Module 1: Statutory Framework & Mandate
This opening module of Compliance Risk Framework training establishes the legal and regulatory basis for the function's existence.
- The Regulatory Landscape: mapping the specific statutory requirements (e.g., UK FCA/PRA, GDPR, or sectoral-specific legislation) that necessitate a compliance function
- Defining the Mandate: distinguishing between "advisory" compliance (guidance) and "monitoring" compliance (oversight) – SYSC 6
- Independence and Authority: the evidentiary requirements for demonstrating functional independence from the front office or commercial operations
- The "Three Lines of Defence" Model: defining the compliance function as the second line of defence
Module 2: Risk Assessment & Methodology
A compliance function must be risk-based to be effective. This section covers the data-driven approach to identifying focus areas.
- Establishing a Risk Universe: identifying all regulatory risks applicable to the entity
- Risk Scoring (Impact vs. Probability): utilising a quantitative matrix to prioritise resources
- Gap Analysis: assessing the "As-Is" state against the "To-Be" regulatory requirement
- The Compliance Monitoring Plan (CMP): designing a schedule based on the findings of the risk assessment
- EXERCISE - The "Risk Heat Map" Live Build
- Goal: Practice the quantitative assessment of risk
Module 3: Policy, Process, and Controls
This module addresses the "How" of compliance - turning legal requirements into repeatable business processes.
- Policy Hierarchy: differentiating between high-level principles, detailed policies, and Standard Operating Procedures (SOPs)
- Designing Effective Controls:
- Preventative Controls: Automation or "hard" stops in a process
- Detective Controls: Reconciliations and post-event reviews
- Evidence of Compliance: establishing the "audit trail" required to prove to regulators that controls are functioning as intended
- Training & Culture: methods for disseminating policy and measuring employee comprehension
- EXERCISE – Reflection and Self-assessment – Where do you identify weaknesses – group-source three positive actions to strengthen your position.
Module 4: Monitoring, Reporting, and Remediation
The final module of this compliance monitoring framework course focuses on the feedback loop: finding issues and fixing them.
- The Monitoring Cycle:
- Sampling and Testing
- Finding Identification
- Management Response
- Management Information (MI) & Reporting: creating fact-based reports for the Board or Audit Committee. Key Performance Indicators (KPIs) vs. Key Risk Indicators (KRIs)
- Handling Breach Management: the evidentiary process for identifying, logging, and reporting regulatory breaches.Continuous Improvement: Using "Root Cause Analysis" to ensure remediation addresses the source of the failure, not just the symptom
Summary and Close