Feature Compliance Strategy
The First 90 Days as a New Compliance Officer: Inventory Before You Rewrite
A compliance checklist template for your first 90 days: inventory obligations, issues, complaints, commitments, controls, access, and evidence first.
Table of Contents
TL;DR
- Your first deliverable is not a new policy suite. It is a verified map of obligations, commitments, products, controls, gaps, owners, and evidence.
- Work in this order: preserve and triage in days 1–30, validate how the program operates in days 31–60, then commit to a realistic build plan in days 61–90.
- Keep a “management says” column separate from “evidence confirms.” That distinction will save you during the first exam or bank-partner review.
The fastest way to lose your first 90 days is to start rewriting the compliance manual on day three.
You were just hired with nothing—or, more accurately, with six SharePoint sites, an expired calendar, a complaint tracker nobody owns, and a confident assurance that “the last compliance person handled that.”
A useful compliance checklist template starts with inventory, not prose. Before changing what the program says, establish what the company does, what it owes, what has already gone wrong, and what evidence exists.
That sequence matches how examiners think. The OCC’s Compliance Management Systems Comptroller’s Handbook defines a CMS as policies, procedures, processes, monitoring and testing, and compliance audit. Its examiner framework covers board and management oversight, change management, risk identification, corrective action, policies and procedures, training, monitoring and audit, and complaint response. A new binder addresses only one slice.
Days 1–5: secure the record before diagnosing it
The first week is evidence preservation and access recovery.
Ask for administrator or read access—not emailed screenshots—to the systems that hold:
- contracts and bank-partner agreements;
- regulator, licensing, and examination correspondence;
- complaint and dispute records;
- issue, audit, and remediation trackers;
- policy and procedure repositories;
- regulatory change alerts and implementation records;
- learning-management and training records;
- product, marketing, and change-approval tickets;
- vendor inventory and diligence files;
- transaction monitoring, case management, and quality-assurance tools;
- board and compliance committee materials;
- customer communications and disclosure versions.
Record access requests and limitations. “Compliance could not independently retrieve complaint data and relied on monthly Operations exports” is itself a governance fact. Do not hide it in your personal notes.
Preserve the old record before reorganizing. Bulk-moving files into your preferred folder structure can break links from issue trackers, destroy version context, or make historical approvals hard to reconstruct. Take a repository inventory, identify systems of record, and establish retention before cleanup.
Build a source-of-truth register
| Domain | System of record | Owner | Coverage dates | Access | Known limitation | Next verification |
|---|---|---|---|---|---|---|
| Consumer complaints | Support platform | VP Support | Jan. 2025–present | Read only | Social-media complaints excluded | Reconcile channels to complaint policy |
| Bank-partner commitments | Contract repository | General Counsel | Active agreements | Pending | Side letters stored in email | Legal certification and sample |
| Compliance issues | Shared workbook | Head of Compliance | Mixed | Full | Closure evidence not linked | Sample all High/Critical closures |
| Training | LMS | People Ops | 2024–present | Admin | Contractor population unclear | Reconcile HR roster to assignments |
The entries are illustrative. The method is the point: distinguish the location of information from confidence that it is complete.
Days 1–30: inventory obligations and live exposure
The CFPB’s Compliance Management Review Examination Procedures says a CMS should be integrated across product design, delivery, and administration; issues should be self-identified; corrective action should be initiated; and service providers should be overseen. Use those operating pathways to structure discovery.
1. Obligations and deadlines
Create one obligation register that identifies:
- law, regulation, license, order, contract, network rule, or policy source;
- specific requirement and citation;
- entity, product, state, customer, and activity in scope;
- control and evidence expected;
- business and compliance owners;
- filing, review, reporting, or renewal date;
- current status and verification source.
Do not confuse a regulatory library with an applicability decision. A folder containing the Equal Credit Opportunity Act does not establish which products invoke which requirements, where controls operate, or whether your company is the creditor, service provider, or program manager.
Start with deadlines that can hurt immediately: license renewals, regulatory responses, bank-partner deliverables, required filings, remediation commitments, customer-notice obligations, and open examination requests.
2. Commitments somebody already made
Commitments hide in places a policy inventory misses:
- consent orders and examination responses;
- MRA or MRIA remediation plans;
- bank-partner oversight letters;
- audit management responses;
- board-approved corrective actions;
- customer remediation promises;
- contract schedules and side letters;
- responses to due-diligence questionnaires;
- statements in prior regulatory applications.
Build a commitments ledger with exact language, date, recipient, owner, deadline, status, and evidence. A promise to “implement quarterly monitoring” is an obligation even if nobody added it to the compliance calendar.
