Opening contribution…
Opening contribution…
YYnamed18 September 2026
AI summary · What this changes
Proposal replaces "Regtech / suptech" with "Regtech / suptech and other terms reflect digital oversight tools"
This proposal modifies the Rules Clarity & Comprehensiveness pillar by replacing the term "Regtech / suptech" with expanded language "Regtech / suptech and other terms reflect digital oversight tools". The change adds clarification that these terms encompass digital oversight tools more broadly, moving from a narrow definition to one that explicitly includes related digital oversight terminology and concepts.
Author’s reasonI think it is helpful to be relatively broad to encompass private governance as well
On the board and under discussion. Nothing in the methodology has changed.
From the moderators
Testing the system
01 · Edit · p01.s1019
reworked · 7 words in
Regtech / suptech and other terms reflect digital oversight tools
Full recorded document context, including this proposal’s other changes. Surrounding passages use their current wording. Edits against older wording are marked separately.
Preview only. Red strikethrough marks removals; green underlining marks additions. Unchanged passages remain in place.
Whether the rules can be read and relied on: a perimeter defined in law, mandates that name their holder, and expectations written down rather than passed on in meetings.
This pillar asks a plain question. Can a firm read the law and work out who regulates it, for what, and under what authority? Most of the friction in fintech regulation is not disagreement about policy. It is uncertainty about which body holds the pen.
It covers the definition of the perimeter, the allocation of mandates between agencies, the instrument that grants each mandate, the process by which any of it changes, and the written expectations that supervised firms are actually held to. It does not assess whether the arrangement is centralised or dispersed. Both work. What matters is that it is published, stable, and does not require a relationship with the regulator to understand.
Scores here move slowly. A jurisdiction that reorganises its financial supervision every few years will score lower than one with an older but settled arrangement, because predictability is the thing being measured.
Covers what activities need authorisation, how supervisory mandates are allocated and published, how the perimeter changes, and whether every binding rule traces back to the provision that enables it. Excludes the policy content of the rules themselves, institutional architecture where the allocation is published and stable, and legislative speed.
Rules Clarity and Comprehensiveness (RCC) measures whether a jurisdiction's fintech-relevant rules are findable and understandable, and complete enough to cover common fintech activities and risks, in a way that a regulated firm, or a prospective entrant, can determine what licence it needs, what obligations apply, and how to comply, using publicly available materials.
This is not a friendliness or deregulatory score. It does not reward laxity. It rewards clarity, coherence, and coverage of the fintech rulebook itself.
The set of activities that require authorisation, and the instrument that defines them
Allocation of supervisory mandates, including published tie-breaks for overlap
Process for changing the perimeter: notice, consultation, commencement
Traceability from each binding rule to its enabling provision
Written supervisory expectations and their version history
Reporting requirements specified to the field level
The substantive policy content of the rules themselves
Institutional architecture, provided the allocation is published and stable
Legislative speed, which is a political question rather than a clarity one
Accessibility and usability
Definitions and perimeter clarity
Coverage and completeness
Consistency, change management and interpretive support
Weights are a starting point. The working group may revise them with documented rationale, which means they are open to an edit too.
A framework published only in the national language scores the same as one published in English. Practical access for foreign entrants is not captured here.
Where a consolidated rulebook trails recent instruments, the assessment reads the consolidated version and may miss very recent change.
Pillar definition
Eight indicators, RCC-1 to RCC-8. This is the working group's draft text. Select any passage to suggest an edit.
Rules Clarity & Comprehensiveness (RCC) measures whether a jurisdiction’s fintech‑relevant rules are:
Findable and understandable (“clarity”), and complete enough to cover common fintech activities and risks (“comprehensiveness”), in a way that a regulated firm, or prospective entrant, can determine what licence it needs, what obligations apply, and how to comply, using publicly available materials.
This is not a “friendliness” or deregulatory score. It does not reward laxity; it rewards clarity, coherence, and coverage of the fintech rulebook itself.
Scope and boundaries
In scope (fintech‑relevant rule corpus):
Primary laws and regulations covering:
Core: Payments / payment systems / e-money Banking / lending / credit Securities / investment / advice / management Insurance Digital assets: custody, issuance of crypto tokens / asset tokenisation / stablecoins, crypto‑asset services (if applicable) Subareas within core: Regtech / suptech Digital banking / fintech licensing / regulation digital lending / BNPL Roboadvisory / automated trading Financial infrastructure / trading systems Data analytics / AI Internal IT systems Crowdfunding (if applicable)
Cross‑cutting supervisory requirements that materially affect fintech operations, including:
Core: AML/CFT / (e)kyc Data protection Data use / portability / consent in financial services Identity Subareas: Outsourcing / cloud Cybersecurity Operational resilience Safeguarding of funds Market conduct requirements
Out of scope:
Ecosystem outcomes (e.g. investment levels, number of fintechs). Enforcement “toughness” (except as it affects interpretive clarity and transparency). Broader “quality of regulation” debates unrelated to clarity or coverage.
RCC evaluates the quality and navigability of the rulebook as a rulebook, not the substantive policy stance or outcomes.
Scoring conventions and evidence rule
RCC uses a 0–3 evidence‑based scale:
0 = Opaque / materially unclear: key requirements are hard to find, ambiguous, contradictory, or not operational. No regulation at all.
1 = Partially clear: some guidance exists but significant ambiguity or gaps remain, creating material uncertainty for common models. Advisory / policy statements etc, providing some level of clarification. Role of supervisory processes.
2 = Clear and workable: most relevant rules are findable and understandable; some gaps or fragmentation remain.
3 = Highly clear, coherent, and comprehensive: rules are well‑organised, well‑defined, publicly accessible, consistently explained, and cover the core fintech perimeter with clear compliance pathways.
Across the RCC matrix, a score of 3 should normally require all of the conditions for a 2, plus evidence that the framework is clearly organised and easy to navigate. In practice, this should usually mean that a firm can see how the relevant pieces fit together through a clear official entry point such as a portal, consolidated handbook, licensing map, rulebook structure, or equivalent public navigational tool.
For any score of 3, the evidence log should normally include at least:
a public navigational or mapping tool (for example, portal, handbook, licensing map, or guidance that helps users find obligations), and at least one public binding instrument (law, regulation, rulebook or equivalent) supporting the underlying obligations.
Every score must be supported by public sources (laws / regulations, regulator handbooks, licensing pages, official FAQs / guidance, consultation documents, official portals, policy statements / judicial decisions etc.). “Reputation” or private information cannot be used as evidence.
Conduct of review
The initial review will typically be undertaken as a desk review process. Ideally, it will be followed by direct engagement with participants, similarly to other international standards review processes.
For purposes of FRFI scoring, the RCC Working Group has adopted the following definition of Fintech:
“Fintech businesses use existing or new technology via centralised or decentralised systems to disrupt, to reimagine, to expand a services offering, to create financial instruments, to inhabit a niche, or to offer new ways for people to participate in their financial lives, either directly or through existing financial services providers, from a business, sales, information, analytics, product, regulatory or risk management standpoint.”
