The specific prompt that became one of the founding cases for Kalipso was a Policy Statement from the FCA. The PS was published on a Thursday afternoon. We received it on our email distribution list. It went into the same folder as the other FCA publications that week. By the time it was properly read, two days had passed. The obligation it introduced had an effective date that was, at that point, 60 days away.
That 2-day gap between publication and substantive reading is not unusual. In a compliance function where everyone is managing a full workload, a new FCA publication lands in the queue with everything else. The gap between the alert and the action is the time between when the publication appears and when a compliance officer has read it, assessed its significance, and initiated a response. At most firms, that gap is measured in days, sometimes weeks. The question is what that gap costs.
What Manual Triage Actually Looks Like
A compliance team that does not have an automated classification system handles FCA publications through a four-step manual triage. First, someone notices the publication and logs it. Second, a compliance officer reads enough of the document to form a view on whether it is relevant to the firm. Third, if it is relevant, the document goes to the person with subject matter expertise to assess the specific implications. Fourth, that assessment is turned into an action plan: what policy document needs to be updated, which functions need to be notified, and by when.
Each step takes time, and the time at each step is variable. Step one depends on how frequently the monitoring source is checked. Step two depends on the compliance officer's workload when the publication arrives. Step three depends on the availability of the subject matter expert. Step four depends on how much complexity is involved in the required response. In a well-resourced compliance function with a light publication load, this process might take one or two days. At higher volumes and lower resource, five to ten days is not uncommon.
The problem is not the process structure. The problem is the cumulative latency. A regulatory publication with a 90-day effective date leaves 88 days of action time if the triage process takes 2 days. It leaves 80 days if it takes 10 days. For most straightforward policy updates, 80 days is sufficient. For obligations that require system changes, staff retraining, or client communications, the margin narrows quickly.
The Two Dimensions of Response Time
There are two dimensions to regulatory response time that most discussions collapse into one. The first is speed to action: how quickly from publication does the compliance team initiate a response process? The second is speed to risk identification: how quickly does the compliance team understand whether the firm is currently exposed under the new obligation, as distinct from whether it will comply by the effective date?
Speed to action is the dimension most compliance processes are designed around. The triage, assignment, and action plan process produces a response. Speed to risk identification is different: it requires the compliance officer to assess the current state of the firm's compliance posture against the new obligation before the new obligation is in force. That assessment tells the compliance team whether the firm needs to change something, or whether existing processes already satisfy the new requirement.
The risk identification assessment is harder to do quickly because it requires knowledge of both the new obligation and the firm's current practices. A compliance officer reading a new supervisory statement on Consumer Duty board reporting needs to know what the firm's current board report contains in order to assess whether the new expectation creates a gap. That contextual knowledge is not always available immediately when the publication arrives.
Automated Triage Output: A Briefing, Not a Decision
What automated regulatory monitoring changes in this picture is the first step of the triage process. A system that reads the publication, classifies it by regulatory framework and firm-type applicability, and generates a plain-English summary with an initial assessment of whether any compliance review is likely needed reduces the time between publication and the compliance officer's first engagement with the substance of the document.
We track this specifically with Kalipso customers. The average time from FCA publication to first compliance officer review of the substantive content, when the compliance team uses Kalipso, is under four hours for publications classified as high-priority. Without the system, the median time to first substantive review is 2.5 days. The difference matters when effective dates are tight or when the firm's current posture means it may already be out of compliance on a point the new publication clarifies.
We are not saying that the automated summary replaces the compliance officer's reading of the document. For high-priority publications, the compliance officer needs to read the source. What the automated output provides is a prioritised briefing that allows the compliance officer to allocate reading time to the publications that warrant it, rather than allocating equal time to everything that arrives in the inbox. The briefing is not the decision; it is the context that makes the decision faster.
A 90-Day Pilot: What We Observed
One of the earlier deployments of Kalipso was with a compliance team at a UK-based payment services firm. They had a three-person compliance team managing FCA, PSR, and ICO monitoring alongside their core compliance programme. Their prior process was entirely manual: FCA email alerts went to one person, who reviewed and forwarded relevant items with a brief note.
After 90 days using Kalipso, the time from FCA publication to first substantive compliance review for high-priority items fell from an average of around three hours to under one hour. The change was not because the compliance officers read faster. It was because the classification layer removed the decision about which items warranted immediate reading versus deferred reading. Items that arrived pre-classified as high-priority and pre-summarised could be assessed in twenty minutes rather than the thirty to forty minutes required to read the source document and form an initial view from scratch.
The total workload did not decrease; the publication volume did not change. What changed was the distribution of effort. More effort went to the items that warranted it, and less effort went to items that had been pre-assessed as low-priority for the firm's specific permissions and product mix.
What a Realistic Response Timeline Looks Like
For most regulatory publications, a two-to-five-day cycle from publication to initial risk assessment and action plan is achievable with a three-to-five-person compliance function, provided the triage process is systematic. For publications with complex implications (those requiring system changes, client communications, or board-level sign-off), two weeks to initial action plan and eight to twelve weeks to implementation is a realistic estimate, which means the 90-day effective date window is tight but workable.
The scenario that creates genuine risk is the combination of: a publication with a short effective date (under 60 days), a complex implementation requirement, and a slow triage process. That combination is uncommon but not rare. The FCA does issue publications with short effective dates, particularly for clarifications or corrections to existing requirements where the regulatory intent is to close a gap quickly. A compliance function with a triage lag of ten or more days is materially less prepared for those situations than one with a triage lag of under forty-eight hours.
The investment in faster triage is not primarily about the average publication. It is about the tail risk: the publication with the short effective date and the complex implication that arrives when the compliance team's bandwidth is already stretched. That tail risk is where the gap between a two-day response cycle and a ten-day response cycle becomes the difference between a managed implementation and a supervisory conversation about why the firm was late.