By FSCL Director Riaz Patel
Money Expo India 2026 in Mumbai offers a useful starting point for examining a contradiction that is becoming increasingly difficult to ignore in modern finance. The financial industry has spent years building technology capable of making transactions, information and financial services appear almost completely borderless, while the institutions responsible for those activities continue to operate within clearly defined legal and regulatory jurisdictions.
The event brings together different parts of an increasingly technology-driven financial ecosystem, but beneath the products, platforms and services on display lies a more consequential question. How does regulation keep pace when the infrastructure supporting finance can cross borders far more easily than the laws governing it?
I have always found the language of technological disruption slightly misleading when it is applied to finance, because it encourages us to believe that technology has somehow dissolved the borders within which financial systems operate. The cloud certainly has no meaningful geography from the perspective of a customer who can access an application from almost anywhere, and an API can connect institutions separated by thousands of kilometres without either side having to know much about the other’s physical infrastructure. But the regulator still has a territory, a statute book, a supervisory mandate and, ultimately, a jurisdiction within which somebody must be held accountable when the apparently seamless financial system stops being seamless.
That contradiction is becoming one of the defining questions of modern finance. The discussions and businesses represented at Money Expo India 2026 are part of a financial environment in which information, instructions, capital and services increasingly move across jurisdictions almost instantaneously, while the institutions responsible for those transactions continue to be regulated according to geographical boundaries designed for a considerably less connected financial world. Technology has therefore raced ahead of the regulatory imagination, and the question confronting financial centres today is not whether regulation can catch up with technology, but whether regulation can evolve without compromising the very confidence that makes financial markets function.
The issue is particularly important as financial businesses increasingly construct their operations across several jurisdictions. A company may be incorporated in one country, hold its regulatory licence in another, use cloud infrastructure located elsewhere, obtain market data from a fourth jurisdiction, process payments through a fifth and serve customers scattered across continents, all while presenting a single digital interface to the world. From the customer’s perspective, there is one financial institution; from the regulator’s perspective, there may be an entire chain of institutions, vendors and technological dependencies, each potentially governed by a different legal framework. That is where the apparent elegance of the cloud encounters the messy reality of financial regulation.
The regulator cannot regulate an abstraction
I do not believe the answer is to pretend that geography no longer matters. Financial regulation exists precisely because money is not an abstraction when things go wrong; deposits, securities, customer data, obligations and losses belong to identifiable people and institutions, and someone has to possess the legal authority to intervene when the system fails.
The difficulty is that the technology supporting those obligations can be distributed almost without regard to national boundaries. A financial institution may depend upon cloud computing, outsourced technology, cybersecurity systems, data analytics and third-party software providers operating in different jurisdictions, meaning that a regulator seeking to understand the institution’s operational resilience can no longer restrict its examination to the institution’s own premises or balance sheet.
This changes the meaning of supervision. The regulator increasingly has to understand not merely what the financial institution does, but what the financial institution depends upon and that distinction is crucial. A bank can have sufficient capital, sound governance and a strong management team and still become incapable of serving customers if a critical technology provider suffers a prolonged outage.
A broker can remain solvent while its trading platform becomes inaccessible. A payment institution can have perfectly adequate liquidity while a failure somewhere in its technological chain prevents customers from moving money. Financial stability and technological resilience are consequently becoming inseparable.
A new regulatory question
For years, outsourcing was treated primarily as a management issue. A financial institution could obtain a specialist service from an external provider and remain responsible for its operations, while regulators concentrated largely on the regulated institution itself.
Cloud computing complicates that model because technology providers can become deeply embedded in the daily functioning of financial institutions. The relationship is no longer necessarily one of a bank purchasing an occasional service from a vendor; the technology provider may host critical systems, store sensitive information, process enormous quantities of data and support applications upon which thousands or millions of customers depend.
The regulatory question then becomes uncomfortable - How much of the financial system can be outsourced before the regulator is effectively supervising an institution whose most important infrastructure sits outside its direct jurisdiction?
There is no simple answer because banning cross-border technology would undermine many of the efficiencies that make modern financial services possible. At the same time, allowing critical infrastructure to become completely opaque would create risks that regulators could discover only after an outage, cyberattack or operational failure had already damaged customers and markets.
The sensible approach, in my view, is neither technological protectionism nor regulatory surrender. It is a framework in which institutions remain unequivocally responsible for their critical dependencies while regulators acquire sufficient visibility into those dependencies to understand where systemic vulnerabilities might emerge.
Singapore’s regulatory proposition
This is one reason Singapore’s position in the Asian financial system is interesting. Its attraction has never depended solely on technology or tax considerations; its broader proposition has been built around the combination of financial sophistication, institutional credibility, infrastructure and regulation.
