Marentis Labs

The Regulatory Direction

Regulators in the UK, EU and US are converging on continuous oversight, effective challenge and personal accountability — the very capabilities the traditional model cannot deliver. This chapter maps that regulatory direction, including the UK Corporate Governance Code's Provision 29 internal-controls declaration.

Regulators are converging on requirements the current model cannot meet. Across multiple jurisdictions, independently and without coordination, regulatory frameworks are moving toward continuous oversight, adversarial testing, personal accountability, and independent challenge. Regulators are not using the language of Strategic Governance as a Service. But the direction of travel is unmistakable.

Independent regulators, responding to the same evidence, have converged on the same set of requirements without coordination. The evidence they share is consistent. Governance frameworks that looked complete on paper failed in practice. The result is a regulatory environment that is, progressively and from multiple directions, creating the conditions in which a continuous, adversarial, independent governance function is structurally necessary.

The UK Corporate Governance Code: From Periodic Establishment to Continuous Maintenance

The Financial Reporting Council published the updated UK Corporate Governance Code [1], effective 1 January 2025. The revisions are, in places, linguistically subtle while structurally they are anything but.

Principle O, the foundation of the Code’s risk and controls framework, was revised to require that boards not merely “establish” but “maintain” effective risk management and internal control frameworks. The addition of “maintain” is a shift from a one-time act of design to a continuous obligation of oversight. It implies that a board which builds a framework and then relies on periodic review is no longer meeting the Code’s expectations.

Provision 28 was revised to require boards to explain the procedures they have in place for identifying and managing emerging risks (risks that do not yet appear on conventional risk registers and may not yet have a defined owner). This is a requirement for forward-looking, horizon-scanning governance, precisely the kind of activity that is crowded out when the second and third lines are consumed by monitoring and retrospective assurance.

Most significantly, Provision 29 (effective 1 January 2026) requires boards to make an annual declaration on the effectiveness of the organisation’s material internal controls. The scope is explicit, covering financial, operational, reporting, and compliance controls. It extends well beyond financial reporting. Boards must take personal, public ownership of control effectiveness across all four dimensions of the business.

The practical implication is that boards will need independently validated evidence that their material controls are effective. The question the Code implicitly raises, and does not answer, is: who provides that independent validation on a continuous basis, across the full scope of material controls, with a mandate that extends beyond the retrospective assurance provided by internal audit?

The Caremark Doctrine: From Compliance to Mission-Critical Risk

While the UK’s governance evolution is principles-based, the United States has developed a parallel, and in some respects more consequential, trajectory through case law. The Caremark doctrine, originating in a 1996 Delaware Chancery Court decision, has evolved over three decades from a narrow compliance-monitoring duty into an expansive fiduciary obligation that now reaches the heart of operational governance.

The original In re Caremark decision (1996) established that directors have a duty to implement information and reporting systems. Stone v. Ritter (2006) [2] affirmed and codified this as a two-prong test, under which liability arises where directors either utterly fail to implement any reporting system, or, having implemented one, consciously fail to monitor its operation.

For over two decades, Caremark claims were virtually impossible for plaintiffs to win. The doctrine was real but dormant. That changed in 2019.

Marchand v. Barnhill (2019) revitalised the doctrine in a case involving Blue Bell Creameries, an ice cream manufacturer whose products were linked to a listeria outbreak. The Delaware Supreme Court held that the board had breached its Caremark duties by failing to monitor food safety, an operational risk that was “mission critical” to the company’s business, extending the oversight obligation beyond legal compliance. The court introduced a new principle. Where a risk is intrinsically critical to the company’s operations, the board’s oversight obligation is heightened.

Boeing confirmed and extended Marchand. The $237.5 million Caremark cash settlement (the largest in Delaware history) was based on the finding that Boeing’s board had established no committee-level oversight of aircraft safety, the single most mission-critical operational risk in commercial aviation.

In January 2023, the Delaware Court of Chancery took the doctrine further still. In In re McDonald’s Corporation (2023) [3], the court extended Caremark duties from directors to corporate officers. The standard is identical. Officers face personal liability for bad-faith failure to oversee matters within their remit. The effect is to create personal accountability at every level of the governance hierarchy for mission-critical oversight.

