Feature Compliance Strategy
Regulatory Change Implementation Record: Prove the Alert Became a Working Control
A regulatory change log tells you when the alert arrived. An implementation record proves the alert became a working control. Here's what the evidence chain needs to contain.
Table of Contents
TL;DR
- Most compliance teams log that the regulatory alert arrived. Few can prove what happened after it did.
- Examiners look for a documented chain: alert received → applicability determined → policy/procedures updated → training delivered → systems configured → monitoring updated → effective date verified.
- The OCC’s CMS booklet, FDIC’s Examination Manual, and CFPB’s CMR procedures all require evidence that regulatory changes were “incorporated into business processes” — not just noted.
- USAA FSB paid $140 million in 2022 partly because it knew about AML deficiencies from at least 2017 and couldn’t prove they were fixed by 2021. That’s four years of unimplemented regulatory requirements with a paper trail of promises and no implementation record.
USAA Federal Savings Bank had been informed of significant AML program problems by the OCC no later than 2017. The bank told the OCC it would fix them by 2020, then by June 2021. When FinCEN assessed a $140 million civil money penalty on March 17, 2022, the finding was explicit: USAA “knew that it was failing to meet the regulatory requirements of its federal functional regulator (the OCC) concerning its AML program, but failed to bring itself into compliance with those requirements for over five years.”
Awareness is not implementation. A plan is not an implementation record. FinCEN and the OCC penalized USAA not for ignorance but for failing to prove that awareness became action.
This is the gap most regulatory change management programs leave open: they track alerts, log effective dates, and record commitments. What they don’t document is the chain of evidence from alert to working control.
What “implementation” actually means to an examiner
The OCC’s Compliance Management Systems Comptroller’s Handbook (June 2018) defines the compliance program as having specific named components, including change management as a distinct sub-function alongside policies and procedures, training, monitoring, and complaint response.
Within the compliance program, the OCC requires documented processes to “identify, evaluate, and implement changes to consumer-protection laws.” All three verbs must be documented. Identifying a rule change and logging it is step one of three. The OCC also states that training “should be documented” — not just delivered but documented. Monitoring must be “bank-wide inclusive of the bank’s products, services, and activities.”
The FDIC Consumer Compliance Examination Manual (updated December 2024) defines a CMS as how an institution “ensures that requirements are incorporated into business processes” and “reviews operations to ensure responsibilities are carried out and requirements are met.” The FDIC’s implementation test is whether the requirement is in the actual business process — not just in the policy document.
The CFPB’s Compliance Management Review Examination Procedures evaluate change management across all five examination modules. A critical principle: self-identification and correction of implementation gaps is treated as a CMS strength. Being caught by an examiner is a weakness. Having an implementation record shows you can self-verify, which is exactly what examiners want to see.
The OCC FY2025 Bank Supervision Operating Plan reinforces this: “change-management and third-party risk management continue as topics of focus in many, if not most, examination categories.” Examiners will “focus on the adequacy of change management processes for rulemakings” across BSA/AML, consumer compliance, and operational risk categories.
What “failure to implement” looks like in practice
Three patterns appear repeatedly across recent enforcement actions:
Pattern 1: “Failure to correct a previously identified deficiency.”
This exact language appears verbatim in the OCC’s December 2024 cease-and-desist order against Bank of America and its June 2024 order against CNB Bank & Trust. In both cases, a prior examination identified a deficiency, the bank committed to remediation, and the next examination found the same gap. The bank could not show that the prior commitment produced a working control.
Pattern 2: Governance, controls, training, and testing all failing together.
The OCC’s October 2024 cease-and-desist order and $450 million penalty against TD Bank enumerated deficiencies across internal controls, governance, independent testing, and training. These four elements appear together because they are the same four an examiner checks when verifying whether a regulatory change was implemented: Did the controls change? Was governance informed? Was testing updated? Were staff trained? A complete implementation record addresses all four.
