Sit in the post-mortem of a regulatory miss and a pattern repeats. The requirement that was breached was not unknown. The change had been published months earlier, a horizon-scanning service had flagged it, and someone had dutifully logged it in the obligations register. Detection worked. The register was accurate on the day of the inspection.
What failed was everything after detection: nobody connected the change to the four work instructions, two product specifications and one supplier contract it quietly invalidated. Each of those documents remained in force, confidently wrong, until an auditor or an incident found the gap. The register described the obligation. The risk lived in the mapping that never happened.
Why good registers still produce misses
The regulatory intelligence market has largely solved detection. Publication feeds, subscription services and update digests mean the change itself is rarely the surprise. Three gaps downstream of detection do the damage:
- The mapping is manual, so it is partial. Connecting a changed requirement to the specific procedures, labels, permits and contracts it affects is expert work, performed under time pressure, one change at a time. When the volume of change exceeds the hours available, the mapping silently degrades from "everything affected" to "what the reviewer thought of".
- Applicability is decided once and never revisited. A requirement judged not applicable three years ago stays filed as such, while the company enters a new market, adds a product line or acquires a site that makes it applicable. Nobody re-asks the question, because nothing prompts it.
- Deployment is a project, not a consequence. Even a correctly mapped change becomes a change request, a training update, a document revision cycle, each on its own calendar. In a complex operation the distance from "change understood" to "change operating on the shop floor" is routinely measured in quarters, and the obligation was in force the whole time.
The evidentiary bar is rising
A second shift is quieter. Regulators and auditors are moving from "show me the register" to "show me your working": why did you conclude this requirement does not apply to that site? When this changed, which documents did you review, and who signed off that the label was still compliant?
Those questions demand an evidence chain, not a spreadsheet: the change, the assessment, the affected artefacts, the decisions and the sign-offs, connected and timestamped. A conclusion of non-applicability without recorded reasoning is indistinguishable, from the inspector's side of the table, from never having looked. This is where AI-assisted regulatory work will be held to the highest standard of all. A predicted applicability call is only usable if the basis for it can be produced on demand.
The defensible position is not "we have a register". It is "for any requirement, we can show what it touches, what we decided, and why".
One change, three departments
The deepest problem with treating regulatory intelligence as a single function's register is that changes refuse to stay in one domain. A new substance restriction is simultaneously a product compliance question (formulations and specifications), a trade question (tariff classifications and export declarations) and an ESG question (disclosure and supplier attestations). Each function typically discovers its slice independently, on its own timeline, with its own partial mapping.
Structurally, this is the same computational problem repeated: classify the change, resolve the entities and artefacts it touches, check documents for conformance, route the exceptions to owners. Solve that problem class once, against a connected model of the company's products, sites, documents and suppliers, and one published change propagates to every affected corner in one pass, with the evidence chain generated as a by-product rather than reconstructed for the audit.
The question to put to your own programme: take last quarter's most significant regulatory change, and ask how many affected documents, products and contracts were identified, by whom, and where that assessment is recorded. If the answer takes longer than a day to assemble, the mapping is the gap. Closing it is what the Prophesee Regulatory module is built for. See what one change touches in your operation.