In the meantime, more is being asked of compliance professionals. In an era of disruption, evolving market dynamics and digital challengers, compliance teams are under pressure to confirm that new services, delivered through new channels, meet regulatory expectations. With pressure to get the ‘minimum viable product’ into the market place at break-neck pace – something has to give!
And it is. A change in mindset is gradually occurring that is bringing the traditional ‘first lines’ and ‘second lines’ closer together:

John Clinton
1. Businesses are starting to realise that conduct risk will never be properly managed until the first line understands and embraces the notion that it is their responsibility to design and sell products that meet their customer needs – and not a second line responsibility to constrain their innovation. This is a first step in a cultural change, shifting away from a ‘compliance’ mentality to a ‘conduct’ mentality;
2. Equally, the second line is starting to engage in a different way with their first line colleagues – adopting a more collaborative and advisory approach and eschewing the traditional ‘waterfall’ model of engaging, for example, throughout product design iteration, launch and product evolution – rather than as a final ‘gate keeper’.
EY is supporting its clients in making this transition in a number of different ways. The first is the adoption of a ‘trust by design’ mentality, whereby firms adopt a customer-oriented focus on trust from top to bottom; from organisational purpose, strategy and governance through product design and delivery. With this mindset, the lines of defence, and particularly risk and compliance can increasingly become a trusted advisor to the business rather than a perceived hinderance to it.
The second is to assist our client’s risk functions to be digitally led to strengthen trust and increase business performance. Successful organisations are challenging themselves with the right questions to differentiate with trust:
Adaptive governance: How is our strategy and operating model designed to create the foundation for trust?
Customer journey: How do we design and protect customer trust?
Intelligent decisions: How are we empowered to make strategic decisions?
Data and technology ecosystem: How are we harnessing the power of data and technology to increase performance?
Cybersecurity and business resilience: Will our organisation sustain trust through the biggest tests?
We are helping clients in a number of ways to engage with and meet these challenges. For example:
• We are assisting Boards and C-Suite executives who are asking for better risk and cyber intelligence aligned to their business imperatives;
• We are assisting risk and compliance functions to re-evaluate their governance structure and to harness technology to better manage risk throughout the organisation;
• We are helping clients so design blueprints and roadmaps to protect their future through better risk data intelligence and continuous monitoring;
• We are supporting financial service clients who are developing and deploying product and service management programs with digitised controls; and
• We are supporting clients in the journey to embrace emerging technologies such as AI, RPA, drones, and advanced analytics to collect risk intelligence and monitor controls to make better decisions.
In the transformative age, agility is a necessity rather than a luxury. As with all facets of the financial service firm, compliance must embrace this challenge. Part of the journey involves engaging with and utilising emerging technologies to enhance efficiency and effectiveness. In parallel, compliance and risk functions must continue to support their colleagues in putting customer trust at the centre of everything they do.