Skip to main content

RegTech has long since moved from promise to infrastructure. Yet understanding where we stand today requires tracing the path that led here: the regulators’ early intuitions, the data that confirmed them, the models that took shape. This article is a structured recap of that trajectory, from the first experiments with machine readable regulations to the architecture of a truly data-driven compliance.

Table of contents

  1. MDMER: what it is and where it came from
  2. Risks and real-world challenges of machine executable regulations
  3. The EBA and RegTech as a European priority
  4. Automated regulatory intelligence and machine readable regulations
  5. RegTech and GDP: the documented link
  6. The regulation as a platform model
  7. Italian banks and RegTech: the CIPA-ABI report snapshot
  8. A bottom-up approach to regulatory compliance

MDMER: what it is and where it came from

What exactly do we mean by “machine executable regulations”, and where does this idea come from?

MDMER (Model-Driven, Machine Executable Regulations) are regulations designed from the ground up to be understood and executed directly by machines, without the need for prior human interpretation. This is not about digitising a PDF: it is about rethinking the very logical structure of a regulation.

It all began in November 2017, when the FCA (Financial Conduct Authority) and the Bank of England enlisted experts from the UK Government, the private sector and academia to create a proof-of-concept model for implementing machine executable financial regulations. This Tech Sprint introduced the MDMER approach as a response to the need to monitor and analyse thousands of regulatory sources in real time, equipping the banking sector with a tool to keep pace with ever-changing regulatory updates and supporting supervisory authorities in their oversight work.

The EBA (European Banking Authority) subsequently highlighted that regulations would benefit from translation into machine executable form, identifying as the primary advantage the elimination of the need for institutions to interpret legislation that is insufficiently clear, or the risk of misinterpreting it.

That 2017 intuition, then experimental, is today at the centre of European regulatory agendas.

The expected benefits of machine executable regulations

The adoption of machine executable regulations brings concrete benefits across several dimensions. In terms of clarity, they cannot be as ambiguous as typical natural-language regulations. On temporal efficiency, they decrease the time it takes to update, implement and monitor regulatory enforcement. On cost efficiency, they generate immediate savings on the private-sector side by reducing the need for expensive and time-consuming disambiguation, and over time lower the overall cost of monitoring and enforcing regulations on the government side. On change management, they enable regulators to more efficiently distribute regulatory changes to market actors, and allow regulated entities to adapt to those changes more quickly.

The core shift is this: while today regulatory interpretation and disambiguation takes place after a regulation has been promulgated, in a “back-end” phase, MDMER aims to move this burden to the “front-end” with the regulators, achieving full disambiguation at the moment of drafting.

Risks and real-world challenges of machine executable regulations

The MDMER concept is powerful. Its implementation, however, presents concrete obstacles that would be naive to ignore.

Among the most significant technical risks is that of incorrect disambiguation during the coding phase, which could embed interpretive errors directly into the regulations themselves. Added to this are the risk of errors in the code base, a lack of flexibility in adapting to unforeseen circumstances, opacity of the underlying logical mechanisms, and significant versioning challenges when regulations are updated.

The EBA itself, in its response to the European Commission’s consultation of June 2020, noted that implementing this kind of approach would require “rethinking the way regulations are conceived” in order to achieve the standardisation and automation needed for machine executable regulations. The first step would be defining precise rules and logics to use in writing regulations themselves, so that machines receive a code ready to be automatically executed without any further processing.

The same authority had identified, as early as 2017, two possible approaches to implementing MDMER. The first focuses regulatory efforts on validating the model rather than having regulators generate such code themselves. The second involves having regulators translate existing regulations into MDMER themselves, deciding which regulations are made machine executable, in what form, and at what time.

These trade-offs have not yet been resolved systemically at the European level: the path toward fully machine executable regulations remains an open process, even if the tools to move closer to that goal are today far more mature than they were in 2017.

The EBA and RegTech as a European priority

RegTech did not remain a niche topic. From 2021 onwards, the European Banking Authority published its analysis of RegTech in the EU financial sector, confirming with data and research what sector operators already perceived: Regulatory Technology had become a strategic priority for European financial digitalisation.

That analysis was based on a survey conducted between the end of 2020 and the beginning of 2021 on a total of 115 financial institutions from 26 member states and 147 RegTech providers both inside and outside the EEA (European Economic Area). The two groups involved identified distinct but complementary benefits.

Financial institutions that had already adopted RegTech solutions highlighted: enhanced risk management capabilities, better monitoring and sampling capabilities, reduced human error. RegTech providers emphasised: increased efficiency, reduced impact of ongoing regulatory change, improved effectiveness.

The overall level of satisfaction with the value added by RegTech solutions was high: 10% of financial institutions declared themselves “very satisfied” and 60% satisfied. The highest degree of satisfaction was reached by Software as a Service (SaaS) solutions, outperforming both RegTech-as-a-Service and on-premises alternatives. Even the Covid-19 pandemic had not slowed the momentum: the majority of institutions reported no impact on their RegTech project implementation.

