SupTech Is No Longer Optional – What IOSCO’s Global Survey Means for Capital Market Regulators

Every year, the International Association of Deposit Insurers (IADI) quietly does something no single regulator, bank, or vendor could ever pull off alone: it surveys 114 deposit insurance schemes spanning every region on earth and asks them, in effect, “If a bank in your jurisdiction failed tomorrow, could you actually do your job?” 

The Deposit Insurance in 2026 – Global Trends Report, released this March, is the answer – twelve years of consistent survey data compressed into one picture of where global depositor protection stands. Read closely, it isn’t really a report about policy. It’s a report about readiness. And readiness, as the numbers make clear, increasingly comes down to one thing: whether a deposit insurer has structured, validated data on hand before a crisis starts, not after. 

Deposit Insurance Scheme Payouts Are Getting Faster - About Twice as Fast

A decade ago, only one-third of deposit insurers globally could begin reimbursing depositors within seven working days of a bank failure. By 2024, that share had increased to 70%. The revised IADI Core Principles have since raised expectations further, setting an aspirational target of beginning reimbursement within three working days. Today, 37% of deposit insurers already meet that target. 

That’s real, measurable progress. Median reimbursement times in Middle East & Africa fell from over 20 days in 2013 to 6 days in 2024. Asia-Pacific went from 18 days to 5. These aren’t rounding errors  they represent millions of depositors regaining access to their savings in days rather than weeks, precisely when they need it most. 

Why Eight Percentage Points Change Everything in Deposit Insurance Scheme

Forty-nine securities regulators. Every IOSCO region. Over 75% of the world’s securities market value represented in a single dataset. When IOSCO published the findings of its first-ever SupTech Survey this June, it did something capital market regulators rarely get: a genuine, data-backed picture of how their peers around the world are actually using technology to supervise markets – not just the ambition, but the budgets, the barriers, and the gaps. 

Ninety-two percent of the authorities surveyed said efficiency is the main reason they’re investing in supervisory technology. Eighty-six percent flagged cyber risk as their biggest worry. Just over half have a dedicated SupTech budget, and 45% have put strategic leadership – not IT departments – in charge of getting there. Capital markets and consumer protection came out as the two supervisory domains where SupTech is already doing the most work, ahead of AML, licensing, or prudential oversight. If you regulate securities markets, this survey isn’t background reading. It’s a mirror. 

The findings describe something capital market regulators have suspected for a while: technology is no longer a back-office upgrade sitting alongside the real work of supervision. It’s becoming the infrastructure the real work depends on! 

Capital Markets Is Already Where SupTech Lives

Of everything in the IOSCO survey, this is the headline capital market regulators should sit with first: capital markets supervision is one of only two domains – alongside consumer protection – where more than half of all surveyed authorities report active SupTech use, at 67%. Interest in expanding that use further is even higher, at 65%, meaning regulators aren’t slowing down after their first wave of deployments. They’re doubling down. 

That’s a meaningful signal. It means the tools securities regulators have already built – automated filing validation, surveillance analytics, market conduct monitoring – aren’t experiments anymore. They’re becoming the default way capital markets are supervised. The regulators still running on manual filings, spreadsheet reconciliation, or point-in-time reviews aren’t behind a handful of outliers. They’re behind a majority that has already moved on. 

Digital Assets: The Gap Every Regulator Is Watching

The most interesting number in the entire report might be the one describing where capital market regulators want to go next. Interest in applying SupTech to digital assets oversight sits at 35% – nearly double the 18% of authorities that currently have anything operational in that space. No other domain in the survey shows that scale of gap between appetite and deployment. 

That’s not a coincidence. Digital assets and tokenised instruments are forcing capital market regulators to supervise structures that didn’t exist when most legacy filing and surveillance systems were built. Authorities know they need the capability. Very few have it running yet. For any capital market regulator thinking about where to prioritise the next phase of technology investment, this is close to a roadmap handed to you by 49 of your peers. 

