Skip to main content
Category: Compliance Programs

Compliance Monitoring

Also known as: compliance monitoring program, compliance surveillance
Simply put

Compliance monitoring is the ongoing process of checking whether an organization is actually following the laws, regulations, and internal policies that apply to it. Rather than assuming rules are being followed, the organization regularly assesses its day-to-day activities to catch problems and reduce the risk of violations. In some regulated sectors, external authorities also conduct their own monitoring to confirm that regulated parties obey applicable laws.

Formal definition

Compliance monitoring is a systematic, generally continuous activity of assessing, tracking, reviewing, and evaluating whether an organization adheres to applicable regulatory requirements, internal policies and procedures, and relevant industry or best-practice standards, with the aim of identifying compliance risk issues in operational activities. It is typically owned by the compliance function as a second-line assurance activity and is distinct from first-line operational controls performed by management and from independent internal audit assurance; the specific scope, methods, and reporting lines vary by jurisdiction, sector, entity type, and applicable framework. The term is also used by certain regulators (for example, environmental authorities) to describe supervisory monitoring of a regulated community, which is a separate use from an entity's internal monitoring program. This entry is educational and not legal, audit, or compliance advice.

Why it matters

Compliance monitoring addresses a fundamental governance gap: the difference between having policies on paper and confirming they are actually followed in practice. Without a monitoring program, an organization relies on the assumption that laws, regulations, and internal procedures are being observed across its day-to-day operations. Ongoing assessment replaces that assumption with evidence, enabling the organization to identify compliance risk issues in operational activities before they escalate into violations, regulatory enforcement, or reputational harm.

The discipline also clarifies accountability. Compliance monitoring is typically a second-line assurance activity owned by the compliance function, sitting between the first-line operational controls performed by management and the independent assurance provided by internal audit. This separation matters because conflating the three lines can leave gaps in coverage or create false confidence that a control is both operating and being independently verified when it is not. Boards and senior management generally rely on monitoring outputs to understand whether the control environment is functioning as designed, though the specific scope, methods, and reporting lines vary considerably by jurisdiction, sector, and entity type.

It is worth noting that the term carries a distinct meaning in certain regulatory contexts. Some authorities, for example, the U.S. Environmental Protection Agency, use compliance monitoring to describe their own supervisory oversight of a regulated community to confirm adherence to applicable laws. That external, supervisory use is separate from an entity's internal monitoring program, and readers should be careful not to conflate the two when interpreting requirements that apply to them.

Who it's relevant to

Chief Compliance Officers
As the typical owners of the compliance monitoring program, chief compliance officers are responsible for designing monitoring activities around identified risks, ensuring monitoring remains distinct from first-line controls and independent audit, and reporting findings through appropriate channels. Program scope and methods generally need to be tailored to the organization's regulatory environment and risk profile.
Internal Auditors
Internal audit provides independent, third-line assurance and should understand where compliance monitoring sits within the lines of defense to avoid duplication or gaps. Auditors may evaluate whether the compliance function's monitoring is appropriately designed and operating, while preserving their own independence from the second-line activity they assess.
Boards and Their Committees
Boards and committees such as audit or risk committees generally rely on monitoring outputs to exercise oversight of whether compliance risk is being managed. Their role is oversight rather than the operational performance of monitoring, and they typically look to monitoring reports to inform their assessment of the control environment.
Operational Management (First Line)
Management performs the first-line controls that monitoring is designed to assess and is generally responsible for remediating deficiencies that monitoring identifies. Understanding the distinction between owning a control and having that control independently monitored helps management respond appropriately to findings.
Entities in Externally Supervised Sectors
Organizations in regulated sectors, such as those subject to environmental regulators, should recognize that certain authorities conduct their own compliance monitoring to confirm the regulated community obeys applicable laws. This external supervisory monitoring is separate from an entity's internal program, and both may apply depending on the jurisdiction and sector.

Inside Compliance Monitoring

Monitoring Plan or Schedule
A documented, risk-based plan setting out what compliance obligations are to be monitored, how frequently, by whom, and using what methods. Typically prioritized according to the assessed compliance risk of each area rather than reviewing all obligations at equal intensity.
Control Testing
Activities that assess whether compliance controls are both suitably designed and operating effectively over time. Distinguishing control design from operating effectiveness matters: a well-designed control can still fail in practice, and monitoring generally aims to confirm both dimensions.
Data and Metrics
Key indicators, exception reports, sampling results, and trend information used to detect potential non-compliance. Metrics support monitoring but are typically inputs to professional judgment rather than conclusive evidence on their own.
Issue Identification and Escalation
Defined pathways for recording potential breaches, deficiencies, or emerging risks and escalating them to the appropriate level of management, and where warranted, to a board committee. The escalation route depends on severity, entity structure, and internal policy.
Remediation Tracking
Recording corrective actions, assigning ownership, and following up to confirm that identified issues are addressed. Monitoring generally includes verifying that remediation was completed and effective, not only that it was initiated.
Reporting
Communication of monitoring results to management, senior leadership, and oversight bodies. Reporting content and frequency vary by jurisdiction, sector, entity type, and internal governance arrangements.

