Skip to main content
Category: Regulatory Management

Regulatory Examination

Also known as: Regulatory Exam, Supervisory Examination
Simply put

A regulatory examination is a formal review conducted by a supervisory authority to check whether an organization is following applicable laws, regulations, and governance requirements. Examiners may review records, processes, and controls, sometimes through on-site visits, to identify areas of non-compliance. The scope, frequency, and legal basis of such examinations depend on the regulator, the sector, and the type of entity involved.

Formal definition

A regulatory examination is a supervisory review carried out by a government agency or self-regulatory organization to assess a registrant's or regulated entity's compliance with applicable statutes, regulations, rules, and governance obligations. Depending on the regulator's authority and program, examinations may be conducted on-site or remotely and can encompass review of books and records, testing of compliance controls, and evaluation of governance and risk management practices. Examinations are exercises of supervisory authority distinct from an organization's own internal compliance monitoring or independent assurance functions; their specific scope, methodology, and legal standing vary by jurisdiction, regulator, sector, and entity type. This entry is educational and not legal, audit, or compliance advice; the term should not be confused with individual qualification examinations, which test a person's knowledge for registration or licensing purposes rather than reviewing an organization's compliance.

Why it matters

Regulatory examinations are one of the principal mechanisms through which supervisory authorities verify that regulated entities are meeting their legal and regulatory obligations. Unlike an organization's own internal compliance monitoring or independent assurance activities, an examination is an exercise of external supervisory authority, the findings can carry significant consequences, potentially including remediation requirements, heightened supervisory attention, or, depending on the regulator and the facts, referral for enforcement. Because examinations often involve review of books and records and testing of compliance controls, they effectively test whether an entity's control framework is not only well-designed on paper but operating effectively in practice.

For boards and senior management, examinations matter because they surface how the organization's governance, risk management, and compliance practices appear to an external supervisor. Gaps identified during an examination can indicate weaknesses in control design or operating effectiveness that the entity's own assurance functions did not fully capture. The scope, frequency, and legal basis of examinations vary by jurisdiction, sector, and entity type, so the significance of any given examination depends heavily on the specific regulator's authority and program and on the facts of the entity being reviewed.

Because the consequences and expectations differ so widely across regulators and sectors, organizations generally treat examination readiness as an ongoing discipline rather than a one-time exercise. This entry is educational and not legal, audit, or compliance advice; the practical implications of any examination will turn on the applicable rules and the entity's own circumstances.

Who it's relevant to

Chief Compliance Officers
Compliance officers typically own the day-to-day interaction with examiners, coordinating the production of records and responses and mapping examination expectations to the organization's compliance program. Examinations test whether the compliance controls they maintain are operating effectively, not merely designed adequately.
General Counsel and Legal
Legal functions generally advise on the entity's obligations, the scope of the regulator's authority, and how findings should be interpreted and addressed. Because the legal standing and consequences of examinations vary by jurisdiction and regulator, counsel helps the organization understand what a given examination can and cannot require.
Boards and Board Committees
The board and its relevant committees exercise oversight of how management responds to examinations and remediates identified gaps. Their role is generally supervisory rather than operational, overseeing whether management's response is adequate rather than conducting the response themselves.
Internal Audit and Assurance Functions
Independent assurance functions provide the organization its own view of control effectiveness, separate from the external supervisory review. Examination findings can highlight where internal assurance did not fully capture a weakness, informing future audit planning and scope.
Risk Management
Risk functions have an interest in how examinations evaluate governance and risk management practices and in whether examination outcomes indicate residual risk beyond the organization's stated appetite. Findings can feed back into how the entity assesses and monitors its control environment.

Inside Regulatory Examination

Examination Scope and Mandate
The defined boundaries of the review, typically set by the supervising regulator based on its statutory authority over a particular entity type or activity. Scope varies by jurisdiction, sector, and the regulator's remit, and may be routine, thematic, or triggered by specific concerns.
Document and Information Requests
Formal requests for policies, procedures, records, board and committee minutes, risk assessments, and management information. Responsibility for producing and validating these materials generally sits with management and the relevant control functions rather than the board.
On-Site and Off-Site Fieldwork
The examiners' testing and observation activities, which may include interviews, transaction sampling, and evaluation of both control design and operating effectiveness. These are distinct: a well-designed control can still fail to operate effectively in practice.
Findings and Deficiency Ratings
The examiner's conclusions, often categorized by severity. Findings typically distinguish between weaknesses in control design and gaps in operating effectiveness, though rating scales and terminology vary by regulator and jurisdiction.
Remediation Expectations and Follow-Up
Required corrective actions with timelines, and the mechanism by which the regulator tracks closure. Accountability for remediation generally rests with management, while the board or a relevant committee typically holds oversight responsibility for monitoring progress.
Supervisory Communication
The formal outputs of the examination, which may include an exit meeting, a written report or letter, and any supervisory actions. The nature and enforceability of these outputs depend on the regulator's legal powers and the applicable regime.

Common questions

Answers to the questions practitioners most commonly ask about Regulatory Examination.

