← Back to Insights

Agile in a Regulated World: Balancing Scrum with BSA/AML and GxP Compliance

Agile promises speed. Regulated industries demand control. On paper, those sound like opposing forces — and for a long time, I treated them that way, running Scrum ceremonies in one track and compliance checkpoints in another, hoping the two would meet somewhere before go-live.

They don’t meet on their own. You have to design them to.

In banking, that meant treating BSA/AML, KYC, and SAR requirements not as a final gate before release, but as acceptance criteria baked into the backlog itself. A user story wasn’t “done” when the feature worked — it was done when the control tied to that feature could be evidenced, tested, and traced back to the requirement that created it. That single shift, moving compliance language into the definition of done, is what let sprints stay sprints instead of turning into two-week feature builds followed by a six-week audit scramble.

In pharma, the same principle applies to GxP and validation standards, just with a different vocabulary. Model lifecycle workflows, data lineage, and validation evidence all need to exist somewhere durable and reviewable — and the teams that fight this hardest are usually the ones trying to bolt documentation on after the sprint closes. It’s far cheaper, and far less painful, to generate that documentation as a byproduct of the same tools the team already uses to track delivery — Jira tickets that double as change records, Confluence pages that double as validation artifacts.

The other lesson, harder to systematize but just as important: bring Compliance, Risk, and QA into the ceremonies themselves, not just the sign-off at the end. When a compliance SME sits in sprint planning and can flag a control gap while the story is still being scoped, that’s a five-minute conversation. When the same gap surfaces during UAT, it’s a re-opened sprint, a missed release date, and a much less five-minute conversation with stakeholders.

None of this means slowing Agile down to match the pace of compliance. It means recognizing that in regulated environments, “working software” was never the whole definition of done — it just took some environments longer to admit it. Once a team designs its ceremonies, its Jira workflow, and its Definition of Done around that reality, Scrum and regulation stop being opposing forces and start being the same conversation, held once, instead of twice.