Skip to main content
The state of ai impact assessment
Category: Regulatory Obligations Management

Regulatory Correspondence

Also known as: Controlled Correspondence
Simply put

Regulatory correspondence refers to written communications exchanged between an organization and a regulatory authority, or communications an organization distributes that fall under regulatory rules. These exchanges often document questions, commitments, and expectations, and can later become the basis for audit inquiries. Because such records can carry compliance significance, organizations frequently track and manage them carefully.

Formal definition

Regulatory correspondence encompasses written communications (including electronic) that are subject to regulatory requirements or exchanged with a supervisory authority, though its precise meaning is context- and jurisdiction-specific. In some securities contexts, 'correspondence' is defined narrowly by reference to distribution thresholds; for example, one exhibit filed in connection with a self-regulatory organization rule defines 'correspondence' as any written (including electronic) communication distributed or made available to 25 or fewer retail investors within a 30-day period. In the pharmaceutical sector, the term commonly denotes 'controlled correspondence,' a structured route of communication between the FDA and the generic-drug industry used to facilitate generic-drug development, governed by applicable FDA guidance. Practitioners often treat correspondence as a control-relevant record because it can establish regulatory expectations and commitments and serve as a starting point for audit questions; effective tracking and management are widely regarded as leading practice rather than a single uniform obligation. Applicability, definitions, and thresholds vary by regulator, sector, and jurisdiction, and specific requirements should be verified against the governing primary source.

Why it matters

Regulatory correspondence often functions as a durable record of the specific expectations a regulator has communicated and the commitments an organization has made in return. Because these written exchanges can establish where regulatory expectations are set and where commitments are documented, they frequently become the starting point for later audit questions and supervisory inquiries. Treating correspondence casually can therefore create compliance exposure that only becomes apparent when a regulator revisits an earlier exchange.

The stakes are heightened by the fact that correspondence records are commonly relied upon during examinations and audits. Where such records are misplaced or poorly tracked, an organization may struggle to demonstrate what was asked, what was promised, and what was ultimately done, which can complicate its ability to evidence compliance. For this reason, a well-organized tracking system is often described as a team's best defense against these challenges, particularly in heavily regulated sectors such as pharmaceuticals.

It is important to note that the significance and precise definition of regulatory correspondence vary by regulator, sector, and jurisdiction. In some securities contexts the term is defined narrowly by reference to distribution thresholds, while in the pharmaceutical sector it commonly refers to a structured 'controlled correspondence' channel. Organizations should confirm which meaning and requirements apply to their circumstances against the governing primary source, as robust tracking is widely regarded as leading practice rather than a single uniform legal obligation.

Who it's relevant to

Compliance officers
Compliance teams rely on accurate correspondence records to demonstrate what regulators have asked, what the organization has committed to, and how those commitments were met. Because correspondence is often where audit questions begin, maintaining organized and retrievable records supports the ability to evidence compliance during examinations.
Regulatory affairs professionals in pharmaceuticals
For teams working on generic-drug development, controlled correspondence is a crucial route of communication with the FDA governed by applicable guidance. Tracking these exchanges carefully is widely regarded as a best practice, helping teams avoid misplaced or poorly documented communications that could undermine development activities.
Securities and investor communications teams
In some securities contexts, whether a communication qualifies as 'correspondence' can depend on distribution thresholds, such as being distributed or made available to a limited number of retail investors within a defined period. These teams should confirm the applicable definitions and thresholds against the governing rule, as they influence how communications are classified and handled.
Internal auditors
Auditors frequently use correspondence as a starting point for inquiries, since it can document the regulatory expectations and commitments an organization is accountable for. Reliable tracking and retention of these records support the audit process and help establish what was agreed with regulators.
General counsel and legal teams
Because regulatory correspondence can carry compliance significance and reflect binding commitments, legal teams have an interest in ensuring exchanges are managed carefully. They can also advise on jurisdiction- and sector-specific definitions and requirements, which vary and may require professional interpretation against primary sources.

Inside Regulatory Correspondence

Inbound Regulatory Communications
Written or electronic communications received from regulators, supervisory authorities, or oversight bodies, which may include information requests, examination findings, inquiries, notices, warning letters, or formal orders. The nature and legal weight of these communications vary by jurisdiction and regulator.
Outbound Responses and Submissions
Communications directed from the organization to a regulator, such as responses to inquiries, remediation plans, self-disclosures, filings, and requests for clarification or guidance. These often carry compliance obligations and, in many contexts, may be relied upon by the regulator.
Metadata and Tracking Attributes
Contextual details typically captured for each item, such as the originating or receiving regulator, date of receipt, applicable deadlines, subject matter, responsible owner, and current status. These attributes support accountability and timely handling.
Deadlines and Response Obligations
Time-bound requirements associated with a communication, which may be legally binding or set by the regulator's request. Missing such deadlines can, depending on jurisdiction and severity, carry regulatory consequences that should be verified against the specific obligation.
Records Retention and Audit Trail
The retained record of correspondence and related actions, supporting demonstrable evidence of how the organization received, evaluated, and responded to regulatory contact. Retention periods and format requirements vary by jurisdiction, sector, and internal policy.
Ownership and Escalation Assignment
The designation of accountable individuals or functions (often compliance, legal, or a designated liaison) responsible for handling, escalating, and closing out a given correspondence item, reflecting the governance dimension of decision rights and roles.

