Overlapping supervisory expectations, a permanent audit cycle, and evidence gathered by hand every quarter.
A regulated financial institution in the region is rarely answering to one regime. Central bank supervision runs continuously, a national assurance standard applies in parallel, an international certification is demanded by counterparties, and a privacy law sits underneath all of it. Each of these asks similar questions in a different vocabulary, and most institutions answer them separately, which is why the audit crunch never actually ends.
One control baseline, assessed once, expressed against each regime that applies. Where a mapping between two frameworks genuinely exists, evidence gathered for one supports the other, which removes the duplicated collection that consumes most of the quarter. Where a mapping does not exist, we say so rather than implying reuse.
Treating supervision as an examination to pass. A central bank is a continuing supervisor rather than a one-time examiner, so evidence that a control operated every month matters more than evidence that it exists today. Programmes built for an audit date tend to fail the second year.