Articles
0
MIN READ

The governance layer: turning a law firm's risk policy and processes into action

Share

Author

Julia Salasky
Julia Salasky
,
CEO

Table of Contents

Find out how we can help you onboard clients faster
Book a demo

The gap between having a risk policy and being confident it’s being enforced is a yawning one. MLROs, COLPs and heads of risk have to create a culture of compliance, do file audits and be a point of escalation for queries about what the firm’s policy means in any given situation. 

Legl has introduced a Governance Layer to bridge that gap. The Governance Layer enables compliance leaders to take their policy – the rules, procedures and guidelines about what to do and what is needed in any given situation – sometimes a flow chart, or knowledge within people’s heads – and make it a live system. Think of it as taking your risk policy and making it operate automatically, across people and processes, with clear audit trails.

How a risk policy is enforced today

Asking individuals at a firm to internalise a firm’s risk policy, and take consistent decisions off the back of it, is one of the hardest tasks of a risk leader.  

Risk policies are generally high level, or very nuanced. In practice, any policy must be enforced, but rules and procedures are generally absorbed by the people who do them over time. A reviewer with eight years at the firm might apply a specific approach without thinking, and the partner who helped write the policy might remember a previous way of working. The new joiner in another office might apply whatever they were told that day. All three work from the same document and do different things with it.

Risk policies are often enforced from memory, and memory spreads unevenly across forty people or two hundred, and across two offices or six. So the decisions can vary with whoever applies it.

Compliance software has traditionally not fixed this

Firms have bought a lot of compliance technology over the past decade, and most of it does its job well. It runs the identity check, screens the name against watchlists and collects the source of funds document for the matter.

These tools execute tasks. Nothing in them checks whether the tasks that ran were the ones your policy required for this client in this situation. Each tool applies its defaults, and the defaults are the same for every firm that uses it. The part of your policy that is yours, the lines you draw where another firm would draw them somewhere else, stays in the PDF.

So a firm can have excellent onboarding tools and still fail the question the accountable person cares about most: did we apply our policy the same way to everyone?

Two things that make a governance layer urgent

The challenge of applying a risk policy consistently has always been a challenge, but there are three recent developments that make it even more time-sensitive:

Accountability now sits with a named person. The SRA has discussed separating COLP and COFA roles from the people who run larger firms, and AML supervision is moving to the FCA, which tests whether controls work in practice. So the person accountable for the policy is less likely to be in the room where decisions are made, and more likely to be asked to prove what happened there. Personal liability means that person needs evidence more than efficiency.

Scaling a firm without adding headcount. Many firms are growing quickly, and need to be able to address client risk across more clients with fewer headcount to support that growth. Creating consistency of rules and procedures improves the fee earner and central teams’ workload and speeds file opening times.

From policy to control 

For the clients your firm took on last month, what are you most worried about in terms of decisions and actions taken by your team? For clients who required escalations, or for clients where additional documentation may have been required pursuant to your policy, how confident are you that the right approach was taken?  

A compliance culture is thousands of small decisions made the same way by different people when nobody is watching. A governance layer makes that culture observable, which means you can prove it.

What a governance layer is

A governance layer looks across your policy – as well as working collaboratively to ensure you extract “implicit rules” from your team’s working practices, flowcharts and so on  – and turns this into an auditable, consistent approach of rules and procedures that are automated within your compliance tool. A rule is a fast, deterministic process: flag it, clear it, route it, or ask the client to fix something.

When clients provide information that doesn’t match your risk policy (for example, if your policy rejects newly issued IDs for clients in a high risk third party country), it remediates immediately with the client directly, so that your team only sees results in line with your precise policy. If your policy requires certain matters or issues to be escalated, that happens automatically in line with your policy. 

And it audits everything, creating a clear trail of where decisions were automated or a client was re-engaged to provide different information. 

The decision stays with a person. Operationalising rules means that what the team sees is precisely the information in accordance with your risk policy, making it faster, more streamlined and more consistent. 

In other words, the firm can automatically apply its own policy to every client, and its people spend their time on judgment.

Where Legl stands

Legl has built the governance layer into the platform – enabling firms to marry up their actual operational approach to their risk policy. 

From understanding your risk policy to enforcing it behind the scenes, a governance layer enables firms to drive consistency and a culture of compliance.  

It significantly reduces manual work and reduces human error. It is utterly personalised to the firm, to the risk appetite and the processes, policies and procedures that are important to driving top in class compliance, while reducing time to opening files. 

Get in touch with the Legl team to learn more about implementing a governance layer at your firm today.