The role of the chief compliance officer (CCO) at financial institutions has evolved as technology, automation and access to data present new opportunities and challenges for executives.
“Today’s compliance officer faces that very burdensome trade-off of creating a really good frictionless experience for their end users … but also building compliance confidence within their organization,” Jennifer Sun, chief executive at financial compliance software provider StarCompliance, tells Bank Automation News in this episode of “The Buzz” podcast.
The onus is on compliance officers to better leverage data by becoming educated in technology, automation, artificial intelligence and machine learning in order “to be able to actually do the job of a modern CCO today,” Sun says.
Listen as Sun and StarCompliance Chief Technology Officer David Rowland discuss the dynamic role of compliance officers as technology advances at financial institutions.
Bank Automation Summit Fall 2022, taking place Sept. 19-20 in Seattle, is a crucial event on automation and automation technology in banking. Learn more and register for Bank Automation Summit Fall 2022.
Subscribe to The Buzz Podcast on iTunes, Spotify, Google podcast, or download the episode.
The following is a transcript generated by AI technology that has been lightly edited but still contains errors.
Hello, and welcome to The Buzz, a bank automation news podcast. My name is Whitney McDonald, and I’m the deputy editor of bank automation news. I’m joined by StarCompliance CEO Jennifer Sun and CTO David Rowland, they discussed how big data has changed the role of the Chief Compliance Officer.Jennifer Sunn 00:24
Prior to coming to star and working with a compliance officer client base, I don’t think that I fully appreciated how hard their job is, they have really, really intense jobs. And it is, honestly, it’s not for the faint of heart, I’m just continuously impressed with all of the things that compliance officers have to do. If you just look at their you know, in the end, we’re talking about like 30,000 feet, the trade offs that they have to make every day is number one, their job is to create, you know, a culture of compliance or create compliance confidence within their organization, which gives their CEO and their leadership team a sense that, hey, you’re on it, and that when you’re on it, I’m going to feel comfortable that our risk and our exposure is low. Okay. But then, from a compliance standpoint, in order to give that compliance confidence, you actually have to put a lot of policies and controls in place. And sometimes you can kind of overdo that, where your desire to make it a riskless environment creates all of these overburdening controls. And it puts a lot of burden on your employees to actually have to do a lot of things manually paperwork, email, disclosures, etc. And then your employees don’t want to do it. Okay, so today’s compliance officer faces that very burdensome trade off of creating a really good frictionless experience for their end users, which are the employees, but also building compliance confidence within their organization, okay. And they know they have to do both, okay, so either A, you could lock everything down, and then create the most riskless environment as possible, but then you will slow down your business, okay. Or you could just open all the floodgates and let everybody do everything, it speeds up business decision making, obviously, because you don’t have all these controls in place, but then you create a lot of risk. And so today’s CCO, and this is where I think vendors and automation and data come in, they have to look for better solutions that enable them to be in this like better and more optimized state, which is I want to create a really great compliance culture for my company. But I want to employ compliance programs and ways of doing it that isn’t so burdensome, that our employees just say, forget it, I’m not going to do it. Okay. And so like, that’s where the automation and the data come in. Okay. Some of the most interesting discussions that I’ve had with our customers is about the changing nature of the compliance managers job. So having set the stage for what I just said, and the fact that they’re now going to use more technology and more data, the most interesting thing is a lot of them do not have this skill set. Okay. Traditional compliance managers came into the industry a decade two decades ago, they’re super experienced in regulation. They’re super experienced in policy. But they’re not technologists, they don’t understand software. And they don’t understand. They know what data is physically there. But they don’t know how to use it, how to report it, how to aggregate it, how to manipulate it, how to search for it, and all the different things that they need to do to be able to actually do the job of the modern CCO today. And so in talking to our clients, I’m always curious. Okay, so where has your job changed? Right? And what are the things that you need to do to be better at that job? And it’s really, really fascinating to see that sort of evolution. Right. So the old CCO you know, I mean, the, you know, the stereotype of the CCO is like, Oh, you’re the rule enforcer, right? You’re the person, the guy or the girl that’s always saying, no, no, no, no, no, but that today’s CCO can’t be that sort of rigid rule enforcer anymore. They actually have to be seen as a business partner. Okay. So to be seen, as a business partner, you have to use compliance data to say no where you really need to, but also find more ways to say yes, to help your, your your business move forward. Okay. And that’s understanding risk. So you can say, okay, that’s actually not that as bad as I thought, let’s approve that. Another area where, where and we spoke about it before was the old day compliance officer was all about locking down risks. He can’t do anything. And now they have this whole new purpose. It’s about building compliance, culture, confidence, and the creating let let’s call it a frictionless experience for Your