Regulatory Change Impact Assessment Template (With a Worked DORA Example)
In short
A regulatory change impact assessment is the six-section, firm-side document that decides whether a new rule applies, what it changes and who owns each resulting obligation, and the template below is completed end to end for Commission Delegated Regulation (EU) 2025/532, the DORA subcontracting RTS. CUBE's 2025 Cost of Compliance Report found that 74% of firms take more than a year to implement new regulations, so the assessment should start at final-report stage, not at the application date.
Free, no email needed. Sheets: READ ME, Section 0 Document control, Section 1 Change identification, Section 2 Applicability screen, Section 3 Impact analysis, Section 4 Obligation breakdown, Section 5 Implementation plan, Section 6 Sign-off & changelog. All templates
A regulatory change impact assessment is the document a compliance team produces when a specific new rule lands: what the instrument is, whether it applies to you (with written reasoning either way), which functions and contracts it touches, and which owned, deadlined obligations fall out of it. Below is the full six-section template, ungated and in the page body, followed by the same template filled in end to end for Commission Delegated Regulation (EU) 2025/532, the DORA subcontracting RTS that entered into force on 22 July 2025. The discipline matters because implementation is slow: CUBE's Cost of Compliance Report 2025 (2,000+ senior compliance, risk and legal leaders, published 4 November 2025) found that 74% of firms take more than a year to implement new regulations.
The most valuable field in an impact assessment is the one templates rarely ship, the documented "no material impact" decision with written reasoning. When a supervisor asks "did you consider this instrument?", a dated out-of-scope decision with two sentences of reasoning is a defensible answer. A blank row is not.
This template lives in our trackers and templates library alongside the regulatory change tracker spreadsheet, which is the register this assessment feeds.
A regulatory impact assessment is what the regulator writes; this template is what you write when the rule lands
If you searched "how to write a regulatory impact assessment" and landed on OMB and OECD documents, you found sound guidance for a different document. A regulatory impact assessment (RIA) is a systematic appraisal a rule-maker performs before regulating: the costs and benefits of a proposed rule, per the OECD's RIA guidance and OMB Circular A-4 (the 2003 version, reinstated in February 2025 when OMB revoked the 2023 revision; OIRA summarizes its method in a primer). The European Commission's impact assessment guidance asks the same kind of questions: who is affected, how, at what cost and benefit, and whether the response is proportionate. Governments write RIAs so they regulate carefully.
A regulatory change impact assessment is the mirror-image document written by the regulated firm after a change is detected. The question is not "should this rule exist?" but "this rule exists, so what do we do about it, by when, and who owns it?" It sits between two disciplines it is often confused with: monitoring (detecting the change, covered in how compliance teams track regulatory changes) and regulatory change management, the end-to-end process this assessment is one stage of.
A complete assessment answers five questions:
- What changed, and what is the legal status of the source?
- Which entities, jurisdictions, products, services and activities are in scope?
- What changes for policies, controls, systems, people and third parties?
- Which actions are required, who owns them, and by when?
- What evidence supports the conclusion, and what will prove the implementation was completed?
The depth should match the organization's size, complexity and risk profile. The OCC's Comptroller's Handbook on compliance management systems makes the same point about change management: its formality should be commensurate with those factors, and changes should be evaluated across every affected line of business.
Everything below is the firm-side document.
The template has six sections, and every field carries a one-line instruction
Copy the tables below into a document or spreadsheet and start filling them in this afternoon, or use the free Excel workbook (one tab per section, each holding the blank fields alongside the completed 2025/532 example). Each field carries a one-line instruction; that is the field-by-field annotation, so the worked example that follows can stand on its own.
Section 0: Document control
| Field | How to fill it |
|---|---|
| Assessment ID | Sequential, for example RCIA-2025-041, referenced from your change tracker and obligations register |
| Assessor | Named person, not a team. One person stays accountable for the final assessment even when many contribute |
| Date of assessment | The date of this version. Re-assessments get new dates, logged in Section 6 |
| Status | Draft / In review / Approved / Closed |
| Next-review trigger | A date or an event. "On publication in the Official Journal" is a better trigger than an arbitrary date for an instrument still moving |
| Approver and sign-off date | Whoever owns the risk acceptance, typically the Head of Compliance or CCO |
Section 1: Change identification
This is the section gated templates tend to skip, and it is where assessments go wrong before they start.
