The space between the rules
A conversation with Daniel Pharaon, SVP – Internal Audit at Midis Group, on what compliance really means, and what it quietly builds in markets where integrity is always being tested.
1. Most people think compliance is about rules. But rules are Legal’s territory. What is compliance actually about, and why does that distinction matter?
The confusion is understandable. Legal’s job is to interpret rules, to tell you what the law says, where the boundaries are, and how to defend the organization if those boundaries are tested. That’s essential work. Compliance is something different, it’s about building the conditions under which employees consistently do the right thing even when no rule explicitly covers the situation in front of them. Compliance operates in the space between the written rules and what’s happening on the ground. That space, especially in our markets, is enormous.
In practice, that means compliance is fundamentally about culture, judgment, and trust.
It’s about, for example, whether a sales manager in a high-pressure quarter knows, instinctively, where the line is on a client gift. That’s also why we try to keep these conversations real inside Midis, with examples, not theory. And the return on that shift? It’s largely invisible, but it’s very real. In the short term, it becomes visible for a competitor who makes the other choice. In the long term, it’s when our reputation for integrity wins us major clients and vendors. Midis’ history has borne that out.
2. AI is entering our workflows. What do most leaders underestimate about what that means for compliance?
Most leaders are asking the right question: ‘how do we use AI responsibly?’ But they’re framing it too narrowly, I think. The conversation tends to focus on data privacy and output accuracy, but those are only the surface layer. What’s really underestimated is the accountability gap AI creates inside existing processes. When a human makes a decision, there’s a person, a judgment call, a traceable rationale. When an AI-assisted process produces an outcome, that accountability chain gets lost. Who owned that decision? What assumptions were baked into the model? These are compliance questions, and most governance frameworks weren’t designed to answer them.
3. What does maintaining a high level of integrity actually require, and what has it built over time that couldn’t have been built any other way?
It requires consistency under pressure. Anyone can maintain standards when environments are stable and margins are comfortable.
“The character of an organization reveals itself when the deal is large, the timeline is short, and there’s someone across the table suggesting that this is not how things work here”
Maintaining that standard means having clear frameworks, visible leadership, and an environment where raising a concern is treated as a contribution, not a friction point. It means being willing to walk away without drama or apology – reflecting a position, not a limitation. What that builds over time is trust at scale, with partners, regulators, clients, and the people inside the organization itself. Vendors know a commitment from Midis means something. Internally, top talent choose organizations where they don’t have to compromise their judgment to succeed.

Ultimately, the compliance standard is a talent standard. It shapes who stays, who thrives, and the quality of judgment embedded across the company. That’s a competitive asset you simply cannot buy.
It accumulates, slowly and deliberately, and becomes a genuine competitive asset in markets where trust is always being tested.
4. The compliance map across emerging EMEA keeps shifting. What does it look like right now, and what signal are you watching that the rest of the business probably isn’t?
Right now the map is characterized by three overlapping dynamics: regulatory acceleration, enforcement maturation, and geopolitical fragmentation.

Regulatory acceleration, particularly in data protection and AI governance, is the most visible, but it’s not the most consequential. Enforcement maturation is the quieter shift, but arguably the more consequential one. Markets where enforcement was historically light are now building institutional capacity, better-resourced regulators, cross-border cooperation, a greater willingness to use enforcement as a signal of institutional seriousness. The risk profile has changed, even if the written rules haven’t.
Geopolitical fragmentation adds a further layer; the realignment of trade relationships and competing regulatory blocs mean compliance decisions increasingly have a geopolitical dimension that didn’t exist five years ago.
But the signal we’re watching most carefully, and which I think is genuinely below the radar for most of the business, is the evolution of third-party and supply chain liability frameworks across the region. Several jurisdictions are moving toward models where your compliance exposure extends to the conduct of partners, agents, and distributors within your ecosystem.
Due diligence on a new partner isn’t a one-time checkbox at onboarding anymore, it’s an ongoing obligation with potential legal consequence. Organizations still running static, event-triggered reviews, are building a vulnerability they may not see until it’s tested. That’s where we’re spending time today.