Sign in

Blog · Industry

Compliance: guides and articles

Which obligations have no mapped control. Which entities have not been reviewed inside their cycle. Which controls were tested, which failed, and which have never been tested at all. From the obligations register, the control library and the testing log, reconciled so the board pack and the regulator see the same numbers.

Coverage and territory · Compliance

Incident reporting against activity: the unit that reports nothing is not the safest one

How a compliance team reads its incident and near-miss reports against the activity that produces them, from the incident register and the activity data: reports per unit of activity, transactions, trades, accounts opened, the units well below the firm's own rate, the rate against the unit's audit findings, why a low reporting rate with high findings is a culture measure, and the list of units where the register is quiet and the evidence is not.

16 Sept 20262 min read
Board and management reporting · Compliance

Issue ageing by owner: open findings past their remediation date

How a compliance or internal audit team reports the findings that are open past their agreed remediation date, from the issue register: ageing bands per owner and business unit, the extensions granted and how many times, the high-rated issues past date, and the trend that shows a remediation programme slipping before the board asks why the same finding is on the pack for the third quarter.

16 Sept 20263 min read
Coverage and territory · Compliance

Obligation-to-control coverage, asserted: the compliance roll-up

How a compliance function measures control coverage from the obligations register, the control library and the testing log: obligations with no mapped control, controls past their test date, entities outside their review cycle, and the reconciliation that lets the board pack and the regulator see one number.

16 Sept 20263 min read
Coverage and territory · Compliance

Regulatory change coverage: new obligations with no control mapped yet

How a compliance team tracks the gap between regulatory change and control coverage from its own obligation register and change log: obligations added or amended per period, the days each has been live with no mapped control, the business units where unmapped obligations concentrate, the ageing of the mapping backlog, and the identity that every obligation is either mapped, in progress or unmapped with a date.

16 Sept 20262 min read
Coverage and territory · Compliance

Ten questions a head of compliance asks, and the table that answers each

The ten questions a head of compliance puts to the business units and the compliance team, which obligations have no control, which controls were not tested on schedule, which findings are past their date and how many times extended, which regulatory changes have no mapping yet, who is overdue on training, which units report nothing, which high-rated issues are open, what will a regulator find first, what did the last audit find that the register did not, and what changed, each with the table from the registers, the identity behind it, and the answer to send back.

16 Sept 20262 min read
Board and management reporting · Compliance

Testing cadence: controls tested on schedule, and the ones that slipped

How a compliance team measures whether each control was tested when its plan said it would be, from the control register and the testing log: cadence adherence per control owner and business unit, the slipped-test list ranked by the risk the control covers, and the trend that shows a testing programme quietly falling behind before the regulator asks.

16 Sept 20262 min read
Coverage and territory · Compliance

Training completion against role requirement: who is overdue, by unit

How a compliance team measures mandatory training coverage from the learning system export and the HR roster: each person's required modules from their role, completions and expiry dates, the share complete per business unit and per module, the people overdue with the days, the new joiners past their onboarding window, and the identity that every required assignment is complete, overdue or not yet due.

16 Sept 20262 min read
Alternatives and comparisons · Compliance

How to choose analytics software for compliance: questions, data and traps

How compliance teams should choose analytics software: start from the questions, check the data you hold, ask vendors ten questions, avoid the traps.

24 Sept 20264 min read
AI and self-service analytics · Compliance

Is it safe to upload customer data to an AI analytics tool? Nine questions to ask first

A checklist for anyone about to put a customer ledger, a CRM export or a contract file into an AI analytics tool. It covers what is actually in a sales export that makes it sensitive, the nine questions to put to any vendor, covering model training, where data is processed, who at the vendor can see it, retention and deletion, tenancy, pseudonymisation, access control, the model provider behind the tool, and what happens at exit, what a good answer sounds like for each, and how to reduce the risk yourself by removing what the analysis does not need.

17 Sept 20265 min read
Board and management reporting · Compliance

KPIs for compliance teams: ten measures that matter, each with its formula and the export it comes from

The ten KPIs a compliance function should run on, each with its formula, the export it comes from and what it tells you: obligation to control coverage, regulatory change coverage, control testing on schedule, test failure rate and repeat failures, issue ageing by owner, training completion against role requirement, incident reporting against activity, policy attestation, time to close findings, and evidence completeness. Also the three measures most compliance teams miss, the figures to drop, the identities, and who owns what.

17 Sept 20264 min read
Coverage and territory · Compliance

Obligation coverage on ten obligations: the whole arithmetic on one page

The complete obligation-to-control coverage calculation on ten obligations, small enough to check by hand: each obligation's rating and business unit from the register, the controls mapped to it, the control's testing frequency and last test date, whether the control is on cadence, the obligation's state, covered by a control on cadence, covered by a slipped control, mapped to a retired control, or unmapped, coverage by unit and by rating, the change backlog for the two obligations from this year's regulatory changes, and the assertion that the states sum to ten, so a reader can reproduce every figure and then run it on their own registers.

17 Sept 20264 min read
Covirage for Compliance

Control coverage analytics for compliance teams. Every obligation, every control, every test.

See the page