This definition is intentionally broad and inclusive. It encompasses new entrants and legacy players, retail and institutional services, and both the provision of financial services directly to end users and the provision of technology that enables others to provide such services. It covers activities conducted on both centralised systems (traditional software, cloud infrastructure) and decentralised systems (blockchain, distributed ledger technology).
A regulatory framework that does not keep pace with new technologies and fintech business models slows the realisation of these potential benefits, by creating uncertainty and friction around licensing, obligations, and compliance
Implication for Scoring: The Regulatory Status Problem
A critical feature of this definition is that it deliberately spans the full spectrum of regulatory status. Fintech businesses as defined above may be:
Category A, Directly Regulated: The firm itself holds a license or registration and is subject to direct regulatory obligations. Forward looking approach. Category B, Unregulated: The firm’s activities do not trigger a licensing or registration requirement and the firm is not subject to direct regulatory obligations. Category C, Unregulated but Indirectly Regulated: The firm is not itself licensed or registered, but provides services to a regulated entity that enable regulated functions, and as a result is subject to regulatory requirements imposed through the regulated entity’s obligations via outsourcing rules, vendor management requirements, or contractual terms imposed by regulatory compulsion.
This three-way distinction creates the following two scoring challenges.
First, for firms in Category B: how does the regulatory framework communicate to an unregulated FinTech firm that it is unregulated, and do so with sufficient clarity that the firm can rely on that determination? A firm that is simply silent in the regulatory framework faces uncertainty, which is itself a form of regulatory unclarity. A well-functioning regulatory environment provides clear negative perimeter guidance, affirmative statements about what is not regulated, not just positive licensing requirements.
Second, for firms in Category C: how does the regulatory framework communicate to an indirectly regulated FinTech firm what obligations flow to it through its regulated clients, and does it do so in a way that is publicly accessible and operationally usable? This category is growing rapidly as regulators extend supervisory reach to critical third-party technology providers, and the clarity, or lack thereof, of those indirect obligations is a material issue for FinTech firms operating as vendors to the regulated sector.
These are addressed through the indicators in the instructions and considerations .
Why this Distinction Matters for RCC
Regulatory regimes differ fundamentally in how they express obligations, and this difference has direct consequences for how RCC indicators should be scored. The RCC pillar measures whether a jurisdiction’s fintech-relevant rules are clear, findable, and complete. But “clear” means something different depending on the regulatory philosophy underlying the framework being assessed. Scorers who fail to account for this distinction will systematically undervalue sophisticated principles-based systems and overvalue prescriptive rules-based systems that may in practice be less navigable.
Rules-Based Regimes
A rules-based regime specifies obligations in precise, detailed terms. It tells regulated firms exactly what they must do, when, how, and in what form. Typical features include numerical thresholds, prescribed reporting formats, mandatory contract terms, defined timelines, enumerated prohibited activities, and specific procedural requirements. The firm’s compliance question is essentially binary: did it follow the specified rule or not?
Rules-based regimes are strong on operational clarity: a firm generally knows exactly what it must file, in what format, and by when. Their limitation is that detailed rules can become outdated quickly as technology and business models evolve, may produce compliance-with-the-letter-but-not-the-spirit behaviour, and can create rigidity that impedes legitimate innovation.
Principles-Based Regimes
A principles-based regime specifies obligations in terms of outcomes or standards of conduct, leaving firms to determine how to achieve them. It tells regulated firms what to achieve, treat customers fairly, maintain adequate capital, manage risk prudently, act with integrity, without dictating the specific means. The firm exercises judgment about how to comply.
Principles-based regimes are strong on outcome clarity: a firm generally knows what standard it is expected to meet and what objective it is expected to achieve. Their limitation is operational ambiguity: a firm may understand perfectly well that it must “treat customers fairly” while remaining genuinely uncertain about whether a specific product feature, disclosure format, or complaint-handling procedure satisfies that obligation. In a principles-based system, that operational content is typically supplied not by the rules themselves but by supplementary interpretive mechanisms, supervisory guidance, published case studies, regulatory speeches, enforcement decisions, and FAQs, which accumulate over time to give the principles practical meaning.
Outcomes-based Regimes
An outcomes-based regime focuses on a particular set of results. The system is then designed to achieve the results which are being targeted.
Such systems - to be effective - must have clear outcomes. Those outcomes must then be clearly tied to the elements of the regulatory system. [add example]
Merit-based Regimes
Merit-based regimes focus on qualitative results: decisions are based on intentions. A merit-based regime may thus be similar in some ways to an outcome based system. However, an outcome based system typically seeks objective results while a merit-based system targets more subjectively. An outcome based system may target “better quality financial products and services” while a merit-based system may target “good financial products and services”.
Merit-based systems often lack clarity of merits being targeted. For clarity, a merits-based regime would need to have clear targets enabled by a regulatory system designed to achieve those targets.
The Spectrum in Practice
Real regulatory systems sit at various points on a spectrum between these categories and most are hybrids. A jurisdiction may use principles for conduct and outcomes while using precise rules for technical requirements such as capital ratios, prescribed reporting taxonomies, and defined timelines for complaint resolution. The UK’s FCA Handbook is a well-known example of a sophisticated hybrid: it contains both high-level principles (the FCA’s Principles for Businesses) and highly detailed prescriptive rules. The EU’s approach under MiCA tends toward greater prescriptiveness. The US operates differently again, with some agencies using a mix of principles and rules while others rely more heavily on supervisory guidance.
How This Affects RCC Scoring
The key analytical point for RCC scoring is this: a principles-based regime can be highly clear on outcomes while being less clear on operations; a rules-based regime tends toward the opposite: clearer on operations but potentially less adaptable and less clear on the underlying purpose of the obligation. To be effective, an outcomes or a merit based regime must have clear outcomes or targets and a system designed to achieve these. No approach is inherently superior from a clarity standpoint, and the FRFI does not take a position on which regulatory philosophy produces better outcomes. What the FRFI measures is how well each jurisdiction achieves clarity within its own chosen approach, and whether the mechanisms it uses to supply operational content are adequate for a regulated firm to determine and implement its obligations.
This has three practical consequences for scoring:
Multiple paths to a high score exist. For indicators where this tension arises, principally RCC-2, RCC-4, RCC-5, RCC-6, and RCC-7, a jurisdiction can reach a score of 3 via a rules-based path, a principles-based path, an outcomes-based path or a merits-based path. The evidence required differs and these paths are specified explicitly in the affected indicators. A principles-based regime should not receive a 3 solely because the underlying principles are well expressed at a high level. A 3 requires that those principles be made operationally usable through a sufficiently mature public interpretive infrastructure, for example through FAQs, speeches, case studies, examples, supervisory statements, enforcement summaries, or equivalent materials that show how the principles are applied in practice. RCC-6 carries greater weight in principles-based systems. In a rules-based system, the rules themselves supply operational content. In a principles-based system, that content is supplied through guidance, FAQs, supervisory statements, and enforcement precedent. For principles-based jurisdictions, RCC-6 is the mechanism by which principles acquire operational clarity. Scorers should read RCC-5 and RCC-6 together for principles-based jurisdictions. Scorers must identify the regulatory philosophy before scoring and note it in the evidence log. This affects both the evidence sought and the rubric path applied. See Section 7 (Evaluator Instructions) for the required procedure.
