Video: Designing a Risk-Based Compliance Monitoring Programme | Duration: 2872s | Summary: Designing a Risk-Based Compliance Monitoring Programme | Chapters: Introduction and Housekeeping (24.03s), Evidencing Compliance Practices (436.535s), Designing Monitoring Programs (993.14s), Defending Compliance Monitoring (1860.89s), Key Takeaways and Conclusion (2718.56s), Closing and Contacts (2840.605s)
Transcript for "Designing a Risk-Based Compliance Monitoring Programme":
Okay, hi everyone and welcome to this Optima and Comply webinar session on designing a risk based compliance monitoring framework. Super important topic so I'm very excited to get stuck in. Some people are just kind of trickling in so I wanted to cover some quick housekeeping items. We will be sending a recording of this webinar out to everyone who's registered so you can watch it back, you can share it with your colleagues, etc. We'll also try and make some time for questions at the end but we do have a load of content to get through today so if you don't have time, please feel free put your questions and comments in the Q and A box and we will review them afterwards and get back to you so without further ado, let's meet our panel. I'm Vicki Moon, I'm Marketing Manager here at Comply. I'll be hosting and moderating today's session. For those of you that aren't familiar with Comply, we're a global technology provider helping firms to automate their employee conflicts of interest so anything from personal account dealing and gifts and hospitality as well as firm level compliance requirements like your compliance calendars and your accountability frameworks. I will hand over to my amazing panellists. Dina, do you want to go first? Hi, I'm Dina De Silva. I've been at Optima for, I think, just over six and a half years now and my background is really started in operations, kind of moved into the regulatory compliance space a couple of years ago, in house mostly, and then six and a half years ago decided to join the consultancy world, so I mainly cover, the larger clients, sort of our hedge fund clients and run a couple of the outsourced monitoring programs, as well as the, marketplace framework at Optima. Great, thanks Dina. So I'm Alex, I'm a director at Optima. I've actually been at Optima for eight years now, recently had my eight year anniversary. I specialise in providing compliance support services predominantly to firms in the private markets, so working with private equity firms, private credit firms and VC managers. I provide a whole range of compliance support services, including helping build out compliance frameworks, creating compliance risk assessments and designing and operating compliance monitoring programmes as well, which is quite topical for today. In terms of Optima, we are a global regulatory consultancy. We have over 200 employees now and we operate across The UK, The US, Asia and The UAE. We predominantly work with buy side firms across hedge funds and private markets and we provide the full suite of compliance support services from outsourced compliance support to secondments to mock audits and assurance reviews and everything in between. Great, thank you. It's great to have you both here today. Today, we're going to be discussing risk based compliance monitoring. It's a topic that's become increasingly important in recent years. Monitoring is no longer a static annual exercise. It's now a key part of how firms are demonstrating that they're identifying, prioritising and managing risk. So, in this session, we're going to be exploring what that means in practice so everything from FCA expectations and then the common pitfalls that our panel are seeing out in the market in various different types of firms as well. And then finally, the top tips for designing a monitoring programme that balances both proportionality and defensibility. So, let's kick off today's session then, shall we? Let's have a look at regulatory expectations. As I mentioned, we're seeing a bit of a shift in how people view monitoring and particularly in how the FCA is talking about monitoring. So, from your perspective, what's changed in the FCA's approach and why is monitoring now a lot more critical to their supervisory strategy? Thanks Vicki. So, first of all, the FCA has actually always been very focused on compliance monitoring and having an effective compliance monitoring programme is a core expectation of the FCA and it's like a critical component of a firm's compliance framework and one of the key documents that demonstrates the firm's ability to comply with the FCA rules on an ongoing basis. Where we're seeing a bit of a shift and this was called out in the FCA's five year supervisory strategy issued last year was that the FCA really made it clear that they expect firms to be able to demonstrate how they identify, prioritise and manage risks in a dynamic evolving way. And so this really means that compliance monitoring shouldn't be viewed as a tick box exercise that's not risk based and it shouldn't be a static annual compliance exercise. Instead the FCA really expects firms to actively test whether controls are effective as their risks evolve. What does this mean? The FCA really is focused on risk based compliance monitoring and that's where having a compliance risk assessment in place to demonstrate where your risks lie and have that mapped to your compliance monitoring is very critical. The other element to this is it should be a dynamic exercise so your CMP should take account of evolving business growth and evolving business risks and also look at the external regulatory environment and FCA priorities. The other area is also to have that clear governance and challenge and oversight over your monitoring decisions. So just linking it to the FCA supervisory strategy more broadly, why is this risk based dynamic approach so important? And this is because the FCA is a principle based outcome focused regulator. The FCA isn't going to be prescriptive to firms about what their C and P