Skip to main content

On-demand webinar coming soon...

Blog

Compliance program performance metrics: How to measure compliance

Which compliance KPIs to measure, how to know your program is working, and how to track improvement over time

Kelly Maxwell
Content Marketing Specialist, OneTrust
September 7, 2022

Stack of multi-colored shipping containers

A company that measures compliance effectively can prevent reputational damage, protect the bottom line, and potentially avoid costly fines and enforcement actions – all by arming itself with the right compliance program performance metrics. But in a data-driven world, it is easy to get overwhelmed by the sheer volume of numbers at our fingertips. We are regularly inundated with metrics, so determining what really matters ends up being equal parts art and science.

As compliance becomes compulsory in our rapidly evolving and regulated business landscape, how do you measure your organization’s compliance effectiveness? Read on to learn more about how to make your data do the heavy lifting for you and your compliance initiatives.

Why tracking compliance program performance is essential

The U.S. Department of Justice (DOJ) Criminal Division updated their Evaluation of Corporate Compliance Programs guidelines in June 2020 – and the update emphasizes that compliance teams need to know whether their program is working.

The DOJ’s Corporate Compliance Programs guidance includes three questions that prosecutors should ask when investigating a company: 

  • Is the organization’s compliance program well-designed?
  • Is the program being applied earnestly and in good faith, e.g. is it being implemented effectively?
  • Does the program work in practice?

Keep these three questions top of mind to not only set your compliance initiatives up for success, but to prevent any costly legal consequences. In particular, compliance officers at companies that are under a monitorship or corporate resolution should pay close attention to the first question, as the DOJ revealed in 2022 that they will require CCOs and CEOs to certify that their program is well-designed at the close of the monitorship.

The DOJ’s updated guidance also includes two sentences that deserve special attention:

  • Have the policies and procedures been published in a searchable format for easy reference?
  • Does the company track access to various policies and procedures to understand what policies are attracting more attention from relevant employees?

Not only does this guidance emphasize the importance of your internal policies and procedures, but it also calls out compliance program performance metrics – specifically, which policies are garnering employee engagement. If employees are engaging with your policies, but you don’t have the data to prove it, as far as the DOJ is concerned, your compliance efforts fall short and may be subject to further scrutiny. Measuring your organization’s compliance effectiveness is more than checking off boxes in an extensive list of guidelines; it is about taking the time to make sure that your compliance program is structured to measure what matters most.

How do you measure your organization’s compliance effectiveness?

Compliance metrics come from many potential sources – culture surveys, risk assessments, disclosures, and your helpline, to name a few. With the right compliance management tools, you can view a substantial amount of that vital data in centralized dashboards. But without a strategy or knowing which compliance program performance metrics you’re trying to measure, the raw data can be overwhelming.

Start by identifying your compliance KPIs.

What are compliance KPIs?

Key performance indicators – aka KPIs – are the data points or metrics that indicate how well your team or organization is performing at key initiatives. Compliance KPIs can measure employee engagement and awareness of your compliance program, how well your organization complies with local, national, and global regulations, and ethical decision-making throughout the workforce.

How do you measure compliance KPIs?

Your compliance tech platforms – for example, your hotline, disclosure manager, policy manager, and compliance portal – should each provide you with rich data, and ideally each of these platforms connects to the others in one holistic dashboard. The most sophisticated compliance measurement platforms incorporate HR data and other inputs to provide a complete picture of risk across the organization.

 

Screenshot of onetrust platform showing message from chief compliance officer

 

What if you don’t have access to a dedicated compliance measurement platform? While manual spreadsheets can be time-consuming and lack real-time data, they’re better than nothing. If you are using a manual process to track KPIs, import updated numbers on a regular basis and maintain your records over an extended period so you can track your program’s progress.

Which compliance KPIs should you measure?

The most important KPIs are the ones that track directly to your program’s goals – but you may have to dig a little deeper than the obvious compliance metrics like policy attestation rate or reporting rate.

