How Can We Maximise Regulatory Technology & Avoid Its Potential Pitfalls? What recent results from the European Banking Authority and ESMA reports show

The European Banking Authority (EBA) has recently published an analysis looking into the RegTech landscape in the EU. The report assesses the many benefits, challenges and risks of the use of RegTech in the EU and lays out the steps to be taken to support the sound adoption and scale-up of solutions in this sector. The study also proposes actions designed to enhance the knowledge and skills of the competent authorities (CAs). ESMA has also published a report on Trends, Risks and Vulnerabilities of the Financial sector dedicating a part on RegTech and SupTech and the change for Markets and authorities. This report highlights that market participants are increasingly using new automated tools in a variety of areas, while potential applications of new tools for regulators include greater surveillance capacity and improved data collection and management. When technology is used for compliance, it is called Regulatory Technology or ‘RegTech’. Regtech is defined as any range of applications of technology‐enabled innovation for regulatory, compliance and reporting requirements implemented by a regulated institution – with or without the assistance of RegTech provider. RegTech solutions in Financial Institutions (FIs) and Investment Firms (FI’s) are currently evident in: Anti-Money-Laundering and Countering the Financing of Terrorism (AML/CFT) – for example, providing solutions for sanction screening or remote onboarding of customers. Fraud prevention – through automated behaviour and transaction monitoring. Prudential reporting – supporting institutions in their regulatory submissions. ICT security – providing detection mechanisms for an institution’s operations security. Creditworthiness assessments – providing new capabilities for assessing the creditworthiness of clients. Regulatory Reporting – supporting institutions in their trade reporting. Risk Management Benefits According to financial organisations using RegTech solutions, their key benefits are improved risk management, better monitoring and sample capabilities, and a reduction in human error. At the same time, RegTech providers place heavy emphasis on their ability to increase efficiency and effectiveness and quell the impact of ongoing regulatory change. Some of the increasing disparities in perspective between financial institutions (FIs) and RegTech providers suggest that further research of the benefits afforded by RegTech solutions is required. ESMA also believes that the move towards a more data-driven and pro-active approach will enhance monitoring of the financial sector and help ensure better outcomes for market participants and consumers. The continual push for efficiencies and cost savings, particularly for back-end and legacy systems as well as for labour-intensive processes will increase the use of RegTech in the foreseeable future. Risks EBA highlighted that when not implemented correctly, RegTech solutions may also generate risks for FIs that would need to be identified, monitored and managed. These risks may relate to, for example, compliance, concentration, business continuity, ICT and security, reputational issues, internal governance, conduct and consumer protection, and/or technology. RegTech may also create new risks for CAs supervising FIs. These include potential difficulties in assessing the effectiveness and reliability of the technological solutions used by FIs, and a potential lack of skills and tools needed to supervise the use of technology enabled RegTech solutions and, say, audit the underlying algorithms. ESMA focused on the risks and challenges for regulators and market participants in the areas of data collection and management, digital transition and failure on the part of market participants to adapt to the new digitalised infrastructure and the need from regulators to invest in the technological tools and human skills that will allow them to effectively analyse the results, operational risks and the risks from strategic incentives such as developing expertise in RegTech. Challenges The EBA report suggests that the majority of challenges to RegTech market development involve internal factors within the FIs and providers. Likewise, ESMA considers most of those challenges to apply for FIs. However, a lack of common regulatory standards across the EU could also constitute a barrier to the wider market adoption of RegTech solutions. The main challenges from the FI perspective are summarısed as follows: Data-related challenges and cybersecurity threats: FIs often indicate data quality, data privacy and protection, lack of data integration, data availability, and lack of data standardisation and harmonisation as issues. Interoperability and integration with the existing legacy systems: FI legacy systems and processes have too many silos, making RegTech adoption difficult, and this is further compounded by doubts about the ICT capacity of FIs to support FinTech, RegTech, and InsurTech solutions. Changes to regulation: changes with national or international regulations and other regulatory challenges