employees. The second thing that they’re doing is they’re changing their mindsets, or they’re forced to change their mindsets from that of who was seen traditionally as a blocker, and changing now, their role within their organizations as seen as a collaborator, right, that’s the kind of partner to the business that we talked about. In doing that, and being more as a partner to the business and collaborating, you can’t just be somebody that looks at information after the fact, you actually have to use information and data to actually be way more proactive. But in order to be proactive, you can’t just look at data in silos, and fragmented fragmented anymore, you actually have to use data to give you a more holistic view of everything going around on in your and the risks going on in your organization. So that you can actually be on the front foot in your decision making, as opposed to the back foot. And then the last thing, which we alluded to already, is they have to understand technology now. And they have to get super educated about data. Because automation, artificial intelligence, the use of machine learning, is really starting to come to reg tech now. And the modern compliance officer needs to understand that. And so I would say, if you like looked at a timeline of evolution, on where CCOs are today, it’s honestly, it’s a mixed bag, it’s a mixed bag, you have, you know, old time CCOs that have been in the seat for two decades. And they’re not quite there, you have those in their mid in their career, where they’re in their sort of late 30s. You know, they’re in their 30s, where they’re young enough that they know a lot of software and data, but they also are experienced enough in regulation and policy, and, you know, the the old ways of doing things, and they’re definitely in transition. And then you have, you know, newer CCOs into the industry that are very, very software driven, and very automation and data driven. And they are probably more forward thinking more aggressive in investing dollars into this particular area. And I definitely see that we have we encounter all the time. I know customers in all three of those buckets. David, you want to speak a little bit about like some of those challenges that they face, though, in the decision making of how to adopt, you know, data technology? Because there are definitely challenges there.David Rowland 07:22
There are and I think Jen touched on a great point, right. So, you know, typically speaking, compliance teams don’t have, you know, a team of data scientists, they are not, you know, people write in Python, querying large data warehouses and pulling out, you know, anomalies from, you know, just masses and masses of data. And I think one of the things that we’ve been trying to do at Star and have built some, some really great products and solutions around is giving compliance teams tools that allow them to do that. But for a regular end end user, so we’re sort of simplifying their experience by doing the heavy lifting. So you don’t have to be a data scientist, he can still, you know, do anomaly detection, you can still look at outliers and patterns, and you know, zoned in on things that are, you know, the real hotspots in your organization. And I think one of the foundations to this is having a really good data strategy and being able to expand and grow that data set, because it’s, it’s not just one point of data, like Jen said earlier, it’s getting that holistic view of data. So unless you’ve really thought through that, that data strategy piece, you have a way of bringing that data together. And then querying all that data collectively and joining the dots of that data. This this type of analytics is quite hard to do. So for example, using modern Cloud Data Warehousing tools, like snowflake, right, which gives you pretty much unlimited storage and compute and flexibility in terms of how you bring data together. Clients can bring their own data in there that may not even be part of our platform, it’s important for them to, to join together with with our data to give them the right type of insights. And then layering sort of end user friendly technology on top of that, Modern BI tools, thought sports a great example of a BI tool that gives a sort of natural language interface to a user to write English language queries to search data. And it has built in AI models to generate the most suitable output of that data, you know, whether it’s a certain type of chart or whether it’s, you know, identifying, you know, select criteria within a query or tamasic for you. So using a combination of these tools, and really, really simplifying it from a technology point of view for end users who aren’t, you know, experienced in complex for more technical tools that developers have data scientists used today, don’t think thatJennifer Sun 10:21
that’s a point worth, like spending, there’s a couple more minutes on, because, you know, we’ve all heard that sort of term, you know, crawl, walk and run. And that’s really describing the evolution of big data within, you know, our compliance space is that, because there’s so much of it coming in different places, it’s actually extremely complex for one organization, actually, to do it themselves. Okay. So imagine bringing together all your employee, you know, compliance data, with all of your third party trading, you know, your your trading data, everybody’s e communications data, your news and other third party data, actually, most companies can’t even get their arms around how to do it, okay? It’s actually really complicated. Actually, a lot of vendors don’t know how to do it either. And it’s still at the early stages in the compliance, you know, space, we’re all kind of moving in that direction, but learning as we go along. So knowing that, and then knowing the evolution of the CCO and the job and the things that they need to do. That’s why we’ve taken the approach that David described is if we went from taking a traditional CCO, and then suddenly saying, oh, big data, AI, ml, and you have to do all