Effective independent monitoring: from compliance oversight to transformation

Thursday 6 August 2026

Melina Llodrá
LLODRÁ Law, Buenos Aires
mll@llodra.law

Sol Fiorella Jure
LLODRÁ Law, Buenos Aires
sjure@llodra.law

Introduction

Regulators, financial institutions and international organisations increasingly assess integrity compliance programmes not by their existence, but by their actual effectiveness in practice. Drawing on experience acting as an independent monitor in matters financed by the Inter-American Development Bank (IDB) Group, this article addresses the role of the independent monitor, the key features of effective monitorship (including the pivotal role of artificial intelligence (AI)), as well as the main challenges encountered and opportunities arising throughout this process.

An evolving compliance landscape

Over the past few years, companies operating in cross-border markets have been faced with increasing expectations regarding the effectiveness of their integrity compliance programmes. Regulators, enforcement authorities, financial institutions, investors, business partners and international organisations are no longer focused solely on whether a company has adopted formal policies. The more pressing question now is whether those policies are understood, implemented, tested and driven by measurable results. Companies are expected to demonstrate that their compliance framework operates effectively in practice and is tailored to the actual risks, structure, industry and geographic exposure of the business. From that perspective, monitoring is not simply a mechanism to verify formal compliance; it is a tool to assess whether the company’s integrity commitments have been effectively implemented and whether the company has the capacity to sustain them over time.

The real challenge: from formal compliance to operational evidence

Independent monitoring is neither a conventional audit nor a box-ticking exercise. When properly conducted, it is a structured, risk-based and independent process designed to assess whether a company’s integrity framework is well-designed, effectively implemented and sustainable, a standard that, within the IDB Group context, shapes how monitors evaluate a company’s remediation efforts against its sanctions or integrity-related commitments.

In practice, this is often where the main gap appears. The issue is rarely the absence of rules; more often, it is whether those rules are applied during the ordinary course of business. For instance, is there a tailored risk-based matrix that triggers specific compliance policies and procedures? How are third parties screened and monitored during the lifecycle of their engagement? Do employees know how to identify and escalate red flags and report potential wrongdoing? How are conflicts of interest addressed and managed in practice? What is the actual role of the compliance function from a corporate governance perspective? Is the company able to provide evidence of how its integrity compliance programme is managed and monitored?

These are just some initial questions that reveal whether compliance is operational within the business. Answering them requires more than reviewing documents. A holistic approach is needed to understand the company’s integrity compliance programme. At the very least, such an approach should involve interviews, transaction testing, an assessment of the company’s internal controls, a review of third-party files, analysis of the company’s training and communication efforts, an evaluation of the reporting channels in place and follow-up processes concerning any remediation measures.

The independent monitor’s role

The monitor must be independent from the company subject to monitorship. This independence is essential to ensure that the assessment is objective, credible and evidence-based, rather than reliant on the company’s own description of its programme.

At the same time, independence should not be confused with distance. A monitor needs sufficient access to the relevant information, personnel, documentation and internal processes in order to understand how the company operates and, thus, be able to make recommendations that are feasible and tailored to the company’s business and needs. The company always remains responsible for designing, implementing and managing its own integrity compliance programme. The monitor’s role is to assess its effectiveness, recommend further improvements, test its actual implementation and report the findings to the IDB sanctions officer. Striking the right balance is central to conducting effective monitorship. A monitor who is too detached may fail to capture how compliance works during the ordinary course of the company’s business and may fail to understand the company’s compliance culture. On the other hand, a monitor who becomes too involved in management decisions may compromise their own independence.

Key phases of effective monitorship

An effective monitoring process typically begins with an initial assessment and concludes with a final report. The process, however, is not strictly linear: assessment, recommendations, remediation, testing and reporting continuously inform one another in an iterative cycle.

Understanding the company

Before assessing the effectiveness of an integrity compliance programme, the monitor needs to understand the company’s DNA, that is, its business model and culture, ownership and governance structure, operations, regulatory exposure, third-party relationships, decision-making processes and existing compliance framework. This initial assessment enables the areas of greatest risk for the company to be identified and the scope of work to be defined.

Designing a risk-based work plan

The monitor should not review everything with the same level of intensity. The work plan identifies priority areas, information requests, interviewees, testing methodology, timelines and expected deliverables, so that the process remains structured, proportionate and focused on the key risks.

Review and testing

Depending on the company’s risk profile, this phase typically includes reviewing third-party due diligence files, gifts and hospitality approvals, donations and sponsorships, procurement processes, interactions with public officials, books and records, payment controls, training records, reporting channels and internal investigations, among others. This exercise may be time consuming when it involves a large volume of documents and data. A tailored AI tool can materially improve the efficiency and consistency of the review process by organising and classifying information, cross-referencing data, identifying anomalies and patterns and flagging transactions or documents that require closer examination. However, AI should remain a support tool operating under human control: the design of the testing methodology, the validation and interpretation of the results and all of the findings and conclusions must remain subject to the monitor’s professional judgment.

By reviewing and testing the evidence, the main objective is to determine whether the given integrity compliance programme is applied consistently and documented properly. Defining and using clear, tailored and specific key performance indicators (KPIs) is essential during the assessment phase.

Periodic recommendations

The findings should lead to clear, evidence-based and practical recommendations, not merely descriptive observations. They are meant to guide remediation efforts and give the company a clear sense of what needs to improve before the next review period. In this sense, reports produced as a result of monitoring function less as a record of progress or deficiencies identified and more as a feasible roadmap.

This is why the monitoring process operates as a feedback cycle: the company receives recommendations, implements corrective measures and the monitor reassesses those measures during the following reporting period to determine whether they have been adequately implemented and are working in practice, according to clear, tailored and specific KPIs.

The final report

By the final stage, the monitor should be able to assess not only whether specific gaps were addressed, but whether the company has developed a more mature, effective and sustainable integrity framework and, ultimately, whether it can maintain those improvements once the monitoring process has ended. 

Challenges and opportunities from monitorship practice

Experience of compliance, corporate governance, investigations and monitoring processes points to a consistent theme: effectiveness is evidenced through practice. This is why effective monitoring requires judgment rather than the mechanical application of generic models or international standards. While the framework described above reflects the IDB Group’s sanctions procedures, the underlying logic is transferable to other monitoring regimes, whether imposed by national enforcement authorities or other multilateral development banks. In each case, the core exercise is the same: understanding the company’s risks and culture, testing how the integrity compliance programme is implemented in practice and determining whether the programme is strong enough to respond to the environment in which the company does business.

Companies may initially perceive independent monitoring as an obligation imposed on them by an external authority. However, if properly conducted, it is also an opportunity for a company to reach the next level and transform its structure into a more efficient business by strengthening its governance processes, improving its internal controls, identifying any gaps in accountability, enhancing its documentation practices and building a more sustainable compliance culture.