Centralised compliance teams effectiveness.
Centralised Compliance Teams Effectiveness
1. Introduction
A centralised compliance team is a dedicated function within an organisation that coordinates legal, regulatory, policy and procedural compliance across different departments, branches, subsidiaries or business units.
Instead of allowing every department to manage compliance independently, a central compliance function establishes common standards, maintains compliance calendars, monitors regulatory obligations, conducts reviews, provides legal and regulatory guidance, and reports significant compliance risks to senior management or the board.
Centralisation can improve consistency, monitoring and accountability. However, it does not automatically eliminate legal risk. A central compliance team can be effective only when it has adequate authority, access to information, independence, qualified personnel and cooperation from operational departments.
Indian judicial decisions concerning compliance officers, corporate governance, statutory duties and corporate liability demonstrate that compliance is a substantive responsibility and cannot always be reduced to merely maintaining records or signing documents. In Securities and Exchange Board of India v. V. Shankar, the Supreme Court specifically held that a compliance officer's role under the applicable SEBI regulations included ensuring regulatory compliance, not merely handling investor grievances.
2. Meaning of a Centralised Compliance Team
A centralised compliance team is an organisational unit responsible for coordinating compliance requirements across the organisation.
Its responsibilities may include:
identifying applicable laws and regulations;
maintaining a central compliance register;
preparing compliance calendars;
monitoring statutory deadlines;
issuing compliance policies;
conducting internal compliance reviews;
coordinating regulatory inspections;
monitoring branch-level compliance;
investigating reported compliance failures;
advising management;
maintaining evidence of compliance;
reporting material violations; and
coordinating with external regulators and legal advisers.
The central team may operate from the organisation's head office while individual business units remain responsible for implementing the requirements.
3. Objectives of Centralised Compliance
The principal objectives include:
3.1 Uniformity
A central team can establish one organisation-wide compliance standard instead of allowing different branches to interpret the same legal requirement differently.
3.2 Risk Identification
Central monitoring allows management to identify repeated or systemic violations.
3.3 Regulatory Consistency
Policies, reporting procedures and documentation can be standardised.
3.4 Accountability
A central compliance function provides a defined mechanism for reporting compliance failures.
3.5 Prevention
The purpose of compliance is not merely to discover violations after they occur. A properly designed compliance system should prevent or reduce the likelihood of violations.
3.6 Management Information
A central team can consolidate compliance information from different departments and provide management with a broader picture of regulatory risk.
4. Structure of a Centralised Compliance Function
A typical centralised structure may contain:
Board / Board Committee
↓
Chief Compliance Officer / Head of Compliance
↓
Central Compliance Team
↓
Regional / Departmental Compliance Coordinators
↓
Business Units / Branches
This structure does not necessarily mean that all compliance responsibilities are transferred to the central team.
Operational departments normally remain responsible for implementing the law in their day-to-day activities.
5. Centralisation Does Not Transfer All Legal Responsibility
One of the most important principles is that the creation of a central compliance department does not automatically transfer every statutory responsibility away from directors, officers or business managers.
For example, where a statute specifically imposes duties upon:
directors;
company secretaries;
compliance officers;
employers;
occupiers;
principal employers; or
other designated officers,
those statutory responsibilities continue to operate according to the legislation.
The Supreme Court's decision in SEBI v. V. Shankar illustrates this point. The Court rejected the interpretation that a compliance officer's function was merely administrative and held that the applicable regulation expressly required the compliance officer to ensure compliance with the buyback regulations.
Therefore:
Centralisation is an organisational arrangement, not a statutory exemption from liability.
6. Effectiveness of Centralised Compliance Teams
The effectiveness of a centralised compliance team can be assessed through several factors.
A. Independence
The compliance team should be sufficiently independent from the business functions whose activities it is required to monitor.
If the compliance officer is completely dependent on the business unit being monitored, there may be a risk of conflicts of interest.
B. Authority
The team should have authority to:
obtain documents;
question relevant personnel;
conduct reviews;
escalate violations;
recommend corrective measures; and
report significant risks to senior management or the board.
A compliance team without sufficient authority may become merely an administrative reporting function.
C. Access to Information
Compliance monitoring is ineffective if the central team receives incomplete or delayed information.
