Andy Burnham is the UK’s seventh prime minister in the past 10 years. A Burnham government probably won’t mean wholesale changes that affect corporate risk, governance and compliance, but Punter Southall partner Jonathan Armstrong unpacks the areas to watch in the weeks and months to come.
A new UK prime minister does not rewrite the compliance rulebook overnight, but changes in personnel, government departments and political priorities can still have a significant impact on compliance. But what are the likely changes?
Andy Burnham took office in July with a crowded domestic and international agenda, so it seems unlikely there will be an immediate rush of new compliance-related legislation. The direction of travel may nevertheless become clearer as the new administration settles in, and the early indications are that this could be a considerable reset.
It is too early to make concrete predictions, but some areas are already emerging as priorities that compliance and in-house legal teams will want to watch closely.
What next for AI & data?
AI is perhaps the most obvious area where action is likely. Burnham has already changed the way his government deals with it, with the closure of the Department for Science, Innovation and Technology (DSIT) and changes to ministerial responsibilities. AI Minister Kanishka Narayan will now sit within the cabinet office and attend cabinet meetings, while also forming part of the new Department for Business, Innovation, Science and Trade.
We don’t yet know what this will mean for AI regulation, although there are suggestions that Burnham may favor greater regulation and potentially adopt some of the approaches taken in the EU AI Act. Narayan has already spoken publicly about the risks AI poses, including concerns about jobs and the pace of change. This is clearly an area to watch as the new structure beds in and policy starts to emerge.
The information commissioner’s office has seen changes too. Information Commissioner John Edwards announced his retirement in June following an internal investigation into his conduct, and recruitment for a new information commission chair is underway. This comes at a challenging time for the regulator, which is dealing with a rise in complaints — including increasingly complex complaints created with the help of generative AI — while also having new powers under the Data (Use and Access) Act 2025.
Government procurement could be significant
As mayor of greater Manchester, Burnham used public-sector spending to pursue progressive procurement, also known as social value procurement, as a way of trying to influence behavior in the supply chain. He has also spoken about ESG-related issues, including forced labor.
We could therefore see greater emphasis on ESG, supply-chain transparency and anti-corruption in government procurement, as well as pressure on suppliers to support wider social objectives, such as providing apprenticeships for young unemployed people.
The interesting point for compliance teams is that this does not necessarily require a major piece of new legislation. The government has considerable buying power and could use procurement requirements and contracts to drive change. For businesses working with the UK public sector, it will be important to watch how any new priorities feed through into contractual requirements.
Considerations for Global Compliance Programs Under UK’s New Failure to Prevent Fraud Offense
Liability can result from conduct at parent or subsidiary level
Read moreDetailsESG may move back up the agenda
We know some businesses have de-prioritized ESG programs following changes in the US, but they may want to think carefully before assuming the UK will move in the same direction.
Some of the push toward greater corporate responsibility could happen without legislative change. Section 172 of the UK Companies Act 2006 already requires boards to consider issues like the long-term consequences of decisions, the impact of the company’s operations on the community and environment and the importance of maintaining a reputation for high standards of business conduct. We could simply see greater emphasis placed on those existing responsibilities.
Modern slavery is another area we’d expect compliance teams to keep an eye on. The new administration may favor updating the Modern Slavery Act 2015, although finding parliamentary time could be difficult. In the shorter term, we’d expect more focus on what the government can achieve through its power as a buyer of goods and services.
Fraud, whistleblowing & cybersecurity
The failure to prevent fraud offense is now part of the landscape, while Serious Fraud Office funding has increased, with a particular emphasis on intelligence-gathering, proactively identifying major economic crime and improving technology and investigative capability. Use of the new failure-to-prevent-fraud powers could mean a materially tougher enforcement environment for large corporations, particularly where public money is involved.
Whistleblowing is another one to watch. Burnham is generally seen as more pro-employee than the previous administration and has previously spoken in favor of stronger whistleblower protections, including in the National Health Service and for those exposing wrongdoing in public bodies. In the longer term, we could see protections strengthened, perhaps building on some of the changes already seen across the EU.
Cybersecurity is less clear following the closure of DSIT. Responsibility for proposed changes to UK cybersecurity law is likely to move to the newly enlarged Department for Digital, Culture, Media and Sport. The Cyber Security and Resilience Bill is still progressing, with the committee stage in the House of Lords due to begin in September. It may be that the new administration reviews the effort needed to get the bill over the line once that process is complete.
Devolution could create another, less obvious headache. If areas like planning, housing enforcement, transport regulation and skills funding are increasingly devolved, compliance professionals could find themselves dealing with different regulators in different parts of the UK, potentially adding both complexity and cost.
What should compliance teams do now?
We still don’t know a lot, and businesses should be wary of trying to predict every move the new administration might make. But waiting for new legislation before doing anything is not a good answer, either.
Compliance and legal teams should make sure they have a plan for monitoring developments, revisit ESG programs that may have been de-prioritized, ensure boards and directors of UK limited companies (including subsidiaries) are clear about their existing responsibilities and look carefully at the potential implications for any part of the business working with the UK public sector.
The next change in compliance may not arrive with the fanfare of a major new act of Parliament, but it could come through procurement terms, shifting government priorities or a change in regulatory emphasis. For compliance teams, the challenge will be spotting those shifts early and being ready to respond.


Jonathan Armstrong is a partner at Punter Southall. He is an experienced lawyer with a concentration on technology and compliance. His practice includes advising multinational companies on matters involving risk, compliance and technology across Europe. He has handled legal matters in more than 60 countries involving emerging technology, corporate governance, ethics code implementation, reputation, internal investigations, marketing, branding and global privacy policies. Jonathan has counseled a range of clients on breach prevention, mitigation and response. He has also been particularly active in advising multinational corporations on their response to the UK Bribery Act 2010 and its inter-relationship with the U.S. Foreign Corrupt Practices Act (FCPA). 







