Navigating compliance at scale: What fintechs can learn from Monzo 

By Rav Hayer, Managing Director, UK and Ireland, and Head of BFSI, Europe at Thoughtworks    

Fintech leaders across the sector should take note of the Financial Conduct Authority’s £21 million penalty against Monzo Bank. This isn’t merely another regulatory headline. The core message remains unmistakable: whilst digital innovation and customer focus drive success, robust compliance frameworks must not be overlooked. As fintech’s continue reshaping the banking landscape, regulatory fundamentals deserve equal priority alongside the user-focused features that create competitive advantage. 

Five compliance insights for financial institutions 

Monzo’s recent fine serves as a powerful reminder to banks and fintechs alike: if you’re aiming to disrupt traditional finance, you can’t afford to treat compliance as an afterthought. Staying innovative and staying compliant must go hand in hand. 

1. Embed compliance from the start

    Monzo’s journey shows just how critical it is to embed anti-money laundering (AML) and know your customer (KYC) measures right from the start. These aren’t just regulatory checkboxes, they’re foundational to building trust and resilience. That means designing systems that can scale with your business, handle data responsibly, verify identities thoroughly, and continuously assess risk as your customer base grows and evolves. 

    2. The role of technology in scaling controls 

    As companies grow, so do the risks. What worked in the early days, like manual checks, quickly becomes unsustainable. That’s why businesses should advocate for smart engineering from the ground up. Think modular microservices, event-driven systems, and automated testing. These aren’t just tech buzzwords, they’re practical tools that help businesses stay agile, compliant, and customer-friendly, even as regulations shift. 

    3. Human expertise remains essential 

    Even with the most advanced AI and machine learning tools at their disposal, Monzo’s experience underscores a crucial truth: technology alone isn’t enough. Automation excels at scanning vast datasets, flagging anomalies, and streamlining repetitive tasks, but it lacks the nuance and contextual understanding that only human judgement can provide. When financial institutions face complex or high-risk scenarios, it’s the seasoned professionals who make the difference. They interpret subtle signals, weigh ethical considerations, and make informed decisions that machines simply aren’t equipped to handle. 

    The most resilient compliance strategies don’t rely solely on algorithms. Instead, they strike a balance between smart technology and skilled human oversight. It’s this partnership that ensures financial crime is not only detected but properly understood and addressed. 

    4. Data quality underpins compliance 

    One of the key issues Monzo faced was around dodgy address data, a small detail with humongous consequences. In today’s data-driven world, poor-quality information can undermine your entire compliance framework. Financial firms need to treat data governance as a top priority, ensuring that records are clean, consistent, and reliable across the board. 

    5. Staying ahead with vigilant compliance 

    Monzo’s commitment to overhauling its financial crime systems is commendable and it highlights a broader truth: compliance isn’t a one-time fix. It’s an ongoing process that requires constant vigilance, regular updates, and open communication with regulators. The most resilient organisations don’t just react to problems; they anticipate them and have planned ahead. 

    In today’s regulatory environment, innovative technology isn’t just a nice-to-have; it’s essential. It’s what enables financial institutions to stay resilient, responsive, and ready for scrutiny. Too often, compliance is seen as a box-ticking exercise or a barrier to innovation. But that mindset is simply outdated. For fintechs and banks looking to build lasting, trustworthy brands, compliance should be viewed as a strategic asset. When done right, it doesn’t just keep regulators happy, it builds customer confidence, protects the business from reputational damage, and sets companies apart in a crowded market. 

    Robust compliance frameworks, powered by smart technology, allow organisations to scale safely. They help detect risks early, adapt to new regulations quickly, and maintain transparency at every level. In a world where trust is currency, this kind of operational integrity becomes a true competitive advantage.