The UK’s financial regulatory framework is entering another period of change, with implications that could extend well beyond the rules firms must follow.
The Financial Services and Markets Bill is designed to modernise financial regulation, spanning regulatory oversight, authorisation, consumer protection and the wider regulatory framework. It is also estimated by the UK government to save regulated firms a total of £1.08bn. For RegTech, however, its significance could lie in what this changing environment demands from the technology supporting compliance.
As regulation becomes more dynamic and interconnected, financial institutions may need more than tools that simply keep pace with new rules. Could the Bill therefore reshape what firms expect from RegTech, and where the market goes next?
The next step for RegTech
A key question to ask with this incoming bill is whether the legislation will create new demand for RegTech.
In the view of Iain Armstrong, executive director of FCC strategy at ComplyAdvantage, it will, though not in the way a deregulatory bill may suggest.
He said, “The UK’s Financial Services and Markets Bill – introduced to Parliament on May 20, 2026 – promises a new era of growth through faster four-month authorizations, provisional licensing, and a unified supervisory structure, with the Payment Systems Regulator folded into the Financial Conduct Authority (FCA).”
Despite research from ComplyAdvantage finding just over half of compliance leaders advocating for innovation-focused regulation, Armstrong believes appetite doesn’t mean readiness – a lighter rulebook simply shifts the burden of proof.
“Under outcomes-based regulation, firms can no longer rely on checklist compliance. Instead, they’re required to actively demonstrate that their judgment was sound and to reconstruct the reasoning behind it – a transition that turns compliance into an evidence problem before it becomes a technology problem,” said Armstrong.
As the FCA consolidates authority over authorised push payment fraud reimbursement and faster market entries demanding screening capabilities from day one, businesses should ensure their decision-making logic is robust, auditable and defendable.
Kevin McGuinness, global head of strategy of Napier Ai, also agrees it will create new demand, however, such demand will not be immediate and will be uneven.
“Much of the Bill is about streamlining, and firms are unlikely to feel its full impact before 2028, he said.
The measure most likely to create direct tech demand is AML supervisory reform, views the Napier strategy head.
He explained, “Supervision of legal, accountancy and trust and company service providers is currently spread across 22 professional body supervisors, and the Office for Professional Body AML Supervision (OPBAS) reported in March 2026 that these bodies continue to perform poorly on enforcement. Moving that population under a single FCA-led regime will raise expectations for client screening, risk assessment and evidence of controls.”
The Payment System Regulator’s move into the FCA will additionally bring authorised push payment fraud reimbursement and AML under one roof, McGuinness said, bolstering the case for businesses to stop running fraud and financial crime detection in separate silos.
Whilst the headline reforms are about growth and simplification, the AML supervisory change is the key one-to-watch for McGuiness in strengthening demand.
He said, “Thousands of professional services firms will move from 22 supervisors to one, and the FCA’s expectations will not be any less stringent. Many of those firms have never needed to invest in screening and risk assessment at the level a single, consistent supervisor will expect. Firms that start preparing now will set the standard others are measured against.”
For Marc Salter, lead account executive of ACA Group, he is also in agreement in its ability to boost demand, albeit a structural demand.
He said, “It isn’t a single rule change, it’s a rule write over several years. It means firms have to re-map their compliance obligations repeatedly between now and 2027. That’s a recurring need for RegTech, not a one-time need.”
Salter detailed how the FCA has explicity said it wants to see itself as a ‘smarter regulator’, using more data-led supervision.
“That will no doubt push the burden of accurate, timely reporting onto market participants which is a direct RegTech use case. So, in short, it’s not a new demand for a single type of technology, but one that affects monitoring, reporting and evidencing of controls. The winners will be the platforms that can flex across that range rather than point solutions,” he remarked.
An individual who is less warm on the idea of boosted demand is Max Worrall, EMEA Account Executive at Cascade.
He said, “Potentially, but the interesting question is what kind of demand it creates. The government’s own description says the objective is to make the administrative burden proportionate without compromising core consumer, prudential and market protections.”
The bill, he added, is designed to reduce regulatory friction rather than reduce the need for firms to demonstrate that they are well controlled.
“The reforms include transferring the Payment Systems Regulator’s functions into the FCA, reforming the Financial Ombudsman Service, changing the SM&CR, reforming consumer credit regulation, introducing a provisional licensing framework and changing the ring-fencing regime. Parliament’s current description also confirms that the Bill introduces the provisional licences regime,” Worrall added.
The Cascade account executive stressed that a more principles-based and proportionate regulatory environment can give firms greater flexibility in how they meet regulatory expectations.
He added, “However, flexibility creates another requirement: firms need to be able to demonstrate why they took a particular approach.”
