Most growing companies build compliance reactively — responding to a customer requirement, a regulatory deadline, or an incident. The result is a patchwork of documents and policies that satisfy individual requests but don't function as a coherent programme. A structured compliance programme, built intentionally, is more efficient, more effective, and more credible with enterprise customers and regulators.
What a Compliance Programme Is
A compliance programme is the organised set of policies, processes, controls, documentation, and governance arrangements through which a company meets its regulatory obligations and manages compliance risk.
A mature compliance programme includes:
- Regulatory scope mapping (which regulations apply)
- Governance structure (who is accountable for compliance)
- Policy framework (documented policies covering each regulatory obligation)
- Operational controls (procedures and processes implementing the policies)
- Monitoring and testing (verifying controls are working)
- Incident response (what happens when things go wrong)
- Documentation and records (evidence of compliance)
- Training (ensuring staff understand their obligations)
Step 1: Regulatory Scope Mapping
Before you can build a compliance programme, you need to know which regulations apply. The mapping should cover:
Applicable regulations: GDPR, UK GDPR, NIS2, DORA, AI Act, Data Act, CSRD, Swiss FADP, and any sector-specific regulations (financial services, healthcare, etc.)
Basis for applicability: Why each regulation applies — the specific criterion (e.g., processing EU personal data; in-scope sector under NIS2; financial entity under DORA)
Obligations summary: The key obligations under each applicable regulation — not the full regulatory text, but a structured list of what the company must do
Gap assessment: For each obligation, whether the company currently meets it, partially meets it, or has no relevant control in place
This mapping becomes the foundation of your compliance programme and should be maintained and updated as regulations change.
Step 2: Governance Structure
Who owns compliance?
For a 50-person company: the CEO or CFO typically has compliance accountability, with a designated operational lead (Head of Legal, Head of Ops, or fractional DPO/compliance officer).
For a 100–250-person company: a dedicated compliance or legal function, or a senior manager with the compliance portfolio.
Governance arrangements:
- Compliance owner with board-level reporting line
- Quarterly compliance review with senior management
- Compliance items in board agenda at least annually
- Clear escalation path for compliance incidents
GDPR-specific governance: DPO required for certain organisations (public authorities, those carrying out large-scale systematic monitoring, or those processing special category data at scale). Others should designate a point of contact for data protection matters even if a formal DPO is not required.
Step 3: Policy Framework
A minimum policy framework for a SaaS company with GDPR, AI Act, and NIS2 obligations:
Core policies:
- Information Security Policy — covering access control, encryption, incident response, vulnerability management, BCP
- Data Protection Policy — GDPR principles, lawful bases, retention, data subject rights
- Acceptable Use Policy — what employees can and cannot do with company and customer data
- Privacy Notice — public-facing, GDPR Article 13/14 compliant
- Cookie Policy — GDPR/PECR compliant
Operational procedures:
- Data Subject Rights Request Procedure — how to handle GDPR requests within 30 days
- Data Breach Response Procedure — how to identify, assess, contain, and report incidents
- Third-Party Vendor Assessment Procedure — how to assess and onboard vendors with data access
- AI System Governance Procedure — how AI systems are reviewed, approved, and monitored
Specific compliance documentation:
- Records of Processing Activities (ROPA) — Article 30 register
- Data Processing Agreements — standard DPA for customer use, signed DPAs for vendors
- Sub-processor List — maintained and published
- AI System Register — inventory of AI systems with risk classification
- NIS2 Incident Report Template — for reporting to competent authority
Step 4: Controls Implementation
Policies without controls are decoration. For each policy, identify the operational controls that implement it:
Information security controls:
- MFA on all production systems and email
- Role-based access control with least privilege
- Annual penetration testing
- Vulnerability scanning (weekly minimum)
- Encrypted laptops and mobile devices
Data protection controls:
- Cookie consent management platform
- Data minimisation review in product development
- DSAR workflow (ticket system with 30-day tracking)
- Vendor DPA process (no vendor onboarded without DPA)
AI governance controls:
- AI system review checklist before deployment
- Human oversight documentation for high-risk AI
- Transparency disclosure mechanism for chatbots
Step 5: Monitoring and Testing
Compliance controls need to be tested to verify they work:
Annual activities:
- Internal compliance review — check that controls are functioning
- Annual penetration test
- DPA review — are all vendor DPAs current?
- ROPA review — is the register still accurate?
- Policy review — are policies current with regulatory changes?
Ongoing monitoring:
- Security incident detection (SIEM or equivalent)
- Vulnerability scanning outputs reviewed weekly
- Data access logs reviewed periodically
Step 6: Training
Annual mandatory training for all staff:
- Data protection basics (GDPR principles, handling personal data, recognising phishing)
- Information security awareness (strong passwords, MFA, phishing, incident reporting)
- Acceptable use of IT systems
Role-specific training:
- Developers: secure coding practices, privacy by design
- Sales/marketing: consent requirements, marketing compliance
- Management: governance responsibilities, reporting obligations
Step 7: Documentation and Evidence
Regulators and enterprise customers want to see evidence — not just policies. Build a compliance documentation library:
- Signed DPAs with all vendors
- Training completion records
- Penetration test reports and remediation evidence
- DSAR responses and timelines
- Incident reports and lessons learned
- Audit reports and findings