Regulatory Change Management Software: A 2026 Buyer's Guide With RFP Questions and a Scorecard
In short
The most useful test of regulatory change management software is to replay 10 updates your team handled last quarter, from your own regulators, through each shortlisted tool and score what it catches, whether its applicability calls cite the source clause, how much noise it adds and how fast each change reaches an owner. Buy the owner as well as the product: six acquisitions between July 2023 and June 2026, including CUBE's purchase of Thomson Reuters Regulatory Intelligence and Bloomberg Industry Group's purchase of Regology, put change-of-control and data-export terms on the RFP.
Free, no email needed. Sheets: READ ME, Criteria and weights, RFP questions, Vendor scorecard, Trial log, Changelog. All templates
Regulatory change management software exists to answer four questions about every publication from the regulators that supervise you: does it apply to us, who owns the response, by when, and what evidence will show it was done. The test that separates the tools is easy to describe and rarely run: take about 10 updates your team handled last quarter, give every vendor the same company profile and the same regulator list, and score what each tool catches, whether its applicability calls cite the source clause, how much noise it adds and how long each change takes to reach an owner.
Applicability is where a small team's hours go. In a February 2026 survey of 204 compliance, legal and risk professionals by Regology, a vendor in this market, 85.3% said they monitor regulatory updates, only 30.9% said the alerts they receive are always relevant, and nearly 58% worked on teams of five people or fewer (Regology, 27 February 2026). A commenter in an August 2026 r/Compliance thread put it in one line: finding the changes is the easy half, and working out which ones affect you is the hard one. Today's methods are compared in how compliance teams track regulatory changes.
The free workbook with this guide holds the criteria, weights and 36 RFP questions below, a four-vendor scorecard and a trial log. Disclosure: RegWatch, my company, sells in this market; it gets one labeled section near the end and should face every test here.
Regulatory change management software turns a regulator's publication into an owned, evidenced decision
Regulatory change management is a five-step process, and the software is whatever records it:
- Watch the regulators, legislatures and standard setters you name, on a schedule, including rules not yet in force (regulatory horizon scanning).
- Triage each item: is it relevant, and does it apply to a specific entity, product or market?
- Assess what changes for policies, controls, systems, contracts and people. The impact assessment template lays out the fields.
- Assign each applicable requirement as an obligation with an owner, a deadline and the evidence that will prove it was met, held in an obligations register.
- Prove and report: keep the evidence, the attestations and every decision, report status to the board and answer the examiner.
Regulatory intelligence software concentrates on the first two steps: sourcing, summarizing, tagging and alerting. Regulatory change management software is judged on the last three, and the better regulatory change management systems carry one record from the first step to the last. This disambiguation separates the terms if they still blur.
The fifth step is the one supervisors test. The OCC's Comptroller's Handbook booklet on compliance management systems (version 1.0, June 2018) expects management to "anticipate and respond in a timely manner" to changes in applicable consumer protection laws and regulations, with a change process as formal as the bank's size, complexity and risk profile require. When examiners review completed changes, the information they may look at includes "project management tracking records, applicable committee meeting minutes, adopted policies and procedures related to the change, and monitoring or audit reports." The booklet covers consumer compliance at US national banks, and it is still the clearest public list I know of what an examiner pulls. If a decision lives in someone's inbox, answering that sample turns into archaeology.
Three kinds of product are sold as regulatory change management software
Vendors use the same phrases, regulatory change management platform, regulatory intelligence software, regulatory change management tools, for different products. Know which kind you are scoring, because each fails a different test.