should cover or the scope and frequency of testing. The FCA does give firms that flexibility to take a risk based proportionate approach based on the nature, size and complexity of their business. So that flexible regulatory approach is good in theory but it does place a lot more judgement on firms and their compliance teams to be able to defend their C and P and ensure that it stands up to regulatory scrutiny. This is why that risk assessment exercise and that regular review of your C and P is so important. Great, so many firms are going to say that they already do monitoring and of course we probably do. What does the FCA actually mean by evidencing compliance and where do firms kind of often fall short with that? Yes, so evidencing obviously goes beyond just documenting your compliance monitoring programme or completed test results. Evidence in compliance means you should be able to prove with credible retrievable evidence that your firm consistently meets regulatory requirements and delivers good outcomes to clients, customers, not just that you believe it does, right? And so good evidence, you're looking at key characteristics here, you're looking at traceability. So you can link a finding back to a test, you can link a test back to the risk, you can link a risk back to regulation, right? Being reproducible. So is there another reviewer? Would that be able would that reviewer be able to re perform that test? Would they be able to reach the same conclusion? We're looking at it being outcomes focused. It shows that it's not just that controls have operated, but that they have achieved the intended result. Also being complete, so what was tested, how it was tested, what was found and what was done about it. The FCA often pushes back when firms say well we have a policy, so firms are often relying on well written policies and document procedures, but they cannot show whether staff actually followed them, or whether they work in practice. So a policy is not evidence. Or firms will often say well we did the monitoring, but there's actually no depth to the monitoring, there's no clear methodology, no rationale for sample selection, no record of what was actually reviewed, and we also see the FCA come back on weak or inconsistent management information, so the metrics aren't really linked to the risks. The data quality is sometimes questionable and there's often like no thresholds or triggers. Again another one is having no order trail, so missing working papers, no documentation of judgments, no version controls, and another one being findings without follow through, so no root cause analysis, and to Alex's point, like no clear ownership, no validation or remediation, or testing activity not its effectiveness. It will say well 10 number of files were reviewed, but you're not actually testing the controls that actually worked. So also being over reliable on your first sign attestations without independent verification, so getting your front office to attest that they've done something, but not actually testing it. So those are a couple of the common areas where the FCA kind of pushes back on. Okay, interesting. Let's move on to what good would look like in practice and also dig into some of those common weaknesses that you've already mentioned. So, if an FCA supervisor asks you to explain the link between your risk assessment and your C and P, what does good look like there? I think the first thing is that the link between your risk assessment and CMP should be directly and visibly linked so you really need to evidence that connection. The FCA has been really clear that risk assessments and CMP should not sit isolation and really your risk assessment output should drive the monitoring scope, the depth and the frequency that is in your CNP so you can really evidence that why behind your monitoring programme. For example, if your risk assessment rates certain regulatory themes as high risk but then you have a CMP that's doing limited or infrequent monitoring around those risks, firms should expect challenge from the regulator. Equally, if you're doing disproportionate monitoring of low risk areas without clear justification, this can also raise questions around the effectiveness and proportionality of your CMP. The other thing is the compliance mantra if it's not recorded, it didn't happen is really a fundamental principle underpinning FCA regulation and this is why it's so important to have that link between your risk assessment and C and P really clearly mapped out so that you can demonstrate that to a regulator if they asked. So what does this mean in practice? So firms really should be identifying, assessing, mitigating and managing risks, ensuring the monitoring tests, not just the existence of these risks and controls, but the effectiveness of the controls. And risk assessment outputs should directly inform the monitoring scope, the depth of the testing, the monitoring frequency, the type of monitoring and the prioritisation of testing as well so where you should be focusing your resourcing. Great! I love that if it's not recorded, it didn't happen. Great! And we've also got some of the common weaknesses that have been highlighted by the FCA in recent reviews. Do you just want to give a bit more detail around that and does that tally with what you're seeing in the market? Yeah, I think the common weaknesses on the slide we do see across the market and that's also some of the weaknesses the FCA has been speaking about in publications and reviews that it's done. I mean the first one you know poor alignment between risk appetite and monitoring activity. You know, we do see sometimes CMPs that are really not risk based or proportionate and one of the common weaknesses or confusions I find with firms is sometimes they're trying to run a CMP that's covering every single FCA rule and requirement and that's just not really feasible. It's becoming very much an ineffective tick box C and P exercise and it's not really prioritising where the real risks are