Common questions

Answers to the questions practitioners most commonly ask about Regulatory Correspondence.

Is regulatory correspondence limited to formal enforcement letters or notices?
No. While enforcement letters and formal notices are a prominent category, regulatory correspondence typically encompasses a much broader range of communications exchanged between an organization and a regulator. This often includes routine information requests, acknowledgments, filing confirmations, guidance responses, examination-related communications, and clarifying exchanges. Treating only enforcement-related items as regulatory correspondence risks under-scoping recordkeeping and monitoring practices. The precise boundaries of what an organization treats as regulatory correspondence can vary by internal policy, sector, and jurisdiction, so scope should be defined explicitly.
Does managing regulatory correspondence fall solely within the compliance function?
Not necessarily. Although compliance often coordinates or oversees regulatory correspondence, the activity commonly spans more than one governance pillar. Governance concerns the roles and decision rights that determine who is authorized to respond to a regulator, while compliance concerns adherence to applicable obligations reflected in that correspondence. Legal counsel, risk management, and business units may also be involved. Attributing the entire process to compliance alone can obscure important questions of authority, escalation, and accountability that are properly governance matters.
Who should be authorized to respond to a regulator on the organization's behalf?
This is typically a governance question resolved through defined roles and decision rights rather than a fixed rule. Many organizations designate specific individuals or functions, often within compliance, legal, or a regulatory relations team, as authorized points of contact, with escalation paths for significant matters. The appropriate arrangement depends on organizational structure, sector, and applicable requirements. Documenting authorization and escalation expectations in policy helps reduce the risk of inconsistent or unauthorized responses, though the specifics should be tailored to the organization's context.
How should regulatory correspondence be recorded and retained?
Practices commonly include capturing both inbound and outbound communications in a defined system or repository, with associated metadata such as date, regulator, subject, and responsible owner. Retention periods are often driven by applicable legal and regulatory requirements, which vary by jurisdiction and sector, as well as by internal recordkeeping policy. Because retention obligations and any applicable privilege considerations depend on the governing rules, organizations should confirm specific retention periods and handling requirements against the relevant primary sources and, where appropriate, legal advice.
How can an organization track deadlines and required actions arising from regulatory correspondence?
Organizations frequently use tracking mechanisms, ranging from logs to dedicated workflow tools, to record response deadlines, assigned owners, and completion status. Common practices include flagging correspondence that requires action, setting reminders ahead of due dates, and defining escalation triggers for approaching or missed deadlines. The aim is to reduce the risk of nonresponse or late response. The suitability of any particular approach depends on volume, complexity, and available resources, and no tracking process should be assumed to eliminate the risk of missed obligations.
How does regulatory correspondence connect to broader compliance and risk monitoring?
Regulatory correspondence can serve as a source of information for compliance monitoring and risk assessment, for example by signaling regulator concerns, emerging expectations, or areas warranting remediation. Some organizations analyze patterns across correspondence to identify recurring themes that may inform control improvements or risk treatment. How this integration is structured varies by organization, and any conclusions drawn from correspondence should be validated through appropriate assessment rather than treated as definitive on their own.

Common misconceptions

Regulatory correspondence is purely an administrative or clerical task.
While it involves logging and tracking, the handling of regulatory correspondence often spans governance (who has decision rights and accountability), compliance (meeting binding obligations and deadlines), and, at times, legal interpretation. Misjudging the significance or legal weight of a communication can have consequences, and certain items may warrant professional legal advice.
All regulatory correspondence carries the same legal weight and urgency.
Communications range from routine informational notices to formal orders or warning letters, and their legal effect, response obligations, and associated deadlines vary considerably by jurisdiction, regulator, and the nature of the item. Each communication typically needs to be assessed on its own terms rather than treated uniformly.
Once a response is submitted, the correspondence is closed and no further action is needed.
Responses often create ongoing obligations, such as remediation commitments or follow-up submissions, and may be relied upon by the regulator. Maintaining the record, tracking outstanding commitments, and monitoring for regulator follow-up are frequently part of proper handling.

Best practices

Maintain a centralized register that logs each item of regulatory correspondence with its source, receipt date, subject, assigned owner, applicable deadline, and current status to support accountability and timely handling.
Assign clear ownership and defined escalation paths so that each communication reaches the appropriate function, such as compliance, legal, or a designated regulatory liaison, based on its significance and any legal implications.
Assess each communication individually to determine its legal weight and response obligations, and seek professional legal advice where the interpretation of an obligation is uncertain or context-dependent.
Track deadlines and outstanding commitments actively, including follow-up submissions and remediation actions arising from responses, rather than treating a submitted response as final closure.
Retain a complete and defensible audit trail of correspondence and related actions in line with applicable retention requirements, recognizing that retention periods and format expectations vary by jurisdiction, sector, and internal policy.
Periodically review the correspondence-handling process against relevant governance and compliance expectations, and verify specific deadlines, requirements, and consequences against the primary regulatory source.
Promotional banner for the Penetration Report Template Kit