Aaron Holmes, CEO at Kani Payments, on the need for regulatory readiness

For years, Fintechs have approached regulation as a compliance challenge.

When a new rule arrives, firms typically turn to compliance teams, legal advisors and consultants to understand what has changed and what needs to be done. The assumption is that once the requirements are understood, the hard part is largely over. Increasingly, that assumption no longer holds true.

The FCA’s updated safeguarding regime, introduced under PS25/12, highlights a much broader shift taking place across financial services. Regulation is no longer simply testing whether firms understand the rules. It is testing whether their operating models can support them.That distinction matters because understanding a regulatory requirement and operationalising it are two very different things.

Recent research into safeguarding readiness across the UK payments sector illustrates the challenge clearly. While 32% of payments firms believe they are already compliant with the FCA’s updated requirements, only 13% are currently performing the daily reconciliations the new regime expects. At the same time, 84% say they could explain their safeguarding calculations to an auditor if required.

Taken together, the findings point to a widening gap between understanding the requirements and operationalising them. The industry understands where it needs to get to. The question is whether its infrastructure is capable of taking it there.

When compliance becomes an infrastructure problem

Much of the conversation around safeguarding has focused on reporting obligations, governance requirements and regulatory expectations. But safeguarding is increasingly becoming an operational challenge.

The updated framework requires firms to move from periodic compliance activities to continuous operational control. Daily reconciliations, enhanced record-keeping and evidence readiness are not simply more frequent versions of existing processes. They require fundamentally different ways of working.

For many organisations, this means rethinking how data flows through the business, how reconciliations are performed, how exceptions are managed and how evidence is stored and retrieved. In other words, the challenge is infrastructure.

This is why many firms find themselves in a difficult position. They understand exactly what regulators expect but are working with processes originally designed for weekly or monthly cycles. A weekly reconciliation process cannot simply be accelerated and expected to deliver daily control. The underlying systems, workflows and governance structures need to evolve alongside the regulation itself. The safeguarding reforms are making that reality impossible to ignore.

The limits of legacy operating models

One of the most telling findings from the research is the industry’s continued reliance on spreadsheets. Nearly two-thirds of firms still use spreadsheets in some form to support safeguarding returns. While spreadsheets are not inherently problematic, they were never designed to provide the level of control, auditability and evidential readiness regulators increasingly expect.

As compliance requirements become more demanding, manual processes become increasingly difficult to scale and evidence. Data must be extracted from multiple systems. Calculations require manual intervention. Audit trails become fragmented. Key knowledge often sits with a small number of individuals who understand how various reports and reconciliations fit together.

None of these challenges are unique to safeguarding. They are symptoms of a wider issue affecting many areas of financial services. As firms grow, operational complexity increases. Processes that once worked perfectly well begin to strain under the weight of regulatory scrutiny, reporting obligations and customer expectations.

The result is that compliance teams increasingly find themselves trying to solve problems that are, at their core, technology and infrastructure challenges.

A trend extending far beyond safeguarding

What makes safeguarding particularly interesting is that it reflects a broader regulatory direction of travel. Across financial services, regulators are placing greater emphasis on demonstrable outcomes rather than documented intent.

Whether the topic is operational resilience, Consumer Duty, financial crime controls or safeguarding, firms are being asked to prove that controls work consistently in practice, not simply that policies exist on paper. That requires a different level of operational maturity.

Regulators increasingly want evidence that can be produced quickly, reconciliations that happen consistently and controls that are embedded into day-to-day operations. The expectation is not that firms can assemble evidence when requested. It is that evidence already exists and can be retrieved immediately.

Historically, many compliance processes have been designed around reporting deadlines and audit events. Increasingly, regulators are expecting firms to operate in a constant state of readiness. That changes the role of technology from a supporting function to a critical component of regulatory compliance.

Building for the next generation of regulation

The payments industry has always been highly effective at adapting to change. The challenge now is recognising that regulation is increasingly testing operational capability as much as compliance knowledge.

The future regulatory battleground will centre on operational capability rather than awareness of the rules. Most firms understand what regulators are asking of them.

