I’ve argued that compliance is meh. I’ve also argued that compliance is awesome.
You may be impressed that I can hold two seemingly contradictory views in my mind without accepting either, and if you are, I have another truth bomb for you: compliance is dangerous.
Not in the sense that most compliance obligations are unregulated Benzodiazepines, but because “compliance education” perpetuates the myth that merely following the rules is enough. The real disasters occur when people comply without considering the risks the rules are meant to address or the behaviours they are intended to influence.
That statement might sound provocative, particularly coming from someone who spends considerable time helping licensees and advisers navigate regulatory obligations. But the point is important. Most compliance issues don’t occur because people deliberately set out to break the rules. They arise when people focus on the rules themselves and lose sight of their purpose.
This is where many traditional approaches to compliance go wrong.
Compliance teams maintain obligation registers, update policies, conduct training, monitor breaches and test controls. Boards seek assurance that regulatory requirements are being met. Regulators issue legislation, regulations and guidance. The underlying assumption is straightforward: regulation creates rules and compliance ensures those rules are followed.
Yet this understanding is becoming increasingly inadequate.
It’s bonkers.
Today’s regulatory environment is characterised by complexity, rapid technological change, evolving consumer expectations and increasing regulatory scrutiny. In this environment, compliance can’t be understood simply as adherence to rules. It requires a deeper understanding of what regulation aims to achieve and how organisations can respond most effectively.
Legal scholar Julia Black offers a definition of regulation that provides a useful starting point. Regulation, she argues, consists of “sustained and focused attempts to change the behaviour of others to address a collective problem or attain an identified end or ends.” This definition shifts the focus away from rules and towards outcomes.
Under this framework, regulation is not primarily about creating obligations. It’s about influencing behaviour to manage risks and achieve public policy objectives.
That recognition matters.
Every regulatory obligation exists because someone has identified a risk requiring intervention. Responsible lending obligations seek to reduce the risk of consumer harm. Anti-money laundering requirements seek to protect the integrity of financial systems. Privacy laws seek to manage risks associated with the misuse of personal information. Breach reporting obligations seek to improve regulatory visibility and accountability.
The rules themselves aren’t the objective. The risks they’re designed to address are.
Licensees and advisers often criticise compliance as being overly complex, bureaucratic or disconnected from commercial reality. That frustration is understandable. As Julia Black has observed more broadly regarding regulation, regulatory systems frequently produce “complex, messy and highly imperfect” outcomes. This is perhaps inevitable because regulation is attempting to address difficult problems through the interaction of multiple actors, each with different incentives, interests and objectives.
Compliance operates within that same environment. It must balance consumer protection with commercial innovation, certainty with flexibility, prescription with professional judgment, and individual interests with broader market outcomes. The challenge isn’t to eliminate that complexity, but to manage it in a way that remains focused on risk and regulatory purpose.
This perspective also helps explain why organisations can sometimes satisfy regulatory requirements in form while failing in substance. Recent history provides numerous examples of firms that maintained extensive compliance frameworks, documented controls and comprehensive policies, yet still produced poor customer outcomes, misconduct or significant regulatory failures.
In many cases, the problem wasn’t an absence of rules. The problem was a failure to understand the purpose of those rules.
Even worse, the common response to regulatory failures is to create more detailed regulations. The assumption is intuitive: if organisations have failed to comply, greater prescription should provide greater certainty and better outcomes.
However, regulatory experience often demonstrates the opposite.
Increasing the precision and volume of rules can create new forms of complexity. Detailed rules inevitably contain gaps, interact with other rules in unforeseen ways and generate outcomes that legislators and regulators may not have intended. Organisations become focused on satisfying the letter of the requirement rather than addressing the underlying risk that gave rise to the rule in the first place.
This creates a regulatory paradox.
The more detailed a regulatory framework becomes, the greater the risk that compliance becomes procedural rather than purposeful. Resources are devoted to interpreting increasingly complex requirements, while attention is diverted from the behaviours and outcomes that regulation was designed to achieve.
This results in a form of technical compliance that satisfies individual requirements but fails to address broader regulatory concerns.
This is one reason why modern regulatory systems increasingly rely on a combination of rules and principles.
Rules provide certainty. They establish minimum standards and clearly articulate expectations. They are particularly effective where activities are well understood, and the desired behaviour can be specified in advance.
Principles perform a different function. They guide conduct where rules can’t anticipate every circumstance. Obligations such as acting efficiently, honestly and fairly, managing conflicts appropriately or treating customers fairly are not designed to prescribe every action. They establish standards against which behaviour can be assessed.
As business models become more complex and technologies evolve more rapidly, principles become increasingly important. No regulator can draft rules capable of anticipating every future scenario, product innovation or technological development. Principles provide the flexibility necessary to respond to changing circumstances while remaining focused on regulatory objectives.