can be another key barrier to RegTech adoption. Costs and procurement process: RegTech solutions seen as part of compliance and usually treated as a back‐office function may be at risk of underinvestment. Lack of necessary skills and training: when working with either in‐house or external RegTech solutions, FIs need specialists, e.g. data scientists and engineers, to be able, where relevant, to scout, assess, operate, and maintain updated RegTech solutions. Perceived immaturity of RegTech providers’ solutions: FIs that see RegTech as a potential competitive advantage often cite the lack of available and mature RegTech solutions as a challenge. Challenges from the RegTech provider perspective include: Lack of technological capabilities – the lack of some clients API capabilities and lack of standardisation are perceived as obstacles for technical integration. Security, data privacy and protection issues – privacy regulation may be one of the key constrains for FIs from sharing datasets with RegTech providers. Changes of national and international regulation – complex and continuously evolving regulatory landscape is perceived as a challenge, in particular on prudential reporting, fraud prevention and AML/CFT. Cost of user acquisition – a challenge, especially for recently established and smaller RegTech providers. Lack of FI understanding of RegTech solutions –it appears to RegTech providers that FIs may not be fully aware of all advantages that RegTech solutions may bring. Lack of harmonised legal and regulatory requirements – RegTech providers perceive the lack of harmonisation of regulatory requirements across the EU and the lack of regulatory data standards to be obstacles for wider market adoption of RegTech solutions. Clarity of regulatory/supervisory guidance – RegTech providers consider the lack of regulatory/supervisory

EBA final report on revised money-laundering and terrorist financing risk factors guidelines under the Fourth Money Laundering Directive

On 1 March 2021, the EBA published its final report setting out revised guidelines on customer due diligence (CDD) and the factors credit and financial institutions should consider when assessing money laundering (ML) and terrorist financing (TF) risk associated with business relationships and occasional transactions under Articles 17 and 18(4) of Fourth Money Laundering Directive (EU 2015/849) (MLD4). MLD4 and a risk-based approach The anti-money laundering directives are the key pieces of legislation which make up the current European Union anti-money laundering (AML) and counter-terrorist financing (CTF) regime.  MLD4 placed a risk-based approach at the center of the regime. As the risk of ML and TF can vary, a risk-based approach helps to manage that risk effectively. MLD4 was required to be transposed into national law by 26 June 2017. Guidelines The greater emphasis in MLD4 on a risk-based approach meant that there was a greater need for guidance for National Competent Authorities (NCAs) and firms. Under MLD4, the European Supervisory Authorities (ESAs) were required to issue guidelines by 26 June 2017, addressed to NCAs and firms, on the risk factors firms should take into consideration and the measures they should take in situations where simplified or enhanced customer due diligence (CDD) would be appropriate. The aim was to promote a common understanding, by firms and competent authorities, of what the risk-based approach to AML/CFT entails and how it should be applied. The Final Guidelines (JC/2017/37) were published on 26 June 2017.  The guidelines have applied since 26 June 2018. Guidelines are addressed to NCAs and firms and their purpose is to clarify the supervisory expectations and to enhance the convergence of supervisory practices. Although they are non-binding, NCAs and firms to whom guidelines are addressed are expected to comply with them (on a “comply or explain” basis). MLD5 and ESA ongoing work On 19 June 2018, the Fifth Money Laundering Directive (EU 2018/843) (MLD5) entered into force. MLD5 was required to transpose into national law by 10 January 2020.  MLD5 amended MLD4 to strengthen the fight against terrorist finance and ensure the increased transparency of financial transactions. As a result, the Guidelines needed to be updated to take account of the new legal framework.  At the same time, the ESAs’ ongoing work on ML/TF risk highlighted several areas where significant differences continued to exist in firms’ approaches to AML/CFT. The EBA’s new role Since 1 January 2020, the responsibility to produce these guidelines (and to update them) has been passed to the European Banking Authority (EBA), by virtue of Article 3(3) of the Omnibus Directive amending Article 17 of MLD4, giving the EBA powers to lead, co-ordinate and monitor efforts to strengthen AML and CTF measures across the EU in respect of financial institutions. The EBA launched a consultation on a revised version of the guidelines on 5 February 2020 proposing changes to reflect MLD5, as well as concerns identified by the ESAs. The revised guidelines On 1 March 2021, the EBA published its final revised guidelines. General Guidelines The EBA has provided more details to existing central