Compliance monitoring plan
A risk-based, dated schedule of what the compliance function will monitor and test, how often, by what method and with whom responsible.
A compliance monitoring plan is the compliance function's written, risk-based schedule of what it will monitor and test over a period, how often, by what method and with whom responsible. For investment firms under MiFID II it is a legal requirement: Article 22(2) of Commission Delegated Regulation (EU) 2017/565 requires the compliance function to "establish a risk-based monitoring programme" covering all of the firm's investment services and activities, with priorities "determined by the compliance risk assessment ensuring that compliance risk is comprehensively monitored."
Banking guidance says much the same. The Basel Committee's BCBS 113 (paragraph 43) says the compliance function's responsibilities "should be carried out under a compliance programme that sets out its planned activities," such as policy reviews, compliance risk assessment, compliance testing and staff education, and that the program "should be risk-based."
A usable plan typically records:
- the scope: entities, business lines, products and jurisdictions covered;
- the compliance risk assessment that sets priorities, and the date it was last refreshed;
- each monitoring activity, with its method (file review, data analysis, walkthrough), frequency and owner;
- the sources and cadence for tracking regulatory change, so new obligations enter the plan;
- how findings are rated, escalated, remediated and reported to senior management.
The regulatory change element is often the weakest. A plan built only around testing existing rules will not notice when the rules move. That is why the scope of regulatory horizon scanning, meaning the jurisdictions, business lines and topics in view, belongs in the same document, and why each accepted change should update both the plan and the obligations register. How to write that scanning scope is covered in step 1 of the regulatory horizon scanning process.
This entry is general information, not legal advice.
