Blog

What Happens When Your Communications Compliance Fails? The New Operational Resilience Challenge

Financial Institutions
Compliance Resilience - hand holding a mobile phone with a tablet on the desk behind
5 min read

Share:

The European Union’s Digital Operations and Compliance Act (DORA) first came into effect in January 2025. 18 months later, financial firms and regulators have a clearer picture of the impact of the regulation, how compliance departments are adapting to the digital transformation, and what companies still need to do to ensure effective cybersecurity practices in the age of AI and wireless comms.

Summarize this article with AI

For financial institutions operating in the European Union, DORA is one of the “Big 2” regulatory frameworks, along with MiFID II. Where MiFID concerns companies' internal recording measures, DORA widens its scope to regulating and assessing businesses’ resilience in the face of external threats and data breaches.

The regulation is a response to an increasingly interconnected technological supply chain. Cyberattacks and communications failures often affect multiple companies simultaneously, with DORA conceived as a Europe-wide attempt to mitigate this risk. The 2024 CrowdStrike outage threw this into sharp relief. When the American cybersecurity company incorrectly installed an update to its systems, the resulting downtime affected hundreds of its clients, crashing websites around the world, grounding flights, and costing clients an estimated $4.5 billion in revenue.

The same year, the Swiss banking authority FINMA revised its guidelines for operational risk management, “taking account of advancing technological developments...particularly in connection with information and communication technology, handling critical data and cyber risks”.

As mobile communications continue to establish itself as an integral requirement for the contemporary financial industry, recording and regulatory compliance is now widely understood to be an integral aspect of operational resilience, rather than an administrative obstacle.

Maintaining compliance in the AI era

Any long-term regulatory thinking must also contend with one of the most transformational and fast-moving technologies to enter the financial world in decades: artificial intelligence.

AI has become integral to both financial cybersecurity and crime, used both to mitigate and facilitate new forms of cyberattack. The European Union’s cybersecurity agency ENISA has stated that artificial intelligence is a “defining element of the threat landscape”, used in 80% of all phishing and social engineering attempts.

AI voice-to-text services pose a unique challenge to companies’ compliance and recording obligations, while the use of LLMs by employees has created a new source of potential data breaches - trade secrets and sensitive information are readily being shared on these platforms, with internal AI policies often implemented long after workforces adopt LLM usage.

For compliance departments, strict AI usage regulations are necessary to reduce these risks. As governments and external regulators explore new AI policies, financial institutions face a compliance dilemma: AI usage and regulatory protocols like DORA increasingly contradict each other, requiring increased oversight from compliance departments, ongoing alignment with governing bodies like the EU, and mounting administrative workload.

Banks require a flexible, evolving compliance and recording partner that can continually adapt the scale, sophistication, and coverage of their mobile recording strategy to satisfy multiple recording regulations and inchoate AI policies.

Reliance on a small number of companies with access to sensitive data also raises the risk of breach and cyberattack – fewer shared service providers means a higher concentration of data entrusted to a tiny number of companies, with pooled customer data. It’s not just AI – across the technology industry, essential services are increasingly supplied by a vanishingly small number of companies, with the CrowdStrike incident throwing this reality into sharp relief.

In this landscape, financial institutions are rightly focusing on swiftly building operational resilience, with compliance and mobile recording strategy at the core.

The existential risks of comms failures

Voice, mobile, messaging, surveillance, and recording systems are fundamental to how regulated firms operate.

Financial industry workers are well aware of the personal cost of iffy mobile service and conflicting communications guidelines. Patchy coverage, inconsistent internal comms policies, and unpredictable pricing models impact employees’ day-to-day ability to do their jobs, slowly but surely eroding employee satisfaction and burdening IT teams with additional paperwork and one-on-one support requests.

In a wider sense, unreliable communications and poorly-implemented compliance and recording services do more than just impact day-to-day operations – they pose an existential threat to the company and wider financial system. This may sound extravagant, but the modern financial sector is so deeply interconnected that the knock-on effects of a single breach can swiftly propagate across industries. As Ernst & Young recently found, "supply‑chain interdependencies have become one of the largest structural barriers to resilience across sectors”, with the financial sector particularly vulnerable. FINMA further identified ICT lapses as a key operational resilience risk to the financial sector. Banks cannot simply diversify their service providers – instead, they must explore and adopt state-of-the-art recording and compliance technologies that can continually adapt to fit new regulatory requirements and provide centralized control over their workforce’s mobile communications.