| Field | How to fill it |
|---|---|
| Instrument name and official citation | Full title plus a stable identifier (CELEX number, OJ reference, Federal Register citation), never just a nickname |
| Issuing authority and tier | Who made the rule and how authoritative it is (a regulation outranks a speech) |
| Instrument level or type | Level 1 legislation / Level 2 delegated or implementing act (RTS, ITS) / guidance / consultation / enforcement signal |
| Lifecycle status | Consultation, final report, adopted, published in OJ, in force, applies, with dates for each known stage, "as of" dated |
| Key dates | Publication, entry into force, application, first reporting or submission deadline. These are four different dates, and conflating them is the classic failure |
| Provisions changed and baseline | Which articles changed, and which earlier version you compared against |
| How detected | Source and date detected. This is the audit-trail field; the lag between publication and detection is a KPI worth tracking |
| Change statement | One sentence: the source changes [requirement] for [regulated population or activity] in [jurisdiction] from [date], subject to [conditions or open dependencies] |
If the change statement cannot be completed yet, the development needs more legal research before it can be assessed.
The level and type field earns its row. Under DORA, the Level 1 obligation to manage subcontracting risk applied from 17 January 2025, while the Level 2 detail specifying how landed in July 2025 and was rejected by the Commission once in between. A template without a level field cannot represent that reality, and most of DORA's operational substance lives in Level 2. The incident-reporting clocks are one example: the initial report within four hours of classifying an incident as major and no later than 24 hours from awareness, the intermediate report within 72 hours of the initial notification, and the final report no later than one month after the latest intermediate report sit in Delegated Regulation (EU) 2025/301 of 23 October 2024, not in DORA itself. (The Commission's November 2025 Digital Omnibus proposes routing DORA incident reports through a single entry point; as of 30 September 2026 that is still a proposal in a Parliament committee.)
Section 2: Applicability screen
| Field | How to fill it |
|---|---|
| Entity types in scope | As defined in the instrument, cited by article |
| Our legal entities affected | By jurisdiction. A group answer is not an answer |
| Jurisdictional nexus | What ties us to the rule: establishment, licensing, customer location, employee location, data subjects, product distribution |
| Activities and products touched | Specific lines of business, not "operations" |
| Population | Consumers, employees, counterparties or another defined group the rule protects |
| Exemptions and proportionality | For example DORA's Article 4 proportionality principle and microenterprise carve-outs, with the provision cited |
| Third parties | Whether the duty extends to outsourced services, agents, distributors or processors |
| Timing | Transition periods, grandfathering, phased application |
| Applicability decision | In scope / Out of scope / Partially in scope / Unknown, with written reasoning even when out of scope |
| Supporting business facts | The facts the decision rests on: an entity register, a licensing record, a product inventory, a threshold calculation |
That last pair of fields is the defensibility artifact. Write the reasoning at the moment of decision, date it, and never delete it; dismissed changes with documented reasoning are what distinguish a triage process from a guess. "Not applicable" is not self-proving, so cite the business fact that makes it true. Use "Unknown" when a material fact is missing, and assign an owner and a date to resolve it rather than forcing a premature yes or no.
Applicability and materiality are separate decisions. A rule can legally apply and need little work because existing controls already satisfy it. Another development can impose no direct obligation and still change supervisory expectations, enforcement exposure or contract terms.
Section 3: Impact analysis
Run a functions-affected matrix, with a row for each function and columns for affected? / what changes / current-state reference:
| Function | Affected? | What changes | Current-state reference (policy, control or contract) |
|---|---|---|---|
| Compliance | |||
| Legal | |||
| Procurement and third-party risk | |||
| IT and security | |||
| Operations | |||
| Finance | |||
| Front office |
Then check the change against eight domains, so nothing is missed: obligations and controls (created, amended, clarified or removed), products and customers, processes and operations, data and technology, policies and governance, people and training, contracts and third parties, and financial or strategic effects. Then rate the whole change:
| Field | Rubric |
|---|---|
| Materiality | High = new obligation requiring a new control or contract change. Medium = existing control needs amendment. Low = documentation or awareness only |
| Urgency | Application date minus today: a mechanical calculation, not a feeling |
| Estimated cost and effort band | A = documentation only. B = process or contract changes. C = new systems or controls |
| Confidence | How sure you are of the interpretation and of the business facts behind it |
Materiality is judged on consistent dimensions: severity if the requirement is not met, reach across entities and markets, harm to customers or the market, time available, complexity and reversibility, and the strength of existing controls. Do not let a single score replace the analysis. A High, Medium or Low label is only useful when its rationale is visible.
