Governance spend is justifiable to any board when it passes four tests - countability, scaling logic, displacement accounting, and auditability. AI governance investment passes all four.
Your FD has presented you with another compliance investment ask. You will approve some and decline others. Here are the four tests that should determine which, and how AI governance investment looks against them.
AI compliance spend is a fixed cost of doing business in Europe. The CFO's question is not whether to spend, but whether the spend is structured, peer-aligned, and producing leverage. This piece is a CFO-to-CFO framework for evaluating compliance asks generally, with AI governance run through the framework as the worked example.
Three Benchmarks for Compliance Spend
Three ratios let you answer the question "are we spending the right amount" with peer-comparison data rather than internal anecdote.
Compliance spend as a percentage of revenue. Published surveys from Deloitte, Thomson Reuters, and the major audit firms have placed European mid-market compliance spend in the 1.5% to 4% of revenue range, with financial services running at the upper end and lighter-regulated industries at the lower. The figure to use for benchmarking is your firm's own number relative to the published distribution. Below 1.5% in a regulated industry is typically under-investment showing up later as audit findings; above 4% in a lighter-regulated industry is typically duplication or organisational drift in the compliance function.
Compliance FTE per €100M revenue. The published benchmark range for mid-market is roughly 0.5 to 2.0 FTE per €100M revenue, with financial services well above the upper end of that range and regulated technology firms (fintech, healthtech, edtech) clustering around the middle. The figure is more useful than the percentage-of-revenue measure for headcount-planning conversations.
Compliance spend per regulated activity. Less commonly used but more diagnostic. Take the firm's compliance budget, divide by the number of distinct regulated activities the firm operates against; GDPR processing, financial services authorisation, EU AI Act high-risk deployment, DORA scope, NIS2 scope, sector-specific authorisations. The per-activity number reveals whether the compliance function is appropriately resourced for the actual obligation surface, or whether some activities are being underserved while others are over-covered, the diagnostic that sits at the heart of sound enterprise risk management.
Use the benchmarks as orientation, not as targets. The right number for your firm depends on the regulatory exposure profile, the size of the customer-facing surface, and the maturity of the compliance function. The benchmarks are useful because they tell you whether you are inside or outside the credible range, which is the conversation a board has.
Four CFO Tests for Any Compliance Investment
Apply these to every compliance ask. The asks that pass all four are usually fundable; the asks that fail one or more deserve harder questions before approval.
- Is the spend countable? You should be able to state, in advance, what the investment produces in measurable terms - a register entry count, a documentation cycle, an audit-ready output, a coverage ratio against an obligation surface. "We need to do better on AI governance" is not countable. "We need an audit-ready inventory of every AI tool in the environment, refreshed monthly, with classification entries for the high-risk subset" is. That specificity is what separates AI compliance investment from compliance theatre.
- Does the spend scale with regulatory exposure or with revenue? Compliance investments that scale with revenue (as the firm grows, the function grows linearly) are usually defensible. Investments that scale with regulatory exposure; the number of obligations, the number of in-scope activities, are usually justifiable to the board because the spend track tracks the risk track. Investments that scale with neither are typically vendor expansion rather than capability expansion.
- What does it displace? Most compliance asks are presented as net new spend. Most are partially displacement of existing spend, manual maintenance time, audit consultant fees, point-tool subscriptions that are not pulling weight. The displaced cost is the part of the funding equation the FD often does not surface, and surfacing it is where compliance automation changes the magnitude of the ask materially.
- Is the investment itself auditable? Will you be able to demonstrate, in twelve months, that the spend produced the outputs you said it would? If the answer is no, if the deliverables are framework-shaped rather than output-shaped, the investment is more risky than the magnitude suggests.
AI Governance Against the Four Tests
Run the framework against an AI governance investment ask, the typical mid-market scope of a 90-day discovery and classification programme followed by steady-state operation.
Is the spend countable? Yes. The deliverables are specific: a complete inventory of AI tools in active use, classification of each against EU AI Act tiers, mapping to GDPR processor status and DORA register where applicable, the documentation pipeline producing the framework-specific outputs. Each is a measurable artefact with a sign-off cadence.
Does it scale with regulatory exposure? Directly. The work scales with the number of AI tools in the inventory and the proportion classified as high-risk under Annex III, which itself scales with the firm's AI deployment surface. The spend tracks the obligation.
What does it displace? The substantive question. AI governance investment displaces, in most mid-market firms, three categories of existing spend: the FTE hours the DPO and security team currently spend maintaining incomplete registers in spreadsheets; the audit consultancy fees the firm pays in the run-up to inspections to produce the documentation that should be continuously available; and where the firm is paying for documentation platforms (OneTrust seats, GRC tools) that are under-utilised because the underlying inventory is incomplete. The net new spend, after displacement, is materially smaller than the headline ask.
