EU vs US: Navigating Regulatory Expectations

When the Regulator Calls First, You Have Already Lost I launched a fintech product in the US and the UK on the same day in 2017. It felt like a milestone. Two major markets, simultaneous entry, the kind of thing I put in an investor update with some pride. What I did not fully appreciate at the time was that I had not launched one product into two markets. I had launched two entirely different regulatory relationships, and I only understood that after one of them had already gone wrong. The US engagement started with a detailed inquiry. A user complaint had reached the regulator before my proactive risk framework had reached anyone. The product was live, customers were onboarding, and the first substantive conversation I had with a US regulator was reactive. I was explaining myself rather than introducing myself. The tone of that distinction matters more than most founders realise until they are sitting in it. The UK experience was almost the inverse. I had pre-application meetings, scenario testing, and a structured review of my risk framework before a single customer had touched the product. The FCA wanted to understand how I thought before they watched how I behaved. At the time, I found the process slow and occasionally bureaucratic. In hindsight, I would have paid for it. The Moment I Realised I Was Already Behind Here is the part I do not often tell. By the time I understood that my US launch was already out of compliance – not catastrophically, but materially – I had been operating for several weeks. The product had passed my internal review. It had passed legal. I had built a risk framework I was genuinely proud of. What I had not done was map my compliance assumptions against US-specific regulatory philosophy, because I had made the mistake of assuming that a well-built product with strong internal governance would translate cleanly across jurisdictions. It did not. The first user complaint was not about the product. It was about a data handling notice. A feature that no customer had meaningfully used – and that most of my team had forgotten was even in the product – had a data retention disclosure that did not meet state-level requirements in one US market. The regulator’s first question to me was not about my business model, my risk controls, or my financial standing. It was about my data retention policy for a feature my customers had ignored. I had spent months perfecting the user experience. The regulator’s opening question was about a disclosure buried in a settings page. There is a lesson in that irony that I have never fully stopped finding uncomfortable. Three Things I Now Understand That I Did Not Then The rules are not the philosophy. Every jurisdiction has rules. What determines how those rules are applied – the timing of engagement, the tolerance for ambiguity, the willingness to work through uncertainty with me – is the philosophy sitting underneath them. The US regulatory model, particularly in financial services, operates on a philosophy of permissiveness with enforcement backstop. I am broadly allowed to innovate, and the system corrects through action after the fact. The EU and UK model is built on a philosophy of pre-emptive assurance. The regulator wants confidence before I build momentum, not accountability after I have it. Neither philosophy is superior. But confusing one for the other is where serious exposure lives. Proactive engagement is not a soft skill in the EU – it is a market entry strategy. The assumption most founders carry into European regulatory engagement is that more rules mean slower progress. The opposite is often true. Because EU and UK regulators expect pre-engagement, they are structurally set up to give it to me. The FCA’s innovation pathways, the sandbox frameworks, the pre-application guidance – these exist because the philosophy demands proactive dialogue. If I use them properly, I arrive at launch with documented regulatory alignment rather than undisclosed risk. That is not a slower path to market. That is a cleaner one. The regulator does not surprise me. I surprise myself. This is the thing I keep coming back to. In both markets, the regulator behaved exactly as their published guidance, their public speeches, and their prior enforcement actions would have predicted. I was the one who had not read the signals correctly. I had read the rules. I had not read the character of the institution. Those are different things, and the gap between them is where most cross-border regulatory failure actually happens. What This Means If You Are Building Across Jurisdictions Now If I am running a fintech, a GRC platform, or any regulated product across more than one geography, the question is not whether I have legal coverage in each market. The question is whether the person responsible for regulatory strategy in each market has genuine fluency in how that regulator thinks, not just what it requires. Rules can be read by a good lawyer. Philosophy has to be learned through proximity – through pre-meetings, through sandbox engagement, through understanding what a regulator has said in its last five public consultations and why. The organisations I have seen handle multi-jurisdictional launches well share one common trait: they treat regulatory engagement as a relationship to be built before it is needed, not a process to be managed after something goes wrong. That requires time, and it requires the kind of senior attention that often gets deprioritised in favour of product and commercial priorities. I have made that deprioritisation myself. I am not exempt from the lesson. It also requires the kind of honest internal culture where the compliance team feels genuinely empowered to raise a concern before launch, not after. That is a different conversation – one I have written about elsewhere – but it is inseparable from this one. The Closing Thought Two regulators, one product, entirely different outcomes – and the difference had nothing to do with the quality of what

