## ftnea2022002

## Source details

**Canonical URL:** [ftnea2022002](https://www.imf.org/-/media/files/publications/ftn063/2022/english/ftnea2022002.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/ftn063/2022/english/ftnea2022002.pdf.md)
- [Structured JSON version](/-/media/files/publications/ftn063/2022/english/ftnea2022002.pdf.json)

---

### Executive summary and context
- Fintech developments: unbundling and decentralization of services; rapid technology and business-model change; strong economies of scale; cross-border and cross-sectoral expansion; focus on retail services.
- BigTech advantages: existing user base and big data; artificial intelligence and machine learning; cross-subsidization; economies of scale; data analytics, network externalities, and interwoven activities loop (Crisanto, Ehrentaud, and Fabian 2021).
- Short-term benefits of BigTech presence: potential to increase financial inclusion, lower costs, and expand consumer choice.
- Long-term risks: concentration, contagion, reputation risks, and potential systemic implications in local financial markets.

### Key elements that distinguish BigTech from fintech start-ups
- No single agreed definition; BigTech described as “large companies with established technology platforms” (FSB 2019) and “large technology companies” (Financial Stability Institute).
- Distinguishing factors: number of users, number of jurisdictions of operation, revenue, and scope of activities.
- BigTech can reverse fintech unbundling by bundling a wide range of financial services within the group using:
  - Large proprietary data sets and lower-cost access to those data.
  - Cross-subsidization and economies of scale.
  - Integration across sectoral services creating “one-stop” propositions more attractive than those of traditional financial conglomerates.

### Channels of financial-stability risk from BigTech expansion
- Three broad channels:
  - Cumulative activities across sectors that increase overall risk due to lack of effective cross-sectoral regulation.
  - Operational interconnectedness with financial incumbents (for example, between loan-originating BigTech and commercial banks providing funding).
  - Financial interconnectedness via provision of single systemically important activities like the cloud or systemic payments infrastructures.
- Combined effects can create “too big to fail” scenarios.

### Sectoral expansion evidence and trends
- Payments:
  - Initial BigTech focus; many BigTechs had existing platforms enabling rapid offering of digital payment services (example: Facebook Pay).
  - Payments regulation in some jurisdictions had supported new entrants, facilitating BigTech entrance.
  - In 2020, BigTechs invested over $2 billion in fintech companies, with Google’s parent Alphabet alone generating 23 fintech investments.
- Lending:
  - BigTechs leverage consumer preference and spending data to offer lending to underserved consumers and SMEs.
  - BigTech lending to SMEs is largest in Asia but gaining traction globally.
- Insurance:
  - BigTechs leverage product-protection and warranty experience and proprietary data (social media, chat functions) to tailor insurance products.
  - Consumer purchase propensity from BigTechs increased from 27 percent to 44 percent between 2016 and 2020 (World InsurTech Report 2020).
- Stablecoins and large-scale payment initiatives:
  - Proposed BigTech-led global stablecoins could be potentially systemic at launch given large user bases and network effects.
  - In low-income and emerging markets, stablecoins denominated in advanced-economy hard currencies could attract investor demand and affect local markets.
  - Closed networks with high barriers to entry could increase market power and fragment existing payment infrastructures (FSB 2020).

### Market-structure and pandemic effects
- COVID-19 accelerated digitalization of retail financial services and strengthened the role of BigTechs and digitally prepared incumbents.
- Market shares of BigTechs and larger fintech-driven firms increased during the pandemic at the expense of smaller fintech start-ups and less digitally prepared incumbents.
- Benefits: improved financial inclusion, cost savings, efficiencies, and improved consumer welfare.
- Risks: consumer abuse due to low financial literacy, potential monopolistic behavior, and financial instability.

### Regulatory framework recommendations and options (Bali Fintech Agenda and hybrid approach)
- Bali Fintech Agenda: 12-policy-element framework to harness fintech benefits while mitigating risks (embrace fintech, ensure open competition, foster financial inclusion, develop robust financial and data infrastructure).
- Hybrid regulatory approach recommended:
  - Home supervisors: establish proportionate entity-based regulation to cover BigTech as a group (principle-based, flexible, and proportionate to entity-wide risks).
  - Host supervisors: apply activity-based regulations supplemented by groupwide supervision by the home supervisor to ensure a level playing field for specific activities.
  - Broader coordination: engagement with nonfinancial regulators and competition authorities, particularly for home regulators.
- Interim measures while new legal/regulatory frameworks are developed:
  - Active use of existing regulatory powers.
  - Indirect supervision through regulated entities in the group.
  - Proper implementation of nonbank and conduct regulations.
  - Active coordination across authorities to prepare for multi-jurisdictional BigTech entry, activities, and business lines.
  - Encourage public-private collaboration for better governance frameworks, industry codes, and enhanced disclosure.
- International coordination:
  - Explore options to promote global consistency in BigTech treatment through existing or new global bodies with broad mandates beyond financial-sector standard setters.
  - Recommendation to review the 2012 Principles for the Supervision of Financial Conglomerates to address regulatory gaps and mitigate new risks (including systemic risk).

### Geographic patterns of BigTech expansion
- Advanced economies:
  - Focus on payment and lending services where other nonbank entities are also actively expanding.
  - United States: Alphabet, Amazon, Apple, Meta, and Microsoft have all expanded into financial services, with the largest presence in payments and credit.
    - Three firms (Alphabet, Amazon, and Microsoft) also provide cloud services for regulated entities.
  - Japan example: NTT docomo and Rakuten entering financial services at a slower pace.
- Emerging markets:
  - Wider scope including banking, insurance, and investment services.
  - China: Alibaba (through Ant Group), Tencent, and Baidu have greater presence across banking, payments, lending, insurance, and investment; operations often partner extensively with commercial banks.
  - Other regions: South America (Mercado Libre); east Africa (Safaricom); Indian subcontinent (Jio).

