The gap between detecting a rule change and understanding it

A circular lands. Someone catches it. Job done - or so it looks.
But detecting a change and understanding it are not the same thing. And the gap between the two is where most of the real risk sits.
What "Detected" actually means
Most compliance and operational teams have some version of a detection process. A person, or a tool, monitors exchange notices and regulatory circulars. Maybe both have their own process. When something new comes in, it gets logged. Flagged. Maybe forwarded to the right desk.
That's detection. It answers one question: did something change?
It does not answer the questions that actually matter:
What does this change apply to - which products, which venues, which parts of the business?
When does it take effect, and is that date the same across every jurisdiction it touches?
Does it conflict with, duplicate, or quietly override something already in place?
Who needs to act on it, and by when?
Detection tells you a document exists. Understanding tells you what to do about it. Most firms are well resourced for the first and thin on the second.
Where the gap shows up
Two circulars, nine days apart. Eurex Clearing 058/2026, Introduction of updated Public Key Infrastructure. ECC clearing circular 63/2026, Introduction of updated Public Key Infrastructure. Both affect FIXML connectivity. The ECC circular instructs members to create new certificates through the Deutsche Börse certificate generator, in the DBAG member section, for the C7 FIXML technical account.
Two clearing houses in the same group. Two reference numbers. One piece of work, or two.
Neither circular answers that. Each is written as though it is the only one, which is how circulars are written, because the issuing entity has no view of what else landed in your inbox that fortnight.
So detection fires twice, correctly. Then someone has to decide whether the second alert is a duplicate of the first. If coverage is organised entity by entity, which most coverage is, the two arrive with different owners and neither sees the other. If one person holds both, they are making a call about shared certificate infrastructure between two legal entities on the basis of a matching title. The circulars give them nothing better to go on.
Get it wrong in one direction and the work is done twice. Get it wrong in the other and one connection is running on a certificate that will not be renewed, and you find out on the cutover date.
Throughput does not help with this. A firm processing a thousand changes a month faces the same question as a firm processing fifty: are these two alerts one job. That is not a detection problem. Detection did exactly what it was built to do. It is a question about whether the inputs are correctly related to each other, and nothing in the monitoring layer is looking at the relationship.
The cost of stopping at detection
Firms that stop at detection tend to find out the gap exists the expensive way.
A change gets logged, sits in a queue, and gets actioned when someone eventually has time to research what it means. If that research doesn't happen before the effective date, the firm is non-compliant not because nobody saw the change, but because seeing it and understanding it were treated as the same step.
And when a regulator or an internal audit later asks how a decision was reached - why this change was actioned this way, on this date, based on what - "we saw the circular" isn't an answer. There's no evidence trail from detection to decision, because understanding was never captured as its own step in the process.
That's the exposure. Not missed circulars - most firms are reasonably good at catching those. Missed implications, sitting downstream of changes everyone technically saw.
Closing the gap
Closing this gap doesn't mean hiring more people to read faster. It means building a step between detection and action that most processes currently skip: research that's fast enough to happen before the deadline, and evidenced enough to hold up when someone asks how you got there.
That's a different capability than monitoring. Monitoring watches for change. Research answers what the change means, with a source behind the answer - not a best guess made under time pressure.
We're exploring exactly this with Sigma AI, in a live session on 10 November - what it actually looks like to close the gap between detecting a rule change and understanding it, in real time, across multiple rulebooks at once. [More details soon.]



Comments