Skip to content

Regulatory change without re-reading the Code

The regulator publishes an amended handbook. Somebody prints both versions and reads them side by side. There is a better way to run that afternoon.

By Vantage Point · Published 17 August 20265 min read

The afternoon everyone recognises

An amended handbook lands. Someone prints the old and new versions and reads them side by side, highlighter in hand, hoping nothing is missed. The findings go into an email, the email into a folder, and three months later nobody can say with confidence which procedures were updated because of it.

The problem is not diligence. It is that the change is being assessed against a document rather than against a structure. If the obligations were already broken out by source and mapped to risks and controls, the same afternoon looks very different.

Track at source level

Start by knowing exactly which sources apply: which codes of practice, which handbook, which laws, which internal policies. Each source is broken into obligations, and each obligation is mapped to the risks it gives rise to and the controls that satisfy it. That structure is the regulatory library, and it is what a regulatory change is assessed against.

When a source is amended, the question is no longer “what changed in this document?” but “which of our obligations changed, and what depends on them?”.

See the diff, not the document

The most useful thing a system can do with a regulatory change is show the difference: the old wording beside the new, obligation by obligation, with the unchanged sections out of the way. A line-by-line diff turns a re-read into a review, and it means the compliance officer’s judgement is spent on what changed rather than on finding it.

From change to obligation to action

Each changed obligation should show what hangs off it: the risks it gives rise to, the controls that satisfy it, the tests that check those controls, the entities it applies to. That is the impact assessment, and it comes from the map rather than from memory.

Then raise the action. One owned corrective action per change that needs work (a policy updated, a control redesigned, a risk rescored, training delivered), with a deadline set against the regulator’s effective date, linked back to the change that raised it. Approval of the updated obligation wording is a separate, recorded step, so nothing changes in the library silently.

Across a client book

For a fund administrator or an outsourced compliance officer, one regulatory change touches many entities (see Running compliance for a client book). The review is done once; the action is raised per entity where it applies, so each client board sees its own status and the consolidated view shows which entities have closed it. Nothing is rekeyed and no entity is missed because it was not on the list that day.

The trail the regulator wants

On a visit the question is rarely “did you know about the change?”. It is “show me how you assessed it, what you decided, who did the work and when it was finished”. A trail from the source amendment, through the affected obligations, to the actions and their closure, answers that from the system. An email in a folder does not.

Internal policies belong in the same library

Firms hold themselves to more than the regulator requires: group standards, internal policies, voluntary codes. Treat those as obligations too, in the same library, mapped to the same risks and controls. The coverage picture is then complete, and a change to an internal policy is handled with the same discipline as a change to the handbook.

How Vantage Point runs it

Vantage Point’s regulatory library ships pre-built with the Jersey Codes of Practice (Trust Company Business, Investment Business, Fund Services, Banking) and the AML/CFT/CPF Handbook, mapped to the risk taxonomy and a starter set of controls; Guernsey and the Isle of Man are next on the library roadmap, with further jurisdictions to follow. When a rule changes, the system flags it with a line-by-line diff, lists the obligations affected, and the action to deal with it is one click away, with approval recorded and every affected entity alerted. Add your own obligations for internal policies and non-regulatory standards. See the regulatory library.

Questions

How should a compliance function track regulatory change?
At source level: know which handbooks, codes and laws apply, keep each broken into obligations, and when a source is amended, identify the specific obligations that changed. Then raise an owned action for each change that needs a policy, procedure, control or risk updated, and record when it closed.
What is a regulatory obligations library?
A structured register of the obligations a firm is subject to, organised by source (a code of practice, a handbook, a law, an internal policy), each mapped to the risks it gives rise to and the controls that satisfy it. Kept current, it is what a rule change is assessed against.
How quickly should a firm respond to a regulatory change?
The assessment of impact should be immediate; the change to policies, controls and training follows the regulator's effective date. What matters to a reviewer is that the change was identified, its impact assessed, an owner named and the work tracked to closure, with the dates recorded.
Should internal policies sit in the same library as regulatory obligations?
Yes. Internal policies and group standards are obligations the firm holds itself to, and their controls and risks are assessed the same way. Keeping them in the same library gives one coverage picture rather than two.
Next step30 min · Tailored · No deck

See it running on your firm's structure.

A 30-minute walkthrough using your entities, your licences and a real workflow you bring to the call. No slide deck.