Skip to main content
Should We Wait for New Legislation?Enterprise Risk Management
4 min readFor Compliance Officers

Should We Wait for New Legislation?

Understanding the Current Compliance Landscape

Since Andy Burnham took office in July, compliance officers across sectors have been asking: what changes now? The closure of the Department for Science, Innovation and Technology (DSIT), increased funding for the Serious Fraud Office, and John Edwards's retirement announcement from the Information Commissioner's Office have created uncertainty. However, the most pressing questions aren't about new laws. They're about procurement terms, contract requirements, and monitoring policy shifts that won't appear in legislation trackers. These are the key concerns raised in recent practitioner discussions.


Q1: We don't bid on government contracts. Should we still care about procurement policy changes?

Yes, procurement priorities influence regulatory focus. If the government mandates supply-chain transparency or apprenticeship commitments in contracts, it indicates where compliance expectations are heading. Section 172 of the UK Companies Act 2006 already requires your board to consider long-term consequences, community impact, and reputation. When procurement terms formalize these expectations, auditors and regulators will use them as benchmarks even for companies outside the public sector.

Also, consider your indirect exposure. If your customers or partners work with the public sector, their new contractual obligations could affect you through their vendor requirements.


Q2: How do we monitor policy shifts that aren't legislation?

Implement a three-layer monitoring system. First, track ministerial appointments and departmental changes. For instance, AI Minister Kanishka Narayan's role in the Cabinet Office and the new Department for Business, Innovation, Science and Trade suggests AI policy will be coordinated at a high level, leading to faster implementation.

Second, monitor procurement guidance and contract templates from the Crown Commercial Service and sector-specific authorities. Changes here often precede regulatory shifts.

Third, pay attention to regulator speeches and enforcement priorities. The Serious Fraud Office's increased funding emphasizes intelligence-gathering and proactive identification of major economic crimes. This isn't a law change, but it significantly impacts your risk profile if you're a large corporation handling public funds.


Q3: Our board de-prioritized ESG programs after US policy shifts. Should we reverse that?

First, review your Section 172 compliance. UK law requires directors to consider environmental impact, community effects, and business conduct standards. If your board minutes don't document how you're meeting these duties, you have a governance gap.

Next, assess your public-sector exposure. If you supply government entities or their prime contractors, expect ESG criteria and supply-chain transparency requirements to appear in procurement terms without new legislation. The government can drive compliance expectations through contracts more swiftly than through Parliament.

Don't assume UK policy will mirror US direction. The compliance landscape here has different statutory foundations and a distinct political trajectory.


Q4: What does the failure-to-prevent-fraud offense mean for our compliance program?

Your fraud prevention procedures must be proportionate, documented, and actively enforced. With increased Serious Fraud Office funding focused on technology and investigative capability, expect more sophisticated detection of control failures.

Your program should cover six principles: top-level commitment, risk assessment, proportionate procedures, due diligence, communication and training, and monitoring and review. Document how you've applied each principle to your specific risk profile. Regulators will expect you to demonstrate thoughtful consideration of your fraud risks and the controls you've implemented.

If you handle public money or work with government entities, assume you're in a high-scrutiny category.


Q5: Should we strengthen whistleblowing protections now or wait?

Strengthen them now. The current administration is more pro-employee, and there's been public discussion about enhancing protections. Review your procedures against three tests: Can employees report anonymously through multiple channels? Are protections clear for workers who raise concerns about public interest issues? Do managers understand that retaliation includes subtle exclusion or assignment changes?

Check your documentation. If an employee reports fraud or safety concerns and later claims retaliation, ensure you have a clear record of how you handled the disclosure and why you made subsequent decisions about their role. Weak documentation creates liability even when you've acted correctly.


Q6: The Cyber Security and Resilience Bill is still moving through Parliament. Should we wait to see final text before updating our program?

No. The committee stage in the House of Lords is scheduled for September, but you can already anticipate the direction. Use the current draft to identify likely requirements and start building capabilities now. If the final text is weaker, you'll have stronger controls than required. If it's stronger, you won't be scrambling.

Consider the risk of devolution. If cybersecurity enforcement is devolved, you could face different regulators in different parts of the UK. Start mapping which of your operations fall under which jurisdictions and what that might mean for reporting obligations and incident response protocols.


Next Steps

Monitor the Department for Business, Innovation, Science and Trade's guidance as it consolidates DSIT's former responsibilities. Watch the Crown Commercial Service for procurement template changes. Track Serious Fraud Office case announcements and enforcement priorities. Don't ignore the new Information Commissioner once appointed; the regulator is dealing with rising complaints, including complex ones generated with AI assistance, while implementing new powers under the Data (Use and Access) Act 2025.

The next compliance shift won't arrive with parliamentary fanfare. It'll appear in a contract term, a procurement requirement, or a regulator's shift in enforcement emphasis. Your task is to spot it early.

You Might Also Like