Regulation and Regulators
Regulation
This section provides some background on regulation to help explain the approach CUBE has taken to reg mapping.
What a regulation is?
Regulation is the application of law by government to address market failures and to protect society from various harms. Regulation can be both prohibitive -- preventing firms from doing something -- and facilitative -- permitting firms to do something.
The financial system is now heavily regulated as a reaction to endogenous risks that have materialised over time during various financial crises as well as exogenous risks such as the emergence of new technologies, geo-political issues and other external shocks. Endogenous risks include the inherent fragility of banks maturity transformation role that they play in the economy and regulation is needed to ensure they remain solvent and manage credit, market and liquidity risk appropriately. Other problems also occur in financial markets, where issues such as information asymmetry and principal-agent relationships can result in misconduct. The financial system is also open to abuse by criminals in the form of money laundering, terrorist financing and fraud.
The emergence of new technologies and products such as AI and digital assets result in new risks that need to be managed. Exogenous shocks such as the Covid-19 pandemic and conflicts such as the Russian invasion of the Ukraine can also result in regulatory intervention.
Financial regulation, therefore, aims to address these various types of risk as well as facilitating the fair and efficient functioning of financial markets. Table 2.1 shows the different types of regulation and gives examples of each. Please note, not all regulations issued by financial regulators fit neatly into these four categories. Examples are cybersecurity regulation, operational resilience, data privacy and protection and ESG regulation.
Table 2.1 Types of Financial Regulations
| Type of Regulation | Objective | Example |
|---|---|---|
| Prudential regulation | Maintain the safety and soundness of individual financial institutions and the financial system as a whole by managing systemic risk through the application of liquidity and capital adequacy standards | EU Capital Requirements Regulation III and Capital Requirements Directive VI |
| Financial Markets Conduct Regulation | Protect consumers and investors and ensure fair and transparent markets | SEC Title 17, Chapter II, 240.14e-3, Prevention of Misuse of Material, Non-public Information |
| Financial Market Infrastructure Regulation | Ensure the safety and efficiency of key market infrastructure players such as clearing, settlement and payment arrangements | EU Market Infrastructure Regulation (EMIR) |
| Anti-money laundering regulation | Protect the financial systems from the threats of money laundering and the financing of terrorism and proliferation | US Bank Secrecy Act (BSA) 1970 |
| Other | Management of other types of risks e.g. system failure, information security, ESG | EU Digital Operational Resilience Act |
It is helpful to think of financial regulation in terms of risk management. Regulators will consider the risks to the overall stability, safety and soundness of the financial system and implement regulations to manage these risks. In some cases, regulation will align with risks that financial institutions would already be managing (e.g. market risk, credit risk) but in other cases, may impose a burden of risk management where firms may not necessarily consider it necessary, such as in the case of anti-money laundering.
It should be noted that being a regulated firm necessarily involves the management of a specific type of risk -- regulatory risk. This is the risk of non-compliance with regulation, failure to remediate known compliance issues or failing to respond to regulatory changes. Non-compliance can result in sanctions which negatively impact the financial institution, both financially and reputationally.
Aspects of regulatory process
There are three key interconnected processes involved in regulation as shown in Figure 2.1 -- standard setting, monitoring and enforcement.
Figure 2.1 The Regulatory Process

Standard setting
The first step in the regulatory process is the setting of standards -- essentially the rules which regulated firms must follow to be compliant. In the world of financial regulation, standards are often first established at an international level by bodies such as the Basel Commission on Banking Supervision (BCBS), the International Organisation of Securities Commissioners (IOSCO) and the Financial Action Taskforce (FATF).
These international standards are not legally binding, so national (and regional in the case of the EU) governments need to pass legislation to implement them in their countries and may choose to modify the standards to suit the risks and context of their own jurisdiction. In some cases, elements of rulemaking are also delegated to national financial regulators.
In addition to standards set at an international level, country-specific regulation may be developed -- an example of this would be accountability regimes such as the UK's Senior Managers and Certification Regime (SMCR).
Within national regulators, the policy teams are generally responsible for the revision of existing standards and the development of new ones through liaison with both national legislatures and international standard setters.
Monitoring
Once standards have been established, financial regulators need to monitor compliance with these standards on an ongoing basis. This is generally the responsibility of the supervisory arm of the national financial regulators. Each will use slightly different approaches and techniques ranging from regular meetings, on-site inspections through to the analysis of data submitted on both a standardised, regular basis and in response to specific ad hoc information requests.
In the UK, for example, the Financial Conduct Authority (FCA) and Prudential Regulation Authority (PRA) both have supervisory principles which are 'forward-looking' and focused on the key risks that firms pose based on their business model and conduct. These supervisors will devote more resources to larger firms or those that they consider pose a bigger risk of causing harm and will therefore engage more frequently with these firms.
In the US, supervision can look very different. For example, the Securities and Exchange Commission, via the Division of Examinations, will conduct on-site exams or inspections, the targets of which are identified using risk analysis. The SEC publishes an annual list of exam priorities and risk alerts which contain observations about these examination topics.
It should be noted that it is in this monitoring part of the regulatory process that regulators are most likely to communicate their expectations with respect to compliance and in turn, this will depend on the supervisors' understanding and interpretation of the standards. Supervisors may ask things of regulated firms that are not necessarily codified in legal texts but will still influence their opinion of a firm's compliance.
