Capacity returned: full-time roles' worth of change-tracking capacity.
Honest recovery of change-tracking capacity per year.
Capacity spent tracking regulatory change, down to a fraction of one FTE.
Change identification: continuous vs periodic, manual, best-effort.
Challenge
Someone has to read what the regulators published this week, work out whether it applies to this institution, to which entity, in which jurisdiction, and to which product, then map the new obligation to the policies and controls that already exist and find which now have a gap. Then the rules move again and the work restarts.
- It is unbounded. The rules never stop moving, so the work never finishes and never gets smaller. Juniper Research forecasts regtech spend rising 124% between 2023 and 2028, from $83 billion to $207 billion, which is the market's way of saying the volume is still accelerating.
- It consumes the wrong people. Reading and triaging publications does not need a senior compliance officer's judgment, but it needs enough context that it cannot go to a junior. So it lands on the people who should be exercising judgment and crowds the judgment out.
- 42% of C-suite time and 43% of board time. Now goes to regulatory and supervisory compliance, up from 24% and 27% in 2016, while employee hours spent complying grew 61% between 2016 and 2023 (Bank Policy Institute, 2024).
- It produces nothing an examiner can see. A third of compliance capacity goes to the prerequisite for the work rather than the work. No return filed, no control tested. Pure overhead the institution cannot stop paying.
- The only available response was to hire. Every new regime added headcount to the fastest-growing line in the operating budget.
What the treadmill costs before the work starts
120
People in the compliance function
$150,000
Fully loaded, per head
20-30%
Of that capacity, on tracking change
$3.6M-$5.4M
A year spent reading, on an $18M capacity base
Solution
CreateOS deployed a regulatory-change-monitoring agent that runs continuously inside the institution's boundary. It scans the regulatory sources, identifies what is relevant to this institution, and maps each new obligation to the specific policies and controls it touches.
A third of the team just keeping up
Reading what regulators published, then working out what it touched. Then the rules moved again.
24-36roles' worth returned
Scanning and mapping collapse
What reaches a desk is a short list already mapped to the controls affected.
What lands on a compliance officer's desk is no longer a feed. It is a short list of changes that apply to this institution, each one already mapped to the policies and controls affected, with the gaps flagged. The reading, the filtering, and the mapping are done. The judgment is not, and is not meant to be.
- Scanning, filtering, and first-pass mapping are done. The reading is complete before anything reaches a desk. The judgment is not, and is not meant to be.
- The monitoring itself is auditable. An institution cannot tell an examiner it monitors change because a system does it. It has to show what was published, assessed, judged relevant, mapped, and who decided. That trail is the difference between a tool the team uses and a control the institution can evidence.
- The policy and control library never leaves. Mapping obligations to controls means reading the internal policy set, control framework, and risk taxonomy. That material stays inside the institution's own infrastructure and jurisdiction.
- The one agent with a reason to touch the outside world. Its path is defined in the kernel rather than a config file: approved regulatory sources and nothing else, with nothing travelling outbound.
- Untrusted external content is contained daily. The monitoring agent runs in its own guest kernel, in a disposable environment, because ingesting the internet on the institution's behalf is exactly the job that needs a hard boundary.
CreateOS is SOC 2 Type II and ISO 27001 certified.
Outcome Derived
The treadmill stopped. The capacity came back.
| Metric | Before | After |
|---|---|---|
| Capacity spent tracking regulatory change | 20% to 30% of the compliance team | A fraction of one FTE |
| Change identification | Periodic, manual, best-effort | Continuous |
| Obligation-to-control mapping | Manual, per analyst | Automated, with lineage |
| Evidence that change is monitored | Assertion | Logged, replayable trail |
| Senior compliance time | Consumed by triage | Returned to judgment |
| Policy and control library exposure | Would leave the boundary in a SaaS model | Never leaves |
The treadmill stopped, and 24 to 36 full-time roles' worth of capacity came back.
- $3.6M to $5.4M was going to the prerequisite, not the work. A 120-person team at a fully loaded $150,000 per head is roughly $18M of annual capacity, and 20% to 30% of it went on change tracking.
- The honest recovery is $2.2M to $4.0M, not the full $5.4M. Assessing a material change and deciding what to do about it stays human, and should. What the agent removes is the reading, filtering, and first-pass mapping: the bulk of the effort, not all of it.
- A redeployment story, not a redundancy story. The institution did not fire 30 compliance people. It stopped spending 30 people's worth of capacity on reading publications. A function under-resourced for judgment does not want to be smaller, it wants to stop drowning.
- That distinction is why the CCO sponsors it. Rather than fights it, which is the difference between a programme that lands and one that stalls internally.
- Change monitoring is upstream of everything else. An institution that knows continuously, with evidence, which obligations apply and which controls they touch reports more accurately and walks into an examination prepared. The capacity saving is visible; the accuracy is compounding.
What We Would Prove, and How
Weeks 1 to 2, baseline. Measure what the institution actually spends on change tracking today: which people, how much of their week, across which regimes and jurisdictions. This is the yardstick, and most institutions have never measured it.
Weeks 2 to 6, build and integrate. Stand up the monitoring agent, connect it to the relevant regulatory sources along allowlisted paths, ingest the institution's policy library, control framework, and risk taxonomy, deploy self-hosted inside the boundary.
Weeks 6 to 9, parallel run. The agent monitors alongside the existing team. Every change it flags is compared against what the team caught, and every change the team caught is checked against what the agent surfaced. Both directions matter. A monitoring system that misses is worse than no system, because the institution stops looking.
Week 9 onward, controlled adoption. The team works from the agent's mapped output, with human judgment on every material change, expanding across regimes and jurisdictions as the coverage record builds.
Success criteria, agreed up front: change-tracking capacity reduced by at least 60% against the measured baseline, zero material changes missed against the parallel-run comparison, every flagged change mapped to the affected controls with a replayable trail, and human decision preserved on every material change.
Highlights
- Capacity returned: 24 to 36 full-time roles' worth.
- Honest recovery: $2.2M to $4.0M of change-tracking capacity a year.
- Capacity spent tracking regulatory change: 20% to 30% → a fraction of one FTE.
- Change identification: Periodic, manual, best-effort → Continuous.



