Regulatory Horizon Scanning Template: Free Framework and Excel Download
In short
A regulatory horizon scanning template is a register with one row per pre-effective regulatory development, and this one has 21 columns across six worksheets, free as an Excel file with no email gate. The worked example is the EU AI Act high-risk deadline, which the Digital Omnibus on AI moved from 2 August 2026 to 2 December 2027 for stand-alone Annex III systems.
Free, no email needed. Sheets: READ ME, Horizon Register, Source Directory, Scoring rubric, Monthly report, Changelog. All templates
A regulatory horizon scanning template is a register: one row per pre-effective regulatory development, with columns for the instrument and citation, lifecycle stage, impact, proximity to the application date, a named owner and a next action. The one on this page has 21 columns across six worksheets, and the Excel file is free with no email gate. The official alternative, GOV.UK's horizon scanning template (published 29 August 2024 by the Government Office for Science), is a short ODT example built for policymakers doing futures work, and it says so: it is "an example," to be adapted.
A horizon-scan register is a dated pipeline of instruments with owners, not a trends radar, and plenty of horizon-scanning material would dispute that. STEEP wheels, weak-signal matrices and futures radars come from foresight practice, and they are fine tools for strategy teams. A regulatory horizon scanning register answers a narrower, harder question: which rules are coming, when do they bind us, who owns our response, and can we prove we decided? Every column below exists to answer that question. (If you want the discipline itself defined from primary sources first, start with What is regulatory horizon scanning? and come back for the tooling.)
Foresight templates were built for futures work, not for compliance records
The GOV.UK template is a useful reference point because it is official, and it shows what a foresight template optimizes for: it belongs to the UK Futures Toolkit and serves policymakers scanning for emerging trends. It has no applicability decision, no owner column, no citation field, and nothing an auditor would recognize as a compliance record.
That gap shapes what "good" means here. A compliance-grade register has to survive two tests that foresight templates never face: an internal auditor asking why was this item dismissed and who decided?, and a deadline that moves after you have already planned around it. The first test drives the applicability-plus-rationale columns. The second happened in 2026, when the EU AI Act's high-risk deadline moved by sixteen months, and that move is the worked example running through this whole template.
The register carries 21 columns because a compliance record has to survive two tests a foresight template never faces
The Excel file has six worksheets, each with one job:
| Sheet | What it is | Why it exists |
|---|---|---|
| 1. READ ME | Purpose, cadence (weekly capture, monthly report, quarterly deep scan), versioning, not-legal-advice note | Lets the register survive staff turnover |
| 2. Horizon Register | The core tracker: 21 columns, one row per development, with data-validation dropdowns | Holds the dated pipeline |
| 3. Source Directory | 15 pre-filled official forward-look sources with URLs, cadence and what each tells you | Most capture failures start with a missing source, not a spreadsheet gap |
| 4. Scoring rubric | Written H/M/L impact definitions plus an impact × proximity priority matrix | Makes two reviewers score the same item the same way |
| 5. Monthly report | Annotated report framework with three filled example rows | Turns the register's data into the committee output |
| 6. Changelog | Date, change, author | Records who changed what and when, so any row can be dated |
Here is the full register, column by column, with a worked example filled in from one real regime, the EU AI Act high-risk deferral, exactly as I would enter it as of 30 September 2026:
| # | Column | What goes in it | Worked example: EU AI Act high-risk deferral |
|---|---|---|---|
| 1 | Ref ID | HS-YYYY-###, never reused |
HS-2026-014 |
| 2 | Date captured | When it entered the register | 2026-05-08 |
| 3 | Jurisdiction | Dropdown; one row per jurisdiction if impacts diverge | EU |
| 4 | Regulator or issuing body | The body whose act binds you | European Commission and EU co-legislators |
| 5 | Instrument and citation | Precise instrument, article-level where known | Regulation (EU) 2024/1689 Art 6(2), Annex III and Art 113; amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI) |
| 6 | Source (name and URL) | Link the primary text or official tracker, never press coverage | Regulation (EU) 2026/1744, Official Journal of 24 July 2026 |
| 7 | Source tier | A = official text (OJ, Federal Register); B = official forward-look (Grid, Unified Agenda); C = consultation, draft or speech; D = industry press | A (published text); it was tier B at trilogue stage |
