The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Finance/The Fintech & Payments Power 50
The Fintech & Payments Power 50 artwork

Fintech Power 50 webinar: Regtech at scale - control, cost and accountability

The Fintech & Payments Power 50 · 2026-05-22 · 38 min

0:00--:--

Key moments - from our scoring

Substance score

48 / 100

Five dimensions, 20 points each

Insight Density10 / 20
Originality9 / 20
Guest Caliber11 / 20
Specificity & Evidence10 / 20
Conversational Craft8 / 20

This FinTech Power 50 webinar brings together Simon Kingston from Jumio, a leading identity verification vendor, and Steven Simmons from Sequoia, a customer data verification platform, to discuss how RegTech is evolving under intense regulatory scrutiny. The conversation centers on three critical areas: the shift from KYC as a one-time tick box to continuous due diligence using biometric authentication as an ongoing risk signal; the tension between automation and human oversight in compliance workflows; and how to maintain transparency and explainability as AI becomes increasingly embedded in regulatory decision-making. Kingston explains Jumio's approach to operationalizing compliance at scale through layered identity verification combining biometrics, document analysis, and behavioral data - while stressing that firms cannot abdicate responsibility to vendors. Simmons describes Sequoia's role in extracting structured insights from unstructured customer documents (bank statements, payslips, tax records) to enable auditable lending and affordability decisions without prescribing the final determination. Both speakers address the regulatory imperative - particularly the EU's Digital Operational Resilience Act and emerging UK cybersecurity measures - highlighting that RegTech must be treated as an operating model encompassing governance, evidence, and accountability, not merely software. The discussion explores emerging concepts like identity intelligence networks, the challenge of defeating deepfakes with multimodal biometrics, and the need to balance speed and cost efficiency with model governance and regulatory evidence.

Key takeaways

  • →Identity verification should be treated as an ongoing living risk signal throughout the customer lifecycle, not just a one-time onboarding tickbox, utilizing established biometric profiles for stronger continuous authentication.
  • →RegTech is fundamentally an operating model combining tooling, data signals, and governance - not just software - and firms cannot abdicate responsibility to vendors for compliance outcomes.
  • →Banks must balance straight-through processing automation with meaningful human override capabilities and clear audit trails, rather than over-relying on AI black boxes.
  • →Data normalization and extraction from unstructured sources (bank statements, payslips, tax documents) is essential for producing auditable, high-quality decision support that humans can actually use.
  • →Network effects from cross-institutional identity intelligence sharing, enabled by strong biometric profiles, can help prevent fraud at scale while respecting data privacy constraints.

In this episode

  1. 1Introduction to RegTech at Scale: Control, Cost and Accountability
  2. 2Identity Verification and KYC: Jumio's Role in Operationalizing Compliance
  3. 3Customer Verification and Data Insights: Sequoia's Platform for Decision Making
  4. 4Evolution from One-Time KYC to Continuous Due Diligence and Living Risk Signals
  5. 5Biometric Authentication and Identity Intelligence for Ongoing Customer Monitoring
  6. 6Balancing Automation with Human Oversight: Straight-Through Processing vs. Manual Review
  7. 7AI, Explainability and Model Governance: Managing the Black Box Phenomenon
  8. 8Regulatory Requirements and Network Effects for Fraud Prevention

Mentioned

Jumio CorporationCircumstances SequoiaRuth VanteferSimon KingstonSteven SimmonsExperianMortgage Advice BureauEU Digital Operational Resilience ActData Access and Usage ActAI Act

Guests

Simon KingstonSteven Simmons

Topics in this episode

Know Your Customer (KYC)Identity Verificationbiometric authenticationMachine learning model governanceJumio CorporationCircumstances SequoiaContinuous Due DiligenceEU Digital Operational Resilience ActUK operational resilience in fintech and bankingDocument fraud detection

Questions this episode answers

How does Jumio define its role in RegTech versus providing advisory services?

Jumio positions itself as turning regulatory policy into operational control through technology, focusing on the start of the customer lifecycle with KYC, identity verification, and AML screening. It provides tooling (automation and orchestration), data elements (risk signals and biometric assessment), and some governance layer to evidence data flow and decision-making, but does not position itself as providing overarching regulatory advice - that remains the client's responsibility.

What is the key difference between Sequoia's and Jumio's roles in customer onboarding?

Jumio handles identity verification and biometric authentication at the point of onboarding, while Sequoia focuses on extracting structured data and surfacing insights from unstructured customer documents (bank statements, payslips, tax records) to support affordability and income verification decisions without making the final decision itself.

