Europe · Sanctions and compliance

The role of the Board of Directors in corporate compliance

Erich Rath11 min read

The Role of the Board of Directors in Corporate Compliance Practice Guidelines for Board Members, General Counsels and Compliance Officers of International Companies

Mainstream

The role of the board of directors in corporate compliance is not a formal statement of policy. It is a personal responsibility to ensure that the company does not break the law.

The main question is not whether the company has accepted compliance procedures. The main question is whether board members can prove that they have fulfilled their duty of oversight and have done due diligence when a breach occurs.

Effective participation of the Board of Directors in the compliance system is based on three fundamental tests:

  • Does the board know the real compliance risks of the business?
  • Is there a system in place that detects and prevents these risks?
  • Can the Board document its actions and decisions?

If these three elements are missing, board members risk not only the company’s reputation, but also personal administrative and criminal liability in some jurisdictions. In the context of EU sanctions, export controls and cross-border investigations, this is not a theory, but a reality of recent years.

When the role of the board of directors in compliance is raised

The issue of board responsibilities becomes critically practical in the following situations:

  • the company operates in markets affected by EU sanctions regimes;
  • products or technologies are subject to export controls (EU Regulation 2021/821);
  • the business has subsidiaries, counterparties or supply chains in third countries;
  • Due diligence is conducted under the M&A framework and historical sanctions violations are discovered.
  • the company receives a request from the national regulator or the European Commission;
  • “red flags” – suspicious payments, bypass schemes, signs of re-export to sanctioned jurisdictions were identified;
  • the appointment or reappointment of board members after a compliance incident is considered;
  • The internal investigation revealed systemic oversight deficiencies.

In all these cases, regulators, and later courts, will assess not only the actions of management, but also what the board did or did not do.

The mistake most boards of directors make

Many of the advice comes from a false premise:

Compliance is the job of the legal department and the compliance officer.

That's a dangerous misconception.

The correct question is as follows:

Has the Board of Directors established a compliance system that allows it to make informed decisions and identify risks that threaten the business and its members personally in a timely manner?

Delegation of operational functions does not remove fiduciary duties from the board of directors. In key EU jurisdictions, especially Germany, the Netherlands and France, as well as at the level of the case-law of the Court of Justice of the EU, a standard is consistently being developed: Members of the governing bodies are liable if they have not properly organized the compliance function, have not monitored its operation or ignored signals of violations.

In the area of sanctions and export controls, this logic is reinforced by: Member States have introduced a directive on harmonisation of criminal liability for breaches of restrictive measures, which directly raises the issue of responsibility of senior officials.

Step 1. Determine applicable compliance obligations

The first thing the board should do is not hire consultants or approve policies, but to clearly define what regulatory requirements the business is subject to.

Key regulatory blocks for an international company in the EU:

  • Council Regulations on restrictive measures (sanctions packages);
  • Regulation 2021/821 on the export controls of dual-use goods and technologies
  • national legislation of the country of incorporation on the liability of legal entities and managers;
  • sectoral requirements (financial sector, energy, defense industry);
  • rules of currency control and prohibition on the provision of economic resources;
  • recommendations of the European Commission and national regulators on due diligence;
  • Extraterritorial risks (including the possible impact of U.S. sanctions, where applicable)

If a company has several business units in different countries, the compliance map should be built taking into account all overlapping regimes. The board does not have to know every technical detail, but it does require that the map be prepared, updated and included in strategic decisions.

Step 2. Assessing the real risks of business

Compliance risks are not limited to direct supplies to sanctioned countries.

The Board of Directors should understand the risks associated with:

  • re-export through third countries;
  • use of front companies and intermediaries;
  • payments in currencies subject to restrictions;
  • intangible technology transfer (technical assistance, cloud services, software);
  • participation in projects with indirect involvement of sanctioned persons;
  • controlled delivery through subsidiaries;
  • transactions with companies whose beneficiaries are hidden;
  • professional services (legal, accounting, consulting), which can be qualified as the provision of economic resources.

The risk-based approach enshrined in the Commission’s recommendations requires the Council to periodically review the risk map and mandate management to update it.

Step 3. Approval of the structure of the compliance function

The Board of Directors is responsible for ensuring that the compliance function is:

  • independent of operational management;
  • Provided with sufficient resources (budget, staff, IT systems);
  • integrated into key business processes (sales, procurement, M&A, finance);
  • Reports directly to the board or audit/complice committee.