Can you continue working if your communications stack breaks?

Even with these risks, it’s clear that wireless communications aren’t going anywhere. They have become a foundational tool for the financial industry. From emoji usage to instant messaging services and voice-to-text transcription, mobile technology is continually impacting business communication norms, blurring the lines between personal and business interactions. Companies must continually adopt these new technologies to allow their teams to work at their highest level. Failure to do so is no longer an option in the fast-moving financial world.

By adopting built-in countermeasures, financial institutions can provide their teams with the freedom of mobile communications, while mitigating compliance and cybersecurity risk.

1. Redundancy

Redundancy is key to sustaining operations when a mobile network or communications system fails. It’s the process of having a backup, secure service in place. While not directly combatting security threats, redundancy is a damage limitation measure that ensures that operations can continue in the event of a breach or comms failure. As the owner of a worldwide core network, 1GLOBAL protects its clients from signal outages and mobile network lapses by having access to alternative carriers in every country, bolstering operational resilience.

2. In-network recording

Most company-wide mobile recording strategies can be broadly defined as either app-based or in-network. App-based recording is carried out through software on the user’s devices.

In-network is the gold standard for mobile recording and bookkeeping. It takes any agency away from the individual users, capturing communications at the network level instead. Another significant advantage in-network recording has over app-based models is that it avoids hardware or OS-related crashes that can impact recordings via apps. As communications are captured at the network level, any downstream issues will not impact recording quality or reliability.

Perhaps more significantly, in-network services operate across a far wider range of devices. Smartwatches, cellular laptops, and tablets are occupying a growing portion of the mobile market and slowly creeping their way into business usage. Not all of these support mobile recording apps, or app usage in general. Financial institutions are still obliged to capture all digital communications, regardless of the device they took place on. In-network recording is the only way to ensure this.

Resilience requires visibility

The firms best prepared for disruption are those that can monitor communications environments in real time, identify failures quickly, and demonstrate complete oversight across channels. Anticipating and adapting to constantly shifting communications norms and regulatory frameworks is a key ingredient for long-term security and business success.

Naturally, this is easier said than done. From DORA to FINMA, any financial institution that operates in multiple markets is subject to several, sometimes conflicting regulatory measures. Operating internationally also creates a secondary compliance challenge: firms frequently work with different compliance and recording partners when entering a new market. While this can help them adhere to local regulations in every country of operation, working with multiple vendors places an administrative strain on internal compliance, legal, and accounting teams.

1GLOBAL can alleviate this strain by supplying state-of-the-art mobile recording services across 200+ countries that adapt and comply with each local measure. Crucially, 1GLOBAL provides local compliance in each of these markets through a single partnership.

It’s this international flexibility, coupled with over a decade of expertise, that has made 1GLOBAL the mobile recording provider of choice for dozens of international financial firms, including 8 of the world’s 10 largest investment banks.

Building Compliance That Survives Disruption

1GLOBAL occupies a unique space in the compliance and recording sector. The company is both a trusted compliance partner to global banks and a standalone mobile operator, with full MVNO status in 10 separate countries. This allows 1GLOBAL to offer full-stack, in-network recording capabilities, backed by multiple points of geo-redundancy, to ensure constant, secure communications capture that eliminates risk of downtime or human interference. Data is routed through and stored in local servers, rather than overseas.

By implementing 1GLOBAL’s in-network compliance solutions, companies can bolster their long-term operational resilience, safe in the knowledge that any international expansion or sudden changes in regulation will be supported by a flexible, competent, and scalable mobile recording service.

Find out more about using 1GLOBAL compliance with your business by contacting our team today.

About 1GLOBAL

1GLOBAL is a distinguished international provider of specialty telecommunications services catering to Global Enterprises, Financial Institutions, IoT, Mobile Operators and Tech & Travel companies. 1GLOBAL is an eSIM pioneer, a fully accredited and GSMA-certified telco, an MVNE, and a full MVNO in ten countries, fully regulated in 42 countries, and covers 190+ countries.

1GLOBAL delivers comprehensive communication solutions that encompass Voice, Data & SMS - all supported by a unique global core network. Its constantly expanding portfolio of advanced products and services includes MVNE services, white label eSIMs, Connectivity Solutions, Compliance and Recording, Consumer & M2M SIM Provisioning and an Entitlement Server.

Author Details
Portrait

1GLOBAL is a trading name of 1GLOBAL Holdings B.V.