It should have access to:
contracts;
employee records where legally permissible;
transaction records;
regulatory filings;
licences;
inspection reports;
audit findings;
internal investigation reports; and
relevant operational data.
D. Skilled Personnel
Compliance frequently requires knowledge of:
labour law;
company law;
securities regulation;
taxation;
environmental law;
data protection;
anti-corruption legislation;
industry-specific regulations; and
contractual requirements.
The effectiveness of centralisation therefore depends substantially upon the expertise of the compliance personnel.
7. Centralised Compliance Register
A central compliance team can maintain a consolidated compliance register containing:
| Compliance Area | Requirement | Responsible Unit | Due Date | Status | Evidence |
|---|---|---|---|---|---|
| Labour | Statutory return | HR | Prescribed date | Completed | Filing record |
| Tax | Statutory filing | Finance | Prescribed date | Pending | Return |
| Corporate | Annual filing | Legal/CS | Prescribed date | Completed | Filing receipt |
| Licence | Renewal | Operations | Renewal date | Pending | Licence |
| Safety | Inspection | Plant/Factory | Scheduled date | Completed | Inspection report |
Such a register can help identify:
overdue obligations;
repeated failures;
high-risk departments;
approaching deadlines;
incomplete documentation; and
systemic compliance weaknesses.
However, maintaining a register alone does not establish legal compliance.
8. Centralised Monitoring vs Decentralised Compliance
| Factor | Centralised Compliance | Decentralised Compliance |
|---|---|---|
| Control | Strong central oversight | Greater local autonomy |
| Uniformity | Generally higher | May vary between departments |
| Expertise | Can be concentrated | May be fragmented |
| Local knowledge | May be weaker | Usually stronger |
| Cost | May reduce duplication | May duplicate resources |
| Monitoring | Easier to consolidate | More difficult to consolidate |
| Responsiveness | May be slower for local issues | Often faster locally |
| Risk of information gaps | Possible | Possible |
| Accountability | Clearly centralised | Distributed |
| Scalability | Strong for large organisations | May become difficult as organisation grows |
The most effective model may therefore be a hybrid system, where standards and monitoring are centralised but implementation remains partly decentralised.
9. Centralised Compliance and Corporate Governance
Compliance is closely connected with corporate governance.
Directors are expected to establish appropriate systems for compliance with applicable laws. Modern corporate governance therefore treats compliance not simply as a legal department function but as part of organisational risk management.
Section 134 of the Companies Act, 2013 requires the directors' responsibility statement to address, among other matters, the existence of proper systems to ensure compliance with applicable laws and that such systems are adequate and operating effectively.
The Institute of Company Secretaries of India has similarly identified the directors' responsibility for devising a proper system to ensure compliance with applicable laws and ensuring that such systems operate effectively.
Thus:
Effective compliance is a governance responsibility, not merely an administrative function.
10. Compliance Teams and Internal Controls
Centralised compliance teams are particularly useful when integrated with internal-control systems.
A strong system can operate as follows:
Law → Compliance obligation → Internal control → Responsible officer → Monitoring → Evidence → Review → Corrective action
For example, if an organisation must file a statutory return every quarter:
the central team identifies the requirement;
the responsible department is assigned;
the deadline is recorded;
evidence is uploaded;
the central team verifies completion;
exceptions are escalated; and
repeated failures are analysed.
This creates an audit trail.
11. Preventive Compliance
An effective central team should focus on prevention rather than merely punishment.
Preventive measures may include:
compliance training;
standard operating procedures;
legal updates;
checklists;
approval workflows;
automated reminders;
risk assessments;
periodic audits;
whistle-blower mechanisms; and
pre-transaction legal review.
Preventive compliance reduces the possibility that a violation will reach the stage of regulatory enforcement.
12. Risk-Based Compliance
Centralised compliance teams should not necessarily treat every obligation as equally risky.
A risk-based model may classify matters as:
High Risk
anti-corruption;
financial reporting;
safety;
environmental compliance;
securities regulation;
data protection;
major employment obligations.
Medium Risk
Routine regulatory filings and operational licences.
Low Risk
Minor administrative obligations having limited legal or financial consequences.
Resources should generally be concentrated on higher-risk areas.
13. Compliance Monitoring and Escalation
A central compliance team should establish an escalation mechanism.