That combination becomes more important as digital finance expands because sophisticated financial companies do not necessarily want the least regulation. They want regulation that is sufficiently predictable to allow them to innovate without creating uncertainty about whether a business model will remain viable once it becomes commercially significant.
There is a difference between being lightly regulated and being intelligently regulated. The former may reduce immediate costs, while the latter can reduce uncertainty, improve institutional trust and make it easier for financial businesses to establish relationships with banks, investors and counterparties.
Singapore’s challenge, however, is that regulation cannot become so cautious that it suppresses precisely the technological innovation on which future financial competitiveness will depend. The most successful financial centres will have to demonstrate that supervision can coexist with experimentation without allowing experimentation to become an excuse for inadequate accountability.
Dubai and the regulatory proposition
Dubai presents a different but equally instructive model because its financial development has occurred alongside a broader effort to position the city as an international business and investment gateway. Its financial ecosystem has expanded across conventional finance, wealth management, fintech and newer digital financial activities, creating a market in which international businesses can establish regional operations while maintaining connections to markets well beyond the Gulf.
The attraction of such a model depends heavily on regulatory clarity. International financial businesses can tolerate compliance requirements when they understand them, but uncertainty about licensing, permissible activities, data handling or supervisory expectations can become a much greater barrier than regulation itself.
This is where Dubai’s continuing development will be particularly interesting to watch. The ambition to become a global financial hub requires more than attracting capital and businesses; it requires creating sufficient confidence among institutions that the regulatory architecture will remain credible as financial technology changes faster than conventional legislation.
A financial centre cannot build its reputation merely by announcing that it welcomes innovation. It must demonstrate that it can distinguish innovation from regulatory arbitrage and can provide credible supervision without making legitimate innovation unnecessarily difficult.
Labuan’s different equation
Labuan offers another perspective because its proposition is more specialised. Its role within Malaysia’s international business and financial ecosystem means that the relevant question is not whether it can reproduce the scale of Singapore or the global financial branding of Dubai, but whether it can remain useful to businesses seeking a particular combination of cross-border financial services, regulatory structure and regional access.
Specialised jurisdictions face an interesting regulatory dilemma. They need enough flexibility to remain commercially relevant in a rapidly changing financial environment, but they also need sufficient regulatory credibility to ensure that flexibility is interpreted as sophistication rather than weakness.
This is particularly important in digital finance because the technology makes it easier than ever for businesses to move operations between jurisdictions. A specialised financial centre can no longer assume that companies will remain simply because they are already there; it has to provide continuing reasons for them to stay, and regulatory certainty is likely to be one of the most important.
Regulation cannot be an afterthought
One of the mistakes financial technology companies sometimes make is to treat regulation as something that arrives after the product has been designed. That approach may have worked when digital finance was small and experimental, but it becomes increasingly dangerous once technology sits inside the infrastructure through which large volumes of money and financial information move.
Regulation now has to be designed into the architecture itself. Identity verification, transaction monitoring, data governance, cybersecurity, consumer protection and auditability cannot simply be attached to a product at the end of the development cycle because the technology may already have embedded assumptions about how customers are identified, how information moves and how decisions are made.
This is particularly true as artificial intelligence enters financial services. An algorithm can operate across jurisdictions without recognising the legal boundaries that matter to the regulator, yet the consequences of its decisions can fall upon customers who are protected by specific national laws. The technology may not know where the border is but the customer certainly does.
The problem of regulatory fragmentation
The greatest challenge may ultimately be fragmentation. When a financial institution operates across several jurisdictions, it can find itself complying with overlapping requirements governing data, outsourcing, cybersecurity, customer protection and reporting, with each regulator understandably focused on the risks within its own mandate.
The institution therefore becomes the meeting point of several regulatory systems that were not necessarily designed to operate together. Compliance becomes more expensive, but the greater concern is that contradictory requirements can make it difficult to determine which rules should govern a particular activity when technology crosses borders faster than regulators can coordinate.
In my view, this is why regulatory cooperation is becoming an essential component of financial-centre competitiveness. A jurisdiction that can establish credible mechanisms for cooperation with foreign regulators may offer internationally oriented businesses a significant advantage because cross-border expansion becomes more predictable. The future financial centre may therefore be judged partly by how effectively its regulator can communicate with regulators elsewhere.
The sovereignty question
There is also a deeper issue here that cannot be solved through technology alone, sovereignty. Financial regulation is ultimately an expression of a state’s authority over activities that affect its citizens, markets and economy, while cloud infrastructure and digital networks operate according to technological architectures that can span several sovereign territories simultaneously.
