Who owns trust in financial services?

financial services

Trust sits at the centre of financial services, underpinning the relationship between customers and firms while giving regulators confidence that institutions can manage risk and protect the markets in which they operate. Yet as the industry becomes increasingly dependent on digital systems, third-party providers, artificial intelligence and data, responsibility for maintaining that trust is becoming harder to define.

The challenge is not simply whether financial institutions can be trusted, but whether they can demonstrate that the technologies and processes behind their decisions are reliable, transparent and properly controlled. With fraud becoming more sophisticated and financial services becoming more interconnected, the question of who ultimately owns trust is becoming increasingly important.

In the final part of this RegTech Analyst Series, we delve into the final piece of the Future of Trust: Rethinking KYC in a Digital Financial System discussion. In this final piece, we ask a fundamental question: who owns trust in financial services?

The earlier parts focused on other critical areas, including most recently part 3, where the identity problem in KYC was discussed, how dangerous is the rise of synthetic identity fraud, whether we are entering a new era of digital ID and has KYC become a digital trust problem.

This built on the earlier part 2, where we jumped into why traditional KYC is no longer sufficient for an increasingly dynamic risk landscape, and how continuous KYC is emerging as the next evolution in customer due diligence.

In part 1, we asked industry leaders why traditional KYC no longer works and the reasons why it may be hitting its limit in today’s world.

Who owns digital ID assurance

The first question to on this wider topic, is who should own digital identity assurance, and why?

In the view of Zurab Kotaria, co-founder and CEO of Identomat, digital identity assurance has to be a shared responsibility, but accountability ultimatelysits with the institution making the decision.

He said, “Financial institutions need to know who they are dealing with and be able to demonstrate why they trusted a particular customer or transaction. At the same time, they should not have to build every layer of identity infrastructure themselves. Technology providers, trusted data sources, foundational ID issuers, regulators and financial institutions all have a role to play in creating a reliable digital identity ecosystem.”

For the Identomat CEO, the important distinction is between outsourcing technology and outsourcing responsibility.

“Firms can use specialised providers to verify identities, assess risk and automate parts of the process, but they still need visibility into how those decisions are made and confidence that the controls meet their own risk standards,” he added.

As financial services and IDs and credentials becoming increasingly more digital, identity assurance, Kotaria remarked, will become less of a single KYC step and more of an underlying trust layer that supports the entire customer relationship.

Kevin McGuinness, global head of strategy at Napier AI, meanwhile, believes that digital identity assurance is already being unbundled from the institution.

He explained, “Under eIDAS 2.0, every EU member state must offer a certified digital identity wallet by the end of 2026, with regulated sectors expected to accept it from late 2027. In the UK, version 1.0 of the digital verification services trust framework comes into force on 1 September 2026, on a statutory footing under the Data (Use and Access) Act 2025 and with its own certification mark. “

All of this is meaning that governments are becoming the issuers of verified attributes and certified providers are becoming the assurance layer.

“But owning identity is not the same as owning trust,” said McGuinness. “Verifying who someone is will increasingly be a utility service. Assessing what that customer is likely to do — and standing behind the decision to onboard them, discount an alert or file a report — stays with the regulated institution. No wallet, bureau or vendor takes that liability off the money laundering reporting officer (MLRO). That is why collaboration matters, but only a particular kind of collaboration.”

Will KYC’s future hinge on collaboration?

KYC is a fast-changing space, and being able to meet the needs of new technologies is more important than ever in a world that is becoming rapidly more requiring of nimble and agile technologies.

Will the future of KYC depend on industry collaboration? In the view of McGuinness, shared identity infrastructure, shared typologies and shared intelligence inside regulator-sanctioned utilities, such as Singapore’s COSMIC platform, Canada’s Project Shadow, the Financial Conduct Authority’s synthetic data work, will genuinely raise the floor for everyone.

He said, “Shared liability does not exist, and firms should be sceptical of any model that implies it does. For most institutions the most valuable form of collaboration is more practical: working with providers who see the risk landscape across many institutions rather than one, so that detection logic and typologies improve from collective experience instead of a single firm’s alert history.”

Meanwhile, Kotaria is clear in his stance that collaboration is required, particularly because financial crime does not operate within the boundaries of a single institution.

Kotaria remarked, “Fraudulent identities, synthetic identities, compromised documents, and other risk signals can appear across multiple platforms long before any one institution has enough information to identify a pattern independently.

“Greater collaboration can help the industry move from isolated KYC processes toward more interoperable and risk-based identity ecosystems. At the same time, this collaboration must be balanced with privacy, data protection, security, and clear accountability.”

The Identomat head also anticipates that KYC itself will become more connected internally.

His view is that identity verification, AML screening, fraud detection, transaction monitoring and ongoing customer risk assessment have traditionally been treated as separate processes.

He commented, “Bringing these signals together can give institutions a much more complete understanding of customer risk. This is exactly what Identomat focuses on: helping businesses connect these different elements within a unified, configurable compliance and identity verification framework.

KYC in 2031

Will regulators expect from KYC five years from now? The financial industry has experienced rapid change the last few years as AI embeds itself into operational structures. To even look ahead two years, nevermind five, is a big jump indeed.

“I expect regulators to increasingly focus on the effectiveness of KYC rather than simply whether a firm can demonstrate that a check took place,” said Kotaria.

“Completing identity verification at onboarding will not be enough if a customer’s circumstances or risk profile can change significantly over time. We are already moving toward a model where firms need to understand customer risk throughout the entire lifecycle and respond when new information or risk signals emerge.”

For Kotaria, this will widen expectations around continuous monitoring, data quality, explainability, auditability, and risk-based decision-making.

 “As automation and AI become more deeply embedded in compliance, firms will also need to demonstrate how automated decisions are governed, what information influenced them, and when human intervention is required,” he said.

Five years from now, Identomat’s CEO believes the strongest KYC frameworks will be those that are able to demonstrate not only that a decision was made, but why it was made and whether it remained appropriate as the customer’s risk evolved.

He finished, “Clear auditability should be a fundamental part of every compliance framework, and at Identomat, we are proud to provide businesses with the tools to maintain transparent, traceable records throughout the verification and decision-making process”.

Five years from now, McGuinness expects supervisors to be asking a different question.

He explained, “Not “show me your know your customer (KYC) policy” but “show me how your assessment of this customer changed, and why”. Periodic review cycles will look increasingly indefensible when continuous data is available and the technology to act on it is proven. 

He gave the example of the EU’s Anti-Money Laundering Regulation, which applies from 10 July 2027, and the Anti-Money Laundering Authority begins direct supervision of selected cross-border institutions in 2028. In McGuinness’ words, the direction is already set: evidenced, dynamic and auditable client risk assessment across the full customer lifecycle.

McGuinness concluded, “We would frame that as perpetual client risk assessment (pCRA) rather than perpetual KYC (pKYC) — a single risk view that updates from screening, payment behaviour and fraud signals, with a documented risk-based rationale behind every score. The expectation will not be that firms use artificial intelligence (AI). It will be that they can explain what it did.”

Read the daily RegTech news

Copyright © 2026 RegTech Analyst

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2026 RegTech Analyst

Investors

The following investor(s) were tagged in this article.