Quantitative Tightening and the Macroeconomic Reality

When the System Tightens: What Quantitative Tightening Actually Does to Your Risk Models I was sitting across a conference table from the risk team at a mid-sized asset manager in late 2022. Good people, experienced people, the kind of shop that had weathered 2008, navigated the COVID volatility, and built their frameworks carefully over two decades of hard lessons. We were reviewing their liquidity stress scenarios, the kind of exercise that, in most years, is professionally useful without being professionally urgent. Their models looked fine, their buffers looked more than adequate. I ran the numbers three times, not because anything was wrong, but because the results seemed too comfortable for the environment we were sitting in. The Bank of England had been raising rates, the Fed was well into its tightening cycle. Quantitative tightening, the deliberate reduction of central bank balance sheets after years of extraordinary expansion, had been underway for months. And yet everything on those spreadsheets looked orderly. I should have trusted the discomfort more than the spreadsheets. The Situation The problem with QT is that it is not a single event I can model. It is an atmospheric change. Between 2009 and 2021, central banks globally expanded their balance sheets to an almost incomprehensible degree, the Fed alone went from roughly $900bn to over $8 trillion. That capital had to go somewhere, it found its way into asset valuations, into compressed credit spreads, into the quiet assumption baked into almost every risk model that liquidity was ambient, that it was simply there, like oxygen. What QT does is reduce the oxygen concentration, slowly, incrementally. And because the reduction is gradual, the feedback loop is delayed, which is precisely what makes it dangerous. By Q1 2023, the asset manager I had been advising was seeing things that their models had not flagged as probable. Refinancing costs had jumped in ways that ate into assumptions built during a period of structurally different rates. Counterparty appetite had thinned, not dramatically, not catastrophically, but perceptibly. Two positions they had classified as liquid turned out to be liquid in theory and illiquid in practice. There was no single headline event, no Lehman moment, nothing had broken, everything had just become slightly harder, simultaneously, across every dimension that mattered at once. I remember one of the senior risk managers saying, with a kind of tired accuracy: “We planned for the doors to get narrower, we did not plan for all of them to get narrower at the same time.” That line stayed with me, because it was exactly right, and it described something that conventional stress testing, built around individual shock scenarios, is structurally ill-equipped to capture. Three Things QT Does That the Rates Headline Doesn’t Tell You **First: it changes what “liquid” means.** In a QE environment, markets are deep because central bank purchases create a persistent buyer with no return requirement. Remove that buyer and liquidity becomes conditional, it exists when sentiment is stable and disappears precisely when you need it most, which is to say, when sentiment isn’t. Assets that traded freely in 2020 and 2021 carried liquidity assumptions that were products of that specific environment, those assumptions did not automatically update when the environment changed. The models were not wrong, they were answering a question that no longer reflected reality. **Second: the transmission lag is long enough to be genuinely deceptive.** Rate rises are felt quickly, in mortgage costs, in corporate debt service, in consumer spending data. Balance sheet reduction works over a longer cycle, through the gradual withdrawal of reserve balances from the banking system and the slow repricing of risk appetite throughout the credit chain. This means institutions can operate inside deteriorating conditions for months before anything manifests in their numbers, the system tightens before the data tells you the system is tightening. By the time the evidence is visible, the adjustment window has narrowed considerably. **Third: QT interacts with everything else at once.** The rates shock was the headline, the balance sheet reduction was the mechanism running underneath it, invisibly. Taken alone, either would have been manageable for most well-run institutions, together, they changed the physics of the environment. Duration risk repriced, collateral values shifted, the correlation assumptions in multi-asset portfolios, correlations built during a decade of suppressed volatility, began to behave unexpectedly. Risk managers who had stress-tested each factor individually found themselves in a world where the factors had become entangled. What This Means for Your Organisation Right Now The question most risk functions are asking is whether they can survive a rate shock, that is the right question, but it is the second question. The first question is whether your liquidity assumptions, your correlation assumptions, and your counterparty models were calibrated in a world that no longer exists. For most institutions, the honest answer is: partially. The models were updated, but the underlying assumptions about how markets behave, how liquidity moves, and how correlated risk manifests were formed in an extended period of exceptional monetary accommodation. QT is not just a policy reversal, it is the removal of the conditions under which modern risk management frameworks were largely built and refined. Running those frameworks forward without interrogating their foundations is not risk management, it is institutional memory applied to a changed environment and called discipline. The asset manager I mentioned did not fail, they adapted, but later than they should have, and at greater cost than necessary. The lesson was not that their risk team was inadequate, the lesson was that the environment had changed its operating assumptions and nobody had formally updated theirs to match. Closing The market does not care when your models were last calibrated, and it is completely indifferent to the decade in which your assumptions were formed.

What Basel III Is Really Testing in Banks Today

When Passing Every Test Is Not the Same as Being Prepared I sat across from a risk committee in Q3 2022 that had done everything right on paper. Liquidity coverage ratio was above threshold, net stable funding ratio was solid, and capital filings were submitted on time, every quarter, without drama. The room carried the particular confidence of people who had followed the rules and knew it. Six weeks later, a rate shock hit. The CFO called me, and he was not panicking, which, looking back, made it worse. Panic I could have worked with. What he had instead was genuine bewilderment. “We passed every stress test, Laksh. How is this happening?” I gave him an honest answer in that call, but the question itself stayed with me for much longer. Because he was right, they had passed every test, and they were still unprepared. The gap, between the test and the reality, is what I have been thinking about ever since. The Situation Here is what their balance sheet actually looked like, beneath the ratios. I saw that the product team had spent eighteen months pushing into longer-duration liabilities because the margins were attractive. Treasury had flagged concerns internally, twice. Both times the conversation ended when someone cited the capital ratios as evidence the position was sound. I decided that the stress tests had been produced by a small team, reviewed by risk, filed with the regulator, and essentially not touched again until the next cycle. I also decided that capital planning happened once a year, in a process the business units attended long enough to sign the assumptions and then left. No one had broken a rule. Every number was real. I followed the framework with genuine diligence. However, I did not think. The stress tests were treated as a compliance artefact, something I produce for the regulator, not something I use to make a better decision the following Monday. When the rate environment shifted faster than the annual cycle had modelled, there was no mechanism to catch it. The treasury desk and the product desk had been living in parallel universes, and Basel III had given them enough paperwork in common to feel like they were collaborating. I say with no pleasure that a bank can be a model Basel III institution and still be structurally unprepared for a real-world shock. I designed the framework to be rigorous, but I also implemented it in a way that is backward-looking. Filing last quarter’s ratios tells me where I was. It tells me almost nothing about where the next decision is taking me. Three Things That Conversation Confirmed **Resilience is an operating discipline, not a reported state.** I noticed that the institutions that held through the 2022 rate environment shared something: risk was not a department I consulted after the fact. It was a presence in the room when the product got priced, when the liability structure got approved, when the assumption about customer behaviour got embedded in a model. The ratio I filed was a consequence of the thinking that had already happened. Not the other way around. Most banks have inverted this. I use the ratio to justify decisions already made. When the ratio looks acceptable, the conversation stops. That is not risk management. That is risk rationalisation. **Stress testing works only if someone owns the result.** I found that the problem with how stress testing is practised in the majority of mid-sized institutions is not the methodology. The models are often genuinely sophisticated. The problem is what happens the morning after the document is filed. I ask myself, who reads it? Who changes something because of it? In that 2022 committee, the answer was effectively no one, not because they were negligent, but because the process had no forcing function attached to it. Stress testing had become a production exercise. A skilled team spent weeks building a credible scenario, and the output lived in a folder. I believe that stress testing earns its cost only when it is connected to a decision. When a scenario changes a pricing assumption, modifies a product approval, or triggers a board conversation about exposure, that is when it does the thing it was designed to do. Otherwise, it is expensive documentation. **Capital planning done annually is capital planning done wrong.** I think that the world that Basel III was designed for no longer moves at an annual cycle. Rate environments shift in quarters. Funding markets can reprice in weeks. The assumption embedded in most capital planning processes, that I review the balance sheet once a year in a structured exercise, is structurally mismatched with how risk actually arrives. It arrives continuously. It arrives in product decisions and pricing decisions and hiring decisions and the small assumptions that compound quietly until one external event makes them visible all at once. I have seen that the institutions that navigate volatility most effectively treat capital planning as a standing discipline with a live component, regular, shorter reviews that connect the balance sheet to the decisions being made now, not the decisions made last autumn. What This Means for Your Organisation If you are a CFO, a CRO, or a board member reading this, the question worth asking is not whether your ratios are in order. They probably are. The question is whether the people approving products, pricing liabilities, and building forecasts have ever been in the same room as the stress test output. Whether your capital planning process ends when the document is filed or when the business has changed something because of it. Whether your treasury desk and your product desk are genuinely in conversation before the decision, or only after the loss has been recognised. The answer to that question tells me more about your resilience than any number you will report this quarter. I gave the industry a language for resilience. What I cannot mandate is whether you use it to think or merely to report. The banks that

