Most institutions running card network (scheme) compliance describe themselves as organized. Fewer are, and the gap has a cost attached.
There are three ways to run the same job. The useful question isn't which one you're in. It's the distance to the next one, because that's where the cost sits.
Reactive. Bulletins pulled from network portals by hand, tracked in a spreadsheet, distributed by email. Resilience rests on two or three people who happen to know things. It's the industry default, and it works right up until a deadline slips or a fee change lands unnoticed. Then it takes weeks to reconstruct what happened.
Managed. One place where every bulletin is captured, an owner assigned to each item, and a record of what was decided and why. This is mostly a structural change, not a technology one. Deadlines stop depending on someone's memory.
Strategic. Relevant announcements are surfaced and routed automatically, so the team spends its time prioritizing instead of processing. Leadership sees exposure live instead of reconstructing it after something goes wrong, and IT, product and finance get early warning rather than a deadline.
Most institutions sit in the first and describe themselves as the second.
Few could say for sure, because few measure it. Thomson Reuters found that 45% of financial services organizations don't formally track the total cost of compliance across the firm.
Part of the reason is that the cost is spread across budgets nobody looks at together: compliance headcount, engineering time pulled onto late mandates, and fees nobody chose to pay.
One question to put to your team this week. If a mandate slipped today, how long would it take us to notice, and who would be accountable?
If the answer takes more than a sentence, you have your answer.
From a briefing I've written with Rivero on what network compliance actually costs here.