Recently, there has been no shortage of regulatory changes on the horizon.
For example, companies doing business in Europe need to prepare to comply with the Corporate Sustainability Reporting Directive (CSRD), which requires businesses to report on a variety of environmental, social, and governance (ESG) metrics and submit to third-party audits.
Additionally, the U.S. Securities Exchange Commission has introduced new cybersecurity disclosure rules that will require businesses to disclose material cybersecurity incidents and report on their cyber risk management and governance strategies and abilities.
The agency is also updating rules on climate risk disclosure.
This is just a small glimpse into what is already in place and what is coming down the pipeline.
In the last few years, it has become clear that corporate boards will have to figure out how to ensure good governance in a world of constant change.
Here are six strategies to help directors stay adaptable while reducing compliance risk.
1. Understand & Stay Informed About Regulatory Changes.
Any director will have a difficult time providing oversight for something they don’t quite understand. For that reason, it’s important that board members find ways to receive timely information and insight related to regulatory shifts and any emerging risks that may be associated with them.
Having the necessary information and education about current and upcoming regulatory changes allows directors to be active participants in the governance process. It ensures that their lack of expertise won’t have them sitting on the sidelines without a plan for what to do next.
2. Ensure Access to Technical & Compliance Experts.
One way that boards can keep directors up to date about new regulations and their implications for the business is to have access to expertise on the subject.
In the case of new cybersecurity regulations, this may look like building bridges with in-house IT experts and involving the chief information security officer in discussions about compliance strategies for new SEC cybersecurity disclosure rules.
Boards should consider nominating members who possess deep compliance knowledge and experience.
These directors may come from various backgrounds, such as law or government. They may also have been compliance officers in other corporations. This ensures that they have the business knowledge required to govern these matters effectively.
Having a compliance expert on the board is instrumental in ensuring directors are addressing the right oversight questions. Their presence also speeds up training and education for board members who do not have compliance expertise, ensuring everyone is on the same page.
3. Identify &Mitigate Non-Compliance Risks.
In response to tightening regulations, boards should lead enterprise-wide risk assessments. These will determine which parts of the business are subject to regulations and where there are gaps in meeting compliance objectives.
After these risk assessments, boards should take the time to link all identified risks to specific consequences of non-compliance.
Knowing all possible outcomes helps boards understand the material risks to the organization if compliance is not prioritized. Additionally, it helps management create a viable risk mitigation plan, communicate with greater transparency about that plan, and allocate the right amount of resources toward corrective action.
4.Keep New Regulations on the Board’s Agenda.
Because regulations worldwide are changing so frequently, compliance can be a moving target. Although the risk management committee will be continually discussing regulatory developments, this should also be a regular agenda topic for the full board.
This regular discussion not only ensures proper oversight but also empowers directors to make more informed decisions about new policies, processes, controls, and other compliance-related issues.
5. Ensure Clear Communication & Collaboration.
Maintaining compliance in the modern age requires constant and clear communication between the board and the management team. First, it’s important that boards and management develop a common language for discussing complex issues.
When it comes to highly technical areas like cybersecurity, discussions can become saddled with jargon that board members without technical expertise must decode. Instead, a better use of the board’s time would be shifting the conversation to elements that matter most to the board, such as the economic impact of cyberattacks.
Additionally, the board should engage the management team in asking critical questions and outlining expectations for compliance strategies. A few common questions that should come up in these collaborative discussions include the following:
- How are the company’s compliance strategies aligned with recent regulatory changes?
- What are your plans for adapting to proposed and upcoming regulations?
- What is the process for identifying and communicating regulatory risks to the board?
- What compliance training programs will be used to educate the board and personnel at all levels on recent and ongoing changes to the regulatory environment?
- How are you managing compliance across all jurisdictions in which the company does business?
These questions serve as a foundation and a starting point for helping the board maintain proper oversight, even as regulations change.
6. Foster a Board Culture of Adaptability.
As regulations shift, boards may need to consider adaptive solutions or alternative ways of working and communicating that don’t fit into their norms.
For example, directors may need to invite new people to the table (such as technical experts) or change the nomination criteria for board members. Directors may have to embrace unfamiliar technology that will enhance compliance monitoring.
Consequently, the board must foster a culture of adaptability, both in the boardroom and throughout the organization. The world may never return to its former slow pace of regulatory change, so directors should get used to pivoting quickly to ensure ongoing compliance.
Takeway: The Only Constant Is Regulatory Change.
The corporate world has entered a new territory in which regulatory pressure will only increase. In figuring out how to navigate it, boards must commit to understanding and staying informed about regulatory changes through internal and external experts.
It is worth considering nominating board members with compliance expertise to streamline this process and ensure the board is addressing the right issues.
Additionally, boards should ensure they understand and know how to mitigate the risks of non-compliance. They should remain in constant communication with the management team about how they plan to adapt to the new pace of change.
Above all, directors must be able to maintain a culture of adaptability, as this is what will enable the board and the business to thrive as the regulatory landscape accelerates.