For example:
Level 1: Minor delay → business unit correction
Level 2: Repeated failure → regional management
Level 3: Material violation → central compliance head
Level 4: Serious regulatory risk → senior management / board committee
Level 5: Suspected criminal or major regulatory misconduct → investigation and appropriate reporting
This prevents serious matters from being hidden within routine administrative reporting.
14. Compliance Team and Internal Audit
Compliance and internal audit are related but distinct functions.
Compliance
Primarily asks:
“Are we complying with applicable laws, regulations and policies?”
Internal Audit
Primarily asks:
“Are our controls and processes working effectively and are risks properly managed?”
Legal Department
Primarily asks:
“What does the law require and what are the legal consequences?”
A centralised structure works best when these functions cooperate while maintaining appropriate independence.
15. Compliance Failures and Corporate Liability
Centralisation cannot by itself prevent corporate liability.
The Supreme Court has repeatedly recognised that a company may be prosecuted for offences where the law permits corporate criminal liability.
At the same time, individual officers cannot automatically be treated as personally liable merely because they hold a position in the company. Personal liability generally requires the statutory basis and facts necessary to establish it.
In National Small Industries Corporation Ltd. v. Harmeet Singh Paintal, the Supreme Court held that merely being a director is not enough to establish vicarious criminal liability under Section 141 of the Negotiable Instruments Act; the statutory requirements concerning responsibility for the conduct of the business must be satisfied.
This principle is important for centralised compliance structures.
A company cannot simply say:
“The compliance department was responsible.”
Nor can an employee automatically be held liable merely because:
“He was a director/officer.”
The actual statutory duties and factual responsibility must be examined.
16. Importance of Clear Allocation of Responsibility
An effective centralised system should clearly specify:
who owns each compliance obligation;
who performs the obligation;
who reviews it;
who maintains evidence;
who approves exceptions;
who escalates failures; and
who reports material risks.
A common failure occurs when responsibility is described collectively as “Compliance Department” without identifying the person or business unit responsible for execution.
Centralisation should therefore create clarity rather than ambiguity.
17. Case Law
1. Securities and Exchange Board of India v. V. Shankar, 2023 INSC 719
This is one of the most directly relevant Supreme Court decisions concerning the role of a compliance officer.
The case concerned the Company Secretary of Deccan Chronicle Holdings Limited, who was also the compliance officer under the SEBI Buyback Regulations.
The Securities Appellate Tribunal had interpreted the role narrowly, treating the compliance officer's responsibility as essentially limited to investor grievance redressal.
The Supreme Court rejected that interpretation. It held that the regulation had two purposes:
ensuring compliance with the buyback regulations; and
redressing investor grievances.
The Court therefore held that the compliance officer's role included ensuring regulatory compliance.
Principle
A compliance function is substantive where the governing regulation expressly assigns responsibility for ensuring compliance; it cannot be reduced to a purely administrative or grievance-handling role.
This case strongly supports the proposition that centralised compliance teams must possess real compliance-monitoring responsibilities.
2. Vineet Narain v. Union of India, (1998) 1 SCC 226
The Supreme Court considered the need for institutional mechanisms to ensure effective investigation of corruption and proper supervision of investigative agencies.
The judgment resulted in important institutional reforms concerning the Central Vigilance Commission and the CBI.
Principle
Effective institutional oversight requires independence, defined responsibilities and mechanisms capable of preventing improper interference.
The principle is relevant to corporate compliance because a compliance team is effective only when it has sufficient independence and authority to identify and escalate misconduct.
3. National Small Industries Corporation Ltd. v. Harmeet Singh Paintal, (2010) 3 SCC 330
The Supreme Court considered the circumstances in which directors and officers could be held vicariously liable for corporate offences under Section 141 of the Negotiable Instruments Act.
The Court held that merely being a director is not sufficient. The complaint must satisfy the statutory requirements showing that the person was in charge of and responsible for the conduct of the company's business.
Principle
Corporate compliance responsibility and individual legal liability must be determined according to statutory duties and actual responsibility rather than job title alone.
This principle is important where organisations centralise compliance responsibilities.
4. SMS Pharmaceuticals Ltd. v. Neeta Bhalla, (2005) 8 SCC 89
The Supreme Court examined liability of directors and officers under Section 141 of the Negotiable Instruments Act.
