Platform
Compliance Management

Regulatory Change Management

Track regulatory change from horizon-scan to implemented control

Capture regulatory developments, assess their impact on your obligations, policies and controls, and drive the resulting changes to completion with owners and deadlines — so regulatory change becomes a managed pipeline rather than a scramble. OnyxOne Regulatory Change Management gives compliance teams one place to see what is coming, decide what it means for the firm, and prove that every applicable change was assessed and implemented before it took effect.

At a glance

How it works, visually

A representative compliance flowSchematic
Item receivedOnboarding / eventRiskthreshold?Auto-clearLow risk · loggedEscalate to reviewAnalyst investigatesRecord &auditNoYes — parallel review paths

How an obligation or event is triaged, escalated when it matters, and recorded either way.

The challenge

The problems this module solves

The operational realities that make this hard for compliance and risk teams today.

Change is spotted late and inconsistently

Regulatory developments arrive through newsletters, alerts, advisers and word of mouth, landing in different inboxes with no shared record. Something material is missed or noticed late, and the firm is implementing a change under time pressure that it could have planned for months earlier.

Impact assessment is ad hoc and undocumented

When a change is noticed, working out what it means — which obligations, policies and controls it touches — happens informally in email and meetings. The reasoning isn't captured, so the same analysis is redone later and there is no record of why the firm concluded a change did or didn't apply.

Nothing connects a rule change to what must change

A new requirement should trigger updates to specific obligations, policies and controls, but those live in other systems. Without a link, implementation relies on someone remembering every downstream artefact a change affects, and things get missed.

Implementation isn't tracked to a deadline

A change is accepted, actions are handed out, and then visibility evaporates. Nobody can say with confidence whether every required update will be done before the rule takes effect, and the first sign of a slipped deadline is often the effective date itself.

There's no audit trail of how change was handled

When a regulator asks how the firm identified, assessed and implemented a particular change, the answer is scattered across emails and documents. Demonstrating a controlled, timely response is slow and the evidence has gaps.

The approach

How OnyxOne addresses it

One intake for every regulatory development

Capture regulatory changes — from horizon-scanning feeds, regulator publications, advisers or internal spotting — into a single pipeline with source, date, jurisdiction and theme. Nothing depends on the right person seeing the right email; every development lands in one governed queue with an owner.

Structured, recorded impact assessment

Each development is triaged and assessed against the firm's obligations, policies and controls, with the reasoning captured — including a documented conclusion where a change is judged not to apply. The assessment is a durable record, not a conversation, so it stands up to challenge and isn't redone.

Change linked to the artefacts it affects

An applicable change links directly to the specific obligations, policies and controls it touches. Implementation follows the actual downstream artefacts rather than someone's memory, so every affected policy and control is accounted for.

Implementation driven to the effective date

Required updates become tracked actions with owners, milestones and target dates anchored to the change's effective date. Progress is visible, slippage is surfaced early, and the firm can see well in advance whether it will be ready in time.

A complete, evidenced change record

From first capture through assessment, decision and implementation, every step is recorded. The firm can show, for any change, how it was identified, what it decided and why, who did the work and when it completed — a controlled response evidenced end to end.

Capabilities

What's in the module

Turn on what you need and add more as your programme scales.

Change intake pipeline

One queue for regulatory developments from horizon-scanning feeds, publications, advisers and internal spotting, each owned and triaged.

Horizon scanning

Capture and categorise forthcoming and proposed changes by jurisdiction, theme and effective date before they take effect.

Impact assessment

Structured, recorded assessment of each change against obligations, policies and controls, including reasoned not-applicable decisions.

Applicability triage

Route and prioritise developments by relevance to the firm's products, jurisdictions and business units.

Artefact linkage

Link an applicable change to the specific obligations, policies and controls it affects for accurate implementation.

Implementation planning

Turn required updates into tracked actions with owners, milestones and deadlines anchored to the effective date.

Deadline management

Track implementation against effective dates, surfacing at-risk and overdue work early.

Decision & rationale capture

Record decisions and their reasoning, including why a change was judged not to apply, as durable evidence.

Obligation-library sync

Push accepted changes into the obligations library so what the firm must do stays current.

Immutable change trail

Every capture, assessment, decision and action is written to an append-only audit record.

