A regulatory inventory, also called a compliance obligations inventory, is a maintained list of the laws, regulations, supervisory guidance, standards and binding commitments that apply to an organization, with each requirement mapped to the business lines it affects, an accountable owner, and the policies and controls that address it. It is the reference point for the rest of a compliance program: the risk assessment, testing plans, training and regulatory change management all draw on it. ISO 37301:2021 requires organizations to identify and document their compliance obligations (clause 4.5), and U.S. bank supervisors assess whether a compliance management system addresses all applicable laws and regulations.
A regulatory inventory is a documented, maintained list of the legal and regulatory requirements that apply to an organization, together with the analysis that shows why each applies and the mappings that show where each is addressed. It is also called a compliance obligations inventory, a regulatory requirements inventory or a law and regulation inventory. Each entry identifies a requirement by citation, records the business lines, products or processes it affects, names an accountable owner, and links to the policies, procedures and controls through which the organization meets it.
The inventory answers a basic question that every other part of a compliance program assumes has been answered: which rules apply here. A risk assessment scores the risk of failing to meet requirements; a testing plan tests whether controls meet them; training teaches staff about them. None of these can be complete unless the list of requirements is complete.
Where the expectation comes from
No U.S. statute requires a document called a regulatory inventory. The expectation arises from standards that require an organization to know, and to be able to show that it knows, the requirements it is subject to.
- ISO 37301:2021, clause 4.5 (Compliance obligations). The international standard for compliance management systems requires an organization to systematically identify its compliance obligations arising from its activities, products and services, assess their impact on its operations, have processes to identify new and changed obligations, and maintain documented information of its compliance obligations. The standard defines compliance obligations to include both requirements the organization must comply with and those it chooses to comply with.
- OCC Comptroller's Handbook, "Compliance Management Systems" (Version 1.0, June 2018). The booklet defines a bank's compliance management system in terms of compliance with all applicable laws and regulations, and places responsibility for that compliance on the board and management collectively.
- CFPB Supervision and Examination Manual, Compliance Management Review procedures (August 2017). The procedures assess whether a supervised entity's compliance program, policies and procedures address the Federal consumer financial laws applicable to its products and services, and direct examiners to review processes for identifying new and changed regulatory requirements.
In practice, an examiner or auditor who asks how an organization knows its policies cover every applicable requirement is asking for the inventory, whether or not the organization calls it that.
What an entry contains
The level of detail varies by organization. A common structure records the following fields for each requirement.
| Field | Content |
|---|---|
| Citation | The source and pinpoint, for example a section of the Code of Federal Regulations, a state statute, a guidance document or a standard's clause, with its effective date. |
| Requirement summary | A plain-language statement of what the requirement obliges the organization to do or not do. |
| Applicability | Whether it applies, to which legal entities, jurisdictions, products and business lines, and the reasoning, including thresholds or exemptions relied on. |
| Owner | The person or function accountable for meeting the requirement, usually in the first line, with a second-line compliance contact. |
| Policies and procedures | Links to the documents that implement the requirement. |
| Controls | Links to the controls in the control library that address it, and to the tests of those controls. |
| Risk rating | The compliance risk associated with the requirement, drawn from or feeding the compliance risk assessment. |
| Review history | The date of the last review, the reviewer and any open changes. |
Granularity is a design choice. Some inventories record each regulation as one entry; others break a regulation into its individual requirements, which makes the mapping to controls more precise but the inventory larger to maintain.
Applicability analysis
Building an inventory starts with a scan of the requirements that could apply, drawn from the organization's charter or licences, the jurisdictions in which it operates or has customers, its products and services, its size, and its contracts. Each candidate requirement then receives an applicability decision. Many rules turn on thresholds or definitions: an asset size, a transaction volume, whether a product is offered to consumers, whether the organization is a covered entity under a particular statute. The applicability record states the facts relied on, so that the decision can be revisited when those facts change, for example when the organization crosses a threshold or launches a new product.
Decisions that a requirement does not apply are recorded as well. They show that the requirement was considered, and they identify what change in the business would make it applicable.
Mapping to policies and controls
The mappings are what distinguish an inventory from a list of laws. A requirement mapped to a policy, a procedure and a tested control can be shown to be met. A requirement with no mapping is a visible gap. Mappings run in both directions: from a requirement to the controls that address it, and from a control to every requirement it supports, which shows the consequence of changing or removing that control.
Maintenance through regulatory change management
An inventory is accurate only as of its last update. It is kept current through regulatory change management, which identifies new and amended requirements, decides their applicability, and updates the inventory and its mappings. Internal changes also trigger updates: new products, new jurisdictions, acquisitions, and changes in size that cross regulatory thresholds. Many organizations also perform a periodic full review of the inventory, commonly annually, to catch changes that the event-driven process missed.
Who maintains it and where it is kept
The compliance function usually owns the inventory, with legal counsel for interpretation and business-line owners confirming how requirements are met in practice. Small organizations often keep it in a spreadsheet. Larger organizations commonly keep it in GRC software, where each requirement can be linked to policies, controls, risks, test results and issues, and where changes can be tracked with a history.
Common weaknesses
- Incomplete scope. Federal rules are listed while state requirements, supervisory guidance, card network rules or contractual commitments are not.
- No recorded reasoning. Applicability decisions are made but not documented, so they cannot be reviewed.
- Mappings not maintained. Controls or policies change and the links to requirements are not updated.
- Citations too broad. A whole statute is cited where a specific section is what applies, which makes it hard to confirm coverage.
- Static document. The inventory is built once, for an examination or a project, and not kept current.
Primary sources
- ISO 37301:2021, Compliance management systems: Requirements with guidance for use: Clause 4.5 requires an organization to identify, assess and document its compliance obligations and to identify new and changed obligations.
- OCC Comptroller's Handbook, Compliance Management Systems (Version 1.0, June 2018): Defines a bank's CMS in terms of compliance with all applicable laws and regulations.
- CFPB Supervision and Examination Manual, Compliance Management Review procedures (August 2017): Examination of whether policies and procedures address applicable Federal consumer financial laws, and of processes for identifying new and changed requirements.