Can firms reconcile data quickly and accurately? Can they evidence decisions and controls without extensive manual effort? Can they demonstrate consistency across processes, teams and systems? Can they respond to regulatory scrutiny without relying on institutional knowledge or spreadsheet-based workarounds? These are infrastructure questions as much as compliance questions.

The organisations best positioned for the future will be those that recognise this early. Rather than treating regulation as a series of individual projects, they will build operational foundations capable of supporting continuous compliance across multiple regulatory frameworks. In that environment, regulatory readiness becomes less about reacting to change and more about being flexible enough to adapt from the outset.

Learn more at kanipayments.com

  • Digital Payments
  • Neobanking

Kani Payments CTO Panos Savvas on the next generation of banking and payments and why it’s not just about fast banking but complex banking

The future of banking won’t be decided by algorithms or apps, but by how well we manage the data that drives them...

For years, ‘next generation banking’ has been shorthand for agility, innovation and a clean break from the technological baggage that constrained traditional institutions. Neobanks and fintech challengers built their reputations on speed, automation and digital-first thinking. Yet as the sector matures at a rapid pace, a more layered picture is emerging.

Despite their reputation for a ‘tech-centric’ approach, many digital banks are discovering that operational excellence is harder to achieve than customer experience. In some of the most critical areas of financial infrastructure, data management, reconciliation and reporting, modern banks are grappling with challenges that feel decidedly old generation.

Of course, this is not a failure of innovation, but a reminder that progress in banking is rarely linear. Building for scale, compliance and resilience inevitably exposes the complexity beneath the sleek surface of digital transformation and in this sense banks aren’t alone with this.

The Automation Illusion

Being ‘born in the cloud’ should have freed newcomers from legacy infrastructures. Yet research shows that manual processes remain surprisingly prevalent. Kani’s recent survey found that 22 per cent of UK neobanks still use spreadsheets as a standalone tool to perform reconciliation and compliance reporting. A much higher proportion than any other group surveyed.

This is a very revealing statistic. While the customer interface has evolved rapidly, the back office hasn’t kept pace. The typical neobank experience may be seamless for users on the surface, but behind the scenes, operations often rely on fragmented data flows, multiple third-party integrations and human oversight.

The mismatch doesn’t make them laggards. It simply highlights a structural truth: automation is easy to market, but difficult to master. Data integrity, not digital branding, is what separates the truly next generation from the merely new.

Data: The Hidden Legacy

Every modern bank understands that clean, reliable data is its most valuable asset. It fuels compliance, supports decision-making and underpins every audit trail. Yet half of neobanks in the same survey said data cleansing was among their most time-consuming reconciliation tasks, with 44 per cent citing auditing and 39 per cent data verification as similar drains on time.

These are not edge cases, they are foundational disciplines. When half of a bank’s operational resource is tied up in validation rather than value creation, the issue is not technology but data governance.

Traditional institutions often blame legacy systems for inefficiency. For fintechs, the challenge is different. Modern platforms are fast to deploy, but when combined across multiple partners without shared data standards, they can create inconsistencies that require manual resolution. The future of finance depends less on speed and more on how consistently that speed produces trustworthy data.

Managing Risk, Not Just Reputation

Errors in reconciliation aren’t just accounting irritants, they’re board-level risks. Half of neobanks pointed to compliance exposure as their biggest concern, with 44 per cent linking data breaks directly to market trust.

That finding alone reflects sector maturity. Modern institutions now recognise that trust is not simply a brand asset but a measurable operational outcome. The firms investing in traceability, explainability and real-time audit trails are also the ones strengthening their regulatory relationships.

It’s important to recognise that regulators are not barriers to innovation. They are collaborators in resilience that want firms to show evidence-based controls. The direction of regulation, particularly under initiatives like the UK’s Consumer Duty and Europe’s PSD3, points toward transparency, not obstruction.

Turning Data into Context

How a bank enriches and contextualises transaction data is a reliable indicator of operational maturity. Yet many organisations, not only neobanks, still have enrichment processes that rely heavily on human intervention. 61 per cent of neobanks manually add metadata to transactions, while only a third integrate third-party data automatically.