Dashboards

The views your team works from

Purpose-built dashboards and views, each answering a question a specific role needs to act on.

An executive viewIllustrative
ILLUSTRATIVE EXAMPLEOPEN CASES128SLA ADHERENCE96%SCREENING ALERTS1.2kOVERDUE REVIEWS14Cases by categoryAMLKYCFraudSanctionsConductOtherRisk mixby tierHighMediumLow

A representative layout of the KPI tiles and charts these dashboards present. Figures shown are illustrative examples, not real data.

Change pipeline

Every regulatory development by status, theme and jurisdiction, from capture through assessment to implemented, with owners.

Horizon scan

Forthcoming and proposed changes on a timeline by effective date, so the firm sees what is coming and when.

Impact assessment board

Assessments in progress and completed, with applicability decisions, rationale and the artefacts each change affects.

Implementation tracker

Implementation actions against effective dates, with at-risk and overdue work surfaced early.

Change evidence view

The end-to-end record for any development — capture, assessment, decision, actions — assembled as examination-ready evidence.

Automation

What the platform automates

Rules, workflows, alerts and scheduling that run the routine so your team works the exceptions.

Feed intake & routing

Developments from connected horizon-scanning sources are captured into the pipeline and routed to owners by theme and jurisdiction.

Deadline countdown alerts

Implementation actions are tracked against effective dates and flagged as at-risk before they slip, not after.

Artefact-review flags

When a change is linked to a policy or control, the owners of those artefacts are notified that a review is required.

Obligation-library sync

Accepted changes update or create obligations in the compliance library and flag affected mappings automatically.

Action reminders & escalation

Implementation actions are reminded before they fall due and escalated when they slip past target.

AI assistance

Where AI helps the analyst

Assistive, decision-support features that speed up the work on the record. Suggestions are always reviewable, and a person stays in control of every decision.

Development summarisation

Drafts a concise summary of a captured regulatory development from its source text, which the compliance owner reviews before it informs the assessment.

Impact-suggestion assistance

Suggests which existing obligations, policies and controls a change may affect based on similarity, for a person to confirm — it never decides applicability on its own.

Implementation-plan drafting

Proposes a first-cut set of implementation actions from the assessed impact, leaving owners, deadlines and scope to be set and owned by a person.

The workflow

The enterprise workflow

A defined, end-to-end process with clear ownership at every stage.

The workflow, step by stepSchematic
01CaptureRegulatory developments are captured into one pipeline with source, jurisdiction,theme and effective date, each assigned an owner.02Triage applicabilityEach development is triaged for relevance to the firm's products, jurisdictions andunits, and prioritised accordingly.03Assess impactApplicable changes are assessed against obligations, policies and controls, with thereasoning and conclusion documented.04Link affected artefactsThe change is linked to the specific obligations, policies and controls it touchesso nothing downstream is missed.05Implement to deadlineRequired updates become tracked actions with owners and target dates anchored to theeffective date and driven to completion.06Evidence & syncThe full change record stands as evidence, and accepted changes update theobligations library so it stays current.

Every result, decision and override is captured against the record it belongs to.

01

Capture

Regulatory developments are captured into one pipeline with source, jurisdiction, theme and effective date, each assigned an owner.

02

Triage applicability

Each development is triaged for relevance to the firm's products, jurisdictions and units, and prioritised accordingly.

03

Assess impact

Applicable changes are assessed against obligations, policies and controls, with the reasoning and conclusion documented.

04

Link affected artefacts

The change is linked to the specific obligations, policies and controls it touches so nothing downstream is missed.

05

Implement to deadline

Required updates become tracked actions with owners and target dates anchored to the effective date and driven to completion.

06

Evidence & sync

The full change record stands as evidence, and accepted changes update the obligations library so it stays current.

The value

What your team gains

Managed

A pipeline, not a scramble

One intake and a defined workflow turn regulatory change from a stream of missed emails into a governed pipeline the firm can plan against.

Documented

Assessments that stand up

Recorded impact assessments — including reasoned not-applicable decisions — mean the firm can defend how it judged every change.

Traceable

Nothing downstream is missed

Linking a change to the exact obligations, policies and controls it affects means implementation follows the artefacts, not someone's memory.