Cyber Risk Is the Number One Barrier - By a Wide Margin

Eighty-six percent of capital market and securities regulators surveyed rank cyber and data security risk as high or critical to their technology plans – the single most-cited concern in the entire report, and one that climbs past 91% among smaller authorities and emerging-market regulators specifically. 

That’s a strong signal for any authority weighing how to modernise its filing, surveillance, or reporting infrastructure: the platforms doing the actual replacing matter as much as the capability they add. A surveillance system or e-filing platform that adds analytical power but weakens data security isn’t modernisation – it’s a new category of exposure, at exactly the moment regulators are handling more sensitive market data than ever. 

There’s a reassuring counterpoint buried in the same section of the survey, though. Staff redundancy barely registers as a concern anywhere in the data – just 4% of respondents flagged it. Across every type of regulator surveyed, technology adoption is understood as something that strengthens the people doing the supervising, not something that replaces them. For a capital markets examiner drowning in manual XBRL reconciliation or disclosure review, that’s exactly the point. 

Budgets and Ownership Are Catching Up With Ambition

One of the more encouraging patterns in the IOSCO report is that resourcing is starting to match the rhetoric. Just over half of surveyed authorities now have a dedicated technology budget, rising to 63% among smaller authorities and 56% among growth and emerging markets. Leadership ownership has shifted too – 45% of authorities have put strategic leadership, rather than technical teams alone, in charge of driving the agenda. 

That’s a genuinely useful data point for any capital market regulator making the internal case for investment. The “wait and see” era of SupTech spending is closing globally, not just among the largest, best-resourced authorities. Smaller and emerging-market regulators, in fact, were more likely than the total sample to cite efficiency and timeliness as urgent, and more likely to have already secured dedicated budget – evidence that modernising doesn’t require waiting for a bigger balance sheet first. 

Where Regulators Cooperate - and Where They Don't

The survey also surfaced a pattern worth sitting with. When capital market and securities regulators cooperate internationally on technology, they overwhelmingly share experiences and lessons rather than tools or code – 67% said their cooperation centres on swapping practices, versus just 22% who share actual technical infrastructure. 

That gap between policy-level and operational-level cooperation is worth closing. IOSCO’s own committees and working groups already do strong work on shared principles and market conduct standards. What’s rarer is regulators comparing notes on the actual reporting stack behind their filings, the taxonomy choices behind their XBRL implementation, or the analytics layer behind their surveillance system – the operational detail that turns a shared policy view into something that works day to day. Legal and confidentiality constraints, cited by 41% of authorities that don’t share more, are real. But they’re not the whole story, and peer regulators who’ve already built interoperable, standards-based reporting platforms have a lot to offer here. 

The Gap Between Ambition and Capability

Perhaps the most telling pattern in the whole survey is the size of the gap between what authorities want and what they currently run. Across product development, analytics, storage, and validation, the difference between authorities currently using high-tech tools and those aspiring to get there exceeds 40 percentage points. Most respondents describe themselves as running “mid-tech” – functional, but far from cutting-edge – with limited funding, more than any lack of internal expertise, cited as the main reason the gap hasn’t closed. 

Capital market regulators will recognise this immediately. Everyone agrees that machine-readable filings, automated validation, and real-time surveillance analytics are where supervision is heading. Fewer regulators have closed the distance between that ambition and what their current systems can deliver when a filing deadline hits or a market conduct issue needs investigating in real time. 

Mid-Tech Is the Norm

It’s worth being precise about what “SupTech adoption” actually looks like inside most capital market authorities today, because the survey pushes back on a common assumption. This isn’t a story of regulators racing to deploy machine learning and advanced analytics across every function. Most authorities report relying on what the survey calls medium-tech solutions for their core functions – analytics, data collection, storage – rather than frontier tools. Traditional transaction data and fraud-detection systems still form the backbone of most surveillance work, even as social media and trading forum monitoring slowly enter the picture as early-warning signals. 

