Your APAC Compliance Programme Was Built For a Region That Doesn’t Exist

The gap shows up in your supplier contracts before it shows up in your risk register.

Image décorative

APAC survives as a label because it makes planning easier. It fits neatly into corporate structures, sales territories, and expansion strategies. Governance does not share that convenience, and the gap between the two is where compliance programmes quietly fail.

Here is what most risk leaders get wrong. They treat Asia-Pacific as one region requiring local adjustment. It is closer to a dozen governance systems pursuing competing national objectives, and your suppliers are already carrying those competing obligations into your business. You will not find that exposure on a jurisdictional risk register. It arrives through operational relationships instead.

Treating Asia-Pacific as a single regulatory region obscures the very thing making it difficult to manage. The region is less a coherent regulatory market than a collection of fundamentally different governance systems occupying the same part of the world. Businesses move between common law, civil law, and hybrid legal systems while governments pursue very different policy objectives.

For one, regulation may be intended to accelerate economic development. For another, it may reinforce financial stability, strengthen digital sovereignty, or reduce strategic dependence on foreign technology. Similar rules serve different purposes because they emerge from very different political and economic priorities.

The complexity becomes difficult to ignore once your operations begin relying on third parties. Cloud providers, technology vendors, outsourced business services, and cross-border service providers rarely operate within a single jurisdiction. They support customers across several jurisdictions, carrying different regulatory expectations into the same commercial relationship. What appears to be one supplier can, from a governance perspective, represent multiple regulatory environments operating simultaneously.

What defines APAC is the absence of a common regulatory philosophy. The number of regulators matters far less, but adds to further complexity. Many multinational enterprises continue to approach the region as though consistency is the starting point, and local variation simply requires adjustment. The opposite is true.

The starting point is divergence. Consistency has to be built deliberately, and with a clear understanding of why governments are regulating in different ways and what those differences mean for the business. Geopolitics is making this harder because it now shapes the objectives behind regulation itself. So governance has to begin somewhere different. The dependencies running through your operations will tell you more than the jurisdictions on your risk register.

In This Article
  1. Regulation Is Following National Strategy
  2. Regulatory Complexity Lives Inside Operational Relationships
  3. Compliance Was Designed Around Jurisdictions, but Your Business Was Not
  4. From Country Compliance to Regulatory Intelligence
  5. APAC Is Showing You Where Governance Is Headed
  6. Ask Jan: Questions I Get About APAC

Regulation Is Following National Strategy

The differences across APAC are becoming more pronounced because governments are no longer regulating with the same destination in mind. For many years, your compliance programme could reasonably expect regulatory approaches to drift gradually toward one another. International standards proliferated, global trade deepened, and digital economies matured. Convergence was never complete, but it often felt like the direction of travel. Those assumptions no longer hold.

Across APAC, regulation increasingly reflects domestic strategic priorities. Economic growth, technological leadership, national security, digital sovereignty, and financial resilience have all become matters of public policy, and governments are using regulation to pursue those objectives. Similar topics produce very different regulatory outcomes because they are answering different national questions.

Those differences do not stay inside legislation. They shape how regulators supervise, how aggressively they enforce, and what they expect from your organisation and the others they oversee. Two jurisdictions may both regulate outsourcing, artificial intelligence, or cybersecurity, yet ask fundamentally different questions about what good governance looks like.

Data governance shows this clearly. Requirements governing the movement and storage of data are no longer shaped by privacy considerations alone. Questions of sovereignty, strategic autonomy, and national security increasingly influence where data should reside and who should be able to access it.

Artificial intelligence follows a similar pattern. Governments across the region recognise its economic importance, but they differ in how they balance innovation, accountability, public trust, and state oversight. Cybersecurity, critical infrastructure, and operational resilience are evolving in much the same way.

Recent regulatory developments illustrate that divergence directly, and outsourcing oversight in financial services is a useful test case. Australia’s APRA prudential standard, CPS 230, places operational resilience, material service providers, and third-party dependencies at the centre of prudential supervision, requiring institutions to demonstrate they can withstand disruption to critical operations.

Singapore’s MAS Guidelines on Outsourcing, effective from December 2024, govern the same terrain from a different position: a more prescriptive set of expectations for managing outsourcing arrangements, consistent with Singapore’s positioning as a financial hub built on supervisory certainty. Both regimes govern third-party dependency in regulated financial institutions. Each does so from a different regulatory starting point.

Data governance shows the same pattern. India’s Digital Personal Data Protection Act (DPDPA) reflects a rapidly expanding digital economy seeking to strengthen individual data rights while supporting continued innovation. China’s data framework, built around the Cybersecurity Law, the Data Security Law, and the Personal Information Protection Law, addresses similar terrain from a different starting point, anchoring data localisation and cross-border transfer controls in national security and digital sovereignty rather than in innovation-led consumer protection. Both regimes govern the same underlying subject. They do so in service of different strategic objectives.

