Skip to main content

How to Prepare a Regulatory Filing with Stakeholder Risk Assessment

A practical guide to preparing a regulatory filing that includes a credible stakeholder risk assessment, from evidence gathering through submission. Readers will finish with a clear method for sequencing the work, testing assumptions, and demonstrating genuine compliance to regulators.

Preparing a regulatory filing that includes a stakeholder risk assessment is not a documentation exercise. It is a test of whether your firm actually understands who is affected by what you are doing, what could go wrong, and whether your controls hold up under challenge. Regulators read these filings looking for evidence of judgement, not just process. This guide sets out how to prepare one that stands up.

Key Executive Takeaways

  • A credible stakeholder risk assessment starts with identifying who is materially affected and what harm they could suffer, then works backwards to controls and evidence.
  • The most common failure is a filing that describes internal process well but cannot answer basic questions about customer, counterparty, or market impact.
  • Submission quality is set weeks before drafting begins: by the discipline of your evidence base, the honesty of your risk register, and the seniority of internal challenge.

Start with the regulator's actual question

Every filing sits inside a specific regulatory purpose: a change in permissions, a product approval, a periodic assessment, a material notification. Before anyone drafts anything, write in one paragraph what the regulator is trying to establish and what decision they will make on the back of your submission. If your team cannot articulate this cleanly, the filing will drift into generic assurance language and lose credibility.

Then map the specific rules, guidance, and supervisory expectations that apply. Not the general framework: the exact provisions the regulator will test your submission against.

Identify stakeholders by material effect, not by convenience

Stakeholder identification is where most filings weaken. Teams list obvious groups (customers, staff, shareholders) and stop. A proper assessment forces harder questions:

  • Which customer segments are affected differently, and which are vulnerable?
  • Which counterparties, intermediaries, or third parties carry knock-on exposure?
  • Which market participants could be affected by information asymmetry or timing?
  • Which internal groups, including control functions, carry residual risk if the change goes wrong?

For each group, state the mechanism of impact in one sentence. Vagueness here shows up sharply under supervisory scrutiny.

Build the risk register from stakeholder harm, not internal categories

Risk registers built around operational, conduct, and financial silos tend to miss the point. Build yours around what could actually happen to each stakeholder group, then classify. For each risk, capture: the harm, the likelihood under current controls, the severity if it crystallises, the leading indicators, and the specific control that addresses it. Where a control is untested or new, say so. A register that shows only green ratings is a red flag to any experienced supervisor.

Evidence before narrative

Do not draft the filing until you have the evidence base assembled. That means: management information showing the risk picture over time, minutes demonstrating governance oversight, testing results for material controls, customer research or complaint data where relevant, and third-party assurance where applicable. If a claim in the filing cannot be traced to a document, remove it or generate the evidence.

Internal challenge before external submission

The filing should be challenged by someone senior who was not involved in drafting: a non-executive, a second-line head, or external counsel. Give them the regulator's question and the draft, and ask them to identify what they would push back on. If challenge produces only minor edits, it has not been rigorous enough. Rework until the submission holds up against your toughest internal critic.

What good looks like

A strong filing is specific, evidenced, and honest about residual risk. It names the stakeholders, quantifies the exposure, shows how controls have been tested, and sets out what the firm will do if leading indicators move the wrong way. It does not oversell. Regulators respond well to firms that demonstrate they understand their own weaknesses and are managing them, and poorly to firms that present a uniformly reassuring picture.

Next step

Before your next filing, run the stakeholder identification exercise cold with a group that has not seen the draft. If the list they produce differs materially from yours, you have found the gap that needs closing before submission.

Frequently Asked Questions

How far in advance should we start preparing?

For a material filing, evidence gathering and stakeholder analysis should begin at least eight to twelve weeks before submission. Drafting is the last third of the work, not the first.

Who should own the stakeholder risk assessment?

Ownership sits with the business line accountable for the activity, with second-line risk providing challenge and compliance confirming the regulatory read. Splitting ownership across functions produces weaker filings.

How do we handle risks we cannot fully mitigate?

Name them, explain why residual risk exists, describe the monitoring in place, and set out the trigger for further action. Regulators expect residual risk. They do not expect it to be hidden.

What if new information emerges after submission?

Notify the regulator promptly with a clear account of what changed, the revised risk position, and any actions taken. Timely disclosure preserves credibility; delayed disclosure damages it.

Frequently asked questions

How far in advance should we start preparing?

For a material filing, evidence gathering and stakeholder analysis should begin at least eight to twelve weeks before submission. Drafting is the last third of the work, not the first.

Who should own the stakeholder risk assessment?

Ownership sits with the business line accountable for the activity, with second-line risk providing challenge and compliance confirming the regulatory read. Splitting ownership across functions produces weaker filings.

How do we handle risks we cannot fully mitigate?

Name them, explain why residual risk exists, describe the monitoring in place, and set out the trigger for further action. Regulators expect residual risk. They do not expect it to be hidden.

What if new information emerges after submission?

Notify the regulator promptly with a clear account of what changed, the revised risk position, and any actions taken. Timely disclosure preserves credibility; delayed disclosure damages it.

Related guides

Regulation & Regulatory Change

What Regulators Look For in a Submission: A Practical Guide

This guide explains what regulators actually assess when reviewing a formal submission, from authorisation applications to Section 166 responses and thematic returns. After reading it, you will know how to structure a submission that reflects genuine control, sound judgement and credible governance.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Regulation & Regulatory Change

How to Structure a Section 166 Skilled Person Review Response

This guide sets out how senior leaders in regulated firms should structure their response to a Section 166 skilled person review, from the moment the requirement notice arrives to the remediation phase. It covers governance, evidence, stakeholder handling, and the judgement calls that determine whether the firm emerges credibly or damaged.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Regulation & Regulatory Change

What Regulators Look For in a Submission: A Practical Guide

This guide sets out what regulators actually assess when they receive a submission from a regulated firm, from authorisation applications to skilled person responses and change-in-control filings. After reading, you will know how to prepare submissions that demonstrate genuine compliance, sound judgement, and credible governance.

Regulatory submissionRegulatorsRegulatory uncertainty
4 min readRead guide →
Regulation & Regulatory Change

How to Prepare for an FCA Supervisory Visit: A Practical Guide

This guide sets out how senior leaders in regulated firms should prepare for an FCA supervisory visit, from initial notification through to post-visit follow-up. After reading, you will know how to organise your evidence, brief your people, and engage the supervisory team credibly.

Regulatory submissionRegulatorsExecutive teams
4 min readRead guide →
Regulation & Regulatory Change

Structuring a Section 178 Notification That Withstands PRA Group Structure Review

This guide sets out how to prepare a Change in Control notification that presents the acquirer's group with the clarity, completeness, and supervisory logic the PRA expects. After reading, you will know how to sequence disclosures, frame group complexity honestly, and engage the regulator in a way that supports timely approval on the merits.

Regulatory submissionAcquisitionRegulators
4 min readRead guide →

Where internal confidence may exceed external evidence

Polar Insight helps leadership teams test critical assumptions against stakeholder, market, regulatory, and operational reality before risk compounds.

Explore Stakeholder Proximity