### Interconnectedness: partnerships, lending, and investment linkages
- Partnerships with commercial banks:
  - Common cooperative arrangements in consumer loans; BigTechs provide customer interface, banks provide funding.
  - Risk allocation example: some cases indicate BigTech participation as low as 2 percent of a loan, where 98 percent of the loan, and risk, is borne by the partnering commercial bank.
  - BigTechs can charge transaction fees to commercial banks while keeping risk exposure minimal.
  - Moral hazard: incentives to increase lending volume with lower credit quality if banks do not conduct proper credit risk management and loss-sharing.
- Investment products and MMFs:
  - MMF integration with payment services has seen significant BigTech interest, particularly in east Asia.
  - MMFs required to invest customers’ funds in high-quality and short-term assets such as short-term government bonds or other highly rated issuers’ bonds.
  - With historic low interest rates in the second half of the last decade, some BigTech-offered MMFs began offering higher returns than bank deposits.
  - Risks of integrated payment-MMF products:
    - Rapid on-demand withdrawals can be inconsistent with liquidity of underlying MMF assets.
    - Exposure to higher liquidity mismatch risks than those of advanced economies.
    - Safety nets (central bank liquidity facilities and deposit insurance) generally not available to MMFs offered by BigTechs.
- Interconnections with FMIs and CCPs:
  - Examples: Alipay and WeChat Pay interconnected with NetsUnion Clearing Corporation (China); Google Pay direct connection with Unified Payments Interface and Immediate Payment Service (India).

### Concentration of cloud services and systemic implications
- Cloud functions: SaaS, IaaS, PaaS.
- Key concentration statistics:
  - Bank of England 2020 survey: more than 70 percent of banks and 80 percent of insurers rely on just two cloud providers for IaaS.
  - Globally, 52 percent of cloud services are provided by just two BigTechs, while over two-thirds of services are provided by the top four BigTechs (Richter 2021).
- Implications:
  - Reliance on a small number of cloud providers creates potential for large-scale operational disruption.
  - Failure of a cloud service or provider could create a significant event in financial services with material contagion across sectors.
  - In some respects, BigTechs are already “too big to fail.”

### Key risks of BigTech (summary)
- Financial stability:
  - Cumulative activities across sectors; interconnectedness with incumbents; provision of systemically important activities (cloud, payments infrastructure).
- Consumer protection:
  - Reduced consumer choice through “rebundling”; market dominance; lack of appropriate disclosure; free/cheaper services via data capture.
- Market integrity:
  - Challenges of regulation, supervision, and enforcement across jurisdictions and for firms with core nonfinancial businesses.
- Financial integrity (noted beyond scope):
  - Platforms that could facilitate cross-border fraud, theft, and money laundering; end-user unawareness with blockchain-based propositions.

### Regulatory approaches, trade-offs, and practical adaptations
- Predominant approaches:
  - Entity-based regulation: applied to licensed entities or groups; governance, prudential, and conduct requirements; principle-based and flexible.
  - Activity-based regulation: applied to any person or firm engaging in regulated activities; typically prescriptive; requires precise definitions of activities.
  - Hybrid approach: combines entity- and activity-based elements with clear allocation between home and host jurisdictions.
- Observations and trade-offs:
  - Existing frameworks can create unlevel playing fields and regulatory arbitrage favoring BigTechs.
  - Trade-offs between efficiency and stability; data privacy versus data sharing for prudential purposes.
  - Entity-based approach better for prudential stability but problematic if perimeter unclear; activity-based approach can be simpler but may limit supervisors’ early action.

### Interim measures, disclosure, and industry codes
- Interim measures:
  - Encourage BigTechs to develop codes of conduct addressing spillover risks.
  - Enhance disclosure of BigTech financial services to foster market discipline.
    - Current disclosure by BigTechs does not describe their financial services and associated risks in detail.
    - Disclosures can be mandatory or voluntary; standardized mandatory disclosure across firms is most impactful.
- Industry codes:
  - Can provide market protections and save regulatory resources; best developed through public-private collaboration with public consultation.
  - Codes should focus on outcomes rather than detailed rules.
  - Limitations: potential “halo effects” where users incorrectly assume regulatory protections exist.

### BOX 2 — Disclosure of BigTech Financial Services: current issues and regulatory implications
- Current disclosures and business models:
  - BigTechs typically facilitate financial transactions between incumbents and end users; funding and credit/liquidity risks usually taken by partnering banks and financial institutions.
  - Disclosures have not included critical information on risk sharing between BigTechs and incumbent financial institutions.
  - Some BigTech firms that provide lending disclose activities under “account receivables” without credit quality information.
  - In one situation, a firm appeared to have extensive credit support from a related-party bank outside group consolidation.
- Contagion and reputational risks:
  - Lack of transparency means costs of disruption are largely unknown; BigTech collapse could force partnering banks and regulators to consider rescue interventions.
  - Recommendation: BigTech firms should be required to enhance disclosure regarding financial services, including step-in and reputational risks.
- Implications for regulatory architecture:
  - Longer-term solutions may require home supervisors to consider entity-based regulation (for example, a “BigTech license” or systemic designation).
  - Home supervisors will need stronger coordination with data, privacy, competition, and consumer protection agencies and with foreign host regulators.
  - Host supervisors may rely on home supervisors and focus on activity-based regulation, but may need concrete actions if home action is slow.
- Potential regulatory approaches for home authorities:
  - Require financial holding companies for financial services activities.
  - Create BigTech licenses covering entire groups.
  - Designate BigTechs as systemically important infrastructures.
- Designation metrics could include concentration and interconnectedness, market share of related financial services, and degree of cross-border and cross-sectoral activities.

