Kurumsal UyumCorporate Compliance

Uyum (Compliance) Hukuku: Kavram, Tarihsel Gelişim, Uluslararası Standartlar ve Türk Hukuku

Compliance Law: Concept, Historical Development, International Standards and Turkish Law

Ceylan Avukatlık · Kurumsal Uyum · Ders ve değerlendirme metni
Ceylan Law Office · Corporate Compliance · Instructional and analytical text

Çağdaş hukuk düzenleri, ihlal sonrası ceza uygulayan klasik anlayıştan, ihlalin gerçekleşmeden önlenmesini esas alan bir paradigmaya doğru evrilmiştir. Bu dönüşümün merkezindeki kavram, uluslararası literatürde "compliance" olarak adlandırılan ve Türkçeye "uyum" ya da "kurumsal uyum" olarak çevrilen kavramdır.

1. Uyum (Compliance) Kavramı

En genel anlamıyla uyum, bir kişinin veya kurumun tabi olduğu hukuk kurallarına, düzenleyici gerekliliklere, sektörel standartlara ve benimsediği etik ilkelere uygun davranmasını sağlamaya yönelik sistematik çabaların bütünüdür. Kavramı iki anlam katmanında düşünmek gerekir: birincisi bir sonuç durumu (kurumun belirli bir anda hukuka uygun konumda olması); ikincisi ve daha önemlisi bir kurumsal işlev — hukuka uygunluğu sürekli temin etmek üzere kurulan politikalar, prosedürler, kontroller, eğitimler, izleme ve raporlama yapılarının tümü.

Bu çerçevede bir uyum programı, hukuka aykırılıkları ve etik ihlalleri önlemek, tespit etmek ve bunlara müdahale etmek için tasarlanan bütüncül sistemdir. Etkin bir uyum programının asgari unsurları arasında yazılı politika ve prosedürler, üst yönetimin desteği ve gözetimi, risk değerlendirmesi, eğitim ve farkındalık, gizli ihbar (whistleblowing) kanalları, izleme ve denetim, disiplin mekanizmaları ve sürekli iyileştirme yer alır.

Uyum; hukuk, işletme, etik, risk yönetimi ve kurumsal yönetim arasında kesişen melez bir kavramdır. Hukuk normunu "kâğıt üzerindeki hukuktan" (law in books) "yaşayan hukuka" (law in action) dönüştüren kurumsal aracıdır.

2. Mevzuata Uygunluğun Ötesinde: Dört Boyut

Çağdaş uyum kavramı, indirgemeci "kurala uyma" anlayışının ötesine dört boyutla geçer:

3. Kavramsal Ayrımlar

Birbirinin yerine kullanılan ancak kapsamları farklı kavramları ayırmak gerekir: legal compliance (kanunlara biçimsel uygunluk — en dar anlam), regulatory compliance (BDDK, SPK, EPDK, BTK gibi regülatörlerin ikincil mevzuatına uygunluk), ethics and compliance (kural takibini değerlere dayalı davranışla birleştiren yaklaşım) ve corporate compliance (uyum işlevinin kurum bünyesinde örgütlenmiş bütünü). Bu kavramlar iç içe halkalar gibidir: en içte yasal uyum, onu çevreleyen düzenleyici uyum, genel uyum ve en dışta etik/değer temelli uyum kültürü.

4. Uyum Anlayışının Tarihsel Gelişimi

Bugünkü anlamıyla uyum — kurumların devletin doğrudan denetimini tamamlayan bir öz-düzenleme (self-regulation) sistemi kurması — esas olarak yirminci yüzyılın ikinci yarısında ABD'de şekillenmiştir. "Denetimli öz-düzenleme" modelinde devlet, kurumlardan kendi iç uyum sistemlerini kurmalarını bekler; bu sistemlerin varlığı ve etkinliği sorumluluğun belirlenmesinde dikkate alınır.

