Regulatory Governance & Compliance Oversight · Compliance Governance Systems & Operational Architecture

Internal Compliance Audit & Periodic Risk Review.

The point of a periodic review is to find the gap before a regulator, an auditor, or an acquirer does.

A compliance function that has run cleanly for years is the one most exposed to a quiet drift — an event filing missed in a busy quarter, a register left un-updated after a board change, a registration that lapsed when the person who owned it left. Nothing fails loudly; the gap simply sits there until something forces it into view.

A periodic compliance review exists to surface that drift on the company’s own terms, while it is still cheap to correct, rather than under the pressure of a notice or a diligence exercise. This page sets out how the firm scopes and runs that review as a preventive governance discipline — not an audit checklist.

The Framework

How We Scope a Compliance Review.

A useful review is not a re-run of the statutory audit, and it is not a checklist applied uniformly to every obligation. It is a risk-led exercise that concentrates effort where exposure actually concentrates — the event-driven filings, the lapsed-ownership gaps, and the areas where a prior corrective action was promised but never closed.

The discipline is to start from the signals that predict where a system has drifted, scope the review against those, and end with a corrective plan that has named owners and dates rather than a list of findings. We frame the work against four questions, each defining one stage of a review built to prevent, not merely to document.

  • Risk signals Where the indicators — staff turnover, recent board or capital changes, a fast-growing entity count — suggest a control is most likely to have slipped.
  • Scoped depth Concentrating the review on high-exposure obligations rather than applying uniform checklist coverage to areas that carry little risk.
  • Gap identification Distinguishing a genuine compliance gap that creates exposure from a documentation gap that merely needs tidying.
  • Corrective ownership Whether each finding closes with a named owner, a remediation step, and a date — not a finding that re-appears in the next review.
The Analysis

A Preventive Review, Not a Post-Mortem.

The decision that defines this page is when and how to look — whether the company examines itself on its own schedule or waits until an external event examines it. That distinction is set out below.

01

From Risk Signal to Corrective Plan

A preventive review begins from signals, not from a fixed list. Certain events reliably precede a compliance gap — a change in directors or KMP, a capital raise, a new registration or regulator, a period of high turnover in the compliance team — and a review timed to follow them catches the drift those events tend to cause.

The scope then follows the exposure. Annual filings under the Companies Act 2013 tend to run on a calendar and rarely slip; the failures cluster in event-driven obligations that have no fixed date — a charge satisfaction, an allotment return, a director-change filing — and in the statutory registers that quietly fall out of step with what actually happened. A risk-led scope spends its effort there.

Gap identification is where judgment matters most. The review separates a documentation gap that can be closed by tidying the record from a substantive default that has already crystallised exposure for the company or its officers, because the two demand very different responses — and conflating them either wastes effort or understates a real risk.

The output is a corrective plan, not a findings memo. Each gap is assigned an owner, a remediation step, and a date, so the review closes the loop rather than handing the board a longer list of things to worry about. A review that ends in a list, not a plan, simply documents the drift it was meant to reverse.

Structural Implications

What a Periodic Review Sets in Motion.

Running the review on the company’s own schedule changes its position in three material ways:

01

Exposure Found Early

Gaps surface while remediation is still cheap and discretionary, rather than after a notice has fixed the cost and the timeline.

02

Diligence Readiness

A company that audits itself regularly enters a transaction with a clean, defensible record rather than a remediation project that re-prices the deal.

03

Demonstrated Oversight

A documented review cycle is itself evidence that the board exercised preventive oversight, which matters when officer conduct is examined after a default.