Common questions

Answers to the questions practitioners most commonly ask about Compliance Monitoring.

Is compliance monitoring the same as internal audit?
No. Although the two functions are related and often coordinate, they are generally distinct. Compliance monitoring is typically a second-line activity owned by the compliance function, which designs, embeds, and checks controls against applicable legal and regulatory requirements on an ongoing basis. Internal audit, by contrast, is usually a third-line assurance function that independently evaluates the design and operating effectiveness of controls, including the compliance function's own monitoring activities. Conflating the two can blur the independence that separates the second and third lines. The precise allocation of these responsibilities varies by entity type, sector, and jurisdiction, so an organization should confirm how its own model assigns them.
Does compliance monitoring mean the compliance function owns the risk being monitored?
Generally, no. Monitoring is an assurance-oriented activity, not ownership of the underlying risk. In many organizations that follow a three-lines model, the first line, meaning the business or operational management, owns and manages the risk and its day-to-day controls. The compliance function typically provides oversight, guidance, and independent checking as a second-line activity, but this does not transfer accountability for the risk itself away from management. Treating monitoring as a transfer of ownership can create a false sense of coverage. How accountability is documented depends on the entity's governance framework and its own judgment about role allocation.
How does an organization decide what to include in a compliance monitoring plan?
In practice, monitoring plans are commonly prioritized on a risk basis, directing more frequent or intensive review toward areas of higher assessed compliance risk. Inputs often include the organization's compliance risk assessment, applicable legal and regulatory obligations, prior findings, regulatory expectations, and changes in the business or its environment. The specific methodology, scope, and coverage cycle depend on the entity's size, sector, jurisdiction, and risk appetite. This is an area shaped by professional judgment, and the design should be documented so that coverage decisions can be explained and revisited.
What is the difference between monitoring control design and control operating effectiveness in a compliance context?
These are separate questions and should not be treated as interchangeable. Assessing control design generally asks whether a control, if operating as intended, would adequately address the applicable requirement or risk. Assessing operating effectiveness generally asks whether the control actually functioned as designed over a relevant period. A control can be well designed yet fail in operation, or operate consistently while being poorly designed for the obligation. Effective monitoring typically considers both dimensions, and the depth of testing depends on the risk and the organization's own approach.
How should compliance monitoring findings be escalated and reported?
Reporting arrangements generally depend on the organization's governance structure, but monitoring outputs are commonly reported to senior management and, for significant matters, to a relevant board committee such as an audit or risk committee, consistent with each body's role. Management typically retains responsibility for remediating identified issues, while the board or its committee exercises oversight rather than day-to-day remediation. Clear escalation thresholds, tracking of remediation, and timely reporting are often features of an effective process, but the specific channels, frequency, and thresholds should reflect the entity's framework and applicable expectations.
How is compliance monitoring documented to demonstrate that it took place?
Documentation practices vary, but organizations commonly retain records of the monitoring plan, the scope and methodology applied, the work performed, the evidence reviewed, the conclusions reached, and any findings and follow-up actions. Such records can help demonstrate that monitoring was carried out on a risk basis and that issues were tracked to resolution. The appropriate level of documentation depends on the entity, its sector, and any applicable regulatory expectations. This entry is educational and does not constitute legal, audit, or compliance advice; an organization should apply its own judgment and confirm requirements in its jurisdiction.

Common misconceptions

Compliance monitoring is the same as internal audit.
They are distinct. Compliance monitoring is typically a first- or second-line activity owned by the compliance function or by management, focused on ongoing checking of specific obligations. Internal audit generally provides independent third-line assurance over the adequacy of controls, including the monitoring activities themselves. Conflating the two undermines the separation of ownership and independent assurance.
If a control is well designed, monitoring can confirm compliance is achieved.
Design and operating effectiveness are separate questions. A control that is soundly designed may still fail to operate as intended. Monitoring generally seeks evidence of both, and testing a sample provides reasonable, not absolute, assurance about the wider population.
Monitoring every compliance obligation at the same intensity demonstrates diligence.
Effective monitoring is typically risk-based, concentrating effort where the assessed compliance risk is greatest. Uniform coverage can waste resources and dilute attention on higher-risk areas. The appropriate calibration depends on the entity's facts, obligations, and risk profile.

Best practices

Base the monitoring plan on a documented compliance risk assessment so that frequency and depth of testing reflect the relative risk of each obligation area.
Test both control design and operating effectiveness, and clearly document the sampling approach and its limitations so results are not overstated.
Maintain clear escalation pathways that route issues to the appropriate management level and, where warranted, to the relevant board committee, keeping ownership of remediation distinct from independent assurance.
Track remediation to closure and verify that corrective actions were effective, rather than treating an issue as resolved once an action is merely assigned.
Keep compliance monitoring functionally distinct from internal audit assurance, and confirm that reporting lines preserve the independence and objectivity of each function.
Tailor reporting content and frequency to the audience and to applicable jurisdictional, sector, and entity-specific requirements, and treat monitoring outputs as educational inputs to professional judgment rather than definitive conclusions.