| 8 | Lifecycle stage | Signal, Consultation, Adopted, In force, Enforcement observed | In force (amending act in force 27 Jul 2026; high-risk rules not yet applicable) |
| 9 | Plain-language summary | 2 to 3 sentences a non-lawyer can act on | Application of high-risk AI obligations deferred from 2 Aug 2026 to 2 Dec 2027 (stand-alone Annex III) and 2 Aug 2028 (embedded in Annex I products) |
| 10 | Business areas affected | Dropdown or multi-select | AI product governance; model risk; procurement |
| 11 | Applicability | In scope / Monitor / Out of scope | In scope |
| 12 | Decision rationale | Why in or out; the audit trail | We deploy an Annex III system (candidate screening); the deferral changes the conformity timeline, not scope |
| 13 | Impact (H/M/L) | Against the Sheet 4 rubric, not gut feel | H |
| 14 | Proximity | Months to application date | About 14 months (to 2 Dec 2027) |
| 15 | Priority | Auto from the impact × proximity matrix | P1 |
| 16 | Key dates ("as of" dated) | Consultation close, adoption, application | Trilogue 7 May 2026; Parliament 16 Jun 2026; Council 29 Jun 2026; signed 8 Jul 2026; OJ 24 Jul 2026; in force 27 Jul 2026; application 2 Dec 2027. As of 30 Sep 2026 |
| 17 | Owner | A name, not a department | Head of Compliance |
| 18 | Next action and due date | The single next step | Re-baseline the conformity plan against 2 Dec 2027 by 30 Oct 2026 |
| 19 | Status | New / Assessed / Assigned / In implementation / Closed / Deprioritized | Assigned |
| 20 | Linked obligation ID | Ties into your obligations register once adopted | OB-2026-031 |
| 21 | Last reviewed | Date a human last confirmed the row is still true | 2026-09-30 |
Two design choices deserve defending, because most trackers omit both. Column 12 (decision rationale) exists because the dismissals are half the audit value: "out of scope, we hold no EU authorization" written down in March is what protects you in an examination in November. Column 21 (last reviewed) exists because regulatory facts rot, which the worked example is about to demonstrate.
The worked example follows an EU AI Act deadline that moved sixteen months
If you ever need to convince a budget holder that a horizon register needs lifecycle-stage and last-reviewed columns, this is the story to tell, because it happened between review cycles of the same row.
The AI Act's original schedule, set by Article 113 (European Commission AI Act Service Desk), staggered application: prohibitions from 2 February 2025, GPAI and governance provisions from 2 August 2025, the bulk of the regulation (including most high-risk obligations) from 2 August 2026, and Article 6(1) classification from 2 August 2027. Any register row created in 2024 or 2025 correctly showed high-risk obligations landing in August 2026.
Then the row went stale. The Digital Omnibus on AI reached trilogue agreement on 7 May 2026. After Parliament's approval on 16 June 2026, Council adoption on 29 June 2026 and signature on 8 July 2026, the Official Journal carried it on 24 July 2026 as Regulation (EU) 2026/1744, in force from 27 July 2026. It replaced the original dates with fixed ones and dropped the standards-linked trigger the Commission had proposed: 2 December 2027 for stand-alone high-risk AI systems under Annex III, and 2 August 2028 for high-risk AI embedded in products regulated under Annex I. The Commission's timeline page (last updated 3 August 2026) now states those dates.
And the deferral is not a blanket delay, which is why the summary column names the specific obligations that moved rather than saying "AI Act delayed." The general application date of 2 August 2026 stood, and the AI Office can now enforce the rules for general-purpose AI model providers. The Article 50 transparency obligations also started on 2 August 2026, with one carve-out: systems already on the market get until 2 December 2026 to comply with the marking and detection duty in Article 50(2). New prohibitions on non-consensual intimate deepfakes and child sexual abuse material apply from 2 December 2026, and the deadline for national regulatory sandboxes moved to 2 August 2027. One amending act leaves you tracking five dates (2 August 2026, 2 December 2026, 2 August 2027, 2 December 2027 and 2 August 2028), more than a single "AI Act" row can hold. Log the deferral as its own row, and keep separate rows for the obligations that kept their dates.
Walk through what the register just did. A team whose row still said "2 Aug 2026, source: a vendor blog from 2025" was either burning budget against a deadline that no longer applies or, worse, had learned to distrust its own tracker. A team with the lifecycle-stage column, the "as of" dates in column 16 and the review discipline of column 21 caught the move at trilogue stage, re-scored proximity from 3 months to 19, and re-planned calmly. The only variable between those two teams was the columns.
