Executive Interviews

Beyond Compliance: Building Operating Models for Continuous Regulatory Change

In this interview, Shah discusses the implementation challenges that shaped the Dual-Flow Operating Model, the governance practices that support successful enterprise transformation, and the operational lessons financial institutions can apply to strengthen both compliance delivery and long-term organizational resilience.

Darshan Shah is Program Manager at Devfi Inc., where he leads enterprise transformation programs for financial institutions. Shah specializes in Know Your Customer (KYC) modernization, cloud migration, enterprise data integration, technology governance, and cross-functional program leadership within highly regulated financial environments. Throughout his career, he has directed complex initiatives for organizations including Morgan Stanley, Vanguard, and Bank of America, delivering large-scale compliance implementations while maintaining the operational stability of business-critical platforms.

Financial institutions now face a constant stream of new requirements while simultaneously modernizing legacy platforms, migrating applications to the cloud, and supporting business operations that cannot pause for implementation activities. His experience leading these programs inspired Shah to develop the Dual-Flow Operating Model, an original implementation framework that separates immediate compliance delivery from longer-term operating model transformation. The framework enables organizations to satisfy evolving obligations without losing momentum on broader modernization objectives or creating unnecessary technical debt.

In this interview, Shah discusses the implementation challenges that shaped the Dual-Flow Operating Model, the governance practices that support successful enterprise transformation, and the operational lessons financial institutions can apply to strengthen both compliance delivery and long-term organizational resilience.

ELLEN WARREN: Financial institutions have always needed to respond to new regulatory requirements. What has changed over the past decade that makes implementing those programs significantly more complex today?

DARSHAN SHAH: Over the past decade, the world has become increasingly dependent on digitalization, with advanced technology now playing a critical role in almost every aspect of banking operations. As technological reliance continues to grow, so do the associated risks. Even a disruption lasting only a few seconds can have significant financial, reputational, and operational consequences for a financial institution.

Regulatory mandates also come with strict implementation deadlines, leaving institutions little flexibility while requiring significant changes to systems and processes without disrupting business continuity. The challenge extends beyond technology alone. New requirements often affect operational processes, customer communications, database structures, and other critical business functions, making close coordination across multiple teams essential to successful implementation.

What makes implementation even more complex is the broad range of areas affected by these regulatory requirements. These often extend beyond technology, requiring modifications to operational processes, customer communications, database structures, and other critical business functions.

EW: You’ve developed what you call the Dual-Flow Operating Model to address those challenges. What recurring implementation problems led you to develop this framework, and what gap did you believe existing project approaches were failing to address?

DS: One recurring implementation challenge was developing a single approach that could effectively support both new and existing customers. Applying the same solution to both groups without recognizing their different circumstances would have created significant operational challenges. Existing customers needed additional regulatory information, but collecting it manually would have increased the workload for customer-facing teams while potentially changing customer risk ratings and the frequency of subsequent Know Your Customer (KYC) reviews.

The solution was to process both customer segments through the same Customer Onboarding (COB) journey, effectively treating existing customers as new customers for the purpose of completing the additional regulatory requirements. For existing customers, previously collected information was pre-populated into the onboarding process, minimizing duplication, reducing manual effort, and creating a more seamless customer experience while ensuring the newly required information was captured and assessed appropriately. 

EW: Once implementation moves from planning to execution, financial institutions must integrate change into complex, interconnected operating environments without disrupting critical business functions. How do you approach that challenge?

DS: Business continuity was the primary consideration when implementing these regulatory changes, particularly because the Customer Onboarding (COB) page supports hundreds of customer interactions each day. Introducing significant changes directly into the existing onboarding journey could have disrupted the customer experience and affected day-to-day business operations.

To mitigate that risk, we introduced an additional validation layer to determine whether a customer was new or existing before initiating the appropriate onboarding flow. Existing customers were not asked to provide information already available in the system and instead completed only the newly required regulatory fields, minimizing disruption and eliminating unnecessary duplication of data. 

New customers continued through the standard onboarding process with the additional eKYC questions incorporated into the journey. This implementation preserved business continuity by introducing the required regulatory changes without significantly disrupting customer interactions or ongoing operations. 

Technology changes alone were not enough. We also established a structured customer engagement plan, with communication teams proactively explaining the regulatory changes, outlining the required actions, and encouraging existing customers to provide the information needed to maintain compliance. 

EW: Over the course of your career, you’ve been entrusted with directing enterprise-scale enhanced KYC initiatives within some of the world’s largest financial institutions. What lessons from those implementations proved most influential in shaping the Dual-Flow Operating Model?