Section 4: Obligation breakdown
One row per discrete obligation. This is the section that turns analysis into work, and it feeds your obligations register directly (the template for that is the regulatory obligations register template).
| Obligation | Provision | Owner | Deadline | Required action | Evidence that will prove compliance | Validation |
|---|---|---|---|---|---|---|
The evidence column is the field templates most often omit. Decide at assessment time what artifact will prove each obligation is met (a revised policy, an amended contract, a filed report), or the obligation will be "done" in a status column and unprovable in an audit. The validation column names how someone other than the owner will test that the change worked, whether by sample, walk-through or control test.
Section 5: Implementation plan
| Field | How to fill it |
|---|---|
| Actions, owners, dates | The project plan distilled from Section 4 |
| Dependencies | Contract renewal calendars, system release windows, budget cycles |
| Interim-risk acceptance | Where full compliance by the deadline is not achievable, record the interim control, its limits, who accepted the risk, when, the review cadence and the date the interim control retires |
| Post-implementation review | The date someone checks that the change achieved its intended outcome |
The OCC handbook expects examiners to ask whether an organization reviews a change after it is implemented and whether project records, committee minutes, adopted procedures and monitoring show that the process worked as intended. The last row of that table is how you have an answer.
Section 6: Sign-off and changelog
A visible change log (date, change, source) for the assessment itself. Instruments move; the January 2025 rejection in the worked example below invalidated part of an assessment written in August 2024, and the changelog is how that shows. Keep three more things with it. Separate facts, assumptions and professional judgments, and record contrary views that shaped the decision. Add a review trigger whenever a conclusion depends on guidance that may change. And list the events that reopen the assessment: an amendment, a correction, a final text, an interpretation by a regulator or court, local implementation, a new product, a new jurisdiction, a supplier change, an acquisition, or an assumption that turns out to be wrong.
| Date | Change | Source |
|---|---|---|
Before approval, ask eight questions. Is the source authoritative and current? Is its legal status described correctly? Have all relevant entities, jurisdictions, products and third parties been considered? Are the business facts confirmed by the people who own the activity? Does every significant conclusion have evidence? Are actions specific, owned and timed against the compliance date? Is validation defined? Are uncertainties and escalations visible?
The worked example assesses Delegated Regulation (EU) 2025/532 from an EU payment institution's compliance seat
Now the same template, completed. The scenario is hypothetical but the regulation is real: a mid-size EU payment institution (one of the 20 categories of financial entity listed in DORA Article 2(1); see EIOPA's DORA overview) whose card acquiring and processing run on ICT providers that subcontract. All regulatory facts below are as of 30 September 2026 and cite the final text on EUR-Lex: Commission Delegated Regulation (EU) 2025/532.