For compliance professionals, this has important implications.
Compliance isn’t simply the process of mapping obligations and testing controls. It’s the process of understanding how regulatory obligations, risks and organisational behaviours interact.
The central question is not whether a rule exists, but what risk that rule is seeking to manage.
This is where risk-based compliance becomes essential.
A risk-based approach recognises that not all obligations carry the same significance and not all risks warrant the same level of attention. It focuses organisational resources on areas where the potential for consumer harm, regulatory intervention, operational disruption or reputational damage is greatest.
Rather than treating compliance as an exercise in administering an ever-expanding list of obligations, risk-based compliance seeks to understand the purpose of those obligations and prioritise effort accordingly.
Importantly, risk-based compliance isn’t a lesser form of compliance. It’s a more mature and strategically aligned one.
It recognises that regulation is ultimately concerned with outcomes rather than processes. It acknowledges that effective governance requires judgment as well as adherence. And it understands that compliance functions should contribute to organisational decision-making rather than operate solely as monitoring mechanisms.
This philosophy has always been central to Assured Support’s approach.
Compliance isn’t viewed as a documentation exercise or a checklist function. Policies, procedures, registers, monitoring programs and assurance activities remain important, but they are tools rather than objectives. Their value lies in their ability to help organisations identify, assess and manage the risks that regulation seeks to address.
This requires a focus on infrastructure, governance, accountability, decision-making, culture and behaviour as much as it does on regulatory obligations themselves.
Ultimately, organisations do not create value through compliance documents. They create value through behaviours that promote trust, protect consumers, support sound decision-making and achieve regulatory outcomes.
As regulatory complexity continues to increase, organisations that view compliance solely as rule administration are likely to find themselves overwhelmed by the volume of obligations they face. Those who understand compliance as a risk-based system of behavioural governance will be better positioned to navigate uncertainty, respond to change, and meet the expectations of regulators, customers, and stakeholders alike.
Compliance isn’t about collecting rules. It’s about understanding risks, influencing behaviour and achieving the outcomes that regulation was designed to deliver.
Ensure your compliance framework drives results, not just documentation. Assured Support helps AFSL holders and advisers prioritise high-risk obligations, embed risk-based behaviours, and achieve regulatory outcomes with confidence. Align your compliance strategy with purpose and oversight to protect customers, foster trust, and meet evolving regulator expectations.
If you enjoyed this, we recommend
Compliance 101: Approaches and Principles
The Compliance Gap: Licensees’ Anxieties and ASIC’s Focus
Compliance Culture: An Analysis of Industry Practices and Areas for Improvement
Frequently Asked Questions
Compliance isn’t about ticking boxes; it’s about understanding the regulatory intent behind each obligation. Effective compliance ensures organisational decisions proactively mitigate consumer harm, financial risk, and reputational damage, aligning behaviour with both the law and broader public policy outcomes.
In practice, this requires interpreting rules through a risk lens, monitoring operational behaviours, and continuously evaluating whether compliance activities deliver the intended protective outcomes.
Rules provide certainty, but they cannot anticipate every scenario. Principles such as acting efficiently, honestly, fairly, and managing conflicts appropriately guide behaviour where prescriptive rules fall short.
They enable advisers and licensees to exercise professional judgment in complex or novel situations, ensuring that compliance decisions remain aligned with regulatory objectives, protect consumers, and withstand regulatory scrutiny.
Principles also support a risk-based approach, helping organisations prioritise actions that matter most.
Risk-based compliance prioritises organisational effort on obligations and activities with the highest potential for consumer harm, operational disruption, or regulatory intervention.
It involves assessing risks, mapping them against regulatory intent, and allocating resources proportionally.
This approach moves beyond uniform monitoring to dynamic, intelligence-led compliance programs, where controls, audits, and training are targeted, measurable, and focused on outcomes rather than procedural adherence.
Yes. Compliance in form, satisfying checklists and documenting processes, does not guarantee compliance in substance.
Firms can comply with the letter of the law while producing poor customer outcomes if they fail to consider the behavioural or risk objectives behind rules.
Effective compliance integrates monitoring, scenario testing, and outcome measurement to ensure policies, controls, and procedures actually prevent harm and meet regulatory expectations.
Modern compliance teams must integrate governance, culture, monitoring, and strategic decision-making. They should use risk-based prioritisation, scenario analysis, and behavioural oversight to ensure obligations are met in a way that protects clients and the firm.
Teams must also communicate regulatory purpose, provide practical guidance to advisers, and continuously adapt compliance frameworks as products, technology, and consumer expectations evolve. Tools like Assured Support’s risk frameworks or [complye] can support ongoing tracking and audit readiness.