The right architecture includes:

  • Compliance officer with direct access to the board;
  • Council-level compliance committee (especially relevant for high-risk companies)
  • regular reporting (at least once a quarter);
  • An escalation procedure in which serious incidents are brought to the council immediately.

The Council should enshrine this architecture in its statutes, committees and policy-makers.

Step 4. Provide a system of sanctions due diligence

This is the operational task of management, but the board must set the standard.

The system should cover:

  • Verification of counterparties, beneficiaries and end recipients against EU sanctions lists and national lists;
  • screening of goods for export control;
  • End-use and end-user analysis
  • Red flag control (non-standard supply routes, complex payment chains, circumvention requests)
  • procedures for suspending the transaction when risk is identified.

From the point of view of the Council, it is critical not to write these procedures on paper, but to make sure that they work. This is done through independent audits and testing (sampling).

Step 5. Provide information and training to Council members

The board cannot effectively perform its supervisory function if it does not understand the basic rules.

Minimum standard:

  • Annual training of the Council members on sanctions, export control and personal liability;
  • regular strategic sessions on compliance risks;
  • Providing the Council with brief analytical notes on new sanctions packages and their impact on business.

In the event of an incident, the regulator will inevitably ask: Did the Board understand the applicable restrictions? The lack of training protocols becomes an aggravating circumstance.

Step 6. Monitoring and internal investigations

A compliance system without monitoring is an illusion of control.

The Board shall ensure that the Company:

  • Whistleblowing channels complying with EU Directive 2019/1937 are in place.
  • There is an internal investigation procedure when signals are received;
  • The results of investigations are reviewed at the level of the board or compliance committee;
  • Corrective measures, including personnel and disciplinary decisions, are being taken.

Particularly sensitive: If the board receives information about possible sanctions violations and does not take action, this practically guarantees accusations of inaction or connivance by the regulator.

Step 7. Evaluate and document the decisions of the Board

Many council members are at risk not because they have not done compliance, but because they have failed to prove their prudence.

The Council shall ensure that:

  • discussion of compliance risks and sanctions issues in the minutes of the meetings;
  • Compliance officer reports and decisions thereon;
  • justifying approval of transactions in sensitive regions;
  • the results of risk assessment and measures taken to reduce them.

The rule is simple: If this is not the case, it is not the case from the regulator’s point of view.

Step 8. Checking the personal risks of the Board members

Board members in a number of EU countries can be held administratively, civilly and even criminally liable for a company’s violation of sanctions if it is proven that they have not provided proper supervision.

Key areas of personal risk:

  • liability to the company (shareholders' claims for damages);
  • liability to third parties;
  • Prohibition of employment (disqualification);
  • in some cases – criminal prosecution (Germany, France, the Netherlands);
  • Reputational impacts and restrictions on cross-border travel.

The Board should regularly receive legal analysis of these risks, taking into account the specific jurisdiction and enforcement practices.

Direct oversight or delegation: It is important to understand the board of directors

CriteriaDirect oversight of the boardDelegating to Management Without Control
Compliance with the duty of care standardProvided that decisions are documentedPractically not provided
Protection from personal liabilityStrengthen positionWeakening position
Early identification of risksHigher.Below.
Council resourcesIt takes time and expertise.Save time, but create blind spots
Acceptable for small risksNot always justified.It can be justified with low risk and strong control.
Acceptable in the field of sanctions and exportsPractically necessarily.Extremely risky.

Conclusion: In the areas of sanctions and export controls, delegation without active supervision is the transfer of responsibility without risk transfer, which ultimately remains on the board.

Common mistakes of the Board of Directors in the compliance system

  1. There are policies without their testing, but they do not work in practice.
  2. No member of the Council has any knowledge of sanctions and export control.
  3. For a year, you can skip the sanctions package, which will destroy the entire business unit.
  4. Ignoring Compliance Officers If the compliance officer reports a problem and the board does not respond, it is an aggravating circumstance.
  5. When a compliance officer is subordinate to a CFO or sales manager, a conflict of interest is inevitable.
  6. Underestimating extraterritorial risks A deal could be legal under EU law but pose risks under US or UK sanctions if there are contacts with their jurisdictions.
  7. When a breach is detected, chaos begins instead of a structured response.
  8. The purchase of a company with historical sanctions violations without proper verification is one of the most frequent reasons for subsequent investigations.

