Proving Compliance, Decision by Decision

Updated: 1 day ago

For most financial institutions, compliance is demonstrated in aggregate. Policies are documented. Controls are described. Procedures are tested on samples. Reports are produced periodically. When an examiner arrives, the institution shows that its framework exists and generally works.
That model is under pressure. Regulators and supervisors increasingly ask not whether the framework exists, but whether a specific decision, about a specific customer, on a specific date, complied with the rules in force at that moment. Answering that question for one decision is laborious. Answering it for thousands is often impossible.
The question that defines the next generation of compliance is precise: was this decision compliant with the institutional policy in force, and can the institution demonstrate it?
Why aggregate compliance is no longer enough
Three changes are pushing compliance from the framework level to the decision level.
Automation multiplies decisions. When onboarding, monitoring and screening decisions are automated, their volume grows by orders of magnitude. Sampling a few hundred cases from millions says little about the rest.
Rules change constantly. Regulations, internal policies and risk appetites are updated regularly. Each change raises a question that aggregate compliance can't answer: which decisions were made under the old rule, which under the new, and were any made under the wrong one?
Scrutiny is case-specific. Complaints, disputes, investigations and litigation concern individual decisions. A well-documented framework doesn't help much if the institution can't reconstruct the decision in question.
What decision-level compliance requires
Demonstrating compliance decision by decision rests on four capabilities.
Versioned policy. Every policy, whether a customer acceptance policy, an AML monitoring rule or a screening threshold, exists in explicit versions, each with an effective date and an approval record. At any moment, the institution knows exactly which version was in force.
Decisions linked to policy versions. Every decision records the exact policy version that produced it. That turns "was this compliant?" from an investigation into a lookup.
Evidence captured at decision time. The decision record stores what the institution knew when it decided: the documents, checks and data, as they were, not as they are now. Compliance is judged against what was known, not against information that arrived later.
Reconstructable outcomes. Given the recorded evidence and the policy version, the decision can be reproduced exactly. That is what makes the record a demonstration rather than an assertion.
Three applications
Business customer onboarding
Onboarding a business customer involves a sequence of decisions: is the information sufficient, are the beneficial owners identified, does the risk profile fall within appetite, is enhanced due diligence required?
With a versioned acceptance policy, each onboarding decision records the policy version applied, the evidence considered and the outcome: accept, reject, accept with conditions, or escalate for enhanced review. When the acceptance policy changes, the institution can identify every customer onboarded under the previous version and decide, deliberately, whether any need review.
AML monitoring decisions
AML monitoring generates alerts, and every alert leads to a decision: close it, investigate further, or escalate toward a suspicious activity report. These decisions are among the most scrutinized in banking, and among the hardest to reconstruct.
When each alert disposition is recorded as a decision, with the rule that generated the alert, the evidence reviewed, the analyst's authority, the justification and the outcome, the institution can demonstrate, for any alert, why it was handled the way it was. Patterns in dispositions, such as an analyst who closes alerts much faster than peers, become visible.
Regulatory change on past decisions
When a rule changes, institutions face a difficult question: what about decisions already made?
With decision-level records, that question can be answered systematically. The institution can simulate the new rule against past decisions, identify which outcomes would have differed, and decide what to do: nothing, review, or remediate. That turns regulatory change from a source of uncertainty into a managed process.
The boundary: decisions, not data
Decision-level compliance depends on good data, such as identity verification, registry information, sanctions lists and adverse media. Those are specialized services with established providers.
The decision layer doesn't replace them. It consumes their outputs as evidence, applies the institution's policy, issues typed decisions and records everything. That separation keeps each component focused: data providers verify facts, and the decision layer governs what the institution does with them.
Compliance as a byproduct
The most important consequence of decision-level compliance is a change in how compliance work is done.
In the traditional model, compliance evidence is produced after the fact: reports compiled, samples tested, documents assembled for examinations. It is expensive, periodic and always somewhat behind.
When every decision is recorded with its policy version, evidence and outcome, compliance evidence is produced continuously, as a byproduct of operating. Examiners can be given direct, verifiable access to decision records. Internal audit can test every decision instead of a sample. Reports become queries.
What institutions should be able to show
Which version of each policy was in force at any date, and who approved it.
For any decision, the exact policy version that produced it.
The evidence available at the moment of the decision, as it was then.
The reproduction of any decision from its recorded evidence and policy.
Every human intervention, with authority and justification.
The impact of a policy change on past decisions, before and after it takes effect.
Records in a format examiners can review and verify directly.
From asserting to demonstrating
Compliance has always been about trust: regulators trusting that institutions follow the rules. That trust has traditionally rested on assertions supported by samples.
The next model replaces assertion with demonstration. Not "our framework ensures compliance," but "here is the decision, here is the rule that applied, here is the evidence, and here is the proof that it was not altered."
Was this decision compliant with the policy in force, and can we demonstrate it? Every institution should be able to answer that question, for every decision.
Want to see how decision-level compliance could work in your institution? Talk to our team →

Comments