Cross-Regional Compliance: How to Surface Risks Before They Escalate

Legal & Compliance

Alaa El-Shaarawi - FaceUp Copywriter and Content Manager

Alaa El-Shaarawi

Copywriter and Content Manager

Published

2026-07-21

Reading time

11 min

Table of contents

    Subscribe to our newsletter

    Cross-Regional Compliance: How to Surface Risks Before They Escalate

    Most compliance programs look solid on paper. Policies are documented, training is completed, and reporting channels are technically in place. And yet, issues still surface too late. Leaders are caught off guard. Employees stay silent when it matters most.

    By the time a problem becomes visible, it’s usually harder to contain and more expensive to resolve. The gap isn’t necessarily in the framework, but in how compliance lives inside the organization.

    This article is based on insights from the FaceUp webinar, Master Cross-Regional Compliance with Ljuba Kovačević, Senior Compliance Leader at GE Vernova.

    In the session, Daniëlla Gyselinck speaks with Ljuba about what separates programs that exist from those that actually work. Drawing from years of experience across EMEA, Ljuba shares what it takes to build compliance systems that influence behavior, surface risks early, and support real business decisions.

    As Ljuba put it, the greatest value of compliance comes when it helps organizations identify and address issues before they become larger problems.

    Special Graphic - Ljuba.png

    Modern Compliance Starts With Prevention

    Compliance has traditionally been reactive: an issue arises, it gets investigated, damage is controlled, and lessons are documented. But by the time something becomes visible, it’s already expensive. Financially, legally, and culturally. The real value of compliance lies in prevention.

    Ljuba described an early experience where an internal report was handled quickly and fairly before it escalated. It never became a crisis because the company was able to act while the issue was still small.

    “That taught me the value of trust, early action, and clear processes. Companies can learn before it becomes a real issue, before regulators come in, and employees can share what they see.”

    This is where many organizations fall short. Once an issue is widely visible, the opportunity to contain it early is usually gone.

    Prevention works because it shifts the timeline. Instead of responding to outcomes, companies respond to signals. Those signals often come from employees. From things they see daily and concerns that would never appear in formal audits or standard reporting lines.

    When those signals are captured early, organizations can act before:

    • Regulators get involved
    • Costs increase
    • Reputation is damaged
    • Issues become harder to manage internally
    • Teams lose trust

    If those signals are missed, the focus shifts from prevention to response. This is where compliance moves from a cost center to a risk control mechanism that actively protects the business.

    Global Compliance Programs Need Local Adaptation

    Rolling out compliance across regions introduces complexity that policies alone can’t solve. Organizations often design global standards with the expectation that they’ll apply uniformly. In practice, they rarely do.

    Different regions bring different realities:

    • Cultural perceptions of authority and reporting
    • Language nuances that affect how policies are understood
    • Labor laws and works councils that influence implementation
    • Varying levels of compliance maturity

    Ljuba emphasized a principle that consistently works: global standards, local execution.

    Global Standards, Local Execution

    Making a system available doesn’t mean people will use it. Adoption depends on trust. 

    “You can’t apply the same approach in every region and expect the same level of trust.”

    This means keeping a unified framework while adapting how it’s introduced, communicated, and embedded in each region. For example, a speak-up channel may be technically identical across countries, but how it’s explained, positioned, and trusted can differ significantly.

    In some regions, employees may hesitate due to historical or cultural associations with reporting. In others, adoption may be faster but require clearer guidance on process and expectations.

    Ignoring these differences leads to low engagement. Respecting them drives adoption. It also reduces the risk of blind spots where issues go unnoticed for longer.

    Special Graphic - Local adaptation.png

    Compliance Adoption Depends on Trust

    One of the most underestimated challenges in compliance is perception. In many organizations, reporting channels are still viewed negatively. They’re associated with escalation, punishment, or internal conflict.

    This perception alone is enough to prevent usage. The solution isn’t adding more tools, but changing how those tools are understood.

    Compliance need to be framed as a way to:

    • Protect employees
    • Prevent harm
    • Improve how teams work

    "People don't report because there's a system. They report because they believe something will happen when they do."

    When employees see reporting as something that benefits them, not something that puts them at risk, behavior changes. This requires deliberate communication.

    Organizations need to:

    • Clearly explain how reporting works
    • Show what happens after a report is submitted
    • Share examples of positive outcomes
    • Reinforce confidentiality and protection

    Without this, low reporting is often a sign of low trust in the system.

