Investigating Automated Change Analysis in FinTech Regulations
Elahidoost, Parisa, Villamizar, Hugo, Angermeir, Florian, Streit, Jonathan, Méndez Fernández, Daniel, Unterkalmsteiner, Michael, Gorschek, Tony · Zenodo (CERN European Organization for Nuclear Research) · 2025
Context: Software systems in regulated domains must continuously adapt to evolving legal requirements. Practitioners repeatedly interpret, classify, and implement regulatory updates often without systematic support for identifying what has changed or how those changes affect technical artifacts. This makes compliance maintenance labor intensive and error prone. Recent advances in large language models (LLMs) raise the question of where automation can reliably assist this process. Objectives: We aim to (1) characterize the nature of regulatory changes and derive a systematic taxonomy, (2) understand through the lens of practitioners where automation is most useful, and (3) assess the feasibility of using LLMs for detecting and classifying regulatory changes. Method: We conducted a mixed-methods study grounded in the German social security (DEÜV) in collaboration with practitioners from a FinTech company. First, we developed a taxonomy of regulatory changes through manual document analysis of four Regulatory Implementation Specifications (RIS), followed by a workshop and expert interviews. Second, we validated the taxonomy and elicited challenges through semi-structured practitioner interviews. Third, we built a gold-standard dataset of 93 annotated change instances and evaluated seven state-of-the-art LLMs within an automated detection and classification pipeline. Results: The resulting taxonomy defines five change scopes (Textual and Editorial, Data and Field, Procedural, Compliance and Enforcement, Policy) and four optional contextual dimensions (Temporal, Sector-Specific, Stakeholder-Specific, Regional-Specific). Practitioners found it intuitive and valuable for filtering relevant changes, especially Data and Field updates. They highlighted recurring challenges: tight implementation deadlines, legal ambiguity, limited traceability and impact analysis, and overlapping categories. In the automation study, proprietary models achieved the strongest performance, while open-weight models showed greater variability. Performance declined on narrative and poorly structured documents, indicating sensitivity to document format and granularity of context. Conclusion: The proposed taxonomy provides a practical lens for organizing regulatory change information, and LLMs can support the identification and classification of recurring, structurally explicit changes. Their limitations on context-dependent and infrequent categories suggest that automation should complement, rather than replace, expert assessment, motivating future work on human-in-the-loop compliance tooling across broader regulatory ecosystems.