
The Compliance Framework That Connects Your Board to Every Club
Table of contents
Key takeaways
- The ISCA Systematic Approach to compliance has three axes - content, realisation, and control - each of which requires infrastructure, not just intention
- Most governing bodies have the content (codes, policies) but lack the realisation layer (distribution, education, tracking) and the control layer (whistleblowing, investigation, documentation)
- Email cannot carry governance workflows - it has no states beyond sent and not sent, no audit trail, and no way to confirm acknowledgement
- Technology respects constitutional autonomy: clubs run themselves while the federation gets the visibility it needs to govern
- If your compliance framework exists only on paper, you don't have a framework - you have a document
A state sporting body I work with has 230 affiliated clubs. Their governance team consists of two people. Those two people are responsible for ensuring that every one of those 230 clubs has current insurance, up-to-date child safety policies, completed committee returns, financial member records, and compliance with a code of conduct that was updated eighteen months ago.
They do this by email.
They send the policy. They send a reminder. They send another reminder. They chase by phone. They update a spreadsheet. At the end of the cycle, they have partial compliance data that's already out of date. Then the next compliance cycle starts.
This isn't a people problem. It's an infrastructure problem. You can't run a governance framework across hundreds of autonomous organisations using tools designed for person-to-person communication.
The framework that already exists
In 2013, ISCA and Transparency International Germany published guidelines for good governance in grassroots sport, supported by the European Commission's DG for Education and Culture. The work came out of the Good Governance in Grassroots Sport project - a multi-country initiative involving researchers and practitioners from Denmark, France, Italy, Spain, Romania, and the UK.
The centrepiece of those guidelines is what they call the Systematic Approach to compliance. It's a framework with three axes, each building on the last.
The Content Axis: what your organisation stands for. This includes an ethics code that defines expected behaviour, a zero tolerance commitment that makes consequences real, and tone from the top - visible leadership that models the standards.
The Realisation Axis: how you operationalise the content. This includes risk analysis to understand where vulnerabilities exist, structures and guidelines that translate principles into procedures, and communication and education to ensure every person in the system knows what's expected.
The Control Axis: how you enforce and correct. This includes whistleblowing channels for reporting concerns, investigation processes for following up, and a sanctions framework for consequences.
The framework is sound. Mogens Kirkeby, then president of ISCA, wrote in the foreword that grassroots sport organisations need to "prove their ability to govern themselves" or face external regulation. The Systematic Approach is how you prove it.
But here's the problem. The framework was designed as a conceptual model. It tells you what a compliance system needs. It doesn't tell you how a governing body with 200 clubs, two staff, and an email account actually runs one.
That's the gap I want to walk through.
Content Axis: you probably have this already
Most governing bodies have done the content work. They've written the code of conduct. The board has endorsed it. There's a child safety policy. There are rules about conflicts of interest, financial management, and member welfare.
The content exists. It sits in a folder on the shared drive, or on the website under "governance," or in a PDF that was emailed to clubs when it was first approved.
The problem isn't the content. The problem is what happens after it's written.
Ethics Code - distribution with proof
An ethics code that nobody has read is decoration. The ISCA framework assumes the code is distributed, understood, and acknowledged. That means every club officer, every coach, every volunteer in a relevant role has received the code and confirmed they've read it.
How do you do that across 200 clubs? You can't email a PDF to 200 club secretaries and assume it reaches every committee member. You need the code versioned - so you know which version each person acknowledged. You need acknowledgement tracked - not "the club secretary said they'd pass it on," but individual confirmation. And you need this recorded somewhere that survives committee turnover.
Zero Tolerance - more than a sentence in the annual report
Zero tolerance means incidents are tracked, responded to, and resolved. It means there's a record. It means patterns are visible. "We take a zero tolerance approach to discrimination" is a sentence. An incident register with timestamps, responses, and outcomes is a system.
Most governing bodies have the sentence. Almost none have the system.