The Real Signal Behind Bonus Season in Financial Services

The Sentence Before the Number Bonus season has a particular texture in financial services. There is the waiting, which everyone pretends not to be doing. There is the calibration meeting, which everyone pretends is objective. And then there is the conversation itself, twelve minutes, sometimes fifteen, in which an institution attempts to compress a human being’s entire year into a number and a handshake. Most organisations do this reasonably well. They train their managers. They prepare talking points. They ensure the number is fair, or fair enough, or at least defensible. What almost no organisation does well is the sentence that comes before the number, the one that names, specifically and without ceremony, what the person actually did and why it was hard. That gap, between the number and the sentence, is where a surprising amount of talent quietly decides to leave., – What Happened in January In January this year, I sat in a room with a team that had done something genuinely difficult. Eighteen months. A cross-regional data platform spanning four geographies, hundreds of stakeholders, and the kind of legacy infrastructure that makes perfectly sensible engineers stare at their laptops in silence. The numbers had landed. The bonuses were fair, I had fought for them to be fair, which is its own kind of exhausting process that nobody outside the conversation ever fully sees. The room was quiet in the wrong way. I had expected relief. I got politeness. And in the gap between those two things, I recognised something I should have understood years earlier: the team was not waiting for the number. They were waiting for the sentence before it. The one that said: *we know what you built, we know what it cost, and we know it would not have happened without you*. What I had prepared was thorough. What I had not prepared was precise. I had the data. I did not have the language. And watching people absorb a fair number with the affect of people receiving a utility bill, I understood, slightly too late, though still not entirely too late, that I had confused adequate compensation with actual recognition. They are not the same thing, and conflating them is one of the more quietly expensive mistakes a leader makes. We recovered. The conversations that followed were different because I made them different, more specific, more named, more willing to say the difficult thing aloud: *this was genuinely hard and you are genuinely good*. But I did not forget the quiet in that room., – What Recognition Actually Is The first thing worth saying is this: recognition is not praise. Praise is general, *you did a great job, the team was brilliant, we really appreciate everything you do*. It is the warm noise organisations make when they mean well but have not done the work of paying attention. People are polite about praise. They say thank you. They do not remember it. Recognition is specific. It names the thing. It says: the moment in October when you held the vendor negotiation together for three weeks while two of your leads were out, that was the moment. It says: the reason this platform works across Singapore and London and New York is because you made four hundred small decisions well, in sequence, without anyone asking you to. Recognition is evidence that someone was watching. That is what makes it different. Praise says *you are valued*. Recognition says *you were seen*. The distinction matters because being seen is the thing that compounds. It shapes how a person walks into the next difficult year, with energy, or merely obligation. Both will deliver. Only one will stay., – Why Institutions Default to Currency The second thing worth understanding is why most organisations reach for the number when they should be reaching for the sentence. It is not negligence, mostly. It is measurement. Organisations are extraordinarily good at quantifying what they can quantify, and a bonus is clean, it has a figure, a rationale, a market benchmark. It can be defended in a calibration meeting. It can be put in a letter. A precise sentence cannot be put in a letter. Or rather, it can, but writing it requires the manager to have been paying close enough attention to know what to write. That is the actual cost. Not the money. The attention. Most senior leaders are not inattentive people. They are overextended people who have learned to trust the systems, the frameworks, the ratings, the pay bands, to carry the weight of recognition. The systems are fine at compensation. They are structurally incapable of specificity. Nobody has ever felt deeply seen by a pay band., – The Practical Implication None of this requires a restructured compensation process, a new framework, or a leadership offsite. It requires about twenty minutes of preparation per conversation, the kind of preparation where you actually write down, before you enter the room, the two or three things that were specifically true about this person’s year. Not the general. The named. What did they do that was hard? What would not have happened without them? Where did they make a call that others would have deferred? The answers to those questions are the sentence. And the sentence, delivered before the number, changes the architecture of the conversation entirely. The number stops being the point. It becomes confirmation of something the person already knows you understand. That is not a small shift. For a team that has spent eighteen months building something genuinely difficult, it is the difference between leaving the room satisfied and leaving the room seen. And seen, as it turns out, is the thing people remember when they are deciding whether to do another eighteen months., – Bonuses compensate. Sentences remember. The organisations that understand the difference will find out, slowly and then all at once, that their people do too., –

