Regulatory Change Management
Track regulatory change from horizon-scan to implemented control
Capture regulatory developments, assess their impact on your obligations, policies and controls, and drive the resulting changes to completion with owners and deadlines — so regulatory change becomes a managed pipeline rather than a scramble. OnyxOne Regulatory Change Management gives compliance teams one place to see what is coming, decide what it means for the firm, and prove that every applicable change was assessed and implemented before it took effect.
How it works, visually
How an obligation or event is triaged, escalated when it matters, and recorded either way.
The problems this module solves
The operational realities that make this hard for compliance and risk teams today.
Change is spotted late and inconsistently
Regulatory developments arrive through newsletters, alerts, advisers and word of mouth, landing in different inboxes with no shared record. Something material is missed or noticed late, and the firm is implementing a change under time pressure that it could have planned for months earlier.
Impact assessment is ad hoc and undocumented
When a change is noticed, working out what it means — which obligations, policies and controls it touches — happens informally in email and meetings. The reasoning isn't captured, so the same analysis is redone later and there is no record of why the firm concluded a change did or didn't apply.
Nothing connects a rule change to what must change
A new requirement should trigger updates to specific obligations, policies and controls, but those live in other systems. Without a link, implementation relies on someone remembering every downstream artefact a change affects, and things get missed.
Implementation isn't tracked to a deadline
A change is accepted, actions are handed out, and then visibility evaporates. Nobody can say with confidence whether every required update will be done before the rule takes effect, and the first sign of a slipped deadline is often the effective date itself.
There's no audit trail of how change was handled
When a regulator asks how the firm identified, assessed and implemented a particular change, the answer is scattered across emails and documents. Demonstrating a controlled, timely response is slow and the evidence has gaps.
How OnyxOne addresses it
One intake for every regulatory development
Capture regulatory changes — from horizon-scanning feeds, regulator publications, advisers or internal spotting — into a single pipeline with source, date, jurisdiction and theme. Nothing depends on the right person seeing the right email; every development lands in one governed queue with an owner.
Structured, recorded impact assessment
Each development is triaged and assessed against the firm's obligations, policies and controls, with the reasoning captured — including a documented conclusion where a change is judged not to apply. The assessment is a durable record, not a conversation, so it stands up to challenge and isn't redone.
Change linked to the artefacts it affects
An applicable change links directly to the specific obligations, policies and controls it touches. Implementation follows the actual downstream artefacts rather than someone's memory, so every affected policy and control is accounted for.
Implementation driven to the effective date
Required updates become tracked actions with owners, milestones and target dates anchored to the change's effective date. Progress is visible, slippage is surfaced early, and the firm can see well in advance whether it will be ready in time.
A complete, evidenced change record
From first capture through assessment, decision and implementation, every step is recorded. The firm can show, for any change, how it was identified, what it decided and why, who did the work and when it completed — a controlled response evidenced end to end.
What's in the module
Turn on what you need and add more as your programme scales.
Change intake pipeline
One queue for regulatory developments from horizon-scanning feeds, publications, advisers and internal spotting, each owned and triaged.
Horizon scanning
Capture and categorise forthcoming and proposed changes by jurisdiction, theme and effective date before they take effect.
Impact assessment
Structured, recorded assessment of each change against obligations, policies and controls, including reasoned not-applicable decisions.
Applicability triage
Route and prioritise developments by relevance to the firm's products, jurisdictions and business units.
Artefact linkage
Link an applicable change to the specific obligations, policies and controls it affects for accurate implementation.
Implementation planning
Turn required updates into tracked actions with owners, milestones and deadlines anchored to the effective date.
Deadline management
Track implementation against effective dates, surfacing at-risk and overdue work early.
Decision & rationale capture
Record decisions and their reasoning, including why a change was judged not to apply, as durable evidence.
Obligation-library sync
Push accepted changes into the obligations library so what the firm must do stays current.
Immutable change trail
Every capture, assessment, decision and action is written to an append-only audit record.
The views your team works from
Purpose-built dashboards and views, each answering a question a specific role needs to act on.
A representative layout of the KPI tiles and charts these dashboards present. Figures shown are illustrative examples, not real data.
Change pipeline
Every regulatory development by status, theme and jurisdiction, from capture through assessment to implemented, with owners.
Horizon scan
Forthcoming and proposed changes on a timeline by effective date, so the firm sees what is coming and when.
Impact assessment board
Assessments in progress and completed, with applicability decisions, rationale and the artefacts each change affects.
Implementation tracker
Implementation actions against effective dates, with at-risk and overdue work surfaced early.
Change evidence view
The end-to-end record for any development — capture, assessment, decision, actions — assembled as examination-ready evidence.
What the platform automates
Rules, workflows, alerts and scheduling that run the routine so your team works the exceptions.
Feed intake & routing
Developments from connected horizon-scanning sources are captured into the pipeline and routed to owners by theme and jurisdiction.
Deadline countdown alerts
Implementation actions are tracked against effective dates and flagged as at-risk before they slip, not after.
Artefact-review flags
When a change is linked to a policy or control, the owners of those artefacts are notified that a review is required.
Obligation-library sync
Accepted changes update or create obligations in the compliance library and flag affected mappings automatically.
Action reminders & escalation
Implementation actions are reminded before they fall due and escalated when they slip past target.
Where AI helps the analyst
Assistive, decision-support features that speed up the work on the record. Suggestions are always reviewable, and a person stays in control of every decision.
