That model is becoming harder to sustain.

Tax reforms are changing where companies book profits and how they invest. Financial-reporting standards are altering the data architecture behind management accounts. Anti-money-laundering rules are increasing the cost of onboarding customers and counterparties. Data-protection requirements are reaching deeper into product design and technology infrastructure. Sustainability rules are extending compliance into supply chains. Competition authorities are intervening more directly in digital business models. Labour rules are changing the economics of employment. Corporate-governance reforms are placing greater responsibility on boards for internal controls. Licensing regimes are becoming more digital, capital-intensive and conditional.

The result is a structural shift: compliance is becoming part of corporate strategy because regulation increasingly changes the economics of the business itself.

The question for boards is therefore no longer simply whether the company is compliant.

It is whether the company's business model remains attractive after the cost of complying with the rules is fully priced in.

That distinction matters for investors, founders and established companies alike. A regulatory requirement can raise operating costs, delay market entry, increase capital requirements, restrict customer acquisition, force changes to products or make a previously attractive market uneconomic. It can also create advantages for companies that already possess the technology, capital, reporting infrastructure and institutional capability needed to comply.

In other words, regulation is increasingly becoming a competitive variable.

 Compliance is becoming a cost of market access

The most important change is not that individual regulations are becoming more demanding. It is that more of them now affect the underlying operating model.

Consider the direction of travel in taxation.

Nigeria's new Tax Acts came into effect from 1 January 2026, with new rules governing tax liabilities, administration, incentives, exemptions, record keeping and transactions spanning the old and new regimes. The reforms also incorporate greater use of digital administration, including VAT and corporate-tax fiscalisation and e-invoicing. The IMF estimates that Nigeria's tax-administration reforms, including fiscalisation and e-invoicing, could contribute materially to revenue mobilisation.

The implication for business is broader than a change in the tax bill.

Companies must invest in systems capable of producing the information tax authorities increasingly expect. Finance, technology, procurement and commercial teams become part of the compliance chain. Businesses with fragmented accounting systems or informal processes face a higher transition cost.

The same pattern is visible globally. Deloitte's 2026 survey of 1,010 tax and finance leaders across 28 jurisdictions found that 40% identified rising tax-compliance burdens as the biggest issue affecting their organisations, while 84% expected more public tax disclosures over the following two to three years.

The strategic consequence is straightforward: tax compliance increasingly influences technology investment, group structure, transaction design and the location of economic activity.

For multinational groups, the OECD's Pillar Two framework adds another layer. The global minimum-tax regime continues to generate administrative requirements and technical adjustments, while the OECD's January 2026 package introduced further simplifications and safe harbours.

The cost bearer: finance departments, technology teams, multinational groups and ultimately shareholders.

The beneficiaries: tax authorities, governments seeking more predictable revenue and companies with sophisticated tax-data infrastructure.

The business models most exposed: multinational groups, cross-border platforms, asset-light structures relying on complex tax arrangements and companies operating across multiple tax jurisdictions.

 Financial reporting is becoming an operating-system issue

Financial reporting is moving in the same direction.

IFRS 18, effective for annual reporting periods beginning on or after 1 January 2027, replaces IAS 1 and introduces new requirements around the presentation of financial performance and management-defined performance measures. Companies will need to prepare comparative information and provide greater transparency around how management communicates financial performance.

That is not merely an accounting change.

The quality of financial reporting increasingly depends on how information is generated upstream. ERP systems, management reporting, business-unit data, performance measures and internal controls all become part of the reporting architecture.

For large companies, the principal cost may therefore be less the accounting interpretation itself than the redesign of systems and processes needed to produce reliable information.

This favours companies with integrated financial-data infrastructure. It places a heavier burden on businesses that have grown through acquisitions, operate decentralised finance systems or rely heavily on spreadsheets and manual reconciliation.

The strategic question for boards becomes whether reporting infrastructure is capable of supporting future regulation without repeatedly requiring expensive reconstruction.

That is a capital-allocation decision, not simply an accounting decision.

AML/CFT is changing who a company can do business with

Anti-money-laundering and counter-terrorist-financing requirements create an even more direct link between compliance and commercial strategy.

The FATF's risk-based approach increasingly requires businesses and supervisors to distinguish between higher- and lower-risk customers and activities rather than applying identical controls to everyone. The organisation has also emphasised that poorly calibrated AML/CFT measures can unintentionally exclude legitimate customers and businesses from the financial system.

For banks, fintechs, payment companies, securities firms, professional-services businesses and other regulated entities, compliance therefore affects customer acquisition.

Every additional identification requirement, transaction-monitoring rule or enhanced-due-diligence procedure can increase onboarding costs and slow conversion.

But excessive de-risking creates a second problem: legitimate customers may be rejected because the cost of serving them is considered too high.

Nigeria's progress under the FATF framework illustrates the institutional direction. Reforms have included stronger risk-based supervision, improved access to beneficial-ownership information and greater enforcement capacity.

This makes beneficial ownership, KYC and transaction monitoring increasingly relevant to companies outside traditional banking.

The cost bearer: regulated financial institutions, fintechs, professional-services firms and customers operating in higher-risk corridors.