### Illustrative regulatory measures in practice (summaries)
- China:
  - Required BigTech entities to set up a financial holding company.
  - Indirect supervision through commercial banks: banks must carry out independent loan risk assessment; cap co-lending with internet platforms at no more than 50 percent of outstanding loans; limit co-lending with one platform to 25 percent of the bank’s tier-1 net capital; conduct online lending only within the jurisdiction of their registration; internet platforms required to provide at least 30 percent of the funding in any single joint loan with a bank; regional banks cannot raise cross-regional deposits from platforms.
- European measures:
  - Digital Services Act and Digital Markets Act include powers to improve disclosures, mitigate abusive market practices, ensure data portability and interoperability.
  - Financial Conglomerates Directive (FICOD) could cover BigTech where financial activities are material, with stress testing and enhanced information exchange, but may not capture entities with narrow financial activities.

### Box 3 (continued): regulatory developments, challenges, and conclusions
- EU:
  - The Digital Operational Resilience Act establishes a framework whereby a BigTech considered a critical third-party provider can come under regulatory oversight for that activity.
- US:
  - US financial authorities have not taken concrete actions but the President’s Working Group on Financial Markets issued a report on stablecoins recommending limits on affiliation with commercial entities; limits on use of users’ transaction data; and risk-management requirements for entities performing critical activities.
  - The report recommends FSOC consider designation of stablecoin arrangements as systemically important as an interim measure.
- China and EU comparison:
  - China focuses on financial subsidiaries with financial authorities as lead supervisors; EU focuses broadly on activities with regulatory lead not necessarily a financial regulator.
- Key supervisory challenges:
  - Designation as systemically important is administratively burdensome and may take substantial time.
  - Cross-sector coordination and home-host role allocation are difficult due to diffuse risk locations and decision-making.
  - Regulatory design and timing: developing robust measures may take years; traditional prudential tools may not be binding where BigTechs are less exposed to credit, market, and liquidity risks.

### Final conclusions and policy recommendations
- Need for a hybrid regulatory approach combining entity- and activity-based elements.
- Home supervisors should ideally establish entity-based coverage of global BigTech group risks; host supervisors should address local risks via activity-based regulations.
- Strong coordination between home and host supervisors is essential, with a clear allocation of responsibilities.
- Short-term actions: active use of existing powers, indirect supervision through regulated entities, proper implementation of nonbank and conduct regulations, and encouragement of industry codes of conduct and enhanced disclosures.
- International coordination and standards: explore options for global consistency; review the 2012 Principles for the Supervision of Financial Conglomerates; IMF can help facilitate global dialogue and review/implement new standards.

### Selected definitions
- Activity-based regulation: applied to any person or entity that engages in certain regulated activities, for example, facilitating the buying and selling of investments or operating lending activities.
- BigTech: platform-based business model focused on maximizing interactions between a large number of mainly retail users. BigTechs are usually large technology conglomerates with extensive customer networks and core businesses across markets, for example, in social media, internet search, and e-commerce.
- Entity-based regulation: applied to licensed entities or groups that engage in regulated activities (such as deposit taking, payment facilitation, lending, and securities issuance); requirements imposed at the entity level may include governance, prudential, and conduct requirements.
- Hybrid regulation: combines elements of both activity- and entity-based regulation depending on the nature of each jurisdiction’s regulatory structure and whether the jurisdiction houses the headquarters of a firm or hosts its activities.

*International Monetary Fund—Fintech Notes (ftnea2022002).*

### Box 1. Different Trends of BigTech Expansion into Financial Services . . . . . . . . . . . . . . . . . . . . . . . . . .

### Box 1. Different Trends of BigTech Expansion into Financial Services

### Executive summary and context
- Fintech developments: unbundling and decentralization of services; rapid technology and business-model change; strong economies of scale; cross-border and cross-sectoral expansion; focus on retail services.
- BigTech advantages: existing user base and big data; artificial intelligence and machine learning; cross-subsidization; economies of scale; data analytics, network externalities, and interwoven activities loop (Crisanto, Ehrentaud, and Fabian 2021).
- Short-term benefits of BigTech presence: potential to increase financial inclusion, lower costs, and expand consumer choice.
- Long-term risks: concentration, contagion, reputation risks, and potential systemic implications in local financial markets.

### Key elements that distinguish BigTech from fintech start-ups
- No single agreed definition, but BigTech described as “large companies with established technology platforms” (FSB 2019) and “large technology companies” (Financial Stability Institute).
- Distinguishing factors: number of users, number of jurisdictions of operation, revenue, and scope of activities.
- BigTech can reverse fintech unbundling by bundling a wide range of financial services within the group using:
  - Large proprietary data sets and lower-cost access to those data.
  - Cross-subsidization and economies of scale.
  - Integration across sectoral services creating “one-stop” propositions more attractive than those of traditional financial conglomerates.

### Channels of financial-stability risk from BigTech expansion
- Three broad ways BigTech expansion can create risks to financial stability:
  - By carrying out several activities that increase risk when carried out cumulatively (and due to lack of effective cross-sectoral regulation).
  - Through operational interconnectedness with financial incumbents (for example, between loan-originating BigTech and commercial banks providing funding).
  - Through financial interconnectedness via provision of single systemically important activities like the cloud or systemic payments infrastructures.
- Combined effects can create “too big to fail” scenarios.

