Financial services

The same disclosure in nine filings, slightly out of step

Annual reports, prospectuses, factsheets, conduct disclosures, ESG narratives, submissions across two or three jurisdictions: the same statements appear in many places, often translated, often out of step. The regulator's question is which version was approved, by whom, and when.

A modern trading or analyst office: a single analyst at a multi-monitor workstation viewed from behind, a colleague walking past mid-distance, financial-district towers visible beyond the windows.
ApprovedComponent v3
68% Reuse rate
The structural problem

The document cannot be the source of truth

The same legal statement (a risk factor in a prospectus, an accounting policy in a 10-K, a fee schedule in a fund factsheet, a recovery-and-resolution paragraph in a DORA submission) lives in many documents at once, in many languages, on different publication cycles.

The cost of aligning them by hand is large and invisible: legal-review hours, translator queries, disclosure-team overtime, and the audit cost of reconstructing version history afterwards. The fix is one approved statement, used in many documents.

Regulatory landscape by region

A different supervisor in every jurisdiction. The same evidence burden

The frameworks differ on scope and prescription, but every major financial supervisor expects the same things: traceable content, an audit-grade approval record, and evidence that the disclosure published yesterday is materially the one approved last quarter.

North America

US · Canada
  • SEC, Securities and Exchange Commission. Annual and quarterly reports (Form 10-K / 10-Q), material-event reports (Form 8-K), prospectuses, proxy statements.
  • FINRA, broker-dealer supervision and communications-with-the-public rules.
  • SOX, Sarbanes-Oxley §302/§404 internal controls over financial reporting.
  • Dodd-Frank, post-2008 reforms including swaps reporting and resolution planning.
  • OCC, Fed, FDIC, federal banking supervision; state regulators add jurisdiction-specific overlays.

Western Europe

EU institutions · FR · BE · NL · IT · ES · PT
  • MiFID II / MiFIR, Markets in Financial Instruments Directive II and Regulation. Investor-protection disclosures, transaction reporting.
  • EMIR, European Market Infrastructure Regulation. Derivative trade reporting and central clearing.
  • DORA, Digital Operational Resilience Act (effective January 2025). ICT risk-management documentation expectations across all regulated financial entities.
  • CRD / CRR, capital requirements framework, with disclosure obligations under Pillar 3.
  • SFDR, Sustainable Finance Disclosure Regulation. Standardized ESG disclosures for financial-market participants.

DACH

Germany · Austria · Switzerland
  • BaFin, German Federal Financial Supervisory Authority. Comprehensive supervision of banking, insurance, and securities.
  • FINMA, Swiss Financial Market Supervisory Authority. Independent of EU framework with its own prudential rules.
  • KWG / WpHG, German Banking Act and Securities Trading Act.
  • FinSA / FinIA, Swiss Federal Act on Financial Services and Financial Institutions Act.

UK & Nordics

UK · DK · NO · SE · FI
  • FCA, UK Financial Conduct Authority. Conduct supervision, market integrity, consumer protection.
  • PRA, Prudential Regulation Authority (Bank of England). Capital and resilience supervision for banks and large insurers.
  • Finanstilsynet, Danish and Norwegian financial supervisory authorities (separate bodies sharing the name).
  • Finansinspektionen (SE) and Finanssivalvonta (FI), Swedish and Finnish supervisors. Coordinated through the Nordic supervisory cooperation framework.
How DitaExchange addresses it

One approved statement, many filings

Each approved disclosure paragraph (a risk factor, an accounting policy, a fee description, an ESG metric definition, a recovery-plan statement) becomes a component with its own identity, version and approval record.

