Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Compliance Strategy

Compliance Calendar KRIs: How to Track Deadlines Before They Become Findings

Most compliance teams find out about missed deadlines when a regulator asks. These KRIs catch deadline risk before it shows up as an MRA—covering upcoming obligations, owner slippage, evidence completeness, and late filing history.

By Rebecca Leung · June 1, 2026 ·
Table of Contents

You’re in an exam. The examiner asks to see your SAR filings for a specific period. You hand over the log, and thirty seconds later they’re flagging three filings that were four days late. The conversation shifts from “how does your BSA program work” to “why did this happen and what are you doing about it.”

That’s how a missed deadline becomes a finding. Not because you didn’t know the obligation existed—you did. Because nobody was tracking whether the machinery behind it was running on time.

A compliance calendar tells you what’s due. Compliance calendar KRIs tell you whether you’re on track to hit it.

TL;DR

  • A compliance calendar without KRIs is a list. KRIs are what turn it into a risk signal.
  • The most useful metrics track forward: upcoming deadlines without owners, evidence completeness days before due, and owner acknowledgment lag.
  • Lagging metrics (missed filing count, breach rate) are still essential—they tell you whether your forward indicators are working.
  • Regulatory deadline failures that generate the most findings: SAR/CTR filings, FINRA Rule 4530 disclosures, annual certifications, and exam response deadlines.

Why Your Compliance Calendar Isn’t a Risk Tool

Most compliance calendars are built as reference documents. They list obligations, due dates, and owners. Someone updates them after a filing is made. The calendar tells you what happened, not what’s about to go wrong.

The gap becomes obvious when something slips. The owner who was supposed to pull CTR data this week is out sick. The FINRA 4530 disclosure you thought was handled by legal is actually sitting in a draft someone forgot to send. The NYDFS annual certification is due February 15 and today is February 10.

None of that shows up in the calendar because the calendar only shows the deadline—not whether you’re positioned to hit it.

KRIs plug that gap. They monitor the leading and lagging signals that indicate whether your compliance calendar process is actually working, rather than just existing.

The Regulatory Deadlines That Generate the Most Findings

Before talking about the KRIs, it helps to anchor on what’s actually at risk. Not every deadline failure is equal. Some generate immediate regulatory consequences; others surface as findings during exams.

Hard statutory filing deadlines carry the highest risk. FinCEN’s BSA regulations require currency transaction reports (CTRs) to be filed within 15 calendar days of the triggering transaction, and suspicious activity reports (SARs) within 30 days of initial detection of suspicious activity (with an additional 30-day extension available if no suspect is identified). These are not soft targets—late filings are a BSA violation, and pattern failure is an MRA or enforcement action.

FinCEN’s $390 million enforcement action against Capital One in January 2021 included failure to file thousands of SARs and failure to file approximately 50,000 CTRs on more than $16 billion in cash transactions. In March 2026, FinCEN assessed its largest-ever penalty against a broker-dealer: an $80 million civil money penalty against Canaccord Genuity, in part for failing to file at least 160 SARs over a three-year period. In both cases, the underlying monitoring reports existed—they just went unreviewed, and the filings were never made.

FINRA Rule 4530 requires member firms to report specified regulatory events, judgments, and associated-person actions within 30 days of when the firm knew or should have known. Late 4530 filings appear regularly in FINRA’s monthly disciplinary actions. The fine per occurrence is modest, but volume signals a broken compliance calendar process.

NYDFS Part 500 annual certifications are due every February 15. Covered entities that fail to file—or file after the deadline—get flagged immediately; the NYDFS knows who submitted and when.

Examination response deadlines are often overlooked as KRI candidates. When an OCC or FDIC examiner sends an information request, the response window is typically 10 to 30 days. Missing it escalates examiner concern regardless of the substance of the underlying issue.

State licensing renewals are a chronic gap for multi-state fintechs. Renewal deadlines vary by state and license type, and a missed renewal can trigger a license lapse or emergency application process.

The 7 Compliance Calendar KRIs

These KRIs track your deadline management process, not just the outcomes. The goal is to surface risk early—before a deadline is missed, not after.

