ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Compliance and Risk

Controlling risk and compliance: It takes a system

June 30, 2022
Reading Time: 6 mins read
Controlling risk and compliance: It takes a system

By Ben Harrison and Nigel Riley

While financial services firms have spent significant resources to knit together systems that allow them to aggregate financial risks such as credit, counterparty and market risk, they have sometimes neglected the systems to manage the tremendous compliance obligations from other forms of non-financial risk. For instance, investment banks and private equity firms who manage deals typically have decentralized and siloed information. These siloed organizations have yet to find a meaningful way to manage conflicts of interest, which sit at the crux of non-financial risks and control.

Financial services companies need a system—not just a cohesive organizational infrastructure, but the technology that supports it—before they can adequately manage their tremendous compliance obligations and related areas of non-financial risk. Very often, they have not one technology, but five or more, each supporting a different division or function.

rightwards arrow
View more
risk and compliance articles

Compliance problems are most common among distributed organizations with many pockets of people handling their own clients and deals and running their own strategy, each supported by unique technologies with independent databases. Arranging entrepreneurial silos might be considered an organizing system that breeds success in dealmaking. Unfortunately, market forces and stricter regulations increase the need to streamline critical risk-management activities. They can no longer neglect the need to manage compliance risk with a form of central oversight and control – and the need for a central technology to support a consistent and accessible database across deal flow, CRM, staffing, contracts and other activities to manage risk. Finding the balance between individual dealmaking and non-financial risk and compliance management is vital.

As market forces demand more transparent reporting and stricter regulations take hold, many firms are attempting to evolve into more collaborative organizations. Yet industry reports, including a recent study by PwC, acknowledge that many financial services companies maintain compartmentalized or legacy programs even as they invest in new technologies and platforms. That’s a waste of time for deal-oriented due diligence as days tick by. It is also an elephant in the room of compliance risk.

When each system is touching a different part of the proverbial elephant, the risk is that the firm never knows exactly what it is facing, cannot get a sense of its size or weight and certainly never expects a stampede. When multiple systems are active and each owns its own information and exposure, the firm faces significant, and potentially multiple, risks.

Unifying deal, relationship, and compliance records can accelerate conflict review and resolution. Increased collaboration between compliance teams and investment professionals can drive success.

Conflicts or collaboration and compliance

Conflicts of interest stand atop the issues that can be difficult to track and analyze—whether conducting normal diligence or facing a regulatory crisis.

Conflicts are critical to five key areas of risk across any investment bank:

  • Deal-related compliance
  • Personal conflict of interest compliance
  • Material non-public information
  • Obligation, including industry exclusivity or key-person limitations
  • Reputation risk

The need to streamline critical risk-management activities and unify deal, relationships and compliance records may not be clear until organizations need to accelerate a conflict review and resolution. Firms that maintain conflicting databases don’t have an approach to prevent any of these issues. Each might be built on a tech “platform” that supports a single function, perhaps deal-related activities and valuations, CRM for pipelines, financial reporting, or internal accounting.

As noted in a pre-pandemic McKinsey report: “Platforms are distinct units, but their value is based on how effectively they work together. Most companies overlook the criticality of making all IT components work together seamlessly because their attention is focused on individual projects.” It’s reasonable to expect that the increase in remote work has increased the need for a more institutional system of sharing and collaboration.

Examining how that works in times of crisis helps to make the point.

Larger firms are the most visible and often the most vulnerable when crisis strikes. When facing exposure to a company’s collapse, a la Enron, a large investment firm’s own decentralization may lead it to waste time trying to understand its level of involvement, type of risk and total exposure across multiple business units. Such delays in reporting or repeated corrections have led to re-statements that lose trust and increased challenges by government regulators. These challenges, in turn, might lead to class action suits by investors who see the lack of information as negligence—or simply strain their own investors’ confidence and stock price.

In addition to the web of investments, it is vital to track the vast network of relationships. A large investment firm that empowers its teams to work separately is also likely to have myriad tentacles connecting many of its people in the organization to a single executive or company in crisis. It takes time to confirm if the rogue player is a private equity client. Perhaps the firm has not made a direct investment, but what if a board member’s company works with a client of the company in trouble? What if directors are on multiple boards? Is the troubled company one that a managing partner has been prospecting? Even worse, is that rogue player you just met with accused of insider trading?

Compliance is data managed well

The problem for compliance is not in the lack of data and information within the firm. The problem is taking too long to use it. One the one hand, a study by Thomson Reuters suggests that compliance teams are spending one to three hours tracking and analyzing regulatory developments, which they credit to better technologies and databases.

On the other hand, that tracking is often limited to the question of new regulations. When it comes to deal compliance, it can take days to find and reach all professionals who may work with the company, check each of their different data systems, identify all contractual promises of exclusivity and address key-person obligations if one person becomes key to several deals. The firm might never compare reputational exposure to the compliance database or perhaps the billing system and staffing records. It might be difficult to reconcile potentially conflicting dates and other pertinent information. Even more, for full compliance, a firm may need to rectify or justify different compliance parameters across divisions in a decentralized, transaction-oriented company to auditors.

Most of these risks can be managed by streamlining the process and having a single source from which to access all prospects, active deals, entities on watchlists, the network of professional relationships and histories of different business divisions and functions.

