The Hidden Cost of Compliance: Resourcing It Properly
This blog was originally posted on 3nd October, 2026. Further regulatory developments may have occurred after publication. To keep up-to-date with the latest compliance news, sign up to our newsletter.
THIS BLOG WAS WRITTEN BY THE ADHERENT MARKETING TEAM TO INFORM AND ENGAGE. HOWEVER, COMPLEX REGULATORY QUESTIONS REQUIRE SPECIALIST KNOWLEDGE. TO GET ACCURATE, EXPERT ANSWERS, PLEASE CLICK ASK AN EXPERT.
Quick Answer
The true cost of meeting a new product requirement is a four-part estimate: process change, money, time, and people. Most teams price only the visible items, meaning registration fees, testing, and external advice, and miss the larger costs that sit in other teams’ budgets. Start with process. Until you know which processes change, every financial number is a guess. Then price each change as one-off and recurring, map the dependency chain that sets the calendar, and name the teams whose time the work will actually consume.
Table of Contents
- Why is compliance resourcing consistently underestimated?
- Which processes have to change to meet a new requirement?
- How do you estimate the financial cost of compliance change?
- How long does compliance change actually take?
- Which teams and people need to be involved, and when?
- Frequently Asked Questions
Key takeaways
- Compliance cost is a four-part estimate: process change, money, time, and people. Leave any part out and the requirement looks cheap until it is underway.
- Underestimation is structural, not careless. The visible costs are easy to price. The invisible ones sit in engineering, sourcing, and quality budgets and never get counted against the requirement that caused them.
- Start with process, not money. Which processes change determines every other number.
- Time is driven by dependency chains, not effort hours. Supplier response cycles, lab queues, and tooling changes set the calendar, and they usually run in series.
- People cost is mostly other people’s time. Name the teams and the point in the sequence each is needed, or the plan assumes capacity that does not exist.
- Write down the assumption behind every number. A defensible estimate is one where a reviewer can see what would have to be true for it to hold.
Why is compliance resourcing consistently underestimated?
Compliance resourcing is underestimated because the costs that are easy to see are a minority of the total. Registration fees, testing, and external counsel land in the compliance budget and get priced. Specification rework, supplier data collection, evidence retention, and retraining sit in other teams’ budgets and rarely get attributed back to the requirement that caused them.
That split is the single biggest source of error. A requirement that costs the compliance function very little can consume months of engineering and sourcing time, and none of it appears in the number presented to leadership.
Three other dynamics make it worse.
Applicability ambiguity inflates scope after the fact. Teams size the work against the regulation text, then rescope once guidance, harmonised standards, or enforcement practice clarify what is actually required. The second number is almost always larger than the first.
Volume acts as a multiplier that first estimates ignore. A requirement affecting one product and the same requirement affecting a portfolio are the same regulation and completely different projects. Adherent’s own figures put the average at 1,002 regulations for a new product entering a single market, which is the scale that turns a per-product estimate into a programme.
For wider context on where compliance budgets and workloads actually sit, Adherent’s benchmarks for chief compliance officers is a useful reference point when challenging a first estimate.
Then there is the optimism of the first estimate. It is usually produced by the person who read the regulation, before anyone who owns an affected process has seen it. Once a launch date or market-entry commitment is public, the estimate tends to get bent to fit the date rather than the date adjusted to fit the estimate.
The fix is not more caution. It is a four-part estimate with written assumptions.
Which processes have to change to meet a new requirement?
Start with process. A new requirement typically touches six areas: product design and specification, sourcing and supplier data, testing and verification, labelling and packaging, technical documentation and evidence, and commercial or market release.
For each area, ask the owner one question: does this change what you produce, or only how you record it? That distinction separates three change types that cost very differently. A new activity is expensive. A changed activity is moderate. Changed record-keeping only is usually cheap, provided the record can be produced from something that already exists.
Upstream data dependencies are the most commonly missed process change. Substance declarations, material composition data, and supplier attestations all have to be requested, chased, validated, and stored. That work is invisible at scoping time and dominant during delivery.
Downstream dependencies get missed nearly as often: existing stock, catalogues, distributor documentation, and any market-facing claim that the change makes inaccurate.
Cross-market compounding cuts both ways. The same requirement may already be satisfied in one market through an existing control and force genuine change in another, so a single global number hides the real distribution.
The EU Batteries Regulation is a useful worked example, because it touches nearly all six areas at once. Adherent’s analysis of Regulation 2023/1542 sets out how due diligence, labelling, and documentation obligations arrive together rather than in sequence.
The output of this step is the line-item list for the financial estimate. Nothing gets a price until it is on this list.
How do you estimate the financial cost of compliance change?
Price each process change as a line item, then split it into one-off and recurring. One-off covers testing, tooling, artwork, system configuration, and external advice. Recurring covers renewals, re-testing, supplier data refresh, reporting cycles, and keeping audit evidence current.
