Legal expert Stavros Koumentakis published guidance on September 11, 2026, outlining how corporate board members face personal liability when regulatory compliance systems fail to deliver timely information to executive decision-makers.
Koumentakis, managing partner at Koumentakis and Associates Law Firm, stated that a functional compliance framework requires clear risk evaluation and control mechanisms that actively inform management actions rather than remaining passive administrative procedures.
Koumentakis and Associates Law Firm provides corporate legal advisory services in Greece, focusing on commercial law and governance standards for public limited companies. Writing in an ongoing legal commentary series, Koumentakis emphasized that executive oversight must translate internal risk assessments into concrete corrective actions.
Management does not need to understand every technical detail within an enterprise. However, Koumentakis noted that board members are required to identify material risks, allocate sufficient resources, establish clear organizational roles, and verify that corporate decisions are fully executed in practice.
He explained that individual exposure and personal liability for board members depend on the applicable regulatory framework, designated duties, and specific individual conduct. He added that internal civil liability toward a corporation does not cover all personal risk, as administrative or criminal liability requires specific statutory provisions.
Legal Basis of Board Supervision
Under statutory corporate law governing public limited companies, members of a board of directors must strictly comply with national legislation and company articles of association while serving corporate interests. Board members must supervise the execution of decisions and continuously inform colleagues about company affairs.
The required standard of care is assessed based on the specific circumstances, role, and duties of each board member. Koumentakis pointed out that establishing a regulatory compliance system does not automatically eliminate management liability, but instead structures the information necessary to fulfill existing duties of care, loyalty, and oversight.
When a severe risk becomes visible and gets formally reported to management, subsequent inaction becomes significantly harder to justify legally. Koumentakis warned that simply adopting internal policies or appointing compliance officers is ineffective if information fails to reach decision-makers who hold the power to intervene.
Delegation Rules and Supervision Limits
Corporate management frequently delegates operational tasks to specialized departments or executives. However, Koumentakis stressed that delegating authority does not remove supervisory obligations, which remain with the board of directors or designated individual members.
Proper delegation requires careful personnel selection, clearly defined tasks, adequate authority, real operational resources, and regular reporting mechanisms. Corporate structures must maintain full clarity regarding who holds responsibility, what tasks are undertaken, and how performance execution is verified.
In cases of severe corporate non-compliance, management cannot avoid liability by claiming that a matter was delegated to a specific department. Koumentakis stated that board members must inspect what was reported, evaluate the questions asked, and verify that remediation actually occurred.
He clarified that executive supervision does not require daily micromanagement. Instead, board members must ensure timely intervention whenever material issues arise.

Decision-Oriented Compliance Information
Providing management with a basic list of pending issues is insufficient if it lacks prioritization, severity levels, time sensitivity, and actionable options. Koumentakis emphasized that critical compliance reports must detail verified facts, potential risks, available choices, and the specific decision requested from management.
Corporate reporting must clearly distinguish confirmed factual evidence from subjective estimates while highlighting the financial cost of inaction. He noted that legal counsel translates legal exposure into commercial consequences, though legal advisors never replace executive decision-making.
Risk Appetite and Business Judgment Standards
While no executive team can eliminate all corporate risk, management must explicitly define the types and levels of risk it is willing to assume or retain. Koumentakis cautioned that deliberately violating mandatory legal rules never constitutes a valid commercial choice.
Acceptance of residual risk applies only to risks remaining after reasonable control measures are implemented, requiring formal justification and periodic review. Risk appetite becomes effective when translated into explicit tolerance limits, authorization thresholds, and formal escalation pathways.
To qualify as a reasonable business decision under standard corporate governance rules, actions must be taken in good faith, with adequate information, and to serve corporate interests. Obtaining external advisory opinions strengthens decision-making but does not provide an independent shield against liability, while conflicts of interest require immediate disclosure and recusal.

Audit Trails and Crisis Leadership Protocols
Executive supervision must generate a verifiable audit trail. Koumentakis recommended documenting identified risks, expert recommendations, executive decisions, assigned personnel, and scheduled review dates contemporaneously rather than creating records retroactively after issues emerge.
Board members should not rely solely on assurances provided by operational personnel executing corporate procedures. Compliance and risk management functions must critically evaluate control implementation, while internal audit provides independent assurance through direct, unhindered reporting lines.
During a corporate crisis, management requires structured information channels, predefined emergency roles, and rapid decision-making based on available facts. Immediate priorities include protecting personnel, preserving evidence, limiting damage, and fulfilling regulatory obligations, followed by root cause analysis and verified corrective action plans.

Key Governance Principles and Future Focus
Koumentakis concluded that while no compliance framework grants total immunity, a structured system documents that material risks were identified, evaluated, and mitigated. The crucial test for board members is proving what they knew, what they decided, and how they supervised execution.
Responsible corporate governance links information flow, decision-making, delegation, due diligence, and verification into a continuous cycle. Koumentakis noted that these same standards apply to external suppliers, service providers, and corporate agents, adding that third-party selection, contracting, and monitoring will be detailed in the next article of the series.
