Compliance

Compliance & Regulatory by Design

Intermediate

Compliance is not paperwork wrapped around the product. It is something the product must prove, on demand, with evidence. In a regulated AML business, the question is never "are we compliant?" in general. It is "can we prove it for this specific decision, on this date, to this regulator?" Build so the answer is always yes.

Designing for compliance means the controls a regulation requires are enforced in code, and the evidence it requires is produced automatically. It is not rebuilt under a deadline when an auditor asks. When teams add compliance late, they discover the log they needed was never written, the consent was never recorded, or the decision cannot be explained.

Our obligations are concrete and overlap: AML/KYC rules, GDPR (including special-category biometric data), data residency, and, for automated risk decisions, the EU AI Act. Each one sets controls and evidence requirements. The cheapest way to meet them is to make the compliant path the default path.

Build the controls in

Produce evidence automatically

Self-review checklist

Why it matters: Regulators do not accept good intentions. They require controls they can see and evidence created at the time, and the penalties for failing include fines, loss of licence, and personal liability. Compliance designed in is invisible and cheap. Compliance rebuilt under an audit deadline is expensive, stressful, and often impossible.