Public Law Codexery

Regulatory compliance

Organizational adherence to laws, policies, and regulations.

Regulatory compliance

Regulatory compliance is the objective organizations pursue to make sure they know about and follow relevant laws, policies, and regulations. As regulations multiply and the demand for operational transparency grows, companies increasingly rely on unified, harmonized sets of compliance controls. This method helps meet all necessary governance requirements without duplicating effort or wasting resources. Compliance itself means conforming to a rule—whether a specification, policy, standard, or law. Traditionally, it has been understood through deterrence theory: punishing a behavior reduces violations by the offender (specific deterrence) and by others (general deterrence). Economic theory supports this view, framing punishment as a cost and compliance as a cost-benefit balance (Becker 1968). However, psychological research on motivation offers a different perspective: offering rewards (Deci, Koestner, and Ryan, 1999) or imposing fines (Gneezy and Rustichini, 2000) for a behavior creates extrinsic motivation that can weaken intrinsic motivation and ultimately reduce compliance.

Regulations and accrediting bodies differ by industry—examples include PCI-DSS and GLBA in finance, FISMA for U.S. federal agencies, HACCP for food and beverage, and the Joint Commission and HIPAA in healthcare. Some organizations use other compliance frameworks (like COBIT) or standards (such as NIST) to guide how they meet regulations. To handle reporting requirements, some companies store compliance data—any data belonging to the enterprise or covered by law that can be used to implement or verify compliance—in a separate repository. Compliance software is increasingly used to manage this data more efficiently, which may include calculations, data transfers, and audit trails.

The International Organization for Standardization (ISO) provides a key international standard, ISO 37301:2021 (which replaces ISO 19600:2014), for how businesses approach regulatory compliance. It emphasizes that compliance and risk should operate together as "colleagues" within a shared framework, with some nuances to account for their differences. ISO also produces standards like ISO/IEC 27002 to help organizations meet regulatory compliance in security management and assurance. Other specialized bodies, such as the American Society of Mechanical Engineers (ASME), develop standards and regulation codes that provide rules and directives to ensure products comply with safety, security, or design standards.

Regulatory compliance varies not only by industry but also by location. Financial, research, and pharmaceutical regulations in one country may be similar to those in another but with distinct nuances, often reflecting "reactions to the changing objectives and requirements in different countries, industries, and policy contexts."

In Australia, major financial services regulators for deposits, insurance, and superannuation include the Reserve Bank of Australia (RBA), the Australian Prudential Regulation Authority (APRA), the Australian Securities & Investments Commission (ASIC), and the Australian Competition & Consumer Commission (ACCC). These bodies ensure financial institutions meet their promises, document transactional information, maintain fair competition, and protect consumers. APRA specifically oversees superannuation, including new rules requiring trustees to demonstrate adequate resources (human, technology, and financial), risk management systems, and the necessary skills and expertise to manage a superannuation fund, with individuals being "fit and proper." Other key Australian regulators include the Australian Communications & Media Authority (ACMA) for broadcasting, internet, and communications; the Clean Energy Regulator for monitoring and enforcing compliance with energy and carbon emission schemes; and the Therapeutic Goods Administration for drugs, devices, and biologics. Australian organizations seeking compliance may use AS ISO 19600:2015 (which supersedes AS 3806-2006), a standard that focuses on the organizational elements needed to support compliance and recognizes the need for continual improvement.

In Canada, federal regulation of deposits, insurance, and superannuation is handled by two independent bodies: the OSFI, under the Bank Act, and FINTRAC, mandated by the Proceeds of Crime (Money Laundering) and Terrorist Financing Act, 2001 (PCMLTFA). These groups protect consumers, regulate risk control and management, and investigate illegal activities like money laundering and terrorist financing. At the provincial level, each province has its own laws and agencies. Unlike other major federations, Canada has no federal securities regulatory authority; instead, provincial and territorial regulators coordinate through the Canadian Securities Administrators (CSA) to harmonize capital market regulation. Other key Canadian regulators include the Canadian Food Inspection Agency (CFIA) for food safety, animal health, and plant health, and Health Canada.

field
Regulatory compliance
known_for
Ensuring organizations meet legal, policy, and regulatory requirements across industries and nations
key_regulators_example
APRA (Australia), OSFI (Canada), Dutch Central Bank (Netherlands)
related_frameworks
COBIT, NIST, PCI-DSS, GLBA, FISMA, HACCP, HIPAA

Lore & Background

Regulatory compliance has traditionally been explained by reference to deterrence theory, according to which punishing a behavior will decrease violations both by the wrongdoer (specific deterrence) and by others (general deterrence). This view has been supported by economic theory, which has framed punishment in terms of costs and has explained compliance in terms of a cost-benefit equilibrium. However, psychological research on motivation provides an alternative view: granting rewards or imposing fines for a certain behavior is a form of extrinsic motivation that weakens intrinsic motivation and ultimately undermines compliance.

Reader's Guide

Regulatory compliance is a critical function for organizations worldwide, shaped by a mix of deterrence theory, economic cost-benefit analysis, and psychological insights into motivation. The field has evolved to include consolidated and harmonized sets of compliance controls to avoid duplication of effort. Compliance varies by nation and industry, with examples including financial regulators like Australia's APRA, Canada's OSFI, and the Netherlands' Dutch Central Bank, as well as sector-specific frameworks such as PCI-DSS, HIPAA, and HACCP. Organizations increasingly use compliance software and separate data stores to manage reporting requirements and audit trails. Non-compliance can lead to fines, product recalls, or restrictions on market access, making effective compliance management essential for operational transparency and legal adherence.

Did You Know?

More in Public Law 1-24

Spotted an error? Know more?

This is a living reference — every entry is fact-audited, and reader corrections feed straight into our audit queue. Suggest an edit · See this site's audit record

Comments

Loading…
Open in the interactive codex →