First, the lifecycle that makes this instrument such a good test of the template (documented on the EBA's Single Rulebook page for the RTS and, for the rejection episode, in PwC Legal's analysis):
| Date | Event |
|---|---|
| 26 July 2024 | ESAs publish the joint Final Report on the draft RTS (JC 2024 53) |
| 21 January 2025 | Commission rejects the draft by letter: draft Article 5, on conditions across the ICT subcontracting chain, went beyond the empowerment in DORA Article 30(5) |
| 7 March 2025 | ESAs issue their Opinion on the amended draft |
| 24 March 2025 | Commission adopts the delegated regulation |
| 2 July 2025 | Published in the Official Journal |
| 22 July 2025 | In force, with no transitional provision for existing contracts |
Section 0: Document control (completed)
| Field | Entry |
|---|---|
| Assessment ID | RCIA-2025-041 |
| Assessor | Head of Compliance |
| Date of assessment | 7 July 2025 (v3; prior versions 12 August 2024 and 3 February 2025, see Section 6) |
| Status | Approved |
| Next-review trigger | Event: any ESAs guidance or Q&A on the RTS. Date backstop: first annual third-party risk review after in-force |
| Approver and sign-off date | CCO, 15 July 2025 |
Section 1: Change identification (completed)
| Field | Entry |
|---|---|
| Instrument | Commission Delegated Regulation (EU) 2025/532 of 24 March 2025, an RTS specifying the elements to determine and assess when subcontracting ICT services supporting critical or important functions. CELEX 32025R0532; OJ L, 2.7.2025 |
| Issuing authority and tier | European Commission, on the ESAs' (EBA, EIOPA, ESMA) draft. Tier A |
| Instrument level or type | Level 2: RTS under DORA Art. 30(5), supplementing Regulation (EU) 2022/2554 (Level 1, applies from 17 January 2025) |
| Lifecycle status | In force (22 July 2025). Full history: final report 26 Jul 2024, Commission rejection 21 Jan 2025, ESAs Opinion 7 Mar 2025, adopted 24 Mar 2025, OJ 2 Jul 2025, in force 22 Jul 2025. As of 7 Jul 2025 |
| Key dates | Publication 2 Jul 2025; entry into force and application 22 Jul 2025; no separate application date; no transitional period |
| Provisions changed and baseline | New instrument; baseline is DORA Art. 30(5) and our v2 assessment of the amended draft |
| How detected | Daily OJ sweep, detected 2 July 2025, same day. Instrument tracked since the ESAs final report through EBA source monitoring, 26 July 2024 |
| Change statement | The RTS requires DORA financial entities to assess defined elements of ICT subcontracting chains, secure specified contract content and handle provider notifications of material changes, from 22 July 2025, with no transitional provision for existing contracts, although changes to them must be made in a timely manner on a documented timeline |
Section 2: Applicability screen (completed)
| Field | Entry |
|---|---|
| Entity types in scope | Financial entities under DORA Art. 2 that use ICT services supporting critical or important functions under contracts permitting subcontracting; includes payment institutions |
| Our legal entities affected | EU payment institution entity (home-state license). Non-EU group entities are out of DORA scope |
| Jurisdictional nexus | Establishment and license in the EU member state |
| Activities and products touched | Card acquiring and payment processing, both run on ICT arrangements classified as supporting critical or important functions in our DORA register of information |
| Population | Not applicable: a supervisory duty on the entity, not a customer-facing rule |
| Exemptions and proportionality | DORA Art. 4 proportionality applies to how we implement; we are not a microenterprise, so no carve-out |
| Third parties | Yes: ICT providers and their subcontractors |
| Timing | No transition period |
| Applicability decision | In scope. Reasoning: we are a DORA financial entity, and at least four ICT arrangements supporting critical or important functions permit subcontracting (cloud hosting, acquiring processing, fraud scoring, card personalization). Recorded 12 Aug 2024, reconfirmed against the final text 7 Jul 2025 |
| Supporting business facts | Entity register, license record, and the four register-of-information entries flagged as supporting critical or important functions |
Section 3: Impact analysis (completed)
| Function | Affected? | What changes | Current-state reference |
|---|---|---|---|
| Compliance | Yes | Owns re-assessment, register updates and the evidence trail | Third-party risk policy v2.3; DORA register of information |
| Legal | Yes | Contract addenda for the mandatory content in Art. 4 across in-scope ICT contracts | Master services agreements; outsourcing addenda |
| Procurement and third-party risk | Yes | Pre-contract due diligence extended to the Art. 1 risk-profile elements and the Art. 3 risk assessment, including whether the provider can monitor its own subcontractors | Vendor due-diligence questionnaire v4 |
| IT and security | Yes | Monitoring of subcontracting chains for critical functions; data-location tracking | Cloud governance standard; CMDB |
| Operations | Partially | Exit and termination playbooks extended for subcontracting failures (Art. 6) | Business continuity and exit plans |
| Finance | Low | Budget line for external counsel on contract remediation | Outsourcing budget FY2025 |
