Why regulatory complexity keeps growing, even when the headlines say otherwise
Governments on both sides of the Atlantic are publicly committed to reducing regulatory complexity. The data tells a different story: regulatory change is growing at around 20% a year, and simplification in one place reliably triggers acceleration somewhere else.
CEO Peter Schramme explains what that means for risk, capital, and the license to operate.
Quick summary
- Despite global deregulation headlines, regulatory change is accelerating at around 20% per year — simplification in one jurisdiction triggers new requirements in others.
- Enhesa CEO Peter Schramme explains why compliance is a license to operate, and how rising complexity creates material risk across EHS, product compliance, and capital access.
- Regulatory complexity demands more than tracking change — it requires understanding what materially threatens your business.
At the very moment that regulators in the world’s two largest economic blocs are publicly committed to reducing the administrative burden on business, the reality looks very different in practice. The volume of regulatory change that multinationals are navigating grows at around 20% a year, as new requirements layer on top of major amendments to existing ones, compounding over time (based on Enhesa’s global regulatory database). That disconnect between what is being said and what is happening tells us something important about how regulatory complexity actually works.
Let me explain what I mean by that.
Why simplification doesn't reduce complexity
The current wave of regulatory reform points to simplification. The EU’s omnibus packages are designed to streamline obligations, consolidate frameworks, and reduce the reporting burden. The US is rolling back federal-level requirements with stated intent. Taken at face value, the direction of travel looks unambiguous: fewer rules, less friction, more clarity.
Regulatory change doesn’t work that way, however. It behaves more like water finding its level. When you dam a river in one place, the water doesn’t disappear altogether. It finds new channels and moves faster and often less predictably than before. As we have seen, reducing regulation at the federal level accelerates it at the US state level. Likewise, streamlining regulations in the EU makes member states start filling the gaps.
The result is a significant increase in regulation as jurisdictions compensate in some cases and accelerate in others. Volume is also being driven by the increasing complexity of business and market contexts. As markets become more interconnected, companies are operating across more supply chains and jurisdictions than ever before, continuously generating the need for more regulatory guardrails.
But volume isn’t the whole story. Markets that were once moving toward regulatory alignment are now moving apart, as geopolitical realities make convergence harder to sustain. The reality companies face is fragmentation plus volume – a challenge that is far from simple.
Where this goes wrong
When companies encounter growing complexity, their natural reflex is to treat it as an administrative problem to manage. The logic is that more regulations require more tracking and more people processing updates and filing reports. That thinking is understandable because it is how most compliance functions were built. Yet this approach is also leaving organizations exposed to business risk in ways they often can’t see until something goes wrong.
Compliance is not a strategic advantage. It is a license to operate. And a license to operate governs three things: whether your facilities can run (safely), whether your products can reach the market, and whether you can access capital. The bigger the business, the more it has riding on all three.
This challenge is not confined to any single part of the business but is hitting multiple domains simultaneously, and each has its own risk profile. EHS teams are managing evolving occupational exposure limits, new process safety requirements, and environmental obligations that differ by jurisdiction and change by the quarter. Product compliance teams are managing market access across dozens of jurisdictions where requirements are diverging rather than converging. Chemical intelligence teams are tracking substance restrictions that determine whether products can be sold at all. PFAS alone spans over a thousand regulatory initiatives globally.
The consequences of getting any one of these wrong can run deep. A chemical restriction doesn’t just generate a reporting obligation. It can force a reformulation, remove a product from a market, or trigger a supply chain redesign, sometimes with little to no lead time. EHS non-compliance at a facility level rarely stays at the facility level. It surfaces in boardrooms, in investor calls and in press coverage that moves faster than any remediation plan. Companies carrying the most exposure are the ones treating these as three separate problems, while the regulatory environment treats them as one.
The audience has changed
There is a second force compounding this, and compliance leaders underestimate it at their peril. The audience for regulatory and compliance data has expanded. What used to be a conversation between companies and regulators is now a conversation that includes investors, rating agencies, insurers, customers, and in many cases employees and the public.
