Trying to play tennis in a hurricane – that’s the experience of many financial firms as they attempt to navigate the complex and dynamic set of requirements regulating the finance sector.
In February and April of 2024, partners LeapXpert and SteelEye convened roundtable discussions in New York and London, aiming to explore strategies for mastering communication compliance in financial services. These discussions, attended by compliance and surveillance leaders, fostered extensive and insightful dialogues covering topics such as off-channel communications, regulator sentiment, the integration of artificial intelligence (AI), and more.
In this blog post, we highlight the key insights gleaned from these discussions, focusing on the challenges identified by participants and outlining top priorities for the year 2024.
Off-Channel Communications: Privacy concerns, Emerging Channels, and Communications Hopping
The ever-evolving landscape of communication channels poses a persistent challenge for firms striving to maintain compliance and thwart off-channel communications. This challenge is exacerbated by the delicate balance required to monitor communications while respecting employee privacy. Ethical dilemmas loom large, raising questions about the extent to which firms should intervene in their employees’ private interactions. Nevertheless, the consequences of inadequate monitoring can lead to unintentional regulatory violations, prompting many firms to reassess their surveillance protocols.
Compounding these challenges are Bring Your Own Device (BYOD) policies, prompting a shift back to corporate devices to mitigate risks. While this move may alleviate privacy concerns by delineating personal and business communications, it doesn’t eliminate the threat of bad actors exploiting personal devices for illicit activities. To get around this, best practice stipulated monitoring for communications hopping by for example triggering alerts when a trader shares their personal number as part of a conversation or uses language such as “I will message you on WhatsApp”.
Moreover, platforms like WhatsApp and LinkedIn are increasingly utilized for business communications, have prompted a reassessment of which channels should be monitored by compliance. For example, LinkedIn’s dual role as a professional networking tool and personal platform introduces unique complexities. Despite instances where the absence of monitoring on LinkedIn resulted in regulatory breaches, some firms remain hesitant to enforce stringent oversight due to privacy considerations.
Adding to the complexity is the phenomenon of linguistic switching, wherein bad actors evade surveillance by switching language. Traditional surveillance technologies limited to predetermined languages, such as English, are insufficient in detecting these tactics. Hence, there’s a growing emphasis on incorporating multilingual capabilities into communication surveillance processes.
Overall, there is an emphasis on the necessity of proactive measures to effectively manage compliance risks amidst these evolving communication trends.
Harnessing AI/ML
Numerous challenges confronting compliance and surveillance teams stem from manual and repetitive tasks, driving the demand for tools to streamline and automate these aspects of compliance.
Artificial intelligence (AI) and machine learning (ML) technologies have been identified as tools that can help firms achieve this. Overall, there is an acceptance of AI/ML solutions, and many firms are investing in AI for compliance in 2024. In fact, nearly 2-in-3 firms have already implemented some form of AI for compliance.
However, despite the growing acceptance of AI/ML solutions, reservations persist regarding their regulatory acceptance and effectiveness. While most firms recognize the transformative impact of AI/ML in improving compliance processes and detecting regulatory anomalies, concerns linger regarding the necessity for regulatory approval and the ethical implications of automated surveillance.
The Regulatory Landscape: Contrasting Approaches in the US and UK
In the United States, the regulatory environment is characterized by stringent enforcement actions and substantial fines for non-compliance. Regulators adopt a no-nonsense stance on enforcement, emphasizing self-reporting and cooperation from firms. Many financial institutions have undergone regulatory audits and faced enforcement actions, particularly concerning off-channel communications.
While US regulators acknowledge the challenges faced by financial institutions, they expect proactive engagement on off-channel communications. Regulators believe they have provided sufficient time for firms to align their policies with the latest guidance, and those falling short will face accountability. This is evident in the hefty fines exceeding $3 billion imposed for record-keeping failures in recent years.
