What are the biggest barriers to third-party RegTech adoption?

RegTech

RegTech has moved from an emerging technology category to an increasingly important part of the compliance stack. Yet while vendors continue to invest heavily in AI, automation and new regulatory solutions, financial institutions are not adopting third-party RegTech at the same pace.

The gap points to a deeper problem than technology readiness. Legacy infrastructure, fragmented data, integration costs and internal resistance can all make adopting an external solution more difficult than building around existing systems. At the same time, compliance teams must weigh the promise of innovation against questions of trust, explainability, security and regulatory accountability.

So, what barriers loom largest when it comes to third-party RegTech adoption? We recently asked industry leaders where they believe such roadblocks exist, and why.

The Global State of RegTech 2026 – a report co-authored by RegTech Analyst and Parker Lawrence Research – delved into this key topic during the report. You can download the full report here.

As part of the report, vendors and institutions were challenged on a number of key areas within the FinTech market, with the central discussion point being where they identified the biggest barriers to third-party RegTech adoption.

The report saw certain areas of almost agreement, with integration of legacy systems seen as key barrier by both, 52% of institutions and 58% of vendors. On the opposing side, an area such as fragmented internal ownership saw 50% from vendors, and only 22% by institutions.

In the first part of a two-part series, we speak to industry thought leaders to get their take on it.

Why FIs are still cautious about third-party RegTech

Why are financial institutions still on shaky ground when it comes to third-party RegTech? For Keir Anderson, a senior tax professional at TAINA Technology, believes that at its core, it comes down to trust.

He explains, “Financial institutions are being asked to rely on technology providers for activities that sit at the heart of their compliance and regulatory obligations. While many RegTech firms have been operating successfully for years, they often don’t carry the same brand recognition as the large accounting firms, law firms, or traditional consulting organizations that financial institutions have historically relied upon.”

There is, he adds, a significant difference between obtaining advice and changing an operating model. “Adopting a RegTech solution often means embedding technology into key processes, relying on automated decision-making, and adjusting established workflows. That’s understandably a much bigger step than engaging an advisor for an opinion,” said Anderson.

For Anderson, the responsibility for overcoming that concern sits with the RegTech provider. He believes firms need to demonstrate that their solutions are built by industry practitioners, are grounded in the regulations, reflect established market practice and are supported by robust governance, auditability, and transparency.

He added, “Once financial institutions understand that, the conversation tends to move from “Can we trust this?” to “How quickly can we implement it?”.

For Areg Nzsdejan, CEO of Cardamon, two things dominate on this topic – data and accountability.

He explained, “Compliance data is some of the most sensitive data a firm holds – client information, risk assessments, internal control findings. Handing that to a third party triggers procurement, legal, and information security processes that can run for months”.

Even after a sign off, the Cardamon head states that there is a deep unease, as if the tool gets something wrong, the firm is still the one facing the regulator.

“Vendors do not take on that liability. Firms know this, and it makes them cautious in a way that is entirely rational,” said Nzsdejan.

The factor that follows this is integration. He stresses that most institutions are not starting from a greenfield, and have legacy systems, fragmented data, and compliance workflows that have been stitched together over decades.

He remarked, “Onboarding a new RegTech tool into that environment is rarely as straightforward as vendors promise in the sales cycle. At Cardamon, we’ve optimised for this by not requiring heavy connectivity – we have agentic document ingestion as well as easy to use push/pull APIs and our integration timelines are 1-2 weeks instead of 1-2 quarters.”

Sebastian Hetzler, co-CEO of IMTF, was succinct on this topic, stating that financial institutions are not necessarily hesitant to adopt third-party RegTech solution. Instead, they are cautious about introducing additional complexity into already complex technology environments.

The adoption barriers hard to overcome

Amongst all these adoption barriers, a question being asked of vendors and institutions is which are the toughest to scale over.

In the view of Nzsdejan, integration is hard, but is solvable with time and resource. The hardest barrier in his view is trust, specifically, the gap between what vendors claim and what procurement, legal, and compliance teams are actually willing to sign off on.

He commented, “Procurement cycles in large financial institutions move slowly and risk-aversely by design. Vendors that are moving fast and selling transformation find themselves in a long, exhausting process designed for a different era.”

Nzsdejan added that the accountability question is ‘genuinely unresolved’, as firms want AI to do more, but they also want someone to be accountable if it goes wrong.

Hetzler is of the view that the greatest barriers  are often rooted in legacy architectures, fragmented data and integration challenges.

He stated, “Many institutions continue to rely on multiple systems for KYC, AML transaction monitoring, sanctions screening, fraud detection and case management, each operating with its own data model and workflows. Adding another standalone solution can create further silos rather than improving overall effectiveness.”

As financial crime to tighten its interconnected bonds, this fragmented approach in the view of Hetzler makes it more difficult to establish a complete view of customer risk, investigate cross-domain activity and respond efficiently to evolving threats.

“The challenge is therefore no longer simply deploying new technology, but ensuring it fits within a broader, connected compliance ecosystem,” he explained.