The trajectory. Caremark has evolved from a duty to build compliance systems (1996) to a duty to monitor those systems (2006) to a duty to build governance architecture specifically around mission-critical operational risks (2019–2022) to personal officer-level liability for oversight failures (2023). The direction is consistent. Courts are no longer asking whether boards had governance frameworks. They are asking whether those frameworks were designed to address the risks that actually mattered and whether anyone was mandated to challenge the assumption that they did.

DORA: The Adversarial Principle in Regulation

The European Union’s Digital Operational Resilience Act [4], fully effective from 17 January 2025, introduces a regulatory concept with implications beyond its immediate scope, namely the principle that critical functions should be subjected to structured, adversarial challenge as a governance-level control.

DORA requires significant financial entities to conduct threat-led penetration testing (TLPT) of critical IT functions at least every three years, based on bespoke threat intelligence tailored to the entity’s risk profile. The framework aligns with the European Central Bank’s TIBER-EU methodology, which provides governance-level guidance on red teaming as a structured control framework.

An epistemological distinction is necessary. DORA’s TLPT operates in the technical domain. A penetration test either breaches a system’s defences or it does not. The outcome is empirically verifiable. Strategic governance challenge operates in a different domain. A board’s M&A thesis, its technology investment case, or its strategic assumptions about competitive positioning cannot be empirically broken before the fact. What can be tested is not the assumption itself but the quality of evidence supporting it, in particular whether the proxies are weak, the reasoning motivated, or the cognitive biases documented in Section 3 are operating on the decision. Technical testing delivers a binary verdict. Strategic falsification delivers a calibrated assessment of evidentiary fragility.

The significance of DORA for this paper’s argument lies not in a claim of equivalence between technical and strategic testing. It lies in the regulatory recognition that critical functions should be subjected to structured adversarial scrutiny, not as a voluntary exercise in risk maturity, but as a governance obligation. The governance function that oversees it is accountable for ensuring that the testing produces actionable intelligence. That principle, the principle that adversarial challenge is a governance-level control, applies with equal force in the strategic domain, where the consequences of unchallenged assumptions are no less severe and the evidentiary basis is often more fragile.

DORA applies to credit institutions, investment firms, payment institutions, insurance undertakings, and other financial entities across the EU. Its TLPT requirement applies to systemically significant entities. The principle it embeds, that critical functions require structured adversarial scrutiny, extends naturally from technical infrastructure to strategic governance, provided the epistemological distinction is maintained. SGaaS maintains it. The methodology described in Section 9 applies Popperian falsification to governance assumptions, dismantling the evidence that supports strategic positions rather than claiming to break the positions themselves.

SM&CR: Personal Accountability as a Governance Accelerant

The UK’s Senior Managers and Certification Regime [5], implemented progressively from March 2016 for banks and building societies and extended to all FCA-regulated firms from December 2019, represents a different dimension of the regulatory convergence, the creation of personal consequences for governance failure.

Under SM&CR, each Senior Management Function holder has a statutory Duty of Responsibility. If the firm breaches a regulatory requirement, the senior manager responsible for that area faces personal enforcement action unless they can demonstrate they took “reasonable steps” to prevent or stop the breach. The burden is on the individual and the consequences are personal, including financial penalties, restrictions, and reputational damage that follow the individual personally.

SM&CR does not prescribe how senior managers should discharge their duty, nor does it mandate any particular governance structure. What it creates is a powerful incentive (or more precisely, a powerful fear) that drives demand for demonstrable, independently validated governance assurance. A senior manager whose Statement of Responsibilities includes risk oversight has a personal interest in ensuring that an independent function is continuously challenging the governance framework within which they operate. If the framework fails, “I relied on internal audit’s annual assurance” may not satisfy the “reasonable steps” test. “I commissioned continuous, adversarial, independent review and acted on the findings” is a materially stronger defence.

