Katrien Martens, Global Compliance Manager & DPO at Barco, joined us as guest speaker. Drawing on her experience in an international and highly regulated business environment, she opened the discussion on four themes: implementation challenges, monitoring and effectiveness, culture and engagement, and the digitalisation of Compliance.
The discussion highlighted that, despite differences between organisations and sectors, Compliance teams often face remarkably similar challenges.
More policies do not mean better Compliance
One of the recurring challenges was the gap between policies on paper and their application in practice. Several participants recognised the risks of having too many policies or making them too detailed and complex. Trying to anticipate every possible situation can ultimately create a “forest of policies” that employees struggle to navigate.
Simplicity therefore matters. Policies need to give employees sufficient guidance without making Compliance unnecessarily burdensome. Several examples discussed during the Roundtable pointed towards shorter, more principle-based policies and frameworks that help employees understand not only what is expected of them, but also why. That “why” is important: when employees cannot understand the reasoning behind a rule, Compliance risks losing credibility.
Accessibility matters too. Even a clear and well-designed policy has limited value if employees do not know where to find it. Making policies easy to access and navigate is therefore another important part of effective implementation.
Ownership was another recurring theme. Rather than Compliance drafting and owning every policy, involving the business can help to ensure that policies reflect operational reality. The same principle applies when exceptions arise: Compliance can advise and perform a risk assessment, but the relevant business owner ultimately needs to understand and accept the risk, with higher-risk decisions escalated to the appropriate level.
For international organisations, an additional layer of complexity arises. A global framework may provide consistency, but local legislation, enforcement practices and cultural differences cannot simply be ignored. Finding the right balance between global principles and local implementation remains a practical challenge.
Tone from the top matters, but so does the tone of middle management
“Tone from the top” has long been part of the Compliance vocabulary. The discussion showed, however, why middle management deserves at least as much attention when organisations want policies to translate into actual behaviour.
Employees interact with their direct managers every day. Those managers approve requests and often play a crucial role in translating policies into everyday behaviour.
Senior leadership therefore remains essential, but its message needs to travel through the organisation. Participants discussed the importance of accountability at management level and of embedding Compliance requirements into existing business processes rather than simply adding more approval layers. This moves Compliance away from being something that sits alongside the business and towards something that becomes part of how decisions are made.
Can you prove that Compliance works?
This may be one of the most difficult questions for any Compliance function. Training completion rates can be measured, speak-up reports can be counted, and audit findings can be tracked. But do those figures prove that behaviour has changed? The Roundtable discussion showed how difficult that question remains.
Speak-up data provides a good example. Is a high number of reports evidence of problems, or of a healthy culture in which employees feel comfortable raising concerns? On the other hand, does a low number indicate that few incidents occur, or that employees are reluctant to speak up? The figures therefore need a story behind them.
Participants discussed combining quantitative metrics with other sources of information, including audit findings, employee surveys - to which Compliance could consider adding a number of targeted questions - as well as feedback and observations gathered through direct contact with the business. Simply talking to people before and after training sessions can reveal issues that might otherwise go unnoticed.
The relationship between Compliance monitoring and Internal Audit was another point of discussion. While Audit can provide valuable insights, Compliance monitoring should not simply duplicate the role of Audit. Monitoring helps to identify trends and improve policies and processes. Maintaining that distinction is important, particularly if Compliance wants to be perceived as a business partner rather than as another audit function.
Actual Compliance cases can provide another valuable source of insight. Several organisations represented at the Roundtable use anonymised real-life cases in internal communications, training or Compliance committees. Sharing these cases also makes abstract rules more tangible by showing employees and management what can happen within an organisation.
The potential business impact of Compliance risks matters too. Translating a risk into potential financial consequences or business interruption can make it considerably more concrete for management.
Moving beyond e-learning
If Compliance aims to influence behaviour, training cannot be reduced to an annual e-learning module.
The discussion produced several practical examples of alternative approaches: team workshops, quizzes, gamification and discussions based on real-life dilemmas. One particularly practical suggestion was to incorporate Compliance topics into existing team meetings across the business, rather than always organising a separate Compliance session. This allows Compliance messages to become part of regular business discussions and creates opportunities to address relevant topics in the context in which they arise.
Local relevance is important as well. When training employees in different countries, using the local language and examples that reflect their working environment can help make the content more meaningful.
The role of managers again becomes important here. Employees should not only hear Compliance messages from the Compliance function. Hearing their own manager discuss a dilemma or reinforce a principle can help bring that message much closer to day-to-day work.
AI and automation: where does human judgement remain essential?
Digitalisation inevitably formed part of the discussion. Participants shared examples of AI and other tools being explored for policy drafting, making policies shorter or more visual, regulatory research, due diligence and preliminary assessments.
The potential to reduce manual work is clear, but so are the limitations. A tool may help pre-fill a due diligence assessment or perform an initial review, for example, but human judgement remains necessary. Participants also highlighted that organisations need to determine their risk appetite before deciding which decisions or controls can safely be automated.
Another challenge is technological fragmentation. Having multiple tools is not necessarily the same as having a complete view. Getting different systems to communicate with each other and bringing the available information together remains complex.
The discussion therefore suggested a pragmatic approach: technology can support Compliance professionals and remove part of the manual workload, but it does not remove the need for professional judgement.
From Compliance framework to Compliance practice
Across the four themes, one common thread emerged: effective Compliance cannot be measured by the number of policies, controls, training modules or tools an organisation has implemented.
The harder question is whether people understand the rules, whether managers reinforce them, whether risks are genuinely owned by the business and whether the Compliance function can identify what is and is not working in practice.
There is no single metric, training format or technology that solves that challenge. But bringing Compliance closer to everyday business decisions, using concrete cases, keeping frameworks workable and combining data with what professionals observe on the ground can all help bridge the gap between Compliance on paper and Compliance in practice.
A warm thank you to Katrien Martens and all participants for contributing their experiences, questions and practical examples to another insightful YouConnect Compliance Roundtable.
MeetDistrict Spectrum/Madou
Avenue Bischoffsheim 15 - 1000 Brussels
MeetDistrict The Link
Posthofbrug 6/8 - 2600 Antwerp
Main office
Nederkouter 124 - 9000 Ghent
Burotel
Rue du Congrès 35 - 1000 Brussels