The role of the compliance function has evolved significantly across Kenya and East Africa. In banking, fintech, insurance, SACCOs, NGOs, manufacturing, and the public sector, compliance is no longer a back-office activity focused solely on policy documentation.
Boards and leadership teams now expect the compliance function to be a strategic enabler; one that protects the organisation from regulatory exposure, supports sustainable growth, and provides the board with reliable assurance that obligations are being met.
This article outlines what boards across sectors expect from the compliance function, structured around the three pillars that define an effective compliance programme: Prevent, Detect, and Respond.
The Three Pillars: Prevent, Detect, Respond
The activities of a compliance function are most clearly understood when organised into three interconnected categories. Each pillar represents a distinct set of deliverables that boards expect to see operating effectively.
Pillar 1: Prevent
Prevention is the foundation of the compliance function’s mandate. It encompasses all activities designed to ensure that the organisation and its employees understand their regulatory obligations and have the tools, policies, and guidance to meet them proactively.
Regulatory Obligation Management
The compliance function is responsible for maintaining a comprehensive and current register of all regulatory and statutory obligations applicable to the organisation. This includes mapping obligations to specific business units, locations, and responsible individuals, tracking regulatory changes and assessing their impact on the organisation, and ensuring that new obligations are incorporated into the compliance programme promptly.
For a bank, this means staying current with CBK circulars, AML/CFT amendments, and consumer protection updates. For an NGO, it means tracking donor compliance requirements across multiple funding streams. For a SACCO, it means monitoring SASRA regulatory updates and ensuring timely alignment.
Policies, Procedures, and Standards
The compliance function leads the development, review, and maintenance of compliance-related policies. This includes the compliance management framework itself, individual regulatory policies such as Anti-Bribery and Corruption, AML/CFT, Data Protection, and Conflict of Interest, standard operating procedures that translate policy requirements into practical guidance, and a policy governance lifecycle that ensures regular review, version control, and board approval.
Boards expect policies to be practical, accessible, and written in language that employees can act on, avoiding excessive legalese while maintaining the rigour that regulators expect.
Training and Awareness
The compliance function designs and delivers training programmes that ensure employees at every level understand their compliance responsibilities. Effective training is role-specific and risk-based: board members receive governance-level briefings on regulatory developments, senior management receives strategic compliance updates and accountability guidance, operational staff receive practical training relevant to their specific roles and regulatory touchpoints, and new employees complete mandatory compliance induction within their first 90 days.
Boards expect the compliance function to track training completion rates and report on coverage, identifying any areas where training uptake requires attention.
Advisory and Guidance
Beyond formal policies and training, the compliance function serves as an advisory resource for the business. This includes providing guidance on regulatory implications of new products, services, or market entries, advising on the compliance aspects of contracts, partnerships, and third-party relationships, and supporting business units in interpreting regulatory requirements and implementing practical controls.
Pillar 2: Detect
Detection is the monitoring and assurance layer of the compliance function. It encompasses all activities designed to identify non-compliance, emerging risks, or control weaknesses before they escalate into material issues.
Compliance Monitoring and Testing
The compliance function conducts regular monitoring and testing activities to verify that obligations are being met.
This includes compliance self-assessments, where business owners periodically confirm their compliance status against assigned obligations, compliance assurance testing, where the compliance team independently verifies the accuracy of self-assessments and the effectiveness of controls, and thematic reviews focused on high-risk areas identified through the compliance risk assessment.
Monitoring results are documented and reported to management and the board, providing evidence-based assurance on the organisation’s compliance posture.
Whistleblowing and Confidential Reporting
The compliance function is responsible for establishing and managing confidential reporting channels through which employees, customers, and third parties can raise concerns about potential non-compliance, fraud, or unethical behaviour.
This includes maintaining a whistleblowing policy and procedures, ensuring that reporting channels are accessible, confidential, and well-communicated, managing the triage and initial assessment of reports received, and protecting reporters from retaliation in accordance with organisational policy and applicable law.
Third-Party Due Diligence
Boards expect the compliance function to oversee due diligence processes for third-party relationships, including suppliers, agents, intermediaries, and joint venture partners.
This is particularly important in sectors with high corruption or regulatory risk, and typically involves screening third parties against sanctions lists and adverse media, assessing the compliance risk profile of proposed relationships, and monitoring ongoing third-party compliance throughout the relationship lifecycle.
Data Analytics and Continuous Monitoring
As compliance functions mature, boards expect increasing use of data analytics to enhance detection capabilities. This includes transaction monitoring in financial services, automated scanning of compliance-relevant data for anomalies or red flags, and trend analysis to identify emerging compliance risks before they materialise as incidents.
