Join a community of professionals and get:
on all CeFPro events.
unlock speaker decks and audience polls.
Full library access the moment you sign up.
Digital Content

- Unlimited access to peer-contribution articles and insights
- Global research and market intelligence reports
- Discover Connect Magazine, a monthly publication
- Panel discussion and presentation recordings

- Use global frameworks with local execution.
- Map obligations to risks and controls.
- Measure outcomes, not activity volumes.
- Standardise where requirements overlap.
- Align cross-border resilience and cyber rules.
- Use technology with strong governance.
What are the most effective approaches for managing compliance across multiple jurisdictions while minimising duplication of effort and maintaining consistent risk oversight?
I believe the most effective model is a globally consistent framework with disciplined local execution. I would start with a single regulatory inventory, common business process and risk taxonomies, and an enterprise control library that maps each obligation to risks, processes, controls and evidence. That allows the organisation to apply a common-control baseline once, add jurisdiction-specific requirements only where necessary, and maintain one aggregated view of residual risk. Clear global and local ownership, central regulatory-change governance, and common reporting thresholds are essential to preserving accountability while reducing duplicate assessments and testing.
How can organisations ensure that regulatory compliance activities drive meaningful risk management outcomes, rather than becoming predominantly process-driven or box-ticking exercises?
From my perspective, compliance must be connected to business outcomes—not measured by completed activities alone. Obligations should be mapped to the risks they are intended to mitigate, the critical services and processes they support, and the controls that change exposure. Success measures should therefore include control effectiveness, trend in residual risk, incidents, customer or market impact, and remediation quality—not simply training completion, policy attestations or review volumes. Strong challenge, scenario analysis and clear escalation against risk appetite help ensure compliance activity drives decisions and reinforces resilience.
What practical strategies can firms adopt to address the operational challenges and inefficiencies created by diverging regulatory requirements across different markets?
I would address divergence through structured decomposition and deliberate standardisation. Firms should translate rules into discrete obligations, map them to a shared taxonomy and control library, and identify where requirements are equivalent, stricter or genuinely unique. A “highest common denominator” standard can be applied where it is proportionate, while local overlays address legitimate differences. Centres of expertise, reusable evidence, integrated assurance, common data definitions and an enterprise view of regulatory change can materially reduce parallel work. Where divergence creates unavoidable cost or risk, the decision should be transparent, risk-based and escalated to the appropriate governance forum.
Looking ahead, how realistic is greater regulatory synchronisation across jurisdictions, and which areas of financial regulation would benefit most from increased alignment?
I expect full synchronisation to remain unlikely because laws, supervisory mandates, market structures and national priorities differ. Greater convergence is realistic, however, around outcomes, principles, definitions and data standards. The greatest value would come from alignment in operational resilience, cyber incident reporting, third-party and cloud oversight, AI governance, data and privacy requirements, and core prudential standards. These are inherently cross-border risks, and inconsistent definitions, timelines and reporting formats create cost without necessarily improving protection. International standards can establish a common floor, while jurisdictions retain proportionate local implementation.
As regulatory expectations continue to expand, what best practices will help organisations create scalable, technology-enabled compliance frameworks that remain effective without significantly increasing operational burden or cost?
The foundation should be a scalable data and governance architecture rather than a collection of point solutions. I would prioritise one obligation repository, common taxonomies, a reusable control library, clear ownership, and workflow-enabled regulatory change and issue management. Technology and AI can accelerate horizon scanning, obligation mapping, evidence collection, control monitoring and reporting, but they must operate within strong data-quality, model-governance and human-accountability guardrails. The objective is “design once, use many times”: automate routine activity, integrate assurance, focus expert capacity on judgement and emerging risk, and measure whether the framework is reducing exposure and protecting critical services—not merely lowering processing time.
Spruille Braden is a seasoned profession in the Financial Services industry with subject matter expertise in many critical functions at top tier banks. Spruille is the Enterprise Head of Operational Resilience at Citi. Prior to Citi he was the Head of Operational Resilience at Sumitomo Mitsui Banking Corporation (SMBC) where led the development and implementation of the function at the firm. Prior to SMBC Spruille spend nearly 15 years at UBS where he held several roles that spanned all three lines of defense. Notably Spruille was the Americas Head of Business Continuity Management (BCM) at UBS for 6 years where he led a team of Risk professionals tasked with ensuring the resiliency of their Americas-based operations. As a member of the COO Group he drove strategic programs and initiatives that often spanned multiple competency areas. He helped develop the Operational Resilience program that encompassed Business Cyber Technology and Third Party Risk Management strategies in accordance with internal and external drivers. Spruille was a co-chair for SIFMA’s Resilience Forum where he helped shape responses to regulatory guidance through the collaborative peer industry group. Spruille lives in Connecticut with his wife Jamie and three daughters Emma Elodie and Hailey (ages 11 8 and 8 respectively).