Unfortunately, despite massive industry expansion, rudimentary operating systems are not keeping up with increased examination by regulators. Even in more centralized data systems, limited functionality demands hours and expertise to mentally analyze the pros/cons and potential conflicts and liabilities inherent in a deal, a relationship or an employee.

Risk is contagious

We have seen how the effect of mismatched systems clashes with an environment of increasing regulations and causes delays in recognizing firmwide and personal conflicts of interest. It also weakens the ability of conflict and compliance teams to manage other risks.

Most directly, a lack of a unified system can obfuscate each contracted key-person obligation, making exclusive relationships harder to consider and the sudden loss of a key person harder to manage.

Reputational risk management is also challenging organizations as criminal behavior grabs headlines and stirs public fury, or as activist investors with ESG parameters demand clear social policies. The autumn 2021 DealCloud Pulse survey of investment bankers found that 87 percent would not invest in companies or sectors that could have a negative impact on their reputation regardless of potential returns.

While many firms are instituting new policies to meet regulatory or reputational risk issues, any new firmwide policy proposals should be checked throughout a system to measure their impact, and then tracked for compliance across all records. Even firms with a clear hands-off policy for certain industries can face complications when, for example, a joint-venture participant or investment target has its own exposure to that industry. Compliance teams will need to follow what bankers and their teams are working on and what’s been approved or declined—all with an internal audit trail that will highlight issues and resolve them as quickly as possible. Or, as called for in a recent KPMG report, every employee needs to take responsibility for risk management supported by a “robust governance, risk and compliance program.”

A culture of collaboration around compliance and risk can be reinforced when bankers focus on reducing opportunity risk. Once on board with a single system, many bankers have found that efficiency reduces deal risk in several ways. They save time developing the pipeline, target deals with the deepest relationships, and leverage active business in other parts of the organization.

Without collaboration between compliance teams and investment professionals—without databases that house all geographies and business divisions—banking teams waste precious time that may result in potential deals slipping away. Many tell stories about feeling like they were led down a garden path on too many deals before conflicts and other compliance issues were uncovered. Once they have the right system, all teams appreciate saving time rather than wasting it in a bottleneck of diligence.

Ben Harrison is president of financial services and Nigel Riley is general manager for risk and compliance at Intapp.

Tags: DataEnterprise risk managementThird-party risk
ShareTweetPin

Related Posts

Banking agencies pledge more scrutiny of core provider business practices

Banking agencies pledge more scrutiny of core provider business practices

Compliance and Risk
September 11, 2026

The federal banking agencies pledged to step up oversight of third-party core providers whose business practices “unreasonably limit” community banks from conducting due diligence or from negotiating contract terms that address the banks’ business needs.

CISA releases updated guide on insider threats

CISA releases updated guide on insider threats

Compliance and Risk
September 11, 2026

The guide gives organizations a current look at insider threats and practical steps to develop or enhance an insider threat program, according to CISA.

Podcast: Remembering 9/11, a quarter century later

Podcast: Remembering 9/11, a quarter century later

ABA Banking Journal Podcast
September 10, 2026

Conversations with two financial industry professionals help illuminate the impact 9/11 had on bankers, the financial system and the whole nation.

FBI publishes first cyber strategy roadmap

FBI publishes first cyber strategy roadmap

Compliance and Risk
September 10, 2026

The FBI released its first “cyber strategy” that outlines the law enforcement agency’s priorities in combating cybercrime and protecting critical infrastructure.

FinCEN releases financial trend analysis on health care fraud

FinCEN releases financial trend analysis on health care fraud

Compliance and Risk
September 10, 2026

Financial institutions flagged approximately $17.5 billion in suspicious activity related to potential health care fraud during a one-year period starting in 2025, according to a financial trend analysis released by FinCEN.

ABA to FCC: Protect critical calls to bank customers

FCC releases draft order to protect fraud alerts

Compliance and Risk
September 9, 2026

The Federal Communications Commission released a draft order that would rewrite the agency’s “revoke all” rule – an action that ABA has long advocated. The FCC will vote on the draft order at its Sept. 30 open meeting.

NEWSBYTES

Banking agencies pledge more scrutiny of core provider business practices

September 11, 2026

Preliminary: Consumer sentiment decreased 3.9 points in September

September 11, 2026

ABA DataBank: The ‘she-conomy’ drives job growth

September 11, 2026

SPONSORED CONTENT

Banking Technology at a Strategic Crossroads

Banking Technology at a Strategic Crossroads

September 8, 2026
Taming AI Agent Sprawl: A Playbook for Consumer Lending

Taming AI Agent Sprawl: A Playbook for Consumer Lending

September 1, 2026
Grow Public Deposits Without the Operational Burden End Fragment

Grow Public Deposits Without the Operational Burden End Fragment

September 1, 2026
Could Your Bank Absorb the Hidden Cost of Running Legacy Systems?

Could Your Bank Absorb the Hidden Cost of Running Legacy Systems?

August 20, 2026

PODCASTS

Podcast: Remembering 9/11, a quarter century later

September 10, 2026

Podcast: Banking the brave new world of college athletics

August 4, 2026

Podcast: Tactics for meaningful strategic planning

July 28, 2026

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2026 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2026 American Bankers Association. All rights reserved.