Banks face rising control costs with no defensible reason

banks

Ask a bank how many controls it operates and a confident answer is rare. Ask how many it actually needs, and which ones, and the silence is telling.

According to Corlytics, most large institutions run control estates numbering in the thousands, accumulated organically over decades: one regulation, one audit finding, one remediation at a time.

A significant share are not genuine controls at all, but reports, processes, statements or policies masquerading as such. Each one costs money to run, test and monitor.

Control proliferation is not new. Estates have swelled since the Subprime Crisis, but the traditional fixes, consultants and in-house programmes, no longer suffice. New players such as FinTechs and data providers, amplified risks including AI, an increasingly interconnected market and heightened regulatory expectations have outpaced them.

The pain points are well known. Traceability to control requirements is rarely system-based, is often achieved manually and is difficult to maintain. Controls data is inconsistent and subjective, with 30-40% of inventories frequently comprising non-controls. And estates are reactive by design: new regulation or policy requirements do not update inventories in real time, leaving institutions perpetually looking in the rear-view mirror.

The structural consequences are serious. Risk exposure is often unknown, unquantified and addressed only after the fact. Growth suffers as business velocity slows and time-to-compliance stretches. Manual, fragmented processes drive up operating costs and create opportunity costs besides.

The idea worth taking seriously is a barcode for controls: a machine-readable identity for each control, built not from a reference number but from the underlying requirements it exists to satisfy, both external regulatory obligations and internal policies, procedures and processes.

That shift changes what is possible. Compression comes immediately, as duplication stops being an opinion and becomes a query, cutting cost-of-control. Impostors surface, since a “control” mapping to no requirement is not a control, flushing reports and monitoring out of the estate so testing effort goes where it genuinely reduces risk.

Descriptions improve through advanced AI engines, as vague statements such as “Management reviews access periodically” cannot survive contact with a specific procedure clause. And completeness becomes something firms evidence rather than assert, with every requirement codified and mapped.

The usual trade-off, where completeness inflates the estate while cost discipline risks gaps, collapses under a requirement-first methodology. Institutions cover what they must, once, described precisely enough to test, with a defensible line back to source for regulators.

The prize is not a tidier inventory but fewer controls doing more, provably, with a gatekeeper architecture safeguarding quality. Controls become an asset supporting growth, for instance by reducing time to trade when entering new products or markets, because needs and gaps are clear before trading begins.

The full Corlytics post is here. 

Read the daily FinTech news

Copyright © 2026 FinTech Global

Enjoying the stories?

Subscribe to our daily FinTech newsletter and get the latest industry news & research

Investors

The following investor(s) were tagged in this article.