Centralised compliance teams effectiveness.

Centralised Compliance Teams Effectiveness

1. Introduction

A centralised compliance team is a dedicated function within an organisation that coordinates legal, regulatory, policy and procedural compliance across different departments, branches, subsidiaries or business units.

Instead of allowing every department to manage compliance independently, a central compliance function establishes common standards, maintains compliance calendars, monitors regulatory obligations, conducts reviews, provides legal and regulatory guidance, and reports significant compliance risks to senior management or the board.

Centralisation can improve consistency, monitoring and accountability. However, it does not automatically eliminate legal risk. A central compliance team can be effective only when it has adequate authority, access to information, independence, qualified personnel and cooperation from operational departments.

Indian judicial decisions concerning compliance officers, corporate governance, statutory duties and corporate liability demonstrate that compliance is a substantive responsibility and cannot always be reduced to merely maintaining records or signing documents. In Securities and Exchange Board of India v. V. Shankar, the Supreme Court specifically held that a compliance officer's role under the applicable SEBI regulations included ensuring regulatory compliance, not merely handling investor grievances.

2. Meaning of a Centralised Compliance Team

A centralised compliance team is an organisational unit responsible for coordinating compliance requirements across the organisation.

Its responsibilities may include:

identifying applicable laws and regulations;

maintaining a central compliance register;

preparing compliance calendars;

monitoring statutory deadlines;

issuing compliance policies;

conducting internal compliance reviews;

coordinating regulatory inspections;

monitoring branch-level compliance;

investigating reported compliance failures;

advising management;

maintaining evidence of compliance;

reporting material violations; and

coordinating with external regulators and legal advisers.

The central team may operate from the organisation's head office while individual business units remain responsible for implementing the requirements.

3. Objectives of Centralised Compliance

The principal objectives include:

3.1 Uniformity

A central team can establish one organisation-wide compliance standard instead of allowing different branches to interpret the same legal requirement differently.

3.2 Risk Identification

Central monitoring allows management to identify repeated or systemic violations.

3.3 Regulatory Consistency

Policies, reporting procedures and documentation can be standardised.

3.4 Accountability

A central compliance function provides a defined mechanism for reporting compliance failures.

3.5 Prevention

The purpose of compliance is not merely to discover violations after they occur. A properly designed compliance system should prevent or reduce the likelihood of violations.

3.6 Management Information

A central team can consolidate compliance information from different departments and provide management with a broader picture of regulatory risk.

4. Structure of a Centralised Compliance Function

A typical centralised structure may contain:

Board / Board Committee

Chief Compliance Officer / Head of Compliance

Central Compliance Team

Regional / Departmental Compliance Coordinators

Business Units / Branches

This structure does not necessarily mean that all compliance responsibilities are transferred to the central team.

Operational departments normally remain responsible for implementing the law in their day-to-day activities.

5. Centralisation Does Not Transfer All Legal Responsibility

One of the most important principles is that the creation of a central compliance department does not automatically transfer every statutory responsibility away from directors, officers or business managers.

For example, where a statute specifically imposes duties upon:

directors;

company secretaries;

compliance officers;

employers;

occupiers;

principal employers; or

other designated officers,

those statutory responsibilities continue to operate according to the legislation.

The Supreme Court's decision in SEBI v. V. Shankar illustrates this point. The Court rejected the interpretation that a compliance officer's function was merely administrative and held that the applicable regulation expressly required the compliance officer to ensure compliance with the buyback regulations.

Therefore:

Centralisation is an organisational arrangement, not a statutory exemption from liability.

6. Effectiveness of Centralised Compliance Teams

The effectiveness of a centralised compliance team can be assessed through several factors.

A. Independence

The compliance team should be sufficiently independent from the business functions whose activities it is required to monitor.

If the compliance officer is completely dependent on the business unit being monitored, there may be a risk of conflicts of interest.

B. Authority

The team should have authority to:

obtain documents;

question relevant personnel;

conduct reviews;

escalate violations;

recommend corrective measures; and

report significant risks to senior management or the board.

A compliance team without sufficient authority may become merely an administrative reporting function.

C. Access to Information

Compliance monitoring is ineffective if the central team receives incomplete or delayed information.