parts of the guidelines, as well as adding new guidance on emerging risks: business-wide and individual ML/TF risk assessments; customer due to diligence measures including the identification of the beneficial owner and enhanced due diligence in relation to high risk third countries; TF risk factors; and emerging risks, such as the use of innovative solutions for CDD purposes. High risk third countries The revised Guidelines require firms to carefully assess the risks associated with business relationships and transactions where the customer is known to maintain close personal or professional links with a high-risk third country, or beneficial owner(s) is/are known to maintain close personal or professional links with a high-risk third country. Beneficial ownership Under the revised guidelines, when discharging their obligations set out in Article 13(1)(b) of MLD4 to understand the customer’s ownership and control structure, firms should: ask the customer who their beneficial owners are; document the information obtained; and then take all necessary and reasonable measures to verify the information: to achieve this, firms should consider using beneficial ownership registers where available. Beneficial ownership registers – Firms should be mindful that using information contained in beneficial ownership registers does not, in itself, fulfil their duty to take adequate and risk-sensitive measures to identify the beneficial owner and verify their identity. Firms may have to take additional steps to identify and verify the beneficial owner, specifically where the risk associated with the business relationship is increased or where the firm has doubts that the person listed in the register is the ultimate beneficial owner. Control through other means – Firms should also take reasonable measures to understand the customer’s ownership and control structure. The measures firms take to understand the customer’s ownership and control structure should be sufficient so that the firm can be reasonably satisfied that it understands the risk associated with different layers of ownership and control. In particular, firms should be satisfied that, the customer’s ownership and control structure are not unduly complex or opaque; or complex or opaque ownership and control structures have a legitimate legal or economic reason. Firms should pay particular attention to persons who may exercise ‘control through other means. Examples of ‘control through other means’ firms should consider include: control without direct ownership, for example through close family relationships, or historical or contractual associations; using, enjoying or benefiting from the assets owned by the customer; responsibility for strategic decisions that fundamentally affect the business practices or general direction of a legal person. Identifying the customer’s senior managing officials  – Firms should resort to identifying the customer’s senior managing officials as beneficial owners only if: They have exhausted all possible means of identifying the natural person who ultimately owns or controls the customer; Their inability to identify the natural person who ultimately owns or controls the customer does not give rise to suspicions of ML/TF; and They are satisfied that the reason given by the customer as to why the natural person who ultimately owns or controls the customer cannot be identified is plausible. De-risking EBA

Complyport Tech presents extensive opportunities for firms in the future, Thomson Reuters survey shows

Can corporate governance and the culture of financial services firms keep up with the pace of growth of regulatory technology?   During the past several years, regulators have invested heavily in technology to protect and monitor regulatory reporting data quality. The main challenges for 2021 will focus on new regulations, preparing for those with effective dates this year and those that are going through the legislation, proposal and comment processes. This leaves financial services firms with no option but to address automated reporting as a way of validating all data submitted to regulators, detecting and correcting data issues as they arise, and setting up an overall data governance framework across different regulatory reporting requirements. Thus, Regulatory Technology (RegTech) is crucial for operational management and strategic decision-making for both the risk and compliance functions as it is designed to help firms understand and meet legal requirements more effectively and efficiently. According to Thomson Reuters Regulatory Intelligence’s 2020 annual survey report “RegTech and the role of compliance in 2021”, despite firms facing several budget challenges during the pandemic, the adoption and implementation of regulatory technology has taken a huge step forward with 70% of the surveyed firms reporting that COVID-19 increased their reliance on technological solutions. The study, which shares the experiences of more than 400 compliance and risk practitioners, found that this sector’s growth is expected to accelerate in the coming months and years. Firms and their customers are realising the great value of adopting a wide variety of Fintech