IBS Intelligence Global FinTech Interviews
Go one-on-one with the innovators, disruptors, leaders, and decision-makers driving change in FinTech and financial services. IBS Intelligence delivers exclusive global interviews that uncover strategies, challenges, and the ideas powering the next wave of financial technology.
IBS Intelligence Global FinTech Interviews
EP1032: Channel bans at a four-year high
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Rob Mason, Director, Regulatory Intelligence, Global Relay
Financial services providers have been reassessing their communications compliance strategies, according to a recent report by Global Relay. The report found that 66% of financial services firms now ban communications channels – the highest percentage in the annual survey’s four-year history and a significant jump from 2025 when the figure was 41%. At the same time, AI adoption continues to accelerate with 54% of firms not currently using AI for compliance or surveillance planning to introduce it within the next 12 months. Robin Amlôt of IBS Intelligence speaks to Rob Mason of Global Relay.
I'm Robin Amler of IBS Intelligence. You're listening to the IBSI Views podcast. With me is Rob Mason, Director of Regulatory Intelligence at Global Relay, which recently put out a report saying that 66% of financial services firms now ban communications channels. Why are channels being banned, Rob? What's going on here?
SPEAKER_00So thanks very much, Robin. Lovely to be here. Just to start by saying that financially regulated firms have a reg requirement to deliver and keep relevant records for respective communications to monitor them against a number of risks, and primarily that's around market abuse. So things like insider dealing, where they relate to orders and trades in a regulated asset class. And what we saw is the US take a very strong regulatory view on those record keeping requirements, especially around some particular channels, WhatsApp being one that was named quite frequently with massive fines across the industry because some channels were not captured. So those communication channels were required to be prohibited. And in some degree, that had always happened, and firms maintain a list of approved channels which are recorded and captured for compliance. However, prohibition clearly doesn't work as a risk management strategy. So the expectation is that firms need to do more. So as a vendor, for example, that we work for at Global Relay, we've developed solutions that can enable some of those more esoteric communications channel communication channels to be used. And we feel we enable firms to operate more widely and do so compliantly. Banning of those channels is still in play at some firms, but there's a much clearer understanding of the risks, unsurprisingly, when you consider $3 billion worth of fines across the industry. So that has the uh habit of focusing the mind a little bit. And we've seen a lot of enhanced focus and attention in this space as a result.
SPEAKER_01You mentioned WhatsApp. How are you going to know if I'm on WhatsApp?
SPEAKER_00So it's a it's a great question. I think it's more really to make sure that everybody understands the consequences of their actions. So, generally speaking, and in the early stages of when this was beginning to unravel and the SEC, the Securities Exchange Commission in the US took a fairly dim view of this, some firms decided to try and recoup some of the fines that were being levied against them by making people personally liable and they were essentially sort of docking bonuses or wages as a consequence. So, what that is, is if your client or the person on the end of the phone who wants to deal with you chooses to use WhatsApp, it's the responsibility of the employee at the organization to say, no, I can't do business on this particular channel and give you an alternative, or make efforts to be able to record or capture that so that it can be fed into the respective systems for compliance. Now, that's not to say that you can jump out of the office and have a WhatsApp conversation on the side without anybody knowing, and I think that's a prevailing risk that everybody's aware of and has been in the course of history, particularly around things like insider dealing, where obviously dissemination or or spreading of information is key. You can't manage that. But from a firm perspective, you need to be able to do everything in your power to be able to train and make sure everyone else is aware what is permitted and what sits within the rules and regulations of the business that they're undertaking.
SPEAKER_01This is about governance, it's about compliance. But there is an issue of, I understand, regional differences in the way that this is actually handled. It's different in North America to the way it's handled in Europe, to the way it's handled in Asia. Do we need glob your global relay? Do we need global solutions?
SPEAKER_00Yes, it's an interesting one. I mean, uh the bigger institutions have a generally adopt a global minimum standard, and what they take is the most sort of strict regulation and try and adopt that. And if they don't do that and they have regional regulations, then it forms some cracks and things tend to fall down those cracks. I spent seven years working at a big Swiss investment bank as the head of their monitoring and surveillance piece, and we decided to go down the path of how of having a global minimum standard across the board. Now that might have exceeded some of the local regulations in some of the jurisdictions in which we operated, but we felt much more comfortable in adopting that and a consistent line. And I think consistency is the key. Now, with regards to North America, yeah, I mean, interestingly, they themselves probably were the subject of the majority of the regul of the regulators, the SEC's focus. So consequently, those punitive fines meant that they've sort of taken probably the most radical action to make sure that they don't suffer the same fate in future.
SPEAKER_01Once bitten twice shy, perhaps.
SPEAKER_00Yeah, absolutely. I mean, as I said, uh across a period of about three years, I think it kind of the total's a bit variable, but across industry and across firm, not a single firm, but across all of the firms which the SEC captured, it was something in the vicinity of three billion with a B billion dollar fines. So you can imagine that there was a fairly sort of significant ripple in the pool with regards to those folks that were paying those fines and making sure everybody knew that that wasn't going to happen again.
