By Appbay Technologies
A new CEO’s early initiatives get judged on speed as much as results.
A bank has recently welcomed new leadership, tasked with driving strategic growth while strengthening institutional stability. But under a retail Islamic banking licence, every growth initiative still clears Sharia review, then risk review – not both at once.
That sequencing quietly doubles the timeline right when new leadership’s early wins are under the closest scrutiny.
The Priority: Growth With Discipline, Under New Leadership
Driving strategic growth while maintaining financial discipline is a genuinely reasonable mandate for new leadership to carry. It signals ambition balanced with prudence-exactly what a board wants to see from a new CEO’s opening chapter.
But new leadership typically means a fresh strategic review, and any transformation initiatives launched under a new CEO get closer, faster scrutiny than those inherited from a predecessor. There’s an implicit “prove it early” pressure baked into the moment-and that pressure runs headlong into a structural reality the bank’s own licence creates.
The Hidden Problem: Two Reviews, One After Another
Here’s where the operational strain actually shows up, inside most Islamic banks running this structure:
- Two reviews, one after another-every growth initiative clears Sharia compliance, then standard risk review, never both at once
- Growth timeline stretched twice over-sequencing effectively doubles the time-to-launch for every initiative
- Two functions, no shared workflow-Sharia compliance and risk review operate independently, with no coordinated process connecting them
- Early initiatives, closest scrutiny-this sequencing tax lands hardest on exactly the initiatives new leadership needs to move fastest
Why does this exist? Operating under a retail Islamic banking licence means every growth initiative needs Sharia-compliance review layered on top of standard risk review-that’s a licensing fact, not an inference. Left unstreamlined, that dual-review requirement slows the “balance growth with discipline” commitment considerably, precisely because the two reviews run sequentially instead of together.
Why This Matters Now
New leadership, the licence-driven compliance requirement, and the growth ambition are all named, current, board-level facts. This isn’t a hypothetical process improvement-it’s the exact tension sitting under the bank’s own stated priorities right now.
The board’s question isn’t whether an initiative is Sharia-compliant and low-risk. It’s sharper than that:
“Why did it take twice as long to launch as it should have-when both reviews could have run at the same time?”
For the Head of Sharia Compliance or CRO, this plays out as a live, board-visible timeline problem, measured against concrete metrics:
- Time-to-launch per initiative-how long does each growth initiative actually take to clear both reviews?
- Dual-review completion rate-are both reviews finishing on a pace the board can actually see progress against?
- Growth pace vs mandate-is the bank’s growth speed matching what new leadership was brought in to deliver?
A new CEO’s early wins are judged on speed as much as results-and a sequential review process is often the quiet reason speed falls short of expectations.
The Fix: Run Both Reviews at Once, Not One After the Other
The instinct when growth needs to move faster is often to pressure one review or the other to move quicker on its own-cutting corners on depth to save time. That approach trades review quality for speed, which is exactly the wrong trade under a licence that requires both reviews to hold up on their own merits.
The better path uses Appbay’s Master Compliance Copilot, extended into a parallel-track review workflow that runs Sharia and standard risk review concurrently, rather than sequentially.
The core capability-extract, compare against policy, flag gaps-applies directly to Sharia criteria. The genuine addition is architecting the workflow so both reviews actually run in parallel, not one after the other.
1. Growth Initiative Documentation Ingestion
One intake point feeds both review tracks simultaneously-no waiting for one function to finish before the other starts.
2. AI-Driven Parallel Extraction
Sharia criteria and standard risk policy are assessed at the same time, side by side, not in sequence.
3. Gap Flagging, Both Tracks
Issues are surfaced from either review as soon as they’re found-not discovered only after the first review finally wraps up.
4. Dual Sign-Off
Both compliance functions approve independently, without waiting on each other’s timeline.
5. Appian-Orchestrated Workflow
One coordinated process manages both tracks to completion, keeping them genuinely synchronized rather than loosely parallel.
6. Audit Trail
Every decision from both reviews is traceable, CBB-ready from day one.
This turns “twice the review time” into “the same review depth, running at once-without cutting either review short.
Proof, Not a Full Compliance Restructure
- 8-12 week proof of concept-scoped to one growth initiative’s dual-review process
- AI-driven parallel extraction-assessing both Sharia and risk criteria from day one, side by side
- Human sign-off retained from both functions-automation speeds the extraction, people still make the final call
- Appian-orchestrated audit trail-one defensible record covering both review tracks
- Time-to-launch visibility-a concrete, board-reportable metric proving the timeline has actually shortened
This isn’t a full compliance function restructure. It’s a fast, scoped proof that both reviews can run at once – on one initiative – before it becomes the standard process.
This Pattern Isn’t Unique to One Bank
Any Islamic banking institution operating under a retail licence, especially under new leadership with a visible growth mandate, will face this same structural tax: two necessary reviews, running sequentially, quietly doubling every initiative’s timeline. The banks getting ahead of this aren’t cutting either review short to move faster. They’re running both at once.
Let’s Compare Notes
We’re working with Islamic banks across the GCC on exactly this-growth speed without cutting either review short. If your organization is navigating a similar dual-review structure, we’d welcome the conversation.
Send us a message to discuss your compliance review workflow.