lying for the firm. The other area around limited explanation or lack of explanation on why specific tests are being done in the CMP, we do see that weakness as well and we often sometimes see CMPs that are relying on confirmations from people without there being any independent review or check being done by compliance. Really true independent second line of defence monitoring should involve reviewing the underlying testing records and evidence of what testing was done to try to give that explanation. Insufficient evidence of senior management oversight and challenge that is a common risk area. We sometimes see compliance monitoring being a siloed exercise that's sitting with the compliance team and it really needs to be understood, reviewed and challenged by senior management as well. So it's really important that firms aren't just completing their CMP but they're then producing effective management information that can then go to the relevant board of committee. And then unclear ownership or findings and remediations like we often see sometimes that firms are doing a great job with their CMP, they have good findings, good recommendations but then sometimes they're missing that link to have clearly defined owners for the recommendations and remediation actions and sometimes there's no tracking or next steps which then means these outstanding actions sometimes just amiss or they stay outstanding for a long period of time, which is a regulatory risk. Then finally on that slide, know, CMPs that remain unchanged despite evolving business or regulatory risks. Like again, sometimes we see with firms, like there's a real push to design a really thoughtful risk based C and P, but then sometimes it then falls down the list of priorities later on and isn't reviewed regularly, it doesn't keep up with business growth or evolving regulatory priorities, so that is definitely an area of weakness. And then one final point I wanted to make on this section around weaknesses is that in The UK we do have a lot of managers that are delegated investment managers or delegated portfolio managers to larger US or global firms and these firms typically have a centralised global compliance monitoring programme that often might be run from The US, for example. One area of weakness we do see is that UK compliance do not always maintain effective oversight over the testing for The UK regulated business. And so that's an area where the UK team really should ensure they're maintaining oversight over the monitoring being performed globally and they should receive metrics, there should be escalation of any breaches and issues to UK compliance and there should still be that effective management information from global testing going directly to The UK boards and committees so The UK can demonstrate oversight over The UK regulated business. Okay, yeah that's really interesting. Particularly the added complexity with global businesses as well. Exactly. It's tricky. Agreed. Okay, so we've talked a little bit about what the FCA expects and what good or poor practice might look like in respect of their regulatory expectations. Let's move on to some of the practicalities of designing a risk based monitoring programme: all the good stuff. So, you've got your risk assessment in place. What should firms be doing next to ensure that it genuinely informs their monitoring plan? Yeah sure, so obviously we always say the risk assessment should drive what you monitor, how often you monitor it and how deeply I think we already mentioned it on today's webinar. And so a good starting point is, as we say, for firms to use the risk assessment outputs to assess kind of monitoring themes, you know, align frequency of testing with the inherent and residual risks, to determine methodology what is most suited based on the risk profile of the firm, you know, regulatory risk as well, and to determine the depth of these reviews. So for every key risk, the third really should identify both preventative and detective controls. So preventative controls, we're looking at approvals, training, or detective controls would look at your monitoring and surveillance. Then you really should be asking which of these controls will compliance test independently. Then we look at setting monitoring intensity frequency based on these risks. So as we already mentioned, high risk areas should technically have greater frequency. They should have larger sample sizes, deeper and more qualitative testing, and as we've kind of noted, more senior oversight. Noting that you know both qualitative factors such as governance concerns, so areas that have already been identified by your governing body or your CCO as an area of concern, should really feed into kind of more effective monitoring, maybe more frequent monitoring. Also depends on the regulated activities undertaken by the business, maybe there's areas of higher risk, And to tie in with regulatory focus areas. So what is the FCA focusing on? Are there any new rules? Is there any new guidance? Is there emerging regulatory risks that we need to be looking at, that need to feed into our monitoring plan? And the quantitative indicators, so looking at you know, it's for example, their transaction volumes, employee trading activity, all of that should be used and would have been assessed as part of your risk assessment, but should be used to inform your compliance monitoring plan. So it's a bit of a blended approach and that is seen as good practice. You should also be thinking about a multi year compliance monitoring plan. The strong firms generally create like one to three year monitoring cycles, just to ensure that all your material risks are covered over time. And here what I tend to advise definitely some of the larger clients, is to break your CMP into three key areas. So we focus on the core monitoring, which is more what compliance own as a regulatory risk. And so compliance would be heavily involved in the monitoring the analysis. And this tends to be more your code of ethics