In our previous post on the Legal Service, we saw how regulatory compliance, when it is experienced as a requirement imposed from outside, ends up costing more than the protection it provides.
And we established a first rule: understand the company’s operational processes in order to identify their legal implications.
The practical question remains: where do you begin?
Two ways to take on board the law In practice, an SME has two approaches available to it.
The first starts with the law. A specialist is hired to examine the regulations, translate them into a list of compliance requirements and verify that the company meets them. The result is a list of boxes to tick and a file of documents demonstrating compliance.
The second approach starts with the company itself. Its transformation processes (purchasing, warehousing, production and sales) are analysed, and a detailed assessment is carried out to examine the risks the business faces at each stage. The regulations come into play later, as one of the criteria used to define the contours of the overall risk.
The first approach is faster and offers a sense of security. However, it answers a different question to the one that truly matters to the business owner.
The right question
It is always an advantage to work with a business owner who asks me: ‘What risks do I face if I don’t comply?’
It is the right question, because it shifts the focus from documentation to actual business management. And the correct answer requires the second approach, because the sanctions a company is exposed to are only part of the risks.
Beyond the fine itself, there are consequences that no checklist highlights:
A list of compliance requirements tells you whether the company is compliant. A process assessment, however, reveals the cost of non-compliance and identifies which areas of management are at risk.
A practical example: the raw materials warehouse
Imagine a company that manufactures tablets on behalf of third parties. A checklist would verify that the raw materials warehouse maintains a temperature log and that it is filled out regularly. Box ticked.
However, process analysis raises different questions. Who reviews the recorded data, and how often? What happens if a batch of raw materials is stored outside the specified conditions but is sent to production anyway? How does the client contract allocate liability in the event of a product recall? And does the supplier contract allow recourse against the supplier?
In this scenario, the regulatory fine is likely to be the least significant cost. Batch recalls, the loss of the client and litigation weigh far more heavily. This is precisely where a company that understands its processes will already have built in safeguards.
One piece, not an isolated chapter
This topic belongs to the side of the Rubik’s cube dedicated to the Legal Service: one of the six major areas that make up sound SME administration.
Starting with processes does not mean ignoring regulations, but giving them their proper place: a tool for reading management risks, not a list to be filed away. In the next post, we will examine the regulatory requirements that truly impact business management, and how to identify them starting from the processes.
When you think about your company’s compliance, do you start with the law or with your processes? Leave us your comments, and follow us on LinkedIn @Pietro Cavalli so you don’t miss the next piece of the journey.