Skip to content

Journey: Regulation to Compliance

A single obligation, followed from the moment a regulator publishes to the moment the organisation can state and defend its position.

Fictional example. The bank, the circular and all record references are illustrative.


The situation

A prudential supervisor publishes a circular amending outsourcing requirements. Among its provisions:

"Institutions shall restrict, monitor and periodically review privileged access to systems supporting outsourced critical functions."


Week 1 — Detection and triage

Monday. The tenant's scheduled sweep checks nine registered regulatory sources. One returns a change: a new circular on the supervisor's circulars feed.

Tuesday. The event appears in the change feed with an AI summary noting it appears to amend outsourcing notification thresholds and access control requirements.

A Compliance Analyst opens the circular and reads it. The summary is broadly right and misses a transitional provision giving existing arrangements six months.

She accepts the event with the reason:

"Amends material outsourcing notification thresholds and adds privileged access requirements for outsourced critical functions. Transitional provision gives existing arrangements six months. Sending to extraction; transitional deadline to be captured."

What exists now: a triaged change event with a recorded human decision. No obligations.


Week 1 — Extraction

Wednesday. The accepted event goes to Smart Extract. Extraction proposes 47 candidates.

Thursday and Friday. The analyst reviews every candidate:

OutcomeCount
Published as-is22
Published after editing9
Merged, 6 into 33
Split, 3 into 66
Rejected7
Published40

Among the 40 is PA-4.2 — Privileged access restriction and review for outsourced critical functions, which the analyst split from a clause that also covered monitoring.

The transitional compliance date is captured as a deadline.

What exists now: 40 requirements in the library. No applicability, no ownership, no compliance position.


Week 2 — Scope and adoption

The circular applies to systems supporting outsourced critical functions. The bank already holds SCP-2026-0004 — Core Banking Production with 38 effective-dated members.

The Head of Compliance creates Framework Adoption FAD-2026-0009, binding the circular to that scope for the purpose of regulatory filing.

Adoption seeds 40 applicability records, all Under Review, all governance state draft.

What exists now: an adoption and 40 undetermined applicability records.


Weeks 2 to 4 — Applicability

The Compliance Analyst works through each requirement.

For PA-4.2 she records Applicable — the bank operates outsourced critical functions on systems in this scope.

For eleven others she records Not Applicable with justifications. One reads:

"The institution does not operate a proprietary trading platform. This clause applies to outsourced arrangements supporting trading activity, of which the institution has none. Confirmed with the Head of Markets, March 2026."

The Compliance Manager reviews each. She rejects one proposed exclusion:

"Provider responsibility does not remove our obligation. This is Applicable, discharged through provider assurance evidence."

The analyst revises it and it is approved.

Final position: 30 Applicable, 10 Not Applicable, all approved.

What exists now: an authoritative applicability position. Nothing is implemented.


Week 4 — Ownership

The Compliance Manager makes ownership offers by department through the Requirements register. PA-4.2 is offered to the Head of IT Security, who accepts through his Workbench.

The acceptance step is not administrative

An owner who never agreed to own something is not an owner in any sense a supervisor would accept. The offer-and-accept handshake turns a field into an accountability record with a timestamp.


Weeks 5 to 6 — Mapping

The analyst runs control discovery against PA-4.2 and then an AI proposal pass. Three proposals result:

ControlProposed asReviewed as
CTL-2026-0041 MFA Standardequivalentsubset
CTL-2026-0044 Privileged Access Managementequivalentequivalent
CTL-2026-0019 Network Access Controlrelatedno_match

The Compliance Manager adjusts two:

  • MFA covers authentication strength, not restriction and periodic review. subset.
  • Network segmentation is a different control objective. Recording no_match prevents the same suggestion recurring every quarter.

What exists now: two approved mappings. Mapping is not compliance — nothing about the bank's actual position has changed.


Weeks 6 to 8 — Evidence

Three expected evidence requirements are defined on CTL-2026-0044 and accepted by a second person:

ExpectationCadence
Daily privileged access state per accountDaily
Quarterly recertification per in-scope systemQuarterly
Annual attestation by the Head of IT SecurityAnnual

A connection to the identity platform already exists. A collector is defined to read privileged access state daily.

The first run resolves 214 of 214 accounts and produces 214 assertions.


Week 8 — Indicators

Indicator IND-2026-0009 is defined on CTL-2026-0044: rule all_pass, mandatory, daily, scoped to SCP-2026-0012 with 214 members.

First evaluation:

MetricValue
Expected214
Observed, fresh214
Pass211
Fail3
Coverage100%
Resultfail

Derived control effectiveness: ineffective — a mandatory indicator failed. It cannot be averaged away.


Week 8 — Determination

Requirement assurance for PA-4.2:

DimensionValue
ApplicabilityApplicable, approved
Evidence statuscurrent
Evidence coverage100%, 214 of 214
Control effectivenessineffective
Requirement satisfactionnot_satisfied
Governance dispositionremediation_required
Review statemanual_review_required

Note that coverage is complete and evidence is fresh. The obligation is still not satisfied, because a mapped implementing control is ineffective.


Weeks 8 to 13 — Remediation

Finding FND-2026-0071 is raised. Action plan ACT-2026-0188 follows: owner IT Security Operations, approver the Compliance Manager, verifier a Senior Compliance Analyst.

Two accounts are remediated by day 18. The third is a service account requiring a vendor protocol change, so exception EXC-2026-0031 is requested.

The CRO returns it: the compensating controls are described but the session review cadence is not stated. Resubmitted with the cadence specified, it is approved for 90 days with a reassessment at day 75.

Determination after the exception:

DimensionValue
Requirement satisfactionnot_satisfied — unchanged
Governance dispositionaccepted_deviation, referencing EXC-2026-0031

The exception did not satisfy the obligation

Satisfaction stays not_satisfied. The disposition records that the organisation formally accepted a deviation, with an approver, an expiry and a reassessment date.

A platform that flipped this to satisfied would be hiding a live gap behind an approval.

Closure: the action plan is verified at day 34 — the verifier confirms the indicator passes for the two remediated accounts and the third is covered. The finding closes.


What the position looks like at week 13

ElementState
RequirementPA-4.2, owned and accepted
ApplicabilityApplicable, approved
Mappings2 approved, 1 recorded as no-match
EvidenceDaily collector, quarterly recertification, annual attestation
Coverage100%
Effectivenessineffective
Satisfactionnot_satisfied
Dispositionaccepted_deviation, expiring in 90 days
FindingClosed
Action planCompleted and verified

What the board pack says: one obligation with an accepted deviation, an approver, a compensating control and an expiry date. Not a green tick, and not an unexplained red one.

What an assessor can reconstruct: every step above, as of any date, with the actor and timestamp on each.


The elapsed time

Thirteen weeks from publication to a defensible governed position, of which roughly two were extraction and applicability, three were mapping and evidence, and five were remediation.

The five weeks of remediation is the honest part. The obligation was genuinely unmet for that period, and the record says so.


OrviQ Enterprise Governance, Risk & Compliance Platform