type, regulatory risks, so your personal account dealing, your entertainment, outside business interests, as well as market abuse related regulatory risks, for example. Then you kind of have your tasks which are where compliance need to ensure that a regulatory requirement is met, given they own the regulatory risk, such as around regulatory filings for example. This can tie in with your compliance calendar. So some of it is compliance zone, some of it might be you know finance completing the financial returns or with data, but you need to just ensure that these are being done in a timely manner. And then the last piece of the C and P, I would say, is more your thematic reviews. So this is the second line monitoring really. So where you've got different business areas owning the regulatory risk, and then periodically compliance are doing these deep dive reviews to ensure that regulatory expectations are being met, and that it aligns with current regulatory, outlook as well. So that's sort of how I generally approach it. And the third really ties in with a bit of MI, so different business areas that own that regulatory risk should be feeding their own MI into the governance framework of the firm. So as part of building out your CMP, you can map out the different regulatory risks as you've done in your risk assessment, and just identify where MI should be flowing in to the governance framework of the firm. So it all really ties in with the risk assessment, which we keep saying is key to the whole process. Great, so you talked a little bit about the different types of monitoring. Is there a single right type of monitoring? I'm getting the sense that the FCA expects like a mixed approach and a blended approach. Would you say that that's correct? Yeah, that's correct. As we know, the FCA is not really a one size fits all type of regulator so it's not going to prescribe a right type of monitoring and, as you said, it's very much that mix of approaches that is important because firms should be able to defend the approach and then also choose the type of testing and monitoring that is appropriate for the risk being tested. So know, has really given such a valuable overview of that but as we said, we do see a blended approach typically across our clients where we know we might have firms that have, as Dean has said, sort of tasks that are typically owned by compliance and maybe a link to a compliance calendar, the confirmation type of checks. Then we see firms having often quarterly CMPs which cover code of ethics items, they also often cover staff compliance items, e comm surveillance, some of the higher risk topics that should be reviewed frequently such as market abuse surveillance and financial crime topics and then we see that supplemented often with thematic deeper dive reviews that often may sit with another area of the business but compliance are then doing that second line defence check and looking at the framework more holistically. For example, a lot of my clients are in the private market space and so the FCA has been doing a lot of thematic reviews in the private markets and so a lot of my clients will therefore be doing thematic reviews that are aligned with those topics and they often use the FCA's own thematic review as a guide to how they're going to conduct their own thematic deep dive. So for example, in the private markets, a lot of my clients will be looking at thematic reviews covering their conflicts of interest frameworks, valuation practices, inside information flows, financial crime related items. Yeah, and I'd say in the hedge fund space similarly, you know, there's a lot of talk on risk management and liquidity management. So a lot of the hedge funds are now thinking, okay, these aren't really compliance owned areas, but we should be thinking about doing a thematic review in relation to our liquidity frameworks or our risk management frameworks, so it really kind of all ties in. Great, so I'm conscious of time, so should we move on to testing and effective testing control? We often hear the phrase but what does it actually mean in FCA terms? I think that means kind of going beyond confirming that a control exists. I think we've noted this previously. So you've got to assess whether it actually works in practice, and that it's delivering the intended regulatory outcome, right? So we've got a bit of a difference between a design testing, which is you'd say, okay, is this control appropriately designed? So if a policy says all communications must be reviewed, you go in, you say there's a process, there's a system, this is a paper based assurance, right? Effectiveness testing would say does this control actually work consistently in real life? So the same example policies all communications must be reviewed, you now need to be asking are communications actually being reviewed? Are issues being identified and escalated? Are poor outcomes still happening despite these controls? That is more evidence based outcomes driven assurance, and that is what regulator wants to see. Your control is effective if it is operating consistently, so not just occasionally or when it's audited right, it works across teams, products, time periods. It also achieves the intended outcome. So it prevents those breaches. It detects issues only. I mean, sorry, early, not only, and protects customers as well. So your first test for effectiveness is by going beyond those basic tests. So you're looking at filing, the files and sample testing, you're looking at reviewing real life transactions, cases, interaction, you're validating the policy was followed, judgment was appropriate, the outcome was compliant. You're also potentially looking at outcomes testing, are clients receiving fair outcomes, examples you'd look at fee valuation assessments, product suitability there. A big one is data led testing. So as we mentioned, the use of management information and analytics to identify these exceptions, outliers, also, you know, patterns of failure. And then as we've