Auditable evidence trails around risk decisions could become more important firms. Worrall believes financial firms will want to be able to quickly access that decision for regulatory inspections, audits and investment reviews.
“RegTechs will need to ensure that these capabilities are part of their product roadmaps. They should allow clients the flexibility to demonstrate how risk-based decisions have been made and evidence risk mitigation that reflects their own internal documented policies and procedures. Technology that creates an auditable evidence trail around risk decisions could become more valuable,” he said.
When reform exposes tech gaps
Where will regulatory reform expose the biggest technology gaps? In the view of Janet Bastiman, chief data scientist at Napier AI, for key areas stand out.
The first area she details is that professional services firms whose client screening and risk assessment tooling was built for a lighter-touch regime. Secondly, the gap between fraud and AML systems, which becomes harder to justify once one regulator oversees both.
Thirdly, fast-growing new entrants using provisional licences, which will need compliance architecture that scales with them from day one. Fourth, evidence: a streamlined SMCR (Senior Managers and Certification Regime, the UK’s framework for making named individuals personally accountable for what happens in financial services firms.
Bastiman said, “The FCA and PRA run it, and it covers banks, insurers, investment firms and most other FCA-regulated firms.) reduces process burden, but it does not reduce the need to show why a decision was made. “
The last gap is the least visible, said Bastiman, but the most important. She cited the company’s research on regulatory maturity that places the UK among the “AI Accelerators”: markets where supervision is outcomes-based and regulators are actively encouraging AI in AML. Outcomes-based supervision rewards firms whose systems make every alert, disposition and escalation explainable and auditable, she said.
Bastiman finished, “When regulators reduce prescriptive process requirements, they rarely reduce the need for evidence. They shift the burden from ‘did you follow the procedure’ to ‘can you show the outcome was right’. That is a much harder question for a legacy system to answer, because it was designed to prove activity, not effectiveness. Outcomes-based supervision is an explainability requirement in all but name.”
Worrall, meanwhile, remarked that if firms still rely on fragmented data, manual workflows and evidence held outside the core compliance system could become exposed.
“It’s not just the coalition of evidence of decision making that takes time but it’s the retrospective justification and explanation of historic decisions when challenged,” said Worrall.
He adds that the biggest tech gaps are not likely to be created by any single provision of the bill directly, but more likely to emerge where firms have to translate simplified regulation into consistent, demonstratable processes.
He said, “A lack of connected regulatory-change, obligation and control mapping will bring a new exposure.”
Worrall concluded, “Regulatory reform may expose a technology gap that has been hiding in plain sight: firms don’t necessarily lack compliance technology; they lack connected compliance infrastructure.
“As regulation becomes more proportionate and processes are simplified, the ability to demonstrate how a risk-based decision was reached, what evidence supported it and whether the control operated effectively becomes increasingly important. For RegTech providers, that creates an opportunity to move beyond automating individual compliance tasks and towards becoming the infrastructure that connects data, risk, decisions and evidence.”
Salter, meanwhile, was succinct, “Firms that were previously doing activities that were not FCA regulated before, which means they are starting from zero – no compliance monitoring, no MI and no audit trail. That’s the widest gap – they will need the full compliance technology stack.”
The last comment on this topic came from Armstrong, who believes that the first gap on this point is a compliance paradox.
He explained, “Asked which areas of AML regulation require tightening in our research, 39% of compliance leaders named stronger public–private data-sharing protocols, and 38% named more specific transaction monitoring requirements. Paradoxically, firms are seeking greater specificity at the exact moment regulators are moving toward broader, outcomes-based expectations. Advanced technology should help bridge this gap by translating high-level outcomes into precise operational guardrails.”
The second gap, Armstrong comments, lies in delivery. Regulatory change is already a giant bottleneck for software adoption, with 29% of firms citing shifting regulatory expectations and another 29% citing shifting regulatory expectations, and another 29% citing the risk of non-compliance with existing rules, as barriers to upgrading their compliance solutions?
“Reform on this scale risks paralyzing the very implementation projects it should accelerate, as risk-averse firms defer budgets pending clarity. The Bill fundamentally changes the posture of supervision, raising the bar for defensibility across every control a firm operates,” Armstrong quipped.
Turning regulatory change into advantage
Can UK RegTech firms turn regulatory change into a competitive advantage?
Here, Salter declared, “The FCA is actively co-building with RegTech firms – their sandbox and TechSprint program give UK vendors regulator-tested use cases as sales proof points. That’s an advantage over competitors from other markets.”
However, he is clear to say that being UK-based doesn’t automatically give you an edge, but instead, being fast and close with the regulator does.
Meanwhile, McGuinness believes there is potential here, if they threat UK’s regulatory posture as a proving ground rather than a domestic market.