Is a regulatory examination the same as an internal audit?
No. Although both involve reviewing an organization's activities against a set of expectations, they are distinct in ownership and purpose. A regulatory examination is generally conducted by an external supervisory authority exercising its statutory powers over a regulated entity, and its findings can carry supervisory or enforcement consequences. Internal audit is an assurance function within the organization, typically reporting to the audit committee, that provides independent evaluation of governance, risk, and control processes to inform management and the board. The two may examine overlapping subject matter, but the examiner acts on behalf of the regulator, not the entity. Whether a particular activity falls to one or the other depends on jurisdiction, sector, and the applicable supervisory regime.
Does passing a regulatory examination mean the organization's compliance program is effective?
Not necessarily. An examination generally assesses the entity against specific supervisory expectations at a point in time and within a defined scope, so it does not amount to a comprehensive certification that a compliance program is effective in all respects. Examiners typically sample activities and focus on particular risk areas, and the absence of findings does not warrant the conclusion that no deficiencies exist. Assessing the design and operating effectiveness of a compliance program is an ongoing responsibility of management and the relevant assurance functions, distinct from the periodic view a regulator forms during an examination. These entries are educational and not legal, audit, or compliance advice.
How should an organization prepare when it receives notice of a regulatory examination?
Preparation practices vary by jurisdiction, sector, and entity type, but organizations generally establish a coordinated response, often led by the compliance function with support from legal, and confirm reporting lines to senior management and, where appropriate, the board or a relevant committee. Common steps typically include reviewing the examination scope and any information requests, identifying document custodians, and assessing the completeness and accuracy of records responsive to the request. Whether particular materials are subject to legal privilege or specific handling requirements depends on the facts and applicable law and generally warrants professional judgment. This is a general description, not a compliance checklist for any specific regime.
Who within the organization should own the relationship with the examiners?
Accountability arrangements differ across organizations and regimes, but a single coordinating point of contact, frequently within the compliance function, is generally used to manage communications, track requests, and maintain a consistent record of interactions. This coordination role is distinct from the board's oversight responsibility and from management's operational duty to run the business and remediate issues. The board or a designated committee typically retains oversight of how significant examination matters are handled, without assuming day-to-day operational tasks. The precise allocation depends on the entity's governance structure and any supervisory expectations that apply.
How are examination findings typically tracked and remediated?
Organizations generally record findings, categorize them by significance, assign clear ownership, and set target dates, often within an issue-management or remediation-tracking process. Management typically owns the design and implementation of corrective actions, while an assurance function such as internal audit may separately evaluate whether remediation has been completed and is operating as intended; combining those roles can undermine independence. It is generally useful to distinguish addressing a control's design weakness from confirming its operating effectiveness once remediated, as these are separate questions. Reporting on remediation status to senior management and the relevant board committee is a common practice. Specific timelines and expectations depend on the regulator and the nature of the findings.
What records support an effective response to a regulatory examination?
Practices vary, but organizations generally maintain documentation demonstrating how policies, procedures, and controls operate, along with evidence of their application, such as approvals, monitoring outputs, and records of decisions. Contemporaneous and well-organized records typically make it easier to respond to information requests accurately and within any deadlines set. What must be retained, and for how long, depends on applicable recordkeeping requirements, which differ by jurisdiction and sector. Organizations should also be mindful that the way information is prepared and shared can raise legal considerations, so involving legal counsel where questions of privilege or disclosure arise is generally advisable. These entries are educational and not legal advice.

Common misconceptions

A regulatory examination is the same as an internal or external audit.
An examination is conducted by a supervisory authority exercising its own mandate and generally focuses on compliance with binding law and supervisory expectations. Internal audit is an independent assurance function within the entity, and external audit typically addresses financial statements. The three serve different purposes and answer to different stakeholders, and one does not substitute for the others.
The board is responsible for producing examination materials and directly responding to examiner requests.
In many governance models, management and the relevant control functions own the operational task of assembling records, responding to requests, and implementing remediation. The board and its committees generally hold an oversight role, monitoring the process and the adequacy of the response rather than performing the day-to-day work.
A clean examination result means the entity's risks are fully controlled.
An examination typically assesses compliance and controls within a defined scope at a point in time. It does not eliminate residual risk, nor does it guarantee that controls will continue to operate effectively. Findings, or their absence, reflect the examiner's sampling and judgment within the mandate, not a comprehensive assurance over all risks.

Best practices

Maintain examination-ready documentation on an ongoing basis, ensuring policies, risk assessments, and control evidence are current, version-controlled, and readily retrievable rather than assembled reactively.
Clarify roles in advance so that management and control functions own the response and evidence production while the board or relevant committee is positioned to exercise oversight and monitor progress.
Designate a coordinated point of contact for regulator communications to ensure requests are logged, responses are consistent and accurate, and no representations are made beyond what the underlying records support.
Track findings by type, distinguishing control design weaknesses from operating effectiveness gaps, and assign clear remediation owners with realistic timelines and defined closure criteria.
Report examination status and remediation progress to the appropriate board committee so oversight is documented and accountability is preserved.
Treat examination outcomes as inputs to the broader risk and compliance program, feeding lessons learned back into control design and monitoring, while recognizing the exercise reflects a point-in-time review within a defined scope.