| Kind of product | What you are buying | What to test hardest | Fits when |
|---|---|---|---|
| Regulatory content and intelligence providers | Monitored and curated content: rulebooks, taxonomies, summaries and editorial analysis, often with an inventory of obligations | Whether the "does this apply to us" call is made for your entities or handed back to your team, and how a change reaches an owner | You need depth across many regulators in a few sectors and have analysts to apply it |
| GRC suites with a regulatory change module | A change workflow inside the system that already holds your controls, risks, policies and attestations, fed by built-in or licensed content | Where the content comes from, the implementation effort, and whether first-line owners who log in twice a quarter can finish their tasks | The suite is already your system of record and its change module passes the trial below |
| AI-native monitoring and applicability tools | Software that reads the sources you choose, scores each finding against a company profile and writes the reasoning | Original publication dates, source provenance, stored reasoning for suppressed items, and whether it stops at the alert | Your bottleneck is triage across many jurisdictions with a small team |
The labels blur, and acquisitions blur them faster. CUBE, which bought the expert-curated content of Thomson Reuters Regulatory Intelligence, called itself an AI-native regulatory intelligence company in a September 2026 release; Archer, a GRC suite vendor, bought Compliance.ai, whose product monitors regulatory updates; and the legal AI platforms Legora and Harvey added monitoring in 2026. Score the function, whatever the label.
AI-native tools deserve their own skepticism. When a builder posted a monitoring prototype to r/Compliance in March 2026, the first reply asked, half joking, whether it was news feeds with a chatbot bolted on, and the builder answered with auditability: a traceable path from source to decision. Apply that test to every kind of tool here, and see what breaks when a chatbot does horizon scanning.
Six acquisitions and two launches since July 2023 changed who sells these tools
Check the date on any vendor list you rely on, ours included. Each row below is dated and sourced as of 30 September 2026.
| Date | What happened | What it changes for a buyer |
|---|---|---|
| 5 Jul 2023 | Corlytics acquired Clausematch, a policy management vendor | Corlytics' offering now spans monitoring, change management, policy management and attestation |
| 20 Feb 2024 | Archer announced its acquisition of Compliance.ai | compliance.ai now tells existing users that their platform is Archer Evolv Compliance |
| 31 Dec 2024 | CUBE completed its acquisition of Thomson Reuters Regulatory Intelligence and Oden; terms were not disclosed | CUBE's FAQ: for TRRI renewals from 1 November 2026, the existing subscription ends when customers move to CUBE Intel, on or by that date |
| 19 Feb 2026 | CUBE acquired 4CRisk, which maps policies and procedures to regulatory obligations, controls and risks | Policy-to-obligation mapping joins a regulatory intelligence platform |
| 6 May 2026 | Legora acquired Graceview, a regulatory horizon scanning platform | A legal AI platform buys a monitoring product |
| 2 Jun 2026 | Legora launched Monitors as generally available, stating 10,000+ official primary sources across 100+ jurisdictions | Monitoring sold as a feature of a legal workspace, with findings, owners and deadlines tracked in lists |
| 3 Jun 2026 | Bloomberg Industry Group acquired Regology; the release gives no financial terms | Regology's acquisition FAQ says contracts, subscriptions and pricing are not changing immediately |
| 1 Sep 2026 | Harvey introduced Horizon Scanning in Early Access for Harvey customers, stating more than 12,000 sources across 100+ jurisdictions | Monitoring sold as a feature of a legal AI platform, with outputs such as memo revisions and policy updates |
Three consequences belong in your evaluation.
The product you demo may not be the one you renew. CUBE is moving TRRI customers onto CUBE Intel, and compliance.ai's users now work in Archer Evolv Compliance. Ask whether the product on your shortlist will be merged, renamed or retired within 24 months, and write the answer into the order form.
Integration plans are stated in general terms. Bloomberg's release describes integrating regulatory change management capabilities into its portfolio, without dates. Test the version you will actually run, on your data, and treat the rest as roadmap.
Contracts move with the business. CUBE's FAQ says all existing TRRI contracts were assigned to CUBE from 31 December 2024. Negotiate notice and a termination right on a change of control, price protection at renewal, an exit if the product is retired or migrated, and a data-export warranty covering decisions and the audit log in an open format. An acquirer's assurance that nothing changes immediately is a reason to put those terms in writing.
Acquisitions also bring capital and content depth, and independent vendors carry the opposite risk of being bought next, or failing, so ask every vendor the same ownership questions. For vendor detail on this regtech market, see the horizon scanning tools comparison, the Compliance.ai alternatives and the TRRI migration guide.
Eight tests show how to choose regulatory change management software
Each test has a pass condition you can check in a trial. Run all eight on every shortlisted vendor, your incumbent included, and keep the evidence.