On time

Ready before the effective date

Actions anchored to effective dates with early slippage warnings mean the firm sees whether it will be ready in time, not on the day.

A complete change audit trail

Every step from capture to implementation is recorded, so demonstrating a controlled, timely response is a report rather than a reconstruction.

An obligations library that stays current

Accepted changes flow into the obligations library, so the firm's record of what it must do keeps pace with the rules.

Built for

Industries it serves

Financial ServicesBankingInsuranceInvestment FirmsFintechAsset ManagementCorporate & Trust Service ProvidersLegal FirmsRegulated Enterprises
Integrations

Works with your existing systems

Described as capabilities — OnyxOne connects to the systems your deployment requires, configured per implementation.

Compliance obligations
  • Pushes accepted changes into the compliance-management obligations library and flags the mappings that need review
Policies & controls
  • Links changes to the affected policies and controls so implementation updates the right artefacts in policy management and internal controls
Regulatory knowledge
  • Draws on and updates the regulatory knowledge base so the underlying rules and interpretation stay aligned
Horizon-scanning feeds
  • Ingests regulatory developments from your existing horizon-scanning and regulatory-intelligence sources into one pipeline
Collaboration & notification
  • Routes assessment tasks, implementation actions and deadline alerts through your existing email and messaging channels
Assurance

Security, compliance & reporting

Security & data handling

  • Change records, assessments and implementation actions are encrypted in transit and at rest, with access governed by role-based permissions.
  • Sensitive assessment detail can be restricted to named compliance and oversight roles.
  • Segregation of duties can prevent the same person from both assessing and signing off a change where policy requires it.
  • Every capture, assessment, decision and action is written to an append-only audit trail.
  • Retention of change records and impact assessments is configurable to your regulatory obligations.

Compliance support

  • Supports the regulatory-change and horizon-scanning expectations placed on regulated firms
  • Provides documented impact-assessment and implementation evidence for regulatory examination
  • Keeps the compliance obligations library aligned to current and forthcoming rules
  • Underpins the compliance layer of a three-lines-of-defence model
  • Supplies a dated, end-to-end audit trail of how each change was handled

Reports & exports

  • Regulatory change pipeline by status, theme and jurisdiction
  • Horizon-scan report of forthcoming changes by effective date
  • Impact-assessment reports with applicability decisions and rationale
  • Implementation-status reports against effective dates
  • At-risk and overdue implementation reports
  • Change audit-trail and evidence packs per development
Best practice

How to get the most from it

Capture everything into one pipeline

Route every source of regulatory intelligence into a single intake. The moment developments arrive in scattered inboxes, something material will be missed or noticed too late.

Document not-applicable decisions too

Record why a change doesn't apply, not just why it does. A reasoned not-applicable decision is exactly what a regulator asks for, and it stops the same analysis being redone.

Anchor actions to the effective date

Set implementation deadlines from the date the rule takes effect and work backwards. Actions without a real deadline slip until the effective date arrives.

Sync accepted changes into obligations

Push accepted changes into the obligations library so it stays current. A change management process disconnected from the obligations it changes leaves the library behind.

FAQ

Questions, answered

How are regulatory developments captured?

Developments from horizon-scanning feeds, regulator publications, advisers and internal spotting are captured into one pipeline with source, jurisdiction, theme and effective date, each assigned an owner — so nothing depends on the right person happening to see the right email.

How does impact assessment work?

Each applicable change is assessed against the firm's obligations, policies and controls, with the reasoning captured — including a documented conclusion where a change is judged not to apply. The assessment is a durable record that stands up to challenge rather than a conversation that gets redone.

How does a change connect to what must be updated?

An applicable change links directly to the specific obligations, policies and controls it affects, so implementation follows the actual downstream artefacts rather than relying on someone remembering every one a change touches.

How is implementation kept on schedule?

Required updates become tracked actions with owners, milestones and target dates anchored to the change's effective date. Progress is visible and slippage is surfaced early, so the firm can see well in advance whether it will be ready in time.

Does this keep the obligations library current?

Yes. Accepted changes flow into the compliance obligations library and flag the mappings that need review, so the firm's record of what it must do keeps pace with new and amended rules.

See Regulatory Change Management in your programme

Book a walkthrough and we'll show how this module fits your policy, workflows and obligations — then scope an implementation.