Beyond Compliance: Building Effective, Proportionate and Trusted Financial Regulation in Eswatini
Financial regulation is often judged by what is easiest to observe: the number of licences issued, inspections completed, regulatory returns submitted, directives issued or penalties imposed. Those measures matter, but they do not tell us on their own whether regulation is working.
The harder questions concern outcomes. Are institutions becoming safer and better governed? Are consumers being treated fairly? Are supervisors identifying material risks early enough? Are scarce regulatory resources being directed towards the areas of greatest potential harm? Is the information collected from institutions improving decisions, or merely increasing reporting volume?
These questions are especially important in smaller financial systems such as Eswatini, where both regulators and regulated institutions operate with finite human, financial and technological resources. The objective cannot simply be more regulation. It must be regulation that is effective, proportionate and capable of strengthening trust in the financial system.
Regulatory effectiveness starts with outcomes
Compliance is indispensable. Financial institutions must meet the laws, licence conditions, prudential standards, conduct requirements and financial-integrity obligations that apply to them. Yet compliance is a means to an end, not the end itself.
A regulated institution can maintain a comprehensive policy library and still be poorly governed. It can submit returns on time while failing to detect a weakening financial position. It can operate a complaints process without learning from repeated consumer harm. It can conduct AML/CFT/PF training while frontline staff remain unable to recognise the risks most relevant to the institution.
This distinction matters because financial regulation ultimately exists to protect outcomes: the safety and soundness of institutions, fair treatment of consumers, integrity of markets, resilience against financial crime and confidence that financial institutions can meet their obligations.
Eswatini’s regulatory architecture already reflects this broader purpose. The Financial Services Regulatory Authority Act, 2010 establishes the FSRA’s responsibilities within the non-bank financial sector, while the Authority describes its role as licensing, regulating, monitoring and supervising financial-services providers and administering financial-services laws. The Central Bank of Eswatini’s Financial Regulation Department combines banking supervision with policy, conduct and enforcement, financial surveillance and financial-integrity functions for institutions under the Bank’s purview.
The regulatory task is not one-dimensional. An institution may be financially sound but treat customers poorly. It may have acceptable consumer-facing processes while maintaining weak financial-crime controls. It may satisfy prescribed ratios while governance is deteriorating. Effective supervision needs to see the institution as a system rather than a collection of isolated compliance requirements.
From compliance documents to institutional capability
A useful way to interpret regulation is to ask what capability a requirement is intended to create, preserve or test.
Capital requirements are not merely figures to report. They provide capacity to absorb losses. Customer-due-diligence requirements are not simply identification documents to collect. They help an institution understand whom it is dealing with and manage exposure to financial crime. Governance requirements are not satisfied by appointing directors; they create structures for oversight, challenge and accountability.
The same logic applies to information. A complaints register is not valuable because it exists. Its value lies in whether recurring complaints reveal product weaknesses, misconduct or emerging consumer harm. A regulatory return is not useful merely because it reaches the supervisor. It becomes useful when its information supports risk assessment, supervisory prioritisation or early intervention.
Training offers another example. Attendance records can prove that a session took place, but they do not prove that capability improved. The relevant question is whether staff understand their responsibilities and behave differently as a result.
This is where regulatory compliance becomes institutional capability. A policy that is not implemented does not control risk. A risk assessment that is not revisited cannot guide decisions as circumstances change. A board that receives information without interrogating it cannot provide meaningful oversight.
Strong institutions internalise the purpose of regulation rather than treating it as an external administrative exercise.
Prudential supervision: understanding the institution behind the numbers
Prudential supervision is concerned with whether financial institutions remain safe, sound and capable of meeting their obligations. Depending on the institution, this can involve capital, liquidity, asset quality, concentration risk, provisioning, governance, risk management, operational resilience, financial reporting and internal controls.
The Central Bank of Eswatini describes its Banking Supervision Division as a micro-prudential function using both onsite and offsite supervision and frequent financial information to assess the soundness of banks on an ongoing basis. Its stated prudential areas include capital adequacy, asset quality, risk management, liquidity, stress testing and loan-loss provisioning.
