Banking Regulatory Compliance and Legal Risk Training Course

5 days Legal Certificate on completion
Course codeSD-L-007
Duration5 days
LevelIntermediate
CategoryLegal
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Banking legal and compliance teams must convert dense regulatory obligations into controls that can withstand supervisory scrutiny, internal challenge and operational change. A missed conduct requirement, weak customer due diligence record, poorly governed product approval or incomplete regulatory notification can trigger enforcement action, customer remediation, capital impact and reputational damage. This course equips professionals to identify legal risk early, interpret banking requirements in context and document defensible compliance decisions across retail, corporate and investment banking activities.

Participants examine the regulatory architecture governing banks, including prudential supervision, anti-money laundering and counter-terrorist financing, conduct of business, data protection, sanctions, consumer protection and outsourcing. They learn to build obligation registers, map rules to business processes, assess inherent and residual legal risk, design preventive and detective controls, test evidence, manage regulatory change and escalate material breaches. The programme also develops practical judgement for advising product, operations, risk and senior management teams without treating compliance as a purely checklist-based function.

Delivery combines instructor-led legal analysis with realistic bank scenarios, control-design workshops, peer review and structured case discussions. Participants work with a regulatory obligation inventory, legal-risk assessment matrix, control-testing plan and breach-escalation template. By the final day, each participant produces a bank-specific legal and regulatory compliance action plan that identifies priority obligations, ownership, control gaps, evidence requirements and implementation milestones for use on return to work.

The course is designed for experienced banking professionals who work at the intersection of legal, compliance, risk, operations, products or audit and need a more systematic way to manage regulatory obligations.

Course objectives

By the end of this course, participants will be able to:

  • Interpret banking laws, regulatory rules and supervisory guidance using a structured applicability analysis
  • Build a regulatory obligation register linking legal requirements to business owners, processes and evidence
  • Conduct a legal-risk assessment using inherent-risk, control-effectiveness and residual-risk scoring
  • Map anti-money laundering, sanctions and conduct obligations to customer lifecycle controls
  • Design preventive and detective compliance controls with defined owners, frequencies and test evidence
  • Plan regulatory change implementation through impact assessments, gap logs and accountable action plans
  • Prepare a material breach escalation record with facts, legal analysis, remediation and notification decisions
  • Produce a 90-day banking compliance action plan for a selected business area

Benefits of attending

For you

  • Gain a repeatable method for turning regulatory text into clear operational obligations and control requirements
  • Build credibility when advising business leaders on legal-risk decisions, product changes and remediation priorities
  • Strengthen the evidence-based judgement needed to challenge weak compliance rationales and incomplete control records
  • Create work-ready templates for obligation mapping, legal-risk assessment, control testing and breach escalation
  • Position yourself for broader responsibilities in banking compliance advisory, regulatory risk or second-line oversight

For your organisation

  • Improve traceability from external banking requirements to policies, processes, controls and accountable owners
  • Reduce missed obligations during regulatory change, product launches, outsourcing arrangements and process redesign
  • Create more consistent legal-risk assessments and clearer prioritisation of remediation expenditure
  • Strengthen audit and supervisory readiness through defined control evidence, testing plans and escalation records
  • Improve cross-functional decisions between legal, compliance, risk, operations and product teams

Target competencies

Regulatory interpretationLegal-risk assessmentObligation mappingControl designBreach escalationRegulatory change management

Who should attend

  • Banking Compliance Managers — who must translate regulatory obligations into monitored business controls
  • In-House Banking Lawyers — who advise on regulatory interpretation, product governance and reportable events
  • Operational Risk Managers — who assess legal-risk exposure and challenge control design
  • AML and Financial Crime Officers — who need to connect CDD, sanctions and transaction-monitoring duties to legal requirements
  • Internal Auditors — who evaluate whether regulatory controls are designed, evidenced and operating effectively
  • Product and Operations Managers — who must implement compliant customer journeys, disclosures and escalation processes

Requirements and prerequisites

Participants should have at least one to three years of experience in banking, financial services compliance, legal, risk, audit, financial crime or operations. They should already understand basic banking products and customer lifecycle processes, such as account opening, lending, payments, trading or complaints handling. Familiarity with the terms AML, KYC, sanctions, conduct risk, internal controls and regulatory reporting is assumed. Participants should be comfortable reading policy documents and using spreadsheets for simple registers and action tracking. No law degree, programming ability, specialist legal database subscription or prior regulatory investigation experience is required.

Training methodology

An instructor with banking legal and compliance experience leads focused sessions on applicable rules, supervisory expectations and decision frameworks. Participants then apply the frameworks to bank scenarios involving onboarding, product approval, sanctions alerts, complaints, outsourcing and control failures. Small groups build obligation registers, score legal risks, define controls and challenge each other's evidence standards. Daily debriefs compare alternative legal and operational responses. The final workshop converts course outputs into an individual 90-day implementation plan aligned to the participant's own bank, function or control area.

Course outline

Day 1: Banking regulation, legal duties and risk ownership

  • Banking regulatory architecture and the roles of prudential, conduct and financial-crime supervisors
  • Sources of legal obligation: statutes, regulations, rulebooks, guidance and enforcement precedents
  • Three-lines model and the allocation of legal, compliance, risk and business accountability
  • Legal-risk taxonomy for banking products, customers, channels and third-party arrangements
  • Rule applicability analysis by entity, jurisdiction, customer segment and activity
  • Regulatory obligation register structure and minimum data fields
  • Policy hierarchy, delegated authorities and evidence of governance decisions

Workshop: Participants build an initial obligation register for a digital deposit and payments product, assigning applicability, owners and evidence sources.

