Data Driven Compliance: A SBR solution for regulated entities
Andrea Gentilini
No 26283, BAFFI CAREFIN Working Papers from BAFFI CAREFIN, Centre for Applied Research on International Markets Banking Finance and Regulation, Universita' Bocconi, Milano, Italy
Abstract:
EU financial regulation obliges supervised entities to report transaction-level, position-level and portfolio-level data at a granularity unmatched in any other regulatory domain. National Competent Authorities (NCAs) have begun converting these flows into Data-Driven Supervision (DDS): reproducible indicators, composite risk scores and triage pathways that allocate scarce supervisory capacity where risk concentrates (Gentilini, 2026a). DDS contributes in an efficient manner to address the fundamental needs of efficient, convergent and consistent supervision, within an architecture that combines a centralised, collegial layer for risk identification and metric design with decentralised, proximity-based application at NCA level (Gentilini, 2026b). This paper argues that the same data, the same indicator logic and the same scoring methodology can — and should — be deployed symmetrically by the entities themselves, as Data-Driven Compliance (DDC): an internal control discipline in which firms compute, monitor and remediate the very indicators their supervisors compute about them. DDC converts regulatory reporting from a terminal cost into a source of compliance assurance, lowers the cost of evidencing compliance, and creates the informational basis for a structured dialogue between entities and NCAs over which data and indicators are fit for purpose. Drawing on case studies across AIFMD, EMIR, MiFIR, MMFR and SFTR reporting — anchored in ESMA’s Data Quality Engagement Framework for the provision of data and follow-up on data quality issues — the paper formalises the DDC construct mathematically and concludes with a single actionable recommendation: ESMA should adopt dedicated Guidelines under Article 16 of its founding Regulation making it mandatory for NCAs to require supervised entities to develop and regularly use the indicator-based controls that constitute ESMA’s Data Quality Engagement Framework, to monitor their outcomes and resolve the issues they flag, and — only where issues were flagged — to report annually to their NCA on the issues identified and their resolution. The proposal is framed as simplification and burden reduction, not as new substantive obligation.
Keywords: data-driven supervision; data-driven compliance; supervisory convergence; regulatory reporting; ESMA Guidelines; data quality; EMIR; MiFIR; AIFMD; SFTR; MMFR. (search for similar items in EconPapers)
JEL-codes: C53 E37 G21 O17 (search for similar items in EconPapers)
Pages: 40
Date: 2026
New Economics Papers: this item is included in nep-reg
References: Add references at CitEc
Citations:
Downloads: (external link)
https://repec.unibocconi.it/baffic/baf/papers/cbafwp26283.pdf (application/pdf)
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:baf:cbafwp:cbafwp26283
Access Statistics for this paper
More papers in BAFFI CAREFIN Working Papers from BAFFI CAREFIN, Centre for Applied Research on International Markets Banking Finance and Regulation, Universita' Bocconi, Milano, Italy Via Röntgen, 1 - 20136 Milano - Italy. Contact information at EDIRC.
Bibliographic data for series maintained by Michela Pozzi ().