    Creating Confidence in the Reporting Process

    Implementing a reporting tool is only the first step. Adoption depends on trust, and trust depends on communication.

    Organizations need to invest in:

    • Clear onboarding and explanation of the system
    • Transparency around investigation processes
    • Visibility into outcomes and improvements
    • Continuous reinforcement over time

    One common mistake is treating implementation as a one-time project. In reality, speak-up programs require ongoing attention.

    Employees need to see that reporting leads to action, concerns are taken seriously, and the system is reliable. When this happens, engagement increases. When it doesn’t, the system becomes inactive.

    Cross-Regional Compliance Requires Visibility and Alignment

    Compliance doesn’t operate in isolation. And when alignment breaks down, something subtle but risky starts to happen.

    As Ljuba pointed out, especially in remote and distributed environments, teams can begin to operate independently. Over time, they develop their own ways of working, their own interpretations of rules, and their own norms. In some cases, they effectively become their own “kingdoms.”

    Not by design, but as a result of limited visibility and weak cross-team connection. When that happens, culture fragments.

    What gets flagged in one team might be ignored in another. Small issues stay local until they escalate. And when they finally surface, it often becomes clear that early signals were missed.

    Cross-Functional Ownership Keeps Teams Aligned

    Behind this sits a structural reality. Compliance initiatives require coordination across multiple functions:

    • Legal to interpret regulations
    • HR to align with employee processes
    • IT to support systems and data
    • Operations to implement changes
    • Communications to drive awareness

    This naturally creates friction. Each function has its own priorities, timelines, and constraints. According to Ljuba, successful implementation depends on structure and clarity:

    • Assigning clear ownership across teams
    • Defining simple, shared metrics
    • Establishing regular communication cadence

    But structure alone isn’t enough. Alignment requires trust and influence. Compliance leaders need to explain why initiatives matter, how they support business goals, and what impact they’ll have.

    This is also where whistleblowing systems play an important role. They create visibility across teams that might otherwise remain disconnected, helping surface issues early before they spread across these “kingdoms.”

    When teams understand the value, collaboration becomes easier. Without that understanding, compliance remains a secondary priority.

    But alignment breaks down for a different reason: teams often don’t define risk the same way. Without a shared definition, issues fall between teams instead of being addressed.

    Lack of Visibility Creates Business Risk

    Lack of visibility is one of the most dangerous gaps in any organization. When leadership doesn’t have a clear view of what’s happening across teams and regions, risks don’t disappear. They accumulate.

    This often leads to:

    • Issues being discovered too late
    • Increased regulatory exposure
    • Reputational damage
    • Loss of employee trust
    • Difficulty attracting and retaining talent

    In distributed and remote environments, this risk is even higher. Teams operating without visibility may develop their own norms. Over time, this creates fragmentation. What’s acceptable in one part of the organization may differ in another.

    Without consistent oversight, these differences can lead to serious issues. Visibility isn’t about control. It’s about awareness, and awareness depends on having the right systems in place.

    The biggest risk is the gap between what leadership sees and what’s actually happening across teams.

    Compliance Is Becoming a Strategic Business Partner

    The role of compliance has evolved significantly over the past decade. It’s no longer enough to act as a rule enforcer. Modern compliance teams are expected to:

    • Support decision-making
    • Translate risk into business impact
    • Contribute to strategy
    • Shape organizational culture

    This shift changes how compliance is perceived internally. When positioned as a control function, compliance is often resisted. When positioned as a partner, it becomes part of how decisions are made.

    “Compliance shouldn’t feel like a “policing” function. It should help employees do their jobs better and safer, including supporting both physical and psychological safety, as well as clearer decision-making.”

    When compliance is embedded this way, it becomes part of how work actually gets done, not just a layer applied on top.

    What Influential Compliance Leaders Do Differently

    Understanding regulations is a baseline requirement. What differentiates impactful compliance leaders is their ability to influence. Ljuba identified several traits that consistently make a difference:

    • Curiosity: Strong compliance leaders actively learn how different parts of the business operate. This allows them to identify risks early and contribute meaningfully.
    • Clarity: Complex regulations need to be translated into simple, actionable guidance. Teams don’t have time to interpret legal language.
    • Data Awareness: Decisions backed by data carry more weight. Metrics such as reporting trends, case volumes, and regional patterns provide credibility.
    • Courage and Diplomacy: There are moments when compliance needs to push back. Doing this effectively requires balance. Saying no is part of the role, but offering a better alternative is what builds trust.

