Ten Capabilities Every Telecoms Compliance Practice Needs, Whatever Its Size

Greg Mook

SUBSCRIBE CONTACT US

Author



KEY TAKEAWAYS

  • Every compliance risk needs a named business owner with the authority and resources to act on it; Legal and Regulatory advise and challenge, but they should not own it by default.

  • Senior management or the Board must set the compliance risk appetite and turn it into practical decision rules and escalation thresholds.

  • Compliance checks should be built into defined trigger points (product approval, non-standard deals, operational changes, and regulatory incidents) so nobody has to remember to ask.

  • Legacy exposures and regulatory change affecting the existing estate should go into one central register, each with an owner, a remediation plan, and oversight that matches how serious it is.

  • A contract with a supplier is not enough on its own: providers also need operational processes that actually get information and action from third parties within regulatory deadlines.

5 MIN READ


There is no single correct compliance operating model. A small domestic provider does not need the same infrastructure as a multinational operator, and different companies will organise Legal, Regulatory, Privacy, Security and other specialist functions differently and with differing levels of maturity.


There are, however, some basic elements without which a company cannot have an effective compliance practice.


This article is aimed principally at legal and regulatory professionals in the communications industry. It does not prescribe an organisation chart, committee composition, or technology platform. Instead, it sets out the minimum capabilities that must exist and the points at which compliance needs to connect with the business.


I. Why Communications Compliance is Difficult


Regulatory obligations on the communications industry have expanded dramatically since liberalisation.


Competition and access rules now sit alongside consumer protection, universal connectivity, emergency services, lawful interception, confidentiality, fraud prevention, cybersecurity, supply-chain assurance, resilience, online safety, and wider concerns about the trustworthiness of communications.


Different regulators oversee these obligations, while the relevant expertise within a company is often spread across several functions. Effective compliance therefore requires coordination as well as specialist knowledge.


Technology has also fragmented the delivery chain. Contracting, numbering, connectivity, hosting, termination, billing, and support may be undertaken by different companies, often in different jurisdictions. This makes it harder to determine which obligations apply, to whom, and where responsibility sits.


Regulation also changes while products, contracts, systems and networks remain in place.

Communications companies often have complex legacy estates shaped by acquisitions, historic

product variants and country-specific operating models. Identifying how a new requirement affects the existing estate can therefore be as difficult as interpreting the requirement itself.


The aim is not to eliminate all uncertainty and risk, but to have a disciplined system that

identifies the important issues, brings in the right expertise, makes decisions at the right level and follows them through.


II. The Basic Ingredients


1. Clear Business Accountability


Someone in the business must be accountable for each specific compliance risk.

Legal, Regulatory, and other compliance specialists provide expertise, interpretation, and challenge but they should not become the default owner of risks arising from products, customers or operations.


The precise ownership model can vary. What matters is that there is an identifiable person with

sufficient authority to own the risk, ensure agreed mitigations are addressed, and secure the necessary resources.


2. Visible Senior-Management Support


Senior management must visibly demonstrate that compliance matters. Leaders need to reinforce

compliance expectations through their decisions, communications, and willingness to support

remediation when issues arise.


Without visible leadership support, even a well-designed compliance process can be undermined by

commercial pressure, or simply treated as optional.


3. Senior Management Sets Compliance Risk Appetite


The level of regulatory or compliance risk the company is prepared to accept must be set by senior

management or the Board.


Individual product, sales or operational owners can make decisions within those boundaries but not

determine the company's risk tolerance themselves. Senior management must therefore establish the

principles, thresholds, and escalation requirements for accepting compliance risk. These should

translate the company’s risk appetite into practical decision rules, making clear which risks can be

managed within the business and which require escalation to senior management, a Risk &

Compliance Committee, or the Board.


4. Access to Competent Expertise


The business needs timely access to the specialists necessary to understand the regulatory issues it

faces.


In a communications company, this may involve Telecoms Regulatory, Legal, Privacy, Cyber Security,

Fraud, Sanctions, National Security, Tax, or other specialists. The experts may be internal, external, or

a combination of both.


