---
id: KB-LE-004
url: https://app.codecontract.io/help/legal/building-a-compliance-process-people-use
idioma: en
categoria: sector-legal
subcategoria: compliance
audiencia: usuario
nivel: intermedio
actualizado: 2026-08-13
tambienEn: [es]
relacionados: [KB-LE-001, KB-CF-011, KB-LE-012]
citadoPor: [KB-LE-011, KB-LE-019, KB-LE-024]
---

# A compliance programme people actually use

_The difference between having a manual and proving it is applied._

**Responde a:** compliance programme documentation · prove compliance is applied · compliance training records · evidence of a compliance programme

A compliance programme is judged on one thing when the moment comes: whether it can be shown to have been alive before the problem. A manual approved three years ago and filed in a folder proves nothing — and whoever reviews it knows that.

## What must be provable

| Element | What proves it | What does NOT |
| --- | --- | --- |
| That it exists | The programme, with a trusted approval date | A document in a shared folder |
| That it is known | Training with who, when and a signed acknowledgement | An email with the manual attached |
| That it is reviewed | Periodic reviews, dated | That the latest version is three years old |
| That it is applied | Concrete cases detected and handled | That there have been none |

> [!IMPORTANT]
> The last row weighs most and is the most uncomfortable. A programme with no case recorded in three years does not prove everything is fine: it proves it is not being used, or that nobody dares use it.

## What makes it genuinely used

**En corto**

- Training with a signed acknowledgement and an expiry, like any other.
- Reviews scheduled rather than waiting for someone to remember.
- A trusted-dated record of every approved version.

> [!WARNING]
> Certifying the programme on the day it is approved and at each review has a concrete purpose: if one day you must show it existed before an event, the date cannot be whatever your file server says.

## What a tool cannot do

Design the programme, decide which risks apply to you, or judge whether it is sufficient. That is your adviser's or compliance officer's work. What it can do is leave a dated record of everything you do, which is exactly what is hard to reconstruct afterwards.

> [!NOTE]
> If your programme requires certain third parties to sign up to a code of conduct, that is precisely a signature request with tracking: who signed, when, and who is missing.

**Do training records count as evidence?**

With a signed acknowledgement and a date, they are what is asked for.

**What if we detect a case?**

Recording and handling it is what sustains the programme, not what weakens it.

**Is this advice?**

No. The programme's content is defined by whoever should; this explains how to record it.

## Ejemplos

**A company approved its programme four years ago with no evidence it is applied.**

- Certifies the current version
- Launches training with signed acknowledgement
- Schedules the annual review

→ Six months later it can show the programme is alive, which is all that is asked.

**The programme exists in a document nobody opens.**

- Turns it into tasks with an owner and a date

→ The programme leaves a trail that it is used.

**Training happens and nothing is recorded.**

- Records who did it and when

→ The evidence exists when it is asked for.

**An auditor asks for evidence and is shown the manual.**

- Shows the record of real operations

→ The control moves from assertion to evidence.

**Periodic reviews happen whenever somebody remembers.**

- Schedules the reminders by calendar

→ The cadence keeps itself.

**The organisation changes and the programme stays the same.**

- Reviews it when something relevant changes

→ The programme describes today's company.