already mentioned these thematic reviews deep dives into these high risk areas, and this is often where the FDA I think finds major issues. Common regulatory pushbacks, you know, you're testing the process, you're not testing the outcome. The firms are showing, oh well the policies were being followed, but unfortunately your clients or customers are still experiencing harm. Another one is sample sizes being too small or biased, so the testing is not representative and also the conclusions are therefore unreliable. And we've mentioned this one, the tick box monitoring, You're checking completion and not the actual quality and so you're looking at was a review done instead of was it done properly and then the lack of linkage to risk. One thing it would be good to spend some time on as well is proportionality. I think it's something we've touched on earlier and something that the FCA talks about a lot but ultimately it's up to firms to interpret what's proportionate for their firm while still maintaining core expectations and that's obviously easier said than done. So, if we start with smaller firms, they often worry that they'll be held to the same standards as large institutions so how does proportionality work in practice for those smaller firms out there? The FCA will recognise for the smaller firms that they don't need to have the same level and depth of compliance monitoring programme as a larger, more complicated business. What the FCA does still expect though is clear risk based rationale and a tailored compliance monitoring programme that is representative of where the risks for the smaller firms truly lie. So the thing with smaller firms is that the FCA has called out, I think they mentioned it as well in MarketWatch83 recently, that there are some vulnerabilities with smaller firms where they can rely, for example, on generic compliance monitoring, informal policies, undocumented judgments. There can sometimes be weak independence with compliance due to the proximity of compliance to the business and that can lead to issues with compliance monitoring where sometimes there might be reliance on informal documents or confirmation from team members without there being any independent review of files or testing. So the real practical approach really should be to really clearly be mapping out the risks for your smaller business. You could then either have more of a thematic review based programme where you're focusing on those key risk areas and doing, say, a thematic review each quarter that's really tailored to that risk or you could also have a CMP that is still proportionate but it's concise and tailored because it's mapped effectively to the core risks of the firm. Because ultimately if you have a very comprehensive CMP and you're a smaller firm and you potentially don't have the same level of resourcing then you could end up with a CMP that's not completed effectively, it's late and that creates its own regulatory risk. The other thing that smaller firms can think about is the use of technology. So smaller firms often do more manual spreadsheet based monitoring but they can also utilise technology still. Doesn't need to be complicated, things that could be automated, systems potentially like Comply where they can then streamline monitoring, run reports, have kind of automated tools set up can also be really helpful and it can also help with quantitative evidence to sit behind the CMP, so pulling reports on code of ethics items or looking at training completion etc without so much heavy effort sitting with the compliance team. One thing I would say just to reassure some of the smaller firms is that the FCA is always very focused on prioritisation of harm. Really think about the areas of your business that have the greatest potential for client and investor harm for your business and focus on that in your monitoring programme because that ties back to the FCA's focus as a consumer led regulator. And then also, if you are focused on doing the right thing and you can demonstrate that you proactive in managing risks and doing the right things for your clients, you're likely to meet SCA expectations for your monitoring. I'll the touch larger clients. So I know we covered the smaller clients. So I'll just I'll just go straight in, because I think with the larger clients obviously complex, the larger firms, you know, the SCA expects more sophisticated monitoring due to obviously the operational complexity. This includes more robust management information, obviously scalable controls, as well as the implementation of technology to support the compliance framework and clear alignment between hosting monitoring findings and governance forums. Because obviously with large organisations, we tend to have multiple committees. The exceptions based monitoring is flowing into loads of subcommittees and then we expect that further exceptions based monitoring with kind of key material findings to flow into the governing body, the key governing body. The FCA will frequently challenge larger firms where monitoring has also not kept pace with growth. Sometimes see these larger firms grow quite rapidly and they struggle to keep up with the actual monitoring programmes around this growth, ensuring that they are really monitoring against the increased risks as well. And then also the fragmentation of ownership. So it's not always clear, is this owned by compliance, is it owned by risk, is it owned by another area of the business? And that tends to be one of the areas that I think a lot of firms do tend to struggle with. And then we sometimes do see firms still trying to monitor everything every year. And I think as a large organisation it's especially impossible and then just leads to more shallow testing, which doesn't align with the FCA's expectations. So I think it's definitely quite different to the smaller firms, but there are challenges for the larger firms as well, slightly different ones. Yeah, something we hear a lot, particularly with our larger clients