KTH Tech/SIGNAL/Compliance Management in Projects: A Delivery Guide

Effective compliance management in projects

By KTH-Tech · Enterprise delivery · 7 min read

On most enterprise programmes, compliance is treated as a gate at the end — a scramble for evidence just before go-live, run by people who weren't in the room when the decisions were made. That's why it so often blows budgets and timelines. Compliance isn't a phase; it's a property of how the work is run. Managed well, it barely registers as a cost. Managed as an afterthought, it becomes the most expensive part of the project.

This is how we think about it at KTH-Tech, drawn from 19+ years and R2bn+ of delivered programme value across banking, retail, mining, healthcare and government — sectors where getting compliance wrong isn't a slap on the wrist, it's a headline.

Start with the obligations, not the checklist

Before a single deliverable is planned, map the regulatory landscape the project lives in. In South Africa that usually means some combination of POPIA (personal information), PCI DSS (card data), King IV (governance), sector rules (FSCA, the Information Regulator, industry bodies), and internal risk policy. The point isn't to produce a document — it's to know, on day one, which decisions are constrained and by what.

Compliance isn't a phase you reach. It's a property of how the work is run — designed in at the start, or paid for painfully at the end.

Make one person accountable

Diffuse ownership is why compliance falls through the cracks. Every programme needs a single named owner for compliance outcomes — not a committee, a person — with the authority to stop work that creates unacceptable exposure. On regulated programmes this role sits close to the programme lead, not buried three layers down.

Build the evidence as you go

The most expensive mistake in project compliance is reconstructing evidence after the fact. Instead, capture it continuously:

Done this way, your audit pack assembles itself. Done at the end, it's archaeology.

Put compliance risks in the same register as everything else

Compliance risk shouldn't live in a separate spreadsheet that nobody reads. Fold it into the programme's main risk register, review the top items in the same weekly governance forum as delivery and budget risks, and give each one an owner and a date. A regulatory risk with no owner and no review date is decoration, not management.

Hold your vendors to the same line

On multi-supplier programmes, your third parties inherit your obligations. Whatever cadence, evidence and control standard you hold internally, contract your vendors to the same — and verify it, don't assume it. This is exactly where large programmes accumulate silent, inherited risk.

A simple operating rhythm

  1. Kick-off: map obligations, name the owner, define what "compliant" means for this programme.
  2. Weekly: review top compliance risks alongside delivery risks; log decisions and controls as they land.
  3. Stage gates: confirm the evidence exists before advancing — a quick check, not a cliff-edge audit.
  4. Close-out: the audit pack is already assembled; hand it over and feed lessons into the next programme's baseline.

The bottom line

Effective compliance management isn't about doing more paperwork — it's about doing it continuously and in the open, owned by someone with authority, and reviewed alongside the rest of delivery. Programmes that work this way pass their audits almost as a by-product. Programmes that don't discover, too late, that compliance was never a document problem — it was a delivery-discipline problem.

Running a regulated programme?

KTH-Tech's DELIVR hub builds compliance into delivery on high-stakes programmes — governance, risk and evidence that satisfy board-level and regulatory scrutiny. Let's talk.

Talk to our delivery team →

This article is general guidance, not legal or compliance advice. Your obligations depend on your sector, data and jurisdiction — validate against the relevant regulations and a qualified professional.