Skip to main content
Category: Compliance Programs

Compliance Testing

Also known as: Conformance Testing, Type Testing
Simply put

Compliance testing is the process of checking whether an organization, product, or process actually meets the standards it is supposed to follow, whether those come from law, industry requirements, or internal policies. It is often described as a kind of practice audit, in which reviewers examine systems, processes, and controls to confirm adherence and identify gaps. The specific standards being tested against, and how rigorous the testing is, depend on the applicable regulation, sector, and the organization's own policies.

Formal definition

Compliance testing (also referred to as conformance testing or type testing) generally refers to the systematic evaluation of an organization, product, or process to determine whether it adheres to applicable regulatory, industry, or internal standards. In a compliance program context, it typically functions as a targeted assurance activity in which compliance personnel examine systems, processes, and controls for adherence to a specified rule, policy, or regulation, distinct from broader internal audit or enterprise risk management. The scope, criteria, and frequency of testing vary by jurisdiction, sector, and entity type, and results are generally used to evidence adherence and surface remediation needs. This entry is educational and not legal, audit, or compliance advice; the precise standards, ownership, and accountability for any given test depend on the facts and the organization's governance structure.

Why it matters

Compliance testing gives an organization direct evidence about whether its stated commitments to regulatory, industry, or internal standards are being honored in practice, rather than only on paper. A policy can be well-drafted and a control well-designed, yet still fail in operation; testing is the mechanism by which a compliance function moves from assuming adherence to demonstrating it. Because it is often described as a kind of practice audit, it surfaces gaps before an external regulator, certification body, or customer does, giving management the opportunity to remediate on its own terms.

The value of compliance testing also lies in what it produces for accountability and oversight. Test results generally serve as documented evidence of adherence and as a structured way to identify remediation needs, which can be reported to senior management and, where appropriate, to the board or its relevant committee. This distinguishes testing as a targeted assurance activity from broader internal audit work or enterprise risk management: it is typically owned within the compliance program and focused on a specified rule, policy, or regulation rather than the full universe of enterprise risks.

The scope and rigor of compliance testing are not universal. What must be tested, how often, and against which criteria depend on the applicable regulation, sector, and entity type, as well as the organization's own policies. For that reason, an effective testing program is calibrated to the standards that actually bind or apply to the organization, and its findings should be read as informing, not replacing, professional legal, audit, or compliance judgment.

Who it's relevant to

Chief Compliance Officers and Compliance Teams
Compliance functions typically own compliance testing as a targeted assurance activity, using it to confirm that specified rules, policies, or regulations are being followed and to document evidence of adherence. It gives them a structured way to identify and prioritize remediation before issues escalate to regulators or external reviewers.
Internal Auditors and Assurance Functions
Although compliance testing is generally distinct from broader internal audit and enterprise risk management, assurance functions have an interest in how testing is scoped and performed, and may rely on or corroborate its results. Understanding where compliance testing sits helps avoid duplication and clarifies which function is accountable for a given evaluation.
Boards and Oversight Committees
Boards and their relevant committees exercise oversight of the compliance program and generally rely on testing results as evidence that stated standards are being met and that gaps are being remediated. The nature and frequency of reporting they receive depend on the organization's governance structure and the standards that apply to it.
Product, Quality, and Engineering Teams
Where compliance testing takes the form of conformance or type testing, product, quality, and engineering personnel are relevant because it is their processes, products, or services being evaluated against a defined specification. Their involvement is often essential to producing testable criteria and to acting on identified nonconformities.

Inside Compliance Testing

Control Identification and Scoping
Compliance testing begins by identifying which controls, policies, or regulatory requirements fall within the scope of the review, typically driven by a risk assessment that prioritizes higher-risk obligations. Scope generally reflects the applicable legal requirements and internal policies for the entity, which vary by jurisdiction, sector, and entity type.
Design Assessment
An evaluation of whether a control, as designed, is capable of preventing or detecting the compliance failure it is intended to address. This is distinct from testing whether the control actually operated as intended over a period.
Operating Effectiveness Testing
An examination of whether a control functioned consistently as designed throughout the relevant period, typically using techniques such as inquiry, observation, inspection of evidence, and re-performance. A well-designed control can still fail on operating effectiveness.
Sampling and Population Definition
The selection of items from a defined population to draw conclusions about the whole, using judgmental, statistical, or risk-based methods. Sample size and method generally depend on control frequency, risk, and the level of assurance sought.
Evidence and Documentation
The retention of workpapers, test steps, samples examined, and results that support conclusions and allow the work to be reviewed or reperformed. Documentation quality affects the reliability and defensibility of testing conclusions.
Findings, Deficiencies, and Remediation Tracking
The characterization of exceptions by severity, escalation as appropriate, and monitoring of corrective actions to completion. Distinguishing an isolated exception from a systemic control failure is generally a matter of professional judgment.
Reporting and Accountability
Communication of results to the appropriate level of management and, where relevant, oversight bodies. Compliance testing is typically owned by the compliance function (a second-line activity) or by internal audit (a third-line assurance activity), with the responsibility differing depending on how the organization structures its lines of defense.

