How Multinational Boards Handle Conflicting Regulations
By Adrian Lawrence FCA, founder of NED Capital · Part of the Board Governance Hub
In short: A multinational board handles conflicting regulations by treating regulatory divergence as a governance risk to be overseen, not an operational problem to be delegated. It sets a group-wide compliance standard — usually the strictest applicable regime — then holds a clear line on where local subsidiary boards may diverge, ensuring each director understands that their duty under the UK Companies Act attaches to the company they serve, not the group as a whole.
For any board overseeing operations in more than one country, conflicting regulation is a structural feature of the role rather than an occasional problem. A data-handling rule that is mandatory in one jurisdiction may be prohibited in another; an anti-bribery standard set in the UK reaches conduct on the other side of the world; a tax structure that is efficient in one country attracts scrutiny in the next. The board cannot resolve these conflicts by choosing one rule over another. Its task is to build a governance framework that lets the group operate coherently across incompatible regimes — and to satisfy itself that the framework is working.
This is squarely non-executive territory. The executive team runs compliance day to day; the board, and its independent directors in particular, provide the oversight, the challenge and the judgement on where the group’s risk appetite sits. This guide sets out how effective multinational boards approach the problem, where the governance responsibility falls, and what it means for the way a board is composed.
The Core Problem: Group Coherence vs Local Duty
The defining tension for a multinational board is that the group is a commercial reality but not, in law, a single entity. A UK parent and its overseas subsidiaries are separate companies, each with its own board and its own directors, and each director owes their duties — under sections 171 to 177 of the Companies Act 2006 in the case of a UK company — to the company they serve, not to the group. When a group-level policy conflicts with what is lawful or in the interests of a particular subsidiary, the local directors cannot simply defer to the parent. A director who follows a group instruction that breaches their own company’s legal or fiduciary position remains personally responsible for that breach.
This is why regulatory conflict is a board matter and not merely a compliance one. The board must design a structure in which group-wide consistency and local legal duty can coexist — typically by setting a high common standard the whole group observes, while leaving explicit room for local boards to go further where their own law requires. Getting that balance wrong in either direction is costly: too much central control exposes subsidiary directors to breaches of local duty; too little leaves the group with no coherent standard and no defensible position when a regulator asks who was responsible.
Setting a Group Standard: The “Highest Common Denominator”
The most common approach effective boards take is to adopt the strictest applicable standard as the group baseline. Where one jurisdiction demands a higher level of data protection, anti-bribery control or financial disclosure than the others, the group applies that higher standard everywhere unless there is a specific legal reason not to. The logic is straightforward: meeting the strictest requirement generally satisfies the more lenient ones, and it gives the group a single, defensible policy rather than a patchwork that is difficult to govern and easy to breach.
The clearest example is the reach of certain regimes beyond their home territory. The UK Bribery Act applies to the conduct of a UK-connected organisation wherever in the world it occurs, so a group governed from the UK must hold every subsidiary to that standard regardless of weaker local anti-corruption law. Similarly, data protection obligations frequently follow the data subject rather than the company, meaning a group handling UK or EU personal data must meet those standards even where the processing happens elsewhere. The board’s role is to recognise which of the regimes it faces have this extraterritorial reach and to set the group baseline accordingly — because in those cases there is no real choice to be made.
Where the highest-common-denominator approach does not work is when two regimes are genuinely incompatible — where complying with one necessarily breaches the other. Data localisation requirements that force information to stay within a country’s borders can conflict directly with disclosure obligations elsewhere. Here there is no single standard that satisfies both, and the board must take a considered position on which exposure it will carry, usually with specialist legal advice, and document the reasoning. Overseeing that judgement — not making the operational choice, but ensuring it was made deliberately and defensibly — is one of the clearest oversight duties a multinational board holds.
The Board’s Oversight Role Under the UK Code
For UK-listed groups, the UK Corporate Governance Code frames how the board should approach this. The Code makes the board responsible for establishing the nature and extent of the principal risks it is willing to take and for maintaining a robust risk management and internal control framework. Cross-border regulatory conflict is precisely such a principal risk for a multinational, and the Code’s expectation is that the board owns it — setting the risk appetite, reviewing the effectiveness of the controls, and reporting on both.
In practice, the work runs through the committee structure. The audit committee, whose remit under the Code includes reviewing the internal control and risk management systems, is usually where regulatory-conflict risk is examined in detail — the adequacy of compliance monitoring across jurisdictions, the group’s response to regulatory change, and the assurance the board receives that subsidiary-level obligations are being met. A group with significant regulatory exposure may operate a dedicated risk committee alongside it. The audit committee chair carries real weight here: it falls to them to ensure the board is genuinely sighted on where the group’s regulatory conflicts lie and is not simply receiving reassurance.