Pillar 3: Respond
Response encompasses all activities related to managing compliance incidents, conducting investigations, implementing corrective actions, and driving remediation across the organisation.
Incident and Case Management
The compliance function manages the end-to-end process for compliance incidents, from initial detection or reporting through to resolution. This includes receiving and triaging compliance concerns, conducting or coordinating investigations, documenting findings and conclusions, and escalating material issues to senior management and the board as appropriate.
Corrective Action and Remediation
When non-compliance is identified, the compliance function ensures that corrective action plans are developed, assigned to responsible owners, tracked to completion, and verified for effectiveness. This remediation process is critical to demonstrating to regulators, donors, and stakeholders that the organisation does not merely identify compliance issues; it resolves them.
Regulatory Reporting and Engagement
The compliance function manages the organisation’s relationship with regulators, including preparing and submitting required regulatory reports, coordinating responses to regulatory examinations and inspection findings, managing licence renewals and regulatory approvals, and communicating proactively with regulators on material compliance matters.
Measuring Compliance Function Effectiveness
Boards increasingly expect the compliance function to report against defined metrics that demonstrate programme effectiveness. Common compliance key performance indicators include:
- Compliance obligation coverage rate: percentage of obligations actively monitored
- Self-assessment completion rate: percentage of compliance events self-assessed on time
- Non-compliance rate: number and trend of non-compliance events by category and severity
- Corrective action closure rate: percentage of corrective actions completed within agreed timelines
- Training completion rate: percentage of employees completing mandatory compliance training on schedule
- Whistleblowing report volume and resolution time
- Regulatory examination findings: number, severity, and closure status
These metrics provide the board with a data-driven view of compliance function performance and enable informed governance oversight.
The Case for Automation: Where Boards Are Heading Next
As compliance functions take on broader mandates and manage an increasing volume of obligations, boards have recognised the value of technology in supporting compliance delivery. Manual processes such as spreadsheets, email reminders, and static reports serve well at a limited scale but become increasingly difficult to sustain as regulatory environments expand.
Purpose-built compliance management platforms enable automated scheduling and tracking of compliance events, structured self-assessment and approval workflows, real-time dashboards that give the board current compliance status at any point, corrective action tracking with automated reminders and escalation, and a complete audit trail of all compliance activity.
If your organisation is ready to explore automated compliance management, read our companion article relating to Trigarc Compliance on this link.
| Elevate Your Compliance Function’s Impact Whether you are establishing a compliance function for the first time, strengthening an existing team, or exploring technology to support compliance delivery, FNJ & Associates can help. We provide compliance function advisory, compliance framework development, regulatory obligation mapping, training programme design, and our Trigarc Compliance platform for automated compliance management. Visit fnjassociates.co.ke to schedule a consultation with our team. |
Frequently Asked Questions
What is the primary role of the compliance function?
The compliance function ensures that the organisation meets its regulatory and statutory obligations through a structured programme of prevention, detection, and response. It serves as both an assurance function and a strategic advisor to the business and the board.
How does the compliance function differ from internal audit?
The compliance function operates as a second-line function, responsible for designing and monitoring compliance controls on an ongoing basis. Internal audit operates as a third-line function, providing independent assurance over the effectiveness of both compliance and risk management. The two functions are complementary and should coordinate closely.
What qualifications should a compliance officer have?
Compliance officers typically hold professional qualifications in law, accounting, risk management, or governance. Relevant certifications include Certified Compliance Professional, Certified Anti-Money Laundering Specialist, and ICA Diplomas. The most effective compliance officers combine technical knowledge with strong communication skills and business acumen.
How should the compliance function report to the board?
The compliance function should provide regular reports to the Board Risk and Compliance Committee or Board Audit Committee, typically quarterly. Reports should include compliance status against obligations, monitoring results, non-compliance events and corrective action progress, training completion metrics, and key regulatory developments.
Can the compliance function be outsourced?
Yes. Many organisations in Kenya outsource or co-source compliance activities, particularly compliance monitoring, policy development, and training. Firms like FNJ & Associates provide compliance advisory and outsourcing services across all sectors. Platforms like Trigarc Compliance enable organisations to manage day-to-day compliance activities with automated workflows.
| About FNJ & Associates FNJ & Associates is a professional services firm offering audit and assurance, risk management advisory, tax advisory, compliance, forensic audit, ERP implementation, and corporate training services across Kenya and East Africa. Our Trigarc Compliance platform helps organisations automate compliance obligation tracking and strengthen regulatory governance outcomes. Visit us at fnjassociates.co.ke to learn more. |