3. Open issues—and suspiciously closed ones
Collect findings from regulatory exams, internal audit, compliance testing, risk assessments, complaints, incidents, vendor reviews, and self-identification.
For every High or Critical item, check:
- original finding and source;
- root cause;
- remediation action and accountable owner;
- approved due date and extensions;
- closure evidence;
- independent validation;
- recurrence or related complaints;
- residual risk acceptance.
Do not accept “closed” as a fact without evidence. The issue closure guide separates action completion from verified risk reduction—exactly the distinction an inherited tracker tends to blur.
4. Complaints, disputes, and customer remediation
Complaint data tells you where the program is failing in production. Reconcile all intake channels: support, email, phone, chat, app stores, social media, CFPB portal, bank partners, Better Business Bureau, and legal escalations where applicable.
The Federal Reserve’s Consumer Compliance Outlook article “Enhancing the Compliance Management Program with Complaint Data” explains how complaint analysis can identify compliance risks and support program enhancement. Do not stop at volume. Review themes, severity, products, channels, root causes, refunds, reopened complaints, regulatory allegations, and repeat customers.
A practical first-month artifact is a top-ten complaint sample: five recent escalations and five high-impact or repeat cases. Trace each from intake to investigation, response, remediation, root cause, and control change.
5. Products, money movement, and customer journeys
Policies are organized by topic. Harm happens through workflows.
For each active product, map:
- legal entities and licenses;
- sponsor banks, processors, and critical vendors;
- customer segments and jurisdictions;
- application, onboarding, decision, servicing, complaint, and exit steps;
- fees, disclosures, marketing claims, and customer communications;
- movement and custody of funds;
- manual overrides and operational queues;
- regulatory control owners;
- planned product or configuration changes.
Ask Product to show the live journey. Ask Operations to show the exceptions. Ask Engineering to show configurations. The documented process and the working process are often cousins, not twins.
By day 30: deliver a triage memo, not a transformation deck
Classify findings into four lanes:
| Lane | Decision test | Example response |
|---|---|---|
| Contain now | Active harm, likely legal breach, unauthorized activity, or missing critical control | Pause feature, restrict access, correct disclosure, escalate to counsel |
| Deadline-bound | Regulatory, licensing, contractual, exam, or board commitment is approaching | Named owner, daily tracking, evidence plan |
| Validate quickly | Material risk exists but facts or control operation are uncertain | Targeted sample, walkthrough, configuration review |
| Roadmap | Documentation debt or program enhancement without immediate exposure | Prioritized 60–90 day design work |
A triage memo should state verified facts, assumptions, unknowns, interim controls, required decisions, and owners. Avoid calling every inherited weakness “critical.” If everything is urgent, leadership cannot tell what must happen Monday.
Days 31–60: test whether the program actually operates
Now move from inventory to validation.
Walk one obligation through the whole chain
Choose a high-risk obligation and trace:
Source → applicability → policy → procedure → system configuration → training → monitoring → issue handling → management reporting.
For example, take one fee disclosure. Verify the legal requirement, approved disclosure, product configuration, customer presentation, change history, quality-assurance test, complaint trend, and reporting. This single-chain test exposes handoff failures faster than reading 40 policies independently.
The regulatory change implementation record provides the same proof chain for new rules: applicability, implementation, configuration, training, testing, effective date, and residual gaps.
Inventory undocumented controls
Some of the strongest controls may exist only because a tenured Operations analyst remembers to run them. Capture:
- trigger and population;
- activity performed;
- system and data used;
- frequency;
- owner and backup;
- evidence retained;
- reviewer or escalation;
- known exceptions;
- dependency on one person.
Do not immediately write these into policy as permanent design. First determine whether the control is required, reliable, scalable, and correctly owned. A heroic spreadsheet reconciliation may be the only thing preventing harm—and also a control that fails during one employee’s vacation.
Compare representations with evidence
Use three status labels:
- Verified: direct evidence supports the conclusion.
- Represented: an owner stated it, but evidence is pending.
- Contradicted: evidence conflicts with the stated process.
Example:
| Statement | Status | Evidence |
|---|---|---|
| “All marketing is reviewed by Compliance” | Contradicted | Three live campaigns have no approval ticket |
| “Critical vendors are reviewed annually” | Represented | Calendar supplied; completed reviews not yet sampled |
| “Refund overrides require dual approval” | Verified | Configuration plus 25-item sample shows two approvers |
This is not a “gotcha” register. It prevents a verbal walkthrough from becoming an unsupported assurance to the board, examiner, or bank partner.
Days 61–90: decide what to rebuild, repair, or retire
Only now should large-scale rewriting begin.
