Reference · Vendor-neutral

RegTech glossary.

The terms a compliance, risk, or HSE team will meet this quarter — in banking, fintech, digital assets, and energy. Sourced where it matters, cross-linked everywhere.

36 terms

A

Audit trail#audit-trail
A chronological, tamper-evident record of who did what, when, and on what basis.
The minimum artefact behind any compliance claim. A useful trail links the action to the obligation it satisfies and to the person accountable for it.
See also:Evidence packageHash-chained evidence

B

BSA#bsa
Bank Secrecy Act (US, 1970).
Foundational US AML statute. Requires financial institutions to keep records, file Currency Transaction Reports (CTRs) and Suspicious Activity Reports (SARs), and run an AML program. Enforced by FinCEN.
See also:FinCENSAR / STRAMLSource: FinCEN — BSA
Basel framework#basel-framework
International standards for bank capital, liquidity, and risk reporting.
A set of standards agreed by the Basel Committee and implemented through national rules. Drives capital adequacy, liquidity coverage, leverage, and the supervisory reporting that evidences them.
See also:ObligationControlSource: BIS — Basel Framework

C

Control#control
A specific, testable action a firm performs to satisfy an obligation.
Controls are the operational unit between an obligation (the rule) and evidence (the proof). A good control has an owner, a frequency, a deterministic test, and produces evidence on every run.
See also:ObligationEvidence package
Consumer protection#consumer-protection
Rules requiring fair treatment, clear disclosure, and good outcomes for retail customers.
Covers fair lending, pricing transparency, complaint handling, adverse-action notices, and product governance. Enforcement usually turns on whether the firm can evidence the outcome, not just the policy.
See also:ObligationEvidence package

D

DORA#dora
Digital Operational Resilience Act (EU, in force Jan 2025).
Sets ICT risk-management, incident-reporting, resilience-testing, and third-party-risk obligations for EU financial entities and their critical ICT service providers.
See also:MiCAObligationSource: EUR-Lex — DORA

E

Evidence package#evidence-package
A signed, hash-chained bundle that proves a control ran against an obligation at a point in time.
An evidence package binds five things: the obligation id, the control id, the input data in scope, the reviewer's decision, and a cryptographic seal (hash + signer). It is the artifact a supervisor or auditor actually accepts — not a screenshot or PDF.
See also:Hash-chained evidenceControlObligation
Emissions reporting#emissions-reporting
Measuring and reporting greenhouse-gas and pollutant releases against permitted limits.
Operators monitor emissions continuously or by survey, compare readings against permit thresholds, and file periodic reports. Each filing depends on a defensible chain from the sensor reading to the number submitted.
See also:Permit conditionEvidence package
Examination#examination
A supervisor's structured review of a regulated firm's compliance.
Examiners request evidence that specific controls operated over a period. Firms that can produce dated, signed records answer in hours; firms that cannot spend weeks reconstructing them.
See also:Evidence packageAudit trailSupTech

F

FATF#fatf
Financial Action Task Force.
Inter-governmental body that sets global AML, CFT, and counter-proliferation-financing standards. Its 40 Recommendations — including R.16 (Travel Rule) — are transposed into national law by member jurisdictions.
See also:Travel RuleAMLSource: FATF
FinCEN#fincen
Financial Crimes Enforcement Network (US Treasury bureau).
Administers the BSA. Receives SARs and CTRs, publishes typology advisories (e.g. mixer exposure, ransomware), and operates the Beneficial Ownership Information registry.
See also:BSASAR / STROFACSource: FinCEN

G

GENIUS Act#genius-act
Guiding and Establishing National Innovation for U.S. Stablecoins Act.
US federal framework for payment-stablecoin issuers: 1:1 high-quality liquid reserves, monthly disclosures, redemption rights, federal/state dual chartering. Applies to issuers serving US persons.
See also:StablecoinMiCA
GRC#grc
Governance, Risk, and Compliance.
Legacy software category — Archer, MetricStream, ServiceNow GRC, Workiva. Models risks and controls in static registers behind a SaaS UI. RegTech is the event-driven, API-first generation that is gradually replacing GRC.
See also:RegTechControl

H

Hash-chained evidence#hash-chained-evidence
Evidence whose integrity is enforced by a chain of cryptographic hashes.
Each evidence package references the SHA-256 hash of the previous one, so tampering with any record invalidates every record after it. The chain root is published or signed by a trusted key, giving an auditor a tamper-evident timeline.
See also:Evidence package

K

KYC#kyc
Know Your Customer.
The identity-verification and risk-rating steps a firm performs on a natural person before, and during, a customer relationship. Modern KYC is risk-tiered and continuous, not a one-time onboarding step.
See also:KYBAMLPEP
KYB#kyb
Know Your Business.
Identity, ownership, and risk verification for a legal entity. Includes beneficial-ownership tracing, sanctions screening of the entity and its UBOs, and ongoing monitoring.
See also:KYCSanctions screening

M

MAS#mas
Monetary Authority of Singapore.
Singapore's integrated central bank and financial regulator. Issues the Payment Services Act (PS Act) licences for Digital Payment Token (DPT) services and runs AML/CFT Notices including 626A for DPTs.
Source: MAS
MiCA#mica
Markets in Crypto-Assets Regulation (EU).
EU-wide regime for crypto-asset issuers and service providers (CASPs). Title III covers e-money tokens (EMTs), Title IV covers asset-referenced tokens (ARTs), Title V licenses CASPs. Art. 36 governs reserve composition for EMT/ART issuers; Art. 23 governs large-redemption procedures.
See also:DORAStablecoinVASPSource: EUR-Lex — MiCA
MiFID II#mifid-ii
Markets in Financial Instruments Directive II (EU).
EU framework for investment firms and trading venues. Covers transaction reporting (RTS 22), best-execution (RTS 27/28), product governance, and inducements.
See also:Obligation