For your risk and compliance teams, similar business decisions produce very different regulatory consequences depending on where they are made. Yet many risk and compliance functions are still organised around the assumption of consistency.

APAC rewards a different assumption. Divergence is the operating environment, and it reaches your enterprise through suppliers, technology platforms, and business relationships connecting it across the region. Your dependencies determine which regulators reach you.

Regulatory Complexity Lives Inside Operational Relationships

Regulatory divergence arrives through the ordinary mechanics of running the business. One of your suppliers may support operations across Australia, Singapore, Japan, India, and several other jurisdictions, each imposing different expectations for outsourcing, cybersecurity, operational resilience, or data governance.

One of your cloud providers may host services perfectly acceptable in one market while requiring additional contractual safeguards or oversight in another. The commercial relationship appears singular. The regulatory obligations attached to it are anything but.

The same pattern extends beyond direct suppliers. Fourth-party dependencies introduce regulatory exposure that your risk teams neither contract for nor fully understand. A software vendor’s hosting provider, a logistics partner supporting a critical supplier, or an outsourced technology service buried several layers down the supply chain can all create obligations remaining invisible until disruption, regulatory scrutiny, or an incident forces them into view.

The operating model of the modern enterprise makes this complexity almost inevitable:

  • Data crosses borders continuously
  • Business services are delivered through distributed technology environments
  • Products, services, and operational processes routinely pass through more regulatory jurisdictions than organisational reporting lines

Your teams rarely encounter regulatory complexity through legal analysis. You encounter it through suppliers suddenly requiring different contractual commitments, technology platforms needing to satisfy competing regulatory expectations, or customers whose compliance obligations begin flowing downstream into the wider supply chain.

Understanding individual regulations remains necessary, but it is no longer sufficient. The harder task is understanding how those regulations converge around the same operational relationships, and why third-party ecosystems have become one of the primary routes regulatory divergence takes into your enterprise.

The problem is structural. Compliance functions were built around jurisdictions, and the exposure sits in the dependencies.

Compliance Was Designed Around Jurisdictions, but Your Business Was Not

Compliance capabilities were historically organised around a simple sequence: understand the regulations applying within a jurisdiction, translate them into policies and controls, and demonstrate you are meeting the obligations. This reflected the way many multinational corporations were structured. Geography provided a practical boundary for governance.

Business no longer respects those boundaries. Today’s operating models connect suppliers, customers, technology platforms, data, and business services across multiple jurisdictions at the same time. The relationships mattering most to the enterprise rarely sit neatly inside a single country, and neither do the risks attached to them.

Governance is being reorganised around operational relationships rather than regulatory domains. Supplier risk, technology risk, cyber risk, and regulatory compliance increasingly gather around the same operational relationships, requiring legal, procurement, information security, privacy, compliance, and enterprise risk functions to assess the same dependency from different perspectives. The regulation may concern outsourcing, data protection, operational resilience, or cybersecurity. The operational relationship is frequently the same.

Regulatory change therefore moves through your organisation faster than governance functions anticipate. A single development may require revisions to policies, adjustments to internal controls, changes to supplier oversight, updates to technology platforms, and new resilience testing, all before the business has fully understood the implications.

Your risk and compliance teams need to start somewhere different. Rather than asking, “What does this regulation require?” the more useful question is, “Where across the business does this regulatory change create operational impact?”

Compliance becomes less about interpreting regulations and more about understanding how the enterprise works. That shift requires capabilities most compliance functions do not currently have. Seeing a single dependency in full, across every regulator attached to it, is where most programmes fall short.

See Where Regulatory Divergence Enters Your Supply Chain

Mitratech helps risk and compliance teams map regulatory obligations across jurisdictions before divergence becomes a finding.

Discover More Now

From Country Compliance to Regulatory Intelligence

More country-specific compliance programmes will not solve this. You need a different way of understanding regulation altogether, starting with continuous awareness.

Periodic regulatory reviews still have value, but they offer only snapshots of an environment continuing to evolve. Leading governance functions are replacing periodic review with continuous monitoring, allowing regulatory developments to be assessed as they emerge rather than after they have already begun affecting the business. What separates more mature programmes is what happens next.

Regulatory obligations are increasingly being mapped directly to business processes, controls, technologies, and third-party relationships. Regulatory intelligence is also becoming part of third-party risk management (TPRM) itself, allowing your TPRM function to evaluate how evolving requirements affect critical suppliers, outsourcing arrangements, and technology providers over time. The focus shifts from “Which regulator issued this?” to “Which parts of the business does this change touch?”

No single function can answer those questions on its own. Legal, compliance, procurement, information security, privacy, and enterprise risk all see different aspects of regulatory change. Bringing those perspectives together creates a far more accurate picture of your enterprise exposure than any function develops independently.

Mitratech’s 2025 third-party risk research found compliance team involvement in TPRM programmes has risen from 42% in 2023 to 88% in 2025, while nearly 70% of TPRM teams remain understaffed and cover only 40% of their vendor base on average. (Mitratech study) The demand for cross-functional regulatory oversight is rising faster than the capacity to deliver it.

