A quiet change is reshaping how regulated firms and their supervisors relate to one another, and many risk and compliance teams have yet to grasp its full implications.
According to Sherlocq, for roughly 20 years, oversight followed a predictable pattern. Firms controlled the data, and regulators requested it. Firms then chose how that information was packaged, submitted and explained.
Supervisors relied heavily on what firms decided to share, and experienced compliance professionals knew that inspection preparation was as much about presentation as substance.
That model is fading. Supervisors can now analyse board minutes, management reports, policies, procedures and large data sets with unprecedented speed. They can summarise complex policies, test them against regulatory requirements and interrogate data at scale. Analysis that once took weeks can now be ready on the first day of an inspection.
Regulators across financial stability, data protection, consumer markets and other areas have invested heavily in data infrastructure. The UK’s Financial Conduct Authority has expanded its data science capabilities to monitor transactions, identify outliers and model firm behaviour.
The European Central Bank’s supervisory arm uses automated tools to cross-check disclosures for inconsistencies. In the US, the SEC’s enforcement division relies on analytics to spot possible misconduct before formal investigations begin. Meanwhile, every regulator in the UAE is developing SupTech capabilities, often incorporating artificial intelligence.
The consequence is that supervisors increasingly arrive with a view already formed from the data, not from what firms have told them. They may know that complaints rose months before a product issue was flagged, or that conduct metrics place a firm well outside its peer group. Yet many compliance teams still depend on the same spreadsheets and manual attestations they used five years ago.
This imbalance creates real risks. Inspections can now bring genuine surprises, and a gap between what the regulator knows and what the firm knows is itself a sign of weak risk management. Supervisory conversations have also shifted, with regulators focused on testing explanations against evidence rather than listening to narratives. Firms arriving with high-level summaries can lose credibility quickly. Enforcement timelines are also shortening, reducing the window for self-correction.
The response starts with honest self-assessment. Firms need an unfiltered view of what their own data reveals, alongside a clear understanding of current regulatory expectations. Risk and compliance functions must work more closely with data and technology teams, since interpreting regulatory data demands different skills from drafting policy. Candour should replace narrative management, and horizon-scanning must become a priority as supervisors expand their capabilities and share intelligence across borders.
Ultimately, this is less a technology story than a question of who holds the better information. For the first time in a generation, that may be the regulator.
Bryan Stirewalt, Former Chief Executive, DFSA; Strategic Advisor, Sherlocq, said, “Supervisors have always known more than firms assumed. What has changed is the scale and speed of that advantage. Regulators are no longer dependent on what firms choose to surface. They are building the picture themselves, and firms that have not grasped that shift are walking into supervisory conversations already behind.”
Bhavin Shah, Founder and CEO, Sherlocq, added, “The compliance function was built for a world where firms held the data advantage. That world no longer exists. Sherlocq exists precisely for this moment: to give compliance teams the same quality of regulatory intelligence their supervisors are already working with.”
Read the full Sherlocq post here.
By Daniel Willis, Editor of RegTech Analyst
Copyright © 2026 RegTech Analyst
Copyright © 2026 RegTech Analyst





