Reference · Vendor-neutral
RegTech glossary.
The terms a compliance, risk, or HSE team will meet this quarter — in banking, fintech, digital assets, and energy. Sourced where it matters, cross-linked everywhere.
36 terms
A
- AML#aml
- Anti-Money Laundering.
- The program, controls, and obligations a regulated firm must operate to detect and report attempts to convert proceeds of crime into apparently legitimate funds. In practice: KYC/KYB, sanctions screening, transaction monitoring, SAR/STR filing.
- See also:KYCTransaction monitoringSAR / STRSanctions screeningSource: FATF — AML/CFT ↗
- Audit trail#audit-trail
- A chronological, tamper-evident record of who did what, when, and on what basis.
- The minimum artefact behind any compliance claim. A useful trail links the action to the obligation it satisfies and to the person accountable for it.
- See also:Evidence packageHash-chained evidence
B
- BSA#bsa
- Bank Secrecy Act (US, 1970).
- Foundational US AML statute. Requires financial institutions to keep records, file Currency Transaction Reports (CTRs) and Suspicious Activity Reports (SARs), and run an AML program. Enforced by FinCEN.
- See also:FinCENSAR / STRAMLSource: FinCEN — BSA ↗
- Basel framework#basel-framework
- International standards for bank capital, liquidity, and risk reporting.
- A set of standards agreed by the Basel Committee and implemented through national rules. Drives capital adequacy, liquidity coverage, leverage, and the supervisory reporting that evidences them.
- See also:ObligationControlSource: BIS — Basel Framework ↗
C
- Control#control
- A specific, testable action a firm performs to satisfy an obligation.
- Controls are the operational unit between an obligation (the rule) and evidence (the proof). A good control has an owner, a frequency, a deterministic test, and produces evidence on every run.
- See also:ObligationEvidence package
- Consumer protection#consumer-protection
- Rules requiring fair treatment, clear disclosure, and good outcomes for retail customers.
- Covers fair lending, pricing transparency, complaint handling, adverse-action notices, and product governance. Enforcement usually turns on whether the firm can evidence the outcome, not just the policy.
- See also:ObligationEvidence package
D
- DORA#dora
- Digital Operational Resilience Act (EU, in force Jan 2025).
- Sets ICT risk-management, incident-reporting, resilience-testing, and third-party-risk obligations for EU financial entities and their critical ICT service providers.
- See also:MiCAObligationSource: EUR-Lex — DORA ↗
E
- Evidence package#evidence-package
- A signed, hash-chained bundle that proves a control ran against an obligation at a point in time.
- An evidence package binds five things: the obligation id, the control id, the input data in scope, the reviewer's decision, and a cryptographic seal (hash + signer). It is the artifact a supervisor or auditor actually accepts — not a screenshot or PDF.
- See also:Hash-chained evidenceControlObligation
- Emissions reporting#emissions-reporting
- Measuring and reporting greenhouse-gas and pollutant releases against permitted limits.
- Operators monitor emissions continuously or by survey, compare readings against permit thresholds, and file periodic reports. Each filing depends on a defensible chain from the sensor reading to the number submitted.
- See also:Permit conditionEvidence package
- Examination#examination
- A supervisor's structured review of a regulated firm's compliance.
- Examiners request evidence that specific controls operated over a period. Firms that can produce dated, signed records answer in hours; firms that cannot spend weeks reconstructing them.
- See also:Evidence packageAudit trailSupTech
F
- FATF#fatf
- Financial Action Task Force.
- Inter-governmental body that sets global AML, CFT, and counter-proliferation-financing standards. Its 40 Recommendations — including R.16 (Travel Rule) — are transposed into national law by member jurisdictions.
- See also:Travel RuleAMLSource: FATF ↗
- FinCEN#fincen
- Financial Crimes Enforcement Network (US Treasury bureau).
