Ask your compliance data anything. Sienna Insights, now available.
Join the webinar

Compliance in 2026: five pressures, one shrinking budget

Regulation is diverging, fines have hit record levels, and scandals travel in hours. The five forces behind the pressure on compliance officers, and what holds up under it.

Jasmin Stollhof
September 24, 2026
—
5 min read

Organizational risk is climbing, penalties have hit record levels, and the public reacts to misconduct in hours. At the same time budgets are tightening and calls for deregulation are getting louder in several major markets. That combination is harder to manage than a straightforward increase in regulation.

KPMG surveyed 725 chief ethics and compliance officers across eight countries and six sectors in August 2026. Asked to name their top challenge for the next two years, 33% said new regulatory requirements. A further 20% named the velocity of regulatory change as a separate problem from the rules themselves.

Five forces sit behind that picture, and each one compounds the others.

1. Volume: more rules, pulling in different directions

The EU Whistleblowing Directive, CSRD, CSDDD, LkSG, DORA, NIS2, and the EU AI Act all landed within a few years of each other. Each arrives with its own scope, deadline, and reporting format, and each asks a different question of the same underlying processes.

Divergence is the harder development. Regulatory direction is no longer uniform across markets, which fragments the work rather than reducing it. KPMG's survey shows the split: 41% of US compliance leaders named new regulatory requirements as their top challenge, against 30% elsewhere. The US is the market where deregulatory pressure is loudest, and its compliance leaders are the most worried about new rules. Uncertainty about which requirements will apply is its own burden.

PwC's compliance practice in the Netherlands points to four drivers behind the growing reporting load: constant reform (the OECD's Pillar Two minimum tax rate, CSRD sustainability reporting), authorities asking for data faster and more often, too few people to absorb the work, and cross-border obligations that each need capacity to interpret.

Teams that cope best have stopped treating each regulation as a separate project. They build one reporting and disclosure infrastructure that meets the strictest applicable standard, then map new obligations onto it. Adding a jurisdiction becomes a configuration question instead of a rebuild.

If you are mapping obligations under the EU framework, our guide to the EU Whistleblowing Directive sets out the baseline requirements for internal channels, acknowledgment timelines, and retaliation protection.

2. Velocity: real-time reporting, minimal tolerance for error

Regulators and tax authorities now expect faster and more frequent reporting, in some cases close to real time. PwC's specialists note that incomplete or inaccurate submissions meet steadily less tolerance than they once did.

A team built around quarterly cycles and manual reconciliation cannot produce accurate output on a continuous schedule. The work shifts from periodic assembly to keeping data permanently ready to be read.

3. Penalties: fines that dwarf the compliance budget

In August 2026 the Dutch Data Protection Authority fined Uber 825 million euros (roughly 966 million dollars) for deactivating driver accounts through automated systems without adequate notice or human involvement. It is the second largest GDPR penalty to date, behind Meta's 1.2 billion euro fine in Ireland. The regulator's deputy chair called the infringements serious and noted that affected drivers lost their income from one moment to the next. Uber says it strongly disagrees and will appeal.

Set the specifics aside and look at the scale. A single enforcement decision now exceeds the annual compliance spend of most large enterprises many times over. Three years ago a compliance officer asking for budget competed with other cost centers. Today the same request belongs in the enterprise risk register alongside cyber and supply chain exposure.

4. Reputation: scandal travels faster than investigation

In July 2025 a short video from a Coldplay concert put Astronomer's chief executive on screens worldwide within a day. He resigned that weekend. No regulator was involved and no law was broken. Incident to public awareness to leadership change ran in under 72 hours. A standard internal investigation takes weeks.

KPMG Australia shows what happens when an internal process and a public one run on different clocks. In March 2026, whistleblower allegations became public that partners had misused confidential client information to win audit work. The firm initially called the allegations unsubstantiated. After a fourth internal investigation, it acknowledged that internal documents had been misused and that it had mishandled the original complaint.

The chief executive, audit head, and chairman resigned. An Australian parliamentary committee opened an inquiry and in August 2026 heard evidence from Macquarie, Westpac, Optus, and Dexus, all clients named in connection with the allegations. Macquarie's chairman told the hearing the bank could reconsider KPMG's appointment as auditor. A Westpac director resigned over his ties to the firm. The inquiry is ongoing.

5. Positioning: compliance still reads as a cost center

Writing for the International Compliance Association, executive advisor Amii Barnard-Bahn describes a frustration common across the profession: leadership often sees compliance as a cost center with no connection to growth. She recounts a Fortune 500 chief executive telling her that compliance matters but accounts for about a fifth of what the CEO has to worry about. The proportion is the point. A well-evidenced case can still lose to a louder one.

Her conclusion is that influence has to be built before it is needed: frame compliance priorities in the language executives already use, tie them to business strategy, and get CFO and HR sponsorship before the decision meeting.

Budget cuts do not just limit the response, they create the risk

Constraint changes the risk profile itself. Barnard-Bahn's point is that budget cuts raise the pressure on people across the business to cut corners, which raises fraud exposure. Changes to working models raise privacy and security risk. Resources fall exactly when risk climbs.

