 -- Python Test Case Generation Track
 
Mathan flower ppt.pptx slide orchids ✨🌸
Mathan flower ppt.pptx slide orchids ✨🌸Mathan flower ppt.pptx slide orchids ✨🌸
Mathan flower ppt.pptx slide orchids ✨🌸
 
Call Girls In Aerocity 🤳 Call Us +919599264170
Call Girls In Aerocity 🤳 Call Us +919599264170Call Girls In Aerocity 🤳 Call Us +919599264170
Call Girls In Aerocity 🤳 Call Us +919599264170
 
THE COUNTRY WHO SOLVED THE WORLD_HOW CHINA LAUNCHED THE CIVILIZATION REVOLUTI...
THE COUNTRY WHO SOLVED THE WORLD_HOW CHINA LAUNCHED THE CIVILIZATION REVOLUTI...THE COUNTRY WHO SOLVED THE WORLD_HOW CHINA LAUNCHED THE CIVILIZATION REVOLUTI...
THE COUNTRY WHO SOLVED THE WORLD_HOW CHINA LAUNCHED THE CIVILIZATION REVOLUTI...
 
Dutch Power - 26 maart 2024 - Henk Kras - Circular Plastics
Dutch Power - 26 maart 2024 - Henk Kras - Circular PlasticsDutch Power - 26 maart 2024 - Henk Kras - Circular Plastics
Dutch Power - 26 maart 2024 - Henk Kras - Circular Plastics
 
RACHEL-ANN M. TENIBRO PRODUCT RESEARCH PRESENTATION
RACHEL-ANN M. TENIBRO PRODUCT RESEARCH PRESENTATIONRACHEL-ANN M. TENIBRO PRODUCT RESEARCH PRESENTATION
RACHEL-ANN M. TENIBRO PRODUCT RESEARCH PRESENTATION
 
Work Remotely with Confluence ACE 2.pptx
Work Remotely with Confluence ACE 2.pptxWork Remotely with Confluence ACE 2.pptx
Work Remotely with Confluence ACE 2.pptx
 
miladyskindiseases-200705210221 2.!!pptx
miladyskindiseases-200705210221 2.!!pptxmiladyskindiseases-200705210221 2.!!pptx
miladyskindiseases-200705210221 2.!!pptx
 
The Ten Facts About People With Autism Presentation
The Ten Facts About People With Autism PresentationThe Ten Facts About People With Autism Presentation
The Ten Facts About People With Autism Presentation
 
Quality by design.. ppt for RA (1ST SEM
Quality by design.. ppt for  RA (1ST SEMQuality by design.. ppt for  RA (1ST SEM
Quality by design.. ppt for RA (1ST SEM
 
PAG-UNLAD NG EKONOMIYA na dapat isaalang alang sa pag-aaral.
PAG-UNLAD NG EKONOMIYA na dapat isaalang alang sa pag-aaral.PAG-UNLAD NG EKONOMIYA na dapat isaalang alang sa pag-aaral.
PAG-UNLAD NG EKONOMIYA na dapat isaalang alang sa pag-aaral.
 
The 3rd Intl. Workshop on NL-based Software Engineering
The 3rd Intl. Workshop on NL-based Software EngineeringThe 3rd Intl. Workshop on NL-based Software Engineering
The 3rd Intl. Workshop on NL-based Software Engineering
 
Simulation-based Testing of Unmanned Aerial Vehicles with Aerialist
Simulation-based Testing of Unmanned Aerial Vehicles with AerialistSimulation-based Testing of Unmanned Aerial Vehicles with Aerialist
Simulation-based Testing of Unmanned Aerial Vehicles with Aerialist
 
Genshin Impact PPT Template by EaTemp.pptx
Genshin Impact PPT Template by EaTemp.pptxGenshin Impact PPT Template by EaTemp.pptx
Genshin Impact PPT Template by EaTemp.pptx
 
Event 4 Introduction to Open Source.pptx
Event 4 Introduction to Open Source.pptxEvent 4 Introduction to Open Source.pptx
Event 4 Introduction to Open Source.pptx
 
Engaging Eid Ul Fitr Presentation for Kindergartners.pptx
Engaging Eid Ul Fitr Presentation for Kindergartners.pptxEngaging Eid Ul Fitr Presentation for Kindergartners.pptx
Engaging Eid Ul Fitr Presentation for Kindergartners.pptx
 
DGT @ CTAC 2024 Valencia: Most crucial invest to digitalisation_Sven Zoelle_v...
DGT @ CTAC 2024 Valencia: Most crucial invest to digitalisation_Sven Zoelle_v...DGT @ CTAC 2024 Valencia: Most crucial invest to digitalisation_Sven Zoelle_v...
DGT @ CTAC 2024 Valencia: Most crucial invest to digitalisation_Sven Zoelle_v...
 