AI Risk Control Strategy for Global Banking Operations

I first noticed something off in 2022. A tier-one bank’s AI reported zero issues across a full quarter of transaction monitoring. The risk committee reviewed the numbers, saw the clean run, and moved on. False positives were down. Processing time had dropped by sixty percent. By every measure they had, the model worked exactly as designed. A mid-level analyst thought something felt wrong. Not a hunch without reason. She had fifteen years in correspondent banking. Fifteen years watching money move through nested accounts, cross-border flows, paper entities that seemed solid one day and vanished the next. She read those rhythms like a cardiologist reads an ECG, not just the spikes, but the silences that shouldn’t be that quiet., – The Situation She flagged a counterparty. When I asked what had triggered her concern, she hesitated. The honest answer? She couldn’t fully explain it. The flows looked normal. The entity had paperwork. The model had processed and cleared it without a hitch. No single data point stood out. What she had was a shape. A pattern she’d seen before, not identical, but close enough that fifteen years of experience made her notice. The counterparty was structuring: deliberately breaking transactions into pieces to stay below automated detection limits. The method wasn’t new, but the setup, the jurisdictions, the counterparty type, the timing, fell outside the model’s training data. It had never encountered this exact arrangement, so it said nothing. Here’s what haunts me about that year. The model wasn’t broken. It did exactly what it was built to do, precisely. The risk committee wasn’t careless. They reviewed the outputs they were given. The governance process looked correct from every angle it could see. That’s the problem. The system had no visible failure mode for the people responsible for spotting failures. It had no red light. It only had the absence of one, and the organisation had, over time and without anyone saying it aloud, learned to treat that silence as safety., – What Actually Failed The first failure wasn’t the model. It was the way we thought about what the AI was doing. Some AI risk governance treats model metrics as a stand-in for real-world coverage. False positives. Processing speed. Accuracy on test data. These numbers matter. They tell you something real. But they don’t tell you what the model has never seen. A model trained on past transactions will catch patterns it knows. It won’t notice when the world changes, when a new structuring trick emerges, when a rarely used jurisdiction becomes a conduit. It can’t warn you about its own blind spots. That’s not a flaw in design. It’s how these systems learn. The second failure was subtler. When AI metrics look good for long stretches, organisations adjust their human oversight accordingly. Senior analysts spend less time on cleared transactions. Review processes thin out around the automated layer. That makes sense, you wouldn’t manually check every calculation a spreadsheet makes. But the analogy is wrong. A spreadsheet follows rules consistently. An AI model learns patterns from data, and the patterns it never saw are the ones it will never find. The oversight we’re cutting back is exactly the oversight we need to catch what the model misses. The third failure is the one that stays with me. It’s what happened to the analyst’s instinct inside the organisation before that moment. She had flagged things before that didn’t turn into confirmed issues. That’s how real pattern recognition works, not every signal leads to a finding. In some places, repeated flags without outcomes become a professional liability. Analysts learn to adjust their instincts to match what the model approves. The pressure, unspoken but real, pushes toward alignment with the machine. When the machine says nothing is wrong, insisting something is feels risky. Organisations can quietly erode that confidence over time without meaning to., – What This Means for Your Organisation If you run AI-assisted transaction monitoring, or any AI-assisted risk function in a regulated setting, the question isn’t whether your model performs well. It’s whether your oversight is built around what the model cannot see, or whether it’s been quietly reshaped around what the model can process. Those are not the same structures. The institutions getting this right aren’t choosing between AI capability and human judgment. They’re being precise about what each can actually do. AI handles volume and applies learned patterns at a scale no team can match. Experienced analysts spot anomalies outside those patterns, not because they’re better than the model, but because they’re different from it in the ways that count. The gap between the model’s world and reality isn’t something you close by improving the model. You close it by staffing it., – The best AI risk control system I’ve seen wasn’t the one with the strongest model. It was the one that knew, without doubt, where the model ended and what had to happen next. A system that understands its limits is still a system. One that doesn’t is a liability wearing impressive metrics.

