Beyond Compliance: Lowering The Cost Of Regulatory Change

Direct Source Verification: This story is aggregated from Forbes (forbes.com). Full reporting rights and copyright belong to the primary publisher.
Often, the regulations themselves are less of a challenge than the fact that many organizations try to comply with each regulation individually. ​

Ann Blakely is the managing principal of Baker Tilly’s digital solutions practice, with a focus on modernizing legacy business models.

gettyRegulatory change has become a constant for organizations across every industry. New reporting requirements, evolving compliance standards and heightened expectations around data security, transparency and governance are arriving frequently.​

Often, the regulations themselves are less of a challenge than the fact that many organizations try to comply with each regulation individually. ​

Many organizations respond to each new requirement as a discrete project: Implement a point solution, create a spreadsheet, add a manual control or modify an existing system. The immediate requirement gets addressed, but another layer of complexity is added.​

Over time, these decisions create regulatory technical debt: technology and process complexity created by solving requirements individually rather than building capabilities that can be reused. Organizations spend more time finding and reconciling data, modifying integrations and redesigning controls, steadily increasing the cost of change.

While organizations cannot predict every new regulation, they can prepare for the certainty that requirements will continue to change. That means asking not only whether an investment satisfies today’s requirement, but whether it makes the next change easier or harder.

Investments in shared data, configurable platforms, reusable controls and automation can meet today’s regulatory needs while making future changes faster and less expensive. The best regulatory investments leave the enterprise more adaptable than they found it.

Baker Tilly provides technology and modernization services in these areas, and these recommendations reflect our experience helping organizations navigate regulatory change. ​

Regulatory requirements change, but the need for reliable data does not. Integrated data architectures and strong governance can provide a trusted organizational view of information that supports multiple reporting, compliance and business needs.

Instead of repeatedly finding, reconciling and validating data, organizations can build data capabilities once and reuse them. Clear ownership and consistent data definitions are critical to making that foundation trustworthy across functions.

Highly customized technology environments often make regulatory changes slower and more expensive. Configurable cloud platforms, modular architectures and standardized integrations allow organizations to change processes and reporting without extensive redevelopment.

The goal is not simply modernization. It is optionality: making future changes easier to absorb. Leaders should weigh immediate customization needs against the complexity they may create for future changes.

Manual reporting, approvals and reconciliation increase cost and risk. Automation can improve consistency while freeing teams to focus on higher-value analysis.

Organizations can also design controls and workflows that can be adapted across multiple requirements rather than rebuilding them each time. Standardizing processes before automating can help to avoid embedding existing inefficiencies.

Compliance should not be managed solely as a sequence of projects. Organizations that continuously modernize their technology, data and processes are better positioned to respond as requirements change.

Doing so requires sustained coordination across technology, compliance, risk and business teams. The question becomes not only, “Are we compliant today?” but also, “How difficult will it be for us to change tomorrow?”

Artificial intelligence makes this shift even more important. AI is simultaneously creating new regulatory complexity and becoming a powerful tool for managing it.

As organizations embed AI into more business processes, leaders face evolving expectations around privacy, transparency, explainability, data governance, model risk, third-party oversight and human accountability.

At the same time, AI can help organizations interpret changing requirements, identify affected data and processes, monitor controls, detect anomalies and accelerate regulatory reporting and analysis.

Organizations need strong technology, data and governance foundations to manage AI-related risks.​ With those foundations in place, AI itself can help organizations manage regulatory change more efficiently.

As a trusted advisor across tax, advisory and assurance, serving thousands of clients in highly regulated industries, we find the principle is consistent across industries, but the opportunity looks different by sector.

• Financial Services: For mid-market banks and credit unions, AI is moving rapidly into core business processes. Creating a separate governance process for every use case risks adding more complexity. A scalable approach applies governance models across use cases according to risk, complexity and institutional size.

• Healthcare: Healthcare organizations manage clinical, operational and financial information across complex technology environments. Investments in interoperability, data governance and scalable infrastructure can support regulatory requirements while creating the trusted data foundation needed for analytics, AI and new models of care.

• Public Sector: Government agencies routinely respond to changing reporting requirements, grant standards, funding rules and policy priorities. Modern cloud platforms, integrated data and configurable processes can allow new requirements to be incorporated without repeatedly rebuilding systems and processes.

• Higher Education: Higher education institutions are expanding AI while navigating evolving expectations around privacy, transparency and responsible use. Institutions can embed responsible AI into existing academic, administrative and governance processes rather than creating isolated initiatives that add complexity.

No organization can know exactly what the next regulation will require. But leaders can determine whether today’s investments will make the organization better prepared when it arrives.

They should ask whether they are solving requirements in ways that can be reused, eliminating or adding regulatory technical debt, building adaptable technology and automating repetitive compliance work. Most importantly: Are today’s technology investments lowering the organization’s future cost of change?

The organizations best prepared for regulatory change will not necessarily be those that spend the most on compliance, but those that get the most enduring value from every regulatory dollar they spend.

Instead of funding one-off compliance projects, they will use regulatory requirements as catalysts to simplify technology, strengthen data, automate controls and create reusable capabilities.

That changes the objective from complying with the next regulation to building an organization that is continuously ready to change.​​

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Original Source
https://www.forbes.com/councils/forbestechcouncil/2026/10/02/beyond-compliance-lowering-the-cost-of-regulatory-change/
Visit Forbes ↗
SHARE STORY:
𝕏 f in

Related Coverage in Business