Session Three: Delivering Regulatory Change

Session Three: Delivering Regulatory Change — Transformation Delivery for Financial Services

Transformation Delivery for Financial Services

A Practitioner's Course

Session Three

Delivering Regulatory Change

What makes regulatory change different from discretionary transformation, and why that difference should shape scope, planning, and governance from the outset

Session Three: Delivering Regulatory Change

A significant proportion of transformation in financial services is not discretionary. It is driven by a regulatory obligation: a new requirement, a supervisory expectation, or an enforcement outcome that requires the organisation to change how it operates. Regulatory change delivery deserves its own session because it has characteristics that make it more demanding than other types of transformation, and the organisations that handle it well understand those characteristics from the outset rather than applying a generic delivery approach and hoping it holds.

Three constraints that define regulatory change

The deadline is fixed and externally imposed

A discretionary programme that runs into difficulty can extend its date, descope, or phase the release. A regulatory programme generally cannot. The regulator sets the deadline, and missing it has consequences ranging from supervisory action through to enforcement and, in the most serious cases, personal consequences for senior managers. The UK's implementation of Basel 3.1, in force from 1 January 2027, is a useful illustration: the date has already been deferred once, from an earlier proposed start, but firms cannot assume a further deferral and must plan against the confirmed date.

The scope is defined by someone else

In discretionary transformation, the organisation decides what it is doing and can adjust scope as it learns. In regulatory change, the scope is defined by the regulation. The organisation's task is to interpret what the regulation requires and translate that into operational and technical change, and that interpretation is harder than it looks. The most expensive mistakes in regulatory change happen at the scoping stage, when an organisation interprets a requirement narrowly, broadly, or wrongly, and builds against that interpretation. By the time the gap surfaces, design decisions have been made and systems configured, and rework is expensive.

The consequences of failure are not just commercial

A discretionary programme that overruns produces a commercial consequence: a delayed benefit, a written-off cost. A regulatory programme that fails produces a regulatory breach, and in the UK, the Duty of Responsibility under section 66A of the Financial Services and Markets Act 2000 means a senior manager may be held accountable if they did not take the steps a person in their position could reasonably be expected to take. That distinction changes how risk should be treated and how governance should be designed, and it is why Session Two's point about active sponsorship carries particular weight in a regulatory programme.

Getting the scope right

Reading the regulation is the first task of any regulatory change programme, and it is the step organisations most consistently rush. Getting the interpretation right requires genuine cross-functional engagement before the programme plan is agreed: legal and compliance to interpret the regulation, operations to understand the current-state processes affected, technology to assess the required system changes, and risk to identify what the obligation means for the firm's risk profile.

Regulatory programmes also need to track guidance actively. Regulators publish consultation papers, supervisory statements, and clarifications that refine what they expect after the primary obligation is set. A programme scoped against an initial reading of the regulation may need adjusting as that guidance develops, and the programme needs a mechanism to monitor developments and assess their impact on scope.

Operational readiness is not the same as technical delivery

Regulatory change programmes typically need the organisation to be operationally ready before the deadline, not just technically compliant. A system might be built, but if the people who need to use it are not trained, the surrounding processes are not documented, and the organisation has not tested that it can operate effectively in the new way, it is not ready.

Operational readiness assessment is one of the most consistently underinvested elements of regulatory change delivery. Programmes that run well technically often stumble at implementation because the organisation has not done the work to prepare people and processes for the change. This is particularly true where the change affects customer-facing processes, where staff need to understand not just what they are doing differently but why, so they can handle edge cases and exceptions with judgement rather than a script.

The FCA's operational resilience rules give a concrete example of what operational readiness means in practice: firms in scope had to complete mapping and testing of their important business services by 31 March 2025, so they could demonstrate, not merely assert, that they could remain within agreed impact tolerances, including through periods of significant change.

Regulatory change in a multi-programme environment

Most large financial institutions run several regulatory change programmes simultaneously, alongside technology-led and customer-led transformation, competing for the same resources and leadership attention. Organisations that manage this well maintain a clear view of their portfolio: which programmes are in flight, what resources they are consuming, and where genuine conflicts exist for the same limited resource.

A regulatory deadline creates a prioritisation driver, but it is not always straightforward. When two regulatory deadlines conflict for the same resource, a decision needs to be made at an appropriate level, with the right information and authority. That is a governance question, not something an individual programme manager should have to negotiate informally with a peer.

Jurisdiction equivalents

New Zealand

New Zealand's Conduct of Financial Institutions regime is a clear domestic example of a fixed-deadline, externally scoped regulatory change programme. Financial institutions had to establish an approved fair conduct programme meeting the minimum requirements in section 446J of the Financial Markets Conduct Act 2013 before applying for a licence, with the regime coming into force in 2025. Session Eight returns to CoFI in detail, using the handover from build to ongoing operation as its worked example.

Australia

Australia's Financial Accountability Regime illustrates a different scoping discipline: a staged commencement, with authorised deposit-taking institutions brought in first on 15 March 2024 and insurance entities and superannuation trustees following twelve months later on 15 March 2025. That staging gave the regulators time to observe implementation in one sector before extending obligations to others, and gave firms in the later cohort a working precedent to scope against, an approach worth considering wherever a regulatory programme can be sequenced rather than delivered all at once.

Coming up in Session Four

Session Four covers change management as a delivery discipline rather than a workstream: the ADKAR model as a diagnostic, stakeholder mapping under personal accountability regimes, and why training in a regulated environment carries evidential weight. Continue to Session Four.

Further reading and resources

Financial Services and Markets Act 2000, section 66A. The Duty of Responsibility and its consequences for senior managers where a firm breaches a regulatory requirement in their area. Available at legislation.gov.uk.

FCA Policy Statement PS21/3 and PRA Supervisory Statement SS1/21. Operational resilience rules, including the requirement to map and test important business services by 31 March 2025. Available at fca.org.uk and bankofengland.co.uk.

PRA Policy Statement PS1/26. Final Basel 3.1 rules, in force from 1 January 2027. Available at bankofengland.co.uk.

Financial Markets Conduct Act 2013, Subpart 6A. The Conduct of Financial Institutions regime and its minimum programme requirements. Available at legislation.govt.nz.

Financial Accountability Regime commencement materials. APRA and ASIC guidance on the staged commencement for banking, insurance, and superannuation entities. Available at apra.gov.au and asic.gov.au.

Regulatory Change Delivery in Financial Services. The published Ārai Tika guide this session draws on, with a fuller treatment of reading the regulation, planning backwards from a fixed deadline, and evidencing compliance. Available at araitika.com.

Ārai Tika