KRIWhat It MeasuresFrequencyAmber ThresholdRed Threshold
Upcoming deadlines without owners# of deadlines in next 30 days with no assigned ownerWeekly≥1 critical deadline≥1 hard statutory deadline
Evidence completeness at T-14% of deadlines in 14 days with required evidence uploadedWeekly<80%<60%
Owner acknowledgment lagAvg days from deadline assignment to owner confirmationMonthly>5 business days>10 business days
Deadline breach rate% of deadlines missed or requiring emergency extension this quarterMonthly>5%>10%
Missed hard filing count# of statutory or regulatory filings made after their deadlineMonthly≥1≥3
Extension request volume# of extension requests filed this reporting period vs. prior periodQuarterly20% increase50% increase or >5 in 30 days
Exam response aging# of open examiner information requests with <7 days remainingWeekly≥1≥1 critical item

KRI 1: Upcoming Deadlines Without Owners

This is the simplest forward-looking signal—and often the most revealing. Run a filter on your compliance calendar for deadlines in the next 30 days. How many rows have a blank or “TBD” in the owner column?

A single critical deadline without an owner is amber. A hard statutory filing (SAR, CTR, 4530) without an owner is immediately red regardless of days remaining.

The data source is your compliance calendar. The failure mode this catches: obligations that were added to the calendar during a quiet period and never formally assigned when the responsible person changed roles or left.

KRI 2: Evidence Completeness at T-14

Most compliance teams discover missing evidence the day before a deadline. This KRI inverts that—it measures whether the evidence needed for upcoming filings has been collected 14 days out.

Define what “evidence” means per obligation category. For a SAR filing, it’s the investigative case notes and supporting transaction data. For an annual certification, it’s the underlying attestation forms from control owners. For a state license renewal, it’s the updated financials and background check documentation.

T-14 completeness below 80% is amber. Below 60% means your team is already in reactive mode and needs intervention.

KRI 3: Owner Acknowledgment Lag

When you assign a deadline to an owner, does the owner acknowledge it? How long does it take?

An owner who acknowledged their Q4 SAR filing workflow one business day after assignment is very different from an owner who took two weeks to respond—or never confirmed at all. The latter is a signal that ownership is nominal rather than real.

Track acknowledgment timestamps in your calendar system or workflow tool. Averages above five business days suggest unclear ownership or workload issues. Above ten days is a governance concern.

KRI 4: Deadline Breach Rate

This lagging metric measures what percentage of your obligations this quarter missed their deadline or required an emergency extension (not a routine one planned ahead). It tells you whether your forward-looking KRIs are actually preventing failures.

A quarter with zero breaches is the baseline. Any breach should trigger a root cause review. Five percent breach rate is amber; above ten percent suggests a systemic problem—either understaffing, calendar gaps, or owner accountability failures.

KRI 5: Missed Hard Filing Count

This is the most consequential lagging metric: how many statutory or regulatory filings with fixed deadlines were actually submitted late? One late SAR is amber. Three in a quarter is red and requires board-level reporting.

Don’t aggregate this with soft internal deadlines. The point is to isolate regulatory obligations with direct legal consequences from internal reporting that, while important, doesn’t carry the same enforcement risk.

KRI 6: Extension Request Volume

Not all extension requests signal risk—many are routine. But a spike in extension requests (20%+ above prior period) suggests your forward-looking controls are breaking down. People are asking for more time because they ran out of it.

Track extension requests by obligation category to understand whether the spike is concentrated (e.g., all in BSA/AML) or broad-based. Concentrated spikes usually indicate a staffing or process problem in one area; broad-based spikes suggest a calendar management or workload issue.

KRI 7: Exam Response Aging

When examiners are in your building (or your systems), every information request has an implicit urgency. Track open examiner requests in your compliance calendar and flag any that have fewer than seven business days remaining without a substantive draft.

This KRI is situational—it only applies during or shortly after an examination cycle—but it’s the highest-stakes deadline category you manage.

Calibrating Thresholds for Your Organization

Thresholds should be calibrated to your specific regulatory environment, team size, and filing volume. A two-person compliance team managing 40 annual obligations will have different amber/red thresholds than a twelve-person team managing 200.

The starting framework: set amber at the level where the KRI signals you need to investigate, and red at the level where escalation to leadership is required. Revisit annually or after any missed deadline to understand whether the threshold would have caught the failure in time.

One calibration rule that holds across organization sizes: never set “missed hard filing count” above zero for green status. One late statutory filing is always at least amber, regardless of circumstances.