How are banks moving away from one-time KYC checks to continuous due diligence?

Banks are increasingly reusing the biometric profile established during onboarding as a stronger form of ongoing customer authentication for high-risk transactions (password resets, address changes, third-party appointments), replacing knowledge-based authentication with facial biometrics and liveness checks while monitoring changes in customer status for AML purposes.

What is identity intelligence and how does Jumio plan to deploy it?

Identity intelligence applies credit-bureau-style monitoring to detect behavior changes over time; Jumio is moving toward flagging users who have been associated with negative decisions elsewhere in its network, anonymously alerting clients if a previously legitimate customer shows signs of fraud or if a fraudster attempts to open accounts across multiple platforms.

How do RegTech vendors balance AI performance with regulatory explainability requirements?

Rather than relying entirely on AI, vendors like Jumio are taking a layered approach combining AI for speed and accuracy with human review checkpoints; they QA a percentage of outputs (Jumio QAs 10% of half a million daily verifications), maintain model governance and training policies, and ensure clients retain decision-making authority and can evidence why they rely on vendor recommendations to regulators.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

10 / 20

The episode contains a handful of genuinely useful ideas - biometric reuse for ongoing authentication, cross-transactional risk profiles as an identity-intelligence network, and the three-stage automation model (extract → surface insights → decide) - but large portions of the runtime are consumed by the host's lengthy preambles, mutual agreement, and high-level platitudes that add little for an informed operator.

we're doing half a million verifications a day. Right. You can't go and check each individual in each individual one, but we selectively check to continually monitor the accuracy of our output
we have what we call a cross, uh, transactional risk, um, profile that we can, if we have seen that individual elsewhere in our database, we can anonymize a flag

Originality

9 / 20

The analogy of building identity intelligence networks similar to credit bureaus is a moderately fresh framing, and Sequoia's explicit refusal to own the decision layer is a clear architectural stance; however, most of the discussion recycles well-established RegTech talking points - layered KYC, AI explainability tensions, human-in-the-loop - without genuine contrarian argument or first-principles reasoning.

we're now moving towards what we call, you know, um, identity intelligence if you like, perhaps in the same ways the credit bureaus have historically done it
the only country that has reduced fraud, I think I read an article recently, um, over the past year is Australia

Guest Caliber

11 / 20

Steven Simmons as co-founder and CDO of an active platform is a legitimate practitioner with hands-on domain depth; Simon Kingston's title is Head of Partner Sales EMEA, making him a senior commercial rather than technical or product executive, which limits the operational depth he can provide on architecture and model governance decisions.

we are unique in being able to extract all UK bank statements, all formats of UK bank statements and all UK payslips. And these are being used by providers like Experian and the Mortgage Advice Bureau
we have quite a significant investment in our own QA team. So we actually QA 10% of our verifications

Specificity & Evidence

10 / 20

A small number of concrete data points appear - 500k daily verifications, 10% QA sampling, named clients Experian and Mortgage Advice Bureau - and specific regulations are correctly cited (DORA, Data Access and Usage Act, AI Act, UK cybersecurity resilience bill); however, fraud reduction rates, ROI figures, processing-time benchmarks, and case study outcomes are entirely absent, leaving most claims at the level of assertion.

we're doing half a million verifications a day
we actually QA 10% of our verifications

Conversational Craft

8 / 20

The host demonstrates genuine domain knowledge and occasionally frames sharp questions about architecture and automation trade-offs, but she habitually pre-answers her own questions in lengthy preambles, rarely challenges a guest claim, and allows both guests to stay comfortably within their marketing comfort zones throughout the conversation.

how are your clients rethinking architecture so that identity becomes more of a living risk signal instead of just a tick box onboarding
you cannot abdicate your respons the responsibility in this with the provider

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B45%
  • Speaker A37%
  • Speaker C18%

Most-used words

data44risk21customer17different16decision16identity15regtech14course13process13documents13information12jumio10processes10financial10verification10trying10

Episode notes

Regtech now sits inside core financial operations: reporting, monitoring, resilience, conduct and third-party oversight. As reliance on automation increases, regulators are asking harder questions about evidence, ownership and control, especially when systems fail or decisions are challenged. Firms are being pushed to show how controls work in practice, how data flows through systems, and how accountability is defined. At the same time, boards are questioning spend, duplication across tools, and exposure to third-party providers. That shift in scrutiny goes beyond formal submissions. Regulators care less about box-ticking and more about whether firms can prove their controls work on an ongoing basis. As a result, everyday issues like data quality, consistency and operating set-ups are coming under closer attention. This Fintech Power 50 webinar will bring together a panel to discuss how RegTech is holding up under scrutiny. The conversation will focus on what stands up in practice, where pressure points show up, and how organisations are responding to tougher regulatory expectations