- Administers the BSA. Receives SARs and CTRs, publishes typology advisories (e.g. mixer exposure, ransomware), and operates the Beneficial Ownership Information registry.
- See also:BSASAR / STROFACSource: FinCEN ↗
G
- GENIUS Act#genius-act
- Guiding and Establishing National Innovation for U.S. Stablecoins Act.
- US federal framework for payment-stablecoin issuers: 1:1 high-quality liquid reserves, monthly disclosures, redemption rights, federal/state dual chartering. Applies to issuers serving US persons.
- See also:StablecoinMiCA
- GRC#grc
- Governance, Risk, and Compliance.
- Legacy software category — Archer, MetricStream, ServiceNow GRC, Workiva. Models risks and controls in static registers behind a SaaS UI. RegTech is the event-driven, API-first generation that is gradually replacing GRC.
- See also:RegTechControl
H
- Hash-chained evidence#hash-chained-evidence
- Evidence whose integrity is enforced by a chain of cryptographic hashes.
- Each evidence package references the SHA-256 hash of the previous one, so tampering with any record invalidates every record after it. The chain root is published or signed by a trusted key, giving an auditor a tamper-evident timeline.
- See also:Evidence package
K
- KYC#kyc
- Know Your Customer.
- The identity-verification and risk-rating steps a firm performs on a natural person before, and during, a customer relationship. Modern KYC is risk-tiered and continuous, not a one-time onboarding step.
- See also:KYBAMLPEP
- KYB#kyb
- Know Your Business.
- Identity, ownership, and risk verification for a legal entity. Includes beneficial-ownership tracing, sanctions screening of the entity and its UBOs, and ongoing monitoring.
- See also:KYCSanctions screening
M
- MAS#mas
- Monetary Authority of Singapore.
- Singapore's integrated central bank and financial regulator. Issues the Payment Services Act (PS Act) licences for Digital Payment Token (DPT) services and runs AML/CFT Notices including 626A for DPTs.
- Source: MAS ↗
- MiCA#mica
- Markets in Crypto-Assets Regulation (EU).
- EU-wide regime for crypto-asset issuers and service providers (CASPs). Title III covers e-money tokens (EMTs), Title IV covers asset-referenced tokens (ARTs), Title V licenses CASPs. Art. 36 governs reserve composition for EMT/ART issuers; Art. 23 governs large-redemption procedures.
- See also:DORAStablecoinVASPSource: EUR-Lex — MiCA ↗
- MiFID II#mifid-ii
- Markets in Financial Instruments Directive II (EU).
- EU framework for investment firms and trading venues. Covers transaction reporting (RTS 22), best-execution (RTS 27/28), product governance, and inducements.
- See also:Obligation
N
- NYDFS Part 500#nydfs-part-500
- NY Cybersecurity Regulation.
- Mandatory cybersecurity program, 72-hour incident notification, MFA, annual certification, and third-party-risk obligations for entities authorized by the New York Department of Financial Services. Updated 2023 (Part 500.17).
- See also:DORASource: NYDFS ↗
O
- Obligation#obligation
- A specific, citable requirement extracted from a regulation, statute, or guidance document.
- Obligations are the atomic unit a RegTech operating layer reasons over. Each has an id (e.g. MiCA.Art36.Reserve.Composition), a source, a version, an applicability scope, and a set of mapped controls. When the source changes, the obligation gets a new version and its controls get re-tested.
- See also:ControlEvidence packageRegulatory change management
- OFAC#ofac
- Office of Foreign Assets Control (US Treasury).
- Administers US economic and trade sanctions. Maintains the SDN (Specially Designated Nationals) and Consolidated lists. Applies the 50% rule: entities owned 50%+ by sanctioned parties are themselves sanctioned even if not listed.
- See also:Sanctions screeningSource: OFAC ↗
P
- PEP#pep
- Politically Exposed Person.
- A natural person who holds, or has held, a prominent public function — and their close associates and family. Most jurisdictions require enhanced due diligence (EDD) for PEP relationships.