For example, if your goal is to increase awareness of your helpline and code of conduct, are you tracking how many times the code is viewed, or how many reports are submitted outside of awareness campaign cycles? What about the number of clicks or interactions within your interactive code of conduct? (Hint: you should be. The DOJ included this question in their most recent guidance for corporate compliance programs.) If your goal is to overcome reporting reluctance, are you comparing the intake rate across different intake channels like open-door versus anonymous online reports?

Our Compliance KPIs Worksheet contains many more suggested KPIs for you to measure. Throughout the process of completing it, you’ll identify which data you already have access to, and what it can tell you about how effective your compliance program is. Here’s a preview of some of the compliance measures you’ll explore:

Compliance KPIs to measure compliance program performance:

  • Number of times and how often code and policies are reviewed and/or updated
  • Number and nature of code and policy violations
  • Culture surveys and knowledge assessments results
  • Training reach, medium, frequency, and completion rates
  • Reach, medium, frequency, and engagement rates of compliance communications
  • Training program update rates
  • Post-training test results
  • Number and nature of incidents by employees who have completed training
  • Reporting rates, known and anonymous/1000 employees by reporting channel
  • Retaliation report trends, including the number of reports of retaliation

How to choose which compliance KPIs to prioritize

First, you have to understand what data you currently have access to. There are sources of rich, untapped data in your HR department, sales team, and more that your compliance program can use to gain deeper insights into issues like cultural health, brand reputation, and silent retaliation.

Then, you can put each data point in context – both to understand how to interpret it, and to evaluate how relevant it is to your compliance program’s goals and your regulatory requirements. These insights empower you to more effectively allocate resources, tell a more compelling compliance story to your Board of Directors, and ultimately achieve a healthier and more ethical culture.

Use our Compliance KPIs worksheet as a health check on your current data analysis and compare results with your teammates. You may be surprised to find that compliance-adjacent roles have access to different data than you do or are layering data in ways you hadn’t considered to create a more holistic risk profile.

Tracking compliance performance over time

The rise in stakeholder capitalism means that regulators, employees, and customers demand more from the companies they regularly interact with. But when measuring something as multifaceted as the ethical health of your organization, how do you treat your KPIs with the respect and attention they deserve?

Reveal your organization’s biggest compliance strengths and weaknesses by tracking improvement over time, using the same set of benchmarks. Over the long term, you can measure exactly how much progress your focus and cross-departmental energy has brought about.

Use our Compliance KPIs worksheet to conduct a health audit and data analysis for your organization. Compare your results to other compliance-adjacent roles at your company and develop a plan of action for all your organization’s data.


You may also like

Webinar

Ethics Program Management

EthicsConnect: Risk - It’s not just for breakfast anymore

Join us for a deep dive into embedding privacy by design into the fabric of your business to promote the responsible use of data.

April 25, 2024

Learn more

Webinar

Supplier Sustainability & Responsibility

Modern slavery: Identifying exploitation and managing forced labor risks

In this webinar, OneTrust and Andrew Wallis, CEO at Unseen, will discuss the scale and impact of modern slavery on businesses' global supply chains.

March 14, 2024

Learn more

eBook

Ethics Program Management

Business messaging apps: A guide to corporate compliance

How can your business use third-party messaging apps while staying compliant? Dive into key usage considerations based on the DOJ’s 2023 guidance.

February 13, 2024

Learn more

Infographic

Third-Party Risk

4 top-of-mind challenges for CISOs in 2024

What key challenges do CISOs face going into the new year? Download this infographic to hear what experts from industries across the board have to say.

January 30, 2024

Learn more

Webinar

Third-Party Due Diligence

Best practices for conducting third-party due diligence for ethics & compliance​

Join this webinar for best practices for conducting third-party due diligence for ethics and compliance.

January 11, 2024

Learn more

Webinar

Ethics Program Management

Ethics Exchange: Third-party applications and ephemeral apps

Learn practical advice on how to navigate the risks of ephemeral apps and employee privacy in BYOD world.

