Blog · Industry
Which obligations have no mapped control. Which entities have not been reviewed inside their cycle. Which controls were tested, which failed, and which have never been tested at all. From the obligations register, the control library and the testing log, reconciled so the board pack and the regulator see the same numbers.
How a compliance team reads its incident and near-miss reports against the activity that produces them, from the incident register and the activity data: reports per unit of activity, transactions, trades, accounts opened, the units well below the firm's own rate, the rate against the unit's audit findings, why a low reporting rate with high findings is a culture measure, and the list of units where the register is quiet and the evidence is not.
16 Sept 20262 min readHow a compliance or internal audit team reports the findings that are open past their agreed remediation date, from the issue register: ageing bands per owner and business unit, the extensions granted and how many times, the high-rated issues past date, and the trend that shows a remediation programme slipping before the board asks why the same finding is on the pack for the third quarter.
16 Sept 20263 min readHow a compliance function measures control coverage from the obligations register, the control library and the testing log: obligations with no mapped control, controls past their test date, entities outside their review cycle, and the reconciliation that lets the board pack and the regulator see one number.
16 Sept 20263 min readHow a compliance team tracks the gap between regulatory change and control coverage from its own obligation register and change log: obligations added or amended per period, the days each has been live with no mapped control, the business units where unmapped obligations concentrate, the ageing of the mapping backlog, and the identity that every obligation is either mapped, in progress or unmapped with a date.
16 Sept 20262 min readThe ten questions a head of compliance puts to the business units and the compliance team, which obligations have no control, which controls were not tested on schedule, which findings are past their date and how many times extended, which regulatory changes have no mapping yet, who is overdue on training, which units report nothing, which high-rated issues are open, what will a regulator find first, what did the last audit find that the register did not, and what changed, each with the table from the registers, the identity behind it, and the answer to send back.
16 Sept 20262 min readHow a compliance team measures whether each control was tested when its plan said it would be, from the control register and the testing log: cadence adherence per control owner and business unit, the slipped-test list ranked by the risk the control covers, and the trend that shows a testing programme quietly falling behind before the regulator asks.
16 Sept 20262 min readHow a compliance team measures mandatory training coverage from the learning system export and the HR roster: each person's required modules from their role, completions and expiry dates, the share complete per business unit and per module, the people overdue with the days, the new joiners past their onboarding window, and the identity that every required assignment is complete, overdue or not yet due.
16 Sept 20262 min readHow compliance teams should choose analytics software: start from the questions, check the data you hold, ask vendors ten questions, avoid the traps.
24 Sept 20264 min readA checklist for anyone about to put a customer ledger, a CRM export or a contract file into an AI analytics tool. It covers what is actually in a sales export that makes it sensitive, the nine questions to put to any vendor, covering model training, where data is processed, who at the vendor can see it, retention and deletion, tenancy, pseudonymisation, access control, the model provider behind the tool, and what happens at exit, what a good answer sounds like for each, and how to reduce the risk yourself by removing what the analysis does not need.
17 Sept 20265 min readThe ten KPIs a compliance function should run on, each with its formula, the export it comes from and what it tells you: obligation to control coverage, regulatory change coverage, control testing on schedule, test failure rate and repeat failures, issue ageing by owner, training completion against role requirement, incident reporting against activity, policy attestation, time to close findings, and evidence completeness. Also the three measures most compliance teams miss, the figures to drop, the identities, and who owns what.
17 Sept 20264 min readThe complete obligation-to-control coverage calculation on ten obligations, small enough to check by hand: each obligation's rating and business unit from the register, the controls mapped to it, the control's testing frequency and last test date, whether the control is on cadence, the obligation's state, covered by a control on cadence, covered by a slipped control, mapped to a retired control, or unmapped, coverage by unit and by rating, the change backlog for the two obligations from this year's regulatory changes, and the assertion that the states sum to ten, so a reader can reproduce every figure and then run it on their own registers.
17 Sept 20264 min readControl coverage analytics for compliance teams. Every obligation, every control, every test.
See the page