Andy Burnham’s ascension to the role of the United Kingdom’s seventh Prime Minister in the past ten years marks a significant moment in British political history, potentially ushering in a new era of governance. While a complete overhaul of corporate risk, governance, and compliance frameworks is not immediately anticipated, a closer examination by Jonathan Armstrong, a partner at Punter Southall, reveals several key areas that businesses and their compliance departments should monitor closely in the coming weeks and months. The transition of power, even without a deluge of new legislation, can fundamentally alter the regulatory environment through shifts in ministerial responsibilities, departmental structures, and evolving political priorities.

The immediate aftermath of Burnham’s July inauguration suggests that an overwhelming rush of new compliance-related legislation is unlikely, given his packed domestic and international agenda. However, as the new administration solidifies its footing, a discernible shift in direction may emerge, hinting at a considerable reset in policy. While concrete predictions remain premature, certain priority areas are already coming into focus, necessitating close attention from compliance and in-house legal teams.

The Evolving Landscape of Artificial Intelligence and Data Regulation

Artificial Intelligence (AI) stands out as a prominent area where significant governmental action is anticipated. Prime Minister Burnham has already initiated changes to how his government approaches AI, notably with the dissolution of the Department for Science, Innovation and Technology (DSIT). Ministerial responsibilities are being realigned, with AI Minister Kanishka Narayan now integrated into the Cabinet Office, granting him direct access to cabinet discussions. Furthermore, Narayan will also be a part of the newly formed Department for Business, Innovation, Science and Trade, consolidating oversight and strategic direction.

The precise implications for AI regulation remain to be fully elucidated. However, there are indications that the Burnham government may lean towards more robust regulatory measures, potentially drawing inspiration from the European Union’s AI Act. Minister Narayan has publicly articulated concerns regarding the risks posed by AI, including its potential impact on employment and the rapid pace of technological advancement. This area is therefore a critical one to observe as the new governmental structure takes shape and policy initiatives begin to materialize. For context, the EU AI Act, which came into effect in June 2024, aims to establish a comprehensive legal framework for AI, categorizing AI systems based on their risk level and imposing corresponding obligations on developers and deployers. The UK’s approach, while potentially influenced by this, is likely to be tailored to its own economic and technological landscape.

The Information Commissioner’s Office (ICO) has also experienced recent changes. John Edwards, the Information Commissioner, announced his retirement in June, following an internal investigation into his conduct. The recruitment process for a new Information Commissioner is currently underway. This transition occurs at a challenging juncture for the regulator, which is grappling with an escalating volume of complaints. These complaints are increasingly sophisticated, often generated with the assistance of generative AI. Simultaneously, the ICO is tasked with implementing new powers granted under the Data (Use and Access) Act 2025, a piece of legislation designed to facilitate data sharing for specific public interest purposes while maintaining robust privacy safeguards. The appointment of a new Commissioner will be crucial in navigating these complex challenges and shaping the future of data protection and privacy in the UK.

Government Procurement: A Potent Tool for Driving Social and Environmental Change

Andy Burnham’s track record as Mayor of Greater Manchester offers a clear indication of his administration’s potential approach to government procurement. He consistently leveraged public sector spending to champion progressive procurement practices, often referred to as social value procurement, as a means of influencing supply chain behavior. His vocal support for Environmental, Social, and Governance (ESG) principles, including a firm stance against forced labor, further underscores this commitment.

Consequently, it is plausible that the Burnham government will place a heightened emphasis on ESG considerations, supply chain transparency, and anti-corruption measures within government procurement processes. This could translate into increased pressure on suppliers to actively support broader societal objectives, such as the provision of apprenticeships for young unemployed individuals. The implications for businesses are significant: contractual requirements may evolve to reflect these new priorities, even in the absence of extensive new legislation. The government’s considerable purchasing power provides a potent mechanism for driving change, making it imperative for companies engaged with the UK public sector to closely monitor how these emerging priorities translate into tangible contractual obligations. For example, a company seeking a government contract might now be evaluated not only on price and quality but also on its demonstrable commitment to ethical sourcing, carbon reduction targets, and community engagement initiatives.

