Site icon Finance Derivative

Control, compliance and communication: the overlooked governance gap in financial services

By Karl Bagci, Director of IT and Information Security at Exclaimer

Financial institutions are built for control. Nobody in the sector needs reminding that governance, risk and continuity are core disciplines: they are capabilities banks, insurers and market infrastructure providers have spent decades refining to keep capital, conduct and compliance in line.

What has changed is the context those disciplines have operate in. We’re all grappling with more digital, interconnected and third-party driven operating models, alongside customers who expect zero interruption and regulators who want hard evidence that resilience holds under cyber, supplier and AI-related stress.  By 2026, operational resilience is being tested less by one-off outages and more by the day-to-day realities of how modern financial institutions actually run.

That’s why the conversation has to move beyond the most obvious systems. Core banking platforms, payment infrastructure and cloud environments will always be in the spotlight, but the weak points are just as likely to sit in the layers around them: the tools, processes and everyday communications that keep regulated business moving, but are still not always treated as critical resilience assets. 

Outbound communication is one of those layers

Email remains deeply embedded in financial services, underpinning everything from client servicing and legal notices to investor communications and regulated disclosures. In Exclaimer’s State of Business Email which draws on responses from IT leaders across industries and geographies, found that 89% of IT leaders in finance say email will remain a primary communication tool for businesses in the next five years, and that almost half of global IT leaders (48%) say the majority of their internal and external communication still relies on direct email – more than any other channel – with usage highest in complex, regulated environments where records and accountability are critical.

The same research shows how central this is for finance specifically. When IT leaders were asked which teams rely most heavily on email communication, they pointed to IT (56%), HR and internal comms (37%), customer success (31%) and finance (31%). In other words, finance functions sit firmly among the most email-dependent parts of the organisation – exactly where operational risk, regulatory pressure and reputational scrutiny are most acute.

It is also one of the most consistent points where governance intersects with everyday behaviour. Yet while firms have strengthened the controls around access, infrastructure and security, enforcement over outbound communication is often less centralised or consistently enforced.

That gap is easy to underestimate because it rarely looks like a major incident at first. A missing disclaimer, inconsistent legal entity reference or unmanaged signature does not resemble a systems outage. But across thousands of interactions, these inconsistencies become evidence of a broader problem: policy may exist centrally, but execution is still dispersed.

For compliance leaders, this distinction matters. Regulators want to see whether firms can demonstrate consistency in practice, not describe it in documentation. DORA, UK resilience rules and third-party risk expectations all point in the same direction: firms need to understand dependencies, govern them properly and prove resilience works across the operational chain. That creates a more nuanced challenge for the traditional build-for-control mindset.

Ownership is not the same as resilience

Exclaimer’s Build vs Buy research found that 71% of in-house IT builds are eventually abandoned, rising to 83% in heavily regulated sectors such as finance and manufacturing. Only a small minority finish on time or on budget, while many require ongoing maintenance that pulls skilled compliance, security and technology teams away from higher-value resilience work.

The issue is not internal development itself; financial institutions will always need engineering capability. The risk lies in using scarce capacity to maintain non-differentiating internal tools simply because “we built it ourselves” feels like control. That can become control theatre: visible ownership without durable governance.

True discipline is different. It means the firm can set policy, enforce it consistently, monitor exceptions, evidence compliance and adapt quickly when regulation, risk or business structure changes. Sometimes that will be achieved through internal systems. Increasingly, for operational processes that require scale and consistency rather than competitive uniqueness, it may be better achieved through specialist platforms with clear assurance, auditability and governance.

Communication governance is a useful example because it sits at the visible edge of the institution. It is where employees, clients, counterparties and regulators encounter the organisation in motion. If disclaimers, legal notices and identity details are still managed manually, or inconsistently across entities and devices, then the firm has accepted a level of operational variance that modern resilience programmes should be working to reduce.

AI will make this more urgent

As financial institutions embed AI and automation more deeply into customer communications, internal workflows and decision-making, communication volumes will scale faster, governance timelines will compress and policy-execution gaps may widen significantly. The issue is not simply that firms will communicate more, but that they will need to govern a far greater volume of increasingly dynamic outputs with far less tolerance for inconsistency. In that environment, manual governance models are likely to become progressively less viable, making automated, policy-driven control far more central to operational resilience.

The firms that navigate this best will not be those that build everything, or those that outsource indiscriminately. They will be the ones that are most honest about where resilience is actually strengthened, particularly as AI and automation add new layers of complexity. They will reserve internal talent for the capabilities that differentiate the institution, while using governed specialist providers where consistency, resilience and compliance can be delivered at scale.

Exit mobile version