Glossary

Compliance Management System

The integrated framework of policies, procedures, training, and monitoring through which an organisation manages compliance risk. ISO 37301:2021 sets the canonical structure: identify obligations, assess risks, design controls (including a whistleblowing channel), train staff, monitor, review, improve. The CMS is typically owned by the compliance officer and reports to the board's audit committee.

Full definition

A compliance management system (CMS) is the operationalized framework that turns laws and regulations into day-to-day behaviour. ISO 37301:2021 sets out the canonical structure: identify obligations, assess risks, design controls (including a whistleblowing channel), train staff, monitor, review, improve. The CMS is typically owned by the compliance officer and reports to the board's audit committee. Whistleblowing is one of the few CMS controls that detects what other controls miss. It is the 'sensor of last resort'.

Related terms

Read more

Confidly puts compliance theory into practice in 15 minutes

14-day free trial. EU-hosted. No credit card. Cancel anytime.

Multi-entity? Talk to us →