Operational Resilience Beyond DORA: 2026 Perspectives

Operational Resilience Is Not a Document. It Is a Data Problem. DORA is already law. Most institutions are still working out whether they can actually comply with it. That distinction matters. There is a wide gulf between an organisation that has spent eighteen months building a compliance framework and one that can answer the questions the framework exists to answer. The first is visible. The second is rare. The gap between them is not a regulatory problem, it is an infrastructural one the industry has quietly avoided for years. The March 2026 Information Register submission is about to make that avoidance very loud. — The Room That Went Quiet Early in 2025, I sat with the CRO of a mid-sized financial institution. DORA had just become enforceable. Her team had done what looked, by any reasonable standard, like serious work. Eighteen months of it. Policy documents. Risk registers. Governance structures. Third-party mapping. They had the architecture of compliance. It was genuinely impressive, the kind of work that gets presented well in a board pack. Then someone in the room asked about the March 2026 Information Register submission. The room went quiet. Not the polite quiet of people organising their thoughts. The other kind, where everyone is doing rapid mental arithmetic and arriving at the same uncomfortable answer. The data needed to populate that register simply did not exist in a usable form. It was distributed across systems that did not talk to each other, owned by teams with different definitions of the same terms, stored in formats that made aggregation a manual project measured in weeks, not hours. Eighteen months of compliance work. The underlying data layer: untouched. I have been in enough of these rooms to know this silence is not unique to that institution. I have seen versions of it in London, in Dubai, in Mumbai. Different organisations, different regulators, identical pause. What struck me that day was not the gap itself, I had expected to find gaps. It was the specific shape of it. The team had built compliance theatre. Beautifully documented. Operationally hollow. — Three Things That Conversation Made Undeniable **The first is that most institutions confuse documentation with readiness.** This is not laziness or incompetence. It is a rational response to how compliance has historically been evaluated. Regulators asked for evidence of frameworks. Organisations produced frameworks. The feedback loop rewarded paperwork. DORA has changed the question being asked. The Information Register is not a document, it is a live query run against your actual data architecture. You cannot write your way to a passing grade. The data either exists in a coherent, mappable form, or it does not. **The second is that this is the same problem wearing different clothes.** The broken data layer that cannot support an Information Register submission is the same broken data layer that cannot support AI or ML initiatives. When organisations talk about data readiness for artificial intelligence, and the conversation comes up constantly now, they often frame it as a new investment required for new capabilities. In most cases, it is neither new nor optional. It is a pre-existing infrastructure deficit that AI ambitions have simply made impossible to defer. I wrote about the adjacent problem, the way third-party data creates hidden exposure, in an earlier piece on [rethinking third-party risk](https://lakshvaswani.com/when-partners-become-liabilities-rethinking-third-party-risk/). The pattern is the same: the problem is not the risk you can see. It is the one your data architecture cannot tell you about. **The third is the one the industry least wants to hear.** Operational resilience frameworks that rest on poor data infrastructure are not frameworks. They are documents waiting to embarrass you. The scenario matters here: a genuine operational disruption, a regulatory examination, a cyber incident requiring rapid forensics. All of them require the same thing, accurate, accessible, well-governed data about your critical functions, your dependencies, and your recovery pathways. If that data does not exist in a usable form under normal conditions, it will not materialise under pressure. I have written previously about [the human side of cyber risk](https://lakshvaswani.com/when-firewalls-fail-the-human-side-of-cyber-risk/) and the way institutional confidence about resilience tends to collapse precisely when it is tested. Data readiness is the structural version of that same overconfidence. — What This Means for the Institutions Still Building If your organisation is in the cohort that has the framework but not the data infrastructure to support it, and based on everything I am seeing, that is most of the industry, the path forward has a specific sequence. The Information Register deadline is the forcing function, but treating it as a one-time submission exercise would be a significant mistake. The register is a symptom question. The actual question it is asking is whether your data governance, your system architecture, and your critical function mapping are coherent enough to produce a reliable, auditable output on demand. Answering yes in 2026 and reverting to fragmentation in 2027 solves nothing. Continuous readiness cannot be delegated to a project team that convenes before a regulatory deadline. It has to be owned at the top, funded accordingly, and treated as a permanent operational capability, not an event. This also has direct implications for AI ambitions. Boards and executive committees increasingly want to understand when and how they can deploy AI and ML across risk and compliance functions. The honest answer is that those capabilities will perform in direct proportion to the quality of the data they run on. Closing the data preparedness gap is not a precondition for AI, it is the work itself. — The institutions that come out of the DORA era in the strongest position will not be the ones with the most sophisticated frameworks. They will be the ones that quietly fixed their data infrastructure while everyone else was still formatting governance documents. A resilience framework that relies on data you cannot actually produce is not a framework. It is a liability you have not invoiced yet.

