Compliance is still often perceived as a separate department that gets involved in the process only when the contract has already been prepared, the counterparty has been found, all terms have been agreed upon, the team has spent time, and the business is ready to make a payment. In the view of corporate governance expert Elena Nusinova, this is one of the main mistakes made by companies that formally build a control system but do not get real protection from it. In a column for RBC-Ukraine, the specialist explains why compliance must be integrated into the process from the first step to the completion of the deal, what risks arise from a formal approach, and how to combine control, decision speed, automation, and personal accountability.
Compliance as a final barrier: where the systemic error lies
The typical scheme in most companies looks like this: counterparties are found, contracts are concluded, lawyers prepare documents, finance specialists model payments, and operational units plan the cooperation. Dozens of people are involved in this process, and weeks of negotiations and preparation are spent. And only at the final stage does compliance enter the game: it is this department that is handed the contract, the process, and the payment for approval. At this moment, the check reveals a risk that requires the cooperation to be stopped. Formally, compliance has performed its function correctly. But from the perspective of the business process, the company has already incurred substantial costs: employee time, legal support, negotiations, operation preparation, and sometimes reputational commitments to the other party. Nusinova emphasizes: if a company truly wants to manage risks rather than create the appearance of control, compliance must work not as a final barrier but as a cross-cutting element of the business process.
Cross-cutting control: from basic screening to in-depth verification
According to the expert, if a standard basic screening is carried out at the start, then at subsequent stages an in-depth check must be provided where it is truly necessary. Repeated control at intermediate stages allows the company to understand much earlier whether it should even proceed with cooperation with a particular partner. Nusinova notes that such a strategy does not complicate the business but, on the contrary, saves resources: the company does not invest months in a project that at the final stage turns out to be impassable due to compliance requirements. At all key stages — from hiring an employee for a critical or managerial position to choosing a supplier, working with a contractor, opening accounts, making payments, and attracting investors — compliance must be present as an embedded element, not as an external overseer.
Automation and the limits of machine analysis
Basic screening today can be largely automated. When a process roadmap is built and cross-cutting compliance is embedded into it, this function begins to deliver real efficiency. Standard checks — for example, whether a counterparty is Russian in a given case — have long been built into operational products and automated systems. However, as Nusinova emphasizes, a program cannot analyze beyond the basic level. If the ultimate beneficial owner turns out to be a citizen of China or Greece, the algorithm stops. Further, compliance specialists must step in, who examine the company from different angles: who actually controls the structure, what links stand between the operating company and the ultimate owner, whether there are related parties, sanctions or reputational risks, and whether the business structure corresponds to the declared economic activity. The stronger control systems become, the more complex the schemes that try to circumvent them. Automation is necessary, but it is not yet able to fully replace professional judgment.
Three blocks without which the system is incomplete
Nusinova highlights three blocks without which a compliance system cannot practically be considered complete. The first of them is counterparties: it is important not to limit oneself to a formal name check in a database but to build a multi-level analysis of the ownership structure and actual control. The expert points out that it is at this stage that depth is most often lost: the company sees a 'clean' name in the registry but does not understand who stands behind it and what risks the structure as a whole carries. The other two blocks, which the expert identifies in her methodology, complement control over internal processes and accountability for decisions made, forming a closed loop of risk management from entering a deal to closing it.
The key takeaway of the column is that compliance stops being a burden for the business at the moment it stops being the final instance. A control process embedded in every stage does not slow down decisions — it makes them more accurate and protects the company from losses that far exceed the cost of a preventive check. For a market where sanctions, reputational, and operational risks continue to grow, the transition from formal compliance to cross-cutting risk management stops being an option and becomes a condition for sustainable operation.