Full transcript

38 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Hello everybody. Welcome to the FinTech podcast on RegTech at scale, control, cost and accountability. I'm Ruth Vantefer, one of your FinTech Power 50 Avengers, as it were. And I have with me Simon Kingston, who is the head and partner sales EMEA at Jumio Corporation, and Steven Simmons, who is the co founder and chief data officer at Circumstances Sequoia. And today we will be talking about regtech, as I said, at the next level. So clearly regtech is with us for more than a decade. Technology innovation is ramping around us, but of course apart from all the Regtech requirements and the regulatory requirements of reporting, monitoring, resilience conduct and third party oversight, increasingly specifically on the cyber side we have an increasing reliance as we embed regtek in our systems on these automation processes. And regulators of course are asking more and more critical questions about how we own uh, these processes, how we evidence our compliance, leveraging technology, especially when it happens that systems fail or systems get compromised. So all of these firms around us, whether it's FinTechs or Bigtex or any other tech or financial services institution, we all pushed on showing to regulators how we control these things in practice, how data is identified, flows through different systems and how we uh, define different levels of accountability and monitoring. This calls of course up to the board. I sit on various boards for many years and I can tell you boards are being questioned about this. But boards are also questioning the internal organization because board members have accountability to regulators and at the same time the organization has to make sure that all of these things work, uh, really in sync, uh, and there are no gaps. Uh, so the FinTech Fair Power 50 webinar today will bring together these discussion points around how regtech is really holding up under this increased scrutiny we see from regulators. If we think about the EU Digital Operational Resilience Act, UK measures around enhancing operational resilience in tech, fintech and banking, and of course the cybersecurity resilience bill that is currently being discussed uh, in the House of Commons. Um, so we're going to talk about these topics and I would like to uh, first of all ask some scene setting questions, uh, particularly to understand a little bit more where Simon and Steven come from. So regtech means very different things to an identity verification vendor like Jumio. If you compare that with a data verification and platform provider like Sequoia. And so obviously these differences have to be drawn out, it would be great. Maybe starting with Simon, how do you define your slice of regtech and where do you see boundaries between tooling data and also overarching advice. Over to Simon.

Speaker B: Yes, thank you Ruth. Delighted to be here uh today. Thank you for the invitation. I think from an identity perspective uh Regitech is really all about turning policy into operational control, uh using technology to support that at scale. We live in a, a digital environment. We're moving from analog if you like, bricks and mortar um and so being able to use technology to support that digital transition um, is key. At Jumio our slice traditionally sits at the very start of the customer life cycle. Establishing who the customer is, kind of the KYC play if you like, how confident are we in that identity and whether that confidence can stand up to regulatory scrutiny uh later on. So from a tooling perspective, you know, maybe that's the automation that uh, the tools um, that automate the regulatory execution probably including the identity verification, IML screening, um, and increasingly other data inputs as well and the orchestration of those inputs and the work and the automation of that workflow. It's about operationalizing compliance at scale. Uh I guess the data elements are the risk signals behind the decision um making the ultimate decision making. So the identity attributes um, that we capture in that process, the documents that we cover in that process, the biometric uh, assessment. And whilst Jumio's legacy um, and historically has been purely in that sort of IDV space, you know, recognizing the need to augment um, that biometric and document based verification with other data points as well, we're increasingly deploying a layered approach uh, using many other um, data points. So intelligence from the device, additional risk signals, eky, classic data, orientated signals, email checks, et cetera, stuff that we can do in the background so to speak to sort of reduce the overall friction of the agreement. But um, and then it's the advice and the governance. So if you like the interpretive layer that's less where Jumio plays but it's still an important part of our overall platform in being able to evidence as you say, the flow of the data, what data points have been assessed and importantly what metrics or um, assessments are being applied to each piece of that data to give an overall sort of balance, um, risk score if you like for that, for um, the true identity of that individual. So I think you know, and as you said regulators increasingly care not that a check happened um, but whether a firm can show an evidence how it happens, the flow, the flow of that information and the asset the assessment was based. So Regitech should really be treated as um, an operating model, not just as a piece of software. Software flow, because, yeah, there are m. Many elements to it.