Custody Services Myth-Buster: The Hidden Revenue Story

Back-Office in Name Only: Why Your Custody Relationship Is a Capital Decision I’ve seen an expensive mistake that never appears on a risk register. It’s not a loss event. It’s not a failed audit. It’s revenue that simply doesn’t exist because nobody with the authority to ask for it ever did. Custody services are the most persistent example of this in institutional finance. The industry narrative has always been comfortable: a custodian holds your assets, settles your trades, and sends you a report at month-end. Passive. Reliable. Boring. The kind of thing you hand to someone competent and sensible and then stop thinking about. That narrative is wrong. Not partially wrong, structurally wrong. And the cost of believing it is not abstract. It shows up in yield you didn’t earn, capital you didn’t deploy efficiently, and withholding tax you paid and never reclaimed. The custodian wasn’t hiding these opportunities. Most of the time, nobody was asking. — The Founder I Got Wrong Eighteen months ago, I wrote a post that touched on this. It landed reasonably well, which meant people agreed with the surface observation: founders and senior executives often don’t know what revenue they’re leaving inside their custody relationships. Securities lending sitting dormant. Collateral fragmented across trading desks. Tax reclaim processes still manual, still slow, still leaking. I framed it as a discovery problem. Executives weren’t aware. Once they knew, they would act. I was half right. Half right in a way that cost the argument its real point. Last month, I went back to that same founder. Eighteen months on. They had, in fact, renegotiated the custody relationship. Securities lending was activated. Collateral had been consolidated. The withholding tax reclaim process, cross-border dividends, treaty benefits, the entire machinery, was finally automated. Material improvement across all three. I asked what had actually changed internally to make it happen. He said: “We had to stop treating it as the CFO’s problem.” I sat with that for a moment. Because what he meant was not that the CFO had been failing. He meant the relationship had been categorised as operational, handed down the chain to people with competence but without authority, and quietly left there. Nobody at principal level was asking the economics question. So nobody answered it. The custodian wasn’t withholding anything. The client had simply decided, implicitly, without ever actually deciding, that this was a back-office matter. I got it wrong in 2024 because I diagnosed the symptom instead of the condition. Awareness was never the constraint. Ownership was. — What Custody Services Actually Are Let me be precise about what is sitting inside these relationships, because the vocabulary matters. **Securities lending** is the most straightforward and the most underused. When you hold equity positions you’re not actively trading, a custodian can lend those securities to short sellers and other market participants in exchange for collateral and a fee. The asset remains economically yours. The yield is incremental. For funds with meaningful long positions, this is not a rounding error, it’s a deliberate revenue line. Treated as operational, it goes unreviewed. Treated as a capital decision, it gets optimised. **Collateral management** is where the complexity compounds. Firms running multiple trading desks, derivative positions, and financing arrangements are often posting collateral inefficiently, either concentrating high-quality assets where lower-quality ones would satisfy requirements, or failing to recycle collateral across the enterprise in any coherent way. A custodian with tri-party collateral management capability can transform this. But only if someone at the table has both the authority to restructure the arrangement and the mandate to ask whether the current setup is optimal. Most of the time, that person doesn’t exist in the conversation. **Tax reclamation on cross-border dividends** is the least glamorous and possibly the most consistently mismanaged. When a fund receives dividends from foreign equities, withholding tax is typically deducted at source. Many jurisdictions have treaty arrangements that reduce or eliminate that liability, but reclaiming it requires documentation, timing, and process. Automated, this is recoverable value. Manual and deprioritised, it leaks quietly for years. I’ve seen organisations leave meaningful basis points on the table annually, not because the process was complicated, but because no one had made it anyone’s responsibility to care. — The Ownership Problem Is an Organisational Problem Here’s the counter-intuitive part. The custodian almost always knows what is being left unrealised. They have the data. They can see the lending pool, the collateral inefficiency, the unclaimed reclaims. The better custodians will raise it. Some will raise it repeatedly. But a conversation initiated by a service provider and received by an operations team produces a very specific kind of outcome: it produces a note in a file, a polite acknowledgement, and continued inaction. Not because the operations team is incompetent. Because they don’t have the authority to restructure a commercial relationship, and they know it. The decision to activate securities lending, renegotiate collateral terms, or invest in tax reclaim automation is a capital allocation decision. It requires someone who owns the P&L implication, has the authority to engage the custodian at a principal level, and has set aside time to actually review the economics, not just the operational SLAs. Back-office decisions made at back-office levels produce back-office outcomes. This is not a criticism of operations professionals. It’s a structural observation about where certain categories of decision need to live. — What This Means in Practice If your custody relationship doesn’t have a named senior owner reviewing the economics quarterly, you don’t have a custody strategy. You have a contract. Those are genuinely not the same thing. This applies equally to asset managers, fintech platforms with balance sheet exposure, family offices, and corporate treasuries with cross-border holdings. The specifics vary. The pattern doesn’t. And if you’re building or advising on the infrastructure layer, as I’ve written about in the context of cyber risk and human decision-making, the lesson is the same: the technical capability is rarely the constraint. The governance around it usually is. The founder I spoke to

The Hidden Revenue Engine in Custody Banking

Custody Is Not a Warehouse. It Never Was. A category of assumption in financial services never gets challenged because it lives in the wrong part of the conversation. Not strategy. Not risk. Operations. Because it lives there, it quietly costs firms money for years without anyone noticing, or, more precisely, without anyone deciding to notice. Custody is one of those assumptions. Ask most senior executives what their custodian does, and you’ll get some variation of the same answer: they hold the assets, settle the trades, keep everything safe. Which is true. It’s also roughly as complete as saying a CFO’s job is to count the money. Safety and settlement are the entry requirements, not the service ceiling. What sits above them, and what most firms are systematically failing to access, is an entirely different conversation. — The Situation In 2021, I reviewed the cost structure of a mid-tier asset manager. Standard work. The kind of exercise where you expect to find a few contract renewals overdue, some vendor consolidation opportunities, the usual operational drift. Custody appeared in the analysis as a line item under operational overhead. No flag. No red circle. Just another fixed cost being paid on time every quarter, which apparently meant there was nothing to discuss. I pushed to look at the actual relationship, not just the invoice. The operations lead looked mildly confused. “We haven’t had any issues,” he said. That sentence, I’ve learned over the years, is the one that should worry you most. What we found when we looked properly wasn’t a disaster. It was something subtler and, in some ways, worse: a slow, systematic bleed that had been running unexamined for three years. Securities lending revenue was sitting uncollected, the programme existed in theory, but the commercial terms had never been optimised and monitoring had lapsed. Collateral was being posted inefficiently across three trading desks that were operating independently, each solving its own problem without any view of the aggregate drag. And withholding tax reclaims on European dividends, treaty benefits the firm was legally entitled to, had not been filed in eighteen months. The money wasn’t lost. It was just sitting unclaimed inside a process nobody had thought to run. I’ll be honest about what I felt when we quantified it. Not vindicated. Uncomfortable. Because the operations team were competent people who hadn’t been negligent, they’d been under-resourced, under-informed about what was available, and operating inside an unspoken organisational assumption that custody was a settled, closed question. Nobody had told them otherwise. And I’d been in enough boardrooms to know that nobody was going to volunteer that conversation upward unprompted. — What Custody Actually Is **Securities lending is not a passive income stream.** The mechanics are familiar enough: the custodian lends holdings to counterparties in exchange for collateral and a fee. But the difference between a well-run securities lending programme and a poorly managed one isn’t marginal. It depends on the split negotiated with the custodian, the demand profile of the underlying securities, the quality of counterparty selection, and whether the programme is being actively monitored against market benchmarks. Dormant assets, equities held through a long-only strategy, bonds held to maturity, are not dormant from a lending perspective. They are inventory. Whether that inventory earns anything depends entirely on whether someone is paying attention. Most firms I’ve reviewed aren’t. **Collateral management is where capital efficiency lives or dies.** When trading desks operate independently, which they almost always do, collateral decisions get made locally without visibility into the portfolio-wide position. The result is duplication: the same eligible assets being used multiple times across margin calls and counterparty obligations, but not optimised for where they create the least drag. A custodian with proper collateral management infrastructure sees the whole picture and can route assets to minimise capital consumption. The firms using this well have a structural cost advantage over the ones still running the three-spreadsheets-in-parallel model. This isn’t a sophisticated observation. It’s just one that requires someone senior enough to demand the conversation and junior enough to actually sit in the operational detail. That overlap is rarer than it should be. **Tax reclamation is money most firms don’t know they’re owed.** Cross-border dividend payments are subject to withholding tax under domestic rules, but double taxation treaties between countries create entitlement to reclaim the difference. The process is administrative: filings, deadlines, documentation requirements that vary by jurisdiction. It’s also the kind of work that falls between the custodian’s scope and the internal tax team’s awareness if the relationship isn’t actively managed. Eighteen months of uncollected reclaims on a European equity allocation isn’t an edge case. I’ve seen it more than once, in organisations that would describe their tax function as sophisticated. Automation exists. Treaty entitlements exist. The gap is almost always governance, specifically, who owns the question. — What This Means Practically The organisations that treat custody as infrastructure, as something to be reviewed, not just paid, have a measurable advantage that shows up in net returns. This isn’t about switching custodians or renegotiating contracts as an annual performance. It’s about establishing a regular discipline of asking what value is available inside the existing relationship and whether it’s being accessed. That means someone with enough authority to sit outside the operational team’s comfort zone and ask the questions that feel impolite: What is our current split on securities lending? When did we last file a reclaim? What is our aggregate collateral utilisation and who owns it? The relationship with a custodian is not unlike the one I described in [when cyber risk becomes a human failure rather than a technical one](https://lakshvaswani.com/when-firewalls-fail-the-human-side-of-cyber-risk/), the exposure is often not in the event that gets escalated, it’s in the assumption that has never been examined. And as I’ve argued in the context of [regulatory expectations across different jurisdictions](https://lakshvaswani.com/the-trust-deficit-why-transparency-empathy-and-execution-are-the-future-of-compliance-leadership/), the cost of oversight is almost never as high as the cost of its absence. The most expensive service you can buy is one you’re already paying for and not using.

