Skip to content
Compliance Management That Actually Holds Up: A Practical Framework for Financial Institutions
Compliance Risk Management

Compliance Management That Actually Holds Up: A Practical Framework for Financial Institutions

William C Hord
William C HordChief Strategy Officer - ERM Pilot

ERM Pilot | Compliance Risk Management Series by William Hord, Chief Strategy Officer

Talk to any compliance officer after an examination and you'll often hear a version of the same complaint. The institution wasn't necessarily out of compliance — it just couldn't prove it was in compliance, quickly and consistently, in the format the examiner needed. That gap between "we do this" and "we can show you exactly how, where, and when" is where most Matters Requiring Attention actually come from.

I've spent enough time on both sides of the exam table to know that a compliance program isn't a binder, a policy library, or a spreadsheet of regulations. It's a chain of logic that has to hold together end to end: regulation → obligation → gap → control/policy/evidence → assessment and finding. Break any link, and the rest of the chain becomes decoration. Let's walk through how that chain actually gets built in practice.

Step 1: Define the Regulatory Universe Before You Do Anything Else

You can't manage what you haven't inventoried. The starting point is a complete, current regulatory universe — every law, rule, and supervisory expectation that applies to your institution based on charter type, product mix, geography, and asset size. For a bank, that means working from the OCC's, FDIC's, or Federal Reserve's expectations depending on your primary regulator; for a credit union, it means NCUA's rules and guidance. Consumer financial protection laws generally apply regardless of charter, which is why the CFPB's Compliance Management Review examination procedures explicitly expect a compliance management system that's built into the full product and service lifecycle, not bolted onto it afterward.

The mistake I see most often here is treating the regulatory universe as static. It isn't. New products trigger new obligations, geographic expansion triggers new state-law overlays, and regulators themselves periodically update expectations — the FFIEC BSA/AML Examination Manual, for instance, is revised on an ongoing basis as risk-focused examination priorities shift. Your regulatory universe needs an owner and a review cadence, not a one-time inventory exercise.

Step 2: Translate Each Regulation Into Discrete, Testable Obligations

A regulation is not an obligation. 12 CFR 1030 is a regulation; "disclose the annual percentage yield using the standard formula before the account is opened" is an obligation. This translation step is where most compliance programs quietly lose rigor, because it's tempting to leave requirements at the regulation level and assume everyone "knows what it means."

The OCC's Comptroller's Handbook booklet on Compliance Management Systems is explicit that an effective CMS depends on policies and procedures that translate legal requirements into specific, actionable staff guidance. Practically, that means building an obligations register: one row per discrete requirement, with a citation back to the source regulation, an assigned owner, a review frequency, and a status. NCUA frames this the same way for credit unions in its guidance on Compliance Management Systems and Compliance Risk, noting that the depth of a credit union's CMS should scale with its size and complexity — but the underlying discipline of turning regulatory text into owned, trackable obligations doesn't change based on asset size.

Step 3: Run the Gap Analysis — and Be Honest About Exceptions

Once you know what's required, the next question is uncomfortable but necessary: what are we actually doing today, and where does it fall short? This is the gap analysis, and it only works if it's adversarial rather than confirmatory. You're not looking for reasons the current state is fine; you're looking for the specific place where an obligation and your documented practice diverge.

The Federal Reserve's SR 08-8 / CA 08-11 guidance on compliance risk management makes a point that applies well beyond large banking organizations: risk assessments are the foundation of an effective compliance monitoring and testing program, and the scope and frequency of testing should be a function of that risk assessment — not a fixed calendar. In practice, that means your gap analysis output should feed directly into where you test hardest and how often, and every identified gap needs a documented exception with a remediation owner, a target date, and — critically — a decision on interim risk acceptance if the fix will take time. An exception without an owner and a date isn't a tracked risk; it's a rumor.

It's also worth knowing what an unresolved gap turns into. For OCC-supervised institutions, a gap that goes unaddressed can surface in an exam as a Matter Requiring Attention (MRA) — the OCC's own language describes an MRA as a practice that deviates from sound governance, internal controls, or risk management, and that could hurt earnings, capital, or risk profile, or result in noncompliance with law, if it isn't corrected. That's a useful mental model even outside an OCC relationship: a gap you've tracked and are actively remediating is a managed risk; a gap that sits quietly until an examiner finds it is a finding waiting to happen.

Step 4: Link Processes, Controls, Policies, and Evidence Into One Chain

This is the step that separates a documented compliance program from a defensible one. Every obligation should trace forward to: the business process it governs, the control(s) that enforce it, the policy or procedure that authorizes those controls, and the evidence that demonstrates the control actually operated. If you can't walk that chain in one sitting for any given obligation, you have documentation, not a compliance management system.

Structurally, this is where governance roles matter. The IIA's Three Lines Model is useful here even outside internal audit circles: first-line business units own and operate the controls day to day, second-line compliance and risk functions design the framework and provide oversight and challenge, and third-line internal audit provides independent assurance that the first two lines are functioning as intended. When ownership is ambiguous — when nobody's title actually maps to a given control — evidence retention becomes an afterthought, and that's exactly where exam findings tend to cluster. The FDIC's Consumer Compliance Examination Manual is structured around this same expectation: a sound CMS integrates board and management oversight, a compliance program, and independent review into a single accountable structure, not three disconnected activities.

