What Is Regulatory Horizon Scanning? A Guide for Compliance Teams
In short
Regulatory horizon scanning is the systematic collection of early signals about regulation that has not yet taken effect, and the UK Government Office for Science defines horizon scanning as collecting insights on emerging trends and weak signals of change. No law mandates it by name, but the US DOJ's compliance-program guidance and ISO 37301 both test for the capability, so the record of what you saw and dismissed matters more than the size of your feed.
Regulatory horizon scanning is the systematic collection of early signals about regulation that has not yet taken effect: proposals, consultations, political agreements, and rules that are adopted but not yet applicable. The point is to act on a deadline years before it bites. The definition of horizon scanning comes from the UK Government Office for Science's Futures Toolkit (updated 29 August 2024): "the systematic collection of insights on emerging trends and weak signals of change to identify potential threats, risks and opportunities."
Horizon scanning is not primarily a discovery problem you solve by buying a bigger feed, though much of the vendor content in this category treats it as one. Regulators already publish their own horizon scans, for free. The UK's Regulatory Initiatives Grid laid out 135 live initiatives across the next 24 months in its May 2026 edition. The harder work is triage discipline and an auditable record of each item seen, each item dismissed and the reason, which is what examiners probe.
This article is the pillar of our horizon scanning hub.
Horizon scanning is a 1967 management discipline, not a RegTech feature
The vocabulary predates every vendor selling it by decades. Francis J. Aguilar's Scanning the Business Environment (Macmillan, 1967) established environmental scanning as the practice of acquiring information about events and relationships in a company's outside environment to help management chart its future course of action. Aguilar was writing for general managers reading trade press and talking to customers. The method is the same one compliance teams run today against the Federal Register and EUR-Lex: cast a wide net, look for weak signals, feed them into planning.
The UK government professionalized the practice through its foresight program. The Government Office for Science's Futures Toolkit, the closest thing the discipline has to a canonical text, supplies both the definition quoted above and the Three Horizons framework this article builds on later: Horizon 1 is the established present, Horizon 2 the transition where "tomorrow becomes more apparent as today fades," and Horizon 3 the emerging patterns barely visible today. Other official methods follow the same shape. The UK National Screening Committee's horizon scanning approach lists six cyclical steps (identification, filtration, prioritization, assessment, dissemination, and follow-up), which is a workable skeleton for a compliance team too.
Regulatory horizon scanning is that discipline pointed at one specific outside environment: legislatures, regulators, standard-setters and courts. The compliance function adopted it because regulation is the rare domain where the future formally pre-announces itself. A regulation does not appear overnight; it travels through green papers, consultations, drafts, adoption and staged application dates. Each stage is a signal, and each signal is published.
Scanning ends where monitoring begins: the line is publication of binding text
The terms get used interchangeably, and the confusion costs teams real coverage gaps. The clean split:
- Regulatory monitoring detects what has been published as binding or is already in force: a final rule, an enforcement notice, updated guidance. It answers one question, "what changed?" It works inside a fixed source list.
- Regulatory horizon scanning covers what is proposed, consulted on, politically agreed, or adopted but not yet applicable. Its job is to see what is coming, and when, before the text is ever final, and to keep asking whether the source list and scope are still complete.
- Regulatory change management is what happens after either one fires: assessing impact, assigning owners, implementing, and evidencing. Obligations management sits at the end of that chain, maintaining the requirements that apply and tying them to evidence, so that a confirmed development can update the obligations record without anyone rekeying it.
A team that only monitors finds out about a regime when the implementation window is already half gone. A team that only scans drowns in consultations that never become law. You need both, feeding one change-management pipeline. I untangle the three terms (plus "regulatory intelligence," which vendors use to mean any of them) in Regulatory intelligence vs horizon scanning vs change management.