The Court recognised that a company may have numerous directors and that every director does not necessarily participate in the day-to-day conduct of the company's business.
Principle
Individual responsibility must be established according to the person's actual statutory and operational role; designation alone does not automatically create liability.
For centralised compliance structures, responsibility should therefore be clearly allocated and documented.
5. Sunil Bharti Mittal v. Central Bureau of Investigation, (2015) 4 SCC 609
The Supreme Court considered the criminal liability of company directors and officers.
The Court emphasised that a director cannot automatically be prosecuted merely because of his position in the company. Individual criminal liability requires a legal basis and the necessary factual foundation.
Principle
Corporate status or office alone does not automatically create individual criminal liability; personal involvement and the applicable statutory provisions must be established.
This is relevant to centralised compliance because delegating a function to a compliance team does not automatically impose criminal liability upon every member of that team.
6. Standard Chartered Bank v. Directorate of Enforcement, (2006) 6 SCC 327
The Supreme Court considered whether a company could be prosecuted for offences carrying imprisonment as a punishment.
The Court held that a company can be prosecuted and subjected to punishment, including monetary punishment, even where the statutory offence also prescribes imprisonment.
Principle
A corporate entity is capable of being prosecuted for statutory offences, and corporate compliance systems are therefore important safeguards against regulatory and criminal exposure.
A centralised compliance team can help identify and prevent conduct that may expose the company to prosecution.
7. State of Maharashtra v. Syndicate Transport Co. (P) Ltd., AIR 1964 SC 195
The Supreme Court examined corporate criminal responsibility and the relationship between corporate entities and criminal offences.
The decision illustrates that corporate liability depends upon the statutory scheme and the nature of the offence.
Principle
Corporate criminal responsibility depends upon the legal character of the offence and the governing statute; organisations cannot assume that corporate structure automatically prevents legal consequences.
8. Rajeev Saumitra v. Neetu Singh, Delhi High Court
The Court considered directors' fiduciary responsibilities under the Companies Act, including the prohibition against obtaining undue advantage and the obligation to act in the company's interests.
The case illustrates that corporate governance duties extend beyond formal compliance and include substantive obligations concerning conflicts of interest and corporate interests.
Principle
Effective corporate governance requires directors and officers to comply with substantive fiduciary duties rather than merely satisfying formal filing requirements.
18. Centralised Compliance Teams and Board Responsibility
A central compliance team should regularly report material compliance risks to the board or an appropriate board committee.
Reports may include:
number of overdue obligations;
significant regulatory violations;
repeated exceptions;
unresolved audit findings;
whistle-blower complaints;
regulatory notices;
litigation exposure;
high-risk compliance areas;
corrective action status; and
emerging legal requirements.
The board should not treat the compliance department as a substitute for its own governance responsibilities.
19. Technology and Centralised Compliance
Technology can significantly improve the effectiveness of centralised compliance.
A compliance management system can provide:
automated reminders;
centralised obligation registers;
workflow approvals;
document storage;
evidence tracking;
dashboards;
escalation alerts;
audit trails;
responsibility mapping; and
management reporting.
However, technology cannot correct poor allocation of responsibility.
A sophisticated software system is ineffective if:
obligations are incorrectly identified;
deadlines are wrong;
responsible persons are not assigned;
evidence is incomplete; or
exceptions are ignored.
20. Advantages of Centralised Compliance Teams
1. Standardisation
Common compliance standards can be applied across the organisation.
2. Economies of Scale
Specialised compliance professionals can support several departments.
3. Better Monitoring
Central dashboards can identify recurring failures.
4. Stronger Expertise
Specialists can focus on complex regulatory requirements.
5. Better Documentation
A central repository can preserve compliance evidence.
6. Improved Regulatory Response
The organisation can respond more consistently to regulatory notices and inspections.
7. Early Risk Detection
Central analysis can identify patterns that individual branches may not notice.
21. Limitations of Centralised Compliance Teams
Centralisation also has risks.
1. Distance from Operations
A central team may not understand local operational realities.
2. Information Delay
Branches may fail to report violations promptly.
3. Over-centralisation
Routine matters may require unnecessary central approval.