The Code also expects the board to assess and monitor culture. That matters in a multinational context because a group standard is only as good as its observance in the subsidiary that is furthest from head office. A board that sets a strong anti-bribery policy but never tests whether it is lived on the ground in a higher-risk market has not discharged its oversight duty — it has documented an intention. Independent directors asking how the board knows the standard is being followed, rather than accepting that it has been issued, is the substance of the role.
Subsidiary Governance and the Local Board
How a group structures its subsidiary boards has a direct bearing on how well it handles conflicting regulation. A common failing is the “letterbox” subsidiary board — one that exists on paper, meets rarely, and rubber-stamps decisions taken at group level. Such a board offers no protection when local regulation diverges, because no one is exercising genuine local oversight, and it exposes the subsidiary’s directors to personal liability for decisions they did not meaningfully take.
Better-governed groups give material subsidiaries a functioning board with real local knowledge, sometimes including an independent non-executive director appointed specifically for their understanding of the local regulatory environment. The value of a genuinely independent voice on a subsidiary board is that it can identify where a group policy would breach local law before the breach happens, and can hold a defensible position when group and local interests diverge. This is particularly important in regulated sectors: a financial services subsidiary answerable to its own national regulator needs directors who understand that regulator’s expectations and can meet them, not merely relay group policy. Where the UK entity is itself regulated, our work on FCA-regulated board governance deals with the additional layer the SMCR imposes on those appointments.
Practical Mechanisms Boards Use
Beyond the structural questions, boards that manage regulatory conflict well tend to share a set of practical habits:
A group-wide policy framework with defined local carve-outs. One set of core standards applies everywhere, with an explicit, documented process for a subsidiary to depart from it where local law requires — so divergence is deliberate and recorded, not accidental.
A regulatory-change process that reaches the board. Regulation moves constantly across a dozen jurisdictions. The board needs a mechanism — usually through the audit or risk committee — that surfaces material regulatory change and its implications, rather than learning of it after a breach.
Clear escalation from subsidiary to group. When a local board identifies a conflict between group policy and local duty, there must be a defined route to escalate it to the group board for resolution, rather than the local directors quietly absorbing the risk.
Assurance the board actually tests. The board should receive independent assurance — through internal audit or external review — that the group standard is being observed in practice in each material jurisdiction, and should treat that assurance sceptically rather than as a formality.
None of these is exotic. What distinguishes boards that handle conflicting regulation well is not a special technique but the discipline to treat regulatory divergence as a standing agenda item with a named owner, rather than an issue that surfaces only when something has already gone wrong.
What This Means for Board Composition
Handling conflicting regulation well is, ultimately, a function of who sits on the board. A group with significant cross-border exposure needs directors who have operated across jurisdictions and understand that regulatory divergence is a governance risk to be structured, not a nuisance to be delegated. It needs an audit or risk committee chair capable of interrogating compliance across multiple regimes, and it benefits from independent directors with genuine knowledge of the group’s principal markets — people who can tell the board when a group policy will not survive contact with local law.
This is where board composition and regulatory resilience meet. Appointing a non-executive director with the right international and regulatory experience is one of the more effective things a multinational board can do to strengthen its oversight of conflicting regulation. At NED Capital we help boards identify and appoint independent directors and committee chairs with precisely this profile — directors who understand cross-border governance and can provide credible challenge on where the group’s regulatory risk really sits. Every search is led personally by Adrian Lawrence FCA. To discuss strengthening your board, our NED recruitment service is the place to start, and boards planning ahead may find our guide on how to appoint a non-executive director a useful next step.
About the author
Adrian Lawrence FCA is the founder of NED Capital and a Fellow of the Institute of Chartered Accountants in England and Wales (ICAEW), holding an ICAEW practising certificate in his own name. A former listed-company Finance Director, he holds a BSc from Queen Mary College, University of London and has over 25 years of experience working with boards, investors and business owners across the UK. He founded NED Capital to connect organisations with the independent non-executive directors they need to strengthen governance and strategic oversight — and personally leads candidate assessment on every board search mandate.
Related Services
NED Capital appoints independent directors and committee chairs to boards overseeing complex, cross-border and regulated operations. Every search is led personally by Adrian Lawrence FCA.
Strengthening a Board That Spans Borders?
Whether you need an independent director with cross-border regulatory experience, an audit or risk committee chair, or a chair to lead a multinational board, we bring specialist knowledge of governance and the board market. Every search is tailored, discreet and led personally by Adrian Lawrence FCA.
NED Capital | Sister practice of FD Capital | ICAEW practising certificate held by Adrian Lawrence FCA.
Adrian Lawrence FCA is the founder of NED Capital and a Fellow of the Institute of Chartered Accountants in England and Wales (ICAEW) and holds an ICAEW practising certificate in his own name. He holds a BSc from Queen Mary College, University of London, and has over 25 years of experience working with boards, investors and business owners across the UK. He founded NED Capital to connect businesses with the independent Non-Executive Directors they need to provide challenge, governance and strategic oversight — and personally leads candidate assessments for board-level appointments.