Skip to content

What a compliance monitoring programme should contain

A CMP is not a calendar of things to look at. It is the evidence that your controls operate. Here is the shape of one that survives a thematic review.

By Vantage Point · Published 17 August 20265 min read

Start from the controls, not the calendar

The weakest monitoring programmes were built by asking “what should we look at this year?”. The strongest were built by asking “which controls do we rely on, and how do we know each one is operating?”. That question produces a test for every control that matters, at a frequency set by the risk the control treats, and it leaves out the tests that exist only because a template had a row for them.

So the first artefact is not the plan. It is the control register, mapped to the obligations each control satisfies and the risks it mitigates (how those risks are scored is in Inherent, residual and appetite). If a control has no obligation and no risk behind it, ask why it is a control. If an obligation has no control behind it, that gap is the first thing the programme should test.

The plan

The plan is the year’s tests laid out with four things against each: the control (or controls) under test, the owner, the frequency and the due dates. It is signed off once, at the start of the year, and changed deliberately when the risk picture changes, with the change recorded.

A workable plan also carries a workload view. Compliance functions are usually one to five people; if forty tests fall due in the same fortnight, the plan is fiction. Spread the calendar so it can be run by the people who have to run it.

The tests

Each test needs a template that says what the tester does, what the sample is, what evidence is expected and what a pass looks like. Templates are what make a test repeatable across quarters and, for firms with a client book, across entities. Without them, the same test run by two people reaches two conclusions.

Sampling should be stated up front (ten client files, all payments over a threshold, every new account in the quarter) so nobody can accuse the tester of picking the easy ones. Where the sample is judgemental, say so, and say why.

Conclusions that mean something

Four conclusions are enough: Pass; Pass with minor issues; Fail, needs review; Fail, critical. Two levels of fail matter because the response is different: a needs-review failure raises an action and a rethink; a critical failure means a control you rely on is not operating and the risk it treats is, for now, uncontrolled.

Whatever the scale, the conclusion must be a field, not a paragraph. Committee reporting depends on being able to count them.

Evidence

Every test records what was looked at, by whom, when, and what was found, with the evidence attached or referenced. This is the part that makes the CMP defensible in front of a regulator, and it is the part that spreadsheets lose: the evidence lives in someone’s mailbox and the spreadsheet says “Pass”.

What follows a finding

A failed test should raise a corrective action automatically, with an owner, a deadline and a link back to the control and the risk. When the action closes you should be able to see what changed: the control’s operating rating, the residual risk, and the outcome of the next scheduled test. Effectiveness becomes something you measure across the year rather than something you assert at the end of it.

The report

The monitoring plan report answers, at any point in the year, three questions: how much of the plan has run, what did it conclude, and what is open as a result. If it reads from the same records the tests were logged in, it is ready the day before every committee meeting and reconciles with the risk register beside it (see What the committee pack needs).

How Vantage Point runs it

In Vantage Point the CMP is a module on the same data model as obligations, risks and controls. Tests are linked to controls and controls to obligations; the calendar and workload views carry alerts as tests fall due; conclusions are Pass, Pass with Minor Issues, Fail with Needs Review and Fail Critical; a failing test raises a corrective action automatically; and the monitoring plan report is one of the seven report types, live at any point in the year. See the CMP module.

Questions

How many tests should a compliance monitoring programme have?
As many as the risks and controls justify and no more. A programme built from the control register lands at a test for every control that matters, at a frequency set by the risk it treats. Programmes built from a template usually carry tests nobody can explain and miss the ones an inspector asks about first.
What is the difference between a compliance monitoring programme and an internal audit?
The CMP is the compliance function's own first and second line assurance that its controls operate day to day; internal audit is independent, periodic and reports to the audit committee. A good CMP makes internal audit's job shorter because the evidence already exists.
How often should the CMP be reported to the board?
The plan is approved once a year and progress is reported at every committee meeting: tests completed, conclusions, actions raised and closed, and anything that changed the risk picture. The report should read from live records rather than be assembled the week before.
What happens when a test fails?
A corrective action is raised with an owner and a deadline, linked to the control that failed and the risk it treats. When the action closes, the control rating and the residual risk are reviewed, and the next scheduled test confirms the fix.
Next step30 min · Tailored · No deck

See it running on your firm's structure.

A 30-minute walkthrough using your entities, your licences and a real workflow you bring to the call. No slide deck.