Regulatory Change Horizon Scanning Centre
Internal workspace for tracking regulatory change signals across ADGM/FSRA · UK FCA · MAS · MiFID/MiFID II and the cross-cutting themes that govern BLACKSWAN Capital Markets OS. Every signal is triaged, counsel-reviewed, mapped to the 21-pack evidence spine, and converted to a tracked obligation with policy / procedure / control / evidence updates. Conservative posture: this is internal horizon scanning — not legal advice, not regulator submission, not approval, not certification, not audit opinion, not authorization for external launch.
Twelve signals · scope · posture · owner · counsel status
ADGM perimeter & outsourcing signals
FSRA expectations on outsourcing, MNPI handling, and incident notification timing. Counsel-bound rule-pack review pending 2026-05-19.
FCA SMCR / OpRes signals
SMCR-aligned governance · operational resilience self-assessment · IBS mapping · material outsourcing notification.
MAS TRM & FEAT signals
MAS Technology Risk Management gap-list · FEAT principles for AI · outsourcing notification triggers.
MiFID record-keeping & product-governance signals
No order placement / execution; alignment to MiFID record-keeping & product-governance principles for evidence retention.
Capital & liquidity readiness signals
Prudential expectations where in scope; capital/liquidity posture; auditor engagement pending.
Conduct risk & market integrity signals
Conduct risk MI, complaints flow, market-abuse / MNPI containment — counsel-bound external phrasing.
Outsourcing & concentration signals
Material outsourcing classification (CHG-006), vendor concentration, exit-plan posture, DORA-adjacent themes.
OpRes / impact-tolerance signals
Tier-1 RTO 30m / RPO 5m · DR drill 2026-06-12 · IBS map · regulator-facing posture under counsel review.
AI / model governance signals
FEAT alignment narrative · human-in-loop on every model output · counsel-bound rule pack.
Data protection & cross-border signals
UK / EU / MAS / ADGM cross-border posture; DPA · SCC · DSR runbook live. Counsel review on cross-border language.
AML / KYC & market-abuse signals
KYC partner contract pending · MNPI containment (POL-003); market-abuse posture counsel-locked.
Revenue recognition & tax/VAT signals
Revenue treatment baseline locked; external auditor engagement pending · tax adviser draft in flight.
Ten changes · severity · source · effective date · owner · affected packs · state
| Change ID | Title | Jurisdiction / theme | Severity | Source | Effective date | Owner | Affected packs | State |
|---|---|---|---|---|---|---|---|---|
| RCH-001 | ADGM activity-perimeter clarification | ADGM / FSRA | High | Pre-application adviser route | n/a · standing | Head of Regulatory · External Counsel | Auth · Activity Perimeter · Reg. Exam Response · Reg. Change | Counsel Review |
| RCH-002 | FCA Operational Resilience self-assessment refresh | UK FCA | High | FCA OpRes regime | Annual · next post-DR drill | SRE Lead · CISO · External Counsel | Control Testing · Incident · Outsourcing Concentration · Reg. Change | Impact Assessed |
| RCH-003 | FCA material-outsourcing reclassification | UK FCA | High | Internal review (CHG-006) | 2026-06-01 effective | Head of Procurement · Risk Committee · External Counsel | Partner Route · Outsourcing Concentration · Reg. Change | Implementing |
| RCH-004 | MAS TRM gap-list update | MAS | Medium | Adviser review (pending slot) | Adviser-bound | CISO · Head of Regulatory · External Counsel | Auth · Control Testing · Model Risk · Outsourcing Concentration | Counsel Review |
| RCH-005 | MAS FEAT alignment narrative | MAS · AI / Model Risk | Medium | FEAT principles | Counsel-bound | CISO · Head of Regulatory · External Counsel | Regulatory Digital Twin · Model Risk · Reg. Change | Counsel Review |
| RCH-006 | MiFID II no-execution & record-keeping language lock | EU MiFID II / MiFIR | Medium | MiFID record-keeping principles | Counsel-bound | Head of Regulatory · CFO · External Counsel | Activity Perimeter · Product Governance · Policy Attestation | Counsel Review |