Speaker A: Very interconnected. That's right. And I think, I mean particularly on identity, because I worked a lot on helping the UK to understand a little bit more on the authentication side, multimodal biometrics. The more different variables you have to triangulate both in onboarding and ongoing, particularly the lesser risk, at least, I mean, the lesser you can m. Then you can minimize the risk of all the deep fakes. We just talked about a second ago, before we started the call, because the use of AI in the adversary space is of course creating a lot more complexity on how to execute regtech solutions of regtech, as you say.

Speaker C: Right.

Speaker A: So that must be a big piece too.

Speaker B: Yeah, yeah, no, absolutely. And obviously, um, AI has a significant role to play, um, in that we deploy many machine learning models that we continually iterate. And I think, you know, it's incumbent upon us as well to continually iterate those models, develop those models in the light of emerging, um, threat patterns, um, video injection, deep fake injection and creating, you know, trying to stay one step ahead of the, of the fraudsters, uh, from that perspective. And also a large part of that we're getting increasingly in RFPs is how do we stay on top of that? What's our software development policy, what are our training models and how do we evidence and test those training models, um, in the real world, uh, and we're relatively unique, we have quite a significant investment in our own QA team. So we actually QA 10% of our verifications because, you know, when you're doing this at, uh, scale, we're doing half a million verifications a day. Right. You can't go and check each individual in each individual one, but we selectively check to continually monitor the accuracy of our output. And you know, that's an increasing differentiator, uh, for us, given the appetite for the regulators for whilst it's, you know, we only make a recommendation at the end of the day based on what we've got. It's the customer's decision and the human within that, uh, process who makes the ultimate, uh, decision. But we have to help them evidence why they can rely on Jumio.

Speaker A: And this is, I think this is just fundamentally a good reminder for everybody these solutions are not taking away the problem altogether, but they help you to more efficiently address your own compliance and your own risk management. Because there is another layer that has helped you to funnel the jungle into a few trees where you still need to apply your own, um, also your own risk Appetite and metrics and controls as well.

Speaker B: But yeah, absolutely. And I think that's one of the biggest sort of misunderstood areas.

Speaker A: If you demystify that already at this

Speaker C: time,

Speaker B: you cannot abdicate your respons the responsibility in this with the provider.

Speaker A: That's right, yeah, yeah. With the one that onboards the actor. Yeah.

Speaker B: At the same time you know we're confident in that technology does a better job than humans typically invalidating all of the security aspects of a document and the biometric assessment. It's not foolproof of course. Um, and so you know, risk appetite, fraud appetite um, has to be clearly um, defined and owned um, by the financial institutions themselves.

Speaker C: That's right.

Speaker A: So Stephen, sorry. Um, this was a good one to start demystifying m those big blocks. Starting early on. I would really love to hear how at Sequoia you're kind of slicing the ragtech cake. What do you do? How do you do it? And maybe a few more points to complement what Simon was saying. Thanks.

Speaker C: Yeah. So at Sequoia we're a customer verification and a data insights platform. And so our focus is uh, automating the business processes at the customer interface. So if our typical clients would be banks, brokers, lenders of all sorts, payments companies, kind of these um, regulated financial services businesses and we give the lenders or the brokers the tools and the data that they need to make high quality auditable decisions from the information that their customers provide. So for us very much it's about providing the platform and the tooling and the data that's to make regulatory driven decisions from unstructured information that the customers um, give their brokers. So for instance bank statements, payslips, uh, these types of documents, tax documents. We are uh, experts at extracting the structured data out of these unstructured documents and producing high uh, quality overviews for income and um, expenditure checks, maybe for an affordability check, um, for a mortgage or for uh, um, income and employer check or a pre employment check. These types of things along with verification of the um, integrity of the documents. As fraud is a bigger and bigger problem and we present these to our clients so that they're able to make the decision. We focus very much on um, the upstream part of surfacing insights from customer data and then giving that in a form that is easy for customers to make their decisions, whether that's in their own decision engine or um, a manual underwriter is looking at it. But um, the data is all there in an auditable, complete, highly traceable form, um, with all of the controls and safeguards that are needed for a regulatory environment.

Speaker A: So you effectively doing a lot on data quality ultimately as well in terms of helping people to understand the data, to normalize it and to then make the data work for you so that you can make better decisions effectively, which is a critical.