Rewrite in control order
Prioritize documents where:
- the operating process materially differs from policy;
- obligations or products changed;
- ownership is wrong or vacant;
- the current policy creates repeated exceptions;
- procedures cannot be tested;
- an issue, complaint trend, or exam commitment requires change.
For each revision, identify the implementation owner, system or procedure change, training population, effective date, monitoring test, and evidence. Policy approval without operating change is document production, not remediation.
Build a 12-month plan with capacity attached
A credible roadmap includes:
| Work item | Risk addressed | Deliverable | Owner | Dependency | Decision date | Validation |
|---|---|---|---|---|---|---|
| Complaint taxonomy repair | Repeat issues are not visible across channels | Unified taxonomy and channel mapping | Compliance + Support | Data export changes | Day 75 | Sample 50 cases across channels |
| Commitment ledger | Bank-partner deliverables may be missed | Central register with reminders | Compliance + Legal | Contract inventory | Day 60 | Reconcile active agreements |
| Monitoring plan | Controls lack second-line testing | Risk-based test universe and calendar | Compliance Testing | Obligation/control map | Day 90 | Committee approval and first test |
Sample sizes and dates are illustrative. Calibrate testing to population, harm, history, and resources, and reconcile samples to source-system populations so convenient records cannot be selected.
Ask management for decisions, not applause
Your day-90 report should show:
- verified program map;
- urgent exposures contained;
- overdue and upcoming obligations;
- issue and commitment inventory;
- evidence and ownership gaps;
- products and third parties requiring deeper review;
- resources and access needed;
- decisions that exceed your authority;
- sequenced roadmap with validation.
The OCC handbook says boards should receive risk assessments, monitoring, and independent audit information sufficient to assess CMS effectiveness and provide credible challenge. Give leadership the information needed to decide—not 40 green status boxes.
What not to do in the first 90 days
Do not delete the old evidence trail. Preserve versions, approvals, and actual dates.
Do not promise a clean program before inventory is complete. Report confidence and unknowns.
Do not let the loudest stakeholder set the priority list. Rank by harm, obligation, deadline, and control dependency.
Do not own every control. Compliance should govern and challenge; business, Operations, Product, Engineering, and vendor owners must operate many controls.
Do not make the policy more mature than operations. A strict new requirement with no system, staffing, or owner creates instant noncompliance.
Do not spend 90 days diagnosing without containment. Inventory first does not mean wait to act on active harm or an imminent missed obligation.
So What?
Your first-week task is simple: build the source-of-truth register and the commitments ledger. Your first-month task is harder: identify which inherited statements are verified, represented, or contradicted. Your day-90 task is to leave management with a prioritized, owned, fundable plan.
The best signal that the takeover worked is not a prettier manual. It is that you can answer, with evidence: what do we owe, where does the control operate, who owns it, what is broken, what are we doing, and who accepted anything left open?
The GRC Starter Kit bundles the foundational registers, risk, issue, vendor, and AI-governance templates a new compliance hire needs to turn that inventory into an operating program.
Sources
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
GRC Starter Kit
Everything a new compliance hire needs to build their first risk program — 6 products at 46% off.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What should a new compliance officer do in the first 30 days?
Which compliance documents should be inventoried first?
Should a new compliance officer immediately rewrite outdated policies?
How should a solo compliance officer prioritize inherited gaps?
What should the first 90-day compliance report include?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
GRC Starter Kit
Everything a new compliance hire needs to build their first risk program — 6 products at 46% off.
◆ Keep reading
Related posts.
Compliance Strategy
Bank Holding Company Source-of-Strength: What Fintechs Getting Bank Charters Haven't Accounted For
When a fintech gets a bank charter and forms a bank holding company, it inherits the source-of-strength obligation — a capital backstop requirement most fintech BHC playbooks don't address. The TS Banking Group July 2026 written agreement shows what happens when this surfaces at exam time.
Jul 30, 2026
Compliance Strategy
Federal Reserve Regulation O Proposal: Rebuild the Control Logic, Not Just the Limits
The 2026 Regulation O proposal raises insider-lending thresholds and changes passive-fund treatment. Here is the bank control impact.
Jul 30, 2026
Compliance Strategy
The House CFPB Reform Discussion Draft: What the $21B Supervisory Threshold and Congressional Appropriations Proposal Mean for Your Compliance Program
On July 24, 2026, the House Financial Services Committee published a 70-page CFPB restructuring draft. Here's what's in the five titles, what the $21B threshold change actually affects, and why the compliance programs that survive any version of this are built around legal obligations — not exam schedules.
Jul 28, 2026