Back to blogs
Blogs & Insights

Anxious About Your Next Regulatory Examination? So Is Every CCO Who Is Being Honest.

The scramble before a regulatory examination rarely means the work was not done. It means the evidence was never built continuously. Dinesh Arora, Founder of Finnulate, on why examination anxiety persists and what it quietly reveals about governance.

Anxious About Your Next Regulatory Examination? So Is Every CCO Who Is Being Honest.

There is a particular kind of silence that falls over an institution the day the regulatory examination letter arrives.

It is not panic. Not quite. It is something quieter and more unsettling: a collective intake of breath as people begin mentally running through everything that was supposed to be done, should have been done, was probably done but may not have been documented well enough.

If you have sat in a CCO's chair, or a CEO's chair, or on a board audit committee, you know this feeling. You may not talk about it openly. But you know it.

This blog is about that feeling. Where it comes from, why it persists, and what it quietly reveals about how most institutions actually govern compliance.

The Feeling Nobody Talks About

Regulatory examinations are not surprise events. Every regulated institution knows they are coming. Roughly when. Roughly what will be covered. Roughly what the examiner will be looking for. The regulatory framework is published. The supervisory priorities are signalled. The compliance obligations are known.

And yet, almost universally, the weeks leading up to an examination look the same. Teams working late. Documents being retrieved from filing systems and inboxes. Evidence being assembled. Responses being drafted. A quiet anxiety settling over the compliance function that radiates outward toward the CCO, the CEO, and eventually the board.

Why does this happen every single time?

The honest answer is that the examination does not create the problem. It reveals it.

And what it reveals is almost always the same structural gap. Between what the institution intended to do, and what it can actually demonstrate it did.

The Root Cause Is Not What You Think

The instinctive explanation is a resource problem. Not enough people. Not enough budget. Not enough time.

These are real constraints. But they are not the root cause.

The root cause is architectural.

Most institutions manage compliance as activity. Circulars are read, tasks are extracted, responsibilities are assigned, checklists are ticked. The compliance team is busy, genuinely and exhaustingly busy. But busyness is not the same as governed obligation management.

The difference is this. Activity tells you what was done. Obligation governance tells you what was required, whether it was done, who is accountable, and what the evidence is, at any point in time, without advance notice.

When the examination letter arrives, the scramble begins not because the work was not done. In most cases, much of it was. The scramble begins because the evidence of the work, the trail that connects the obligation to the action to the closure, was never built continuously. It has to be assembled retrospectively, from emails, files, memory, and goodwill.

And assembled evidence is never as convincing as contemporaneous evidence. Examiners know the difference. So do the institutions being examined.

What Happens Inside the Boardroom

Boards of regulated institutions receive compliance reports. Quarterly updates, audit committee presentations, management attestations. The formats are familiar, the language is reassuring, and the board takes comfort from what it reads.

But there is a question that rarely gets asked in that boardroom, and it is the most important one.

Is what we are reading a summary of what was done, or evidence of what can be proven?

These are not the same thing. A summary tells the board that the compliance team completed 94 per cent of its planned activities last quarter. Evidence would tell the board which specific obligations were met, which were not, what the gap is, who owns the open items, and what the residual regulatory risk looks like today.

The first gives the board comfort. The second gives the board assurance.

Comfort and assurance feel similar in a quarterly meeting. They feel very different when an examiner is in the building.

For the Board to reflect on: when did your audit committee last ask to see the evidence behind a compliance closure, not the summary, but the actual evidence?

The Constraints Nobody Wants to Name

Ask a CCO privately what their biggest challenge is, and the answer is rarely dramatic. It is mundane and structural.

Too many obligations across too many regulators, tracked on too many spreadsheets, updated by too few people who are also managing day-to-day queries, regulatory correspondence, policy updates, examination responses, and board reporting, all simultaneously.

