When Your Regulator Knows More Than You

When Your Regulator Knows More Than You

Supervisors are quietly building out data science teams. Here is what that means in practice.

There is a quiet shift happening in the relationship between regulated firms and their supervisors, and most risk and compliance teams have not fully reckoned with it yet.

For much of the past two decades, the dynamic in supervisory oversight followed a familiar rhythm. Firms held the data. Regulators asked for it and firms decided how it was packaged, submitted, and explained. Supervisors were, in many respects, dependent on the information firms chose to surface. Skilled risk and compliance professionals understood this. Preparation for an inspection was certainly about substance, but also about presentation.

That rhythm is breaking down. Supervisors now have the tools to look across board minutes, management reports, policies and procedures, and data sets, in ways they have never had before. A supervisor might be able to determine the content of board meetings, summarize complex policies, compare policies with regulatory requirements, and query large data sets. Weeks of work to determine initial findings can now be compressed to day one of the inspection.

The Intelligence Gap Has Reversed

Supervisory bodies across areas of focus such as financial stability, data protection, consumer markets, and beyond have made significant investments in data infrastructure over the past several years. The UK’s Financial Conduct Authority, for instance, has built out its data science capabilities to monitor transaction patterns, flag outliers, and model firm behaviours at scale. The European Central Bank’s supervisory arm uses automated tools to cross-reference disclosures and identify inconsistencies. In the United States, the SEC’s enforcement division has leaned heavily into data analytics to detect potential misconduct well before a formal investigation is triggered. Every regulator in the UAE is building out SupTech capabilities, which often involve an element of artificial intelligence.

The result is that regulators increasingly arrive at conversations with the regulated population already holding a view. This view has been formed not from what firms told them, but from what the data showed on its own. A supervisor might already know your complaints volumes spiked three months before you flagged a product concern, that your transaction reporting indicates patterns at odds with your stated business model, or that your conduct metrics make you an outlier against peers. None of that came from you.

Your risk and compliance teams, meanwhile, may be working from the same spreadsheets and manual attestation processes they used five years ago.

What This Means in Practice

The asymmetry creates several concrete risks that firms need to take seriously.

Inspection surprise is now a genuine threat. When regulators could only see what you showed them, inspections were broadly manageable. Now, a supervisor may enter a meeting with analytical findings your own team has not surfaced internally. The gap between what your regulator knows and what your risk and compliance functions know is, itself, a finding that speaks to the maturity and effectiveness of your risk management.

Regulatory dialogue has changed the register. There was a time when firms could reasonably expect to set the terms of a supervisory conversation. That time has passed in many sectors. Regulators who have done their analytical homework are less interested in your narrative and more focused on reconciling your explanations against the patterns they have already seen. Firms that come to these meetings underprepared, armed with high-level summaries rather than granular insight, lose credibility quickly and often permanently.

Enforcement timelines are compressing. Because data tools allow supervisors to build evidential pictures faster, the interval between a problem emerging and a regulator acting might shorten considerably. Firms can no longer rely on the slow pace of traditional supervision to provide a window for self-correction.

The Strategic Response

None of this means firms are powerless. It does mean that the traditional compliance playbook needs updating.

The most effective response begins with honest self-assessment. What does your data show about how your business is operating? Not the curated version prepared for a regulatory return, but the unfiltered picture. And just as important: do you know what your regulator now expects? The firms that fare best are the ones that can see their own position the way a supervisor would, measuring their policies and disclosures against current regulatory requirements and expectations.

This also means risk and compliance functions need a closer relationship with data and technology teams. The skill set required to interpret regulatory data, identify anomalies, and construct a coherent picture of operational risk is not the same skill set that drafts policy frameworks and manages audit logs. Both are necessary. Firms that treat them as separate disciplines are creating a structural gap.

Equally important is rethinking how you approach regulatory dialogue. The posture of managing a narrative is increasingly counterproductive. Regulators with strong analytical capability can spot inconsistency, and a firm that appears to be shaping rather than sharing information damages its relationship with its supervisor in ways that are difficult to repair. Candour, particularly where your data tells a complicated story, tends to be a better strategy than polish.

Finally, horizon-scanning matters more than it ever did. Supervisors keep building capability, expanding what they collect, and sharing intelligence across borders, and the volume of regulatory output they generate is impossible to track by hand across multiple jurisdictions. What a regulator cannot see today they may well see in twelve months, and what they expect of you shifts just as quickly. A compliance programme built around today’s rules, rather than where the rules are heading, is already behind.

The Underlying Message

The regulatory asymmetry that is emerging across sectors is not, at its core, a technology story. It is about who holds the better information, and for the first time in a long while, that might be the regulator.

For a generation, regulated firms operated with a structural advantage in that equation. That advantage has eroded significantly, and in some sectors it is reversing. Risk and compliance teams that understand this shift and build their programmes accordingly will be better equipped to manage inspections, engage in productive regulatory dialogue, and reduce their enforcement exposure.

Those that do not may find that the most consequential conversation with their regulator is not the one they prepared for, but the one they never saw coming.

See how compliance and legal teams use Sherlocq to map an issue to the relevant rules and enforcement precedent across jurisdictions in minutes. Book a private demo at sherlocq.com

Sources

Ready to bring intelligence
to your compliance work?

Join compliance professionals, lawyers, risk managers, and regulators already using Sherlocq.

Try Sherlocq Talk to our team