GrowArticle

When the rules change, your staff records are the slowest thing to fix

Fintech regulation keeps moving. Capital can be raised and systems can be built, but evidence of what an employee was assessed on or understood cannot be recreated after the fact.

Elizabeth de BruijnWritten byElizabeth de Bruijn
11 min readPublished

In January 2025, crypto supervision in Indonesia moved from Bappebti, the commodity futures regulator, to the OJK, the financial services authority. On paper that is an administrative transfer. In practice it is a change of regime.[1]

OJK Regulation 27/2024 set requirements for digital-financial-asset and crypto-asset trading, including licensing, governance, risk management and consumer protection. The governing framework has since been amended, so organisations need to work from the current applicable rule and licensing guidance.[1]

Most of the companies affected treated this as three projects: a legal project, a capital project and a systems project. The fourth one, the people project, tends to get discovered late. And it is the one with the longest lead time.

Lina Al-Khatib seated at a meeting table with colleagues
Lina Al-KhatibA regulatory change still needs people across the business to act on it.

This is not an Indonesian story

If it were, it would not be worth writing about. But look at the last two years in fintech and the pattern is hard to miss.

DORA became applicable to European financial entities in January 2025, bringing ICT risk management, incident reporting, resilience testing and third-party risk into scope, with compulsory digital-operational-resilience training for relevant staff. The EU AI Act is phasing in across several years: AI literacy duties have applied since February 2025, transparency obligations apply from August 2026, and the high-risk rules covering recruitment and worker-management systems apply from August 2027. New York City also regulates certain automated employment decision tools through bias-audit and notice requirements.[2],[3],[4]

None of these are the same regulation. All of them do the same thing to your organisation: they change who is in scope, what those people must be able to demonstrate, and what you have to be able to produce on request.

So the useful question is not how to handle the current change. It is what condition your records need to be in so that the next one is administrative rather than existential.

What regulatory change actually asks of your people

Strip the legal language off almost any supervisory change and it resolves into three demands about individuals.

Who holds which role, and since when. Not the job title on the contract. The actual function, the reporting line, the authority to approve or execute, and the date it started. Regulators care about roles because obligations attach to functions rather than to people.

What was assessed before they took it on. Fit-and-proper, competence, background verification, conflicts. And crucially, the evidence of the assessment rather than the fact of it. “We checked” is a claim. A dated record showing what was checked, by whom, against what criteria, is evidence.

What they have been trained on, and whether they understood it. This is where most organisations discover a gap they did not know they had, because a training completion record and evidence of comprehension are different artifacts. A completion log proves attendance. It does not answer the question a supervisor is actually asking, which is whether the person can be relied on to act correctly.

Three demands, all of them about the past, and that is the whole problem.

The lead-time asymmetry

Here is why the people side is the one that catches organisations out, and it is not because it is complicated.

Capital can be raised. Painful, sometimes expensive, and it can be done in weeks if the business is viable.

Systems can be built. Six months, maybe twelve, and you can spend money to compress it. Hire contractors, buy instead of build, run parallel workstreams.

Records of the past cannot be created. If a person was trained in 2023 and nobody recorded what they were trained on, no amount of money produces that record in 2026. If somebody has held a role for two years without a documented assessment, you cannot assess them retroactively as of the date they started. You can assess them now, which leaves a two-year hole that a supervisor will notice.

This is the only category of readiness that money cannot accelerate. It compounds in the wrong direction: every month you operate without recording things properly, the historical gap gets one month wider, and the cost of the eventual remediation goes up rather than down.

A long regulatory runway can look generous for capital and systems. For evidence it is a trap, because the record needed later has to start now.

The hidden problem is role classification

The demand that catches companies most often is the first one, and it looks the most trivial.

Regulatory change almost always redefines the perimeter. A function that was outside scope is now inside it. A threshold moves. A new category of activity is named. And to work out what your new perimeter contains, you need to know what each role in your company can actually do.

Lina Al-Khatib seated behind a laptop in an office
Lina Al-KhatibA role record must be usable without relying on somebody’s memory.

Most fintechs do not know this in any retrievable form. They know it informally, in the heads of the people who granted the access, and they know it in scattered systems: an access management tool, a permissions table, a set of tickets, someone’s spreadsheet.

So when the rules change, determining who is now in scope requires auditing every person individually. That is weeks of work, it produces a snapshot that decays immediately, and it has to be repeated the next time something moves.

The alternative is unglamorous and cheap: record the classification when the role is created and when the person is hired, rather than reconstructing it when someone asks. What can this role access. What can it approve. What obligations attach. Four minutes per requisition, and it converts a recurring audit into a query.