Pre-populate the source directory from regulators' own forward-look publications
The strongest argument against buying a "regulatory radar" from a template farm is that regulators already run horizon scanning on themselves and publish the output free. Sheet 3 ships pre-filled with 15 sources, most of them regulators' own forward looks; these are the anchors:
| Source | What it tells you | Cadence | Format |
|---|---|---|---|
| UK Regulatory Initiatives Grid (FCA-hosted, Forum-published) | The UK financial-services pipeline over 24 months; the 10th edition (19 May 2026) carries 135 live initiatives across the Forum's regulators | Twice a year, per the Grid itself | PDF and interactive dashboard (earlier editions also as spreadsheets) |
| US Unified Agenda (reginfo.gov) | Every federal agency's planned rulemakings, semiannual in principle under EO 12866 and 5 U.S.C. 602 | Spring and fall in principle, but irregular: the edition after Spring 2025 arrived in July 2026 | Web, searchable |
| Federal Register | Proposed and final US rules as they publish | Daily | Web, API |
| EUR-Lex and the Official Journal | Adopted EU law, the tier-A source of record | Daily | Web, feeds |
| European Commission Work Programme | The EU's planned legislative initiatives for the year | Annual | PDF, web |
| EBA, ESMA and EIOPA work programs | Each ESA's planned mandates, consultations and technical standards | Annual | PDF, web |
| Bank of England and PRA policy pages | UK prudential pipeline; feeds the Grid | Ongoing | Web |
| EC AI Act Service Desk | The Commission's own application timeline for the AI Act, article by article | Ongoing | Web |
| KPMG Regulatory Barometer | A free, published example of a horizon-scan-style report that scores aggregate regulatory pressure on UK and EU financial services (7.2 in April 2026, from 7.3 in October 2025) | About twice a year | |
| GOV.UK Futures Toolkit template | The futures-method cousin (29 Aug 2024): useful for strategy scanning, not compliance | Static | ODT |
Every row in the directory records the cadence because the cadence sets your scanning schedule. Daily sources (Federal Register, OJ) justify weekly capture; forward looks that publish once or twice a year, and sometimes skip an edition (the Grid, the Unified Agenda), justify the quarterly deep scan where you reconcile your register against the regulators' own pipeline and ask what you missed.
This directory is weighted toward financial services because that is where forward-look publishing is richest. If you sit outside financial services, swap the sector-specific rows (the Regulatory Initiatives Grid, the EBA, ESMA and EIOPA work programs, and the Bank of England and PRA pages) for your own regulators' equivalents; the Federal Register, EUR-Lex and the Official Journal, the Unified Agenda and the European Commission Work Programme stay useful for everyone.
Score impact and proximity against a written rubric, or two reviewers will never agree
Much guidance on horizon scanning says "assess the impact" without saying how, which is how the same consultation gets scored High by the analyst who read it and Low by the one who did not. Sheet 4 fixes the words in place:
| Rating | Financial | Operational | License to operate |
|---|---|---|---|
| H | Material cost at entity level: capital, reporting, repricing or remediation budget | New systems, new roles or a multi-function change project | Touches an authorization condition, or enforcement precedent already exists |
| M | Absorbable within one budget cycle | Process or policy change inside one function | Likely supervisory attention; no authorization risk |
| L | Negligible direct cost | Documentation-level updates | No plausible near-term supervisory interest |
Score the higher of the three dimensions, then cross it with proximity (column 14) to get the priority that drives the register's sort order:
| Impact ↓ / Proximity → | 6 months or less | 7 to 18 months | More than 18 months |
|---|---|---|---|
| H | P1: act now | P1: act now | P2: plan |
| M | P1: act now | P2: plan | P3: monitor |
| L | P2: plan | P3: monitor | P3: monitor |
The worked example lands where the matrix says it should: high impact at 14 months' proximity is still P1, because a conformity-assessment program for an Annex III system is a multi-quarter build. The matrix exists to stop "it's not until December 2027" from becoming "so we'll look at it in 2027."
The monthly horizon scanning report turns the register from a database into a decision
A register that never gets read does no compliance work. Sheet 5 is the output layer: a one-page monthly report your risk committee can absorb in five minutes. Its structure:
- TL;DR change table: every item that moved this month, with what changed, who is affected, the deadline and the recommended action.
- Per-item detail: 3 to 5 sentences each, the deadline stated "as of" the report date, and the next action named with an owner.
- What we're watching next: the opinionated forecast: consultations closing, votes scheduled, editions due.
- Register health: items added, closed and overdue for review.
