Regulatory reporting is a core pillar of compliance within financial institutions, but costs and complexity continue to rise, creating a host of challenges.
The Bank of England’s ‘Future of Finance’ report estimated that regulatory reporting costs UK banks between £2bn and £4.5bn annually. As firms face more regulations, especially those expanding across borders, the number of rules they must report on grows. Adding to this challenge is a shift in how reporting is conducted, with regulators moving away from periodic reports to real-time, creating more strain on existing reporting systems.
Despite all the advances and investment in bolstering reporting efforts with new technology, it is a process that continues to be costly and complex.
Statistical versus prudential reporting
However, when assessing the true cost and complexity involved with regulatory reporting, Luke DiRollo, CEO of ALMIS International (ALMIS) emphasised the importance of distinguishing between statistical reporting and prudential reporting.
The former provides central banks with macroeconomic and monetary statistics and, for banks, is fundamentally a compliance exercise and a cost of doing business. These are relatively straightforward, DiRollo noted, with very few complex calculations being required. However, prudential reporting is very different, he said. It enables supervisors to assess the safety and soundness of individual institutions.
“Looking back 20 years, prudential risk management represented one of the most significant investments banks made in finance capabilities. It demands deep expertise because it sits at the heart of how banks operate and ultimately drives performance.”
Banks are designed for maturity transformation, which creates liquidity, credit and interest risk. Each asset and liability contributes to this “intricate, interconnected, inherently intelligent discipline of balance sheet management,” DiRollo explained. As such, regulators implement risk management standards via the Pillar 1 framework, under which banks then produce monthly or quarterly reports covering all loans, deposits and relevant exposure. All of this is built on volumes of data, transformation and sophisticated calculations.
When reduced to fundamentals, prudential reporting is based on four pillars: data capture, data lineage, legal interpretation and calculation, DiRollo stated. However, most banks gain little value from Pillar 1 reports.
He said, “Some of the underlying metrics are undoubtedly useful, but the effort required to move from raw data to a compliant submission – combined with the supervisory consequences of poor controls or inaccurate reporting – (often) means that the reporting process becomes an end in itself rather than a source of strategic insight. Can you imagine giving a Liquidity Coverage Ratio (LCR) or Own Funds report to a non-executive director when asked about a certain risk? I wouldn’t recommend it.”
He added, “This assessment isn’t a criticism of regulators. It’s more about how our sector needs to evolve as a community. The objective is entirely understandable. To obtain consistent, reliable information that supports effective supervision. However, the current implementation has several unintended consequences.”
Why the cost of reporting remains high
Reporting might seem like a simple task, but there are numerous moving parts that add to its complexity, while outdated systems remain deeply ingrained. What makes the cost of reporting so difficult to address is that there is no single cause.
As RelyComply CEO Bradley Elliott noted, “The more moving parts involved in an anti-fincrime defense system, the more the infamous ‘cost of compliance’ grows into a money pit. Reporting is a crucial aspect, drawing together individual businesses and FIUs – where retaining manual ‘old-school’ techniques to highlight risky alerts is highly detrimental to fulfilling regional and global AML rules.”
On top of this, the lack of consistency across borders makes reporting even harder. Firms operating across multiple locations face different rules ranging from major differences to more nuanced ones, often creating vulnerable holes in the global compliance effort. Elliott said, “Unlike payments messaging, which has now largely standardised globally under ISO 20022, there is no equivalent common standard for suspicious activity reporting – each FIU sets its own format, fields, and thresholds. Requirements can be misinterpreted, reports filled with errors, and time wasted on low-risk alerts. This all hinders the ability to commit to sharp SAR deadlines.”
Then there is the fact that regulation never stops. There is an unprecedented level of regulatory change that financial institutions have to contend with. There is an endless stream of new rules, updates to existing legislation and evolving regulatory expectations. Adding to this, Keir Anderson, a senior tax professional at TAINA Technology, also noted that a significant challenge is the fact the industry is becoming increasingly interconnected. Firms are expected to aggregate, validate and report large volumes of data that comes from various systems, business lines and jurisdictions. This makes maintaining a clear audit trail incredibly difficult.
He said, “I don’t believe there will ever be a single global regulatory framework that removes all of these challenges. Different countries have different policy objectives, reporting requirements, and supervisory priorities. As a result, firms must continuously adapt to a moving regulatory landscape while also managing the realities of operating globally.
“The goal is not to eliminate every challenge. The goal is to build processes, controls, and technologies that allow organisations to respond efficiently as requirements evolve.”
What makes the cost of reporting harder to accept is that the task should not be difficult. It just comes down to a system that is full of inefficiency.
Duco van Lanschot, co-founder and CEO, Duna, said, “The report is rarely the hard part. A filing is only as good as the evidence behind it, and that evidence sits across seven or eight disconnected systems and analyst judgment no one wrote down. Every report means reconstructing a decision after the fact. Do that thousands of times a month, against rules that keep changing, and the cost compounds. Only about 2% of financial crime is ever detected: enormous effort, most of it missing the target.”
Existing reporting frameworks and workflows were not designed for the current level of change and regulatory expectations. Manual work and disjointed systems leave teams falling further behind and vulnerable for mistakes and fines. There needs to be a new generation of regulatory reporting, according to Dr. Sebastian Hetzler, co-CEO at IMTF, that is embedded into the broader workflow, rather than treated as a standalone process.
