Absolutely. So how do we do it?
Compliance has typically been a relatively static area since it rarely goes away once a regulation is implemented. This leads to inefficiencies as new processes and systems are dropped on top of old methods without reviewing the entire Compliance structure, operations, tools, and objectives.
First, let’s review some of the critical tenets of Agile.
- The customer value measures all the work it adds. Compliance has two customers: the company’s end customer and the regulatory agency that oversees the company. These two may have conflicting desires and objectives, so it’s essential to understand exactly what each team wants.
- Projects should be broken down into the lowest viable release. A release can be software or a business process, new or changed.
- Developing the backlog of what needs to be done and prioritizing the backlog. This is a joint effort between all stakeholders-business, technology, and compliance.
The first step is to identify what needs to be done. It’s easy to locate the new regulation that we need to comply with, but if the thought of adding one more series of reports to the monthly stack fills you with dread, then examine your Compliance eco-system as a whole. Keep in mind who your customer is!
- Where does your data originate?
- Is the data manipulated in spreadsheets, opening you to errors? Or does the data you receive need to be cleaned or adjusted before submitting it?
- How labor intensive is it to get the data you need?
- Are your technology tools working for the benefit of your customers?
- Do we provide a summary and detailed data in a format that our customers can easily consume? When did you last ask them what they wanted?
- Are the Compliance requirements built into the product development process?
- Are Internal Controls embedded in our tools and processes or tacked on afterward?
The answers to these questions will lead you to develop your backlog of work. In most cases, your backlog items will need to be split into more granular problems and solutions at the first pass. Keep breaking until each idea is decomposed into the minimum viable product, the smallest unit that can be delivered and still add value to your customers. Now, prioritize the backlog, and start your first sprint with the highest priority item.
Keep in mind that Agile fosters continuous improvement. Don’t let your backlog stay static. Keep adding items to your backlog that benefit your customers, and remember that Agile is a journey, not a destination!
If you’d like help implementing Agile in your business processes, reach out. We know so many experts in this space, and we can certainly guide your following conversation.
This article was originally authored by Paul Bayne.
Paul left this world after a courageous and inspiring fight with brain cancer. https://www.gofundme.com/f/a-film-on-life-after-a-terminal-cancer-diagnosis

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics