The Compliance Intelligence Failure at the Centre of the Next Crisis

The Compliance Intelligence Failure at the Centre of the Next Crisis

Past financial crises were not failures of regulation. They were failures to connect information that already existed.

In November 2022, the rules existed. Disclosure obligations existed. Regulators across multiple jurisdictions were watching. Yet the collapse of FTX, one of the world’s largest crypto exchanges, still blindsided markets, creditors, and supervisors alike. The problem wasn’t simply the absence of controls at the firm. It was what the broader system failed to assemble in time: signals that were there, visible in public filings, regulatory correspondence, and industry chatter, but never connected into a coherent picture until billions had evaporated.

The next crisis won’t start with a missing regulation. It will start with someone not joining the dots.

This is the central argument of this piece: that the next significant financial event will be made materially worse by a failure to understand, integrate, and act on regulatory information in time, which can be called a compliance intelligence failure. And unlike systemic leverage or asset bubbles, this is a failure mode that is entirely preventable.

What is compliance intelligence, exactly?

It’s worth being precise about the term, because it is often confused with something narrower. Compliance intelligence is not a regulatory update newsletter. It is not a checklist reviewed by the legal team once a quarter. It is the active, ongoing process of knowing what regulators across jurisdictions are saying, changing, and enforcing, and connecting that knowledge to your firm’s specific products, customers, and risk exposures.

Compliance intelligence is the difference between reading each weather report in isolation and actually seeing that a storm is forming.

Tick-box compliance asks: Are we technically within the rules today? Intelligence-driven compliance asks something harder: Where are the rules moving, and are we positioned ahead of that shift? One is reactive. The other gives a firm room to move first. And the difference is far from academic, because a regulator’s posture often tightens well before any rule formally changes, through thematic reviews, supervisory letters, enforcement priorities, and the speeches of senior officials that careful observers learn to read closely.

What past crises really tell us

Three episodes are instructive here, and none of them are particularly contested in retrospect. The 2008 global financial crisis is the obvious starting point. What is striking, looking back, is not that regulators felt no concern, but how fragmented and compartmentalised that concern was. Supervisors in the US flagged consumer lending risks. European authorities worried about liquidity. Firm-level risk managers saw their own books. Nobody assembled the full picture until it was too late to matter.

The IL&FS collapse in India in 2018 followed a similar pattern. The infrastructure lender had accumulated debt across a complex web of subsidiaries, and the warning signs, including audit qualifications, liquidity pressure, and governance concerns, were present in various regulatory and financial disclosures for months before the default. A subsequent RBI report found that non-performing assets had been understated for years. The information existed. The connective tissue did not.

More recently, the implosion of several major crypto entities demonstrated the same failure in a newer context. Enforcement actions, regulatory warnings, and solvency concerns appeared in public records well ahead of collapse. What was absent was the capacity or the discipline to synthesise those signals and act on them early.

In each case, the post-mortem verdict is the same: the warnings were there. The regulatory intelligence to interpret and act on them was not.

Defining a compliance intelligence failure

A compliance intelligence failure occurs when the information needed to make better decisions is available, but is missed, siloed, or treated as inert background noise rather than actionable signal. More specifically, it happens when signals, regulators’ new guidance, thematic reviews, enforcement patterns across peer firms, supervisory speeches, are not picked up in time, or are picked up but not escalated or acted on.

It also occurs when cross-border differences in regulatory posture are not properly mapped. A global institution operating across the EU, US, UK, and Asia faces materially different supervisory environments. Underestimating the divergence or failing to track where different regulators are heading creates blind spots that compound into systemic exposure.

Consider two hypothetical but entirely plausible examples. A consumer lender ignores a series of supervisory speeches and thematic review findings in one region highlighting rising arrears in unsecured credit while aggressively scaling a similar product in a second market. Or a bank receives no direct enforcement action but misses a pattern of transaction monitoring findings across peer institutions in another jurisdiction, a pattern that suggests its own controls will face scrutiny within months.

Neither firm is breaking any rule at the point the signals appear. But both are accumulating invisible risk, of the kind that becomes obvious only in hindsight.

What firms should be doing differently

The practical response is not simply to hire more compliance staff. It is to build a genuine regulatory intelligence function: one with clear ownership, a real seat in business decisions, and the standing to flag a shift before it becomes a problem.

That starts with centralised tracking. Key regulatory outputs across major jurisdictions, enforcement decisions, consultation papers, thematic reviews, supervisory priorities, need to be monitored systematically, not left to individual legal and compliance teams working in their own lanes. Someone needs to own the synthesis, and that function needs authority to push insights into the business rather than circulate a weekly reading list.

The second step is mapping regulatory themes to actual products and risk exposures. If supervisors across three jurisdictions are tightening their expectations around retail leverage, that should immediately translate into a conversation about specific products, specific limits, and specific controls, not a general awareness note. Intelligence without action is just expensive monitoring.

This is precisely the kind of capability that tools like Sherlocq are designed to support. Across multiple jurisdictions, it lets a compliance or risk team pull together what regulators have actually said, including enforcement trends, supervisory guidance, and thematic review findings, into a single sourced answer in minutes, and then read it against the firm’s own products and exposures. That is the connective work that usually goes undone: not predicting the future, but seeing the signals that are already on the record before they harden into formal requirements or enforcement.

Third, regulatory intelligence needs to enter the firm’s governance structures, not as a newsletter distributed to senior management, but as a substantive input to risk appetite discussions, board packs, product approvals, and model governance reviews. The firms that were best positioned going into past crises were not necessarily the smartest; they were the ones where regulatory intelligence was treated as a first-class risk input rather than a compliance housekeeping function.

Finally, firms should build a clear, cross-jurisdiction view of where supervisory risk is concentrating. Where are supervisors tightening? What patterns keep recurring in enforcement actions? Where does that overlap with the firm’s own risk profile? Keeping the answers to those questions current, and revisiting them as new

guidance and enforcement land, is the closest thing available to a crisis-prevention mechanism that actually works.

Risk grows in the blind spots

If past crises taught us anything, it is that systemic risk does not appear out of nowhere. It accumulates, quietly and invisibly, in the gaps between what is known and what is connected: between the regulatory signal and the business decision, between the supervisory speech and the product strategy review.

The next time markets crack, we will again look back at speeches, circulars, inspection reports, and enforcement actions and say: the warnings were there. The only real question is whether firms build the intelligence infrastructure to see them in time, or whether, once again, the dots remain stubbornly unjoined.

In your own organisation, is regulatory information something that is monitored, or something that is actually used to change decisions?

Ready to bring intelligence
to your compliance work?

Join compliance professionals, lawyers, risk managers, and regulators already using Sherlocq.

Try Sherlocq Talk to our team