Skip to main content

How to Prepare a Regulatory Filing With Stakeholder Risk Assessment

A practical guide for senior leaders on integrating stakeholder risk assessment into a regulatory filing so it reads as evidence of genuine control, not compliance theatre. After reading, you will know how to sequence the work, what to include, and where filings typically fall short under supervisory review.

A regulatory filing that includes a stakeholder risk assessment is not two documents stapled together. It is one argument: that the firm understands who is affected by the matter being filed, has tested how those parties could be harmed or could react, and has built controls and disclosures that reflect that understanding. Supervisors read filings for coherence. If the stakeholder analysis does not connect to the risks, mitigations, and governance you describe elsewhere, the filing weakens itself.

Key Executive Takeaways

  • A stakeholder risk assessment inside a regulatory filing must trace a clear line from identified stakeholder groups to specific risks, controls, and disclosures, not sit as a standalone annex.
  • The most common failure is asserting stakeholder impact without evidence: no data, no engagement record, no differentiation between customer segments, counterparties, employees, and market participants.
  • Good filings show the firm has already acted on what the assessment revealed, including the uncomfortable findings, and explain governance oversight in specific terms.

Start With the Regulatory Question, Not the Stakeholder Map

Every filing answers a specific supervisory question: are you a fit and proper controller, is your wind-down orderly, is your product delivering good outcomes, is your capital adequate. The stakeholder risk assessment exists to sharpen your answer to that question. Before drafting anything, write in one sentence what the regulator is being asked to conclude. Every stakeholder finding should feed that conclusion or be cut.

This discipline prevents the most tedious failure mode: a generic stakeholder register listing customers, employees, shareholders, regulators, and communities, with no differentiation and no consequence.

Identify Stakeholders at the Right Resolution

Broad categories are useless. Segment stakeholders to the level where risk actually differs. For a Consumer Duty submission, that might mean vulnerable customers in specific product cohorts, not customers generally. For a Section 166 response, it might mean counterparties above a materiality threshold plus the specific desks that face them. For a change in control, it might mean depositors, wholesale funders, key employees under retention risk, and the acquired firm's regulators in other jurisdictions.

What good looks like: each stakeholder group has a defined boundary, a population estimate, and a stated reason for inclusion.

Assess Risk From the Stakeholder's Position, Not Yours

The internal view of risk is almost always narrower than the stakeholder view. Ask, for each group: what could go wrong for them, how would they detect it, what would they do about it, and what would that mean for the firm and the market. This is where perception, behaviour, and second-order effects belong: customer complaint patterns, counterparty withdrawal risk, employee attrition, media and political reaction, regulator to regulator escalation.

Evidence matters. Reference actual engagement, complaint data, exit interviews, counterparty conversations, prior supervisory correspondence. Assertion without source is the flag that draws follow-up questions.

Connect Findings to Controls and Disclosure

Every material stakeholder risk should map to a specific control, a specific disclosure in the filing, or an explicit acceptance with rationale and governance sign-off. If a risk appears in the assessment but not in the mitigation section, a supervisor will notice. If a control appears without a corresponding risk, it looks defensive.

Where findings are uncomfortable, address them directly. Filings that acknowledge a real weakness and describe a credible remediation plan land better than filings that appear to have discovered nothing.

Show Governance, Not Just Process

Name the committee that reviewed the assessment. Give the date. Summarise the challenge that was raised and how it changed the filing. Senior Managers should be able to speak to the assessment without briefing. If the assessment was produced by a working group and never tested at board or ExCo level, say so and explain why that was appropriate, or fix it before filing.

Pressure Test Before Submission

Have someone outside the drafting team read the filing cold and answer three questions: who is affected, what could harm them, and what has the firm done about it. If they cannot answer clearly, the filing is not ready.

Next Step

Before your next filing, decide who owns the stakeholder assessment inside the submission, when it will be reviewed at committee, and how its findings will be evidenced. That decision, taken early, is what separates a filing that stands up to scrutiny from one that invites it.

