For years, Fintechs have approached regulation as a compliance challenge.
When a new rule arrives, firms typically turn to compliance teams, legal advisors and consultants to understand what has changed and what needs to be done. The assumption is that once the requirements are understood, the hard part is largely over. Increasingly, that assumption no longer holds true.
The FCA’s updated safeguarding regime, introduced under PS25/12, highlights a much broader shift taking place across financial services. Regulation is no longer simply testing whether firms understand the rules. It is testing whether their operating models can support them.That distinction matters because understanding a regulatory requirement and operationalising it are two very different things.
Recent research into safeguarding readiness across the UK payments sector illustrates the challenge clearly. While 32% of payments firms believe they are already compliant with the FCA’s updated requirements, only 13% are currently performing the daily reconciliations the new regime expects. At the same time, 84% say they could explain their safeguarding calculations to an auditor if required.
Taken together, the findings point to a widening gap between understanding the requirements and operationalising them. The industry understands where it needs to get to. The question is whether its infrastructure is capable of taking it there.
When compliance becomes an infrastructure problem
Much of the conversation around safeguarding has focused on reporting obligations, governance requirements and regulatory expectations. But safeguarding is increasingly becoming an operational challenge.
The updated framework requires firms to move from periodic compliance activities to continuous operational control. Daily reconciliations, enhanced record-keeping and evidence readiness are not simply more frequent versions of existing processes. They require fundamentally different ways of working.
For many organisations, this means rethinking how data flows through the business, how reconciliations are performed, how exceptions are managed and how evidence is stored and retrieved. In other words, the challenge is infrastructure.
This is why many firms find themselves in a difficult position. They understand exactly what regulators expect but are working with processes originally designed for weekly or monthly cycles. A weekly reconciliation process cannot simply be accelerated and expected to deliver daily control. The underlying systems, workflows and governance structures need to evolve alongside the regulation itself. The safeguarding reforms are making that reality impossible to ignore.
The limits of legacy operating models
One of the most telling findings from the research is the industry’s continued reliance on spreadsheets. Nearly two-thirds of firms still use spreadsheets in some form to support safeguarding returns. While spreadsheets are not inherently problematic, they were never designed to provide the level of control, auditability and evidential readiness regulators increasingly expect.
As compliance requirements become more demanding, manual processes become increasingly difficult to scale and evidence. Data must be extracted from multiple systems. Calculations require manual intervention. Audit trails become fragmented. Key knowledge often sits with a small number of individuals who understand how various reports and reconciliations fit together.
None of these challenges are unique to safeguarding. They are symptoms of a wider issue affecting many areas of financial services. As firms grow, operational complexity increases. Processes that once worked perfectly well begin to strain under the weight of regulatory scrutiny, reporting obligations and customer expectations.
The result is that compliance teams increasingly find themselves trying to solve problems that are, at their core, technology and infrastructure challenges.
A trend extending far beyond safeguarding
What makes safeguarding particularly interesting is that it reflects a broader regulatory direction of travel. Across financial services, regulators are placing greater emphasis on demonstrable outcomes rather than documented intent.
Whether the topic is operational resilience, Consumer Duty, financial crime controls or safeguarding, firms are being asked to prove that controls work consistently in practice, not simply that policies exist on paper. That requires a different level of operational maturity.
Regulators increasingly want evidence that can be produced quickly, reconciliations that happen consistently and controls that are embedded into day-to-day operations. The expectation is not that firms can assemble evidence when requested. It is that evidence already exists and can be retrieved immediately.
Historically, many compliance processes have been designed around reporting deadlines and audit events. Increasingly, regulators are expecting firms to operate in a constant state of readiness. That changes the role of technology from a supporting function to a critical component of regulatory compliance.
Building for the next generation of regulation
The payments industry has always been highly effective at adapting to change. The challenge now is recognising that regulation is increasingly testing operational capability as much as compliance knowledge.
The future regulatory battleground will centre on operational capability rather than awareness of the rules. Most firms understand what regulators are asking of them.
Can firms reconcile data quickly and accurately? Can they evidence decisions and controls without extensive manual effort? Can they demonstrate consistency across processes, teams and systems? Can they respond to regulatory scrutiny without relying on institutional knowledge or spreadsheet-based workarounds? These are infrastructure questions as much as compliance questions.
The organisations best positioned for the future will be those that recognise this early. Rather than treating regulation as a series of individual projects, they will build operational foundations capable of supporting continuous compliance across multiple regulatory frameworks. In that environment, regulatory readiness becomes less about reacting to change and more about being flexible enough to adapt from the outset.
Learn more at kanipayments.com

- Digital Payments
- Neobanking