solutions. The survey also shows that firms must be careful to deploy solutions on solid foundations. This means getting corporate governance right. A quarter of respondents said that corporate boards and the risk and compliance functions need to be more involved in finding and adopting Fintech solutions for the firm, highlighting the absence of appropriate skill sets as one reason for this lack of involvement. Moreover, RegTech applications continue to provide popular, embedded solutions for firms in areas such as compliance monitoring, financial crime, AML/CTF, sanctions and regulatory reporting. Budgets are predicted to increase with a mix of in-house and external solutions as the option most frequently selected by respondents. Interestingly, just 16% of firms reported they had implemented RegTech solutions, with a further 34% stating that RegTech solutions were affecting the management of compliance. Notably, the report identifies a shift from build to buy; firms that employ inhouse solutions fell to 6% in 2020 from 17% in 2019, while 12% reported that all of their RegTech solutions were developed externally.   Why choose Complyport Tech to be your regulatory technology partner? Complyport Tech is a leading and award-winning regulatory technology provider for the financial services industry, specialising in reporting solutions arising from the requirements of a number of complex and challenging international regulations such as EMIR, MiFID II/MiFIR, SFTR, FATCA, DAC6 and CRS. Complyport Tech also provides innovative and comprehensive solutions for Best Execution Monitoring, RTS 27/28 Reporting, AML Transaction Monitoring and Screening, Trade Surveillance (Market Abuse), and eKYC (Screening, eIDV, Document Authentication).   Industry Pioneers Complyport Tech was one of the first providers in Europe to report under the European Market Infrastructure Regulation (EMIR) with 1.5 billion+ transactions successfully submitted since February 2014. The company currently supports over 170 B2B global clients, having been recognised for the Best RegTech Reporting Solution for 2019 by Finance Magnates London and named as one of the 100 most innovative RegTech companies in the world for 2020 and 2021 by RegTech Analyst. LSE-listed brokers, including some of the biggest CFD brokers in the world, currently use Complyport Tech’s innovative solutions.   RegTech Experts Complyport Tech is not just a technology company that develops software to help clients report. At the core of its offerings lies compliance. Complyport Tech provides quality assurance that the reporting obligations are correctly covered in terms of data quality.  If the need arises, the firm can also directly support businesses before any national competent authority without needing any external third-party advisory or assistance. Complyport Tech  can directly and uninterruptedly report to a number of EU national competent authorities. Complyport Tech’s products have been repeatedly tested and passed several rigorous reviews by EU regulatory authorities, providing full transparency for both clients and EU national competent authorities. Moreover, the company offers financial institutions the unique facility to comply with a firm’s reporting obligations before the regulatory authorities, carry out audit trails, and conduct their own reconciliations. Complyport Tech has managed to successfully and innovatively combine the compliance and technology functions with both of its teams working in close unison. This allows the company to be flexible, efficient and effective in supporting the many new, demanding and dynamic requirements of the global RegTech world.. The team’s combined expertise underpins the company’s success in providing targeted solutions to its clients and addressing their reporting needs across a diverse regulatory landscape.   One-Stop RegTech Provider Complyport Tech’s solutions are all delivered under the Polaris Platform, the company’s single and powerful RegTech tool. Besides transaction reporting, the Polaris platform combines, under a single unit interface, unique solutions such as Market Abuse Surveillance, AML Transaction Monitoring, Best Execution Monitoring, RTS reports and CRS/FATCA reporting, among others. This allows Complyport Tech to package its offerings to its clients by reducing direct and indirect costs, maintain a single point of contact for support and access to the system, and avoid the need of multiple integrations with various vendors, thus saving clients both time and resources.   Impeccable Support Services Complyport Tech’s dedicated and experienced support team specialises in regulatory reporting, providing continuous support on what is needed to master transaction reporting requirements. This starts from the onboarding phase and covers the whole process up until the initiation of the live reporting, the handover of the platform to the client, and ongoing day-to-day support.   Unparalleled Compliance Expertise Complyport Tech is a member of MAP S.Platis Group, a leading financial services consultancy group in the region that maintains one of the largest and most experienced teams of financial services compliance experts in the EU. This ensures that