Skip to content
Open access

Cross-Industry Unified Compliance Frameworks for Multinational Organizations

Jun 2026 · Multiverse Journal · Vol 3, pp. 93-114 · 0 citations · 4 references

Abstract

Multinational organizations operating across diverse regulatory regimes face significant challenges in managing compliance obligations that span multiple jurisdictions, industries, and legal frameworks. The fragmented nature of compliance management, characterized by siloed risk assessments, disconnected control mechanisms, and duplicative reporting structures, creates operational inefficiencies, heightened compliance risks, and increased costs. This paper examines the conceptual foundations and practical implementation of cross-industry unified compliance frameworks designed to address these challenges. Building upon Chinenye's (2013) foundational work on transitioning from fragmented compliance to integrated governance, this study explores how multinational organizations can harmonize regulatory controls, security protocols, and risk management processes across disparate operational contexts. Through analysis of international standards (ISO 19600, ISO 31000, COSO ERM), technological enablers (blockchain, automation, GRC platforms), and governance architectures, the paper proposes a comprehensive framework for achieving compliance integration. The framework emphasizes centralized policy development coupled with localized implementation, continuous monitoring mechanisms, and stakeholder engagement across organizational boundaries. Findings indicate that successful unified compliance frameworks require alignment of organizational culture, technology infrastructure, and governance structures while maintaining flexibility to accommodate jurisdiction-specific requirements. The paper concludes with recommendations for practitioners and identifies areas for future research in compliance harmonization and regulatory technology. 

Read PDF

Similar papers

Review Open access Jul 2026

Fragmentation and Harmonization of Cybersecurity and IT Control Frameworks: An Integrative Review of U.S. Governance Practices

Cybersecurity and information technology control frameworks in the United States exhibit significant fragmentation arising from overlapping regulatory mandates and duplicated controls. Audits and compliance activities in financial institutions and critical infrastructure sectors identify vulnerabilities but reveal limitations when applied as static mechanisms rather than adaptive processes. Mapping exercises between National Institute of Standards and Technology Cybersecurity Framework, Control Objectives for Information and Related Technology, and International Organization for Standardization 27001 consistently document both shared requirements and gaps that widen with the introduction of artificial intelligence and machine learning. Federal harmonization efforts have produced initial coordination yet face persistent barriers from agency-specific mandates and scarce longitudinal outcome data. Governance practices navigate these tensions through sector-specific applications that balance operational demands against systemic interoperability needs. The empirical studies highlight the need for continued attention to framework alignment, regulatory coordination, and empirical validation if resilience is to match evolving threats. Effective integration of controls requires addressing both practical implementation challenges and broader policy structures that shape cybersecurity governance across regulated industries. These dynamics underscore the importance of reducing unnecessary duplication while preserving essential specialization to support more resilient national cybersecurity posture. Ultimately, achieving meaningful harmonization will depend on sustained policy coordination and the development of robust evidence on post-alignment outcomes. This review synthesizes cross-sector evidence to identify structural, operational, and technological barriers to harmonization, while proposing an integrative governance perspective grounded in recent empirical and policy literature.

William Asare Yirenkyi, G. Apaflo, Matilda Konotey et al. · 0 citations
Open access Jul 2026

The uneven path to global value chain upgrading: regulations, private governance, and supplier compliance

Global value chains (GVCs) generate efficiency through production fragmentation but simultaneously create sustainability vulnerabilities that can undermine GVC resilience. While MNE buyer-led private ordering and state regulation represent the primary governance responses to these risks, their effects on supplier compliance remain contested. We develop a domain-sensitive governance framework showing that labor and environmental compliance differ systematically in their cost–benefit structures, and which in turn shape the effectiveness of governance forms in driving compliance across sustainability domains. Using a panel of over 2000 suppliers across emerging economies, we find evidence for the asymmetric effectiveness of governance forms across compliance domains. In the labor domain, both regulation and private ordering improve compliance, as stronger labor regulations increase MNE sourcing and reinforce suppliers’ incentives to upgrade. In contrast, in the environmental domain, while private ordering improves compliance, stringent environmental regulation reduces MNE sourcing, weakening suppliers’ incentives to invest in environmental improvements. We identify a buyer–regulation intermediation mechanism through which regulatory stringency shapes supplier compliance indirectly by altering MNE sourcing strategies. Our findings advance GVC governance research by showing that sustainability compliance, and thus resilience, depends not only on governance instruments but also on domain-specific incentive structures and buyer-mediated governance dynamics.

