Ten compliance trends in financial institutions

1 November 2019 Security Services & Risk Management, Retail (Industry)


Steyn Basson

Having been involved in the compliance space for more than a decade in some form or another, we have identified ten key compliance characteristics and trends in the majority of South African (and African) financial institutions.

1. Increased load – Whereas a number of years ago compliance was a process that required a small team of people (as a percentage of IT staff) to manage, we have seen a steady increase in the proportion of staff assigned to compliance as opposed to revenue-generating activities. This is due to a steady increase in the number of compliance checks and reports required by regulators, and an increase in the coverage of the reports (i.e., inclusion of more clients and reporting records), as well as an increase in the detail required (i.e., more detail on each client and/or reporting record).

2. Keyman dependency and burnout – A number of organisations make use of a few key staff members to run critical reporting processes. In many cases, this leads to burnout due to the significant levels of stress during reporting periods, or serious issues in cases where staff members actually resign or move on.

3. Reporting deadline pressure – Most organisations still treat reporting season(s) as an event rather than a process, i.e., once (annual) submissions have been completed, everything goes on ice till a month or two before the next report is due. This leads to immense pressure and lots of late nights for the staff entrusted with the reporting process, as well as a lot of (often nasty) surprises and at times missed deadlines and cutting corners when it comes to data quality. Treating reporting as a process leads to early insight into data quality and a huge reduction in pressure during submission season.

4. Lack of repeatability – In a number of cases the activities that are performed to enable reporting for one season have to be started from scratch for the next reporting season. Although some level of rework is to be expected at times, all too often client corrections are made on the final submitted reports, meaning there is almost no re-use of hours and hours of work for the next submission season.

5. Lack of responsibility – In many cases, there are many ‘grey areas’ when it comes to responsibility. Should reporting form part of the IT process, or should business take ownership? In the scenario where it becomes an IT responsibility, we tend to see many cases where business sends inaccurate data to IT, leaving IT with a very difficult task to ensure reporting occurs as expected.

Similarly, if it becomes a business-focused task, often business does not have the appropriate tools to help them clean or prepare their data. The technical nature of the issues that occur during submission means that business is highly reliant on IT for a task that IT does not consider part of their key responsibilities. The answer lies somewhere in between, but we have seen very few organisations that have managed to strike the correct balance.

6. Lack of automation – In a few cases, the reporting process is manual, from the sourcing of data to clean-up processes to the creating and validating (and submitting) of the final file.

7. Data quality issues – Data quality issues plague the majority of financial institutions. Most organisations have legacy data that predates the current stricter compliance landscape, meaning that data that was more than sufficient when it was originally captured now falls well short of minimum requirements. However, this problem extends to newer financial institutions as well (as well as newer data at older financial institutions). In a large number of cases, internal bank systems just can't keep up with the broadening scope of regulation and the resultant data quality requirements, meaning that despite the best training and guidance in this regard, low-quality data still makes a regular appearance in financial systems.

8. Tactical rather than strategic solutions – Due to the nature of how compliance has evolved over the years, a large number of financial institutions make use of tactical rather than strategic solutions today. When compliance requirements were first introduced, it was sufficient to do the bare minimum and repurpose other reports and/or systems/processes to achieve compliance. This was since the scope of the requirements was low, and didn't require much complexity to achieve. In many cases, financial institutions also took a ‘wait and see’ stance to understand where the bar would be set.

As each subsequent year has introduced more requirements, the previous year's solution would be taken out of retirement and tweaked to achieve the new requirements. After a few years of this, the reporting solutions at a number of institutions started resembling a massive snowball rolling down a hill, invariably collapsing and leaving financial institutions with (almost) no solution at all. Additionally, the snowball (tactical) solution almost invariably does not address issues in the most optimal way possible, and there are lots of holes. Being able to take a strategic stance to reporting means considering all of the pitfalls and other aspects upfront.

