When a regulator issues a Section 166 Requirement Notice, two programmes begin. The visible one belongs to the skilled person: scoped by the regulator, counted in published statistics, fee averaging close to a million pounds. The invisible one belongs to the firm: RFI management, document production, interviews, evidence packs, remediation planning, governance, reporting, and the handover into business as usual.
Nobody publishes what that second programme costs. For a multi-business-unit bank it routinely exceeds the skilled person’s fee. And unlike the fee, it is a cost the firm can actually control.
Why these programmes fail so predictably
A Section 166 response is not a large but ordinary change programme, and three properties explain why treating it like one never quite works.
- The evidence bar is regulatory. Everything submitted may later be tested: in supervision, in a follow-up review, in enforcement. Provenance, versioning and completeness matter as much as content. A programme that reconstructs its evidence afterwards has already failed that test; it just doesn’t know yet.
- The timetable is, in effect, contractual. Milestones are commitments to the regulator, and slippage is itself reportable. This is why the industry’s normal 30–45% overrun is not merely expensive here. It is a regulatory event in its own right.
- Three masters read one dataset. The bank runs delivery, the skilled person consumes evidence, the regulator consumes progress. The moment the board pack, the skilled person’s tracker and the regulatory update disagree, credibility starts to drain, and credibility is the programme’s only real currency.
Two beliefs that feel prudent and are backwards
When the Notice lands, the clock is already running, and almost every firm makes the same call on the same logic.
Belief one: structure takes too long to build. So trackers, reporting and processes get assembled mid-flight and iterated under fire, while delivery is already underway. Belief two: too much governance makes a programme rigid. So governance is kept light, and then stripped further whenever things get tight.
Both beliefs are understandable. Both produce the same six failures.
Agility comes from firm controls
A ballerina doesn’t pivot on the leg that moves. She pivots on the leg that holds: strong, controlled, planted.
This is the whole argument. Prepared comms, briefed stakeholders, locked change windows and one golden source are not what stop a programme pivoting. They are the planted leg that makes the pivot possible. When the skilled person’s focus shifts or new findings land, a change made once flows through plan, reporting and comms; the programme absorbs it in days instead of firefighting for weeks.
ACON stands for Agile Controls, and the name is the method.
Where it came from
Early in a major UK bank’s Section 166, as design lead, I put forward an operating model along these lines: governance, sprint cycles, a controlled delivery workflow, maintained SOPs. With the clock already running it felt, understandably, like too much structure too soon, and the programme pressed on.
Two years of building-while-delivering followed. Trackers, reports and SOPs reworked over and over, strategy reset after reset, until the programme itself asked for a proper workflow. Once the structured model was adopted, validation rates rose by more than 50%, every phase submission passed skilled person review first time, and submissions went to the regulator on time.
ACON was built during that time. The steps of a Section 166 are substantially the same every time; only the scope, the business units and the findings change. So the foundation can be built once, properly, in advance, then moulded to each bank in weeks rather than assembled under fire.
The system
Mobilise once, then deliver and govern in parallel: the inverse of building while delivering.
- Mobilisation, weeks 1–3. Governance model and delegated authorities, organisation structure and named owners, comms architecture, privilege-aware production discipline, and the full planning baseline. Requirements documented and locked inside two weeks; the programme workbook generated, tested and live by week three.
- Delivery, week 4 to close. One golden-source plan: live critical path with same-day breach visibility, eight-week look-ahead, executive dashboard, pre-loaded risk register, budget and burn-down, authority-trailed audit log.
- PMO, two-week sprints alongside. Governance and comms kept ahead of the programme: briefed before change lands, refreshed every cycle, never allowed to rot.
One source, six views
The suite serves every audience from one dataset. A master programme workbook feeds SLA-timed workflow trackers for the volume work of a review (RFIs, interviews, case builds, sample testing, findings checks, report responses), with one refresh updating every report.
The case handler sees a simple queue. The programme director sees six phases. Internal audit sees everything, read-only. Microsoft-native and macro-free throughout: Excel, SharePoint and PowerPoint, the estate the bank already licenses, trusts and audits, plugging into Power BI, Tableau, the GRC platform and MS Project where needed. No new platform, no procurement cycle, no data leaving the estate.
What it comes down to
On a response programme running at half a million pounds a month, a “normal” 30% overrun is roughly seven additional months: extended run-rate, extended skilled person engagement, and a conversation with the regulator nobody wanted. Weak governance is consistently cited among the leading root causes.
The time invested at mobilisation is the cheapest time in the whole programme. Re-do work and firefighting are the price of skipping it.
The engineering of the toolkit itself stays out of the public edition. What is here, the diagnosis and what good looks like, is deliberately generous. Expertise is demonstrated, not asserted.