Skip to content
All articlesCompliance PracticeField guide

Compliance vs Legal: Who Owns What?

Separate compliance and legal responsibilities with clear decision owners, handoffs, and records that prevent duplicate work.

TT
Truvara Team
October 7, 2026
8 min read

Two teams, one obligation, two trackers, and no shared owner. The friction between compliance and legal may not be a disagreement about the work itself. It is a disagreement about who holds it.

The overlap is real and narrow: both functions read the same obligations and both sign off on how the business responds to them. The confusion is not whether the overlap exists, but which side owns the final call.

Compliance reads an obligation and decides how the company puts it into practice. Which control addresses it, what evidence shows the control worked, who reviews that evidence, and where the record is kept. Legal reads the same obligation and decides what it means for the company, what the company commits to in a contract, and where the exposure sits when something goes wrong.

Both functions look at one duty. They answer different questions about it. That is why a clean split is possible, and why it can be skipped: the work feels collaborative, so nobody writes down who decides.

DecisionCompliance lead ownsLegal ownsShared input
Which control addresses an obligationThe design and the evidenceWhether the wording holds upBoth review the mapping
Contract language that commits the companyThe operational consequencesThe final wordingBoth read the clause
A gap that is accepted rather than closedThe narrative and the follow-up ownerThe exposure if it is read strictlyBoth record the call
Contact with an external reviewerThe evidence pack and the answersThe framing of sensitive statementsBoth prepare together

The right column matters. Shared input is not shared ownership. One function decides, the other is consulted before the decision, and the record shows both.

Who holds each decision

Name the decision owner, not the department. A decision belongs to the person who can defend it clearly in front of a reviewer, customer, or leadership team. Everything else is collaboration.

The test sounds harsh and it works. When two people own a decision, neither owns it. When a review board owns it, the board owns nothing once it adjourns. Someone has to be able to say what was decided, why, and what happens next, without checking with the other function first.

Pair the owner with a consulted party. The consulted party gets a defined window to object, and the owner decides after that window closes. This keeps legal from becoming a permanent bottleneck and keeps compliance from committing legal positions it did not intend to take.

For the control side of that split, the discipline of naming a single accountable person is the same one behind internal controls design.

When the same obligation is tracked in two places

A duplicated tracker is a symptom, not the disease. It can mean the split was left implicit, so both sides built their own version of the truth.

A compliance lead finds a duty listed in the compliance register with one owner and one due date. The same duty sits in a legal matter log with a different owner and a different date. Neither entry is wrong. The two people maintaining them talk once a quarter, at best, and neither knows the other has a copy.

This is the some expensive form of overlap. It does not show up as duplicated effort alone, it shows up as divergence. The register says the gap closed. The matter log says it is open pending a contract amendment. Nobody can answer which record is current without a meeting.

The fix is not to merge the trackers. It is to decide which record is authoritative for which part of the obligation, and then to point the other one at it. Compliance keeps the operational record. Legal keeps the interpretive and contractual record. The register references the matter log where the interpretation lives, and the matter log references the register where the evidence lives.

For how those records hold up under review, the same standard behind evidence hierarchy applies. A record someone can defend beats two records that contradict each other.

How to document the split

Write the split down as a short ownership register: obligation, primary owner, consulted party, and where the record lives. A paragraph in a wiki page drifts once someone edits it. A maintained table does not, especially when it sits beside the records behind the decision.

Keep the register small enough that it stays current. It does not need to capture every task, only obligations where compliance and legal both have a stake. If the list runs long, that is a sign the split is still unclear rather than a sign the register is too short.

Work itemPrimary ownerConsultedRecord lives in
Interpreting what an obligation meansLegalComplianceMatter notes
Designing the control and the evidenceComplianceLegalCompliance register
Commitments made in a contractLegalComplianceContract repository
Answering an external reviewerComplianceLegalCompliance register
Classifying an incidentComplianceLegalIncident log

The value here is not the table. It is the argument that produced it. Getting compliance and legal to agree on the owner for a single row surfaces the disagreement about a dozen rows nobody had written down.

Pick the level of the register with care. Listing every task turns it into a project plan nobody maintains. Listing only the broadest categories leaves the everyday decisions unowned. The useful level is the obligation: one row per duty where two functions could plausibly own the call.

Handoffs that hold

A handoff fails when it arrives as a request rather than a package. The receiving function should get the decision, the reasoning, and the record, not a question.

Compliance to legal is the request for interpretation. Compliance sends the obligation, its own reading, the control it plans, and the outcome it is trying to reach. Legal answers within the window, on the record.

Legal to compliance is the new commitment. Legal sends the clause, what the company promised, and the date the promise starts. Compliance maps it to a control and confirms the mapping back.

For an external review, one function leads while the other supplies context. One function leads, the other supplies, and both agree the lead before the first question is answered. The failure mode is two answers to one question, delivered a week apart.

A handoff worth its name includes the record, not a summary of it. That is the same principle behind assurance program design, where a review is only repeatable when the evidence travels with the decision.

Keep the handoff on the record, not in a chat thread. A decision made in a direct message is invisible to the next reviewer and to the person who inherits the obligation.

Keeping the boundary honest as work changes

The split is not static. New markets, new contracts, and new obligations move the line, so the register needs a review rhythm tied to those events rather than to the calendar.

Watch for the signals that the boundary has already moved.

SignalWhat it can meanFirst move
A new clause appears in a signed contractLegal committed to something operations then need to deliverMap it to a control
An external question arrivesBoth functions now answer for one responseAgree the lead
A gap is accepted with a follow-up dateOwnership of the follow-up is unclearName the owner
A duty shows up in a second trackerThe split was not written downPoint one record at the other

Review the register when one of these happens, rather than on a fixed cycle. A calendar review catches drift after it has settled. An event review catches it while the people involved still remember why they decided what they did.

A review is not a rewrite. An event sometimes changes one row. The discipline is confirming that the owner still agrees, the consulted party still knows, and the record still points where it should.

FAQ

The function that can defend the decision on its own. If it is about how the company operates and shows the work, compliance owns it. If it is about what the company promised and how exposed it is, legal owns it. The other function is consulted, not co-owner.

The obligation in plain terms, the control compliance plans to use, and the outcome compliance is trying to reach. Legal asked to interpret a duty without that context will answer the abstract question, which may not be the question the business needs settled.

How do we stop the same work being tracked twice?

Agree which record is authoritative for each part of the obligation, then make the other record point at it. One tracker holds the operational evidence, the other holds the interpretation and the contractual position. Duplication is fine as long as one record is the source and the other links to it.

As a standing member, only if the committee spends its time on decisions that need legal input. Otherwise invite legal when the agenda touches obligations, contracts, or sensitive external contact, and keep the record of what legal advised.

A clear answer, in writing, with the reasoning attached, by the agreed date. An answer of "it depends" is legitimate only when it is followed by what it depends on and who will decide.

Where CASK helps

CASK keeps the record behind a decision in one place, so the compliance lead and the legal team work from the same obligation rather than two versions of it. It runs on your desktop, drafts from the records you point it at, and leaves the decision with the person who owns it.

The boundary between the two functions is a judgment call, and CASK does not make that call for you. What it does is keep the interpretation, the evidence, and the owner attached to one record, so a handoff carries its own context.

If your compliance register and your legal matter log keep drifting apart, CASK by Truvara is built for exactly that seam.

TT

Truvara Team

Truvara.ai