The Regulatory Blind Spot: What Interim CEOs Find When They Open the Book

by Nicolas Henckes, Founder & CEO

Most interim CEO mandates begin with a conversation about strategy: growth, succession, a merger to integrate, a crisis to stabilise. Regulation rarely comes up in the first call. By week three, it usually does, not because anyone raised it, but because it surfaces on its own, in an employment contract nobody re-read, a personal data file nobody documented, or a founder's signature on an invention nobody formally assigned to the company.

This is not negligence in the way the word is usually meant. Luxembourg's SMEs and family businesses were built on relationships, speed and trust, not on compliance departments. For twenty or thirty years, that worked. The gap only becomes visible at the moment of transition, which is precisely when an interim CEO is in the room.

Why the gap is structural, not accidental

An SME with fifteen or fifty employees does not have a general counsel. It has a founder who signed everything personally, an accountant who handles payroll, and a fiduciaire that files what the law requires and nothing more. Most of the time, regulation gets addressed reactively, when a client demands a clause or an inspector asks a question. Nobody owns it as a standing responsibility.

During a stable period, this is a manageable risk. During a transition such as a succession, an M&A integration, a subsidiary launch, or a leadership change, it stops being manageable, because transitions are exactly when regulatory exposure gets tested: new shareholders read the contracts, new auditors ask for the documentation, a buyer's due diligence team goes through everything with no incentive to be generous.

In our experience, four areas surface with near total consistency. None of them are exotic. All of them are neglected in a predictable, structural way.

Four blind spots we see in almost every mission

1. Employment contracts that were never updated for the last decade of labour law. Over the past three years alone, Luxembourg has legislated a right to disconnect (loi du 28 juin 2023), mandatory internal whistleblowing channels for any private employer above fifty workers (Law of 16 May 2023, transposing EU directive 2019/1937), and it continues to enforce a long-standing but often neglected obligation to keep a daily working-time register for every employee (Code du travail, article L.211-29, the same principle the CJEU generalised across the EU in its 2019 CCOO ruling). None of this is new law dressed up as new risk. What is new is enforcement. The right to disconnect carried a three-year grace period before its administrative sanctions took effect, a window most SMEs treated as permission to wait rather than as a countdown, and that window has just closed. An SME with sixty employees and no whistleblowing channel, no disconnection policy, and a working-time register that stopped being kept the moment hybrid work started is not an unusual case. It is close to the median.

2. Data protection that was set up once and never revisited. The GDPR is not new, but SME compliance with it is frequently frozen at whatever state it reached around 2018: a privacy policy on the website, a register that was never updated, HR files with no retention logic. A transition is when this gets tested: a new HR system, a new shareholder's due diligence, an acquirer's data room. The CNPD is Luxembourg's supervisory authority for the GDPR, and it has just been designated the national authority for the AI Act as well, which is the third blind spot.

3. AI governance, arriving faster than most SMEs expect. The AI Act's obligation on AI literacy (ensuring staff have a sufficient understanding of the AI tools they deploy) has applied since February 2025, with no size threshold and no exemption for SMEs. High-risk system obligations reach full applicability in August 2026, with a Digital Omnibus proposal working its way through the EU institutions to soften timelines and extend SME simplifications to mid-caps. None of this is theoretical for a Luxembourg SME already running an AI-based scheduling tool, a chatbot, or a recommendation engine. The mistake is not ignorance of the AI Act. It is the assumption that "we are too small for this to apply to us", a category Luxembourg's own regulators, through the CNPD's January 2026 conference on the subject, were explicit is not true.

4. Intellectual property and trade secrets that were never formally secured. Luxembourg copyright law requires the assignment of rights to be proven in writing and interprets it restrictively in favour of the creator, meaning a founder who built the product, the brand, or the code personally may not have actually transferred those rights to the company, even after years of treating them as company assets. Since the 2019 transposition of the EU trade secrets directive, Luxembourg also gives businesses a genuine civil remedy against the illicit use or disclosure of undisclosed know-how, but only for information that was actually protected as secret. A folder open to the whole office does not qualify. Neither does a departing employee's laptop that nobody thought to lock down.

Why this stops being abstract

Two things turn a neglected compliance file into a real cost.

The first is direct sanction. The ITM can fine an employer between EUR 251 and EUR 25,000 per breach on the disconnection rules alone, weighted by the gravity of the failure and how the employer responds once flagged and a whistleblowing channel that was never set up, or a working-time register that does not exist, is exactly the kind of gap an inspection surfaces without much effort. None of this requires a disgruntled employee to trigger it. An ITM control can be routine. ITM and CNPD inspections do generally allow a company acting in good faith some room to correct a gap before sanctioning it. That grace only exists once the gap is visible and being fixed - it does not exist retroactively once a buyer's due diligence has already priced it into an offer.

The second, and often larger, cost shows up later: at the moment of a sale. A buyer's due diligence team does not treat labour and data compliance as a formality. It treats every uncorrected gap as a specific, quantifiable risk, and prices it accordingly: an escrow, a price adjustment, a warranty carved out and reserved for the day after closing. A backlog that looked manageable when the founder was still running the company becomes a negotiating lever in the hands of a buyer who has no reason to be generous about it. In our experience, this is where the cost of neglect is felt most sharply, not in a fine paid today, but in a valuation quietly reduced months later, for reasons the seller only fully understands when the data room report lands on the table.

The opposite mistake is also possible

None of this is an argument for turning an SME into a compliance department overnight. A founder-run business with five employees does not need the governance architecture of a listed company, and an interim CEO who arrives with a binder of new policies before understanding the business has misread the mission. The goal is not maximal compliance. It is closing the specific gaps that would actually hurt the company if an inspector, a regulator, or a buyer's due diligence team tested them and knowing the difference between the two.

Why this belongs in the first weeks, not the exit interview

We do not spend months on analysis. Within the first weeks of a mandate, a structured assessment should already be mapping where the company actually stands on these four points, not as a legal audit for its own sake, but because each one is a source of financial and reputational exposure that compounds the longer it goes unaddressed, and a discount waiting to be applied the day a buyer looks closely. Updating an employment framework, tidying a GDPR register, or formally assigning IP rights is straightforward when caught early. It is a different, much harder conversation when caught during a due diligence process or an ITM inspection.

An interim CEO who only manages the P&L and leaves the regulatory exposure exactly as they found it has not finished the job.

______________

By Nicolas Henckes, Founder & CEO of Kitsune Advisory. Kitsune Advisory provides interim and fractional CEO services to companies in Luxembourg, France, Belgium, Germany, and Switzerland.

Next
Next

When the Larger Company Comes Knocking