Finance Accounting Marketing Human Resources Sales Corporate Governance Technology Startup Procurement Law
Select Page
⚡ TL;DR
RegTech is technology used by firms to interpret obligations, identify customers, screen sanctions, monitor transactions, surveil markets, manage evidence and submit regulatory data. SupTech is the corresponding use of data and technology by supervisors. The distinction matters because a vendor usually supplies software without becoming responsible for the regulated firm’s judgement or permission. In the UK, firm-side systems connect to official infrastructure such as the FCA’s RegData and My FCA portals and the PRA’s BEEDS collections. The PRA’s February 2026 Future Banking Data paper described more than 400 banking reporting templates and proposed a pragmatic programme built around collecting data ‘once and well’. The FCA’s 2026/27 programme includes an internally developed AI authorisation tool, generative AI and better data analytics, while its Digital Sandbox, Regulatory Sandbox and AI Live Testing support controlled experimentation. The key control is evidence: data lineage, model validation, false-positive and false-negative measurement, human escalation, change governance and reproducible decisions. Outsourcing does not transfer regulatory responsibility, even after the first four cloud providers entered direct UK critical-third-party oversight in July 2026.

Compliance technology is valuable only when it makes a regulated decision more accurate, timely and explainable. A dashboard that closes alerts faster can still miss risk; a model that finds more matches can overwhelm investigators; a reporting engine can submit on time while mapping the wrong source field. Regtech is therefore a data-and-control discipline before it is a software category.

This guide maps the UK market from firm obligations to digital supervision. It connects with Kurums’ FCA, PRA and PSR guide, financial-crime and identity map, open-banking guide and UK fintech ecosystem analysis. Illustrative vendors are not rankings or endorsements.

Editorial scope: This is business education, not personal financial, legal or investment advice. Rules, permissions and protection depend on the specific regulated entity and product.
Key Takeaways

What is the boundary between RegTech and SupTech?
RegTech helps firms comply and evidence decisions; SupTech helps authorities collect data, prioritise risk and supervise markets and firms.

Who remains accountable after outsourcing?
The regulated firm, its board and senior management retain responsibility for rules, risk appetite, decisions, data and customer or market outcomes.

What should a buyer measure?
Not just automation: test coverage, data quality, false negatives, alert ageing, explainability, regulatory mapping, resilience, change control and total investigation cost.

The UK RegTech-to-SupTech Data LoopObligationsRules & riskFirm SystemsDetect & decideRegDataReport evidenceSupervisorsAnalyse & actFeedback, findings and regulatory change should update controls without breaking lineage.
Feedback, findings and regulatory change should update controls without breaking lineage.

What is RegTech?

RegTech is a functional label for technology that supports regulatory compliance and risk management. It includes identity verification, KYC and KYB, sanctions and PEP screening, transaction monitoring, communications surveillance, regulatory change, complaints analysis, prudential reporting and evidence management. A vendor can serve several regulated sectors without itself conducting a regulated activity.

The category should not be defined by artificial intelligence. Rules engines, workflow, entity matching, secure data transfer and reconciliation can create more value than a predictive model. Nor is every internal compliance system a fintech business. Regtech becomes a market when reusable data, software and expertise are delivered across firms, often through subscription, usage or implementation fees.

What is SupTech?

Supervisory technology, or SupTech, is the use of digital tools by authorities to collect, validate and analyse data, identify risk and support supervisory decisions. It can prioritise authorisation cases, detect anomalies across returns, connect market intelligence or reduce administrative work. The output informs public decision-making and therefore needs governance, security and human accountability.

RegTech and SupTech form a loop. Firms translate rules into controls and submit evidence; authorities compare data and communicate findings or policy; firms update systems. Friction arises when definitions differ across returns, regulators or source systems. Better technology cannot fully compensate for inconsistent legal concepts, which is why taxonomies, data dictionaries and change governance are core infrastructure.

Does a RegTech provider need FCA authorisation?

Providing software to a regulated firm does not by itself make the provider FCA-authorised. The answer depends on the activities actually performed, the contractual role and whether a regulated service is carried on. The FCA’s sandbox register explicitly notes that some RegTech and SupTech providers are not listed because they supply technology without carrying out regulated activity.