The beneficiaries: financial institutions with strong compliance technology, identity providers, regtech companies and regulators.

The business models most exposed: high-volume, low-margin fintech; correspondent banking; cross-border payments; digital assets; remittance businesses; and services involving complex ownership structures.

Data protection is becoming product economics

Data protection has moved even further from the legal department into product development.

The European Data Protection Board's 2026 coordinated enforcement action is focusing on transparency and information obligations under the GDPR, with 25 data-protection authorities participating. Enforcement can include orders as well as fines, with GDPR penalties reaching up to €20 million or 4% of global annual turnover.

The significance is not simply the maximum fine.

Data governance increasingly determines how a company designs its customer journey, advertising model, AI deployment, analytics infrastructure and data-sharing arrangements.

The UK's 2026 Business Data Survey provides a useful indication of the organisational burden. Among businesses handling digitised personal data and employing staff, 56% reported having someone whose role included leading on data-protection compliance. The figure rose to 92% among large businesses. Large and medium-sized businesses were also considerably more likely than smaller firms to employ or outsource specialist personnel.

Compliance therefore creates a scale effect.

Large companies can spread the fixed cost of privacy teams, security systems and legal expertise across substantial revenues. Smaller companies cannot.

That can strengthen incumbents while raising barriers to entry for smaller technology companies.

ESG is shifting from disclosure to supply-chain economics

Sustainability regulation presents another version of the same phenomenon.

The OECD's 2026 Responsible Business Outlook found that 84% of OECD countries have laws requiring companies to report on or conduct due diligence concerning social and environmental impacts. Those jurisdictions represent approximately 55% of global GDP. Yet fewer than 20% of the largest listed companies surveyed reported actually evaluating supplier risk on environmental and social criteria.

That gap is commercially important.

As sustainability regulation becomes more embedded in procurement, companies cannot treat ESG as an annual-report exercise. Suppliers may need to provide emissions information, labour data, traceability records and evidence of responsible business practices.

The compliance burden therefore travels down the supply chain.

A large multinational may have the resources to build a supplier-monitoring system. A small manufacturer supplying that multinational may have to absorb the cost without possessing the same financial or technical capacity.

This creates a potential consolidation effect: suppliers unable to document compliance risk losing access to major customers, even where their underlying products remain competitive.

The beneficiary may not necessarily be the most productive supplier. It may be the supplier with the strongest documentation, traceability and reporting infrastructure.

That distinction will matter increasingly in African manufacturing and export markets seeking access to regulated consumer markets.

Competition policy is becoming a constraint on digital business models

Competition regulation is also becoming more operational.

The EU's Digital Markets Act demonstrates how regulation can directly alter the economics of dominant platforms. In July 2026, the European Commission fined Google €460 million over self-preferencing and €430 million over restrictions on app developers' ability to steer consumers towards alternative purchasing channels.

The significance extends beyond the fine.

Competition rules can determine ranking systems, payment arrangements, platform access, interoperability, distribution channels and relationships with business users.

The European Commission's first DMA review concluded that the rules were already producing changes including new consent mechanisms, data-portability tools, choice screens and interoperability measures, while opening opportunities for smaller businesses.

This creates a strategic redistribution.

Large platforms may bear the immediate compliance cost. Smaller businesses can benefit if regulation weakens gatekeeper advantages and lowers access barriers.

For investors, however, the key issue is that the valuation of a platform business can no longer be assessed purely from users, revenue and margins. Regulatory constraints on monetisation and distribution are increasingly part of the business model.

Labour regulation is entering the cost base

Labour regulation has a similar effect but through a different channel.

In Nigeria, the launch of the National Industrial Relations Policy in May 2026 introduced a national framework aimed at strengthening labour relations, worker protections, business confidence and economic stability.

The strategic impact of labour regulation is often underestimated because employment compliance is treated as an HR function.

For labour-intensive companies, however, changes in employment obligations affect unit economics.

A business model built around contractors, temporary labour, low-cost outsourcing or informal employment can carry a very different regulatory cost from one built around formal employment.

Boards therefore need to ask a more fundamental question: does the company's labour model remain economically viable when the full cost of lawful employment is included?

This matters particularly for logistics, retail, manufacturing, hospitality, construction, agriculture and platform businesses.

The beneficiary can be the compliant employer if regulation reduces unfair competition from informal operators. The cost bearer is the employer whose previous cost advantage depended on lower labour standards.

 

Corporate governance is making compliance a board responsibility

Perhaps the clearest evidence of the shift into the boardroom comes from governance itself.

The UK's Corporate Governance Code 2024 applies to financial years beginning on or after 1 January 2025, while Provision 29 applies from 1 January 2026. It requires boards to monitor and review material internal controls and provide a declaration on their effectiveness. Those controls extend beyond finance to operational, reporting and compliance controls.

The Financial Reporting Council's guidance makes the strategic implication explicit: boards should consider risk management and internal control as part of the company's purpose, strategy, business model and governance. Material controls may include controls over cybersecurity, data protection and new technologies.

The board is therefore increasingly expected to understand not only whether controls exist, but whether they actually work.

That changes the economics of compliance.