That creates difficult questions about access to information, investigative powers and accountability. If critical financial data sits in another jurisdiction, what happens when a regulator needs immediate access to it; if a cloud provider is subject to another country’s laws, whose rules take precedence; and if a technology failure originates outside the jurisdiction but causes harm inside it, where should responsibility ultimately rest?
These are no longer theoretical questions. They are becoming practical problems as financial institutions become increasingly dependent on third-party technology providers and as financial services become more distributed across national borders.
The future belongs to connected regulators
I do not think the answer is to try to rebuild financial regulation around the geography of the twentieth century. Nor do I think the solution lies in allowing technology companies and financial institutions to create their own borderless regulatory universe simply because their infrastructure happens to operate in the cloud.
The more realistic future is one of connected regulation, in which regulators remain territorially accountable but become far more capable of cooperating across jurisdictions. Supervisory technology, information-sharing arrangements, common standards and coordinated approaches to critical infrastructure will become increasingly important as financial institutions build operations that no single regulator can fully understand in isolation.
This could become a competitive advantage for financial centres such as Singapore and Dubai, while offering specialised jurisdictions such as Labuan an opportunity to demonstrate that regulatory sophistication does not necessarily require enormous scale. The jurisdictions that succeed will be those that can make cross-border finance easier without making accountability weaker.
The border has not disappeared
The cloud has undoubtedly changed the meaning of distance. A financial institution can now serve customers it will never meet, employ systems it does not physically own and depend upon infrastructure located beyond the jurisdiction in which it is licensed, making the traditional relationship between financial activity and physical territory increasingly difficult to define.
But the border has not disappeared. It has moved into the data centre, the licensing document, the compliance system, the customer agreement and the regulator’s jurisdictional mandate. Technology may allow information and financial instructions to travel almost instantaneously across those boundaries, but when something fails, the questions become stubbornly geographical. Whose customer is this? Whose data is this? Whose law applies? Which regulator has authority? And who is responsible?
Those questions will not be answered by the cloud. They will be answered by the jurisdictions that build the regulatory architecture around it. And that, ultimately, may become one of the defining contests among the next generation of financial centres: not who can make finance the most borderless, but who can make cross-border finance work while ensuring that accountability never becomes borderless too.
Read the LinkedIn post
By FSCL Director Riaz Patel
Money Expo India 2026 in Mumbai offers a useful starting point for examining a contradiction that is becoming increasingly difficult to ignore in modern finance. The financial industry has spent years building technology capable of making transactions, information and financial services appear almost completely borderless, while the institutions responsible for those activities continue to operate within clearly defined legal and regulatory jurisdictions.
The event brings together different parts of an increasingly technology-driven financial ecosystem, but beneath the products, platforms and services on display lies a more consequential question. How does regulation keep pace when the infrastructure supporting finance can cross borders far more easily than the laws governing it?
I have always found the language of technological disruption slightly misleading when it is applied to finance, because it encourages us to believe that technology has somehow dissolved the borders within which financial systems operate. The cloud certainly has no meaningful geography from the perspective of a customer who can access an application from almost anywhere, and an API can connect institutions separated by thousands of kilometres without either side having to know much about the other’s physical infrastructure. But the regulator still has a territory, a statute book, a supervisory mandate and, ultimately, a jurisdiction within which somebody must be held accountable when the apparently seamless financial system stops being seamless.
That contradiction is becoming one of the defining questions of modern finance. The discussions and businesses represented at Money Expo India 2026 are part of a financial environment in which information, instructions, capital and services increasingly move across jurisdictions almost instantaneously, while the institutions responsible for those transactions continue to be regulated according to geographical boundaries designed for a considerably less connected financial world. Technology has therefore raced ahead of the regulatory imagination, and the question confronting financial centres today is not whether regulation can catch up with technology, but whether regulation can evolve without compromising the very confidence that makes financial markets function.
The issue is particularly important as financial businesses increasingly construct their operations across several jurisdictions. A company may be incorporated in one country, hold its regulatory licence in another, use cloud infrastructure located elsewhere, obtain market data from a fourth jurisdiction, process payments through a fifth and serve customers scattered across continents, all while presenting a single digital interface to the world. From the customer’s perspective, there is one financial institution; from the regulator’s perspective, there may be an entire chain of institutions, vendors and technological dependencies, each potentially governed by a different legal framework. That is where the apparent elegance of the cloud encounters the messy reality of financial regulation.
