• Beyond the Rulebook: Building A Compliance Culture That Delivers Sustainable Change

Beyond the Rulebook: Building A Compliance Culture That Delivers Sustainable Change

A strong compliance framework is essential, but it is not self-executing. Sustainable outcomes depend on whether people understand the purpose of controls, feel responsible for applying them, and are willing to challenge, escalate and learn when something goes wrong.

The strongest compliance manuals can still produce weak outcomes if the surrounding culture encourages speed over judgement, treats escalation as failure, or regards compliance as the responsibility of a specialist function. Conversely, an organisation with a mature compliance culture uses policies as a foundation for sound decisions, not as a substitute for them.

This distinction has become increasingly important as regulators place greater emphasis on whether risk management arrangements are effective in practice. A recent Monetary Authority of Singapore paper on culture capabilities contributes usefully to this broader discussion. Without treating culture as a checklist, it reinforces the importance of looking beyond the immediate control failure and considering whether leadership, decision-making, accountability and organisational behaviours support durable change.

Culture is the operating environment for compliance

Compliance culture is sometimes described as the “tone from the top”. Leadership is critical, but culture is broader. It is reflected in the everyday signals people receive about what the organisation truly values: which decisions are rewarded, what gets challenged, whether bad news travels quickly, and how teams respond when commercial and risk priorities compete. In a mature compliance culture, compliance considerations form part of the organisation’s thinking and decision-making from the outset, rather than being introduced only at the final review or approval stage.

A practical way to think about compliance culture is as the operating environment in which controls function. A customer due diligence procedure for instance may be well designed, but its effectiveness will depend on whether employees regard unresolved information as a genuine risk issue, whether management teams support further enquiry, and whether escalation leads to constructive challenge rather than blame.

Therefore, the pertinent question for organisations is not whether they can reproduce a regulatory framework. It is whether they can identify the cultural conditions most relevant to their own business model and translate them into observable expectations. The answer will differ by organisation, but the test is consistent. Do governance, incentives and day-to-day management decisions reinforce the behaviours on which the compliance framework depends?

From departmental ownership to shared accountability

One of the most important shifts is to move away from treating compliance as something “owned” only by the compliance function. Instead, compliance considerations should be embedded into the organisation’s planning, decision-making and day-to-day operations, including when products, client relationships, processes and strategic initiatives are first considered. The compliance function should provide subject-matter expertise, independent oversight and challenge. The business, however, remains responsible for managing the risks created by its activities. Senior management must connect the two through clear governance, credible incentives and timely decision-making.

Shared accountability does not mean blurred accountability. Clear roles and responsibilities remain essential. Front-line teams should understand which risks they own and when escalation is required, while compliance functions should retain sufficient independence to advise, monitor and challenge when necessary.

What boards should look for in practice

Leadership signals

Boards should consider whether leadership decisions consistently reinforce the organisation’s stated risk appetite and values. The relevant evidence is not limited to formal communications. It includes how leaders respond when commercial objectives compete with risk considerations, whether difficult issues receive timely attention, and whether the quality of decision-making is valued alongside financial performance.

Quality of challenge and escalation

A healthy compliance culture allows uncertainty, disagreement and emerging concerns to be raised early. For boards, the question is not simply whether escalation channels exist, but whether the organisation’s governance arrangements produce candid discussion, clear ownership and decisions that are appropriately documented. A rise in challenge or near-miss reporting may warrant attention, but it should be interpreted in context rather than automatically treated as evidence of deteriorating controls.

Learning and sustainable outcomes

Boards should look beyond the closure of individual findings and ask whether the organisation learns from incidents, recurring exceptions and difficult decisions. Remediation is more likely to be sustainable where root causes are understood, incentives and responsibilities are aligned, and independent assurance tests whether the intended behavioural and risk outcomes have taken hold over time.

Avoiding the “policy equals culture” trap

Policies remain indispensable. They define expectations, establish decision parameters and support consistent execution. But the existence of a policy is evidence that a requirement has been articulated, not that it has been understood, applied or reinforced.

A more effective approach is to connect each significant policy requirement to clear ownership, capability, incentives, escalation and assurance. Organisations should ask: Who must make the judgement? Do they have the knowledge and authority to do so? What happens when the requirement conflicts with another objective? How will management know whether the intended behaviour is occurring? What evidence would demonstrate effectiveness to a board, auditor or regulator?

Making compliance part of the decision process

Embedding compliance into organisational thinking does not mean requiring the Compliance function to approve every operational choice. It means that relevant legal, regulatory, conduct and financial crime risk considerations are identified early enough to influence decisions, rather than being addressed only after commercial proposals have already been developed.

This can be seen in everyday business activity. When considering a new client relationship, discussions should include not only commercial considerations, but also the organisation’s ability to understand and manage the associated risks. This may include understanding matters such as the client's source of wealth, the context in which wealth was accumulated and whether sufficient information is available to support that understanding. Addressing these questions early allows concerns to be identified and mitigated before expectations become fixed.

Measuring culture without reducing it to a score

Compliance culture cannot be understood through a single metric. Breach statistics, training completion rates and reported issues can provide useful information, but they rarely tell the full story in isolation. Organisations should therefore focus on patterns, context and behaviours alongside quantitative indicators when assessing whether expected standards are becoming embedded in day-to-day decision-making.

While these principles are often discussed in the context of regulated businesses, many are equally relevant wherever governance and oversight play an important role. Family offices, privately owned businesses and other organisations responsible for managing family wealth may face different regulatory obligations, but many of the same themes apply. Clear accountability, effective challenge, timely escalation and sound decision-making remain fundamental to the long-term stewardship of assets, relationships and institutions.

The real test: what happens under pressure

Compliance culture is most visible when an organisation faces various types of pressure. A valuable client is chasing, a deadline is approaching, information is incomplete, or an established decision is being challenged. In those moments, employees look to the organisation’s actual choices for guidance. Where compliance considerations are already incorporated into the organisation’s thinking, they are less likely to be perceived as a separate obstacle introduced at the end of a process. If leaders consistently support sound judgement, timely escalation and accountable decision-making, compliance becomes part of how the organisation operates. The objective is not a risk-free culture, nor a culture in which every decision is deferred to compliance teams. It is a culture in which risks are recognised, discussed openly, owned by the right people and managed with discipline. That is how organisations move from closing findings to achieving sustainable change, and from having a compliance framework to living it.

The Trident Perspective

At Trident, we recognise that a strong compliance culture is shaped by the cumulative effect of daily decisions. Policies and controls provide an important foundation, but lasting effectiveness depends on individuals understanding their responsibilities, exercising sound judgement, and seeking guidance or escalating concerns when appropriate.  

By embedding compliance considerations into our governance framework, client lifecycle processes and day-to-day decision-making, we aim to foster a culture in which compliance supports informed and responsible business decisions. For more information on Trident Trust Singapore's approach to governance, risk management and compliance, please contact us at singapore@tridenttrust.com.

Author


Tim Khaw

Compliance, Director - Singapore

tkhaw@tridenttrust.com +65 6653 1800