Skip to content
RiskTemplates · The Daily Brief Friday, July 31, 2026
Wire The Exodus OFAC Settlement: What a $3.1M Crypto Wallet Enforcement Action Teaches About Sanctions Compliance Programs JUL 30

Feature Compliance Strategy

Regulatory Change Implementation Record: Prove the Alert Became a Working Control

A regulatory change log tells you when the alert arrived. An implementation record proves the alert became a working control. Here's what the evidence chain needs to contain.

Table of Contents

TL;DR

  • Most compliance teams log that the regulatory alert arrived. Few can prove what happened after it did.
  • Examiners look for a documented chain: alert received → applicability determined → policy/procedures updated → training delivered → systems configured → monitoring updated → effective date verified.
  • The OCC’s CMS booklet, FDIC’s Examination Manual, and CFPB’s CMR procedures all require evidence that regulatory changes were “incorporated into business processes” — not just noted.
  • USAA FSB paid $140 million in 2022 partly because it knew about AML deficiencies from at least 2017 and couldn’t prove they were fixed by 2021. That’s four years of unimplemented regulatory requirements with a paper trail of promises and no implementation record.

USAA Federal Savings Bank had been informed of significant AML program problems by the OCC no later than 2017. The bank told the OCC it would fix them by 2020, then by June 2021. When FinCEN assessed a $140 million civil money penalty on March 17, 2022, the finding was explicit: USAA “knew that it was failing to meet the regulatory requirements of its federal functional regulator (the OCC) concerning its AML program, but failed to bring itself into compliance with those requirements for over five years.”

Awareness is not implementation. A plan is not an implementation record. FinCEN and the OCC penalized USAA not for ignorance but for failing to prove that awareness became action.

This is the gap most regulatory change management programs leave open: they track alerts, log effective dates, and record commitments. What they don’t document is the chain of evidence from alert to working control.

What “implementation” actually means to an examiner

The OCC’s Compliance Management Systems Comptroller’s Handbook (June 2018) defines the compliance program as having specific named components, including change management as a distinct sub-function alongside policies and procedures, training, monitoring, and complaint response.

Within the compliance program, the OCC requires documented processes to “identify, evaluate, and implement changes to consumer-protection laws.” All three verbs must be documented. Identifying a rule change and logging it is step one of three. The OCC also states that training “should be documented” — not just delivered but documented. Monitoring must be “bank-wide inclusive of the bank’s products, services, and activities.”

The FDIC Consumer Compliance Examination Manual (updated December 2024) defines a CMS as how an institution “ensures that requirements are incorporated into business processes” and “reviews operations to ensure responsibilities are carried out and requirements are met.” The FDIC’s implementation test is whether the requirement is in the actual business process — not just in the policy document.

The CFPB’s Compliance Management Review Examination Procedures evaluate change management across all five examination modules. A critical principle: self-identification and correction of implementation gaps is treated as a CMS strength. Being caught by an examiner is a weakness. Having an implementation record shows you can self-verify, which is exactly what examiners want to see.

The OCC FY2025 Bank Supervision Operating Plan reinforces this: “change-management and third-party risk management continue as topics of focus in many, if not most, examination categories.” Examiners will “focus on the adequacy of change management processes for rulemakings” across BSA/AML, consumer compliance, and operational risk categories.

What “failure to implement” looks like in practice

Three patterns appear repeatedly across recent enforcement actions:

Pattern 1: “Failure to correct a previously identified deficiency.”

This exact language appears verbatim in the OCC’s December 2024 cease-and-desist order against Bank of America and its June 2024 order against CNB Bank & Trust. In both cases, a prior examination identified a deficiency, the bank committed to remediation, and the next examination found the same gap. The bank could not show that the prior commitment produced a working control.

Pattern 2: Governance, controls, training, and testing all failing together.

The OCC’s October 2024 cease-and-desist order and $450 million penalty against TD Bank enumerated deficiencies across internal controls, governance, independent testing, and training. These four elements appear together because they are the same four an examiner checks when verifying whether a regulatory change was implemented: Did the controls change? Was governance informed? Was testing updated? Were staff trained? A complete implementation record addresses all four.

