Horizon scanning: the missing discipline in compliance programs
The signals for regulatory change are almost always there before the rule is final. Horizon scanning is how compliance teams learn to read them, turning a reactive function into a strategic one.
Quick summary
- Most compliance programs are built around applicability and materiality — but neither answers the harder question of what’s coming next.
- Horizon scanning — tracking regulatory signals before they become binding requirements — is the missing third discipline in most compliance programs, argues Enhesa SVP Jillian Stacy.
- The science almost always moves before the regulation does — sometimes by decades — meaning companies that only monitor what’s already in force are already behind.
I talk to a lot of compliance and EHS leaders at large multinationals. When I ask them how they think about the future and what’s coming, the conversation tends to slow down.
It’s not that people are ignoring the question. It’s that most compliance programs weren’t built to answer it.
Built for today, not tomorrow
Over the past several years, two fundamental compliance disciplines have been taking shape. The first is applicability: figuring out which regulations actually apply to an organization’s operations, products, or chemicals. Not just in individual markets but across every jurisdiction in which they operate. Although there’s always room for improvement, the more mature organizations have a version of it in place.
The second is materiality. Most people know the term from its roots in financial reporting, as a way to identify the issues that matter most to a business and its stakeholders, and more recently from sustainability reporting. The idea is now being used more broadly to note risk as well as opportunities. In a compliance context it comes down to a few key questions: of everything that applies, what actually matters most? And where are the biggest risks and opportunities to add value for the organization?
Together, applicability and materiality help organizations first understand, then prioritize their requirements today. But they don’t answer the harder question of what’s next.
That’s where most compliance programs fall short and where a third discipline comes into play: foresight. Knowing what’s coming. At Enhesa, we call this horizon scanning: a structured approach to tracking what’s developing, what’s being proposed, and what’s likely to land. It’s what turns compliance from a reactive function into something more strategic.
There’s a pattern to regulatory change
What’s happening in the regulatory landscape right now shows why horizon scanning matters.
At the federal level in the US, there’s a push toward deregulation which, on paper, suggests a lighter compliance burden. But in reality, the opposite is happening. As federal requirements lift, individual states are ramping up regulations across environment, health and safety (EHS), chemicals, climate, and product-related areas, developing their own rules with different scopes, timelines, and expectations.
For compliance teams across these areas, this is adding a lot of complexity. Not only are there more jurisdictions to cover, there’s also more to track and less predictability about what requirements will come next.
In the EU, the Omnibus package is another example. Introduced in 2025 and adopted in 2026, it was designed to simplify sustainability reporting frameworks like CSRD, CSDDD, and CBAM. But for teams that had already built programs around them, it has meant going back and reworking what they’ve already done.
The sustainability omnibus isn’t the only one. The EU has also been advancing a Chemicals Omnibus and an Environment Omnibus, both of which have largely flown under the radar, but carry significant implications.
The challenge remains the same: rules are evolving faster than compliance programs can adapt.
This is where horizon scanning becomes critical.
In both the US and the EU, the signals for regulatory change were there. But teams were still caught off guard because those signals weren’t being tracked or connected early enough to act on.
The science goes first
There’s another layer to this that I find really fascinating too, especially coming from the chemicals side. If you look closely, regulation is not where change starts.
Take PFAS, for example. In 1968, a dental researcher named Donald Taves found something unusual in human blood samples: fluorinated compounds that had no business being there. By 1975, his team had confirmed this across more than a hundred samples.
The first hard regulatory response, the EU’s restriction on PFOS, didn’t come until 2006. That’s a 38-year gap between the scientific signal and the regulatory action.
If your chemicals program was only set up to track what was already regulated, you were already behind
Complacency, in this environment, is where problems start. This points to a deeper issue: Many organizations are still treating regulatory change as a volume problem to be managed, when it is really a risk problem to be interpreted. If the distinction sounds subtle, think about how, in practice, it changes how you prioritize, where you invest, and how you make decisions.
Building for tomorrow, not just today
The gap between signal and regulatory response isn’t unique to PFAS or to chemicals. It shows up across occupational health, environmental risk, product compliance, and sustainability. Whether it’s rising heat-related incidents driving new workplace protections, battery safety risks shaping product regulations, or growing evidence on microplastics leading to restrictions, the dynamic is consistent. Signals emerge first, and regulation follows and builds over time.
Right now, many compliance teams are monitoring regulations already in force because their programs are built on a one- to three-year horizon. That work is fundamental, but it will only get you so far.
Business strategy can’t be built on today’s requirements alone. It also needs to reflect the long-term picture, by understanding what could impact your organization five to ten years from now, or even decades ahead when you consider the science.
A robust compliance program doesn’t just track what applies today or what matters most. It also looks ahead and asks: do we know what’s coming, and are we ready for it? Because by the time a regulation is final, it’s rarely a surprise. The direction has usually been clear for some time.
Jillian Stacy
Jillian Stacy is SVP Chemical Intelligence & Group Expert Services at Enhesa. She is a co-author of the MIT Sloan Management Review article ‘The Looming Challenge of Chemical Disclosures’ and writes regularly on chemical transparency, PFAS regulation, and sustainable chemistry.
Read more from Jill here.