Speaker C: Absolutely very much. The origin of Sequoia is a uh, unified financial data platform. And so um, our expertise is on bringing together the likes of identity verification information from Jumio, consumer credit reports, uh, company credit reports, company registry information, open banking information. We also are unique in being able to extract all UK bank statements, all formats of UK bank statements and all UK payslips. And these are being used by providers like Experian and the Mortgage Advice Bureau to um, support their affordability processes.

Speaker A: Yeah, an absolute essential solution which again I think back to the earlier message is something that a human, there's no way a human can do it and you have so many data sources now and they tend to be all in different formats. So you need a normalization layer and then an analytics layer and the layers

Speaker C: of cross checks to produce that auditability so you can have confidence in the final decision.

Speaker A: Yeah, excellent. Okay. Um, so Simon, we've seen a shift from one of kyc, which was the first step of Regtech being really used in that space, to continuous due diligence perpetual kyc. I mentioned earlier, obviously banks have to constantly authenticate transactions customers, they sometimes don't do it well, the data sits on the phone rather than with the bank. There are all sorts of problems with who sees what data and can actually say with a legitimate confirmation that this is true and this is truly my customer, which is why we have so much fraud. Uh, but how are your clients rethinking architecture so that identity becomes more of a living risk signal instead of just a tick box onboarding? I mean we're clearly miles away from the initial tick boxing I guess in some institutions. But there's always still the risk that it's just a tick box rather than a uh, business informed, strategic way of leveraging Regtech. So would love to hear your thoughts on that.

Speaker B: Yeah, so I think as you say, one of the big architectural shifts we're seeing is away from the one time events, uh, to being able to um, utilize that trust anchor that you've spent and invested quite a lot in establishing at the beginning of the customer life cycle. Um, so we're seeing most of the banks now use that biometric profile that's been established, um, for their customer as a much stronger form of ongoing customer Authentication. So just as you use your facial biometrics to activate your phone, once you've set up and established your credentials on that phone, um, you can use your biometric profile to establish liveness and selfie as a, as a replacement for the kind of knowledge based authentication and we're seeing customers use that a, it's now you know a common practice for users to be very comfortable to do that. It's much more speedy and much more secure than one time messaging or sms texting, uh, etc. Um, and it's kind of the expected digital experience but it's also very secure. You know you're doing a number of, a number of things in that um, strong customer authentic authentication. And we're seeing people layer that into, in front of high risk um, transactions whether that's denominated by a high value transaction or something like a password reset or a change of address or the appointee of a third party into, into the account. We saw, you know, we've seen, we've seen historically as well organizations suffer fraud when you know a customer is onboarded, they've set up their bank account but the, the intercept is then when they go to download the mobile app. Um, we've seen lots of injection points where people have sort of managed to you know, we all know that data is fairly freely available on the net once it's out there, you know in data form. But it's much harder as we as we know to, to um, spoof um the biometrics. So we're seeing the reuse and what we call authentication and you mentioned it earlier, that sort of ongoing biometric authentication throughout the life cycle of the customer now replacing knowledge based activity. We're also seeing customers asking ah yes, it's well established from an AML um perspective looking at changes of, of status um and that and providing those feeds in and in our orchestration platform we can provide those signals that there's been a change of status, that now they are a politically exposed individual or there is some adverse media. There are those flags that are easier. We also are uh, at Jumio we sort of transition to becoming more of a data controller and there's kind of a um, natural conflict here between sort of data privacy rules and regulations on the one hand and the rules and regulations we'd all be better served if we were sharing our collective knowledge of users. And of course it's very easy to do that associated with a strong biometric profile. But nevertheless you know um, and we are very prevalent in the gaming sector which is a regulate, you know, another regulated sector not quite as tightly regulated as financial services. Um, but setting ourselves up as a data controller now we have what we call a cross, uh, transactional risk, um, profile that we can, if we have seen that individual elsewhere in our database, we can anonymize a flag, you know, have they been associated with any negative decisions? And we can do that. And we're now moving towards what we call, you know, um, identity intelligence if you like, perhaps in the same ways the credit bureaus have historically done it. Has there been a change of status, have a user can come on board, be perfectly legitimate, but they may change their behavior over time. And we are seeing a lot of increasing demand for this. So if you're part of our network and the likelihood is fraudsters sort of perpetuate their fraud on multiple different platforms in multiple different environments, we've got a higher chance of seeing that and sending it, hey, that guy that you onboarded two years ago, we've just seen that come up in a high risk, low risk fraud.

