Beyond Whack-A-Mole: The smart way to cut regulatory compliance costs

Beyond Whack-A-Mole: The smart way to cut regulatory compliance costs

Tired of regulatory Whack-A-Mole? Financial firms are stuck chasing endless findings, risks and issues − a costly cycle that satisfies no one, least of all regulators. But by shifting from a top-down, transaction-driven model to a bottom-up, value-centric approach, supported by smart technology, organisations can turn compliance from a burden into a strategic advantage. Richard Taylor, Head of Resilience, SecOps & GRC, at Calitii, explains.

If you’re old enough, you’ll remember the simple joy of playing Whack-A-Mole. Not the digital version, but the real deal using a mallet to hit little plastic moles that kept popping up. It was all about speed and a satisfying thud!

Today’s regulatory landscape can feel remarkably similar. The same ‘moles’ – findings, risks, issues and tasks – keep surfacing across organisations. No matter how hard teams work to address them, they inevitably pop back up somewhere else.

It’s an exhausting, expensive, inefficient cycle that drains valuable resources. And financial regulators such as the FCA and PRA definitely don’t like the game or the moles.

But what if there was a better way to keep businesses compliant? What if instead of endlessly chasing these regulatory moles, we could actually solve the underlying problems before they surfaced?

Migrating from a top-down, transactional model to a bottom-up, value-centric approach

Many organisations are stuck in a ‘transaction chasing’ process – juggling hundreds of Matters Requiring Attention (MRAs), failed Risk Control Self Assessments (RCSAs) and Key Control Indicators (KCIs). Alongside this, today’s C-suites and GRC teams are drowning in acronym soup – ISO 27001, GDPR, DORA, FCA-SYSC/COBS/DISP, FSMA – each bringing its own set of requirements, deadlines and potential penalties.

The regulations themselves aren’t the problem (most of the time); they serve an important purpose. The issue is our approach which tends to be top down not bottom up, or more accurately, input, rather than output focused. And while some regulations refer to nebulous concepts like ‘resilience’, too often they involve a list of instructions that need to be ticked off and adhered to.

Excessive bureaucracy leads to employee overload and disengagement, and the exact opposite of what you’re trying to achieve – an increase in risk.

Instead of chasing individual transactions (and yes, a regulation can be a transaction: ‘We need to comply with ‘ABCD’’- is a large self-contained unit, just like a database transaction), companies need to move to asset-centric and value-centric operating models. The former is when organisations stop chasing transactions and instead, transactions chase them as strategic asset owners. This is a major step forward and significantly more efficient. But what’s the point of the asset? It’s there to deliver value; to the organisation, its clients and the market. This latter value-centric operating model should be the driving force behind every compliance activity.

This is where structured thinking, and technology come in.

Step 1: Define objectives

Companies need to ask themselves: Why are we doing this? What are our quantifiable objectives and goals? How will we measure success? They need to articulate the value they’re driving for the company, their clients and the market. In short, what’s the point? It’s time to capture these in a digital platform to allow you to adopt a data-centric approach to decision-making.

Step 2: Define the organisation

Then they need to digitally map, in a phased, manageable way, the entire organisational structure including operational hierarchies (e.g. functional, legal, entity, user, cost centre, departmental, technical, service, third parties, Software Bill of Materials (SBOM), etc.) using a modern modelling platform.

Step 3: Connection

And then, and here’s the really critical point, they need to link steps 1 and 2. The company’s objectives need to be placed at the top and its structure at the bottom, joining the components where appropriate. This creates a comprehensive view of how individual tasks like compliance activities cascade upward to impact major objectives and overall resilience. Ideally this would be using the same platform but as a minimum, these functions need to be joined up using, for example, Application Programming Interfaces (APIs). The ongoing maintenance of two disparate data models needs to be taken into account doing this though.

Step 4: Automate the intelligence

Alongside this, companies need to subscribe to a regulatory content provider that provides structured feeds integrating automatically with your compliance platform. The critical factor here is deduplication at the control level – not all providers offer this, but it’s absolutely vital for efficiency. It also needs to integrate with your objectives and organisational description, for example (ideally) linking regulatory controls to specific departments, services and business functions.

The financial benefits of this approach are staggering. Imagine this scenario: when new regulations emerge (let’s call it ‘Regulation B’), there’s typically a 20-90% overlap with existing regulatory controls. So, in a best-case deduplication scenario of 90%, if an existing ‘Regulation A’ has 500 controls and new ‘Regulation B’ introduces 500 more controls, traditional transaction-chasing would treat these as 1,000 separate requirements. But with proper deduplication and integration, you might discover 400 overlapping controls.

The savings calculation is eye-opening:

  • 800 avoided duplicate control tests
  • Multiplied by 52 testing cycles per year
  • Multiplied by (e.g.) 60 minutes per test
  • Equals around 2.5 million minutes or around 41,600 hours saved annually which equals…
  • The equivalent of over 23 full time employees

That’s just one regulatory cycle. Multiply this across multiple regulations and the savings become truly transformational, genuinely strategic, in fact.

Smart compliance technology delivers benefits far beyond cost reduction including:

Scalability: When new regulations appear, you can simply download, deduplicate, assess the impact and action. They can then also be used across the entire business, not just by the Three Lines of Defence.

Visibility: Your vulnerable assets (bottom level) now automatically link back to one or more important business services and critical/important functions which in turn link to the value they are driving in the first place. You can now clearly see the value of your IT and governance, risk and compliance investment.

Risk intelligence: You have the ability to have entity specific risk, all the way up the stack from endpoint to strategic objectives.

Regulatory confidence: Auditors and regulators respond positively to organisations that demonstrate integrated, value and risk-driven compliance approaches.

Data and value-centric decision-making: That is why we’re here, isn’t it? To become more efficient and deliver value to customers?

From compliance to competitive advantage

Companies that move beyond reactive compliance aren’t just saving money; they’re gaining competitive advantages. While some remain stuck playing regulatory Whack-A-Mole, smart businesses have realised that the only way to win is to stop playing the game entirely and start controlling it instead. The technology already exists to make the transformation a reality today and AI is set to enhance options even further. You’ll need a platform to connect everything and present it in a meaningful way. And you will, of course, need the right partner to support this process. The business case is compelling, and the potential financial benefits are enormous.

Remember, if you’re not doing it, your competitors are….

Moles? Whacked – for good. Thud.

Browse our latest issue

Intelligent Fin.tech

View Magazine Archive