Where several disciplines may be relevant, the business needs a straightforward way to obtain

coordinated advice. Business users should not have to understand how the compliance organisation is structured, approach several teams separately, or repeatedly provide the same information to different compliance functions. The most effective model is often a Single Front Door: one entry point through which the issue is triaged, the relevant specialists are engaged, and a coordinated response is provided back to the business.


Specialists also need practical ways to translate their expertise into the business. Depending on the

organisation, this may include concise guidance, training, accessible summaries of regulatory

requirements, and systems that enable business teams to find or request the information they need.


5. Visibility of Obligations and Known Exposure


A company needs a sufficiently reliable view of the regulatory obligations that matter to its business and of any known areas of non-compliance or uncertainty.


The mechanism can be proportionate. A small provider may maintain a focused register of licences and material obligations. A multinational may require linked product, country, entity, licence and obligation inventories.


The important distinction is between “we have reasonable confidence that we are operating within our

compliance risk appetite” and “we have not identified a problem.” Known or suspected legacy exposures should be recorded in a central register rather than remaining within individual teams,

emails, or local tracking. Each exposure must be assessed and prioritised according to risk, with a clear business owner, remediation plan, and appropriate management visibility. The more material the

exposure, the more senior the oversight and any decision to tolerate it temporarily should be.


Maintaining a single view of legacy exposures also allows management to understand the

organisation’s aggregate compliance exposure, identify recurring themes and prioritise remediation

across the business.


6. Mandatory Compliance Trigger Points


Compliance cannot depend on somebody remembering to ask Legal or Regulatory for advice.


The company should define the circumstances in which a compliance assessment is mandatory and

embed those checks into the relevant business processes.


For most communications businesses there are three particularly important planned routes, together

with a separate route for regulatory incidents.


  • Standard products. Compliance must be built into product development and approval. Once a product has been assessed and approved, the business can sell it within the approved parameters without repeating the full compliance exercise for every transaction.


  • Bespoke or non-standard products and deals. Sales or deal governance must identify departures from the standard product. A new country, unusual customer requirement, different supplier, bespoke contractual commitment, or a novel technical solution may invalidate assumptions made when the standard product was approved. Such cases should trigger a proportionate compliance review.


  • Defined operational or internal-process changes. Compliance checks may also be required when the company changes the way it operates. Examples might include moving personal data into a new system, changing a network or supplier arrangement, introducing a new customer registration process, or materially changing the way an existing service is delivered.


  • Regulatory incidents. The company also needs a defined route for identifying and escalating incidents that may have regulatory consequences. Relevant specialists should be involved quickly enough to determine whether regulator, customer, or other notifications are required within prescribed deadlines, and any resulting exposure should feed into the same decision, remediation, and evidence processes used elsewhere in the framework.


The trigger points will differ by company and compliance discipline. The important requirement is that

they are defined and built into the business processes where relevant decisions are actually made.

Compliance issues may also surface outside these planned processes, typically through customer or

supplier queries, internal reviews, or a query from a regulator. The company needs a route for these

issues to enter the same assessment, decision, and remediation process.


7. A Structured Route for Difficult Decisions


Difficult compliance issues require a dialogue between the business and the relevant specialists. Not

every issue produces a simple yes or no answer.


Compliance specialists can explain the requirement, the degree of uncertainty, and the likely

consequences of proceeding. Where appropriate, this must include a consistent assessment of

likelihood and impact. A simple risk assessment matrix provides a consistent basis for making and

escalating these decisions. Typically, it assesses likelihood against impact, using four or five defined

levels for each. The scales should reflect the organisation and, where possible, align with its wider

enterprise risk methodology.


Impact should consider more than the potential regulatory penalty. Relevant dimensions may include:


  • Regulatory consequences, including fines, licence action or other sanctions
  • Customer or service impact
  • Financial impact, including revenue or cost
  • Operational impact
  • Reputational impact
  • Strategic impact, including the ability to continue a product, enter a market or pursue a material business objective.


