Regulatory Horizon Scanning

Know what applies to your business, and what to do about it

Horizon scanning is the ongoing monitoring of privacy and AI regulation across the jurisdictions a business operates in, translated into what the company actually has to do and by when. The output is a maintained compliance library — not a newsletter.

What it is and who needs it

Horizon scanning is the ongoing monitoring of privacy and AI regulation across the jurisdictions a business operates in, translated into what the company actually has to do and by when. The output is a maintained compliance library mapping applicable obligations to the business, with changes assessed for impact and turned into dated actions.

Any company operating across multiple jurisdictions needs it, particularly where US state privacy and AI laws are taking effect on staggered timelines and obligations are shifting faster than an annual policy review can absorb.

This is not a newsletter. Regulatory updates that arrive without applicability assessment, impact scoring, and a dated action with an owner are awareness, not monitoring. The compliance library maps obligations to your business and keeps that mapping current as the regulatory landscape changes.

What usually prompts this work

Usually the company has discovered a requirement late. A law took effect that nobody tracked, a customer or regulator asked how the business monitors regulatory change and there was no answer, or an audit finding identified that obligations were not mapped to the business.

The other common trigger is expansion — a company enters new states or new markets and realises its compliance position was built for a footprint it has outgrown.

How it works

  1. 01

    Establish the regulatory footprint

    Confirm the jurisdictions engaged by the company's operations, customers, employees, and data flows.

  2. 02

    Build the compliance library

    Map applicable privacy and AI obligations to the business and identify which functions and processing activities each one touches.

  3. 03

    Assess the current position

    Record where the business already meets its obligations, where it does not, and where the position is unclear.

  4. 04

    Set the monitoring process

    Define sources, cadence, and who is responsible for reviewing what.

  5. 05

    Assess each development for applicability and impact

    Convert the relevant ones into dated actions with assigned owners rather than passing along the update.

  6. 06

    Report and maintain

    Report to leadership on a regular cadence and maintain the library so it reflects the obligations as they stand, not as they stood at the last review.

Pricing

Compliance library build and initial mapping
Fixed fee Typically four to eight weeks, depending on the number of jurisdictions in scope.
Ongoing monitoring
Monthly retainer Light monthly retainer, or bundled into a fractional DPO engagement where one is in place.

Where monitoring breaks down

Monitoring gets confused with awareness. Someone subscribes to alerts, the updates arrive, and nothing translates into an action with an owner and a date.

Scope is set by where the company is headquartered rather than where its data subjects are, so obligations arising from customers or employees in other jurisdictions get missed entirely.

Effective dates are tracked while the earlier operational lead time is not, so work starts too late to be ready.

Sector-specific and AI regulation gets tracked separately from privacy, or not at all. And the library, where one exists, is built once and then diverges from the business as the footprint changes.

What is and is not included

Included

  • Regulatory footprint assessment across jurisdictions engaged
  • Compliance library mapping applicable obligations to the business
  • Current position assessment against those obligations
  • Defined monitoring sources, cadence, and ownership
  • Applicability and impact assessment of regulatory developments
  • Dated actions with assigned owners
  • Periodic reporting to leadership
  • Ongoing maintenance of the library

Not included

  • Legal advice or formal legal opinions, which sit with counsel
  • Implementation of the remediation actions identified, scoped separately or under retainer
  • Technical or platform configuration
  • Representation before a regulator

Experience

A sovereign investment institution required regulatory monitoring across the jurisdictions engaged by its operations and data flows. I carried out the horizon scanning, mapping applicable privacy and data protection obligations to the business, assessing developments for relevance and impact rather than circulating them wholesale, and translating the ones that mattered into defined actions.

The institution moved from receiving regulatory updates to holding a maintained view of what applied to it and what had to be done about it.

Questions

How is this different from a regulatory alert service?

An alert service delivers awareness. This service assesses each development for applicability and impact to your business, and converts the relevant ones into dated actions with assigned owners. The distinction matters: updates that arrive without that translation produce no change in what the business does.

Why does scoping by headquarters miss obligations?

Scope set by where the company is headquartered rather than where its data subjects are means obligations arising from customers or employees in other jurisdictions get missed entirely. The regulatory footprint is built from operations, customers, employees, and data flows — not the registered address.

What happens to the library as the business changes?

The library is maintained on an ongoing basis so it reflects the obligations as they stand, not as they stood at the last review. A library built once and left diverges from the business as its footprint changes; ongoing maintenance is what keeps it current.

Can this be bundled with a fractional DPO arrangement?

Yes. Ongoing monitoring runs as a light monthly retainer, or is bundled into a fractional DPO engagement where one is in place. Where there is an ongoing retainer, the horizon scanning is part of the function rather than a separate track.

Our services

Ready to map your regulatory footprint?

Get in touch

Building the compliance library and initial mapping typically runs four to eight weeks as a fixed fee project. Scope the engagement on a call.

Write to us

Prefer email? Start here.

A short note about your situation is plenty. Replies come from rasha.hisham@appliedprivacyconsulting.com.