That description captures an important principle: prudential supervision cannot be reduced to checking ratios.
A supervisor needs to understand the institution behind the numbers. How does it generate income? What risks arise from that business model? Are those risks understood by management? Does the board receive information capable of supporting meaningful oversight? Are liquidity pressures, asset-quality deterioration or concentrations becoming visible? Would the institution remain resilient under adverse conditions?
The Basel Committee’s 2024 Core Principles for Effective Banking Supervision reinforce this approach. The Core Principles are minimum global standards for the sound prudential regulation and supervision of banks and banking systems. They cover supervisory powers and techniques as well as governance, risk management, capital, liquidity, financial reporting and internal controls. The revised framework also places proportionality across the Core Principles, allowing supervision to reflect a bank’s risk profile, systemic importance and the characteristics of the financial system without diluting minimum prudential standards.
Although the Basel Core Principles apply specifically to banking supervision, the underlying supervisory lesson travels further: good supervision requires judgement about material risk, not merely confirmation that formal requirements have been met.
Market conduct: regulation must ask what happens to the consumer
Financial soundness alone does not establish that a financial institution is operating responsibly. An institution can be profitable and adequately capitalised while selling unsuitable products, imposing opaque charges, creating unfair barriers to exit or redress, or using incentives that encourage harmful sales behaviour.
Market-conduct supervision asks a different question: what outcomes are consumers experiencing because of the way products are designed, priced, marketed, sold and administered?
This has become an increasingly explicit part of Eswatini’s supervisory framework. The Central Bank’s Market Conduct and Consumer Protection Unit supervises the conduct of banks and other financial institutions under the Bank’s purview. Its stated areas of assessment include product development, disclosure and transparency, sales processes, post-sale treatment, complaints and redress.
The FSRA’s Market Conduct Expectations to Financial Services Providers, dated 14 March 2024, similarly moves the discussion beyond procedural compliance. The Authority identifies concerns such as weak governance, inappropriate incentives, high or opaque fees, reckless lending, conflicts of interest and insufficient disclosure. Its expectations cover price and value, product suitability and customer understanding, consumer support, culture, governance, business models and conduct-risk controls.
The implication is significant. A disclosure is not effective merely because it was issued; it needs to be clear and meaningful enough to support an informed decision. A complaints system is not effective because it appears in a policy; consumers need to be able to use it and obtain appropriate redress. A credit agreement is not necessarily responsible simply because it was signed; affordability, suitability, transparency and collection practices remain relevant.
Market conduct reaches into the business model because consumer outcomes are shaped by decisions made across the institution, not by the compliance function alone.
Financial integrity and risk-based supervision
Financial institutions also have responsibilities to protect the financial system from money laundering, terrorist financing, proliferation financing and related abuse. This area is particularly vulnerable to a checklist mentality: forms are completed, identification documents are collected, training is scheduled and periodic reviews are recorded.
A genuine risk-based approach demands more.
Institutions need to understand the risks arising from their customers, products, services, delivery channels, transactions and geographic exposures, then design controls that respond to those risks. Supervisors face the parallel task of deciding where their own attention and resources should be concentrated.
The February 2025 FATF Recommendations are clear on this point. The Interpretive Note to Recommendation 26 describes risk-based supervision as the process by which a supervisor allocates resources according to its understanding of money-laundering and terrorist-financing risks. It also states that the frequency and intensity of onsite and offsite supervision should be informed by the risk profile of the institution or group and by the risks present in the country. Those risk profiles should be reviewed periodically and when major developments occur.
This approach is especially relevant where supervisory capacity is finite. Treating every institution, transaction and breach as equally significant can consume resources without improving outcomes. Risk-based supervision requires prioritisation, and prioritisation requires evidence, judgement and the willingness to revise assessments when circumstances change.
The shift also matters for financial inclusion. FATF’s 2025 amendments strengthened the emphasis on proportionality and simplified measures under the risk-based approach, reflecting the need to manage financial-crime risks without unnecessarily excluding legitimate customers from formal financial services.
Proportionality is not weaker regulation
Proportionality is often invoked but not always defined carefully.