1. Coverage is a map of your named regulators and source types
List every regulator, legislature and standard setter your entities answer to, and the source types you need from each: final rules, consultations, guidance and Q&As, supervisory statements and Dear CEO letters, enforcement actions, speeches and official journals. Ask each vendor for a source-by-source map against that list: covered or not, through what (official feed, crawler or editorial team), how often checked and in which language. A headline count of countries says nothing about your list, and vendor counts drift between pages and months, as our Compliance.ai comparison shows for one vendor.
Then ask how the vendor records the original publication date when a page shows only an updated one, so a republished page does not pass as news, and who notices when a source breaks. Regulators redesign websites and retire feeds, and someone has to own the watch.
Pass: a coverage map against your list with gaps admitted, and a source you name added and checked during the trial.
2. Applicability is decided for your entities, products and markets, with the clause cited
A relevance score says an item falls inside your monitoring perimeter. Applicability says it binds a particular entity, product or market, and that call is where your team spends its time. Give every vendor the same company profile: legal entities and licenses by jurisdiction, products and customer types, markets, material outsourcing, and the thresholds you sit above or below. Then put look-alike pairs in the test set, such as a rule for credit institutions when you hold only a payment institution license.
Pass: each call cites the clause that sets the rule's scope and the profile fact it relied on, and out-of-scope items stay on record with that reasoning, where you can review and overturn them.
3. An accepted change becomes an obligation with an owner, a deadline and evidence
Accept an item in the trial and time the path to an obligation with a named owner, a due date tied to the rule's effective dates and a defined evidence requirement. This stretch is the slow part: CUBE's Cost of Compliance Report 2025, a survey of more than 2,000 senior compliance, risk and legal leaders published on 4 November 2025, found that 74% of firms take more than a year to implement new regulations. CUBE sells regulatory intelligence, so read that as a vendor survey.
Then hand the obligation to a first-line owner who logs in twice a quarter and see whether they can attest without training. In a May 2026 r/grc thread on why teams still run compliance in Excel, a commenter with CISO and second-line risk director experience said full GRC tools are built for the reporting users who buy them, while adoption and good data depend on non-specialists. Check lifecycle handling as well: when a consultation becomes a final rule or a rule is amended, the obligation should reopen. The obligations register template lists the fields an auditor expects.
Pass: owner, deadline and evidence set inside the product, an unassisted attestation by one of your owners, and a reopened record after a status change.
4. The decision record survives an examiner's sample a year later, "not applicable" decisions included
Examiners sample, and so do internal auditors: they pick an item from last year and ask you to walk it through. The record has to show what was published and when, when you found it, the text your decision relied on, who decided and why, which obligations followed and the evidence that closed them. Dismissals are the easiest decisions to leave unrecorded, and a dated "does not apply" with its reason is what proves you considered a rule you did nothing about.
Ask how the log detects alteration. In a tamper-evident audit log, such as a hash chain where each entry carries a hash of the one before, an edited or deleted entry is detectable. Then ask whether you can export the whole record in an open format, during the contract and at exit.
Pass: three complete records exported at the end of the trial, one of them a dismissal, that a colleague who was not involved can follow without asking you anything.
5. AI transparency shows what the model read, why it decided and who reviewed it
Most tools now use language models somewhere, so ask about the record the model leaves. In a March 2026 r/ComplianceOps thread, a poster who had sat through four vendor demos that month asked each for the audit trail behind its agent's decisions, got vague answers, and wrote that if they put an AI tool in front of a regulator and "can't explain exactly what it did and why, I'm the one who gets fined." A reply from someone who said they work on the examination side added that pointing to the vendor would itself be a finding, because the institution owns its program whatever tools it uses. Both posts concerned anti-money laundering tools; the logic carries over.
For three trial items, one of them suppressed, ask to see the source text the model read, its output and reasoning, the model or prompt version, and the person who accepted or rejected the call, and ask whether the vendor will report misses and wrong calls on your trial data. Human-in-the-loop review counts only if the human decision is recorded. See LLM accuracy on regulatory text for how models fail, and what AI agents do in compliance for the run record an auditor should read.
Pass: source text, reasoning, model version and reviewer visible for every call you sample, suppressed items included.