Connecting Calendar KRIs to Your Broader Program

Compliance calendar KRIs don’t operate in isolation. They should feed into your compliance monitoring and testing program as a leading indicator of program health, and into your exam readiness evidence package as documentation that your deadline management process is functioning.

When regulators evaluate your compliance calendar process—which happens in virtually every consumer compliance exam—they’re looking for three things: a comprehensive list of obligations, clear ownership, and evidence that someone is actually monitoring whether they’re being met. Compliance calendar KRIs provide that third element.

The regulatory change KRIs framework is a useful companion here. New obligations get added to your calendar through your regulatory change management process; the compliance calendar KRIs then track whether those newly-added obligations get owned and met.

What Examiners Actually Ask

When the OCC, FDIC, or FINRA looks at your compliance calendar process, the questions tend to run like this:

  • “Walk me through how you identify new regulatory obligations and add them to your calendar.”
  • “Who is responsible for each obligation, and how do you ensure they’re aware?”
  • “Show me the documentation for the last time you missed a deadline and what you did about it.”
  • “What alerts or monitoring do you have in place to catch upcoming deadlines before they slip?”

The first three questions your calendar answers. The last one requires KRIs.

If your answer to “what monitoring do you have” is “we look at the calendar periodically,” you’ve handed the examiner an opening. KRIs with documented thresholds, escalation owners, and evidence of regular review change that answer to something defensible.

So What?

A compliance calendar KRI program is not a heavy lift. Seven metrics. A weekly scan of two or three of them. A monthly report to the compliance committee. An evidence log that shows the calendar isn’t decorative.

The alternative is discovering your SAR filing process broke down on day 31, not day 14. That’s a finding. The compliance calendar KRI catches it at day 14 when you can still fix it.

For teams building or refreshing their compliance program documentation—including the calendar, monitoring framework, and evidence binder—the Compliance Essentials bundle includes the templates to operationalize all of it.


External references:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is a compliance calendar KRI?
A compliance calendar KRI is a forward-looking metric that tracks deadline health: how many upcoming regulatory obligations have owners, whether evidence is being collected ahead of deadlines, how often deadlines slip, and whether late filings are accumulating. Unlike a lagging metric that reports a missed filing after it's already late, a compliance calendar KRI signals risk before the deadline.
How many compliance calendar KRIs should we track?
Start with five to seven. At minimum: upcoming deadlines without owners, evidence completeness at T-14 days, missed filing count in the current reporting period, deadline breach rate, and open regulatory response items with approaching deadlines. Add extension request volume and owner acknowledgment time once you have a baseline.
What's the difference between a compliance calendar and a compliance calendar KRI?
The compliance calendar is the schedule—what's due, when, and who owns it. The compliance calendar KRIs are the health metrics for that schedule: are owners acknowledging their deadlines? Are they pulling evidence on time? How many deadlines slipped last quarter? The calendar shows you what's coming; the KRIs tell you whether you're on track to hit it.
What regulatory deadlines are most commonly missed by fintechs?
FinCEN SAR and CTR filings top the list—both have hard statutory deadlines (30 days for SARs from initial detection, 15 calendar days for CTRs). State licensing renewal deadlines are another frequent gap, especially for fintechs operating across multiple states. FINRA Rule 4530 disclosures (within 30 days of triggering events) and annual NYDFS Part 500 certifications (February 15) are also commonly delayed.
What evidence should a compliance calendar KRI program generate?
Each KRI needs a data source and evidence trail: the underlying deadline log with due dates, owners, and status; acknowledgment timestamps from owners; evidence submissions with upload dates versus due dates; extension request records; and a missed filing log. That evidence package is what an examiner or auditor will ask to see when they evaluate your compliance calendar process.
Can a spreadsheet support compliance calendar KRIs, or do I need a GRC platform?
A well-structured spreadsheet can support a compliance calendar KRI program for teams managing under 100 annual obligations. The key is having consistent status fields, an owner column that gets actively maintained, and a reporting tab that aggregates upcoming and overdue counts. A GRC platform adds workflow automation and escalation, but the KRI logic is the same regardless of tooling.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Compliance Essentials

Multi-domain compliance coverage: data privacy, incident response, BCP/DR, and SOC 2 — 43% off.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.