Skip to main content
Chartis_Compliance Rewired article pic

Compliance is undergoing a structural reset. The traditional operating model, built around prescriptive regulation, manual interpretation, static obligation maps and siloed ownership, is reaching its limits as regulatory complexity increases. Firms are also facing requirements for faster responses, with more evidence and greater accountability. As a result, a continuous, risk-based function is emerging, leading with data, automation and intelligence to pre-empt compliance obligations, detect issues earlier, manage compliance performance more proactively and de-risk decision-making.

This change is not happening in isolation. Across large banks, super-regional institutions and asset managers, compliance risk is increasing, while firms are feeling pressure to do more with less supervisory certainty and fewer resources. In that context, compliance can no longer be treated as a periodic control exercise but rather as an always-on operating capability that strengthens resilience, supports governance and helps the business adapt to regulatory change more effectively.

Why the old model is broken

For many years, compliance functions relied on a familiar pattern: identify the regulation, translate it into controls, map those controls to processes and review the model on a periodic basis. That approach made sense in a slower-moving economic and regulatory environment, but it is now creating fragmentation, duplication and a patchwork of local systems that are difficult to govern and even harder to explain. As regulations have stacked up, the default response has often been to add controls rather than redesign the operating model, which has increased complexity without necessarily improving outcomes.

Demonstrating control assessments is no longer enough. Firms now need to demonstrate why a specific control exists, what risk it addresses, how it performs and whether it supports the decisions that matter. This is a major shift in mindset. Instead of focusing primarily on coverage, compliance teams are being asked to prove effectiveness, traceability and business relevance.

This shift also reflects the growing cost of compliance failure, which can trigger operational disruption, force work stoppages, consume management attention and damage brand value. The direct cost of remediation is often only the beginning; indirect losses, such as increased oversight, extra reporting and strategic restrictions, can become much larger over time. In more serious cases, failures can also result in individual liability and longer-term market consequences, including higher capital costs.

From prescriptions to principles

The regulatory environment itself is changing, creating much of the impetus for the rewire. Regulatory ‘frameworks’ (such as the Digital Operational Resilience Act [DORA], for example) have formalized the importance of digital operational resilience, information and communication technology (ICT) risk management, incident reporting, information sharing and third-party risk. This is pushing compliance further into technology, resilience and operational oversight, rather than leaving it confined to policy review and control testing.

DORA is the most detailed and clearly defined risk framework for digital risk and a step change from more narrowly focused regulatory guidelines. However, given its broad coverage, it is better thought of as a reference set of rules rather than as a point-by-point implementation guideline. Effectively an outline for what regulators would like to see (similar to Basel’s BCBS 239), it provides vendors and institutions alike with a broad structure for designing an operational resilience framework.

Advantages and disadvantages

The advantages and disadvantages of prescription- and principles-based approaches are summarized in Table 1.

The result is a more demanding operating environment. Compliance leaders are not only expected to interpret rules, but also to anticipate where regulatory change is heading, so they can assess the potential impact on their business without disrupting operations. That requires stronger data foundations, more consistent governance over regulatory obligations and a much tighter link between regulation and execution.

From oversight to intelligence

The modern compliance function is becoming more analytical and more connected. Chartis describes the evolving model as one that expands beyond a narrow control function into broad oversight and accountability, with deeper intersections between compliance, risk, audit, operations and technology. This is not just a structural change but a functional one as well. Compliance is increasingly expected to provide forward intelligence, not just retrospective reporting.

Consequently, technology is becoming increasingly important. Dashboards, automated monitoring, intelligent control testing and analytics can help compliance teams identify emerging issues sooner and respond faster. Just as importantly, they can improve consistency and transparency across the organization. In a more mature model, compliance becomes a partner to the business, helping product, legal, operations and risk teams understand the regulatory implications of change before issues become expensive problems.

This evolution also changes how compliance is measured. The old metrics – policy completion, control coverage and review cadence – are no longer enough on their own. Increasingly, firms are being judged on data quality, their responsiveness to change, the effectiveness of their monitoring, the performance of their compliance controls and the degree to which their compliance programs work across risk and audit functions. In other words, compliance is moving from a back-office planning and reporting function to a performance-driven discipline.

The role of AI

AI is at the heart of this rewiring, particularly agentic AI systems that pursue defined goals autonomously by planning, making contextual decisions and executing multi-step actions within governed constraints. This distinction is important because compliance is a high-stakes operation with critical workflows, not a domain where uncontrolled automation is acceptable. The value of agentic compliance solutions lies in their ability to support structured, repeatable and auditable work at scale.

In a practical example, agentic compliance can automate and integrate horizon scanning, policy management, regulatory mapping, workflow orchestration, issue triage and escalation, and compliance testing. But it only works if firms put the right guardrails in place: high-quality data, transparency, human oversight for high-stakes actions, detailed logging, rollback capabilities, least-privilege access and clear escalation paths. Without these controls, agentic compliance will increase risk rather than reduce it. The risk shifts to the agentic system.

The opportunity is therefore not simply to automate compliance tasks but to redesign the compliance operating model around trusted intelligence. That requires careful governance, but it also offers real benefits: lower compliance exposure, better control efficiency, reduced operational risk and greater strategic flexibility.

The new target model

The emerging target operating model for compliance is continuous, AI-enabled and tightly linked to risk and audit. It is built on real-time data, ongoing monitoring and early issue detection, so firms can address risks before they become failures. It is also more measurable, with clearer accountabilities and more explicit performance expectations across the function.

This is a profound change in how compliance creates value. Instead of a cost of doing business, compliance is becoming a strategic capability that helps firms operate with more confidence in a volatile environment. That matters for boards, executives, regulators and investors alike. The firms that rewire and modernize their compliance function successfully will be better not just at meeting obligations, but also at adapting to change, preserving resilience and supporting growth.

In the years ahead, compliance will increasingly be judged by its ability to deliver demonstrable outcomes rather than procedural comfort. That means the winners will be firms that embrace integrated platforms, disciplined governance and AI-enabled operating models without losing sight of accountability and control. In that sense, compliance is not simply being digitized. It is being rewired for a different era of business and growth.

Only users who have a paid subscription or are part of a corporate subscription are able to print or copy content.

To access these options, along with all other subscription benefits, please contact info@chartis-research.com or view our subscription options here: https://www.chartis-research.com/static/become-a-member

You are currently unable to copy this content. Please contact info@chartis-research.com to find out more.

Most read articles loading...

You need to sign in to use this feature. If you don’t have a Chartis account, please register for an account.

Sign in
You are currently on corporate access.

To use this feature you will need an individual account. If you have one already please sign in.

Sign in.

Alternatively you can request an individual account here.