It should have access to:

contracts;

employee records where legally permissible;

transaction records;

regulatory filings;

licences;

inspection reports;

audit findings;

internal investigation reports; and

relevant operational data.

D. Skilled Personnel

Compliance frequently requires knowledge of:

labour law;

company law;

securities regulation;

taxation;

environmental law;

data protection;

anti-corruption legislation;

industry-specific regulations; and

contractual requirements.

The effectiveness of centralisation therefore depends substantially upon the expertise of the compliance personnel.

7. Centralised Compliance Register

A central compliance team can maintain a consolidated compliance register containing:

Compliance AreaRequirementResponsible UnitDue DateStatusEvidence
LabourStatutory returnHRPrescribed dateCompletedFiling record
TaxStatutory filingFinancePrescribed datePendingReturn
CorporateAnnual filingLegal/CSPrescribed dateCompletedFiling receipt
LicenceRenewalOperationsRenewal datePendingLicence
SafetyInspectionPlant/FactoryScheduled dateCompletedInspection report

Such a register can help identify:

overdue obligations;

repeated failures;

high-risk departments;

approaching deadlines;

incomplete documentation; and

systemic compliance weaknesses.

However, maintaining a register alone does not establish legal compliance.

8. Centralised Monitoring vs Decentralised Compliance

FactorCentralised ComplianceDecentralised Compliance
ControlStrong central oversightGreater local autonomy
UniformityGenerally higherMay vary between departments
ExpertiseCan be concentratedMay be fragmented
Local knowledgeMay be weakerUsually stronger
CostMay reduce duplicationMay duplicate resources
MonitoringEasier to consolidateMore difficult to consolidate
ResponsivenessMay be slower for local issuesOften faster locally
Risk of information gapsPossiblePossible
AccountabilityClearly centralisedDistributed
ScalabilityStrong for large organisationsMay become difficult as organisation grows

The most effective model may therefore be a hybrid system, where standards and monitoring are centralised but implementation remains partly decentralised.

9. Centralised Compliance and Corporate Governance

Compliance is closely connected with corporate governance.

Directors are expected to establish appropriate systems for compliance with applicable laws. Modern corporate governance therefore treats compliance not simply as a legal department function but as part of organisational risk management.

Section 134 of the Companies Act, 2013 requires the directors' responsibility statement to address, among other matters, the existence of proper systems to ensure compliance with applicable laws and that such systems are adequate and operating effectively.

The Institute of Company Secretaries of India has similarly identified the directors' responsibility for devising a proper system to ensure compliance with applicable laws and ensuring that such systems operate effectively.

Thus:

Effective compliance is a governance responsibility, not merely an administrative function.

10. Compliance Teams and Internal Controls

Centralised compliance teams are particularly useful when integrated with internal-control systems.

A strong system can operate as follows:

Law → Compliance obligation → Internal control → Responsible officer → Monitoring → Evidence → Review → Corrective action

For example, if an organisation must file a statutory return every quarter:

the central team identifies the requirement;

the responsible department is assigned;

the deadline is recorded;

evidence is uploaded;

the central team verifies completion;

exceptions are escalated; and

repeated failures are analysed.

This creates an audit trail.

11. Preventive Compliance

An effective central team should focus on prevention rather than merely punishment.

Preventive measures may include:

compliance training;

standard operating procedures;

legal updates;

checklists;

approval workflows;

automated reminders;

risk assessments;

periodic audits;

whistle-blower mechanisms; and

pre-transaction legal review.

Preventive compliance reduces the possibility that a violation will reach the stage of regulatory enforcement.

12. Risk-Based Compliance

Centralised compliance teams should not necessarily treat every obligation as equally risky.

A risk-based model may classify matters as:

High Risk

anti-corruption;

financial reporting;

safety;

environmental compliance;

securities regulation;

data protection;

major employment obligations.

Medium Risk

Routine regulatory filings and operational licences.

Low Risk

Minor administrative obligations having limited legal or financial consequences.

Resources should generally be concentrated on higher-risk areas.

13. Compliance Monitoring and Escalation

A central compliance team should establish an escalation mechanism.

