How to Conduct a Governance Review After a Regulatory Enforcement Action
This guide sets out how to run a credible, board-led governance review in the wake of a regulatory enforcement action. After reading, you will know how to scope the review, sequence findings, engage the regulator, and convert lessons into durable governance change.
An enforcement action is a governance event, not just a compliance one. The regulator has already concluded that something in your control environment failed to work as intended, and the board's response will shape supervisory posture for years. A governance review done well demonstrates that the firm understands what happened, why it happened, and what has structurally changed. Done badly, it becomes a costly restatement of the enforcement notice with a fresh cover page.
Key Executive Takeaways
- The purpose of a post-enforcement governance review is to establish root causes at the level of decision rights, information flow, and accountability, not to relitigate the underlying facts.
- Independence, evidence discipline, and a clear line between findings and remediation are what make the review credible to the board and the regulator.
- The output must translate into specific changes to committee structure, MI, risk appetite, and Senior Manager accountabilities, with measurable indicators the board will track.
Start by defining what the review is actually for
Before commissioning anyone, the board or its chair should agree three things in writing: the review's scope, its independence arrangements, and how its output will be used. Confusion here is the single biggest cause of reviews that fail to satisfy either the board or the supervisor.
Scope should cover the governance conditions that allowed the failure: board and committee effectiveness, the operation of the three lines, MI quality, escalation behaviour, Senior Manager accountabilities under SM&CR, and the culture signals that shaped decisions. It should not attempt to reinvestigate the conduct itself. That work has been done.
Independence matters because the regulator will ask. If the review is run by the general counsel or the CRO, expect challenge. Most credible reviews are led by a non executive, supported by external counsel or an independent firm, with a clear reporting line to the board or a dedicated committee.
Reconstruct the decision chain, not the incident
The useful question is not what went wrong, but who knew what, when, and what governance mechanism should have caught it. Build a timeline of decisions, escalations, and non escalations. Identify every point where a committee, forum, or individual had the information or authority to intervene and did not.
Where most reviews go wrong is stopping at the first plausible cause. A weak first line control is rarely the full story. Ask why the second line did not challenge it, why the board committee did not see it, and why the MI did not surface it. Push until you reach a structural answer: a reporting line, a scope gap, a capability shortfall, a cultural norm.
Test the governance architecture against the failure
Hold the current committee structure, terms of reference, delegated authorities, and risk appetite statements against the specific decisions that went wrong. If a committee had oversight but no MI, that is a design flaw. If a Senior Manager had accountability but no meaningful control, that is an SM&CR problem the regulator will notice before you do.
Good reviews produce a matrix mapping each root cause to the specific governance artefact that needs to change: a terms of reference amendment, a new standing agenda item, a revised escalation threshold, a reallocation of prescribed responsibilities, a change to the MI pack.
Separate findings from remediation, and sequence carefully
A common error is bundling findings and fixes into a single paper the board signs off in one sitting. Split them. The board should first accept the findings, including the uncomfortable ones about its own effectiveness. Only then should management return with a remediation plan, costed, owned, and time bound.
Remediation should distinguish between immediate corrective actions, structural governance changes, and cultural work. Each has different tempo and different evidence of completion. Track them separately.
Engage the regulator with the review, not around it
Share the terms of reference early. Share the findings before they are final if the relationship supports it. Regulators respond well to firms that treat the review as a genuine act of self correction and badly to firms that use it as a defensive document. Where findings are more critical than the enforcement notice itself, say so. That is a mark of seriousness.
The next decision
Before commissioning the review, the chair should decide who owns it, who it reports to, and what the board will do differently on the day it lands. If those three answers are not clear, the review is not yet ready to start.
Frequently Asked Questions
Should the review be legally privileged?
Some elements, particularly interviews touching on individual accountability, may sensibly sit under privilege. But a wholesale privilege wrapper undermines credibility with the regulator and often with the board. Take specific legal advice on which workstreams warrant it, and be prepared to share the substantive findings.
How long should a governance review take?
Most credible reviews run twelve to twenty weeks. Shorter reviews rarely reach structural root causes. Longer ones lose board attention and delay remediation. Build in a mid point checkpoint with the board committee.
Who should lead it if the chair or SID was implicated?
External leadership becomes essential. A senior independent reviewer, typically a former regulator, senior lawyer, or experienced NED from outside the firm, should chair the process and report to a specifically constituted board sub committee.
How do we know remediation has actually worked?
Define indicators at the outset: changes in escalation volume, quality of challenge captured in minutes, MI coverage against risk appetite, results of a follow up effectiveness review twelve months on. Without indicators, remediation becomes a checklist rather than a change.
Frequently asked questions
Should the review be legally privileged?
Some elements, particularly interviews touching on individual accountability, may sensibly sit under privilege. But a wholesale privilege wrapper undermines credibility with the regulator and often with the board. Take specific legal advice on which workstreams warrant it, and be prepared to share the substantive findings.
How long should a governance review take?
Most credible reviews run twelve to twenty weeks. Shorter reviews rarely reach structural root causes. Longer ones lose board attention and delay remediation. Build in a mid point checkpoint with the board committee.
Who should lead it if the chair or SID was implicated?
External leadership becomes essential. A senior independent reviewer, typically a former regulator, senior lawyer, or experienced NED from outside the firm, should chair the process and report to a specifically constituted board sub committee.
How do we know remediation has actually worked?
Define indicators at the outset: changes in escalation volume, quality of challenge captured in minutes, MI coverage against risk appetite, results of a follow up effectiveness review twelve months on. Without indicators, remediation becomes a checklist rather than a change.
Related guides
How to Structure a Basel 3.1 Board Paper That Secures Approval
This guide sets out how to write a Basel 3.1 implementation board paper that wins approval without softening the capital impact numbers. Read it to sharpen your framing, sequencing, and stakeholder handling before the paper goes to committee.
Structuring a Consumer Duty Board Champion Report That Evidences Good Outcomes
This guide sets out how to write a Consumer Duty board champion report that demonstrably evidences good outcomes without triggering FCA product intervention or supervisory escalation. It shows senior leaders what to include, what to leave out, and how to frame difficult findings so the board can act without handing the regulator a case file.
How to Structure a Whistleblowing Annual Report to the Board Under SYSC 18
This guide sets out how to build a board-level whistleblowing report that meets FCA SYSC 18.6 expectations while protecting reporter identity and case confidentiality. After reading, you will know what to include, what to leave out, and how to frame themes so the board can discharge oversight without becoming a de facto investigations committee.
How to Prepare a Credible SM&CR Statement of Responsibilities Update After a Senior Hire
A practical guide to producing an accurate, defensible Statement of Responsibilities update when a Senior Manager joins or changes role. Readers will finish knowing how to sequence the drafting, capture handovers cleanly, and submit something that stands up to FCA scrutiny.
How to Construct a Defensible ICAAP Narrative Aligned to Board Risk Appetite
This guide sets out how to build an ICAAP narrative that connects capital assessment to board-owned risk appetite in a way supervisors find credible. After reading, you will know how to structure the story, where the weak points usually sit, and what evidence to marshal before submission.
Where internal consensus may be mistaken for validation
Polar Insight's Decision Rooms bring outside challenge to a live decision, so blind spots and untested assumptions surface before commitment, not after.
Explore Decision Rooms