Why Payment Products Drift After Launch
In payment compliance, launch is the moment of maximum regulatory confidence. A product has been assessed against relevant schemes. Controls have been designed. Obligations have been mapped. The compliance team has signed off. The product enters operation in a known regulatory state.
Within 12 to 18 months — in most cases, significantly sooner — that regulatory state will have changed. Not dramatically. Not in ways that generate immediate incidents. But the gap between the product's actual compliance posture and its intended baseline will have grown. This is regulatory drift: the gradual, often invisible divergence of a payment product from the regulatory framework that was designed to govern it.
The Three Drivers of Drift
Regulatory drift has three primary causes. Understanding each is necessary for designing governance structures that address them.
Scheme Rulebook Updates
Major payment schemes — EPC, Bacs, Pay.UK, card networks — update their rulebooks annually, and sometimes more frequently. Each update contains new obligations, modified obligations, and occasionally, obligations that have been removed. Payment teams that do not systematically track these changes against their existing control landscape will accumulate unaddressed obligations with each update cycle.
The problem is compounded for firms participating in multiple schemes simultaneously. A payment product that participates in SCT, SCT Inst, and FPS is exposed to rulebook changes across three different update calendars, each with its own obligation structure and change notification process.
Regulatory Evolution
Beyond scheme rulebooks, payment products operate within a broader regulatory environment that evolves continuously. PSR policy statements, FCA guidance, EBA opinions, and primary legislation all generate new or modified obligations that may apply to payment products in ways that their original compliance design did not anticipate.
Product Evolution
Products themselves change. New corridors are added. New customer segments are onboarded. New edge cases emerge in operation. Each change can alter the regulatory risk profile of the product in ways that existing controls were not designed to address.
Why Existing Approaches Fail
The dominant response to regulatory drift is the periodic review — an annual or bi-annual compliance assessment that identifies current gaps and generates remediation plans. This approach has two structural problems.
First, it is episodic. Between reviews, drift accumulates unmonitored. The review does not prevent drift; it measures it after the fact. For products operating in high-velocity regulatory environments, the gap between reviews is long enough to generate material compliance risk.
Second, it is disconnected from operational reality. Periodic reviews are typically conducted by second-line teams or external advisers who are not embedded in the product's day-to-day operation. They work from documentation rather than from live operational data, which means they are measuring the compliance design, not the compliance reality.
Regulatory drift is not caused by negligence. It is caused by the absence of a governance structure capable of absorbing continuous change without manual intervention.
The PLG Framework Response
The Payment Lifecycle Governance Framework addresses regulatory drift by reframing compliance as a continuous operational output rather than a periodic review activity. The framework's six-control taxonomy — Customer Journey, Failure Handling, Monitoring, Regulatory, Scheme Control, and Customer Feedback — provides a structured basis for maintaining a complete, current picture of a product's obligation landscape.
Critically, the framework is designed to be maintained by first-line teams embedded in product operations — not by second-line reviewers conducting periodic assessments. This embeds compliance awareness into the operational layer of payment governance, creating the conditions for continuous rather than episodic alignment.
The Regulatory Drift Index provides a quantified measure of current drift, enabling teams to prioritise remediation and to track improvement over time. This replaces the binary pass/fail of periodic reviews with a continuous, granular picture of compliance health.