Bad RegTech outcomes aren’t just a Vendor problem. They’re an Ownership problem too.

Nathan Naicker
Implementation Manager, FinregE

Financial institutions have spent a decade buying compliance technology on the assumption that better software would close their compliance gaps. Regulators and institutions’ own data increasingly suggest otherwise. Nathan Naicker, Implementation Manager at FinregE, reports.

Back in July 2024, the OCC fined Citibank $75 million[1] and the US Federal Reserve fined it $60.6 million[2], both citing insufficient progress against a 2020 consent order under which the OCC had already fined the bank $400 million[3] for deficiencies in risk management, controls, and data governance. It can be argued that when a well-resourced institution has years to fix a known problem and still fails to do so, the missing piece is most likely not a new technology or new tool it could have bought, but rather a better process it failed to adopt.

That distinction looks set to define RegTech’s next decade. Financial institutions were projected to spend $2.37 billion[4] on RegTech in 2026, the broader RegTech market is valued at almost $250 billion[5], and 95% of firms already report scaled use of at least one RegTech tool. So, the question is not whether institutions will adopt RegTech, but how they can ensure it pays off.

The block is seldom the one we blame first

Parker & Lawrence Research recently found[6] 52% of compliance leaders citing legacy-system integration as the leading implementation obstacle, followed closely by the state of their own data at 47%. However, this does not absolve vendors who continue to exhibit the typical failure modes of coverage gaps and overselling, which firms are encouraged to spot and address with appropriate contractual safeguards.

The bigger problem remains institution’s own data, sitting unexamined and unowned years before any vendor contract is signed. This challenge has three main accountabilities:

  1. Whether a vendor’s regulatory content covers a firm’s obligations.
  2. Whether client data (duplicated obligations, undocumented shorthand, and inconsistent legacy classification) is even fit to migrate.
  3. Who owns the decisions required to clean it up (the least visible and most easily underrated of the three).

Half of the vendors surveyed named fragmented internal ownership a significant barrier while less than a quarter of institutions agreed.

What supervisory bodies have found

Regulators in different domains have converged on the same underlying problem i.e. technology does not transfer responsibility for controls, expertise, or data quality away from the regulated firm.

The EBA’s July 2025[7] opinion, for example, found that more than half of serious anti-money-laundering failures reported to EuReCA involving improper RegTech use were attributable to “inadequate in-house expertise, poor governance, and insufficient oversight.” Separately, the FCA’s prudential-reporting review[8] of 3,800 firms and 323,000 tests found ~60% passed nearly everything, while one in ten exhibited “fundamental weaknesses in those firms’ regulatory reporting systems and controls.”

This is not new. BCBS 239, Basel’s principles for effective risk-data aggregation and reporting, put data governance, architecture, and accuracy on banks’ agenda in 2013[9]. A decade later, Deloitte’s benchmark survey[10] found 69% of banks still only planning data lineage from front office to reporting layer. The Committee’s own explanation was more damning: that boards “lack awareness of and attention to data issues.” This is not a technology gap, but the result of data being managed just well enough to answer a specific compliance question when asked but not maintained well enough to be trusted consistently over time.

Where artificial intelligence genuinely helps, and where it stops

A 2025 University of Ottawa study[11] found GPT-4o classified regulatory provisions at 89% precision and 87% recall – well ahead of older keyword-based baselines. The study concerns food-safety regulation rather than financial compliance, though its broader finding, that LLMs outperform simpler regulatory-text classification methods, seems plausible enough to generalise cautiously. Adjacent vendor-affiliated research[12] suggests document-triage costs have also fallen sharply, though that evidence warrants monitoring with healthy scepticism.

None of this means AI resolves judgment. Without expert innovation, current AI systems can flag likely duplicates through semantic similarity but cannot yet determine (unassisted) whether similar obligations are duplicates or legitimately separate requirements. Fed governed data, AI compounds the benefit. Fed chaos, AI compounds the chaos faster than any reviewer could.

The cost of discovering this too late

No rigorous RegTech-specific figure exists for what poor data adds to implementation cost. Gartner’s 2020 research[13] estimated poor data quality cost organisations an average $12.9 million annually, a dated figure for sure but arguably still defensible given poor adoption by firms of better processes around data quality, data handling, and data processing that continue. The commercial risk is not about precise numbers but rather follows a pattern implementation teams know all too well: insufficient data discovery happens before contracting, and the resulting gap surfaces only once implementation is underway, arriving as an unplanned cost rather than a budgeted one.

What a disciplined rollout looks like

This is not an argument against RegTech adoption, but against buying it as one undifferentiated line item when in practice it comprises three workstreams requiring ownership. Financial institutions should consider:

  1. Conducting data-readiness discovery before contracting. This should be followed by solution-specific profiling once the platform’s data model is known, acknowledging that vendor fit cannot be assessed independently of the selected solution.
  2. Separating licence, implementation, and remediation commercially with acceptance thresholds agreed upfront. Name an accountable owner for data readiness and remediation before the project begins, the cheapest correction available and one consistently skipped.
  3. Deploying AI deliberately, with human review, as an accelerant of data classification and data cleanup.

Vendors can be sued, fined by contract, or replaced. However, what cannot be contracted away is an institution’s accountability to regulators and that starts and ends with data ownership.

[1] US Office of the Comptroller of the Currency (OCC) Official Press Release: https://www.occ.gov/news-issuances/news-releases/2024/nr-occ-2024-76.html

[2] US Federal Reserve Official Press Release: https://www.federalreserve.gov/newsevents/pressreleases/enforcement20240710a.htm

[3] US OCC Official Press Release: https://www.occ.gov/news-issuances/news-releases/2020/nr-occ-2020-132.html

[4] Parker and Lawrence Research’s “Global State of RegTech 2026” survey: https://www.parkerlawrence.co.uk/research/global-state-of-regtech-2026

[5] Parker and Lawrence Research’s Press Release by EIN Presswire: https://www.einpresswire.com/article/912042594/new-research-estimates-global-regtech-market-at-245bn-as-ai-accelerates-transformation-of-risk-and-compliance

[6] FinTech Global, citing Parker and Lawrence Research’s “Global State of RegTech 2026” survey: https://fintech.global/2026/08/17/what-are-the-biggest-barriers-to-third-party-regtech-adoption-2/

[7] EBA/Op/2025/10, official PDF: https://www.eba.europa.eu/sites/default/files/2025-07/13ae2f94-dc04-4a50-9f24-af2808e78944/Opinion%20and%20Report%20on%20ML%20TF%20risks.pdf

[8] FCA official publication: https://www.fca.org.uk/publications/good-poor-practice/prudential-regulatory-reporting-investment-firms-data-quality-review

[9] Bank for International Settlements, Basel Committee on Banking Supervision 2013 “Principles for effective risk data aggregation and risk reporting” document: https://www.bis.org/publ/bcbs239.pdf

[10] Deloitte, BCBS 239 Benchmark Survey 2024: https://www.deloitte.com/lu/en/Industries/banking-capital-markets/research/bcbs-239-benchmark-survey-2024.html

[11] Springer, Empirical Software Engineering, and its arXiv preprint: https://link.springer.com/article/10.1007/s10664-025-10619-z ; https://arxiv.org/pdf/2501.14683

[12] “Better Call GPT,” arXiv preprint (Onit AI Center of Excellence): https://arxiv.org/abs/2401.16212

[13] Gartner’s data quality topic page: https://www.gartner.com/en/data-analytics/topics/data-quality

Downloads Alert