Risk Attribute

Compliance and Governance Programme

Expert-reviewed Updated: 2026-09-03 Expert-reviewed: 2026-09-04 (Guido Hesse, Hesse Group Holding AG) Version 0.1.0

Compliance and governance programme records whether the applicant maintains a formal, documented compliance function and governance framework, as queried in directors' and officers' liability proposal forms.

Category
Finance/Governance
Data type
Yes/No
Risk drivers
Frequency, Moral hazard
Underwriting impact
Premium, Condition/Warranty, Exclusion

Typical proposal-form questions

  • Does the company maintain a formal compliance function or compliance management system, and to whom does it report?
  • Are there documented policies covering anti-bribery, competition law, data protection and whistleblowing?
  • When was the compliance programme last independently reviewed or audited?

Evidence

  • Compliance policy manual
  • Internal audit or compliance review report
  • Organisational chart showing compliance reporting lines

Why it matters for underwriting

A formal compliance and governance programme is a direct proxy for the likelihood that regulatory breaches, bribery, competition law violations or other misconduct will occur and escalate into a D&O claim. Underwriters view a documented, independently reviewed programme as evidence that management has built structural safeguards against moral hazard, rather than relying on individual judgement alone.

Capturing the attribute and evidence

Proposal forms ask whether a formal compliance function exists, to whom it reports, and whether documented policies cover core areas such as anti-bribery, competition law, data protection and whistleblowing. Underwriters request the compliance policy manual, any internal audit or review reports, and an organisational chart showing the reporting lines, to confirm the programme is genuinely embedded rather than existing only on paper.

Effect on coverage, premium and conditions

A robust, independently reviewed compliance programme supports standard or preferred pricing and fewer specific conditions. The absence of a formal programme, or reliance on informal, undocumented practices, typically results in premium loadings, conditions requiring minimum compliance standards during the policy period, or exclusions targeting known areas of weakness such as third-party due diligence.

Mitigation measures

Establishing a documented compliance function with clear reporting lines into senior management or the board, covering core risk areas with written policies, and subjecting the programme to periodic independent review are the primary mitigation steps. Regular staff training, a functioning whistleblowing channel, and prompt remediation of review findings further demonstrate an actively maintained programme.

Standards and codes

  • ISO 31000:2018 – Risk management, Guidelines