Skip to content
Reference

Regulatory Change Management: Definition, Process and Supervisory Expectations

The short version

Regulatory change management is the process by which an organization finds out about new or amended laws, regulations and supervisory guidance, decides whether and how they apply, works out what has to change in its policies, procedures, controls, systems and training, makes those changes before the effective date, and keeps a record of each step. U.S. financial regulators treat it as part of board and management oversight within a compliance management system: the CFPB, the OCC and the FFIEC's consumer compliance rating system each name change management as a factor examiners assess.

Regulatory change management is the process by which an organization identifies new, amended and repealed legal and regulatory requirements, determines whether they apply to it, analyses their effect on its policies, procedures, controls, products and systems, implements the necessary changes, and documents the result. It is a standing process rather than a project: requirements change continuously, and the process runs each change through the same stages.

In financial services the term covers statutes, regulations, official interpretations, supervisory guidance, enforcement actions that signal a regulator's reading of existing rules, and changes to industry standards the organization is bound to by contract, such as card network rules. It is one component of a compliance management system and depends on the organization knowing which requirements already apply to it, which is the function of a regulatory inventory.

Where the expectation comes from

No single U.S. statute requires a regulatory change management process by that name. The expectation comes from supervisory standards for compliance management, which name change management explicitly.

Outside banking supervision, ISO 37301:2021, the international standard for compliance management systems, requires an organization to identify its compliance obligations and to have a process for identifying new and changed obligations (clause 4.5). Other regulators express the same expectation in their own terms; the common element is that a compliance program is judged partly on whether it keeps pace with the rules it is meant to satisfy.

The stages of the process

Regulatory change management is normally described in five stages. Organizations name and divide them differently, but the sequence is consistent.

StageWhat happensTypical output
1. IdentificationMonitoring official sources (the Federal Register, agency websites and bulletins, state registers, standard-setting bodies) for proposed, final and amended requirements. Often called horizon scanning.A log of each change with its source, citation, status (proposed or final) and effective date.
2. Applicability assessmentDeciding whether the change applies, given the organization's charter or licence, jurisdictions, products, customers and size thresholds.A recorded applicability decision with its reasoning, including decisions that a change does not apply.
3. Impact analysisTracing the change to the policies, procedures, controls, systems, disclosures, forms, vendor contracts and training it affects, and estimating the work involved.An impact assessment listing affected items, owners and the gap between the current state and the new requirement.
4. ImplementationRevising documents, changing systems, updating controls and training staff, with approvals, before the effective date.An implementation plan with tasks, owners and deadlines, and evidence that each task was completed.
5. Validation and documentationConfirming after the effective date that the change operates as intended, usually through compliance monitoring or testing, and reporting to management and the board.Post-implementation review results and a closed change record.

Applicability and impact in more detail

The applicability decision is where most of the judgment sits. A rule may apply only above an asset threshold, only to certain product types, or only in certain states. A documented decision that a rule does not apply is as important as one that it does, because an examiner reviewing the process will ask how the organization reached that conclusion. Applicability decisions are usually made by compliance staff with legal counsel for ambiguous cases.

Impact analysis depends on traceability. An organization that has already mapped its requirements to the policies and controls that satisfy them can trace an amended requirement directly to the documents and controls that must change. An organization without that mapping has to search for affected items each time, which is slower and more likely to miss something. This is why regulatory change management and the regulatory inventory are usually maintained together.

Roles and governance

Responsibility is usually divided along the lines described by the Institute of Internal Auditors' Three Lines Model (2020). The compliance function, in a second-line role, typically runs identification, applicability and impact analysis and oversees implementation. Business-line owners, in first-line roles, make the operational changes to products, processes and systems. Legal counsel interprets ambiguous requirements. Internal audit, in the third line, may review the change management process itself. Senior management and the board receive reporting on significant changes and on whether implementation is on schedule, consistent with the oversight role the OCC and CFPB describe.

Many organizations use a committee, often called a regulatory change committee or compliance committee, to review significant changes, assign owners and track implementation across business lines.

Records the process produces

A regulatory change management process is judged by its records. A complete record for each change typically includes the source and citation, the date it was identified, the applicability decision and its reasoning, the impact assessment, the implementation plan and approvals, evidence of completion (revised policies, system change tickets, training records), and the post-implementation review. These records let an examiner or auditor follow a specific change from publication to operation.

Software support

Regulatory change management software typically collects regulatory publications from official sources, filters them by jurisdiction and topic, routes them to reviewers, records applicability decisions, and tracks implementation tasks. Many products also link each change to the organization's regulatory inventory, policies and controls so that impact analysis can start from existing mappings. The software supports the process; the applicability judgment, the interpretation of ambiguous text and the decision to accept a residual gap remain with the organization's compliance staff and counsel.

Common weaknesses

Primary sources

Common questions

What is regulatory change management?
Regulatory change management is the process of identifying new and amended laws, regulations and guidance, deciding whether they apply, analysing their effect on policies, procedures, controls and systems, implementing the necessary changes before the effective date, and documenting each step.
Is regulatory change management required?
No U.S. statute requires it by name, but supervisors expect it. The FFIEC's 2016 consumer compliance rating system, the CFPB's Compliance Management Review procedures and the OCC's Compliance Management Systems booklet each name change management as part of board and management oversight that examiners assess.
What are the stages of regulatory change management?
The process is usually described in five stages: identification of the change, applicability assessment, impact analysis against policies and controls, implementation, and validation with documentation.
How is regulatory change management related to a regulatory inventory?
The regulatory inventory lists the requirements that currently apply and maps them to owners, policies and controls. Regulatory change management keeps that inventory current, and the inventory's mappings make impact analysis faster because an amended requirement can be traced directly to what it affects.
Who is responsible for regulatory change management?
The compliance function usually runs identification, applicability and impact analysis and oversees implementation; business-line owners make the operational changes; legal counsel interprets ambiguous requirements; and senior management and the board oversee the process.
About this library

This reference library is maintained by Rupture Labs. We perform BSA/AML independent testing and automated control testing against every record, with each requirement cited to its rule. Talk to a practitioner.