Compliance in business is the practice of meeting every obligation that governs how a company operates: laws, regulations, industry standards, contractual duties, and the firm’s own internal policies. A working compliance program identifies which rules apply, assigns owners, trains staff, monitors adherence, and produces evidence that would satisfy a regulator or auditor.
On October 10, 2024, TD Bank pleaded guilty to Bank Secrecy Act and money laundering conspiracy charges and agreed to pay $3.09 billion across four US agencies. The OCC added something costlier than cash: a $434 billion asset cap that froze the growth of TD’s entire US retail franchise.
Prosecutors found the bank had prioritized growth and cost control over its compliance obligations for years, while employees joked internally about how easy it was to move dirty money. The American Bankers Association called the resolution historic, and every compliance officer in America took notes.
|
Compliance in Business: Key Takeaways |
|
Compliance in business means meeting every legal, regulatory, and internal obligation that applies to your operations, and being able to prove it with records an examiner accepts. |
|
TD Bank pleaded guilty in October 2024 and paid $3.09 billion across the DOJ, FinCEN, OCC, and Federal Reserve, plus a $434 billion asset cap on its US retail bank. |
|
The SEC filed 456 enforcement actions in fiscal 2025 and ordered $17.9 billion in monetary relief, while whistleblower tips hit a record 53,753, up 19 percent. |
|
Regulatory compliance answers to outside authorities; corporate compliance adds the internal policies, ethics, and governance a company imposes on itself. |
|
Build the program on the DOJ’s Evaluation of Corporate Compliance Programs and ISO 37301: risk assessment, policies, training, monitoring, reporting channels, and enforcement. |
|
GDPR fines have reached 7.1 billion euros cumulatively per DLA Piper’s January 2026 survey, and OSHA’s willful-violation ceiling stands at $165,514 per violation. |
This guide explains what compliance in business actually covers, separates regulatory duties from corporate ones, prices the failures with 2024 to 2026 enforcement data, and lays out the program structure the Department of Justice itself uses to judge accused companies.
What Compliance Means in Business
TD Bank’s collapse into criminality was a compliance failure in the fullest sense: the rules were clear, the bank knew them, and the program meant to enforce them was starved. Compliance covers three layers of obligation: external law and regulation, adopted industry standards, and the company’s own policies.
The international benchmark, ISO 37301, defines a compliance management system as the structure that identifies obligations, embeds them in operations, and evaluates performance against them. The practical work starts with a compliance risk assessment that maps which rules touch which processes.
Most US companies carry compliance obligations in six recurring domains, whatever their size or sector. Each domain brings its own regulators, its own penalty scale, and its own evidence expectations, so treat the list below as the minimum map for an obligations register:
- Employment and labor: wage and hour rules, anti-discrimination law, leave entitlements
- Workplace safety: OSHA standards, incident recording, hazard communication
- Data and privacy: GDPR, state privacy acts, sector rules like HIPAA and GLBA
- Financial integrity: tax, SOX controls, anti-money laundering, sanctions screening
- Sector regulation: FDA, FERC, FCC, state licensing boards, and similar authorities
- Contractual and voluntary standards: PCI DSS, SOC 2, ISO certifications customers demand
A single transaction can cross several domains at once, which is why mature firms manage obligations through one compliance risk analysis rather than six disconnected checklists, and why governance, risk, and compliance functions increasingly converge under one shared operating model.
Regulatory Rules and Internal Rules Do Different Jobs
Those six domains split along one fault line: who wrote the rule. Regulatory compliance answers to governments and their agencies, while corporate compliance covers the standards a company imposes on itself, from codes of conduct to gift policies, often stricter than any statute requires.
|
Dimension |
Regulatory compliance |
Corporate compliance |
Consequence of failure |
|
Source of the rule |
Statutes, regulations, agency guidance |
Board policies, code of conduct, values |
Different forums, same reputational hit |
|
Enforcer |
SEC, DOJ, OSHA, FinCEN, state AGs |
Management, board, internal audit |
Fines and prosecution vs discipline |
|
Flexibility |
None: the floor is the law |
Set by the company, can exceed law |
Waivers erode culture fast |
|
Evidence expected |
Filings, records, audit trails |
Attestations, training logs, cases |
Both are discoverable in litigation |
|
Example |
Filing accurate currency reports |
Banning gifts above a threshold |
TD Bank failed the first kind |
The two layers reinforce each other. A company that enforces its internal rules builds the culture and records that keep it inside the external ones, which is why the US Sentencing Guidelines for organizations cut penalties for firms that ran a genuine program before the violation, and why COSO’s internal control framework makes compliance a core objective.
Why the Cost of Getting It Wrong Keeps Climbing
Enforcement data makes the price explicit. TD Bank’s $3.09 billion split four ways, and the asset cap analysts value in lost growth may exceed the cash penalty over time. The chart below shows how a single program failure multiplies across agencies.

