Skip to content

Running compliance for a client book: delegated monitoring with oversight

Twelve client entities or two hundred, the problem is the same: each board wants its own position, the regulator wants the whole book evidenced, and the master spreadsheet can give neither.

By Vantage Point · Published 17 August 20264 min read

Two customers, one function

A fund administrator or trust company runs compliance twice over. Its own licence has obligations, risks, controls and a monitoring plan. So does every entity it administers, and each of those has a board that wants to know its own position, on its own paper, without another client’s numbers on the same page. Meanwhile the administrator’s regulator wants the whole book evidenced as one delegated function under central oversight.

The master spreadsheet answers neither. It cannot give a client board its own view without a day of unpicking, and it cannot give the regulator a consolidated position without hiding the entity that is outside appetite behind an average.

The model: every entity is a first-class compliance function

The design that works treats each administered entity as its own compliance function: its own obligations register scoped to its licence, its own risk assessment and appetite bands, its own control set, its own monitoring plan, its own registers and its own audit trail. Above them sits a consolidated view for the administrator’s compliance team and audit committee.

This is not duplication. The taxonomy, the control library and the test templates are shared, so the method is consistent across the book; only the data is per entity. Adding the fortieth entity is a configuration, not another copy of the manual estate.

Delegated monitoring with oversight, not by rekeying

Delegated monitoring goes wrong in one of two ways: the client entity’s compliance is monitored by nobody in particular, or it is monitored by the administrator rekeying the entity’s position into a group summary once a quarter. Oversight by rekeying is not oversight; it is a lagging copy.

With per-entity records, oversight is a view: which entities have tests overdue, which have residual risks outside appetite, which have actions past their deadline. The administrator’s team looks across; the client board looks down. Neither is a spreadsheet exercise.

Per-entity access for client boards

A client board should be able to log in and see its own entity, and only its own entity: risk register and heatmap, monitoring plan progress, open actions, registers. That is a permission model (role-based, entity-scoped) rather than a reporting task, and it removes the quarterly scramble to produce twelve packs from one master file.

Bringing the book in

The entities you administer already exist in your administration system. The compliance system should take them from there rather than have someone type them again; the entities you run there are the entities you monitor here. Structure, licence type and jurisdiction then drive what the obligations library, the risk taxonomy and the starter controls populate for each.

Existing registers, risk assessments and monitoring histories come across per entity during onboarding, imported and checked with you, so no client’s history starts from zero.

The consolidated view

The administrator’s own committee needs to see the book as a whole: entities by appetite position, overdue tests and actions by entity, regulatory changes and which entities have closed them. Because it reads from the per-entity records, it reconciles with what each client board sees, and a question from either side is answered from the same data.

How Vantage Point runs it

Vantage Point’s Entities module gives every managed entity its own registers, risk assessment and monitoring plan, with role-based, entity-scoped access for client boards and consolidated views for the administrator. The administered book syncs from Quantios Core, so nothing is rekeyed (see integrations). When a regulation changes, every affected entity is alerted and the review is applied per entity. Client entities are priced per entity, never by user. See the solution for fund administrators and TCSPs and the Entities module.

Questions

Should each administered entity have its own compliance monitoring plan?
Yes, scoped to the licence it holds. A fund and a trust vehicle in the same book carry different obligations and different risks; a shared plan either over-tests one or under-tests the other. Templates keep the method consistent while the plan stays per entity.
How does a fund administrator evidence delegated monitoring?
By keeping each entity's tests, findings and actions in that entity's own record with its own audit trail, and reporting to the client board from that record. Central oversight is a consolidated view across those records, not a rekeyed summary.
What should a client board see?
Their own entity and nothing else: its risk register and appetite position, its monitoring plan progress, its open actions and its registers, in a pack pulled from live data. Per-entity access controls make that a permission, not a manual extract.
How does a regulatory change get applied across a client book?
One review of the change, applied per entity: every affected entity is alerted, the action is raised in each entity's own context with an owner and a deadline, and the consolidated view shows which entities have closed it.
Next step30 min · Tailored · No deck

See it running on your firm's structure.

A 30-minute walkthrough using your entities, your licences and a real workflow you bring to the call. No slide deck.