The compliance technology stack in most regulated institutions reflects exactly where compliance sits in the institutional priority order. Core banking systems are state of the art. Treasury systems are sophisticated. Risk systems have had significant investment. Compliance tools are often a patchwork. A workflow system here, a document repository there, a shared drive that everyone has access to and nobody fully maintains.

This is not a criticism. It is an honest observation about how institutional budgets flow. Technology investment follows revenue and risk. Compliance, positioned as a cost centre and a governance function, gets what is left over.

Until the examination arrives. At which point everyone discovers that what was left over was not sufficient to demonstrate what the institution needs to demonstrate.

For the CCO to reflect on: if your regulator walked in tomorrow and asked you to show the evidence of compliance for your top twenty open obligations, how long would it take you to produce it, and how confident would you be in what you produced?

The Conversation That Does Not Happen

There is a conversation that should happen regularly in every regulated institution between the CCO and the functional heads. The CFO, CTO, COO, Chief Risk Officer, Chief Business Officer. A conversation about which compliance obligations sit within their functions, what the evidence of compliance looks like, and who is accountable when the examiner asks.

In most institutions, this conversation happens once a year, in the weeks before an examination. Sometimes it happens for the first time when the examination letter arrives.

The reason is not lack of goodwill. It is lack of a shared operating picture. The CCO does not have a tool that gives functional heads a real-time view of the obligations they own and the evidence they need to maintain. Functional heads do not have a mechanism that surfaces compliance accountability as part of their daily operating rhythm. So compliance remains the CCO's problem, until it becomes everyone's problem.

Examinations have a way of distributing ownership very quickly.

For the CxO to reflect on: do you know, right now, which regulatory obligations sit within your function, and could you evidence compliance with each of them if asked today?

What the Examiner Actually Finds

Examiners are experienced professionals. They have seen hundreds of institutions across their supervisory careers. They know what a genuinely compliant institution looks like, and they know what a compliant-on-paper institution looks like. The difference is usually visible within the first day.

What they find in most examinations is not malice. It is not deliberate non-compliance. It is a gap, consistent, structural, and familiar, between what was intended and what was evidenced.

They find obligations tracked on spreadsheets that nobody fully owned. They find evidence files assembled in the two weeks before the examination arrived. They find board presentations that describe compliance activity without linking it to specific obligations. They find Corrective Action Plans from previous examinations that were marked as closed but whose underlying issues were not structurally resolved.

And they find institutions that are genuinely surprised by what the examination surfaces. Not because the leadership was negligent, but because nobody had a complete, real-time picture of the compliance position at any point between examinations.

The CEO is often the last to know and the first to be accountable.

For the CEO to reflect on: between now and your next examination, could you walk into your boardroom on any given Monday morning and give the board a precise, evidence-backed answer to the question: what is our compliance position today?

The Question Worth Sitting With

I have spent nearly four decades inside regulated institutions. As a banker, as a Group CEO, and as a board member. I have sat on both sides of the compliance table. I have been the person responsible for giving the board assurance and the person on the board asking for it.

The anxiety around regulatory examination is real. And it is legitimate. But it is not inevitable.

The institutions that approach examinations without anxiety are not necessarily more compliant than others. They are more governed. Their compliance position is visible continuously, not assembled periodically. Their evidence exists because it was built as work happened, not reconstructed after the fact. Their boards receive assurance because the system produces it, not because the CCO worked through the weekend to prepare a presentation.

That shift, from activity management to obligation governance, is not a technology question. It is a leadership question. It requires the board to ask for evidence, not comfort. It requires the CEO to make compliance infrastructure a priority, not an afterthought. It requires the CCO to be given the standing and the tools to govern, not just to report.

Dinesh Arora is the Founder of Finnulate AI and has spent nearly four decades in banking, including as Group CEO of a leading East African banking group and as a Board Advisor and Risk Committee Chair for banking subsidiaries in the region.

The examination letter, when it arrives, should feel like a formality. Not every institution is there yet. But every institution can ask itself honestly: why not?

Continue Exploring

See how Finnulate brings compliance execution, ownership, and proof together.

Book a DemoView all blogs