Shao Hong built a career defined by cross-border financial leadership, most recently serving as Assurance Partner and Head of China Assurance Practice at PwC Australia from 2018 to 2025. Based in Sydney, Shao Hong has spent more than two decades guiding IPO readiness engagements, financial due diligence, and complex cross-border transactions between Australia and China, including work on the Industrial and Commercial Bank of China listing and cross-border engagements on the Hong Kong Stock Exchange. Earlier in her career, she spent more than a decade with EY in Australia, China, and the United States, rising to Assurance Director. A former National Treasurer of the Australia China Business Council, she holds dual accreditation through Chartered Accountants Australia and New Zealand and the Chinese Institute of Certified Public Accountants. That same attention to governance and accountability underlies why organizations must build a strong culture of regulatory compliance.
In business, compliance culture is a set of shared values, behaviors, and ethical standards that coalesce to define business operations. By effectively establishing a culture of compliance, leaders can ensure that every employee adheres to expectations each day.
Compliance failures typically do not begin with written policy, but rather as behavioral lapses, especially when they come from leadership. Examples include a manager who eschews reporting protocols or makes a habit of cutting procedural corners. These attitudes trickle down, resulting in employees who engage in similar behavior or stop raising concerns about violations.
Role modeling is critical when it comes to enforcing a strong compliance culture. Board members and senior leaders need to demonstrate a dedication to compliance through both their actions and their support for compliance programs and reporting. Leaders must introduce other employees to important compliance topics early on during their tenures, ideally using data-driven, scenario-based approaches that help employees understand what ethical business practices look like in action.
Perhaps most importantly, compliance processes need to be clear and easy to follow. This requires compliant leaders to develop effective frameworks for complying with regulations while still accomplishing business objectives.
Compliance structures must also account for governance and enterprise risk. Feedback loops, improvement cycles that enable compliance framework evolution, and platforms that support cross-functional compliance partnerships are among the other important factors to consider. In short, compliance must function as a foundational, all-encompassing aspect of an organization’s operations.
With this in mind, chief compliance officers need to take part in the development of different employee-driven programs, such as leadership development initiatives and new employee orientation.
Failure to establish and maintain a healthy compliance framework can lead to harmful compliance culture gaps. A compliance culture gap involves a notable disconnect between an organization’s stated rules, regulations, and ethical standards and how members of staff actually execute their daily responsibilities. “Unwritten norms” and “unspoken rules” rank among the key contributors to compliance culture gaps.
Employees may feel intense pressure to meet unrealistic goals, which can lead workers to ignore ethical standards and, in extreme cases, break the law.
Compliance gaps are similar to compliance risks and compliance violations. Compliance risk describes the potential outcome of allowing a compliance gap to persist, while a compliance violation occurs after a regulator takes note of a gap and penalizes the organization.
Common examples of compliance gaps include employees using third-party messaging apps for sensitive business communications and insufficient workflow supervision (such as the monitoring of only a single channel even though workers use multiple platforms). The Securities and Exchange Commission and the Financial Industry Regulatory Authority are among the organizations responsible for penalizing these compliance gaps.
Other gaps and violations are industry-specific, such as Health Insurance Portability and Accountability Act violations in the medical industry and Freedom of Information Act violations in government.
Organizations must establish a schedule for compliance gap analyses. These initiatives may cover all frameworks and internal policies, or apply a smaller scope, such as focusing only on a company’s adherence to state-level requirements or industry standards. After identifying and categorizing gaps by severity, type, and regulatory exposure, leaders can prioritize risk and take steps to remediate gaps before they lead to costly violations.
About Shao Hong
Shao Hong is a Sydney-based financial executive who served as Assurance Partner and Head of China Assurance Practice at PwC Australia from 2018 to 2025. With more than two decades of experience, she has led IPO readiness engagements, cross-border financial reporting, and audit oversight across Australia, China, Hong Kong, and the United States. A former National Treasurer of the Australia China Business Council, she holds dual professional qualifications through CA ANZ and CICPA.
Lynn Martelli is an editor at Readability. She received her MFA in Creative Writing from Antioch University and has worked as an editor for over 10 years. Lynn has edited a wide variety of books, including fiction, non-fiction, memoirs, and more. In her free time, Lynn enjoys reading, writing, and spending time with her family and friends.