Day 2: Financial crime, customer protection and data obligations

  • Risk-based customer due diligence and beneficial ownership verification requirements
  • Sanctions screening obligations, alert disposition and escalation documentation
  • Transaction-monitoring governance, suspicious activity reporting and record-retention duties
  • Consumer protection rules for disclosures, fair treatment, complaints and vulnerable customers
  • Market conduct and conflicts-of-interest controls in banking sales and advisory activity
  • Data protection principles for customer data, lawful processing and cross-border transfers
  • FATF Recommendations as a benchmark for financial-crime control design

Workshop: Teams analyse a high-risk customer onboarding case and produce a documented CDD, sanctions and escalation decision.

Day 3: Controls, product governance and third-party legal risk

  • Converting obligations into preventive, detective and corrective control objectives
  • Risk and control self-assessment techniques for legal and compliance risks
  • Control design specifications: owner, frequency, population, threshold and evidence
  • Product approval committees, target-market assessments and conduct-risk sign-off
  • Outsourcing due diligence, contractual clauses, exit planning and ongoing oversight
  • Records management and audit trails for legally significant customer and governance decisions
  • Control testing design using samples, walkthroughs, exceptions and root-cause analysis

Workshop: Participants map a lending-process obligation to controls and create a control-testing sheet with evidence criteria.

Day 4: Regulatory change, breaches and supervisory engagement

  • Regulatory change intake, horizon scanning and applicability triage
  • Impact assessment methods for rule changes affecting systems, policies, products and training
  • Gap analysis and remediation planning with accountable owners and due dates
  • Materiality assessment for compliance incidents and potential legal breaches
  • Breach investigation records, legal privilege considerations and fact preservation
  • Regulatory notification decisions, communications governance and remediation commitments
  • Supervisory examination preparation, document requests and management response tracking

Workshop: Working from a new conduct rule and an incident report, participants create an impact assessment and material-breach escalation pack.

Day 5: Integrated legal-risk governance and workplace application

  • Residual legal-risk reporting for management committees and boards
  • Key risk indicators and key control indicators for banking compliance oversight
  • Issue management, root-cause analysis and sustainable remediation verification
  • Using ISO 37301 principles to structure a compliance management system
  • Basel Committee expectations for governance, risk data and operational resilience
  • Challenge techniques for business rationales, control attestations and risk acceptance requests
  • Ninety-day implementation planning for priority legal and regulatory risk improvements

Workshop: Participants present a bank-specific legal and compliance action plan containing priorities, controls, owners, evidence and 90-day milestones.

Tools & standards covered

Microsoft Excel, ISO 37301 Compliance Management Systems, FATF Recommendations, Basel Committee Core Principles for Effective Banking Supervision

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

You should understand core banking activities and have working exposure to compliance, legal, risk, audit, financial crime or operations. The course assumes familiarity with terms such as AML, KYC, sanctions and internal controls, but it does not require a law degree or prior experience of regulatory enforcement.

A laptop is recommended for completing the obligation-register, risk-assessment and action-plan exercises. No subscription to a legal database is required; all case materials and templates are supplied during the course.

Yes. In-house lawyers will develop stronger methods for translating legal interpretation into operational controls, while compliance professionals will strengthen their ability to frame issues, evidence decisions and escalate legal risk. Discussions deliberately examine where legal, compliance and business responsibilities differ.

AML is covered as one important legal-risk area, but the course goes further into conduct, consumer protection, data, product governance, outsourcing, regulatory change and breach management. Its central method is obligation-to-control traceability across the bank, rather than training on one specialist rule set.

The templates can be applied to a product change, control review, outsourcing assessment, audit finding or regulatory implementation project. Participants leave with a prioritised 90-day plan, so the course is structured around a defined workplace application rather than theoretical legal knowledge alone.

You will leave with completed examples of an obligation register, legal-risk assessment, control-testing sheet, breach-escalation record and regulatory change impact assessment. You will also produce a tailored action plan for a selected banking business area or compliance issue.

Upcoming sessions

  • 21 – 25 Sep 2026
    Cape Town · USD 4,200
    Book
  • 28 Sep – 02 Oct 2026
    Live Online · USD 1,500
    Book
  • 05 – 09 Oct 2026
    Nairobi · USD 3,000
    Book
  • 02 – 06 Nov 2026
    Cape Town · USD 4,200
    Book
  • 09 – 13 Nov 2026
    Live Online · USD 1,500
    Book
  • 16 – 20 Nov 2026
    Live Online · USD 1,500
    Book
  • 16 – 20 Nov 2026
    Cape Town · USD 4,200
    Book
  • 16 – 20 Nov 2026
    Dubai · USD 4,500
    Book

49 more dates — ask us.


Group of 5+?

Request in-house delivery or group rates →

Related courses in Legal

5 Days Certificate

Public Procurement Law and Tender Compliance for Procurement Managers Training Course

Public procurement managers operate where commercial urgency meets mandatory legal controls. A poorly drafted specification, inconsistent cl…

5 Days Certificate

IRAC Legal Analysis and Case Writing Skills Training Course

Legal professionals are often expected to turn a dense fact pattern, statute, contract clause, or court decision into advice that is concise…

5 Days Certificate

Employment Law Compliance for HR Managers Training Course

HR managers are expected to make employment decisions that are fair, timely, commercially sound and legally defensible. Yet recruitment shor…

5 Days Certificate

Clio Legal Practice Management Software Training Course

Legal teams lose time and create avoidable risk when matter details, client communications, time entries, documents, bills and trust transac…