A subtle but significant change is reshaping how regulated firms and their supervisors interact, and many risk and compliance teams have yet to fully absorb its implications.
According to Sherlocq, for around 20 years, supervisory oversight followed a predictable pattern. Firms controlled the data, and when regulators requested information, firms decided how it was packaged, submitted and explained.
Supervisors relied heavily on whatever firms chose to share, and experienced compliance professionals knew that inspection readiness was as much about presentation as substance.
That model is now unravelling. Supervisors can analyse board minutes, management reports, policies, procedures and large data sets with unprecedented speed. They can summarise complex policies, test them against regulatory requirements and interrogate vast volumes of data. Work that once took weeks to produce initial findings can now be completed on the first day of an inspection.
Regulators across financial stability, data protection, consumer markets and other areas have invested heavily in data infrastructure. The UK’s Financial Conduct Authority has expanded its data science capability to track transaction patterns, identify outliers and model firm behaviour at scale.
The European Central Bank’s supervisory arm deploys automated tools to cross-check disclosures for inconsistencies. In the US, the SEC’s enforcement division increasingly uses analytics to spot potential misconduct before formal investigations begin, while every regulator in the UAE is developing SupTech capabilities, often incorporating artificial intelligence.
The upshot is that supervisors increasingly enter conversations with a view already formed, built on what the data revealed independently. A regulator may know that complaints rose months before a firm raised a product issue, or that its conduct metrics place it well outside peer norms.
Meanwhile, many compliance teams still rely on the spreadsheets and manual attestations they used five years ago.
This imbalance creates clear risks. Inspection surprises are now a real danger, and the gap between what a regulator knows and what a firm knows is itself a finding about risk management maturity.
Regulatory dialogue has also shifted, with supervisors focused on reconciling explanations against patterns they have already identified. Firms arriving with high-level summaries rather than granular insight can lose credibility quickly. Enforcement timelines are also shortening, narrowing the window for self-correction.
The response starts with honest self-assessment, seeing the business as a supervisor would and benchmarking policies against current expectations. Risk and compliance functions need closer ties with data and technology teams, as treating these as separate disciplines creates structural weakness. Candour should replace narrative management, since analytically capable regulators readily detect inconsistency. Horizon-scanning across jurisdictions is also essential, as what regulators cannot see today they may well see within a year.
Ultimately, this is less a technology story than a question of who holds the better information. For the first time in a generation, it may be the regulator.
Bryan Stirewalt, Former Chief Executive, DFSA; Strategic Advisor, Sherlocq, said, “Supervisors have always known more than firms assumed. What has changed is the scale and speed of that advantage. Regulators are no longer dependent on what firms choose to surface. They are building the picture themselves, and firms that have not grasped that shift are walking into supervisory conversations already behind.”
Bhavin Shah, Founder and CEO, Sherlocq, added, “The compliance function was built for a world where firms held the data advantage. That world no longer exists. Sherlocq exists precisely for this moment: to give compliance teams the same quality of regulatory intelligence their supervisors are already working with.”
Read the full Sherlocq post here.
By Daniel Willis, Editor of RegTech Analyst
Copyright © 2026 FinTech Global