| RCH-007 | Cross-border data transfer posture refresh | Theme · Data / privacy | Medium | UK · EU · MAS · ADGM | Continuous | Data Governance Lead · CISO · External Counsel | KYC/KYB · Data-Room MNPI · Outsourcing Concentration · Policy Attestation | Counsel Review |
| RCH-008 | Incident notification timeline per jurisdiction | All jurisdictions · Theme · Incident | High | Internal · counsel countersign pending | On Sev-1 / Sev-2 incident | Head of Regulatory · CISO · External Counsel | Incident · Reg. Change · Reg. Exam Response | Counsel Review |
| RCH-009 | Revenue treatment classifier validation | Theme · Revenue / tax | Medium | External Auditor (engagement pending) | Auditor-bound | CFO · External Auditor | Revenue Recognition · Tax/VAT · Capital/Liquidity | Impact Assessed |
| RCH-010 | Complaints capture flow + conduct-risk MI | Theme · Conduct | Low | Internal · pre first pilot | Pre first pilot | Head of Commercial · CoS · Risk Committee | Complaints · Conduct Risk MI · Reg. Change | Triaged |
21 BLACKSWAN evidence packs × current open changes touching each pack
| Evidence pack | Owning Centre(s) | Touching changes | Aggregate posture | Recommended next step |
|---|---|---|---|---|
| Auth | Security Operations · Enterprise Architecture | RCH-001 · RCH-004 | Counsel Review | Close Entra cutover · refresh ADGM perimeter narrative |
| KYC / KYB Onboarding | Commercial Readiness · Vendor Risk | RCH-007 | Counsel Review | KYC contract sign-off + cross-border DPA review |
| Data-Room MNPI Access | Stakeholder Rooms · Data Governance | RCH-007 | Counsel Review | Continue per-share access review · maintain redaction posture |
| Settlement Responsibility | Financial Controls | — | Stable | None — quarterly review |
| Activity Perimeter Decision | Regulatory Escalation · Jurisdiction Playbooks | RCH-001 · RCH-006 | Counsel Review | Lock no-execution / no-client-money language |
| Control Testing | Approval & Sign-Off · Model Governance | RCH-002 · RCH-004 | Impact Assessed | Re-test post DR drill 2026-06-12 |
| Partner-Route Assurance | Vendor Risk · Commercial Readiness | RCH-003 | Implementing | Effective 2026-06-01 — confirm counsel countersign |
| Revenue Recognition | Financial Controls | RCH-009 | Impact Assessed | Auditor engagement letter close |
| Tax / VAT | Financial Controls | RCH-009 | Impact Assessed | Complete adviser draft before 2026-07-15 |
| Regulatory Digital Twin Decision | Model Governance · Regulatory Escalation | RCH-005 | Counsel Review | Lock FEAT alignment narrative post counsel session |
| Model Risk | Model Governance | RCH-004 · RCH-005 | Counsel Review | Re-validate model risk pack post counsel session |
| Incident | Production Monitoring · Security Operations | RCH-002 · RCH-008 | Counsel Review | Lock counsel-approved notification timelines |
| Board-Pack Attestation | Strategic Reporting · Programme Governance | — | Stable | Continue monthly cadence |
| Regulatory Change | Regulatory Escalation · Jurisdiction Playbooks | RCH-001 · RCH-002 · RCH-003 · RCH-004 · RCH-005 · RCH-006 · RCH-008 · RCH-010 | Implementing | Continue weekly horizon sweep |
| Complaints | Commercial Readiness · Operating Model | RCH-010 | Triaged | Define complaint-capture flow before first pilot |
| Outsourcing Concentration | Vendor Risk · Enterprise Architecture | RCH-002 · RCH-003 · RCH-004 · RCH-007 | Implementing | Close vendor reclassification (CHG-006) |
| Capital / Liquidity Readiness | Financial Controls | RCH-009 | Impact Assessed | Counsel review of capital posture |
| Policy Attestation | Operating Model · Security Operations | RCH-006 · RCH-007 | Counsel Review | Refresh attestation policy post counsel session |
| Product Governance | Commercial Readiness · Approval & Sign-Off | RCH-006 | Counsel Review | Lock MiFID-aligned product governance footer |
| Conduct Risk MI | Operating Model · Strategic Reporting | RCH-010 | Triaged | Define MI capture for complaint flow |
| Regulatory Exam Response | Regulatory Escalation · Model Governance | RCH-001 · RCH-008 | Counsel Review | Maintain restricted-use posture · counsel countersign |
Six steps · intake → counsel sign-off · evidence-ready
Signal capture
Horizon scanner logs the change; jurisdiction / theme tagged; severity drafted; pack-impact list scoped.