here at Comply but not exclusively but particularly businesses that have multiple business lines or international entities, for example, the concept of having a single source of truth for everything. So that kind of leads me on to the topic of integration and why that's kind of such a big topic at the minute, particularly for those larger or more complex firms. I don't know if you can speak a little bit about that. Yes, so integration is obviously about whether firms actually understand their risks and their outcomes holistically, or is it just about managing, you know, these fragmented snapshots, right? And regulatory expectations is that you have that holistic overview. So this most firms would have risk assessments kind of in one system, you know, compliance monitoring is in another system, complaints data is somewhere else, financial crime again sits separately, and then your management information is stitched together manually. And I think a lot of firms struggle with it. Know sometimes when I'm putting together MI for some clients, it really is trying to like, you know, put it all together manually to actually present something of value. And sometimes it results in inconsistent data, or conflicting narratives as well, and potentially delayed insights. So the SCA's perspective is if your data isn't integrated, your view of that risk may not be as reliable. So your single source of truth really means it doesn't really mean one system for everything, it just means, you know, consistent reconciled data. So you know, for example, having the same definitions of your risk ratings, you know, your products, who your clients are, you know, connecting data sets. So your ability to link your monitoring results with these incidents with, you know, your risk assessment for example. And so really it's more about one coherent narrative. So I think when asked by the FCA, like how do you know your customers or clients are getting good outcomes? You should be able to have a joined up, a data backed, consistent answer across functions, which I don't think is always is always the case. So if this matters, because if they want to have real time, reliable and holistic understanding of risks and customer outcomes, not fragmented insights and you know ad hoc explanations, and so as data volume grow, you know manual monitoring does become unfortunately ineffective and unsustainable in ways. So many large firms are integrating kind of more of a holistic approach. So here you will see, you know, sometimes your code of ethics tools will feed into HR tools, links up to expenses, G and E and expenses, for example, your trading data when looking at trade surveillance for example, include your PAD information, include outside business interest information, might include your comm surveillance. So really all of this enables kind of enables firms to strengthen their surveillance programs really, and reduces risk obviously of silo data. Yeah, I was just going to add to that. I think this holistic one source of truth is quite a buzzword with the FCA and with my clients we're seeing a lot of focus on looking at the monitoring and trying to make it more joined up. As Dina said, it's potentially looking at, okay, we have our G and E monitoring but actually let's link it potentially to what's being submitted and expenses. Let's have more meaningful testing off the back of that. Okay, we're doing e comm surveillance and telephone monitoring surveillance. We should really be mapping that to our market abuse surveillance and alerts or we should be mapping it to some personal account dealing alerts. So again, I think it's very much a hot topic across clients to really think about where they can kind of join the dots and do that more holistic, monitoring off the back of it. Yeah and that information flowing into the different committees, so not just keeping it in like a compliance committee or a risk committee, it's showing that interplay between compliance, that reg risk, and also trying to create that accountability to other business areas. So I think that's key. Yeah, having it data backed is so important and especially now we've got so much data at our fingertips, it's just getting it, uncovering it and then connecting it, as you said. Great! So, let's move on to the practical steps that firms on the session today can use. This kind of gives it away a little bit But the final section is going be all about how we can ensure compliance monitoring programmes stand up to regulatory scrutiny. You can give your view on what practical steps actually make a difference when it comes to defending your CMP to an SCA supervisor, for example. Yeah, of course. So I think this defensibility point, it's really one of the key themes of this webinar and I think it's about if you're defending your CMP to a supervisor, it's not just about pointing to your lovely completed testing, it's also again this like the why, the rationale behind the testing. So really firms should practically be focusing on strengthening that traceability between their risks, the controls they have in place and the testing they're doing as a result. Again, evidencing everything you're doing, so regular reviews and refreshes of your monitoring plans, documenting decisions and changes, documenting findings and recommendations and having that ownership over them. And then the other real key piece to defend a C and P is that evidence of senior management oversight and challenge and I know Dean has talked about this quite a lot in the webinar but management information is really key and is the piece that often tells you the why behind the monitoring because it's kind of looking at sometimes those metrics, those trends, those patterns and so putting together that effective management information on your monitoring is really critical to defending the C and P, especially when you have monitoring programmes that can be quite detailed and complex. So it's really important to have that effective meaningful management information that