SaaStr Workshop Wednesday w/ Kyle Norton, Owner.com
SaaStr Workshop Wednesday w/ Kyle Norton, Owner.comSaaStr Workshop Wednesday w/ Kyle Norton, Owner.com
SaaStr Workshop Wednesday w/ Kyle Norton, Owner.com
 

State of Compliance 2021 at Mid-Market Firms - Nimonik

  • 1. State of Compliance 2021 Survey Results by Nimonik
  • 2. Compliance is a moving target. No organization is ever fully compliant with all of its obligations. “Obligations are any mandatory or voluntary requirement that your company needs to comply with. You can separate obligations into two broad categories - Internal and External. Internal obligations come from corporate documents, while external obligations come from government regulators and industry bodies.” In addition to changing obligations, organizations are constantly changing due to mergers, acquisitions and management change. These changes are a constant struggle for any organization. This survey of over 150 industry professionals paints a portrait of compliance in 2021. We hope you will find some insights worth sharing with your colleagues. What is this survey?
  • 3. The survey In 2021, Nimonik surveyed 100 compliance and risk professionals at mid-size businesses or business units of larger organizations. The aim is to better understand how they are managing compliance and how they see the compliance landscape evolving in the next year. When results from Chinese companies differed substantially, we broke out their data in the charts.
  • 4. Executive Summary Most organizations surveyed feel their compliance burden will increase in the years to come, but they are relatively well equipped to tackle it. Chinese companies have more concerns around fines, penalties and sanctions than North American or European companies. Most organizations feel they could use more resources to tackle compliance; this is especially true in China. All organizations indicated that they lost substantial time and money on “surprises”. These losses were often in the often thousands of hours and millions of dollars. This is perhaps the single biggest issue organizations are facing: how to reduce or avoid unwanted events?
  • 6.
  • 7.
  • 8.
  • 10. Perception of compliance burden Most organizations feel they have over 2,500 obligations with about 4% changing every year. This lines up with observations at Nimonik. Our data of over 450,000 regulatory documents shows that about 3.5% or over 15,750 documents are repealed, replaced, introduced or amended every year. Internal obligations from contracts, permits, supplier agreements and stakeholder engagements form at least 30% of obligations. These are generally not being managed effectively, as demonstrated by our 2020 survey on Internal Obligations. Organizations have a high level of confidence they are “mostly” in compliance; whether they have the data to support this is another question entirely.
  • 11.
  • 12.
  • 13.
  • 14.
  • 15. Management systems Most organizations have some form of a compliance program in place. Chinese companies rely much more on management systems than North American companies. Technology for managing compliance is still not widespread in the industry, with nearly 50% of organizations still reliant on pen, paper, Word and Excel. North American and European companies are mostly satisfied with their systems, whereas Chinese companies are less satisfied. In terms of prioritization, risk ranking is popular across the board, but Chinese companies rely more heavily on potential fines and on government inspections. It seems that many organizations are still audit driven - meaning they rely on external and internal audits to drive their compliance priorities, which is not ideal.
  • 16.
  • 17.
  • 18.
  • 19.
  • 20.
  • 21.
  • 22. Perception of compliance The survey participants indicated their companies are generally in favor of compliance programs and view proactive compliance as an investment. It is likely that the sample for this survey consisted of people and organizations who are further along in their organizational maturity. Most participants felt that compliance is part of operational excellence, which is a good sign that more and more organizations are taking action on compliance programs. Many organizations feel they still lack resources to tackle compliance; the shortage is particularly acute amongst Chinese companies.
  • 23.
  • 24.
  • 25.
  • 26.
  • 27.
  • 28.
  • 29. “Surprises” Nearly all participants indicated they had substantial compliance “Surprises” which indicates there is still room for improvement. Some participants indicated they could not quantify the amount of time spent on unplanned events, but “it was a heck of a lot of time”. Time is money and as such, it is critical that organizations quantify time spent on unplanned events to help further justify investments in proactive compliance. Organizations indicated that they could have avoided a substantial portion of these surprises with better systems and planning.
  • 30.
  • 31.
  • 32. Emerging Trends The vast majority of organizations see their regulatory and compliance burden increasing in the years to come. Organizations feel they mostly have the tools in place to tackle this increasing work, but that they will continue to invest in programs, systems and software across their organization. Environmental, Social and Governance (ESG) are becoming an increasingly important part of their compliance programs and many organizations plan to further integrate ESG with their compliance systems.
  • 33.
  • 34.
  • 35.
  • 36.
  • 38. The most thorough response we received was, “A systematic approach to building a compliance function allows you to structure and create an effective compliance function in an organization. In this case, the following questions are key: an approach to identifying compliance areas and a methodology for constructing a compliance function; structuring the compliance function (centralized and decentralized compliance function; separation of areas of responsibility with the function of risk management, internal control, internal audit); external assessment of the compliance function (who and for what evaluates the compliance function; what actions should be taken in the company in this regard).” However, the majority of participants indicated that the compliance responsibilities remain highly decentralized and fragmented. At a high level, how is your compliance program structured?
