All articles
Compliance 101RegulationGovernance17 August 202610 min read

What is regulatory compliance?

Regulatory compliance is how an organisation proves — continuously, and with evidence — that it operates within the rules that apply to it. Here is what that means in practice.

Regulatory compliance is the discipline of making sure an organisation operates within the laws, licence conditions, regulations and supervisory expectations that apply to it — and being able to prove it at any moment, with evidence, to a regulator who did not watch it happen. That second half is the part most definitions leave out, and it is the part that consumes most of the work.

Compliance is not the absence of breaches. It is the presence of evidence that the controls ran.

A working definition

Strip away the jargon and regulatory compliance has four moving parts. You identify the obligations that apply to your business. You design controls that make meeting them the default behaviour rather than an act of goodwill. You run those controls consistently and capture evidence as they run. And you monitor, test and report — internally to the board, externally to the regulator. Every mature compliance function, in any sector, is some version of those four loops.

  1. 1.Identify — which laws, licence conditions and standards bind which entity, in which market.
  2. 2.Design — controls, policies and procedures mapped to named risks and obligations.
  3. 3.Operate — run the controls, capture evidence at the moment of action.
  4. 4.Assure — monitor, test, report, remediate, and repeat.

Compliance is not the same as legal, risk or audit

These four functions get conflated constantly, and the confusion causes real damage in operating models. Legal interprets what the rule means. Risk quantifies what could go wrong and how much it would hurt. Compliance builds and runs the machinery that keeps day-to-day operations inside the rule. Internal audit independently checks whether that machinery actually works. A company that merges compliance into legal usually ends up with excellent memos and no operating controls.

  • Legal — what does the rule mean, and what is our exposure?
  • Risk — what could go wrong, how likely, how costly?
  • Compliance — how do we make the right behaviour the default, every day, with proof?
  • Internal audit — independent verification that the above is real.

What a compliance function does day to day

In a regulated consumer business, the daily reality is far more operational than the word 'compliance' suggests. It is queues, decisions, deadlines and files. In sixteen years across commercial, risk and compliance roles in iGaming — including scaling Kaizen Gaming's function as the company grew from nine people to around nine hundred, and later redesigning a compliance operations division managing six licences inside an NYSE-listed group — the recurring workload has looked like this:

  • Customer due diligence and KYC — verifying identity, age and eligibility before and during the relationship.
  • Anti-money-laundering monitoring — transaction monitoring, source-of-funds review, escalation and reporting of suspicion.
  • Sanctions, PEP and adverse-media screening, on onboarding and on an ongoing basis.
  • Consumer-protection duties — in iGaming, responsible-gambling interventions, affordability and self-exclusion.
  • Marketing and product review — approving campaigns, bonus mechanics and copy before they reach a market.
  • Licence maintenance and regulatory reporting — filings, notifications, key-person changes, statutory returns.
  • Data protection obligations, retention schedules and access rights.
  • Training, attestation and evidencing that staff actually understood it.
  • Regulator correspondence, audits, inspections and remediation plans.

The three lines model, in plain terms

Most regulators expect some version of a three-lines structure. The first line is the business itself — the people who own the risk because they create it, and who run the front-line controls. The second line is compliance and risk: setting standards, challenging the first line, monitoring and reporting. The third line is internal audit, independent of both. Where this breaks in practice is when the second line quietly absorbs first-line work; the business stops owning its own controls, compliance becomes a bottleneck, and everyone loses.

Multi-jurisdiction compliance: one framework, local annexes

As soon as a business holds more than one licence, compliance becomes an information-architecture problem. The failure mode is building a separate operating model per market: six licences, six ways of doing KYC, six evidence repositories, and no ability to answer a group-level question. The approach that holds up is one group standard per domain plus a thin per-market annex that records only the genuine deltas — thresholds, timeframes, reporting formats, local language requirements, local consumer-protection duties — with a change log showing when each delta appeared and why.

How compliance is measured

A function that cannot show numbers is treated as a cost centre and loses every budget argument. The measures worth reporting to a board are throughput and quality, not activity: queue volume and ageing, time-to-decision on enhanced due diligence, false-positive rate on screening, reporting punctuality, findings raised versus closed, and repeat findings — the last being the single best indicator of whether remediation is real or cosmetic.

What non-compliance actually costs

Fines are the headline, but rarely the largest cost. Licence conditions, suspensions and market exits stop revenue outright. Payment providers and banks de-risk away from operators with a poor record. Remediation programmes consume engineering and operations capacity for quarters. And in listed groups, a regulatory finding is a disclosure event with a market-cap consequence long before any penalty is paid.

Which sectors are most affected

Any sector where the state licenses the activity or protects the consumer: financial services, payments, crypto, lending, insurance, healthcare, gambling, pharmaceuticals, energy and increasingly anything processing personal data at scale. The specific rules differ enormously; the operating pattern — identify, design, operate, assure — does not.

Getting it right without slowing the business

The best compliance functions are consulted before launch rather than after, can absorb a new market without a reorganisation, and can answer a regulator's question within a working day. That is achievable, but only when compliance is designed as an operating capability with data, tooling and measurement behind it — not as a policy library. Used that way, the licence stops being a constraint and starts being the moat.

Frequently asked

What is regulatory compliance in simple terms?

It is how an organisation makes sure it operates within the laws, licence conditions and regulations that apply to it — and can prove it with evidence at any time. In practice it means identifying obligations, designing controls, running them consistently, and monitoring and reporting the results.

What is the difference between compliance and legal?

Legal interprets what a rule means and advises on exposure. Compliance builds and runs the day-to-day machinery that keeps operations inside that rule, and produces the evidence proving it. Risk quantifies what could go wrong; internal audit independently checks that all of it works.

What does a compliance officer do day to day?

Customer due diligence and KYC, AML transaction monitoring and escalation, sanctions and PEP screening, consumer-protection interventions, marketing and product review, regulatory reporting and licence maintenance, staff training and attestation, and handling regulator correspondence, audits and remediation.

What are the three lines of defence in compliance?

The first line is the business, which owns the risk it creates and runs front-line controls. The second line is compliance and risk, which sets standards, challenges and monitors. The third line is internal audit, independent of both, verifying that the system genuinely works.

What happens if a company fails to comply with regulations?

Consequences range from fines and remediation orders to licence conditions, suspension or forced market exit. Indirect costs are usually larger: loss of banking and payment partners, engineering capacity consumed by remediation, and — for listed companies — disclosure and share-price impact.

Building or scaling a compliance function?

I have done this from zero three times, across multiple licences and a NYSE-listed parent. Happy to compare notes.

Keep reading