# Why Financial Services Must Stay Compliant
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2020-04-30
Category: FINANCE
Category URL: https://financedigest.com/category/finance
Meta Title: The Impact of Global Financial Regulations on Organisations
Meta Description: Discover the impact of global regulations on financial services &amp; how organisations can stay compliant. From SOX to GDPR, find out why accountability is
URL: https://financedigest.com/why-financial-services-must-stay-complianthtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/fd090917-1-2-1736838920737-compressed.jpg)

_By **Grainne McKeever,** Senior Security Product Marketing Manager at Imperva_

The vast number of regulations introduced over the last few years have had a drastic effect on how and why organisations need to stay compliant across the financial services landscape. The surge of regulations has had positive benefits for organisations across the world and have guaranteed that security and accountability are at the forefront of business strategy.

Let’s start with the [Sarbanes-Oxley Act (SOX)](https://www.investopedia.com/ask/answers/030315/what-impact-does-government-regulation-have-financial-services-sector.asp) which was introduced in 2002. This was announced following a number of financial scandals involving huge conglomerates and obliges companies to establish [internal controls](https://www.financedigest.com/international-space-station-thrown-out-of-control-by-misfire-of-russian-module-nasa.html "International Space Station thrown out of control by misfire of Russian module -NASA") to prevent fraud and abuse, holding senior managers accountable for the accuracy of financial reporting.

![Grainne McKeever](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/grainne-mckeever-1736838920684-compressed.jpg)

Grainne McKeever

The financial crisis in 2008 meant even [tighter rules](https://home.kpmg/xx/en/home/insights/2019/03/beyond-compliance-fs.html) for financial services with the [Dodd-Frank Wall Street Reform](https://www.investopedia.com/ask/answers/032715/how-are-investment-banks-regulated-united-states.asp) and Consumer Protection Act in the US bringing a great deal of new regulations for the sector. In Europe, in a joint move between the UK, France and Germany, banks were forced to contribute to the region’s economic recovery by paying an annual [tax levy](https://www.bbc.com/news/business-20811289).

The UK experienced a complete overhaul of its financial regulatory structure when the existing tripartite system was abolished and replaced by a new framework consisting of the Financial Policy Committee (FPC), the Prudential Regulation Authority (PRA), and the Financial Conduct Authority (FCA). Since then, new regional directives have materialised, including the New York State Department of Financial Services’ (NYDFS) regulation, and the Monetary Authority of Singapore’s ( [MAS-TRM](https://www.mas.gov.sg/regulation/regulations-and-guidance?topics=Risk%20Management%2FTechnology%20Risk)) guidelines.

Driven largely by digital transformation, the emergence of much more rigorous privacy and security regulations around the globe such as the European Union’s General [Data Protection](https://www.financedigest.com/modern-data-protection-how-organisations-can-protect-against-cyber-attacks.html "Modern Data Protection: How organisations can protect against cyber attacks") Regulation (GDPR) and the California Consumer Privacy Act (CCPA) in the United States, has created additional regulatory layers for organisations to comply with. While GDPR is not specific to financial [services](https://www.financedigest.com/facilitating-open-finance-through-secure-services.html "Facilitating open finance through secure services"), it has had an enormous impact on this industry.

A common requirement of many regulations is to appoint a [Chief Information Security Officer](https://www.financedigest.com/the-new-role-of-the-cfo-the-de-facto-chief-growth-officer.html "The New Role of the CFO: The De Facto Chief Growth Officer") (CISO), Chief Technical Officer (CTO) or, in the case of GDPR, a Data Protection Officer (DPO). Each of these appointments come with specific obligations these roles [must manage to ensure](https://www.financedigest.com/developmental-best-practices-must-change-to-ensure-the-post-pandemic-recovery-of-financial-services.html "Developmental best practices must change to ensure the post-pandemic recovery of financial services") their organisations stay compliant.

**[Data Privacy](https://www.financedigest.com/how-to-navigate-multiple-data-privacy-regulatory-frameworks.html "How to navigate multiple data privacy regulatory frameworks")**

Many regulations are designed to protect personal [customer data](https://www.financedigest.com/how-payment-institutions-can-leverage-data-to-support-merchant-customers.html "How payment institutions can leverage data to support merchant customers"). The GDPR, for example, places the emphasis on commitment to individuals’ [data privacy by implementing a _Data Protection by Design_ approach](https://www.financedigest.com/how-finance-firms-can-unify-two-data-approaches-to-improve-both-compliance-and-security.html "How finance firms can unify two data approaches to improve both compliance and security"), implying organisations need to build privacy and protection into their products, services, and applications.