That dependence on manual enrichment reflects an industry-wide balancing act. The challenge is not capability but confidence. Integrating external data sources requires robust governance, clear permissions and the ability to trace every enrichment to its origin. For a sector under constant regulatory scrutiny, it’s no surprise that many firms err on the side of caution.

The next step is to make enrichment auditable as well as automated, so that data quality, not data quantity, becomes the competitive differentiator.

The AI Rush

Artificial intelligence (AI) has become the headline act of modern banking, promising to transform everything from fraud detection to credit scoring. Yet there’s a risk in assuming that AI will fix underlying operational inefficiencies.

Across the industry, many are racing to bolt AI onto customer-facing functions while leaving back-office processes largely untouched. Without robust data hygiene, reconciliation and enrichment, AI is at risk of improvising around gaps rather than accelerating truth.

True next-generation banking will emerge not from the adoption of algorithms but from the discipline of data stewardship. When banks invest in consistent, explainable data architectures, AI becomes a multiplier for accuracy and trust, not a mask for structural fragility.

Beyond the Buzz

The phrase “next generation banking” has become so elastic that it risks losing all definition. For some, it means AI-driven services; for others, embedded finance or real-time payments. These innovations matter, but they rest on the same foundational truth of, if the data isn’t right, nothing works as it should.

A bank that can open an account in minutes but takes days to close its books is not yet fully digital. A platform that deploys AI for insights but can’t trace the lineage of its data is not yet intelligent. The goal of next-gen banking should be to make the invisible visible, ensuring that every process beneath the surface is as modern as the experience on top.

The Real Definition of “Next Generation”

It’s easy to imagine next-generation banking as something futuristic and abstract. In reality, it’s about something deeply practical: building systems that make data dependable.

Neobanks and fintech banking began as the antidote to legacy complexity. Their next chapter will depend on how well they tackle their own hidden legacies and the invisible operational debt that lurks beneath every modern interface.

The banks that succeed will be those that blend speed with substance, innovation with integrity, and automation with accountability. In the end, the only kind of innovation that endures is the kind that accelerates truth.

Learn more at kanipayments.com

  • Digital Payments
  • Neobanking

Henry Balani, Global Head of Industry & Regulatory Affairs at Encompass Corporation, on meeting the demand for improved risk management, operational efficiency, and customer service with pKYC

The traditional banking and finance industry is evolving. Processes are experiencing a digital transformation as a result of perpetual Know Your Customer (pKYC). The pKYC approach enables modern banks to continuously update and verify customer information in real time. Banks are moving away from the reliance on periodic reviews. This change is driven by technological advancements. And the increasing demand for dynamic and responsive regulatory compliance mechanisms.

Perpetual KYC

Conventional KYC processes commonly involve periodic reviews of customer information at fixed intervals. These reviews are typically conducted every one, three, or five years. While these reviews are thorough and comprehensive, they are also static. This can result in outdated information, potentially overlooking changes in customer risk profiles or new compliance requirements.

On the other hand, perpetual KYC is dynamic and event driven. Through its continuous and automated approach, pKYC enables financial institutions to address risks and compliance needs in real-time. These risks can be determined by continuously monitoring customer activities. Furthermore, automatically updating profiles in response to specific triggers, including changes in personal information, significant transactions, or alterations in beneficial ownership.

Gaining a competitive advantage with pKYC

By leveraging pKYC, banks, and other regulated financial institutions can take advantage of a range of benefits. These are crucial in the modern digital era to gain a competitive edge. Through continuous monitoring, pKYC enables financial institutions to identify and address potential risks promptly. This real-time approach helps mitigate risks associated with financial crimes. Moreover, it ensures compliance with the latest regulatory standards.

pKYC will lead to operational efficiency and cost reduction. By automating many of the manual processes involved in KYC, pKYC significantly reduces the time and resources needed for compliance. This allows financial institutions to focus their efforts on high-risk cases, rather than conducting blanket reviews for all customers, resulting in substantial cost savings.

This process also enables many banks to improve their customer service and management. It also enhances the customer’s experience. With pKYC, customers are not subjected to frequent, intrusive reviews if their profiles remain stable. This results in a smoother and more positive customer experience, potentially increasing overall customer satisfaction and loyalty. Additionally, automated systems minimise human error and ensure consistency in applying KYC policies. This enhances overall regulatory compliance and reduces the risk of non-compliance penalties.