these things. And by the way, in order to get these things, you have to figure out your data, your data, your data, privacy policy, your data, your information, security policy, your data localization policy, your this policy, honestly, I think we would scare them away. And I would be scared, because it would be too much for anyone to take on, frankly, a bit too much for us to take on, even for our clients. And so then we started to break it down into more manageable pieces. And we said, okay, there’s a lot of data out there. How can we ease the industry and ease our clients into it, where what we are doing is matching were their own evolution of their skill set, their experiences and their thinking are, right. And it’s using more sophisticated databases like snowflake and using more visualization tools, like a thoughtspot, to take traditionally data that a human being compliance analyst would literally have to go through an Excel and actually display it on his screen, get as easy for them to digest and see problems, you know, right away. So for example, let’s say you have a quarterly certification, okay, most financial services firms every single quarter, they need employees to attest, or to certify to something, you know, within the organization. So quarterly certifications go out. It’s really, really important for companies to ensure that 100% of their employees are certified or attesting to their understanding of certain policies or regulations. In the old days, it would be about like you’re sending out certifications by email, and you’re using Survey Monkey or some other type of basic survey thing. And some compliance analyst is literally cross analyzing the employee base with how many responses they got, okay, today, down to the line manager, we can whether you’re managing 20 people or 500 people, we can actually give you very, very quick dashboards that say, Hey, of the 500 people that you are monitoring under your supervision, 415 of them have completed their certifications 85 of them have not. And by the way, those 85 are located in this country, that country, this country in this department, that division in that team, right. And so that manager can very pinpoint very quickly, where are the areas of exposure on and then automatically follow up with those people in a very timely and targeted way. Okay,
David Rowland 13:48
just to interject a little bit there as well. I think one of the things is it using modern tools like this as well, it’s not, it’s not just about, you know, representing data in a different way, like using charts instead of tables. It’s all around insight generation, like actionable insight generation. So, aside from some of those examples that Jen is looking at there, I’ll just described, you male also look at like just historical results, like Have you got a, you know, a group of people are always late, or, you know, always late plus have, you know, preclearance exceptions as well like is there sort of bad behaviors that you can sport across different parts of your collected data set, and actually be surfacing these things up that just give a compliance person a more 360 view of that situation or that person?
Jennifer Sun 14:44
We have some clients that are in the asset management and the hedge fund space, that have a lot of volume of trading activity, and they are very on top of the potential risks, you know, of the Get insider trading, and they are actively monitor. And so we have a client in particular who has done a combination of using star compliance and building out their own technology. So, you know, they have had a very smart strategy, I might say where they go and employ vendor based technology for things that are, you know, that you can do off the shelf that they don’t have any, let’s call a technical advantages and building. And so for example, they’ll use star to do us, our core employee compliance suite. So they’re using us for personal trading gifts, an entertainment, you know, monitoring of political contributions outside business activities, and we generate probably about, you know, 75% of the data that comes out of their employee compliance program. But they also said, but hey, sorry, you don’t do trading complies, okay. But we have a ton of hedge fund managers, partners, employees that are in the business of trading, but that also trade in their own personal portfolio. And we want to be able to build a sort of a bridge between the trading activity and the personal and the employee activity. But we also want to marry a lot of the E communications, surveillance, right, because a lot of insider trading ended up getting found because of texts, because of, you know, emails because of phone calls. And so some of the more sophisticated hedge fund managers out there are tracking all three of those things, okay. And because it’s very difficult for the vendor community to tie all that together, because some of that data sits internally, we’ve had some of our more sophisticated clients. Take some initiative to build surveillance tools that bring in data from multiple sources. And monitor, you know it that way. Now, but they’ve also said that that’s really expensive. Okay, it’s really expensive to do all of that infrastructure for one company. And so they also have come to us and said, we already know how to do this, can you actually take it on and do it for us in a more cost effective way, because you have hundreds of clients that you can rationalize that across where we only have ourselves, okay, so that goes to tell you that the challenges, both technical and non technical, are so big and doing that, that individual firms don’t have the cost infrastructure to do it themselves. So there definitely is an opportunity for service providers like star to sort of enter that space, and really help the industry evolve their usage of data over time. And so that’s where I see sort of data going is over time, less rules based, and really using information to detect trends and anomalies, that then we can deduce, you know, and find, you know, bigger risks there.
