Regulatory Compliance for COOs: Building Controls People Actually Follow

Compliance is not a document. It is a set of behaviours that either happen every day inside your operation or they do not, and the COO owns the difference. When it works, an audit is a quiet afternoon of pulling records that already exist. When it fails, a regulator asks a question and three departments spend a week reconstructing what should have been captured in real time.
Your legal and compliance colleagues interpret the rules. You own whether those rules are wired into how work actually gets done — the workflow steps, the approvals, the records, the checks that make the right thing the easy thing. That is an operations problem, and it lands on your desk.
This guide covers the parts a COO can genuinely move: mapping obligations, designing controls people follow, building an evidence trail, monitoring with early-warning metrics, and responding when something breaks. It stays general on purpose — every industry and jurisdiction has its own rulebook, and you should never guess at a specific requirement, penalty, or deadline.
What a COO actually owns
The common failure is treating compliance as a function that produces policies and hoping people read them. Policies do not change behaviour; controls do. A control is a specific, repeatable thing that happens in the flow of work — a required sign-off before funds move, a two-person check on a shipment, a system that will not let a record close without a mandatory field.
Weak looks like a shared drive of policy PDFs, an annual video, and a compliance officer who learns about breaches after the fact. Strong looks like controls embedded so tightly that doing the job correctly and staying compliant are the same action. A useful test: ask what physically stops each rule from being broken right now, without anyone remembering to be careful. If the honest answer is "good intentions", you have a policy, not a control. This is one slice of your broader operational risk work — compliance risk is a category you already manage.
Map your obligations before you build anything
You cannot control what you have not listed. Start with an obligation register: a plain inventory of every regulatory area that touches your operation, what it requires in practical terms, which team owns it, and how you satisfy it today. Build it with legal and the function owners in the room — they know the real workflow, you know where it bends under pressure.
Do this properly and the gaps jump out: requirements no one owns, requirements two teams each assume the other handles, and requirements you satisfy by accident and would lose the day one person leaves. A structured risk assessment framework turns the list into a ranked one, so you spend attention where impact and likelihood are highest rather than treating every rule as equally urgent. Keep it living — assign an owner and a quarterly review so the map stays honest as regulations change and you enter new markets.
Turn rules into controls people follow
Design controls into the workflow rather than bolting them on. Preventive controls stop a problem before it happens — a system that blocks an unapproved payment. Detective controls catch it fast afterwards — a reconciliation that flags a mismatch the next morning. You want mostly preventive, with detective controls as a safety net.
Weak design adds a manual step and calls it done: "everyone must remember to check the box." That holds until it is busy, and busy is when breaches happen. Strong design makes the compliant path the path of least resistance. Consider a firm that kept breaching an approval limit because staff handled urgent requests by email and did the paperwork later. The fix was not more training; it was a form that would not submit above the limit without a second approver attached. The control moved from memory into the workflow, and the breaches stopped.
Know who owns what: the three lines of defence
The three-lines model stops compliance from becoming one team's impossible job. It separates who runs the controls, who oversees them, and who independently checks that the whole thing works. Most compliance failures trace back to blurred accountability, so getting these roles clear is high-value COO work.
| Line | Who it is | What they own | What weak looks like |
|---|---|---|---|
| First line | Operating teams and their managers | Running the controls inside daily work and owning the risk | "Compliance will catch it" — teams treat rules as someone else's problem |
| Second line | Compliance, risk, and quality functions | Setting policy, monitoring, and challenging the first line | A policy factory with no visibility into whether anyone follows the policies |
| Third line | Internal audit, structurally independent | Independent assurance that the first two lines actually work | No independent check, so problems surface only when a regulator finds them |
Build the evidence trail as work happens
To a regulator, if it was not documented, it did not happen. The teams that dread audits assemble evidence afterwards; the teams that treat audits as routine capture it automatically, as a byproduct of doing the work.
Weak practice is a scramble — exporting logs, chasing approvals over email, reconstructing a timeline under pressure and hoping the story holds. Strong practice means the approval, the timestamp, the reviewer, and the record all live in the system that did the work, retrievable in minutes. Favour tools that log actions immutably, require approvals inside systems rather than inboxes, and set retention rules that match your obligations. In regulated financial reporting this is non-negotiable — the specifics sit in your financial compliance work, but the principle is universal: capture the trail while the work is warm, not cold.
Make training change behaviour, not tick a box
A 100% completion rate tells you people clicked through slides, not that anyone behaves differently under pressure. Weak training is a generic annual video watched at 2x speed. Strong training is short, role-specific, and built around the actual decisions each team faces — the warehouse crew does not need finance's session.
Give each group the two or three scenarios they will genuinely hit, show what good looks like, and test recognition rather than recall. Instead of asking "what does the policy say about customer data?", show a realistic request that should be refused and ask what to do next. You are training a reflex, not a memory of the rulebook, so reinforce it when the rules or the workflow change, not just on a calendar date.
Monitor with metrics that warn you early
Good monitoring predicts problems; poor monitoring counts them after they cost you. Leading indicators move before an incident; lagging indicators confirm the damage. You need both, but you should manage by the leading ones.
| Metric type | Example | What it tells you |
|---|---|---|
| Leading | Rising share of transactions needing a manual override | A control is being bypassed — a breach is coming |
| Leading | Growing backlog of unresolved audit findings | Corrective action is stalling before it fails |
| Lagging | Number of incidents reported last quarter | What already went wrong |
| Lagging | Time taken to close a regulatory finding | How slow your response actually is |
When something breaks: incidents, findings, and regulators
Every program has incidents; maturity shows in the response. Define the path: detect, contain, find the root cause, fix the cause not the symptom, and document the whole thing. A breach that recurs because you patched the symptom is worse than the first one, because it looks like negligence rather than an accident.
When a regulator or auditor raises a finding, respond promptly and factually with a corrective plan that has an owner and a date — do not argue it away or let it sit. Keep clean records of every interaction. Serious events overlap with crisis communication, so decide in advance who speaks, who decides, and who tells the board. Report to the board plainly and regularly, not only when something goes wrong — the credibility you build in calm updates carries you on the day you deliver bad news, which is part of your board communication skills.
Budget and resource it honestly
Compliance is not free, and pretending it is guarantees the cheap version that fails when tested. Budget for four real costs: the systems that carry controls and evidence, the training that changes behaviour, external specialists for periodic independent review, and the people who run the second and third lines. A COO's time is expensive — US Bureau of Labor Statistics data put median pay for chief executives at $206,420 in May 2024, and senior operating leaders sit in that band — so a program that pulls executives into recurring firefighting is quietly the costliest option of all. Preventive controls upfront almost always cost less than the fire drills and remediation of getting caught short.
Key takeaways
- Compliance is behaviour, not documents — your job is to convert policies into controls wired into daily work.
- Map obligations first; you cannot control a requirement you have not listed and assigned an owner.
- Design preventive controls into the workflow so the compliant path is the easy path — do not rely on people remembering to be careful.
- Use the three-lines model to keep accountability clear: operations run the controls, compliance oversees, audit independently assures.
- Capture evidence as work happens, so an audit reads existing records instead of triggering a reconstruction.
- Train for behaviour with role-specific scenarios and monitor leading indicators, so you act before a breach rather than after.