9. Distraction – Compliance is often seen as a grudge activity inside financial institutions. It is an activity that generates very little real value to most organisations, and in the vast majority of cases, the preference would be to redeploy the team working on compliance reporting to activities that are more closely aligned with the vision/mission of the organisation. Indeed, in the most extreme cases, compliance teams are seen as a nuisance that needs to be tolerated rather than valuable members of the team.

10. Lack of leverage – Too often the results of compliance processes are not used for anything other than reporting. However, since a massive amount of data needs to flow through compliance systems, there is often an opportunity to unlock additional value. Whether it is due to additional analytics that can be performed on data due to having better-structured, cleaner data, or alternative metrics and insights that can be gained due to the data being structured and collated in one area. In our experience, very few financial institutions leverage this feature.

For these reasons, Synthesis' belief is that looking at strategic rather than tactical solutions can help set financial institutions up for long-term success and lower the risk of non-compliance events.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

The line between locking residents out and restricting their access
News & Events Security Services & Risk Management Residential Estate (Industry)
A June 2026 High Court judgment has clarified one of the most contested issues in modern estate governance: when an HOA's digital access restrictions amount to unlawful self-help or spoliation, and when they do not.

Read more...
Modernise field communications with Push-to-Talk over Cellular
Products & Solutions Security Services & Risk Management
Sentiv is bringing Hytera’s Push-to-Talk over Cellular (PTToC) portfolio to organisations that need a more structured and controlled way to coordinate field teams, without extending a full private radio model to every team, site, or function.

Read more...
Amplifying the value of CCTV systems with AI
IoT & Automation Surveillance Entertainment and Hospitality (Industry) Retail (Industry) AI & Data Analytics
Smart AI platforms enable retail and hospitality organisations to turn their existing CCTV investments into proactive security systems and smart retail ecosystems that boost customer service and ROI.

Read more...
SAFPS urges taxpayers to remain alert to fraud
Security Services & Risk Management News & Events
The SAFPS warns taxpayers about evolving SARS scams this tax season, highlighting common fraud tactics, practical prevention tips, and trusted reporting channels to stay protected.

Read more...
Zero-touch automation certificate life cycle management loop
Products & Solutions Information Security Security Services & Risk Management
ManageEngine completes the certificate life cycle management loop with CA-agnostic, zero-touch automation. New post-deployment automation in Key Manager Plus removes the last manual step in certificate renewal as lifespans gradually shrink to 47 days

Read more...
Fire safety in South Africa
Technoswitch Fire Detection & Suppression Technews Publishing SMART Security Solutions Fire & Safety Security Services & Risk Management Editor's Choice
Fire safety is sometimes ignored, sometimes relegated to whatever is cheapest, and sometimes treated with the seriousness it deserves, given that it focuses on protecting life and assets. SMART Security Solutions asked Brett Birch, MD of Technoswitch, for some insights into the realities of fire safety in South Africa.

Read more...
Nimbus remote fire alarm management
Technoswitch Fire Detection & Suppression Security Services & Risk Management Fire & Safety
Nimbus connects key stakeholders to their fire alarm systems, simplifying compliance with fire safety standards and greatly improving visibility into critical events, thereby augmenting first responder processes that save lives and protect assets.

Read more...
Sophos launches AI-native cybersecurity defence system
News & Events Information Security Security Services & Risk Management
Built for a threat landscape reshaped by AI, Sophos Fusion unites security operations, endpoint, network security, identity, email, and cloud into one defence system that prevents, detects, investigates, and responds at AI speed.

Read more...
Stop supplier fraud at the moment of payment
News & Events Security Services & Risk Management
Cape Town-built platform bridges the gap between onboarding and transaction by securing identity inside the live channels where companies exchange invoices and banking details.

Read more...
Ungoverned AI agents and deepfakes pose critical threats
Information Security Security Services & Risk Management
Global study reveals 64% of South African organisations already deploy autonomous AI agents with little to no governance, while 63% of employees admit they are unlikely to be able to spot attacks such as deepfakes

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.