Regulatory Compliance and Management Liability
(informed decision-making, documented oversight and personal exposure)
Compliance is a management responsibility
In the previous article in this series, we examined how the regulatory map, risk assessment and controls form an operational compliance system. That system creates real value when information reaches management in time and is converted into decision-making, oversight and corrective action. Management does not need — and should not be expected — to know every technical detail. It must, however, understand the material risks, ensure that responsibilities are clearly allocated and adequate resources are available, and verify that decisions are implemented. Personal exposure and liability depend on the applicable legal framework, the role and responsibilities of each member and that person’s specific conduct.
The legal basis of oversight
In public limited companies (S.A.s), members of the board of directors must comply with the law, the articles of association and lawful resolutions of the general meeting. They must also manage the company’s affairs with a view to promoting the corporate interest and supervise implementation of resolutions of the board and the general meeting. They must further keep the other board members informed about corporate affairs (Article 96(1), Law 4548/2018). Each board member is liable towards the company for damage caused by an act or omission constituting a breach of his or her duties (Article 102(1), Law 4548/2018).
Liability does not arise if the member proves that he or she exercised the care of a prudent businessperson operating under similar circumstances. The standard of care is determined by reference to the status and duties of each member (Article 102(2), Law 4548/2018). Members are therefore not all assessed in exactly the same way. This differentiation does not eliminate the need for informed participation and effective oversight within each member’s area of responsibility.
The internal civil liability of board members towards the S.A. under Article 102 of Law 4548/2018 does not exhaust every possible form of personal exposure. These provisions do not affect potential liability of board members for direct loss suffered by shareholders or third parties, which must be based on the applicable legal basis in each case (Article 107, Law 4548/2018). Administrative or criminal liability requires a specific statutory basis. In other corporate forms, the basis and extent of liability may differ.
Compliance does not, by itself, eliminate management liability. It does, however, organise the information required for the discharge of existing duties of care, loyalty and oversight. Once a serious risk becomes visible and has been reported, subsequent inaction becomes more difficult to justify.
Management must know which matters require its own decision, which may be delegated and what information it needs in order to supervise that delegation. The mere existence of policies, committees or designated responsible persons is not sufficient where there is no genuine flow of information and no ability to intervene.
Delegation is not exoneration
Management may, and often must, delegate. In S.A.s, the board of directors may delegate management and representation powers to board members or third parties, where permitted by the articles of association (Article 87(1), Law 4548/2018). Functional delegation to specialised executives or advisers is often necessary in larger businesses.
Delegation does not automatically extinguish supervisory duties that remain with the board or with a particular member. Appropriate selection, a clearly defined mandate, sufficient authority, adequate resources and regular reporting are required. Management must know who is responsible, what that person has undertaken, to whom he or she reports and how performance is verified.
In the case of serious deviations, it is not sufficient to state that “the responsible department was handling it”. Management must consider what was reported, which questions were asked and whether remediation was confirmed. Warning signs — such as repeated delays, vague assurances or recurring exceptions — require active intervention. Oversight does not mean daily micromanagement. It means timely intervention in material matters.
Equal pay as an example of oversight
Equal pay provides a practical example of the distinction between execution and oversight. Management does not need to approve every remuneration decision. It must, however, know whether objective criteria, reliable data and controlled exceptions are in place. Systematic or unjustified discrepancies may create wider financial and legal exposure.
Oversight concerns the system within which decisions are made and the evidential trail they leave. A subsequent assertion of performance or experience carries limited weight where the relevant criteria were neither properly applied nor recorded at the appropriate time. Management needs an aggregated picture of patterns, financial impact and progress of corrective actions.
Information that enables decisions
Management often receives many reports but little useful information. A list of outstanding issues is insufficient if it does not reflect prioritisation, severity, time pressure and available options. For every critical issue, it should be clear what happened, what the risk is, what options are available and which decision is required.
Confirmed facts must be distinguished from assessments. Uncertainty should not be concealed, nor should consequences be presented in a fragmented way. Information should also show the cost of inaction. The option to “wait” is itself a decision, with deadlines, potential loss and options that may disappear.
The absence of reports does not prove the absence of risk. Management must consider whether the system genuinely detects and escalates deviations. Legal counsel has a particular role: translating legal exposure into business consequences and available options, without of course replacing management’s decision.