ESG’s Resurgence and Enhanced Corporate Responsibility

While some businesses may have re-evaluated their commitment to ESG initiatives in response to shifts in the US regulatory landscape, they should exercise caution in assuming a similar trajectory in the UK. The push for greater corporate responsibility may manifest through existing legal frameworks rather than necessitating entirely new legislation. Section 172 of the UK Companies Act 2006 already places a statutory duty on company boards to consider a range of factors, including the long-term consequences of their decisions, the impact of operations on the community and environment, and the importance of upholding high standards of business conduct. A renewed emphasis on these existing responsibilities is a distinct possibility.

Modern slavery remains another critical area for compliance teams. The new administration may express a desire to update the Modern Slavery Act 2015, though securing parliamentary time for such legislation could prove challenging. In the interim, greater focus is expected on what the government can achieve through its considerable power as a purchaser of goods and services, potentially increasing scrutiny on supply chains for evidence of modern slavery. The potential for stricter due diligence requirements and reporting obligations on companies, even without legislative amendments, is a significant consideration.

Tackling Fraud, Empowering Whistleblowers, and Strengthening Cybersecurity

The introduction of the "failure to prevent fraud" offense has fundamentally altered the legal landscape concerning corporate accountability for economic crime. Coupled with increased funding for the Serious Fraud Office (SFO), with a specific focus on intelligence gathering, proactive identification of major economic crime, and enhancement of technological and investigative capabilities, this signifies a tougher enforcement environment. The expanded use of these "failure to prevent" powers could lead to materially more rigorous enforcement actions against large corporations, particularly those involved in public sector contracts. The SFO’s enhanced mandate could result in a proactive investigation strategy, moving beyond reactive responses to reported incidents.

Whistleblowing is another area poised for attention. Prime Minister Burnham is generally perceived as more employee-centric than his predecessors and has previously advocated for more robust whistleblower protections, including within the National Health Service and for individuals exposing wrongdoing in public bodies. The long-term prospect of strengthened whistleblower protections, potentially drawing on evolving standards across the European Union, could create a more secure environment for internal reporting of misconduct. This might involve clearer guidelines for reporting, protection against retaliation, and potentially more streamlined investigation processes for reported concerns.

The future of UK cybersecurity legislation is less clear following the closure of DSIT. Responsibility for proposed changes is likely to transfer to the newly expanded Department for Digital, Culture, Media and Sport. The Cyber Security and Resilience Bill is currently progressing through Parliament, with committee stage in the House of Lords scheduled for September. The new administration may undertake a review of the resources and effort required to enact this bill. The bill aims to update and consolidate existing cybersecurity regulations, reflecting the evolving threat landscape. Its passage and any subsequent refinements will be critical for businesses operating in the digital sphere.

A less apparent but potentially significant challenge could arise from the increasing devolution of powers. If areas such as planning, housing enforcement, transport regulation, and skills funding are increasingly devolved, compliance professionals may find themselves navigating a complex web of different regulators across various parts of the UK. This could introduce both increased complexity and higher compliance costs for businesses operating nationwide. The potential for a fragmented regulatory approach across different regions of the UK presents a unique challenge, requiring businesses to stay abreast of diverse and potentially diverging regulatory requirements.

Strategic Preparedness for Compliance Teams

While the precise contours of the new administration’s policy agenda are still emerging, and businesses should exercise caution against attempting to predict every single move, a passive approach is ill-advised. The most effective strategy for compliance and legal teams involves proactive monitoring and adaptation.

Firstly, establishing robust mechanisms for tracking legislative and regulatory developments is paramount. This includes staying informed about departmental announcements, policy consultations, and parliamentary debates. Secondly, a critical re-evaluation of any ESG programs that may have been de-prioritized is warranted. Companies should assess whether these programs align with potential shifts in government focus and stakeholder expectations. Thirdly, ensuring that boards and directors of UK limited companies, including subsidiaries, have a clear understanding of their existing legal responsibilities, particularly under Section 172 of the Companies Act 2006, is essential. Finally, a thorough examination of the potential implications for any part of the business that engages with the UK public sector is crucial. This involves understanding how evolving procurement priorities might affect contractual terms and business relationships.

The next wave of changes impacting compliance may not be heralded by the grand pronouncements of major new legislation. Instead, these shifts could manifest through subtle but impactful alterations in procurement terms, evolving government priorities, or a recalibration of regulatory emphasis. For compliance teams, the challenge and indeed the imperative, lie in the ability to identify these emerging trends early and to develop agile responses that ensure continued adherence to evolving legal and ethical standards. This proactive stance will be key to navigating the dynamic compliance landscape under the new administration and maintaining a strong ethical and legal foundation for business operations in the United Kingdom.

By