Compliance, Regulatory and Quality: Different Functions, Shared Purpose
As biotech and pharmaceutical organisations grow, the structures around them usually become more complex. There is an increasing need for specialist expertise, new functions are created, and responsibilities become more clearly defined. Among the functions commonly involved in managing organisational risk are Healthcare Compliance, Regulatory Affairs, and Quality. Yet despite their importance, they are not always fully understood.
For example, ask a business leader what distinguishes Compliance from Quality, or where Regulatory Affairs overlaps with either function and their answer is often unclear. In smaller organisations, individuals may perform elements of all three roles. In larger organisations, they tend to operate as separate functions, but then it could appear as if multiple teams are addressing similar issues through different lenses. Employees may wonder why several functions are reviewing the same activity, requesting similar information, or providing guidance on closely related topics.
This uncertainty can create confusion, duplicated effort, gaps in oversight, inconsistent decision-making, and unintended conflicts between functions. Perhaps most importantly, it can reinforce the mistaken belief that compliance is the responsibility of specialist functions rather than a shared organisational commitment.
The reality should be quite different.
Although Compliance, Regulatory Affairs, and Quality have their own unique set of responsibilities, their underlying objective is shared: to help organisations earn and maintain trust. Trust from patients. Trust from healthcare professionals. Trust from regulators. Trust from investors, partners, and employees.
Viewed through this lens, the question is not where one function’s responsibilities end and another’s begin. The more important question is how these functions work together to create an environment where the organisation consistently does the right thing, operates effectively, handles challenges seamlessly, and can withstand scrutiny.
Different Perspectives on the Same Objective
One way to look at the three functions is to consider the unique perspective each of them brings. Each views organisational risk through a different lens.
- Regulatory Affairs focuses on ensuring products meet the requirements of health authorities throughout their lifecycle. It helps organisations understand regulatory expectations, secure and maintain approvals, and manage interactions with regulators.
- Quality focuses on ensuring that products and processes consistently meet defined standards. Quality provides assurance that products are safe, reliable, and manufactured or managed appropriately through implementation of quality management systems, controls, oversight activities, and continuous improvement mechanisms.
- Healthcare Compliance focuses on organisational behaviour. It aims to ensure that employees, leaders, and third parties act ethically, comply with applicable laws and industry codes, and make decisions that can withstand external scrutiny.
These perspectives are different, but they are not competing.
Regulatory asks, “Are we authorised to do this?”
Quality asks, “Can we demonstrate that this is being done correctly and consistently?”
Compliance asks, “Is this the right thing to do, and are we doing it appropriately?”
Together, they provide a more complete view of organisational risk than any one function could achieve in isolation.
Beyond Organisational Charts
When talking about Compliance, Regulatory Affairs, and Quality, many healthcare organisations treat them as separate disciplines. Organisational charts reinforce this distinction, with each function reporting through different structures, maintaining different procedures, and focusing on different regulatory requirements.
Yet stakeholders outside the organisation rarely see these distinctions.
A regulator does not distinguish between a regulatory weakness, a quality issue, or a compliance failure when assessing organisational credibility. Investors evaluating a biotech approaching commercialisation are interested in whether the organisation is well governed, adequately controlled, and capable of sustainable growth. Patients are concerned with the safety and effectiveness of products, not which department manages a particular process.
External stakeholders see only one organisation.
This distinction matters because it shifts the conversation away from functional ownership and towards organisational outcomes. Effective governance is not achieved simply through the existence of individual functions. It is achieved when those functions, while retaining their distinct responsibilities, work together to support consistent decision-making, effective risk management, and a culture of accountability.
The Risk of Functional Silos and Poor Coordination
Issues do not arise because Compliance, Regulatory Affairs, and Quality exist as separate disciplines. In fact, maintaining specialist expertise, independent challenge, and clear accountabilities is often essential. The challenge arises when information, insights, and decisions are not effectively shared across those functions.
The Compliance team may identify a concern involving healthcare professional engagement without fully understanding the underlying regulatory implications. The Quality team may detect process weaknesses that have broader compliance consequences. Regulatory specialists may be aware of evolving requirements that have not yet been fully incorporated into quality systems or organisational controls.
If information remains within functional boundaries and is not communicated effectively, important risks can be overlooked or addressed too late.
This challenge becomes particularly significant during periods of organisational change. Organisations transitioning from clinical development into commercial operations frequently experience a rapid increase in external interactions, regulatory obligations, third-party relationships, and stakeholder scrutiny. Decisions become faster, more decentralised, and more visible.
In this environment, effective partnership between Compliance, Regulatory Affairs, and Quality becomes a business necessity. The objective is not to blur accountabilities, combine reporting lines, or create uniform processes. Rather, it is to ensure that specialist functions remain aligned around shared organisational objectives, risks, and strategic priorities.
Where Collaboration Creates Value
Some of the most important risk areas within pharmaceutical organisations sit at the intersection of these three functions.
Consider data integrity. Regulatory teams rely on accurate and reliable data to support submissions as well as to communicate effectively with health authorities. Quality functions establish controls designed to ensure data is generated, recorded, reviewed, and retained appropriately. Compliance functions help ensure employees to understand their responsibilities and how behaviours support transparency and accountability.
The objective is shared, even if the perspectives differ.
Data protection also falls into this category. Patient, healthcare professional, employee, and business data must be managed responsibly and lawfully. Regulatory requirements, quality controls, record management processes, and privacy obligations are often interrelated. Treating data protection as the responsibility of a single function can mean the important risks are left unaddressed.
Third-party oversight presents another example. Suppliers, distributors, contract research organisations, and service providers may introduce regulatory, quality, and compliance risks through the work they do on your behalf. Effective oversight therefore requires coordinated input from multiple functions rather than separate assessments conducted in isolation.
The strongest organisations recognise these overlaps and deliberately create opportunities for collaboration, breaking down the barriers. Effective governance depends less on organisational integration and more on organisational alignment, ensuring that distinct functions connect their expertise, coordinate their activities, and work together to support sustainable business performance.
Building a Culture, Not Just a Framework
All of these functions contributes to creating an environment where people understand expectations, raise concerns, learn from mistakes, and make informed decisions. All support transparency, accountability, and continuous improvement. Each seeks to prevent problems before they occur rather than expecting incidents to be managed.
All of these functions shape culture. Importantly, none of them owns culture.
Leaders often describe compliance culture as something created by the compliance department. However, culture emerges from organisational behaviours, incentives, decisions, and leadership actions. Specialist functions provide expertise, challenge, and guidance, but culture is shaped by the organisation as a whole and embedded by leaders.
The most effective pharma or biotech organisations do not view Compliance, Regulatory Affairs, and Quality as separate control functions operating independently. They view them as partners who support common objectives: protecting patients, supporting business performance, and maintaining stakeholder trust.
Ultimately, regulators, healthcare professionals, investors, partners, and patients do not judge organisations by the effectiveness of individual functions. They judge them by the quality of their decisions, the integrity of their actions, and the confidence they inspire. Building that confidence requires Compliance, Regulatory, and Quality to work as a united system of governance, not as separate disciplines.
How GRC Catalyst can help
At GRC Catalyst, we help biotech and healthcare organisations strengthen governance, clarify responsibilities, and create practical ways for specialist functions to work together more effectively. The goal is not simply compliance with requirements, but building the confidence, resilience, and trust needed to support sustainable growth.
Disclaimer
This article reflects the views and professional judgement of the author. Where external sources have been used, they have been referenced as appropriate. The author is responsible for the substance, interpretation and final editorial review of the article. AI tools were used to support research, improving the grammar and flow of the article, and factual checking.