The workbook ships with three example rows filled in; the first reads like this in the example report for July 2026:
| What changed | Who's affected | Deadline | Recommended action |
|---|---|---|---|
| The Digital Omnibus on AI was signed on 8 Jul 2026 and entered into force on 27 Jul 2026: high-risk obligations now apply from 2 Dec 2027 (stand-alone Annex III) and 2 Aug 2028 (Annex I embedded). The general application date of 2 Aug 2026 is unchanged. | Deployers and providers of high-risk AI systems | 2 Dec 2027 (was 2 Aug 2026) | Re-baseline the conformity roadmap; keep transparency and GPAI work on its own schedule |
The other two example rows are one item from the 10th edition of the Regulatory Initiatives Grid (19 May 2026) and the release of the 2026 Unified Agenda in July 2026, each dated as of the report, so they date themselves honestly rather than pretending to be evergreen.
Monthly reporting on a 2027 pipeline sounds premature; the implementation data says otherwise. CUBE's Cost of Compliance Report 2025 put the share of firms taking more than a year to implement new regulations at 74%, from a survey of 2,000+ senior compliance, risk and legal leaders across 11 markets published on 4 November 2025. When implementation runs a year or longer, a register that only starts moving at adoption has already burned its runway. The monthly report is where horizon scanning hands off to regulatory change management, and where column 20 links each accepted item into your obligations register.
The horizon scanning process flow chart is a register pipeline, not a foresight radar
Foresight radars and futures-studies flow charts are built for a different job. The register implements a compliance-specific flow in six stages:
| Stage | What happens | Where it lives |
|---|---|---|
| 1. Sources | Official forward-look publications are the input | Sheet 3, the Source Directory |
| 2. Capture | Weekly: new rows are added and tier A to D is tagged | Sheet 2, columns 1 to 8 |
| 3. Triage | In scope, monitor or out of scope, with the rationale logged | Columns 11 and 12 |
| 4. Impact assessment | H/M/L impact × proximity via the rubric | Columns 13 to 15 and Sheet 4 |
| 5. Obligation and owner | In-scope adopted items get a named owner and link to the obligations register | Columns 17 and 20 |
| 6. Report | Monthly, to the risk committee | Sheet 5 |
Two rules keep the flow honest. Out-of-scope items stay in the register with their rationale and are never deleted. And a quarterly review loop re-scores open items, updates "last reviewed" and reconciles the register against each new Grid or Unified Agenda edition, so nothing passes unreconciled.
Cadence, anchored to how the sources actually publish: weekly capture (the Federal Register and OJ publish daily; a week is the widest window that will not embarrass you), monthly report (matches committee cycles), and quarterly deep scan (matches the once-or-twice-a-year rhythm of the Grid and the Unified Agenda). The step-by-step operating guide for each stage of this flow is its own article: the regulatory horizon scanning process.
One UK-specific note, since heads of compliance ask whether any of this is mandatory. No FCA rule says "horizon scanning." SYSC 6.1.1R requires a firm to maintain adequate policies and procedures sufficient to ensure it complies with its obligations under the regulatory system (FCA Handbook, SYSC 6.1, as of 30 September 2026), and it is difficult to evidence that standard with no documented view of incoming change. UK supervisors test for the capability without ever mandating the label, and the legal claim goes no further than that.
Horizon registers die by deleting dismissals, sourcing from press and skipping the obligation handoff
Building a radar instead of a register. Foresight radars track themes ("AI regulation is heating up"); a compliance register tracks instruments (Regulation (EU) 2024/1689, Art 6(2) and Annex III, applying 2 December 2027, owner named). Themes look good in a board deck, but you cannot test them against a citation or a date, and every row in the register needs both.
Deleting out-of-scope items. The dismissal with rationale is the half of the register auditors care most about, because it proves triage happened. Out-of-scope rows get status "Closed" and stay put.
Sourcing from press coverage. Column 6 links the primary text or the official tracker. Secondary coverage mis-dates things (republication dates, or agreement in principle reported as settled law), and the AI Act example shows how expensive a wrong date is.
No last-reviewed discipline. A register where column 21 says 2025 on an EU AI row is worse than no register, because it gives false confidence. Stale rows are the reason living documents need a visible regulatory change log, including this one.
Never linking to obligations. A register that produces awareness but never an owned obligation changes nothing. Column 20 is the handoff: each in-scope, adopted item becomes an entry in the obligations register with an owner, a deadline and evidence. If that column is still empty after six months, nobody is acting on the register.
Use the spreadsheet until it hurts, then automate the reading, never the judgment
This spreadsheet is sufficient for a team watching one or two jurisdictions and a handful of regulators. Fill Sheet 3, hold the weekly capture slot sacred, and you will outperform most paid "regulatory radar" subscriptions, because your register carries decisions and owners, not headlines.