Speaker A: Yeah. So you have a great opportunity to almost help the network because you're helping so many different people with the onboarding and monitoring. And I think when we take that to the next level, which is something we in the financial industry fought for for years, is of course information sharing between industry participants. And the Data Access and Usage act is now encouraging this. But of course it has to sort of zero knowledge in a way. But you could for example, say somebody with this Biometric has opened 100 fraudulent accounts across those banks. Don't let that kind of identity in with those biometrics next time around. Or as I said earlier, if you had a better check on biometrics on the phone versus within the bank, you wouldn't know whether it's uh, somebody who actually uses the phone but isn't the owner of the account versus um, the actual true individual. So I think there's a lot more we can do without divulging the actual data privacy related issues with personal identifiable information to actually address that point. But I think that's exactly the right way to have a network effect to help the community. And obviously extreme cases where you have karma points in China you can no longer buy milk, we don't want to get there. But there's obviously a way of evidencing behavior that was not uh, legal and therefore prevent that. Um, so Stephen, on automation, so maybe switching gear a little bit around the challenge of automation and again the regulatory nexus as well, that's clearly a Big part of your proposition too. Um, and so is control. So how do you strike the balance between straight through processing and giving underwriters and compliance officers meaningful human override and transparency on each decision? Maybe some views on that.

Speaker C: Yep, now that's a great question. I think when we look at the overall process that our um, customers are trying to solve for, we see their automation flow as involving three distinct stages. So the first stage is extracting data, the second stage is surfacing insights about that data and then the third stage is making decisions. So as a um, supplier of customer onboarding technology, uh, Sequoia focuses on the first two of these stages. So that is for extraction we take input documents like payslips, bank statements, tax documents and we extract their information into structured data. So this is uh, according to a uh, highly specified schema that is based around the business rules and the decision processes that are typically employed there and that's ready to be used in the next stage. So the second stage is surfacing insights about this unstructured data. And so these are answering real tangible business questions like answering what's the proof of income or an affordability assessment or is the high integrity in the documents that have been provided, have they met the um, financial institutions completeness rules? So these types of insights are really the um, end decisions that um, banks and lenders want to make. So whether it's for a mortgage or for car finance, international payments, personal loans, rental checks, etc. The overall um flow is the same. You want to extract the structured data uh, from these uh, source documents and then produce insights that are easy for a decision process. So as a provider we stop at that point um, at actually making the decision. We see that um, so many financial services businesses, maybe they have their own decision platforms, their own decision flows. We see um, every type of process that you can imagine from people that are trying to get 100% straight through processing through to people that want to have a manual underwriter review everything. And they just want to see these insights packaged in a summary form to help them focus on where the biggest risks are. So um, we uh, give the insights that are suitable for use in any CRM system or decision system. And that lets clients do their own prioritization to strike the balance between the needs of compliance and the business's goals for efficiency and automation.

Speaker A: Yeah, awesome. And I think it's really important to still keep the client in the loop because what I see on the other extreme, and maybe just switching a little bit to the AI topic, there are also sometimes slightly over ambitious approaches around AI and then somehow you say, okay, we can um, get rid of lots of stuff and let AI do certain things without actually having real experience about some of the challenges of AI So maybe coming back to Simon on this, um, the regulators are understanding that the AI black box phenomenon is a challenge. Um, I was working on an AI quantum thriller that I started last year and I thought, what can I imagine how bad it can get with AI and then certain things that I thought, okay, this could happen. AI lying, scheming, deleting stuff, pretending things they already happened last year. So somehow, um, it's sort of, it's a highly creative process to imagine even worse things. But how do you balance this explainability, fairness audits, model governance with the pressure from the clients that obviously want to see cut costs, response time costs, uh, to make things really fast and efficient. But if you then have a significant reliance on AI where there's always some elements that will be hard to explain or maybe unexplainable, I'm sure the regulators have a concern with that and maybe even reflecting on the AI act in that context as well.

