The core set
Almost every regulated firm keeps a version of these:
- Breaches: regulatory and internal, with the obligation breached, the root cause, the remediation and whether it was reported.
- Complaints: received, acknowledged, investigated, resolved, with timings against the standard the regulator expects.
- Conflicts of interest: declared, assessed, managed, reviewed.
- Gifts and entertainment: given and received, value, approver, threshold, and whether it was accepted.
- Outsourcing: the arrangement, the criticality, the due diligence, the review cycle.
- PEPs and sanctions: screening outcomes and the decisions taken on them.
- Suspicious activity: for AML-supervised firms, the internal reports, the MLRO’s decision and any external submission.
- Declined business: who was turned away, and why.
Data protection adds subject access requests and a record of processors and controllers. Firms holding client assets add error and loss. Insurance, litigation, people (fitness and propriety) and CDD reliance round out the set for trust and fund businesses.
What each register must record
Whatever the register, the test is the same: could a reviewer reconstruct the decision from the entry alone? That means the event, the date, the people involved, the assessment, the decision, who made it and when, and what followed. Each entry needs a status (draft, active, complete, archived) and an owner, and the register as a whole needs a record of who changed which field and when.
Add the fields the register will need before it needs them: a threshold on the gifts register, an approver, a hospitality flag; a criticality on outsourcing; a reported-to-regulator flag on breaches with the date. Registers that start minimal grow by copying columns across, and every copy is a fork.
Why the gifts register is still a spreadsheet
Because it started as one, and nothing forced the change. A gifts register is small, familiar and easy to keep in Excel. The problem is not the spreadsheet; it is what happens around it. The approver replies by email and the email is the record. Two people keep copies. Someone tidies a column and history goes with it. The threshold changes and old entries are silently judged by the new one. The alert that a director has accepted three lunches from the same counterparty is a person remembering.
None of this matters until it does: a complaint, a whistleblowing report, an on-site visit. Then the questions are exactly the ones a spreadsheet cannot answer: who approved this, when, and what did they see?
The point at which registers outgrow spreadsheets
There are four tells. You cannot show who changed a row. Two people are editing different copies. The alert is a human. And the same event lives in three registers with three descriptions (the breach, the complaint it caused, the action it raised) with no link between them.
The fix is not a bigger spreadsheet. It is a register that carries its own audit trail, its own alerts, configurable fields with a version history, and a link from the entry to the action it raised and the obligation it touched. For an AML-supervised firm that is the whole of the land: see AML-only firms.
Registers as the way in
For most firms registers are the easiest place to start putting compliance on one system: the data already exists, the owners are known, and the improvement is visible in a week. From there the risk assessment and the monitoring plan follow, and the spreadsheets retire one by one.
How Vantage Point runs it
Vantage Point ships fourteen pre-built registers (breaches, complaints, conflicts, gifts and entertainment, outsourcing, data subject access requests, declined business and investors, error and loss, insurance, litigation, people, CDD reliance, exceptions, and data processors and controllers), each with a default schema, configurable and versioned fields, alert definitions and an audit trail on every entry, plus a form builder for the registers you need that are not in the set, such as PEP, sanctions or SAR registers. Every register exports to Excel in one click. See the Registers module.
Questions
- Which registers does a regulated firm need to keep?
- The set depends on the licence, but most regulated financial-services firms keep breaches, complaints, conflicts of interest, gifts and entertainment, outsourcing, PEPs, sanctions screening outcomes and, for AML-supervised firms, SARs and declined business. Data protection adds data subject access requests and processors. Firms holding client assets add error and loss.
- What must a compliance register record?
- Enough to reconstruct the decision: what happened, when, who was involved, what was decided, by whom and when, and what followed. Each entry needs a status and an owner, and the register needs a trail of who changed what, or the record cannot be relied on.
- When does a spreadsheet register stop being acceptable?
- When you cannot show who changed a row, when two people edit different copies, when the alert is a person remembering, or when the same event lives in three registers with three descriptions. Regulators rarely object to spreadsheets as such; they object to what spreadsheets cannot prove.
- Can register fields change once the register is in use?
- They should be able to. A gifts register that starts with six fields will need a threshold, an approver and a hospitality flag within a year. Configurable, versioned fields let the register grow without losing the history of the entries recorded under the earlier layout.