| Front office | No | No customer-facing change | None |
| Field | Entry |
|---|---|
| Materiality | High: new obligations requiring contract changes and new due-diligence steps (rubric: new obligation plus contract change) |
| Urgency | Assessed 7 Jul 2025 against in-force 22 Jul 2025: 15 days for new-contract readiness; legacy-contract exposure handled in Section 5 |
| Cost and effort band | B: process and contract changes; external counsel for addenda; no new systems |
| Confidence | High on scope and dates (final text on EUR-Lex); medium on how supervisors will read "well in time" in Art. 5 |
Section 4: Obligation breakdown (completed)
| Obligation | Provision | Owner | Deadline | Required action | Evidence | Validation |
|---|---|---|---|---|---|---|
| Take the elements that shape the overall risk profile and complexity of an ICT service into account when assessing subcontracting | Art. 1 | Head of TPRM | 22 Jul 2025 (new contracts) | Extend the due-diligence questionnaire with the Art. 1 elements | Revised questionnaire and completed assessments on file | Second-line sample of three new onboardings |
| Complete the due diligence and risk assessment before agreeing that a critical or important service may be subcontracted, including whether the provider can monitor its own subcontractors | Art. 3 | Head of TPRM | 22 Jul 2025 (new contracts) | Add the Art. 3 conditions, including a provider-oversight capability check, to onboarding due diligence | Due-diligence report section per provider | Second-line sample of three new onboardings |
| Ensure contracts contain the mandatory content: monitoring, data location, security standards, authority access, change notification | Art. 4 | General Counsel | New contracts 22 Jul 2025; legacy per Section 5 | Clause-gap review of in-scope ICT contracts; issue addenda | Signed addenda; clause-gap tracker | Legal spot-check of executed addenda |
| Handle provider notifications of material subcontracting changes ("well in time") | Art. 5 (final text) | Head of Compliance | 22 Jul 2025 | Stand up a notification-intake and response protocol with a defined assessment SLA | Notification-handling SOP; response log | Tabletop test with a mock notification |
| Maintain termination rights for subcontracting breaches | Art. 6 | General Counsel and Operations | 22 Jul 2025 | Extend exit plans and the termination playbook to subcontracting-triggered exits | Updated exit plans | Exit-plan walkthrough with Operations |
| Update the DORA register of information for subcontracting detail | DORA Art. 28(3); CIR (EU) 2024/2956 templates | Head of Compliance | Next annual register submission | Refresh subcontractor entries across the 15 register templates | Register export; submission receipt | Reconcile the register against contract records |
That last row is the knock-on most assessments miss. The register of information is already a live supervisory artifact, and your subcontracting data feeds it: the ESAs collected the first registers via competent authorities by 30 April 2025 and used them to designate the first 19 critical ICT third-party providers on 18 November 2025, including AWS, Microsoft and Google Cloud.
Section 5: Implementation plan (completed)
| Field | Entry |
|---|---|
| Actions, owners, dates | Per Section 4; weekly stand-up owned by the Head of Compliance until all rows are green |
| Dependencies | Contract renewal calendar (two of four in-scope contracts renew in Q4 2025); external counsel capacity |
| Interim-risk acceptance | The regulation has no transitional provision for existing contracts. Decision: remediate legacy contracts at renewal or within 12 months, whichever is earlier; interim exposure accepted by the board risk committee on 15 July 2025, reviewed quarterly, retired when the last addendum is signed. This is a deliberate, documented risk decision, not a grace period the regulation grants, and it matches Article 4(2), which asks for changes to existing contracts "in a timely manner and as soon as it is possible" and for the planned timeline to be documented |
| Post-implementation review | 15 January 2026: sample of new contracts and addenda checked against Art. 4, results to the risk committee |
Section 6: Sign-off and changelog (completed)
| Date | Change | Source |
|---|---|---|
| 12 Aug 2024 | v1 assessed against the ESAs final report; obligations drafted including draft Art. 5 chain-monitoring conditions | ESAs Final Report JC 2024 53 |
| 3 Feb 2025 | v2: Commission rejection noted (letter of 21 Jan 2025); draft-Art. 5 chain-condition workstream paused, all other workstreams continued | Commission rejection letter via EBA |
| 10 Mar 2025 | ESAs Opinion on the amended draft noted; scope of the final text now stable | ESAs Opinion, 7 Mar 2025 |
| 7 Jul 2025 | v3 against the final OJ text: draft chain-monitoring conditions absent from the final text; "Art. 5" now denotes material-change notification. Obligations re-based; approved | EUR-Lex CELEX 32025R0532 |
The changelog shows that the rejected draft's Article 5 and the final regulation's Article 5 are different provisions that happen to share a number. A team working from a July 2024 summary would build a chain-monitoring program the final text does not require in that form, and might miss the notification protocol it does require, which is why the template always cites the final EUR-Lex text.