For example:

Level 1: Minor delay → business unit correction

Level 2: Repeated failure → regional management

Level 3: Material violation → central compliance head

Level 4: Serious regulatory risk → senior management / board committee

Level 5: Suspected criminal or major regulatory misconduct → investigation and appropriate reporting

This prevents serious matters from being hidden within routine administrative reporting.

14. Compliance Team and Internal Audit

Compliance and internal audit are related but distinct functions.

Compliance

Primarily asks:

“Are we complying with applicable laws, regulations and policies?”

Internal Audit

Primarily asks:

“Are our controls and processes working effectively and are risks properly managed?”

Legal Department

Primarily asks:

“What does the law require and what are the legal consequences?”

A centralised structure works best when these functions cooperate while maintaining appropriate independence.

15. Compliance Failures and Corporate Liability

Centralisation cannot by itself prevent corporate liability.

The Supreme Court has repeatedly recognised that a company may be prosecuted for offences where the law permits corporate criminal liability.

At the same time, individual officers cannot automatically be treated as personally liable merely because they hold a position in the company. Personal liability generally requires the statutory basis and facts necessary to establish it.

In National Small Industries Corporation Ltd. v. Harmeet Singh Paintal, the Supreme Court held that merely being a director is not enough to establish vicarious criminal liability under Section 141 of the Negotiable Instruments Act; the statutory requirements concerning responsibility for the conduct of the business must be satisfied.

This principle is important for centralised compliance structures.

A company cannot simply say:

“The compliance department was responsible.”

Nor can an employee automatically be held liable merely because:

“He was a director/officer.”

The actual statutory duties and factual responsibility must be examined.

16. Importance of Clear Allocation of Responsibility

An effective centralised system should clearly specify:

who owns each compliance obligation;

who performs the obligation;

who reviews it;

who maintains evidence;

who approves exceptions;

who escalates failures; and

who reports material risks.

A common failure occurs when responsibility is described collectively as “Compliance Department” without identifying the person or business unit responsible for execution.

Centralisation should therefore create clarity rather than ambiguity.

17. Case Law

1. Securities and Exchange Board of India v. V. Shankar, 2023 INSC 719

This is one of the most directly relevant Supreme Court decisions concerning the role of a compliance officer.

The case concerned the Company Secretary of Deccan Chronicle Holdings Limited, who was also the compliance officer under the SEBI Buyback Regulations.

The Securities Appellate Tribunal had interpreted the role narrowly, treating the compliance officer's responsibility as essentially limited to investor grievance redressal.

The Supreme Court rejected that interpretation. It held that the regulation had two purposes:

ensuring compliance with the buyback regulations; and

redressing investor grievances.

The Court therefore held that the compliance officer's role included ensuring regulatory compliance.

Principle

A compliance function is substantive where the governing regulation expressly assigns responsibility for ensuring compliance; it cannot be reduced to a purely administrative or grievance-handling role.

This case strongly supports the proposition that centralised compliance teams must possess real compliance-monitoring responsibilities.

2. Vineet Narain v. Union of India, (1998) 1 SCC 226

The Supreme Court considered the need for institutional mechanisms to ensure effective investigation of corruption and proper supervision of investigative agencies.

The judgment resulted in important institutional reforms concerning the Central Vigilance Commission and the CBI.

Principle

Effective institutional oversight requires independence, defined responsibilities and mechanisms capable of preventing improper interference.

The principle is relevant to corporate compliance because a compliance team is effective only when it has sufficient independence and authority to identify and escalate misconduct.

3. National Small Industries Corporation Ltd. v. Harmeet Singh Paintal, (2010) 3 SCC 330

The Supreme Court considered the circumstances in which directors and officers could be held vicariously liable for corporate offences under Section 141 of the Negotiable Instruments Act.

The Court held that merely being a director is not sufficient. The complaint must satisfy the statutory requirements showing that the person was in charge of and responsible for the conduct of the company's business.

Principle

Corporate compliance responsibility and individual legal liability must be determined according to statutory duties and actual responsibility rather than job title alone.

This principle is important where organisations centralise compliance responsibilities.

4. SMS Pharmaceuticals Ltd. v. Neeta Bhalla, (2005) 8 SCC 89

The Supreme Court examined liability of directors and officers under Section 141 of the Negotiable Instruments Act.

