Skip to main content
Category: Regulatory Compliance

Non-Compliance

Also known as: Noncompliance, Non-compliance
Simply put

Non-compliance is the failure or refusal to follow a rule, law, regulation, or internal policy that applies to an organization or individual. It describes a state of not meeting a required standard, whether that failure is deliberate or unintentional. Non-compliance can lead to consequences that range from operational disruption to regulatory penalties, depending on the obligation involved.

Formal definition

Non-compliance refers to a condition in which the conduct, processes, products, or documentation of an organization or its personnel are not in accordance with applicable external laws and regulations or internal policies, standards, and procedures. In a GRC context, it is distinct from nonconformance, which more commonly denotes a failure to meet a specified requirement such as a quality standard or protocol, whereas non-compliance is typically framed against binding legal, regulatory, or policy obligations. The specific obligations, thresholds, and consequences vary by jurisdiction, sector, and organization, and identifying non-compliance is a compliance and management responsibility that may be evaluated separately by independent assurance functions. This entry addresses the concept only and does not cover remediation methods, penalty schedules, or legal advice.

Why it matters

Non-compliance matters because it exposes an organization to a spectrum of consequences that can extend well beyond a single failed requirement. Depending on the obligation involved, the effects may range from operational disruption to regulatory penalties. Some regulators and commentators note that non-compliance can, in severe cases, halt business operations, with associated revenue impact and longer-term competitive damage. Because the specific obligations, thresholds, and consequences vary by jurisdiction, sector, and organization, the significance of a given instance of non-compliance depends heavily on which rule, law, regulation, or policy has not been met.

Who it's relevant to

Compliance Officers
Compliance officers are typically responsible for mapping applicable external laws, regulations, and internal policies, and for identifying where conduct, processes, products, or documentation fall short of those obligations. Understanding the concept of non-compliance helps them frame findings against the correct binding requirement rather than a general quality expectation.
Risk and Operational Managers
Because non-compliance can disrupt operations and, in severe cases, halt business activity, managers responsible for day-to-day processes have a stake in recognizing and treating conditions that deviate from required standards. In many organizations, identifying and correcting non-compliance is a management responsibility that sits alongside broader risk considerations.
Internal Auditors and Assurance Functions
Independent assurance functions may evaluate the presence or handling of non-compliance separately from the management activities that identify it. Keeping this distinction clear supports the independence and objectivity expected of assurance work, so that the assessment of non-compliance remains separate from the processes being assessed.
Quality and Regulatory Specialists
Specialists working across quality and regulatory domains benefit from distinguishing non-compliance from nonconformance. Non-compliance is typically framed against binding legal, regulatory, or policy obligations, whereas nonconformance more commonly denotes a failure to meet a specified requirement such as a quality standard or protocol.

Inside Non-Compliance

Regulatory Non-Compliance
A failure to adhere to external laws, regulations, or supervisory requirements applicable to the organization, the scope of which typically depends on jurisdiction, industry, and organization size.
Policy Non-Compliance
A departure from an organization's own internal policies, standards, or procedures, distinct from breaches of external legal obligations though the two may overlap.
Breach Event
The identifiable act or omission that constitutes the deviation, which may be a single occurrence or a systemic pattern of recurring deviations.
Severity and Materiality
An assessment of the significance of the deviation, which commonly informs escalation, reporting, and remediation decisions; materiality thresholds vary by framework and context.
Root Cause
The underlying reason for the deviation, such as control failure, inadequate training, process gaps, or intentional circumvention, distinguished from the symptom itself.
Remediation and Corrective Action
Management activities intended to address the deviation and reduce the likelihood of recurrence; these are management responsibilities distinct from assurance functions that may identify or verify them.

Common questions

Answers to the questions practitioners most commonly ask about Non-Compliance.

