Regulatory reporting is the mandatory submission of data by a regulated firm to its supervisors, on a fixed schedule and in a fixed format, so the regulator can monitor the firm’s financial health, its conduct, and the risks it carries. A bank reporting its capital position, a broker reporting its trades, a payments firm flagging a suspicious transaction: all of it is regulatory reporting.
It is also one of the easiest ways for a firm to be fined without ever doing anything dishonest. In March 2019 the FCA fined Goldman Sachs International £34.3 million for transaction-reporting failures, after errors ran through 220 million reports over a decade. Nobody alleged fraud. The reports were simply wrong, and that was enough.
What regulatory reporting is, in practice
Every regulated financial firm has to tell its regulator what it is doing, in structured data, at set intervals. The regulator uses that data to spot a bank running low on capital, a trading desk building a dangerous position, or a pattern of payments that looks like money laundering, before it becomes a crisis.
It has three fixed parts. The data is prescribed, so the firm reports exactly the fields the regulator specifies, not a summary of its choosing. The format is prescribed too, down to the file type and the codes used. And the timing is prescribed, whether that means daily, monthly, quarterly or, for a suspicious transaction, almost immediately. A report that is late, in the wrong format, or missing fields is a breach, even when the underlying business is sound.
The main types of regulatory reporting
Regulatory reporting is not one obligation but several, each answering a different supervisory question.
| Type | What it reports | Example regimes |
|---|---|---|
| Prudential reporting | Capital, liquidity, and risk exposures, to prove the firm can absorb losses | COREP and FINREP in the EU/UK; Call Reports in the US |
| Transaction and trade reporting | The details of trades and derivatives, so regulators can see market activity and abuse | MiFID II/MiFIR transaction reporting; EMIR derivative reporting |
| Financial-crime reporting | Suspicious activity and transactions, plus sanctions and AML data | Suspicious Activity Reports; goAML filings in the UAE |
| Conduct and operational reporting | Complaints, breaches, outages, and other conduct data | Various regulator-specific returns |
The first two carry the heaviest data burden, because they run on a fixed calendar and cover enormous volumes. Financial-crime reporting is different in character: it is event-driven, triggered the moment a firm forms a suspicion, and it comes with the tightest deadlines.
Who regulates it: the regimes by jurisdiction
A firm’s regulatory reporting requirements are set nationally, so a firm operating across borders reports into several regimes at once, each with its own formats, calendars and definitions. This is where most of the complexity sits, and where the cost of running across borders builds up.
In the UK, the FCA and the Bank of England’s Prudential Regulation Authority run the reporting regimes, covering prudential returns, MiFID transaction reporting and conduct data. The FCA’s own regulatory reporting hub sets out what firms owe.
In the EU, the European Banking Authority mandates the two frameworks that anchor prudential reporting across the bloc. COREP (Common Reporting) covers own funds, capital adequacy and credit, market and operational risk. FINREP (Financial Reporting) covers the financial statements of banks that report under IFRS. Both are delivered through the EBA’s Implementing Technical Standards and updated on a rolling release, so the templates themselves keep changing.
In the US, the picture is split across agencies. Banks file FFIEC Call Reports, the Consolidated Reports of Condition and Income, with their federal regulators. Derivatives and swaps are reported to the CFTC and SEC under the Dodd-Frank framework. And FINRA runs its own conduct-reporting rules for broker-dealers.
The UAE and the wider Gulf add a fourth regime that non-regional firms routinely underestimate, covered in its own section below.
Why reporting failures are so costly
Transaction reporting is where the fines cluster, because the data is high in volume, technical, and easy to get wrong at scale. When a static data table is misconfigured or a feed drops fields, the errors don’t show up as one mistake. They multiply across millions of reports before anyone notices.
The Goldman Sachs fine above came from errors spread across 220 million transaction reports between 2007 and 2017, and it wasn’t an isolated case. In October 2017 the FCA fined Merrill Lynch International £34.5 million for failing to report 68.5 million exchange-traded derivative transactions, its first enforcement action under the EMIR reporting regime. The cause was mundane: an error in a static data table that went unnoticed.
The FCA has since fined a series of banks for the same class of failing. Regulators now treat reporting accuracy as a control in its own right, not a clerical afterthought.
For a compliance team, the risk sits in the plumbing. The data pipeline, the reference data and the field mappings are where the fines start, long before anyone reads a finished report.
The burden: what regulatory reporting actually costs
The scale of reporting is easy to underestimate. The FCA alone receives around 500,000 scheduled regulatory reports a year, and the cost of producing regulatory reports for UK firms has been estimated at between £1.5 billion and £4 billion a year.
Most of that cost sits in the work behind the filing rather than the filing itself: pulling data from systems that were never designed to talk to each other, reconciling it, mapping it to the regulator’s templates, checking it, and doing the whole thing again every time a rule or a template changes.