Data privacy is also one of the key requirements of the NYDFS regulation which mandates that firms should implement and maintain policies and procedures for the protection of their information [systems](https://www.financedigest.com/health-care-information-systems-market-growth-set-to-surge-significantly-during-2018-2026.html "Health Care Information Systems Market Growth Set to Surge Significantly during 2018 – 2026") and the non-public information stored in them. For MAS-TRM, the protection of customer data, transactions and systems is included in its [risk management](https://www.financedigest.com/treasury-and-risk-management-application-market-to-bring-in-revenue-of-us-7-1-bn-by-2028-comprehensive-research-report-by-fmi.html "Treasury and Risk Management Application Market to bring in revenue of US$ 7.1 Bn by 2028 – Comprehensive Research Report by FMI") principles and best practice standards.

**Full Visibility**

To [protect your assets](https://www.financedigest.com/how-to-best-protect-assets-following-major-global-shifts.html "How to Best Protect Assets Following Major Global Shifts"), first you need to know where your databases are located and what information they contain. Only when you have [full visibility of what regulatory content your databases hold](https://www.financedigest.com/major-myths-and-questions-holding-banking-and-financial-services-back-from-full-digital-id-adoption.html "Major myths and questions holding banking and financial services back from full digital ID adoption") can you conduct an assessment to prioritise and assign a risk profile to datasets.

**Who, What, When and How?**

A recurring requirement of data regulation is that organisations should have visibility of user [access to be able to answer WHO is accessing WHAT data](https://www.financedigest.com/businesses-seek-better-access-to-data-to-support-environmental-objectives-bright-data-research-reveals.html "Businesses seek better access to data to support environmental objectives, Bright Data Research Reveals"), WHEN, and HOW that data is being used. This is certainly true of the GDPR which requires organisations to maintain a [secure environment for data](https://www.financedigest.com/how-financial-services-can-secure-data-and-build-trust-in-todays-modern-environment.html "How financial services can secure data and build trust in today’s modern environment") processing. For MAS-TRM, establishing appropriate security [monitoring systems](https://www.financedigest.com/vehicle-speed-monitoring-system-market-key-players-swot-analysis-key-indicators-and-forecast-to-2026.html "Vehicle Speed Monitoring System Market Key Players, SWOT Analysis, Key Indicators and Forecast to 2026") and processes is outlined as a requirement in the guidelines, “to facilitate prompt detection of unauthorised or malicious activities by internal and external parties.”

**Avoiding Regulatory Penalties**

[Reporting incidents in time](https://www.financedigest.com/credit-suisse-executives-reassure-investors-after-cds-spike-financial-times-reports.html "Credit Suisse executives reassure investors after CDS spike, Financial Times reports") is critical for avoiding regulatory penalties, which can be severe and costly for an organisation, both financially and in terms of reputational damage. However, [security teams are often overwhelmed with large volumes of incident alerts risking a genuine threat](https://www.financedigest.com/how-financial-services-firms-can-mitigate-against-their-top-data-security-threats.html "How Financial Services Firms Can Mitigate Against Their Top Data Security Threats") slipping through the net.

Using advanced [machine learning](https://www.financedigest.com/transforming-insurance-through-artificial-intelligence-and-machine-learning.html "Transforming Insurance Through Artificial Intelligence and Machine Learning") and peer group analysis to distil the number of alerts that bubble to the surface will make it easier to recognise a real breach in time to stop it from accessing internal networks.

Financial [services must](https://www.financedigest.com/as-saas-grows-financial-services-must-rethink-their-security-approach.html "As SaaS grows, financial services must rethink their security approach") adhere to data protection, data discovery, data monitoring and incident reporting as it will allow them to continue to flourish whilst having security at heart.

Government regulation affects the financial [services industries](https://www.financedigest.com/why-sustainability-presents-one-of-the-greatest-opportunities-for-the-financial-services-industry.html "Why sustainability presents one of the greatest opportunities for the Financial Services industry") in a number of ways and each regulation has its own impact dependent on the organisation. Increased privacy and security [regulations](https://www.financedigest.com/uk-finance-regulators-should-pay-heed-to-energy-security-policy-says-sunak.html "UK finance regulators should pay heed to energy security policy, says Sunak") will ensure that security remains vital for businesses and that confidence is maintained throughout the sector, ultimately reducing possible security concerns.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