Avrupa'da uyum daha geç ve farklı bir gelenekte gelişti. UK Bribery Act (2010), "ticari kuruluşun rüşveti önlemede başarısız olması" adıyla özgün bir kurumsal suç tipi getirerek, şirketin tek savunmasını "yeterli prosedürlere" (adequate procedures) sahip olduğunu kanıtlamaya bağlamış; böylece etkin uyum programını cezaî sorumluluktan kurtulmanın şartı hâline getirmiştir. Fransa'nın Sapin II (2016) Kanunu belirli şirketlere yolsuzlukla mücadele programı kurma yükümlülüğü getirmiş ve AFA'yı kurmuştur. Uluslararası planda OECD Rüşvetle Mücadele Sözleşmesi (1997) ve BM Yolsuzlukla Mücadele Sözleşmesi — UNCAC (2003) belirleyicidir.

Uyum hukuku büyük ölçüde bir "skandal–tepki" döngüsünde ilerlemiştir: Watergate FCPA'yı, Enron/WorldCom SOX'u, 2008 krizi Dodd-Frank'i doğurmuştur. Küreselleşme ise en katı standartları (FCPA, UK Bribery Act, GDPR) fiilen evrensel normlara dönüştürmüştür.

5. Uluslararası Standartlar ve Düzenleyici Çerçeve

Çağdaş uyum, çoğu zaman doğrudan bağlayıcı olmasa da (soft law) fiilen "iyi uygulama" ölçütü kabul edilen bir standartlar bütünü üzerinde yükselir:

Bu standartların üç temel işlevi vardır: kılavuzluk (etkin sistemi nasıl kuracağını göstermesi), meşruiyet/güvence (yatırımcı ve iş ortaklarına ciddiyetin kanıtı) ve hukukî savunma (ihlal hâlinde sorumluluğun hafifletilmesi).

6. Kurumsal Yönetim ile İlişki

Uyum ile kurumsal yönetim (corporate governance) arasındaki ilişki parça–bütün ilişkisidir: uyum, etkin kurumsal yönetimin vazgeçilmez bir bileşeni ve somut tezahürüdür. Şeffaflık, hesap verebilirlik, sorumluluk ve adillik ilkeleri ancak işleyen bir uyum sistemiyle gerçekliğe taşınır.

Uyumun kurumsal yapıdaki yeri "üç savunma hattı" (three lines of defence) modeliyle açıklanır: birinci hat riski fiilen üstlenen operasyonel iş birimleri; ikinci hat riski gözeten ve çerçeveleyen uyum ve risk yönetimi işlevleri; üçüncü hat tüm sistemi bağımsız değerlendiren iç denetimdir. İç kontrol, risk yönetimi, uyum ve iç denetim birbirini tamamlar ancak birbirinin yerine geçmez; bağımsızlıklarının korunması kritiktir.

Uyum işlevinin taşıyıcısı, uyum görevlisidir (compliance officer / CCO). Etkinliği üç niteliğe bağlıdır: bağımsızlık, yönetim kuruluna/denetim komitesine doğrudan erişim ve yeterli yetki ve kaynak. Etkin uyumun en belirleyici tek unsuru ise "tepeden gelen ton"dur (tone from the top): üst yönetimin uyuma yalnızca sözde değil, kaynak ayırarak, ihlalleri rütbe ayrımı yapmadan yaptırıma bağlayarak ve örnek olarak fiilen bağlılık göstermesi. Bu zayıf olduğunda en gelişmiş program dahi "kâğıt üzerinde program" olarak kalır.

7. Türk Hukukundaki Yansımalar

Türk hukukunda uyum, tek bir "uyum kanunu" altında değil, hukuk dallarına yayılmış sektörel düzenlemeler aracılığıyla şekillenir:

Genel eğilim, AB müktesebatına uyum, FATF gibi mekanizmaların baskısı ve küresel entegrasyonla birlikte Türk uyum hukukunun zamanla daha bütünsel ve sıkı bir çerçeveye doğru evrildiği yönündedir.

8. Uygulamadan Örnekler

Sınır ötesi rüşvet: Yurt dışı ihalesi için "danışman" eliyle kamu görevlisine yapılan ödeme, "danışmanlık ücreti" görünümünde olsa da rüşvettir; şirket hem TCK m.252 hem de (bağlantı varsa) FCPA/UK Bribery Act kapsamında sorumlu olabilir. Üçüncü taraf gerekli özeni, muhasebe kontrolleri ve eğitim bu riski engellerdi.

Rekabet — bilgi paylaşımı: Dernek toplantısında rakiplerle fiyat/kapasite planı paylaşımı, açık anlaşma olmasa dahi "uyumlu eylem" sayılıp cironun %10'una varan cezaya yol açabilir.

