Comment on CFTC-2026-1321, CFTC-2026-1321-0001, Bilal Ali , Zafar

Bilal Ali ZafarSupportOther
Summary: Bilal Ali Zafar, a risk management professional at the National Industrialisation Company (TASNEE), argues that the primary barrier to fintech adoption is a lack of clear governance standards for integrating fintech partner risks into enterprise risk architectures. He recommends that the Commission issue specific guidance on governance integration, establish a tiered authorization pathway for fintech service providers, and set minimum operational resilience requirements.
Re: Request for Information — Identifying Regulations to Facilitate Innovation and Competition to Financial Products and Services for Fintech Firms Docket: CFTC-2026-1321 | RIN 3038-ZA24 Submitted by: Bilal Ali Zafar Title: Manager, Risk Management and Business Continuity Management Organization: National Industrialisation Company (TASNEE), Riyadh, Saudi Arabia I submit this comment in response to the Commodity Futures Trading Commission's Request for Information on Identifying Regulations to Facilitate Innovation and Competition for Fintech Firms (Docket CFTC-2026-1321, RIN 3038-ZA24), issued pursuant to Executive Order 14405. I am a governance, risk, and compliance practitioner with over seventeen years of experience designing enterprise risk management, regulatory compliance, business continuity, and digital governance frameworks across financial services, insurance, asset management, and industrial sectors in Pakistan, Saudi Arabia, and Malaysia. The primary barrier to fintech adoption at CFTC-registered entities is not a registration process problem. It is a governance integration problem. When a fintech firm partners with a futures commission merchant, a swap dealer, or a commodity pool operator, the existing regulatory framework defines the registered entity's obligations but provides no guidance on how to incorporate fintech partner risks into the enterprise risk architecture. The result is that registered entities routinely manage these risks outside the risk register, outside board reporting, and outside escalation pathways, not by choice, but because no governance standard exists. At the Mutual Fund Association of Pakistan, where I served as Company Secretary for the self-regulatory organization overseeing Pakistan's collective investment scheme industry, I observed this pattern directly: member firms applied inconsistent and unpredictable due diligence frameworks to fintech service providers because no integrated governance standard existed. At ABL Asset Management Company, where I designed the first automated AML and CRS compliance monitoring module in Pakistan's collective investment scheme industry, I experienced the same friction from the fintech solution side. I offer three specific recommendations. First, the Commission should issue guidance defining minimum governance integration standards for fintech partnerships at CFTC-registered entities. Specifically, registered entities should be required to incorporate fintech partner risks into the enterprise risk register, assign named risk ownership for each fintech-related risk category, and include fintech partnership risk in board-level reporting on the same cadence applied to other material operational risks. This would resolve the primary source of friction fintech firms encounter: unpredictable due diligence requirements caused by the absence of a common governance framework. Second, the Commission should consider a tiered authorization pathway for fintech firms operating solely as service providers to CFTC registrants, without directly accessing clearing, trading, or settlement infrastructure. The registered entity's enterprise risk governance framework, properly integrated to include fintech partner risks, provides the accountability mechanism that makes a tiered approach viable without compromising supervisory oversight. Third, the Commission should establish minimum operational resilience and business continuity requirements for fintech partnerships proportional to how operationally critical the fintech partner is to the registered entity's regulated functions. Where a fintech platform is critical to executing regulated activities, the registered entity's continuity program should include documented provisions for that dependency, and this expectation should be explicit in Commission guidance. Governance clarity accelerates rather than impedes fintech adoption. Institutional uncertainty about what governance integration is required is the reason CFTC registrants approach fintech partnerships with unnecessary caution. Clear Commission guidance on integration standards would reduce that uncertainty and enable adoption at a pace consistent with the underlying technology risk profile. I am available to discuss these observations further and welcome the opportunity to contribute to any subsequent consultative process. Thank you for accepting this submission. Respectfully submitted, Bilal Ali Zafar CISA | CRMP (ANAB-accredited) | GRCP Manager, Risk Management and BCM — National Industrialisation Company (TASNEE), Riyadh, KSA bilalalizafar@gmail.com | +966-56-8214435

View on Regulations.gov