Over twenty-three years of practice, I’ve learned that a well-documented compliance program isn’t necessarily a well-functioning one. Training records, signed acknowledgments, and completion reports show that a program exists, but a program can look rigorous on paper while doing little to shape how employees actually behave. What matters for business leaders is whether policies and procedures guide decisions, particularly when employees face financial pressure, competing priorities, or difficult choices.
Treat Requirements as the Starting Point
A common mistake that organizations make is to treat meeting regulatory requirements, such as ensuring that employees complete annual training or setting up an employee hotline, as the objective rather than the starting point. When that happens, success is measured by whether the requirement has been checked off. When the objective shifts to encouraging compliant behavior, the metrics change with it. If the purpose of a hotline is to get employees to raise concerns, for example, success is measured by whether employees actually trust and use it. Leaders need to communicate that raising concerns is not only permitted but valued and reinforce that message in meetings and internal communications as well as in training. Companies also need to give employees multiple accessible ways to report concerns, including anonymous options where appropriate. Perhaps most importantly, employees need to see that reports are handled promptly and confidentially and that those concerns lead to meaningful action.
I’ve seen versions of this play out more than once. A hotline report alleges that a salesperson isn’t following a required sales process, such as discount approvals. The company looks into it, finds a gap in the process that made the shortcut easy, fixes it, and lets the team know, without naming anyone, that a report led to a real change. That company has done more to encourage reporting than another year of training could.
Build Compliance into Incentives and Reviews
Employees pay close attention to what the company rewards. The goal for leaders should be to set up systems in which compliant behavior is easier, comes more naturally, and is more strongly reinforced than noncompliant behavior, and compensation and performance reviews are where that reinforcement is most visible. That means building specific compliance expectations into employees’ key performance indicators (KPIs) and considering them when decisions are made about raises and promotions. It also means checking whether existing incentives quietly work against the compliance program. Consider a SaaS company that pays sales commissions on signed bookings whether or not the contract went through required legal or security review. Every rep has a financial reason to route around that review at quarter-end, and no amount of training will outweigh a commission check. Paying commissions only on deals that cleared the required review, and evaluating sales managers on whether their teams follow the process, removes that conflict.
Build Preventive Controls into Systems
Many compliance programs are designed primarily to detect misconduct after it happens. For instance, tools such as hotlines and audits allow the company to learn about violations or patterns of troubling behavior. But while these tools are an important part of an effective compliance program, they surface problems after the fact, when they may have already caused operational, financial, or reputational harm. By incorporating preventive controls into the way a business operates, companies can make misconduct more difficult to commit in the first place. For instance, controls can be incorporated into financial or procurement systems to automatically stop transactions that violate company policies. Role-based permissions can block various groups of employees from accessing sensitive customer or financial data. For a SaaS company, preventive controls can also mean a contract management tool that won’t route a customer agreement for signature until nonstandard terms have been approved, or an offboarding process that automatically revokes a departing employee’s access to production systems and customer data on their last day. Operational systems can also be configured to prevent continued activity when a required license, certification, or insurance policy has expired. In addition to preventing problems before they happen, well-designed preventive controls reinforce the message about what is and isn’t permitted.
Don’t Overlook Middle Managers
Senior leaders set the tone for a compliance program, but most employees rarely see them make decisions. The people who determine whether expectations actually reach the front lines, where day-to-day decisions get made, are middle managers. Companies should make compliance an explicit part of how managers are evaluated. Managers should be assessed not only on whether they personally follow policies, but also on whether they reinforce compliant behavior, identify emerging risks, and create an environment where employees feel comfortable reporting concerns. Employees watch what their managers do when business pressure arises. If a manager overlooks a policy violation to keep a major customer happy or dismisses a reported problem as “not a big deal,” front-line employees conclude that compliance is optional. When a manager declines to approve a questionable expense or holds a transaction because required due diligence isn’t complete, employees learn that compliance matters.
Measure Your Progress
Effective compliance programs track more than whether policies, training, and controls are in place. They also measure whether employees understand those requirements, follow them under pressure, and feel comfortable speaking up when something goes wrong.
A measurement system should incorporate leading, behavioral, and outcome indicators. Leading indicators show if the company is creating conditions to support a compliant culture. Training completion rates and post-training assessment scores belong here, though on their own they only show that the basics are in place. Other leading indicators could include the percentage of managers who discuss compliance issues during team meetings or the percentage of employees who know how to raise a concern if they have one. Behavioral indicators show if employees are acting according to compliance expectations, particularly when they have discretion or nobody is watching. These indicators can include the number of employees who raise concerns through appropriate channels rather than ignoring questionable conduct, or who proactively disclose potential conflicts of interest. Outcome indicators, which measure whether the compliance program is actually reducing risk, may include the number of compliance violations recorded, the incidence of regulatory investigations or enforcement actions, or the volume of data privacy incidents. Together, these indicators allow you to assess whether the system is being built, whether employees are using it, and whether it’s producing the desired result.
I’ve helped companies set up online ethics hotlines that then went months without a single report. When that quiet stretch is reported to the board, the usual reaction is relief. I understand the instinct, and I hope all is well, but a low number should prompt a question before it prompts a celebration. It may mean there’s nothing to report. It may also mean employees don’t know the hotline exists, don’t trust it to stay confidential, or don’t believe anything will change. The right response is to ask why no one is using it and what might be going unsaid.
Looking Ahead
A compliance program earns its keep when employees know what’s expected, systems make the compliant choice the easy one, managers back those expectations up under pressure, and people feel safe speaking up. For business leaders, the payoff is a program that holds up when it’s tested, whether by an investor’s diligence request, a customer’s security review, or an employee deciding whether to say something. A well-documented program is a good start, and a well-functioning one is what protects the business.
Victoria R. Husband is a partner in the General Counsel and Corporate practice groups at Potomac Law (PLC). Based in Austin, Texas, Vicky guides businesses through complex regulatory landscapes while enhancing operational efficiency and mitigating legal risks.