The company should define increasing levels of impact for each dimension – for example from Minor

to Severe. Where several dimensions are affected, the overall assessment should normally reflect the

most material credible consequence rather than averaging the impacts.


Likelihood should also use defined levels, for example: Rare, Unlikely, Possible, Likely, and Almost

Certain, based on probability, expected frequency or both. An illustrative scale might range from an

event expected less than once in ten years at the lower end to one expected to occur frequently at the

upper end.


The resulting risk rating should link directly to the company’s risk appetite and escalation thresholds:

the greater the risk, the more senior the required decision-maker. Where mitigation is proposed, both

the initial risk and the expected residual risk should be clear.


The specialist's role is to provide informed advice and independent challenge. The final commercial

decision belongs with an authorised business decision-maker.


Where a proposal is clearly non-compliant, it should be changed. Where there is material legal or

regulatory uncertainty, or residual compliance risk remains after mitigation, the issue should enter a

defined Risk Decision and escalation process. The greater the potential exposure, the more senior the

decision-maker should be.


Risk acceptance must not become a substitute for remediation. Any mitigations agreed in the decision-making process must have clear owners, actions and review points.


8. Regulatory Change Management


The company needs a reliable way of identifying regulatory developments that may affect it.

Horizon scanning should do more than distribute legal updates. Relevant developments need to be

assessed for applicability and impact, assigned to the affected business owners and tracked through

implementation.


Importantly, the assessment should include the existing estate. A regulatory change may render an

existing product, contract, system, process, or delivery model non-compliant, or move it outside the

company’s compliance risk appetite. The company therefore needs to identify the affected installed

base and assess the resulting exposure.


Any issues identified through regulatory change must then be managed in the same way as other

legacy exposures: recorded in the central register, assessed and prioritised according to risk, assigned

to a business owner, supported by a remediation plan, and given management oversight appropriate to their materiality.


This must also include updating the relevant library of regulatory obligations and maintaining a clear link between the new requirement and the products, contracts, systems or processes it affects.


Where important regulation is still being developed, Regulatory or Public Policy teams may also have

an opportunity to engage with consultations and influence the eventual requirement.


9. Third-Party and Delivery-Chain Assurance


Communications providers frequently depend on suppliers, carriers, number providers, cloud platforms and other partners to deliver services to their customers. These activities can be relevant to the provider’s own obligations.


The company must understand which compliance obligations depend on third parties, allocate

responsibilities clearly, and obtain appropriate assurance that those responsibilities are being met.


Depending on the risk, this may include due diligence, contractual requirements and flow-downs,

evidence of compliance, reporting obligations, audit or information rights, and ongoing review.


The company must also identify where compliance with its own obligations depends on obtaining

information or action from another party. For example, where a numbering range is supplied through a

reseller, the formal number holder may receive a lawful authority request seeking information about the subscriber or end user associated with a particular number. The information needed to respond may be held by the reseller rather than the number holder. Effective compliance therefore requires both a contractual obligation on the reseller to provide the necessary information and an operational process capable of obtaining and supplying it within the required timescale.


The same principle applies more broadly to regulatory enquiries, security incidents, customer

complaints, fraud investigations, and other situations in which information may need to move quickly

across organisational boundaries.


Contracts can allocate responsibilities and create rights to information or assistance, but contractual

wording alone is not enough. The company should be satisfied that the supporting operational

processes, contacts, escalation routes and information flows actually work.


10. Evidence and Assurance


The company should be able to demonstrate what it did and periodically test whether its compliance

arrangements are working as intended.


Material compliance assessments, interpretations, decisions, accepted risks and remediation actions

should be capable of being reconstructed without depending on individual memory. This is important for two reasons. Firstly, in the event of a challenge from a regulator, the company may need to

demonstrate that its approach was considered, reasonable, and appropriately governed. Secondly, it

will inform future decisions by providing a reliable record of how similar issues were previously

assessed and resolved.


The evidence does not need to sit in a sophisticated compliance platform. It may be held in workflow

systems, ticketing tools, repositories or other existing systems. What matters is that significant

decisions and actions are identifiable, retrievable and sufficiently complete.


