How to Prepare a Regulatory Filing With Stakeholder Risk Assessment
A practical guide to embedding stakeholder risk assessment into a regulatory filing so it reads as credible, evidenced, and decision-ready. After reading, you will know how to sequence the work, what supervisors actually look for, and where filings typically fall apart.
Most regulatory filings that include a stakeholder risk assessment fail in the same way: they treat stakeholders as a communications afterthought rather than a source of substantive risk evidence. Supervisors can tell the difference within two pages. This guide sets out how to prepare a filing where the stakeholder assessment is genuinely load-bearing, not decorative.
Key Executive Takeaways
- A stakeholder risk assessment in a regulatory filing must show evidenced views from named stakeholder groups, mapped to specific risks the regulator cares about, not a generic engagement summary.
- Sequence matters: build the stakeholder evidence base before drafting the filing narrative, so the narrative is constrained by what you actually know.
- The most common failure is asserting stakeholder confidence without documentation that would survive a supervisory challenge or a Section 166 style review.
Start With the Regulator's Actual Question
Before any stakeholder work begins, be precise about what the filing is being judged against. A change in control application, a variation of permission, an ICAAP or ORSA submission, and a resolution pack each carry different implicit questions about stakeholders. The regulator is not asking whether stakeholders are happy. They are asking whether stakeholder positions create prudential, conduct, or operational risk that management has identified and can control.
Write down, in one sentence, the risk question your stakeholder assessment must answer. If you cannot, the filing will drift.
Map Stakeholders to Risk Categories, Not Org Charts
Most internal stakeholder maps are organised by relationship (customers, staff, investors, regulators, suppliers). For a filing, reorganise them by the risk they could crystallise:
- Stakeholders who could withdraw capital, funding, or liquidity
- Stakeholders who could trigger conduct or complaints exposure
- Stakeholders who could disrupt operations or critical third party services
- Stakeholders whose public position could shift supervisory tone
- Stakeholders with contractual or fiduciary standing to challenge the decision
This reframing is where the assessment gets its analytical spine. Without it, you will produce a stakeholder list, not a risk assessment.
Gather Evidence That Would Survive Scrutiny
Assertions like "key investors are supportive" or "customer feedback has been positive" will not hold up. What holds up:
- Dated records of engagement, including who was spoken to, by whom, and what was said
- Direct quotations or documented positions from named stakeholder representatives
- Independent research or third party perception data where internal views may be self-serving
- Dissenting or cautionary views, captured honestly, with the management response
If your file contains only supportive views, a supervisor will assume you filtered. Include the harder feedback and show how it was addressed.
Draft the Filing Section With Three Layers
A credible stakeholder risk section in a filing has three layers, in this order:
- The method: how stakeholders were identified, prioritised, and engaged, and over what period.
- The findings: what each priority stakeholder group actually thinks, including areas of concern.
- The risk conclusion: what this means for the specific risks the filing addresses, and what mitigations or controls are in place.
The risk conclusion is where most filings collapse into generality. Be specific. If a stakeholder group has concerns about integration risk, say so, and point to the exact control that addresses it.
What Good Looks Like
A strong filing lets a supervisor trace a straight line from a named stakeholder concern to a documented mitigation to a board-approved control. It acknowledges uncertainty. It does not oversell consensus. It treats stakeholder risk as a live input to prudential judgement, not a reputational overlay.
Common Failures to Avoid
- Using engagement volume (number of meetings, survey responses) as a proxy for insight
- Presenting internal stakeholder views as if they were external validation
- Omitting stakeholders whose views are inconvenient
- Writing the narrative first and back-filling the evidence
Your Next Decision
Before your next filing goes to the board for approval, ask one question: could an external reviewer reconstruct our stakeholder risk conclusions from the underlying evidence pack? If the answer is no, the filing is not ready, regardless of how polished the drafting looks.
Frequently Asked Questions
How far back should stakeholder evidence go?
Generally twelve months for routine filings, longer for transactions or authorisations where the regulator will want to see a pattern of engagement rather than a pre-filing sprint.
Should we disclose dissenting stakeholder views?
Yes, with the management response. Filings that show only alignment invite the question of what was left out. Documented disagreement, resolved or acknowledged, is a mark of credibility.
Who should own the stakeholder risk section internally?
Risk or compliance should own the framing and conclusions. Investor relations, corporate affairs, or public policy can contribute evidence but should not draft the risk judgement.
How detailed should the methodology description be?
Detailed enough that a supervisor could replicate the approach. Vague methodology is the fastest way to have the entire section discounted.
Does this apply to routine filings or only material ones?
The depth scales with materiality, but the discipline applies to both. Routine filings with weak stakeholder sections create precedent problems when a material filing later relies on the same approach.
Frequently asked questions
How far back should stakeholder evidence go?
Generally twelve months for routine filings, longer for transactions or authorisations where the regulator will want to see a pattern of engagement rather than a pre-filing sprint.
Should we disclose dissenting stakeholder views?
Yes, with the management response. Filings that show only alignment invite the question of what was left out. Documented disagreement, resolved or acknowledged, is a mark of credibility.
Who should own the stakeholder risk section internally?
Risk or compliance should own the framing and conclusions. Investor relations, corporate affairs, or public policy can contribute evidence but should not draft the risk judgement.
How detailed should the methodology description be?
Detailed enough that a supervisor could replicate the approach. Vague methodology is the fastest way to have the entire section discounted.
Does this apply to routine filings or only material ones?
The depth scales with materiality, but the discipline applies to both. Routine filings with weak stakeholder sections create precedent problems when a material filing later relies on the same approach.
Related guides
What Regulators Actually Look For in a Submission
This guide sets out what supervisors and authorisation teams genuinely assess when they read a regulatory submission, beyond the formal checklist. After reading, you will know how to structure a submission that survives challenge and moves through review without the avoidable delays that sink most timelines.
How to Prepare for an FCA Supervisory Visit
A practical guide to preparing for an FCA supervisory visit, from interpreting the scoping letter to managing the day itself and the follow-up. After reading, you will know what good preparation looks like, where firms typically slip, and how to position your firm to come out of the visit stronger.
How to Run an ESG Materiality Assessment That Holds Up to Scrutiny
A practical guide to designing and executing an ESG materiality assessment for regulated financial services firms. Readers will finish with a clear method for scoping, engaging stakeholders, prioritising issues, and producing outputs that survive audit, supervisor, and board challenge.
How to Handle a Pre-Emptive Regulator Meeting After a Governance Failure
This guide covers how to prepare for and run a self-initiated regulator meeting when you have discovered a material governance failure inside your firm. After reading, you will know how to sequence the disclosure, frame the failure, and position remediation in a way that preserves credibility and controls the supervisory response.
How to Build a Regulatory Narrative for a Change in Control Application at a UK Bank or Insurer
This guide sets out how to construct a coherent regulatory narrative for a Section 178 change in control application to the PRA and FCA. After reading it, you will understand how to frame the acquirer story, sequence supervisory engagement, and pre-empt the objections that stall or block approval.
Where internal confidence may exceed external evidence
Polar Insight helps leadership teams test critical assumptions against stakeholder, market, regulatory, and operational reality before risk compounds.
Explore Stakeholder Proximity