Tone from the Top - visible, not just verbal
The ISCA framework emphasises that leaders must visibly model governance standards. In practice, this means the CEO, president, and board need communication channels that reach the network - not just the clubs that open their emails.
When the president writes about integrity, it should arrive in a channel that club officers actually use, not buried in a newsletter PDF. When the board makes a governance decision, the rationale should be shared in a way that's accessible, not locked in board minutes that nobody outside head office ever sees.
Realisation Axis: this is where everyone gets stuck
The content axis is about what you believe. The realisation axis is about making it real across every club in your network. This is where the gap between policy and practice becomes a chasm.
Risk Analysis - you need data, not guesswork
The ISCA guidelines call for systematic risk analysis. Where are the governance vulnerabilities across your network? Which clubs have had committee turnover that might mean policies haven't been handed over? Which clubs haven't returned their annual compliance forms? Which regions have clusters of complaints?
Risk analysis requires data. If your data comes from a spreadsheet that one person maintains, and that person is also doing event coordination, coaching education, and stakeholder management, your risk analysis is whatever they can remember. That's not analysis. That's anecdote.
A proper risk picture requires visibility across the network: which clubs are current on insurance, which have completed safeguarding requirements, which have acknowledged the latest code of conduct, which have filed their committee returns. When you can see that in one place, you can allocate resources to the clubs that need support, not the clubs that happen to be loudest.
Structures and Guidelines - they have to reach every club officer
Writing guidelines is necessary. Getting them to the right people is the hard part.
A safeguarding guideline needs to reach every club safeguarding officer. A financial management guideline needs to reach every club treasurer. A governance guideline needs to reach every club president and secretary.
But most governing bodies don't know who holds which role at each club. Committee details are submitted annually - if at all - and are out of date within months. The safeguarding officer from last year resigned in June. The new one was appointed in August. The governing body doesn't find out until the next annual return, which is due in March.
Role-based communication - where information routes to a person based on their function, not their name - solves this. But it requires a system that knows who holds which role at each club, in real time. Email lists built from last year's annual returns can't do this.
Communication and Education - tracked, not broadcast
The ISCA framework specifies that communication must be targeted and education must be tracked. Who has completed the safeguarding training? Who has read the updated financial procedures? Who hasn't?
Email can tell you it was sent. It cannot tell you it was read, understood, or acted on. Open tracking is unreliable. Click tracking tells you someone clicked, not that they completed something. There's no way to build a compliance picture from email metadata.
Education tracking - which club officers have completed which training modules, when, and whether their certification is still current - requires a system purpose-built for it. Henrik Brandt at the Institute for Sport Studies in Denmark contributed to the ISCA project's analysis of how organisations can make education systematic rather than ad hoc. His conclusion: it requires infrastructure, not enthusiasm.
Control Axis: the part nobody wants to build
The realisation axis is where governing bodies get stuck. The control axis is where they avoid looking entirely.
Whistleblowing - "email the chair" is not a channel
The ISCA framework calls for proper whistleblowing mechanisms. A way for anyone in the system - members, volunteers, parents, coaches - to report concerns safely.
Most governing bodies handle this by listing a contact email on their website. Some don't even do that. "If you have concerns, contact the president" is not a whistleblowing channel. It's an invitation to be talked out of reporting.
A proper channel is independent, documented, and confidential. The person reporting can submit information without confronting the person they're reporting about. There's a record of what was submitted and when. There's an obligation to investigate and respond.
This doesn't require an expensive external service. It requires a dedicated channel with a documented process and an audit trail. Technology can provide the channel. The organisation has to provide the process and the will.
Investigation and Sanctions - documentation is everything
When an investigation happens - and eventually one will - the governing body needs to demonstrate that it followed a process. That it was aware of relevant policies. That the people involved were notified. That the decision was documented. That there's an audit trail from complaint to resolution.
