Control sprawl is draining banks. Here’s the fix

banks

Ask a bank how many controls it operates and you will rarely receive a confident answer. Ask how many it actually needs, and which ones, and the response is usually silence.

According to Corlytics, most large institutions run control estates numbering in the thousands, accumulated organically over decades: one regulation, one audit finding, one remediation exercise at a time. A significant share are not genuinely controls at all, but reports, processes, statements or policies. Yet every item in the inventory costs money to run, test and monitor.

Control proliferation is not a new problem, having accelerated since the Subprime Crisis. But the traditional remedies, consultants and in-house programmes, no longer suffice. New players such as FinTechs and data providers, amplified risks including AI, an increasingly interconnected market and rising regulatory expectations have outpaced them.

The pain points are well known. There is little system-based traceability to control requirements, with mapping too often achieved manually and difficult to maintain. Controls data is noisy and inconsistent, its creation and upkeep subjective, with 30-40% of inventories frequently comprising non-controls.

And the model is reactive by design: new regulation or policy requirements do not update inventories in real time, leaving institutions permanently looking in the rear-view mirror.

The structural consequences follow. Risk exposure is often unknown, unquantified and addressed only after the fact. Growth is constrained as business velocity slows and time-to-compliance lengthens. Manual, fragmented processes drive up operating costs and generate opportunity costs besides.

The idea worth taking seriously is a barcode for controls: a machine-readable identity for each control, derived not from a reference number but from the underlying requirements it exists to satisfy, both external regulatory obligations and internal policies, procedures and processes.

This requirement-based approach unlocks several gains. Compression comes immediately, as duplication stops being an opinion and becomes a query, cutting the cost of control while maintaining coverage. Impostors surface, since a “control” mapping to no requirement is not a control, flushing reports and monitoring out of the estate so testing effort targets genuine risk reduction.

Descriptions are uplifted through advanced AI engines and anchored to specific requirements, making them testable and defensible under examination. And completeness becomes something firms evidence rather than assert, with every requirement codified and mapped.

The usual trade-off, in which completeness inflates the estate while cost discipline risks gaps, collapses under this methodology. Institutions cover what they must, once, precisely enough to test, with a documented line back to the source that can be shown to regulators.

The prize is not a tidier inventory, but fewer controls doing more, provably, within an estate whose costs stop rising for no defensible reason. Controls become an asset supporting growth, for instance reducing time to trade when entering new products or markets, since needs and gaps are clear before trading begins.

The full Corlytics post is here. 

Read the daily RegTech news

Copyright © 2026 RegTech Analyst

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2018 RegTech Analyst

Investors

The following investor(s) were tagged in this article.