Operating across multiple jurisdictions creates a deceptively simple compliance challenge: the rules may look similar, but the way they are implemented, supervised and enforced rarely is.

Whether serving customers across borders, operating through overseas group structures or expanding into new markets, financial firms increasingly need to manage multiple regulatory frameworks at the same time.

Cross-jurisdiction compliance is the process of ensuring a firm meets the legal, regulatory, and supervisory expectations of every country or region in which it operates.

For compliance leaders, Chief Compliance Officers (CCOs), Money Laundering Reporting Officers (MLROs) and Chief Risk Officers (CROs), the challenge is not simply understanding different rulebooks, it is building a framework that can manage overlap, divergence, and local expectations without creating confusion or unnecessary complexity.

Why does cross-jurisdiction compliance matter?

Regulation shapes almost every aspect of a firm’s operations. Firms may need to manage different requirements relating to:

When operating across the UK and EU, or across multiple international markets, these obligations do not always align neatly. Some rules may be broadly similar in purpose, while others differ in scope, timing, or supervisory interpretation. This means firms need a compliance programme that is sufficiently robust to meet regulatory expectations across multiple jurisdictions.

What does cross-jurisdiction compliance involve?

Cross-jurisdiction compliance extends beyond monitoring jurisdictional requirements and tracking regulations. It involves aligning people, processes, controls, and governance so that compliance works in practice across multiple jurisdictions.

 

1. Understanding where requirements differ

The first step is identifying the applicable regulatory requirements within each jurisdiction and assessing where differences exist. This is particularly important where regulations look similar on the surface but are applied differently by local regulators.

For example, firms may face differences in:

  • AML monitoring and reporting expectations
  • Customer due diligence requirements
  • Governance responsibilities for senior managers
  • Resilience and outsourcing standards
  • Local regulatory reporting requirements

Without a clear understanding of these obligations, firms risk relying on assumptions that may not align with local regulatory expectations.

A practical example

A financial services group may operate a single AML framework across its European entities. The group policy sets common standards for customer risk assessment, CDD and transaction monitoring, but local requirements around reporting, governance or higher-risk customers may differ. If those differences are not identified and reflected in local procedures, the group can have a strong global framework while still creating compliance gaps at entity level.

 

2. Building the right governance model

An effective cross-jurisdiction framework relies strongly on good governance. Firms need to clearly define:

  • Who owns compliance at group level
  • Who is responsible within each legal entity or branch
  • How regulatory changes are identified and escalated
  • When local teams can adapt global policies

This is especially important in larger groups, where decision-making is centralised but regulatory accountability remains local.

 

3. Designing policies that work across borders

Many firms make the mistake of relying on a single global policy without considering local variation. In practice, firms usually need:

  • Group policies for core principles and minimum standards
  • Shared control frameworks for consistency
  • Local procedures or addenda for jurisdiction-specific rules

This approach helps firms avoid both extremes: fragmented local documents on one hand, and overly generic global policies on the other.

 

4. Strengthening evidence and reporting

Compliance is not simply about meeting regulatory requirements, firms must also be able to demonstrate how compliance is achieved, monitored and governed. This means maintaining:

  • A clear record of applicable obligations
  • Evidence of policy implementation
  • Management information for boards and committees
  • Control testing and assurance outputs
  • Regulatory change logs and decision records

Strong documentation is essential when responding to regulatory reviews, audits, or internal assurance activity.

 

What are we seeing in practice?

The challenge for many firms is not a lack of compliance infrastructure. It is making a group framework work consistently at local level.

We often see firms with well-developed global policies and control frameworks, but differences emerge when those controls are implemented across individual entities. Local teams may interpret requirements differently, regulatory change may not flow consistently through the group, or local procedures may evolve without being reflected centrally.

The result can be a gap between group-level design and local execution. Identifying those differences is therefore an important part of assessing whether a cross-jurisdiction framework is genuinely effective.

Where does cross-jurisdiction compliance go wrong?

Cross-jurisdiction compliance often becomes difficult because firms are trying to balance efficiency with local responsiveness. Common problems include:

Assuming similar regulations are effectively the same

Firms assume that because two jurisdictions pursue the same regulatory objective, the underlying requirements and supervisory expectations are the same.

Unclear ownership between central and local teams

Central teams may design the framework, while local entities retain regulatory accountability, creating uncertainty over who owns decisions and remediation.

Duplicated controls across entities

Different entities build separate solutions to similar requirements, increasing cost and making group oversight more difficult.

Weak change management for new regulatory developments

Local developments are not always captured, assessed and incorporated into group policies and controls consistently.

Inconsistent reporting and evidence standards

Controls may operate across the group, but individual entities cannot always demonstrate their effectiveness to the same standard.

Over time, these issues can create a framework that is harder to manage, more expensive to maintain, and more vulnerable to challenge from regulators.

How can firms strengthen cross-jurisdiction compliance?

To strengthen cross-jurisdiction compliance, firms should focus on a few practical steps:

  1. Map your regulatory obligations: Create a clear view of the requirements applying to each entity and jurisdiction.
  2. Identify where requirements diverge: Distinguish between requirements that can be addressed through a common group control and those requiring local adaptation.
  3. Clarify governance and accountability across entities: Define who owns policy, implementation, monitoring, escalation and regulatory engagement.
  4. Review policies and procedures to ensure local requirements are reflected: Use group-wide minimum standards supported by local procedures or addenda where necessary.
  5. Strengthen regulatory change management: Ensure developments in each jurisdiction are identified, assessed and reflected across the wider framework.
  6. Test the framework implementation locally: Do not rely solely on group-level policy reviews. Test whether controls are operating effectively within individual entities and jurisdictions.

A well-designed framework not only reduces regulatory risk but also supports greater operational efficiency, stronger governance and more effective decision making.

Cross-jurisdiction compliance readiness check

Ask yourself:

✔ Do we have a clear view of the regulatory obligations applying to each entity?

✔ Can we identify where local requirements differ from our group framework?

✔ Is accountability between group and local compliance teams clearly defined?

✔ Do regulatory changes flow consistently into policies, procedures and controls?

✔ Can each entity evidence that group controls operate effectively in its jurisdiction?

✔ Does senior management have sufficient MI to identify gaps across the group?

If any of these questions are difficult to answer, there may be gaps between your group compliance framework and how it operates locally.

How fscom can help

Managing compliance across multiple jurisdictions requires a framework that delivers consistency at group level without overlooking local regulatory expectations.

fscom can help firms assess cross-jurisdiction compliance frameworks, identify gaps between group and local controls, strengthen governance and regulatory change processes, and provide independent assurance over how controls operate in practice.

If you would like to understand where your framework is working well – and where local differences may be creating risk – get in touch with our team.

This post contains a general summary of advice and is not a complete or definitive statement of the law. Specific advice should be obtained where appropriate.