Compliance can be enforced by department, by law, or with the help of an auditor.
Navex Global put together a great compliance glossary that provides a good starting point when learning about compliance: https://infinitekb.com/compliance-glossary/
FTC Safeguards
https://www.ftc.gov/business-guidance/resources/ftc-safeguards-rule-what-your-business-needs-know
ISO 27001
https://www.iso.org/standard/27001
Graham-Leach-Bliley Act
https://iapp.org/resources/article/guide-to-the-gramm-leach-bliley-act/