The Illusion of Instant Compliance
Recent conversations with CISOs and compliance leads reveal a troubling trend: organizations are buying compliance tools expecting immediate risk reduction, only to find their problems multiplying. This issue became particularly evident after the European Banking Authority flagged regtech implementation failures in their 2025 Opinion on ML/TF Risks. The core problem? Governance is lagging behind procurement.
Q1: We Just Bought a Transaction Monitoring Platform. Why Is Our Auditor Still Flagging Gaps?
Because the platform doesn't know your business.
Off-the-shelf tools come with default settings designed for generic financial institutions. Your auditor is highlighting the gap between these assumptions and your actual risk profile. If you haven't customized the tool to reflect your customer segments, transaction patterns, and geographic exposure, you're merely staging compliance, not practicing it.
Before the tool can deliver value, ensure clear ownership of each control it executes, document how these controls map to your specific regulatory obligations, and have someone with expertise validate the alerts. The EBA report explicitly states that inadequate in-house expertise and poor governance are the real barriers to effective regtech implementation, not the technology itself.
Q2: How Do We Know If Our Regtech Vendor Is Covering the Risks We Think They Are?
You test it. Specifically, test the controls the vendor's tool is supposed to execute.
Many organizations treat vendor technology as a black box: data goes in, compliance reports come out, and everyone assumes it's working. But automated controls still require verification. You need to ensure the logic is sound, data inputs are complete, and outputs are accurate.
Create a control testing schedule that includes your regtech platforms. For each automated control, document the risk it mitigates, the evidence it should produce, and what failure looks like. Test quarterly at a minimum. If your team can't explain how the tool works or validate its outputs, you don't have a control, you have a liability.
Q3: Our Compliance Dashboard Shows Everything's Green. Why Doesn't That Reassure Me?
Because green doesn't mean "effective," it means "no one tested it recently enough to find a problem."
Dashboards aggregate status indicators, but these are only as reliable as the controls behind them. If your controls aren't mapped to actual risks, if testing is sporadic, or if ownership is unclear, then green just means you haven't looked closely enough yet.
The EBA found that 70% of supervisors see money laundering and terrorism financing risks rising in the EU financial sector. This indicates that organizations with impressive compliance tech are still failing. The difference between a false positive and genuine assurance is governance. You need a single source of truth connecting risks, controls, obligations, and test results, and people who understand what they're looking at.
Q4: We Don't Have Deep AML Expertise In-House. Can't We Just Rely on the Vendor's Configuration?
No. You can use their configuration as a starting point, but you own the outcome.
Regulators won't accept "the vendor set it up that way" as a defense. You're responsible for understanding your risk environment and ensuring your controls address it. This means you need enough internal expertise to evaluate whether the vendor's approach is appropriate for your institution.
If you lack that expertise, hire it or develop it. Bring in a consultant to help customize and validate the initial setup, then train your team to maintain it. Otherwise, you're over-relying on vendors without the ability to validate outputs or detect false assurance.
Q5: How Do We Avoid Duplicating Controls Across Different Tools and Teams?
With a unified controls library and clear accountability.
Duplication occurs when controls are managed in silos: compliance has their spreadsheet, IT has their GRC platform, operations has their process documentation, and no one's comparing notes. This results in redundant testing, conflicting ownership, and gaps where everyone assumed someone else had it covered.
Start by inventorying every control across the organization. Map each one to the risks it mitigates and the obligations it satisfies. Assign a single owner for each control, even if multiple teams contribute to its execution. Then consolidate everything into one system of record, whether that's a GRC platform or a well-governed database. The goal isn't to eliminate all redundancy, but to make it deliberate instead of accidental.
Q6: What Does "Good Governance" for Regtech Look Like in Practice?
It looks like structure, visibility, and accountability.
Good governance means you can answer these questions at any time: What risks are we managing? Which controls mitigate each risk? Who owns each control? When was it last tested? What evidence do we have that it's working? What regulatory obligations does it satisfy?
In practice, this requires:
- Control design documentation explaining what the control does, how it works, and what failure looks like
- Testing schedules with automated reminders and evidence collection workflows
- Clear ownership with escalation paths when controls fail or need adjustment
- Integration between your regtech tools and your broader risk and compliance framework
- Regular reviews where leadership examines control effectiveness, not just dashboard colors
The EBA's warning about insufficient oversight isn't abstract. It means firms are deploying tools without the structure to manage them, creating new vulnerabilities instead of reducing existing ones.
Next Steps
If your organization is struggling with these issues, the problem isn't the technology you bought. It's the governance you didn't build around it.
Start by auditing your current state: document every compliance tool, every control it's supposed to execute, and every gap in ownership or testing. Then build the structure to manage it: a controls library, testing workflows, and reporting that gives you real visibility.
The EBA's 2025 Opinion on ML/TF Risks is worth reading in full, especially if you're in financial services. But the lessons apply across industries: compliance technology is only as good as the governance that supports it, and you can't outsource understanding of your own risk environment.





