
Opinion: FinTech, RegTech and AnyTech is facing an existential crisis.

It's taken more than a decade for financial sector regulators to wake up to the fact that deploying technology is a form of outsourcing. This sluggish thinking has failed to take account of the reality that companies make a false assumption that they are buying technology, or even the product of a particular vendor, but in fact they are buying the people behind the product.
Across the financial sector and beyond, an increasing dependence on technology is taken as a done deal. Yet updates to the functionality of software, often for safety and security, indicate that products ranging from automated processes including cars and infrastructure controls are shipped without adequate testing and without certainty as to their effect.
And so are many examples of operational software from desktop applications to mission-critical programs and user-facing applications (Apps).
So far, regulators have paid attention, primarily, to the question of the data sources but there is a slow recognition that the actual software is also a cause for concern.
Told you so.
I have long been warning that one of the reasons that outsourcing fails is lack of continuity at the coalface. From call-centres to programming, from data-analysis to writing algorithms, from "user interface" design to error detection, reporting and correction and, of course, addressing consequences.
True, The Australian Securities and Investment Commission has recently told financial services businesses, in particular, that they are responsible for the consequences arising from the tech they deploy. But in doing so, their reasoning has been superficial. Even that is better than in the vast majority of countries.
Others have openly supported the approach I suggested almost 30 years ago in relation to outsourced compliance systems: you can outsource function but you can't outsource responsibility. And we have seen in the meantime that RegTech companies have compensated their large clients where failures have resulted e.g. litigation. In the past week, World Money Laundering Report picked out the bones of a case in the USA where a fund has settled a case upon payment of a large sum of money where the fund relied on a reputable third party for assessment of the nature of business undertaken by companies in which the fund bought shares and the third party's reports were wrong.
We have seen many cases around the world where regulators have spelled out that internal processes must be reviewed and that "set and forget" is not an option (although, to be fair, mostly they should be, at least at their core).
If we take tech out of the equation and consider what a competent and effective business looks like, it is one that has the right people in the right job and where continuity of staff, particularly those setting policies, is vitally important. Even the UK's Financial Conduct Authority, which is hardly noted for being alert, has at last noticed that the churning of senior officers in financial crime jobs is a risk factor.
It is this churning point that has long been an indicator of problems in the provision of outsourced back office functions.
As the software moved towards the outsourcing of ever more mission-critical functions, technology companies moved in. This is not new: in the 1980s, doctors in the USA would dictate their notes, transfer the voice files via ISDN to a transcription centre in India where they would be typed up and document files transferred back ready to be printed out and added to patients' files the next morning. A number of companies, including Kurzweil, IBM and Philips decided to develop voice-recognition and transcription software. Voice Recognition and Auto-Transcription remains one of my basic tests for whether so-called artificial intelligence is viable. It isn't. The evidence of this is in front of you every single day when you turn on subtitles for TV. Only today, I was watching the new Springsteen documentary in which the automated "captioning" software said Garry Tallent (the double R and L are correct) plays "base".
Sign up for The World Money Laundering Report Weekly Digest at https://www.financialcrimeriskandcompliance.com/info/?p=subscribe&id=1
Technology can't do nuance or context.
The fact that technology can't do nuance or context is in part due to the fact that context and nuance require an extraordinary amount and array of information and the ability to filter that information and to build connections which are not binary. In sort, simple data-matching doesn't work in many applications.
But in many ways it does. So, for name checking, on the face of it, it's brilliant. So, (to borrow Mr Tallent's name for a moment), the fact that it is spelled in that way and is a combination of two words that are uncommonly spelled means that name checks will find it. But John Smith or Jane Brown are difficult. And a million Chinese can be Wong, CHI Kim breaks Western focussed systems and there are at least nine ways of spelling Mohammed. The reality is that false results, be they positive or negative, will always be a feature of the tech as they are with human research: tech has the advantage of accessing more information, more widely, much faster than people, provided it is told where to look.
So, it can be an additional tool but it should not be a conclusive decision-maker.
That's absolutely fine, so long as users like you realise its limitations. And so long as users like you can be sure it's not a house built on sand.
Who's building the foundations?
Marketing people have convinced the world that brands can be relied upon. But this presumption is wrong.
Toyota engines are widely regarded as bulletproof (in figurative terms) but this year 100,000 Tundra models were subject to a recall due to a fault in the new 3.4 litre V6 turbo engine. Audi has recalled many examples of its E-TRON, as used in the Iron Man films because of a fire-risk from its batteries and in the meantime, users are cautioned not to charge the battery to more than 80% of its capacity. A year ago, Daikin withdrew a complete line of air conditioners/heat pumps after 52 reports of overheating compressors with ten resulting in fires. DeWalt/Stanley/Craftsman sledgehammers on sale from 2013-2022 were recalled after 200 reports of the head coming loose. And perhaps the most disconcerting is that Jaguar Land Rover in the USA is recalling many 2024 model Defenders, Discoveries and three models of Range Rover because the oil filter housing may crack and oil can leak into the engine compartment causing a fire.