The horizon-scanning loop runs from sources to board report, with a feedback arrow most teams forget
In five verbs, a complete process does this: it detects a development from a relevant source, decides whether it matters to the organization, assesses its likely legal and business impact, assigns ownership and implementation work, and preserves the source, the reasoning and the evidence. Functioning programs, manual or automated, spread those five verbs across the same eight stages. Here they are with the object names we use inside RegWatch, because naming the stages precisely is half the battle:
| Stage | What happens | Who owns it | RegWatch object |
|---|---|---|---|
| 1. Sources | Regulators, official journals and consultations, tiered by authority | Compliance | Source |
| 2. Scan | New items retrieved in strict date windows | Agents or analysts (volume) | Finding |
| 3. Triage | Accept or suppress each item, with recorded reasoning | Agents propose, humans can audit | Alert |
| 4. Impact | Plain-language business impact mapped to products, entities and controls | Humans (judgment) | Alert detail |
| 5. Obligation | A named owner and a deadline: the unit of accountability | Humans (ownership) | Obligation |
| 6. Implement | Controls, policy updates and training | Humans (execution) | Obligation |
| 7. Evidence | An audit trail of decisions and artifacts | Both | Evidence and audit log |
| 8. Feedback | Outcomes tune the scanning profile: new sources, sharper exclusions | Compliance | Watchlist settings |
Two stages deserve emphasis because they are where programs actually fail.
Stage 3, triage, is the program. Forwarding a regulator's newsletter to a distribution list is not triage. Triage means documented inclusion and exclusion criteria, deduplication across sources and, this is the part almost nobody does, a recorded reason for every dismissal. When an examiner asks why you did not act on a consultation that later became a rule you missed, "we saw it and dismissed it because X, logged on this date" is a defensible answer and "it never came up" is not.
Stage 8, feedback, is what separates mature programs from busy ones. If an obligation blindsided you, the scanning profile was wrong: a missing source, an exclusion rule too aggressive, a jurisdiction not covered. Teams that never route outcomes back into the profile run the same blind spots for years.
The stage-by-stage build-out, with owners and time budgets, is its own article: The regulatory horizon scanning process: 7 steps from sources to board report. The output of stage 5 should land in a structured register; see our obligations register template and the obligations register glossary entry.
Most programs score worst on evidence: score your maturity on seven dimensions
Before reading anyone's pitch, including ours, score your current program. Rate each dimension 1 to 5 against the level descriptions below, honestly, and total the result. It takes ten minutes and it will tell you where the next quarter of effort belongs. The matrix below is the scorecard; copy it into a sheet and mark your level in each row.
| Dimension | 1: Reactive | 2: Informal | 3: Defined | 4: Managed | 5: Continuous |
|---|---|---|---|---|---|
| 1. Source coverage | We learn about rules when they are in force, from clients or peers | A few newsletters and one regulator's mailing list | Documented source list per jurisdiction, including consultations and drafts, not just final texts | Sources tiered by authority; coverage reviewed quarterly against misses | Curated source inventory across all operating jurisdictions, health-checked, with gaps flagged whenever a miss traces to a missing source |
| 2. Cadence and timeliness | Ad hoc: someone checks when they remember | Weekly-ish, skipped under workload | Fixed weekly cadence with a named runner and a backup | Daily for priority jurisdictions; publication-to-awareness lag measured | Scheduled automated retrieval in strict date windows; lag measured and reported |
| 3. Relevance triage | Everything found is forwarded raw | One person's gut call, nothing written down | Written inclusion and exclusion criteria; duplicates removed manually | Criteria versioned; suppression rates tracked; noise complaints investigated | First-pass triage runs automatically against a maintained relevance profile, with deduplication and documented exclusions, so people review reasoning instead of raw feeds |
| 4. Impact assessment | None: the item itself is the deliverable | A forwarded link with "FYI, relevant?" | Standard template: what changed, who is affected, by when | Impact mapped to specific products, entities and controls; severity rubric applied consistently | Draft impact analysis generated per item and reviewed by the accountable human before circulation |
| 5. Ownership and deadlines | Nobody is accountable for acting on a change | Actions live in email threads | Every accepted change becomes a register entry with a named owner and date | Register reviewed monthly; overdue items escalate | Every alert converts to a structured obligation with owner, deadline and status visible up to board level |