36 Hours Straight: A Team Story in Financial Services

What Happens at Hour Thirty-Six There is a particular quality of silence that only exists when thirty-six hours of noise suddenly stops. Not peaceful silence. Not relieved silence. The silence of eleven people who have been in the same room since Thursday morning, across four time zones, held together by a shared problem and one very patient coffee machine – and who have just watched the fix land. Nobody moved. Nobody said anything. For a full minute, we just sat with it. The kind of silence that a team earns, not one that settles on them by accident. I have been in enough war rooms to know that the technical resolution is rarely the moment that stays with you. What stays is the human texture of the hours that built toward it. This weekend gave me more of that texture than I expected. — The Situation We were forty-eight hours into what had started as a manageable incident on Thursday morning. I say “manageable” because that is what the first assessment suggested. It was not manageable. It was the kind of problem that presents politely, shakes your hand, and then halfway through the introduction mentions it has brought several cousins. You solve the first layer, and it introduces you to a second. You solve the second, and a third emerges with a quietly baffling root cause that nobody had a clean precedent for. At some point around hour twenty, I stopped asking “how much further?” and started asking “who needs a break and who needs coffee?” Here is the moment I will not forget: it was sometime around 2am on Saturday. One of our engineers – someone who had been heads-down for hours, barely speaking – looked up from their screen and said, flatly, “I don’t actually think this is the problem anymore. I think we’ve been solving the wrong thing.” The room went quiet in a different way. Not the good quiet. The kind where everyone does a rapid internal calculation of how much work that statement might just have invalidated. I felt it too – that brief, cold drop of “please don’t let that be true.” It was true. And saying it out loud was the thing that turned the corner. We had been six hours into a technically correct solution to the wrong diagnosis. The engineer who said it had known for some time, I think – had been sitting with it, testing their own certainty before naming it in a room full of tired, invested people. That moment of honesty, offered quietly and without drama, was worth more than everything that came before it. I have been in transformation programmes where that observation would never have been made aloud. Where the cost of being the person who says “we’ve been solving the wrong thing” is too high – socially, politically, professionally. This weekend, it cost nothing. That is not an accident. That is a culture. — Three Things I Have Carried Out of That Room **The teams that hold together under pressure have usually done the work before the pressure arrives.** There was no team-building exercise that produced what I saw this weekend. There was months of working alongside each other, small acts of reliability, the accumulated evidence that when you say you’ll pick something up, you pick it up. Trust is not built in a crisis. It is *revealed* by one. What the war room showed us was simply what had already been true. **Fatigue is an honesty accelerator.** By hour thirty, the energy required to perform competence – to manage your image, to frame your uncertainty carefully – is simply no longer available. People stop polishing their contributions and start handing each other raw information. The humour gets darker because it stops being a social tool and starts being a genuine release valve. The observations get sharper because there is no bandwidth left for softening them. I have sat in two-hour steering committees where less truth was exchanged than in the last six hours of this incident. Organisations should find this alarming and instructive in equal measure. **The people who show up at 3am are not doing it for the SLA.** This is the insight that sat with me longest, and it is not a comfortable one for anyone who has spent time building incentive frameworks, performance structures, or engagement metrics. The engineer who reframed our diagnosis at 2am was not motivated by a KPI. The colleague who quietly took over so someone else could rest was not making a career calculation. There is a category of professional commitment that exists entirely outside the reward architecture – and the organisations that understand this tend to be the ones that keep their best people. You cannot manufacture it. You can only create conditions where it survives. — What This Means Beyond This Weekend If you lead a team, or a function, or a programme of any meaningful scale, I would ask you one question: would your team tell you at 2am that you have been solving the wrong problem? Not hypothetically. Specifically. In the room. With six hours of work already on the board and an audience of tired, invested colleagues. If the answer is uncertain, that is the work. Not the governance framework. Not the roadmap. The thing that makes transformation either survive contact with reality or quietly collapse under it is whether the people in the room will tell you the true thing when it is inconvenient and late and expensive to hear. Technical incidents are, in a strange way, gifts. They compress months of organisational dynamics into hours. They show you – quickly, clearly, without the usual insulation of process – what your culture actually is. Not what it says it is. What it does when nobody is watching the clock. We updated the runbook. We scheduled the post-mortem. We will find the systemic gaps and we will close them, methodically, the way you are supposed to. But the thing I

