Strategic Business Leader · Audit and compliance
Compliance, Laws and Regulation for ACCA Strategic Business Leader
Updated 11 October 2026 · Fact-checked
Compliance means an organisation follows the laws, regulations and codes that apply to it. Compliance risk is the chance of penalty, loss or reputational damage if it does not. To answer SBL questions, identify the rules, assess the risk, recommend controls, and explain how compliance and internal audit monitor them.
Understand Compliance, Laws and Regulation
Every organisation operates inside a set of rules. Some are laws passed by governments, such as employment, tax, health and safety, and data protection law. Some are regulations set by regulators, such as financial services or environmental authorities. Others are codes, such as a corporate governance code or the organisation's own code of conduct.
Compliance risk is the risk of legal penalties, fines, financial loss, loss of licence or reputational damage from failing to follow these rules. It also covers the cost of complying. Operating across several countries raises the risk, because rules differ and may conflict.
There are two broad approaches to rules. A rules-based approach sets mandatory requirements, and you must obey them in every case. A principles-based approach sets broad principles and uses comply or explain. Under comply or explain, a company follows the code or discloses where it does not and gives reasons. Shareholders and other stakeholders then judge whether the explanation is acceptable. Comply or explain suits flexibility but relies on honest, informed judgement by investors.
Compliance is monitored in layers. Managers own compliance in their areas as part of the first line. A compliance function sits in the second line. It tracks changes in law, sets policies, trains staff, and advises and reports to the board. Internal audit is the third line. It gives independent assurance by testing whether controls work and rules are followed, then reports to the audit committee. The board remains responsible overall, and the audit committee oversees the process. External auditors also look at compliance where it affects the financial statements.
In SBL you apply this to a scenario. Think about culture too. If senior people ignore rules or reward results at any cost, staff follow. Compliance works best when it is backed by ethical tone from the top, clear policies, training, and a safe route to report concerns such as whistleblowing.
Key rules to remember
- Compliance risk
- Compliance risk = likelihood of breach × impact of breach (fines, loss of licence, legal costs, reputation)
- A way of thinking, not a calculation. Use it to rank which rules need the strongest controls.
- Comply or explain
- Comply with the code, or disclose the departure and give reasons
- Principles-based. It is not optional to say something. Silence on a departure is a failure.
- Three lines of assurance
- First line: management. Second line: compliance and risk functions. Third line: internal audit
- Internal audit is independent of management. Say so when assessing assurance.
- Rules-based vs principles-based
- Rules-based: mandatory, specific, penalties for breach. Principles-based: broad principles, judgement, explanation of departures
- Link to the scenario: rules-based gives certainty but can encourage box-ticking.
How to solve Compliance, Laws and Regulation questions
Use this method for any question on compliance, laws and regulation. Anchor every point to the scenario.
- 1Read the requirement and note the verb (identify, assess, evaluate, recommend, explain).
- 2Identify which laws, regulations or codes apply to the organisation, including each country it operates in.
- 3Spot the breaches or weak points in the scenario, such as poor culture, missing training, pressure on targets or unclear responsibility.
- 4Assess the compliance risk: likelihood and impact, including fines, licence, legal action, reputation and stakeholder trust.
- 5Recommend actions: policies, a compliance function, training, controls, whistleblowing channels, board and audit committee oversight.
- 6Explain how compliance is monitored: management, the compliance function, internal audit testing and reporting to the audit committee.
- 7Conclude with a clear, justified recommendation, written in the format asked for (report, memo, briefing).
Quickest way: Rule, Risk, Control, Monitor
When to use it: Use when time is short or you are planning a written answer. It gives a four-part structure in about a minute.
- Rule: which law, regulation or code applies, and is it rules-based or comply or explain?
- Risk: what could go wrong in the scenario, and what is the impact?
- Control: what policy, training, system or culture change reduces the risk?
- Monitor: who checks, meaning management, compliance function, internal audit, audit committee?
- Add a scenario fact to each heading so the answer is applied, not generic.
Common mistakes in Compliance, Laws and Regulation
Treating comply or explain as optional compliance.
Students read it as 'you can ignore the code if you wish'.
Fix: State that departures are allowed only with a disclosed, reasoned explanation, and that stakeholders judge it.
Confusing the compliance function with internal audit.
Both check rules, so they seem the same.
Fix: The compliance function is a second-line advisor and monitor. Internal audit is independent third-line assurance that tests controls, including the compliance function itself.
Listing laws without applying them to the scenario.
Students recall theory and skip analysis.
Fix: Tie each rule to a scenario fact, such as an overseas subsidiary or a sales target, and explain the consequence.
Focusing only on fines and ignoring reputation, licence and culture.
Penalties are the most obvious cost.
Fix: Cover financial, operational and reputational impacts, and the effect on stakeholders and share value.