Veri ihlali: Siber saldırıyla kişisel verilerin sızması hâlinde KVKK uyarınca Kurul'a ve ilgililere bildirim zorunludur; önceden kurulu bir veri koruma programı hem riski azaltır hem de yükümlülüklerin zamanında yerine getirilmesini sağlar.

Kara para aklama: Ekonomik gerekçesi açıklanamayan çok sayıda küçük havalenin hızla aktarılması ("katmanlama") MASAK'a şüpheli işlem olarak bildirilmelidir.

9. Sonuç

Uyum, artık yalnızca uzmanlaşmış bir alt-disiplin değil, hukuk pratiğinin her alanına nüfuz eden bir düşünme biçimidir. Çağdaş uyum; mevzuata uygunluğu, etiği, risk önlemeyi, kurumsal kültürü ve hesap verebilirliği bir arada taşır ve hukukun ağırlık merkezinin cezalandırmadan önlemeye, geçmişten geleceğe kaymasını temsil eder. Etkin uyum, sağlam kurumsal yönetim olmadan mümkün değildir; bağımsız bir uyum işlevi, güçlü bir uyum görevlisi konumu ve her şeyden önce "tepeden gelen ton" bu yapının taşıyıcılarıdır. Bir kurumun gerçek anlamda uyumlu olması, nihayetinde dürüstlüğü kurumsal karakterine içselleştirmesiyle mümkündür.

Contemporary legal orders have evolved from the classical understanding of punishing violations after the fact toward a paradigm centered on preventing violations before they occur. The concept at the heart of this transformation is the one termed "compliance" in the international literature, rendered in Turkish as "uyum" or "corporate compliance."

1. The Concept of Compliance

In its most general sense, compliance is the entirety of the systematic efforts aimed at ensuring that a person or an institution acts in conformity with the legal rules to which it is subject, with regulatory requirements, sector standards, and the ethical principles it has adopted. The concept must be understood on two levels of meaning: first, as a state of outcome (the institution being in a legally compliant position at a given moment); and second, and more importantly, as an institutional function — the entirety of the policies, procedures, controls, training, monitoring, and reporting structures established to continuously secure legal conformity.

Within this framework, a compliance program is the holistic system designed to prevent, detect, and respond to legal violations and ethical breaches. Among the minimum elements of an effective compliance program are written policies and procedures, senior management support and oversight, risk assessment, training and awareness, whistleblowing channels, monitoring and auditing, disciplinary mechanisms, and continuous improvement.

Compliance is a hybrid concept lying at the intersection of law, business administration, ethics, risk management, and corporate governance. It is the institutional instrument that transforms the legal norm from "law in books" into "law in action."

2. Beyond Regulatory Conformity: Four Dimensions

The contemporary concept of compliance moves beyond the reductive understanding of "rule-following" through four dimensions:

3. Conceptual Distinctions

It is necessary to distinguish concepts that are used interchangeably but differ in scope: legal compliance (formal conformity with statutes — the narrowest sense), regulatory compliance (conformity with the secondary legislation of regulators such as the BRSA, the Capital Markets Board, EMRA, and the ICTA), ethics and compliance (an approach that combines rule-following with values-based conduct), and corporate compliance (the organized whole of the compliance function within the institution). These concepts are like concentric rings: legal compliance at the innermost core, surrounded by regulatory compliance, then general compliance, and at the outermost an ethics- and values-based culture of compliance.

4. The Historical Development of the Compliance Approach

Compliance in its present sense — institutions establishing a system of self-regulation that complements the state's direct oversight — took shape mainly in the second half of the twentieth century in the United States. Under the "enforced self-regulation" model, the state expects institutions to establish their own internal compliance systems; the existence and effectiveness of these systems are taken into account in determining liability.

In Europe, compliance developed later and within a different tradition. The UK Bribery Act (2010), by introducing an original corporate offense entitled "failure of a commercial organization to prevent bribery," made the company's sole defense contingent on proving that it had "adequate procedures" in place; it thereby turned an effective compliance program into a condition for escaping criminal liability. France's Sapin II (2016) Act imposed on certain companies the obligation to establish an anti-corruption program and created the AFA. On the international plane, the OECD Anti-Bribery Convention (1997) and the UN Convention against Corruption — UNCAC (2003) are decisive.

