Skip to content
Seqlense DOC Seqlense Web3 Monitoring Seqlense Notes Audit & Advisory Investigation Crypto OSINT Investigation Training & Advisory Seqlense Immo Pricing Academy Blog Partners Supported Chains Contact My Seqlense Get Started
Back to blog

Mapping a new regulation to your internal controls

A repeatable method that goes from legal text to a named control owner.

A new regulation lands as a PDF, a press release, or a link from a colleague. Weeks later it needs to be a set of controls that someone actually owns and operates. The gap between those two states is where most compliance programmes lose time and traceability. This is a repeatable method to close that gap: from raw legal text to a named control owner, with an audit trail you can defend.


Why a method beats a scramble

Every significant text triggers the same reflex: read it, panic a little, and start a spreadsheet. The problem is not effort, it is repeatability. When each new regulation is mapped in its own ad hoc way, you cannot compare coverage across texts, you cannot prove why a control exists, and you cannot answer the auditor's simplest question: who is responsible for this obligation and how do we evidence it?

A method fixes that by forcing the same steps in the same order every time. It also makes the work delegable, because a junior analyst following the steps produces output a reviewer can trust.


The six steps


1. Scope and classify the text

Before reading line by line, decide what the text is and whether it binds you. Is it a regulation, a guideline, a consultation, an opinion, or a Q and A? A consultation signals a direction of travel, not an obligation. Binding guidelines from a supervisor carry a comply or explain expectation. Record the source, the document type, the effective date, and the transition period. Half of scope errors come from treating a soft-law text as hard law, or the reverse.


2. Decompose into atomic obligations

Read the text and cut it into the smallest units that each express a single requirement. One article often hides several obligations. A good atomic obligation is a sentence with a verb of duty: "shall notify", "must retain", "is prohibited from". Give each one a stable identifier, for example REG-14.2-a, so you can reference it everywhere downstream. Keep a short verbatim quote next to your paraphrase so the reviewer can check your reading without reopening the source.


3. Assess applicability and materiality

Not every obligation applies to your firm, and not every applicable one carries the same weight. For each atomic obligation, decide: does it apply given our licences, activities, and client base? If yes, how material is the failure risk (regulatory, financial, reputational)? Mark the ones that do not apply and, crucially, record why. "Not applicable, we hold no payment licence" is a defensible answer. A blank cell is not.


4. Map each obligation to a control

Now the core move: connect every applicable obligation to a control. A control is the concrete thing you do to satisfy the requirement. Reuse before you build. Most obligations map to a control you already run, sometimes with a tweak. For each mapping, record the control state:

  • Covered: an existing control already satisfies the obligation.
  • Partial: a control exists but needs adjustment to close the gap.
  • Missing: no control exists and one must be created.

The output of this step is a gap list, which is really your remediation backlog.


5. Assign a named owner

Every control needs one accountable human, not a team and not a mailbox. The owner is answerable for the control operating as designed. Distinguish the control owner (accountable) from the operator (who runs it day to day) where they differ. If you cannot name an owner, the control does not really exist yet. This step is where mapping becomes governance.


6. Define evidence and cadence

A control you cannot evidence is a control you cannot prove in an audit. For each control, define the evidence it produces (a log, a report, a sign-off, a screenshot) and the frequency at which it operates and is reviewed. Tie the evidence back to the atomic obligation identifier so the chain runs cleanly from legal text to proof.


The artefact this produces

The whole method converges on one living register. A single row carries the full lineage:

Field Example
Obligation ID REG-14.2-a
Source and type Guidance, effective 2026-01
Applicability Applies
Control Onboarding sanctions screening
State Partial
Owner Head of Financial Crime
Evidence and cadence Screening log, daily

When a text changes, you re-run the affected rows instead of starting over. When an auditor asks about an obligation, you follow one row from the words in the regulation to the person who owns the response.


Keeping the input clean

The method only works if you catch the texts that matter and read them for what they are. That upstream watch is easy to underrate. Missing a consultation means missing your window to prepare; misreading an opinion as binding means burning effort on controls no one required.

This is where structured regulatory watch earns its place. Seqlense Doc tracks publications across roughly 85 European regulators and tags each by document type (doctype:guidance, doctype:consultation, doctype:regulation and more), so step one of the method starts from a clean, classified feed rather than a scramble through supervisor websites. Filters like source: and lang: narrow the stream to the authorities and languages that bind you. The mapping work is still yours to do, but you begin from the right text, correctly labelled, with the effective date already in view.

Adopt the six steps, keep one register, and name an owner for every control. The next regulation stops being a fire drill and becomes a process you have run before.

Related articles

Reading an on-chain money trail: a beginner's guide

How funds are traced across hops, clusters and services on a public ledger.

AMF, BaFin, CSSF and FCA in one view

Running a coherent cross-border watch across four major regulators.