← Back to ResourcesCompliance Operations

Regulatory Horizon Scanning: How UK Compliance Teams Stay Ahead of Change

Senthil Shivaa#Regulatory Horizon Scanning#Regulatory Change#Compliance Operations#FCA#PRA#UK Regulation#Regulatory Compliance

The hardest part of regulatory change is rarely finding the rule. It is knowing early enough what it means for your business.

Regulatory change rarely arrives as a surprise. Long before a new requirement starts to apply, there is usually a consultation, a policy statement, a supervisory priority or a line in a regulator’s work programme.

The problem is connecting those signals to the business.

A compliance team might read an FCA publication, notice a change from the PRA and receive an industry update. But unless those signals are captured, assessed and connected to the firm’s obligations, they remain information rather than action.

That is the purpose of regulatory horizon scanning.

From Regulatory Signals to Business Impact

Horizon scanning is often treated as simply keeping up with regulatory news. In practice, it is much more useful than that.

The process is straightforward: identify what has changed or what is likely to change, assess whether it affects the business, decide what needs to happen and give that work an owner. The important part is being able to connect those steps.

If a regulator publishes a new requirement, the firm should be able to show where it was recorded, how its impact was assessed, who was responsible for responding and where the resulting change appears in the obligations register.

Regulatory signal → assessment → decision → owner → action

Without that connection, horizon scanning can become little more than a reading diary.

What UK Compliance Teams Should Watch in 2026

There is no single source that tells a firm everything it needs to know. A useful starting point is the major regulatory work programmes, followed by the consultations, policy statements and rule changes that turn those priorities into specific requirements.

For 2026, four documents provide a useful view of the wider direction:

FCA Annual Work Programme 2026/27 — 26 March 2026
Supervisory priorities and upcoming policy work, including deferred payment credit, data returns and AI assisted authorisation.

PRA Business Plan 2026/27 — 17 April 2026
Prudential priorities including Basel 3.1, Pillar 2A, operational incident reporting and SIMEX26.

EBA Work Programme 2026 — 1 October 2025
EU banking priorities including rulebook simplification, DORA, MiCAR and the transition of AML responsibilities to AMLA.

ESMA Work Programme 2026 — 3 October 2025
EU markets priorities including the Savings and Investments Union, consolidated tape, ESG ratings and T+1 preparation.


These documents show where regulation is heading. The live publications are what tell you when that direction becomes something the business needs to respond to.

For a UK compliance team, that means monitoring FCA and PRA consultations and policy statements, Handbook and Rulebook updates, Dear CEO and portfolio letters, HM Treasury legislation and, where relevant, European developments under DORA.

The Dates Already on the Radar

Good horizon scanning turns broad regulatory priorities into dates the business can act on.

For example, the FCA’s new cryptoasset regime is scheduled to open for applications on 30 September 2026, with the application window closing on 28 February 2027 and the regime commencing on 25 October 2027.

Other dates currently worth tracking include:

1 January 2027: PRA Pillar 2A changes and Strong and Simple reporting requirements take effect.

March 2027: Operational incident and third party reporting regime is scheduled to take effect for PRA firms.

2027: The FCA’s end state safeguarding regime is expected to replace the interim CASS 15 rules, with timing still to be confirmed.

11 October 2027: UK and EU securities markets are scheduled to move to T+1 settlement.

1 January 2028: PRA market risk internal model requirements complete the Basel 3.1 sequence.

A date without an owner is a reminder. A date linked to an impact assessment, an accountable person and a clear action is part of a compliance process.

What Good Horizon Scanning Looks Like

The technology can vary. The discipline should not.

A smaller team may use a shared tracker and inbox. A larger organisation may use dedicated regulatory intelligence software. Either can work if the process is clearly owned.

At a minimum, a team should be able to demonstrate four things.

The sources are defined. Everyone knows what is being monitored and how often.

Relevant signals are recorded. The team can show when a publication was reviewed and what was identified.

Impact is assessed. There is a documented decision on whether the change affects the firm, including why something was considered out of scope.

The obligations register moves. Where a regulatory change is relevant, the resulting obligation, control or action is updated and linked back to the original source.

That last step is often the difference between monitoring regulation and managing it.

If the scanning log never changes the obligations register, the firm may be collecting regulatory information without actually incorporating it into its compliance framework.

The Process Should Leave Evidence

A strong process should leave a trail that someone else can follow.

If a reviewer asks, “You saw this change. What did you do with it?”, the answer should not depend on finding the person who happened to read the original email.

That trail demonstrates not only that the firm monitors regulatory change, but that it has a controlled way of responding to it.

Where Technology Fits

This is where regulatory technology can make the process more manageable.

A shared spreadsheet may be enough for a small team, but monitoring becomes harder as the number of regulators, jurisdictions and regulatory changes grows. External intelligence services can help with the reading, but a feed alone does not explain what a change means for a particular business.

Technology can help bring those steps together: monitoring the sources, recording relevant changes, supporting impact assessment and maintaining the connection to the obligations register.

This is the approach behind Comply2Reg’s RegPulse, which monitors FCA, PRA, EBA, ESMA and Thai regulatory sources with impact assessment built into the process.

The underlying principle, however, does not depend on the tool.

The real test is simple: can you trace a regulatory change from the regulator’s publication to the decision your business made about it?

Staying Ahead Does Not Mean Predicting the Future

Horizon scanning is sometimes made to sound like an exercise in predicting what regulators will do next.

It is not.

Compliance teams do not need to predict the future perfectly. They need to recognise credible signals early enough to understand them, assess their relevance and act before they become urgent.

That means having a defined set of sources, reviewing them consistently, recording what matters and making sure relevant changes reach the people and processes responsible for dealing with them.

The goal is not to read more regulatory updates.

It is to be less surprised by what comes next.

#Regulatory Horizon Scanning#Regulatory Change#Compliance Operations#FCA#PRA#UK Regulation#Regulatory Compliance