The FCA and PRA initiated a review of SM&CR in March 2023, examining whether the regime adequately promotes governance accountability and challenge functions. The review signals regulatory awareness that personal accountability, while necessary, may not be sufficient without the structural governance mechanisms that give senior managers the information they need to discharge their duties.

Operational Resilience: From Risk Registers to Disruption Tolerances

A further dimension of convergence is visible in the operational resilience frameworks emerging across multiple jurisdictions. These frameworks share a common departure from traditional risk management. They ask organisations to go beyond listing risks and quantify their tolerance for disruption, and to demonstrate, continuously, that they can operate within those tolerances.

In the UK, the PRA and FCA’s operational resilience rules required firms to demonstrate by 31 March 2025 that they can operate within defined impact tolerances for their important business services. This is a fundamentally different governance requirement from maintaining a risk register. It requires boards to make quantified commitments about the maximum disruption their organisation can withstand and to test, on an ongoing basis, whether their operations would remain within those bounds under adverse conditions.

In Australia, APRA’s Prudential Standard CPS 230, effective 1 July 2025, establishes that the board is “ultimately accountable” for operational risk management. The standard requires boards to set disruption tolerances for critical operations, approve business continuity plans, and continuously monitor operational risk profiles.

In Canada, OSFI’s Guideline E-21, published in final form in August 2024, mandates continuous monitoring, reporting, and escalation of operational risks to the board, with disruption tolerances set and actively monitored at board level.

The pattern is consistent across jurisdictions. Regulators are requiring boards to move from passive receipt of periodic assurance reports to active, continuous governance of operational resilience. The boards that can demonstrate this level of oversight (with independent validation and adversarial challenge) will satisfy regulatory expectations. Those that continue to rely on periodic internal assurance will face increasing scrutiny.

The Wider Convergence

The regulatory developments described above are not isolated. They are part of a broader, multi-jurisdictional convergence toward the same set of governance requirements.

The Basel Committee’s Corporate Governance Principles for Banks (BCBS 328) require independent risk management functions with sufficient stature to challenge business line decisions, direct reporting to the board, and explicit authority to escalate risk concerns without management veto.

The EU’s Corporate Sustainability Due Diligence Directive [6], entered into force in July 2024, extends board-level accountability to human rights and environmental risks across the entire value chain, requiring continuous identification and assessment of impacts that go far beyond traditional financial governance. Member states are required to transpose the Directive into national law by July 2026, with phased applicability for companies by size thereafter.

The SEC’s cybersecurity governance rules, evolving since 2023, require public companies to disclose board-level cybersecurity oversight practices and the processes through which the board oversees cybersecurity risk, creating strong practical incentives for boards to receive regular briefings on risk assessments and tabletop exercises.

The Japan Financial Services Agency’s Corporate Governance Reform 2025 principles [7] require boards to “persistently assess the appropriateness of current allocation of resources” and strengthens board independence.

The Monetary Authority of Singapore [8] updated its outsourcing notices in December 2023 to mandate board-level governance frameworks for third-party risk with continuous executive oversight.

Multi-jurisdictional regulatory convergence: requirements, traditional responses, and structural gaps
Regulatory RequirementJurisdictionsTraditional ResponseStructural Requirement
Continuous oversight of risk and controlsUK (Principle O), Australia (CPS 230), Canada (E-21), Singapore (MAS)Quarterly board reports; annual risk reviewA function providing continuous, real-time governance intelligence to the board
Adversarial testing of critical functionsEU (DORA TLPT), ECB (TIBER-EU), SEC (tabletop exercises)Periodic technical penetration testing; compliance auditsStructured adversarial challenge extended from technical infrastructure to strategic governance assumptions through falsification of evidentiary support
Mission-critical risk governance architectureUS (Caremark: Marchand, Boeing, McDonald’s), UK (Provision 29)Generic risk committee with broad remitDedicated governance architecture around the organisation’s most consequential risks
Personal accountability for oversightUK (SM&CR), US (Caremark officer liability), Australia (CPS 230 board accountability)Collective board responsibility; “I wasn’t told” defenceDemonstrable evidence that the individual took reasonable steps, including commissioning independent challenge
Independent challenge functionsBCBS 328, FSI Fourth Line, UK SM&CR, APRA CPS 230Internal audit’s periodic assuranceA permanent, independent function mandated to challenge management narratives and board assumptions

