PILLAR 3 OF 3

Compliance.

Demonstrable adherence to external rules — the function that converts laws into controls, controls into evidence, and evidence into the license to keep operating. The densest pillar in U.S. financial services.

Workflow categories

SOC 2 (Trust Services)5 workflows
AICPA TSCCC1–CC9Type I/II
  • Control Evidence Collection & Checklist
  • Vendor Risk Assessment (SOC 2 scope)
  • Security Policy Library
  • Penetration Test Gap Report
  • Continuous Control Testing Schedule

Includes all 5 workflows above.

Financial Regulation5 workflows
Basel IIISOXSECAML/BSA
  • Capital Adequacy Assessment (Basel III)
  • SAR Draft & Filing Workflow
  • KYC/CDD Audit
  • SEC Filing Readiness (10-K/10-Q)
  • AML Program Review

Includes all 5 workflows above.

International Frameworks5 workflows
DORAISO 27001GDPRNIS2
  • DORA ICT Risk Assessment (EU Financial)
  • ISO 27001 Gap Analysis & Annex A
  • GDPR Article 30 Processing Records
  • NIS2 Compliance Mapping
  • Cross-border Data Transfer Mechanisms

Includes all 5 workflows above.

Privacy & Data Protection4 workflows
GDPRCCPA/CPRAHIPAADPIA
  • Data Subject Request (DSR) Tracker
  • Privacy Impact Assessment (DPIA)
  • Breach Notification Workflow
  • Data Retention Policy Review

Includes all 4 workflows above.

Ongoing / Scheduled4 workflows
Horizon ScanningChange MgmtCertification
  • Regulatory Change Impact Review
  • Annual Control Recertification
  • Quarterly Risk Assessment Update
  • Compliance Calendar Management

Includes all 4 workflows above.

HR & People Risk4 workflows
OffboardingAccess RevocationBackground Check
  • Offboarding & Access Revocation Workflow
  • Background Check Program
  • Insider Threat Assessment
  • HR Policy Compliance Review

Includes all 4 workflows above.

The definition

What compliance is

Every bank exam ends at the same question: prove it. Not "did you do the right thing" — show the record that says you did. Under examination, what happened matters less than what you can demonstrate happened. The standing assumption in the room is simple: if it isn't documented, it didn't happen.

That pressure is the reason this pillar exists:

Compliance is the discipline of proving that an institution follows the rules that apply to it — laws, regulations, supervisory expectations, and contractual standards. Its defining word is demonstrable.

Compliance is a translation function. Laws are written in the language of legislatures; institutions run on procedures, systems, and people. Compliance converts one into the other — obligations into controls, controls into evidence, evidence into findings, findings into remediation, tracked to close.

Where it came from

Compliance is the institutional memory of financial failure.

1863

The OCC.

The National Currency Act created the Office of the Comptroller of the Currency — and the first federal bank examiners, empowered to inspect national banks' books. Examination as a standing practice starts here.¹

The pattern: every compliance obligation is a response to a documented abuse. The rulebook is a history of what went wrong, written so it can't go wrong the same way twice.

The evaluators

Compliance is a scored activity. Here's who keeps score.

The regulators and examiners.

  • OCC — supervises national banks; conducts exams and issues supervisory findings
  • Federal Reserve — supervises bank holding companies and state member banks; runs the stress-test regimes
  • FDIC — insures deposits and supervises state non-member banks
  • CFPB — consumer financial protection
  • SEC & FINRA — securities markets, broker-dealers, disclosures
  • FinCEN & OFAC — financial crime, AML, and sanctions
  • State regulators (e.g., NYDFS) — charters, cybersecurity rules, money transmission¹

The independent attesters. CPA firms issue SOC 2 reports under the AICPA's Trust Services Criteria and opinions on SOX controls; accredited certification bodies assess ISO 27001. Attestations carry weight precisely because the attester's name and liability stand behind them.²

The internal lines of defense. First line: the business units that own the risk. Second line: the compliance and risk functions that set policy and challenge. Third line: internal audit, which answers to the board — not to management.³

The KPIs — how integrity gets measured.

  • Exam ratings — the composite grades (capital, assets, management, earnings, liquidity, sensitivity) that determine supervisory intensity
  • Findings and supervisory actions — count, severity, and aging of open items
  • Remediation velocity — days-to-close; overdue findings are a red flag on their own
  • Filing timeliness — SARs, CTRs, call reports, 10-K/10-Q deadlines
  • Control test pass rates — scheduled, documented evidence that controls operate as designed

The integrity standard. Every measure above rests on the same foundation: traceable evidence. A control without evidence is an assertion — and examiners are trained to treat assertions as findings.

1 of 4