### Sectoral expansion evidence and trends
- Payments:
  - Initial BigTech focus; many BigTechs had existing platforms enabling rapid offering of digital payment services (example: Facebook Pay).
  - Payments regulation in some jurisdictions had supported new entrants, facilitating BigTech entrance.
  - In 2020, BigTechs invested over $2 billion in fintech companies, with Google’s parent Alphabet alone generating 23 fintech investments.
- Lending:
  - BigTechs leverage consumer preference and spending data to offer lending to underserved consumers and SMEs.
  - BigTech lending to SMEs is largest in Asia but gaining traction globally.
- Insurance:
  - BigTechs leverage product-protection and warranty experience and proprietary data (social media, chat functions) to tailor insurance products.
  - Consumer purchase propensity from BigTechs increased from 27 percent to 44 percent between 2016 and 2020 (World InsurTech Report 2020).
- Stablecoins and large-scale payment initiatives:
  - Proposed BigTech-led global stablecoins could be potentially systemic at launch given large user bases and network effects.
  - In low-income and emerging markets, stablecoins denominated in advanced-economy hard currencies could attract investor demand and affect local markets.
  - Closed networks with high barriers to entry could increase market power and fragment existing payment infrastructures (FSB 2020).

### Market-structure and pandemic effects
- COVID-19 accelerated digitalization of retail financial services and strengthened the role of BigTechs and digitally prepared incumbents.
- Market shares of BigTechs and larger fintech-driven firms increased during the pandemic at the expense of smaller fintech start-ups and less digitally prepared incumbents.
- Benefits: improved financial inclusion, cost savings, efficiencies, and improved consumer welfare.
- Risks: consumer abuse due to low financial literacy, potential monopolistic behavior, and financial instability.

### Regulatory framework recommendations and options
- Bali Fintech Agenda (BFA): a 12-policy-element framework to harness fintech benefits while mitigating risks, including embracing fintech, ensuring open competition, fostering financial inclusion, and developing robust financial and data infrastructure.
- Hybrid regulatory approach recommended:
  - Home supervisors: establish proportionate entity-based regulation to cover BigTech as a group (principle-based, flexible, and proportionate to entity-wide risks).
  - Host supervisors: apply activity-based regulations supplemented by groupwide supervision by the home supervisor to ensure a level playing field for specific activities.
  - Broader coordination: engagement with nonfinancial regulators and competition authorities, particularly for home regulators, is required to mitigate systemic risks from BigTech activity.
- Interim measures while new legal/regulatory frameworks are developed (which may take several years):
  - Active use of existing regulatory powers.
  - Indirect supervision through regulated entities in the group.
  - Proper implementation of nonbank and conduct regulations.
  - Active coordination across authorities to prepare for multi-jurisdictional BigTech entry, activities, and business lines.
  - Encourage public-private collaboration for better governance frameworks, industry codes, and enhanced disclosure.
- International coordination:
  - Options should be explored to promote global consistency in BigTech treatment through existing or new global bodies with broad mandates beyond financial-sector standard setters.
  - Recommendation to review the 2012 Principles for the Supervision of Financial Conglomerates to address regulatory gaps and mitigate new risks (including systemic risk) arising from conglomerates such as BigTech groups.
- Data policy work: noted promising work on data policy (Carriere-Swallow and Haksar 2019; Haksar and others 2021).

*International Monetary Fund—Fintech Notes (Box 1: Different Trends of BigTech Expansion into Financial Services).*

### BOX 1. Different Trends of BigTech Expansion into Financial Services

### BOX 1. Different Trends of BigTech Expansion into Financial Services

### Geographic patterns of BigTech expansion
- Advanced economies
  - Expansion tends to focus on payment and lending services where other nonbank entities are also actively expanding.
  - Robust and comprehensive regulation in banking and insurance services seems to be a factor behind this route of expansion.
  - United States: Alphabet, Amazon, Apple, Meta, and Microsoft have all expanded into financial services, with the largest presence in payments and credit.
    - Three firms (Alphabet, Amazon, and Microsoft) also provide cloud services for regulated entities.
  - Other advanced economies (example: Japan): NTT docomo and Rakuten are entering financial services (payments, securities, insurance) at a slower pace compared with the United States.
- Emerging markets
  - Scope of BigTech expansion is wider and includes banking, insurance, and investment services.
  - China: Alibaba (through Ant Group), Tencent, and Baidu have greater presence across banking, payments, lending, insurance, and investment; operations are more established and of greater systemic importance and often partner extensively with commercial banks.
  - Other regions: South America (Mercado Libre); east Africa (Safaricom); Indian subcontinent (Jio). BigTechs often outcompete smaller fintech start-ups and sometimes benefit from regulatory frameworks that allow them to outcompete incumbent financial institutions.

### Interconnectedness: partnerships, lending, and investment linkages
- Partnerships with commercial banks
  - Common cooperative arrangements in consumer loans, particularly in low-margin banking services.
  - BigTechs can gather further customer data and open new revenue streams by providing consumer interfaces while partnering with banks to deliver loans.
  - Benefits: potential improvement in financial inclusion by reaching underserved individuals; banks may obtain more diversified loan portfolios.
  - Risk allocation example: some cases indicate BigTech participation as low as 2 percent of a loan, where 98 percent of the loan, and risk, is borne by the partnering commercial bank.
  - BigTechs can charge transaction fees to commercial banks, increasing revenue share while keeping risk exposure minimal.
  - Moral hazard: biased incentives to increase lending volume with lower credit quality if commercial banks don’t conduct proper credit risk management and establish appropriate data and loss-sharing arrangements.
- Investment products and MMFs
  - Money market funds (MMF) integration with payment services has seen significant BigTech interest, particularly in east Asia.
  - MMFs required to invest customers’ funds in high-quality and short-term assets such as short-term government bonds or other highly rated issuers’ bonds.
  - With historic low interest rates in the second half of the last decade, some BigTech-offered MMFs began offering higher returns than bank deposits.
  - Risks of integrated payment-MMF products:
    - Retail MMF investments integrated with payment services allow rapid on-demand withdrawals that can be inconsistent with the liquidity of underlying MMF assets.
    - Exposure to higher liquidity mismatch risks than those of advanced economies.
    - Safety nets (central bank liquidity facilities and deposit insurance) are generally not available to MMFs offered by BigTechs.
    - These features can create contagion and interconnectedness concerns, prompting regulatory tightening.
- Interconnections with FMIs and CCPs
  - BigTech payment and investment services could have exposures and potential contagion to FMIs and CCPs.
  - Examples: Alipay and WeChat Pay interconnected with NetsUnion Clearing Corporation (China); Google Pay direct connection with Unified Payments Interface and Immediate Payment Service (India).