Figure 1. One deficient AML program drew separate penalties from the DOJ, FinCEN, OCC, and Federal Reserve in a single coordinated resolution.
Securities enforcement runs at similar scale. The SEC’s fiscal 2025 results show 456 actions and $17.9 billion in ordered relief, and the agency logged a record 53,753 whistleblower tips, 19 percent more than the prior year. Every one of those tips is a potential investigation someone’s compliance program failed to intercept.

Figure 2. The SEC’s fiscal 2025 scoreboard; the relief total includes one long-running $8 billion Ponzi judgment.
Privacy enforcement compounds the exposure for any firm touching European data. DLA Piper’s January 2026 survey puts cumulative GDPR fines at 7.1 billion euros, with 1.2 billion euros issued in 2025 alone and breach notifications running at 443 per day, up 22 percent year over year.
Against those numbers, program cost is modest: policy work, training hours, monitoring tools, and audits. The fiscal 2024 SEC year ordered a record $8.2 billion in remedies, so two consecutive years of headline enforcement have given every CFO the comparison they need. Prevention is the cheap side of this ledger.
The Regulations That Touch Nearly Every US Company
Whatever your scale, some list of named rules applies to you today. The table below covers the frameworks US practitioners meet most often, and a compliance risk assessment template turns it into a company-specific obligations register in a single afternoon.
|
Framework |
Who it covers |
Core requirement |
Penalty exposure |
|
OSHA |
Nearly all private employers |
Safe workplace, hazard controls, incident records |
Up to $165,514 per willful violation |
|
SOX |
US public companies |
Accurate financials, tested internal controls |
Criminal liability for executives |
|
HIPAA |
Health providers, plans, their vendors |
Safeguard protected health information |
Tiered civil penalties plus criminal exposure |
|
GLBA |
Financial institutions |
Protect customer financial data, Safeguards Rule |
FTC enforcement, state actions |
|
PCI DSS |
Anyone handling card payments |
Twelve security requirements for cardholder data |
Contract penalties, higher fees, card bans |
|
GDPR |
Firms processing EU personal data |
Lawful basis, breach notice within 72 hours |
Up to 4% of global revenue |
OSHA’s penalty schedule held at its January 2025 levels through 2026 after the agency skipped the annual inflation adjustment: $16,550 per serious violation and $165,514 per willful or repeated one. The ceilings look small next to banking fines until they multiply across citations and days.

Figure 3. OSHA’s per-violation ceilings; failure to abate accrues per day, and citations rarely arrive alone.
Sector rules stack on top of the universal set. Healthcare firms run HIPAA risk assessments under HHS rules, card merchants certify against PCI DSS, financial firms manage the GLBA Safeguards Rule and sanctions screening, public filers test controls under the Sarbanes-Oxley Act, and US subsidiaries of EU-facing businesses now track DORA obligations as well.
How to Build a Compliance Program That Holds Up
Knowing the rulebook is the entry fee; the differentiator is a program a prosecutor would credit. The DOJ’s Evaluation of Corporate Compliance Programs, updated in September 2024 to cover AI risk and data access, asks three questions: is the program well designed, is it resourced and empowered, and does it work in practice.
|
Element |
What good looks like |
Evidence on file |
|
1. Risk assessment |
Obligations mapped to processes, scored, refreshed annually |
Scored obligations register |
|
2. Policies and procedures |
Plain-language code of conduct plus targeted procedures |
Version-controlled policy library |
|
3. Training |
Role-based, tested, tracked to completion |
Completion and test records |
|
4. Reporting channels |
Anonymous hotline, no-retaliation rule enforced |
Case log with outcomes |
|
5. Monitoring and testing |
Control testing, data analytics, periodic audits |
Test results and findings register |
|
6. Enforcement and incentives |
Consistent discipline, compliance in performance goals |
Sanction and incentive records |
|
7. Response and improvement |
Root-cause analysis after issues, program updates |
Corrective action tracker |
Two disciplines carry most of the weight. First, anchor everything to the risk assessment, reusing the same 5×5 scoring your enterprise risk management framework already applies, so compliance exposures rank alongside every other risk. Second, monitor continuously through compliance key risk indicators instead of waiting for the annual audit to find the gap.
Tooling helps once the process exists. Our comparison of compliance management software covers the register, workflow, and attestation platforms, and a risk and control self-assessment gives the first line a structured way to test its own controls between formal audits.
Who Owns the Rulebook: Roles and the Three Lines
Programs fail as often on ownership as on design, which is why the DOJ asks pointed questions about autonomy and resources. The working division of labor follows the three lines model, with the chief compliance officer reporting to the board or its audit committee, never solely to the general counsel.
|
Role |
Line |
Core accountability |
Failure smell |
|
Operations managers |
First line |
Run controls inside daily processes |
Compliance seen as someone else’s job |
|
Chief compliance officer |
Second line |
Design program, advise, monitor, escalate |
No budget, no board access |
|
Risk and legal |
Second line |
Interpret obligations, set appetite |
Advice arrives after the decision |
|
Internal audit |
Third line |
Independent assurance on the program |
Audits the paperwork, misses practice |
|
Board / audit committee |
Oversight |
Set tone, resource the program, review cases |
Metrics reviewed, never questioned |
Give the second line teeth through measurement. Legal and compliance KRIs like training completion, overdue attestations, hotline volume, and repeat findings, tied to a stated risk appetite, convert culture into numbers a board can challenge. The KRI design practices that work elsewhere in risk apply unchanged here.