Sub-dimension: Weight / Indicators A: Accessibility & Usability: 20%: RCC-1, RCC-2 B: Definitions & Perimeter Clarity: 30%: RCC-3, RCC-4, RCC-8, RCC-9 C: Coverage & Completeness: 30%: RCC-4, RCC-5 D: Consistency, Change Management & Interpretive Support: 20%: RCC-6, RCC-7
Working Group decision required on whether to adjust weights following addition of RCC-8 and the elevated importance of RCC-6 in principles-based systems. [Weights are indicative and subject to revision; there is no strict scientific basis for their distribution.]
RCC currently uses eight core indicators. The detailed objective-trigger tables in Section 4 specify how to score 0–3; this overview summarises the purpose of each indicator.
RCC-1 Public accessibility & findability: Whether fintech-relevant rules are freely available online and easy to locate via official sources. RCC-2 Regulatory “map” of obligations: Whether regulators provide an official, usable pathway explaining how a fintech firm, across all three regulatory status categories, determines what license it needs, what licensing conditions apply, what obligations apply, and how to navigate the regulatory framework.. RCC-3 Definitions, Taxonomy & Perimeter Clarity for Common Fintech Activities: Whether key regulatory terms and fintech-relevant activity categories are defined clearly enough that a firm can tell, from public sources, whether it falls within the regulatory perimeter and which regime applies. RCC-4 Coverage across core fintech verticals: Whether the rule corpus covers the major fintech activity verticals without large gaps. RCC-5 Compliance operability: Whether a regulated firm, and where applicable an indirectly regulated vendor, can determine how to implement its obligations in practice RCC-6 Interpretive support & Q&A mechanisms: Whether regulators provide reliable public mechanisms (FAQs, guidance, interpretive processes) to reduce uncertainty. RCC-7 Change management & version control: Whether rule changes, whether to prescriptive rules or to principles and their interpretive elaboration, are made transparently and predictably, with sufficient notice for firms to adapt.. RCC-8: Outsourcing Perimeter & Indirect Supervision Clarity: Whether a regulated FinTech firm, or a regulated entity that uses FinTech vendors, can determine from publicly available sources which of its outsourced or delegated functions remain subject to regulatory oversight, and what it must therefore ensure of the third parties to whom those functions have been delegated.
Rules Clarity & Comprehensiveness (RCC) measures whether a jurisdiction's fintech-relevant rules are findable and understandable (“clarity”), and complete enough to cover common fintech activities and risks (“comprehensiveness”), in a way that a regulated firm, or prospective entrant, can determine what licence it needs, what obligations apply, and how to comply, using publicly available materials.
Section 0
Overview
This is not a “friendliness” or deregulatory score. It does not reward laxity; it rewards clarity, coherence, and coverage of the fintech rulebook itself. RCC evaluates the quality and navigability of the rulebook as a rulebook, not the substantive policy stance or outcomes.
Section 1
SCOPE AND BOUNDARIES
22
a
Core:
05
Payments / payment systems / e-money
Text
Banking / lending / credit
Securities / investment / advice / management
Insurance
Digital assets: custody, issuance of crypto tokens / asset tokenisation / stablecoins, crypto‑asset services (if applicable)
Subareas within core:
08
Regtech / suptech and other terms reflect digital oversight tools
Digital banking / fintech licensing / regulation
digital lending / BNPL
Roboadvisory / automated trading
Financial infrastructure / trading systems
Data analytics / AI
Internal IT systems
Crowdfunding (if applicable)
b
04
AML/CFT / (e)kyc
Data protection
Data use / portability / consent in financial services
Identity
Subareas:
Outsourcing / cloud
Cybersecurity
Operational resilience
Safeguarding of funds
Market conduct requirements
03
Ecosystem outcomes (e.g. investment levels, number of fintechs).
B
Enforcement “toughness” (except as it affects interpretive clarity and transparency).
C
Broader “quality of regulation” debates unrelated to clarity or coverage.
RCC CORE VERTICAL CHECKLIST
11
1
Payments / Payment Institutions
What “covered” means for this item
Binding or principles-based regime with published authorisation criteria, conduct obligations, and safeguarding requirements — operational content supplied by rules or interpretive infrastructure
2
E-money / Stored Value / Digital Wallets
Regime covering safeguarding of customer funds, capital requirements, and redemption rights — whether through prescribed rules or outcome-based standards with interpretive support
3
Digital Banking / Neobank Licensing
Published authorization pathway for digital-only bank or restricted banking license, whether through precise licensing criteria or principles-based fitness standards with published guidance
4
Digital Lending / BNPL
Published perimeter guidance and conduct or disclosure obligations, whether prescriptive or principles-based with interpretive support
5
Token Issuance, Stablecoins & Asset Tokenisation
Published regulatory framework that enables a firm to determine: (a) whether issuing a crypto token, virtual digital asset (VDA), or stablecoin requires authorisation or registration, and if so under which regime; (b) what disclosure, reserve, redemption, and ongoing compliance obligations apply; and (c) whether and how existing frameworks apply to tokenised real-world assets or whether a distinct tokenisation-specific regime applies.
6
Crypto-Asset Services
Published classification framework; licensing or registration for at least custody and exchange; AML obligations for VASPs
7
Crowdfunding / Marketplace Lending
Binding framework or principles-based regime with interpretive support for investment-based and/or lending-based crowdfunding
8
AML/CFT Onboarding Rules for Fintech
Published rules or outcome-based standards for digital onboarding including eKYC, risk-based approaches, and tiered CDD thresholds
9
Outsourcing / Cloud / Third-Party Risk
Published expectations — prescriptive or principles-based — for regulated fintech firms on outsourcing, cloud adoption, and third-party risk management
10
Cybersecurity / Operational Resilience
Binding requirements or published supervisory expectations — prescriptive or principles-based — applicable to fintech firms or their regulated partners
Data Rights / Consent / Open Banking
Published rules or framework — prescriptive or principles-based — governing consumer data rights, open banking API standards, or equivalent data portability requirements
Section 2
SCORING CONVENTIONS
Applies the index-wide 0 to 3 scale and four scoring paths specific to this pillar.
1. Band wording. RCC frames the four bands in clarity terms:
0
Opaque / materially unclear
key requirements are hard to find, ambiguous, contradictory, or not operational. No regulation at all.