The conversation that changes most CFOs' minds is not about the cost of the investment; it is about what the investment replaces. Most compliance fund requests land on the CFO's desk as a new expense with a justification number attached. The displacement question reframes it. What are we currently paying for that this replaces? Every single time, the answer includes a pre-inspection consultancy engagement that generates documentation the firm should be able to produce continuously, manual register maintenance that consumes disproportionate time from the DPO and the security team, and one or two documentation platform subscriptions that are underperforming because the inventory underneath them is incomplete. With those numbers on the table alongside the initial ask, the question in the room changes. It is no longer about whether the firm can afford the investment; it is about whether the firm can afford to keep running the spend it already has. - Ankur Arora, Co-Founder, Montro |
Is the investment auditable? Yes, and the audit is built in. The deliverable at day ninety is itself the evidence that the investment produced what was promised. The steady-state operation produces continuous documentation that the board can see at the quarterly cadence, an artefact that confirms the investment is working, every quarter.
Four passes. The investment ask sits in the same category as the other defensible compliance spend the firm makes.
Where AI Governance Displaces Existing Spend
The displacement question deserves a specific accounting because the displaced spend is often invisible in the budget conversation.
Audit consultancy. Most mid-market firms run a substantial pre-inspection consultancy engagement when supervisors signal an inquiry, or annually as part of audit preparation. The engagements run €50,000 to €200,000 each, and the work is often the consultancy producing the documentation the firm should have been able to produce continuously. AI governance investment, done well, reduces or eliminates this category of spend by making the documentation continuously available.
Manual register maintenance. The DPO and security team spend, in audits we have run, the equivalent of five to twelve weeks of distributed FTE per year on manual RoPA maintenance and ICT register upkeep that an automated inventory layer reduces by half to two-thirds. The recovered FTE moves from data work to judgement work, which is the higher-value use of the role, and the core promise of compliance automation in a mid-market compliance function.
Documentation platform underutilisation. Some mid-market firms are paying for documentation platforms (OneTrust, Securiti, BigID) and using a fraction of the capability. The platforms rely on the firm telling them what to document; the firm cannot tell them because the inventory is incomplete. AI governance investment, by closing the inventory gap, either makes the platform investment productive or makes the underutilised platform spend a candidate for review at renewal, a straightforward security governance conversation at the next renewal cycle.
When to Say No to Compliance Asks
The framework cuts both ways. The asks that should be declined typically fail one or more of the four tests, and recognising them is as important to sound enterprise risk management as approving the right ones.
The framework-without-output ask. "We need a privacy programme" without specific deliverables, sign-off cadence, or auditable artefacts. The work disappears into committee.
The vendor-led ask. The investment scoped around what a vendor sells rather than what the firm needs. The tell is when the deliverable list mirrors the vendor's product modules rather than the firm's obligation surface.
The duplicate ask. Compliance investment that does work the firm is already paying for elsewhere. The displacement test catches this when applied honestly.
The unscaled ask. Investment that does not scale with regulatory exposure or revenue, but with consultant time. The spend grows independently of the firm's actual obligation surface, which is the pattern that turns compliance into organisational drag.
The CFO's job is not to minimise compliance spend. It is to ensure the spend is structured, peer-aligned, and producing leverage. The four tests are the working version of that judgement.
Frequently Asked Questions
What is the typical cost of a 90-day AI governance programme for a mid-market firm?
Setup investment varies with firm size and existing compliance function maturity. For a mid-market firm in the 200 to 1,000 employee range, a 90-day discovery and classification programme typically runs between £30,000 and £80,000 all-in, covering the inventory exercise, EU AI Act classification, GDPR processor mapping, and the first documentation outputs. Ongoing annual operating cost after setup is materially lower. The relevant comparison is not the headline cost but the net cost after displacement of existing spend the programme replaces.
How do European mid-market firms typically fund AI governance investment?
Most mid-market AI governance investment comes from three existing budget lines rather than net new headcount: the compliance function's existing consultant and advisory spend, the IT function's tooling budget where documentation platforms are under-utilised, and the DPO's operating budget where manual register maintenance is consuming disproportionate FTE time. Framing the investment as a reallocation rather than an addition, and grounding it in compliance automation savings and displaced consultant spend - is usually more effective with boards than a greenfield ask.
What is the board's legal exposure if AI governance investment is declined and a regulatory finding follows?
Under NIS2 Article 20 and the EU AI Act's management body obligations, management-body accountability can extend to individual board members, not only to the legal entity. A board that declined a documented governance investment proposal and subsequently faced a supervisory finding has a materially harder position than one that approved it. The investment decision and its rationale should be recorded in board minutes regardless of outcome.
How should a CFO respond if the compliance team cannot quantify the ROI of governance spend?
Reframe the question. Governance spend is not an investment with a financial return, it is the cost of operating in a regulated market. The relevant metric is not ROI but cost efficiency: is the firm achieving its compliance obligations at a cost that is peer-aligned and producing auditable outputs? A compliance team that cannot articulate countable deliverables, a displacement argument, and an audit trail for the spend is presenting an under-specified ask, not an unquantifiable one.





