EU Regulatory Domain
EU company-law and governance instruments, and the growing personal accountability of management bodies.
Key facts
EU law has no single governance code, but several instruments shape how companies are directed and controlled.
By 30 June 2026, listed companies had to reach 40% of non-executive or 33% of all director positions for the under-represented sex.
Directive (EU) 2017/828 gives shareholders votes on the remuneration policy and the remuneration report.
NIS2, DORA, the AMLR, the CSRD, the CSDDD and the AI Act increasingly make management bodies accountable for compliance.
Corporate governance is where compliance becomes a responsibility of the management body. EU law does not contain a single governance code, but several instruments shape how companies are directed and controlled, and recent sectoral legislation increasingly makes managers personally accountable for compliance outcomes.
Shareholder Rights Directive II, Directive (EU) 2017/828: shareholder votes on the remuneration policy and remuneration report, rules on related-party transactions, shareholder identification and transparency of institutional investors and proxy advisers;
Directive (EU) 2022/2381 on gender balance among directors of listed companies: listed companies had to reach, by 30 June 2026, at least 40% of non-executive director positions, or 33% of all director positions, held by the under-represented sex, and must report annually and apply transparent selection procedures;
audit reform, Directive 2014/56/EU and Regulation (EU) No 537/2014: audit committees in public-interest entities, auditor rotation and restrictions on non-audit services.
Across EU law, management bodies are now expected to own compliance:
cybersecurity: approval and oversight of cybersecurity measures, liability and mandatory training (NIS2, Article 20);
financial-sector ICT risk: ultimate responsibility for ICT risk management (DORA, Article 5);
anti-money laundering: a member of the management body responsible for compliance (AMLR, Article 11);
sustainability: sustainability information in the management report and due-diligence policies (CSRD and CSDDD);
artificial intelligence: measures to support AI literacy and oversight of AI use (AI Act).
a compliance charter: defining the mandate, independence and reporting lines of the function;
regular reporting: compliance reports to the board and its committees;
conflicts of interest: declarations, registers and management procedures;
policy management: an approved, updated and communicated body of internal policies;
evidence: minutes, decisions and follow-up of recommendations, available for supervisors and auditors.
National company law and corporate governance codes complement these instruments and must be considered in each Member State.
Compliance Assessment: a governance and compliance-function review;
Compliance Secretariat: minutes, registers and the regulatory calendar;
Training & Capacity: board training on compliance responsibilities;
Fractional Compliance Officer: an independent compliance function on retainer.
Related domains: Cybersecurity (NIS2) · Digital Operational Resilience · Sustainability (CSRD/CSDDD) · Anti-Corruption
Official texts: Directive (EU) 2017/828 · Directive (EU) 2022/2381 · Regulation (EU) No 537/2014
General information as of October 2026; it does not constitute legal advice. Confirm the applicable requirements with the competent authorities.
Related domains
Request a free review of your governance and compliance function.