How to Build and Run a Compliance Training Programme
Most guidance on compliance programmes is a list of components. Risk assessment, policies, training, a reporting channel, monitoring, review. All correct, all useless to the person who actually has the job, because a list does not tell you what to do on Monday.
This is written for that person: someone who has just taken responsibility for compliance at an organisation that has grown past the point where informal management works, who has other duties as well, and who needs a defensible position within a year rather than a perfect one within three.
It is sequenced deliberately. The order matters more than the completeness.
The Nordic version of this problem
Nordic companies internationalise early and at small scale. A 300-person Finnish manufacturer with sales entities in Sweden, Norway and Germany has the compliance complexity of an organisation several times its size and a compliance function that is one person at 60 percent of their time.
That is the constraint the whole plan has to respect. Ambition needs to be spent where exposure actually is, and the honest answer is that a small Nordic group cannot do everything a large multinational does and should not try.
Days 1–30
First thirty days: find out what is actually true
Resist the urge to buy training in month one. You do not yet know what you need, and a course catalogue purchased early becomes the thing your programme is built around, which inverts the logic.
Map the legal entities. Every entity, its country, its headcount, what it does. This sounds trivial and it is where the surprises are. Thresholds are national and per entity: whistleblowing routines are required from five employees in Norway against fifty in Finland and Sweden, and small subsidiaries in the wrong country are the most common compliance gap in Nordic groups.
Inventory what exists. Policies, courses, the reporting channel, past training records, any risk assessment. Note what is current, what is signed but unread, and what exists only as a file nobody has opened since 2021.
Interview, do not survey. Talk to twelve people across sales, procurement, HR, finance and operations, in different countries. Ask what they actually do, what makes them uneasy, and what they think the rules are. You will learn more in twelve conversations than in any document review, and you will find out which policies people have never heard of.
Establish who owns it. Get written confirmation of who is accountable at board level and what your mandate is. Programmes without a named executive owner stall in month seven.
By day thirty you should be able to state, in one page, what the organisation is exposed to and what is currently in place.
First quarter
First quarter: assess, then design
Run the risk assessment. Not an elaborate one. For each obligation area that plausibly applies, ask what could go wrong, who could cause it, how likely it is given how you actually operate, and how bad it would be. Score it roughly and consistently rather than precisely.
Score by activity rather than by job title. Nordic organisations are flat and job scopes are broad, so a title tells you much less about exposure here than it does in more hierarchical structures. A single person in a forty-person subsidiary may hold three exposed activities at once.
Write down what you decided not to do. This is the most important paragraph in this article. Risk-based programmes are defensible, but only where the negative decisions are documented. The exposure is never the training you delivered; it is the group you decided to leave out and cannot explain.
Build the training matrix. Role by course by depth, with a country axis, because the same role can require different training in Finland and Sweden. Cyber security training obligations differ between the two, and workplace conduct duties differ again.
Decide the language position. Which languages, for which roles, based on workforce composition rather than country list. Do this now, because it drives procurement.
Then choose a platform or provider, with the matrix in hand. You will ask better questions and buy less.
First year
First year: deliver, measure, review
Sequence the rollout by risk, not by convenience. Deliver to the highest-exposure groups first, even though they are the hardest to schedule, because delivering to the easy population first produces good completion statistics and no risk reduction.
Handle consultation early. Introducing mandatory training that creates new employee obligations engages co-operation obligations in Finland and co-determination practice in Sweden. Groups that treat this as a formality at the end of the project lose weeks. Bringing employee representatives in at design stage costs almost nothing and usually improves the programme.
Communicate why, once, properly. A short message from the chief executive explaining the reason has a measurable effect on completion and a larger effect on whether people take it seriously. Do not let the launch be an automated enrolment email.
Measure something beyond completion. Completion is an attendance record. Track comprehension through assessment where it makes sense, and track behavioural proxies: reporting rates, pre-approval requests, policy consultation, questions to the compliance inbox. Rising numbers on those are usually good news and should be framed for the board as such before the numbers arrive.
Review at twelve months against three questions. Did the risk picture change? Did anything happen that the programme should have prevented? Is the content still accurate? Regulatory content ages badly and 2026 has been a heavy year for change in AI, cyber and sustainability obligations.