6. Board and regulator outputs come straight from the record
A board pack needs a short list: what changed by jurisdiction and business line, what comes into force next quarter, which obligations are overdue, RAG status on the open ones and the material decisions taken. Ask each vendor to produce last quarter's pack from trial data without manual editing, and show it to your CCO; if someone must rework it before every committee, count those hours as cost. Supervision needs a second output: a single-rule evidence pack for a regulator who asks how you handled one rule.
Pass: an unedited board pack your CCO would present, and a single-rule evidence pack produced on request.
7. Deployment, security and data use are settled in writing before the trial ends
Procurement and the CISO should get answers while there is still a choice to make. Ask where the service runs (a shared cloud, a dedicated instance or your own cloud account); where your data is stored and processed, including by model providers and subprocessors; whether your content trains or improves any model, by default and by contract; whether single sign-on works through SAML or OIDC, with role-based access; how customers are isolated from each other; and which independent security audits or certifications cover the service. If data must stay in your own cloud account, ask about a private VPC deployment and what still leaves the account, such as model calls.
Pass: every CISO question answered in writing, with the documents attached.
8. Price, total cost and contract protections are known before you sign
Pricing models vary: per user, per jurisdiction or module, a platform fee, or consumption. Most vendors in this category quote rather than publish; in our comparison of twelve horizon scanning tools, two published a price as of 30 September 2026. One published example: Bloomberg Regology's pricing page lists a Professional plan at $1,700 per user per month on a three-year contract for US federal and state coverage, with global jurisdictions on its quote-based Enterprise tier.
Total cost adds implementation services, integration, renewal uplift and the hours your team spends maintaining the profile, watchlists and users; for a team of three to five, those hours can decide the purchase. Price the spreadsheet too: a reply in the same r/grc thread made the plain point that the tools cost a lot while Excel is close to free, and our free regulatory change tracker includes a scored test for when a team has outgrown one.
Pass: a written all-in quote, an estimate of admin hours per month, and change-of-control, price-protection and data-export terms in the draft contract.
Run last quarter through each tool before you sign
A demo shows a tool on the vendor's chosen sources; this protocol shows it on yours. Budget about a month of elapsed time, with most of your effort in the first step.
- Build the test set. Pick 10 updates your team handled in the last full quarter: about six that applied (a final rule, a consultation, guidance, an enforcement action that changed expectations), three or four that looked relevant but did not apply, and at least one you found late. Record the ground truth for each: publication date, the date your team found it, your applicability decision and its reason, the owner and the date they were assigned. Keep the list from vendors until scoring.
- Fix the inputs. Send every vendor the identical company profile and regulator list, and record the days each takes to reach its first triaged alert.
- Run it twice. In a replay, each vendor processes everything your regulators published that quarter, with your 10 updates inside it. In a live run, the same watchlist runs forward for two to four weeks to measure noise and speed. If a vendor cannot replay, score the live run and note the gap.
- Score every update. Caught or missed (an item recorded as considered and dismissed counts as caught); the call right or wrong (a call routed to human review with sound reasoning counts as right); reasoning 0, 1 or 2 (none; a summary with no clause or profile fact; the scoping clause and the profile fact); and whether the full record exports. From the live run, count irrelevant alerts per week and the median days from publication to an assigned owner.
- Use two reviewers for reasoning. Each scores independently, and you settle differences before totaling.
A worked example shows how the scores separate three vendors
Everything in this example is fictional, and none of the updates refers to a real publication. The firm is a payments group with an e-money institution in the EU, an authorized payment institution in the UK and a money transmitter licensed in 12 US states, with a compliance team of four. Each vendor cell shows caught or missed, the call and the reasoning score.
