BCG:2022年全球ESG合规与风险报告(英文版)_13页_1mb
报告摘要
2022 Global ESG, Compliance & Risk Report Summary
Core Content
This report explores how companies are navigating the increasingly complex global regulatory landscape, focusing on the evolving role of compliance functions in creating value amidst rising uncertainties. It highlights the need for strategic adaptation, cross-functional collaboration, and the integration of digital and ethical practices to manage risks effectively and sustainably.
Main Topics and Key Findings
1. Compliance Mandate: Emphasizing Value Creation
- Clear Mandate: A well-defined compliance mandate is essential for the function to create value.
- Risk Categories: Compliance organizations manage a wide range of risks, including fraud, competition, IT, capital market, and employee risks.
- ESG Integration: ESG-related topics (sustainability, environmental law, human rights) are included in compliance mandates by only 50–67% of organizations.
- Cross-Functional Collaboration: Effective collaboration across departments is crucial to avoid siloed responses and ensure comprehensive risk management.
- Role Variability: The compliance function's role varies by company, from oversight to specific responsibility, and should align with the organization’s business and ESG goals.
2. Geopolitics: Responding to Global Events
- Sanctions and Trade Compliance: These have become a top priority, with a 15-place rise in importance from 2021.
- Crisis Management: Companies must develop crisis response plans to handle supply chain disruptions and sanctions.
- Political Impact: Geopolitical tensions are pushing companies to take a political stance, especially with sanctions being used as a strategic tool.
- EU and Germany: The EU’s Corporate Sustainability Reporting Directive (CSRD) and Germany’s Supply Chain Due Diligence Act are key regulatory developments.
- Top Key Topic: Geopolitical tensions were ranked as the most important topic by survey participants, reflecting its growing relevance.
3. ESG Compliance: Meeting Stakeholder Expectations
- Regulatory Pressure: Over 170 ESG regulations have been introduced globally since 2018.
- Stakeholder Drivers: ESG efforts are driven by regulators (60%), customers (48%), and employees (47%).
- Compliance Role: Compliance functions are often central to ESG management, especially in risk assessment, governance, and reporting.
- Reputational Risks: Social compliance breaches can lead to significant reputational damage.
- Survey Insights: 43% of respondents identified ESG as one of the top five trends, and 79% reported increased commitment to ESG over the past two years.
4. Digitization: Making Up for Lost Time
- Digitization as a Solution: Companies are turning to digitization to improve efficiency and reduce compliance costs.
- Integration Challenges: Many companies lack a fully integrated operating model and are only beginning to explore digital use cases.
- TOM and Digital Strategy: A Target Operating Model (TOM) and integrated architecture are critical for successful digitization.
- Digital Readiness: 54% of respondents feel well or very well positioned to adapt, but 52% have not advanced very far in their digitization journey.
- Cybersecurity Synergy: Digitization and cybersecurity are closely linked, with compliance playing a key role in managing digital risks.
5. Cybersecurity: Addressing Critical Gaps
- Top Priority: Cybersecurity is the most relevant topic for compliance, cited by 62% of respondents.
- Threat Landscape: Cyber threats are becoming more aggressive, sophisticated, and persistent.
- Investment Gaps: Many companies lack sufficient investment in cybersecurity, resilience, and testing.
- IT Infrastructure Challenges: 38% of respondents identified inadequate IT infrastructure as a major challenge.
- Human-Centric Approach: Employee awareness and training are vital to preventing cyberattacks, with weak passwords and lack of multi-factor authentication being key vulnerabilities.
- Scenario Planning: Regular simulation exercises help build incident response capabilities.
- Regulatory Developments: The U.S. Cyber Incident Reporting for Critical Infrastructure Act is a new regulatory requirement in this area.
6. Business Ethics: Establishing a Culture of Integrity
- Ethical Culture: A strong ethical culture is essential for effective compliance and governance.
- Survey Insights: Over half of respondents ranked business ethics among the top five compliance topics.
- Code of Conduct: 70% of respondents reported that their written codes of conduct are well established and communicated.
- Talent and Training: Companies are focusing on attracting and retaining ethical talent, with a growing demand for cyber risk professionals.
- Influence of Compliance: Compliance departments are becoming more influential as they provide guidance on ethical behavior and risk management.
Key Information
- Survey Scope: The report is based on interviews with 250 compliance professionals across industries and regions.
- TOM Importance: A robust Target Operating Model is crucial for managing compliance risks and leveraging digitization.
- Cross-Functional Collaboration: Necessary for addressing complex risks and ensuring comprehensive compliance strategies.
- Regulatory Evolution: The pace of regulatory change is accelerating, especially in ESG and cybersecurity areas.
- Digital Maturity: Companies with advanced digital strategies are better positioned to adapt and innovate in compliance.
Conclusion
To thrive in a complex and uncertain global environment, compliance functions must evolve from mere rule enforcers to strategic advisors that drive value creation. This requires clear mandates, cross-functional collaboration, and a strong focus on digitization and ethical culture. Companies that invest in these areas will not only meet regulatory demands but also enhance their reputation, customer trust, and competitive advantage.
试读结束,高清完整版pdf/doc/ppt,请点下载