Common questions

Answers to the questions practitioners most commonly ask about Compliance Testing.

Is compliance testing the same as internal audit's assurance work?
No. Compliance testing is generally an activity owned by the compliance function (typically a second-line function) to evaluate whether the organization is adhering to applicable laws, regulations, and internal policies. Internal audit, as an independent third-line assurance function, provides separate, objective assurance over the design and operating effectiveness of controls, including over the compliance function's own testing. While both may examine similar controls, the two are distinct in ownership, independence, and reporting lines. Conflating them can undermine the independence that the three-lines model is designed to preserve. This distinction can vary by organizational structure and jurisdiction.
Does passing a compliance test mean the organization is fully compliant and free of risk?
Not necessarily. Compliance testing typically evaluates a sample of transactions, activities, or controls at a point in time, so results reflect what was tested rather than a guarantee of complete compliance across all activity. A favorable result addresses tested controls and does not eliminate residual risk, nor does it substitute for ongoing monitoring. Testing also generally focuses on adherence to defined requirements and may not capture emerging risks or areas outside its scope. Results should be interpreted in light of sample size, methodology, and coverage, and are one input among several into an overall view of compliance health.
How should the scope of a compliance testing program be determined?
Scope is generally determined using a risk-based approach, prioritizing areas with higher exposure based on factors such as regulatory significance, historical issues, transaction volume, and changes in the business or regulatory environment. Many programs map applicable legal and regulatory obligations to specific policies and controls, then focus testing effort where the consequences of non-compliance are most material. Scope decisions typically involve professional judgment and should be documented, and they may vary by sector, jurisdiction, and entity type. Coordination with risk management and internal audit can help avoid gaps and unnecessary duplication.
How do you distinguish testing control design from testing operating effectiveness?
Testing control design generally evaluates whether a control, if operating as intended, is capable of preventing or detecting the relevant compliance failure. Testing operating effectiveness evaluates whether the control actually functioned as designed over a defined period. In practice, design is often assessed first, since a well-operated control that is poorly designed may still leave a compliance gap. Operating effectiveness testing typically relies on examining evidence across multiple instances rather than a single point in time. Keeping these two distinct helps clarify whether an identified weakness stems from how the control was built or from how it was executed.
How should sample sizes and testing frequency be set?
Sample size and frequency are typically driven by the assessed level of risk, the volume and nature of the activity, and the control's importance. Higher-risk or higher-volume areas generally warrant larger samples and more frequent testing, while lower-risk areas may be tested less often. Some organizations reference established sampling methodologies, but the appropriate approach depends on facts and professional judgment rather than a single universal standard. Documenting the rationale for sample size and frequency supports defensibility and allows results to be interpreted with an understanding of their coverage and limitations.
How should compliance testing findings be reported and escalated?
Findings are generally documented with a clear description of the issue, its potential significance, and any recommended remediation, then reported through defined channels within the compliance function and, where appropriate, to management and relevant board committees such as an audit or risk committee. Escalation thresholds typically depend on the severity and potential impact of the finding, with more significant matters reported to more senior levels. Effective reporting distinguishes management's remediation responsibilities from the board's oversight role. Escalation protocols and reporting lines vary by organization, jurisdiction, and governance structure, and should be defined in advance.

Common misconceptions

Compliance testing and internal audit are the same activity.
They can overlap but are generally distinct. Compliance monitoring and testing are often performed by the compliance function as a second-line activity that helps management manage its own compliance risks, whereas internal audit typically provides independent, third-line assurance over the effectiveness of those controls and the compliance function itself. Which function performs a given test depends on the organization's structure and its allocation of roles across the lines of defense.
If a control is well designed, testing its operation is unnecessary.
Design effectiveness and operating effectiveness are separate concepts. A control can be soundly designed yet fail to operate as intended over time due to human error, override, turnover, or process change. Compliance testing generally addresses both dimensions, and passing one does not establish the other.
A clean testing result proves the organization is fully compliant.
Testing typically relies on sampling and covers a defined scope and period, so it provides a level of assurance rather than a guarantee. Results are limited by sample size, the reliability of evidence, and the areas selected for review, and they do not extend to matters outside the tested population or period.

Best practices

Ground the testing plan in a documented risk assessment so that testing effort and frequency are concentrated on higher-risk obligations and controls rather than applied uniformly.
Test design effectiveness and operating effectiveness as distinct steps, and state clearly in workpapers which dimension a given test addresses.
Define the population and sampling method before testing begins, and select sample size and approach based on control frequency, risk, and the intended level of assurance.
Retain sufficient documentation and evidence for each test step so that conclusions can be independently reviewed or reperformed.
Clarify at the outset which function owns the testing and to whom results are reported, keeping second-line monitoring distinct from third-line independent assurance to preserve appropriate accountability.
Characterize exceptions by severity, distinguish isolated errors from systemic failures using professional judgment, and track remediation through to verified completion.