Judged by how they operate
Prosecutors and regulators reviewing a company after misconduct tend to ask whether its compliance systems worked in practice, not merely whether policies existed. They look for evidence that concerns can be raised without retaliation and that reports lead somewhere. A system that exists only as documents, with no data showing that anyone used it, is usually given little weight. The same question comes up in acquisitions, lender diligence, and government contracting, where a counterparty wants proof rather than a binder. Discipline applied unevenly, with senior people treated more gently, is one of the patterns reviewers notice quickly.
The working parts
In practice, the working parts are a reporting channel people trust and a disciplined path from intake to investigation, alongside controls built into payment and approval workflows. Training lands better when it is aimed at the roles with real exposure rather than delivered identically to everyone. Measurement matters as much as the controls: how many reports came in, how long investigations took, what was found, and what changed as a result. Agents, distributors, and other third parties acting for the company need their own layer of diligence and monitoring. Smaller companies can scale all of this down sensibly, since the test is proportionality rather than size.
Testing what you have
We are often asked to look at a compliance program before an acquisition, after an internal complaint, or ahead of a regulator's visit. We start by tracing a few real matters through the system from first report to final action, which shows quickly where it works and where it stalls. We also review whether the people running compliance have enough authority and access to data. Findings are framed as a prioritized set of fixes, and where the review touches possible misconduct, we discuss how to structure the work so the company understands how privilege may or may not apply.