A small credit provider, a SACCO, an insurer, a retirement fund, an investment manager and a large commercial bank do not present identical risks. Applying the same organisational architecture, reporting intensity or supervisory approach to all of them may create significant compliance costs without producing equivalent regulatory benefit.
Proportionality does not mean accepting weaker governance, weaker consumer protection or weaker financial-integrity controls from smaller institutions. It means calibrating the form, complexity and intensity of regulation and supervision to the nature, size, complexity and risk profile of the institution.
The Basel Committee makes the distinction explicit. Its 2024 framework states that proportionality does not dilute prudential standards; it reflects the circumstances of different institutions, financial systems and supervisory capacity.
The FSRA’s 2024 market-conduct expectations make a similar point. The Authority states that there is no one-size-fits-all approach to conduct-risk management and that programmes should be commensurate with the nature and complexity of the provider’s operations.
For a smaller financial system, this is not a technical detail. It is central to regulatory effectiveness.
Excessively complex requirements can raise barriers to entry, increase operating costs and divert scarce institutional resources towards low-value administrative activity. Requirements that are too weak can expose consumers and the financial system to unacceptable harm.
The more useful policy question is not whether regulation should be heavier or lighter. It is whether the regulatory response is proportionate to the risk and capable of achieving the intended outcome.
Regulatory design must fit the system it serves
International standards matter, but effective regulation is not an exercise in copying institutional models from larger economies.
Financial systems differ in size, concentration, product complexity, supervisory resources, legal architecture and data capability. A structure that works in a large international financial centre may be unnecessarily complex in a small market; a simple framework that works in a smaller system may not be adequate for a highly interconnected one.
Eswatini itself illustrates the importance of institutional context. Regulatory responsibilities are divided principally between the Central Bank and the FSRA according to their respective statutory mandates. Within that architecture, effectiveness depends on clarity of responsibility, information quality, coordination where risks cross institutional boundaries and sufficient capability within each authority.
International standards can provide benchmarks without dictating identical institutional design. The Basel Core Principles are expressly framed as universally applicable while recognising differences among banks, banking systems and supervisory capacity.
That is a useful principle beyond banking: regulatory systems should meet credible standards while remaining workable in their own institutional context.
The test is not whether a regulator resembles a regulator elsewhere. The test is whether the architecture allows risks to be identified, responsibilities to remain clear and interventions to occur when they are needed.
Better data should lead to better supervisory intelligence
Modern supervision increasingly depends on information, but the volume of data collected is a poor measure of supervisory sophistication.
A regulator can receive extensive returns without gaining a clear view of emerging risk. An institution can build sophisticated dashboards on data that are incomplete or unreliable. Digital reporting can reduce manual processing while still reproducing poorly designed reporting requirements.
The distinction that matters is between data collection and supervisory intelligence.
The FSRA’s Q1 2026 Quarterly Statistical Bulletin makes this connection explicit. The bulletin is based on regulatory returns submitted by licensed entities together with the Authority’s supervisory and enforcement work. FSRA notes that the quality and depth of its analysis depend on the accuracy and quality of the data submitted. It also identifies continuous monitoring of financial soundness, early identification of deteriorating financial positions and analysis of sectoral risks among the supervisory purposes supported by accurately completed returns.
That connection matters. Data quality is not an administrative issue sitting outside supervision; it directly affects a supervisor’s ability to identify, interpret and respond to risk.
Boards and management face the same problem. They need reliable information on liquidity, asset quality, concentration, complaints, regulatory breaches, suspicious activity, operational incidents and consumer outcomes. If information is late, inconsistent or poorly defined, decision-makers see risk after it has already intensified.
The regulatory objective should not be to collect the maximum amount of data. It should be to collect information that is relevant, accurate, timely, comparable and capable of supporting action.
Technology is an enabler, not the regulatory objective
RegTech and SupTech can strengthen this information architecture.
The Bank for International Settlements describes RegTech as the application of technology to regulatory and compliance requirements and reporting by regulated institutions, while SupTech refers to the use of technology for regulatory, supervisory and oversight purposes.