can go to senior management to drive that effective oversight and challenge. Great and I guess for the firms listening today, where should they kind of start if they want to upgrade or uplift their monitoring programme? What's the kind of key starting point? I'd say I think if you don't know this already, say the key is before you uplift the monitoring program, you need to start with your compliance risk assessment, which as I said will drive what monitoring should be undertaken, frequency, know, the depth of the view etc. So I would say firstly document your compliance risk assessment, you know map it to the FDA handbook, key regulations, ensure that you review it annually or if there are you know regulatory changes or a material business, changes, and make sure that this remains a living document and is linked to your monitoring plan. Then I would say, think about what's been discussed today, some of the findings, some of the weaknesses, you know, your monitoring plan to the firm's risk areas. So look at determining what business areas are in scope of monitoring. I would say, you know, make sure that you are embedding your monitoring within the wider compliance and risk frameworks. So here we talked about looking at the different regulatory risk areas, look at which business areas own the risk, which business areas own the control, kind of identify where that MI should be sitting. So who owns it, is it kind of flowing to the right channels, and then that kind of helps in terms of the escalation and remediation, pathways that obviously need to be clear in terms of managing your monitoring plan. And that at this point you don't want these to just kind of sit there, want somebody to own them, for them to feed back into your risk assessments and your monitoring plan, so it remains dynamic in nature. And then think a bit more about, you know, the core monitoring, the task piece, and what thematics tie in with the regulatory's focus areas for your particular business and regulated activity. And then definitely look at the management information piece. So what is flowing in where, and what really should be going into your governing body, as key MI to support senior management and oversight. So again, the piece around full traceability, you've identified the risk, the control, the test, you have a finding, there needs to be some remediation, and really that needs to flow back in to make sure that that remains dynamic and current and keep on top of emerging risks, and regulatory updates, which I know can be quite challenging. Great, I think we are nearly at time so any questions that have been put in the Q and A, our panellists will take a look at them and we'll publish a bit of a response to those questions. Our team backstage are collating them as we speak So, keep an eye out for that next week. Before we close, we've just got a couple of minutes left. I'd like to just ask the panel if our audience takes away one thing from today's session, what would it be? Either of you can answer. I think we've spoken about this really throughout the whole webinar today But basically, I think risk based monitoring is no longer optional, right? And so the SA expects monitoring programs to be clearly linked to a risk assessment, to be proportionate but evidence led, dynamically updated as we've touched on multiple times, and to be supported by strong governance and oversight, which matters, I think, just as much as the testing. So if firms can demonstrate this, then I think they're in a far better position in terms of supervisory engagements than others. So yeah, I think that would be the key takeaway from today. Don't shy away from reviewing your compliance monitoring programme. I know a lot of firms are like, oh you know it's a big off, but I definitely think it's worth it because you may be doing too much testing on the wrong red risk area, right? And so if you align it to your risks, you might have a more value add compliance monitoring programme. Agreed. Yeah, no I was going to say completely agree with everything you're saying and I kind of feel like it actually ties back to what we talked about at the beginning of the session around the FCA's focus and their supervisory priorities around monitoring. I think I have probably three things to take away from today, if I can cheat a little bit. I think the first one is obviously risk based approach, really focus on where your true regulatory risks lie and Also put yourself in the shoes of the regulator and think about what are the SCA's area of focus, what do they truly care about which is client investor harm, systemic risk to the market. Really think about monitoring and mitigating those risks. And then review your monitoring programme regularly, that whole dynamic evolving exercise with the CMP and think about it both from your internal business perspective, so it should be evolving with your business growth, changes to your business and then also aligned to the external environment. So look at the FCA supervisory priorities, horizon scanning, upcoming rules and regulations that are coming in and aligned to that as well. And then finally, that management information piece, you know, the why behind the monitoring critical component of an effective compliance monitoring programme because it really enables you to assess whether those key controls are operating effectively, identify those trends, drive that senior management buy in and meaningful oversight of your compliance monitoring programme and risk profile and those for me are the three key takeaways from today. Okay, great. Well, thank you both for sharing your insights today. It's been really great talking to you about this. Our contact details are on the slide here so if anyone who's on the session today wants to find out a bit more about Optima or Comply, if you're interested in hearing how technology can help you out here, you're very welcome to reach out to any of us. But that brings us to the end of our session. Thank you all for joining. Thanks Vicky.