Perpetual KYC implementation: Challenges and considerations

Implementing a pKYC operating model is not straightforward. It requires the right blend of infrastructure and operating process. Every firm’s pKYC journey and ecosystem will be unique and cut across people, processes and technologies.

Data is central to the success of pKYC as reviews based on event changes (aka event driven triggers) will not be effective if client information is outdated, missing or incorrect. Without consistent access to relevant and accurate client information, pKYC is impossible. Corporate Digital Identity (CDI) is fast emerging as a foundation for ensuring valid customer information is collected for successful pKYC operations.

Being able to leverage this data requires an ecosystem of technology, which may be developed in house, utilising third-party RegTech providers, or a combination of both. This technology should drive how data is stored, structured and accessed so that pKYC triggers can be comprehensively managed. Customer lifecycle management systems (CLMs) are particularly relevant to pKYC as they connect all components along the workflow processes.

Importantly, overarching executive sponsorship is needed to ensure a successful outcome in transformation initiatives. Recognising the structural and cross departmental challenge, influential sponsors will align the multiple stakeholders involved in driving this change and will champion a firm’s pKYC strategy and approach to regulators and other key stakeholders.

Ultimately, pKYC must be future-proof and scalable, ready to adapt in line with business strategy and regulation to keep firms competitive.

The future of pKYC

The adoption of pKYC is growing, driven by regulatory pressures and the increasing complexity of financial crimes. Financial institutions are recognising the benefits of a proactive, real-time approach to compliance and risk management. The move towards pKYC is seen as a necessary evolution to stay ahead in a highly regulated and competitive financial environment.

As the technological landscape continues to evolve, integrating advanced technologies such as blockchain and further developments in AI and ML will likely enhance pKYC systems’ capabilities. Ensuring higher levels of compliance and risk mitigation, these technologies are able to provide more robust and secure mechanisms for customer verification and monitoring.

Blockchain technology can be utilised to further improve the initial customer authentication and validation process. As a result, we can expect improvements and advancements in the quality of customer data collected during initial customer onboarding processes. Financial institutions can then leverage AI-enhanced tools that can identify and collect the necessary attributes during document processing stages. This ensures that pKYC will utilise relevant, accurate, and up-to-date data. Perpetual KYC represents a significant departure from traditional, periodic KYC, as it offers a wide range of benefits in real-time risk management, operational efficiency, and customer experience. Although the implementation of pKYC poses certain challenges, it also provides numerous advantages, making it an increasingly attractive solution for financial institutions aiming to enhance their compliance and risk management frameworks and maintain a competitive edge in a rapidly evolving regulator landscape.

  • Cybersecurity in FinTech

At DPW Amsterdam 2023, Alan Holland, CEO of Keelvar, tells us about the acceleration of digital transformation in procurement and what it means for the next generation of the workforce.

Keelvar’s mission is simple – to help procurement teams globally to scale sourcing excellence.

Keelvar is powered by unique artificial intelligence, designed by category experts, to deliver significant savings and operational improvements for global enterprises such as the likes of Siemens, Coca-Cola, Samsung, Novartis and more. The company was founded in Europe’s largest AI research lab by a team of computer scientists and engineers specialising in AI, optimisation and game theory applied to strategic sourcing. Keelvar has raised $42 million to date in funding to accelerate product development and global growth.

The company is led by Alan Holland who has served as CEO since the company’s foundation in September 2012. Indeed, in his first year, he led the organisation to win the Cork Company of the Year in the small company category, and the firm has more recently been awarded a Gartner Cool vendor.

Having previously served as a lecturer in artificial intelligence in University College Cork’s Computer Science Department, Holland specialised in Optimisation, Game Theory and Algorithmic Mechanism Design. Such experience has helped give Keelvar an edge in terms of innovating with offerings that exceed competitors’ technical capabilities. This enables Keelvar to define an entirely new category of the solution, putting Keelvar in an ideal position to lead this new category that Keelvar has called autonomous sourcing.