Risk appetite and the business judgment rule
No management body can eliminate every risk. It can, however, define the types and level of risk it is prepared to assume or retain, taking into account legality, potential harm and the ability to remediate. Certain risks can be mitigated or insured. Deliberate violation of a mandatory rule, however, cannot constitute a legitimate business choice merely because the possible sanction appears financially tolerable.
Acceptance of residual risk concerns what remains after reasonable measures have been taken. It should be reasoned, time-limited and subject to review, with clearly identified compensating controls and an appropriate decision-maker. Risk appetite becomes meaningful when translated into risk tolerance limits, approval thresholds and escalation rules. It must be clear what an executive may approve, when a legal opinion is required and when a board decision is necessary.
The business judgment rule is not assessed solely by reference to the outcome. It presupposes good faith, adequate information and the exclusive criterion of serving the corporate interest. These elements are assessed at the time the decision was taken, and the members of the board bear the burden of proving them (Article 102(4), Law 4548/2018). The quality of the decision-making process is therefore decisive.
The business judgment rule is not a general shield for a deliberate breach of the law or for decisions taken without adequate investigation. An external adviser’s opinion strengthens the information basis of the decision, but it must be based on complete facts and address the actual question. Conflicts of interest require timely and sufficient disclosure. Where the statutory conditions are met, the member is not entitled to vote on the relevant matter (Article 97(1) and (3), Law 4548/2018). Timely identification of the conflict protects both the quality of the decision and its evidential credibility.
The audit trail of oversight and independent assurance
Management oversight must leave an audit trail. In S.A.s, discussions and resolutions of the board of directors are recorded in summary form in a special book of minutes (Article 93(1), Law 4548/2018). The record should be concise but meaningful: the risk, the recommendation, the decision, the responsible person and the review date. Material disagreements, reservations and critical assumptions should also be recorded where appropriate.
Documentation has value when it is created at the time of the decision or close to the relevant events. It is not intended to manufacture a defence retrospectively. Minutes that embellish the discussion or record only the final conclusion have limited governance and evidential value.
Management should not rely solely on the assurances of those who perform the process. Depending on the size, the risk and the specific regulatory framework, monitoring and independent assurance are required. Compliance and risk-management functions monitor and critically assess the implementation of controls. Internal audit provides independent assurance.
This distinction is not a uniform legal requirement for every business. What matters is that the relevant functions have access, sufficient capability and the ability to report uncomfortable findings without filtering. In smaller businesses, independence may be strengthened through external review or direct reporting to management.
Independent assurance does not relieve management of its own judgment. It does, however, provide a stronger basis for challenging overly reassuring reports, requesting further evidence and monitoring corrective actions. The effectiveness of the system is measured by its ability to surface uncomfortable information in time, not by the absence of findings.
A crisis tests management
A data breach, workplace accident, environmental incident or serious complaint tests the actual quality of oversight. Management must know where the flow of information ends, who gathers the facts and who preserves the evidence. It must also know who communicates with authorities or customers and when an independent investigation is required.
During the first hours, complete certainty is not required. What is required is an organised decision based on the available information and a clear distinction between confirmed facts and assessments. Limiting harm, protecting persons and evidence and meeting critical obligations in time take priority. Attribution of responsibility should follow a reliable investigation.
After immediate remediation, root-cause analysis, a corrective action plan and verification of implementation are required. Repetition of the same weakness after a documented warning worsens the position of the business and may increase the exposure of both the company and those managing it. A technically remediated incident may remain open as a governance matter.
The response must be completed by follow-up review. It is not enough to issue an instruction or approve a corrective plan. Management must know whether the action was completed, whether it reduced the risk and whether a further decision is required. Follow-up closes the oversight cycle and prevents known weaknesses from recurring.
In summary: practical significance and value
No compliance system provides general immunity. It can, however, document that material risks were identified, assessed and addressed through appropriate mechanisms. For management, the important test is whether it can demonstrate what it knew, what it decided and how it supervised implementation. Responsible management rests on the connection between information, decision-making, delegation, diligence and verification. The same logic extends to suppliers, service providers and agents. Their selection, contractual commitments and monitoring are the subject of the next article.
Managing Partner
Koumentakis and Associates Law Firm
Note: This article forms part of a broader series of articles by our Law Firm on regulatory compliance, consistently approached from a business perspective. Appropriate legal advice should always be sought from a suitably qualified lawyer.