These examples are relevant because they are problems with components which have, at least in theory, many layers of quality control checks from initial design to final manufacture and fitting from companies whose names are synonymous with high quality and longevity. And, away from tech, we've seen so many cases of inadequate audits by mega-audit companies and the payment of significant compensation from their consultancy arms for bad advice in, amongst other things, financial crime compliance.
Clouds and X-as-a-service products and services
As a species, we seem to be anxious to drift through life in a superficial way, determined to accept the superficial especially if it comes with a buzzword that we convince ourselves is meaningful. So, across the world, people have fallen for the idea of "cloud computing." Dozens of companies have built their own clouds and a handful have come to dominate the industry, to the extent that around the world governments are falling over their feet to house data centres without thinking through the two most important questions: what economic benefits will it bring (answer far less than might be imagined because they don't use many people and the tech is almost all sourced somewhere else) and how much power will they draw, with what effect on the national supply and - bizarrely for countries claiming commitment to supposedly green initiatives, the climate (they are massive generators of heat that has to go somewhere and that might be the sea or watercourses, depending on location).
But the cloud is nothing more than a distributed server farm with shared resources and we had those long before we had the buzzword. Software as a service is nothing more than an example of shared resources and, yes, we had those even before computers - we called them libraries. In software terms, it has a name borrowed from somewhere else: multi-tenancy.
To the point
Why are there warning signs that are so severe that they should be red flags i.e. stop signs?
We know that for the past few years, software companies have had a staff turnover problem. We know that people that write software change jobs often and that this is a particular problem in the world's software factory, India. We can see people who have taken up a new job and who immediately add an "available for work" tag to their LinkedIn profile. Here's a painful truth: the people who are working on your outsourced services have no loyalty to their employer and consequently no loyalty to your project, be it one you are developing or one you are buying in.
And we know that data scientists are more loyal but are in great demand in so-called artificial intelligence companies and money talks.
And no loyalty means there is no continuity.
And no continuity means no consistency.
And no consistency means there will be avoidable failures.
We see differences between desktop and mobile interfaces and the way they validate data; we see differences from instance to instance of information in drop down boxes (one payments company has two different lists of reasons for the transfer and they are not compatible - it appears to be entirely random which list I get to see) and even the attitudes of those who arrange information in drop-down lists (so things are hard to find in long lists) and how information is selected (many websites have complex ways of inserting dates, for example).
So you can't presume that what you have today - and on which your clients and staff rely - will be the same tomorrow as it is today. That makes training difficult to maintain or even to be effective.
Also, one significant factor is that as financial institutions add friction to payments e.g. "are you sure you want to make this transaction", people are so fed up with difficult forms that they click through the challenge without thinking about the consequences to make progress.
Why is the problem of churning staff becoming critical now?
Reports are circulating in India that it is becoming very difficult to hold onto staff: people are willing to move after just a few weeks for quite small increases in pay, especially if the move is to a larger company or a more impressive job title which they can leverage to a job overseas.
And it's worse: reports now say that companies are finding it increasingly difficult to recruit experienced staff because they are valuing themselves at or close to first world salaries while in India. I understand a similar situation is developing elsewhere.
So, completing the circle: companies providing outsourced services do not and will not in many cases have continuity in developers. That means that software will have inconsistencies unless there are clear development standards and history shows that such standards are not set.
It also means that, because many software companies are dependent not on sales but on capital raising, which is becoming more and more difficult, it is more important than ever that customers ensure that there is continuity in the production team and in the strategic development team.
Why? Because if there is a failure because of any of those factors, it's your business and your officers that are at risk of everything from criminal prosecution to civil and/or regulatory action.
And that's the existential threat: if the product dies or doesn't work as intended, if the company producing it dies or ceases development, then your own company and its officers' careers could very easily die with it.
-------
Nigel Morris-Cotterill has been a financial crime risk strategist since 1994. He advises and present seminars worldwide. He has a long-standing and deep understanding of the application of computers in the commercial world. He is the author of several books, many papers and innumerable articles and speaks at high-level conferences.
About this section
Opinion pieces or "Op-Eds" are the home-made bombs of the publishing world. So long as they meet editorial standards, are not intentionally offensive with a view to causing hurt or insult and are relevant to our field of endeavour, we will look at submissions.
We like contentious, we like contrarian views. We don't like pretty much any -ism . We recognise that Opinion pieces are one person's view and are not balanced (if they are balanced and reach a reasoned conclusion, they are probably more suited to the Articles section). We do not like acronyms and buzzwords.
Op-Eds are the author's personal views and do not necessarily represent the views of World Money Laundering Report or its publishers.
To submit an Opinion piece, please complete the Contact form.

