The Singapore FinTech Association (SFA) and KPMG in Singapore (KPMG) today launched “Strategic Cloud Adoption in Financial Services: Governing Risk & Scaling RegTech”, a report examining how financial institutions (FIs) in Singapore and across Asia-Pacific are adopting cloud-based regulatory technology (RegTech), and the challenges holding wider adoption back.
The report brings together perspectives from FIs, RegTech providers, cloud service providers, system integrators (SIs) and the Monetary Authority of Singapore (MAS). It addresses the cloud security considerations facing FIs as they deploy RegTech across Singapore and the wider Asia-Pacific region and proposes a common framework for adopting RegTech capabilities without compromising security and risk management.
Today, cloud is no longer treated as an optional infrastructure decision. It now sits behind AI adoption, advanced analytics and much of what RegTech is expected to deliver next, with hybrid and multi-cloud architectures becoming the operating norm. The report finds that the constraints on wider adoption are rarely technological. Institutions continue to struggle to translate principle-based regulatory expectations into consistent daily practice, to establish clear accountability across a widening group of providers, and to sustain cloud-native compliance systems once they have gone live.
Key findings from the report include:
AI and agentic AI use cases require scalable compute, large-scale data processing and rapid model iteration, placing them beyond the reach of most on-premises estates, and 77% of the RegTechs surveyed favour cloud-native deployment. Small and mid-sized FIs are moving fastest, drawn by scalability, cost efficiency and speed of deployment, while many are exploring hybrid or multi-cloud models to avoid dependence on any single provider.
RegTech itself continues to move from manual processes to automation and, increasingly, to AI-assisted decision-making, although most institutions expect to retain a human in the loop for the foreseeable future.
MAS noted that financial institutions are increasingly turning towards innovation and technology for solutions. For this reason, MAS clarified in 2016 that there were no objections to FIs using the cloud if they put in place robust governance and risk management. This is supported by existing regulatory guidelines that give FIs the flexibility to adopt private, public, or hybrid cloud arrangements.
The shared responsibility model is widely understood in principle but unevenly applied in practice, and it becomes more difficult to apply as institutions move from infrastructure services into SaaS and AI-driven services, where the boundary between provider-managed and customer-owned controls is less visible. While CSPs and RegTech providers may handle encryption, key management and infrastructure security, governance, oversight and the consequences of an incident ultimately remain with the FI. Materiality determines how far an institution relies on its providers. For lower-risk workloads, FIs are generally comfortable relying on provider-managed controls, but as workloads become material, oversight moves firmly back in-house.
A fundamental principle already established under the MAS’ Technology Risk Management (TRM) Guidelines and the Guidelines on Outsourcing (Financial Institutions other than Banks) is that accountability remains with the FI, including its board and senior management, regardless of the extent of outsourcing.
Accordingly, FIs should ensure that outsourcing arrangements adequately address identified risks, allow for timely renegotiation, renewal, or exit, and preserve sufficient control to meet regulatory obligations, as well as apply oversight that is commensurate with the materiality and risk of the arrangement.
To make this workable in practice, the report sets out a risk-tiered operating model covering how workloads are classified, responsibilities across infrastructure, data, monitoring and incident response, how much assurance each risk tier warrants, and the governance checkpoints required from design through to exit.
Ninety-four percent of the RegTechs surveyed reported encountering FI hesitancy over cloud, and the reasons given point largely to institutional readiness rather than to the technology itself.
Gaps persist in foundational controls such as identity and access management, logging, network segmentation and data governance, while cloud security and AI talent remains in short supply. SIs add that FIs routinely underestimate the data engineering involved, that procurement and security approvals slow projects down, and that teams are frequently left without the skills to operate a solution once the integrator has completed its work.
Data residency and cross-border requirements continue to shape architectural decisions, with FIs retaining personally identifiable information in-house wherever possible and applying tokenisation, anonymisation and abstraction where data must move, for example by replacing exact dates of birth with age bands. Providers note that regional deployment models and advanced encryption already address many sovereignty concerns but remain underused, largely because firms are uncertain how supervisors will view them.
The report characterises the primary gap not as a lack of regulatory intent, but as the difficulty of translating that intent into practical, defensible operating models, particularly for AI-driven use cases.
Providers describe a due diligence process that repeats itself unnecessarily. Although certifications such as SOC 2 and ISO 27001 are widely held, they are not consistently relied upon, leaving vendors to answer variations of the same questionnaire for every client at a cost that yields little additional risk insight. Expectations around what constitutes sufficient testing also remain unsettled, particularly for AI-enabled tools.
The report calls for reusable “adoption kits” comprising security packs, deployment blueprints, control mappings and responsibility matrices, supported by assurance that can be independently verified. With around 65% of RegTechs operating a single core architecture with limited configurability, greater agreement on standards would also reduce the customisation required to meet institution-specific requirements.
A pragmatic, risk-based approach to due diligence and ongoing oversight is essential. While FIs may leverage third-party attestations (e.g., SOC 2, ISO 27001, CSA STAR), independent reviews, and market intelligence, they remain ultimately accountable for maintaining continuous monitoring and ensuring ongoing relevance and reliability of external assurances.
Concentration risk in the CSP market is treated as a structural feature rather than something diversification alone will resolve. The report recommends standardised RACI models across the cloud and RegTech stack, contractual clarity on roles and liabilities, dependency mapping, and exit strategies capable of withstanding supervisory scrutiny.
The business case has moved well beyond cost efficiency. Publicly reported case examples cited in the report show cloud- and AI-enabled RegTech reducing false positives and alert handling effort by approximately 60 to 80%, manual reporting workload by around 60% and release cycles by roughly 85%, with audit response times up to three times faster. FIs nonetheless continue to find these gains difficult to evidence within their own environments, and are increasingly framing the case around regulatory agility, cross-border reach and access to AI capabilities they would struggle to build and sustain independently.
Realising those benefits depends on the governance questions being settled first, and agentic AI illustrates the point most clearly. Where a CSP hosts a model without training or governing it, customers and providers frequently disagree over who owns the resulting risk, and that disagreement tends to surface in contract negotiations and assurance reviews.
In conclusion, the next phase of cloud maturity will be determined by the effectiveness of collaboration across the ecosystem rather than by technological capability alone. Several themes are expected to shape the landscape ahead, including greater adoption of AI-enabled solutions, increased use of cloud-native architectures, enhanced automation of compliance and risk management processes, and stronger industry-wide approaches to data governance and operational resilience. Governance frameworks, accountability mechanisms and risk management practices will need to keep pace as these technologies mature.
The report also sets out next steps for the industry, including:
Holly Fang, President of the Singapore FinTech Association, said, “The industry has moved past the question of whether cloud belongs in regulated financial services. The conversation now is about how we adopt it well. Institutions are working with more technology partners than ever before, and that only works when everyone is clear about who owns what. The SFA will continue working closely with MAS and industry stakeholders to strengthen cloud adoption, address emerging risks and build the governance foundations the industry needs, so that Singapore remains a leading centre for responsible financial innovation.”
Sinchan Banerjee, Partner, Financial Services Consulting, KPMG in Singapore, said: “Cloud is no longer just an infrastructure decision. It is a strategic prerequisite for AI, regulatory agility and the future of compliance. The challenge is no longer adoption, but governance at scale. The institutions that will lead are those that can translate regulatory expectations into practical operating models with clear accountability across an increasingly complex ecosystem of partners, platforms and AI solutions.”
The full report is available for download at https://singaporefintech.org/publications/.