Enforcement
Regulatory enforcement occurs when a regulated firm has been found to be in breach of the standards. Regulators' enforcement powers and the sanctions open to them to use are also enshrined in law and are generally only imposed after (sometimes lengthy) investigations have been conducted and wrongdoing or misconduct has been identified and proven in accordance with the appropriate evidential standards.
Financial institutions also have a responsibility to report compliance breaches, though the specific requirements vary from country to country.
Figure 2.2 Enforcement pyramid

(Source: Ayres, I., & Braithwaite, J. (1992). Responsive regulation: Transcending the deregulation debate. Oxford University Press, USA.).
The types of sanctions that regulators can employ can vary in severity. Figure 2.2 shows a theoretical model of the enforcement pyramid which illustrates this. At the bottom, regulators may use the tool of persuasion in the first instance (depending on the seriousness of the breach) to give firms the opportunity to remediate the issue. If not corrected, regulators may employ increasingly harsh measures, culminating in the removal of their 'licence to operate' (e.g. banking licence, authorisations to trade certain products in certain markets) which also act as a deterrent to other firms in the industry.
To be able to impose either a civil or criminal penalty, regulators must be able to evidence regulatory breaches and, in some cases, offer firms discounts on fines for early resolution of all or part of a case.
Whilst the results of enforcement actions, such as fines, result in eye-catching headlines, a lot of the negotiations about compliance and regulatory expectations occur behind closed doors, demanding significant amounts of management attention and diversion from business-as-usual.
Principles vs rules
A distinction is often made between principles-based regulation (broad standards focused on fostering certain desired outcomes) and rule-based regulation (a set of detailed rules governing firms' behaviour). Principles-based regulation puts the onus on firms to determine the details of how they will comply with the rules -- often requiring interpretation which is implemented through internal policies and procedures. Rule-based regulation is more prescriptive, dictating exactly what firms need to do to comply.
In reality, financial regulation is a combination of both rules and principles. For example, in the EU, the Markets in Financial Instruments Directive consists of both broad principles, contained in the overarching legal text and detailed rules for compliance contained in the Regulatory Technical Standards (see Box 2.1).
Where the principles vs rules distinction is critical is in the enforcement process. In the US, enforcement and the imposition of sanctions takes a very legalistic approach, with enforcement notices citing the breaking of specific rules. However, in countries such as the UK, enforcement action is taken when firms are considered to have breached the principles and fundamental rules that govern the conduct of regulated firms.
2.1 Principles vs Rules in Mifid II
In Mifid II, we see examples of both principles and rules. In this
example, of the requirements for business continuity arrangements in
algorithmic trading, the Level 1 text includes one sentence on the
types of arrangements firms must have in place, but the RTS (the
Level 2 text) specifies in detail what the nature of these
arrangements should be.
Directive 2014/65/EU
Article 17
Algorithmic trading
- An investment firm that engages in algorithmic trading shall have
in place effective systems and risk controls suitable to the business
it operates to ensure that its trading systems are resilient and have
sufficient capacity, are subject to appropriate trading thresholds
and limits and prevent the sending of erroneous orders or the systems otherwise functioning in a way that may create or contribute to a
disorderly market. Such a firm shall also have in place effective
systems and risk controls to ensure the trading systems cannot be
used for any purpose that is contrary to Regulation (EU) No 596/2014
or to the rules of a trading venue to which it is connected. ### The
investment firm shall have in place effective business continuity
arrangements to deal with any failure of its trading systems### and
shall ensure its systems are fully tested and properly monitored to
ensure that they meet the requirements laid down in this paragraph**.**
However, RTS 6 specifies the arrangements which must be in place:
RTS 6
Article 14 (Article 17(1) of Directive 2014/65/EU)
Business continuity arrangements
-
An investment firm shall have business continuity arrangements in place for its algorithmic trading systems which are appropriate to
the nature, scale and complexity of its business. Those arrangements
shall be documented in a durable medium. -
Business continuity arrangements of an investment firm shall
effectively deal with disruptive incidents and, where appropriate,
ensure a timely resumption of the algorithmic trading. Those
arrangements shall be adapted to the trading systems of each of the
trading venue accessed and shall include the following:
(a) a governance framework for the development and of the
deployment of the business continuity arrangement;
(b) a range of possible adverse scenarios relating to the operation
of the algorithmic trading systems, including the unavailability of
systems, staff, work space, external suppliers or data centres or
loss or alteration of critical data and documents;
(c) procedures for relocating the trading system to a back-up site
and operating the trading system from that site, where having such a
site is appropriate to the nature, scale and complexity of the
algorithmic trading activities of the investment firm;
(d) staff training on the operation of the business continuity
arrangements;
(e) usage policy regarding the functionality referred to in Article 12;
(f) arrangements for shutting down the relevant trading algorithm
or trading system where appropriate;
(g) alternative arrangements for the investment firm to manage
outstanding orders and positions.
-
An investment firm shall ensure that its trading algorithm or
trading system can be shut down in accordance with its business
continuity arrangements without creating disorderly trading
conditions. -
An investment firm shall review and test its business continuity
arrangements on an annual basis and modify the arrangements in light
of that review.