Governance across entities
The single decision that shapes everything downstream is whether the programme is owned at group or entity level.
Group ownership gives consistency, one reporting view and lower unit cost, and produces the complaint Nordic subsidiaries make constantly, which is training that does not reflect local law and arrived without consultation. Entity ownership gives relevance and produces reporting that cannot be consolidated.
What works is group ownership of the master content, the standards and the reporting layer, with entity ownership of national accuracy and delivery, and a defined route by which an entity can require a change to the master. Name the person in each country. Do not leave it to whoever has capacity.
Budget, honestly
Licences are the visible cost and rarely the largest one. Per-seat pricing for compliance e-learning typically falls in a range that is easy to get quoted and easy to compare. The costs that surprise people are localisation, which is expensive when done properly because it is transcreation rather than translation, and internal time, which dominates the total and never appears in the business case.
For a first-year programme at a mid-sized Nordic group, expect internal effort to exceed external spend, expect the risk assessment and matrix to take longer than planned, and expect the rollout itself to be the easy part.
Running compliance as one person
The realistic Nordic case. Four things make it survivable.
Concentrate on the two or three exposures that could actually damage the business and accept a thinner treatment elsewhere, documented as a deliberate decision.
Use the line organisation. You cannot train 900 people personally. You can train 60 managers well and make the programme theirs.
Automate assignment and reminders. Chasing completions manually will consume your entire capacity and is the lowest-value work you do.
Build the audit pack as you go rather than assembling it when asked. A folder maintained monthly takes minutes; reconstructed under pressure it takes a fortnight.
Build or buy
Buy the content that is generic across employers, which is most regulatory subject matter. Nobody needs a bespoke module explaining what a personal data breach is.
Build the content that is specific to you: your scenarios, your escalation routes, your approval processes, your sector’s situations. The highest-value training material in most organisations is fifteen minutes of company-specific scenarios attached to a purchased module.
Insist on being able to export your own completion data in a usable form. Programmes get stranded inside platforms.
Frequently asked questions
How do you build a compliance programme from scratch?
Map entities and inventory what exists in the first thirty days, run a risk assessment and build a training matrix in the first quarter, then deliver by risk order, measure beyond completion and review at twelve months.
What are the elements of an effective compliance programme?
A current risk assessment, policies people can find, role-based training, a working reporting channel, monitoring, documented decisions including negative ones, and a review cycle with a named owner.
Who should own compliance in a company?
Accountability at board level, with day-to-day ownership named and mandated. In groups, split it: group owns the master content and reporting, entities own national accuracy and delivery.
How much does a compliance programme cost?
Licence cost is the visible part and usually not the largest. Localisation done properly and internal time typically exceed it, and internal time is the component most often missing from the business case.
What is a compliance risk assessment?
A structured judgement about what could go wrong, who could cause it, how likely it is given how you actually operate, and how serious it would be. Score by activity rather than job title, particularly in flat Nordic structures.
Can one person run compliance for a group?
Commonly, yes, if the scope is deliberately concentrated, the line organisation carries delivery, administration is automated, and the audit pack is maintained continuously rather than assembled on demand.
Should you build or buy compliance training?
Buy generic regulatory content and build the company-specific scenarios and escalation routes on top. The bespoke layer is where the value is and it is usually small.
How often should a compliance programme be reviewed?
Annually as a minimum, and additionally whenever the risk picture changes, an incident occurs, or a material regulatory change lands.
Sources and further reading
- Arbeidsmiljøloven, kapittel 2 A Varsling – Lovdata, Norwegian whistleblowing routines from five employees
- Ilmoittajansuojelulaki 1171/2022 – Finnish whistleblower protection act, Finlex
- Lag (2021:890) om skydd för personer som rapporterar om missförhållanden – Sveriges riksdag
- Kyberturvallisuuslaki 124/2025 – Finnish Cybersecurity Act, Finlex
- Cybersäkerhetslag (2025:1506) – Sveriges riksdag
- AFS 2023:2 Planering och organisering av arbetsmiljöarbete – Arbetsmiljöverket, Swedish workplace conduct duties from 1 January 2025
- Co-operation Act (1333/2021) – Finlex, unofficial English translation
- Employment (Co-Determination in the Workplace) Act (1976:580) – Government Offices of Sweden, non-official translation