Pattern 3: Unresolved MRAs across examination cycles.

At the end of 2022, Silicon Valley Bank had 31 active MRAs and MRIAs, with six liquidity-related MRAs unresolved for 16 months across multiple examination cycles. The Federal Reserve’s April 2023 review found that “supervisors did not fully appreciate the extent of vulnerabilities, and when supervisors identified vulnerabilities, they did not take sufficient steps to ensure the bank fixed those problems quickly enough.” The bank had remediation plans. It did not have implementation records demonstrating closure.

FINRA’s 2025 Annual Regulatory Oversight Report flagged inadequate written supervisory procedures over 50 times — the single most recurrent finding. FINRA Rule 3110 requires firms to “amend its written supervisory procedures as appropriate within a reasonable time after changes occur in applicable securities laws and regulations.” An outdated WSP is a documented failure to implement.

The implementation record: what the evidence chain must contain

An implementation record is distinct from a change log. A change log records that an alert arrived. An implementation record documents what happened after it did.

The chain has five links. If any link is missing, the record is incomplete:

Link 1: Alert → Applicability Determination

The record must show that someone reviewed the regulatory change, assessed whether it applies to your business (and to which products, processes, channels, or systems), and documented the rationale. “Out of scope because X” is as useful as “in scope because Y” — both need written rationale.

FieldWhat to capture
Source and citationAgency, docket or rule citation, publication date
Effective dateDate the requirement takes effect
Date identifiedDate the institution received or identified the change
In-scope determinationIn scope / out of scope / partially in scope
RationaleWhy this determination was made, by whom, reviewed by whom

Link 2: Applicability Determination → Change Scope

Once in scope, the record must identify every policy, procedure, system, training module, and monitoring control that needs to change. The most common gap here is completeness — the policy gets updated, the procedures don’t; the procedure gets updated, the monitoring control doesn’t.

Map the change scope explicitly: list each artifact that requires modification, the current version, the required modification, and the responsible owner.

Link 3: Change Scope → Update Completion

Each item in the change scope must be updated and evidenced. “Policy updated” means: the policy document was revised, the revision shows the effective date of the regulatory change, and an appropriate authority approved the revision. “Procedure updated” means the same. “System configured” means configuration evidence was documented and tested.

ArtifactRequired updateVersion beforeVersion afterApproval dateApproved by
AML PolicyAdd new beneficial ownership thresholdsv4.2v4.3MM/DD/YYYYCMCO
CDD ProcedureUpdate ownership verification stepsv2.1v2.2MM/DD/YYYYCMCO
Onboarding workflowAdd ownership certification screenBuild #442MM/DD/YYYYCTO + CMCO

Link 4: Update Completion → Training

The OCC CMS booklet explicitly states that training “should be documented.” A training record means: the training module was updated to reflect the new requirement, the appropriate audience was identified, training was delivered (with dates), and completion records are retained with employee names and dates.

Training completion is the most frequently missing link. Policies and procedures get updated; the training module from last year is still running; employees who were trained before the change are operating under old procedures. Implementation is not complete until the workforce is trained on the new requirement.

Link 5: Training → Testing (Monitoring Verification)

The final link is evidence that the control is actually working. Testing after training closes the loop: are transactions being processed correctly under the new requirement? Are disclosures reflecting the updated language? Are monitoring rules calibrated for the new obligation?

Testing evidence can be a quality assurance sample, a compliance monitoring review, or an internal audit test. The point is that someone verified that the change is in operation, not just on paper.

The residual gap record

Not every regulatory change can be fully implemented by the effective date. Vendor systems aren’t ready. Contract amendments are in negotiation. Training can’t reach all staff before go-live.

When you have a gap at the effective date, document it explicitly:

  • What is the gap (which specific component is not yet implemented)?
  • What compensating control is in place during the gap period?
  • Who owns closure?
  • What is the target closure date?
  • Has legal or compliance signed off on the accepted exposure?

