Regulatory change impact assessment

A regulated organization's own analysis of a specific new rule: whether it applies, what it changes, and which owned, deadlined actions follow.

A regulatory change impact assessment is the document a regulated organization writes when a specific new or amended rule lands: what the instrument is, whether it applies (with written reasoning either way), which entities, products, processes, contracts and controls it touches, and which owned, deadlined actions follow. It is the step in regulatory change management that turns a detected change into a plan. US bank examiners test for it without naming it: the OCC's Compliance Management Systems handbook expects management to respond to change "by evaluating the change and implementing responses across affected lines of business," and to "review the change after implementation to determine that actions taken have achieved planned results."

It should not be confused with a regulatory impact assessment, which a rule-maker writes before regulating to weigh the costs and benefits of a proposal. The change impact assessment is the mirror image: it starts from a rule that already exists and works out what the organization must do about it.

A complete assessment answers five questions:

  1. What changed, and what is the legal status of the source?
  2. Which entities, jurisdictions, products and activities are in scope?
  3. What changes for policies, controls, systems, people and third parties?
  4. Which actions are required, who owns them, and by when?
  5. What evidence supports the conclusion and will prove completion?

The most valuable output is often a documented "no material impact" decision. A dated out-of-scope conclusion with two sentences of reasoning is a defensible answer when a supervisor asks whether an instrument was considered; a blank row is not. Accepted outcomes should create or amend rows in the obligations register and be recorded in the regulatory change log.

A six-section template, completed end to end for Commission Delegated Regulation (EU) 2025/532, the DORA subcontracting standard that entered into force on 22 July 2025, is in our regulatory change impact assessment template.

This entry is general information, not legal advice.

Sources

  1. OCC Comptroller's Handbook, Compliance Management Systems (Version 1.0) accessed 30 Sep 2026
  2. Commission Delegated Regulation (EU) 2025/532, EUR-Lex accessed 30 Sep 2026

Know which changes apply to your business.

RegWatch reads the regulators you choose and explains every change it surfaces.

Book a demo