Insight

8 out of 10 payment, lending and investment firms can’t show which policy version is in force.

We read 951 public policy documents from 87 firms. The gaps tell an operational story.

8 out of 10, on a blue and teal gradient.
87firms analyzed
951public documents
3,197obligations checked
1,273findings

01 / Executive summary

Small gaps. A recurring pattern.

We analyzed 951 public policy documents from 87 payment, lending and investment firms: payment providers, consumer and SME lenders, fund and asset managers, securities brokers, and private equity firms. They produced 1,273 findings, and three patterns stand out.

Missing version dates. Incomplete external reporting instructions. Unclear data requirements. Each points to the same operational problem: copies drift apart, templates outlive their source and nobody owns the dates that change.

The fix is to find these gaps
and close them.

02 / Key findings

Three gaps hiding in plain sight.

Each figure counts only the firms we could check for that requirement, so the base varies.

80%67/84 firms checked

Which version is in force?

At least one policy has no visible version or last-updated date. When a customer, auditor or supervisor asks what the firm promised on a given date, the published page cannot answer.

Rule cited in the report: GDPR Art. 12(1)

69%27/39 firms checked

Where can someone report?

The whistleblowing page does not fully explain how to report to a competent authority. The page is public, so the gap is visible to any employee, journalist or supervisor. Of these 27 firms, 21 say nothing at all about external reporting.

Rule cited in the report: Lag (2021:890), 5 kap. 9 § 2 p.

64%49/76 firms checked

Is providing data required?

The privacy notice does not say whether customers must provide their data, or what happens if they do not. It is a one-sentence fix. Nearly two in three checked firms have this gap in their privacy notice.

Rule cited in the report: GDPR Art. 13(2)(e)

03 / Why it happens

A document changes in one place.
And not in another.

The report identifies three operational mechanisms. Copies drift. Templates outlive their source. External facts change on a date nobody tracks.

One policy. Three published copies.

English webpage

Updated wording

Edit published

Swedish webpage

Previous wording

Copy left behind

PDF download

Previous wording

Copy left behind

The English page is updated. The Swedish page and PDF still show the old wording.

04 / Gaps in practice

What the page says.
What needs to change.

One example per mechanism, with the proposed wording that addresses the finding.

EXAMPLE 01 / Copies drift

Same policy. Different answers.

Cookie policy
English and Swedish versions
Gap found

The English list names roughly half as many cookies as the Swedish one, so visitors get a different answer depending on language.

Proposed fix

“The cookies below are set on every language version of this site; this list was last updated on [date].”

Keep one cookie list for every language version.

Rule cited in the report: LEK (2022:482) 9 kap. 28 §

EXAMPLE 02 / Templates linger

The drafting note went live.

Cookie policy
Reference to the privacy notice
Gap found

Where the cookie policy should link to the privacy notice, it still shows the editor’s note to insert a link.

Proposed fix

“How we process personal data collected through cookies is described in our privacy notice: [URL].”

Replace the drafting note with the real privacy-notice link.

Rule cited in the report: GDPR Art. 13

EXAMPLE 03 / Dates change

The amount changed. The sheet did not.

Depositor information sheet
Deposit guarantee ceiling
Gap found

The depositor information sheet still states the old ceiling, while the firm’s own product page shows the new one.

Proposed fix

“The deposit guarantee covers up to 1,150,000 kronor per depositor and institution (from 1 January 2026).”

Update the sheet and give the effective date an owner.

Rule cited in the report: Lag (1995:1571) om insättningsgaranti 4 § · RGKFS 2025:2

05 / The way forward

From one snapshot
to staying current.

A yearly gap list catches these findings, then misses them again eleven months later. What works is treating policies as operations: every published policy gets a date and an owner, and copies follow one master text.

The dates that change documents, including guarantee amounts, authority names and closing platforms, sit on a calendar with someone responsible.

From a policy update to action

A new cookie is added to the policy text. Follow this example through the rulebook, tasks and review.

  1. 01

    Snapshot

    Your public documents checked against the rules that apply.

  2. 02

    Rulebook

    Policies become rules, one line each, traced to the source clause.

  3. 03

    Tasks

    Every gap gets an owner; evidence is checked as it arrives.

  4. 04

    Kept current

    A change to a rule, amount or authority flags what it touches.

Your team reviews the revised copies before publishing.

Hybridity turns policies into rules with owners, tasks and evidence, and flags what a change touches. Closing compliance gaps before they become barriers, so you can move faster.

Get your gap analysis

See what your public documents say today, and what it takes to close the gaps.

Source: Hybridity Regulatory Exposure Snapshots, Q4 2026, week 1. 87 payment, lending and investment firms. 951 public documents read and 3,197 obligations checked.

Markets: Sweden (82 firms); Belgium, Norway, EU/UK and Jersey (5 firms combined). The sample is predominantly Swedish. Percentages are rounded and use a different checked base for each requirement.

Regulatory areas: GDPR and UK GDPR, cookies and ePrivacy (LEK, PECR), consumer redress and complaints, whistleblowing, document control, deposit guarantee, SFDR, payment services, investment firm and fund disclosures, crowdfunding (ECSPR), consumer credit, accessibility, and statutory company information.

A finding is a statement about a document, never a verdict on the company. Obligations that can only be evidenced internally have not been counted.

Christopher von Corswant appointed CFOO of Hybridity

Press release

Svea Bank invests SEK 20 million in Hybridity to advance AI-driven compliance to the financial sector

Press release

Ariel Ekgren joins as Chief AI Officer at Hybridity

Press release

Hybridity and Iniziato enter strategic partnership to solve compliance using AI

Press release

Start with your policies.

Closing compliance gaps between guessing and knowing, so you can move faster with confidence.

Book a demo