Partially clear
some guidance exists but significant ambiguity or gaps remain, creating material uncertainty for common models. Advisory / policy statements etc, providing some level of clarification. Role of supervisory processes.
Clear and workable
most relevant rules are findable and understandable; some gaps or fragmentation remain.
Highly clear, coherent, and comprehensive
rules are well‑organised, well‑defined, publicly accessible, consistently explained, and cover the core fintech perimeter with clear compliance pathways.
2. Condition for a 3:
Across the RCC matrix a score of 3 normally requires all the conditions for a 2 plus evidence that the framework is clearly organised and easy to navigate, in practice that a firm can see how the pieces fit together through a clear official entry point such as a portal, consolidated handbook, licensing map or rulebook structure. For any 3 the evidence log should normally include a public navigational or mapping tool (for example, portal, handbook, licensing map, or guidance that helps users find obligations), and at least one public binding instrument (law, regulation, rulebook or equivalent) supporting the underlying obligations. Every score must be supported by public sources (laws / regulations, regulator handbooks, licensing pages, official FAQs / guidance, consultation documents, official portals, policy statements / judicial decisions etc.). “Reputation” or private information cannot be used as evidence.
Section 3
Sub-Dimensions
Sub-dimension
Weight / Indicators
A — Accessibility & Usability
20% — RCC-1 , RCC-2
B — Definitions & Perimeter Clarity
30% — RCC-3, RCC-8
C — Coverage & Completeness
30% — RCC-4, RCC-5
D — Consistency, Change Management & Interpretive Support
20% — RCC-6, RCC-7
Section 4
Indicator Matrix
A
D
RCC-1
Sub-dim A
00 sug
Sub-dimension:
What it measures
Framing note
Regulatory philosophy note
Findability standard
“Findable” means discoverable via a prescribed public search path available to the reference assessor. As a minimum, evaluators should treat the standard path as: (1) official regulator homepage or government legal portal; (2) fintech-, licensing-, or supervision-specific entry point where available; (3) official rulebook, licensing manual, or primary legal database; and (4) use of a bounded set of keyword search terms relevant to the activity under review, within a defined effort budget. A source or rule set retrievable only through insider shortcuts, direct regulator contact, or non-public navigation aids shall not count toward RCC-1 unless it is also reachable through this standard path.
Scoring Rubric
Score
Proposed Objective Trigger
Some rules available online via official sources but spread across multiple unlinked agency websites with no consolidation. A user following one regulator's site cannot readily locate rules from a co-regulator.
Scoring paths
All (single path)
Primary evidence sources
Edge cases & scoring notes
• Do not penalise non-English jurisdictions for language alone. Score availability and structure; official translations are a plus; note machine-translation use. • A well-designed website with poor substantive content should not score above 2. Distinguish design from substance. • If rules are accessible only through a paid subscription database, score conservatively (max 2).
Aggregation rule
Direct
single integer score 0-3.
Suggest an edit
Endorse a level
Cite this indicator
RCC-2
Whether regulators provide an official, usable pathway explaining how a fintech firm — across all three regulatory status categories — determines what license it needs, what licensing conditions apply, what obligations apply, and how to navigate the regulatory framework. This indicator assesses the overall navigability of the regulatory map, including both the positive perimeter (what is regulated and how) and, to the extent the framework provides it, the negative perimeter (what falls outside the regulatory perimeter and how a firm can confirm that position). Non-inclusion of an activity within the positive perimeter may, in some contexts, suffice.
This indicator has multiple scoring paths reflecting the principles / rules / outcomes / merit spectrum. A rules-based system achieves a high score through a detailed decision tree or licensing map that routes common fintech models to specific authorization categories with named obligations. A principles-based system achieves a high score through clear outcome-oriented guidance on regulatory status, supported by interpretive materials that supply operational content. Multiple paths are valid and should be noted in the evidence log.
Note on the negative perimeter
A complete regulatory map ideally communicates not only what is regulated but also what is not — giving firms outside the perimeter a basis for confirming their unregulated status. Why comprehensive negative guidance is structurally impossible: Laws and regulations are written to define what is regulated, and comprehensive confirmation of the negative can only emerge piecemeal through no-action letters, interpretive relief, published scope limitations, and explicit exclusions that accumulate over time in response to specific fact patterns. It is therefore not realistic to require comprehensive negative perimeter guidance as a condition of a high score. How it is treated in scoring: The presence of negative perimeter clarity is treated as a quality marker: its absence does not prevent a jurisdiction from reaching a score of 3, but its presence — in the form of a functioning no-action or interpretive relief process with published output, published scope limitation statements, or explicit statutory exclusions covering common FinTech models — is a feature that distinguishes an excellent regulatory map from a merely good one, and should be noted in the evidence log and reflected in the overall assessment.
No official guidance on licensing pathways or regulatory status determination for any of the three firm categories. A firm must determine its regulatory position through direct regulator engagement or legal advice only. No published basis for any firm — regulated, unregulated, or indirectly regulated — to understand where it stands.
Rules-based path
Published decision tree, licensing map, or equivalent guidance that: (a) routes common fintech models to specific authorization categories with named, prescribed licensing conditions and obligations per category; (b) provides at least some affirmative guidance on activities falling outside the regulatory perimeter, whether through explicit statutory exclusions, published scope limitation statements, or a functioning no-action or interpretive relief process with publicly accessible output (such that non-regulated entities understand whether using a regulated infrastructure provider still requires them to be regulated); and (c) addresses or cross-references the outsourcing framework and regulated function delegation so that regulated entities understand that delegating functions does not remove them from the regulatory perimeter. Covers all three regulatory status categories to the degree the regulatory mechanisms permit. Updated to reflect changes within the last 12 months.
Principles-based path
Published guidance that clearly describes the regulatory status of common fintech models and the standards they are expected to meet; supplemented by interpretive materials (FAQs, case studies, supervisory statements) that give those standards operational content; provides at least some signal about the negative perimeter through published scope statements, supervisory speeches, or a published no-action or interpretive relief process with accessible output; and addresses or cross-references the outsourcing framework so that regulated entities understand the implications of delegating regulated functions. Covers all three regulatory status categories to the degree the regulatory mechanisms permit. Updated within the past three years.
Outcomes-based path
Published framework that defines regulatory scope by reference to the outcomes or risks produced by a firm's activity as opposed to the activity category itself which: (a) enables a firm to determine from publicly available materials whether the outcomes it produces bring it within the regulatory perimeter, with sufficient guidance on the threshold between regulated and unregulated activity for a firm to self-assess; (b) maps common fintech business models to the outcome-based criteria governing their regulatory status; (c) provides at least some public guidance about activities that fall outside the perimeter, through published outcome thresholds, scope limitation statements, or a functioning interpretive process with publicly accessible output; and (d) addresses or cross-references the outsourcing framework so that regulated entities understand that delegating the production of regulated outcomes does not remove them from the perimeter. Covers all three regulatory status categories to the degree the regulatory mechanisms permit. Updated to reflect changes within the last 12 months.
