New! AI Board Member: Walk into every meeting knowing nothing was missed. Request early accessarrow_forward
Diligent Logo
Diligent Logo
Products
arrow_drop_down
Solutions
arrow_drop_down
Resources
arrow_drop_down
Diligent AI

The role of the compliance department in entity management

August 7, 2026
8 min read
Compass that points to the word "compliance"

In this article

  • Intro
  • What is compliance in corporate culture, and why is it important?
  • What is the relationship between compliance enforcement and entity management?
  • What structures should an entity put in place for compliance?
  • How technology supports compliance across entities
  • FAQ
The Diligent team

The Diligent team

GRC trends and insights

A compliance department is the function responsible for making sure an organization meets its legal, regulatory and ethical obligations across every jurisdiction it operates in. Identifying risks, designing controls and monitoring adherence, often independently of the legal department. In the past, the core aspects of corporate governance related to government and regulatory authorities were subsumed under the activities of Legal departments or handled by the board or its subcommittees in an individualized or ad hoc manner.

However, the explosive financial scandals at Enron and WorldCom around the turn of the millennium, the Madoff crisis over a decade later, and the ensuing tightening up of regulatory authority through laws such as Dodd-Frank and Sarbanes-Oxley pushed corporate governance in the direction of a new and autonomous realm: compliance.

This post provides a practical introduction to the basics of compliance, its importance in contemporary enterprise, its relationship to the broader tasks of entity management and the possible structures enforcing compliance can take.

This article covers:

  • What compliance means in corporate culture and why it matters
  • How compliance relates to entity management
  • What structures organizations use to enforce compliance
  • How technology supports compliance across a multi-entity structure
  • Answers to common questions about the compliance function

What is compliance in corporate culture, and why is it important?

Compliance covers, most basically, the practices that allow an organization to measure itself by the standards of the law under regulatory regimes where it operates and to deter violations. Although it is in the last instance an imposition by the state and regulators that deter malfeasance through sanctions and penalties, the function of a compliance officer, department or practices is more proactive than simply making sure their organization stays clear of legal hurdles. Best compliance practice is a proactive approach that, at a basic level, involves fostering the mentality and culture that keep a company clear of not only applicable laws, rules and regulations, but also its own internal codes of conduct, procedures, policies and ethical standards.

The stakes behind that proactive posture keep rising. In the GC Risk Index 2026, Diligent Institute found that 67% of senior legal leaders say the time they spend on enterprise governance, risk and compliance has increased over the past year — a signal of how much more ground a compliance function is expected to cover than it was even a few years ago.

While the idea of complying with the law is, of course, not new to business, compliance as a function autonomous from the general counsel/legal department, and even from leadership, is a relatively recent development in corporate culture. Compliance departments will usually develop authority that goes beyond that of a general counsel, and in some cases beyond the board and investors themselves, to interface with government directly.

Put one way, while the role of a legal department is to tell leadership and senior management what it can do, a compliance department exists to tell them what they should do. Both perspectives need to exist and be in balance with each other. The most basic functions of such a department include:

  • Identifying the risks (legal and otherwise) that an organization faces in the course of affairs
  • Designing strategies and controls that protect the organization from those risks
  • Monitoring and reporting on the effectiveness of controls to leadership and regulators
  • Resolving difficulties in the processes of compliance as they occur
  • Advising the organization on rules, controls and standards overall

What is the relationship between compliance enforcement and entity management?

The larger and more complex the operations of the firm, particularly as it grows and establishes subsidiaries across different regulatory jurisdictions, the larger and more complex the operations of the firm, particularly as it grows and establishes subsidiaries across different regulatory jurisdictions, the greater the compliance risks and the more necessary it is to have established processes and internal specialization for enforcing compliance. Legislative instability is an unavoidable feature of the current business landscape. Shifts in trade policy, sanctions regimes and cross-border tax rules regularly force multinational organizations to re-examine the standards each entity operates under and to stand up new entities in new jurisdictions.

This makes it more important than ever that compliance standards are established appropriate to each jurisdiction a multinational organization operates within, and that these standards are internationally integrated to absorb the shocks that rapid shifts in economic policy in one country can produce in others.

