Back to Insights
Analysis

Why Compliance Teams Keep Missing Buried Rule Changes

Pierre Ferran 7 min read
Buried regulatory rule changes

Before I started Kalipso, I was working in-house at a mid-size investment firm. We had a small compliance team, a reasonable monitoring process by the standards of the time, and we thought we were keeping up with FCA publications. Then we missed a filing obligation that had been introduced in a policy statement. Not because we did not read the policy statement. We read the headline provisions. We missed the obligation because it was in Annex 3, described in two paragraphs, cross-referencing a form that did not yet exist on the FCA website at the time the PS was published.

When we discovered the gap, the obligation had already been in force for several months. The exposure was manageable, but the conversation with the board about how it happened was not pleasant. The honest answer, which I delivered, was that our monitoring process was not designed to catch this kind of thing. We were reading for the main story. The main story in most policy statements is not where the new obligations are.

The Anatomy of a Missed Rule Change

Missed rule changes in financial services share a consistent anatomy. The first element is volume: the FCA publishes hundreds of items a year across policy statements, consultation papers, guidance consultations, Dear CEO letters, supervisory statements, and technical notes. No compliance team reads all of them in full. The selection heuristic most teams use is publication type and headline description. If a policy statement is titled "Capital Requirements for Investment Firms" and your firm does not hold investment firm permissions, it goes in the low-priority pile. This is rational. It is also how obligations buried in cross-sector provisions get missed.

The second element is publication structure. Regulatory publications are not written to make compliance easy. They are written to satisfy legal drafting standards, to address consultation responses, and to set out policy reasoning. The operative provisions, the actual rule changes that create obligations, are often in annexes, in instrument appendices, or in cross-references to the FCA Handbook. A 200-page consultation paper with two substantive paragraphs of new obligation in Annex 3 is not uncommon. A compliance team reading the executive summary and the main body chapters has technically read the document without reading the obligation.

The third element is knowledge timeline. There is typically a gap between when a regulatory publication is released and when its compliance implications are understood. This gap is partly about reading time and partly about interpretation: whether a given provision applies to the firm's specific product structure or regulatory permission set is sometimes not obvious from the text. Enforcement actions related to missed rule changes almost always show this pattern: the obligation was published, the publication was received, the obligation was not identified as applicable until it was too late.

The Volume Problem Has Gotten Worse

The FCA published over 400 regulatory items in 2025 across all publication types. The PRA published separately; ESMA and EBA added to the volume for firms with EU-facing operations. ICO publications added data protection obligations to the stack. The aggregate publication volume from the combination of UK and EU regulatory bodies relevant to a mid-size UK financial firm is roughly one to two items per working day across the year.

That volume is not manageable by a compliance team that reads each item from scratch. It requires a triage process: which publications need full reading, which need a targeted skim, and which can be noted and filed without detailed analysis. Building that triage process well requires classification before reading, ideally by someone or something that has read the document before the compliance team does. That is the role of a monitoring system: not to replace the compliance team's reading, but to present each item with enough context that the compliance team knows whether and how deeply to read it.

Three Components of a Process That Catches Buried Changes

The compliance teams that consistently catch buried rule changes share three process components. First, they monitor at the full publication level, not just by reading published summaries or relying on third-party newsletters. Newsletters and regulatory round-ups are useful for context. They do not replace monitoring of the primary source, because editorial selection introduces blind spots: the newsletter covers the items the editor thought were important, not necessarily the items relevant to your firm's specific permissions and products.

Second, they apply firm-type and product-type filtering before the reading stage, not after. A monitoring process that presents every FCA publication to the compliance team for triage assumes that the team has the bandwidth to triage everything. At current publication volumes, that assumption is wrong. Pre-filtering by firm type, permission type, and product applicability reduces the reading queue to the subset that is actually potentially relevant, which is a manageable number.

Third, they have a structured process for tracking obligations that are flagged but not yet in force. Regulatory publications frequently introduce obligations with future effective dates. A monitoring process that captures the obligation on publication but does not maintain a live record of the obligation through to its effective date will produce a gap if the gap between publication and effective date is long enough that the original publication is no longer in active view.

Technology's Role: Narrow but Critical

We are not saying that technology solves the problem of missed rule changes by itself. Classifying a publication as relevant to a particular firm type is harder than it looks, and false positives (flagging publications as relevant when they are not) erode trust in monitoring systems just as false negatives (missing relevant publications) create compliance risk. A monitoring system that fires too many alerts produces a team that stops reading the alerts, which is worse than no monitoring system at all.

What technology does well in this context is handle the reading and initial classification of high-volume publication streams consistently. A human compliance officer reading 400 FCA publications a year, plus PRA plus ESMA plus ICO, will apply inconsistent attention at different points in the year, will make triage errors when bandwidth is low, and will not catch every buried provision in every document. A system that reads every document, extracts provisions, and classifies them against a firm-type taxonomy does not have those failure modes. It has different ones, and those need to be understood and monitored. But the core reliability at volume is different in kind.

The annex problem is where technology earns its value. An FCA policy statement published as a 200-page PDF, with operative provisions in Annex 3, is the same reading challenge for a system as a 5-page guidance note. The system reads the annex because it reads the whole document. That is the gap we built Kalipso to close.

Stay ahead of every change

Get regulatory updates before they become compliance gaps.

Kalipso monitors 45+ UK and EU regulatory feeds continuously. Request access and your team starts receiving plain-English alerts with remediation steps drafted.