The EBA’s role in supporting RegTech adoption

The Factsheets linked to the EBA analysis clarified that RegTech was one of the EBA’s priority topics in its 2020-2021 Digital Finance work programme, in line with Article 31 of the EBA Founding Regulation (EU) No. 1093/2010, which mandates the authority to promote supervisory convergence and facilitate market entry for actors and products relying on technological innovation.

For the near future, the EBA had identified several priority activities: continuing to build knowledge and raise awareness about RegTech within the regulatory and supervisory community, pursuing the harmonisation of the EU regulatory framework, and leveraging the EFIF (European Forum for Innovation Facilitators) alongside national Regulatory Sandboxes and Innovation Hubs to facilitate innovation.

That agenda produced concrete results: today the European debate on digital compliance firmly incorporates RegTech, and more recent frameworks such as DORA and the AI Act were conceived with explicit attention to their technological implementability.

Automated regulatory intelligence and machine readable regulations

Every sphere of economic and social life is governed by regulations that must be understood and applied. This need is especially acute in hyper-regulated sectors such as banking, where the volume of regulatory updates has grown exponentially since the 2008 financial crisis.

The sheer volume of regulatory updates, combined with the inadequacy of traditional analysis tools, had for years weighed entirely on compliance professionals, forcing them into time-consuming manual work that slowed down regulatory transposition at financial institutions. This context made the ability to receive automatic real-time updates no longer optional but essential.

This is why the centralisation of ARI (Automated Regulatory Intelligence) emerged: an approach aimed at automating compliance workflows at the steps where human involvement adds no specific value, freeing time and resources for the decision-making activities that genuinely require professional judgement.

How automated regulatory alerting works

Automation within Regulatory Intelligence focuses on a specific phase of the compliance process: the so-called regulatory alerting, which consists in the collection and analysis of regulatory updates necessary to assess their relevance to any specific financial institution and the possible need to proceed with a risk assessment.

The automatable steps include Regulatory Sensing and Outlook (identifying causes of potential risks from external triggering events such as regulatory changes, or internal ones such as the creation of new products), Legal Inventory Management (updating corporate legal inventories), Regulatory Requirements Update (updating related regulatory requirements), Regulatory Alert (a customised notification system that flags relevant updates), and Impact Analysis (a first impact analysis as a starting point for subsequent compliance steps including Risk Assessment, Gap Analysis, Compliance Plan Update, and Reporting).

One essential point bears repeating: ARI cannot and must not replace human beings in compliance activities. Its purpose is to automate the steps that are currently too slow, not sufficiently accurate, and subject to operational risks, freeing professionals to focus on what genuinely requires their expertise: making quick decisions based on the right information.

Standardisation as a necessary condition

The key that makes ARI possible is the standardisation of regulatory data, and specifically the existence of a machine readable electronic format for financial regulations. Without this foundation, any automation system works on raw, unstructured material, inevitably producing partial results.

Aptus.AI’s proprietary technology transforms legal documents into a standard machine readable format and analyses them through Artificial Intelligence with a holistic approach supporting all regulatory areas, and a multilingual approach covering all languages of the European Union. In a cross-regulatory and cross-country context, this capability makes it possible not only to reduce the time and costs of implementing financial regulatory updates, but also to automatically extract regulatory requirements and obligations. And it does so even on draft documents, offering for the first time the ability to anticipate regulatory trends and develop proactive compliance strategies that support the business.

RegTech and GDP: the documented link

Talking about RegTech also means talking about economic growth. The connection between regulatory quality and macroeconomic performance is documented and quantifiable.

The World Government Summit’s “RegTech for Regulators” report, produced in collaboration with Accenture, placed at the centre of its analysis an uncomfortable but significant truth: the regulatory environment has a direct bearing on the capacity of an industry or an economy to innovate and grow.

The analysis was grounded in a World Bank study of business regulations conducted across 135 countries, concluding that nations with better regulations grow faster. Professor Jamal Ibrahim Haidar of the Paris School of Economics estimated that a business regulatory reform increases the rate of GDP growth by nearly 0.15% on average, confirming a positive correlation between the perception of regulatory quality and GDP per capita for the top 50 economies, accounting for nearly 92% of global GDP.

From compliance cost to competitive advantage

The World Government Summit report defines RegTech as the innovative application of emerging technologies by organisations to adapt to changing compliance requirements more effectively and efficiently, to mitigate risks due to non-compliance, and to gain competitive advantage.

This approach rests on a precise premise: regulations can move organisations to develop new products and services. Conversely, the absence of a supportive regulatory environment limits an economy’s ability to attract investment and grow.