Start the assessment at final-report stage, because teams that waited for the Official Journal got 20 days
The timeline above settles the "when do we assess?" argument with arithmetic. A team that opened this assessment at the ESAs' final report (26 July 2024) had roughly twelve months of runway to the 22 July 2025 in-force date. A team that waited for OJ publication (2 July 2025) had 20 days, against a regulation with no transitional provision that requires contract changes. Set against the CUBE finding that 74% of firms take more than a year to implement a new regulation, twenty days is little more than notice.
The counterargument is "drafts change, so why assess early?" The same instrument answers it: the draft did change, materially, and the assessment survived because it carried lifecycle status and re-assessment triggers instead of pretending the rule was static. Early assessment plus a changelog beats late assessment every time; the January 2025 rejection cost the early team one paused workstream, while late teams lost the entire runway. The same logic applies to proposed rules generally. Assess a proposal when its likely effect or implementation effort justifies preparation, label it as proposed, record the uncertainty, separate preparatory actions from mandatory ones, and reassess when the final text is issued.
Catching instruments at final-report stage is a monitoring-design question. That is horizon scanning feeding change management, and the horizon scanning template covers the upstream half. For changes that span several jurisdictions, start from one common source record, then assess applicability, local implementation, deadlines and actions by jurisdiction and legal entity; one regional conclusion rarely carries over unchanged.
Five mistakes make an impact assessment worthless in front of a supervisor
- No record of out-of-scope decisions. If your process only documents rules you act on, you cannot prove you considered the ones you dismissed. The Section 2 reasoning field is two sentences per instrument; write them.
- Citing drafts, summaries or vendor blogs instead of the final text. The Article 5 renumbering above is the cautionary tale. Cite the CELEX number, link EUR-Lex (or the equivalent primary source), and re-base obligations when the final text lands.
- Conflating publication, entry into force and application. DORA entered into force in January 2023 and applies from 17 January 2025; 2025/532 was published on 2 July 2025 and came into force on 22 July 2025, so each of the four date types needs its own field.
- Inventing grace periods. 2025/532 has no transitional provision for existing contracts. The honest move is Section 5's documented interim-risk acceptance, a real decision with an owner and a review date, not an assumed one, and consistent with Article 4(2), which expects timely changes and a documented timeline.
- Writing penalty folklore into the impact box. "DORA fines firms 1% of turnover" is wrong. DORA sets no EU-level fine tariff for financial entities, because sanctions are set at Member State level, and the periodic penalty payments in Article 35, of up to 1% of average daily worldwide turnover (Article 35(8)) for no more than six months (Article 35(7)), apply only to designated critical ICT third-party providers (as of 30 September 2026, per the DORA text).
A sixth mistake is structural: running assessments as unconnected documents. Each assessment should feed a register, the change tracker for status and the obligations register for the Section 4 rows, and your regulatory change management policy should name the assessment as a mandatory stage with the trigger defined.
The template works in a spreadsheet until volume outruns diligence
Everything above works in a spreadsheet, and if you run five assessments a year, a spreadsheet is the right tool. The template breaks down on volume: the detection lag in Section 1, the re-assessment triggers in Section 0 and the changelog discipline in Section 6 all depend on someone noticing every status change across every instrument you track, and that work does not scale by diligence.
RegWatch (my company) automates this part of the workflow, and its records line up with the template's sections. Section 1 starts from a Finding: the source URL, dates and a verbatim excerpt captured by a scheduled monitoring run. Section 2's applicability call maps to triage: each finding is scored against your company profile, accepted ones get a plain-language "Why this matters," and suppressed ones remain on the record, marked as suppressed. Each Section 4 row becomes an Obligation with an owner, an effective date and an evidence area, and the obligation's history and the audit log carry Section 6. The judgment stays human: whether a rule applies, how hard it hits, and whether the written reasoning holds.
Tooling or not, start by copying the template, picking the most recent instrument that landed on your desk, and filling in all six sections against the primary text. If Section 2's reasoning field or Section 4's evidence and validation columns feel unfamiliar, practice those first, because an examiner asks for them by name.