When Risk Frameworks Become Obsolete: An MRA Story

The Friday I Signed Off on a Risk Framework I Knew Was Broken There’s a particular kind of exhaustion that sets in on a Friday afternoon in Q3 when an OCC examination cycle looms. It’s not the clean tiredness of hard work finished. It’s the grubby, low-grade fatigue of a problem you’ve been managing rather than solving for the better part of a year. Everything on your desk is a version of the same question: how long can we hold this position? In Q3 2021, I found out exactly how long. The answer was four months. We had an open MRA – a Matter Requiring Attention – that had been sitting on the books for eleven months. For anyone outside the OCC’s regulatory world: an MRA isn’t a fine, it isn’t a public censure, but it’s a formal signal that the examiner has found something structurally wrong with your risk management practices and expects you to fix it. It’s the regulator telling you, in careful institutional language, that they’re watching. What we submitted that Friday addressed every word of the finding. It didn’t address the condition that had produced it. I knew this when I signed. — The Decision I Made in That Room The framework we built was technically responsive. That’s the exact right phrase. It answered the question as written rather than the question being asked. We’d brought in outside counsel, run it through the risk committee, and produced something that looked, on paper, like a serious institutional response. It had the right headings. It cited the right regulations. It mapped to the MRA’s specific language with the kind of precision that signals effort. What it didn’t do was account for the direction our risk environment was moving. The original finding had been written against conditions from early 2020. By the time we submitted the remediation framework in 2021, those conditions had shifted materially: vendor concentration had increased, a key operational process had been restructured, and two of the control owners named in the original framework had left the organisation. The framework we submitted was already ageing before the ink dried. I knew this. The head of my risk team knew this. We submitted it anyway, because the examination window was closing and an open MRA going into the next cycle felt like a worse outcome. That’s the calculation that leads you to the wrong decision in a very calm and rational way. The examiner accepted the framework. For approximately four months. Then the follow-up review arrived, and what had been an MRA became an MRA with a deadline. In OCC language, that’s the last door before formal enforcement action. We had to rebuild the entire framework under significant pressure, on a compressed timeline, with an examiner who now had a documented record of our previous submission sitting in the file. We hadn’t bought ourselves time. We’d borrowed it at an interest rate nobody quoted us at closing. — What Regulatory Time-Buying Actually Costs The first thing to understand is that OCC examiners have institutional memory that outlasts personnel changes on both sides of the table. Examination files follow an institution. When you resolve an MRA with a framework that’s already structurally compromised, that’s noted – not always in the formal finding, but in the examiner’s working papers, in the tone of the next examination, in the questions that surface two cycles later about the same underlying risk area. Regulators track patterns, not just incidents. A technically compliant response followed by a material lapse reads, to an experienced examiner, as a pattern. The second thing is that the goodwill cost is real and hard to recover. Regulated institutions often underestimate how much of the OCC examination relationship runs on examiner judgement – judgement about whether management genuinely understands its risk environment, whether leadership takes findings seriously, whether the organisation has a credible culture of risk management or a credible performance of one. That judgement is formed over multiple examination cycles. When you trade a substantive response for a timely one, you’re spending a currency you don’t get back by submitting the next framework on schedule. The third insight, and the one that cost me the most to learn: the MRA itself isn’t the problem. It’s a signal about the condition underneath. This sounds obvious until you’re the person sitting across the table from a Friday afternoon examination deadline with an open finding, at which point it stops being obvious and starts being inconvenient. Most MRA remediation work I’ve reviewed – and I’ve reviewed a substantial amount, at enough institutions to recognise the pattern – is designed around closing the finding rather than resolving the condition. Those aren’t the same activity. The finding is a description of a symptom at a point in time. The condition is a structural feature of how risk is identified, escalated, and owned inside the organisation. You can resolve the former without touching the latter. Banks do it regularly. The examiners know. This same dynamic appears in how organisations manage third-party risk. A vendor who fails a due diligence review is a finding. The governance gap that allowed the vendor relationship to become operationally critical before due diligence was completed is the condition. I’ve written separately about how third-party risk frameworks often suffer from exactly this confusion – treating relationship incidents as the unit of analysis when the control environment is the actual problem. — What This Means for Your Organisation If you’re managing an open MRA right now, the practical implication is this: build the remediation framework for where your risk environment will be in eighteen months, not where it was when the finding was written. That means the control owners named in the framework need to be current. The risk scenarios need to reflect your actual operational configuration, not the one that existed at examination time. The governance structure underpinning the framework needs to have real teeth – real escalation paths, real accountability, real testing cycles – because an OCC examiner