September 5, 2026
Chargeback X ad
Compliance debt

Compliance Debt And The Most Expensive Words in Fintech

Sponsored Content

I have spent much of my career in financial crime, compliance and investigations at fast-growing businesses. This has taught me a thing or two about what I’d like to call compliance debt and a “we’ll fix it later” attitude to compliance issues. 

Years of investigations have taught me: people rarely wake up one morning and decide to launder money or become white-collar criminals. More often, the path there is gradual: a small decision feels explainable, then another one does, and over time individual decisions accumulate until something that once felt exceptional starts to feel normal.

I see a similar mechanism of accumulation inside companies, even though the intent is entirely different. Very few companies set out to build a weak compliance program. Instead, a series of reasonable compromises is made under commercial pressure, each one sensible on its own. The risk is that nobody goes back to revisit them, and the exceptions gradually become the operating model.

That is what I want to explore in this column: how compliance risks actually develop inside businesses, what happens when commercial reality meets policy, and how to deal with those risks before a manageable problem becomes a much bigger one.

The standard launch compromise

Launching before every control is fully automated is a good example. Volumes are still low, so operations can review cases manually while a spreadsheet bridges the gap until the automated control arrives next quarter. Compliance agrees, perhaps with a few conditions.

That can be a reasonable way to launch. A manual process often makes sense at the beginning: it gives the company time to understand a new product, market or segment before automating decisions around it.

The problem starts when next quarter arrives and there is always something more urgent to build. Each decision may still make sense on its own. Together, over time, they create what I think of as compliance debt.

What compliance debt looks like

A gap develops between the business you are operating and the controls you have actually implemented to mitigate known risks and can prove they are working. Over time this unsolved gap accumulates into what I call compliance debt.

It usually develops quietly: a temporary spreadsheet becomes the main control, an exception never expires, a manual review built for 30 merchants is still used at 300, and the person who owned the process moves on while the process stays.

The temporary solution becomes permanent.

When growth outruns controls

Block’s Cash App is a useful public example.

In April 2025, the New York State Department of Financial Services fined Block $40 million over deficiencies in Cash App’s Bank Secrecy Act and anti-money laundering compliance program, as part of a broader consent order that also identified problems with sanctions screening, virtual currency controls, cybersecurity and consumer protection.

The regulator found Block’s policies and processes hadn’t kept pace with its growth: a transaction-monitoring backlog grew from about 18,000 alerts in 2018 to more than 169,000 by 2020, caused in part, the department said, by Block’s inability to predict how Cash App’s growing customer base would affect alert volumes and staffing needs.

Block is hardly the only fintech where regulators have identified this pattern. In 2024, the U.K. Financial Conduct Authority fined Starling Bank nearly £29 million for financial-crime control weaknesses after the bank grew from about 43,000 customers in 2017 to 3.6 million in 2023. Its automated sanctions-screening system, the FCA found, had been checking customers against only a fraction of the relevant list since 2017, a gap Starling didn’t discover until 2023.

Both illustrate the same problem: a control environment can become inadequate because the business around it changes faster than the controls do. A process built for 1,000 customers may not work for 100,000, and a manageable alert queue can become a major remediation project surprisingly quickly.

Once that happens, the company has to deal with everything that accumulated while the gap was open.

Why fixing compliance debt later is harder

By the time a company decides to remediate, the issue may extend far beyond the original process: customers may need to be reviewed again, data that should have been collected at onboarding may be missing, and risk classifications may need to be reassessed across the portfolio.

By then, the business may depend on the customers or activity being reviewed. A segment that started as a small experiment can become a meaningful revenue source, and remediation becomes a commercial decision as much as a compliance one.

The larger the exposure, the harder it is to address, and the pressure often shifts toward adjusting the risk appetite to accommodate the business that already exists. That can be justified: risk appetites should change when the facts change. The real question is whether the underlying control problem has actually been addressed, or simply reclassified as acceptable risk.

Launching before everything is ready

Perfect controls before every launch are unrealistic, particularly in a fast-growing company. The better approach is to make the compromise explicit.

Any material temporary gap should have five things:

  1. An owner: Someone is responsible for closing it.
  2. A deadline: “Post-launch” is not a deadline.
  3. An interim control: Something manages the risk until the permanent solution is ready.
  4. A limit: There is a point beyond which the business cannot keep scaling under the temporary setup.
  5. An escalation trigger: There is an agreed threshold that automatically brings the issue back for review, ideally by someone other than the person responsible for closing the gap.

That last distinction matters: the owner should escalate when a deadline or limit is reached, but governance shouldn’t depend entirely on that person flagging their own missed remediation. The trigger can sit with compliance leadership, a risk committee or senior management, depending on the company.

A promise to fix something next quarter only has value if something happens when next quarter arrives and the issue is still unresolved. That may mean adding people, restricting volumes, delaying another launch or, in some cases, slowing growth until the controls catch up.

Those are uncomfortable decisions, but usually cheaper than years of accumulated exposure under regulatory pressure.

“Remediate later” can be a legitimate strategy. But later needs an owner, a deadline, a budget and consequences if the work is not completed.

Without those things, the company is carrying serious compliance debt.

Darwinium banner ad

Leave a comment

Your email address will not be published. Required fields are marked *