| # | Update in the test set (fictional) | Team's call | Vendor A | Vendor B | Vendor C |
|---|---|---|---|---|---|
| 1 | Final safeguarding rules, EU home supervisor | Applies | Caught, right, 2 | Caught, right, 1 | Caught, right, 2 |
| 2 | Consultation on fraud reimbursement, UK | Applies | Caught, right, 2 | Caught, right, 1 | Missed |
| 3 | Supervisory statement on cloud outsourcing, EU | Applies | Caught, right, 2 | Caught, right, 1 | Caught, right, 2 |
| 4 | Amended money transmission rule, a licensed state | Applies (found 23 days late) | Caught, right, 2 | Caught, right, 1 | Missed |
| 5 | Enforcement action on a peer's transaction monitoring | Applies (control review) | Caught, right, 1 | Caught, wrong, 0 | Caught, right, 2 |
| 6 | Updated sanctions screening guidance | Applies | Caught, right, 2 | Caught, right, 1 | Caught, right, 2 |
| 7 | Rules for crypto-asset service providers | Does not apply | Caught, right, 2 | Caught, wrong, 1 | Caught, right, 2 |
| 8 | Capital rules for credit institutions | Does not apply | Caught, right, 2 | Caught, wrong, 1 | Caught, wrong, 0 |
| 9 | Rule in a state where the group holds no license | Does not apply | Caught, wrong, 0 | Caught, right, 1 | Missed |
| 10 | Consumer credit guidance, UK | Does not apply | Caught, right, 2 | Caught, right, 1 | Caught, right, 2 |
| Result (fictional) | Vendor A | Vendor B | Vendor C |
|---|---|---|---|
| Caught, of 10 | 10 | 10 | 7 |
| Right calls, of 10 | 9 | 7 | 6 |
| Reasoning points, of 20 | 17 | 9 | 12 |
| Irrelevant alerts per week, live run | 7 | 38 | 3 |
| Median days from publication to owner, live run | 2 | 4 | 6 |
| Full record exports, dismissals included | Yes | No | Yes |
| Days to first triaged alert | 3 | 9 | 2 |
The team's own median last quarter was six days from publication to owner. Vendor B catches everything and costs the most attention: 38 irrelevant alerts a week would swamp a four-person team, it called two out-of-scope rules applicable, and it keeps no reasons for its dismissals. Vendor C is quiet partly because it missed three updates, including the state amendment the team itself found late. Vendor A misjudged the unlicensed state, a profile gap that setup would fix, and moved changes to an owner fastest. The trial supplies evidence for most of the scorecard; the RFP answers supply the rest.
A regulatory change management RFP needs 36 questions, each with evidence to request
These are the questions to ask regulatory change management vendors, grouped by the eight tests. Ask in writing, request the evidence in the last column, and score the evidence more than the prose. The workbook adds a response column and a 0 to 5 score for each vendor.
| # | Test | Question | Evidence to request |
|---|---|---|---|
| 1 | Coverage | For each regulator on our list, which source types do you monitor, and how: official feed, crawler or editorial team? | Coverage map against our list |
| 2 | Coverage | How often is each of our sources checked, and what was the lag from publication to your product over the last 90 days? | Latency log for our sources |
| 3 | Coverage | When a page shows only an updated date, how do you record the original publication date? | Two items showing both dates |
| 4 | Coverage | How do you detect a source that stops returning content, and how fast do you tell us? | Source-health log and a sample notice |
| 5 | Coverage | How long does adding a source we name take, and who does the work? | A source added and timed in the trial |
| 6 | Applicability | Which profile facts drive applicability (entities, licenses, products, customers, markets, thresholds), and who maintains them? | Profile schema and change log |
| 7 | Applicability | For an item marked applicable, show the scoping clause and the profile fact the call relied on. | Three reasoning records from the trial |
| 8 | Applicability | Are out-of-scope items kept with a reason, and can we review and overturn them? | One week of suppressed items |
| 9 | Applicability | How do you record a change that applies to one legal entity and not another? | An entity-level decision |
| 10 | Applicability | Can we tune relevance thresholds by topic or jurisdiction, with each change logged? | Configuration history |
| 11 | Obligation | Show an accepted item becoming an obligation with an owner, a deadline and an evidence requirement. | Live demonstration on trial data |
| 12 | Obligation | Can a first-line owner complete an attestation without training? | Unassisted test by one of our owners |
| 13 | Obligation | How are deadlines set: from the rule's effective dates, by us, or both? | Dates traced to the source |