Speaker B: Yes. So I'm uh, not an expert on the AI act, so I'll steer clear of that one. But I think you're right. It's a core tension right now, isn't it? Sort of kind of speed AI perform a high performance and um, evidence and explainability. I think even within a client you've got different camps of people. You know, head of retail banking wants to onboard as many customers as he possibly can and you know, I'll live with the fraud risk, thank you very much. Whereas the MLRO M takes a very different, a different viewpoint and ultimately the regulator is going to sort of, you know, take that viewpoint as well. So, and I think it's about, you know, I mentioned earlier, we now are taking a layered approach. You know, AI has a role uh, to play in speeding up the decisions and making better assessments than a human can. But it's not a complete reliance upon AI. And Steven's talked about, you know, whilst they may be using AI, there's always an element of manual review and trying to strike that balance between straight through processing and the checks that you have. So I think, and you know, in terms of how we're striking that balance, we're trying in the, in the customer journeys that we create as well, and you alluded to it earlier, trying to identify somebody who may be a risky proponent as soon as they come into your network. You know, lots, um, of people are using are onboarding on mobile devices right now. So and there's a lot of device um, centric intelligence that we can get from that even before we've started to do a formal identity verification. You know, so is this a risky device and you're making and throughout this you make layered assessments or you apply different scoring depending upon the various data elements that you, that you capture. Some are more AI orientated than others, some are kind of more data lookup. You know, validate that with the, with the email address or the phone number, you know, does that has that phone, that phone number being um, associated with any risk even before we get to the point. So you can build up a risk profile of this Looks like a bit of a dodgy one. So we need to apply more stringent layers of identity, of identity verification. Um so we have a dynamic orchestration and workflow engine that's sort of navigates through the various checks that people um, might do. Um, but, and then in terms of the feedback that we're giving and all of that data that we are capturing to this point of being explainable is being able to, if we've rejected anybody or at any stage, all of the reason codes or the reason codes for a particular score are provided back to our customers. You know and they, and they will also have that they can set the thresholds themselves in terms of the risk scores that they want to go through from a point of view of straight through processing or those that then they want to take on a uh, more stringent perhaps manual uh review possibly quite likely dipping into Sequoia type of services. We're seeing it all of the time as well. Everybody wants to condense everything into one, into one movement. You know, we, we will capture a ah, about some unstructured documents because often people want to verify an address. Um, and addresses don't sit on every individual identity document and they might, they may certainly be out, out of date. So the ability to sort of you know structure that and put, put all of that information in and then as you know Sequoia would say, you know, then people want to know. Yes, but is that document that we've captured um, uh, legitimate? Has it been doctored in any, in any way? So there's that sort of, and that's where the artificial intelligence comes in to sort of look at the patterns where people, you know, the typical ah, fraudulent manipulation of those types, types of documents. So from our point, our point of view I think it's about being risk appropriate and trying to define risks as you go through that acquisition process and at Jumio as well. You know, where a lot of this often breaks down is it, you know, obviously we're document fundamentally document based. At the end of the day we're capturing, acquiring images of documents and whatever and the ability to capture good quality images, documents and is key in that process as well. Because the last thing you want is to put somebody through the process at the end of the day and sort of say sorry, we didn't capture very good images. So we can't, we can't, can't assess you. That's the worst customer experience doesn't help anybody, the regulator or the customer. So there's a lot of what we call course correction trying to ensure that we're capturing the very best quality to be able to apply the AI and to apply those subsequent risk scoring methods.

Speaker A: Perfect.

Speaker B: Okay. It's quite complex, you're right. Um, I say AI accelerates the risk assessment but it doesn't remove human accountability at the end of the day. And our role within that is how we evidence the decisions that we've made throughout that process in terms of the feedback that we give through our APIs.

Speaker A: So AI is really, I mean just for everybody here on the call. AI is very much a double edged sword. And whilst using it and having expertise in farms like Sequoia or Jumio to apply those tools in the right way with experience and ability to incrementally improve every time, that's different to maybe running off as a financial institution and just plugging certain things into your own system just like that. Because even understanding the behavior of newer types of AI like gen AI, um, takes a while and requires quite some sophisticated ways of dealing with it. And also guardrails in terms of what data and systems you expose it to. Right. So I think that's a really critical one to keep in the back of our minds. Uh, which also then tells you don't fire all the good people that know how certain things work. Right. Um, but given we have to wrap up a little bit, I mean, first of all, I think it's really awesome to see that many years ago when I was pushing for Regtech and working with regulators and technology, we're starting to see true value chains emerging. We have the onboarding and the validation, we have the document pooling together, validation, verification, normalization. So we have a larger and larger data driven value chain of these different providers like the two of you, which are really giving a more solid decision making power and transparency to organizations. And I think that's what is really great to see and how nicely you uh, two players tie in together here. So just a very short wrap up for both of you. Um, if there's one regulation or supervisory practice that you would change, not to weaken protections of course, but to make it easier for firms to adopt high quality regtech without drowning in overlapping expectations. And we obviously know that regulations are, can often be overlapping and even conflicting. Which ones would you get rid of or change? Maybe starting with Steven?