The regulator cannot regulate an abstraction
I do not believe the answer is to pretend that geography no longer matters. Financial regulation exists precisely because money is not an abstraction when things go wrong; deposits, securities, customer data, obligations and losses belong to identifiable people and institutions, and someone has to possess the legal authority to intervene when the system fails.
The difficulty is that the technology supporting those obligations can be distributed almost without regard to national boundaries. A financial institution may depend upon cloud computing, outsourced technology, cybersecurity systems, data analytics and third-party software providers operating in different jurisdictions, meaning that a regulator seeking to understand the institution’s operational resilience can no longer restrict its examination to the institution’s own premises or balance sheet.
This changes the meaning of supervision. The regulator increasingly has to understand not merely what the financial institution does, but what the financial institution depends upon and that distinction is crucial. A bank can have sufficient capital, sound governance and a strong management team and still become incapable of serving customers if a critical technology provider suffers a prolonged outage.
A broker can remain solvent while its trading platform becomes inaccessible. A payment institution can have perfectly adequate liquidity while a failure somewhere in its technological chain prevents customers from moving money. Financial stability and technological resilience are consequently becoming inseparable.
A new regulatory question
For years, outsourcing was treated primarily as a management issue. A financial institution could obtain a specialist service from an external provider and remain responsible for its operations, while regulators concentrated largely on the regulated institution itself.
Cloud computing complicates that model because technology providers can become deeply embedded in the daily functioning of financial institutions. The relationship is no longer necessarily one of a bank purchasing an occasional service from a vendor; the technology provider may host critical systems, store sensitive information, process enormous quantities of data and support applications upon which thousands or millions of customers depend.
The regulatory question then becomes uncomfortable - How much of the financial system can be outsourced before the regulator is effectively supervising an institution whose most important infrastructure sits outside its direct jurisdiction?
There is no simple answer because banning cross-border technology would undermine many of the efficiencies that make modern financial services possible. At the same time, allowing critical infrastructure to become completely opaque would create risks that regulators could discover only after an outage, cyberattack or operational failure had already damaged customers and markets.
The sensible approach, in my view, is neither technological protectionism nor regulatory surrender. It is a framework in which institutions remain unequivocally responsible for their critical dependencies while regulators acquire sufficient visibility into those dependencies to understand where systemic vulnerabilities might emerge.
Singapore’s regulatory proposition
This is one reason Singapore’s position in the Asian financial system is interesting. Its attraction has never depended solely on technology or tax considerations; its broader proposition has been built around the combination of financial sophistication, institutional credibility, infrastructure and regulation.
That combination becomes more important as digital finance expands because sophisticated financial companies do not necessarily want the least regulation. They want regulation that is sufficiently predictable to allow them to innovate without creating uncertainty about whether a business model will remain viable once it becomes commercially significant.
There is a difference between being lightly regulated and being intelligently regulated. The former may reduce immediate costs, while the latter can reduce uncertainty, improve institutional trust and make it easier for financial businesses to establish relationships with banks, investors and counterparties.
Singapore’s challenge, however, is that regulation cannot become so cautious that it suppresses precisely the technological innovation on which future financial competitiveness will depend. The most successful financial centres will have to demonstrate that supervision can coexist with experimentation without allowing experimentation to become an excuse for inadequate accountability.
Dubai and the regulatory proposition
Dubai presents a different but equally instructive model because its financial development has occurred alongside a broader effort to position the city as an international business and investment gateway. Its financial ecosystem has expanded across conventional finance, wealth management, fintech and newer digital financial activities, creating a market in which international businesses can establish regional operations while maintaining connections to markets well beyond the Gulf.
The attraction of such a model depends heavily on regulatory clarity. International financial businesses can tolerate compliance requirements when they understand them, but uncertainty about licensing, permissible activities, data handling or supervisory expectations can become a much greater barrier than regulation itself.
This is where Dubai’s continuing development will be particularly interesting to watch. The ambition to become a global financial hub requires more than attracting capital and businesses; it requires creating sufficient confidence among institutions that the regulatory architecture will remain credible as financial technology changes faster than conventional legislation.
A financial centre cannot build its reputation merely by announcing that it welcomes innovation. It must demonstrate that it can distinguish innovation from regulatory arbitrage and can provide credible supervision without making legitimate innovation unnecessarily difficult.
Labuan’s different equation
Labuan offers another perspective because its proposition is more specialised. Its role within Malaysia’s international business and financial ecosystem means that the relevant question is not whether it can reproduce the scale of Singapore or the global financial branding of Dubai, but whether it can remain useful to businesses seeking a particular combination of cross-border financial services, regulatory structure and regional access.
Specialised jurisdictions face an interesting regulatory dilemma. They need enough flexibility to remain commercially relevant in a rapidly changing financial environment, but they also need sufficient regulatory credibility to ensure that flexibility is interpreted as sophistication rather than weakness.
