An effective compliance programme reduces the chance of misconduct and, when misconduct happens anyway, materially affects how the company is treated. The assessment is usually framed around three questions.

Is it well designed? Grounded in a real risk assessment of this business, not a template. Policies that address the risks the company actually has, in language its people can follow. Training targeted at the roles that face the risk. Due diligence on third parties, which is where a large share of exposure sits.

Is it applied earnestly and in good faith? Adequately resourced and staffed. Compliance with genuine autonomy and access to the board. Discipline applied consistently — including to senior people, which is the test everyone watches. Incentives that do not reward the behaviour the policy prohibits.

Does it work in practice? Evidence of continuous improvement, testing and review. A reporting channel people actually use, and evidence that reports are investigated and acted on. Root-cause analysis after incidents, not just remediation of the specific event.

The recurring failure is the gap between the written programme and the operating reality. A policy nobody follows is worse than no policy, because it establishes what the company knew it should be doing.