Anderson, on the other hand, picks navigating the internal approval process as one of the toughest walls to climb.

He explained, “In my experience, once a financial institution sees a solution addressing a genuine operational problem, stakeholders become highly engaged and can quickly see the potential benefits. The challenge is that implementation often requires approval from multiple functions, including compliance, tax, operations, technology, information security, procurement, legal, and sometimes risk management.”

Each group in Anderson’s mind has a legitimate role to play, however, coordinating those reviews can take significant time and effort. Even when there is strong business support, he adds, the procurement and due diligence process can extend timelines by months.

He remarked, “That’s particularly true for solutions that will become embedded in core operational or compliance processes, where institutions understandably apply a high level of scrutiny before making a commitment.”

The route to scaling the summit

This leaves a vital question: how can vendors overcome these barriers going forward? Anderson is clear in his view that the two watchwords are patience and partnership

He made clear, “Financial institutions are not deliberately creating obstacles. They are managing risk and ensuring new solutions meet the standards expected within their organization. Successful vendors recognize that adoption is often a journey rather than a single purchasing decision.”

Due to this, Anderson states that its key to be flexible, transparent and willing to work collaboratively throughout the evaluation process.

“That means providing clear documentation, demonstrating how decisions are made, explaining governance and controls, and helping stakeholders build confidence in the solution,” he said.

Anderson summarises by stating that the good news is that once that trust has been established and the initial procurement process has been completed, future expansion opportunities often become much easier.

He finished, “Organizations are far more willing to consider additional use cases, functionality, or services from a provider that has already demonstrated value and earned credibility within the business.”

Hetzler’s route to overcoming such barriers requires RegTech vendors to prioritize interoperability as much as innovation.

He said, “Open APIs, flexible integration capabilities, cloud-native architectures and configurable deployment models enable institutions to modernize at their own pace rather than replacing existing systems overnight. Equally important is the ability to unify data and orchestrate workflows across compliance functions, allowing organizations to build on previous investments while progressively reducing operational silos.”

This is why Hetzler rounds off by stating that the next phase of adoption in RegTech will be driven less by individual point solutions and more by platforms that connect data, processes and decision-making across the entire financial crime lifecycle.

He said, “Institutions are increasingly looking for technology that complements and modernizes their existing landscape while delivering a unified, customer-centric view of risk.

“The biggest challenge isn’t adopting another RegTech solution – it’s making sure it doesn’t become another silo. The future belongs to platforms that connect data, workflows and intelligence across the entire financial crime lifecycle, enabling institutions to modernize without adding complexity,” concluded the IMTF co-CEO.

Nzsdejan’s tips for success here are start narrow and prove it.

“The vendors getting adopted fastest are the ones who walk in with a specific, well-scoped use case, deliver it clearly, and let the ROI speak. Trying to sell a platform transformation to a cautious buyer is much harder than solving one real problem well and expanding from there,” he said.

The Cardamon CEO remarked that at his company, they price based on ROI. “We map out the value for each client’s specific situation before they commit. That changes the conversation from “can we trust this?” to “is this worth it?” – which is a much easier question to answer.”

On the topic of accountability, the vendors who will win the day in his mind are those willing to build the infrastructure that makes oversight real – audit trails, rationale for every decision, clear human escalation points. That is not just good governance; it is the thing that gives compliance teams the confidence to actually use the product and something that Nzsdejan states Cardamon leads with.

He summarised, “Trust is built through transparency, and transparency has to be designed in from the start.”

A dozen problems with a root cause

For William Davenport, managing director at Wordwatch, it’s tempting to read the list of RegTech adoption barriers as a dozen separate problems, when most of them share a root cause.

He stated, “FinTech Global’s Global State of RegTech 2026 report shows healthy demand, with 62.7% of organisations increasing spend and 95% already using RegTech at enterprise scale in at least one regulatory domain.

“The obstacles that remain, though, keep pointing the same way. Integration with legacy systems leads at 52%, internal data quality and availability follows at 47%, and 30% say they carry too many disconnected tools. Three of the biggest barriers are all descriptions of fragmented, unreliable data.”

Davenport then links back to the firm’s own survey of 100 compliance, IT and surveillance professionals, which he says echoes the research. “Only 17% had a unified archive across voice and digital, and 79% were still running on legacy systems,” he made clear.

For the Wordwatch MD, this is why so many financial institutions stay cautious. A strong tool on a weak data foundation disappoints, he says, and plenty of teams have learned that the hard way.

He added, “It also explains why the foundational barriers are the hardest to shift: an AI or surveillance tool inherits the data it’s given, so incomplete or unreconciled records get scaled, not fixed.”

Meanwhile, for vendors, the implication is direct for Davenport.

He concluded, “Start with the data layer, work with the estate the customer already has, and help build the business case with the evidence it needs. Organisations aren’t hesitating because they doubt RegTech. They’re waiting until their data is in a state that lets a new tool deliver.”

Read the daily RegTech news

Copyright © 2026 RegTech Analyst

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2018 RegTech Analyst

Investors

The following investor(s) were tagged in this article.