Technology is making the approach more achievable. AI-assisted regulatory analysis and integrated GRC platforms can connect regulatory developments with suppliers, technologies, controls, and business services, which helps your risk teams see where change creates operational consequences rather than simply adding another item to a regulatory tracker.

Map the dependency first, then the regulators attached to it. One question follows from this. If APAC is where these capabilities get tested hardest, what does that tell you about everywhere else?

APAC Is Showing You Where Governance Is Headed

APAC has become one of the clearest tests of organisational resilience because it asks governance functions to operate across competing regulatory models at the same time. The work is building governance that adapts to complexity rather than reducing it.

Competitive advantage looks different as a result. It now comes from recognising where geopolitical developments, regulatory change, operational dependencies, and business strategy intersect before those forces begin pulling the business in different directions. APAC rarely rewards the organisation with the thickest policy manual. It rewards the one understanding where regulation, technology, suppliers, and strategy meet.

The region makes those connections impossible to ignore because it brings together some of the world’s most diverse legal systems, regulatory priorities, and geopolitical interests. The capabilities your business develops to operate successfully there (continuous regulatory intelligence, operational visibility, cross-functional governance, and a deeper understanding of third-party ecosystems) are becoming essential well beyond the region itself. You cannot govern a dependency you have not mapped.

You cannot simplify APAC into a single regulatory model, because no such model exists. What you can build is a governance function capable of recognising patterns, understanding dependencies, and adapting as governments continue to pursue different strategic objectives through regulation.

Every enterprise will eventually operate in an environment where regulation follows national strategy rather than international convergence. APAC is simply where it arrived first.

If your governance model still assumes convergence, the region will find that out before your regulators do. Start with the dependencies and not the jurisdictions.

 

Other blogs in this series:
The Geopolitical Risk That’s Already Inside Your Organisation
European Regulation Doesn’t Stop at Europe’s Borders
The Policy Shift Enterprise Risk Management Wasn’t Built For

Build Regulatory Intelligence That Works Across Jurisdictions

Mitratech connects regulatory change, policy obligations, supplier oversight, and operational risk in a single view, so your teams see where divergence creates exposure.

Discover More Now

 

At Mitratech, we help risk and compliance leaders build governance capable of holding up across competing regulatory models. Our capabilities span third-party risk management, policy management, enterprise risk management, and AI-assisted regulatory intelligence through ARIES™, connecting regulatory developments to the suppliers, controls, and operational dependencies they affect. Governments will never harmonise, so we do not try. We give your teams one view of exposure across all of it

Ask Jan: Questions I Get About APAC

GRC Answers from Jan Stappers, Executive Vice President, GRC Solutions Strategy at Mitratech

Can we just build one APAC compliance framework and adjust locally?
“You can build one, and you should. What you cannot do is expect it to answer the questions each regulator is asking. I have seen firms invest heavily in a regional framework, then discover in the first supervisory conversation that the regulator wanted evidence the framework was never designed to produce. Build the framework for consistency of process, by all means. Do not build it expecting consistency of expectation, because there is none to find.”
Where do compliance programmes get caught out most often?
“Compliance programmes get caught out on suppliers more than anything else. A single cloud provider or outsourced service can sit inside four or five regulatory regimes simultaneously, and the contract in front of you reflects one commercial relationship. Teams tend to assess the supplier once, against the framework of the jurisdiction where the contract was signed. The exposure sits in the other four. My advice is simple. Start with the dependency and work outward to the regulators, rather than starting with the regulators and working inward.”
Is regulatory divergence in Asia-Pacific likely to narrow over time?
“I would plan on divergence widening rather than narrowing. For most of my career, the reasonable assumption was gradual convergence, and for a while it held. It no longer does. When governments regulate to advance national strategy, whether that is technological leadership, digital sovereignty, or financial resilience, they are answering domestic questions. Domestic questions do not converge. Anyone building a five-year compliance roadmap on the expectation of harmonisation is building on sand.”
My programme is organised by jurisdiction. What should I do first?
“My advice is not to restructure first. Start by mapping your critical suppliers and technology platforms against the jurisdictions they touch, and see how many regulatory regimes attach to each one. That exercise usually takes a few weeks, and it tends to be uncomfortable, because most teams find exposure they had no visibility of. You need that picture before you decide anything about structure. Reorganising a compliance function before you understand where your dependencies sit is expensive and rarely solves the problem.”
We have limited APAC operations. Does any of this apply to us?
“Yes, and this is the part I would emphasise. Regulation following national strategy rather than international convergence is not an APAC characteristic. It is the direction of travel globally, and we have written about how the same pattern shows up in European regulation and in US economic security policy. APAC is simply where the divergence is furthest along and hardest to ignore. The capabilities you build for the region are the ones you will need everywhere.”