Platform · Policy management
Policies that know which rules they implement, and say so when those rules change.
Policy management starts each policy from the requirements it has to meet, keeps every version, and records who approved it and on what basis. When a rule behind a section changes, the policy is flagged as drifted, so you revise it before your examiner finds the gap. Any version exports to Word.
The problem it removes
A policy that was right the day it was approved
- Policies are written once, approved by the board, and left alone while the rules they rest on move.
- Nobody can say which section of which policy answers which requirement, so a rule change never reaches the document.
- Versions live as file names like "AML Policy v7 FINAL (2)", and the approval record is a line in the board minutes.
What you see
Each policy, its versions, its approvals and its drift
Every section shows the requirement it implements. When one of those requirements changes, the section is flagged, and a redline compares what the section says against the rule text.
| Section | Implements | Status |
|---|---|---|
| 4.1 Customer due diligence | 31 CFR 1020.210(a)(2)(v) | Current |
| 4.3 Beneficial ownership | 31 CFR 1010.230 | Drift rule amended after approval |
| 6.2 SAR decisioning | 31 CFR 1020.320 | Current |
| Version | Approved by | Basis |
|---|---|---|
| 7 | Board risk committee | Annual review, CDD section rewritten |
| 6 | Board risk committee | Exam finding response |
Illustrative example with invented data. Each flagged section can be compared line by line against the rule text.
How it works
Draft, approve, watch the rules, revise
- Draft. A policy starts as a skeleton built from the requirements in your regulatory inventory, each section carrying its citation. Your team, or a practitioner under your engagement, writes the words; no model decides what the policy must cover.
- Approve. Each version is kept unchanged once saved. Approval is recorded with who approved it and the basis they gave, and an approval without a basis is refused.
- Watch the rules. When regulatory change management reports a change to a rule a section implements, that section is flagged as drifted, and the flag goes to your issue list to be worked.
- Revise. Your policy owner, or a practitioner under your engagement, reviews the drift, revises the section and takes the new version back through approval. Any version exports to Word for your board pack.
Guardrails
What it will never do
- It doesn't publish a policy nobody has approved. Every version has a named approver and a date.
Where it shows up
The work this part does for you
Plain English
What this is, and how anyone does it
Reference articles from our library, cited to the published rules and standards. No sales copy.
- CMSCompliance Management System (CMS): The CFPB FrameworkWhat a CMS is under the CFPB framework: board and management oversight plus a compliance program of policies, training, monitoring and audit, and consumer complaint response. How examiners assess it and how to build one.
- ReferenceRegulatory Change Management: Definition, Process and Supervisory ExpectationsIdentifying new and amended rules, assessing applicability, analysing impact on policies and controls, implementing and documenting the change, and where the CFPB, OCC and FFIEC expect it.
Connected parts
What it works with
Talk to a practitioner
Book a 15-minute chat with our founder.
A real conversation with a senior compliance leader, to see if there's a fit. Not a sales call, not a demo, no pressure.