It is widely accepted that compliance is the final destination of any organization where the decision made would be evaluated for compliance with the law after they have been made. But it is the people who revolutionize their industries who understand that there is much more value added when governance becomes an integral part of the journey, and not only the destination. This principle has been embodied in the successful career of Prem Kumar, Head of Ethics & Compliance, Southeast Asia and India, Takeda Pharmaceuticals.
Given that he has dealt with many challenging cases, Kumar knows how to succeed by finding a balance between business interests and integrity. But there is not only practical skill in his professional background but also wisdom, courage, and people management skills necessary to make the way out of ambiguity and form corporate culture. Nowadays, he is one of those visionary people who redefine the notion of Ethics and Compliance.
Discover how Prem Kumar is redefining Ethics and Compliance as a strategic force for sustainable business growth and lasting trust.
From Gatekeeper to Growth Enabler
Ask Kumar how GRC has changed over the course of his career, and he will tell you the old model is dead. For decades, governance functions operated defensively, brought in after decisions were already made to check them against the rulebook. He believes that approach no longer serves organizations that want to outperform. The businesses winning today embed GRC from the start, present at market-entry decisions, product launches, mergers and acquisitions, and technology rollouts, rather than auditing them after the fact.
Kumar frames this evolution along three distinct lines. First, governance has become a trust multiplier. In an age when regulators, investors, and consumers scrutinize corporate behavior more closely than ever, strong governance functions as a genuine competitive differentiator rather than just a defensive shield. Second, mature GRC accelerates decisions rather than slowing them down. Teams that have already mapped the risk landscape do not need to reinvent a risk assessment for every new initiative, which lets them move faster, not slower. Third, GRC now serves as an early-warning system, using data and cross-functional visibility to catch regulatory, reputational, and cyber risks before they escalate into crises.
“Organizations that internalize this shift don’t ask how we stay compliant. Instead, they ask how strong governance helps us grow responsibly,” he explains. It is a subtle reframe, but one that changes everything about how a compliance function is resourced, staffed, and heard inside a company.
The Milestone That Defined a Career
Every leader has a moment they return to again when reflecting on their own growth. For Kumar, that moment arrived after nearly a decade in consulting, where he advised corporations on white-collar crime investigations and compliance matters from the outside looking in. Stepping into an in-house compliance role means leading the function for a leading pharmaceutical organization in India which changed the equation entirely.
What followed was a full-scale compliance transformation: building a function from the ground up, expanding his remit to a global level, navigating significant investigations, and embedding a unified compliance framework across international markets. He admits that the outcome mattered but what defined the experience was what it demanded of him as a leader, holding a firm line on principle while still bringing skeptical stakeholders along, delivering difficult truths upward without losing leadership’s trust, and making sound decisions under real-time pressure.
That period convinced him that technical knowledge of regulation is table stake in this field. The real differentiator, he says, is judgment, knowing when to escalate, when to coach, when to hold firm, and when to find a pragmatic middle path that protects both an organization’s integrity and its commercial interests.
“Technical expertise in regulation is table stake. The real differentiator is judgment knowing when to escalate, when to coach, when to hold firm, and when to find a pragmatic middle path that protects both the organization and its integrity,” he reflects. It remains the story he returns to most often when mentoring others, precisely because it touches nearly every dimension the role demands.
Building Resilience in an Age of Regulatory Multiplication
Regulatory complexity, in Kumar’s assessment, is not simply growing it is multiplying across multiple dimensions at once. Data privacy laws such as India’s Digital Personal Data Protection Act, evolving pharmaceutical marketing codes like the Uniform Code of Pharmaceutical Marketing Practices, cross-border sanctions regimes, and emerging AI governance frameworks are all developing in parallel, often with little harmonization between jurisdictions.
To build resilience against that kind of complexity, he advocates four deliberate strategies. Organizations need dynamic risk-sensing rather than static, once-a-year risk assessments since regulatory landscapes now shift too fast for annual reviews to keep pace. They need genuine cross-functional integration, giving legal compliance, IT security, and business units shared visibility into risk instead of siloed reporting lines that create blind spots.
They need adaptable, principles-based frameworks rather than rigid rulebooks that require a complete rebuild every time a new regulation appears. And ultimately, resilience depends on people building a broad bench of professionals who understand both the letter of a regulation and the spirit behind it, so no organization depends on a single expert to navigate a crisis.
Where Innovation Meets Accountability
Kumar rejects the idea that innovation and accountability naturally pull against each other. “The tension between innovation and accountability is often overstated. In practice, the two reinforce each other when governance is designed thoughtfully,” he says. His approach starts by bringing compliance into the room during ideation, not at the launch stage. When compliance professionals help shape a new product, market entry, or technology deployment from day one, the initiative can be innovative and compliant simultaneously, rather than facing a last-minute veto.
He also champions proportionate governance. Not every innovation carries the same risk profile, and applying the same scrutiny to a low-risk pilot as to a high-stakes market launch only slows everything down without adding real protection. Tiered risk frameworks that scale oversight to the actual level of risk let innovation move at the pace it needs.