What changesHow
The disclosure paragraph becomes the unit of management Each approved statement carries its own identity, version and approval record, independent of the filings that use it.
Filings are assembled, not re-derived Reports, prospectuses and factsheets are assembled from approved components using DITA content maps.
One risk-factor change reaches every supplement Approve the component once and every filing that references it refreshes. No nine-document sweep before submission.
The audit response becomes a query Change history is captured at the component level, so version history is retrieved rather than reconstructed after the fact.
Legal, compliance and accounting stay in Microsoft Word Counsel, compliance officers, accounting specialists and ESG analysts continue in Word. The DITA structure and reuse mechanics work behind the scenes.
In production

The disclosure types you already produce

Document types DitaExchange has handled in production with financial-services customers, each assembled from approved components rather than maintained as a finished file.

Annual and interim reports

10-K, 10-Q, half-year and full-year reports. Component reuse across legal-entity and group-level filings.

Prospectuses and supplements

Base prospectuses and the supplements that flow from them; one risk-factor change updates every supplement automatically.

Fund factsheets

KIDs, KIIDs, factsheets across fund ranges; standardized wording reused across hundreds of products with the per-fund variants applied at assembly time.

Conduct disclosures

MiFID II investor-protection content, structured for re-use across products and channels.

DORA documentation

ICT risk-management policies, register of information, incident reporting templates. Version-controlled, audit-traceable.

ESG and SFDR disclosures

Sustainability statements aligned across product, entity, and group filings.

The disclosure team stops being the human cache for which statement is current.

The same holds for the methodology and policy libraries behind those documents. One canonical component, referenced by every engagement, product and entity filing that needs it, profiled where a market genuinely differs rather than copied and edited. When the guidance changes, where-used reporting says which filings were reading the version you just replaced.

Disclosure content, under a fixed deadline

Prospectuses, policy documents and disclosures are assembled from language legal and compliance already cleared. Held as components, a cleared change reaches every document that uses it, with its approval record.

See what quality teams get
A financial-services working environment of the kind disclosure content is produced in
In production with

LSEG

London Stock Exchange Group, global financial-markets infrastructure. Documentation across regulatory, market-data, and post-trade businesses.

Frequently asked questions

DORA has applied since January 2025. What does a supervisor actually ask a firm to produce?

The ICT risk-management policies, the register of information and the incident-reporting procedures, as they stood when they mattered. That is a records question before it is a writing question. Policy text carrying its own version and approval date can be produced for a given date. Policy text whose history lives in mailboxes and file properties has to be reconstructed, and reconstruction is what a supervisor reads as weak control.

The same disclosure has to read differently for the FCA and BaFin. Can one approved source carry both?

Yes, when the variation is expressed as a condition on one component rather than as a second copy of it. The jurisdiction-specific wording is profiled at publication, so the shared text stays single-sourced and only the variant clause differs. The failure mode a copy creates is a quiet one: someone updates the German version, the UK version stays behind, and nobody sees it until a review.

Legal, compliance, product and accounting all touch the same paragraph. Who owns it?

One of them, on the component, rather than all of them on a document. Ownership and approval sit on the paragraph itself, so the person accountable for a fee description is not negotiating with the person accountable for the risk factor in the same file. Reviewers work where they already work, in Word or the SharePoint library, and the approval is recorded against the component they cleared.

Our figures come out of the consolidation system. Does a content platform touch them?

No, and it should not. The numbers stay in the systems that own them and are audited there. What a component model manages is the narrative around them: the accounting policy, the risk factor, the ESG metric definition, the recovery-plan statement. The seam between the two layers is where most reporting errors live, so keep each layer in the system that can evidence it.

Our disclosure estate is one annual report and a handful of policies. Do we need a CCMS?

Probably not. A document management system with real editorial discipline absorbs most of what a CCMS does, and it keeps doing so until approved wording appears in many places at once, the content is translated, or approval has to be provable at paragraph level. Where none of those hold, the tooling and process cost outruns the benefit. Better to hear that now than in month three.

Start with the disclosure that costs the most to keep aligned

Most implementations begin with one document family where the cost of inconsistency is visible: a prospectus suite, a fund-factsheet range, a DORA submission. The model compounds from there.