The company must also periodically test whether the framework is operating as intended. Assurance

should go beyond confirming that policies and processes exist and use actual examples to test whether compliance trigger points are being used, appropriate specialists are involved, obligations and exposures remain current, Risk Decisions are properly authorised, remediation is completed, third-party dependencies are being managed, and supporting evidence can be retrieved.


The form and degree of independence can vary with the organisation. Assurance may be provided

through Compliance monitoring, Internal Audit, management testing, external review or a combination

of these. What matters is that weaknesses are identified, reported to the appropriate level of

management and corrected.


11. Governance Across the Framework


The ten ingredients need to operate within an appropriate governance structure. Compliance risk

should be reviewed at a level sufficiently senior to understand the organisation’s aggregate exposure,

challenge significant decisions, ensure that remediation receives the necessary resources, and confirm that the framework continues to operate effectively.


For many larger organisations, this will include regular compliance reporting as a standing agenda item of a senior Risk & Compliance Committee, or equivalent executive forum. Its remit should normally include material compliance exposures, significant Risk Decisions, regulatory investigations and incidents, overdue remediation, important regulatory change, third-party dependencies, and the results of compliance assurance.


Governance should reflect materiality. Routine matters should remain with accountable business

owners, while significant residual risks and major remediation programmes should receive

progressively more senior oversight. The most material matters may require executive or Board

visibility.


Compliance governance should also connect with the organisation’s wider risk-management and

assurance arrangements rather than operating as a separate reporting system. In organisations of

sufficient size, the compliance assurance programme should be coordinated with Internal Audit, so that material compliance risks are appropriately reflected in the audit universe and relevant findings are visible to senior governance. Internal Audit should nevertheless retain its independence in determining its audit programme and conclusions.


III. Proportionate Implementation


These ingredients do not require every company to build a large compliance department.


A smaller provider may combine senior business accountability, external specialist advice, a focused

regulatory register, and direct escalation to the managing director.


A multinational provider may need dedicated specialist teams, formal product and deal governance,

automated workflows, country and product inventories, and multiple tiers of risk committees.


Both models can be effective. The appropriate level of compliance infrastructure should reflect the

organisation’s regulatory exposure, geographic footprint, product complexity, delivery model and rate of change. As complexity and exposure increase, the organisation is likely to need more structured

governance, specialist support, monitoring and assurance.


The test is not how much compliance infrastructure the company has. It is whether the organisation can reliably:


  • Assign clear business accountability for compliance risk
  • Demonstrate visible senior-management support for compliance
  • Make decisions within a clearly defined compliance risk appetite
  • Bring the right expertise to the business when it is needed
  • Maintain a reliable view of its obligations and known exposures
  • Require compliance to be considered at the right trigger points
  • Make and escalate difficult compliance decisions in a structured way
  • Identify and respond to regulatory change
  • Manage compliance dependencies across the delivery chain
  • Demonstrate what it did and test that the framework is working


There is no single approach that achieves this, but a company that cannot answer yes to each of these does not yet have an effective compliance practice.

About the Author

About Us

Cambridge Management Consulting (Cambridge MC) is an international consulting firm that helps companies of all sizes have a better impact on the world. Founded in Cambridge, UK, initially to help the start-up community, Cambridge MC has grown to over 200 consultants working on projects in 25 countries. Our capabilities focus on supporting the private and public sector with their people, process and digital technology challenges.


What makes Cambridge Management Consulting unique is that it doesn’t employ consultants – only senior executives with real industry or government experience and the skills to advise their clients from a place of true credibility. Our team strives to have a highly positive impact on all the organisations they serve. We are confident there is no business or enterprise that we cannot help transform for the better.


Cambridge Management Consulting has offices or legal entities in Cambridge, London, New York, Paris, Dubai, Singapore and Helsinki, with further expansion planned in future. 