### Concentration of cloud services and systemic implications
- Cloud defined: virtual delivery of computing services including servers and storage, analytics, and intelligence.
- Three general cloud functions: software as a service (SaaS), infrastructure as a service (IaaS), platforms as a service (PaaS).
  - SaaS: hosting and delivery of applications managed by third parties.
  - IaaS: access to storage, networking, and virtualization.
  - PaaS: provides software and hardware applications that the user can build upon.
- Key concentration statistics and findings
  - Bank of England 2020 survey: more than 70 percent of banks and 80 percent of insurers rely on just two cloud providers for IaaS.
  - Globally, 52 percent of cloud services are provided by just two BigTechs, while over two-thirds of services are provided by the top four BigTechs (Richter 2021).
- Implications
  - Financial sector reliance on a small number of cloud providers creates potential for large-scale operational disruption.
  - Failure of a cloud service or provider could create a significant event in financial services with poor outcomes for markets, consumers, and financial stability.
  - Cloud concentration extends beyond financial services into the wider economy, so operational disruption could have material contagion impacts across sectors.
  - The importance of these services implies that, in some respects, BigTechs are already “too big to fail.”

### Key risks of BigTech (summary of Table 1)
- Financial stability
  - Expansion across financial sectors carrying out several activities that in isolation might not create systemic risk but can increase risk when carried out cumulatively.
  - Interconnectedness with financial incumbents.
  - Carrying out a single systemically important activity, such as cloud provision or operating payments infrastructure.
- Consumer protection
  - Reduced consumer choice through “rebundling.”
  - Market dominance that could lead to innovation being replaced by markups.
  - Lack of appropriate disclosure of activities, partnerships, or regulatory protection.
  - Free/cheaper services provided through capturing/storing consumer data.
- Market integrity
  - Challenges of regulation, supervision, and enforcement:
    - against BigTechs located in other jurisdictions.
    - against BigTechs with core businesses in nonfinancial sectors (for example, e-commerce).
- Financial integrity (noted as beyond scope of paper but listed)
  - BigTech platforms that could facilitate cross-border fraud, theft, and money laundering.
  - End-user unawareness where BigTechs operate blockchain-based propositions.

### Regulatory approaches, trade-offs, and practical adaptations
- Predominant approaches
  - Entity-based regulation
    - Applied to licensed entities or groups engaging in regulated activities (deposit taking, payment facilitation, lending, securities underwriting).
    - Requirements at the entity level may include governance, prudential, and conduct requirements plus supervisory activities (offsite monitoring, onsite inspections).
    - Often principle-based and allows flexibility; supports continuous engagement and a ladder of interventions short of enforcement.
  - Activity-based regulation
    - Applied to any person or firm that engages in certain regulated activities (for example, facilitating buying/selling of investments or operating lending activities).
    - Typically prescriptive, used for market conduct, compliance ensured by fines and enforcement.
    - Requires precise definitions of activities; may create regulatory arbitrage opportunities and be less effective for rapidly changing fintech activities.
    - Not generally suitable for early supervisory action to modify risky behavior.
  - Hybrid approach
    - Combines elements of entity- and activity-based regulation with clear allocation between home and host jurisdictions and close cooperation among regulators.
    - Entities subject to licensing by home jurisdictions and activity-based requirements by host regulators.
    - Enables monitoring and detection of systemic risks arising across the group.
    - Underlying principle: “same services/activities, same risks, same rules, and same supervision.”
- Observations on existing frameworks and challenges
  - Many financial institutions are subject to both entity- and activity-based regulations (banking more entity-based; securities more activity-based).
  - Nonbank BigTech financial entities often subject to nonbank financial regulation (activity-based), allowing avoidance of comprehensive groupwide entity-based regulation unless they engage in deposit taking or insurance underwriting.
  - Sectoral regulation for financial conglomerates may not capture systemic risks that highly integrated BigTech conglomerates could create.
  - Existing regulatory frameworks can create unlevel playing fields that favor BigTechs and enable regulatory arbitrage.
  - BigTech conglomerates may cross-subsidize financial services from core business revenues, potentially leading to market dominance and long-term conduct and market integrity risks.
  - Power dynamics could shift toward BigTech operators and technologies from regulators because BigTech revenue from regulated financial services may remain a small percentage of total revenue and they are less exposed to credit and liquidity risks.
- Trade-offs
  - Trade-off between efficiency and stability: competitive markets are efficient but may pose risks to financial stability as competition depletes margins and prevents banks from building buffers.
  - Trade-offs around data: between anonymity (privacy) and allowing data access to private providers (efficiency); between anonymity (privacy) and data sharing for prudential purposes (stability).
  - Entity-based approach better for financial stability and prudential requirements but problematic if regulatory perimeter is unclear.
  - Activity-based approach can be simpler and promote a level playing field but may limit supervisors’ ability to take early action.

