Business compliance: where your company begins
A large client started requiring it. A public tender asked for it. The bank inquired. Suddenly the word compliance stopped being a distant matter for multinationals and arrived at the table of companies of every size, often accompanied by the feeling that it is something expensive, complex and reserved for those with their own legal department. This text was written to undo that impression and to answer the most practical question of all: if your company needs to start doing compliance, where to begin. The path is simpler, and more proportional to your size, than it usually seems.
Key points
- Business compliance is being in conformity with the laws and rules that apply to the business, supported by a program that prevents, detects and corrects deviations and risks.
- You do not need a large apparatus to begin. A minimum viable program (risk analysis, code of conduct, reporting channel, training and a person in charge) already protects the company and qualifies it before clients and public tenders.
- The difference between the compliance of a large corporation and that of a small company is one of proportion, not of need. The program must fit the real risk of the business.
Why your company is hearing about compliance
The pressure rarely comes from within. It arrives when a larger client includes, in the contract, the requirement that the supplier have a code of conduct and a reporting channel. It arrives when a public tender, under the new Public Procurement Law, makes a high-value contract conditional on the existence of an integrity program. It arrives when a bank or an investor asks for transparency about governance before releasing credit or committing funds. At those moments, compliance stops being a philosophical choice and becomes a concrete condition for closing a deal.
The difficulty is that the word carries an aura of complexity that frightens the smaller company. The good news is that the requirement, in practice, translates into a set of measures that can be sized to the scale of whoever adopts them.
What business compliance is, without jargon
Business compliance means, in essence, being in conformity: complying with the laws, the rules of the sector and the internal rules the company sets for itself. But the term designates more than mere compliance; it designates the program that makes that compliance organized and verifiable, with policies that guide conduct, mechanisms that detect deviations and routines that correct them. In one sentence, compliance is turning good intentions into structure. For a deeper reading of the subject as a structure of risk management, the text compliance as structure, not cost is worth reading; here, the aim is to show how to begin.
The pillars of compliance
There is some confusion about how many pillars compliance has, and the search reflects it: people speak of three, five, seven. The reason is that different formulations exist. The reference model of Brazil's Office of the Comptroller General organizes the integrity program into five axes: the commitment of senior management, the existence of a responsible body, the periodic analysis of risks, the structuring of rules and instruments, and continuous monitoring. The reading most widespread in the market, in turn, tends to sum compliance up in three practical pillars: prevent, detect and correct. The two views do not contradict each other; the first details what the second summarizes. What matters is not memorizing the number, but ensuring that the program covers each of these functions.
Which law represents compliance in Brazil
There is no single compliance law, but a set of rules that make it relevant. The main one is the Anti-Corruption Law (Law No. 12.846/2013), regulated by Decree No. 11.129/2022, which treats the integrity program as a factor that mitigates the company's liability. The new Public Procurement Law (Law No. 14.133/2021) requires the program of whoever wins high-value public contracts. The General Data Protection Law (Law No. 13.709/2018) adds conformity in the processing of data. And there are rules specific to each sector. It is this set that makes compliance a legal requirement, and not merely good practice.
The minimum viable program: where to begin
For the company that is starting out, the answer is not to copy a multinational's manual, but to build a minimum viable program, lean and proportional, with five elements that already deliver the essentials.
A simple risk analysis
Before any policy, one must know which risks are proper to that activity: whom the company deals with, where there is contact with the public administration, what data it processes. Without that map, the program becomes mere paper.
A code of conduct
The document that translates, in clear language, what the company expects from partners, employees and partners. It is the backbone of the program and, often, the first item a large client asks to see.
A reporting channel
A secure means, preferably with a guarantee of anonymity, so that deviations are reported internally before they become a crisis. It is the most effective detection mechanism and one of the most valued in audits.
Training and communication
A policy no one knows is of no use. Simple, periodic training turns the document into culture.
A person in charge
Someone charged with looking after the program and keeping it alive, even if it is not a whole department. In smaller companies, this function may be combined with another, provided it has real autonomy.
How to implement it in stages
With the elements gathered, implementation follows a natural order: it begins with the diagnosis and risk analysis, moves through the drafting of the policies and the code of conduct, installs the reporting channel, promotes training and rests on continuous monitoring, which reviews the program as the company changes. No stage needs to be grand; all need to be real. A small, effective program protects more than an extensive manual no one applies.
Compliance of large and small companies: the difference is proportion
Perhaps the greatest misunderstanding about the subject is to imagine that compliance is all or nothing. It is not. A ten-person company does not need, nor should it, replicate the structure of a listed company. It needs a program proportional to its concrete risk, one that protects it and qualifies it to contract without imposing a cost that is not justified. Calibrating that proportion, between the real risk and the mechanisms that address it, is what distinguishes a program that works from one that merely takes up space in a drawer.
Frequently asked questions
How the firm works on this subject
The need to start doing compliance usually translates into the following areas of legal work:
- Compliance consulting and preventive advisory: diagnosis, risk analysis and the design of a program proportional to the company's size.
- Drafting of legal documents: code of conduct, internal policies, the reporting-channel regulation and the program's other instruments.
- Consultative advisory: interpretation of the laws applicable to the sector and support for senior management in implementation and monitoring.
- Litigation: defense of the company when a deviation or a liability already presents itself.
It is with this set that Grisostolo Advocacia is concerned in matters of business compliance, always sized to the risk of each business.
Need to begin and do not know where?
If a client, a public tender or a bank has started requiring compliance from your company, it is possible to design a program proportional to your case. We can talk about the first step.
This text is informative in nature and does not constitute legal advice. The design of a compliance program depends on the analysis of the risk proper to each company.