The collapse of FTX in November 2022 did not happen because rules were missing. Disclosure requirements were in place. Regulators across several jurisdictions were watching closely. Yet the exchange’s implosion still caught markets, creditors and supervisors off guard, wiping out billions in value almost overnight.
According to Sherlocq, the real failure was not one of regulation but of synthesis. Signals were visible in public filings, regulatory correspondence and industry commentary, but they were never pieced together in time to prevent disaster.
Sherlocq recently discussed the compliance intelligence failure at the centre of the next crisis.
This pattern, described here as a compliance intelligence failure, is likely to define the next major financial shock too, and unlike systemic leverage or asset bubbles, it is entirely avoidable.
Compliance intelligence is often mistaken for something narrower, such as a regulatory newsletter or a quarterly checklist exercise. In practice, it is the continuous work of tracking what regulators across jurisdictions are saying, changing and enforcing, and linking that directly to a firm’s own products, customers and risk exposures. Tick-box compliance asks whether a firm is technically within the rules today. Intelligence-led compliance asks where the rules are heading next, and whether the firm is positioned ahead of that shift.
History offers three clear examples. The 2008 financial crisis saw regulators across the US and Europe flag separate concerns, consumer lending, liquidity, individual balance sheets, without ever assembling the full picture. India’s IL&FS collapse in 2018 followed the same pattern, with audit qualifications and governance concerns sitting in disclosures for months before default. More recently, crypto’s biggest failures showed enforcement actions and solvency warnings on the public record well before collapse. In each case, the information existed. The connective work did not.
Fixing this requires more than additional compliance headcount. Firms need a genuine regulatory intelligence function with real authority to flag emerging shifts before they escalate, built on centralised tracking of enforcement decisions, consultation papers and supervisory priorities across jurisdictions. Crucially, that intelligence must be mapped directly onto specific products and risk exposures, not filed away as a general awareness note.
This is the gap tools such as Sherlocq are built to close, pulling regulatory signals from multiple jurisdictions into a single sourced view that can be tested against a firm’s own exposures. Regulatory intelligence also needs a seat in governance, informing board packs, risk appetite discussions and product approvals rather than sitting in a compliance newsletter.
Systemic risk rarely appears without warning. It builds quietly in the space between what regulators are signalling and what businesses actually act on. The question every firm should be asking is not whether the information exists, but whether anyone is being trusted to connect it.
Vinit Shah, former general manager, VARA; Strategic Advisor, Sherlocq, said, “Major compliance failures rarely occur because regulations do not exist. More often, the signals are already available across regulatory guidance, consultations, enforcement actions, and public disclosures, but organizations lack the capability to connect them into a coherent picture before risks materialize.
“In digital assets, where regulatory expectations evolve across multiple jurisdictions and at different speeds, compliance can no longer be treated as a periodic exercise or a box-ticking function. It must operate as a continuous intelligence capability. The greatest risk is often not what firms know, but what they fail to see until it is too late”.
Bhavin Shah, founder and CEO, Sherlocq, added, “Every major financial crisis of the past two decades had one thing in common: the warnings were already on the record. The 2008 collapse, IL&FS, FTX, in each case the post-mortem found signals that had been missed, siloed, or treated as background noise rather than actionable intelligence.
“The next crisis will follow the same pattern, unless firms build the infrastructure to connect regulatory signals to business decisions before they harden into enforcement. That connective work is precisely what Sherlocq was built to do: pulling together what regulators have actually said across jurisdictions, in minutes, so that the dots can be joined while there is still time to act.”
Read the full Sherlocq post here.
By Daniel Willis, Editor of RegTech Analyst
Copyright © 2026 RegTech Analyst
Copyright © 2026 RegTech Analyst





