csrdcompliance Put me on the waitlist

Kennisbank

Who should be the owner of an obligation

An obligation without an owner is not an obligation, it is a risk that no one has yet noticed. Yet this is the question on which many files get stuck: not which rules apply, but who within the organization is responsible for demonstrating that something is being done about it. This is one of the core questions that the Compliance Check answers per obligation, alongside the question of what evidence is needed and which control belongs with it.

Why ownership does not arise on its own

In practice, an obligation is often assigned based on who stumbles across it first. The lawyer who reads the article becomes the owner. The controller who compiles the report becomes the owner. That works until the moment accountability must be given, and it turns out that no one has an overview of exactly what has been committed to and on the basis of which evidence.

Ownership that arises by chance is not ownership that a board can explain. The question the Compliance Check asks is therefore not who currently deals with it, but who has the authority, the overview, and the responsibility to carry the obligation, including the evidence that belongs with it.

Three characteristics of an owner

An owner of an obligation is not by definition the person who does the work. There are three characteristics that together determine whether ownership sits in the right place.

First: the owner can explain the obligation without falling back on an external party. If only an advisor can reconstruct why a particular rule does or does not apply, ownership effectively lies outside the organization.

Second: the owner has access to the evidence, or the authority to request it. An owner who does not know where the underlying documentation is located is an owner in name, not in practice.

Third: the owner is the person who is held accountable when the control does not work. This is often the point where things go wrong: the name on the overview is not the same person who gives account as soon as something is tested.

What the method does not solve here

The Compliance Check does not appoint an owner. That is something an instrument cannot do, and it should not. Who within an organization has the authority and the capacity to carry an obligation is an organizational question, not a legal or technical one. The method records which obligation requires ownership, which evidence fits it, and which control makes it demonstrable that it works. Who fills that role remains a decision for the organization itself.

This is also where the method has limits worth naming. The Compliance Check does not address whether an officer has sufficient seniority, or whether a team has sufficient capacity to fulfil the role. Those questions lie outside the scope of an overview that links obligations to evidence and control.

Ownership varies by country

An added complication is that ownership is not filled in the same way everywhere. A European rule may fall to the finance function in one country and to legal affairs in another, simply because the national implementation places a different emphasis there. This is one of the points where national headlines are structurally underestimated: how you keep track of this per country without ending up in a subscription jungle is a question that plays out differently per organization, depending on how many jurisdictions are relevant.

Why this is more than filling in a name

The difference between a report and a working overview lies precisely here. A report lists obligations. An overview that is usable for a board links an owner, a form of evidence, and a control to each obligation, and makes visible where those three do not align. Why that requires a different approach than delivering a report is further explained on the page about why a compliance check is something other than a report.

The question of who should be the owner is also connected to what exactly is asked when a third party tests the file. An assurance statement does not only ask for a name attached to an obligation, but for a trail showing that this name was actually able to verify that the control worked. What an assurance statement requires from a file is described on the page what an assurance statement requires from your file.

And finally: ownership that is absent has a cost, even if it has not yet materialized. What it costs not to know which regime an organization falls under, and therefore also not to know who should be responsible for what, is addressed on the page what it costs not to know which regime you fall under.

The tool is under construction

The Compliance Check currently exists as a method: a way of linking obligations to owner, evidence, and control. The tool that does this automatically and continuously is still in development. Those who want to work with this already can sign up for the waiting list; nothing is offered that does not yet exist.

The next question that arises

Once it is clear who should be the owner of an obligation, the question naturally follows of how much time that owner spends on it, and which part of that work is repeatable enough to organize differently. FTE TO AI offers a work scan for this, which calculates per task which part of the work can be taken over by AI, so that ownership does not automatically mean that someone keeps manually gathering evidence for obligations that can by now be well structured.

Alpha 60de assistent van de Compliance Check

Vraag maar welke verplichting op u van toepassing is, en waaraan u dat kunt aantonen.

Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.