### Interim measures, disclosure, and industry codes
- Interim and near-term measures
  - Encourage BigTechs to develop codes of conduct to address spillover risks from unregulated activities to the financial sector.
  - Enhance disclosure of BigTech financial services to foster market discipline and improve provision of financial services.
    - Current disclosure by BigTechs does not describe their financial services and associated risks in detail.
    - Disclosures can be mandatory (regulation) or voluntary (codes of conduct); standardized mandatory disclosure across firms is most impactful.
- Industry codes of conduct
  - Can provide market protections while saving regulatory resources, particularly where authorities have stretched resources or limited powers.
  - Best developed through public-private collaboration (BigTech, incumbent financial institutions, authorities) with public consultation for transparency.
  - Codes should focus on delivering good outcomes rather than prescribing detailed rules.
  - Limitations: codes may create “halo effects” where users incorrectly assume regulatory protections exist, creating reputational risk for authorities if entities fail or risks materialize.

### Holistic and international policy considerations
- Need for holistic policy responses at the national level to address risks and growing systemic importance of BigTech financial services.
  - Modification and adaptation of regulatory frameworks may be needed to contain regulatory arbitrage, recognizing regulation should remain proportionate to risks.
- Fragmented cross-jurisdictional frameworks can lead to regulatory arbitrage, policy gaps, and buildup of financial stability risks across borders.
  - The Bali Fintech Agenda (BFA) policy elements relevant to BigTech include:
    - Policy Element I (embracing the promise of fintech).
    - Policy Element II (enabling new technologies to enhance financial services provision).
    - Policy Element III (reinforcing competition and commitment to open, free, and contestable markets).
    - Policy Element IV (ensuring the stability of domestic monetary and financial systems).
    - Policy Element VI (adapting regulatory frameworks and supervisory practices).
    - Policy Element XI (encouraging international cooperating and information sharing).
- International cooperation and information sharing are important to mitigate cross-border risks and reduce regulatory friction for entities scaling across markets.
- Longer-term considerations
  - Holistic policy responses may include expanding the regulatory perimeter, enhancing groupwide supervision, and building on guidance from standard-setting bodies.
  - Successful hybrid regulatory implementation requires close coordination between prudential and conduct regulators despite differences in mandates and supervisory objectives.

*Source: IMF staff (BOX 1. Different Trends of BigTech Expansion into Financial Services).*

### BOX 2. Disclosure of BigTech Financial Services

### BOX 2. Disclosure of BigTech Financial Services

### Current disclosures, business models, and risks
- BigTech firms remain platform-based business models that facilitate financial transactions between incumbents and end users.
- BigTech firms don’t normally provide funding or take credit and liquidity risks from the provision of financial services; funding and financial risks are usually taken by partnering banks and other financial institutions.
- Disclosures by BigTech firms until now have not included critical information on risk sharing between BigTechs and incumbent financial institutions.
- Many large BigTech firms are offering payment services, which could inherit certain credit and liquidity risks of merchants and the end users, unless those risks are taken or guaranteed by the partnering financial institutions.
- Some BigTech firms are actively providing lending services themselves:
  - BigTech firms that have grown from e-commerce business often have significant lending activities with their merchants and buyers.
  - They often disclose these activities under “account receivables” without any information on credit quality.
  - In one situation, one firm seems to have had extensive credit support from a related-party bank, but the bank is outside the group consolidation.
  - In general, there is not much disclosure by the BigTech firms on information and risks of their lending activities.
- BigTech financial businesses are exposed to contagion and reputational risks:
  - End users may be using these services based on their trust in the service quality and reputation of the BigTech firms.
  - If systematically important BigTechs collapse, banks that use BigTech platforms or cloud services will face large operational challenges, which may potentially require exceptional rescue interventions.
  - Currently, because of the lack of transparency, the costs of this type of disruption are largely unknown.
  - In the scenario where the partnering financial institution becomes impaired, a BigTech might need to step in and provide continuity to its financial services by taking on credit and liquidity risks.
- Recommendation: BigTech firms should be required to enhance their disclosure regarding financial services (including those risks such as step-in and reputational risks, which may be less quantifiable).

### Implications for regulatory architecture
- Longer term solutions may require more substantive changes, such as regulators reevaluating their roles as home and host supervisors.
- Host jurisdictions may consider activity-based regulations supplemented by groupwide supervision tailored to a BigTech’s specific risks; this can be built within existing regulatory frameworks and can be implemented with fewer additional resources.
- Supplementary group supervision can help impose prudential requirements across a BigTech group’s financial activities, but the effectiveness of such requirements could be limited.
- Over the longer term, a better solution would be that home jurisdictions consider entity-based regulation of large tech conglomerates through entirely new regulatory frameworks designed specifically to capture the risks of BigTech—for example, a “BigTech license” or systemic designation for large tech conglomerates that conduct certain activities within financial services. This approach can capture risks from across financial activities but would likely require significant supervisory resources.
- Home supervisors of BigTech groups will need to strengthen coordination efforts with governmental agencies, other domestic regulators, and host regulators globally:
  - If BigTechs grow to systemic levels, it is more likely that home supervisors will need an entity-based approach.
  - Home supervisors will need to significantly improve domestic coordination with relevant authorities (such as data, privacy, competition, and consumer protection agencies).
  - Home regulators will need to work more closely with domestic regulators from other sectors in which BigTech entities are conducting business.
  - Home regulators will also need to allocate resources into international coordination.
  - A robust regulatory architecture (such as clear and effective coordination arrangements among the relevant financial regulators or integration of regulatory authorities) will help to pool scarce resources for new tasks.
- For host supervisors, a suitable regulatory approach will be best determined by the country context:
  - Host supervisors may potentially rely on home supervisors and focus on activity-based regulations if home supervisors have implemented robust regulations.
  - However, if actions taken by home supervisors are slower than BigTech growth in host jurisdictions, host supervisors may need to take more concrete actions.
  - This could have significant resource implications to the host supervisors, which may require substantial reform of regulatory architecture, and smaller jurisdictions might find it more difficult to enforce than larger jurisdictions.