Speaker C: Yeah, so I think um, the um, type of regulatory trainings that we need is to fully embrace the advances that AI can bring. So much of the ways of working in financial institutions is based around old manual processes with handovers between teams. That made sense when you needed to have a team checking an application form, a team checking a credit, uh, report, uh, team checking this, that or the other. So the underlying processes still tend to have lots of handovers. And so we can really bring to bear the integrating power of AI systems to assimilate information from many sources, but then also refocus on where within that should be the role of um, people if required, or other types of AI agents to cross check and verify the accuracy of the information that's provided. So I think um, the practice that we want to change is to um, assume that the existing processes need to be there for all times. We're not just trying to make incremental changes in one spot or another spot in this very complicated value chain. We're looking for ways that uh, we can automate, take out whole chunks of it where we can get customers to do more of the work right up front rather than discovering that rework needs to be done several days later through a complex decision process. Um, fundamentally reimagine what we're trying to do from the point of view of getting more value earlier in the process, but making that more auditable um, along the way.

Speaker A: Yeah, and I think in a way, if I may just give the analogy, take out manual processes where you can uh, clearly that is also an element of DORA in the operational resilience side at European level. So there are some good regulations that can actually help advance. But of course it's always also supervision. And it should be in any institution's interest to cut out processes that are intrinsically risky for so many different reasons, including cybersecurity, which is of course an area I'm working on a lot. Simon, anything you would scrap, change or create on the regulatory side to help.

Speaker B: Well from, I think I mentioned it earlier, my biggest bugbear is this sort of Kind of conflict between different regulatory bodies, if you like. You know, if we, if we. Look, I think the only country that has reduced fraud, I think I read an article recently, um, over the past year is Australia. And it did it because there was a massive partnership between the telcos, which are what, some of the biggest sort of data sort of holders, the bureaus, but central government and regulation as well and being able to understand the implications, and I mentioned it earlier, the data privacy laws, stuff like that, we've clearly discussed here, that orchestration has a significant role to play, ah, in the effectiveness, uh, of an overall, um, regtech platform and removing internal silos and fragmentation. I think we have to do that at a sovereign, at least at a sovereign level, um, across all of the rulemaking bodies. And that's what I would, um, advocate for most.

Speaker A: That's absolutely bang on. Um, it's what we said for the last few years, bring the telcos and the big techs into the tent because the app scams don't intrinsically start within the bank as just one of many examples. So you hit a nail on the head. It was awesome to talk to you, Stephen and Simon, thank you so much. I hope the audience likes it. Ask me any questions. Um, I work on these topics all the time, write about them and particularly cybersecurity is something that is an underlying theme in all of this. So thank you so much for a great, uh, conversation today. Thanks.

Speaker C: Thank you.

Speaker B: Thank you. Thanks. Goodbye.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Five Seconds to Fraud: Detecting AI Deepfakes Before They Strike with Ben ColmanCyber Sentries: AI Insight to Cloud Security · on Identity Verification87 / 100
  • The $443 Billion AI Lending Bias: Why 65% of Good Customers Get Declined | Carla Canino, Founder and CEO KindleePurpose Driven FinTech · on biometric authentication85 / 100
  • S7 Episode 5: Agentic AI: The Next Frontier in FinTech with Shannon Scott SVP & Global Head of Product at AirwallexDigitally Curious · on Know Your Customer (KYC)85 / 100
  • PayPal Ads’ Big Retail Media Bet: Why Shoppable Ads Could Finally Work (And The Future of Commerce in an AI World)Retail Media Breakfast Club · on Identity Verification80 / 100
  • E167: What keeps payments players up at night?The Laundry · on Know Your Customer (KYC)70 / 100
  • The Mistake Leaders Make When Hiring Their Team w/ B. Scott Swann | Episode 200The Software Leaders Uncensored Podcast · on biometric authentication66 / 100

More from The Fintech & Payments Power 50

All episodes →
  • The Payments Power 50 Podcast - The Future of Open Banking: Trends and Challenges
  • The Payments Power 50 - Cross-Border Payments: Connecting Merchants to Global Customers
  • The Payments Power 50 - AI in Payments Podcast
  • Episode 24: CEO Focus 2024
  • Episode 23: Fintech For Good 2024
Explore the best B2B Finance podcasts →
All The Fintech & Payments Power 50 episodes →