| 6. Evidence and auditability | No record of what was seen or decided | The sent-mail folder is the archive | A decision log exists for accepted items | Dismissals logged with reasons: what we saw and why we did not act | Tamper-evident audit trail of every accept and suppress decision with written reasoning, exportable for examiners |
| 7. Tooling and automation | Inbox and memory | Shared spreadsheet plus free alerts | RSS or keyword feeds into a tracked queue | Dedicated platform; alerts assigned to named owners | Collection and first-pass triage are automated with inspectable reasoning on every decision, so analyst hours shift to judgment rather than gathering |
Scoring bands (total across 7 dimensions, range 7 to 35):
| Total | Band | What to do next |
|---|---|---|
| 7 to 14 | Reactive | Stop firefighting first: fix dimensions 1 and 2 with a documented source list and a fixed weekly cadence. Our horizon scanning template is the fastest starting structure. |
| 15 to 24 | Developing | You collect but do not decide. Write triage criteria and start logging dismissals (dimensions 3 and 6); the seven-step process guide covers both. |
| 25 to 31 | Managed | The process works; now instrument it. Measure publication-to-awareness lag and overdue obligations, and report the radar to the board quarterly. |
| 32 to 35 | Anticipatory | Your constraint is analyst hours, not process. Evaluate automation for stages 2 and 3 (see the 2026 tools comparison) and protect human time for impact judgment. |
The dimension most teams score worst on is number 6, evidence. It is also the one regulators care about most.
Regulators run horizon scanning themselves, and publish the output for free
Vendor explainers rarely lead with the fact that regulators already do this work, at scale, and give the results away.
The UK Regulatory Initiatives Grid is the clearest example. It is published by the Financial Services Regulatory Initiatives Forum, which comprises nine organizations: the Bank of England, the CMA, the FCA, the FRC, HM Treasury (as an observer member), the ICO, the PRA, the PSR and The Pensions Regulator. The Forum compiles a consolidated, dated pipeline of upcoming UK financial-services regulation. The 10th edition, published on 19 May 2026, sets out the planned initiatives for the next 24 months: 135 live initiatives, a third of them joint between authorities. Its purpose is exactly a horizon scan's, and the FCA's Grid page lists the previous nine editions back to May 2020. Note the attribution: this is the Forum's Grid, hosted on the FCA's site, not an FCA-only product. The FCA's operational resilience observations (May 2024) also say that horizon scanning, to understand new and emerging risks and the proximity of their impact, is key to making sure testing is appropriate and controls are in place.
EMA's EU Innovation Network does the equivalent for medicines. This network of European national competent authorities runs a horizon-scanning function to identify emerging science, technologies and trends likely to shape the future regulation of human medicines, and there is even a 2026 peer-reviewed account of how EMA runs it.
In practice, if you operate in UK financial services or EU life sciences, a meaningful slice of your forward pipeline is already compiled, dated and free. Consume these regulator-published scans as tier-one sources. Then spend your effort where they stop: jurisdictions with no Grid equivalent (most of them), cross-sector regimes like the EU AI Act that no single sectoral forum owns, and above all the triage and impact work no regulator will ever do for your specific business.
No law mandates horizon scanning by name, but the DOJ and ISO 37301 evaluate the capability
Some vendor content implies horizon scanning is legally required. It is not, and saying so erodes trust with anyone who checks. No statute names it, but the people who evaluate your compliance program test for it.
The US Department of Justice. The Criminal Division's Evaluation of Corporate Compliance Programs (updated September 2024) tells prosecutors what to probe when deciding charges and penalties. Under policy-and-procedure comprehensiveness it asks, verbatim: "What efforts has the company made to monitor and implement policies and procedures that reflect and deal with the spectrum of risks it faces, including changes to the legal and regulatory landscape and the use of new technologies?" A separate risk-assessment prompt asks whether the company has "a process for identifying and managing emerging internal and external risks that could potentially impact the company's ability to comply with the law." That is a horizon-scanning capability, described without the label, in the document that shapes prosecutorial outcomes. (As of the September 2024 update.)