  • 39. Various comments spoke about the challenge for resource allocation “COVID was very influential, because the impact of a covid exposure in the workplace is very rapid and has a very high cost to the organization.” “COVID has led to funding cuts for certain departments due to increased investment on PPE.” “COVID reassured the company that all compliance processes are necessary.” In general, most participants felt that COVID reinforced the importance of proactive compliance and the value of getting ahead of surprises. Impacts of COVID on compliance functions
  • 40. Various comments spoke about the change in perception “I personally think COVID has raised awareness to the importance of compliance. Employees are more conscious of safety and health risks associated with non-compliance.” It also pushed organizations to go digital faster: “COVID forced us to move from paper based to electronic paperless system.” COVID and the perception of compliance
  • 41. Various comments spoke about the needs to better centralize and organize compliance data and for management to lead the effort “A holistic system where you can manage all of your compliance needs would be beneficial in the industry. We currently need numerous systems to track the data related to HSE management.” “Top level management involvement cardinal for any compliance system to succeed.” “It requires an enterprise-wide commitment for all levels of the organization.” General thoughts on compliance?
  • 42. Participants spoke about increasing burden from their customers and investors. Nearly everyone anticipates greater regulation across the board. “"Obligations" in the form of customer demand: we expect more sustainability demands over and above regulatory obligations from customers.” “ESG will take on a greater and greater role” “We anticipate a significant increase in both state and federal regulations” Emerging trends
  • 43. Nimonik offers a framework and solutions for management of obligations
  • 44. Comprehensive Compliance approach Successful Compliance Programs Successful compliance programs require three key elements: Software solution Centrally managed compliance
  • 45. Minimal Management Supervisor led Systems are in place and training is mandated. Most of the issues are pushed by supervisors and reports identify problematic areas. General staff do not feel a strong responsibility for compliance. Integrated Team based compliance All members of the organization believe that compliance to standards and regulations is good business. Strong comprehension by all of policies and procedures. Easy access to data and software that empower teams. Reactive Focus on putting out fires Organization reacts to EHS, Quality and Compliance issues as they arise. People and teams respond only when there is an immediate problem. Inconsistent Piecemeal approach Some processes and systems are in place. Most facilities or business units are independent and do not share best practices or systems. Compliance Maturity Proactive Forward thinking Meet with stakeholders and regulators. Conduct continuous improvement of compliance program.
  • 46. Most organisations do not know all of their obligations, leading to “surprises”... A typical Facility has 3,000 Compliance Obligations and 200 new ones per year.
  • 47. Product Testing Repurchase materials and support Even higher cost to purchase new materials and make changes to equipment and systems. Production Disruption to production Interrupt regular production, replace staff, equipment or systems, potentially halt production or slow it down. Project Planning Solve early! Adjust plans well before you invest money and time! Implementation Re-Engineering Higher costs to re-train and redesign system When do you discover surprises? Deadline Ouch! Rework projects, materials and people. Major cost overruns and lost revenues.
  • 48. Comprehensive Compliance approach A key factor for success is a ‘Comprehensive Compliance’ approach Software solution Centrally managed Compliance Successful Compliance Programs
  • 49. Modern organizations eliminate surprises with Comprehensive Compliance
  • 50. A Comprehensive Compliance program captures all of your Obligations across your areas of compliance: Quality, environmental, safety, HR, OHS, product... ...and Sources: Regulatory, standards, contracts, permits, stakeholders, customers,... ...and enables timely management of Actions and Audits.
  • 51. Comprehensive Obligations Comprehensive Assurance Business Outcomes 01 02 03 • 360° Coverage • Mandatory and Voluntary • Obligations Mapping • Always Audit Ready • Comprehensive Audit • Performance Assessments • Increased Trust • Reduced Risk • Fewer Surprises Path to Resilience
  • 52. Traditional Compliance Approaches In-house - Inconsistency - Loss of institutional knowledge - Time consuming Consultants - Compliance gaps - Variability in work - Expensive Software + content + consultants - Integration is complex - Expensive to build & maintain
  • 53. Clause Level Compliance Obligations 150,000 specific Obligations Extracted obligations from your documents Web & Mobile Audits Inspect & collect evidence Actions taken? Actions effective? Document Level Compliance Obligations 400,000 Laws, Regulations and Standards Your internal documents Nimonik Solution Architecture Actions Dashboard Actions when obligations change Actions you create Actions from your documents Audits Obligations Actions
  • 54. Continuous Comprehensive Compliance - Nimonik Implementation Select obligations & personalize the system Map responsible people Establish your process Monitor for changes Follow-up on Non-Compliance and OFI Identify Obligations with Questionnaire & Workshop Audit compliance on a regular basis Continuous Improvement Plan Do Check Act
  • 55. Centralize your internal & external compliance obligations and personalize the system Facilitate collaboration across the business Create essential compliance records to prove Due Care Process Rapidly report to management and colleagues Four Key Benefits of Compliance with Nimonik
  • 56. Book a free consultation Nimonik can help you achieve Comprehensive Compliance for Internal and External obligations. nimonik.com | +1-888-608-7511 | info@nimonik.com