Your Compliance List Is Too Long: What to Fix, What to Defend, What to Ignore
Most compliance lists are too long. A review comes back with a hundred findings, the list goes straight to the tech team, and suddenly compliance is competing with the product roadmap for the same engineers. The business starts treating compliance as a blocker, and the compliance function starts being treated as noise.
Martin Crowe’s argument is that the list was never the problem. It was that nobody triaged it. Of those hundred findings, typically a third or more can be argued down on regulator-defensible logic alone. Others can be accepted as a documented risk decision, handled manually without touching tech resource, or defended to the regulator through controls you already have. What is left is the ten things that genuinely have to be built. That is a very different conversation to have with your CTO.
In this session Martin walks through how he triages that list with scaling operators, where the process usually breaks down, and the questions most businesses never think to ask before committing engineering time. Bring the item currently sitting on your own list that you suspect does not need to be there, and he will work through it live.
WHO IT IS FOR
Founders, COOs and operations leads at scaling operators between roughly 10 and 150 staff, in regulated markets, where there is no senior compliance hire in the seat, or a junior is holding it alone. Particularly relevant if you are in a licence application, entering a new market, working through an acquisition, or cleaning up after enforcement.
WHAT ATTENDEES TAKE AWAY
- A triage method for cutting a compliance list down before it reaches the tech team
- How to tell what genuinely must be built from what can be defended through existing controls
- The questions to settle internally before committing engineering resource
- Where compliance most commonly goes wrong at this stage of growth, and what it costs when it does
SPEAKER BIO
Martin Crowe is the founder of NexaCompliance, a Malta-based consultancy working with licensed gambling operators and suppliers across the UK, Malta, Sweden and the Isle of Man, with current market-entry work in Ireland, Finland and Canada. He has worked in compliance since 2017, most of it inside licensed gambling operators, holding named Compliance Lead and MLRO roles before moving those functions external. His work centres on scaling operators without a senior compliance function: licence applications, new-market entry, remediation after reviews and enforcement, and running the function itself. He has spent most of that time turning long compliance lists into short, defensible ones.