DS: The primary objective of this regulatory change was to collect additional customer information that would strengthen the organization’s ability to identify and mitigate risks associated with fraud, money laundering, unlawful funding, and shell companies. Because the change directly affected customers, the implementation approach required careful consideration.

A single, standardized approach would not have been effective because customers present different levels of risk based on factors such as industry and business model. For example, businesses operating in higher-risk sectors, such as casinos or marijuana dispensaries, require greater scrutiny than lower-risk businesses such as convenience stores or ice cream shops. 

Applying the same review requirements to every customer would have used technology and operational resources inefficiently. A risk-based approach allowed customers to be reviewed according to their assigned risk rating, with high-risk customers reviewed annually, medium-risk customers every two years, and low-risk customers every five years. 

The Dual-Flow Operating Model supported this approach by prioritizing high-risk customers for eKYC completion and remediation and maintaining appropriate review cycles for medium- and low-risk customers. That enabled the organization to satisfy regulatory requirements efficiently while optimizing technology and operational resources and minimizing unnecessary customer impact. 

EW: Regulatory transformation requires coordination across technology, operations, compliance, enterprise architecture, business leadership, and external stakeholders. What governance practices have you found most effective for keeping those groups aligned throughout complex implementation programs?

DS: One of the most effective practices was adopting the Scaled Agile framework. Given the scale and complexity of the implementation, coordinating multiple teams was essential to ensure the right resources were available at the right time while minimizing delivery risks and execution gaps.

Program Increment (PI) Planning provided a structured process for reviewing requirements with each impacted team, clarifying responsibilities, identifying dependencies, and prioritizing work within each quarterly planning cycle. Because this was a regulatory initiative with fixed compliance deadlines, PI Planning also helped secure the necessary prioritization across the organization. 

In addition, we established a weekly governance forum, known as the Scrum of Scrums, to monitor progress and maintain alignment across participating teams. During these sessions, we reviewed delivery status, tracked cross-team dependencies, identified emerging risks, and resolved issues before they affected implementation. 

This governance model improved program transparency, enabled earlier risk mitigation, and kept teams aligned around the shared objective of delivering the regulatory changes within the required timeline. 

EW: Every major implementation leaves an organization different than it was before. What changes tell you a regulatory program has strengthened the institution beyond meeting its immediate compliance objectives?

DS: Every regulatory implementation brings its own challenges and lessons. One of the most important from this program was the value of incorporating sufficient time buffers into future regulatory initiatives. Although the team delivered the implementation within the required timeline, building in an additional six months would provide greater flexibility to manage unforeseen risks, dependencies, and implementation complexities.

We also place significant emphasis on maintaining a comprehensive Lessons Learned repository. Documenting insights from each implementation allows the organization to build on prior experience, avoid repeating challenges, and improve the efficiency and effectiveness of future programs. 

Another important lesson was a new perspective on business continuity. This implementation demonstrated that organizations can continue introducing new capabilities while maintaining stable, uninterrupted operations. By minimizing disruption to existing systems, regulatory changes can be delivered more efficiently without compromising the customer experience or day-to-day business activities. 

The organization can continue applying this implementation model and the lessons learned to accelerate future regulatory initiatives while maintaining system stability, operational continuity, and a consistent customer experience.

EW: One unintended consequence of many regulatory initiatives is the accumulation of technical debt. How can technology leaders avoid solving today’s compliance challenges in ways that create larger modernization problems tomorrow?

DS: Technology organizations often prioritize immediate delivery and short-term objectives over building robust, sustainable solutions. In financial services, the pressure to meet regulatory deadlines and avoid compliance consequences can overshadow the broader impact of those changes across the technology landscape, leading to compromises in functionality, system capabilities, and long-term maintainability.

Time and budget constraints can also lead organizations to rely on manual processes instead of automation. While that may address an immediate need, it increases operational dependence on employees and contributes to technical debt over time. 

The eKYC implementation presented exactly this challenge. Had we focused only on onboarding new customers by adding additional questions to the Customer Onboarding (COB) page, the corresponding fields for existing customers would have remained blank. Although that approach might have satisfied the immediate regulatory requirement, it would also have created significant technical debt and long-term data integrity issues. 

Instead, we developed a solution that supported both new and existing customers while consistently capturing the required information. That addressed the immediate regulatory requirement and established a more scalable, sustainable technology foundation. 

I think of technical debt like railway tracks. A small deviation may seem insignificant at the beginning, but over time it can lead to a very different destination. Addressing technical debt early and investing in robust solutions prevents much greater costs, complexity, and operational challenges later. 