### Potential regulatory approaches
- Home authorities have several options when implementing an entity-based approach:
  - Require BigTechs to create financial holding companies for their financial services activities, allowing those authorities to supervise the holding companies on an entity basis.
  - Create more general BigTech licenses and regulate not only the financial entities but also the entire group.
  - Designate BigTechs in financial services as systemically important infrastructures.
- Challenges and implementation considerations:
  - The most important first step to implement an entity-based approach is to identify the lead/home supervisor.
  - Identifying a suitable nexus for home regulation might not always be easy, particularly where a BigTech might be headquartered in one jurisdiction, delegate certain key decision-making functions in another jurisdiction, and carry out most of its financial services activities in a third jurisdiction.
  - Even with a suitable nexus, different jurisdictions might approach entity-based regulation for BigTechs differently depending on their legislative frameworks and the nature of BigTech activities.
  - Financial regulators may not always take the lead in conducting entity-wide regulation for BigTech; in some jurisdictions, other authorities, including competition authorities, might take the lead in ensuring entity-wide oversight of BigTech firms given the cross-sectoral nature of BigTech.
- Designation metrics for a designation approach would need to be agreed across borders and may include:
  - the degree of concentration and interconnectedness,
  - market share of their related financial services (including the services provided by partnering entities),
  - the degree of cross-border and cross-sectoral activities.
  - Such metrics should be developed in close cooperation with foreign authorities where BigTechs have material financial activities.
- Activities-based approach for host authorities:
  - An activities-based approach for host authorities can be easier to implement, although defining relevant activities is likely to be difficult—particularly where these are either new activities or current activities carried out through new technologies or business models.
  - BigTechs are likely to need specific licenses or permissions to conduct specific activities within a jurisdiction.
  - Host jurisdictions may implement or update existing regulation to reflect the growth of BigTechs, for example, by strengthening some operational, cyber, capital, or liquidity requirements.

### Illustrative regulatory measures in practice (summary from Box 3 case studies)
- Chinese measures toward an entity-based approach:
  - Required BigTech entities to set up a financial holding company where each line of the business (for example, consumer finance and insurance) will be subject to relevant prudential and governance requirements.
  - Deployed indirect supervision through existing commercial banks to align incentives between BigTechs and partnering banks, including:
    - commercial banks must carry out independent loan risk assessment;
    - cap co-lending with internet platforms or other partners at no more than 50 percent of outstanding loans;
    - limit co-lending with one platform to 25 percent of the bank’s tier-1 net capital;
    - conduct online lending only within the jurisdiction of their registration;
    - internet platforms are required to provide at least 30 percent of the funding in any single joint loan with a bank;
    - regulations clarify that regional banks would not be able to raise cross-regional deposits from platforms, leading the platform to remove bank-deposit products.
  - Aim: address excessive interconnectedness and contagion risks from BigTech financial services to incumbent financial entities.
- European measures favor activities-based regulation as a primary host-jurisdiction approach:
  - The Digital Services Act and the Digital Markets Act contain targeted powers to leverage against platform providers and online gatekeepers, covering many BigTech entities and including measures to improve disclosures and mitigate abusive market practices, data-combination risks, self-preferencing, and to ensure data portability and interoperability of ancillary services.
  - The Financial Conglomerates Directive (FICOD) is a framework that could cover BigTech through a broad scope that includes entities that operate in financial markets and are regulated subsidiaries of larger parent companies, provided the financial activities are material; FICOD aims to mitigate risks related to size, complexity, concentration, and contagion through stress testing and an enhanced information exchange program between the entity and regulatory authorities.
  - Limitation: FICOD was not designed for BigTech entities with a narrow scope of financial activities and a limited number of entities identified as financial undertakings, so it might not capture all nuanced cross-border and cross-sectoral risks.

*Source: BOX 2. Disclosure of BigTech Financial Services, ftnea2022002*

### Box 3 (continued)

### Box 3 (continued)

### Regulatory developments by jurisdiction
- European Union:
  - The Digital Operational Resilience Act establishes a regulatory framework whereby, if a BigTech entity is considered a critical third-party provider (for example, cloud services), it will come under the regulatory framework.
  - In such a scenario, EU authorities would have direct capacity to oversee the service provider over the provision of that specific activity.
- United States:
  - US financial authorities have not taken concrete actions to regulate BigTech financial activities, but recent work signals recognition of potential systemic risks.
  - The US President’s Working Group on Financial Markets issued a report on stablecoins describing rapid growth, systemic risk, and concentration of economic power of stablecoin arrangements.
  - The report does not use the term “BigTech,” but describes features of BigTech such as “access to existing customer bases” and “combination of a stablecoin issuer or wallet provider and a commercial firm.”
  - The report’s recommendations to address excessive concentration of economic power include:
    - (1) limits on affiliation with commercial entities,
    - (2) limits on use of users’ transaction data,
    - (3) appropriate risk-management requirements on any entities that perform activities critical to the functioning.
  - The report also recommends that the Financial Stability Oversight Council (FSOC) consider designation of stablecoin arrangements as systemically important activities, utilities, or entities as an interim measure to permit the appropriate agency to establish risk-management standards for engaged financial institutions.
- China and EU broader comparison:
  - Chinese and EU authorities have both taken steps to mitigate risks from BigTech entry into domestic financial services and aim for a more holistic, entity-based approach to capture risks across the entity.
  - The Chinese approach focuses more on financial subsidiaries with oversight of BigTechs led by financial regulatory authorities; this mirrors China’s circumstance as a “home” regulator for many BigTech entities operating within its jurisdiction.
  - The EU approach looks broadly at activities of BigTechs across their operations, with the regulatory lead not necessarily taken by financial regulatory authorities; this mirrors the EU’s role often as a “host” regulator.
- US approach:
  - Implied by the President’s Working Group report, US approaches are a mixture of entity-based (FSOC designation) and activity-based (restriction of certain activities such as data sharing) regulations.