ISO 37301. The international compliance-management-system standard, ISO 37301:2021, requires under clause 4.5 that organizations systematically identify their compliance obligations and keep that identification current as obligations are created or amended. A certification audit against 37301 will ask how you learn about new and amended obligations: again, the capability without the label.
UK-regulated firms face the most explicit supervisory version of this expectation; I cover what the FCA actually asks for in FCA horizon scanning expectations. Across all three, nobody will fine you for lacking a document titled "Horizon Scanning Procedure." They will hold it against you when a change you should have seen coming becomes a violation and your file shows no record of ever having looked. That is why dimension 6 of the self-check, evidence of what you dismissed and why, outweighs any sophistication in discovery.
Your regulatory radar needs three horizons, and the EU AI Act just proved the rings move
The Futures Toolkit's Three Horizons framework maps cleanly onto a compliance radar. Think of three concentric rings, closest first:
| Ring | What it holds | How to work it |
|---|---|---|
| H1: in force, or applying within 6 months | Obligations you can already date | Execute: obligations, owners, deadlines |
| H2: 6 to 24 months out | Adopted rules not yet applicable | Plan: gap analysis, budgets, named workstreams |
| H3: 24 months or more, or direction not yet text | Consultations, drafts and political signals | Watch: scan monthly at low fidelity, follow the direction and not the wording |
The three-ring regulatory radar. A single page of dated entries, refreshed quarterly, is the best board artifact a compliance team can produce. Framing credit: Three Horizons, GO-Science Futures Toolkit.
Populated with real entries as they stand on 30 September 2026:
| Ring | Example entries (as of 2026-09-30) | Source |
|---|---|---|
| H1: applying within 6 months | Most of the UK Basel 3.1 package (final rules published 20 January 2026) applies from 1 January 2027, with the internal model approach for market risk delayed to 1 January 2028; EU AI Act prohibitions on non-consensual intimate deepfakes and child sexual abuse material, and the Article 50(2) marking deadline for systems already on the market, apply from 2 December 2026 | Grid, May 2026; EC AI framework page; Regulation (EU) 2026/1744 |
| H2: adopted, applying in 6 to 24 months | The UK regime for cryptoassets, including stablecoins, commences in October 2027; EU AI Act high-risk rules for stand-alone Annex III systems apply 2 December 2027, and for systems embedded in products (lifts, toys, medical devices) 2 August 2028 | Grid, May 2026; EC AI framework page |
| H3: 24 months or more, direction not yet text | FCA consultation on a resolution regime for cryptoasset custodians and stablecoin issuers (expected in H2 2026); HM Treasury's proposals to reform the Appointed Representatives regime (consultation published February 2026) | Grid, May 2026 |
The AI Act's rings just moved. The regulation entered into force on 1 August 2024 with a published glide path: prohibitions from 2 February 2025, GPAI and governance rules from 2 August 2025, general application plus high-risk obligations for stand-alone Annex III systems from 2 August 2026, and high-risk obligations for product-embedded Annex I systems from 2 August 2027. Then, on 7 May 2026, the EU's co-legislators reached a trilogue agreement on the digital "AI omnibus." Parliament approved it on 16 June 2026 and the Council adopted it on 29 June 2026; it was signed on 8 July 2026, published in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744, and entered into force on 27 July 2026. Both high-risk tranches slipped: the Annex III obligations that many teams had project-planned against 2 August 2026 moved to 2 December 2027, and the product-embedded Annex I obligations moved from 2 August 2027 to 2 August 2028, per the European Commission's regulatory framework page (last updated 3 August 2026). The Commission's guidelines on classifying high-risk systems are still in draft, so the text you plan against can still move at the edges.