| 14 | Obligation | When a consultation becomes a final rule, or a rule is amended, what reopens and who is told? | A lifecycle-change example |
| 15 | Obligation | How do obligations link to our policies and controls, and what happens to the links on amendment? | A record before and after an amendment |
| 16 | Decision record | Reconstruct one decision: what was published, when it was found, who decided, why, and what was done. | Exported record for a sampled item |
| 17 | Decision record | Are "not applicable" decisions recorded with a reason, a reviewer and a date? | Sample of dismissed items |
| 18 | Decision record | How would we detect an edited or deleted log entry? | Tamper-evidence mechanism and a check |
| 19 | Decision record | Can we export every item, decision, reason, user and timestamp in an open format, during the contract and at exit? | Sample export and exit clause |
| 20 | Decision record | How long are records kept, and can retention follow our policy? | Retention settings and contract wording |
| 21 | AI transparency | For a model's call, can we see the text it read, its output and the model or prompt version? | Run record for one item |
| 22 | AI transparency | Which steps run without a person, and can we require human approval before anything is dismissed? | Workflow configuration |
| 23 | AI transparency | How do you measure missed items and wrong calls, and will you report them on our trial data? | Trial metrics report |
| 24 | AI transparency | What happens when the model is unsure or a source fails? | Failure and fallback examples |
| 25 | Outputs | Produce last quarter's board pack from trial data with no manual editing. | Unedited board pack |
| 26 | Outputs | Can reports be cut by entity, business line, jurisdiction and owner, with RAG status on open obligations? | Filtered report |
| 27 | Outputs | What would we hand a regulator who asks how we handled one specific rule? | Single-rule evidence pack |
| 28 | Security | Where does the service run, and where is our data stored and processed, including by model providers? | Data-flow diagram and subprocessor list |
| 29 | Security | Is our content used to train or improve any model, by you or your providers, and what does the contract say? | Contract clause |
| 30 | Security | How are customers isolated from each other? | Architecture description |
| 31 | Security | Do you support SAML or OIDC single sign-on and role-based access? | Configuration guide |
| 32 | Security | Which independent security audits or certifications cover the service, with what scope and date? | Current reports under NDA |
| 33 | Commercial | What is the all-in price for our regulators, users and entities, and what costs extra: seats, jurisdictions, AI usage, translation, services? | Written all-in quote |
| 34 | Commercial | How long from signature to the first correctly triaged alert for customers like us, and how many admin hours a month should we plan? | Implementation plan with named roles |
| 35 | Commercial | Who owns you, which products are being merged or retired, and what happens to our price, contract and data on a change of control? | Change-of-control, assignment and price clauses |
| 36 | Commercial | Which two customers of our type and size, a year or more on the product, can we call? | Reference calls |
Nine red flags should end an evaluation early
Any one of these should stop the evaluation, or at least move the vendor to the bottom of the sheet:
- Coverage answered with a global count after you sent a list of named regulators.
- No stored reasoning for a suppressed item, or no suppressed items kept at all.
- Applicability reasoning that restates the summary without a clause or a profile fact.
- A refusal to run your sources or replay your quarter.
- "Not applicable" decisions with no reason, reviewer or date.
- An alert-to-obligation step that turns out to be a services project or a module priced later.
- AI usage, translation or added jurisdictions billed as overages, with no written all-in quote.
- Vague answers about where data is processed and whether it trains models.
- Roadmap promises that never reach the order form, especially from a vendor that was just acquired.
Count the reviews behind any star rating on a review site, and ask for reference calls with firms of your type and size (question 36).
A weighted scorecard turns the trial and the RFP answers into one comparable number
Score each criterion from 0 to 5 on evidence, multiply by its weight, add the products and divide by 5 for a total out of 100. Put your incumbent and the spreadsheet baseline on the same sheet; the workbook does the arithmetic for up to four vendors.
