Governance, risk and compliance (GRC) and enterprise risk management (ERM) groups are tax-adjacent functions that warrant close attention. Although corporate tax departments typically operate outside of GRC and ERM programs, the functions share similar mandates and pressures. In some organizations, tax leaders and GRC/ERM leaders both report into the CFO.
Plus, tax decisions affect financial outcomes and reporting, compliance obligations, audit readiness, and business risk. Tax decisions, like financial reporting decisions, must be explainable and defensible if questions arise later. As a result, tax and other risk functions share a need to approach AI differently – by generating measurable value from AI tools and functionality without introducing unnecessary risk.
So it stands to reason that KPMG’s rundown of 2026 midyear regulatory challenges overlaps with a handful of current global tax compliance challenges. That said, the regulatory ecosystem that the report examines does not specifically address indirect tax compliance.
Three Areas of Common Ground
Even so, many of the themes explored in the report have clear relevance for tax leaders. In particular, the report highlights three areas of common ground:
- Regulatory divergence: As many federal agencies loosen regulations and embrace a lighter supervisory touch, some states are moving in the opposite direction, particularly on rules concerning AI safety, data center licensing and environmental rules. A similar dynamic is playing out on a global scale where the current U.S. shift to deregulation is countered by new, more stringent AI, data protection, and third-party risk management regulations in the European Union and other regions. Indirect tax groups within global enterprises are also contending with regulatory fragmentation and increasing global tax compliance requirements as they strive to comply with a complex jumble of country-specific e-invoicing and digital reporting rules.
- Continuous compliance: U.S. and global regulatory bodies do not diverge on all matters. Expectations for timely self-reporting and continuous oversight of operational resilience are widespread across many jurisdictions. Regulatory compliance is no longer just a periodic event. The same holds for tax compliance, which is becoming a continuous discipline due to the adoption of e-invoicing, real-time reporting and other digital tax reporting rules as well as the growing push for B2B payments efficiency.
- Explainability: The need for “explainability” is repeated three times in KPMG’s analysis of 10 regulatory challenges; the report also points to a related need for “data lineage and controls.” The reason for this emphasis is clear: regulators want proof. Again, so do tax jurisdictions. This makes it imperative for enterprises to prove and defend tax determination and exemption decisions. That proof and defensibility requires managing tax compliance from the initial tax determination through audit defense, even as regulations, business models and risk profiles change.
Continuous Compliance Required
These areas of shared footing can help initiate conversations among finance, tax, IT, GRC and ERM groups regarding objectives, challenges and leading practices.
The KPMG report concludes that managing the regulatory stack in a balanced way now qualifies as a strategic operating imperative. I would argue that this must also include determining tax accurately in real time, proving the logic and data behind each tax determination, and managing indirect tax compliance as a continuous process from determination through audit defense.
Disclaimer
Please remember that the Vertex blog provides information for educational purposes, not specific tax or legal advice. Always consult a qualified tax or legal advisor before taking any action based on this information. The views and opinions expressed in the Vertex blog are those of the authors and do not necessarily reflect the official policy, position, or opinion of Vertex, Inc.