Policy management for financial services: how to be audit-ready

By Dan Hawtrey
Policy management for financial services: how to be audit-ready

Compliance in financial services is complex and is only getting more so. Regulators and bodies such as the FCA in the UK and the SEC and FINRA in the US have the power to impose significant fines that can reach into the tens or hundreds of millions. Senior individuals may be required to be listed as accountable for different areas. They can even be named in a lawsuit. This puts enormous pressure on compliance professionals to ensure everything is watertight. Even beyond the demands of being in a regulated sector, there is a range of other legislation to consider, from employment law to whistleblowing to accessibility requirements.

It’s no surprise that PwC found that 85% of compliance and governance leaders believe that compliance requirements have become more complex over the past three years, and Regology found that 92% of compliance professionals say their job is also getting more difficult.

The challenges around financial services policy management

The challenge of a multi-layered regulatory landscape is felt by the compliance team in areas such as policy management.

Regulators have gone beyond wanting to know that you have policies and that they tick all the appropriate boxes. They now want to know that your policies are up to date. They want evidence that employees are actually following them. And they want to see a robust system in place to make sure all of that happens.  How you manage and govern policies and procedures is as critical as what the policies say. It’s as much about the “how” as it is about the “what”.

One core issue is that, while the need for more robust and comprehensive governance and management practices has grown, the tools that manage policies have not necessarily kept pace.  As we will see, in many financial services companies, policy management has numerous challenges.

What policies do financial services companies have in place?

Any financial services provider will potentially have huge numbers of policies across different areas, including:

  • Regulatory and compliance: covering everything from anti-money laundering to fraud prevention to tackling financial crime to how to frame financial promotions.
  • Governance & risk: from governance structures to whistleblowing to disaster recovery policies.
  • Data protection & security: ensuring information security and data privacy, including how to respond to a data breach.
  • Employment & HR: everything from legal requirements to disciplinary procedures and recruitment processes.
  • Client delivery: all matters relating to working with clients and providing financial advice.
  • Operational policies: important policies like procurement and IT that are important to the everyday running of the business
  • Health & safety: a range of key policies to ensure people stay safe.

For global companies, different versions of these documents may also be required across jurisdictions and locations, or even for different groups of employees.

Financial services policy management: typical challenges

The sheer number of policies and procedures is certainly a factor in making financial services policy management complex, but challenges are frequently due to a lack of a fit-for-purpose solution and limited governance applied to policy lifecycle management.

How regulators view these challenges?

A regulator will take a dim view of a bank or wealth management firm that fails to meet   challenges around policy management and cannot demonstrate:

  • a robust and systematic approach to making sure that policies have named owners and reviewers, established approval workflows and a system to track the status of where each policy is in its review lifecycle.
  • that employees have read and understood relevant policies, with a timestamp for when that happened, and which version of a policy it applies to.
  • an accurate audit trail of any changes to a policy, who made that change, when it was done and what the change was.
  • a proactive, systematic, comprehensive and effective approach to policy management in operation.
  • evidence for all the above during an inspection, at short notice if necessary.

Imagine a regional or challenger bank, or a mid-size wealth management company, that is two weeks away from a compliance-related visit and faces challenges across these areas. Not only will there be two weeks of frenetic and stressful activity, but there will also likely be gaps, incomplete records, policy owners who have since left the business, data errors, and so on.

The regulators are very used to seeing this kind of piecemeal and hurried response, with gaps in the evidence, and know that it is, to some extent, papering over the cracks rather than demonstrating the systematic, well-governed, and effective policy management system they want to see.

How financial services companies can be audit-ready?

Financial services companies need to be “audit-ready” so they can quickly produce evidence that they have policy management under control and support a broader culture of compliance. The best way to achieve this is by investing in a policy management solution that is genuinely fit for purpose for a complex, fast-moving, and highly regulated sector like financial services.

An audit-ready system has several elements in place.

Supporting financial services policy management

Financial services policy management is challenging for multiple reasons. Without tackling these issues, the job of compliance teams becomes much harder.

Investing in a policy management solution like Xoralia can do some of the heavy lifting. It can get you on the road to audit readiness and ease the pressure on compliance professionals.

Want to see how Xoralia might help your team?  Arrange a free demo.

About the author

Photo of Dan Hawtrey

Dan Hawtrey

CEO and product lead

Dan Hawtrey is CEO of Content Formula and the driving force behind Xoralia, a policy management platform built natively on Microsoft 365. Dan writes regularly on policy management, compliance, and the evolving role of AI in how organisations manage knowledge. His articles are grounded in real conversations with the companies and teams using Xoralia day to day.

Related articles

See Xoralia in action

In a 30-minute demo you will see how Xoralia runs inside your own Microsoft 365 tenant - from distribution and attestation through to a continuously built audit trail.

  • Start your free Xoralia trial

    Try the full platform in your own SharePoint tenant. No credit card required.

  • See how Xoralia works in SharePoint

    Explore the product: library, workflows, targeting, attestation, and reporting.

  • How organisations use Xoralia

    Read how regulated teams cut admin and stay audit-ready with Xoralia.

  • What manual policy management is costing you

    Estimate the time and risk you can take out of reviews, chasing, and audits.