Why Financial Institutions Keep Fixing the Wrong Regulatory Problem
-
August 12, 2026
-
The e-mail arrives. Regulators have found another deficiency in your report. The legal, compliance and technology teams spend countless hours pulling, culling and analyzing the report data. The teams correct the report, resubmit the response and move on. Weeks later, another issue emerges. Why? Because the report was never the problem.
Too often, organizations address symptoms of the reporting process without addressing the quality, accessibility, and governance of the data feeding the reports.
In this environment, regulatory risk starts long before a report is filed. Poor data lineage, fragmented systems and organizational silos can undermine confidence in regulatory responses, triggering deeper scrutiny, potential enforcement actions and costly remediation efforts.
How can financial institutions build data foundations that produce accurate and defensible information for regulatory reporting at speed, leveraging their data capabilities beyond compliance to become a strategic capability?
From Explanations to Evidence
Regulators are increasingly examining not just a financial institution’s reports but its whole data governance program, and errors in reporting data are like waving a red cape in front of a bull to invite even greater scrutiny. For financial institutions, producing accurate and timely reports is table stakes. The expectation is now shifting from being able to explain its reporting to regulators to now having to prove it through data.
Regulations, including Financial Institution Regulatory Authority (“FINRA”) Rule 8210,1 increasingly require institutions to produce accurate, defensible and traceable information on demand. In addition, examinations increasingly focus not only on the accuracy of the final report but on the integrity and completeness of the underlying data. Failure to comply by member firms and associated persons can result in a fine, suspension, and more severe actions including bars and expulsions from FINRA.2
Regulators can make ad hoc requests at any time, in addition to formal regulatory requirements. This can be triggered by unusual trading activity near an earnings announcement or whistleblower complaints.
In layman’s terms, regulators want to replay an event, like reviewing camera footage, rather than solely relying on witness statements. Further, as the data analytics of the U.S. Securities and Exchange Commission (“SEC”) have improved, regulated entities are being asked for increasingly large and complex data sets to support investigations.
Why Traditional Reporting Models Fall Short
While data responsive to regulatory requirements and requests likely exists in one of many disconnected systems, ownership, lineage, refresh timing and quality controls hamper data governance and usage efforts.
Regulations such as the Commodity Futures Trading Commission’s (“CFTC”) trade reconstruction requirement expose the limitations of fragmented data environments.3 Without trusted data lineage, retention and governance practices, many institutions will struggle to meet these expectations.
Trade reconstruction is critical to maintaining market integrity and illustrates a new reality. With the rise of prediction markets like Kalshi and Polymarket, regulated capital markets firms are likely to face insider trading investigations that require communications, timing and trading data across multiple platforms and related instruments. Regulators will want to test an organization’s ability to reconstruct such events from source data against strict timelines.
Tabletop exercises can expose data challenges in a safe environment, enabling organizations to make focused improvements. Here are some key considerations when trying to reconstruct trades:
- Don't mistake data retention for reconstruction readiness. Capturing records is only the first step. Reconstructing a transaction requires the ability to retrieve, correlate and reassemble data from multiple sources.
- Building a trade narrative depends on connected data and systems. Reconstructing events requires timestamps, metadata, and clear linkages across disparate and potentially disconnected systems.
- Legacy systems can obscure accountability. Identifying who executed, booked, approved, or contributed to a trade can be challenging, particularly when legacy systems from prior mergers or acquisitions remain siloed.
Case Example
A global financial institution self-disclosed to FINRA after discovering potential misreporting in its electronic bluesheet (“EBS”) reports. The firm retained outside counsel and FTI Consulting to investigate its EBS reporting procedures, which revealed multiple reporting deficiencies – some originating upstream from the EBS submission process itself, raising broader concerns about other regulatory reporting functions.
FTI Consulting’s team assessed more than 68,000 lines of COBOL code to identify gaps in exclusion logic, analyzed billions of transactions across the firm's trade reporting system, and traced issues to upstream feeder systems. The team determined root causes, quantified the volume of affected EBS submissions, and developed remediation procedures to prevent both new and historical "bad" data from being reported. FTI Consulting’s experts also reviewed the firm's quality control and surveillance processes, identified risk areas, and proposed enhancements.
Beyond Structured Data
Another existing CFTC regulation, 17 CFR § 23.203, takes the concept of reconstruction one step further by requiring swap dealers and major swap participants to maintain required records at designated locations, retain them in accordance with applicable CFTC rules, and make them available for inspection by the CFTC and other authorized regulators.4
Beyond reconstruction requirements, record retention and inspection requirements test whether an organization can locate, produce and explain required data. This extends beyond structured datasets to encompass the broader data ecosystem across the enterprise.
The challenge is compounded by the growing volume and variety of information regulators demand. Beyond structured data, institutions must rapidly produce transaction records, electronic messages and other unstructured content across multiple platforms, including third-party owned data that sits outside traditional systems of record. Classifying and linking unstructured data to specific transactions and clients can create a significant challenge for many financial institutions.
Both SEC and CFTC compliance depends on an institution’s ability to capture, retain, monitor, search and produce communications related to transactions on demand. For example, under CFTC record-retention requirements, firms may be required to provide requested records in the United States within 72 hours when records are maintained outside the country, emphasizing regulatory expectations of both speed and accuracy.5
Building a Defensible Data Foundation
Organizations should not look to address and improve their data environment during a crisis or rushed response; this will only compound the issue. Instead, they should look to proactively make focused improvements. Periods of downtime can be a great opportunity for proactive enhancements, but don’t wait for the downtime as it may not come.
While improving data quality and accessibility can appear broad and daunting, there are a few key priorities that can markedly improve data production capabilities, including:
- Build a tested inquiry-readiness capability before the next request arrives. Organizations should evaluate how quickly they could respond to a major regulatory inquiry, identify bottlenecks and establish a roadmap toward a more defensible data environment.
- Move from one-off report correction to repeatable evidence production. The objective is not just to satisfy a single inquiry but to build a repeatable capability. Organizations that continuously improve their data environment, governance processes and response teams will be better positioned to meet increasingly demanding regulatory requests.
- Modernize only where modernization improves defensibility. Organizations should evaluate whether existing repositories can support rapid, defensible responses and prioritize repositories that shorten the response time. The goal is to make information easier to locate, connect and produce when regulators demand it.
- Establish a clear response structure with defined accountability. When requests arrive, organizations should already know which stakeholders need to be involved and what role each will play in the response. Building an organized response framework that includes legal, regulatory, compliance and other relevant functions can improve speed, coordination and accountability.
The next generation of regulatory examinations will increasingly resemble data audits rather than reporting audits. Institutions that continue to view reporting as a downstream compliance activity will struggle to meet expectations for transparency, traceability and speed.
Footnotes:
1: FINRA Rule 8210 authorizes FINRA to require member firms and associated persons to provide information, documents, records, and sworn testimony in connection with its investigations, examinations, complaints, and disciplinary proceedings. See FINRA Rule 8210, “Provision of Information and Testimony and Inspection and Copying of Books,” (May 26, 2026).
2: FINRA Rule 8310, “Sanctions for Violations of the Rules,” (2026).
3: 17 CFR § 38.256 (2025). The CFTC’s trade reconstruction regulation requires a designated contract market to comprehensively and accurately reconstruct all trading on its facility and provide the related audit-trail data and reconstructions to the CFTC in an acceptable form, manner, and timeframe.
4: 17 CFR § 23.203 (2026).
5: 17 CFR § 23.203 (2026).
Published
August 12, 2026
Key Contacts
Senior Managing Director
Senior Managing Director
Managing Director