Frequently Asked Questions

How detailed should the stakeholder risk assessment be inside the filing itself?

Enough to show the reasoning, not the full working papers. Include the segmentation, the material risks by group, the evidence base, and the linkage to controls. Retain the underlying analysis for supervisory request.

Should we disclose stakeholder risks we have not yet fully mitigated?

Yes, with the remediation plan, timeline, and accountable Senior Manager. Undisclosed known risks that surface later damage credibility far more than acknowledged ones under active management.

Who should own the stakeholder assessment: risk, compliance, or the business?

The business owns the risks and the customer or counterparty relationships. Risk and compliance provide challenge and framework. A filing signed off only by second line, with no first line ownership visible, reads as thin.

How do we handle stakeholder views that contradict our filing position?

Represent them accurately, explain how you weighed them, and set out why your position is nonetheless the right one. Suppressing contradictory input is the single fastest way to lose supervisory trust when it later emerges.

Frequently asked questions

How detailed should the stakeholder risk assessment be inside the filing itself?

Enough to show the reasoning, not the full working papers. Include the segmentation, the material risks by group, the evidence base, and the linkage to controls. Retain the underlying analysis for supervisory request.

Should we disclose stakeholder risks we have not yet fully mitigated?

Yes, with the remediation plan, timeline, and accountable Senior Manager. Undisclosed known risks that surface later damage credibility far more than acknowledged ones under active management.

Who should own the stakeholder assessment: risk, compliance, or the business?

The business owns the risks and the customer or counterparty relationships. Risk and compliance provide challenge and framework. A filing signed off only by second line, with no first line ownership visible, reads as thin.

How do we handle stakeholder views that contradict our filing position?

Represent them accurately, explain how you weighed them, and set out why your position is nonetheless the right one. Suppressing contradictory input is the single fastest way to lose supervisory trust when it later emerges.

Related guides

Regulation & Regulatory Change

How to Structure a Recovery Plan Playbook That Passes PRA Credibility Tests

This guide sets out how to build a Recovery Plan playbook that meets the PRA's credibility, usability and timeliness expectations without creating documents that could damage confidence if they surface externally. After reading, you will know how to sequence indicators, options and governance triggers so the plan works as a live management tool rather than a compliance artefact.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Regulation & Regulatory Change

How to Structure an Operational Resilience Self-Assessment That Withstands Regulator Challenge

This guide sets out how to build an operational resilience self-assessment that holds up to FCA and PRA impact tolerance scrutiny. After reading, senior leaders will know how to sequence evidence, frame judgements, and pre-empt the challenges supervisors are most likely to raise.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Regulation & Regulatory Change

How to Structure a Pillar 2 Liquidity Narrative That Anticipates PRA ILAAP Challenge

This guide sets out how to build an ILAAP liquidity narrative that pre-empts the specific challenges PRA supervisors raise on Pillar 2 risks. After reading, senior leaders will know how to sequence the document, where to concentrate evidence, and how to defend judgement calls under supervisory pressure.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Regulation & Regulatory Change

How to Structure a Solvency II ORSA Narrative That Pre-empts PRA Capital Challenge

This guide sets out how to build an ORSA narrative that anticipates PRA scrutiny on capital adequacy, risk quantification, and management action credibility. After reading it, senior insurance leaders will know how to sequence the document, evidence key judgements, and close the gaps supervisors most often probe.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Regulation & Regulatory Change

How to Close a Dear CEO Letter Without Inviting Follow-Up

This guide sets out how to structure a response to a Dear CEO letter that answers the supervisor's concerns cleanly and reduces the odds of a second-round information request. It covers what to include, what to leave out, and the judgement calls that separate a closing response from one that opens new fronts.

Regulatory submissionRegulatorsBoards
4 min readRead guide →

Where internal confidence may exceed external evidence

Polar Insight helps leadership teams test critical assumptions against stakeholder, market, regulatory, and operational reality before risk compounds.

Explore Stakeholder Proximity