Internal triage
Programme + Centre lead confirm scope; SOD applied (intake ≠ owner); RAID entry where P0/P1.
External counsel review
Counsel reviews interpretation of the change; locks phrasing for any regulator-facing artefact.
Pack & control impact
Impact mapped to 21 evidence packs and the control library; obligations registered with named owners.
Policy / procedure / control update
Owner closes obligation through policy text · runbook update · control change · evidence refresh.
Evidence preservation
Evidence hash captured; cross-Centre links updated; audit-event tag applied; change moves to Implemented.
Obligations tied to policy · procedure · control · evidence updates
| Obligation ID | Linked change | Policy update | Procedure / runbook | Control update | Evidence update | Owner | State |
|---|---|---|---|---|---|---|---|
| OBL-001 | RCH-001 · RCH-004 | POL-001 Auth | RB-EVIDENCE-PUBLISH (auth path) | CTL-001 MFA & conditional access | Security Evidence Pack | CISO · Identity Lead | Implementing |
| OBL-002 | RCH-002 | POL-006 Control Testing | RB-DR-FAILOVER | CTL-008 DR RTO/RPO | Architecture · Release Control packs | SRE Lead · CISO | Impact Assessed |
| OBL-003 | RCH-003 | POL-007 Partner Route · POL-016 Outsourcing | RB-VENDOR-ONBOARD | CTL-005 Vendor classification | Vendor Risk · Reg. Change packs | Head of Procurement · External Counsel | Implementing |
| OBL-004 | RCH-004 | POL-018 Policy Attestation · POL-011 Model Risk | RB-MODEL-OVERRIDE | CTL-007 Human-in-loop · CTL-001 MFA | Security Ops · Model Governance packs | CISO · Head of Regulatory | Counsel Review |
| OBL-005 | RCH-005 | POL-010 Digital Twin · POL-011 Model Risk | RB-MODEL-OVERRIDE | CTL-007 Human-in-loop · CTL-010 Counsel countersign | Model Governance · Reg. Change packs | CISO · Head of Regulatory · External Counsel | Counsel Review |
| OBL-006 | RCH-006 | POL-005 Activity Perimeter · POL-019 Product Governance | RB-EVIDENCE-PUBLISH (footer template) | CTL-006 Per-file footer · CTL-010 Counsel countersign | Activity Perimeter · Product Governance packs | Head of Regulatory · External Counsel | Counsel Review |
| OBL-007 | RCH-007 | POL-002 KYC/KYB · POL-003 MNPI · POL-018 Policy Attestation | RB-DG-INCIDENT · RB-ROOM-SHARE | CTL-003 Room access · CTL-006 Per-file footer | Data Governance · Stakeholder Rooms packs | Data Governance Lead · CISO · External Counsel | Counsel Review |
| OBL-008 | RCH-008 | POL-012 Incident · POL-014 Reg. Change | RB-REG-NOTIFY · RB-T1-MASTER | CTL-010 Counsel countersign | Incident · Reg. Exam Response packs | Head of Regulatory · CISO · External Counsel | Counsel Review |
| OBL-009 | RCH-009 | POL-008 Revenue Recognition · POL-009 Tax/VAT · POL-017 Capital/Liquidity | RB-FINANCIAL-CLOSE | CTL-009 Monthly close · CTL-004 Dual sign-off | Financial Controls pack | CFO · External Auditor | Impact Assessed |
| OBL-010 | RCH-010 | POL-015 Complaints · POL-020 Conduct Risk MI | (new) RB-COMPLAINTS-CAPTURE | CTL-006 Per-file footer | Complaints · Conduct Risk MI packs | Head of Commercial · CoS · Risk Committee | Triaged |
Movement criteria between states · gate · owner
| Transition | Gate | Acceptance criteria | Owner | Evidence captured |
|---|---|---|---|---|
| Watchlist → Intake | Triage on signal | Severity drafted · jurisdiction/theme tagged · pack-impact scoped | Head of Regulatory · CoS | Intake note + signal source |
| Intake → Triaged | Internal triage | Programme + Centre lead confirm scope · RAID entry where P0/P1 · SOD applied | Programme Manager · Centre lead | Triage note + RAID reference |