Evidence, specifically, deserves its own discipline. "We have a policy" is not evidence a control operated; a sampled, dated, retrievable record that ties back to the specific transaction or period under review is. If your evidence isn't linked to the specific obligation and control it supports, you'll spend exam week doing forensic reconstruction instead of production.

It helps to know what "evidence" concretely means to an examiner walking in the door. The OCC's CMS booklet points to the same short list every time: board and committee minutes showing the board actually reviewed compliance information, a current organizational chart, a written description of key controls, records of staff training, and the last several cycles of internal or external audit reports. None of that is exotic — but if you can't produce all five for a given business line in the time it takes to make coffee, your evidence chain has a gap the obligation-to-policy mapping alone won't have caught.

Step 5: Assess, Document Findings, and Close the Loop

Assessment is where the chain gets tested against reality. The CFPB's CMR framework, for example, is built around board and management oversight, the compliance program itself, service provider oversight, and — critically — a violations-of-law and consumer-harm module that gets triggered whenever testing surfaces something material. That structure is worth borrowing even if the CFPB isn't your primary regulator: assess the design of the control, test whether it actually operated, and separately evaluate whether any gap caused — or could cause — consumer or institutional harm.

Findings need the same rigor as obligations: a clear statement of the requirement, the evidence of the gap, a root cause (not just a symptom), a corrective action plan with an owner and date, and a validation step before the finding is closed. This is also where BSA/AML programs offer a useful model beyond their specific scope — the requirement for independent compliance testing under 12 CFR 748.2(c) and the equivalent expectations in the FFIEC manual exist precisely because self-assessment without independent validation tends to understate real exposure. Build that independence into your broader compliance testing, not just your BSA program.

The Throughline

None of this is exotic. It's the same discipline regulators have described for years, from the FTC's Safeguards Rule requirements under the Gramm-Leach-Bliley Act to SR 08-8 to the CFPB's CMR manual — build a program that management actually operates day to day, not one that gets assembled the week before an exam. The institutions that walk into an exam calmly aren't the ones with the thickest binders. They're the ones who can pull any single obligation and, in a few clicks or a few minutes, show the regulation, the obligation, the control, the policy, and the evidence — connected, current, and consistent.

That's the standard worth building toward, one obligation at a time.

Sources & References:

  • Consumer Financial Protection Bureau, Compliance Management Review Examination Procedures — https://www.consumerfinance.gov/compliance/supervision-examinations/compliance-management-review-examination-procedures/
  • Federal Financial Institutions Examination Council, BSA/AML Examination Manual — https://bsaaml.ffiec.gov/manual
  • Office of the Comptroller of the Currency, Comptroller's Handbook — Compliance Management Systems — https://www.occ.gov/publications-and-resources/publications/comptrollers-handbook/files/compliance-mgmt-systems/index-compliance-management-systems.html
  • Office of the Comptroller of the Currency, Comptroller's Handbook — Compliance Management Systems (full booklet PDF) — https://www.occ.gov/publications-and-resources/publications/comptrollers-handbook/files/compliance-mgmt-systems/pub-ch-compliance-management-systems.pdf
  • Office of the Comptroller of the Currency, Appeal of Matters Requiring Attention (Third Quarter 2012) — https://www.occ.gov/topics/supervision-and-examination/dispute-resolution/bank-appeals/summaries/files/appeal-matters-requiring-attention-q3-2012.html
  • National Credit Union Administration, Compliance Management Systems and Compliance Risk — https://ncua.gov/regulation-supervision/manuals-guides/federal-consumer-financial-protection-guide/compliance-management/compliance-management-systems-and-compliance-risk
  • Electronic Code of Federal Regulations, 12 CFR § 748.2 — Procedures for Monitoring Bank Secrecy Act (BSA) Compliance — https://www.ecfr.gov/current/title-12/chapter-VII/subchapter-A/part-748/section-748.2
  • Board of Governors of the Federal Reserve System, SR 08-8 / CA 08-11, Compliance Risk Management Programs and Oversight at Large Banking Organizations with Complex Compliance Profiles — https://www.federalreserve.gov/supervisionreg/srletters/SR0808.htm
  • Federal Deposit Insurance Corporation, Consumer Compliance Examination Manual — https://www.fdic.gov/consumer-compliance-examination-manual
  • The Institute of Internal Auditors, The IIA's Three Lines Model: An Update of the Three Lines of Defense — https://www.theiia.org/en/content/position-papers/2020/the-iias-three-lines-model-an-update-of-the-three-lines-of-defense/
  • Federal Trade Commission, Safeguards Rule (Gramm-Leach-Bliley Act, 16 CFR Part 314) — https://www.ftc.gov/legal-library/browse/rules/safeguards-rule

Ready to transform your risk management?

Discover how ERM Pilot can streamline your compliance, automate workflows, and provide real-time insights for your organization.

Stay Updated on ERM Pilot

Join our newsletter to receive the latest news, feature updates, and expert insights on all things risk related.

We respect your privacy. Unsubscribe at any time.