The problem starts at the second level of complexity.
Take this example. A mandate restricts holdings in companies that derive more than 10% of revenue from coal extraction, with the revenue figure sourced from a specific ESG data provider, refreshed quarterly, and applied at the ultimate parent level. This is a single rule, but it touches a custom data feed, a revenue percentage calculation with a threshold, a parent issuer/ultimate parent rollup, and a temporal dimension.
In most compliance platforms, the first three of those are configurable in the UI but the fourth requires a developer. At the very least the quarterly refresh of data requires a data pipeline that the compliance team has no bandwidth to set up let alone maintain. The compliance team will need to raise a ticket with IT, wait for it to get picked up and set up and a few weeks later the rule can go live. In the meantime the mandate manager has been operating in spreadsheet-and-best-judgement and the audit trail is spotty at best.
The pattern repeats across asset classes. A swap rule needs the system to handle notional aggregation across cleared and bilateral exposures. For loans, the rule needs to distinguish a borrower from a sponsor. Overlay rules add the requirement that derivatives be valued consistently with the underlying being hedged. Each of these is a real mandate constraint that sits one layer beyond the standard rule library.
The marketing for "no-code compliance" implicitly defines compliance as the standard rule library. That definition is convenient for the vendor and inadequate for the firm and out of touch with actual investment mandates. A compliance platform that handles 80% of rules without a developer and the other 20% only with one is not a no-code platform, it's a partial-code platform with good sales teams.
The tools moving in the right direction share a few characteristics:
No-code sounds so appealing to the sourcing department at any firm, because everyone knows that the compliance team that owns rule definition is also the team that has the deepest understanding of the mandate, closely followed by the portfolio management team. When compliance and PM teams, who understand the mandate, have to wait for an engineering build cycle to express a rule, a lot of time is wasted; development becomes the bottleneck for compliance. An additional side effect is that the rule gets simplified to fit the existing framework and aspects may be lost in translation.
The firms that have got this right have stopped treating compliance configuration as an IT project. The compliance team owns the rules, the data team owns the data feeds, and the platform sits in between with enough flexibility that the two can meet without an engineering ticket. The firms that have not got this right are usually three audit cycles away from realising they need to.