For a large bank, regulatory reporting is a standing operation with its own teams, technology and budget, and it grows every time a new regime lands.
Digital regulatory reporting: the shift to machine-readable rules
The size of that burden is why regulators are trying to change how reporting works. The FCA and the Bank of England have run a programme on Digital Regulatory Reporting, testing whether reporting rules can be written in a machine-readable, and eventually machine-executable, form.
The idea is to remove the manual interpretation step. Instead of a firm reading a rule, deciding what data it wants, building a return and submitting it, the rule itself would be code that pulls the required data straight from the firm’s systems.
Pilots ran with major UK banks, and the work has continued in phases. It is still early, and it won’t replace existing reporting soon, but it points at where the discipline is heading: less human handling of data, and more of the report generated straight from source. For firms, the near-term effect is pressure to get their data houses in order, because machine-readable reporting only works on clean, well-structured data.
Regulatory reporting in the UAE and the Gulf
For any firm operating in the region, the Gulf runs reporting regimes that sit alongside, not inside, the Western ones. In the UAE, the anchor financial-crime obligation is suspicious-transaction reporting to the Financial Intelligence Unit through the mandatory goAML portal.
The rules are strict. Registration on goAML is mandatory for every entity supervised by the Central Bank of the UAE, taking effect as soon as a firm receives its licence. There is no minimum monetary threshold, so even a small suspicious transaction, including an attempted one, has to be reported. And firms have to file within 35 calendar days of detecting the suspicion. Missing that is a breach in itself.
The federal regime isn’t the whole picture either. The two financial free zones, the DFSA in the Dubai International Financial Centre and the FSRA in Abu Dhabi Global Market, run their own reporting rulebooks. A firm licensed in one of them reports into that regulator as well, so a group operating across the UAE can face the federal Central Bank regime and a free-zone regime at once.
The region tightened all of this after the FATF put the UAE on its grey list in 2022 and removed it in 2024, which made reporting quality an examination priority rather than a box-tick.
What regulatory reporting software has to do
Because the data is spread across systems and the regimes keep changing, most firms of any size run dedicated regulatory reporting software rather than build returns by hand. Buyers evaluating regulatory reporting solutions are really asking whether a tool can do four things well.
It has to pull and reconcile data from the firm’s core systems without manual re-keying. It has to map that data to each regulator’s current templates, and update itself when those templates change. It needs to validate reports against the regulator’s rules before submission, so errors are caught before they multiply across a filing.
And it has to keep an audit trail of what was reported, when, and on what data, because the regulator will ask. A tool that manages the first three but cannot prove the fourth still leaves the firm exposed.
The challenges that persist
The same problems keep coming back for reporting teams. A report is only as good as the reference data and mappings behind it, so poor data quality is where the fines start. Firms report into several regimes with different formats and no shared standard, so the work is fragmented by design. And templates, rules and thresholds keep moving, so every change means rebuilding and re-testing part of the reporting chain.
None of that makes reporting a solved problem. It is a permanent function that has to be resourced and maintained, and that is why it has become one of the largest standing costs in financial-services compliance.
FAQs
What is regulatory reporting in simple terms?
It is the mandatory submission of prescribed data by a regulated firm to its supervisors, on a fixed schedule and in a fixed format, so the regulator can monitor the firm’s health, conduct and risk. It covers capital and liquidity returns, trade and transaction reports, and suspicious-activity reports.
What are the main types of regulatory reporting?
Prudential reporting (capital, liquidity and risk, such as COREP and FINREP), transaction and trade reporting (such as MiFID II and EMIR), financial-crime reporting (suspicious activity and transactions), and conduct and operational reporting (complaints, breaches and outages).
Why do firms get fined for regulatory reporting?
Usually for inaccurate or incomplete reports rather than dishonesty. The FCA has fined banks including Goldman Sachs and Merrill Lynch tens of millions of pounds for transaction-reporting errors that ran across millions of reports, treating reporting accuracy as a control failure in its own right.
What is digital regulatory reporting?
A regulator-led effort, including an FCA and Bank of England programme, to make reporting rules machine-readable and eventually machine-executable, so data can be pulled straight from a firm’s systems rather than interpreted and compiled by hand. It aims to cut the cost and error rate of reporting.
How does regulatory reporting work in the UAE?
UAE firms supervised by the Central Bank must register on the goAML portal and file suspicious-transaction reports to the Financial Intelligence Unit within 35 calendar days of detection, with no minimum threshold. Firms in the DIFC and ADGM free zones also report into the DFSA and FSRA respectively.
Next read
Regulatory reporting is one pillar of a firm’s wider compliance obligations. For the rest of our regtech and compliance coverage, see the Compliance hub.