by Liam King, Haast co-founder
Risk management in highly regulated business runs on three lines of defense.
First line. Marketing or the agency that drafts content for them. The people who create the risk; they own it and check their own work.
Second line. Legal and compliance. They set the rules and oversee the first line. In bigger organizations, it's several layers: brand review, legal, compliance.
Third line. Audit. They check that the first two lines actually work. This is often a continuous improvement function, or a dedicated function taking on tasks like spot checks.
Banks run credit risk this way, insurers run underwriting this way. But marketing compliance has never worked this way, because it relied on goodwill: marketers proactive enough to ask before shipping, and compliance people going out of their way to educate, running training sessions and building guidance packs nobody budgeted for.
Unfortunately, goodwill doesn't scale, and a marketer can't hold fifty unwritten rules in their head. Content drafts went directly to legal and the second line of defense did everything: found the problems, wrote the markup, chased the fixes, carried the whole load. The first line created risk; the second line managed it.
That inversion is why sign-off took two weeks. And two weeks in an understatement: 13 days is the median for a single asset's first pass through approval when customers onboard the Haast AI marketing compliance platform. This time frame excludes rework rounds, agency back-and-forth and campaign assembly. Industry practitioners usually put the full idea-to-launch cycle for a regulated campaign at two to three months, and the published benchmarks make that credible: McKinsey's agile-marketing research found traditional organizations take "multiple weeks or even months" to move an idea into market, and at one international bank, a single email test took eight weeks to clear the process.
The first-draft load the second line was carrying is measurable. Haast platform data shows that the average marketing document contains 9 to 14 compliance issues when it's first written.
Format | Arrive with a red flag | Average issues per asset |
|---|---|---|
Word documents | 81% | 13.8 |
PDFs | 69% | 9.1 |
Video | 62% | 5.5 |
Static images | 38% | 1.8 |
Table 1. First-draft compliance risk by format. Source: Haast platform data, Aug 2026.
Nearly half of these flags are either fine print (22% of categorized flags), or a claim that can't be backed up (another 22%).
Through our work with highly regulated and complex businesses, we’ve found that when you give the first line real tools, the load shifts back to where it belongs. The review happens at the marketer's desk, while the draft is still open, instead of at a gate two weeks downstream. This is a significant shift, and a deeper dive into our data proves it out.
How does marketing compliance improve with the right platform?
The first line of defense starts working in earnest when marketers check their own work.
Every asset on the Haast platform goes through one of two doors: a formal review queue where a compliance reviewer signs off, or a self-serve check the creator runs on their own draft, in minutes, with no reviewer involved.
Two years ago the self-serve door barely existed. Today, 86 of every 100 uploads in our Australian customer base are self-checked by the marketer before compliance sees anything. In the UK, this data point went from 36/100 to 95/100 in a single year (Haast platform data).
Self-checking means self-fixing
Marketers clear roughly 15% of red flags themselves before a reviewer ever opens the file, and 83% of assets now arrive at compliance clean on the first version. When something is flagged, the median gap from flag to fix is 21.7 hours, because the feedback lands while the marketer is still in the document, not three iterations later.
Across customers operating in 2025 and 2026, red flags fell from 45% of first-upload checks to 13%. What this means: Two out of three compliance issues disappear from first drafts within a customer's first year.
The effect also extends to agencies. An agency runs the check on its own work before submitting a clean draft, and a whole review loop between agency, marketing team, and legal never needs to happen.

The check should live where the work happens
Self-serve checking only gets consistently done if nobody has to leave their tools to do it. That's an integration question, on two fronts. Creators check drafts inside the places they write and design: Google Drive, Microsoft Office, Notion, Figma. And the company keeps its workflow where it already runs, with review connected to platforms like monday.com and Adobe Workfront. The check comes to them; nobody learns a new system to do the right thing.
In-tool iteration changes what gets made, too. The marketer refines the draft against the rules as they write, producing world-class compliant content, rather than retrofitting world-class content into compliance – often having lost the creativity that made it work.
Habits change along with the numbers. We can see in our data that the average Flesch readability scores of reviewed content rose nine points in a year, from college-level toward plain English. Greenwashing checks now pass 94% of the time, up from 75%. Unsurprisingly, the most stubborn habit is jargon, still failing 23% of checks: marketers fixed their taglines and copyright lines, but they still write like lawyers.
The content itself is getting harder to review
The first line adopting tools is only half the story. The other half is the content: marketing output is shifting to formats that are both slower to review and multiplying faster than review teams can grow.
Haast data shows that video's share of compliance review more than doubled in a year, from 7.3% of assets to 17.6%, and 2026 passed 2025's full-year video volume by mid-August: 1,064 assets against 532, tracking to roughly triple. (Some of those videos run longer than three hours!)
Video breaks manual review in a way documents never did. A reviewer can skim a page; a video plays in real time, and every claim, caption, and disclaimer has to be caught on screen and on the voice track. It arrives dirty, too, flagged 62% of the time at 5.5 issues per asset.
Personalization platforms compound it: Tools like Adobe, Braze, and Salesforce ship every campaign as dozens of tailored variants, each one technically a new asset, on top of the short-form volume produced for feeds and answer engines. The content needing a check is accelerating well past the rate any legal team is growing.

What should legal do with the time it gets back?
When marketing catches its own problems, legal reviews faster. Among Haast customers, median sign-off fell from 13 days to 3.2 in nine months. That 3.2 days is the asset's whole journey through approval: Everything from the moment the marketer submits it to when a reviewer signs it off under the automated checks. The campaign's idea-to-market cycle is a different, wider measure, but sign-off is usually the part marketing can't compress on its own.