Staff the function deliberately. A risk-based internal audit plan keeps third-line hours pointed at the highest-exposure obligations, an annual audit risk assessment documents why, and the certifications that matter for risk and compliance careers tell you what competence to hire for.
Compliance in Business: Your Questions Answered
What is the difference between regulatory compliance and corporate compliance?
Regulatory compliance means meeting obligations imposed from outside: statutes, agency rules, and court orders enforced by bodies like the SEC, OSHA, and FinCEN. Corporate compliance adds the company’s self-imposed layer of codes, policies, and ethical standards. Regulators increasingly judge the second layer when deciding penalties for breaking the first.
Who is responsible for compliance in a business?
Everyone runs the controls, but accountability concentrates: operations managers own compliance inside their processes, a chief compliance officer designs and monitors the program, internal audit provides independent assurance, and the board sets tone and resources. In a small business the owner holds the CCO role, ideally with an external advisor on call.
What does a business compliance program include?
Seven elements, matching the DOJ’s evaluation criteria: a compliance risk assessment, written policies and procedures, role-based training, confidential reporting channels, monitoring and testing, consistent enforcement with incentives, and a corrective loop that fixes root causes. Evidence matters as much as activity, since an undocumented program scores as no program.
How much does non-compliance cost a business?
Recent US enforcement sets the scale: TD Bank paid $3.09 billion plus an asset cap in 2024, the SEC ordered $17.9 billion in relief across fiscal 2025, and OSHA charges up to $165,514 per willful violation. Indirect costs, including lost contracts, monitorships, and reputational damage, usually exceed the fine.
What are examples of compliance requirements in business?
Common US examples include OSHA workplace safety standards, SOX financial reporting controls for public companies, HIPAA safeguards for health information, GLBA data protection for financial firms, PCI DSS for card payments, and GDPR for EU personal data. State wage, privacy, and licensing rules stack on top of the federal set.
How often should a business review its compliance program?
Refresh the compliance risk assessment annually and after any acquisition, new product, new market, or enforcement action in your sector. Monitor continuously through KRIs and control testing rather than waiting for the yearly cycle. The DOJ explicitly scores whether a program evolves with the business or sits frozen at launch.
Where Programs Stall and How to Unstick Them
TD Bank had policies, a compliance department, and training, and still pleaded guilty, because each piece existed on paper while the practice withered. The failure patterns below repeat across industries, and each has a correction a mid-size team can land within a quarter.
|
Pitfall |
Root cause |
Remedy |
|
Paper program: policies nobody follows |
Compliance treated as documentation |
Test practice, reward reporting, publish case outcomes |
|
Flat budget while the business doubles |
Growth prioritized over control |
Tie compliance headcount to volume and risk metrics |
|
CCO buried under the general counsel |
Structure muffles escalation |
Direct board reporting line with protected tenure |
|
Training completed, nothing learned |
Generic click-through modules |
Role-based scenarios, tested, refreshed on incidents |
|
Hotline silence read as good news |
Retaliation fear, no feedback loop |
Track report rates against benchmarks; probe silence |
|
Findings recur audit after audit |
No root-cause discipline |
Corrective action tracker with owners and deadlines |
The Enforcement and Technology Horizon
Three currents will shape the next two years. Enforcement stays aggressive across administrations: fiscal 2024 set the SEC’s dollar record at $8.2 billion, fiscal 2025 held near-record relief while whistleblower tips jumped 19 percent, and coordinated multi-agency resolutions like TD Bank’s are now the template for serious cases.
Second, regulators now examine the technology inside your program. The DOJ’s September 2024 evaluation update asks how companies govern AI they deploy and whether compliance teams get the same data access as the business, a question most programs still cannot answer well.
Third, obligations keep arriving from adjacent domains. Privacy statutes multiply at the state level, operational resilience rules like DORA reach US firms through their European footprint, and continuity expectations mean your business contingency planning and your compliance management approach will be assessed together, consistent with ISO 31000’s integration principle.
If you run risk or compliance for a growing US firm and your obligations register has not kept pace, that gap is exactly what we help close. Start with our services, then use the contact page to send your three toughest regulatory questions, and we will tell you where the program stands.

Chris Ekai is a Risk Management expert with over 10 years of experience in the field. He has a Master’s(MSc) degree in Risk Management from University of Portsmouth and is a CPA and Finance professional. He currently works as a Content Manager at Risk Publishing, writing about Enterprise Risk Management, Business Continuity Management and Project Management.