The categories teams forget are consistent: internal engineering hours, supplier onboarding and data chasing, translation, PLM and system configuration, evidence storage and retrieval, and training.
Recurring cost is usually the real number. Plenty of requirements are cheap to meet once and expensive to keep meeting, and an estimate that shows only the first year makes the wrong option look attractive. Evidence upkeep is the clearest case. In Thrv Research’s State of the Industry Report, drawn from more than 500 respondents, 62% of compliance leaders said they struggle to provide evidence of compliance to external stakeholders, which is a recurring cost showing up as a recurring problem. Building an evidence system that holds up is what moves that line from recurring firefighting to recurring maintenance.
Price uncertainty honestly. A range plus a named contingency tied to a specific unresolved question is defensible. A flat percentage buffer with no stated cause is not, and it is the first thing a finance partner will challenge.
Always carry the comparison case. The cost of not doing it includes market access loss, delayed launch, rework, and enforcement exposure. The real cost of non-compliance covers how market-access risk compounds when that comparison is left out.
Sometimes the honest answer is that the market does not justify the spend. That is a legitimate output of this estimate, not a failure of it. Framed the other way, a well-costed requirement is also how compliance stops reading as pure overhead, which is the argument in from cost center to competitive edge.
How long does compliance change actually take?
Timelines are set by dependency chains, not effort hours. Three external clocks usually drive the calendar: supplier response cycles, laboratory or certification queues, and tooling or artwork lead times. Because these often run in series, a requirement needing a few weeks of internal work can still take several quarters end to end.
Map the critical path rather than the task list. The question is not how much work there is, it is which steps cannot start until another finishes.
Internal clocks get ignored more often than external ones: approval gates, change-control boards, release cycles, translation, and legal review. None are long individually. Together they routinely add a quarter.
Parallelising has hard limits. Data collection has to precede assessment, assessment precedes design change, and design change precedes verification. You can overlap the edges, but the sequence is real.
Plan backwards from the compliance date, and include the buffer needed for existing stock and product already in market. A date that works for new production and ignores inventory is not a plan.
There is a simple honesty test for any quoted date: name the single longest dependency, and say whether you control it. If the answer is a supplier or a lab, the date is a forecast rather than a commitment.
The front end of this chain is where automation changes the arithmetic. Assessing 200 key regulations manually with a general-purpose LLM takes four to six months. With C2P, six to eight weeks. On the Adherent platform, under ten minutes. That does not shorten a lab queue, but it removes months from the step that gates everything downstream.
Which teams and people need to be involved, and when?
Compliance change is mostly other people’s time. Expect to involve product design and engineering, sourcing and supplier quality, testing and quality assurance, packaging and labelling, legal, the PLM or IT owner, and the commercial team, each at a specific point in the sequence rather than all at once.
Compliance owns the requirement and the evidence. It does not do every task, and an estimate that assumes otherwise will understate elapsed time while overstating the compliance headcount ask.
The capacity problem is the one that quietly breaks plans. If a team is needed at a given stage and has no allocated hours for it, the plan is assuming free capacity that does not exist. Naming the hours makes the assumption visible, which is the point.
Separate who must be told from who must decide. Escalation points and sign-off points are different, and conflating them is why approvals stall.
This is also where a platform changes the people cost rather than the licence cost. Adherent’s agentic AI platform handles regulatory monitoring, applicability assessment, and requirement identification continuously, which moves specialist time from research and triage toward interpretation and decisions. Given Adherent tracks an average of 217 regulatory changes per month globally, the triage load is the part that does not scale by adding people. Compliance monitoring covers how that intake is structured so it produces a shortlist rather than a queue.
FAQ
- How long does compliance implementation usually take?
It depends on the longest external dependency, not on internal effort. Where supplier data collection, lab testing, or tooling changes are involved, several quarters is common even when internal work is a few weeks. Requirements that only change record-keeping can land inside one release cycle. - What does a single requirement cost to meet?
There is no useful average, because the same regulation costs very differently across one product and a portfolio. The workable answer is a line-item estimate per affected process, split into one-off and recurring, with the owning budget named for each line. - Who owns compliance change?
Compliance owns the requirement and the evidence. Design, sourcing, quality, and packaging own the changes themselves. That split is why the people estimate matters more than the headcount ask. - How do you estimate compliance headcount?
Estimate the work first, by stage and by team, then see what it implies. Headcount asks built from workload have a much better survival rate in planning conversations than asks built from a general sense of pressure. - What is the most commonly missed cost?
Supplier data collection, followed by evidence retention. Both are recurring, both sit outside the compliance budget, and neither appears in the regulation text.

See Adherent in Action
Discover how agentic AI is reshaping product compliance for global enterprises.
