Global Advice Network
| Borgergade 111 | DK - 1300 Copenhagen K
|
|
|
|
Building a Compliance Committee That Works in an Australian SMEFor many Australian small and medium enterprises, the idea of standing up a compliance committee sounds like something reserved for the big end of town. The boardroom of a Melbourne-listed mining company or a Sydney-based financial services group is where most people picture these committees sitting. Yet the reality on the ground is that SMEs are increasingly expected to have structured oversight of their anti-corruption, modern slavery and regulatory obligations. Whether you operate as a family-run Pty Ltd in Brisbane or a fast-scaling tech start-up in Perth, the expectation from regulators, banks and overseas partners is the same: you need to show that compliance is not just a folder in the bottom drawer. The good news is that a compliance committee does not need to be a six-person board with external counsel on speed dial. It can be lean, practical and tailored to the size of the business. What matters is that it has clear responsibilities, documented procedures and the authority to act when something goes wrong. The guidance below walks through how to set one up, how to keep it running effectively, and how to make sure it actually adds value rather than becoming another layer of bureaucracy. Mapping the legal and regulatory landscape you actually operate inBefore pulling a committee together, it pays to be clear about what laws and regulators apply to the business. In Australia, the two pieces of legislation that bite hardest for SMEs are the foreign bribery provisions in Division 137 of the Criminal Code Act 1995 and the Modern Slavery Act 2018. If the company exports goods, has overseas suppliers or works with government clients, the bribery offences are particularly relevant. ASIC also plays a role for any business operating in financial services or those that are required to lodge corporate reports, and the ATO keeps a close eye on record-keeping and taxable transactions. A useful starting exercise is to sit down with the leadership team and list every regulator the business touches. For a mid-sized manufacturer in Adelaide, that might include SafeWork SA, the Department of Home Affairs (for visas and skilled migration), ASIC and the ATO. For a consultancy in Canberra, it could be the National Anti-Corruption Commission if the business is bidding for federal contracts. Knowing the field of play makes it far easier to design a committee whose remit matches the risk profile. For SMEs with international exposure, regulators in trading partner countries add another layer. A business exporting processed food into Jakarta or industrial parts into Frankfurt needs to understand the local anti-bribery rules there too. Reviewing country risk profiles before signing distribution agreements is a sensible habit, particularly when working through agents or local intermediaries. Defining the scope and authority of the committeeA committee without a charter is just a chat over coffee. The charter should spell out, in plain English, what the committee is expected to do. Typical responsibilities include reviewing the company's anti-corruption policy, monitoring training completion, investigating reported concerns, overseeing due diligence on third parties, and reporting to the CEO or board on emerging risks. The charter should also be clear about what the committee is not responsible for, to avoid overlap with finance, HR or legal functions. Authority matters just as much as scope. The committee needs to be able to ask questions, request documents, recommend changes to policies and, where warranted, escalate serious concerns to senior leadership or external authorities. Without that authority, members will find their recommendations ignored or watered down. In an Australian SME, this often means the committee reports directly to the managing director or, where one exists, a non-executive director who can act as a sounding board. It is also worth being realistic about how often the committee needs to meet. Quarterly meetings work for most small businesses, with ad-hoc sessions scheduled when a red flag emerges. Documenting meeting minutes, even briefly, creates an audit trail that can be useful if ASIC or the NACC come knocking. Choosing the right members for a small committeeIn a large organisation, a compliance committee might include a chief risk officer, a general counsel, an internal auditor and an external ethics adviser. An SME rarely has those roles, so the committee needs to be assembled from the people who are already in the building. A typical structure might be the chief financial officer, the operations manager, the HR lead and the company secretary or office manager. One of these people should be designated as the compliance lead, with clear accountability for the committee's work. Independence is the piece that often gets missed. If every committee member also reports to the same general manager, there is a real risk of groupthink or, worse, a reluctance to raise concerns about the boss. Where possible, include someone who is not in the direct reporting line of the people whose decisions the committee is reviewing. In a family-owned business, this might mean bringing in an external adviser or a trusted mentor from outside the family. Australian SMEs often underestimate how much credibility an independent voice brings when tough decisions need to be made. Cultural fit also matters. The committee will spend time asking awkward questions about expenses, gifts and supplier relationships. Members need to be comfortable doing that without becoming the person nobody wants to have a beer with at the end of the week. A balance of curiosity, scepticism and collegiality tends to work best. Running meetings that produce outcomes, not paperworkThe single biggest reason compliance committees fail is that they become talking shops. The agenda is broad, the discussion drifts, and the meeting ends without clear actions. A practical approach is to keep agendas tight and to focus each session on one or two substantive items, such as reviewing a recent incident, approving an updated policy, or examining the due diligence file for a new overseas partner. Standing items like training compliance and whistleblower reports can be handled quickly as a checklist at the start. Minutes should record what was discussed, what was decided, who is responsible for the next step, and by when. This is where documentation practices become genuinely useful. When an inspector arrives, the committee will be able to pull together a clear narrative of what it reviewed, when, and what action it took. That kind of paper trail turns a stressful inspection into a manageable one. It is also worth thinking about who chairs the meetings. A rotating chair can spread the load and give different members exposure to the role, but it can also lead to inconsistent follow-through. In most Australian SMEs, having the chief financial officer or the compliance lead chair the meetings provides continuity and ensures that finance, operations and risk views are brought together. Building the policies and procedures the committee will overseeA committee cannot operate effectively if the underlying policies are out of date or written in legal jargon nobody reads. The anti-corruption policy, gifts and hospitality register, whistleblower procedure and third-party due diligence checklist all need to be reviewed and refreshed. For SMEs that are acquiring or merging with other businesses, due diligence becomes even more important, and a pre-acquisition checklist helps the committee work through the inherited risks before they become the new owner's problem. Training is the other piece of the puzzle. Mandatory annual anti-corruption training is common, but the completion rate in many SMEs hovers around 60 per cent. The committee should set a target, monitor it quarterly and follow up with people who have not completed the modules. Short, scenario-based training tends to land better in Australia than long, lecture-style sessions. People are more likely to remember a five-minute case study about a fake invoice scam than a 45-minute walkthrough of the Criminal Code. Growing the committee as the business growsThe committee that works for a 25-person business in Hobart will not work for the same business once it has 150 staff and offices in three states. Building in a regular review of the committee's structure, charter and membership is therefore essential. Some Australian SMEs choose to add an external member once they cross a certain headcount, particularly if they are pursuing larger contracts or planning an IPO. Others introduce sub-committees to handle specific risks, such as a modern slavery working group or a cybersecurity oversight group. International expansion also changes the picture. A business that opens a sales office in Manila or a warehouse in Rotterdam inherits the compliance expectations of those jurisdictions. The committee should treat each new market as a trigger to revisit its risk assessment, refresh its training materials and confirm that local managers understand the reporting lines back to Australia. A simple rule of thumb is that any new country, new entity or new product line deserves a committee discussion before launch. Key elements of an effective SME compliance committee include:
A compliance committee is ultimately a tool, not a destination. It works when it reflects the actual risks the business faces, when its members take the role seriously and when senior leadership backs the committee when difficult calls need to be made. Australian SMEs that treat compliance as part of how they do business, rather than as a box-ticking exercise, will find that their committee becomes a source of genuine competitive advantage. Banks, insurers and overseas partners will take them more seriously, and the business will be in a stronger position when the unexpected happens. |