Appearance
Journey: Regulation to Compliance
A single obligation, followed from the moment a regulator publishes to the moment the organisation can state and defend its position.
Fictional example. The bank, the circular and all record references are illustrative.
The situation
A prudential supervisor publishes a circular amending outsourcing requirements. Among its provisions:
"Institutions shall restrict, monitor and periodically review privileged access to systems supporting outsourced critical functions."
Week 1 — Detection and triage
Monday. The tenant's scheduled sweep checks nine registered regulatory sources. One returns a change: a new circular on the supervisor's circulars feed.
Tuesday. The event appears in the change feed with an AI summary noting it appears to amend outsourcing notification thresholds and access control requirements.
A Compliance Analyst opens the circular and reads it. The summary is broadly right and misses a transitional provision giving existing arrangements six months.
She accepts the event with the reason:
"Amends material outsourcing notification thresholds and adds privileged access requirements for outsourced critical functions. Transitional provision gives existing arrangements six months. Sending to extraction; transitional deadline to be captured."
What exists now: a triaged change event with a recorded human decision. No obligations.
Week 1 — Extraction
Wednesday. The accepted event goes to Smart Extract. Extraction proposes 47 candidates.
Thursday and Friday. The analyst reviews every candidate:
| Outcome | Count |
|---|---|
| Published as-is | 22 |
| Published after editing | 9 |
| Merged, 6 into 3 | 3 |
| Split, 3 into 6 | 6 |
| Rejected | 7 |
| Published | 40 |
Among the 40 is PA-4.2 — Privileged access restriction and review for outsourced critical functions, which the analyst split from a clause that also covered monitoring.
The transitional compliance date is captured as a deadline.
What exists now: 40 requirements in the library. No applicability, no ownership, no compliance position.
Week 2 — Scope and adoption
The circular applies to systems supporting outsourced critical functions. The bank already holds SCP-2026-0004 — Core Banking Production with 38 effective-dated members.
The Head of Compliance creates Framework Adoption FAD-2026-0009, binding the circular to that scope for the purpose of regulatory filing.
Adoption seeds 40 applicability records, all Under Review, all governance state draft.
What exists now: an adoption and 40 undetermined applicability records.
Weeks 2 to 4 — Applicability
The Compliance Analyst works through each requirement.
For PA-4.2 she records Applicable — the bank operates outsourced critical functions on systems in this scope.
For eleven others she records Not Applicable with justifications. One reads:
"The institution does not operate a proprietary trading platform. This clause applies to outsourced arrangements supporting trading activity, of which the institution has none. Confirmed with the Head of Markets, March 2026."
The Compliance Manager reviews each. She rejects one proposed exclusion:
"Provider responsibility does not remove our obligation. This is Applicable, discharged through provider assurance evidence."
The analyst revises it and it is approved.
Final position: 30 Applicable, 10 Not Applicable, all approved.
What exists now: an authoritative applicability position. Nothing is implemented.
Week 4 — Ownership
The Compliance Manager makes ownership offers by department through the Requirements register. PA-4.2 is offered to the Head of IT Security, who accepts through his Workbench.
The acceptance step is not administrative
An owner who never agreed to own something is not an owner in any sense a supervisor would accept. The offer-and-accept handshake turns a field into an accountability record with a timestamp.
Weeks 5 to 6 — Mapping
The analyst runs control discovery against PA-4.2 and then an AI proposal pass. Three proposals result:
| Control | Proposed as | Reviewed as |
|---|---|---|
CTL-2026-0041 MFA Standard | equivalent | subset |
CTL-2026-0044 Privileged Access Management | equivalent | equivalent |
CTL-2026-0019 Network Access Control | related | no_match |
The Compliance Manager adjusts two:
- MFA covers authentication strength, not restriction and periodic review.
subset. - Network segmentation is a different control objective. Recording
no_matchprevents the same suggestion recurring every quarter.
What exists now: two approved mappings. Mapping is not compliance — nothing about the bank's actual position has changed.
Weeks 6 to 8 — Evidence
Three expected evidence requirements are defined on CTL-2026-0044 and accepted by a second person:
| Expectation | Cadence |
|---|---|
| Daily privileged access state per account | Daily |
| Quarterly recertification per in-scope system | Quarterly |
| Annual attestation by the Head of IT Security | Annual |
A connection to the identity platform already exists. A collector is defined to read privileged access state daily.
The first run resolves 214 of 214 accounts and produces 214 assertions.
Week 8 — Indicators
Indicator IND-2026-0009 is defined on CTL-2026-0044: rule all_pass, mandatory, daily, scoped to SCP-2026-0012 with 214 members.
First evaluation:
| Metric | Value |
|---|---|
| Expected | 214 |
| Observed, fresh | 214 |
| Pass | 211 |
| Fail | 3 |
| Coverage | 100% |
| Result | fail |
Derived control effectiveness: ineffective — a mandatory indicator failed. It cannot be averaged away.
Week 8 — Determination
Requirement assurance for PA-4.2:
| Dimension | Value |
|---|---|
| Applicability | Applicable, approved |
| Evidence status | current |
| Evidence coverage | 100%, 214 of 214 |
| Control effectiveness | ineffective |
| Requirement satisfaction | not_satisfied |
| Governance disposition | remediation_required |
| Review state | manual_review_required |
Note that coverage is complete and evidence is fresh. The obligation is still not satisfied, because a mapped implementing control is ineffective.
Weeks 8 to 13 — Remediation
Finding FND-2026-0071 is raised. Action plan ACT-2026-0188 follows: owner IT Security Operations, approver the Compliance Manager, verifier a Senior Compliance Analyst.
Two accounts are remediated by day 18. The third is a service account requiring a vendor protocol change, so exception EXC-2026-0031 is requested.
The CRO returns it: the compensating controls are described but the session review cadence is not stated. Resubmitted with the cadence specified, it is approved for 90 days with a reassessment at day 75.
Determination after the exception:
| Dimension | Value |
|---|---|
| Requirement satisfaction | not_satisfied — unchanged |
| Governance disposition | accepted_deviation, referencing EXC-2026-0031 |
The exception did not satisfy the obligation
Satisfaction stays not_satisfied. The disposition records that the organisation formally accepted a deviation, with an approver, an expiry and a reassessment date.
A platform that flipped this to satisfied would be hiding a live gap behind an approval.
Closure: the action plan is verified at day 34 — the verifier confirms the indicator passes for the two remediated accounts and the third is covered. The finding closes.
What the position looks like at week 13
| Element | State |
|---|---|
| Requirement | PA-4.2, owned and accepted |
| Applicability | Applicable, approved |
| Mappings | 2 approved, 1 recorded as no-match |
| Evidence | Daily collector, quarterly recertification, annual attestation |
| Coverage | 100% |
| Effectiveness | ineffective |
| Satisfaction | not_satisfied |
| Disposition | accepted_deviation, expiring in 90 days |
| Finding | Closed |
| Action plan | Completed and verified |
What the board pack says: one obligation with an accepted deviation, an approver, a compensating control and an expiry date. Not a green tick, and not an unexplained red one.
What an assessor can reconstruct: every step above, as of any date, with the actor and timestamp on each.
The elapsed time
Thirteen weeks from publication to a defensible governed position, of which roughly two were extraction and applicability, three were mapping and evidence, and five were remediation.
The five weeks of remediation is the honest part. The obligation was genuinely unmet for that period, and the record says so.