Whitney McDonald 17:49
Is there anything that we missed, or that you wanted to touch on?
Jennifer Sun 17:55
You know, I will, I’ll leave you with one thought, because it’ll, it’ll hopefully, you know, lay the foundation for a future conversation, as our as the industry and big data, you know, start to evolve is, if you look at the primary use cases of data today, versus where I believe that it should go in the future, you know, people are using it for, you know, financial crime detection, they’re doing it for customer employee onboarding, they’re doing it for transaction monitoring. But really what they’re monitoring is they’re monitoring against whether or not people are following rules. Okay, so again, we talked about regulation, and then policies and controls. And today data is like, Okay, I have control ABC, is employee following ABC. Right. And so there’s a lot of data comparison, reconciliation, to find out which employees are following which rules, okay. But inherently, that means that you have to believe that your rules are correct, and that your rules are comprehensive, and that your rules are capturing everything. But the thing is, they do not okay, and every CCO knows that they know that their rules and controls in place, they believe capture the biggest, the biggest and most, most, most potential risky things, but they also know in the back of their head, it doesn’t capture everything. And what’s kind of scary is they don’t know what it doesn’t capture, right? And really smart employees who are going to inside or trade or they’re going to commit financial crime, they start to understand the rules, and they start to create their own Bad’s, you know, you know, bad actions to go around those roles. So just using data to detect if an employee is following a rule or not, is actually not going to be enough. Okay. And so what I what we see it star is that the future of big data isn’t about detecting rule following or not, it’s actually eliminating the thinking of using data to compare against rules, and instead using data to it aggregate information from lots of different sources and just look for trends, positive or negative, and look for anomalies, and use that to work backwards against reducing the negative activity, as opposed to just making it rules based, right? I’ll give you a really good example. You might have heard of a guy who goes under the name, temper X, his name, his real name is Tom harden. And back in 2008, he was a FBI informant who ended up helping the FBI break up, you know, a massive insider trading ring on Wall Street, where at least a dozen of his co workers and people in that sort of insider trading reign were ultimately brought to justice. And he came and did a presentation star about two years ago for our clients. And the thing that I totally take away. One of the main things I took away from his presentation is that actors don’t just like wake up one day, and they’re like, Oh, I’m going to Insider trade. And then they do that thing once. He said, it actually happens over time. It starts with something small, something innocuous, you get away with it, and you’re like, Oh, I’m getting away with that. And then it builds and builds and builds over time. And his point was, is that organizations didn’t look for the patterns. They didn’t look for those anomalies. And he said, If you really looked at what I was doing, and what the others that were insider trading around me, you would have caught me. But you weren’t looking for those things. All you were looking for was whether or not I was breaking a specific control rule. And of course, I know what the control rules are, so I can make sure I don’t break them. But behind the scenes, they were doing all sorts of things. But data and our policies were not catching the trends. They were looking for those things right. And he said, but if you were looking for those things, you would have caught us earlier.
Whitney McDonald 21:50
You’ve been listening to the buzz, a bank automation news podcast, please follow us on Twitter and LinkedIn. And as a reminder, you can rate this podcast on your platform of choice. Thank you for your time and be sure to visit us at Bank automation news.com For more automation news,
The role of the chief compliance officer (CCO) at financial institutions has evolved as technology, automation and access to data present new opportunities and challenges for executives.
