Back to Insights
Compliance Guide

How to Build a Regulatory Change Management Process That Actually Works

Lena Brauer 12 min read
Building a regulatory change management process

When we started building Kalipso, one of the first things we did was talk to compliance leads at growing financial services firms about how they currently track regulatory changes. The answer, almost universally, was some variant of the same thing: a shared spreadsheet, a few email subscriptions to FCA alerts, and a person whose job it was to check the FCA, PRA, and ESMA websites on a regular basis. Sometimes that checking happened. Sometimes it did not.

The spreadsheet approach works at very small scale, when one person can hold the firm's regulatory footprint in their head and the volume of publications across relevant bodies is manageable enough that a weekly check captures most of what matters. It stops working when the compliance team grows beyond two or three people, when the firm's regulatory obligations span multiple frameworks and multiple jurisdictions, or when the volume of publications from the FCA, PRA, ESMA, EBA, and ICO reaches the level it operates at today. At that point, the spreadsheet is not a system; it is a record of what one person noticed.

The Three Failure Modes

Regulatory change management processes break down in three consistent ways. The first is duplication without consolidation: different people on the compliance team, or different teams within the firm, are monitoring overlapping sets of regulatory sources, but they are not sharing what they find in a structured way. The result is a compliance function that collectively sees most of what it needs to see, but never in one place, and where the same publication may be triaged twice or not at all.

The second failure mode is format variation. Regulatory publications come in many formats. A consultation paper and a technical standard and a supervisory notice from the same regulator have the same URL domain but a very different compliance significance. A monitoring process that does not distinguish between publication types will either under-react to minor guidance updates or over-react to consultation papers that require a response but do not yet impose an obligation. The triage cost in either case is paid by whoever reads the alert.

The third failure mode is feed availability: the assumption that all relevant publications will appear in the place you are looking. Regulatory bodies update websites inconsistently. ESMA publications sometimes appear on the ESMA website before they are indexed in the feeds many firms monitor. FCA publications that cross regulatory frameworks (for example, a joint FCA/PRA letter) may appear under the FCA's listing without separate PRA coverage, or vice versa. A monitoring process that relies on a single feed per regulatory body has blind spots it cannot see.

Document Identity: The Core Problem

One specific problem that scales badly is document identity. The FCA publishes documents at URLs that are not always stable or consistently formatted. A consultation paper may be revised, with the revised version at a different URL but not clearly marked as a revision of the original. Two members of the compliance team monitoring the same FCA page may both log the same underlying document without realising it is the same document. Or the revision may be logged as a new item without the connection to the original consultation being recorded.

Document identity matters because the compliance significance of a revision is different from the compliance significance of a new publication. A revised final rule means something different to an implementation deadline than a first draft consultation. A change management process that cannot distinguish between these cases, or that logs them as separate unrelated events, produces a working record that does not accurately reflect the firm's compliance obligations over time.

A format-agnostic approach to document extraction is one way to address this. Rather than relying on structured metadata to identify document type, a process that reads document content and applies classification based on what the document actually says, rather than what it is labelled, produces more consistent results across the variation in how different regulators label their publications. This is the approach we take in Kalipso, and it is why the feed ingestion layer matters as much as the alert output layer.

Firm-Type Filtering: The Hardest Part

Even a well-designed monitoring and classification system produces too many alerts if it does not filter for relevance to the specific firm. The FCA publishes to all regulated firms. A typical UK-regulated financial institution is not subject to all FCA publications. A firm that holds permissions for investment management, consumer credit, and payment services is subject to a different subset of FCA obligations than a firm that holds only SMCR permissions or only banking licence permissions.

The firm-type filtering problem is harder than it looks because firm-type applicability is not always stated explicitly in the publication. A supervisory statement addressed to "investment firms" covers a statutory category that includes different firm types under different circumstances. A guidance note on Consumer Duty may technically apply to any FCA-regulated firm but have practical implications only for retail-facing operations. Correctly filtering a publication for applicability requires both a taxonomy of firm types and an understanding of the regulatory context in which the publication sits.

The firm-type applicability filter is where most self-built monitoring systems either fail or require significant ongoing maintenance. The taxonomy of firm type applicability needs to track regulatory changes that affect which firms are subject to which obligations. It cannot be built once and left unchanged.

Feed Health Monitoring

A monitoring process is only as reliable as its feeds. A feed that goes silent is indistinguishable from a feed where nothing new has been published, unless the monitoring system actively checks whether the feed is live. Feed health monitoring, where the system verifies that each monitored source is actually delivering output at expected intervals and raises an alert when it is not, is a basic reliability requirement for any monitoring infrastructure at volume.

We built feed health monitoring into Kalipso's infrastructure because we saw, early on, that feed outages without detection produced the worst outcome: a confident absence of alerts that actually meant a period of monitoring failure. A compliance team that receives no alerts for two weeks may correctly conclude that nothing relevant was published, or may incorrectly conclude that when in fact the feed was down. The two are not distinguishable without active health checking.

What a Working Process Actually Looks Like

A regulatory change management process that works at the scale of a growing financial firm has three components that work together: ingestion (monitoring the right sources and capturing what they publish), classification (understanding what each publication is and who it applies to), and workflow (getting the right alerts to the right people with enough context to act on them).

Ingestion without classification produces noise. Classification without workflow produces a database that nobody acts on. Workflow without reliable ingestion and classification produces a process that looks functional but misses things. The three components are interdependent, and a gap in any one of them degrades the whole.

We are not saying that building this in-house is impossible. It requires ongoing engineering effort to maintain feed health, update firm-type taxonomies as the regulatory landscape evolves, and improve classification accuracy as new publication types and formats appear. For compliance teams whose primary function is not building monitoring infrastructure, the question is whether that engineering investment is a better use of resource than buying a maintained system. That is a resource allocation question, and the answer depends on the firm's scale, risk profile, and appetite for building versus buying compliance tooling.

What we can say, from the conversations that led to building Kalipso, is that most compliance teams at growing financial firms do not currently have a process with all three components working reliably. The spreadsheet with email subscriptions is one component, weakly. The gaps are in classification and workflow. Those gaps are where regulatory changes get missed.

Stay ahead of every change

Get regulatory updates before they become compliance gaps.

Kalipso monitors 45+ UK and EU regulatory feeds continuously. Request access and your team starts receiving plain-English alerts with remediation steps drafted.