Blog · Coverage and territory · Compliance
How a compliance team reads its incident and near-miss reports against the activity that produces them, from the incident register and the activity data: reports per unit of activity, transactions, trades, accounts opened, the units well below the firm's own rate, the rate against the unit's audit findings, why a low reporting rate with high findings is a culture measure, and the list of units where the register is quiet and the evidence is not.
A compliance head looks at the incident register and sees that one business unit has reported nothing this year. Either it is the safest unit in the firm or it is the quietest, and the audit findings say which. This guide sets out reporting rate against activity, the norm across units, the comparison to findings, and the quiet-unit list.
Per unit, per period:
Reporting rate = incidents and near-misses reported ÷ activity volume, per thousand Norm = the firm's median reporting rate across units Findings rate = audit and monitoring findings ÷ activity volume, per thousand Reports per finding = reporting rate ÷ findings rate
Quiet if reporting rate < a stated share of the norm and findings rate ≥ the norm.
Unit identifiers only.
incidents = self-reported + found by monitoring + found by audit
Every incident in one source. An incident with no source is listed; source is what separates reporting from finding.
| Unit | Activity (thousands) | Reports | Reporting rate | Norm | Findings rate | Reports per finding | Reading |
|---|---|---|---|---|---|---|---|
| Payments | 840 | 126 | 0.15 | 0.12 | 0.04 | 3.8 | Reporting culture working |
| Lending | 310 | 31 | 0.10 | 0.12 | 0.05 | 2.0 | Normal |
| Treasury | 120 | 2 | 0.02 | 0.12 | 0.06 | 0.3 | Quiet, with findings above norm |
| Wealth | 95 | 14 | 0.15 | 0.12 | 0.02 | 7.5 | Working |
Treasury reports one sixth of the firm's rate and has more findings per transaction than anyone. Two self-reports and seven findings: the register is not hearing what the auditors are.
With the unit head, about the register: whether staff know what to report, whether reporting is safe, whether anyone reads it. Not about the two incidents. The reports-per-finding ratio is the number on the table, and it is a culture number.
| Unit | Reports per finding, 4 quarters ago | Now |
|---|---|---|
| Treasury | 1.1 | 0.3 |
The register went quiet over a year. Something changed in the unit, and the date narrows it.
Raw report counts. The big unit reports most; the small one looks fine.
Low reporting read as safe. The quiet unit praised.
Findings not beside reports. No independent check.
No trend. A register that went quiet reads as one that was always quiet.
Mapped once, the incident register, the activity data and the findings produce the rates, the norm, reports per finding and the quiet-unit list every quarter. Covirage builds this from the exports as they are. The compliance page describes the setup, and the issue ageing guide covers what happens to the findings the quiet unit did not report first.
The volume the unit does that could produce an incident: transactions, trades, accounts opened, payments processed, from the unit's own activity data. Reports per thousand transactions is comparable across units of different size in a way that raw counts are not.
Because findings are the independent record of what went wrong, and a unit whose findings are normal and whose self-reports are near zero is not reporting what it finds. The ratio of reports to findings per unit is the honest signal, and it is the one a regulator reads the same way.
Usually. A unit that reports many near-misses and has few findings is one where the register is used as intended. The report shows both, so the high reporter is read as the culture the firm wants, not as the problem unit.