Does non-compliance always mean the organization will face regulatory penalties?
No. Non-compliance refers to a failure to adhere to an applicable law, regulation, or internal policy, but it does not automatically result in penalties. Whether enforcement action or a penalty follows commonly depends on factors such as the jurisdiction, the nature and severity of the breach, whether it was self-reported, the applicable regulator's discretion, and any remediation undertaken. Some instances may result in no formal sanction, while others may attract significant consequences. The link between a compliance failure and its outcome is therefore contingent rather than certain.
Is non-compliance the same as a risk or a control failure?
Not exactly, though the concepts are related. Non-compliance is a compliance-pillar concept describing a state of non-adherence to a requirement. A control failure is a breakdown in a mechanism intended to prevent or detect such a state, and risk concerns the uncertainty of an adverse outcome against objectives. A control failure may lead to non-compliance, and non-compliance may represent a materialized compliance risk, but the terms are not interchangeable. Treating them as identical can obscure whether the issue lies in the requirement itself, the control designed to meet it, or the assessment of exposure.
How should an organization typically identify instances of non-compliance?
Organizations commonly identify non-compliance through a combination of monitoring, testing, and reporting mechanisms. These may include compliance monitoring activities carried out by a second-line function, control testing, internal audit reviews conducted by an independent third-line function, employee reporting channels such as whistleblowing lines, management self-assessments, and external notifications from regulators or third parties. The appropriate mix depends on the organization's size, sector, and regulatory context. This entry does not cover specific tooling or the design of individual monitoring programs.
What steps generally follow the detection of non-compliance?
Following detection, organizations typically assess the nature, scope, and root cause of the issue, contain any ongoing exposure, and determine what remediation is required. Depending on the requirement breached and the jurisdiction, obligations may include internal escalation, documentation, and in some cases notification to a regulator or affected parties. The response is generally coordinated between management, which owns the remediation, and compliance or assurance functions, which may assess adequacy. Specific legal obligations vary by jurisdiction and sector, and this entry is not a substitute for legal advice.
Who is responsible for addressing non-compliance within an organization?
Responsibility is commonly allocated across the three lines model described by the IIA. Management, as the first line, typically owns the process or activity where the non-compliance arose and is responsible for remediation. The compliance function, often part of the second line, generally provides oversight, guidance, and monitoring. Internal audit, as an independent third line, may provide assurance over how non-compliance is identified and managed but does not own the remediation, preserving its independence. The precise allocation varies by organizational structure and governance model.
How is the significance of a non-compliance instance typically evaluated?
Significance is generally assessed by considering factors such as the importance of the requirement breached, the potential or actual impact, the likelihood of recurrence, whether the issue is isolated or systemic, and the applicable regulatory expectations. Many organizations use severity or materiality criteria to prioritize response and determine escalation and reporting thresholds. These criteria commonly reflect the organization's risk appetite and tolerance as well as jurisdictional and sectoral requirements, and they can differ substantially between organizations.

Common misconceptions

Non-compliance always refers to breaking a law or regulation.
Non-compliance encompasses deviations from both external legal or regulatory obligations and internal policies, standards, and procedures. A failure to follow an internal standard may be non-compliance even where no law has been broken.
Identifying non-compliance is the job of the audit or assurance function that reports it.
Detecting and reporting a deviation is an assurance or oversight activity, but remediating it is a management responsibility. Independent assurance functions maintain objectivity by not owning the controls or corrective actions they evaluate.
Any instance of non-compliance is equally serious and triggers the same response.
Responses commonly depend on the severity, materiality, and root cause of the deviation. Escalation, reporting obligations, and remediation typically scale with significance, and applicable thresholds may differ across jurisdictions, sectors, and frameworks.

Best practices

Classify each identified deviation as regulatory, policy-based, or both, since remediation paths and reporting obligations may differ.
Assess severity and materiality consistently to inform proportionate escalation and reporting decisions.
Investigate and document the root cause rather than treating only the visible symptom, to reduce the likelihood of recurrence.
Assign remediation and corrective action to accountable management owners, keeping this distinct from the assurance functions that detect or verify the deviation.
Confirm applicable reporting obligations against the relevant jurisdiction, industry, and organization size before assuming a requirement applies.
Maintain records of deviations, decisions, and remediation to support oversight, trend analysis, and independent review.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.