All articles
Operating modelTransformationGovernance17 August 20269 min read

How to run a compliance operations redesign

Redesigning a live compliance division is open-heart surgery on a running patient. Here is how I did it across six licences while the parent company was listed on the NYSE.

New to the topic?What is regulatory compliance?The plain-English foundation: what compliance is, what the function does day to day, and how it works across multiple licences.

At GM Gaming / SuperGroup I redesigned the compliance operations division covering six licences while the group was listed on the New York Stock Exchange. Nothing about that context is forgiving: obligations do not pause, reporting cycles are fixed, and a public parent means every control has to be explainable to auditors as well as regulators. A redesign under those conditions is a sequencing problem before it is a design problem.

Step 1 — Baseline honestly, in numbers

Start with an unflattering picture. Every process, its true volume, its actual cycle time, who owns it, which system holds the evidence, and which obligation it satisfies. Not the documented version — the version that happens. Half of what you find will be undocumented workarounds, and those workarounds are your best source of requirements because someone invented them under real pressure.

Step 2 — Map controls to obligations, then delete

Build a matrix of obligation against control. Two things fall out immediately: obligations with no control, which are your risk register for the next quarter, and controls satisfying no obligation, which are pure cost. In every redesign I have run, the second list has been longer than anyone expected. Cutting it funds the rest of the programme and buys goodwill from the teams doing the work.

Every control you delete is capacity you did not have to hire. Start there — it pays for the whole programme.

Step 3 — Design one operating model, six annexes

The target state is a single operating model with per-licence annexes for genuine local differences. One customer risk model with market parameters. One case management flow with market-specific thresholds. One evidence repository organised by control. One deadline calendar showing every market at once. Consistency is not aesthetic here: it is what lets one QA function cover six licences instead of six QA functions covering one each.

Step 4 — Migrate market by market, never all at once

  1. 1.Pick a mid-complexity market first, never the largest and never the easiest.
  2. 2.Run old and new in parallel for one full reporting cycle.
  3. 3.Compare outputs. Every difference is either a bug or an undocumented requirement.
  4. 4.Freeze the pattern, then repeat it. Each subsequent market should be faster than the last.

Step 5 — Keep the audit trail intact through the change

This is where redesigns go wrong under a listed parent. You must be able to show, at any point during migration, which control was operating for which market on which date, and where the evidence lives. Version every policy with effective dates, keep the retired process documented rather than deleted, and log every migration cutover. An auditor's worst question is 'what was running in March?' — and the only good answer is a document you wrote in March.

Step 6 — Bring the business with you

A redesign that only compliance understands will be routed around within a quarter. Commercial, product, payments, customer support and marketing all touch controls. Give each of them one named contact, one clear change in what they experience, and a visible improvement — usually faster decisions on their customers. Compliance earns its authority by being useful, not by being right.

Step 7 — Lock in with QA, not with policy

The redesign is finished when an independent quality-assurance loop samples decisions across every market against the same standard and reports to the board. Policy documents drift the moment attention moves on. A sampling loop with published results is the only mechanism I have found that holds a new operating model in place.

Timeline reality

  • Weeks 1–6: baseline, obligation-to-control matrix, deletion list.
  • Weeks 6–12: target operating model and first-market design.
  • Quarter 2: first market parallel run and cutover.
  • Quarters 3–4: remaining markets at increasing speed.
  • Continuous: QA sampling, board reporting, annex maintenance.

Frequently asked

How do you redesign compliance operations without disrupting the business?

Migrate one market at a time, run old and new processes in parallel for a full reporting cycle, and reconcile every difference before cutover. Never attempt a single big-bang switch across all licences.

What changes when the parent company is publicly listed?

Evidence and auditability become as important as the control itself. Every policy needs effective dates, every cutover needs a log, and you must always be able to show which control was operating in which market on any given date.

How do you make a compliance redesign stick?

With an independent quality-assurance sampling loop that reports to the board. Policy documents drift once attention moves elsewhere; published sampling results do not.

Building or scaling a compliance function?

I have done this from zero three times, across multiple licences and a NYSE-listed parent. Happy to compare notes.

Keep reading