GRC Careers: AI Governance, Risk and Compliance JobsConnecting Talent and Trust. Post a Job Log in

HomeCybersecurity & GRC Career GuidesRegulatory Change Management Skills

Regulatory Change Management Skills

Get new GRC career guides by email. We publish most weeks. No spam, and we never sell or share your address with anyone.

Regulatory Change Management Skills illustration

Regulatory change management is the work of noticing that a rule has changed, working out whether it applies to you, and getting something altered before the deadline rather than after it. Most organizations discover they are bad at this the same way: an auditor asks how they knew about a requirement, and the honest answer is that somebody happened to read an article.

Horizon scanning is a process, not an inbox

Reading law firm newsletters is not horizon scanning, because you are receiving whatever those firms decided to write about. A real process starts from a defined universe: which regulators can bind us, in which jurisdictions, for which products.

From there you monitor sources directly. The Federal Register for US rulemaking. The Official Journal of the European Union for anything EU. Your sector supervisor's own publications. Standards bodies for the frameworks you certify against. Newsletters are a useful supplement and a poor foundation, because they arrive after the fact and are selected by someone else's interests.

Applicability is where the judgment lives

Most published changes do not apply to you, and the ability to say so quickly and defensibly is the skill that keeps a program from drowning.

The questions are ordinary: does this cover our entity type, our jurisdiction, our data, our products? Is there a threshold we sit below? Is there an exemption? Write the answer down even when the answer is no, because the record of having considered it is what protects you when someone asks two years later.

The change that matters most is often not the new law at all. It is a supervisor's guidance reinterpreting an existing one, which creates a new expectation without a single word of legislation moving.

Turning a change into work

A regulatory change lands on your desk as prose and has to leave as tasks. Which policies need editing. Which controls need redesign. Which systems need building. Who is accountable for each. When it has to be done, working backwards from the effective date rather than forwards from today.

Backward planning is what separates programs that meet deadlines from programs that discover in the final month that a system change was needed and engineering is fully booked.

The EU AI Act as a worked example

It is the clearest current illustration of why this discipline matters, because the timeline has both fixed points and moving ones.

The prohibitions and the AI literacy duty applied from 2 February 2025. Obligations for general-purpose AI model providers applied from 2 August 2025. General application, including the Article 50 transparency duties, arrives on 2 August 2026. Then the Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July 2026 and pushed the heaviest high-risk obligations back: Annex III stand-alone systems to 2 December 2027, and AI embedded in Annex I regulated products to 2 August 2028.

A team that stopped tracking after the original text was published has the wrong dates in its plan today. That is precisely the failure this function exists to prevent, and it is a good answer to give when someone asks why the role matters.

Evidence that the process ran

Keep a log. What was identified, when, from which source, the applicability decision and its reasoning, what was changed, and who approved it. Auditors increasingly test the change process itself rather than only the resulting controls, and a log is the only thing that demonstrates it operated.

Where to go next

Frequently Asked Questions

What is regulatory change management?

The process of identifying regulatory and supervisory changes, deciding whether they apply to your organization, converting the ones that do into policy, control and system changes, and evidencing that the process ran. It is judged on whether you knew in time, not on whether you eventually complied.

What is horizon scanning?

Systematically monitoring the sources that can create obligations for you, rather than waiting for news to arrive. That means the Federal Register for US rulemaking, the Official Journal for EU law, your sector supervisor's publications, and the standards bodies behind any framework you certify against.

Are law firm newsletters enough?

No. They are a useful supplement and a poor foundation, because they arrive after the fact and cover what the firm chose to write about. A defensible process starts from a defined universe of regulators, jurisdictions and products, and monitors primary sources.

How do you decide whether a change applies?

Work through entity type, jurisdiction, data, products, thresholds and exemptions, and record the reasoning even when the conclusion is that it does not apply. The written record of having considered it is what protects the organization when the question is asked later.

What is the hardest part of regulatory change management?

Usually not the new legislation but supervisory guidance that reinterprets an existing rule. It creates a new expectation without any law changing, and organizations watching only for new statutes miss it entirely.

How does the EU AI Act illustrate the discipline?

Its timeline moved. Prohibitions applied from 2 February 2025 and GPAI obligations from 2 August 2025, with general application on 2 August 2026. Then Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and deferred high-risk obligations to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I products. A team that stopped tracking after the original text has the wrong dates in its plan.

How should implementation be planned?

Backwards from the effective date rather than forwards from today. Forward planning is how programs discover in the final month that a system change was required and engineering has no capacity.

What evidence do auditors expect?

A log showing what was identified, when, from which source, the applicability decision and its reasoning, the resulting changes and who approved them. Auditors increasingly test the change process itself, not only the controls it produced.

What jobs require regulatory change management skills?

Compliance analyst and manager, regulatory affairs, GRC analyst, policy analyst, and AI governance roles tracking the EU AI Act, sector AI guidance and the evolving standards landscape.

More in this series

Written and reviewed by
Founder and Publisher, GRC Careers and AI Governance Jobs
  • Founder of ExecSearches and GRC Careers
  • Executive search across corporate, higher education, financial services, and nonprofit sectors
  • Focus on AI governance and GRC hiring
VP of Operations and GRC Practitioner
  • More than a decade in risk advisory and internal audit in financial services
  • Led SOX and regulatory audits for Citi, Goldman Sachs, Morgan Stanley, and McKesson
  • Public Accounting Certification, Cornell University