Pattern 3: Unresolved MRAs across examination cycles.
At the end of 2022, Silicon Valley Bank had 31 active MRAs and MRIAs, with six liquidity-related MRAs unresolved for 16 months across multiple examination cycles. The Federal Reserve’s April 2023 review found that “supervisors did not fully appreciate the extent of vulnerabilities, and when supervisors identified vulnerabilities, they did not take sufficient steps to ensure the bank fixed those problems quickly enough.” The bank had remediation plans. It did not have implementation records demonstrating closure.
FINRA’s 2025 Annual Regulatory Oversight Report flagged inadequate written supervisory procedures over 50 times — the single most recurrent finding. FINRA Rule 3110 requires firms to “amend its written supervisory procedures as appropriate within a reasonable time after changes occur in applicable securities laws and regulations.” An outdated WSP is a documented failure to implement.
The implementation record: what the evidence chain must contain
An implementation record is distinct from a change log. A change log records that an alert arrived. An implementation record documents what happened after it did.
The chain has five links. If any link is missing, the record is incomplete:
Link 1: Alert → Applicability Determination
The record must show that someone reviewed the regulatory change, assessed whether it applies to your business (and to which products, processes, channels, or systems), and documented the rationale. “Out of scope because X” is as useful as “in scope because Y” — both need written rationale.
| Field | What to capture |
|---|---|
| Source and citation | Agency, docket or rule citation, publication date |
| Effective date | Date the requirement takes effect |
| Date identified | Date the institution received or identified the change |
| In-scope determination | In scope / out of scope / partially in scope |
| Rationale | Why this determination was made, by whom, reviewed by whom |
Link 2: Applicability Determination → Change Scope
Once in scope, the record must identify every policy, procedure, system, training module, and monitoring control that needs to change. The most common gap here is completeness — the policy gets updated, the procedures don’t; the procedure gets updated, the monitoring control doesn’t.
Map the change scope explicitly: list each artifact that requires modification, the current version, the required modification, and the responsible owner.
Link 3: Change Scope → Update Completion
Each item in the change scope must be updated and evidenced. “Policy updated” means: the policy document was revised, the revision shows the effective date of the regulatory change, and an appropriate authority approved the revision. “Procedure updated” means the same. “System configured” means configuration evidence was documented and tested.
| Artifact | Required update | Version before | Version after | Approval date | Approved by |
|---|---|---|---|---|---|
| AML Policy | Add new beneficial ownership thresholds | v4.2 | v4.3 | MM/DD/YYYY | CMCO |
| CDD Procedure | Update ownership verification steps | v2.1 | v2.2 | MM/DD/YYYY | CMCO |
| Onboarding workflow | Add ownership certification screen | — | Build #442 | MM/DD/YYYY | CTO + CMCO |
Link 4: Update Completion → Training
The OCC CMS booklet explicitly states that training “should be documented.” A training record means: the training module was updated to reflect the new requirement, the appropriate audience was identified, training was delivered (with dates), and completion records are retained with employee names and dates.
Training completion is the most frequently missing link. Policies and procedures get updated; the training module from last year is still running; employees who were trained before the change are operating under old procedures. Implementation is not complete until the workforce is trained on the new requirement.
Link 5: Training → Testing (Monitoring Verification)
The final link is evidence that the control is actually working. Testing after training closes the loop: are transactions being processed correctly under the new requirement? Are disclosures reflecting the updated language? Are monitoring rules calibrated for the new obligation?
Testing evidence can be a quality assurance sample, a compliance monitoring review, or an internal audit test. The point is that someone verified that the change is in operation, not just on paper.
The residual gap record
Not every regulatory change can be fully implemented by the effective date. Vendor systems aren’t ready. Contract amendments are in negotiation. Training can’t reach all staff before go-live.
When you have a gap at the effective date, document it explicitly:
- What is the gap (which specific component is not yet implemented)?
