Expertise Technical assistanceProject managementCustom solutions Industries BankingInsuranceFinance Approach Commitments Insights About Join Pronaxis
Contact us Français

The role of the PMO in a regulatory programme

Governance, planning, risk, reporting and the link between business and IT: what a PMO brings to a regulatory programme in banking or insurance.

Pronaxis9 October 20265 min read

A regulatory programme has particular features. The deadline is set by law and cannot be negotiated. The scope spans several functions at once: compliance, risk, business lines, finance, IT. Requirements are sometimes clarified along the way, through technical standards, guidelines or answers from the authorities.

In this setting, the programme management office, or PMO, plays a central role. It organises the conditions in which those responsible can decide on time and with full knowledge of the facts.

Setting up governance

Governance defines who decides what, how often and on what basis. The PMO proposes it, gets it approved and makes it work.

Committees

A regulatory programme usually relies on three levels:

  • a steering committee, with the sponsors and the functions involved, which settles structural issues;
  • a programme or follow-up committee, which consolidates progress across workstreams and prepares decisions;
  • workstream meetings, at operational level.

The PMO prepares agendas, consolidates the material presented, writes minutes and tracks decisions. A decision that is not written down, dated and assigned is unlikely to be carried out.

Roles

Each workstream has a named owner on the business side and on the technical side. The PMO maintains this responsibility matrix and updates it as the programme evolves.

Building and holding the plan

The plan for a regulatory programme is built backwards from the deadline. Intermediate milestones follow from it: specifications, development, acceptance testing, end-to-end testing, go-live, stabilisation.

The PMO performs three functions on the plan:

  • consolidation: it assembles the workstream plans and checks that they are consistent;
  • dependencies: it identifies links between workstreams, especially where one workstream’s deliverable is needed before another can start;
  • critical path: it identifies the tasks where any delay moves the deadline, and focuses attention on them.

A buffer should be planned before the regulatory deadline. It absorbs the unexpected during acceptance testing and go-live.

Managing risk

In a regulatory programme, the main risk is known: failing to comply by the set date. The PMO breaks it down into concrete, tracked risks.

The risk register

Each risk is described, assessed for likelihood and impact, assigned an owner and linked to an action. The register is reviewed at every programme committee.

Common risks in this type of programme relate to interpretation of the texts, availability of business experts, data quality, dependence on software vendors or providers, and testing capacity.

Escalation

A risk that cannot be handled at workstream level goes up to the relevant committee. The PMO sets the escalation rules and makes sure they are followed. An issue brought to the steering committee early leaves more options than one discovered a few weeks before the deadline.

Producing useful reporting

Reporting exists to inform decisions. It should be short, regular and honest.

A good programme dashboard answers a few questions:

  • Where does each workstream stand against the plan?
  • Which milestones have been met, and which are at risk?
  • Which risks have changed since the last committee?
  • Which decisions are needed, from whom and by when?

Colour-coded indicators are useful, provided they are defined objectively. A workstream reported green until the day before a missed milestone reflects a reporting failure.

Linking business and IT

This is often the PMO’s most decisive function in a regulatory programme.

Compliance and business teams read the text and derive requirements from it. Technical teams translate those requirements into changes to the information system. Between the two, gaps in interpretation appear easily: a legal concept understood differently, a data item defined differently across applications, a special case overlooked.

The PMO helps close these gaps:

  • by organising joint workshops for business and technical teams;
  • by ensuring traceability between the requirements of the text, the specifications and the tests;
  • by maintaining a log of interpretation questions, with validated answers and their source;
  • by checking that acceptance testing covers the regulatory requirements as well as the technical specifications.

This traceability has value beyond the project. In the event of an inspection or audit, it shows how each requirement was addressed.

The PMO profile

An effective PMO on a regulatory programme combines several qualities: rigour in follow-up, the ability to synthesise, ease with senior committees, and enough understanding of the business and the text to ask the right questions. Their role is to know whom to ask each question and to check that the answer is applied.

In our engagements, we recommend having the PMO in place from the scoping phase. It is easier to build governance and traceability at the start than to reconstruct them halfway through.

In short

The PMO on a regulatory programme organises governance, holds the plan, tracks risks, produces reliable reporting and links the requirements of the text to what is delivered technically. Its work is measured by one thing: decisions taken on time, and compliance that can be demonstrated at the deadline.

All insights Français

A project, a team to reinforce, a question?

Tell us what you need. Our management team will reply.