Financial services licensees must ensure IT change management, pre-implementation testing, and detective controls for regulatory reporting systems are robust and regularly reviewed end-to-end, not merely self-assessed via RCSAs. The $35m penalty signals that systemic, long-duration reporting failures—even if unintentional and arising from operational-level IT deficiencies—will attract very substantial penalties, particularly where internal reviews identified risks but failed to drive remediation.
The full text is available to signed-in members.