When your regulator starts asking about your technology

For a long time, regulators cared about your numbers, your conduct and your processes — and technology was assumed to be working in the background. That has changed. Across regulated sectors, regulators now ask about technology directly: how you manage it, how secure it is, how resilient you are, where your data lives. When your regulator starts asking these questions, it is a signal that technology has become part of how you are judged — and being unable to answer well is now a compliance risk in itself.

Why regulators now look at technology

The reason is simple: technology has become central to how regulated businesses operate and where they fail. Outages, breaches and data losses now cause the kind of harm regulators exist to prevent, so they have extended their scrutiny to the systems underneath the business. In financial services this is now explicit and formalised — the operational-resilience regime of DORA requires firms to manage technology risk, test their resilience, and account for their critical third parties. Other sectors are moving the same way. The expectation is no longer that technology quietly works; it is that you can demonstrate you are managing it.

What they expect to see

Regulatory technology questions cluster around a few themes. Governance: that someone owns technology risk and decisions are made deliberately, not informally. Security: that you protect data and systems with appropriate, evidenced controls. Resilience: that you could keep operating, or recover quickly, if something went wrong. Data: that you know what data you hold and where it lives — the question explored in your regulator asked where your data lives. And third parties: that you understand and manage your dependence on the vendors and services you rely on. Underlying all of them is a demand for evidence — not assurances, but the ability to show your working.

Free · 4 minutes

Do you know where AI is already being used in your business — and what it can see?

Fourteen questions on shadow AI, data exposure, oversight, and governance debt — the gap between how fast AI is arriving and how much control you have over it. Banded finding on screen, full sheet by email.

Why “we’re probably fine” is dangerous

The trap is assuming that because nothing has gone wrong, you are compliant. Regulators increasingly want demonstrable governance — documented ownership, assessed risks, tested resilience — not the mere absence of an incident. A business that has been quietly lucky but cannot evidence how it manages technology risk is exposed the moment it is asked. And “we think it’s handled” is precisely the answer that invites a closer look.

How to respond from a position of control

The right response is to get ahead of the questions rather than scrambling to answer them. Establish who owns technology risk. Assess and document your risks honestly. Make sure you can evidence your security, your resilience and your data position. The work is the same work that makes the technology genuinely safer and better governed — it is not compliance theatre, it is the substance regulators are now checking for. Done in advance, a regulator’s question becomes a confident, evidenced answer rather than a panic. This is also frequently what prompts the related conversation when the board starts asking questions about technology the business cannot yet answer.

When a regulator starts asking about your technology, being unable to answer well is itself the risk. We will get you to a position where the answers are ready and evidenced.

Start a Conversation

Free interactive tool

Website compliance checklist

What your site has to do, based on what it actually does

Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.

Free interactive tool

Interactive deadline calculator

Check which regulations apply to you and when

Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.

Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.

Most technology problems are not technology problems. They are control problems.

The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.

Full Governance by Sixteen Pillars

Govern your business. Prove your compliance.

A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.

See what's coming