N

NYDFS Part 500#nydfs-part-500
NY Cybersecurity Regulation.
Mandatory cybersecurity program, 72-hour incident notification, MFA, annual certification, and third-party-risk obligations for entities authorized by the New York Department of Financial Services. Updated 2023 (Part 500.17).
See also:DORASource: NYDFS

O

Obligation#obligation
A specific, citable requirement extracted from a regulation, statute, or guidance document.
Obligations are the atomic unit a RegTech operating layer reasons over. Each has an id (e.g. MiCA.Art36.Reserve.Composition), a source, a version, an applicability scope, and a set of mapped controls. When the source changes, the obligation gets a new version and its controls get re-tested.
See also:ControlEvidence packageRegulatory change management
OFAC#ofac
Office of Foreign Assets Control (US Treasury).
Administers US economic and trade sanctions. Maintains the SDN (Specially Designated Nationals) and Consolidated lists. Applies the 50% rule: entities owned 50%+ by sanctioned parties are themselves sanctioned even if not listed.
See also:Sanctions screeningSource: OFAC

P

PEP#pep
Politically Exposed Person.
A natural person who holds, or has held, a prominent public function — and their close associates and family. Most jurisdictions require enhanced due diligence (EDD) for PEP relationships.
See also:KYCAML
Permit condition#permit-condition
A binding operating limit attached to an environmental or safety permit.
Conditions set thresholds, monitoring frequencies, and reporting duties for a specific site or asset. They change mid-cycle more often than firms expect, which makes version-tracking the whole game.
See also:Emissions reportingObligation
Process safety management#process-safety
The discipline of preventing releases of hazardous materials from industrial processes.
Hazard analysis, mechanical integrity, management of change, and operating procedures — each with an inspection or test that must be documented and retained.
See also:ControlEvidence package

R

RegTech#regtech
Regulatory technology.
Use of information technology to enhance regulatory monitoring, reporting, compliance, and risk management. Coined by the UK FCA in 2015 as a FinTech subset focused on "the delivery of regulatory requirements more efficiently and effectively than existing capabilities."
See also:SupTechGRCSource: FCA — RegTech
Regulatory change management#regulatory-change-management
The discipline of detecting, classifying, and operationalizing change from regulators.
End-to-end: ingest the source → classify materiality and applicability → diff against the existing obligation library → route to a reviewer → update controls → seal evidence. The RegTech operating layer's loop.
See also:ObligationEvidence package

S

SAR / STR#sar-str
Suspicious Activity Report (US) / Suspicious Transaction Report (rest of world).
A confidential filing a regulated firm submits to the FIU (FinCEN in the US) when it has reasonable grounds to suspect funds are related to crime. Tipping-off the subject is itself an offence.
See also:AMLTransaction monitoringFinCEN
Sanctions screening#sanctions-screening
Matching a counterparty, transaction, or beneficial owner against sanctions lists in real time.
Covers SDN, EU Consolidated, UK OFSI, UN, and sectoral programs. False positives are the operational tax; modern screening uses fuzzy matching, secondary attributes, and signer-attested clear/hit decisions.
See also:OFACKYB
SOC 2#soc-2
AICPA Service Organization Control 2.
Attestation framework for service organizations covering Security, Availability, Processing Integrity, Confidentiality, and Privacy. Type I is point-in-time; Type II covers a 6–12 month operating period.
See also:Evidence package
Stablecoin#stablecoin
A crypto-asset designed to maintain a stable value, typically by reference to a single fiat currency.
Regulated under MiCA in the EU (EMT / ART), under the GENIUS Act federally in the US, and under various state regimes (e.g. NYDFS Part 200). Core obligations cluster around reserves, redemption rights, and disclosures.
See also:MiCAGENIUS Act
SupTech#suptech
Supervisory technology — the supervisor-side counterpart of RegTech.
Tools agencies use to ingest filings, monitor markets, run thematic reviews, and analyze granular transaction data. As SupTech improves, the bar for firm-side evidence quality rises in parallel.
See also:RegTech

T

Transaction monitoring#transaction-monitoring
Continuous, rules- and model-based detection of suspicious patterns in transaction flow.
Inputs: customer profile, transaction, counterparty, network exposure. Outputs: alerts, escalations, SAR/STR candidates. Modern programs tune rules against typology advisories (e.g. mixers, layering) and document every rule change as evidence.
See also:AMLSAR / STR
Travel Rule#travel-rule
FATF Recommendation 16, transposed into EU TFR and various national rules.
Requires originator and beneficiary identity information to travel with a transfer between Virtual Asset Service Providers above a de-minimis threshold. The EU TFR removed the threshold for crypto transfers from 30 Dec 2024.
See also:FATFVASP

V

VASP#vasp
Virtual Asset Service Provider.
FATF term for any person or business that conducts virtual-asset exchange, transfer, custody, or issuance services on behalf of others. EU-equivalent is CASP (Crypto-Asset Service Provider) under MiCA.
See also:MiCATravel Rule
Request early access →