EW: Financial institutions are modernizing cloud platforms, replacing legacy infrastructure, and responding to new regulatory requirements at the same time. Based on your experience leading these programs, what guidance would you offer organizations for coordinating these initiatives, so they reinforce one another instead of competing for resources?

DS: I encountered a similar challenge while leading a program that combined legacy platform modernization with a critical regulatory implementation. Although managing both initiatives simultaneously is complex, it is achievable with careful planning, governance, and resource allocation.

My recommendation is to manage modernization and regulatory work as parallel, coordinated workstreams. Treating regulatory implementation as an isolated effort without considering the modernization roadmap increases development complexity and often creates unnecessary rework. 

The underlying architectures are also fundamentally different. Legacy platforms often rely on tightly coupled, on-premises systems, while modern cloud environments use distributed architectures, microservices, and cloud-native infrastructure. Implementing regulatory changes without considering the future-state architecture can increase technical debt and make later migrations more difficult. 

The two initiatives can still progress in parallel because they address different objectives:   the modernization effort migrates the broader application, and the regulatory program focuses on specific business and compliance requirements. For example, selected application components can move to the cloud while regulatory enhancements continue within the legacy environment, allowing compliance obligations to be met without slowing long-term modernization. 

If priorities must be adjusted, regulatory requirements should come first because they carry mandatory deadlines and significant financial, operational, and reputational consequences. Modernization initiatives remain essential, but they can usually be sequenced more flexibly. 

The objective is to advance both initiatives whenever possible while designing regulatory changes with the future technology architecture in mind. That approach minimizes technical debt, reduces rework, and ensures short-term compliance investments also support long-term modernization. 

EW: Artificial intelligence is increasingly influencing software delivery, governance, operational monitoring, and regulatory processes across financial services. Where do you believe AI can strengthen transformation efforts, and where should organizations continue to rely on experienced human judgment?

DS: Artificial Intelligence (AI) has significantly improved the way we work by making tasks such as data retrieval, data analysis, pattern identification, and data-driven decision-making faster and more efficient. At the same time, human experience and judgment remain difficult to replicate. The objective is not to automate everything, but to identify where AI delivers the greatest value while preserving human expertise where it matters most.

We apply that principle throughout our technology programs. For example, governance and operational monitoring now use AI to automate reporting, track delivery progress, identify deviations from expected trends, and highlight potential risks, allowing teams to focus their attention where intervention is actually needed.

Software development and complex technology changes still depend heavily on human expertise. AI may generate code that satisfies a technical requirement, but experienced technology professionals also consider future business needs, system dependencies, scalability, maintainability, and long-term architectural implications.

The greatest value comes from combining AI with experienced human judgment. AI can improve productivity, automate repetitive tasks, and generate valuable insights, while people remain essential for strategic decision-making, governance, complex problem-solving, and anticipating future needs that extend beyond the available data.

EW: Financial institutions will continue balancing new compliance obligations with modernization initiatives for years to come. If you could leave technology and business leaders with one guiding principle for managing that balance, what would it be?

DS: Financial institutions will continue to invest in cloud computing, Artificial Intelligence (AI), machine learning, automation, and advanced analytics to improve operational efficiency, strengthen regulatory compliance, and enhance customer experiences. At the same time, organizations must integrate these technologies in ways that support long-term business strategy and evolving regulatory expectations.

Technology leaders should view regulatory change as an opportunity to strengthen operating models, improve business processes, and modernize technology platforms. Organizations that build flexibility into their architecture and governance will be better positioned to respond efficiently as regulations, customer expectations, and new technologies emerge.

In my experience, the most effective approach has been to prioritize high-impact, “must-have” changes while ensuring these initiatives remain aligned with the organization’s broader modernization strategy. When there are no immediate regulatory compliance obligations or other critical business priorities requiring attention, organizations should proactively allocate capacity to address technical debt, modernize legacy components, and improve overall system resilience.

Regulatory and compliance requirements may require changes to a specific part of the system, but the broader technology ecosystem must remain robust. Focusing only on the immediate compliance requirement without addressing the underlying technical landscape can increase technical debt and create future implementation challenges.

From a system owner’s perspective, finding the right balance between immediate priorities and long-term technology investments is critical. The objective is to meet mandatory business and regulatory requirements while continuously strengthening the technology foundation so the organization remains agile, resilient, scalable, and prepared for future demands.

Comments

TechBullion

FinTech News and Information

Copyright © 2026 TechBullion. All Rights Reserved.

To Top

Pin It on Pinterest

Share This