Grow·Article
When the rules change, your staff records are the slowest thing to fix
Fintech regulation keeps moving. Capital can be raised and systems can be built, but evidence of what an employee was assessed on or understood cannot be recreated after the fact.
In January 2025, crypto supervision in Indonesia moved from Bappebti, the commodity futures regulator, to the OJK, the financial services authority. On paper that is an administrative transfer. In practice it is a change of regime.[1]
OJK Regulation 27/2024 set requirements for digital-financial-asset and crypto-asset trading, including licensing, governance, risk management and consumer protection. The governing framework has since been amended, so organisations need to work from the current applicable rule and licensing guidance.[1]
Most of the companies affected treated this as three projects: a legal project, a capital project and a systems project. The fourth one, the people project, tends to get discovered late. And it is the one with the longest lead time.

This is not an Indonesian story
If it were, it would not be worth writing about. But look at the last two years in fintech and the pattern is hard to miss.
DORA became applicable to European financial entities in January 2025, bringing ICT risk management, incident reporting, resilience testing and third-party risk into scope, with compulsory digital-operational-resilience training for relevant staff. The EU AI Act is phasing in across several years: AI literacy duties have applied since February 2025, transparency obligations apply from August 2026, and the high-risk rules covering recruitment and worker-management systems apply from August 2027. New York City also regulates certain automated employment decision tools through bias-audit and notice requirements.[2],[3],[4]
None of these are the same regulation. All of them do the same thing to your organisation: they change who is in scope, what those people must be able to demonstrate, and what you have to be able to produce on request.
So the useful question is not how to handle the current change. It is what condition your records need to be in so that the next one is administrative rather than existential.
What regulatory change actually asks of your people
Strip the legal language off almost any supervisory change and it resolves into three demands about individuals.
Who holds which role, and since when. Not the job title on the contract. The actual function, the reporting line, the authority to approve or execute, and the date it started. Regulators care about roles because obligations attach to functions rather than to people.
What was assessed before they took it on. Fit-and-proper, competence, background verification, conflicts. And crucially, the evidence of the assessment rather than the fact of it. “We checked” is a claim. A dated record showing what was checked, by whom, against what criteria, is evidence.
What they have been trained on, and whether they understood it. This is where most organisations discover a gap they did not know they had, because a training completion record and evidence of comprehension are different artifacts. A completion log proves attendance. It does not answer the question a supervisor is actually asking, which is whether the person can be relied on to act correctly.
Three demands, all of them about the past, and that is the whole problem.
The lead-time asymmetry
Here is why the people side is the one that catches organisations out, and it is not because it is complicated.
Capital can be raised. Painful, sometimes expensive, and it can be done in weeks if the business is viable.
Systems can be built. Six months, maybe twelve, and you can spend money to compress it. Hire contractors, buy instead of build, run parallel workstreams.
Records of the past cannot be created. If a person was trained in 2023 and nobody recorded what they were trained on, no amount of money produces that record in 2026. If somebody has held a role for two years without a documented assessment, you cannot assess them retroactively as of the date they started. You can assess them now, which leaves a two-year hole that a supervisor will notice.
This is the only category of readiness that money cannot accelerate. It compounds in the wrong direction: every month you operate without recording things properly, the historical gap gets one month wider, and the cost of the eventual remediation goes up rather than down.
A long regulatory runway can look generous for capital and systems. For evidence it is a trap, because the record needed later has to start now.
What to do before the next change
Not a compliance programme. Five things, none of which requires a regulatory trigger to justify.
- 01
Record role classification at hire, not at audit
What the role can reach, what it can approve, and which obligations that triggers. On the requisition, before the person exists.
- 02
Capture assessment evidence at the time
Whatever you check before someone takes on a role, keep the record of what was checked and against what criteria, with a date. Reconstructing this later produces a story rather than a record, and the difference is visible.
- 03
Make mandatory training produce evidence, not attendance
For anything where being wrong is expensive, that means the person produces an answer rather than selecting one, and you keep what they wrote. A scored, timed response is an artifact somebody else can evaluate. A tick is not.
- 04
Track expiry as seriously as completion
Most recurring obligations lapse quietly, because completion has a moment and expiry does not. Anything with a renewal cycle needs a date attached and a warning ahead of it, or your compliance position degrades without anyone noticing.
- 05
Keep it exportable and readable by a stranger
The test is literal: could you hand this to somebody outside your company, with no explanation, and would they be able to reach their own conclusion? If the answer requires you to be in the room explaining, it is not evidence yet.
Why this is worth doing when nothing is currently forcing it
The honest argument is not that regulation is coming, although in fintech it reliably is.
It is that all five of those things are useful anyway. Knowing what a role can access improves your access management. Assessment evidence makes hiring decisions reviewable. Comprehension evidence tells you which training is not working, which is information you want regardless of who asks for it. Expiry tracking prevents the quiet lapse. And an export a stranger can read is what you need for a customer security review, an investor diligence process or an insurance application, all of which arrive more often than regulators do.
The regulatory case is the one that gets it funded. The operational case is why it does not feel like waste when no supervisor turns up.
The test
Pick one employee who has been with you two years and holds a role that touches something sensitive.
Produce, in ten minutes: what their role can access, what was assessed before they took it, what mandatory training they have completed, when it expires, and evidence that they understood it rather than clicked through it.
If that takes ten minutes, the next regulatory change is a project. If it takes an afternoon and three people, it is a risk. And the difference between those two situations is not how well you understand the rules. It is whether your records were built to be read by somebody else.
Sources
- Otoritas Jasa Keuangan. (n.d.). Licensing of financial sector technological innovation, digital financial asset, and crypto asset. https://ojk.go.id/en/fungsi-utama/itsk/perizinan-itsk-aset-keuangan-digital-aset-kripto/default.aspx
- European Parliament and Council of the European Union. (2022). Regulation (EU) 2022/2554 on digital operational resilience for the financial sector. https://eur-lex.europa.eu/eli/reg/2022/2554/oj
- European Parliament and Council of the European Union. (2024). Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32024R1689
- New York City Department of Consumer and Worker Protection. (n.d.). Automated employment decision tools. https://www.nyc.gov/site/dca/about/automated-employment-decision-tools.page
Where CapoFine fits
Make company learning visible before somebody asks for evidence.
Grow supports company-approved learning, role and audience assignment, scheduled learning windows, open-text questions, scenarios, progress and completion visibility. Formal assessments remain a deliberate Grow choice, not the default for every learning activity.