4. Compliance Silos
Business units may assume that “compliance is the compliance department's job.”
5. False Assurance
Management may believe that the existence of a compliance team automatically means the organisation is compliant.
6. Excessive Bureaucracy
Too many approvals can slow legitimate business activity.
7. Lack of Independence
If the compliance team is controlled by the same managers whose conduct it must monitor, its effectiveness may be compromised.
22. Measuring Effectiveness
A centralised compliance team should be evaluated using measurable indicators.
Important indicators include:
percentage of obligations completed on time;
number of overdue compliance actions;
number of repeated violations;
average time taken to close compliance issues;
number of unresolved high-risk findings;
number of regulatory notices;
regulatory penalties;
completion of compliance training;
effectiveness of corrective actions;
number of whistle-blower complaints appropriately investigated; and
recurrence rate of previously identified violations.
The objective should not simply be to achieve a high “compliance percentage.”
A system can show 100% completion while still being ineffective if the underlying controls are weak.
23. Centralised Compliance and Three Lines of Responsibility
A strong organisation can divide responsibility into three broad levels:
First Line — Business
Business units perform the actual operations and comply with applicable requirements.
Second Line — Compliance and Risk
The central compliance function establishes standards, advises, monitors and challenges business decisions.
Third Line — Internal Audit
Internal audit independently evaluates whether governance, risk management and internal controls are functioning effectively.
This separation improves accountability and reduces the risk that the compliance function becomes both operator and reviewer.
24. Centralised Compliance Does Not Mean Centralised Decision-Making
The most effective model is often:
Central standards + local implementation + central monitoring + independent audit
For example:
central team identifies labour-law obligations;
HR implements them;
branch managers maintain local records;
central compliance reviews completion;
internal audit independently tests the system.
This provides both consistency and operational flexibility.
25. Practical Compliance Framework
An effective centralised compliance team should follow the following cycle:
1. Identify
Identify all applicable legal obligations.
2. Map
Map each obligation to the responsible department and officer.
3. Assess
Classify obligations according to legal and operational risk.
4. Implement
Create policies, controls and procedures.
5. Monitor
Review compliance periodically.
6. Record
Maintain documentary evidence.
7. Escalate
Escalate significant or repeated violations.
8. Correct
Implement corrective and preventive action.
9. Verify
Check whether corrective action actually worked.
10. Report
Provide material compliance information to senior management and the board.
26. Centralised Compliance Team vs Compliance Responsibility
It is important to distinguish:
Compliance function
from
Compliance responsibility.
The central team may coordinate compliance, but individual departments may remain legally responsible for particular obligations.
For example:
HR may remain responsible for employment-law compliance;
finance may remain responsible for tax and accounting requirements;
operations may remain responsible for safety;
procurement may remain responsible for procurement controls; and
the company secretary may remain responsible for specific corporate-law functions.
The central team should therefore operate as a coordinator, monitor, adviser and challenger, rather than becoming a convenient mechanism for transferring all responsibility away from operational management.
27. Conclusion
Centralised compliance teams can significantly improve organisational compliance by creating uniform standards, central monitoring, specialised expertise, consistent documentation and effective escalation mechanisms.
However, centralisation alone does not guarantee effectiveness. A compliance team must have adequate independence, authority, resources, information access and clearly defined responsibilities. Business units must continue to implement the requirements relevant to their operations, while senior management and the board must maintain their governance responsibilities.
The Supreme Court's decision in SEBI v. V. Shankar is particularly significant because it demonstrates that where law assigns compliance responsibility to a compliance officer, that responsibility may extend to actively ensuring regulatory compliance rather than merely performing administrative functions.
At the same time, cases such as National Small Industries Corporation Ltd. v. Harmeet Singh Paintal, SMS Pharmaceuticals Ltd. v. Neeta Bhalla, and Sunil Bharti Mittal v. CBI demonstrate that individual liability must be determined according to statutory requirements and actual responsibility rather than merely by organisational designation.
The central principle is:
A centralised compliance team is effective when it combines organisation-wide standards and monitoring with sufficient independence, operational participation, clear allocation of responsibility, reliable documentation and timely escalation; centralisation should strengthen compliance rather than become a mechanism for shifting legal responsibility away from the persons and departments on whom the law actually places it.

comments