How to Run a Strategic Review at a Regulated Firm Without Tipping Your Hand
This guide sets out how to conduct a serious strategic review inside a regulated firm without triggering premature market speculation or regulator concern. You will finish with a clearer view of how to structure the work, sequence disclosures, and manage the internal and external signals that most often go wrong.
Strategic reviews leak. Not usually through malice, but through calendar invites, adviser mandates, board pack distribution lists, and the small behavioural changes that observant regulators and journalists pick up quickly. If you are running a review at a bank, insurer, or asset manager, the technical work is rarely the hard part. The hard part is controlling the signal you emit while you do it.
Here is how to run one properly.
Define the review's perimeter before you define its content
Before any analysis begins, decide three things: what is genuinely in scope, who needs to know it is happening, and what triggers a mandatory disclosure obligation. Most reviews get into trouble because these questions are answered late, usually under pressure.
Be honest about materiality. If the review could plausibly lead to a disposal, a capital action, a change of control, or a material change in risk appetite, your disclosure obligations under MAR, Listing Rules, or equivalent regimes may crystallise earlier than you expect. Get your general counsel and company secretary to write down, in advance, the specific events that would move the review from confidential preparatory work into a disclosable position. This document becomes your control panel.
Build a tight information ring, and keep it tight
The instinct is to widen the group early to get better analysis. Resist it. Start with a working group of no more than six to eight people, including the CEO, CFO, general counsel, chair or SID, and one or two functional leads. Everyone signs a specific NDA referencing the review, not a generic one.
Use a project codename. Not because it fools anyone permanently, but because it disciplines behaviour: it forces people to think before they type, forward, or discuss. Keep documents off shared drives. Use a dedicated data room with named access from day one, even for internal materials.
What goes wrong here: advisers. The moment you appoint bankers or strategy consultants, the ring widens by 20 to 40 people you do not employ. Interview advisers on their internal wall-crossing protocols before you appoint, not after.
Sequence the regulator conversation deliberately
This is the judgement call that separates good reviews from damaging ones. Too early, and you invite supervisory involvement in a decision you have not made. Too late, and you look evasive.
The usable principle: engage the regulator when you have a defined range of options and a governance process to evaluate them, but before you have selected a preferred path. For PRA-regulated firms, this typically means a private, non-minuted conversation with your supervisor at the point the board has agreed the review's scope and terms of reference. Frame it as a courtesy briefing, not a consultation. You are informing, not seeking permission.
What good looks like: the regulator hears about the review from you, in person, before it appears in any board minute that could later be requested. What goes wrong: the first the supervisor learns is via a Sky News alert or an FT reporter's call for comment.
Manage the internal tells
Markets and journalists read organisational behaviour, not just announcements. Sudden changes in executive travel, unexplained board sub-committee meetings, a spike in adviser activity, or the quiet departure of a divisional CEO all get noticed.
Keep the normal rhythm running. Do not cancel investor days, do not postpone results, do not suddenly reshuffle the executive committee. If something must change, have a clean, unrelated reason ready that stands up to scrutiny.
Prepare the disclosure position before you need it
Draft the holding statement, the RNS announcement, and the internal all-staff note while the review is still confidential. Have them legally cleared and sitting in a locked folder. The moment you need them, you will not have time to write them well.
Run a leak scenario with your comms lead and general counsel. Decide, in advance, at what point a market rumour forces you to move from 'no comment' to confirmation. Write down the threshold.
The decision point
Before your next board meeting on this, answer one question: if this review leaked tomorrow morning, do you know exactly who calls the regulator, who briefs the chair, who talks to the FT, and what each of them says? If any of those answers is unclear, that is the work to do this week.
Related guides
How to Handle a Pre-Emptive Regulator Meeting After a Governance Failure
This guide covers how to prepare for and run a self-initiated regulator meeting when you have discovered a material governance failure inside your firm. After reading, you will know how to sequence the disclosure, frame the failure, and position remediation in a way that preserves credibility and controls the supervisory response.
How to Structure a Section 166 Response That Preserves Board Credibility
A practical guide to responding to a Skilled Person review in a way that protects the board's standing with the regulator. Covers how to sequence the engagement, where boards typically damage their own credibility, and how to convert findings into a credible remediation posture.
Board Accountability in Regulated Industries: A Practical Guide
This guide explains how boards in regulated sectors should structure accountability so that it holds up under regulatory, legal, and shareholder scrutiny. After reading, you will know where accountability typically breaks down, what good documentation looks like, and how to test whether your board is actually accountable or merely appears to be.
Regulated Industry Governance Best Practice: A Practical Guide
This guide sets out what good governance actually looks like in a regulated business, covering board composition, decision records, regulator relationships, and the failure modes that trigger enforcement. After reading, you will be able to pressure-test your current governance model against the standards regulators now apply in practice.
What Makes a Decision Defensible to Regulators: A Practical Guide
This guide explains what regulators actually look for when they test whether a decision was sound, and how to build that evidence before you need it. After reading, you will know how to structure, document, and stress-test decisions so they hold up under supervisory scrutiny or enforcement review.
Polar Insight helps senior leaders in financial services understand what their key stakeholders actually think before significant decisions are made.
Book a conversation