| Score | Meaning |
|---|---|
| 0 | Not offered, or the vendor declined to show it |
| 1 | Claimed in writing, not demonstrated |
| 2 | Demonstrated on the vendor's demo data |
| 3 | Demonstrated on your data, with gaps |
| 4 | Demonstrated on your data, meets the requirement |
| 5 | Demonstrated on your data, with evidence you can keep |
| # | Criterion | Weight | What a 5 looks like |
|---|---|---|---|
| 1 | Coverage of your named regulators and source types | 15 | Coverage map against your list, gaps admitted, a named source added in the trial |
| 2 | Applicability with cited reasoning | 20 | Right calls on your test set, each citing the scoping clause and a profile fact |
| 3 | From update to owned obligation | 15 | Owner, deadline and evidence set in the product; first-line owners attest unaided |
| 4 | Decision record and audit trail | 15 | Full export of any item, dismissals included, from a tamper-evident log |
| 5 | AI transparency and human review | 10 | Source text, reasoning, model version and reviewer visible for every call |
| 6 | Board and regulator outputs | 5 | Board pack and single-rule evidence pack straight from the record |
| 7 | Deployment, security and data use | 10 | Every CISO question answered in writing, with documents |
| 8 | Price, total cost and contract protections | 10 | Written all-in quote, known admin effort, change-of-control and export terms |
| Total | 100 |
Applicability carries the most weight because it is where a small team's hours go and where the reasoning an examiner reads is written. Adjust weights to your constraints and record why: a bank whose data must stay in its own cloud account might raise deployment and security to 20 and take 10 from coverage. In the worked example, Vendor A's applicability score of 4 adds 16 points (20 × 4 ÷ 5).
Three gates come before any total, and a vendor that fails one gets no score: the full decision record, dismissals included, exports in an open format; your CISO signs off on deployment and data use; and a written all-in price exists. The gates keep a strong demo from outscoring a requirement you cannot waive.
RegWatch fits teams whose bottleneck is applicability, and it is neither a GRC suite nor a news service
RegWatch, my company, is the third kind of product above, carried through to the obligation. In the terms of the eight tests, so you can check each point in a trial:
- Coverage: it monitors the regulators and sources you choose, on the schedule you set, through watchlists. Any jurisdiction that publishes its rules online can be configured; across customer watchlists, RegWatch monitors 95+ jurisdictions and 688 regulatory sources in production.
- Applicability and obligations: triage scores each finding against your company profile and writes why it matters, with the source clause cited. An accepted alert converts to an obligation with an owner, a deadline and evidence, and each item carries a lifecycle stage: Horizon, Proposal, Consultation, Adopted, In force, Amended, Sunset or Repealed.
- Record and outputs: decisions go to a tamper-evident, append-only audit log, and board-ready reports come from the same record.
- Security and deployment: SAML and OIDC single sign-on, tenant isolation enforced in the database with Postgres row-level security, and customer content not used to train generalized AI models by default. Private VPC runs in your own cloud account on AWS, Azure, Google Cloud, IBM Cloud, Oracle Cloud and others for $24,500 per year, with outbound HTTPS to model providers still required.
- Price: from $799 per month, also through AWS Marketplace or Azure Marketplace.
RegWatch Legal, the second product, adds cited Q&A over documents, Word redlines as tracked changes and tabular review, all drafts for professional review. RegWatch is not a GRC suite, so buy one if you need control testing, risk registers and audit management in one system, and it is not an editorial news service, so a content provider is the better buy for analysts' commentary on each development. It is also a young, independent vendor with its own continuity risk: ask us the ownership questions too.
Bring your own regulators to every demo, ours included
Whichever vendors make your shortlist, run last quarter through them before you sign, and file the scorecard where your auditor will find it. RegWatch, my company, will run the same test with you: book a demo, bring your regulator list and company profile, and the session runs on your own regulators, so you can score us with the workbook like everyone else. More dated comparisons are in the tools and comparisons hub.
Market facts in this article are stated as of 30 September 2026, from vendors' own pages and primary press releases, each linked and dated in the source list.
This article is general information, not legal advice.
Free, no email needed. Sheets: READ ME, Criteria and weights, RFP questions, Vendor scorecard, Trial log, Changelog. All templates
Questions
What is regulatory change management software?
Software that records how a regulated firm handles each regulatory change. It monitors the regulators and sources you name, decides or helps decide whether each update applies to your entities, turns applicable changes into obligations with owners, deadlines and evidence, and keeps a decision record an auditor or examiner can sample later, including the items judged not applicable. Products sold under the name range from regulatory content providers to GRC suite modules and AI-native monitoring tools.