This matters more in fintech than elsewhere because exposure tracks access rather than seniority. A junior developer debugging a failing payment flow may be looking at live transactions, national identification numbers and bank details in their first month. A team lead two levels above them may never open production. Seniority is a poor proxy, and job title is a worse one.

What to do before the next change

Not a compliance programme. Five things, none of which requires a regulatory trigger to justify.

  1. 01

    Record role classification at hire, not at audit

    What the role can reach, what it can approve, and which obligations that triggers. On the requisition, before the person exists.

  2. 02

    Capture assessment evidence at the time

    Whatever you check before someone takes on a role, keep the record of what was checked and against what criteria, with a date. Reconstructing this later produces a story rather than a record, and the difference is visible.

  3. 03

    Make mandatory training produce evidence, not attendance

    For anything where being wrong is expensive, that means the person produces an answer rather than selecting one, and you keep what they wrote. A scored, timed response is an artifact somebody else can evaluate. A tick is not.

  4. 04

    Track expiry as seriously as completion

    Most recurring obligations lapse quietly, because completion has a moment and expiry does not. Anything with a renewal cycle needs a date attached and a warning ahead of it, or your compliance position degrades without anyone noticing.

  5. 05

    Keep it exportable and readable by a stranger

    The test is literal: could you hand this to somebody outside your company, with no explanation, and would they be able to reach their own conclusion? If the answer requires you to be in the room explaining, it is not evidence yet.

Why this is worth doing when nothing is currently forcing it

The honest argument is not that regulation is coming, although in fintech it reliably is.

It is that all five of those things are useful anyway. Knowing what a role can access improves your access management. Assessment evidence makes hiring decisions reviewable. Comprehension evidence tells you which training is not working, which is information you want regardless of who asks for it. Expiry tracking prevents the quiet lapse. And an export a stranger can read is what you need for a customer security review, an investor diligence process or an insurance application, all of which arrive more often than regulators do.

The regulatory case is the one that gets it funded. The operational case is why it does not feel like waste when no supervisor turns up.

The test

Pick one employee who has been with you two years and holds a role that touches something sensitive.

Produce, in ten minutes: what their role can access, what was assessed before they took it, what mandatory training they have completed, when it expires, and evidence that they understood it rather than clicked through it.

If that takes ten minutes, the next regulatory change is a project. If it takes an afternoon and three people, it is a risk. And the difference between those two situations is not how well you understand the rules. It is whether your records were built to be read by somebody else.

Sources

  1. Otoritas Jasa Keuangan. (n.d.). Licensing of financial sector technological innovation, digital financial asset, and crypto asset. https://ojk.go.id/en/fungsi-utama/itsk/perizinan-itsk-aset-keuangan-digital-aset-kripto/default.aspx
  2. European Parliament and Council of the European Union. (2022). Regulation (EU) 2022/2554 on digital operational resilience for the financial sector. https://eur-lex.europa.eu/eli/reg/2022/2554/oj
  3. European Parliament and Council of the European Union. (2024). Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32024R1689
  4. New York City Department of Consumer and Worker Protection. (n.d.). Automated employment decision tools. https://www.nyc.gov/site/dca/about/automated-employment-decision-tools.page

Where CapoFine fits

Make company learning visible before somebody asks for evidence.

Grow supports company-approved learning, role and audience assignment, scheduled learning windows, open-text questions, scenarios, progress and completion visibility. Formal assessments remain a deliberate Grow choice, not the default for every learning activity.

Frequently asked questions

Questions people ask about this topic.

What does a fit-and-proper requirement mean in practice for employees?

It depends on the relevant regime and role. In practice, the organisation needs to be able to demonstrate, for an individual in a relevant role, what was assessed before they took it on, who assessed it, which criteria were used and when it happened. The relevant obligation may attach to a function rather than to a job title.[1]

Which regulatory changes have recently affected fintech staff obligations?

Examples include DORA in the European Union from January 2025, the phased EU AI Act, the transfer of Indonesian crypto supervision from Bappebti to the OJK in January 2025, and New York City rules on some automated employment decision tools. The exact duties depend on the organisation, role, jurisdiction and applicable rule.[1],[2],[3],[4]

Can you retroactively document employee training or assessments?

You can assess or train someone today, but you cannot create a contemporaneous record for a past event. This is why the people side of a regulatory change can have the longest lead time of any workstream.

What is the difference between training completion and evidence of comprehension?

A completion record shows that a person reached the end of a module. Comprehension evidence shows what they understood in a form a third party can evaluate, which can mean retaining an answer rather than only recording a completion mark.

Where should role classification be recorded?

On the role, at the point the requisition is opened, rather than determined when access is requested or reconstructed during an audit. Record what the role can reach, what it can approve and which obligations that triggers.