KPMG's survey shows where the remaining money goes. Among leaders anticipating a budget increase, 77% put it toward data analytics and 75% toward cybersecurity and data privacy. Only 4% reported using automation or AI in hotlines and investigations, the lowest of any use case in the survey. Fewer than a quarter called themselves very well prepared for enhancing compliance culture (20%) or upskilling their teams (21%).

Investment is flowing toward detecting risk in data. Far less is flowing toward the channel through which people report risk directly, at a time when the conditions that make people want to report it are getting worse.

The thread connecting all five

Read the KPMG Australia timeline again and notice where the consequences compounded. The conduct was serious on its own. The handling of the internal report about it is what produced a parliamentary inquiry, three executive departures, and clients publicly reconsidering the relationship.

Someone inside raised it. The process that received it did not resolve it.

Regulation requires you to have a channel. Fines punish what the channel should have caught. Reputational speed decides whether you hear it from an employee in week one or a journalist in month nine. Budget pressure raises the volume of things worth reporting. And a channel that demonstrably works is one of the clearer ways to show a board what the compliance function is worth.

KPMG's own recommendations point the same way: design mechanisms for early detection and reporting of fraud and other incidents, including whistleblowing systems, and build a culture where people feel safe to speak out. Early detection, the report notes, stops a small issue becoming a large-scale crisis.

What holds up under this pressure

Reports reach you before they reach anyone else. That takes genuine anonymity, two-way follow-up, and enough trust that people pick your channel over social media or a regulator. Low report volume usually means people are staying quiet, not that nothing is happening.

Investigations leave a defensible record. Timestamps, decisions, and reasoning in one place, rather than reconstructed from inboxes nine months later when someone asks what you knew.

Escalation does not depend on who caught the report. Route serious allegations away from anyone with an interest in the outcome by design, not by judgment call. KPMG Australia ran three investigations that found nothing before a fourth found something.

One infrastructure covers every obligation. Whistleblowing, HR grievances, supply chain concerns, and conflict disclosures all generate signals about the same organization. Splitting them across separate systems hides the patterns that connect them.

The value is stated in business terms. Cases closed before escalation. Time to resolution. Issues caught internally rather than externally. Those translate into cost avoidance a CFO can read. A list of obligations does not.

If you are reviewing your current setup, our overview of whistleblowing software covers what to look for in intake, case management, and audit trails, and our comparison of whistleblowing software tools sets out how the main providers differ. For the foundations, start with our complete guide to whistleblowing.

Frequently asked questions

What are the biggest challenges facing compliance officers in 2026?
KPMG's 2026 survey of 725 chief ethics and compliance officers found new regulatory requirements the most cited challenge, at 33%. Data analytics and predictive modeling followed at 31%, and velocity of regulatory change at 20%. Most teams face these without proportional increases in budget or headcount.

Does deregulation reduce the compliance burden?
Not usually. When regulatory direction diverges between markets, multinationals track more regimes rather than fewer. KPMG found US compliance leaders more likely than peers elsewhere to name new requirements as their top challenge (41% against 30%), despite the US being where deregulatory pressure is strongest.

How much can non-compliance cost an organization?
Penalties vary by regulation and jurisdiction. Under GDPR the largest fines have exceeded a billion euros, and the Dutch regulator's 825 million euro decision against Uber in August 2026 ranks second to date. Fines are usually only part of the cost, alongside legal fees, remediation, lost contracts, and executive turnover.

Why do reputational risks escalate so quickly now?
Social media removes the gap between an incident and public awareness of it. A video or leaked document can reach a global audience within hours, well before an internal investigation establishes the facts.

What role does whistleblowing play in reducing compliance risk?
Internal reporting channels surface problems while they are still contained. KPMG's 2026 recommendations include designing mechanisms for early detection and reporting of fraud and other incidents, and note that early detection prevents a small issue becoming a large-scale crisis.

How can a compliance team prove it acted appropriately?
Through documentation. A structured case management system records when a report arrived, who handled it, what steps were taken, what was decided, and why. That audit trail is what regulators, boards, and courts examine.

‍

Sources

  • KPMG International, Feeling the pressure: 2026 KPMG Global Chief Ethics and Compliance Officer Survey, August 2026: kpmg.com
  • Amii Barnard-Bahn, Elevating compliance in a constrained environment, International Compliance Association, July 2025: int-comp.org
  • PwC Netherlands, Compliance: from time-consuming to value-adding, February 2024: pwc.nl
  • World Economic Forum, How can we keep pace with policy obligations while maintaining data privacy best practices?, November 2023: weforum.org
  • Reuters, Dutch regulator fines Uber $966 million for automating driver suspensions, August 21, 2026: reuters.com
  • CNN, Astronomer CEO Andy Byron resigns, July 19, 2025: cnn.com
  • Reuters, Macquarie, Westpac to testify in KPMG Australia audit scandal probe, August 13, 2026: reuters.com

Table of contents

Share
Subscribe to newsletter
By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Share