That pragmatism is worth defending, not apologising for. A capital market regulator doesn’t need every function running on artificial intelligence to run an effective supervisory programme – it needs the foundational layer done properly first. Standardised, validated, machine-readable filings are what make everything downstream possible: surveillance analytics only work if the underlying data is clean and structured; risk scoring only works if submissions arrive in a consistent format regulators can compare across entities. Get that foundation right, and the more advanced capabilities the survey shows regulators aspiring to – real-time validation, cross-entity risk analytics, automated anomaly detection – become a natural next step rather than a leap. 

The Road Ahead

Put the pieces of the IOSCO survey together and a clear pattern emerges: technology-driven supervision has stopped being a pilot project for capital markets regulators and started being the baseline expectation. Strategic leadership is taking ownership. Budgets are being earmarked. Cyber risk is being treated as a first-order design requirement rather than an afterthought. And the authorities furthest along aren’t necessarily the largest – smaller and emerging-market regulators are, in several respects, moving faster precisely because they have less legacy infrastructure standing in the way. 

That last point deserves attention from any capital market regulator that assumes modernising filing and surveillance infrastructure is a luxury reserved for the biggest, best-funded authorities. The data says otherwise. The regulators making the fastest progress are the ones treating standardised, machine-readable reporting as foundational infrastructure – not a project to revisit once resources allow. 

Building the Foundation Capital Markets Supervision Now Demands

This is precisely the ground IRIS iFile has been built to cover – a modular, XBRL and SDMX-based regulatory reporting platform purpose-built for capital market regulators and exchanges. It’s already the infrastructure behind data collection at exchanges including the Bombay Stock Exchange, National Stock Exchange, Kuwait Stock Exchange, Qatar Stock Exchange, Tadawul, Dubai Financial Market, and Abu Dhabi Securities Exchange – covering everything from financial results and corporate actions to shareholding patterns, listing compliance, and broker capital adequacy. From automated business rules validation across thousands of data points, to flexible system-to-system and screen-based filing for entities of every technical maturity, to compliance dashboards that flag non-compliant or inconsistent data as it comes in – it’s the kind of infrastructure the IOSCO survey suggests every capital markets authority is quietly racing to build. 

The IOSCO SupTech Survey confirms what many capital market regulators have already sensed: the shift from periodic, manual oversight to real-time, standards-based supervision isn’t a future state anymore. It’s already underway, and the gap between authorities leading it and those still catching up is only going to widen. The question worth asking inside your own authority isn’t whether that shift is coming. It’s whether your reporting and surveillance infrastructure will be ready when the next wave of mandates – digital assets, ESG, AI-driven disclosures – arrives on top of it. 

Curious what a modern, standards-based regulatory reporting platform could look like for your authority? Get in touch with the IRIS iFile team for a walkthrough built around your jurisdiction’s specific filing requirements and market structure. 

Leave a Reply

Your email address will not be published. Required fields are marked *

Are you human? Please solve:Captcha


IRIS RegTech Solutions Limited (formerly known as IRIS Business Services Limited)
Subsidiaries

IRIS Regtech Sdn. Bhd. (Malaysia)

IRIS Business Services (Asia) Pte. Ltd., Singapore

IRIS Business Services, LLC, USA

Atanou S.r.l. (Italy)

IRIS Data Solutions Private Limited

Follow Us On Social
Stay connected and follow us on social media for the latest updates and news.
Avantage
Headquarters
Visualize quality intellectual capital without superior collaboration and idea sharing installed base portals.
Our locations
Where to find us?
https://i0.wp.com/irisregtech.com/wp-content/uploads/2020/04/img-footer-map-1.png?fit=280%2C142&ssl=1
Get in touch
Avantage Social links
Taking seamless key performance indicators offline to maximise the long tail.

©2025 IRIS RegTech Solutions Limited. All rights reserved.
Read our Privacy Policy, Cookies Policy, and Terms & Conditions for more.