December 05, 2023

Learn more

Webinar

Speak-Up Program Management

Navigating the EU Whistleblower Protection Directive: New rules, new risks

Join our expert-led webinar where we explore the EU Whistleblower Protection Directive and practical steps towards compliance. 

November 02, 2023

Learn more

Webinar

Ethics Program Management

Ethics Exchange: Risk assessments

Join our risk assessments experts as we discuss best practices, program templates, and how provide an assessment that provides the best value for your organization.

October 25, 2023

Learn more

Webinar

Ethics Program Management

Ethics Exchange: Investigations

Join our live webinar and learn how to conduct comprehensive ethics investigations that are trustworthy and efficient.

September 07, 2023

Learn more

Webinar

Third-Party Due Diligence

Driving excellence in third-party risk management: An in-depth look at different due diligence approaches

Join our in-depth webinar and learn how to define third-party due dilligence levels and when to apply them during your vendor management lifecycle.

July 20, 2023

Learn more

Webinar

Third-Party Due Diligence

A shortcut to third party due diligence fundamentals

In this webinar, we examine the scope of third-party due dilligence, best practices, and industry trends driving greater scrutiny on third parties.

July 13, 2023

Learn more

Webinar

Third-Party Due Diligence

Sanctions and export controls: Ensuring compliance

Watch our live expert webinar on understanding global sanctions and export controls and how to reduce your organiztion's risk exposure and ensure compliance.

June 29, 2023

Learn more

Video

Third-Party Risk

Third-party management demo

See how OneTrust's third-party management solution can help scale your third-party lifecycle and evaluate vendors with real-time risk intelligence.

June 27, 2023

Learn more

eBook

Ethics & Compliance

Creating an effective code of conduct

In this eBook, learn how to create an effective code of conduct with six key steps. 

June 01, 2023

Learn more

eBook

Third-Party Due Diligence

The global regulations driving third-party due diligence

Download our eBook learn how to start building a robust third-party due dilligence (TPDD) strategy that protects your brand and minimizes risk.

May 30, 2023

Learn more

Webinar

Third-Party Risk

Unpacking the third-party risk regulatory landscape in the Nordic region and beyond

In this live webinar, our expert panel discuss emerging third-party risk regulatory trends in the Nordic region and show how OneTrust can help your business stay complaint.

May 30, 2023

Learn more

Webinar

Third-Party Due Diligence

Ethics live Demo: Third Party Due Diligence webinar

Learn how OneTrust's Third-Party Due Dilligence, backed by Dow Jones, can help provide your business the data it needs to find trustworthy third parties and mitigate risk.

May 18, 2023

Learn more

In-Person Event

Ethics & Compliance

Ethics Exchange: Practical deep dive for third-party due diligence

Organizations are accountable for third-party actions, so they need robust due diligence to protect their reputation. Learn more at our ethics exchange event.

May 11, 2023

Learn more

Checklist

Ethics Program Management

Policy on development and administration of policies template

Get a head start on your ethics program and create a policy on development and administration of policies with our customizable template.

May 10, 2023

Learn more

Webinar

Third-Party Due Diligence

Maturing your third-party due diligence program: Process, data & technology

Experts at OneTrust and Dow Jones discuss third-party due diligence, covering industry trends, challenges, and how to streamline the process with technology.

April 27, 2023 1 min read

Learn more

Webinar

Ethics & Compliance

Unpacking the global third-party due diligence regulatory landscape

Learn how a strategic plan for compliance can help companies eliminate human rights and environmental violations and avoid costly consequences.

March 06, 2023

Learn more

Webinar

Ethics & Compliance

Third party due diligence – A practical deep dive

In this session, we'll look into the scope of third-party due diligence and a deep dive into practical implementation aspects and best practices for organizations.

December 13, 2022

Learn more

Report

Trust Intelligence

Trending toward trust

The "Trending toward trust" report from OneTrust highlights seven key trends that organizations need to know.

