Skip to content

Compliance glossary

The terms this site and the platform use, defined the way a practitioner would define them to a new joiner. Where Vantage Point gives a term a specific shape, that follows the definition.

6 min read

Appetite band

A threshold range on the residual risk score that expresses how much risk a governing body has agreed to carry. Bands turn an adjective ("low appetite") into something testable: a residual score is Accepted, Within, Approaching or Outside the appetite, and the heatmap and reports colour it accordingly. Bands are set per entity, because two boards have not agreed to carry the same risk.

In Vantage Point. Vantage Point reads every residual score against the entity’s own bands: Accepted, Within, Approaching, Outside.

Audit trail

The record of who changed what, and when, across the compliance records a firm relies on: obligations, risks, controls, tests, actions, register entries. An audit trail is what lets a reviewer reconstruct a decision from the record alone, and it is the first thing a spreadsheet estate cannot provide.

In Vantage Point. In Vantage Point every record change is timestamped, attributed and exportable; the audit trail is one of the seven report types.

Board pack (committee pack)

The set of reports a compliance function puts in front of its board or compliance committee: risk position against appetite, monitoring progress and conclusions, open and overdue actions, obligations coverage, breaches and complaints, regulatory change, and the decisions being asked for. A pack assembled from live records reconciles with itself and can be questioned in the room.

Compliance monitoring programme (CMP, compliance monitoring plan)

The plan of tests a compliance function runs through the year to check that its controls operate and its obligations are met, with the sample, the evidence, the conclusion and the actions that follow recorded for each test. A CMP is first- and second-line assurance owned by the compliance function; internal audit is the independent third line.

In Vantage Point. Vantage Point’s CMP module links tests to controls and controls to obligations; conclusions are Pass, Pass with Minor Issues, Fail with Needs Review and Fail Critical, and a failing test raises a corrective action automatically.

Compliance management system (CMS)

The set of structures, processes and records through which an organisation identifies its compliance obligations, assesses the risk of not meeting them, puts controls in place, monitors that they operate, and reports and improves. ISO 37301 is the international standard describing one. Distinct from a GRC suite, which typically spans governance, enterprise risk and IT compliance across a large group.

Control

A policy, procedure or check that treats a compliance risk and satisfies one or more obligations. A control is rated on how well it is designed and how well it operates; the lower of the two is what it earns against residual risk. Controls that map to no obligation and no risk should be questioned; obligations with no control are the first gap to test.

In Vantage Point. Vantage Point rates controls Weak, Developing, Established or Strong on design and on operating effectiveness, with the lower rating driving residual risk.

Corrective action

An owned, dated piece of work raised to fix something a test, a breach, a finding or a regulatory change has surfaced. A corrective action carries a link back to what raised it and forward to what changed when it closed: the control rating, the residual risk, the next test outcome.

In Vantage Point. In Vantage Point a failing monitoring test raises a corrective action automatically; actions also cover monitoring and escalation, with statuses Draft, Active, Complete and Archived.

Delegated monitoring

Compliance monitoring performed for an entity by another firm, typically a fund administrator or trust company for the entities it administers, or an outsourced compliance officer for a client. Delegation does not remove the entity’s own accountability, so the monitoring must be evidenced per entity and overseen centrally.

DNFBP (designated non-financial businesses and professions)

The FATF term for businesses outside financial services that are supervised for anti-money-laundering purposes: accountants, lawyers, estate agents, trust and company service providers, dealers in high-value goods. In many jurisdictions these firms carry AML/CFT/CPF obligations without the prudential and conduct framework that applies to a bank or an investment business.

In Vantage Point. Vantage Point’s modular scope lets AML-supervised firms run the obligations, the risk assessment, the registers and an AML-scoped CMP without the wider machinery.

Entity-scoped

Data, access and reporting that are held and controlled per legal entity. In an entity-scoped system each regulated entity has its own registers, risk assessment, monitoring plan and audit trail, and a user sees only the entities they hold a role in. Consolidated views sit above the per-entity records rather than replacing them.

In Vantage Point. Vantage Point is entity-scoped throughout; access is role-based and entity-scoped, with SAML single sign-on on every plan.

Inherent risk

The exposure to a compliance risk before any controls are considered: how likely the thing is to happen and how bad it would be, given what the business is and does. Scored honestly, inherent risk is high for any activity that could go badly wrong regardless of how well the firm currently controls it.

In Vantage Point. Vantage Point scores inherent risk as likelihood times impact on a 4 by 4 grid, from 1 to 16.

MLRO (Money Laundering Reporting Officer)

The individual a regulated firm appoints to receive internal reports of suspicious activity, decide whether to report externally, and oversee the firm’s anti-money-laundering arrangements. The MLRO relies on the suspicious activity, PEP and sanctions registers, on the AML risk assessment and on the monitoring that tests the firm’s customer due diligence controls.

Obligation

A specific requirement a firm must meet, drawn from a source: a code of practice, a handbook, a law, or an internal policy the firm holds itself to. Obligations are the unit a compliance function maps risks and controls to, and the unit a regulatory change is assessed against.

In Vantage Point. Vantage Point’s regulatory library breaks each source into obligations mapped to the risk taxonomy and a starter set of controls; the Jersey Codes of Practice are pre-built, with Guernsey and the Isle of Man next on the roadmap.

Register

A structured record of events of one kind that a firm must keep and be able to evidence: breaches, complaints, conflicts of interest, gifts and entertainment, outsourcing arrangements, PEPs, sanctions outcomes, suspicious activity reports, declined business, data subject access requests. Each entry needs a status, an owner and a trail of who changed what.

In Vantage Point. Vantage Point ships fourteen pre-built registers with configurable, versioned fields, alerts and an audit trail on every entry, plus a form builder for any register a firm needs.

Regulatory change

An amendment to a source of obligations: a revised code, an updated handbook, a new law. Handling it well means identifying the specific obligations that changed, assessing what depends on them (risks, controls, tests, entities), raising an owned action against the effective date, and keeping the trail from the change to closure.

In Vantage Point. Vantage Point flags a change with a line-by-line diff, lists the obligations affected, and offers the action one click away, with approval recorded.

Residual risk

The compliance risk that remains after the controls the firm actually operates are taken into account: inherent risk less the deduction the controls earn. It is the figure a board’s appetite is set against, and it should move when a monitoring test finds a control is not operating.

In Vantage Point. Vantage Point shows residual risk to one decimal place, driven by the lower of each control’s design and operating rating.

TCSP (trust and company service provider)

A firm that forms, administers or provides directors, trustees, registered offices or nominee services to companies, trusts and other structures for clients. TCSPs run compliance for their own licence and for the entities they administer, which is why per-entity records and central oversight matter to them.

Thematic review

A regulator’s examination of one topic across a number of firms, for example complaints handling or customer due diligence, usually followed by published findings and, for individual firms, requirements to remediate. Firms with a live monitoring programme and per-obligation coverage tend to answer a thematic review from their records rather than from a project.