A failure is no longer necessarily an isolated departmental problem. It can become a governance problem, a disclosure problem, an investor-confidence problem and potentially a valuation problem.

The same direction is visible in banking. Basel Committee guidance published in 2026 states that a bank's board is responsible for overseeing compliance risk, approving compliance policy and ensuring that the compliance function has sufficient authority, independence and resources.

The regulatory architecture is effectively telling boards: you own the risk even when somebody else manages the process.

Licensing is becoming a balance-sheet issue

Licensing adds another layer.

In regulated industries, the licence to operate is increasingly conditional on capital, technology, governance, reporting and ongoing compliance.

Nigeria's capital-market reforms provide a clear example. The Securities and Exchange Commission revised minimum-capital requirements for regulated entities in 2026, including substantial requirements for digital-asset businesses. Affected entities have until 30 June 2027 to meet the revised requirements, with possible sanctions including suspension or withdrawal of registration for failures to comply.

For a digital-asset exchange or intermediary, minimum capital is not a legal footnote.

It is capital that cannot necessarily be deployed elsewhere.

The same logic applies across banking, telecommunications, insurance, energy, aviation and other regulated sectors. Licensing requirements can determine who enters a market, who can scale and who has sufficient balance-sheet capacity to remain independent.

Nigeria's CBN, for example, has continued to expand and digitise licensing and regulatory requirements across financial institutions, while 2026 saw licence actions against microfinance banks that failed to meet regulatory requirements.

The regulatory barrier is therefore becoming a form of market selection.

The common thread is fixed-cost intensity.

The larger and more complex the compliance requirement, the more advantageous scale becomes.

A multinational can hire specialists, automate reporting, build internal audit functions and spread technology costs across several markets. A small business may have to pay external advisers for the same requirements.

That does not mean regulation inevitably protects incumbents. Digital competition rules can open markets, while better financial reporting and governance can reduce information asymmetry and improve access to capital.

But the distributional effect needs to be recognised.

Compliance can create both a cost and a moat.

The strategic question for boards

The traditional compliance question was:

Are we complying?

The more useful strategic questions are now:

What does compliance cost per customer, employee, transaction, supplier, and market?

Which products become less profitable after regulatory costs are included?

Which markets become more attractive because competitors face higher barriers to entry?

Which suppliers could fail compliance requirements and disrupt our supply chain?

How much capital is trapped by licensing or prudential requirements?

Which regulatory changes could alter the assumptions behind our valuation?

This requires a different management architecture.

Boards should expect compliance teams to quantify exposure rather than simply report breaches.

A regulatory dashboard should increasingly show:

  • annual compliance expenditure;

  • regulatory capital committed;

  • revenue exposed to specific rules;

  • customers or suppliers affected;

  • market-entry delays;

  • regulatory fines and remediation exposure;

  • technology investment required;

  • percentage of revenue dependent on regulated activities;

  • concentration of regulatory risk by jurisdiction; and

  • upcoming rule changes capable of altering the business model.

This turns compliance from a cost centre into a strategic-risk map.

Africa's regulatory advantage may come from better execution, not fewer rules

For African markets, the debate is particularly important.

The conventional assumption is that lower regulatory burdens automatically make a market more competitive.

That is too simplistic.

Investors increasingly require credible tax systems, reliable financial reporting, transparent ownership, data protection, effective AML/CFT frameworks, predictable licensing and enforceable corporate governance.

The challenge is therefore not simply to minimise regulation.

It is to reduce regulatory friction while maintaining institutional credibility.

Nigeria's tax reforms, financial-sector capital requirements, digital licensing infrastructure and AML/CFT reforms show the direction of travel: more formalisation, more digital administration and greater regulatory visibility.

For businesses, this means the regulatory environment should increasingly be treated as part of market infrastructure.

A company entering a new African market should not ask only about tax rates, labour costs, consumer demand or infrastructure.

It should ask how much it will cost to become and remain compliant.

That calculation could become as important as the cost of power, logistics or financing.

What changes next

The direction of travel is clear.

Regulation is becoming more interconnected.

Tax depends increasingly on digital records. Financial reporting depends on data architecture. Data protection intersects with AI. ESG intersects with procurement. AML/CFT intersects with ownership structures and payments. Competition policy intersects with platform design. Labour rules intersect with business models. Governance intersects with every material control.

That convergence is what moves compliance into the boardroom.

The companies best positioned for the next regulatory cycle will not necessarily be those with the largest legal departments. They will be those capable of embedding compliance into operating systems, capital allocation, product design and strategic planning.

For boards, the central risk is no longer the isolated cost of a new rule.

It is the cumulative effect of hundreds of rules changing the economics of the company at the same time.

The winners will be companies that can quantify that cumulative burden early, and convert regulatory complexity into a source of operational advantage.

The losers may discover that a business model that looked highly profitable before compliance costs were priced in was never as profitable as it appeared.

Aldrenor Intelligence view: Compliance is no longer simply the cost of obeying the rules. Increasingly, it is part of the cost of doing business, the barrier to entering a market, the price of accessing capital and, in some sectors, the architecture of competitive advantage.

 Sources