Regulatory change management is the process by which an organization finds out about new or amended laws, regulations and supervisory guidance, decides whether and how they apply, works out what has to change in its policies, procedures, controls, systems and training, makes those changes before the effective date, and keeps a record of each step. U.S. financial regulators treat it as part of board and management oversight within a compliance management system: the CFPB, the OCC and the FFIEC's consumer compliance rating system each name change management as a factor examiners assess.
Regulatory change management is the process by which an organization identifies new, amended and repealed legal and regulatory requirements, determines whether they apply to it, analyses their effect on its policies, procedures, controls, products and systems, implements the necessary changes, and documents the result. It is a standing process rather than a project: requirements change continuously, and the process runs each change through the same stages.
In financial services the term covers statutes, regulations, official interpretations, supervisory guidance, enforcement actions that signal a regulator's reading of existing rules, and changes to industry standards the organization is bound to by contract, such as card network rules. It is one component of a compliance management system and depends on the organization knowing which requirements already apply to it, which is the function of a regulatory inventory.
Where the expectation comes from
No single U.S. statute requires a regulatory change management process by that name. The expectation comes from supervisory standards for compliance management, which name change management explicitly.
- FFIEC Uniform Interagency Consumer Compliance Rating System (2016). The rating system, adopted by the FFIEC member agencies in November 2016, assesses board and management oversight using factors that include the effectiveness of the institution's change management processes, including responding timely and satisfactorily to any variety of change, internal or external.
- CFPB Supervision and Examination Manual, Compliance Management Review procedures (August 2017). Under board and management oversight, the procedures describe change management as responding promptly to changes in applicable Federal consumer financial laws, market conditions and products by evaluating the change and implementing responses across affected lines of business, and reviewing the change after implementation. The examination procedures direct examiners to review processes for identifying new regulatory requirements and changes in requirements, and for planning implementation. The training module expects training to be updated in advance of the effective date of new or changed consumer protection laws.
- OCC Comptroller's Handbook, "Compliance Management Systems" (Version 1.0, June 2018). The booklet lists change management as one of the board and management oversight components of a compliance management system, and states that management should anticipate and respond in a timely manner to changes in applicable consumer protection-related laws and regulations, market conditions, and products and services.
Outside banking supervision, ISO 37301:2021, the international standard for compliance management systems, requires an organization to identify its compliance obligations and to have a process for identifying new and changed obligations (clause 4.5). Other regulators express the same expectation in their own terms; the common element is that a compliance program is judged partly on whether it keeps pace with the rules it is meant to satisfy.
The stages of the process
Regulatory change management is normally described in five stages. Organizations name and divide them differently, but the sequence is consistent.
| Stage | What happens | Typical output |
|---|---|---|
| 1. Identification | Monitoring official sources (the Federal Register, agency websites and bulletins, state registers, standard-setting bodies) for proposed, final and amended requirements. Often called horizon scanning. | A log of each change with its source, citation, status (proposed or final) and effective date. |
| 2. Applicability assessment | Deciding whether the change applies, given the organization's charter or licence, jurisdictions, products, customers and size thresholds. | A recorded applicability decision with its reasoning, including decisions that a change does not apply. |
| 3. Impact analysis | Tracing the change to the policies, procedures, controls, systems, disclosures, forms, vendor contracts and training it affects, and estimating the work involved. | An impact assessment listing affected items, owners and the gap between the current state and the new requirement. |
| 4. Implementation | Revising documents, changing systems, updating controls and training staff, with approvals, before the effective date. | An implementation plan with tasks, owners and deadlines, and evidence that each task was completed. |
| 5. Validation and documentation | Confirming after the effective date that the change operates as intended, usually through compliance monitoring or testing, and reporting to management and the board. | Post-implementation review results and a closed change record. |
Applicability and impact in more detail
The applicability decision is where most of the judgment sits. A rule may apply only above an asset threshold, only to certain product types, or only in certain states. A documented decision that a rule does not apply is as important as one that it does, because an examiner reviewing the process will ask how the organization reached that conclusion. Applicability decisions are usually made by compliance staff with legal counsel for ambiguous cases.
Impact analysis depends on traceability. An organization that has already mapped its requirements to the policies and controls that satisfy them can trace an amended requirement directly to the documents and controls that must change. An organization without that mapping has to search for affected items each time, which is slower and more likely to miss something. This is why regulatory change management and the regulatory inventory are usually maintained together.
Roles and governance
Responsibility is usually divided along the lines described by the Institute of Internal Auditors' Three Lines Model (2020). The compliance function, in a second-line role, typically runs identification, applicability and impact analysis and oversees implementation. Business-line owners, in first-line roles, make the operational changes to products, processes and systems. Legal counsel interprets ambiguous requirements. Internal audit, in the third line, may review the change management process itself. Senior management and the board receive reporting on significant changes and on whether implementation is on schedule, consistent with the oversight role the OCC and CFPB describe.
Many organizations use a committee, often called a regulatory change committee or compliance committee, to review significant changes, assign owners and track implementation across business lines.
Records the process produces
A regulatory change management process is judged by its records. A complete record for each change typically includes the source and citation, the date it was identified, the applicability decision and its reasoning, the impact assessment, the implementation plan and approvals, evidence of completion (revised policies, system change tickets, training records), and the post-implementation review. These records let an examiner or auditor follow a specific change from publication to operation.
Software support
Regulatory change management software typically collects regulatory publications from official sources, filters them by jurisdiction and topic, routes them to reviewers, records applicability decisions, and tracks implementation tasks. Many products also link each change to the organization's regulatory inventory, policies and controls so that impact analysis can start from existing mappings. The software supports the process; the applicability judgment, the interpretation of ambiguous text and the decision to accept a residual gap remain with the organization's compliance staff and counsel.
Common weaknesses
- Incomplete sources. Monitoring federal sources but not state regulators, or regulations but not supervisory guidance.
- Unrecorded applicability decisions. Changes judged not to apply with no record of why.
- Impact analysis limited to policies. Policies are updated while systems, disclosures, vendor arrangements or training are not.
- No post-implementation check. The change is marked complete when the document is revised, without confirming that practice changed.
- Proposed rules ignored until final. Lead time is lost when a rule is not tracked until it is published in final form.
Primary sources
- FFIEC, Uniform Interagency Consumer Compliance Rating System, 81 FR 79473 (November 14, 2016): Names the effectiveness of change management processes among the board and management oversight factors.
- CFPB Supervision and Examination Manual, Compliance Management Review procedures (August 2017): Change management expectations and the examination step reviewing processes for identifying new and changed regulatory requirements.
- OCC Comptroller's Handbook, Compliance Management Systems (Version 1.0, June 2018): Change management as a board and management oversight component of a CMS.
- ISO 37301:2021, Compliance management systems: Requirements with guidance for use: Clause 4.5 on identifying compliance obligations and new or changed obligations.
- The IIA's Three Lines Model (July 2020): The allocation of first-line, second-line and third-line roles used to divide responsibility for the process.