| Triaged → Counsel Review | Counsel-bound | External counsel receives scope brief · phrasing draft if regulator-facing | Head of Regulatory · External Counsel | Counsel intake hash |
| Counsel Review → Impact Assessed | Pack impact | 21-pack impact mapped · obligations registered with named owners · controls cross-referenced | Head of Regulatory · Head of Evidence | Impact matrix entry |
| Impact Assessed → Implementing | Owner sign-on | Each obligation has an owner · policy / procedure / control update plan dated · RAID updated | Programme Manager | Obligation tracker entry |
| Implementing → Evidence Ready | Evidence preserved | Evidence hashes captured · cross-Centre links updated · audit-event tag applied | Head of Evidence | Evidence pack diff + hash |
| Evidence Ready → Implemented | Counsel + CEO sign-off | External counsel countersign on regulator-facing language · CEO informed · pack locked | External Counsel · CEO | Counsel countersign hash |
| Implemented → Archived | Retention | 10-year retention class applied · cross-Centre references preserved · ledger frozen | Head of Evidence · Data Governance Lead | Archive manifest hash |
Where horizon-scanning output feeds narrative artefacts — and what is gated
| Output | Audience | Source Centre(s) | Counsel countersign required? | Restriction | Gating evidence |
|---|---|---|---|---|---|
| Board summary · regulatory change section | Board (internal) | Strategic Reporting · Programme Governance | Where regulator-facing only | Restricted / Internal Only | RCH-* intake list · obligation register |
| Investor narrative · regulatory moat section | Investor (redacted variant) | Strategic Reporting | Yes — every external reference | Redacted External | Counsel-locked phrasing |
| Regulator-facing engagement pack (per jurisdiction) | Regulator (counsel-bounded) | Jurisdiction Playbooks | Yes — mandatory | Counsel-locked | JP 7-step counsel workflow · step 6 Pack Lock |
| Regulator exam response binder section | Regulator (counsel-bounded) | Regulatory Escalation · Model Governance | Yes — mandatory | Restricted Use | Counsel countersign + redacted citation |
| Counterparty pilot brief · jurisdiction-specific footers | Counterparty (pilot) | Commercial Readiness · Stakeholder Rooms | Yes — per-pilot | Per-pilot tenant | Pilot-template counsel review |
| Board decision request · regulatory change item | Board (board-only) | Programme Governance | Where regulator-facing | Board Only | Decision register + counsel sign-off |
Items overdue for review or missing an owner
| Alert ID | Item | Review cadence | Last reviewed | Owner | Gap | Remediation path |
|---|---|---|---|---|---|---|
| STALE-RCH-001 | RCH-008 Incident notification timeline · counsel sweep | Monthly · per-incident | 2026-04-09 (intake) | Head of Regulatory · External Counsel | 37 days · counsel session pending | Close at 2026-05-19 counsel session |
| STALE-RCH-002 | RCH-007 Cross-border data transfer posture refresh | Quarterly | 2026-02-12 | Data Governance Lead · CISO · External Counsel | 93 days · 3 days over | Counsel review post-Entra |
| STALE-RCH-003 | RCH-010 Complaints capture flow · owner attestation | Quarterly · pre first pilot | n/a · intake 2026-04-08 | Head of Commercial | Owner not yet attested | Capture owner attestation by 2026-05-30 |
Four gates · all must be green before any change-related artefact leaves internal scope
Counsel-locked phrasing
Every regulator- or investor-facing reference to a change carries counsel-approved phrasing (CTL-010).
