fscom’s 2026 IT compliance report finds governance and oversight remain key weaknesses, with many financial firms struggling to turn policies into practice.
fscom Compliance Maturity Specialists™ has published its 2026 IT compliance report, the firm’s first benchmark of IT governance, cyber security and operational resilience maturity across regulated financial services firms.
Based on IT compliance reviews carried out throughout 2025, the report identifies where firms are performing well and where the most significant weaknesses remain. It records 116 findings across five control domains, with governance, risk and oversight accounting for 58% of all high-severity findings.
Only 20% of firms reviewed demonstrate mature governance, while 30% require material improvement. A recurring theme is the gap between policy and practice: many firms have well-developed frameworks on paper but limited evidence of active monitoring and board-level oversight.
The report also sets out practical actions for each control domain, from access management and third-party risk to business continuity testing.
Its central message is that strong IT compliance depends on more than the right technical controls. Firms also need clear ownership, effective oversight and evidence that their frameworks work in practice.



