### Key challenges for supervisors and implementation
- Designation challenges:
  - The biggest challenge for home supervisors is likely to be the designation of BigTechs as systemically important.
  - Nonbank Systemically Important Financial Institution designation (to large asset managers and insurers) has become stranded by strong industry pushback.
  - The US Financial Stability Oversight Committee is subject to significant administrative burdens to prove systemic risk of the designating group and needs to conduct comprehensive cost benefit analysis.
  - As a consequence, any designation (which may be necessary for the home supervisor to implement entity-based regulations) of a BigTech as systemically important may take substantial time.
- Cross-sector coordination:
  - It might be difficult to coordinate between regulatory agencies across domestic sectors where a BigTech entity is considered systemically important because regulatory appetite may differ by industry.
  - A unified governmental strategy might ensure cross-sector collaboration.
  - Supervisory colleges or networks of domestic regulators (for example, the UK Digital Regulation Cooperation Forum) can help improve collaboration across sectors.
- Home versus host supervisory roles:
  - Identifying and quantifying major risks—and their location—may be difficult, complicating clear understanding between home and host supervisors on respective roles.
  - Key risks generated by BigTechs (operational, contagion, and reputation risks) can be difficult to quantify, and decision-making relevant to such risks may not occur in the group’s official headquarters.
  - Many home supervisors may be reluctant to take on difficult roles where most activities and risks are elsewhere and there is little reward to be the first mover, making international coordination mechanisms challenging.
- Regulatory design and timing:
  - Developing robust regulatory measures and implementing them may take a number of years.
  - For existing entities, some prudential regulations (capital, liquidity, leverage) are binding; however, BigTechs are currently less exposed to traditional risks (such as credit, market, and liquidity risks), so those regulatory measures are neither binding nor effective.
  - New regulatory measures may need to be developed to address material risks brought by BigTech (operational, contagion, and reputation risks).

### Conclusions and policy recommendations
- Need for hybrid regulatory approach:
  - Both activity-based and entity-based approaches have strengths and weaknesses; a hybrid approach is ultimately needed to address potential BigTech risks.
  - Regulatory frameworks should deliver free, open, and contestable markets that enable the development of new technologies while safeguarding the integrity of financial systems and ensuring financial stability.
  - Where firms generate systemic risks (for example, through provision of systemically important technology like cloud services or through cumulative impact of carrying out several activities), such BigTechs should be subject to regulation that covers groupwide risks—where entity-based regulation is more effective.
  - Activity-based regulation is needed to address conduct risks (abusive and monopolistic behavior), which could potentially cause systemic risk in the long term.
  - The hybrid approach, combining elements of both activity- and entity-based regulation, is the most suitable to address potential risks of BigTech.
- Division of responsibilities between home and host supervisors:
  - Ideally, home supervisors should establish an entity-based approach to cover global activities of a BigTech group, while host supervisors could address local risks and concerns mainly through activity-based regulations.
  - Strong coordination is necessary between home and host supervisors, based on a clear allocation of responsibilities.
- Short-term actions pending longer-term frameworks:
  - Short-term solutions may be necessary while robust legal and regulatory frameworks are developed and established, given the potentially lengthy legislative and regulatory processes.
  - Regulatory authorities should actively use all existing regulatory powers (such as indirect supervision through regulated entities and proper implementation of nonbank and conduct regulations) with active coordination with other authorities to address BigTech risks across jurisdictions, activities, and business lines.
  - Regulators should encourage BigTech to adopt and improve governance frameworks through industry codes of conduct and enhanced disclosures.
- International coordination and standards:
  - Options should be explored to promote global consistency in treatment of BigTechs through existing or new global bodies.
  - The G7 calls for further ways to mitigate the risk of regulatory fragmentation and to facilitate coherency of emerging technology ecosystems.
  - Any international coordination body would need a broad mandate to address issues outside the remit of financial sector standard setters.
  - Recommendation to review the 2012 Principles for the Supervision of Financial Conglomerates to address regulatory gaps and mitigate new risks (including systemic risk) arising from conglomerates, such as BigTech groups.
  - The IMF can help facilitate global dialogue, share information, review existing international standards, and implement new standards.

### Definitions (selected)
- Activity-based regulation: applied to any person or entity that engages in certain regulated activities, for example, facilitating the buying and selling of investments or operating lending activities.
- BigTech: platform-based business model focused on maximizing interactions between a large number of mainly retail users. BigTechs are usually large technology conglomerates with extensive customer networks and core businesses across markets, for example, in social media, internet search, and e-commerce.
- Entity-based regulation: applied to licensed entities or groups that engage in regulated activities (such as deposit taking, payment facilitation, lending, and securities issuance). Requirements are imposed at the entity level and may include governance, prudential, and conduct requirements.
- Hybrid regulation: combines elements of both activity- and entity-based regulation depending on the nature of each jurisdiction’s regulatory structure and whether the jurisdiction houses the headquarters of a firm or hosts its activities.

*International Monetary Fund—Fintech Notes, Box 3 (continued).*

---


_Source: https://www.imf.org/-/media/files/publications/ftn063/2022/english/ftnea2022002.pdf_