Merit-based path
Regulatory status turns on what a product is and whether it passes review; published framework clearly sets out the substantive criteria that is required and: (a) enables a firm to determine from publicly available materials what criteria (such as prescribed quality, fairness, or suitability criteria) a proposed product or service must satisfy to obtain regulatory approval or clearance, with common fintech models clearly mapped to the applicable approval process and evaluation criteria; (b) separately identifies the firm-level licensing or registration requirements for the entity offering an approved product; (c) provides at least some public guidance about product types that are exempt from merit review, through published exclusions or a functioning pre-clearance process with accessible output; and (d) addresses how obligations flow to distributors, intermediaries, and technology vendors involved in delivering an approved product, enabling indirectly regulated firms to determine their position. Covers all three regulatory status categories to the degree the regulatory mechanisms permit. Updated to reflect changes within the last 12 months.
Four paths: rules-based, principles-based, outcomes-based, merit-based. The regulatory approach is identified first; the applicable path follows from that.
“How to get authorised” pages; licensing manuals; fintech-specific guidance documents; perimeter guidance publications; published scope limitation statements; statutory exclusion provisions; no-action letters or equivalent with public output; outsourcing/vendor guidance cross-references; innovation office publications; judicial decisions.
• Guidance existing only in non-public supervisory manuals cannot support a score above 1. • A score of 3 requires meaningful coverage of directly regulated and indirectly regulated firm categories. Coverage of the unregulated (Category B) negative perimeter is a quality marker that strengthens the assessment but is not a hard requirement for the top score, given the structural limitations of negative perimeter guidance described above. • Where a jurisdiction has a functioning no-action or interpretive relief process but the output of that process is not publicly released, it supports at most a score of 2 on the negative perimeter dimension — the mechanism exists but does not contribute to public regulatory clarity. • Where published no-action or interpretive letters address specific fact patterns, note in the evidence log which FinTech models or activities are covered and the extent to which the body of published relief gives a coherent picture of the negative perimeter for common FinTech activities. • Note the regulatory philosophy of the jurisdiction and the scoring path applied in the evidence log. • A prohibition on an activity is a legitimate regulatory position. Score whether a firm can determine it is prohibited from public sources — a clearly published prohibition is a form of perimeter clarity and should be treated as such.
single integer score 0-3; the path applied is recorded in the evidence log.
RCC-3
Sub-dim B
Clarity may be achieved in different ways. In rules-based systems, it often comes from precise legal definitions of products, services, and regulated activities. In principles-based or outcomes-based systems, it may come from clear statements of the functions, risks, or outcomes that bring an activity into scope, supported by interpretive guidance, examples, and supervisory statements. Merit-based systems would typically fall into principles, rules or outcome-based approaches in defining merit. Score the overall quality of the jurisdiction's definitional and perimeter clarity, and note in the evidence log whether that clarity comes mainly from formal definitions, functional guidance, or both.
Primary legislation; regulations; perimeter guidance; licensing category descriptions; interpretive notes; fintech-specific classification frameworks; regulator policy statements; published interpretive positions; court / administrative decisions; supervisory statements, speeches, or case studies where these are used to explain scope.
• Score clarity, not permissiveness. A clear prohibition should score the same as a clear permission if it is equally findable and unambiguous. • If multiple regulators define the same term or perimeter differently, score no higher than 2 and note the conflict explicitly if possible. • Definitions borrowed from international standards are acceptable if the source is clear and the jurisdiction applies them consistently. • In principles-based systems, functional guidance can substitute for formal statutory definitions, but only if it is sufficiently clear and consistently applied. • A framework that is clear for traditional financial services but not extended to common fintech activities should score no higher than 2. • Enacted but not yet in force rules should score no higher than 2 until any necessary operational guidance is also available. • Note in the evidence log whether clarity relies mainly on formal definitions, perimeter guidance, or a mixed approach.
RCC-4
Sub-dim C
Whether the jurisdiction's rule corpus covers the major fintech activity verticals without significant gaps. Scored against the Core Vertical Checklist , the score increases as more checklist items are covered with clear, operational, publicly accessible rules or principles with adequate interpretive support.
This indicator is neutral as between regulatory philosophies. A vertical is "covered" whether by precise rules or by clear principles with adequate interpretive support, provided coverage is operational, meaning a firm can determine its obligations for that vertical from public sources. Scored against the Core Vertical Checklist (see the RCC Core Vertical List sheet, which also carries the Year 1 strictness standard and the rule for verticals that do not exist in a jurisdiction). The score increases as more checklist items are covered.
Fewer than 4 checklist verticals covered by clear, operational rules or principles with adequate interpretive support, accessible from public sources.
4 to 5 checklist verticals covered. Major gaps in at least two high-frequency fintech categories.
6 to 8 checklist verticals covered. Remaining gaps in less common or emerging categories.
9 or more checklist verticals covered with clear, operational guidance — whether rules-based or principles-based — including cross-cutting topics. No major regulatory gaps for a standard fintech entrant in any core category.
Laws and regulations for each vertical; regulator handbooks; fintech-specific guidance per vertical; Core Vertical Checklist evidence log (one entry per vertical per jurisdiction); court decisions.
• “Covered” means either: (a) binding law or regulation plus operational guidance (rules-based path); or (b) clear principles plus interpretive support sufficient to give those principles operational content (principles-based path). • A clearly prohibited activity counts as covered — the firm knows its position. Note the prohibition in the evidence log. • Emerging verticals (DeFi, embedded finance) noted but do not penalize the score in Year 1 if genuinely nascent. • A clearly prohibited activity counts as ‘covered’ for RCC‑4 if the prohibition is clearly stated in public sources; record the prohibition explicitly in the evidence log.
Cross-pillar boundary note
For checklist items 8 (AML/CFT onboarding) and 10 (cybersecurity and operational resilience), RCC scores clarity and findability only; RI scores substantive quality.
RCC-5
Whether a regulated firm — and where applicable an indirectly regulated vendor — can determine how to implement its obligations in practice.
This is the indicator most affected by the principles / rules / outcomes distinction. A rules-based system supplies operational content directly through prescriptive requirements. A principles-based system supplies it through interpretive infrastructure, guidance, supervisory statements, enforcement decisions, and FAQs that over time give principles their practical meaning. An outcomes-based system focuses on a series of objective indicators. A merit-based system has clear definitions of merits considered. The key question is not whether the regime uses rules, principles and/or outcomes, but whether, by whatever means, a firm can determine what it must actually do. Scorers must assess the rules and interpretive infrastructure together for principles-based jurisdictions. Read this indicator together with RCC-6 for principles-based systems.
A regulated firm cannot determine from public sources what it must do to comply — whether because obligations are vague and no interpretive support exists (principles-based failure) or because rules exist but are contradictory, inaccessible, or operationally incoherent (rules-based failure).
