Governance fatigue has become the newest organisational risk
Across the UK and EU, organisations are wrestling simultaneously with the EU AI Act, the Digital Operational Resilience Act (DORA), the Corporate Sustainability Reporting Directive (CSRD), the Network and Information Systems Directive 2022/0383 (NIS2), strengthened anti-money laundering reforms, UK operational resilience requirements, Consumer Duty and rapidly evolving AI governance initiatives. Individually, each framework has a clear purpose. Collectively, they can overwhelm governance structures through overlapping controls, reporting obligations and ownership models.
The paradox is striking. Despite larger compliance teams, better technology and more regulatory guidance than ever before, many organisations feel less in control. The challenge is no longer interpreting individual regulations. Instead, it is designing a single governance model capable of coordinating them intelligently, reducing duplication and supporting confident business decisions rather than creating ever more bureaucracy.
When More Rules Create More Risk
Conventional wisdom assumes that more regulation automatically strengthens compliance. In reality, expanding rulebooks often produce duplicated controls, overlapping reporting, inconsistent risk assessments and policy overload that exhaust rather than protect organisations. This growing compliance overload creates governance debt, where maintaining fragmented frameworks consumes resources without improving resilience. Assurance fatigue follows as teams repeatedly gather similar evidence through separate governance structures. A financial institution, for example, may assess the same cyber risks independently for DORA, NIS2, ISO 27001 and operational resilience despite substantial overlap.
Progressive organisations instead recognise regulatory convergence by mapping common controls across multiple frameworks and collecting evidence once for many purposes. The objective shifts from satisfying individual regulations to creating one integrated governance model. More controls do not necessarily deliver more assurance. Better connected controls, supported by unified ownership and evidence, usually achieve far stronger outcomes with less organisational strain.
Escaping the Control Maze
Leading organisations are abandoning separate governance programmes for AI, cyber resilience, ESG, sanctions, financial crime, privacy and operational resilience in favour of integrated governance. Instead of maintaining duplicate controls, they are adopting common controls, shared evidence repositories, integrated risk taxonomies, enterprise control libraries and unified governance platforms. This approach recognises that many regulations rely on the same organisational capabilities, including effective risk management, sound data governance and board oversight.
Emerging ideas such as governance-by-design, integrated assurance, connected controls, digital control libraries and compliance architecture encourage evidence to be collected once and reused many times. For example, firms implementing DORA increasingly map ICT controls to wider enterprise risk frameworks rather than managing them separately, while global technology companies use common control frameworks to satisfy multiple regulatory and customer requirements simultaneously. Increasingly, successful organisations govern capabilities instead of individual regulations, reducing duplication while improving consistency, accountability and resilience.
Why Ownership Matters More Than Ever
Technology can streamline governance, but people still determine whether it succeeds. Many organisations discover that everyone owns part of a regulatory obligation while nobody owns the overall outcome. The result is duplicated committees, conflicting reporting lines, policy ownership confusion and fragmented accountability across the first, second and third lines. Risks fall between organisational boundaries rather than within them.
Leading organisations are responding by replacing isolated compliance teams with cross-functional governance councils, federated ownership models and clear executive accountability for shared risks. For example, several major financial institutions have established enterprise AI governance committees that bring together compliance, legal, cyber, risk, data and business leaders instead of creating another standalone function. This reflects a broader shift towards enterprise accountability, where governance depends upon coordinated decision-making rather than departmental expertise.
The Institute of Internal Auditors’ Three Lines Model similarly emphasises collaboration and alignment across governance roles instead of rigid separation. In an increasingly interconnected regulatory landscape, organisations that collaborate effectively are more likely to identify emerging risks, eliminate duplication and make faster, better-informed decisions.
Creating a Compliance Function That Anticipates Change
Compliance teams are moving beyond reacting to regulatory announcements towards anticipating what comes next. Horizon scanning, regulatory intelligence, AI-assisted monitoring, predictive compliance, regulatory change analytics, scenario planning and strategic risk sensing are becoming core capabilities rather than specialist activities. New developments such as AI-powered regulatory monitoring, machine-readable regulation, continuous compliance and even regulatory digital twins promise to model the impact of future rules before they take effect.
The UK’s Financial Conduct Authority (FCA) has already explored machine-readable and machine-executable regulation through its Digital Regulatory Reporting initiative, while firms increasingly use AI to monitor regulatory developments across multiple jurisdictions. Future compliance professionals will spend less time interpreting lengthy legal texts and more time assessing commercial implications, advising strategy and preparing organisations for emerging obligations. The competitive advantage will lie not in responding fastest after a regulation appears, but in recognising patterns early and adapting governance before disruption occurs. Tomorrow’s compliance function will therefore become a strategic intelligence capability as much as a control function.
Less Bureaucracy, Better Assurance
The future of governance is not more bureaucracy but better design. Successful organisations are making governance simpler, faster, embedded, technology-enabled and proportionate by adopting risk-based assurance, automation, embedded controls, assurance by exception and continuous monitoring. Rather than creating separate compliance activities, they are integrating governance directly into everyday business workflows, allowing risks to be identified and addressed as decisions are made. Financial institutions implementing DORA, for example, are increasingly automating control testing and evidence collection, reducing manual effort while improving confidence in regulatory compliance. This shift enables compliance teams to spend less time chasing documentation and more time advising the business.
Intelligent governance also encourages innovation because controls become part of normal operations instead of obstacles imposed afterwards. The goal is not fewer controls but smarter ones that deliver meaningful assurance without unnecessary administration. Organisations that outperform competitors will not necessarily be those with the biggest compliance departments. They will be those that make governance almost invisible because it is intelligently designed into how the organisation operates every day.
And what about you…?
- Where do you see the greatest signs of governance fatigue in your organisation, such as duplicated reporting, overlapping controls or unclear ownership?
- What one practical step could your organisation take over the next year to simplify governance while strengthening assurance and supporting innovation?