A buyer should not treat authorisation as a generic quality certificate or absence of authorisation as proof of weakness. It should map permissions to services, then assess outsourcing, data protection, security and operational risk. If the vendor also handles payments, decisions or customer relationships, the perimeter analysis may change. Contract language cannot override the substance of the activity.

💡 Pro Tip: Map activity before licence. A RegTech vendor may be unregulated because it supplies software, while a similar-looking provider may need permission because it performs the regulated step.

How does digital identity support KYC and KYB?

KYC establishes who a customer is and the risk of the relationship; KYB extends that work to companies, ownership and control. Technology can capture documents, assess liveness, match biometrics, query registers, resolve entities and screen risk data. A successful identity check is only one input: purpose, source of funds, expected activity and beneficial ownership still require a risk-based assessment.

UK identity infrastructure is changing. Companies House identity verification became a legal requirement for directors and people with significant control from November 2025 on a phased basis. HM Treasury’s February 2026 guidance clarified how certified digital verification services may support Money Laundering Regulations checks, while stating that it supplements rather than supersedes firms’ obligations. Reusable evidence still needs provenance and currentness.

How do screening and transaction monitoring differ?

Customer screening compares people and entities with sanctions, politically exposed person and other risk data at onboarding and through the relationship. Payment screening evaluates parties and message fields before or during movement. Transaction monitoring evaluates behaviour over time against rules, scenarios or models. The same customer can pass screening yet generate suspicious activity later.

Matching quality depends on names, scripts, dates, addresses, identifiers and ownership data. Loose thresholds create false positives; tight thresholds create false negatives. Transaction models add segmentation, typologies and behavioural baselines, but alerts are not findings. Investigators need context, documented disposition and a route to appropriate reporting. Model tuning should measure missed risk as well as workload.

What do UK financial-crime RegTech firms illustrate?

London-founded providers illustrate different layers rather than one winner. ComplyAdvantage combines financial-crime risk intelligence with customer, transaction and payment screening and monitoring. Quantexa uses entity resolution and contextual decision intelligence across financial crime, KYC and fraud. Napier AI offers modular client screening, payment screening, transaction monitoring and customer-risk assessment.

These examples show why category labels are insufficient. A bank may buy risk data from one source, entity resolution from another and case management from a third, or select an integrated platform. Vendor claims about automation and false-positive reduction should be reproduced on the buyer’s data and typologies. Integration, explainability and investigator workflow can matter as much as detection algorithms.

RegTech layer Typical evidence or output Failure to test
Identity, KYC and KYB Verified attributes, ownership map, risk rating and review history Document authenticity without full customer or beneficial-owner understanding
Screening and monitoring Matches, behavioural alerts, investigation and reporting decisions False-negative exposure, noisy alerts and undocumented tuning
Regulatory intelligence Applicable obligation mapped to policy, control, owner and implementation Fast summaries with the wrong entity, permission or effective date
Regulatory reporting Validated return with lineage, reconciliation, approval and resubmission history Portal acceptance of data that is complete syntactically but wrong semantically
SupTech Risk triage, cross-firm analytics and decision support for supervisors Opaque automation, biased prioritisation or weak statutory accountability

How does regulatory-change technology work?

Regulatory-change tools collect publications, classify topics, compare versions and route obligations to owners. The difficult step is applicability: a rule may depend on permission, product, customer, entity, threshold or implementation date. Natural-language processing can narrow the reading burden, but legal and compliance judgement must establish what the firm must actually change.

CUBE is a UK example focused on automated regulatory intelligence and change management, turning regulatory content into classified data and workflows. The value test is not the number of documents ingested. It is whether the firm can trace an external change to an obligation, policy, control, system field, training item, owner, test and approved implementation—with preserved evidence of interpretation.

Where do market surveillance and conduct analytics fit?

Wholesale firms use surveillance to detect possible market abuse across orders, trades, communications and reference data. Retail firms can analyse sales, complaints, vulnerability, fees and service outcomes. Both require a defensible link from behaviour to rule or risk. A generic anomaly score is not enough for an investigator to understand why a case matters.