The Court recognised that a company may have numerous directors and that every director does not necessarily participate in the day-to-day conduct of the company's business.

Principle

Individual responsibility must be established according to the person's actual statutory and operational role; designation alone does not automatically create liability.

For centralised compliance structures, responsibility should therefore be clearly allocated and documented.

5. Sunil Bharti Mittal v. Central Bureau of Investigation, (2015) 4 SCC 609

The Supreme Court considered the criminal liability of company directors and officers.

The Court emphasised that a director cannot automatically be prosecuted merely because of his position in the company. Individual criminal liability requires a legal basis and the necessary factual foundation.

Principle

Corporate status or office alone does not automatically create individual criminal liability; personal involvement and the applicable statutory provisions must be established.

This is relevant to centralised compliance because delegating a function to a compliance team does not automatically impose criminal liability upon every member of that team.

6. Standard Chartered Bank v. Directorate of Enforcement, (2006) 6 SCC 327

The Supreme Court considered whether a company could be prosecuted for offences carrying imprisonment as a punishment.

The Court held that a company can be prosecuted and subjected to punishment, including monetary punishment, even where the statutory offence also prescribes imprisonment.

Principle

A corporate entity is capable of being prosecuted for statutory offences, and corporate compliance systems are therefore important safeguards against regulatory and criminal exposure.

A centralised compliance team can help identify and prevent conduct that may expose the company to prosecution.

7. State of Maharashtra v. Syndicate Transport Co. (P) Ltd., AIR 1964 SC 195

The Supreme Court examined corporate criminal responsibility and the relationship between corporate entities and criminal offences.

The decision illustrates that corporate liability depends upon the statutory scheme and the nature of the offence.

Principle

Corporate criminal responsibility depends upon the legal character of the offence and the governing statute; organisations cannot assume that corporate structure automatically prevents legal consequences.

8. Rajeev Saumitra v. Neetu Singh, Delhi High Court

The Court considered directors' fiduciary responsibilities under the Companies Act, including the prohibition against obtaining undue advantage and the obligation to act in the company's interests.

The case illustrates that corporate governance duties extend beyond formal compliance and include substantive obligations concerning conflicts of interest and corporate interests.

Principle

Effective corporate governance requires directors and officers to comply with substantive fiduciary duties rather than merely satisfying formal filing requirements.

18. Centralised Compliance Teams and Board Responsibility

A central compliance team should regularly report material compliance risks to the board or an appropriate board committee.

Reports may include:

number of overdue obligations;

significant regulatory violations;

repeated exceptions;

unresolved audit findings;

whistle-blower complaints;

regulatory notices;

litigation exposure;

high-risk compliance areas;

corrective action status; and

emerging legal requirements.

The board should not treat the compliance department as a substitute for its own governance responsibilities.

19. Technology and Centralised Compliance

Technology can significantly improve the effectiveness of centralised compliance.

A compliance management system can provide:

automated reminders;

centralised obligation registers;

workflow approvals;

document storage;

evidence tracking;

dashboards;

escalation alerts;

audit trails;

responsibility mapping; and

management reporting.

However, technology cannot correct poor allocation of responsibility.

A sophisticated software system is ineffective if:

obligations are incorrectly identified;

deadlines are wrong;

responsible persons are not assigned;

evidence is incomplete; or

exceptions are ignored.

20. Advantages of Centralised Compliance Teams

1. Standardisation

Common compliance standards can be applied across the organisation.

2. Economies of Scale

Specialised compliance professionals can support several departments.

3. Better Monitoring

Central dashboards can identify recurring failures.

4. Stronger Expertise

Specialists can focus on complex regulatory requirements.

5. Better Documentation

A central repository can preserve compliance evidence.

6. Improved Regulatory Response

The organisation can respond more consistently to regulatory notices and inspections.

7. Early Risk Detection

Central analysis can identify patterns that individual branches may not notice.

21. Limitations of Centralised Compliance Teams

Centralisation also has risks.

1. Distance from Operations

A central team may not understand local operational realities.

2. Information Delay

Branches may fail to report violations promptly.

3. Over-centralisation

Routine matters may require unnecessary central approval.

4. Compliance Silos

Business units may assume that “compliance is the compliance department's job.”