December 12, 2022

Learn more

Webinar

Ethics & Compliance

The number one metric for effective compliance programs: Continuous improvement

Join our webinar to learn how to develop and/or maintain a High-Quality E&C Program and what role data analytics play in improving your compliance program.

November 27, 2022

Learn more

Webinar

Ethics & Compliance

Best practices for conducting third-party due diligence for ethics & compliance

In this session, we'll explore the scope of third-party due diligence and best practices, such as industry trends driving greater scrutiny on third parties.

November 16, 2022

Learn more

Webinar

Ethics Program Management

Live demo: Conflicts of interest management webinar

Learn how to develop a holistic disclosure program, how to make it part of your risk assessment, and how to use it to meet regulatory obligations.

November 01, 2022

Learn more

Checklist

Ethics & Compliance

The CECO’s third party checklist

Use this checklist to ensure that your ethics and compliance program is effectively managing third parties across the entire relationship lifecycle.

October 28, 2022

Learn more

eBook

ESG & Sustainability

The CECO’s guide to managing third parties eBook

Download this eBook to learn the six steps in the lifecycle of risk-based third-party due diligence, compliance terms, and conditions, payment terms, etc.

October 27, 2022

Learn more

White Paper

Ethics & Compliance

Central vs. local intake and case management under the EU Whistleblowing Directive white paper

Download this white paper to learn the specific intake and case management requirements for local subsidiaries and offices across Europe.

October 25, 2022

Learn more

Webinar

Ethics & Compliance

The role of disclosures in risk assessment and management

In this webinar, we’ll discuss developing a holistic disclosure program, making it part of your risk assessment, and using it to meet regulatory obligations.

October 04, 2022

Learn more

White Paper

Ethics & Compliance

What CCOs need to know about the DOJ compliance certification requirement white paper

Download our white paper to learn how the DOJ’s new policy will empower CCOs, and discover what opportunities this new policy presents for your program.

September 01, 2022

Learn more

Webinar

Ethics & Compliance

How to transform your ethics management program through effective employee engagement

In this webinar, we’ll discuss how to develop a successful ethics management program and how to promote trust by developing awareness.

July 28, 2022

Learn more

White Paper

Ethics & Compliance

DOJ’s 2020 update to the evaluation of corporate compliance programs

This white paper explores the 2020 DOJ Compliance Guidance Update and where it takes corporate compliance programs this year and beyond.

July 15, 2022

Learn more

Checklist

Ethics & Compliance

DOJ self-assessment checklist

This enhanced DOJ guidance sets out a baseline, or the minimum standards, to demonstrate an effective ethics & compliance (E&C) program.

July 08, 2022

Learn more

Webinar

Ethics & Compliance

Conflicts of interest and disclosures

Join this roundtable with your peers and experts in ethics and compliance to discuss how to build a successful conflict of interest management program.

July 08, 2022

Learn more

Webinar

Ethics & Compliance

Effective policy governance and distribution

Join this roundtable to discuss how to create effective policies, run effective campaigns and report on each policy’s performance and influence. 

July 08, 2022

Learn more

Webinar

Ethics Program Management

Local vs. central intake and case management: What the EU Whistleblower Directive requires

One of the challenges to come out of the EU Whistleblower Protection Directive is how companies should adopt local vs. centralized case management.

July 06, 2022

Learn more

Webinar

Ethics & Compliance

GDPR and the EU Whistleblower Protection Directive webinar

Join this webinar to learn how to review your whistleblowing processes to comply with the EU Whistleblower Protection Directive, the GDPR and others.

July 06, 2022

Learn more

Webinar

Ethics & Compliance

Hotline reporting under the EU Whistleblower Protection Directive: Unseen consequences, issues & practicalities

While there have been many articles and discussions around the EU Whistleblower Protection Directive, several significant issues have largely gone unnoticed. 

July 06, 2022

Learn more

Webinar

Ethics & Compliance

A hotline innovation masterclass: communications, awareness & confidentiality

Learn how to effectively train and raise awareness on your hotline and how to share information on the Directive so that your company remains compliant.

July 06, 2022

Learn more

Webinar

Ethics & Compliance

Evaluating hotline vendor compliance with the EU Whistleblower Protection Directive

Join us to learn how to choose a hotline vendor, and we also cover the onboarding and implementation process so that you can meet the Directive's deadline.

July 06, 2022

Learn more

Interactive Tool

Ethics & Compliance

Compliance KPIs worksheet interactive tool

Use this worksheet to understand what data you currently have, what you're lacking that may be important, and what certain data points may indicate.

July 05, 2022

Learn more

Webinar

Ethics & Compliance

Whistleblower retaliation under the EU Whistleblower Protection Directive: the reverse burden of proof

Learn how to implement anti-retaliation measures, and how to detect retaliation throughout the whistleblowing process using some new and novel techniques.

July 05, 2022

Learn more

eBook

Ethics & Compliance

14 key requirements to effective conflicts of interest management

Read this eBook to learn the key requirements that are fundamental to building a successful conflict of interest management program.

June 30, 2022

Learn more

Checklist

Ethics & Compliance

Annual compliance program checklist

Download our annual review compliance checklist to evaluate your E&C compliance program, identify key gaps, and prepare for the future.

June 30, 2022

Learn more

Webinar

Trust Intelligence

Become a trusted brand: 7 ways to promote your security, privacy, ethics and ESG programs

We discuss key points, such as choosing which certifications count the most to your business and how to save time when answering questionnaires.

June 20, 2022

Learn more

Checklist

Ethics & Compliance

Anti-retaliation checklist for compliance programs

Use these 19 questions to take a holistic look at how your program can improve training, investigations, policies, & more to prevent retaliation before it occurs.

June 17, 2022

Learn more

Checklist

Ethics & Compliance

EU Whistleblower Directive checklist

Assess your company's EU Whistleblower Directive compliance with this interactive checklist. 

June 16, 2022

Learn more

eBook

Ethics & Compliance

Ultimate guide to the EU Whistleblower Protection Directive

Download our free eBook on the EU Whistleblower Protection Directive learn its key requirements, who's protected, and answers to common questions. 

June 07, 2022

Learn more

Webinar

Privacy & Data Governance

7 ways trusted brands promote their security, privacy, ethics, and ESG programs

Watch this free webinar and learn 7 ways trusted brands promote their security, privacy, ethics, and ESG programs.

May 17, 2022

Learn more

eBook

Ethics & Compliance

The secret to effective policy management

Download this eBook and discover how a centralized policy management system helps drive compliance and ethics policy effectiveness. 

May 11, 2022

Learn more

eBook

Ethics & Compliance

How to build a speak-up culture

Download this step-by-step guide on building a speak-up culture and improve reporting rates. 

April 25, 2022

Learn more

eBook

Ethics & Compliance

Quick guide to the EU Whistleblower Directive

Use this guide to learn how the new EU Whistleblower Directive will be enforced, who is subject to it, and how to comply with it.

April 20, 2022

Learn more

Infographic

Ethics & Compliance

Infographic: The impact of an effective helpline on speak-up culture

Download this infographic and learn how an effective helpline is key to building a speak-up culture. 

April 08, 2022

Learn more

Interactive Tool

Ethics & Compliance

A simple conflict of interest disclosure form template

Download and customize this conflict of interest disclosure template to begin collecting voluntary disclosures at your organization.

April 05, 2022

Learn more

Webinar

Third-Party Due Diligence

7 best practices for conducting third-party due diligence for ethics & compliance

Watch this webinar and learn the seven best practices for third-party due diligence. 

January 03, 2022

Learn more

Webinar

Privacy & Data Governance

Data breach vs. ethics breach: How to prepare for both

In this webinar, we review case studies and tips from recent breaches and analyze which situations qualify as an "ethics breach."

July 07, 2021

Learn more