Coverage is an architecture problem. Employees communicate across approved channels; orders and executions pass through multiple venues and systems; customer journeys cross products and outsourcers. Entity, account and time synchronisation determine whether events can be reconstructed. Surveillance controls should be tested with scenarios and known cases, while access to sensitive communications and personal data remains proportionate.

How does regulatory reporting reach the FCA?

RegData is the FCA’s platform for collecting regulatory data. Firms can view scheduled requirements, due dates and submissions. Since late 2025 access has moved through My FCA, and by March 2026 RegData, Connect and the Online Invoicing System were available behind one sign-in. The portal simplifies access; it does not generate correct source data for the firm.

A reporting stack maps ledger, customer, transaction and risk data to return fields, applies validation, manages adjustments and creates sign-off evidence. XBRL, XML and spreadsheet formats may coexist. Controls should distinguish source correction from reporting overlay and preserve resubmission history. The senior approver needs reconciliation to finance and risk records, not just confirmation that a file passed portal validation.

Why is PRA banking data collection being redesigned?

The PRA’s February 2026 Future Banking Data discussion paper described a data estate covering more than 400 templates, with capital appearing in about 120 and credit risk in more than 100. Firms report through BEEDS, RegData and spreadsheets by email, using XBRL, XML and Excel. Requirements accumulated across domestic, EU-derived, statistical, stress-testing and supervisory needs.

The proposed direction is incremental rather than one replacement platform. Four principles anchor the programme: objective-driven collection, collecting data ‘once and well’, making high-quality supply easier and keeping collections fit for purpose. Template deletions began from December 2025, while simplified capital reporting for Small Domestic Deposit Takers is due from January 2027. Regtech vendors must manage this transition without hard-coding today’s estate.

ℹ️ Context: The PRA’s Future Banking Data paper sets a direction for incremental reform, not a completed single-platform replacement. Build for coexistence and versioned reporting obligations.

Why do data lineage and definitions matter more than the interface?

Lineage explains where a reported or monitored value originated, which transformations were applied and who approved changes. Without it, two accurate systems can produce different answers because customer, exposure, default or complaint are defined differently. A data dictionary should connect regulatory meaning to source fields, calculation logic, granularity, owner, quality rule and retention.

Controls need to survive change. A core-system migration, acquisition, new product or rule taxonomy can break mappings silently. Reconciliations, completeness checks, threshold alerts and sample trace-back should operate before submission or model output reaches a decision. Data quality is not a technology team’s side task; it determines whether compliance evidence can be trusted by management and supervisors.

How is the FCA using AI and data in supervision?

The FCA’s 2026/27 programme includes an internally developed AI tool intended to speed authorisation work, alongside generative AI and expanded data analytics for supervision and intelligence. The authority states that people remain central to decisions. This is SupTech: technology can triage information and surface risk while statutory judgement and accountability stay with the regulator.

For firms, smarter supervision raises the value of consistent, timely and machine-readable evidence. It may also make anomalies across returns easier to detect. The wrong response is to optimise each submission in isolation. Governance should ensure that financial, conduct, complaints and prudential narratives agree—or that explainable differences are documented before a supervisor asks.

What is the difference between the FCA’s sandboxes?

The Regulatory Sandbox supports controlled live-market tests with real consumers and can provide tools such as restricted authorisation, informal steer or rule modifications where appropriate. Applications are open throughout the year and tests are usually limited in scale and duration. Acceptance is not FCA endorsement, and a technology provider may still need a regulated partner or permission for the test.

The Digital Sandbox supports earlier experimentation with a secure environment, more than 300 synthetic, public, anonymised or pseudonymised datasets and over 1,000 API endpoints. The AI Lab adds the Supercharged Sandbox and AI Live Testing. Eight firms entered the second AI Live Testing cohort in April 2026 to examine governance, risk and monitoring through year-end, with an evaluation expected in Q1 2027.

How should AI-enabled RegTech be governed?