It breaks as the footprint grows. Nobody sustains weekly manual capture across ten jurisdictions in a spreadsheet, and a register that stops being maintained keeps looking authoritative long after it has quietly gone stale. (The fuller version of that argument, with the thresholds, is in regulatory change tracker spreadsheet.)
When teams move this workflow onto RegWatch (my company's product), the template maps closely, because the template is the workflow. Sheet 3 becomes the Sources on a watchlist, each tracked with a health status. Weekly capture becomes scheduled monitoring runs against a Watchlist, producing Findings inside strict date windows, each with its source URL, dates and a verbatim excerpt. Triage becomes an Alert with a written "Why this matters" for each accepted item (column 12 for the in-scope rows, generated instead of typed), and a suppressed finding stays on record with that status. Column 20 becomes a one-click Obligation with an owner and an effective date, and evidence attached. The judgment calls (is this in scope, how hard does it hit us) stay human, with the reasoning inspectable either way.
Start with the spreadsheet: it costs nothing and it is yours. It builds the discipline of dated rows, logged dismissals and named owners, which any tool you graduate to should have to prove it can match.
More templates and living trackers are in the trackers and templates hub, and the horizon-scanning hub holds the full horizon-scanning series.
This article is general information, not legal advice.
Free, no email needed. Sheets: READ ME, Horizon Register, Source Directory, Scoring rubric, Monthly report, Changelog. All templates
Questions
What should a regulatory horizon scanning template include?
One row per pre-effective regulatory development, with columns for the instrument and citation, a link to the primary text, source tier, lifecycle stage, an in-scope or out-of-scope decision with written rationale, impact and proximity scores against a written rubric, key dates each marked 'as of', a named owner, a next action and a last-reviewed date. The official GOV.UK template (29 August 2024) has none of the compliance fields because it was built for government policymakers.
What is the difference between horizon scanning and regulatory change management?
Horizon scanning detects the pre-effective pipeline: consultations, drafts, adopted-but-not-applicable rules, and forward-look publications such as the UK Regulatory Initiatives Grid (135 live initiatives in its 10th edition, 19 May 2026). Regulatory change management implements what has been adopted. The handoff matters because implementation is slow, so detection that starts at adoption starts too late.
How often should horizon scanning be done?
Anchor the cadence to how the sources publish: the Federal Register and the EU Official Journal publish daily, the US Unified Agenda is semiannual in principle (though editions have arrived irregularly), and the UK Regulatory Initiatives Grid says it is published twice a year. A workable minimum is weekly capture into the register, a monthly horizon report, and a quarterly deep scan that re-scores every open item.
Is regulatory horizon scanning a legal requirement?
No major rulebook uses the phrase. In the UK, FCA SYSC 6.1.1R requires firms to maintain adequate policies and procedures sufficient to ensure compliance with their obligations under the regulatory system, a standard that is hard to evidence without a documented view of incoming change. Examiners test for the capability; no rule mandates the label.
What free sources can I use for horizon scanning?
Regulators publish their own forward looks free: the UK Regulatory Initiatives Grid (PDF and interactive dashboard), the US Unified Agenda at reginfo.gov, the European Commission Work Programme, the EBA, ESMA and EIOPA annual work programs, and the daily Federal Register and EUR-Lex feeds. KPMG's Regulatory Barometer is a free example of what a horizon-scan-style report looks like.
Terms in this guide
Sources
- GOV.UK, Horizon scanning: template (Government Office for Science, 29 August 2024) accessed 30 Sep 2026
- European Commission, Regulatory framework for AI (application timeline, last updated 3 August 2026) accessed 30 Sep 2026
- European Parliament Legislative Train, Digital Omnibus on AI accessed 30 Sep 2026
- EU AI Act Service Desk, Article 113: entry into force and application accessed 30 Sep 2026
- FCA, Regulatory Initiatives Grid accessed 30 Sep 2026
- reginfo.gov, Unified Agenda of Federal Regulatory and Deregulatory Actions accessed 30 Sep 2026
- Federal Register accessed 30 Sep 2026
- EUR-Lex accessed 30 Sep 2026
- KPMG, Regulatory Barometer accessed 30 Sep 2026
- KPMG, Regulatory Barometer, October 2025 edition (archived copy, 4 January 2026) accessed 1 Oct 2026
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), EUR-Lex accessed 1 Oct 2026
- Federal Register, Introduction to the Unified Agenda of Federal Regulatory and Deregulatory Actions, 2026 (14 August 2026) accessed 1 Oct 2026
- FCA Handbook, SYSC 6.1 accessed 30 Sep 2026
- CUBE, The Cost of Compliance Report 2025 accessed 30 Sep 2026