“Today’s compliance officer faces that very burdensome trade-off of creating a really good frictionless experience for their end users … but also building compliance confidence within their organization,” Jennifer Sun, chief executive at financial compliance software provider StarCompliance, tells Bank Automation News in this episode of “The Buzz” podcast.
The onus is on compliance officers to better leverage data by becoming educated in technology, automation, artificial intelligence and machine learning in order “to be able to actually do the job of a modern CCO today,” Sun says.
Listen as Sun and StarCompliance Chief Technology Officer David Rowland discuss the dynamic role of compliance officers as technology advances at financial institutions.
Bank Automation Summit Fall 2022, taking place Sept. 19-20 in Seattle, is a crucial event on automation and automation technology in banking. Learn more and register for Bank Automation Summit Fall 2022.
Subscribe to The Buzz Podcast on iTunes, Spotify, Google podcast, or download the episode.
The following is a transcript generated by AI technology that has been lightly edited but still contains errors.
Hello, and welcome to The Buzz, a bank automation news podcast. My name is Whitney McDonald, and I’m the deputy editor of bank automation news. I’m joined by StarCompliance CEO Jennifer Sun and CTO David Rowland, they discussed how big data has changed the role of the Chief Compliance Officer.Jennifer Sunn 00:24
Prior to coming to star and working with a compliance officer client base, I don’t think that I fully appreciated how hard their job is, they have really, really intense jobs. And it is, honestly, it’s not for the faint of heart, I’m just continuously impressed with all of the things that compliance officers have to do. If you just look at their you know, in the end, we’re talking about like 30,000 feet, the trade offs that they have to make every day is number one, their job is to create, you know, a culture of compliance or create compliance confidence within their organization, which gives their CEO and their leadership team a sense that, hey, you’re on it, and that when you’re on it, I’m going to feel comfortable that our risk and our exposure is low. Okay. But then, from a compliance standpoint, in order to give that compliance confidence, you actually have to put a lot of policies and controls in place. And sometimes you can kind of overdo that, where your desire to make it a riskless environment creates all of these overburdening controls. And it puts a lot of burden on your employees to actually have to do a lot of things manually paperwork, email, disclosures, etc. And then your employees don’t want to do it. Okay, so today’s compliance officer faces that very burdensome trade off of creating a really good frictionless experience for their end users, which are the employees, but also building compliance confidence within their organization, okay. And they know they have to do both, okay, so either A, you could lock everything down, and then create the most riskless environment as possible, but then you will slow down your business, okay. Or you could just open all the floodgates and let everybody do everything, it speeds up business decision making, obviously, because you don’t have all these controls in place, but then you create a lot of risk. And so today’s CCO, and this is where I think vendors and automation and data come in, they have to look for better solutions that enable them to be in this like better and more optimized state, which is I want to create a really great compliance culture for my company. But I want to employ compliance programs and ways of doing it that isn’t so burdensome, that our employees just say, forget it, I’m not going to do it. Okay. And so like, that’s where the automation and the data come in. Okay. Some of the most interesting discussions that I’ve had with our customers is about the changing nature of the compliance managers job. So having set the stage for what I just said, and the fact that they’re now going to use more technology and more data, the most interesting thing is a lot of them do not have this skill set. Okay. Traditional compliance managers came into the industry a decade two decades ago, they’re super experienced in regulation. They’re super experienced in policy. But they’re not technologists, they don’t understand software. And they don’t understand. They know what data is physically there. But they don’t know how to use it, how to report it, how to aggregate it, how to manipulate it, how to search for it, and all the different things that they need to do to be able to actually do the job of the modern CCO today. And so in talking to our clients, I’m always curious. Okay, so where has your job changed? Right? And what are the things that you need to do to be better at that job? And it’s really, really fascinating to see that sort of evolution. Right. So the old CCO you know, I mean, the, you know, the stereotype of the CCO is like, Oh, you’re the rule enforcer, right? You’re the person, the guy or the girl that’s always saying, no, no, no, no, no, but that today’s CCO can’t be that sort of rigid rule enforcer anymore. They actually have to be seen as a business partner. Okay. So to be seen, as a business partner, you have to use compliance data to say no where you really need to, but also find more ways to say yes, to help your, your your business move forward. Okay. And that’s understanding risk. So you can say, okay, that’s actually not that as bad as I thought, let’s approve that. Another area where, where and we spoke about it before was the old day compliance officer was all about locking down risks. He can’t do anything. And now they have this whole new purpose. It’s about building compliance, culture, confidence, and the creating let let’s call it a frictionless experience for Your employees. The second thing that they’re doing is they’re changing their mindsets, or they’re forced to change their mindsets