Shubham Singh, Ajai Gaur, R. Mudambi · 0 citations
Conference Jul 2026

State of the Art in Critical Infrastructure Protection and Resilience in Portugal: Governance, Incidents, and Gaps

Portugal is expanding its portfolio of recognized critical infrastructures from approximately 150 to more than 400 entities across twelve strategic sectors, reflecting increasing cross-sector interdependence and exposure to hybrid disruptions. Critical infrastructure governance is coordinated by the National Security Office and the National Cybersecurity Center and has been reinforced since 2024 through the establishment of the National Unit for the Protection of Critical Entities. Despite these advances, persistent challenges remain, including fragmented institutional mandates, uneven integration of cyber and physical resilience practices, skills shortages, and dependence on external technological providers. This paper examines how Portugal's critical infrastructure protection and resilience governance is evolving in response to the European Critical Entities Resilience (CER) and NIS2 frameworks. Its novelty lies in combining legal-institutional analysis, incident-based cross-case comparison, and a resilienceassurance framework tailored to CER/NIS2-aligned governance assessment. The study applies a structured review of legal instruments, national strategies, regulatory publications, and publicly documented incidents between 2011 and 2026 in order to synthesize sectoral scope, governance roles, disruption patterns, and assurance gaps across sectors. Findings highlight three recurring governance weaknesses: fragmented institutional coordination, incomplete cyber-physical integration in resilience practices, and the absence of comparable resilience metrics and assurance artifacts. The paper contributes a compact analytical synthesis of Portugal's critical infrastructure governance and proposes a minimal roadmap and assuranceoriented framework to support CER/NIS2-aligned resilience evaluation and continuous improvement.

P. A. P. Costa, António Gonçalves, M. Marques · 0 citations
Open access Jul 2026

Compliance as Strategy: A Law and Management Approach to Corporate Accountability and Sustainable Growth

In an era marked by intensifying regulatory scrutiny and stakeholder activism, corporate compliance is no longer a peripheral legal obligation but a core strategic function. This study examines how organizations can transform compliance from a cost center into a value-creating mechanism that enhances corporate accountability and drives sustainable growth. Drawing on interdisciplinary perspectives from corporate law and strategic management, the paper develops a conceptual framework linking legal compliance, governance quality, risk management, and organizational performance. The research adopts a doctrinal–analytical methodology, synthesizing statutory provisions, governance codes, and contemporary management theories. It integrates agency theory, stakeholder theory, and risk-based compliance models to explain how robust compliance systems reduce legal uncertainty, mitigate regulatory risk, and strengthen stakeholder trust. The study also explores the role of board oversight, compliance culture, and digital governance tools in embedding compliance within strategic decision-making. Findings suggest that firms that internalize compliance as a strategic capability achieve superior outcomes in terms of risk mitigation, reputational capital, and long-term sustainability. Conversely, reactive or minimalist compliance approaches increase exposure to legal sanctions and erode organizational legitimacy. The paper highlights emerging trends such as ESG-linked compliance, data protection regimes, and technology-enabled monitoring, which are reshaping the compliance landscape. The study concludes that integrating legal compliance into corporate strategy is essential for achieving resilient and responsible business performance. It recommends policy and managerial interventions to strengthen compliance governance and align legal frameworks with sustainable development goals.

Partha Priya Das, Moni Deepa Das, Utpal Chakraborty et al. · 0 citations
Open access Aug 2026

The Challenges Posed by Decentralized Finance to Traditional Financial Regulatory Frameworks and Pathways for Restructuring

Decentralized Finance (DeFi) refers to an open financial ecosystem built on blockchain technology that does not require the participation of centralized institutions. The technology and operational mechanisms it employs represent a significant "paradigm mismatch" with the current financial regulatory framework. This paper examines the comprehensive impact of DeFi on existing financial regulation from multiple perspectives, including the blurring of regulatory authority and a lack of accountability; the difficulty in identifying regulatory targets and the ambiguity in determining their nature; the ineffectiveness of regulatory rules and the absence of relevant provisions; overlapping jurisdictions, and difficulties in enforcement. Through a comparative study of regulatory experiences in the United States, Europe, and other regions, this paper proposes solutions such as shifting the existing regulatory philosophy toward functional regulation, embedding compliance requirements into the underlying technology at the institutional level, and strengthening international cooperation at the operational level, while also discussing the specific context in China. This paper identifies a threefold paradigm mismatch between decentralized finance and traditional financial regulation, giving rise to multiple regulatory challenges such as difficulties in holding entities accountable, ambiguity in defining regulatory targets, ineffective regulatory rules, and obstacles to cross-border enforcement. A comparison of regulatory practices in the U.S. and Europe reveals that it is difficult for any single country to independently manage the risks associated with globalized DeFi.

Yingzhu Chen · 0 citations