Skip to content
← Library Technology

Budgeting for an Expanding Control Surface

The strongest compliance budgets give firms room to respond when markets, products and employee behavior change faster than expected.

Across several current conversations, compliance leaders are building investment cases before business plans, policies and control requirements are settled. Annual budgets reward certainty, but emerging risks don't provide any.

Prediction markets, digital assets, tokenized securities, new wrappers and AI-driven activity are changing how firms and employees gain economic exposure, encounter sensitive information and create conflicts. Together, they expand the control surface - the activities, information flows and behaviors a firm must govern.

Business activity is moving now, and today’s funding decisions will determine whether compliance can keep up next year.

Markets Do Not Follow Budget Cycles

Budget requests favor risks the firm already understands. Emerging risks may lack settled regulation, stable product definitions or reliable activity data. Compliance may be unable to quantify exposure because existing systems cannot see it.

Waiting for clarity can feel prudent. But a risk does not remain unfunded just because it was difficult to quantify during budget season. The goal is not to predict every new product or rule. (Forgive the pun!) The goal is to identify which control capabilities the firm will need across several plausible scenarios.

Do Not Turn Every New Risk Into Another Build

New markets don'r create one isolated requirement. There are many variables to account for - new employee accounts on unfamiliar platforms, activity outside existing data feeds, new MNPI vectors and business access to client positions, order flow or firm trading intentions.

The impacts cross personal trading, control-room processes, information barriers and surveillance. Yet firms often fund only the most visible gap: another policy category, system extension or custom workflow.That approach may be necessary but it really shouldn’t be automatic.

More investment in yesterday’s architecture only makes it more expensive to leave. Legacy systems require integration, testing, documentation and maintenance. Their logic may depend on a few developers who understand years of custom rules and exceptions. When they leave, a staffing problem can become a control problem.

Vendors create dependencies too, including concentration and limits on customization. But construction by default is not a strategy, and vendors with broad client bases are stress-testied continuously by hundreds of firms. Plus vendor roadmaps receive robust input from across the capital markets spectrum..

Fund Capabilities, Not Assumptions

Before approving another extension to existing controls, leaders should ask what the control environment must be able to do:

Identify relevant activity across products, venues and wrappers Adapt policies and surveillance rules without a lengthy development cycle Connect employee activity with firm-side information and conflicts Incorporate new data sources without destabilizing existing workflows Reconstruct decisions, exceptions and escalations when challenged Operate without concentrating knowledge in a handful of people

The answers may lead to internal development, specialist technology or both. The distinction is between purposeful construction and construction by default.

Institutions must own their policies, risk decisions and control outcomes. They do not need to own every component supporting them.

Count What the Firm Gives Up and Budget for the Next Market, Too

Internal development carries an opportunity cost doesn't show up in the project estimate. Technology and AI talent are finite. Resources assigned to compliance infrastructure cannot be used elsewhere. That does not make compliance less important. It makes the allocation decision more important.

Everyone knows a large institution can build systems. The question becomes whether rebuilding capability that's already available in the market is the best use of scarce talent and capital - particularly when that capability does not differentiate the institution.

A credible request should address more than software. Compliance may need data access, integration, implementation funding, policy development and clear ownership. Architecture matters, but it cannot compensate for fragmented accountability or unresolved policy. No compliance leader can predict every risk that will emerge during the next planning cycle. The stronger objective is to reduce the time, cost and disruption required to respond when one does.

A budget can close today’s gap while committing the firm to tomorrow’s limitation. Or it can create the adaptability, visibility and accountability needed for whatever arrives next.

That is the real budgeting decision.

Comments (0)