Speed here is worth real money. McKinsey's research on agile marketing measures the wider cycle and finds organizations that move an idea to market in under two weeks instead of months see revenue uplifts of 20 to 40%, with product lines run this way growing up to four times faster. Two weeks of sign-off per asset makes a two-week cycle impossible on its own; a 3.2-day approval step leaves room for everything else.
Still, speed is the small prize. The real question is what legal and compliance do with the hours they used to spend proofreading banner ads.
First: Write the rulebook down
The answer in the data: they use the time to build structures. The average Haast customer encodes 57 distinct compliance rules in their first 90 days, and 37% of all the rules a customer ever writes get written in that window.
Implementation surfaces the unspoken work: the guidelines nobody wrote down, checks different reviewers carried in their heads. The checklist keeps growing after that, from 34 automated checks per asset a year ago to 56 now. One enterprise customer now runs 18 times more checks per quarter than when they started, and their reviews take no longer than they did on day one.
Second: Build the risk-based review framework regulators are inviting
The other structure worth the strategic hours is a risk-based review framework, and regulators are inviting it. In the US, FINRA's proposed change to Rule 2210 (Regulatory Notice 26-14) would replace blanket pre-approval of retail communications with risk-based supervision: firms decide what needs principal review before publication and what can be surveilled after, weighed on factors like product complexity and who wrote the content.
In Australia, the signal points the same way. ASIC's first review of AI adoption by licensees (Report 798) found AI use "focussed predominantly on supporting human decisions and improving efficiencies,” said AI could bring significant benefits, and confirmed the existing technology-neutral obligations govern it rather than new rules. ASIC is also reviewing RG 234, its advertising guidance, with digital and social content in its sights. The message: use the technology, keep humans accountable, and be able to show your governance.
We're seeing the same direction across jurisdictions and markets: regulators will let firms review proportionately if they can prove the process works, with documented rules, trained creators and a complete audit trail. A second line of defense that spends its time building that framework buys marketing speed and the firm defensibility.
Third: Audit gets evidence instead of samples
The audit's job is to test whether the first two lines of defense actually work. Traditionally that means pulling a sample of campaigns and hoping the sample is representative. A checked pipeline enabled by solutions like Haast gives audit the firm's own complete record instead: every asset it submitted, every flag, every fix, every sign-off timestamped, with who approved what and when. No sampling required because audit slices the full log by review route (self-serve check versus formal queue), by medium (documents against the video that used to skip review), by product line, by team or agency, and reads the failure rate in every cut.
Across the 400,000+ checks on the Haast platform, reviewers accept 98.7% of AI checks unchanged. In two years, humans caught 127 issues the AI had passed, against roughly 90,000 flags the AI raised. 96% of overrides are a human dismissing a flag as too strict: when the system errs, it errs cautious. That's the evidence a risk-based framework needs behind it.
Finally: The log becomes the curriculum
The same record fixes the education problem from the goodwill era, when training was whatever compliance could improvise sans budget. The log shows exactly which rules each part of the business trips over: one team's flags are all jargon, an agency keeps missing disclaimers, a product line leans on claims it can't substantiate.
That turns generic annual compliance training into a custom education system. Each team learns the rules it actually breaks, illustrated with its own flagged drafts, and the next quarter's flag rates showing whether the lesson landed.
The compounding loop: each line of defense strengthens the others
The three lines compound and strengthen each other's success, which is why the numbers improve together rather than one at a time. More content through the platform surfaces more rules. More rules mean fewer first-draft mistakes. Fewer mistakes mean faster sign-off. And faster sign-off brings more content: once checking costs minutes, marketers check everything, including the video that used to skip review entirely.
In the Haast data, we can see that Individual customers grew their checked volume between 2x and 10x year on year, and monthly active uploads rose sixfold on a roughly flat customer count. Then the loop starts again.
What the org chart looks like after
First line: Marketers and agencies check and fix their own work before anyone else sees it.
Second line: Legal and compliance review the residual risk in days, and spend the recovered time encoding the rulebook and building the risk-based framework their regulator is asking for.
Third line: Audit reads the log. Each line finally does the job the theory always said it should.
The rulebook legal is freed up to build is now the moat: Customers have written more than 13,000 distinct compliance rules between them, and no two rulebooks look alike, because every brand encodes its own interpretation of the same regulations plus its own tone, taglines, and no-go zones. There is no such thing as "the" compliance rulebook, which is why generic checkers produce generic false positives, and why the rulebook a team writes in its first year is one its competitors can't copy.
The two-week sign-off was the output of a broken operating model, not a law of nature. The three lines of defense were always the right structure. The first line was just waiting for the right tool.
To build a stronger first line of defense, book a product tour.
Liam King combines deep technical expertise with practical industry experience to lead Haast's tech vision. With a background in mathematics, statistics and advanced machine learning, Liam has led large-scale IT transformation projects at Deloitte and excelled in programming at the Australian National University.
Sources
Haast platform data: 400,000+ automated compliance checks across Australian, US and UK customers, two years to August 2026 (Product Stats dataset). All red-flag, sign-off, self-serve, rule-count and format figures come from this dataset. The 13-day and 3.2-day figures are per-asset submission-to-sign-off medians on the platform.
McKinsey & Company, "Agile marketing: A step-by-step guide" — idea-to-market speed and revenue-uplift benchmarks (a different, wider measure than per-asset sign-off), and the source for "multiple weeks or even months" and the eight-week bank email test.
FINRA Regulatory Notice 26-14, via Haast's explainer: FINRA Rule 2210 risk-based review.
ASIC, media release 24-238MR and Report 798, "Beware the gap: governance arrangements in the face of AI innovation" (29 October 2024) — ASIC's first review of AI adoption by licensees.
MFAA, "What brokers need to know as ASIC updates RG 234" — status of ASIC's review of its advertising guidance.
Liam King