A static compliance plan written in 2024 is now wrong twice over: it misses the delay (wasted urgency on some workstreams) and misses what did not move. The AI Act did become applicable on 2 August 2026, the AI Office's power to enforce the rules for general-purpose AI model providers is now live, and the AI-literacy duty in Article 4 survived in softer form: providers and deployers must still take measures to support their staff's AI literacy, though they need not guarantee any specific level. Only a program that re-scans the horizon regularly catches both the moves and the holds. If you deploy AI systems in the EU, our EU AI Act compliance checklist for deployers tracks the current dates.
For a board, this one page, refreshed quarterly, answers the "regulatory radar" question better than any feed or dashboard.
The benefits worth claiming are the ones you can evidence
Every explainer on this topic lists the same five benefits with little evidence. I have kept only the ones I can source.
The volume is unmanageable without a system. Thomson Reuters Regulatory Intelligence monitored 61,228 regulatory events in 2022, the third-highest annual total since 2008, covering 1,374 regulators in 190 countries and equivalent to an average of 234 daily alerts (2022 data, from its 2023 Cost of Compliance report; it shows the scale, not a current count). Nobody reads 234 items a day and also does impact analysis. More context in how many regulatory changes happen per year.
The people accountable rank this as their top problem. KPMG's 2024 Global CCO Survey of 765 chief compliance officers found that new regulatory requirements were the challenge CCOs cited most often (34%), and 84% expect regulatory expectations and scrutiny to increase over the next two years. Seven in ten expect their technology budgets to rise to match. The demand for this capability comes from CCOs describing their own pain.
Runway is the payoff, and DORA proved it. The EU's Digital Operational Resilience Act (Regulation (EU) 2022/2554; glossary primer) was adopted in late 2022 and applied from 17 January 2025. Teams scanning in 2022 got roughly two years to inventory ICT third parties, build the register of information and negotiate contract remediation. Teams that noticed in mid-2024 did the same work in panic mode, at panic-mode consulting rates, and that cost gap on an identical obligation is the return on horizon scanning.
Relevance, not access, is the scarce resource. In Regology's February 2026 survey of 204 compliance, legal and risk professionals, 85.3% said they monitor regulatory updates, but only 30.9% said the alerts they receive are always relevant (Regology, 2026; a small sample, and Regology is a competitor). Triage is where the value is created or lost.
AI changes the economics of scanning, not the accountability
The collection and first-pass triage stages of the loop (stages 2 and 3) are exactly the shape of work language models are good at: high volume, pattern-heavy, cross-lingual and checkable. No human team staffs dozens of jurisdictions on a compliance budget, and that is the economics changing.
What must not change is who answers for the judgment. Two design rules follow, and I hold every tool, including ours, to them:
- Every decision carries inspectable reasoning. When RegWatch's triage agent scores an item, it writes plain-language reasoning against the company's profile, accepted items carry it as "Why this matters," and the decisions people then make on each alert go to a tamper-evident, append-only audit log. An AI decision you can't explain to an examiner is a liability, which makes human-in-the-loop an evidence requirement.
- Humans own impact and ownership (stages 4 and 5). An agent can draft the impact analysis; the accountable officer decides it. The DOJ's September 2024 ECCP update asks how companies identify and manage emerging risks, including risks related to the use of new technologies, so running compliance on an unexplainable black box would sit badly with the very document you are trying to satisfy.
For how agent-based scanning works under the hood, see AI agents for regulatory compliance; for why a raw chatbot is the wrong tool for this job, can you use ChatGPT for regulatory horizon scanning?; and for the vendors, the 2026 tools comparison.
Build the discipline first, then buy software to make it cheap
For a mid-size multinational scoring below 25 on the self-check, I would take these four steps in order and buy nothing until step three:
- Subscribe to the regulator-published scans that cover you. The Regulatory Initiatives Grid if you touch UK financial services; EMA's horizon-scanning outputs for life sciences; your primary regulators' consultation pages everywhere else. Cost: zero. Time: an afternoon.
- Open a dismissal log this week. A shared register with five columns (date seen, item, source, decision, reasoning) converts your existing informal scanning into examinable evidence immediately. It is the cheapest maturity point on the whole table, and the one the DOJ's questions bite on. Structure it with the horizon scanning template.