SPEAKER_01Now there's a balance, or if not balance, a pendulum between monitoring and surveillance on one side and an outright ban on the other. Where should we be? What what works? What what's going to be most effective?
SPEAKER_00Yeah, I as I said at the top, you know, there's always been this list of communication channels which are approved and some which are not approved. So the non-approved ones are essentially prohibited from use. But clearly that doesn't work. That's merely a prohibition, but it's not a risk management solution. So what was required is that yes, you do need to have that list. And despite the fact that more channels are being enabled because of some of the vendor work around this and making sure that business can be enabled across a wider variety of channels, there is nevertheless an implicit requirement for the regulated community to do more than that. So what we've seen is some banks and brokers, particularly the bigger ones where the larger risks prevail, they might themselves send like a phishing message, like you would in your email, but maybe a text message on WhatsApp, just to test to see if any individual picks that up and then doesn't report it or doesn't appropriately deal with that and suggest that there may be some business there. So we've seen a different some different methodologies, but it's more about banning is appropriate, but it shouldn't be in isolation because it doesn't manage the risk, it just tells you what the rules are.
SPEAKER_01It's a dynamic situation that is continually evolving, not least, and we haven't mentioned this yet, and I'm going to bring it into the conversation, artificial intelligence. Because there's a whole other set of issues there about what AIs get up to and what agents get up to on their own.
SPEAKER_00So I I mean, good time to mention this, and you know, very much worth talking about this. I mean, some positives first, perhaps. So the way that banks and brokers and the regulated community manage this risk in terms of identifying some issues that might be in a communication, um, historically has been performed using lexicons, and these are effectively word lists. So when that word that was deemed suspicious crops up in an email exactly, it would flag for investigation of an analyst. Now, that's a pretty blunt instrument, and this has resulted in a huge amount of what they describe as false positives and rarely any real risk detected. And AI has completely changed this. So the way that the AI has leveraged is it will review a communication in that in totality and it will consider whether there's been reasonable grounds for suspicion and flag that accordingly, and it does so incredibly effectively. This has resulted in massive reduction in those in those false positives, but also a huge uptick in the number of truly suspicious communications. Now, some of the issues that the the big institutions in particular are facing is that people are using um large language models like Copilot and ChatGPT and Claude in their everyday work. And what are the regulations or rules around that and how can they maintain some guidelines is very difficult. As ever, there'll be lots of governance around that, so there's lots of good advice. But what we've suggested that we can we can help them with is we provide um a uh a communication ability to be able to capture anything that's fed into one of those types of of um large language models. So we call it a connector, and what that does is that collects all the information that may be pushed into a chat GPT. Now you may or not want to monitor that, but what you can do then is if you have another suspicion, you can look to see what potentially an employee has put in there. And it might be something very, very um innocuous, like could you redraft this email in a certain style or with bullets? But it might be something that's got sensitive data or client-identifying data or something in it, which a bank and broker is not going to want to share with a wider audience. And by putting it into one of those large language models, it's very difficult to know how restricted that information is or whether it's open source for anybody to have a look at.
SPEAKER_01If you put it into an LLM, I would argue that you're basically publishing.
SPEAKER_00Well, this is the problem, and I think the banks share this view. And whilst you know you can have some lots of training and lots of guidance, similarly, you can't account for what an employee might do. And generally, it might not even be malicious, but it might be just ignorance that someone pops something in there because they're not quite sure of a question, and with it they share some sensitive information that could therefore be accessed by another. I guess probably it's more of a sort of a CISO, like a cyber security type problem, rather than anything from a market abuse perspective. But nevertheless, the banks and brokers take this very seriously because all of that data is super sensitive or a significant amount of it.
SPEAKER_01So just to round up, what's global relay itself doing? What do you have on offer? How do you solve this problem for people?
SPEAKER_00Yeah, so I think for our initial use case, we're a record keeping and um a surveillance, monitoring, and surveillance of communications solutions vendor. We've got a huge number of clients signing in the region of excess of 10,000 clients, been operating in the business for 25 years. So we know what we're doing here. And the way that we're identifying some of the risks that might be prevailing is a different way to most of our competitors, and it is leveraging large language models. Now there's some very, very clever stuff around things like risk identification, but also translation and transcription. So pretty much translation of any language, and therefore that brings also into uh transcription of any voice communication, and this is a huge improvement from what was previously on offer and allows voice communications to also be incorporated into a monitoring program for capture. Um what we're seeing is an enormous appetite for this to be undertaken because I think, as I said, that the previous system was relatively ineffective, and we're seeing a lot of the institutions across the board, all regulated asset classes, all regulated types, shapes and sizes in financial services, looking to come and have a conversation about this latest technology. And interestingly, too, even the regulators want to come and have a chat with us to understand what it's on offer so that they can look at their regulated community to ensure that they're keeping up with managing the risks in the best way that they can.