Financial compliance infrastructure gains urgency as EU rulebook expands
Kalipso CEO Pierre Ferran says EU rules and AI are pushing banks to embed compliance into daily operating systems.
By Rafael Ortiz · Fintech Correspondent
· 3 min read
Financial compliance infrastructure is becoming a board-level operating issue as EU regulation spreads across technology, product, risk and legal teams, according to Pierre Ferran, chief executive and founder of Kalipso. In an external opinion published by Finextra, Ferran argued that the accumulation of rules has made manual tracking and handoffs too slow for large financial institutions.
Ferran traced the shift to the General Data Protection Regulation, which was adopted in 2016 and took effect in 2018. He said GDPR moved compliance work beyond legal departments because data protection impact assessments, privacy-by-design decisions and records of processing all require input from engineering, product, security and data teams.
The same pattern is now visible across newer European frameworks, he said. The Digital Operational Resilience Act has applied since January 2025 and requires firms to keep a register of information on ICT third-party arrangements, a task involving procurement and IT as well as legal. MiCAR became fully applicable at the end of 2024, while the AI Act is being introduced through deadlines in 2026 and 2027. A new anti-money-laundering package is due in 2027, and PSD3 remains in the legislative process.
Why is financial compliance becoming infrastructure?
Ferran’s central argument is that regulation now has to be built into the systems and workflows that financial firms use every day. Compliance infrastructure means the tools, records and processes that convert legal obligations into assigned controls, product changes and auditable evidence.
The burden, Ferran said, is no longer mainly the interpretation of a single rule. He wrote that financial institutions already employ strong regulatory specialists, but firms active in several jurisdictions must handle thousands of regulatory developments a day across level-one legislation, delegated acts, technical standards and guidance from the European Banking Authority, the European Securities and Markets Authority and the European Insurance and Occupational Pensions Authority.
That volume exposes weaknesses in older operating models, according to Ferran. In his account, a legal summary, spreadsheet update and later working group can leave risk, technology and product teams working from different readings of the same rule. The delay arises between identifying a legal obligation and turning it into an operational control with clear ownership and evidence.
Ferran compared the change to the earlier move in security, where reviews shifted from late-stage checks to continuous involvement during product development. He said internal audit also needs a record that links later control changes to the specific rule that caused them, including the obligation behind a decision made years earlier.
How does AI fit into regulatory compliance?
Ferran said artificial intelligence is likely to speed up the compliance process, but should not replace accountable legal and compliance judgment. He identified potential uses in reading new guidance, comparing it with internal policies, flagging affected products and processes, producing a common obligation list for multiple teams and drafting policy or control updates.
He also warned that AI recommendations in financial services must be explainable and traceable to the relevant regulatory text, down to article and paragraph level. Systems that cannot show how they reached an answer would face problems in an audit or supervisory review, he said, adding that some compliance steps require deterministic rules rather than generative output.
Ferran said institutions should judge compliance spending partly by operational efficiency, including how quickly a firm can identify applicable obligations, affected products and action owners after a new text appears. In his view, firms with integrated legal, risk, technology and compliance functions will be better placed than those relying mainly on larger compliance teams.
This story draws on original reporting from Finextra Research.