    These traits allow compliance leaders to move from advisory roles into positions of influence.

    Reporting Systems Help Surface Risk Earlier

    Many issues never reach formal channels. Employees may hesitate to report concerns due to fear of retaliation, uncertainty about outcomes, or discomfort with direct communication.

    As Ljuba explained, anonymous reporting isn't just about protecting reporters. It also helps organizations surface concerns that might otherwise never be raised. These channels are particularly valuable in:

    • Remote teams where visibility is limited
    • Smaller teams where anonymity is harder to maintain informally
    • Situations involving sensitive or personal issues

    Reporting Data Reveals More Than Individual Cases

    She also highlighted that reporting data tells a story beyond individual cases. Looking at reporting patterns can help organizations understand where trust is strong and where additional attention may be needed. For example:

    • High reporting volume may indicate active engagement or underlying issues
    • Low reporting volume may signal lack of trust
    • High anonymity rates may point to fear of retaliation

    These insights allow organizations to take targeted action. Without reporting tools, these signals remain invisible. 

    Low reporting doesn’t necessarily reflect fewer issues. It often points to gaps in trust or awareness.

    Special Graphic - Analytics.png

    Technology Is Expanding the Role of Compliance

    Compliance is becoming increasingly data-driven. Organizations are moving beyond tracking past incidents to using data for prediction and prevention. This includes:

    • Identifying patterns across regions or departments
    • Monitoring trends in reporting behavior
    • Using analytics to prioritize risks

    Technology plays a key role in enabling this. Tools can support:

    However, technology doesn’t replace human judgment. Ljuba highlighted that while tools can assist with intake, analysis, and reporting, critical decisions still require human input. This is especially true for:

    • Investigations
    • Ethical assessments
    • Disciplinary actions

    The most effective programs combine both. The risk isn’t just underusing technology, but relying on it without enough human judgment.

    New Expectations Around AI Governance and ESG

    The scope of compliance is expanding. Two areas are driving this shift: AI governance and ESG.

    AI introduces new risks related to data usage, privacy, and decision-making. Organizations need clear guidelines on how AI tools are used internally. This includes:

    • Training employees on responsible usage
    • Defining boundaries for data sharing
    • Establishing governance frameworks

    At the same time, ESG requirements are increasing expectations around transparency and accountability. Compliance teams are now involved in:

    • Supply chain due diligence
    • Human rights considerations
    • Non-financial reporting
    • Sustainability disclosures

    This broadens the role of compliance significantly, positioning it as a key contributor to long-term business strategy. But it also increases business exposure, meaning that when handled poorly, the impact can extend beyond internal processes to reputation and stakeholder trust.

    While every organization faces different compliance challenges, these shifts translate into practical questions for any program. Here are a few areas worth pressure-testing.

    Practical Steps for Compliance Leaders

    1. Map where signals actually come from
      List every way employees can raise concerns, formally and informally. Then ask: which of these channels does leadership actually see? If the answer is fragmented, risks are already slipping through.
    2. Test how early issues can surface
      Take a recent case and trace it back. When was the first signal available? Could it have been caught earlier? If yes, the issue isn’t the case, it’s the system.
    3. Assess trust in reporting channels
      Don’t treat anonymous vs identified reporting as good or bad. Both are valid. The question is whether employees can choose freely, and what that choice signals about trust.
    4. Align on what “risk” means across teams
      Different teams often define risk differently. Create a shared understanding, or you’ll keep missing issues that fall between the cracks.
    5. Make outcomes visible, not just processes
      Within confidentiality limits, communicate the changes, improvements, or actions taken from reports. If people don’t see impact, reporting will stagnate regardless of system quality.

    Trust Is What Makes Compliance Work

    Across all these topics, one principle stands out: compliance only works when people trust it. Trust is built through:

    • Clear communication
    • Consistent action
    • Transparency in outcomes
    • Genuine listening

    Without trust, policies remain unused, reporting systems remain silent, and risks remain hidden.

    “It’s important to build trust with the team and by listening. Only then can you unlock influence. Because without that, policies just sit on shelves, and we want them to be alive.”

    When employees trust compliance, they engage. Issues surface earlier. Leaders gain visibility. And compliance becomes what it was always meant to be: a system that protects people, supports decisions, and strengthens the organization from within.

    The difference often comes down to whether organizations create enough trust for people to speak up before small issues become bigger problems.

    Watch the full webinar session here