Clear standards published for most core regimes, supported by interpretive guidance (FAQs, supervisory statements, published case studies) that gives those standards operational content for at least payments and AML/CFT. A firm can determine what it must achieve and how regulators assess compliance, even if the precise means are not prescribed. Some gaps remain.
Similar to principle or rules based, as appropriate, but clearly tailored to targeted outcomes.
Similar to principles or rules based, as appropriate, but clearly defining approaches to merit.
Clear standards for all core verticals, supported by a mature interpretive infrastructure including: regularly updated FAQs; published supervisory statements on how principles apply in common scenarios; enforcement decisions or published case studies that establish precedent; published regulatory expectations for core risk areas (AML, cybersecurity, safeguarding) expressed as outcomes with illustrative examples; guidance on outsourcing expectations expressed as outcomes. Updated within the past three years. The cumulative interpretive record is sufficient that a new entrant can determine how to comply without direct regulator engagement for standard activities.
Similar to principles or rules based, as appropriate, but clearly tailored to targeted outcomes.
[To follow — to be drafted by the RCC working group]
• A principles-based system with clear principles but thin interpretive infrastructure scores no higher than 1. The principles alone do not supply operational content. • A rules-based system with detailed rules that are contradictory, outdated, or inaccessible scores no higher than 1 regardless of prescriptive detail. • Note the scoring path applied and the maturity of the interpretive infrastructure in the evidence log. • Read this indicator together with RCC-6 for principles-based jurisdictions: a strong RCC-6 score is a precondition for a strong RCC-5 score via the principles-based path.
RCC-6
Sub-dim D
Whether regulators provide reliable, accessible mechanisms (FAQs, guidance, interpretive processes) for firms across all three regulatory status categories to reduce regulatory uncertainty.
This indicator carries greater weight in principles-based systems, where interpretive support is the primary mechanism by which principles acquire operational content. In a rules-based system, strong interpretive support is a quality-of-service feature. In a principles-based system, it is structurally necessary — its absence renders principles operationally unworkable. Scorers should note the regulatory philosophy of the jurisdiction and weight the significance of this indicator accordingly when reading it alongside RCC-5.
Ad hoc or reactive clarifications only. Some published guidance exists but unsystematic and rarely updated. No innovation office, fintech hub / Secretariat / One Stop centre, or equivalent publicly accessible support. Guidance focused on directly regulated firms only.
Predictable interpretive mechanism that supplements the prescriptive framework: (a) regularly updated FAQs with clear publication dates; (b) publicly accessible channel for submitting regulatory questions with published responses; (c) innovation office or fintech hub / Secretariat / One Stop Centre with documented public engagement; (d) interpretive outputs carry clear status (binding, non-binding); (e) guidance addresses all three regulatory status categories.
Mature interpretive ecosystem that gives the principles operational force: (a) comprehensive, regularly updated FAQs covering common compliance scenarios across core verticals; (b) published supervisory statements, Dear CEO letters, or equivalent explaining how principles apply to current market developments; (c) enforcement decision summaries published with reasoning to allow firms to calibrate conduct; (d) published regulatory expectations for specific risk areas expressed in sufficient detail to guide implementation; (e) innovation office or fintech hub / Secretariat / One Stop Centre with accessible public engagement; (f) guidance addresses all three regulatory status categories. The cumulative interpretive record constitutes a de facto operational compliance framework.
• For principles-based systems: a rich historical archive not updated in three or more years scores no higher than 2, as it may not reflect current regulatory expectations. • Private non-precedential communications score max 2 regardless of responsiveness. • A sandbox providing clarity only to sandbox participants does not satisfy this indicator for the general firm population. • Note the scoring path applied and an assessment of the maturity of the interpretive infrastructure in the evidence log.
RCC-7
Whether rule changes — whether to prescriptive rules or to principles and their interpretive elaboration — are made transparently and predictably, with sufficient notice for firms to adapt.
Dual paths apply. In a rules-based system, change management means transparent amendment of specific rules with consultation, notice, and consolidated updates. In a principles-based system, the principles themselves may rarely change, but their operational meaning evolves continuously through interpretive outputs. Change management in a principles-based system therefore includes the transparency and predictability of that interpretive evolution — whether supervisory expectations are updated clearly, whether firms are given notice when the regulator's or legislator's reading of a principle shifts, and whether the cumulative interpretive record is accessible and organised.
All of the following: (a) accessible archive of all supervisory statements, guidance updates, Dear CEO letters, and enforcement summaries, organized by topic and date; (b) clear signalling when the regulator’s interpretation of a principle has evolved, with rationale; (c) adequate notice to industry before a new or revised interpretation takes effect; (d) consolidated or indexed record of current supervisory expectations by vertical or topic area; (e) guidance on implementation expectations for all three regulatory status categories when interpretive changes affect their obligations.
Similar to principles or rules based, as appropriate, but clearly defining approaches to outcomes.
Outcomes-based and merit-based paths
• Measures predictability, not frequency. A jurisdiction that changes rules frequently but transparently should score well. • Emergency measures may legitimately skip standard consultation — note but do not permanently depress the score. • Enacted but not yet in force rules score max 2 until operational guidance is also issued. • Frequent informal signals of shifting expectations without formal notice or archiving score no higher than 1.
RCC-8
Whether a regulated fintech firm , or a regulated entity that uses fintech vendors , can determine from publicly available sources which of its outsourced or delegated functions remain subject to regulatory oversight, and what it must therefore ensure of the third parties to whom those functions have been delegated. The indicator asks whether the framework gives licensed firms a clear, navigable answer to: “When I outsource a function, which functions does my regulator care about, what must I contractually and operationally ensure of my vendor, and how do I demonstrate compliance?”
Distinction from RCC-3 and RCC-5. RCC-3 asks whether a firm knows if it is regulated. RCC-5 asks whether a firm can implement its own internal compliance obligations. RCC-8 addresses the boundary between the regulated firm and its supply chain — which delegated functions remain within the regulatory perimeter and what the regulated firm must do to maintain oversight of them.
Multiple scoring paths apply
Rules-based: Outsourcing perimeter clarity comes from precise statutory or regulatory definitions of which functions are material or critical, combined with prescribed contractual requirements and supervisory expectations that the regulated entity must impose on vendors in each category. Principles-based: Clarity comes from outcome-oriented guidance that tells regulated entities what they must ensure of their vendors — expressed as outcomes to be achieved and evidenced — supplemented by supervisory statements, thematic reviews, and published expectations that give those outcomes operational content over time.
Vendor perspective
The primary vantage point of this indicator is the regulated entity. However, the quality of a jurisdiction’s outsourcing framework is also reflected in whether it extends guidance to vendors directly — whether vendors are told what to expect and prepare for rather than having to infer it from their clients’ obligations. The presence of vendor-facing guidance is therefore a differentiating feature at the top of the scoring range, not a baseline requirement. A jurisdiction can score a 2 with strong regulated-entity-facing guidance alone; reaching a 3 typically requires some public-facing signal addressed to or usable by vendors as well.