Compliance law has largely advanced in a "scandal–response" cycle: Watergate gave rise to the FCPA, Enron/WorldCom to SOX, and the 2008 crisis to Dodd-Frank. Globalization, in turn, has effectively transformed the strictest standards (FCPA, UK Bribery Act, GDPR) into universal norms.

5. International Standards and the Regulatory Framework

Contemporary compliance rests on a body of standards that, though often not directly binding (soft law), are in practice accepted as the benchmark of "good practice":

These standards have three fundamental functions: guidance (showing how to build an effective system), legitimacy/assurance (proof of seriousness to investors and business partners), and legal defense (mitigation of liability in the event of a violation).

6. Relationship with Corporate Governance

The relationship between compliance and corporate governance is one of part to whole: compliance is an indispensable component and concrete manifestation of effective corporate governance. The principles of transparency, accountability, responsibility, and fairness can be brought into reality only through a functioning compliance system.

The place of compliance within the corporate structure is explained by the "three lines of defence" model: the first line consists of the operational business units that actually bear the risk; the second line comprises the compliance and risk management functions that oversee and frame the risk; the third line is internal audit, which independently evaluates the entire system. Internal control, risk management, compliance, and internal audit complement one another but do not substitute for one another; safeguarding their independence is critical.

The bearer of the compliance function is the compliance officer (CCO). Its effectiveness depends on three qualities: independence, direct access to the board of directors/audit committee, and adequate authority and resources. The single most decisive element of effective compliance, however, is the "tone from the top": senior management's genuine commitment to compliance not merely in word but by allocating resources, sanctioning violations without regard to rank, and leading by example. Where this is weak, even the most sophisticated program remains a "paper program."

7. Reflections in Turkish Law

In Turkish law, compliance is shaped not under a single "compliance statute" but through sector-specific regulations dispersed across the branches of law:

The general trend is that, together with harmonization with the EU acquis, pressure from mechanisms such as the FATF, and global integration, Turkish compliance law is over time evolving toward a more holistic and stringent framework.

8. Examples from Practice

Cross-border bribery: A payment made to a public official through a "consultant" for a foreign tender constitutes bribery even if it appears as a "consultancy fee"; the company may be liable both under Article 252 of the Turkish Penal Code and (where there is a connection) under the FCPA/UK Bribery Act. Third-party due diligence, accounting controls, and training would have prevented this risk.

Competition — information sharing: Sharing price/capacity plans with competitors at a trade association meeting may be deemed a "concerted practice" even absent an express agreement, leading to a fine of up to 10% of turnover.

Data breach: Where personal data is leaked through a cyberattack, notification to the Board and to the data subjects is mandatory under the Data Protection Law; a data protection program established in advance both reduces the risk and ensures that obligations are fulfilled in a timely manner.

Money laundering: The rapid transfer of numerous small remittances with no explicable economic rationale ("layering") must be reported to MASAK as a suspicious transaction.

9. Conclusion

Compliance is no longer merely a specialized sub-discipline but a way of thinking that permeates every field of legal practice. Contemporary compliance carries regulatory conformity, ethics, risk prevention, corporate culture, and accountability together, and it represents the shift of law's center of gravity from punishment to prevention, from the past to the future. Effective compliance is not possible without sound corporate governance; an independent compliance function, a strong compliance officer position, and above all the "tone from the top" are the load-bearing elements of this structure. An institution's being truly compliant is ultimately possible only by internalizing integrity into its corporate character.

Uyum (Compliance)Kurumsal YönetimFCPAUK Bribery ActISO 37301ISO 37001FATF / MASAKKVKKTTKSPK
ComplianceCorporate GovernanceFCPAUK Bribery ActISO 37301ISO 37001FATF / MASAKKVKKTCC (Commercial)SPK

Bu yazı genel hukuki bilgilendirme amacı taşır; somut durumunuz bakımından avukatlık hizmeti yerine geçmez.

This article is for general legal information only and does not substitute for legal counsel on your specific situation.

Hukuki desteğe mi ihtiyacınız var?

Need legal support?

Konunuzu ekibimizle görüşün; en kısa sürede size dönüş yapalım.

Discuss your matter with our team; we will get back to you shortly.

Bize UlaşınGet in Touch