Contact Form

Contact - Craig Devolution Blog

Subscribe to our Newsletter

Blog Subscribe

SHARE CONTENT

Sunrise over the ocean.
24 September 2026
Cambridge Management Consulting has achieved Certified B Corporation status, validating its commitment to responsible business and long-term stakeholder value | READ THE FULL PRESS RELEASE
A neon wireframe view of a city with roads and bridges.
by Paul Brooker • 15 September 2026
Sales Transformation | Manual workarounds and fragmented systems are costing telecom operators revenue and margin. Discover how to remove the Complexity Tax and unlock value | READ FULL ARTICLE NOW
A long  bank of solar panels in a field at dusk
by Scott Armstrong • 4 August 2026
ESOS Phase 4 isn't just compliance. Scott Armstrong explains why cheap audits cost more long-term, and how to treat Phase 4 as a strategic energy opportunity | READ FULL ARTICLE
Neon waves and lines with overlay of white plus signs, some dissolving away
by Jason Jennings • 14 July 2026
Procurement | Most organisations are sitting on 3–8 per cent of recoverable third-party spend. Here's where AI-powered spend analysis finds it — and how CFOs can act without cutting into operations | READ FULL ARTICLE
Three interlocked rings, silver, on a back background.
by Ruth Redding • 9 July 2026
Leadership & Change | Ruth Redding on why transformation and AI programmes fail without genuine adoption, and how leaders can build 'Adoption Insurance' into change from day one | READ FULL ARTICLE
by Darren Sheppard • 18 June 2026
Procurement teams that invite structured external challenge — not resist it — build stronger, more defensible decisions. Learn how to use market testing and early supplier engagement to strengthen procurement authority, not undermine it | READ NOW
by Mauro Mortali • 9 May 2026
We were approached by a global networking systems, services, and software company that specialises in optical and routing solutions. Their technology helps carriers, enterprises, and governments build more efficient and scalable networks, particularly for high-bandwidth applications like 5G, cloud computing, and AI-driven networking. Africa is a key strategic market for this client. They are also playing an active role in advancing outlined 5G technology on the continent, emphasising a focus on routing and switching aggregation components, network slicing, and monetisation. The Opportunity The client engaged Cambridge MC to provide external insight and support to augment and accelerate the progress of their Go-to-Market plans for Africa. We proposed our in-house rapid Strategy Stress Test that delivers key insights across areas of your strategy using a 1–5 health-scoring matrix. The client's aim is to grow market share in the region with a precisely focussed strategy that targets their market with key propositions and solutions. We were engaged to review this strategy and their plans for the region, identifying critical opportunities and gaps with a quick turnaround. Approach We used our Rapid Strategy Stress Test methodology which provides: Target geographies, opportunities, and partners for resource effectiveness and success maximisation Assessment of client's Go-to-Market Strategy including identification and testing of key assumptions Identification of new opportunities and any gaps in the strategy Recommendations on how best to capitalise on the market and accelerate their route to success This included carrying out target addressable and client-addressable market sizing by country for the Optical, Data Centre Interconnect, Routing and Switching portfolios; competitor market share analysis; analysis of current and planned data centre build in the target countries; future trend analysis, including Political, Economic, Social, Technological, Legal and Environmental trends by country. We put their GtM strategy and plans through our Stress Test framework, scoring capabilities against best-in-class – across 11 parameters such as Market Potential, Adaptability to Local Needs, Pricing and Marketing & Demand Generation. Recommendations were made against each of the 11 areas relating to opportunities to accelerate their GtM strategy. In order to support effective targeting of resources into key countries, we developed a country prioritisation framework across 15 parameters, such as GDP growth, energy supply, stability of regulatory environment, and ease of doing business. This quantitative assessment was supplemented with the real world experience of our Africa experts. 
A digital human made of blocks and wires jumping into the air
by Ruth Redding • 23 April 2026
Why digital transformation fails: human adoption. Learn how leaders can reduce change resistance, protect ROI and improve programme success with structured change management | READ FULL ARTICLE
Businessman walks across desert into AI portal
9 April 2026
This article suggests how to pilot AI in 90 days with five practical use cases for operations leaders – from triage and forecasting to summarisation – with clear governance and measurable value | READ FULL ARTICLE
More posts