Free Cybersecurity Webinar Series: Expert insights on AI, cybersecurity, compliance, and emerging tech. Register today.
Home / Blog / Compliance
September 2, 2026 by Leigh Anne Elliott
Many organizations spend significant time focusing on compliance requirements, but far fewer take the opportunity to benchmark their programs against their peers. Understanding how other organization’s structure, resource and evaluate compliance can provide valuable insight into areas of strength as well as opportunities for improvement.
FoxPointe Solutions, a division of The Bonadio Group, recently conducted and reviewed the results of a national survey of more than 100 compliance professionals across a variety of industries. While every organization faces unique risks and regulatory expectations, several common themes emerged that compliance leaders should consider when evaluating their own programs.
One of the most encouraging findings from the survey is that compliance is increasingly viewed as a strategic business function, rather than simply a regulatory requirement. Nearly 79% of respondents reported that compliance is involved in organizational strategic planning, while more than 84% indicated that their compliance programs extend beyond a single department and incorporate functions such as risk management, internal audit, or quality oversight.
This represents an important shift. As organizations face evolving regulatory requirements, cybersecurity threats, vendor risks, and operational challenges, effective compliance can no longer operate in a silo. Organizations that integrate compliance into broader governance and risk management discussions are often better positioned to identify emerging risks before they become significant issues.
Despite growing recognition of compliance’s importance, many organizations continue to struggle with staffing and resources.
More than one quarter of survey respondents reported that they do not have adequate resources to carry out their compliance responsibilities effectively. Nearly one third indicated that their compliance programs lack sufficient staffing. At the same time, almost 90% of compliance officers reported having responsibilities outside of compliance.
These findings highlight a challenge faced by organizations of all sizes: expectations continue to expand, but resources often do not keep pace. Compliance leaders are increasingly expected to oversee risk management, investigations, training, policy management, data privacy, cybersecurity coordinator, vendor oversight and other functions, all while maintaining day-to-day compliance.
The question organizations should ask is simple: Does your compliance tram have the capacity to address today’s risks, or are they constantly reacting to yesterday’s issues?
A strong compliance program begins with understanding where the organizations greatest risks exist.
The survey found that nearly 84% of organization conduct an annual risk-assessment, and an impressive 97% perform auditing and monitoring activities based on identified risks.
This trend reflects a growing recognition that risk-based compliance is more effective than attempting to monitor everything equally. Organizations that regularly assess regulatory, operational, technology and cyber security risks can focus their resources where they will have the greatest impact.
For many organizations, risk assessments also serve as a valuable bridge between compliance, information security, internal audit and executive leadership teams.
Another notable trend is the growing use of data analytics to evaluate compliance effectiveness. Nearly two thirds of respondents reported using data analytics within their compliance programs.
As organizations generate more operational and technology-related data than ever before, analytics can help identify anomalies, monitor trends, detect emerging concerns, and measure the effectiveness of controls in real time.
This is especially important as organizations continue to navigate increasingly complex cybersecurity, privacy and regulatory environments. Data-driven compliance programs are often better equipped to identify risks earlier and respond more efficiently than organizations relying solely on manual processes.
While many compliance programs are becoming more mature, succession planning remains an area of concern.
Only about 38% of respondents reported having a succession plan in place for the compliance function.
Organizations frequently invest substantial effort into developing compliance processes, institutional knowledge, and relationships with regulators, auditors and leadership teams. Without a succession strategy, much of that knowledge can be difficult to replace when personnel leave.
As compliance programs grow in complexity, leadership continuity should be considered part of overall risk management planning.
The survey results reveal a profession that continues to evolve. Compliance is becoming more strategic, more data-driven, and more integrated with organizational governance. At the same time, many organizations still face challenges related to staffing, resources, and long-term sustainability.
Whether your organization is focused on regulatory compliance, cybersecurity, risk management, or all three, benchmarking can provide valuable perspective. Understanding how your program compares to peers can help identify gaps, validate strengths, and inform future investments.
At FoxPointe Solutions, a division of The Bonadio Group, we help organizations assess risk, strengthen compliance programs, enhance cybersecurity readiness, and build governance frameworks that support long-term success. If you’re wondering how your program measures up, now may be the perfect time to take a closer look.
The real question isn’t whether you have a compliance program. It’s whether your compliance program keeps pace with the risks your organization faces today.
This material has been prepared for general, informational purposes only and is not intended to provide, and should not be relied on for, tax, legal or accounting advice. Should you require any such advice, please contact us directly. The information contained herein does not create, and your review or use of the information does not constitute, an accountant-client relationship.