Negative perimeter dimension
A related but distinct question is whether a regulated firm can confirm that a particular outsourced function falls outside the indirect supervision regime — that is, that delegating it creates no regulatory obligations in respect of the vendor. As with the broader negative perimeter problem addressed in RCC-2, laws and regulations rarely give comprehensive confirmation of the negative in this context. Confirmation that a function is not subject to outsourcing oversight typically emerges only through no-action or interpretive relief, published scope limitations, or materiality thresholds that clearly exclude certain categories of arrangement. Scorers should note where a jurisdiction provides this kind of negative clarity — it is a positive feature — but its absence should not materially depress the score. The indicator is primarily assessing clarity about what is subject to indirect supervision, not the comprehensiveness of guidance about what is not.
Comprehensive published outcome-oriented framework covering all of the following from the regulated entity’s perspective: (a) clear articulation of which outsourced functions the regulator considers material to the delivery of regulated services, expressed as outcomes-based criteria a regulated firm can apply to its own arrangements; (b) published supervisory expectations, through thematic reviews, Dear CEO letters, or equivalent, that give operational content to the regulated entity’s obligation to ensure vendor compliance, including what "ensuring" looks like in practice for core risk areas (resilience, data security, continuity); (c) published case studies, enforcement summaries, or supervisory findings that establish precedent for how the framework applies to common outsourcing arrangements; (d) treatment of contemporary technology arrangements in at least some published supervisory output; (e) updated or supplemented within the past three years such that the cumulative interpretive record gives a regulated firm sufficient guidance to structure and document its vendor arrangements without direct regulator engagement for standard functions. Additionally, at least one of the following vendor-facing features is present: outcome-oriented guidance addressed to vendors on what they should be prepared to demonstrate; published thematic review findings that implicitly or explicitly address vendor-side conduct; or published interpretive relief indicating that certain arrangements fall outside the indirect supervision regime.
Outsourcing regulations; critical third-party or material service provider frameworks (e.g. EU DORA, UK PRA/FCA outsourcing and third-party risk rules, MAS outsourcing guidelines); prescribed or model contractual terms publications; regulatory guidance on cloud adoption and AI-enabled outsourcing; published supervisory expectations for vendor oversight.
Similar to principles or rules based, as appropriate, but clearly tailored to targeted outcomes or merit.
• RCC scores navigability; RI scores substantive adequacy. This indicator scores whether the outsourcing framework is clear and navigable for regulated entities, not whether it is substantively robust or adequate. A framework can be crystal clear and still be substantively thin — that is assessed by the RI pillar. Coordinate with RI to avoid double-scoring. • A jurisdiction with detailed outsourcing rules for banks that do not extend to FinTech firms or their regulated partners scores no higher than 2. The framework must apply to firm types within the FinTech perimeter. • A jurisdiction that addresses only one type of outsourced function (e.g., IT outsourcing only, or cloud only) without a broader framework for classifying and managing outsourced regulated functions scores no higher than 1, regardless of how detailed that single-function guidance is. • Self-applicability of materiality thresholds matters. Thresholds that a regulated firm can apply to its own arrangements without requiring case-by-case regulatory sign-off support a higher score than thresholds requiring individual regulatory determination. Self-applicability is a meaningful clarity feature. • For the negative perimeter dimension: where a jurisdiction publishes explicit materiality thresholds that clearly exclude certain categories of arrangement from indirect supervision requirements, note this in the evidence log as a positive feature. It informs the overall navigability assessment but does not independently drive the score. • Note in the evidence log: (a) the scoring path applied; (b) the primary evidence relied upon for each scored element; and (c) whether any vendor-facing features were present and what form they took. • A clearly communicated prohibition on a fintech activity counts as perimeter clarity for that activity; a firm knows it cannot undertake the activity.
RCC scores the navigability of the outsourcing framework; RI scores its substantive adequacy. A framework can be clear yet substantively thin; that is assessed by RI.
Public Accessibility & Findability
Whether fintech-relevant rules are freely available online and locatable by a new market entrant using only public sources.
This indicator is neutral as between rules-based, outcome-based, merits-based and principles-based systems. All types of regime can score well or poorly on accessibility.
No centralised official online source for fintech-relevant rules. Key regulatory instruments are offline, scattered across multiple sites with no cross-referencing, or require direct regulator contact to obtain.
Most fintech-relevant rules accessible via official sources. At least one regulator provides a dedicated fintech or digital finance section on its website. Some fragmentation remains across agencies or rule types.
Single official landing page or consolidated regulatory handbook accessible without login. Fintech-specific entry points clearly labeled. Rules indexed or searchable by activity type. Non-English jurisdictions: official translation or machine-translation support available and flagged.
Regulator websites; official legal databases; licensing portals; fintech-dedicated sections of regulator sites.
Regulatory Map of Obligations
Minimal published description of regulated activities exists but does not map to specific fintech models. Guidance applies only to directly regulated firms in the most established categories; no guidance on unregulated or indirectly regulated status; no indication of negative perimeter or scope limitations. Core obligations are described but without much detail.
Clear licensing categories described for directly regulated fintech models. A firm operating a common model can identify the applicable regime from public sources. No equivalent guidance for unregulated or indirectly regulated firms. No published negative perimeter guidance, but the positive map is sufficiently clear that a firm can make reasonable inferences about scope. Core obligations exist but are not specifically mapped to each fintech category.
Definitions, Taxonomy & Perimeter Clarity for Common Fintech Activities
Whether key regulatory terms and fintech-relevant activity categories are defined clearly enough that a firm can tell, from public sources, whether it falls within the regulatory perimeter and which regime applies. This includes common directly regulated fintech models, and any definitions needed to distinguish regulated, indirectly regulated, and unregulated activities at the boundary of scope.
Core fintech-relevant terms and regulated activity categories are absent from statute, regulation, or published guidance, or are described in circular, self-referential, or inconsistent terms. A firm cannot determine from public sources whether it is inside the regulatory perimeter. Scope is resolved mainly through case-by-case intervention or enforcement.
Some core terms or activities are defined, but significant grey zones remain for common fintech models. A firm can determine the perimeter for some established activities, but not reliably for common models such as e-money, digital lending, custody, payment services, or crypto-asset activities. At least two major categories remain undefined, ambiguous, or inconsistently treated across public sources.
Most core terms and activity categories are defined in statute, regulation, or published guidance, and the perimeter is clear for most common fintech activities. Some ambiguity remains for hybrid products, emerging business models, technology vendor scope, or boundary cases between directly regulated, indirectly regulated, and unregulated activity.
There is a comprehensive and coherent taxonomy, whether through formal legal definitions, clearly articulated functional descriptions, or both, covering all core verticals on the Year-1 checklist. Public sources allow firms to determine whether they are regulated, which regime applies, and how common hybrid or edge-case models are treated. Guidance is available for newer structures, and inconsistencies across agencies are minimal or resolved through published coordination mechanisms. Relevant terms for indirect regulation are also clear where needed to understand the boundary of direct regulation.