from that of who was seen traditionally as a blocker, and changing now, their role within their organizations as seen as a collaborator, right, that’s the kind of partner to the business that we talked about. In doing that, and being more as a partner to the business and collaborating, you can’t just be somebody that looks at information after the fact, you actually have to use information and data to actually be way more proactive. But in order to be proactive, you can’t just look at data in silos, and fragmented fragmented anymore, you actually have to use data to give you a more holistic view of everything going around on in your and the risks going on in your organization. So that you can actually be on the front foot in your decision making, as opposed to the back foot. And then the last thing, which we alluded to already, is they have to understand technology now. And they have to get super educated about data. Because automation, artificial intelligence, the use of machine learning, is really starting to come to reg tech now. And the modern compliance officer needs to understand that. And so I would say, if you like looked at a timeline of evolution, on where CCOs are today, it’s honestly, it’s a mixed bag, it’s a mixed bag, you have, you know, old time CCOs that have been in the seat for two decades. And they’re not quite there, you have those in their mid in their career, where they’re in their sort of late 30s. You know, they’re in their 30s, where they’re young enough that they know a lot of software and data, but they also are experienced enough in regulation and policy, and, you know, the the old ways of doing things, and they’re definitely in transition. And then you have, you know, newer CCOs into the industry that are very, very software driven, and very automation and data driven. And they are probably more forward thinking more aggressive in investing dollars into this particular area. And I definitely see that we have we encounter all the time. I know customers in all three of those buckets. David, you want to speak a little bit about like some of those challenges that they face, though, in the decision making of how to adopt, you know, data technology? Because there are definitely challenges there.David Rowland 07:22
There are and I think Jen touched on a great point, right. So, you know, typically speaking, compliance teams don’t have, you know, a team of data scientists, they are not, you know, people write in Python, querying large data warehouses and pulling out, you know, anomalies from, you know, just masses and masses of data. And I think one of the things that we’ve been trying to do at Star and have built some, some really great products and solutions around is giving compliance teams tools that allow them to do that. But for a regular end end user, so we’re sort of simplifying their experience by doing the heavy lifting. So you don’t have to be a data scientist, he can still, you know, do anomaly detection, you can still look at outliers and patterns, and you know, zoned in on things that are, you know, the real hotspots in your organization. And I think one of the foundations to this is having a really good data strategy and being able to expand and grow that data set, because it’s, it’s not just one point of data, like Jen said earlier, it’s getting that holistic view of data. So unless you’ve really thought through that, that data strategy piece, you have a way of bringing that data together. And then querying all that data collectively and joining the dots of that data. This this type of analytics is quite hard to do. So for example, using modern Cloud Data Warehousing tools, like snowflake, right, which gives you pretty much unlimited storage and compute and flexibility in terms of how you bring data together. Clients can bring their own data in there that may not even be part of our platform, it’s important for them to, to join together with with our data to give them the right type of insights. And then layering sort of end user friendly technology on top of that, Modern BI tools, thought sports a great example of a BI tool that gives a sort of natural language interface to a user to write English language queries to search data. And it has built in AI models to generate the most suitable output of that data, you know, whether it’s a certain type of chart or whether it’s, you know, identifying, you know, select criteria within a query or tamasic for you. So using a combination of these tools, and really, really simplifying it from a technology point of view for end users who aren’t, you know, experienced in complex for more technical tools that developers have data scientists used today, don’t think thatJennifer Sun 10:21
that’s a point worth, like spending, there’s a couple more minutes on, because, you know, we’ve all heard that sort of term, you know, crawl, walk and run. And that’s really describing the evolution of big data within, you know, our compliance space is that, because there’s so much of it coming in different places, it’s actually extremely complex for one organization, actually, to do it themselves. Okay. So imagine bringing together all your employee, you know, compliance data, with all of your third party trading, you know, your your trading data, everybody’s e communications data, your news and other third party data, actually, most companies can’t even get their arms around how to do it, okay? It’s actually really complicated. Actually, a lot of vendors don’t know how to do it either. And it’s still at the early stages in the compliance, you know, space, we’re all kind of moving in that direction, but learning as we go along. So knowing that, and then knowing the evolution of the CCO and the job and the things that they need to do. That’s why we’ve taken the approach that David described is if we went from taking a traditional CCO, and then suddenly saying, oh, big data, AI, ml, and you have to do all these things. And by the way, in order to get these things, you