[{"data":1,"prerenderedAt":4},["ShallowReactive",2],{"article-body-the-register-is-not-the-risk":3},"\nSit in the post-mortem of a regulatory miss and a pattern repeats.\nThe requirement that was breached was not unknown. The change had\nbeen published months earlier, a horizon-scanning service had\nflagged it, and someone had dutifully logged it in the obligations\nregister. Detection worked. The register was accurate on the day of\nthe inspection.\n\nWhat failed was everything after detection: nobody connected the\nchange to the four work instructions, two product specifications\nand one supplier contract it quietly invalidated. Each of those\ndocuments remained in force, confidently wrong, until an auditor or\nan incident found the gap. The register described the obligation.\nThe risk lived in the mapping that never happened.\n\n## Why good registers still produce misses\n\nThe regulatory intelligence market has largely solved detection.\nPublication feeds, subscription services and update digests mean\nthe change itself is rarely the surprise. Three gaps downstream of\ndetection do the damage:\n\n- **The mapping is manual, so it is partial.** Connecting a changed\n  requirement to the specific procedures, labels, permits and\n  contracts it affects is expert work, performed under time\n  pressure, one change at a time. When the volume of change\n  exceeds the hours available, the mapping silently degrades from\n  \"everything affected\" to \"what the reviewer thought of\".\n- **Applicability is decided once and never revisited.** A\n  requirement judged not applicable three years ago stays filed as\n  such, while the company enters a new market, adds a product line\n  or acquires a site that makes it applicable. Nobody re-asks the\n  question, because nothing prompts it.\n- **Deployment is a project, not a consequence.** Even a correctly\n  mapped change becomes a change request, a training update, a\n  document revision cycle, each on its own calendar. In a complex\n  operation the distance from \"change understood\" to \"change\n  operating on the shop floor\" is routinely measured in quarters,\n  and the obligation was in force the whole time.\n\n## The evidentiary bar is rising\n\nA second shift is quieter. Regulators and auditors are moving\nfrom \"show me the register\" to \"show me your working\": why\ndid you conclude this requirement does not apply to that site? When\nthis changed, which documents did you review, and who signed off\nthat the label was still compliant?\n\nThose questions demand an evidence chain, not a spreadsheet: the\nchange, the assessment, the affected artefacts, the decisions and\nthe sign-offs, connected and timestamped. A conclusion of\nnon-applicability without recorded reasoning is indistinguishable,\nfrom the inspector's side of the table, from never having looked.\nThis is where AI-assisted regulatory work will be held to the\nhighest standard of all. A predicted applicability call is only\nusable if the basis for it can be produced on demand.\n\n> The defensible position is not \"we have a register\". It is \"for\n> any requirement, we can show what it touches, what we decided,\n> and why\".\n\n## One change, three departments\n\nThe deepest problem with treating regulatory intelligence as a\nsingle function's register is that changes refuse to stay in one\ndomain. A new substance restriction is simultaneously a product\ncompliance question (formulations and specifications), a trade\nquestion (tariff classifications and export declarations) and an\nESG question (disclosure and supplier attestations). Each function\ntypically discovers its slice independently, on its own timeline,\nwith its own partial mapping.\n\nStructurally, this is the same computational problem repeated:\nclassify the change, resolve the entities and artefacts it touches,\ncheck documents for conformance, route the exceptions to owners.\nSolve that problem class once, against a connected model of the\ncompany's products, sites, documents and suppliers, and one\npublished change propagates to every affected corner in one pass,\nwith the evidence chain generated as a by-product rather than\nreconstructed for the audit.\n\nThe question to put to your own programme: take last quarter's most\nsignificant regulatory change, and ask how many affected documents,\nproducts and contracts were identified, by whom, and where that\nassessment is recorded. If the answer takes longer than a day to\nassemble, the mapping is the gap. Closing it is what the Prophesee\nRegulatory module is built for. [See what one change touches in\nyour operation](/contact).\n",1786833838545]