What the committee is actually asking
Strip a compliance committee’s agenda down and it wants answers to five questions. Are we within the risk we agreed to carry? Is the monitoring plan running, and what has it found? What is open, who owns it, and what is late? Has anything changed in the rules that we have not dealt with? Is there anything you need us to decide?
A pack that answers those on its first page, and supports them on the pages behind, is doing its job. A pack that opens with forty pages of register extracts is asking the committee to do the compliance officer’s job.
The core pages
Risk position. The heatmap against the entity’s own appetite bands, the count of risks per band, the ten highest residual risks with their controls and open actions, and what moved since last time.
Monitoring. Plan progress (scheduled, completed, overdue), the conclusions reached in the period, and any critical failure with the action raised against it.
Actions. Open and overdue by owner and priority, with the trail back to what raised each: a test, a breach, a regulatory change.
Coverage. Obligations without controls, controls without a recent test (the monitoring programme’s own gaps), risks without an owner. These are the questions an inspector asks; the committee should hear the answers first.
Breaches and complaints. What was recorded in the period, whether it was reported, and what followed.
Regulatory change. What changed, which obligations it touched, and whether the action is closed.
Decisions. Anything the committee is being asked to approve or accept, stated as a decision.
What it does not need
Full register extracts as appendices; a narrative that repeats the tables in prose; charts that do not answer a question; and anything the committee cannot act on. If a page would not change a decision or a question, leave it out and make it available on request.
Live data or it does not reconcile
The reason hand-built packs fail is not effort; it is arithmetic. A pack assembled from the risk spreadsheet, the monitoring tracker and the actions log will disagree with at least one of them by the time it is read, and nobody in the room can say which is right. A pack that reads from the same records the modules use reconciles with itself, and a question from the chair (“which three risks are outside appetite, and who owns the actions?”) is answered from the system rather than promised for next time.
Pull it the day before, not the week before. The point of live data is that it is live.
Per entity, and consolidated
For a firm running a client book, each client board needs its own pack, scoped to its own entity, and the firm’s own committee needs the consolidated view across the book. Both must come from the same records, or the client board and the group committee are being told two different things about the same entity.
The format question
Committees still read paper and PDFs; secretariats still want Excel to assemble the wider board pack. Whatever the system produces, it should export cleanly to Excel so the committee secretary can take it into the meeting bundle without retyping a number.
How Vantage Point runs it
Vantage Point’s Reports module carries seven report types (risk register, risk appetite, controls effectiveness, monitoring plan, obligations coverage, actions and audit trail), each pulled from live data with per-entity views for client boards and consolidated views for group governance, and each exporting to Excel. Board packs assembled from the set are next on the roadmap. See the Reports module.
Questions
- What should a compliance committee pack contain?
- The risk register position against appetite (with the heatmap), monitoring plan progress and conclusions, open and overdue actions by owner, obligations coverage, breaches and complaints in the period, regulatory changes and their status, and any matter that needs a decision. Each figure should trace to a record.
- How often should the compliance pack go to the board?
- At every scheduled committee meeting, usually quarterly, with an annual pack that approves the monitoring plan and the risk appetite. Anything critical (a serious breach, a failed critical test) goes up between meetings.
- How long should a compliance board pack be?
- As short as the questions allow. A first page that answers what is outside appetite, what is overdue and what needs a decision, then supporting pages the committee can turn to. Forty pages of register extracts is not a pack; it is a data dump with a cover.
- Should the pack be built by hand or from the system?
- From the system. A pack assembled by hand from several files disagrees with the registers it summarises and cannot be interrogated in the room. A pack that reads from live records the day before the meeting reconciles with itself and answers follow-up questions from the same data.