The convergence is not only regulatory. The Committee of Sponsoring Organizations of the Treadway Commission, the consortium of the AAA, AICPA, FEI, IMA, and IIA whose 2017 framework defines the global ERM standard, published From Guidance to Action in 2026 [9]. The paper restates the requirement that risk management be embedded in strategy and decision rhythms rather than reported alongside them, and concedes that most ERM programmes produce documentation without affecting choices. The framework authors have therefore moved, on their own analysis, from the assurance-centric model toward the continuous, decision-led, adversarially tested governance the regulatory developments above are converging on. The direction of travel is regulatory and normative at the same time.

What Regulators Are Asking For and What Does Not Yet Exist

The regulatory convergence described in this section creates a set of requirements that are clear in their direction and challenging in their implementation.

Regulators are asking for continuous, not periodic, governance oversight. They are requiring adversarial testing of critical functions and assumptions. They are creating personal accountability for governance failures at board and officer level. They are demanding independent challenge functions with the authority to escalate without management veto. And they are extending governance obligations beyond financial compliance to mission-critical operational risks across the full scope of the business.

These requirements describe a function that does not currently exist within most organisations’ governance architecture. Internal audit provides retrospective assurance. Risk management monitors the present, but often does not have the bandwidth to look to the future. External audit provides periodic certification. The board itself meets periodically and is remote from day to day business activity.

The Financial Stability Institute recognised this structural gap as early as 2015 [10], proposing a “fourth line of defence” to supplement the three-lines model. But the FSI’s fourth line consisted of external auditors and regulatory supervisors, entities that provide additional periodic assurance rather than the continuous, adversarial, principal-led challenge that regulators are now, by logical implication, increasingly requiring.

The regulatory gap. Regulators across multiple jurisdictions are converging on a consistent set of governance requirements: continuous oversight, adversarial challenge, mission-critical risk architecture, personal accountability, and independent escalation. These requirements describe a function that the existing governance architecture (the Three Lines Model, supplemented by external audit and regulatory supervision) was not designed to provide. The regulatory direction is clear and this paper proposes a structural response: Strategic Governance as a Service.

The following sections examine the value gap this creates and the structural response it demands.



References

  1. Financial Reporting Council. (2024). UK Corporate Governance Code.
  2. Delaware Supreme Court. (2006). Stone v.\ Ritter.
  3. Delaware Court of Chancery. (2023). In re McDonald's Corporation Stockholder Derivative Litigation.
  4. European Parliament & Council of the European Union. (2022). Regulation (EU) 2022/2554 of the European Parliament and of the Council on Digital Operational Resilience for the Financial Sector and Amending Regulations (DORA).
  5. Financial Conduct Authority & Prudential Regulation Authority. (2019). Senior Managers and Certification Regime (SM&CR).
  6. European Parliament & Council of the European Union. (2024). Directive (EU) 2024/1760 of the European Parliament and of the Council of 13 June 2024 on Corporate Sustainability Due Diligence and Amending Directive (EU) 2019/1937 and Regulation (EU) 2023/2859. http://data.europa.eu/eli/dir/2024/1760/oj
  7. Financial Services Agency (Japan). (2025). Action Programme for Corporate Governance Reform 2025. Financial Services Agency.
  8. Monetary Authority of Singapore. (2023). Guidelines on Outsourcing (Banks).
  9. Ryan Luttenton et al.. (2026). From Guidance to Action: Exploring Practical Enterprise Risk Management. Committee of Sponsoring Organizations of the Treadway Commission (COSO).
  10. Isabella Arndorfer & Andrea Minto. (2015). The ``Four Lines of Defence Model'' for Financial Institutions: Taking the Three-Lines-of-Defence Model Further to Reflect Specific Governance Features of Regulated Financial Institutions. Financial Stability Institute, Bank for International Settlements. https://www.bis.org/fsi/fsipapers11.htm