He said, “By integrating reporting directly with alert management, investigations and case management, institutions can automatically leverage information already collected during the investigation, improve data consistency, strengthen auditability and significantly reduce manual effort.”
For ALMIS’s DiRollo, the future of reporting is not simply about the ability to be near real-time, it is about ensuring data is connected to make the process more seamless for teams. He noted a growing vision shared by regulators and practitioners where regulation is completed through standardised data rather than standardised reports. “Regulatory reporting will always be expensive if it’s delivered in isolation.”
The solution is to standardise the underlying data so every stakeholder can reuse it. “For every purpose. Capture and structure data once. Derive the underlying risk metric once. Then aggregate and present those metrics differently depending on the audience – whether that is the regulator, Treasury, Finance, Risk or the Board.”
This concept, which ALMIS operates by, aims to remove duplication across risk and reporting through a single, trusted source that can help compliance and commercial decision-making. However, for it to be a reality, the industry will need to work together. “Regulators, practitioners and technology providers all have a role to play in embracing a common data foundation that serves multiple purposes. Only then can we reduce unnecessary complexity, unlock greater value from prudential data, and build a regulatory framework that is both more efficient and more effective.”
The next generation of reporting technology
There is no quick fix for firms looking to improve their reporting capabilities. They need an approach suited to the modern regulatory environment, one that can adapt and evolve alongside regulation. While it is impossible to predict the way regulations will evolve, firms can ensure their systems are adaptable rather than static.
Taina’s Anderson expects the future of reporting to look digital, automated and integrated into operational processes. As for regulators, he expects them to move towards more direct and standardised methods of data exchange, including APIs and near real-time reporting capabilities.
He added, “From a regulatory perspective, having access to more timely and granular information offers obvious advantages. That said, such an approach would also raise significant questions around data security, privacy, governance, standardisation, and operational burden. While the technology may be possible, market acceptance is a separate question.”
Irrespective of what the exact future looks like, Anderson is confident of three things, more automation, greater data quality and reduced manual intervention. “Firms that invest in strong data foundations today will be far better positioned to adapt to whatever reporting requirements come next.”
Duna’s Lanschot shared a similar prospect for the future of reporting, but his main vision surrounded the continuity of reporting, rather than it being periodic. He said, “Reporting stops being an event and becomes a property of the system.”
Reporting is currently a snapshot of compliance, “stale by the time it lands.” Instead, the next generation will be continuous. “The source of truth lives in the data, every decision is recorded as evidence when it is made, and any filing can be reproduced on demand.” Through this system, when a merchant switches from legitimate goods to counterfeit pharmaceuticals, for example, the record updates and the obligation re-triggers. Everything happens instantly, rather than waiting for the next review to come around in the calendar.
However, Lanschot notes that a technology system running this process will not be valid unless the regulator can trust the output. This will require consistency for the same decision each time, with every step logged. “That is the difference between a filing you can defend and a black box you cannot.
“The firms that win the next decade will treat reporting as evidence their system produces as it runs, not a tax they pay after the fact. Build for the regime you will be held to, not the one you were.”
AI in the future of reporting
Today, discussions around innovation and the future of work almost inevitably turn to how AI can improve workflows. Reporting is no different. The technology can help compliance teams react more quickly to regulatory changes, sifting through content to identify what is relevant to them as well as accessing quick recommendations on how to proceed. It can also help accelerate the generation of reports, whether that means collating data or triggering a review after a change is detected. AI can help firms cope with rising regulatory pressures without needing to hire an army.
However, it is not just a case of implementing AI technology and expecting it to solve all the problems. It is quite well known that you get out what you put in, and if the underlying infrastructure is lacking, so will the AI’s output.
With that mindset, Lanschot believes AI and automation will only transform reporting for the firms that rebuild their evidence layer, rather than just automating the paperwork at the top level. While buying a bolt-on AI solution to existing frameworks might be quicker, Lanschot is confident the result will not be as good as one that has been designed alongside it.
Speaking from experience, he said, “Built properly, the gains are not incremental. Our customers clear most routine cases in under a minute of reviewer time, handle roughly four times the complex work, and cut onboarding submission times by about 60% by pulling data from primary sources. Reporting is the same move: the machine assembles the evidence and drafts the filing, and the expert signs off on the judgment.”
While AI allows compliance teams to achieve more without expanding the team drastically, it does not spell the end of human investigators. IMTF’s Hetzler emphasised that AI is important but not at the expense of people. “Instead, they will enhance productivity by automatically populating reports, validating data completeness, summarising investigation outcomes and recommending report content, while ensuring that compliance professionals retain full oversight and responsibility for regulatory submissions.”
It has already been stated that the future of reporting is likely going to be continuous. This is something AI helps to achieve. RelyComply’s Elliott stated that as reporting becomes focused on earlier detection, rather than reactionary manual remediation, AI-powered platforms will help to ensure reporting is embedded with other continuous due diligence and monitoring to ensure reporting requirements are met instantly.
However, much like Hetzler, humans are still foundational to this role. Elliot said, “The one manual task that should remain is a compliance team’s assessment of explainable AI’s rationale for raising risky alerts. That way, reported SARs are filled with accurate insights needed for potential law enforcement action – a perfect hybrid model of humans and platforms making the correct decisions, and proving a level of oversight regulators greatly require to battle nefarious actors.”
Copyright © 2026 FinTech Global
Copyright © 2026 RegTech Analyst