Conversely, in the UK, interactions with regulators regarding off-channel communications tend to be more positive. UK regulators are perceived as more open to dialogue and cooperation compared to their US counterparts, who are viewed as less sympathetic and more punitive. For instance, the Financial Conduct Authority (FCA) has proactively contacted firms to discuss their plans for monitoring off-channel communications. This sentiment is echoed in SteelEye’s 2024 compliance health check report, indicating that firms find US regulators (FINRA and SEC) more challenging to engage with compared to their UK counterparts.
Regardless of the region, proactive engagement with regulators often leads to constructive dialogue and mutually beneficial outcomes. This underscores the importance of fostering collaborative relationships with regulatory authorities.
Key Takeaways on How to Get Ahead of Off-Channel Communications
The roundtable discussion has highlighted the need for firms to urgently focus on the following issues:
- BYOD (Bring Your Own Device) Policies: Many firms are reevaluating their BYOD policies, considering a shift back to providing corporate devices due to get ahead of off-channel communications.
- Monitor for Communications Hopping: In addition to monitoring corporate devices and communications, firms should set up alerts that trigger when someone shows intent to communications hop. This can be done by setting up triggers for phrases like “I’ll WhatsApp you” or “I’ll text you” or even when someone shares a phone number as part of a conversation.
- Monitoring Emerging Communication Channels: With the proliferation of new communication channels like gaming platforms and LinkedIn, firms need to regularly review their monitoring practices and include new channels.
- Policy Enforcement and Employee Compliance: Merely having policies in place is no longer enough. Firms need to actively enforce policies and address workarounds and ethical gray areas.
- Learning From Regulatory Fines: Firms should analyze enforcement press releases to understand regulatory expectations and avoid similar shortcomings. Self-reporting, cooperation, and remediation are encouraged by regulators and may mitigate penalties.
- Focus on Language Compliance: Firms should ensure language compliance in communication surveillance, including understanding employee language capabilities and monitoring multilingual communication.
- Use of AI: Adoption of AI is inevitable in compliance efforts, and firms should prepare for its integration into their surveillance systems.
- Understand your Technology: Understanding vendor technology and capabilities is crucial for effective compliance, as regulators expect firms to be knowledgeable about the tech they use.
Conclusion
Given these challenges, there is an imperative for financial firms to take proactive measures to stay ahead of regulatory requirements. This proactive approach should involve not only ensuring compliance with existing regulations but also anticipating future regulatory trends and preemptively addressing potential areas of concern.
Firms must conduct regular compliance assessments, staying informed about regulatory updates, and actively engaging with regulators to better understand their expectations.
Collaboration between in-house compliance teams and external technology providers is a critical factor in navigating the complexities of financial regulation. Firms must focus working with their technology vendors to develop tailored solutions that address specific compliance needs and ensuring that they are fully aware of how those technologies are implemented and work. Demonstrating to regulators that you have a thorough understanding of the technology you are using sends a powerful signal that you are in control and take your compliance requirements seriously.
LeapXpert and SteelEye: Your Partners in Compliance
It is increasingly clear that a comprehensive communications solution is needed—one that not only addresses current compliance concerns but also anticipates future regulatory requirements and technological advancements.
The LeapXpert Communications Platform ensures compliance across all channels, providing real-time monitoring capabilities to mitigate risks effectively. With LeapXpert, firms can bring off-channel communications into the regulatory fold, making sure they are carefully monitored.
SteelEye’s fully integrated communication and trade surveillance platform empowers financial firms to proactively manage their compliance obligations, leveraging AI/ML technologies to detect anomalies, automating surveillance tasks, and staying ahead of regulatory changes. By harnessing the power of SteelEye’s comprehensive solution, firms can strengthen their compliance posture, minimize regulatory exposure, and drive business growth.
The LeapXpert and SteelEye partnership provides a comprehensive approach to communications compliance and allows financial firms to benefit from both cutting-edge solutions, seamlessly. By providing a unified solution, firms are empowered to navigate the complexities of regulatory compliance with confidence and resilience.
Reach out to SteelEye and LeapXpert today to learn more
Book a personalized
product demo