Start with the decision and harm, not the model. Document purpose, users, data, output, human role, confidence limits and prohibited uses. Validation should test accuracy by segment, stability, drift, explainability, security and the operational effect of errors. A language model that summarises an investigation poses different risk from a model that automatically closes an alert or declines a customer.

Data-protection duties remain relevant to profiling and automated decisions. The ICO consulted in 2026 on updated automated-decision guidance following the Data (Use and Access) Act 2025; draft consultation material should not be presented as final guidance. Firms need a lawful basis, transparency, data minimisation, appropriate rights and meaningful review. Vendor explainability does not substitute for the deploying firm’s own assessment.

What changes under critical-third-party oversight?

The UK critical-third-party regime allows the Treasury to designate providers whose disruption could threaten financial stability or confidence. From 13 July 2026 the FCA, PRA and Bank of England began overseeing specified systemic services of AWS EMEA, Google Cloud EMEA, Microsoft Ireland Operations and Oracle Corporation UK—the first four designated providers.

Designation does not transfer a firm’s responsibility for operational resilience or outsourcing. The firm still needs concentration analysis, access controls, incident response, data recovery, testing and exit plans. New FCA incident and material-third-party reporting requirements take effect on 18 March 2027; the FCA reported that more than 40% of cyber incidents notified in 2025 involved a third party. Vendor inventory is becoming supervisory data.

⚠️ Risk: Direct oversight of a cloud provider does not make a firm’s deployment resilient. Configuration, concentration, recovery, access and exit remain the regulated firm’s responsibility.

How should a RegTech platform be bought and measured?

Define regulatory use cases and risk appetite before procurement. Test the vendor on representative data, languages, entity types and stress volumes. Measure precision, recall or appropriate detection proxies, false positives, false negatives, alert ageing, investigator time, explainability, availability and data quality. Review model and content-update processes, not just the current demo.

Then test governance and portability: sub-processors, hosting regions, access, encryption, audit rights, regulatory cooperation, incident notice, version control, service levels, price at scale and usable data export. Assign internal owners for rules, tuning, overrides and outcomes. The business case should show safer or more efficient compliance after integration and review cost—not merely fewer people touching an alert.

What does the next UK RegTech architecture look like?

The direction is toward structured obligations, reusable identity evidence, connected entity data, API delivery, continuous controls and richer regulatory analytics. The PRA’s ‘once and well’ principle points toward less duplicated collection, while FCA investment in AI points toward more machine-assisted supervision. The transitional reality will remain hybrid: legacy returns, portals, spreadsheets and modern platforms will coexist.

Advantage will accrue to firms and vendors that preserve semantic and evidential integrity across that hybrid estate. A reusable data layer, controlled taxonomy and modular services can adapt without rebuilding every rule. But centralisation also creates concentration and model risk. The winning system is therefore federated enough to remain resilient and governed enough to produce one defensible account of what the firm knew, decided and reported.

Continue the country series: Explore the United Kingdom Finance & Fintech Hub, or compare the underlying concepts in the Fintech & Transfers Hub.

Frequently Asked Questions

What is the difference between RegTech and SupTech?

RegTech supports firms’ compliance and evidence, while SupTech is technology used by regulators to collect data, identify risk and support supervision.

Does every RegTech vendor need FCA authorisation?

No. Pure technology supply may be unregulated, but the actual activities and contractual role must be tested against the regulatory perimeter.

Does outsourcing compliance software transfer accountability?

No. The regulated firm retains responsibility for its obligations, decisions, data, outsourcing risk and customer or market outcomes.

What is RegData?

RegData is the FCA platform used by firms to view and submit scheduled regulatory data; it is now accessed through the My FCA portal.

Is FCA sandbox acceptance an endorsement?

No. It permits a controlled test and regulatory engagement under agreed safeguards; it does not certify the firm, product or investment.

Primary Sources and Further Reading

This guide prioritises regulators, payment-system operators and company filings. Figures are the latest available at the July 2026 review date.

Last Updated: July 2026 · Reviewed by the Kurums Finance editorial team.

Discover more from Kurums | Business Intelligence

Subscribe to get the latest posts sent to your email.

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading