Key Challenges in RegTech Adoption for Financial Institutions

Five financial institutions know how much misconduct costs like no other. Bank of America, JP Morgan Chase, Morgan Stanley, RBS, and Lloyds Banking Group altogether paid close to $200 billion in fines in four years (2012 to 2016). In the same period, the cost of misconduct for the 20 largest global banks hit $359 billion, signifying a 32% growth over the same cost in 2008-2012.

Over decades of operations and fine payouts, it became apparent that existing compliance practices cannot effectively dodge the bullet, no matter how much is invested in the legal/compliance departments. In fact, on average, financial institutions have 10–15% of their staff dedicated to compliance, but billions are still paid for missteps. Globally, around $80 billion is spent on governance, risk & compliance, and the market is only expected to grow, reaching $120 billion in the next four years.

Over time, the regulatory environments get even more complex – over 300 million pages of regulatory documents will be published by 2020. In addition, over 600 legislative initiatives need to be cataloged by a medium-sized sell-side institution to have a holistic view of their rulebook.

Compliance costs for financial institutions amount to substantial parts of total expenses, with a negative correlation between the size of the institution and the percentage of total costs. While banks with assets ranging from $1 billion to $10 billion reported total compliance costs averaging 2.9% of their non-interest expenses, banks with less than $100 million in assets reported costs averaging 8.7% of their non-interest expenses.

Despite obvious obsolescence of the existing approach to compliance, emerging technologies, and ecosystems – there is a wide variety of RegTech startups building next-gen solutions – there is work to be done by all parties to accelerate the adoption of more efficient systems. That requires standardization of data, recording, storage & management systems, cooperation between jurisdictions on regulatory environments, and standardization of requirements for IT infrastructure and its updates.

Furthermore, we will review some of the key challenges institutions face, regulators, and the ones coming from the tech ecosystem that inhibit the adoption of advanced solutions to a highly complex and inefficient approach to how diverse ecosystems tackle compliance.

Augmentation of fraud monitoring systems

Current AML procedures and fraud monitoring systems are as disparate as compliance reporting. Professionals suggest that coordinated or centralized surveillance could significantly improve efficiency and effectiveness in recognizing suspicious trades.

“Progress in this area will require the authorities to address current obstacles to the sharing of suspicious transaction reporting (STR) customer information and other information that would be useful to more effective AML, CTF, and sanctions compliance.

“There is a need for more industry collaboration on analytics to identify and report suspicious transactions for AML/CTF and sanctions compliance, and for an improvement in pattern recognition across institutions.” – IIF.

Data privacy requirements

Confidentiality of data mounts above regulatory reporting, imposing significant hurdles in adopting new technologies and solutions. Changing reporting mechanisms institution-wide (and industry-wide) largely depends on how it affects data privacy.

With any compliance solution, financial institutions must prioritize protecting the confidentiality of clients’ data and ensure security when transferring that data.

According to IIF, legislations and regulations on data are essential to protect the privacy of individuals and assure the appropriate use of sensitive or personal information. At the same time, restrictions on the ability to use data across national borders may impact the ability of financial institutions to rely on big data or advanced analytics solutions.

“Policymakers should continuously reassess the impacts of technological developments on data security and privacy, ensuring that regulations strike an appropriate balance between protecting privacy and security and effective data use. In addition, removing the existing legal and regulatory impediments to the sharing and using data for regulatory purposes should be a priority.”

Disparity of data management standards

According to the Institute of International Finance, a lack of data standardization and harmonized definitions of key reporting concepts impedes the aggregation of risk data in FIs from across subsidiaries and geographies.

“Definitions of data and key regulatory concepts differ widely internationally, be it in payments systems or regulatory frameworks, even though certain regulatory regimes are negotiated at the international level. This complicates the aggregation of data originating in multiple jurisdictions at an enterprise level, whether by automation or manually. Importantly, the heterogeneity of national requirements and regulations makes it unattractive to develop solutions that cover national regulatory requirements unless the developer reaches a critical mass.”

IIF emphasizes that the diversity of data standards and definitions remain an issue and the stability & efficiency of the global financial system can benefit from harmonization initiatives at an international level. Moreover, as technology and data management requirements change over time and across jurisdictions, it’s equally important to move towards standardization of those data requirements that have been well-established in practice while still keeping a more open approach to new data concepts.

Deloitte’s 2018 Banking Regulatory Outlook recommends that financial institutions implement standard frameworks, policies & procedures, methodologies, and approaches. Institutions need to optimize and standardize activity execution and oversight (e.g., risk assessment, taxonomies) as well as standardize supporting tools, technology, and deployment.

Highly heterogeneous, non-integrated RegTech ecosystem

The RegTech ecosystem has a role to play in transforming how compliance is handled by all parties involved. However, the disparity of standards cannot resolve the complexity and inefficiency unless the technological answer is as complex and non-integrated as the question.

Hundreds of startups offer patch solutions to comprehensive problems, but for the compliance business to change, the startup ecosystem has to offer a unified and standardized way of addressing disparity and complexity of the regulatory environment.

It is likely that the startup ecosystem will go through a curation phase in the next few years, where the vast majority will fall victim to consolidation (M&A, shutdowns, acqui-hires, etc.). The consolidation of resources (financial, talent, technology, and ideas) in the startup environment will balance the market. It will also bring out the best the market can offer, with a very limited number of companies moving towards standardization of the supply side.

To learn about Prove’s identity solutions and how to accelerate revenue while mitigating fraud, schedule a demo today.

Keep reading

See all blogs
How to Defend Against the Rise of SIM Swap Attacks

The Federal Trade Commission (FTC) received reports of a significant increase in SIM swap attacks in 2023, and Experian's 2024 scam forecast identified SIM swapping as one of the top threats, emphasizing the need for heightened awareness and preventive measures.

Mary Ann Miller
July 24, 2024
Fraud in the Age of AI: Meet the Shapeshifter

The COVID-19 pandemic not only changed the way we work and live, it also unleashed a wave of fraud unlike anything we've seen before.

Mary Ann Miller
July 18, 2024
Company News
Introducing Prove Link™ – Unlocking the Power of Identity for Any Business

To continue achieving our mission of accelerating trusted interactions on the internet, we’re proud to announce the introduction of the Prove developer self-service platform and the Prove LinkTM SDK. With these tools, it’s now faster and easier for any company to integrate our industry-leading identity technology into its brand operations.

July 16, 2024
Company News