RegTech can assist regulated institutions with functions such as regulatory reporting, customer due diligence, transaction monitoring, compliance monitoring and records management. SupTech can help supervisors collect and validate information, identify anomalies, develop risk indicators and prioritise supervisory attention.
The potential is real, particularly where institutions or supervisors face resource constraints. But technology does not solve a poorly defined regulatory problem.
Automating an ineffective process produces a faster ineffective process. Artificial intelligence cannot make unreliable data trustworthy. A digital compliance platform cannot compensate for weak governance, unclear accountability or a culture that tolerates misconduct.
The sequence matters. First define the problem. Then understand the risk and the outcome that needs protection. Design the regulatory or institutional response. Determine what information is required. Only then ask whether technology can improve implementation.
This is also where responsible technology policy enters financial regulation. Digital tools require appropriate data governance, cybersecurity, privacy safeguards, explainability where automated decisions matter, and meaningful human oversight.
Innovation should improve institutional capability and supervisory judgement, rather than add technological complexity for its own sake.
Capability is required on both sides of the regulatory relationship
Regulated institutions are not the only organisations that need to build capability.
Regulators must adapt as financial products, business models, distribution channels, cyber risks, financial-crime typologies and data volumes change. Effective supervision requires adequate legal powers, skilled people, reliable information, sound methodologies, operational independence, enforcement capability and institutional learning.
The FATF Recommendations recognise this directly by requiring financial supervisors to have adequate financial, human and technical resources, alongside sufficient operational independence and autonomy.
The Basel Core Principles similarly treat clear responsibilities, legal powers, institutional arrangements and effective supervisory techniques as foundations of sound banking supervision.
This creates a reciprocal relationship.
Capable regulators are more likely to set priorities clearly, distinguish material risk from administrative noise and intervene effectively. Capable institutions are more likely to understand supervisory expectations, provide reliable information and turn regulatory requirements into functioning controls.
Weakness on either side increases the cost of regulation. Supervisors spend more time correcting basic failures, while institutions struggle to interpret or implement expectations consistently.
Regulatory capability is not simply an institutional management issue. It is part of the wider public-policy infrastructure supporting a safe and trusted financial system.
Conclusion
Effective financial regulation is not measured by the size of the rulebook, the quantity of information collected or the number of compliance documents an institution can produce.
Its quality is reflected in outcomes.
Do institutions understand and manage their risks? Are boards capable of meaningful oversight? Are consumers treated fairly? Are financial-crime controls responsive to actual risk? Can supervisors identify deterioration early enough to act? Are regulatory requirements proportionate to the institutions and risks they address? Does information support judgement? Does technology improve implementation rather than merely automate existing weaknesses?
For regulated institutions, the challenge is to move from formal compliance towards genuine institutional capability.
For supervisors, the challenge is to direct finite resources towards material risks while maintaining consistency, fairness and accountability.
For policymakers, the challenge is to ensure that regulatory frameworks remain credible, proportionate and adaptable as markets change.
Technology can strengthen this work. Better data can strengthen it. International standards can provide useful benchmarks. None of them can substitute for institutional competence and sound judgement.
The strongest financial systems are not necessarily those with the most rules. They are those in which regulatory requirements are understood, proportionately implemented, credibly supervised and translated into meaningful outcomes.
That is the point at which regulation moves beyond compliance and becomes part of the institutional foundation for a financial system that is sound, fair, inclusive and trusted.
Selected sources and further reading
- Financial Services Regulatory Authority Act, 2010
- Financial Services Regulatory Authority, Market Conduct Expectations to Financial Services Providers, 14 March 2024
- Central Bank of Eswatini, Financial Regulation
- Central Bank of Eswatini, Market Conduct & Consumer Protection Unit
- Basel Committee on Banking Supervision, Core Principles for Effective Banking Supervision, 2024
- Financial Action Task Force, FATF Recommendations, February 2025 version
- Financial Action Task Force, February 2025 amendments on proportionality and financial inclusion
- Financial Services Regulatory Authority, Quarterly Statistical Bulletin Q1 2026
- Bank for International Settlements, Leveraging Technology to Support Supervision: Challenges and Collaborative Solutions