Checklist of board member

Before signing a protocol or approving a transaction, each board member should ask himself or herself 15 questions:

  1. Do I know what sanctions regimes apply to our business?
  2. Has the risk assessment been carried out across all business lines and jurisdictions?
  3. Is there an independent compliance officer with direct access to the board?
  4. Are there policies on sanctions, export controls and due diligence?
  5. Have these policies been tested in the last 12 months?
  6. Do I receive regular reports of compliance incidents?
  7. Is there a procedure for escalating serious violations to the council?
  8. Have the Council members been trained on current sanctions risks?
  9. Have key counterparties and supply chains been screened for sanctions risks?
  10. Are the discussions on risks documented at the council meetings?
  11. Have I received information about red flags in transactions and response measures?
  12. Is there a Whistleblowing Channel?
  13. Has the personal responsibility of the members of the board been analysed in the relevant jurisdictions?
  14. Is there a plan of action in case of sanctions violations?
  15. Can I, based on the documentation, prove my due diligence before the regulator or the court?

If the answer to at least five questions is negative or uncertain, the compliance system is not secure from the board’s point of view.

What a strong role of the board of directors looks like in the compliance system

The strong model includes five levels:

1. Tone at the Top: A public and internal position of the council demonstrating zero tolerance for sanctions violations. Compliance is not a cost, but a license to do international business.

2. Governance Structure: Clear architecture The Council’s compliance committee, independent compliance officer, fixed lines of accountability, budget and veto power over risky transactions.

3. Risk-Based Policies & Procedures: Real-world risk map policies, automated screening, due diligence procedures, end-user control and end-use.

4. Monitoring & Assurance: Independent compliance audits, selective transaction checks, data screening, not just paper reports.

5. Enforcement & Consequence Management: The consistent application of disciplinary action, rectification of deficiencies and communication with the regulator in the event of an incident, based on documented action by the board.

Without tier one and tier five, even well-written politicians do not save the council from accusations of a formal approach.

FAQ

Can a member of the board of directors be held personally liable for a company’s breach of EU sanctions?

Yeah. In some EU Member States, rules on the responsibility of senior officials for failure to take appropriate measures to prevent infringements are in place or are being introduced. This may be administrative, civil or criminal liability depending on the severity of the infringement and jurisdiction.

What is the evidence of the Council’s performance?

Documentation: Meeting minutes with discussion of compliance risks, approved policies, compliance officer reports, protocols for responding to red flags, confirmation of training.

Is it enough to appoint a compliance officer to remove responsibility from the board?

Nope. The appointment is just one element. The Board shall ensure the independence, resources and accountability of the compliance function and shall exercise effective oversight.

How often should the board consider sanctions risks?

In international business with medium and high risks - at least once a quarter. If there are any drastic changes in the sanctions regimes (the new EU packages), it should be done immediately.

What should the Council do if a violation of sanctions has been found in the past?

Don't panic, but don't shut up. Immediately initiate an internal investigation led by external lawyers, assess the need for voluntary self-disclosure, isolate the problem, and take steps to prevent recurrence. Inaction of the council in such a situation is the greatest risk.

Does the board have to monitor every transaction?

No, but it must approve criteria under which transactions require escalation to the level of a board or compliance committee (countries, amounts, types of goods, red flags).

Related services

  • Sanctions, Export Controls & International Compliance
  • Corporate Governance & Directors’ Duties
  • Cross-Border Internal Investigations
  • Sanctions Due Diligence for M&A Transactions
  • Regulatory Defense & Enforcement Actions
  • Compliance System Design & Audit
  • Personal Liability Risk Assessment for Directors
  • EU Sanctions Advisory & Strategic Risk Management

Related material

  • Personal liability of directors for breach of EU sanctions
  • How to build sanctions compliance in an international company
  • Due diligence of the counterparty under EU sanctions
  • The new EU Export Control Regulation: What the Board of Directors Needs to Know
  • Internal investigation in case of violation of sanctions: practical guide
  • Risks of Board Members in M&A Transactions in Sanctions Jurisdictions
  • How to prepare a company for the inspection of the EU sanctions regulator
  • Tone at the Top: Why does compliance begin with the board of directors?

Conclusion

The role of the board of directors in the corporate compliance system is not an additional burden, but the content of its fiduciary duties in the conditions of strict sanctions regulation.

Effective protection of business and directors is not based on ad hoc approval of documents, but on constant supervision, competence, documentation of decisions and the ability to prove the integrity of their actions.

In the era of European sanctions packages, criminal harmonization and enforcement, the council that wins is not the one that delegates compliance to management, but the one that has built compliance into strategic governance and can demonstrate it to the regulator.

Have a question about the topic of this article?

Write to us and we will respond within one business day.