He said, “The UK regulator is testing AI directly alongside industry through the FCA’s Supercharged Sandbox and AI Live Testing programmes. Napier AI’s Insights AI capability was tested in the Supercharged Sandbox using frequency-based AI algorithms on large-scale synthetic data. Evidence generated in that environment carries weight with regulators well beyond the UK.”
The bill’s new overseas recognition powers and provisional licences may also help UK-built companies and tech scale internationally.
“The advantage, though, will belong to vendors whose technology aligns with how regulators define compliance-first AI, not to those with the most advanced models,” he said.
He finished, “The UK has something most markets don’t: a regulator that tests AI alongside the industry rather than waiting to judge it afterwards. That is a genuine head start for UK RegTech. But advantage won’t come from lighter rules. It will come from building technology that proves outcomes-based regulation works and then taking that proof to every market that is still deciding how to regulate AI.”
The final opinion on this topic came from Armstrong, who said that this belongs to vendors that demonstrate capability rather than describe it.
He said, “Our research found 61% of compliance leaders rank sandbox-based, holistic testing of data, algorithms, configuration, and ease of use among the most valuable ways to assess a RegTech vendor. Only 30% said the same of request-for-proposal responses, meaning buyers operating under supervisory judgment want proof they can point to.
“The UK’s move to outcomes-based financial services regulation, and its position ahead of most jurisdictions, is also a distinct export advantage. Vendors that demonstrate defensibility under UK supervision will be ready to scale globally as other regulators follow suit.”
The government has told regulators to advance a competitiveness and growth objective and a lighter, more proportionate rulebook is likely to be the result.
“But proportionate should not be taken to mean permissive. In fact, firms should see the bargain as follows: they will get more room to apply their judgment, and in return they will have to get better at showing their working,” said Armstrong.
He concluded, “This presents an intriguing line between the Bill and compliance technology. Firms wanting to pursue growth without incurring a downstream enforcement risk can set themselves up for success by treating the audit trail as a first-class citizen, ensuring the products and services they build can hold up to regulatory scrutiny.”
What the change means
For UK financial services firms, the question is no longer whether regulation is changing, but what that change means for the technology supporting compliance.
The Financial Services and Markets Act 2023 is reshaping the UK’s regulatory architecture, enabling retained EU financial services law to be replaced with rules designed specifically for the UK. With that transition happening in stages, firms could face years of rolling regulatory change, with UK requirements increasingly diverging from those of the EU.
According to RelyComply, this could create a new phase of demand for RegTech, but the opportunity will not simply come from adding more compliance software.
“It will come from helping firms adapt their data, reporting, controls and regulatory change processes quickly and reliably,” the company says.
That need is likely to be most pronounced where new regulatory requirements meet fragmented legacy infrastructure. Regulatory reporting is a clear example, with firms often relying on multiple generations of technology alongside spreadsheets and manually maintained processes.
For firms, the challenge is being able to trace regulatory submissions back to their underlying data, translate rule changes into operational requirements and quickly identify which systems, products and processes are affected.
The FCA’s direction of travel offers a useful indication of where those capabilities could be needed. Its 2026/27 work programme includes moving more regulatory data requests onto My FCA and testing data feeds between the FCA and participating firms to reduce manual effort. The regulator has also finalised changes to transaction reporting that will reduce the number of fields from 65 to 52, with the new regime due to take effect in April 2028.
These changes point towards demand for technology that connects regulatory intelligence with a firm’s data and systems, bringing together regulatory change management, data mapping, automated reporting, controls testing and audit-ready evidence.
For RelyComply, however, the answer is less about any single platform than how these capabilities work together.
“The answer is likely to be less about one particular platform and more about connected capabilities,” it says.
Legacy infrastructure could become one of the biggest constraints. A rule may be clear on paper but difficult to implement when relevant data is scattered across incompatible systems. Regulatory reform can therefore expose technology debt that has previously been hidden by manual workarounds.
For RegTech providers, this creates an opportunity to move beyond point solutions and help firms build a more adaptable regulatory operating model.
“The strongest proposition may therefore be adaptability,” RelyComply says. That means technology capable of absorbing regulatory change, mapping it to business processes, identifying affected data and systems, automating implementation where possible and producing evidence for compliance teams.
The result could be a market where regulatory change becomes more than a cost of doing business. It could become a catalyst for modernising the infrastructure underpinning compliance.
For financial institutions, RelyComply’s immediate recommendation is practical: conduct a RegTech gap analysis to identify where regulatory interpretation, data lineage, reporting, controls and change management still depend on manual or legacy processes.
Those weaknesses could determine both the cost of future compliance and the value that new RegTech solutions can deliver.
Copyright © 2026 RegTech Analyst
Copyright © 2026 RegTech Analyst