Compliance teams did not ask for this shift but are now accountable because the outcome their work produces is visible to stakeholders who did not exist in the frame five years ago.
That shift is already influencing how companies are assessed. ISSB standards, adopted by investors, are pulling EHS data on workforce health and safety, climate risk, and environmental management, into capital allocation decisions. The same operational data that once sat in a compliance report now shapes how a company is valued.
The risk of poor operational compliance has moved beyond regulatory risk. It is becoming a valuation risk, a capital-access risk and a reputational risk, and all three move faster than any compliance cycle.
Complacency, in this environment, is where problems start. This points to a deeper issue: Many organizations are still treating regulatory change as a volume problem to be managed, when it is really a risk problem to be interpreted. If the distinction sounds subtle, think about how, in practice, it changes how you prioritize, where you invest, and how you make decisions.
Seeing through the complexity
The question “what is changing?” is a reasonable starting point in regulatory compliance. The more important question is: what has changed that creates material risk to our specific business and our ability to operate, sell, and access capital? A PFAS restriction, for example, is much more than another regulatory update; it signals potential reformulation, supplier disruption, and market access risk.
The shift from managing volume to interpreting risk is what separates compliance from strategic awareness. The same regulatory change demands a different response, depending on where you sit in the organization. In the case of PFAS, product stewardship may have to act on formulation, chemical safety teams on sourcing, and legal on disclosure. The risk is shared, the action is different.
Getting that distinction right, consistently, across markets, across functions, requires the ability to filter regulatory change through a risk lens and ensure that what reaches decision-makers is a material risk to their specific business, not regulatory noise.
That ability to filter out the noise rests on two disciplines.
The first is applicability: which regulations actually affect this site, this product, this substance, and this operation? Without it, everything on the horizon looks equally urgent, and teams spend their scarcest resource — attention — on work that does not change the risk picture.
The second is materiality: among the regulations that do apply, which ones create the risk exposures the business and its stakeholders care about? Materiality is a discipline CFOs, audit committees, and boards have used for decades in financial reporting. The same rigor needs to apply to regulatory intelligence. Not everything is material, and treating everything as material creates its own risk: resource misallocation, strategic distraction, and lost credibility with the leadership that is being asked to act on what compliance surfaces.
Applicability narrows the universe. Materiality prioritizes within it. Companies that have neither end up drowning in volume. Companies that have one but not the other are either firefighting regulations that do not affect them, or treating every applicable obligation with the same urgency, which is a different kind of waste. The organizations best positioned for what comes next have built both. They have moved from monitoring everything to understanding what is material, and they are seeing through the complexity while filtering out the noise.
When regulatory risk is properly understood and mapped across EHS obligations, product requirements, substance restrictions, and supply chain risk exposure, it belongs in the same conversation as market strategy and capital allocation. It is, at its heart, a C-suite and board-level topic.
What this means in practice
The volume and pace of regulatory change is unlikely to slow down. That much is clear from the data, including our own, and from the direction of every dynamic driving it. The challenge for companies is to read the change, understand what it means for their specific business, and build long-term resilience into how they respond.
Peter Schramme
Peter Schramme is the Chief Executive Officer of Enhesa, the world’s leading provider of EHS and regulatory intelligence for global multinationals. He joined Enhesa in 2019 after a 30-year career building and scaling enterprise software and information services businesses across EMEA and beyond, including leadership roles at Thomson Reuters, Objectway, and Lionbridge.
At Enhesa, he has overseen the company’s expansion from a single-track regulatory intelligence provider into a multi-domain compliance platform trusted by half of the Global Fortune 500 and used in more than 25,000 facilities worldwide. He holds engineering degrees from the University of Antwerp and the University of Leuven, and an Executive MBA from University of Antwerp Management School. He writes on the intersection of enterprise strategy, regulatory risk, and the future of compliance intelligence.