- Draw your radar and put it in front of the board. Three rings, real dates, quarterly refresh. The AI Act example above is a ready-made illustration of why this is not bureaucratic theater: the rings moved in 2026 and can move again.
- Automate collection only after steps 1 to 3 exist. Tooling amplifies a process; it cannot substitute for one. When analyst hours on stages 2 and 3 become your binding constraint, that is the moment to evaluate platforms, ours included.
This article is general information, not legal advice.
Questions
What is the difference between horizon scanning and regulatory monitoring?
Regulatory monitoring detects what has already been published or is already in force. Horizon scanning covers what is proposed, consulted on, or adopted but not yet applicable. The UK Government Office for Science defines it as collecting insights on emerging trends and weak signals of change, and the UK Regulatory Initiatives Grid shows the difference by publishing a two-year forward pipeline rather than a news feed.
Is regulatory horizon scanning a legal requirement?
No regime mandates it by that name. But the US DOJ's Evaluation of Corporate Compliance Programs asks whether policies deal with changes to the legal and regulatory landscape, and ISO 37301:2021 clause 4.5 asks organizations to identify their compliance obligations systematically and keep that identification current. Examiners evaluate the capability even though no statute names it.
How far ahead should regulatory horizon scanning look?
At minimum two years, which is the pipeline the UK's Regulatory Initiatives Grid deliberately covers. Major regimes phase in over longer periods: the EU AI Act's obligations span 2025 to 2028. A three-horizons radar tracks the next 0 to 6 months, 6 to 24 months, and 24 months or more, each at a different level of detail.
Who should own horizon scanning in an organization?
The compliance function, under the CCO. KPMG's 2024 survey of 765 chief compliance officers found that new regulatory requirements were the challenge they cited most often (34%), and 84% expect regulatory expectations and scrutiny to keep rising. Compliance owns scanning and triage, business units own implementation of accepted changes, and the board gets the radar view.
Can AI do regulatory horizon scanning?
AI handles the volume problem: Thomson Reuters Regulatory Intelligence counted 61,228 regulatory events in 2022, about 234 per day, which no team reads manually. But triage judgment must stay inspectable. Every accept or dismiss decision needs recorded reasoning a human can audit, because the accountability stays with the compliance officer.
Terms in this guide
Sources
- UK Government Office for Science, The Futures Toolkit (updated 29 August 2024) accessed 30 Sep 2026
- Aguilar, Scanning the Business Environment (Macmillan, 1967) accessed 30 Sep 2026
- UK National Screening Committee, approach to horizon scanning accessed 30 Sep 2026
- FCA, Regulatory Initiatives Grid accessed 30 Sep 2026
- FCA, Regulatory Initiatives Grid, May 2026 (10th edition) accessed 30 Sep 2026
- EMA, EU Innovation Network accessed 30 Sep 2026
- Frontiers in Medicine, Horizon scanning at EMA: preparing for the medicines of the future (16 April 2026) accessed 30 Sep 2026
- FCA, Operational resilience: insights and observations accessed 30 Sep 2026
- US DOJ Criminal Division, Evaluation of Corporate Compliance Programs accessed 30 Sep 2026
- ISO 37301:2021 Compliance management systems accessed 30 Sep 2026
- European Commission, Regulatory framework for AI (application timeline, last updated 3 August 2026) accessed 30 Sep 2026
- European Parliament Legislative Train, Digital Omnibus on AI accessed 30 Sep 2026
- Thomson Reuters Regulatory Intelligence, Cost of Compliance 2023 (2022 regulatory event data) accessed 30 Sep 2026
- KPMG, Global CCO Survey 2024 accessed 30 Sep 2026
- Regulation (EU) 2022/2554 (DORA), EUR-Lex accessed 30 Sep 2026
- Regology, The State of Regulatory Compliance in 2026 (27 February 2026) accessed 30 Sep 2026
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), EUR-Lex accessed 30 Sep 2026