have to figure out your data, your data, your data, privacy policy, your data, your information, security policy, your data localization policy, your this policy, honestly, I think we would scare them away. And I would be scared, because it would be too much for anyone to take on, frankly, a bit too much for us to take on, even for our clients. And so then we started to break it down into more manageable pieces. And we said, okay, there’s a lot of data out there. How can we ease the industry and ease our clients into it, where what we are doing is matching were their own evolution of their skill set, their experiences and their thinking are, right. And it’s using more sophisticated databases like snowflake and using more visualization tools, like a thoughtspot, to take traditionally data that a human being compliance analyst would literally have to go through an Excel and actually display it on his screen, get as easy for them to digest and see problems, you know, right away. So for example, let’s say you have a quarterly certification, okay, most financial services firms every single quarter, they need employees to attest, or to certify to something, you know, within the organization. So quarterly certifications go out. It’s really, really important for companies to ensure that 100% of their employees are certified or attesting to their understanding of certain policies or regulations. In the old days, it would be about like you’re sending out certifications by email, and you’re using Survey Monkey or some other type of basic survey thing. And some compliance analyst is literally cross analyzing the employee base with how many responses they got, okay, today, down to the line manager, we can whether you’re managing 20 people or 500 people, we can actually give you very, very quick dashboards that say, Hey, of the 500 people that you are monitoring under your supervision, 415 of them have completed their certifications 85 of them have not. And by the way, those 85 are located in this country, that country, this country in this department, that division in that team, right. And so that manager can very pinpoint very quickly, where are the areas of exposure on and then automatically follow up with those people in a very timely and targeted way. Okay,
David Rowland 13:48
just to interject a little bit there as well. I think one of the things is it using modern tools like this as well, it’s not, it’s not just about, you know, representing data in a different way, like using charts instead of tables. It’s all around insight generation, like actionable insight generation. So, aside from some of those examples that Jen is looking at there, I’ll just described, you male also look at like just historical results, like Have you got a, you know, a group of people are always late, or, you know, always late plus have, you know, preclearance exceptions as well like is there sort of bad behaviors that you can sport across different parts of your collected data set, and actually be surfacing these things up that just give a compliance person a more 360 view of that situation or that person?
Jennifer Sun 14:44
We have some clients that are in the asset management and the hedge fund space, that have a lot of volume of trading activity, and they are very on top of the potential risks, you know, of the Get insider trading, and they are actively monitor. And so we have a client in particular who has done a combination of using star compliance and building out their own technology. So, you know, they have had a very smart strategy, I might say where they go and employ vendor based technology for things that are, you know, that you can do off the shelf that they don’t have any, let’s call a technical advantages and building. And so for example, they’ll use star to do us, our core employee compliance suite. So they’re using us for personal trading gifts, an entertainment, you know, monitoring of political contributions outside business activities, and we generate probably about, you know, 75% of the data that comes out of their employee compliance program. But they also said, but hey, sorry, you don’t do trading complies, okay. But we have a ton of hedge fund managers, partners, employees that are in the business of trading, but that also trade in their own personal portfolio. And we want to be able to build a sort of a bridge between the trading activity and the personal and the employee activity. But we also want to marry a lot of the E communications, surveillance, right, because a lot of insider trading ended up getting found because of texts, because of, you know, emails because of phone calls. And so some of the more sophisticated hedge fund managers out there are tracking all three of those things, okay. And because it’s very difficult for the vendor community to tie all that together, because some of that data sits internally, we’ve had some of our more sophisticated clients. Take some initiative to build surveillance tools that bring in data from multiple sources. And monitor, you know it that way. Now, but they’ve also said that that’s really expensive. Okay, it’s really expensive to do all of that infrastructure for one company. And so they also have come to us and said, we already know how to do this, can you actually take it on and do it for us in a more cost effective way, because you have hundreds of clients that you can rationalize that across where we only have ourselves, okay, so that goes to tell you that the challenges, both technical and non technical, are so big and doing that, that individual firms don’t have the cost infrastructure to do it themselves. So there definitely is an opportunity for service providers like star to sort of enter that space, and really help the industry evolve their usage of data over time. And so that’s where I see sort of data going is over time, less rules based, and really using information to detect trends and anomalies, that then we can deduce, you know, and find, you know, bigger risks there.
