Compliance is not a folder of policies. It is the operating discipline that connects each important legal obligation to a responsible person, a working control, evidence of performance and a route for escalation.

Make compliance provable

If the business cannot show who owned a duty, what control operated and what happened after a warning, it cannot confidently demonstrate that its programme worked.

01

Start with the business’s real risk

Map the entity, ownership, products, premises, employees, customers, data, payments, suppliers, environmental impact and regulated activities. Then assess the likelihood and consequence of failure rather than treating every rule as equally urgent.

Authority

Company records, licences, approvals and reporting.

Conduct

Bribery, competition, consumer treatment and conflicts.

Operations

People, safety, environment, products and premises.

Information

Privacy, cybersecurity, records and confidentiality.

Prioritise duties that can cause injury, licence loss, criminal exposure, major financial loss or loss of trust. Record why the risk rating and response are proportionate.

02

Build one authoritative legal register

List each applicable law, regulation, licence condition, regulator direction, contractual compliance duty and internal commitment. For every obligation, state the business process, owner, frequency, evidence, escalation route and review date.

Avoid generic checklists copied from another company. Applicability depends on sector, county, size, transactions and operating model. Link the register to corporate filings, tax, employment, data, safety, environment, standards, consumer protection and specialist licensing.

Use primary sources and preserve the version relied on. A regulator’s summary is useful guidance, but the underlying law and licence conditions determine the obligation.

03

Leadership must own the system

The board and senior management should approve the compliance framework, set risk appetite, allocate resources and receive meaningful reports. Operational managers own compliance in their processes; legal or compliance functions advise, challenge and monitor rather than performing every control themselves.

Define reserved decisions, delegations and escalation thresholds. Ensure the person overseeing compliance has access to records and a route to independent leadership when the concern involves management.

BoardOversight, risk appetite, resources and accountability.

ManagementImplementation, culture and corrective action.

Control ownersDaily execution and reliable evidence.

AssuranceIndependent testing, challenge and reporting.

04

Turn obligations into workable controls

Use concise policies supported by procedures, approval thresholds, system restrictions, reconciliations, checklists and recordkeeping. Design controls around how work actually happens, including mobile communication, remote teams and urgent commercial decisions.

Kenya’s Bribery Act is one example of law that makes prevention procedures material. Controls may cover gifts, hospitality, facilitation demands, political or charitable contributions, conflicts, intermediaries and confidential reporting.

Document exceptions. A control routinely bypassed for senior or high-revenue staff teaches the organisation that commercial pressure outranks the rule.

05

Manage risk beyond the company boundary

Agents, distributors, consultants, suppliers, joint-venture partners and outsourced processors can create legal and reputational exposure. Apply risk-based due diligence before appointment and at renewal.

Verify identity, ownership, competence, licences, sanctions or debarment indicators, adverse information, conflicts, remuneration and reason for engagement. Higher-risk arrangements need stronger approvals, contract clauses, audit rights, training and monitoring.

Do not treat a signed questionnaire as proof. Test unexplained commissions, cash requests, offshore payments, vague services, government connections and reluctance to disclose beneficial owners.

06

Train people to recognise and report risk

Training should be role-specific and practical. Directors, sales teams, procurement, HR, finance, drivers, factory staff and data teams face different decisions. Use realistic scenarios and test comprehension.

Provide safe channels for employees and relevant outsiders to raise concerns, including alternatives when line management is implicated. Explain confidentiality, protection against retaliation, triage and expected response times.

Measure more than attendance. Test whether staff can recognise warning signs, locate the procedure, refuse prohibited conduct and escalate promptly.

07

Monitor controls and indicators

Use operational data to identify late filings, expired permits, unusual payments, repeat safety incidents, unresolved complaints, access anomalies, failed supplier checks and overdue corrective actions. Report trends and root causes, not only raw counts.

Periodic testing should confirm that controls operate in practice and records are reliable. Higher-risk areas may need independent audit or specialist review. Track recommendations to verified closure.

Absence of reported problems is not proof of effective compliance. It may signal weak detection, fear of speaking up or a channel employees do not trust.

08

Respond to suspected breaches with discipline

Protect people, stop continuing harm and preserve documents, devices and system records. Limit disclosure to those who need to know and obtain advice on privilege, employment fairness, reporting duties and engagement with regulators or law enforcement.

Set an investigation scope, independent decision-maker, evidence plan and timeline. Interview fairly, test exculpatory as well as adverse evidence, maintain confidentiality and document findings against an appropriate standard.

Remediation should address root cause: control design, incentives, supervision, access, vendors, training or leadership. Apply consequences consistently and verify that corrective actions work.

09

Keep the programme aligned with change

Monitor legislation, gazettes, regulator publications, court decisions and county rules. Assign subject owners to assess relevance and translate developments into revised controls, training and records.

Trigger compliance review when the business enters a county, launches a product, changes ownership, adopts new technology, collects new data, hires foreign staff, imports goods, acquires a company or changes a material supplier.

Review the whole programme periodically against incidents, near misses, audit findings and business strategy. Retire obsolete controls so the system remains usable.

COMPLIANCE CHECKLIST

From legal duties to reliable conduct

  1. Map the business and prioritise material risks.
  2. Create an obligation register from primary sources.
  3. Assign board oversight and operational owners.
  4. Design proportionate policies, procedures and evidence.
  5. Screen and monitor higher-risk third parties.
  6. Train each role on the decisions it actually faces.
  7. Provide trusted reporting and anti-retaliation channels.
  8. Test controls and report trends to leadership.
  9. Investigate fairly and remediate root causes.
  10. Update the programme whenever law or business changes.

COMPLIANCE IS A MANAGEMENT SYSTEM

Know the duty. Own the control. Keep the evidence.

A credible programme makes lawful conduct easier, warning signs visible and correction faster.
Find compliance counsel

FAQ

Frequently asked questions

What is a business compliance programme?

It is the coordinated system used to identify legal obligations, assess risk, assign responsibility, implement controls, train people, monitor performance, investigate concerns and correct failures.

Does a small Kenyan business need a compliance officer?

Not every business must appoint a person with that title. The required structure depends on sector and law, but every business should assign clear responsibility for its material obligations and ensure independent escalation to leadership.

How often should a compliance register be updated?

Review it on a planned cycle and whenever the business, law or operating environment changes—for example, a new product, county, licence, investor, data use, supplier or regulatory notice.

Can policies protect a company if employees break the law?

Policies alone are not enough. A credible programme requires leadership, proportionate procedures, communication, training, monitoring, reporting, investigation and consistent enforcement supported by records.

What should happen after a compliance breach?

Protect people and evidence, stop continuing harm, escalate internally, assess notification duties and privilege, investigate fairly, remediate root causes and document decisions. Obtain specialist advice where exposure is material.

OFFICIAL SOURCES

Read key parts of Kenya’s compliance framework

Legal-information notice: This guide provides general information, not legal, regulatory, audit or investigative advice. Obligations depend on the business, sector, county and date. Confirm current requirements and obtain specialist advice for material risks or incidents.