If your investigation process lives in email threads between the CEO and the board chair, you don't have a documented process. You have a conversation that will be extremely difficult to reconstruct if it's ever scrutinised.
Sanctions without documentation are arbitrary. Documentation without a system is fragile. The committee that handled the investigation turns over. The emails are on someone's old work account. The file was on a laptop that's been wiped.
Making it operational
Here's the thing about the ISCA Systematic Approach: every step maps to a concrete capability that a governing body either has or doesn't have.
| Framework Step | What's Actually Needed | |---|---| | Ethics Code | Versioned documents, distribution, individual acknowledgement tracking | | Zero Tolerance | Incident register, response tracking, pattern visibility | | Tone from Top | Visible leadership channels that reach the network | | Risk Analysis | Real-time compliance data across all clubs | | Guidelines | Role-based distribution to the right people at each club | | Communication | Targeted messaging by role, not broadcast to all | | Education | Training completion tracking, certification currency | | Whistleblowing | Independent reporting channel with audit trail | | Investigation | Documented process, timestamped records | | Sanctions | Decision records, notification logs, appeals documentation |
That table is what TidyConnect was built to address. Not as a governance consulting service - it's technology, not advice. But as the infrastructure layer that makes the framework operational.
TidyConnect gives a governing body line-of-sight across every club, every role, and every compliance requirement in their network. Policies are distributed with version control and acknowledgement tracking. Communication is role-based - the safeguarding lead at each club gets safeguarding updates, the treasurer gets financial compliance deadlines. Compliance dashboards show which clubs are current and which aren't. Document sharing has audit trails. Committee roles are maintained in real time, not once a year.
And critically, it respects constitutional autonomy. Clubs still run themselves. They manage their own members, their own finances, their own events. The governing body gets visibility - not control. That distinction matters enormously in federated sport, where clubs are independent legal entities with their own constitutions, and any technology that feels like surveillance will be rejected.
The alternative is external regulation
Kirkeby's warning in the ISCA foreword wasn't abstract. The EU White Paper on Sport explicitly raised the prospect of government intervention in sport governance if the sector couldn't demonstrate self-regulation. That was 2007. Nearly two decades later, the pressure has only increased. Government funding bodies in Australia, the UK, and New Zealand now require governance reporting as a condition of funding. Insurers are asking about compliance frameworks. Safeguarding regulators want evidence, not assurances.
A governing body that can demonstrate - with evidence, with data, with audit trails - that its compliance framework reaches every club and is actively maintained is in a fundamentally different position from one that says "we emailed the policy."
The ISCA Systematic Approach gives you the framework. The question is whether you have the infrastructure to run it. Two staff, 230 clubs, and an email account isn't enough. It never was.
The framework is the map. The technology is the road. You need both.
References
- ISCA & Transparency International Germany. Guidelines for Good Governance in Grassroots Sport (PDF). Systematic Approach to Compliance.
- European Commission. White Paper on Sport. COM(2007) 391.
- Sport England & UK Sport. A Code for Sports Governance.
- Boillat, C. & Tallec Marston, K. Governance Models Across Football Leagues and Clubs. CIES, 2016.
- Council of Europe. Revised European Sports Charter. CM/Rec(2021)5.
- SIGA. Sport Integrity Global Alliance.
Header image: Pause by Bridget Riley, via WikiArt
Don't miss these

Facility Plan and Usage Schedule for UAE Sports Clubs
Heat scheduling, facility booking, and developer community partnerships - here's how to plan and protect your facility access in the UAE.

How to Find Sponsors for Your UAE Sports Club
The UAE's corporate density makes sponsorship more accessible than in most markets. Here's how to pitch, deliver, and keep sponsors renewing.

Income Generation Ideas for UAE Community Sports Clubs
Beyond membership fees: practical revenue streams for UAE sports clubs, from corporate wellness and coaching academies to sponsorship and tournament hosting.