Above all, he tries to reposition compliance internally not as the department that stops things, but as the team that helps good ideas survive contact with reality, regulators, and public scrutiny, so they scale sustainably instead of being pulled back later.
Leading Through Uncertainty
Every career includes moments that test a leader’s nerve, and Kumar points to one large-scale investigation, conducted with incomplete information, as among the most demanding of his own. The uncertainty was not just about missing facts — it was about the organizational pressure of delivering difficult news to senior stakeholders while the full picture was still coming into focus.
“Resilience in leadership isn’t about having all the answers. It’s about maintaining clarity of principle when the details are still uncertain,” he says. He learned to separate what he knew for certain from what he was inferring, to communicate that distinction transparently to leadership rather than projecting false confidence, and to make provisional decisions that could be adjusted as more information emerged, instead of freezing while waiting for perfect clarity. Just as important, he learned the value of building relationships with stakeholders long before a crisis hits “trust built in calm periods is what allows honest, fast conversations during turbulent times,” he adds.
Technology Reshaping GRC’s Future
Kumar is candid that a handful of emerging trends will reshape GRC in ways that go well beyond incremental change. Artificial intelligence is already enabling continuous monitoring, shifting compliance away from periodic, sample-based audits toward real-time surveillance of transactions, communications, and third-party interactions, dramatically shrinking the gap between when a risk emerges and when it gets caught.
AI governance itself, he notes, is becoming a discipline within GRC. As organizations deploy AI in decision-making, compliance functions must build frameworks to govern the systems themselves, covering explainability, bias, and data provenance not just the humans operating them. Data privacy regulation continues to intensify globally, with frameworks like India’s DPDP Act signaling that data governance and information security are becoming inseparable from core compliance work rather than a specialized side function.
Cybersecurity and compliance, meanwhile, are converging fast: breaches are increasingly treated as governance failures rather than purely technical incidents, meaning compliance leaders need genuine fluency in cyber risk. Finally, Kumar expects regulatory technology to mature significantly, giving mid-sized organizations access to sophisticated monitoring tools once reserved for the largest enterprises alone.
Culture, Mentorship, and What Comes Next
Culture change in compliance, Kumar insists, rarely comes from a policy document. It comes from consistent, visible leadership behavior sustained over time. Employees need to feel that raising a concern will be met with curiosity rather than punishment, and that belief only takes root when leaders demonstrate it repeatedly rather than stating it once in a training deck. He also prioritizes clear, plain-language communication over dense policy text, believing that memorable principles change behavior far more effectively than legal jargon ever could.
According to him recognition matters as much as enforcement. Publicly acknowledging employees who raise concerns early, or who make the harder, more compliant choice, signals that ethics is genuinely valued rather than merely tolerated. Leading by visible example carries even more weight, when leadership walks away from a profitable but questionable deal, or delays a launch to fix a compliance gap, that action communicates more about an organization’s values than any number of mandatory trainings. He also embeds compliance champions within business units, treating ethics as a shared responsibility rather than something owned and imposed solely by a central function.
Exceptional GRC leaders, in his assessment, combine deep technical grounding in regulation with genuine commercial curiosity about how a business operates. They translate complex requirements into plain, actionable guidance, and they have the courage to deliver unwelcome news to senior leadership without damaging the relationship. Perhaps most importantly, they pair firmness on principle with flexibility on approach, recognizing that the right answer to a risk question is rarely a simple yes or no.
To empower the next generation, he believes organizations must give emerging compliance professionals real exposure to business decision-making rather than confining them to policy drafting, rotating them through commercial functions, creating psychologically safe spaces for junior staff to challenge senior leaders on ethics questions, and investing early in emerging skills like data analytics, AI governance, and cybersecurity.
A Legacy Built on Trust
If Kumar could choose one legacy to leave behind, it would be this: that the organizations and teams he worked with came to see compliance not as a constraint bolted onto the business, but as a genuine source of competitive strength, the thing that let them move fast with confidence because they had already thought through the risks. He hopes, too, to be remembered for the people he mentored along the way, having helped build a generation of compliance professionals who lead with both rigor and empathy, understanding that this work, at its core, protects people rather than just processes.
His advice to those entering the field is simple, if not always easy to practice. “Build your credibility patiently. It’s the only real currency you have in this field, and it takes years to build and moments to lose,” he advises. Learn the business as deeply as the regulations since influence comes from being seen as a partner rather than a gatekeeper. Stay curious about adjacent disciplines data privacy, cybersecurity, AI governance because the boundaries of this field are expanding quickly. And never lose sight of why the rules exist in the first place: not for their own sake, but to protect the people and institutions that depend on an organization doing the right thing, even when no one is watching.
He adds one final thought, unprompted, about where the field is headed. The future of GRC leadership, he believes, will depend heavily on the ability to build trust across borders and cultures. As businesses operate more globally, the compliance leaders who thrive will be those who can adapt frameworks to local context without diluting global standards, and who build genuine relationships with regulators and stakeholders rather than merely reacting to them. That cross-cultural fluency, he suggests, will define the next generation of visionary GRC leadership as much as any single regulation or technology ever could.