Whitney McDonald 17:49
Is there anything that we missed, or that you wanted to touch on?
Jennifer Sun 17:55
You know, I will, I’ll leave you with one thought, because it’ll, it’ll hopefully, you know, lay the foundation for a future conversation, as our as the industry and big data, you know, start to evolve is, if you look at the primary use cases of data today, versus where I believe that it should go in the future, you know, people are using it for, you know, financial crime detection, they’re doing it for customer employee onboarding, they’re doing it for transaction monitoring. But really what they’re monitoring is they’re monitoring against whether or not people are following rules. Okay, so again, we talked about regulation, and then policies and controls. And today data is like, Okay, I have control ABC, is employee following ABC. Right. And so there’s a lot of data comparison, reconciliation, to find out which employees are following which rules, okay. But inherently, that means that you have to believe that your rules are correct, and that your rules are comprehensive, and that your rules are capturing everything. But the thing is, they do not okay, and every CCO knows that they know that their rules and controls in place, they believe capture the biggest, the biggest and most, most, most potential risky things, but they also know in the back of their head, it doesn’t capture everything. And what’s kind of scary is they don’t know what it doesn’t capture, right? And really smart employees who are going to inside or trade or they’re going to commit financial crime, they start to understand the rules, and they start to create their own Bad’s, you know, you know, bad actions to go around those roles. So just using data to detect if an employee is following a rule or not, is actually not going to be enough. Okay. And so what I what we see it star is that the future of big data isn’t about detecting rule following or not, it’s actually eliminating the thinking of using data to compare against rules, and instead using data to it aggregate information from lots of different sources and just look for trends, positive or negative, and look for anomalies, and use that to work backwards against reducing the negative activity, as opposed to just making it rules based, right? I’ll give you a really good example. You might have heard of a guy who goes under the name, temper X, his name, his real name is Tom harden. And back in 2008, he was a FBI informant who ended up helping the FBI break up, you know, a massive insider trading ring on Wall Street, where at least a dozen of his co workers and people in that sort of insider trading reign were ultimately brought to justice. And he came and did a presentation star about two years ago for our clients. And the thing that I totally take away. One of the main things I took away from his presentation is that actors don’t just like wake up one day, and they’re like, Oh, I’m going to Insider trade. And then they do that thing once. He said, it actually happens over time. It starts with something small, something innocuous, you get away with it, and you’re like, Oh, I’m getting away with that. And then it builds and builds and builds over time. And his point was, is that organizations didn’t look for the patterns. They didn’t look for those anomalies. And he said, If you really looked at what I was doing, and what the others that were insider trading around me, you would have caught me. But you weren’t looking for those things. All you were looking for was whether or not I was breaking a specific control rule. And of course, I know what the control rules are, so I can make sure I don’t break them. But behind the scenes, they were doing all sorts of things. But data and our policies were not catching the trends. They were looking for those things right. And he said, but if you were looking for those things, you would have caught us earlier.
Whitney McDonald 21:50
You’ve been listening to the buzz, a bank automation news podcast, please follow us on Twitter and LinkedIn. And as a reminder, you can rate this podcast on your platform of choice. Thank you for your time and be sure to visit us at Bank automation news.com For more automation news,