This is particularly important in digital finance because the technology makes it easier than ever for businesses to move operations between jurisdictions. A specialised financial centre can no longer assume that companies will remain simply because they are already there; it has to provide continuing reasons for them to stay, and regulatory certainty is likely to be one of the most important.
Regulation cannot be an afterthought
One of the mistakes financial technology companies sometimes make is to treat regulation as something that arrives after the product has been designed. That approach may have worked when digital finance was small and experimental, but it becomes increasingly dangerous once technology sits inside the infrastructure through which large volumes of money and financial information move.
Regulation now has to be designed into the architecture itself. Identity verification, transaction monitoring, data governance, cybersecurity, consumer protection and auditability cannot simply be attached to a product at the end of the development cycle because the technology may already have embedded assumptions about how customers are identified, how information moves and how decisions are made.
This is particularly true as artificial intelligence enters financial services. An algorithm can operate across jurisdictions without recognising the legal boundaries that matter to the regulator, yet the consequences of its decisions can fall upon customers who are protected by specific national laws. The technology may not know where the border is but the customer certainly does.
The problem of regulatory fragmentation
The greatest challenge may ultimately be fragmentation. When a financial institution operates across several jurisdictions, it can find itself complying with overlapping requirements governing data, outsourcing, cybersecurity, customer protection and reporting, with each regulator understandably focused on the risks within its own mandate.
The institution therefore becomes the meeting point of several regulatory systems that were not necessarily designed to operate together. Compliance becomes more expensive, but the greater concern is that contradictory requirements can make it difficult to determine which rules should govern a particular activity when technology crosses borders faster than regulators can coordinate.
In my view, this is why regulatory cooperation is becoming an essential component of financial-centre competitiveness. A jurisdiction that can establish credible mechanisms for cooperation with foreign regulators may offer internationally oriented businesses a significant advantage because cross-border expansion becomes more predictable. The future financial centre may therefore be judged partly by how effectively its regulator can communicate with regulators elsewhere.
The sovereignty question
There is also a deeper issue here that cannot be solved through technology alone, sovereignty. Financial regulation is ultimately an expression of a state’s authority over activities that affect its citizens, markets and economy, while cloud infrastructure and digital networks operate according to technological architectures that can span several sovereign territories simultaneously.
That creates difficult questions about access to information, investigative powers and accountability. If critical financial data sits in another jurisdiction, what happens when a regulator needs immediate access to it; if a cloud provider is subject to another country’s laws, whose rules take precedence; and if a technology failure originates outside the jurisdiction but causes harm inside it, where should responsibility ultimately rest?
These are no longer theoretical questions. They are becoming practical problems as financial institutions become increasingly dependent on third-party technology providers and as financial services become more distributed across national borders.
The future belongs to connected regulators
I do not think the answer is to try to rebuild financial regulation around the geography of the twentieth century. Nor do I think the solution lies in allowing technology companies and financial institutions to create their own borderless regulatory universe simply because their infrastructure happens to operate in the cloud.
The more realistic future is one of connected regulation, in which regulators remain territorially accountable but become far more capable of cooperating across jurisdictions. Supervisory technology, information-sharing arrangements, common standards and coordinated approaches to critical infrastructure will become increasingly important as financial institutions build operations that no single regulator can fully understand in isolation.
This could become a competitive advantage for financial centres such as Singapore and Dubai, while offering specialised jurisdictions such as Labuan an opportunity to demonstrate that regulatory sophistication does not necessarily require enormous scale. The jurisdictions that succeed will be those that can make cross-border finance easier without making accountability weaker.
The border has not disappeared
The cloud has undoubtedly changed the meaning of distance. A financial institution can now serve customers it will never meet, employ systems it does not physically own and depend upon infrastructure located beyond the jurisdiction in which it is licensed, making the traditional relationship between financial activity and physical territory increasingly difficult to define.
But the border has not disappeared. It has moved into the data centre, the licensing document, the compliance system, the customer agreement and the regulator’s jurisdictional mandate. Technology may allow information and financial instructions to travel almost instantaneously across those boundaries, but when something fails, the questions become stubbornly geographical. Whose customer is this? Whose data is this? Whose law applies? Which regulator has authority? And who is responsible?
Those questions will not be answered by the cloud. They will be answered by the jurisdictions that build the regulatory architecture around it. And that, ultimately, may become one of the defining contests among the next generation of financial centres: not who can make finance the most borderless, but who can make cross-border finance work while ensuring that accountability never becomes borderless too.
Read the LinkedIn post