Development summarisation
Drafts a concise summary of a captured regulatory development from its source text, which the compliance owner reviews before it informs the assessment.
Impact-suggestion assistance
Suggests which existing obligations, policies and controls a change may affect based on similarity, for a person to confirm — it never decides applicability on its own.
Implementation-plan drafting
Proposes a first-cut set of implementation actions from the assessed impact, leaving owners, deadlines and scope to be set and owned by a person.
The enterprise workflow
A defined, end-to-end process with clear ownership at every stage.
Every result, decision and override is captured against the record it belongs to.
Capture
Regulatory developments are captured into one pipeline with source, jurisdiction, theme and effective date, each assigned an owner.
Triage applicability
Each development is triaged for relevance to the firm's products, jurisdictions and units, and prioritised accordingly.
Assess impact
Applicable changes are assessed against obligations, policies and controls, with the reasoning and conclusion documented.
Link affected artefacts
The change is linked to the specific obligations, policies and controls it touches so nothing downstream is missed.
Implement to deadline
Required updates become tracked actions with owners and target dates anchored to the effective date and driven to completion.
Evidence & sync
The full change record stands as evidence, and accepted changes update the obligations library so it stays current.
What your team gains
A pipeline, not a scramble
One intake and a defined workflow turn regulatory change from a stream of missed emails into a governed pipeline the firm can plan against.
Assessments that stand up
Recorded impact assessments — including reasoned not-applicable decisions — mean the firm can defend how it judged every change.
Nothing downstream is missed
Linking a change to the exact obligations, policies and controls it affects means implementation follows the artefacts, not someone's memory.
Ready before the effective date
Actions anchored to effective dates with early slippage warnings mean the firm sees whether it will be ready in time, not on the day.
A complete change audit trail
Every step from capture to implementation is recorded, so demonstrating a controlled, timely response is a report rather than a reconstruction.
An obligations library that stays current
Accepted changes flow into the obligations library, so the firm's record of what it must do keeps pace with the rules.
Industries it serves
Works with your existing systems
Described as capabilities — OnyxOne connects to the systems your deployment requires, configured per implementation.
- Pushes accepted changes into the compliance-management obligations library and flags the mappings that need review
- Links changes to the affected policies and controls so implementation updates the right artefacts in policy management and internal controls
- Draws on and updates the regulatory knowledge base so the underlying rules and interpretation stay aligned
- Ingests regulatory developments from your existing horizon-scanning and regulatory-intelligence sources into one pipeline
- Routes assessment tasks, implementation actions and deadline alerts through your existing email and messaging channels
Security, compliance & reporting
Security & data handling
- Change records, assessments and implementation actions are encrypted in transit and at rest, with access governed by role-based permissions.
- Sensitive assessment detail can be restricted to named compliance and oversight roles.
- Segregation of duties can prevent the same person from both assessing and signing off a change where policy requires it.
- Every capture, assessment, decision and action is written to an append-only audit trail.
- Retention of change records and impact assessments is configurable to your regulatory obligations.
Compliance support
- Supports the regulatory-change and horizon-scanning expectations placed on regulated firms
- Provides documented impact-assessment and implementation evidence for regulatory examination
- Keeps the compliance obligations library aligned to current and forthcoming rules
- Underpins the compliance layer of a three-lines-of-defence model
- Supplies a dated, end-to-end audit trail of how each change was handled
Reports & exports
- Regulatory change pipeline by status, theme and jurisdiction
- Horizon-scan report of forthcoming changes by effective date
- Impact-assessment reports with applicability decisions and rationale
- Implementation-status reports against effective dates
- At-risk and overdue implementation reports
- Change audit-trail and evidence packs per development
How to get the most from it
Capture everything into one pipeline
Route every source of regulatory intelligence into a single intake. The moment developments arrive in scattered inboxes, something material will be missed or noticed too late.
Document not-applicable decisions too
Record why a change doesn't apply, not just why it does. A reasoned not-applicable decision is exactly what a regulator asks for, and it stops the same analysis being redone.
Anchor actions to the effective date
Set implementation deadlines from the date the rule takes effect and work backwards. Actions without a real deadline slip until the effective date arrives.
Sync accepted changes into obligations
Push accepted changes into the obligations library so it stays current. A change management process disconnected from the obligations it changes leaves the library behind.
Questions, answered
How are regulatory developments captured?
Developments from horizon-scanning feeds, regulator publications, advisers and internal spotting are captured into one pipeline with source, jurisdiction, theme and effective date, each assigned an owner — so nothing depends on the right person happening to see the right email.
How does impact assessment work?
Each applicable change is assessed against the firm's obligations, policies and controls, with the reasoning captured — including a documented conclusion where a change is judged not to apply. The assessment is a durable record that stands up to challenge rather than a conversation that gets redone.
How does a change connect to what must be updated?
An applicable change links directly to the specific obligations, policies and controls it affects, so implementation follows the actual downstream artefacts rather than relying on someone remembering every one a change touches.
How is implementation kept on schedule?
Required updates become tracked actions with owners, milestones and target dates anchored to the change's effective date. Progress is visible and slippage is surfaced early, so the firm can see well in advance whether it will be ready in time.
Does this keep the obligations library current?
Yes. Accepted changes flow into the compliance obligations library and flag the mappings that need review, so the firm's record of what it must do keeps pace with new and amended rules.
Related modules
See Regulatory Change Management in your programme
Book a walkthrough and we'll show how this module fits your policy, workflows and obligations — then scope an implementation.