This article is general information, not legal advice.
Free, no email needed. Sheets: READ ME, Section 0 Document control, Section 1 Change identification, Section 2 Applicability screen, Section 3 Impact analysis, Section 4 Obligation breakdown, Section 5 Implementation plan, Section 6 Sign-off & changelog. All templates
Questions
What is a regulatory change impact assessment?
A structured document a regulated firm produces when a specific new or amended regulation is detected. It identifies the instrument, decides applicability with written reasoning, maps the impact across functions and existing controls, and breaks the rule into owned, deadlined obligations with defined evidence. It sits between monitoring, which detects the change, and implementation, which executes the plan.
What is the difference between a regulatory impact assessment (RIA) and a regulatory change impact assessment?
A regulatory impact assessment is written by the regulator before rulemaking, as a cost-benefit appraisal of a proposed rule under OECD guidance and OMB Circular A-4. A regulatory change impact assessment is written by the regulated firm after a change is detected, to work out what it must do.
What should a regulatory change impact assessment include?
Six sections: document control, change identification including the instrument's level and lifecycle status, an applicability screen with a written in-scope or out-of-scope decision, impact analysis across functions and existing controls, an obligation breakdown with owner, deadline, evidence and validation for each row, and an implementation plan with sign-off and changelog. Most templates omit lifecycle status, documented out-of-scope reasoning and evidence per obligation.
When should you run the assessment: at consultation, adoption or entry into force?
At the final-report or adoption stage, with a re-assessment trigger at every later status change. For the DORA subcontracting RTS, teams that assessed at the ESAs' final report (26 July 2024) had about twelve months before the 22 July 2025 in-force date, while teams that waited for Official Journal publication (2 July 2025) had 20 days. The draft also changed in between, which is why triggers matter.
How long does it take to implement a regulatory change?
CUBE's Cost of Compliance Report 2025, a survey of more than 2,000 senior compliance, risk and legal leaders published on 4 November 2025, found that 74% of firms take more than a year to implement new regulations. That is why the assessment has to start at final-report stage rather than at the application date.
When is an impact assessment complete?
When the conclusion is approved, every required action has an owner and a deadline, completion evidence is retained, and material changes have been validated by someone other than the owner. Closing the analysis before implementation is finished opens a gap between interpretation and control. Give a closed assessment both a decision date and defined reopening triggers, such as an amendment, a regulator's interpretation or a new product.
Terms in this guide
Sources
- CUBE, The Cost of Compliance Report 2025 accessed 30 Sep 2026
- Commission Delegated Regulation (EU) 2025/532, EUR-Lex accessed 30 Sep 2026
- EBA Single Rulebook: joint RTS on subcontracting ICT services supporting critical or important functions accessed 30 Sep 2026
- PwC Legal: European Commission rejects the DORA subcontracting RTS accessed 30 Sep 2026
- EBA: The ESAs acknowledge the European Commission's amendments to the technical standard on subcontracting under DORA (7 March 2025) accessed 1 Oct 2026
- Regulation (EU) 2022/2554 (DORA), EUR-Lex accessed 30 Sep 2026
- Commission Delegated Regulation (EU) 2025/301 on ICT-related incident reporting accessed 30 Sep 2026
- Commission Implementing Regulation (EU) 2024/2956, register of information templates accessed 30 Sep 2026
- ESAs announce timeline to collect registers of information and designate critical ICT third-party providers accessed 30 Sep 2026
- EIOPA: ESAs designate the first critical ICT third-party providers under DORA (18 November 2025) accessed 30 Sep 2026
- EIOPA: Digital Operational Resilience Act (DORA) overview accessed 30 Sep 2026
- OECD, Regulatory Impact Assessment accessed 30 Sep 2026
- Office of Information and Regulatory Affairs, Regulatory Impact Analysis: A Primer (on OMB Circular A-4) accessed 30 Sep 2026
- OMB Memorandum M-25-15, Rescission and Reinstatement of Circular A-4 (12 February 2025) accessed 30 Sep 2026
- European Parliament Legislative Observatory, Digital Omnibus (2025/0360(COD)) accessed 30 Sep 2026
- European Commission, Impact assessments accessed 30 Sep 2026
- OCC Comptroller's Handbook, Compliance Management Systems accessed 30 Sep 2026