What structures should an entity put in place for compliance?

Compliance authority that operates independently of business pressure is increasingly seen as essential in corporate culture, but the form this takes depends on the size and needs of each entity. TD Bank offers the clearest recent illustration of what happens without it. In October 2024, the bank pleaded guilty to Bank Secrecy Act and money laundering conspiracy charges and agreed to pay more than $1.8 billion, part of a roughly $3 billion resolution across four US regulators. Between January 2018 and April 2024 the bank left approximately $18.3 trillion in transaction activity unmonitored, and three money laundering networks moved more than $670 million through its accounts. Regulators found that leadership had chosen to underfund the anti-money laundering program while the business grew, even as internal auditors flagged the deficiencies for years. Anti-money laundering spending on the US program was lower in fiscal 2021 than in fiscal 2018, a period in which US assets rose 34%.

The TD Bank case underlines why a compliance function needs standing that does not depend on the goodwill of the executives it is meant to check. Independent authority means adequate resources, a reporting line that reaches the board directly and the ability to escalate without going through the business units under review. The structures that deliver this will always need to be tailored to the size and type of entity, as well as the regulatory landscape it operates within. Larger multinational organizations may find they need not only a compliance department but a Chief Compliance Officer who can work across legal exposure, data privacy, crisis management and IT failures. Smaller organizations may have different needs and capabilities.

How technology supports compliance across entities

Institutional change, like adapting to the compliance environment, can be difficult. But it doesn't have to be. The heaviest compliance burden in a multi-entity organization is keeping an accurate, current picture of every subsidiary: Who its directors are, what it's registered to do, which filings are due and in which jurisdiction. Diligent Entities, part of the Diligent One Platform, maintains that corporate record as a single source of truth across all of an organization's subsidiaries, joint ventures and other entities. It centralizes entity data, tracks compliance obligations and filing deadlines, generates the reports regulators and auditors ask for, and gives the compliance function the visibility it needs to enforce consistent standards across jurisdictions rather than chasing information held in scattered local systems.

FAQ

What does a compliance department do?

A compliance department makes sure an organization meets its legal, regulatory and ethical obligations. Its core work includes identifying the risks the organization faces, designing controls to manage them, monitoring how well those controls work, reporting to leadership and regulators and advising the business on rules and standards. Unlike a purely reactive function, a strong compliance department is proactive: Building a culture that keeps the organization clear of both external regulations and its own internal codes of conduct.

The simplest distinction is that a legal department advises leadership on what the organization can do, while a compliance department focuses on what it should do. Legal manages the organization's legal rights, obligations and disputes; compliance builds and monitors the systems that keep the organization within legal and ethical bounds day to day. In many organizations the compliance function is deliberately independent of legal so that it can raise concerns without conflict of interest.

Independence protects the integrity of the compliance function. When compliance reports through legal, there is a risk that potential violations get managed as legal exposures to be contained rather than problems to be surfaced and fixed. High-profile enforcement cases have shown how compliance concerns can be suppressed when the same function that should raise them also controls the legal response. An independent compliance department, often led by a Chief Compliance Officer, can escalate issues directly to the board.

How does compliance relate to entity management?

The more entities an organization operates, and the more jurisdictions they sit in, the more complex its compliance obligations become. Each subsidiary carries its own registration, filing and disclosure requirements. Entity management is how an organization keeps track of that structure, and it is foundational to compliance: a compliance department cannot enforce standards it cannot see. Accurate, centralized entity data is what allows compliance to apply consistent controls across a multi-entity, multi-jurisdiction organization.

Does a small company need a compliance department?

Not every organization needs a standalone compliance department, but every organization needs a compliance function. Smaller companies may assign compliance responsibilities to existing legal or finance staff rather than building a dedicated team. As an organization grows, adds subsidiaries or enters more heavily regulated markets, the case for a dedicated department, and eventually a Chief Compliance Officer, strengthens. The right structure depends on size, complexity and regulatory exposure.

Ready to give your compliance team a single source of truth across every entity? Book a demo to learn how Diligent Entities supports multi-entity compliance.