- What compensating control is in place during the gap period?
- Who owns closure?
- What is the target closure date?
- Has legal or compliance signed off on the accepted exposure?
An undocumented gap on the effective date is an uncontrolled compliance exposure. A documented gap with a compensating control and a closure timeline is a managed risk. The CFPB treats self-identification and correction as a CMS strength — the same principle applies here. Examiners respond differently to “we identified the gap, accepted it with conditions, and closed it by date X” than to “we didn’t know it was open.”
The two-minute test: do you have an implementation record?
Pull the most recent regulatory change your institution implemented. Ask:
- Is there a dated record showing who determined it was in scope and why?
- Is there a list of every policy, procedure, system, and training module that was updated — with versions and approval dates?
- Is there training completion evidence with employee names and dates?
- Is there testing or monitoring evidence showing the requirement is in operation?
- If there was a gap at effective date, is there a residual gap record?
If you can answer yes to all five, you have an implementation record. If you can’t, your change log has entries but your evidence chain has breaks.
So what?
The OCC spent four years receiving promises from USAA FSB before levying a $140 million penalty. TD Bank had AML obligations that existed on paper and failed in operation. Bank of America couldn’t show it had corrected a previously identified deficiency. SVB carried 16-month-old MRAs into a liquidity crisis.
Every one of these cases had regulatory awareness. None of them had implementation records that demonstrated a working control chain. That’s the gap the record fills — not whether you know the rule, but whether you can prove the rule became practice.
For the broader framework that governs how regulatory change management fits into your compliance program — including risk appetite, committee structure, and monitoring cadence — see the Enterprise Risk Management Framework.
For the compliance program foundation that makes this record possible, see how to build a Compliance Management System that survives a CFPB exam, the regulatory change management program guide, and the compliance monitoring plan template that makes step 5 operationally repeatable.
External sources cited:
- FinCEN, Civil Money Penalty — USAA Federal Savings Bank, March 17, 2022
- OCC, TD Bank Cease and Desist Order, October 2024
- OCC, Comptroller’s Handbook: Compliance Management Systems (June 2018)
- FDIC, Consumer Compliance Examination Manual — CMS Section II-3
- CFPB, Compliance Management Review Examination Procedures
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Enterprise Risk Management Framework (ERMF)
Complete ERM documentation: risk appetite, 3 Lines of Defense, committee charter, and board reporting.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is a regulatory change implementation record?
What do OCC examiners look for in regulatory change management?
What is the most common exam finding related to regulatory change management?
What fields should a regulatory change implementation record include?
What's the difference between a regulatory change log and an implementation record?
When does a regulatory change require a full implementation record versus a lighter review?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Enterprise Risk Management Framework (ERMF)
Complete ERM documentation: risk appetite, 3 Lines of Defense, committee charter, and board reporting.
◆ Keep reading
Related posts.
Compliance Strategy
Bank Holding Company Source-of-Strength: What Fintechs Getting Bank Charters Haven't Accounted For
When a fintech gets a bank charter and forms a bank holding company, it inherits the source-of-strength obligation — a capital backstop requirement most fintech BHC playbooks don't address. The TS Banking Group July 2026 written agreement shows what happens when this surfaces at exam time.
Jul 30, 2026
Compliance Strategy
Federal Reserve Regulation O Proposal: Rebuild the Control Logic, Not Just the Limits
The 2026 Regulation O proposal raises insider-lending thresholds and changes passive-fund treatment. Here is the bank control impact.
Jul 30, 2026
Compliance Strategy
The House CFPB Reform Discussion Draft: What the $21B Supervisory Threshold and Congressional Appropriations Proposal Mean for Your Compliance Program
On July 24, 2026, the House Financial Services Committee published a 70-page CFPB restructuring draft. Here's what's in the five titles, what the $21B threshold change actually affects, and why the compliance programs that survive any version of this are built around legal obligations — not exam schedules.
Jul 28, 2026