EU Regulatory Domain

Corporate Governance

EU company-law and governance instruments, and the growing personal accountability of management bodies.

Key facts

Corporate governance at a glance

No single EU code

EU law has no single governance code, but several instruments shape how companies are directed and controlled.

Board gender balance

By 30 June 2026, listed companies had to reach 40% of non-executive or 33% of all director positions for the under-represented sex.

Shareholder say on pay

Directive (EU) 2017/828 gives shareholders votes on the remuneration policy and the remuneration report.

Personal accountability

NIS2, DORA, the AMLR, the CSRD, the CSDDD and the AI Act increasingly make management bodies accountable for compliance.

Overview

Corporate governance is where compliance becomes a responsibility of the management body. EU law does not contain a single governance code, but several instruments shape how companies are directed and controlled, and recent sectoral legislation increasingly makes managers personally accountable for compliance outcomes.

EU governance instruments

  • Shareholder Rights Directive II, Directive (EU) 2017/828: shareholder votes on the remuneration policy and remuneration report, rules on related-party transactions, shareholder identification and transparency of institutional investors and proxy advisers;

  • Directive (EU) 2022/2381 on gender balance among directors of listed companies: listed companies had to reach, by 30 June 2026, at least 40% of non-executive director positions, or 33% of all director positions, held by the under-represented sex, and must report annually and apply transparent selection procedures;

  • audit reform, Directive 2014/56/EU and Regulation (EU) No 537/2014: audit committees in public-interest entities, auditor rotation and restrictions on non-audit services.

The accountability of management bodies

Across EU law, management bodies are now expected to own compliance:

  • cybersecurity: approval and oversight of cybersecurity measures, liability and mandatory training (NIS2, Article 20);

  • financial-sector ICT risk: ultimate responsibility for ICT risk management (DORA, Article 5);

  • anti-money laundering: a member of the management body responsible for compliance (AMLR, Article 11);

  • sustainability: sustainability information in the management report and due-diligence policies (CSRD and CSDDD);

  • artificial intelligence: measures to support AI literacy and oversight of AI use (AI Act).

Good governance in practice

  • a compliance charter: defining the mandate, independence and reporting lines of the function;

  • regular reporting: compliance reports to the board and its committees;

  • conflicts of interest: declarations, registers and management procedures;

  • policy management: an approved, updated and communicated body of internal policies;

  • evidence: minutes, decisions and follow-up of recommendations, available for supervisors and auditors.

National company law and corporate governance codes complement these instruments and must be considered in each Member State.

How we can help

Related domains: Cybersecurity (NIS2) · Digital Operational Resilience · Sustainability (CSRD/CSDDD) · Anti-Corruption

Official texts: Directive (EU) 2017/828 · Directive (EU) 2022/2381 · Regulation (EU) No 537/2014

General information as of October 2026; it does not constitute legal advice. Confirm the applicable requirements with the competent authorities.

Related domains

Where governance meets other rules

Cybersecurity (NIS2)

Management-body approval, liability and training for cybersecurity

Digital Operational Resilience

Ultimate board responsibility for ICT risk in finance

Anti-Corruption

Compliance programmes as mitigating factors for corporate liability

Give your board a clear view of compliance

Request a free review of your governance and compliance function.