Skip to main content

How to Prepare a Regulatory Filing With Stakeholder Risk Assessment

A practical guide to building a regulatory filing that incorporates a defensible stakeholder risk assessment - covering scoping, evidence, sequencing, and the judgement calls that determine whether the filing holds up under scrutiny. After reading, you will know how to structure the assessment, what evidence regulators expect to see, and where most filings fall short.

How to Prepare a Regulatory Filing With Stakeholder Risk Assessment

Most regulatory filings that include a stakeholder risk assessment fail in the same way: they treat the assessment as a narrative appendix rather than the analytical spine of the submission. Regulators notice. So do boards when something later goes wrong.

This guide sets out how to prepare a filing where the stakeholder risk assessment is genuinely load-bearing - the kind that survives challenge from a supervisor, a Section 166 reviewer, or a future enforcement team reading it cold.

Start with the regulator's actual question

Before drafting anything, write down - in one sentence - what the regulator is being asked to approve, notice, or accept. Variation of permission, change in control, new product approval, recovery plan, Consumer Duty attestation: each carries a different evidentiary bar for stakeholder impact.

Most teams skip this and start with templates. The result is a filing that answers questions no one asked and omits the ones that matter. The stakeholder risk section then becomes generic - customers, employees, shareholders, regulators - with no link to the specific decision under review.

Define stakeholders by exposure, not by category

Generic stakeholder maps are the single biggest weakness in regulatory filings. "Customers" is not a stakeholder group. A 72-year-old fixed-income customer holding a product affected by the change is. So is the IFA network that distributed it.

Segment stakeholders by:

  • Exposure to the specific change - who is materially affected, in what way, over what time horizon
  • Ability to absorb harm - vulnerability, concentration, switching cost
  • Visibility to the regulator - who will write in, complain, or be quoted back to you

If a stakeholder group does not differ on at least two of these axes from another, collapse them. If they do differ, treat them separately throughout the assessment.

Build the evidence base before you write the narrative

A defensible filing rests on evidence gathered before a conclusion was formed. That means:

  • Complaints data segmented to the affected cohorts, not aggregate
  • Direct stakeholder input (research, advisory panels, distributor feedback) dated before the decision
  • Internal challenge - minutes showing the risk was tested, not just noted
  • Comparable cases: what happened when peers made similar changes

Where you do not have evidence, say so explicitly and explain the proxy. Regulators are far more forgiving of acknowledged gaps than of confident assertions they later discover were unsupported.

Sequence the assessment to match the decision logic

The assessment should read in the order the decision was actually made: what was the trigger, what options were considered, which stakeholders were affected by each option, what mitigations were tested, why the chosen path was preferred.

Filings that present the conclusion first and reverse-engineer the analysis are easy to spot. They use phrases like "the firm is satisfied that" before showing how it reached that view. Invert this. Show the working.

Treat mitigations as testable, not aspirational

For each material stakeholder risk, the filing should specify:

  1. The mitigation (what will be done)
  2. The owner (named role, not committee)
  3. The trigger metric (what would tell you it is failing)
  4. The escalation path (who decides to act)

If a mitigation cannot be expressed this way, it is not a mitigation - it is a hope. Strip it out or rewrite it. Supervisors will ask these four questions in any follow-up; better to answer them in the filing.

What good looks like

A strong filing makes it possible for a regulator to disagree with you without having to re-do the analysis. They can see your inputs, your weighting, your judgement calls, and the points at which a reasonable person might reach a different view. That transparency is what builds supervisory trust over time - and what protects the firm if outcomes later diverge from expectations.

Weak filings hide the judgement. Strong ones expose it and defend it.

The next decision

Before the filing leaves the building, give it to someone who was not involved in the decision - ideally someone with supervisory or enforcement background - and ask one question: if this went wrong in 18 months, would this document protect the firm? If the answer is not a confident yes, the stakeholder risk assessment is not finished.

Related guides

Regulation & Regulatory Change

Structuring a Section 178 Notification That Withstands PRA Group Structure Review

This guide sets out how to prepare a Change in Control notification that presents the acquirer's group with the clarity, completeness, and supervisory logic the PRA expects. After reading, you will know how to sequence disclosures, frame group complexity honestly, and engage the regulator in a way that supports timely approval on the merits.

Regulatory submissionAcquisitionRegulators
4 min readRead guide →
Regulation & Regulatory Change

How to Structure a Recovery Plan Playbook That Passes PRA Credibility Tests

This guide sets out how to build a Recovery Plan playbook that meets the PRA's credibility, usability and timeliness expectations without creating documents that could damage confidence if they surface externally. After reading, you will know how to sequence indicators, options and governance triggers so the plan works as a live management tool rather than a compliance artefact.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Regulation & Regulatory Change

How to Structure an Operational Resilience Self-Assessment That Withstands Regulator Challenge

This guide sets out how to build an operational resilience self-assessment that holds up to FCA and PRA impact tolerance scrutiny. After reading, senior leaders will know how to sequence evidence, frame judgements, and pre-empt the challenges supervisors are most likely to raise.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Regulation & Regulatory Change

How to Structure a Section 165 Response That Limits Scope Creep

This guide sets out how to respond to an FCA Section 165 information request in a way that satisfies the statutory duty without widening the supervisory perimeter. After reading, you will know how to scope, sequence, and caveat your response to close down inference-driven follow-ups.

Regulatory submissionRegulatorsRegulatory uncertainty
4 min read · Step by stepRead guide →
Boards, Governance & Defensibility

How to Structure an SM&CR Statement of Responsibilities to Avoid Accountability Gaps

This guide sets out how to draft a Statement of Responsibilities that stands up to FCA and PRA scrutiny without creating unintended liability. Readers will learn how to allocate prescribed responsibilities cleanly, close overlap and gap risks, and produce a document that supports rather than undermines the SMF holder.

Regulatory submissionRegulatorsExecutive teams
4 min readRead guide →

Where internal confidence may exceed external evidence

Polar Insight helps leadership teams test critical assumptions against stakeholder, market, regulatory, and operational reality before risk compounds.

Explore Stakeholder Proximity