Most discussion of regulatory risk management concerns structure: frameworks, committees, appetite statements, control libraries. Yet in firms with mature frameworks, the variability in outcomes rarely...
In most firms, PEP screening and sanctions screening grew up separately. They run against different lists, often on different schedules, sometimes owned by different teams. Yet the exposure they are looking...
Two AML compliance APIs can be sent the same entity, on the same day, with the same matching logic, and return different answers. The difference is rarely in the endpoint. It sits in the source set each...
A counterparty can be assessed three times inside the same firm and produce three different answers. The business team runs a check at onboarding, the compliance function reviews an escalation two months...
Most control frameworks are written as if the rules hold still for a year. They do not. The OFSI and OFAC sanctions lists change frequently, new designations land between policy reviews, and FCA expectations...
Most discussion of regulatory risk management concerns structure: frameworks, committees, appetite statements, control libraries. Yet in firms with mature frameworks, the variability in outcomes rarely comes from the structure. It comes from the information underneath, what the firm actually knows about its counterparties, its markets and the obligations that apply to each. A framework processes inputs. When the inputs are thin, stale or untraceable, the framework processes them anyway. This article works from the data layer upward, and examines what better information changes about the decisions a framework produces.
A well-documented framework applied to incomplete information produces ratings that are confident and unreliable at the same time. The methodology is followed, the scoring matrix is applied, the sign-off is recorded, and the risk assessment still lands wrong, because the analyst assessing a counterparty knew a fraction of what was publicly knowable about it.
There is a point in every programme where further process design stops improving outcomes. Refining the scoring bands does not help if the underlying compliance check missed the enforcement action reported in another jurisdiction. Adding a second reviewer does not help if both reviewers read the same incomplete file. Past that point, input quality is the constraint, and effort spent on structure is effort spent on the wrong layer.
This is uncomfortable because frameworks are visible and inputs are not. A regulatory risk committee can inspect a methodology document. It is much harder to inspect what the assessments running through that methodology did not contain. The firms that have examined solutions for regulatory risk management tend to arrive at the same conclusion: the framework was never the weak point.
Three attributes decide what an assessment is worth, and each has a concrete meaning in a regulatory risk context.
Coverage is the scope of sources in play. An assessment drawn from a web search and a company website rests on what those two sources happen to show. One drawn from licensed news across jurisdictions and languages, corporate registries, sanctions and watchlists, and enforcement reporting rests on materially more. Source coverage determines whether the regulatory action against a counterparty in its home market is in the file or invisible to it. The same logic extends to third party risk management, where vendor risk assessments routinely depend on whatever the vendor chose to disclose.
Currency is when the sources were last checked. An assessment describes the position on the day it was made. The counterparty's ownership, licence status and litigation exposure all move afterwards, and a rating that was accurate at onboarding can be describing a company that no longer exists in that form. Currency is not the same as recency of the review; a review completed last week against sources that had not been refreshed adds a recent date to old information.
Provenance is whether each finding traces to a named origin and date. A risk rating built on findings that carry their source can be re-examined and defended. One built on unattributed notes depends on the memory of whoever wrote them. In regulatory due diligence, the difference decides whether a challenged rating survives the challenge.
Weak inputs rarely surface as an obvious failure. They surface as inconsistency, and the symptoms are easy to misread as process problems.
Two similar counterparties in the same sector carry different risk ratings, because their assessments were built by different analysts working from different ad hoc searches. A rating changes on re-review with no new event behind the change; the second analyst simply found material the first one never saw. An assessment cannot be explained twelve months later without the original analyst in the room, because the file records the conclusion but not the evidence base it rested on.
A fourth symptom appears at portfolio level. The distribution of ratings clusters around the middle band, not because the portfolio is genuinely medium-risk but because analysts working from thin information default to the defensible centre. High ratings need evidence to justify escalation, low ratings need evidence to justify comfort, and an evidence-poor assessment can support neither.
Each of these looks like an execution problem: training, diligence, individual judgement. The instinctive response is more process, another template, another checklist, a tighter methodology. But the analysts were applying the framework correctly to different information. Until the input layer is standardised, so that every assessment draws on the same data for risk management at the same depth, the inconsistency survives every process fix, and the data quality problem keeps presenting itself as a people problem.
An assessment is a statement about a point in time. From the day it is signed off, it decays, and the rate of decay depends on the counterparty and the environment around it. A stable domestic supplier in a lightly regulated sector may hold for a year. A counterparty operating across volatile jurisdictions, or in a sector where the rulebook is moving, can be out of date within a quarter, a dynamic examined in managing regulatory risk in a shifting rulebook.
Refresh cycles should follow that logic rather than the calendar alone: risk-based intervals, with higher-rated entities re-reviewed more frequently and the interval itself recorded as part of the rating decision. The annual blanket review treats every assessment as decaying at the same speed, which no portfolio actually does, and it spends review capacity on stable relationships that could have gone to the volatile ones.
There is also a difference in kind between periodic re-review and monitoring for change. Re-review asks, at an interval, whether the position has moved. Monitoring watches the sources continuously and raises the question when something happens: new enforcement reporting, an ownership change, adverse coverage. Mature programmes run both, and treat the refresh interval as the backstop rather than the mechanism.
Nexis Diligence+ supplies the input layer that the preceding sections describe. A single entity search runs across licensed news in multiple languages, company and registry information, sanctions and watchlists, and biographical sources, giving every assessment the same source coverage regardless of which analyst runs it.
Each finding is dated and attributed, so the governance, risk and compliance record shows not only the conclusion but the evidence it rests on: which source, which date, which document. A regulatory risk rating built this way can be produced later, in front of a reviewer or a regulator, exactly as it stood on the day it was made. Nexis Diligence+ also supports the ongoing side of the cycle, with alerts that monitor an entity between reviews so a stale assessment is flagged by events rather than discovered at the next calendar refresh.
The framework above the data does not change. What changes is that every rating it produces rests on the same depth of evidence.
Strengthen Your Risk Assessments with Nexis Diligence+
Frameworks make risk decisions consistent. Data quality makes them correct. A regulatory risk management programme needs both, but the two failures look different: structural weakness shows up in audits, while input weakness shows up as ratings that vary, drift and cannot be defended under challenge. Improving the information layer improves every output above it, from individual regulatory risk assessment through to the portfolio view the committee sees. For teams reviewing why their outputs vary, the data foundations are the place to look first, and Diligence+ is built to supply them.