SFA, KPMG: Governance Slows Asia RegTech Cloud Adoption
A new report from the Singapore FinTech Association and KPMG reveals operational and accountability issues, not technology, slow financial institutions scaling cloud-based RegTech in Asia-Pacific.

Governance, Not Tech, Is the Barrier
The Singapore FinTech Association (SFA) and KPMG in Singapore found that governance and operational challenges, not technological limits, primarily hinder financial institutions (FIs) in Singapore and across Asia-Pacific from expanding cloud-based regulatory technology (RegTech).
Their joint report gathers insights from FIs, RegTech providers, and the Monetary Authority of Singapore (MAS). It notes FIs often struggle to translate regulatory principles into daily practice, establish clear accountability among diverse providers, and maintain cloud-native compliance systems. Some 77% of RegTech firms surveyed favour cloud-native deployment.
The MAS clarified in 2016 that FIs may use cloud services provided they implement strong governance and risk management.
Accountability Remains with Institutions
The report observes that while the principle of shared responsibility for cloud security is widely understood, its practical application remains uneven. This challenge intensifies as institutions move from basic infrastructure services to more complex Software-as-a-Service (SaaS) and AI-driven offerings.
Here, the division between provider-managed and customer-owned controls becomes less distinct. Regardless of outsourcing, accountability for risk and security ultimately rests with the financial institution, including its board and senior management. This aligns with the MAS’ Technology Risk Management (TRM) Guidelines and its Guidelines on Outsourcing.
The report proposes a risk-tiered operating model to help FIs classify workloads and define responsibilities, from design through to exit.
Institutional Readiness Gaps
A significant 94% of RegTech providers surveyed reported encountering hesitancy from financial institutions regarding cloud adoption. The reasons cited point to institutional readiness rather than the technology itself. Persistent gaps exist in foundational controls, including identity and access management, logging, network segmentation, and data governance.
A shortage of skilled talent in cloud security and AI also slows progress. System integrators noted that FIs frequently underestimate the data engineering required for cloud projects. They highlighted that procurement and security approval processes often delay initiatives, leaving internal teams without the necessary skills to operate new solutions post-integration.
Streamlining RegTech Deployment in Asia
Data residency and cross-border regulatory requirements continue to influence architectural decisions. FIs prefer to keep personally identifiable information in-house or use tokenisation for data movement.
Although regional deployment models and advanced encryption can address many sovereignty concerns, providers note these solutions are underused due to firms' uncertainty about supervisory views. The report identifies the main challenge as translating regulatory intent into practical operating models, particularly for AI applications.
To accelerate adoption, financial institutions could streamline due diligence by consistently applying existing certifications like SOC 2 and ISO 27001, which 94% of RegTech firms already hold, potentially reducing current assessment costs.
This article is journalism, not investment advice; consult a licensed professional before making financial decisions. Market data is indicative, may be delayed, and should be verified with your broker or exchange before use.
Comments.
Comments are moderated. We remove what is unlawful, abusive or off-topic, and and you remain responsible for what you post.
Reader comments open soon. Until then, corrections and responses go to our newsroom, and we publish what we get wrong on Corrections.