CPOstrategy sitting down with Alan Holland, CEO at Keelvar, at DPW Amsterdam 2023

Evolution at scale

Procurement is in a state of flux. The industry is experiencing unprecedented amounts of innovation and change in a way which has ripped up the playbook of what went before it. However, Holland believes it is only in the past half decade or so where transformation has really started to take place. “If we look at the last 10 years, the first five of those procurement was very slow to change,” he discusses. “What we saw were technology landscapes dominated by a small number of large suites vendors who had acquired many companies, but most enterprises were satisfied in buying all the modules they would need to run their procurement function from one vendor. Rarely was it the case that the various modules did what their customers needed. Some of them might have worked in some ways, but others just didn’t serve the need at all.

“In the second five years of our being, things started to change. We did start to notice an increasing acceptance that best-of-breed was the way forward and that enterprises needed to accept that if they were to get the buy-in from their stakeholders, then they needed to work with a combination of best-of-breed vendors and piece together their specific technologies landscape rather than just buying it in bulk from one. I would say it was gradual at first and then suddenly, but it’s only been suddenly in the last couple of years. The pandemic likely accelerated some of that change.”

Trust first

Holland explains that in recent years, large multinationals are placing an increasingly important level of trust in smaller, best-of-breed vendors such as Keelvar to allow them to run their sourcing events and meet niche demands. He believes that in the past it simply wouldn’t have happened and strives to prove that faith right. “I suppose that’s a process where enterprises are gradually increasing their trust in what are smaller vendors, but these smaller vendors are becoming bigger because we’re serving hundreds of large enterprises,” he explains. “We’re gaining in strength and momentum and the barriers to adopting best-of-breed at scale are lowering and the market willingness to jump those barriers is increasing. That momentum is just gathering more and more force.”

Alan Holland, CEO at Keelvar

Using tech as an enabler for talent

Procurement’s talent shortage and the ways to bridge has been a hot topic for years. Whoever you speak to within the industry, everyone will have a different viewpoint. Some say procurement needs a rebrand, others say it’s a lack of education while others think technology could hold the key. For Holland, he believes it’s about making tech work and freeing up people in procurement’s time to focus on more value-add work that will help solve strategic goals.

“What is attracting graduates to procurement now is working with intelligent systems that are powered by AI and that allow them to be strategic and not working on routine or tactical tasks because machines are taking over the data-intensive areas of processing these workflows,” he tells us. “Our second product, which we launched about three years ago is autonomous sourcing. These are sourcing bots that are intelligent software agents that you can now design, build, and operate your own sourcing bots. If you’re somebody who understands best practices in sourcing, you can now build automated workflows so that instead of having to run sourcing events one by one and get through 15 or 20 a year, now you could design bots that are running hundreds of these events per annum.”

Procurement’s bright future

While not only opening up people’s day, using technology as an enabler to make life easier also acts as a way of encouraging the next generation into the industry. “What you’re doing is freeing up many other people’s time to spend on relationship management or innovation discovery and talking to the market, finding out what new suppliers you should be dealing with, visiting suppliers to check things are in order,” he says. “And that is the type of work that people enjoy doing. Machines are taking more of the data-intensive work off their tables, and machines are not good at work related to establishing trust. Machines have no empathy, but people do. The soft skills in procurement are becoming ever more important because the machines are taking over the harder skills. That is leading to a transformation in the type of work that procurement is doing.

“It’s also leading to a transformation in the interest levels that graduates emerging from universities have for this sphere. When it used to be that they were first introduced to a legacy system and told that this is what they needed to use to do their job. Young workers are coming with higher expectations about software and rightfully so, and enterprises are reacting to the need to satisfy the technology requirements of younger recruits now, which is a very good thing. It’s accelerating that digital transformation that we are seeing.”

The next step

Looking ahead, Holland is full of positivity for the future and believes decision-making in procurement is easier than it’s ever been. He believes tomorrow is “very bright” as procurement enters an era with intelligent software agents which can automate workflows and make the human workday more efficient. “There’s a whole new range of possibilities where creative and thoughtful planning will provide a competitive advantage for organisations and procurement can be far more influential in how successful their companies can be. It’s a game-changer.”