The benefits that RegTech solutions bring to regulators operate at two levels. From an internal perspective: building preventive compliance systems, real-time monitoring, improving supervision through the wealth of available data, narrowing the gap between regulatory intent and practical implementation, and increasing internal process efficiency. From an external perspective: ensuring effective competition, reducing compliance expenditure and complexity, and increasing business innovation and competitiveness through integrated compliance mechanisms that automate regulation interpretation and create self-adapting systems.

Today, with DORA in force for the financial sector and the AI Act advancing, this correlation between regulatory quality and economic competitiveness has become even more tangible: organisations that invested in RegTech in previous years now find themselves with structurally more efficient compliance processes.

The regulation as a platform model

If ARI represents the “how” of automating compliance, the Regulation as a Platform (RaaP) model answers the question of “where” the entire regulatory ecosystem is heading.

RaaP identifies a holistic approach in which regulators collaborate with businesses, government bodies and citizens to drive innovation and improve compliance outcomes. This is not an abstract scenario: the first operational prototypes were already active in the early 2020s.

The most advanced example cited in the World Government Summit report is the prototype developed in Australia by Data61, part of the Commonwealth Scientific and Industrial Research Organization (CSIRO). This proof-of-concept aimed to provide free and open access to legislation and regulation through public APIs, enabling users to access a database of logical rules and a reasoning engine to process rules and data in an accessible digital logic.

The process included converting regulations into digital logic, expert review by policy specialists and regulators to ensure the digital logic represented the intent of the law, and final publication on the RaaP prototype by the regulatory authorities.

The concrete benefits of the RaaP model for organisations

Combining the Regulation as a Platform model with existing data and analytics enables the development of innovative risk management platforms. The benefits for organisations operate at three levels.

The first concerns awareness: greater understanding of significant events affecting multiple areas of an organisation, helping to reduce operational ambiguity and risk, particularly in financial services firms. The second concerns alerting: a system that assigns a risk score and notifies responsible parties in real time, introducing an element of certainty and traceability into enterprise risk management. The third concerns action: the ability to take appropriate measures based on the risk score and the actionable guidance produced by the combination of the technological solution and human judgement.

The RaaP model is no longer theoretical: the architecture of platforms like Aptus.AI embodies its core principles, making machine readable regulations accessible and structurally analysable for compliance and legal professionals.

Italian banks and RegTech: the CIPA-ABI report snapshot

The Italian context offers a telling perspective: growing digital maturity in the banking sector on the front of user experience and cyber security, coupled with a specific lag in RegTech adoption that the market itself had begun to acknowledge by 2022.

The “Survey on IT in the Italian banking sector” produced by CIPA (Interbank Convention for Automation) and ABI (Italian Banking Association) photographed the state of digital transformation in the sector on an annual basis. The 2022 report examined responses from 20 banking groups covering 93% of the sector’s total assets, and 4 individual banks, with reference to 2021 and expected future developments.

The growth of SaaS in Italian banking

On the general digitalisation front, the data were unambiguous: 58% of respondent banks were already using cloud services in 2021, while 29% had already initiated a migration process. The most widely adopted model, used in 70% of cloud service cases, was the Software-as-a-Service model, with further growth projected over the long term.

RegTech still underrepresented in the Italian banking agenda

The other side of the picture concerned Regulatory Technology specifically. The entire Governance area, which includes banking compliance, remained a step behind the technology-intensive areas of customer experience, cyber security, and payments management. RegTech solutions were not yet among the top priorities of Italian financial institutions.

By 2026, that picture has already begun to change: the regulatory pressure of DORA, the AI Act, and ESG frameworks has accelerated the internal conversation about RegTech within Italian banks. The gap relative to Anglo-Saxon markets remains, but has narrowed, and the adoption of structured RegTech solutions is now a stated priority in many of the sector’s digital transformation plans.

A bottom-up approach to regulatory compliance

The transformation of financial compliance does not have to come from above. The data and analyses gathered throughout this article converge on a conclusion shared by institutions and operators alike: innovation can also emerge from below, through technological solutions that demonstrate their value in practice before regulatory frameworks make them mandatory.

This is precisely the position expressed by the Deputy Director General of the Bank of Italy, Alessandra Perrazzelli, in reference to the first Call for Proposals of the Fintech Milano Hub, which had selected Aptus.AI among its most relevant projects: the regulatory approach, particularly in a scenario where technological evolution is pushing the supply of new services ever faster, can be shaped not only top-down but also bottom-up.

That statement, made in an experimental context, describes today the very mechanism through which RegTech has effectively established itself: not through a uniform regulatory mandate, but through progressive adoption by operators who recognised in structured regulatory data and machine readable regulations a concrete tool for efficiency and risk control.

The journey traced in this article, from the MDMER concept of 2017 to the EBA analysis of 2021, from the RaaP model to the CIPA-ABI report, is not an archive. It is the map of a transformation still in progress.