- See also:KYCAML
- Permit condition#permit-condition
- A binding operating limit attached to an environmental or safety permit.
- Conditions set thresholds, monitoring frequencies, and reporting duties for a specific site or asset. They change mid-cycle more often than firms expect, which makes version-tracking the whole game.
- See also:Emissions reportingObligation
- Process safety management#process-safety
- The discipline of preventing releases of hazardous materials from industrial processes.
- Hazard analysis, mechanical integrity, management of change, and operating procedures — each with an inspection or test that must be documented and retained.
- See also:ControlEvidence package
R
- RegTech#regtech
- Regulatory technology.
- Use of information technology to enhance regulatory monitoring, reporting, compliance, and risk management. Coined by the UK FCA in 2015 as a FinTech subset focused on "the delivery of regulatory requirements more efficiently and effectively than existing capabilities."
- See also:SupTechGRCSource: FCA — RegTech ↗
- Regulatory change management#regulatory-change-management
- The discipline of detecting, classifying, and operationalizing change from regulators.
- End-to-end: ingest the source → classify materiality and applicability → diff against the existing obligation library → route to a reviewer → update controls → seal evidence. The RegTech operating layer's loop.
- See also:ObligationEvidence package
S
- SAR / STR#sar-str
- Suspicious Activity Report (US) / Suspicious Transaction Report (rest of world).
- A confidential filing a regulated firm submits to the FIU (FinCEN in the US) when it has reasonable grounds to suspect funds are related to crime. Tipping-off the subject is itself an offence.
- See also:AMLTransaction monitoringFinCEN
- Sanctions screening#sanctions-screening
- Matching a counterparty, transaction, or beneficial owner against sanctions lists in real time.
- Covers SDN, EU Consolidated, UK OFSI, UN, and sectoral programs. False positives are the operational tax; modern screening uses fuzzy matching, secondary attributes, and signer-attested clear/hit decisions.
- See also:OFACKYB
- SOC 2#soc-2
- AICPA Service Organization Control 2.
- Attestation framework for service organizations covering Security, Availability, Processing Integrity, Confidentiality, and Privacy. Type I is point-in-time; Type II covers a 6–12 month operating period.
- See also:Evidence package
- Stablecoin#stablecoin
- A crypto-asset designed to maintain a stable value, typically by reference to a single fiat currency.
- Regulated under MiCA in the EU (EMT / ART), under the GENIUS Act federally in the US, and under various state regimes (e.g. NYDFS Part 200). Core obligations cluster around reserves, redemption rights, and disclosures.
- See also:MiCAGENIUS Act
- SupTech#suptech
- Supervisory technology — the supervisor-side counterpart of RegTech.
- Tools agencies use to ingest filings, monitor markets, run thematic reviews, and analyze granular transaction data. As SupTech improves, the bar for firm-side evidence quality rises in parallel.
- See also:RegTech
T
- Transaction monitoring#transaction-monitoring
- Continuous, rules- and model-based detection of suspicious patterns in transaction flow.
- Inputs: customer profile, transaction, counterparty, network exposure. Outputs: alerts, escalations, SAR/STR candidates. Modern programs tune rules against typology advisories (e.g. mixers, layering) and document every rule change as evidence.
- See also:AMLSAR / STR
- Travel Rule#travel-rule
- FATF Recommendation 16, transposed into EU TFR and various national rules.
- Requires originator and beneficiary identity information to travel with a transfer between Virtual Asset Service Providers above a de-minimis threshold. The EU TFR removed the threshold for crypto transfers from 30 Dec 2024.
- See also:FATFVASP
V
- VASP#vasp
- Virtual Asset Service Provider.
- FATF term for any person or business that conducts virtual-asset exchange, transfer, custody, or issuance services on behalf of others. EU-equivalent is CASP (Crypto-Asset Service Provider) under MiCA.
- See also:MiCATravel Rule