SD-10.8 — Compliance Breach Management & Remediation
Business Domain: BD-10 Investment Compliance & Guideline Monitoring (Middle office) · Applies: BOTH
Purpose
Manages a compliance breach from the moment it is raised to the moment it is closed — triaging the alert, classifying the breach, escalating it, driving the correction and recording the resolution. Where SD-10.1 and SD-10.7 detect, SD-10.8 responds. It exists because detecting a breach is not handling it: a raised alert must be investigated, classified by cause and materiality, put in front of the portfolio manager, corrected, and — critically — assessed for whether it triggers a disclosure obligation to a regulator or a client. SD-10.8 is the Service Domain that owns that response and the breach record. It is the compliance-side analogue of SD-12.10’s reconciliation-break handling and SD-07.7’s limit-breach escalation, distinguished by the source of the breach: a guideline or a regulatory rule.
Service Operations
- Triage the alert — review each compliance alert, confirm it is a genuine breach rather than a false positive, and open a breach record.
- Classify the breach — classify it by cause — active (a trade caused it) or passive (a market move, redemption, corporate action or downgrade caused it) — and by materiality — technical / de-minimis or material.
- Escalate to the portfolio manager and compliance governance — put the breach in front of the desk that must correct it and the compliance officers who must oversee it.
- Drive the correction — track the corrective action — the trade or instruction that brings the portfolio back inside the guideline — to completion.
- Assess the disclosure obligation — determine whether the breach triggers a reporting obligation to a regulator or a client, on what threshold and timeline, and hand the trigger to BD-16 SD-16.3 for the filing.
- Record and report the resolution — record the breach, its cause, its correction and its closure, and report the breach population — open, aged, resolved — to compliance governance.
Inputs and outputs
- Inputs: compliance alerts from SD-10.1; regulatory-compliance alerts from SD-10.3; confirmed sanctions matches from SD-10.6; surveillance alerts from SD-10.7; the portfolio and trade record for the investigation.
- Outputs: breach records, corrective-action outcomes, disclosure-obligation triggers and breach reporting — consumed by SD-05.2 Portfolio Management & Monitoring (the desk that corrects), SD-16.3 Regulatory Reporting & Filings (the disclosure), SD-14.8 Internal Audit, SD-14.2 Corporate Compliance & Conduct, and the compliance reporting in BD-13.
Entities
- Consumes: E-03 Portfolio / Mandate, E-04 Holding / Position (
book = ibor— the breach is raised against the live IBOR position SD-10.1 monitors), E-05 Transaction, E-16 Risk Limit (the breachedmandate-typed limit); the SD-10.1 compliance alerts; the SD-10.3 regulatory-compliance alerts; the SD-10.6 confirmed sanctions matches; the SD-10.7 surveillance alerts. - Owns: the compliance-breach record — the raised, classified, aged, resolved breach. a guideline breach is the crossing of an E-16 Risk Limit of
limit_type = mandate, closely parallel to E-18 Limit Breach (owned by SD-07.7). - Open question: whether a guideline / compliance breach is an instance of E-18 Limit Breach or warrants a distinct Compliance Breach entity — the same shape of question SD-12.10 raises for the Reconciliation Break.
Standards
- The active / passive and technical / material breach taxonomy as industry practice.
- The regulatory breach-disclosure regimes — UCITS and AIFMD breach notification, the SEC and FCA expectations on breach reporting.
- The three-lines-of-defence model.
Open extensions
- A Compliance Breach entity, or the extension of E-18 Limit Breach to carry guideline breaches.
- The breach-classification sub-model.
- The disclosure-trigger interface with BD-16 SD-16.3.