
In this lecture you take one of your own policies apart block by block, so you can see which decision it is supposed to govern, who owns it, how it reaches people, how it is checked and what happens when somebody breaks it.
This course is built from six disciplines: business and legal context, people risk and control, cross-border obligations, equality and training, process documentation and audit.
The map of the course
A simple dictionary for reading lectures written for other fields as work on your own rules
Three questions to ask after every lecture
A short self-diagnostic that shows which sections to watch first
Download the Policy Teardown Sheet and fill in one line after each lecture.
Environmental analysis, and STEEPLE in place of PESTEL
Strengths and weaknesses, and environmental scanning
Types of organisational structure, and how one gets chosen
Stakeholders, and the management theories behind the vocabulary
Economic systems and market structures
Competitive strategies, and the five forces
The growth-share matrix
The labour market, and the psychological contract
The instruments of economic policy
Inflation and interest rates, and how they reach your decisions
What central banks do
The types of company, and what changes between them legally
Legal systems and how business gets regulated
Labour legislation
International financial institutions and trade
Globalisation, and what multinational structures change about obligations
Population growth and composition
The social trends that reach an organisation
Inequality
Why any of this appears on a compliance agenda
How technology develops, and what it does to obligations
Knowledge management
Ethics, values and social responsibility
Risk management as a standing agenda item
Strategy models and strategic analysis
Making strategic choices and implementing them
Change management and strategic leadership
Connecting a control function to business performance
The three main statements and what each one answers
The terms you need to follow a leadership conversation
Applying this to your own area
Justifying a control investment in the language decisions are made in
Decision making as the origin of most failure
What the global financial crisis exposed
What people risks are, and why they are counted separately
The current research
The risk heat map, and scoring onto it honestly
The fraud triangle and the safety triangle
The people-risk thermal imager
A full example applied to one function
How decisions get made under pressure
The cognitive biases that survive any amount of policy
Conflict of interest, and how it hides in plain sight
Real examples, and what they had in common
The 4I model
Incidents, and what an incident is telling you
Risk at individual, company and industry level
The standard, in plain terms
The risk hierarchy, and internal against external risk
Finding and assessing risk without turning it into theatre
Eliminating, reducing and escalating
Management maturity, and how to judge it
The dynamics inside a leadership team
The role of the chief executive in the control system
The warning signs that appear before the failure does
Cultural context, and why one control works differently in two companies
Building a risk culture rather than announcing one
Company values, and whether anyone acts on them
Trust as an operating variable
The model, and the usual confusion in the second line
Practical risk reduction
The high-reliability organisation and what it does differently
Auditing corporate culture, and running this with a small team
Making the invisible visible
The moves that improve a decision process
A decision-making checklist you can apply immediately
What a code of conduct has to say to be usable
The job description as a control document
Naming an owner for every obligation
PESTLE analysis applied across countries
Expansion strategies, mergers and acquisitions
The stages of globalisation, and global organisational structures
The operating model, outsourcing, and the balanced scorecard
Attracting people across borders
Employee mobility and international transfers
Selecting and preparing people for an assignment
Relocation, support and return
The performance cycle applied internationally
A global competency model
Global assignments
Talent management across entities
Assessing capability across countries
Training people in more than one jurisdiction
Using a learning platform
Automation systems, and the records they hold
Trade unions and what consultation obliges
European works councils
The International Labour Organization
The Organisation for Economic Co-operation and Development
Cultural differences and cross-cultural communication
Culture shock, and building sensitivity
Managing across cultures and in international teams
Global diversity, and corporate social responsibility
This course contains the use of artificial intelligence.
Nearly every organisation that has had a compliance failure had a policy covering it. The policy was not the problem.
Where compliance actually fails
It fails in the gap between the document and the decision. The policy was written for an auditor, so it is precise and unreadable, and the manager making a call on a Thursday evening does not consult it — they do what seems reasonable. The mandatory training was completed by everyone and changed nobody, because completion was the metric. Nobody owns the control, so when it fails there are three people who each assumed it was one of the others. And the code of conduct describes values rather than decisions, so it cannot be applied to the specific awkward situation in front of you.
What this course covers
Forty-one lessons from the environment down to the audit. The context first: legal systems and how business is regulated, labour legislation, international institutions and trade, what multinational structure changes about obligations, technology, and ethics and social responsibility as an operating matter rather than a poster. Then the risk and control framework: the heat map, the fraud triangle, cognitive bias and conflict of interest, ISO 31000, escalation, leadership-team dynamics, risk culture, the three lines of defence with the usual confusion in the second, the high-reliability organisation, and a code of conduct written so it can be applied. Then obligations across borders: multi-jurisdiction structures, mobility and assignments, unions, European works councils, the International Labour Organization and the OECD, global pay and tax equalisation, and — the core of it — employee data under GDPR and equivalent regimes, the compliance audit, and a plan for running an internal investigation. Then the most regulated area of workplace conduct: the legal requirements, prejudice and discrimination named plainly, and how to design mandatory training that changes behaviour and can be evidenced. Then documented procedures: what to document, BPMN, templates, implementation and a documentation project. Finally the audit itself: three audit levels starting with compliance, express scoring, a weighted checklist, four collection methods, gap analysis, RACI and a roadmap.
What this course does not cover
This is workplace and organisational compliance. It does not cover anti-money-laundering, sanctions screening, financial crime, third-party or supplier due diligence, or sector-specific regulatory reporting. It is also not legal advice and does not qualify you to give any — the obligations described vary by jurisdiction and change, and a lawyer remains a lawyer. If you came looking for financial-sector compliance, this is the wrong course and it is better that you know now.
Who is teaching this
I am Mike Pritula. I built the people system at Preply as it became a unicorn, and I have worked at Wargaming, iDeals and Alfa-Bank. More than 1.6 million students have enrolled in my courses across 185 countries, and over 150,000 specialists have gone through my programmes. I hold PHRi and SHRM-CP certifications and represent HRCI in more than ten countries.
What is included
Lifetime access to all 41 lessons
Active instructor support in the Q&A section
A Udemy Certificate of Completion
Working material: the heat map, the fraud triangle, ISO 31000, the three lines of defence, the data protection checklist, the investigation plan, BPMN templates, the audit checklist and roadmap
A full audit demonstration on a real 200-person company
Where to start
Take one policy your organisation has and find the last decision that should have been governed by it. Then ask whether anyone opened the document. That gap is what this course is about. Enrol now and start today.