5. False Assurance

Management may believe that the existence of a compliance team automatically means the organisation is compliant.

6. Excessive Bureaucracy

Too many approvals can slow legitimate business activity.

7. Lack of Independence

If the compliance team is controlled by the same managers whose conduct it must monitor, its effectiveness may be compromised.

22. Measuring Effectiveness

A centralised compliance team should be evaluated using measurable indicators.

Important indicators include:

percentage of obligations completed on time;

number of overdue compliance actions;

number of repeated violations;

average time taken to close compliance issues;

number of unresolved high-risk findings;

number of regulatory notices;

regulatory penalties;

completion of compliance training;

effectiveness of corrective actions;

number of whistle-blower complaints appropriately investigated; and

recurrence rate of previously identified violations.

The objective should not simply be to achieve a high “compliance percentage.”

A system can show 100% completion while still being ineffective if the underlying controls are weak.

23. Centralised Compliance and Three Lines of Responsibility

A strong organisation can divide responsibility into three broad levels:

First Line — Business

Business units perform the actual operations and comply with applicable requirements.

Second Line — Compliance and Risk

The central compliance function establishes standards, advises, monitors and challenges business decisions.

Third Line — Internal Audit

Internal audit independently evaluates whether governance, risk management and internal controls are functioning effectively.

This separation improves accountability and reduces the risk that the compliance function becomes both operator and reviewer.

24. Centralised Compliance Does Not Mean Centralised Decision-Making

The most effective model is often:

Central standards + local implementation + central monitoring + independent audit

For example:

central team identifies labour-law obligations;

HR implements them;

branch managers maintain local records;

central compliance reviews completion;

internal audit independently tests the system.

This provides both consistency and operational flexibility.

25. Practical Compliance Framework

An effective centralised compliance team should follow the following cycle:

1. Identify

Identify all applicable legal obligations.

2. Map

Map each obligation to the responsible department and officer.

3. Assess

Classify obligations according to legal and operational risk.

4. Implement

Create policies, controls and procedures.

5. Monitor

Review compliance periodically.

6. Record

Maintain documentary evidence.

7. Escalate

Escalate significant or repeated violations.

8. Correct

Implement corrective and preventive action.

9. Verify

Check whether corrective action actually worked.

10. Report

Provide material compliance information to senior management and the board.

26. Centralised Compliance Team vs Compliance Responsibility

It is important to distinguish:

Compliance function

from

Compliance responsibility.

The central team may coordinate compliance, but individual departments may remain legally responsible for particular obligations.

For example:

HR may remain responsible for employment-law compliance;

finance may remain responsible for tax and accounting requirements;

operations may remain responsible for safety;

procurement may remain responsible for procurement controls; and

the company secretary may remain responsible for specific corporate-law functions.

The central team should therefore operate as a coordinator, monitor, adviser and challenger, rather than becoming a convenient mechanism for transferring all responsibility away from operational management.

27. Conclusion

Centralised compliance teams can significantly improve organisational compliance by creating uniform standards, central monitoring, specialised expertise, consistent documentation and effective escalation mechanisms.

However, centralisation alone does not guarantee effectiveness. A compliance team must have adequate independence, authority, resources, information access and clearly defined responsibilities. Business units must continue to implement the requirements relevant to their operations, while senior management and the board must maintain their governance responsibilities.

The Supreme Court's decision in SEBI v. V. Shankar is particularly significant because it demonstrates that where law assigns compliance responsibility to a compliance officer, that responsibility may extend to actively ensuring regulatory compliance rather than merely performing administrative functions.

At the same time, cases such as National Small Industries Corporation Ltd. v. Harmeet Singh Paintal, SMS Pharmaceuticals Ltd. v. Neeta Bhalla, and Sunil Bharti Mittal v. CBI demonstrate that individual liability must be determined according to statutory requirements and actual responsibility rather than merely by organisational designation.

The central principle is:

A centralised compliance team is effective when it combines organisation-wide standards and monitoring with sufficient independence, operational participation, clear allocation of responsibility, reliable documentation and timely escalation; centralisation should strengthen compliance rather than become a mechanism for shifting legal responsibility away from the persons and departments on whom the law actually places it.

LEAVE A COMMENT