Assuming compliance with the law makes conduct ethical.
Law and ethics overlap and are easy to blur.
Fix: Note that behaviour can be legal but unethical. Recommend ethical culture and codes in addition to legal compliance.
Recommending a generic 'more rules' answer.
Students assume more rules are always better.
Fix: Weigh the cost and the risk of box-ticking. Suggest proportionate controls, training and tone from the top.
Worked examples
Example 1
Zentra Foods, a listed company, operates in four countries. A regulator fined its largest subsidiary for breaching local food safety rules. The board learned of this from the press. Explain the compliance risks Zentra faces and recommend how it should monitor compliance. (10 marks)
Show the solution
- Rule: the subsidiary is bound by local food safety law, and Zentra's listing means governance code and disclosure duties also apply at group level.
- Risk: the fine is a direct cost. Other impacts are possible loss of licence, product recalls, falling sales, damage to brand and shareholder confidence. Operating in four countries raises the risk because rules differ.
- The board learning from the press shows a reporting failure: no clear route to escalate breaches to the centre.
- Control: set a group compliance policy that reflects each country's rules, appoint local compliance officers reporting to a group compliance function, train staff and add breach reporting and whistleblowing channels.
- Monitor: local managers own compliance daily. The group compliance function tracks regulatory change and reports to the board. Internal audit tests food safety controls on a risk basis and reports to the audit committee.
- Culture: the board should set the tone that safety is not traded for cost or speed, and should link managers' performance reviews to compliance.
Answer: Zentra faces fines, loss of licence, recall costs and reputational damage, made worse by weak escalation across four countries. It should set a group compliance policy, use a group compliance function with local officers, train staff, provide reporting channels, and have internal audit give independent assurance to the audit committee, all backed by board tone from the top.
Example 2
Brightmoor plc is listed in a country whose governance code works on a comply or explain basis. The chair is also the chief executive. The annual report is silent on this. Evaluate the issue and advise the board. (8 marks)
Show the solution
- Identify the rule: most governance codes recommend separating the roles of chair and chief executive to avoid concentration of power. This is a code provision, not a law.
- Under comply or explain, Brightmoor may depart from the provision, but only by disclosing the departure and giving reasons.
- The silence is the problem. It is a failure to explain, so shareholders cannot judge the departure, and the company may breach listing disclosure requirements.
- Risks: dominant individual, weak challenge of the executive, agency problems, loss of investor trust and possible regulatory action.
- Advice: either split the roles, or disclose the departure with a credible reason and safeguards such as a strong senior independent director and a majority of independent non-executives.
- Monitoring: the nomination committee and audit committee review code compliance each year. Internal audit or company secretary checks the annual report disclosures against the code.
Answer: Combining the roles is permitted under comply or explain only if disclosed and justified. Brightmoor's silence is the failure. The board should either separate the roles or give a reasoned explanation with safeguards, and use committees and checks on the annual report to monitor compliance.
Exam tips
- Always name who monitors compliance and how: management, the compliance function, internal audit, and the audit committee.
- Apply every point to named facts in the scenario. Generic lists earn few marks and weak professional skills marks.
- If asked about codes, show you know the difference between a rules-based approach and comply or explain, and judge which suits the case.
- Link compliance to culture, ethics and whistleblowing. Examiners reward the view that rules alone do not secure compliance.
- Match the requested format, such as a report to the board, and give a clear recommendation at the end.
Practice questions from Audit and compliance
- Zephyr Foods plc is a listed company with no internal audit function. The audit committee is considering whether to establish one. Operation…
- Halden Energy's internal auditors have completed a value-for-money review of maintenance contracts. The review found overspending, but manag…
- Zephyr Logistics plc's internal audit team has been asked by the board to review whether the company's regional warehouses are using staff, …
- Orlando Pharma's board plans to outsource its internal audit function to cut costs. The head of internal audit would be made redundant, and …
- Vantor plc's audit committee is deciding whether to approve a proposal that the external auditor also provide valuation services for an acqu…
Compliance, Laws and Regulation: frequently asked questions
What is compliance risk in ACCA SBL?
It is the risk of fines, legal action, loss of licence or reputational damage from breaking laws, regulations or codes. In SBL you assess it using the scenario and recommend controls and monitoring.
What does comply or explain mean?
A company follows a governance code or discloses where it departs and gives reasons. Stakeholders then judge whether the explanation is acceptable. It is common in principles-based systems.
How does internal audit monitor compliance?
Internal audit tests whether controls designed to ensure compliance operate effectively, reviews adherence to policies and laws on a risk basis, and reports findings and recommendations to the audit committee. It is independent of management.
What is the difference between the compliance function and internal audit?
The compliance function advises, sets policies and monitors rules as part of the second line. Internal audit is the independent third line that gives assurance on whether the whole system, including compliance, works.