Coverage Across Core Fintech Verticals
Compliance Operability
Some operational content exists for at least one vertical, whether through prescriptive rules or published guidance, but most compliance obligations lack the operational specificity needed for a new entrant to implement them without significant direct regulator engagement.
Clear reporting and compliance requirements published for most core regimes, including filing frequencies, formats, and key control expectations for at least payments and AML/CFT. Some gaps in newer or less common regimes.
Published compliance guides, reporting taxonomies, or supervisory handbooks for the majority of core verticals, including: filing formats or templates for key regulatory reports; supervisory expectations for core controls (AML, cybersecurity, safeguarding); example disclosures where consumer-facing obligations apply; outsourcing flow-down requirements. Updated within the past three years.
Reporting manuals; compliance guides; supervisory handbooks; filing templates; outsourcing guidance.
Published FAQs; supervisory statements; enforcement decision summaries; regulatory speeches on compliance expectations; published case studies; outcome-focused guidance documents.
Interpretive Support and Q&A Mechanisms
No published FAQs, guidance updates, or interpretive mechanism. Firms can only seek clarity through formal legal process or direct regulator contact with no public output. Principles-based systems with no interpretive infrastructure are automatically a 0 regardless of how well-drafted the underlying principles are.
Regular published FAQs or guidance updates for at least the major regulated verticals. At least one formal or informal channel for seeking interpretive guidance with a public-facing output. Some gaps in coverage or update frequency. Does not yet address unregulated or indirectly regulated firm categories.
Published FAQs; no-action letters; innovation office publications; guidance update logs.
Supervisory statements; Dear CEO letters; enforcement decision summaries; thematic review publications; speech transcripts with compliance guidance content; published regulatory expectations documents.
Change Management & Version Control
Rule or interpretive changes made without advance notice. Effective dates unclear or retrospective. No consolidated source for tracking current obligations. In a principles-based system: no mechanism for tracking how the regulator’s interpretation of principles has evolved over time.
Some consultation on major changes but process inconsistent. In a principles-based system: interpretive evolution is ad hoc and firms cannot track how supervisory expectations have shifted without direct regulator engagement.
Standard consultation process in place for most significant changes. Transition periods typically provided. Consultation could be public or industry consultation. Official source for effective dates exists. In a principles-based system: supervisory statements and guidance updates are dated and archived, allowing firms to track interpretive evolution, though consolidation is partial.
All of the following: (a) published consultation archive with final rules and responses; (b) explicit effective dates and transition periods in final rules; (c) consolidated rulebook or amendment log showing current version; (d) public rationale for significant changes; (e) implementation guidance issued alongside finalization addressing all three regulatory status categories.
Consultation archives; effective-date notices; consolidated handbooks; regulatory gazettes; transitional guidance.
Archived supervisory statements; thematic review publications; Dear CEO letters; regulatory speeches with forward guidance; published enforcement summaries with reasoning; regulatory update newsletters or equivalent.
Impact assessments and reviews.
Outsourcing Perimeter & Indirect Supervision Clarity
No publicly available framework addressing which outsourced functions remain subject to regulatory oversight. A regulated entity cannot determine from public sources whether delegating a function creates any regulatory obligation in respect of its vendor. Outsourcing obligations, if any, exist only in private supervisory communications or are entirely ad hoc.
Some published outsourcing rules or guidance exists, but it addresses only the regulated entity’s general obligation to manage third-party risk without specifying which functions are material or critical, what contractual terms must be in place, or what the regulated entity must be able to demonstrate to its supervisor. A licensed firm reading the public framework would know it has outsourcing obligations but could not determine their specific content or scope without direct regulator engagement.
Published framework, whether prescriptive rules or principles-based guidance with interpretive support, that enables a regulated entity to determine: (a) which categories of outsourced function are considered material or critical and therefore subject to heightened oversight requirements; (b) the core contractual terms it must put in place with vendors for those functions (at minimum: audit rights, service level requirements, data access, and business continuity); and (c) the supervisory expectations it must be able to demonstrate compliance with. Some gaps remain for newer or emerging technology arrangements (e.g., AI-enabled functions, cloud-native infrastructure, multi-layered subcontracting). Guidance is primarily framed from the regulated entity’s perspective; limited or no guidance addressed to vendors directly.
Comprehensive published framework covering all of the following from the regulated entity’s perspective: (a) clear classification of outsourced functions by materiality or criticality, with defined criteria that a regulated firm can apply to its own arrangements without regulator pre-approval; (b) prescribed or strongly recommended contractual terms for each category of outsourced function, including audit rights, service continuity, data portability, subcontracting controls, and regulator access; (c) explicit supervisory expectations for how the regulated entity must monitor, test, and report on vendor performance and resilience; (d) treatment of contemporary technology arrangements including cloud, AI-enabled functions, and multi-layered subcontracting chains; (e) updated within the past three years. Additionally, at least one of the following vendor-facing features is present: published guidance addressed directly to vendors explaining what regulated clients will require of them; a mechanism through which vendors can engage with the regulator on compliance expectations; or published no-action or interpretive relief confirming that certain arrangements fall outside the indirect supervision regime. Note: the EU’s DORA framework is a reference model for a score of 3 via this path.
Outcome-oriented outsourcing guidance; published supervisory statements on third-party risk management; Dear CEO letters on outsourcing expectations; thematic review reports on firms’ outsourcing arrangements; enforcement decision summaries involving outsourcing failures; published regulatory expectations for operational resilience that address vendor dependencies.
2. What's needed for a top score:
Scoring rules for RCC-4
Year 1 strictness
In Year 1, RCC-4 is applied strictly. A score of 3 is given only where essentially all core verticals on the agreed checklist are covered with clear, operational public rules, or with clear principles plus sufficient interpretive support to make those principles operationally usable in practice.
Verticals that do not exist in a jurisdiction
If a checklist vertical genuinely does not exist in a jurisdiction, count it as covered only if public sources clearly state that the activity is not permitted or not part of the system; otherwise treat it as a gap. For verticals that are core fintech content in most jurisdictions, this treatment is used sparingly and justified explicitly in the evidence log.
Count thresholds
The number of covered verticals required for each score of 0 to 3 is still marked "to be clarified" by the working group (indicatively: 0 = fewer than 4; 1 = 4 to 5; 2 = 6 to 8; 3 = 9 to 10). These thresholds are placeholders and are flagged in the Status column on the Indicators sheet.
Approximately 4-5 checklist verticals covered. Major gaps in at least two high-frequency fintech categories.
Approximately 6–8 checklist verticals covered. Remaining gaps in less common or emerging categories.
Similar to priniciples or rules based, as appropriate, but clearly tailored to targeted outcomes.
Sign in to endorse or challenge. It takes one email and no password.
Reply within an argument, quote a contributor, or link directly to a comment.
Sign in to reply. It takes one email and no password.