An undocumented gap on the effective date is an uncontrolled compliance exposure. A documented gap with a compensating control and a closure timeline is a managed risk. The CFPB treats self-identification and correction as a CMS strength — the same principle applies here. Examiners respond differently to “we identified the gap, accepted it with conditions, and closed it by date X” than to “we didn’t know it was open.”

The two-minute test: do you have an implementation record?

Pull the most recent regulatory change your institution implemented. Ask:

  1. Is there a dated record showing who determined it was in scope and why?
  2. Is there a list of every policy, procedure, system, and training module that was updated — with versions and approval dates?
  3. Is there training completion evidence with employee names and dates?
  4. Is there testing or monitoring evidence showing the requirement is in operation?
  5. If there was a gap at effective date, is there a residual gap record?

If you can answer yes to all five, you have an implementation record. If you can’t, your change log has entries but your evidence chain has breaks.

So what?

The OCC spent four years receiving promises from USAA FSB before levying a $140 million penalty. TD Bank had AML obligations that existed on paper and failed in operation. Bank of America couldn’t show it had corrected a previously identified deficiency. SVB carried 16-month-old MRAs into a liquidity crisis.

Every one of these cases had regulatory awareness. None of them had implementation records that demonstrated a working control chain. That’s the gap the record fills — not whether you know the rule, but whether you can prove the rule became practice.

For the broader framework that governs how regulatory change management fits into your compliance program — including risk appetite, committee structure, and monitoring cadence — see the Enterprise Risk Management Framework.

For the compliance program foundation that makes this record possible, see how to build a Compliance Management System that survives a CFPB exam, the regulatory change management program guide, and the compliance monitoring plan template that makes step 5 operationally repeatable.


External sources cited:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is a regulatory change implementation record?
A regulatory change implementation record is the documented evidence that a regulatory alert was not only received and logged, but that the change was assessed for applicability, the affected policies and procedures were updated, employees were trained, systems were configured, and monitoring was updated to test for the new requirement. It is the chain of evidence from 'we got the alert' to 'the control is working.' Without it, you can show awareness but not implementation.
What do OCC examiners look for in regulatory change management?
The OCC Compliance Management Systems booklet defines change management as a named component of a bank's consumer compliance program. Examiners look for documented processes to 'identify, evaluate, and implement' regulatory changes — all three verbs — plus evidence that training was delivered and documented, policies and procedures were updated, and monitoring was calibrated to test for the new requirement. Examiners do not accept a policy update alone as proof of implementation.
What is the most common exam finding related to regulatory change management?
The FINRA 2025 Annual Regulatory Oversight Report flagged inadequate written supervisory procedures over 50 times — the single most recurrent finding in the report. The most common OCC pattern is 'failure to correct a previously identified deficiency,' which appears verbatim in enforcement orders against Bank of America (December 2024) and CNB Bank (June 2024). Both mean the same thing: the bank or firm received notice of a requirement, committed to implementation, and could not prove it actually happened.
What fields should a regulatory change implementation record include?
At minimum: change source and date received, applicability determination with written rationale, affected products and processes, required changes (policy, procedure, system, training, monitoring), owner for each change, testing/verification results, regulatory effective date, institution completion date, and any residual gaps with compensating controls and timeline to close. Each field creates a documentary link in the evidence chain.
What's the difference between a regulatory change log and an implementation record?
A change log is a tracking tool — it shows you what regulatory changes came through and when. An implementation record is an evidence file — it shows you what happened after the alert arrived, documented with dates, owners, and results at each step. Many compliance teams have change logs. Fewer have implementation records. Examiners care about the implementation record, not just the log.
When does a regulatory change require a full implementation record versus a lighter review?
A full implementation record is appropriate for any change that requires a policy or procedure update, system configuration, training delivery, or monitoring adjustment. A lighter applicability-and-status note is sufficient for changes determined to be out of scope for your business (with documented rationale), minor clarifications that don't change existing practices, or guidance that confirms existing practices are already compliant. The materiality threshold should be defined in your regulatory change management policy.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Enterprise Risk Management Framework (ERMF)

Complete ERM documentation: risk appetite, 3 Lines of Defense, committee charter, and board reporting.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.