How to Prepare a Regulatory Filing With Stakeholder Risk Assessment
A practical guide to embedding stakeholder risk assessment into a regulatory filing so it reads as credible, evidenced, and decision-ready. After reading, you will know how to sequence the work, what supervisors actually look for, and where filings typically fall apart.
Most regulatory filings that include a stakeholder risk assessment fail in the same way: they treat stakeholders as a communications afterthought rather than a source of substantive risk evidence. Supervisors can tell the difference within two pages. This guide sets out how to prepare a filing where the stakeholder assessment is genuinely load-bearing, not decorative.
Key Executive Takeaways
- A stakeholder risk assessment in a regulatory filing must show evidenced views from named stakeholder groups, mapped to specific risks the regulator cares about, not a generic engagement summary.
- Sequence matters: build the stakeholder evidence base before drafting the filing narrative, so the narrative is constrained by what you actually know.
- The most common failure is asserting stakeholder confidence without documentation that would survive a supervisory challenge or a Section 166 style review.
Start With the Regulator's Actual Question
Before any stakeholder work begins, be precise about what the filing is being judged against. A change in control application, a variation of permission, an ICAAP or ORSA submission, and a resolution pack each carry different implicit questions about stakeholders. The regulator is not asking whether stakeholders are happy. They are asking whether stakeholder positions create prudential, conduct, or operational risk that management has identified and can control.
Write down, in one sentence, the risk question your stakeholder assessment must answer. If you cannot, the filing will drift.
Map Stakeholders to Risk Categories, Not Org Charts
Most internal stakeholder maps are organised by relationship (customers, staff, investors, regulators, suppliers). For a filing, reorganise them by the risk they could crystallise:
- Stakeholders who could withdraw capital, funding, or liquidity
- Stakeholders who could trigger conduct or complaints exposure
- Stakeholders who could disrupt operations or critical third party services
- Stakeholders whose public position could shift supervisory tone
- Stakeholders with contractual or fiduciary standing to challenge the decision
This reframing is where the assessment gets its analytical spine. Without it, you will produce a stakeholder list, not a risk assessment.
Gather Evidence That Would Survive Scrutiny
Assertions like "key investors are supportive" or "customer feedback has been positive" will not hold up. What holds up:
- Dated records of engagement, including who was spoken to, by whom, and what was said
- Direct quotations or documented positions from named stakeholder representatives
- Independent research or third party perception data where internal views may be self-serving
- Dissenting or cautionary views, captured honestly, with the management response
If your file contains only supportive views, a supervisor will assume you filtered. Include the harder feedback and show how it was addressed.
Draft the Filing Section With Three Layers
A credible stakeholder risk section in a filing has three layers, in this order:
- The method: how stakeholders were identified, prioritised, and engaged, and over what period.
- The findings: what each priority stakeholder group actually thinks, including areas of concern.
- The risk conclusion: what this means for the specific risks the filing addresses, and what mitigations or controls are in place.
The risk conclusion is where most filings collapse into generality. Be specific. If a stakeholder group has concerns about integration risk, say so, and point to the exact control that addresses it.
What Good Looks Like
A strong filing lets a supervisor trace a straight line from a named stakeholder concern to a documented mitigation to a board-approved control. It acknowledges uncertainty. It does not oversell consensus. It treats stakeholder risk as a live input to prudential judgement, not a reputational overlay.
Common Failures to Avoid
- Using engagement volume (number of meetings, survey responses) as a proxy for insight
- Presenting internal stakeholder views as if they were external validation
- Omitting stakeholders whose views are inconvenient
- Writing the narrative first and back-filling the evidence
Your Next Decision
Before your next filing goes to the board for approval, ask one question: could an external reviewer reconstruct our stakeholder risk conclusions from the underlying evidence pack? If the answer is no, the filing is not ready, regardless of how polished the drafting looks.
Frequently Asked Questions
How far back should stakeholder evidence go?
Generally twelve months for routine filings, longer for transactions or authorisations where the regulator will want to see a pattern of engagement rather than a pre-filing sprint.
Should we disclose dissenting stakeholder views?
Yes, with the management response. Filings that show only alignment invite the question of what was left out. Documented disagreement, resolved or acknowledged, is a mark of credibility.
Who should own the stakeholder risk section internally?
Risk or compliance should own the framing and conclusions. Investor relations, corporate affairs, or public policy can contribute evidence but should not draft the risk judgement.
How detailed should the methodology description be?
Detailed enough that a supervisor could replicate the approach. Vague methodology is the fastest way to have the entire section discounted.
Does this apply to routine filings or only material ones?
The depth scales with materiality, but the discipline applies to both. Routine filings with weak stakeholder sections create precedent problems when a material filing later relies on the same approach.
Frequently asked questions
How far back should stakeholder evidence go?
Generally twelve months for routine filings, longer for transactions or authorisations where the regulator will want to see a pattern of engagement rather than a pre-filing sprint.
Should we disclose dissenting stakeholder views?
Yes, with the management response. Filings that show only alignment invite the question of what was left out. Documented disagreement, resolved or acknowledged, is a mark of credibility.
Who should own the stakeholder risk section internally?
Risk or compliance should own the framing and conclusions. Investor relations, corporate affairs, or public policy can contribute evidence but should not draft the risk judgement.
How detailed should the methodology description be?
Detailed enough that a supervisor could replicate the approach. Vague methodology is the fastest way to have the entire section discounted.
Does this apply to routine filings or only material ones?
The depth scales with materiality, but the discipline applies to both. Routine filings with weak stakeholder sections create precedent problems when a material filing later relies on the same approach.
Related guides
How to Structure a Section 166 Skilled Person Review Response
This guide sets out how senior leaders in regulated firms should structure their response to a Section 166 skilled person review, from the moment the requirement notice arrives to the remediation phase. It covers governance, evidence, stakeholder handling, and the judgement calls that determine whether the firm emerges credibly or damaged.
What Regulators Look For in a Submission: A Practical Guide
This guide sets out what regulators actually assess when they receive a submission from a regulated firm, from authorisation applications to skilled person responses and change-in-control filings. After reading, you will know how to prepare submissions that demonstrate genuine compliance, sound judgement, and credible governance.
How to Prepare for an FCA Supervisory Visit: A Practical Guide
This guide sets out how senior leaders in regulated firms should prepare for an FCA supervisory visit, from initial notification through to post-visit follow-up. After reading, you will know how to organise your evidence, brief your people, and engage the supervisory team credibly.
Structuring a Section 178 Notification That Withstands PRA Group Structure Review
This guide sets out how to prepare a Change in Control notification that presents the acquirer's group with the clarity, completeness, and supervisory logic the PRA expects. After reading, you will know how to sequence disclosures, frame group complexity honestly, and engage the regulator in a way that supports timely approval on the merits.
How to Structure a Recovery Plan Playbook That Passes PRA Credibility Tests
This guide sets out how to build a Recovery Plan playbook that meets the PRA's credibility, usability and timeliness expectations without creating documents that could damage confidence if they surface externally. After reading, you will know how to sequence indicators, options and governance triggers so the plan works as a live management tool rather than a compliance artefact.
Where internal confidence may exceed external evidence
Polar Insight helps leadership teams test critical assumptions against stakeholder, market, regulatory, and operational reality before risk compounds.
Explore Stakeholder Proximity