How to Build a Regulatory Change Management Programme for Client Funds
Why Regulatory Change Management Is a Programme, Not a Project
Regulatory change is continuous. PS25 is being implemented. PSD3 is advancing through the EU legislative process. MiCA's Level 2 technical standards are still being finalised. The GENIUS Act's implementing regulations have not yet been issued. And behind each of these headline changes are dozens of supervisory statements, guidance notes, and technical amendments that affect operational compliance.
A firm that treats each regulatory change as an isolated project, mobilising resources when a new requirement is published, then disbanding until the next one, will always be reactive. The alternative is a standing regulatory change management programme: a defined process for identifying, assessing, implementing, and evidencing response to regulatory change on a continuous basis.
Stage 1: Identification: Horizon Scanning
The first stage of any regulatory change management programme is systematic identification of relevant regulatory developments. This requires monitoring the sources described in the horizon scanning article, regulator publications, legislative trackers, trade body updates, and enforcement trends, on a continuous basis.
The identification process should be structured: each identified development should be logged with its source, date, summary, and preliminary relevance assessment. This log becomes the input for the next stage, impact assessment, and the basis for board reporting on the regulatory pipeline.
Technology-assisted monitoring is strongly recommended for firms subject to multiple frameworks or operating across jurisdictions. The volume of regulatory output makes manual monitoring unreliable, and the consequences of missing a relevant development can be significant.
Stage 2: Impact Assessment
Not every regulatory development requires action. The impact assessment stage determines which identified changes affect the firm, how significantly, and on what timeline.
A structured impact assessment should evaluate: applicability (does this change apply to our firm, given our authorisations, activities, and jurisdictions?); materiality (how significant is the operational, financial, or risk impact?); timeline (when does the change take effect, and what is the realistic implementation timeline?); and dependencies (does implementation require changes to systems, processes, third-party arrangements, or governance structures?).
The output of impact assessment should be a prioritised implementation plan, ranked by timeline urgency and materiality, that can be presented to the board for resource allocation and sign-off.
Stage 3: Implementation and Testing
Implementation is where most regulatory change management programmes fail, not for lack of awareness, but for lack of capacity. Compliance teams that spend their time on operational tasks (daily reconciliation, exception management, report production) often lack the bandwidth to implement significant changes alongside their day-to-day responsibilities.
The most effective approach is to treat implementation as a workstream within the compliance programme, with defined ownership, milestones, and reporting, rather than an additional responsibility layered on top of existing workloads. This may require temporary additional resource, or it may require automation of routine operational tasks to free existing resource for implementation work.
Testing is a critical and often neglected step. Before a regulatory change takes effect, the firm should verify that its systems, processes, and controls have been updated correctly. This is particularly important for changes that affect reconciliation methodology, breach notification procedures, or reporting formats, where an implementation error could result in a compliance failure from Day 1 of the new regime.
Stage 4: Evidence and Board Reporting
The final stage is documenting the firm's response to each regulatory change, creating an evidence record that demonstrates the change was identified, assessed, implemented, and tested. This evidence is valuable in supervisory reviews: it demonstrates governance maturity and proactive compliance management.
Board reporting on regulatory change should be integrated with the broader governance reporting cycle. The board should receive regular updates on the regulatory pipeline (Stage 1 outputs), material impact assessments (Stage 2 outputs), implementation progress (Stage 3 status), and post-implementation confirmation (Stage 4 evidence).
This end-to-end evidence trail, from identification through implementation, demonstrates the kind of systematic regulatory change management that regulators expect from well-governed firms.
How Safeheld Supports Regulatory Change Management
Safeheld provides the identification layer (continuous horizon scanning and regulatory monitoring) and the evidence layer (automated documentation of the firm's response to regulatory change) of a comprehensive change management programme.
Regulatory developments identified through horizon scanning are logged in the platform with materiality assessments and implementation tracking. Board reports are generated automatically, summarising the regulatory pipeline, implementation status, and any outstanding actions. The result is a standing change management programme, not a series of ad hoc responses, that demonstrates governance maturity to regulators and the board alike.