How much does regulatory change management software cost?
Most vendors quote rather than publish. In our comparison of twelve horizon scanning tools, two published a price as of 30 September 2026: Bloomberg Regology's Professional plan at $1,700 per user per month on a three-year contract for US federal and state coverage, and RegWatch, the author's company, from $799 per month. Total cost also includes implementation services, integration, renewal uplift and the hours your team spends maintaining the company profile and watchlists.
What is the difference between regulatory intelligence software and regulatory change management software?
Regulatory intelligence software finds and analyzes regulatory developments: monitoring, summaries, taxonomies and alerts. Regulatory change management software carries an applicable change through to a result: an owned obligation, a deadline, evidence of completion and a record of every decision, including decisions that a change does not apply. Many products now do both, so test the handoff between the two, which is where changes stall.
Can ChatGPT replace regulatory change management software?
Not for the record an examiner samples. A general chatbot can explain a regulation you name, but it does not check a defined list of sources on a schedule, keep the original publication date and the passage it relied on, assign owners and deadlines, or leave an audit trail of who decided what and why. It can help draft and explain; the monitoring and the record need a system built for them.
How long does it take to implement regulatory change management software?
Ask each vendor, in writing, for the time from signature to the first correctly triaged alert for customers of your size, then check it in a trial, where the setup effort gives you a preview of the rollout. Most of the work sits with your team, because no vendor can write your regulator list, your company profile or your list of obligation owners for you.
What questions should you ask regulatory change management vendors?
Ask for evidence you can keep. Five questions expose weak tools quickly: show the stored reasoning for an item you suppressed last week; reconstruct one decision end to end from the record; run our regulator list and last quarter's updates; put every extra cost in a written all-in quote; and tell us who owns you and what our contract says if that changes. A full bank of 36 RFP questions, grouped by eight tests, is in the article.
Terms in this guide
Sources
- Regology: The State of Regulatory Compliance in 2026 (27 February 2026; survey of 204 compliance, legal and risk professionals) accessed 6 Oct 2026
- CUBE: The Cost of Compliance Report 2025 (4 November 2025) accessed 6 Oct 2026
- OCC: Comptroller's Handbook, Compliance Management Systems (version 1.0, June 2018) accessed 6 Oct 2026
- CUBE: completes acquisition of Thomson Reuters Regulatory Intelligence and Oden (PR Newswire, 2 January 2025) accessed 6 Oct 2026
- CUBE: CUBE Intel FAQs for renewals from 1 November 2026 accessed 6 Oct 2026
- CUBE: acquires 4CRisk (19 February 2026) accessed 6 Oct 2026
- CUBE and IBM: new collaboration announced (16 September 2026) accessed 6 Oct 2026
- Archer: acquires Compliance.ai (Business Wire, 20 February 2024) accessed 6 Oct 2026
- Compliance.ai: home page (Archer-branded) accessed 6 Oct 2026
- Corlytics: Corlytics and Clausematch come together (5 July 2023) accessed 6 Oct 2026
- Bloomberg Industry Group: acquires Regology (PR Newswire, 3 June 2026) accessed 6 Oct 2026
- Regology: Bloomberg acquisition FAQ accessed 6 Oct 2026
- Regology: pricing page accessed 6 Oct 2026
- Legora: acquires Graceview (6 May 2026) accessed 6 Oct 2026
- Legora: Introducing Monitors (2 June 2026) accessed 6 Oct 2026
- Harvey: Introducing Horizon Scanning (1 September 2026) accessed 6 Oct 2026
- Reddit, r/Compliance: thread on keeping track of regulatory changes (18 August 2026; comment cited from 29 August 2026) accessed 6 Oct 2026
- Reddit, r/Compliance: thread on a regulatory intelligence prototype for DACH and EU teams (20 March 2026) accessed 6 Oct 2026
- Reddit, r/ComplianceOps: thread on compliance vendors' AI agent claims (5 March 2026) accessed 6 Oct 2026
- Reddit, r/grc: thread on why teams still use Excel for compliance (9 May 2026) accessed 6 Oct 2026