Pack-impact resolved
Affected packs (subset of 21) have an obligation in tracker; obligations have owners and target dates.
Evidence hashed & cross-linked
Evidence updates carry hash + freshness date; cross-Centre links updated; audit-event tag applied.
Restriction applied per audience
Per the Strategic Reporting restriction panel; internal-only / board-only / redacted-investor / regulator-locked.
Audit log of horizon-scanning events
| Timestamp (UTC) | Actor | Change / signal | Action | Evidence hash | Limitation recorded | Next step |
|---|---|---|---|---|---|---|
| 2026-05-08 09:00 | Head of Regulatory · CoS | Signal board | RCHS-SIG — 12 signals published | sha256:rchs…aa01 | "Internal horizon scanning." | Weekly sweep |
| 2026-05-09 11:14 | Head of Regulatory · External Counsel | Intake triage | RCHS-IN — 10 changes opened | sha256:rchs…aa02 | "Internal; counsel-bound." | Counsel session 2026-05-19 |
| 2026-05-10 09:22 | Head of Evidence · Head of Regulatory | Impact matrix | RCHS-IM — 21 packs × 10 changes mapped | sha256:rchs…aa03 | "Internal." | Refresh on counsel countersign |
| 2026-05-11 14:08 | External Counsel · Head of Regulatory · CEO | Interpretation workflow | RCHS-WF — 6-step workflow live | sha256:rchs…aa04 | "No regulator-facing phrasing without counsel countersign." | Lock phrasing on next session |
| 2026-05-12 09:50 | Programme Manager · Head of Evidence | Obligation tracker | RCHS-OBL — 10 obligations opened | sha256:rchs…aa05 | "Internal." | Weekly review with owners |
| 2026-05-13 11:42 | Programme Manager · External Counsel | Acceptance criteria | RCHS-ACC — 8 transitions defined | sha256:rchs…aa06 | "Internal." | Apply on next intake |
| 2026-05-14 08:18 | CoS · External Counsel · CEO | Narrative-generator posture | RCHS-NAR — 6 outputs scoped | sha256:rchs…aa07 | "No external narrative without counsel countersign." | Refresh on counsel sign-off |
| 2026-05-15 09:00 | Programme Manager | Stale / unowned sweep | RCHS-STALE — 3 alerts opened | sha256:rchs…aa08 | "Internal." | Close STALE-RCH-003 by 2026-05-30 |
| 2026-05-15 11:30 | External Counsel · CEO · Head of Evidence | Export readiness gates | RCHS-GATES — 3 of 4 gates met | sha256:rchs…aa09 | "No external artefact ships without all four gates." | Close Gate 1 post 2026-05-19 |
| 2026-05-16 07:55 | CEO · Head of Regulatory · External Counsel | Centre attestation | RCHS-ATTESTATION — monthly attestation | sha256:rchs…aa10 | "Internal; not regulatory approval." | Re-attest monthly |
What this Centre is — and is not
- Staging / simulated regulatory-change data. All signal IDs, change IDs, obligation IDs, evidence hashes, dates, and audit events shown here are seed values for an internal horizon-scanning workflow. They are not a live regulator feed, not a live counsel system, and not a live audit log.
- Internal horizon-scanning workflow only. This Centre captures BLACKSWAN's internal regulatory-change tracking posture. It is not legal advice, not regulator submission, not regulatory approval, not certification, not an audit opinion, and not authorization for external launch.
- Counsel-bound interpretation. Interpretation of any regulatory signal is performed by external counsel; internal phrasing is owner-drafted. Counsel countersign is required before any regulator-facing artefact is produced from a signal.
- Conservative perimeter posture. Platform does not place, route, or execute orders, does not hold client money, and does not give investment advice. Activity-perimeter language remains counsel-locked across all four jurisdictions.
- Engagement is hypothetical until counsel-bounded windows open. Signal cadences, intake triggers, and obligation target dates describe internal readiness cadence only. No regulator engagement is implied by display in this Centre.