Compliance has always been a cornerstone of banking, but in today’s fast-moving financial landscape, its role has never been more critical. Beyond protecting institutions and their clients, a strong compliance function helps safeguard a bank’s reputation and lays the foundations for sustainable growth. Yet the job is also becoming increasingly complex, as emerging industries, cross-border business models and sophisticated payment flows create new regulatory challenges and heightened exposure to areas such as anti-money laundering and fraud.

One response would be to simply avoid these complexities altogether. But at Lidion Bank, the philosophy is different. Rather than de-risking by closing the door on entire sectors, the bank sees an opportunity to understand them better and support businesses that may have struggled to find a banking partner elsewhere.

Having joined Lidion Bank a year ago after building her career in a more traditional, retail-focused banking environment, Kylie Vassallo brought with her a fresh perspective on the role compliance can play. Moving to a corporate-focused institution serving international clients offered a broader view of how compliance can support business objectives while maintaining robust governance.

“We try not to avoid entire sectors simply because they are more complex or evolving,” Ms Vassallo explains. “Instead, we seek to understand the risks properly, assess them carefully and make sure the right governance and controls are in place.”

Importantly, she stresses that this should never be mistaken for taking a softer approach. “Compliance isn’t there to lower standards or simply wave things through,” she says. “It’s there to ensure that when the bank supports a particular client base or sector, it does so with its eyes open, with clear rationale, proper oversight and a framework that is sustainable.”

Reflecting on how the regulatory landscape has been evolving in the last few years, Ms Vassallo believes one of the biggest changes has been the shift from compliance as a purely technical exercise to one that is firmly focused on outcomes. Simply having policies and procedures in place is no longer enough. “Regulators increasingly want to see that compliance is embedded in day-to-day workflows, understood across the organisation and, ultimately, effective in practice,” she explains. “Banks also need to be able to demonstrate the evidence behind what they are doing.”

This evolution is being driven not only by growing digital risks, but also by major European reforms such as CRR III, CRD VI and the Digital Operational Resilience Act (DORA), which strengthen expectations around governance, capital resilience and risk management.

For Ms Vassallo, meeting those expectations requires compliance to extend well beyond the Compliance department itself. “Compliance is no longer something that sits within one team alone,” she says. “It has become a shared responsibility that touches every function, from Risk and IT to Operations and the wider business.”

At Lidion, that collaborative mindset is reinforced by the organisation’s size. As a relatively small and agile institution, Vassallo notes that teams work closely together, allowing information to flow quickly and regulatory considerations to become part of everyday conversations rather than something addressed in isolation. At Lidion, compliance is not viewed solely as a regulatory requirement but as a top-down commitment, supported by leadership and integrated into the Bank's strategic decision-making.

In practice, this means Compliance is brought into discussions at an early stage, with colleagues from across the business contributing their expertise. “By getting everyone around the table from the outset, we can identify potential issues early, agree on ownership and build the right controls from the start instead of trying to fix problems afterwards,” she explains, noting that this approach has helped foster a culture where compliance is not seen as a box-ticking exercise, but as a shared responsibility across the organisation.

With compliance and regulation evolving at such a rapid pace, and with the added challenge of keeping up not only with changing regulatory expectations but also with the nuances that exist across different jurisdictions, the task can seem overwhelming, particularly for a relatively small team serving an international client base like Lidion’s.

According to Ms Vassallo, this is precisely why the bank embraces the principle of proportionality when it comes to compliance. In simple terms, proportionality means applying regulatory expectations in a way that is appropriate to the bank’s size, business model and risk profile, while still meeting the same high standards expected of any regulated institution. It is not about taking a lighter approach to compliance, but about ensuring that frameworks are practical, justified and fit for purpose.

As Ms Vassallo explains: “Smaller and growing banks can sometimes fall into the trap of over-engineering every process to mirror much larger institutions, or assuming that certain requirements are too advanced to be relevant. But usually, the best approach is somewhere in the middle, where the framework remains robust but is also tailored and defensible. That’s why I believe the real test is whether you can clearly explain your approach to regulators and why it has been designed that way.”

Technology is playing an increasingly important role in strengthening compliance, not by replacing human judgement, but by giving teams better tools to make informed decisions. She notes that much of the work was traditionally manual and reactive, with significant time spent on repetitive processes. Today, automation and data analytics are helping banks like Lidion monitor activity more accurately, identify potential issues earlier and produce clearer reporting.

“Technology allows us to focus more on analysis, judgement and forward-looking work,” she explains. “It improves the quality of our oversight rather than replacing it.” Better reporting and monitoring also make it easier to spot trends, escalate concerns more quickly and provide regulators with tangible evidence that controls are working in practice rather than simply existing on paper.

As for the years ahead, Ms Vassallo expects compliance to become even more outcomes focused. Strong governance, effective financial crime prevention, digital resilience and consistent oversight across cross-border operations will all remain high on the agenda. She also anticipates increased scrutiny around how banks use artificial intelligence, with regulators placing greater emphasis on ensuring AI is deployed responsibly and within appropriate governance frameworks.

“At Lidion, we will continue to take a proportional approach while considering the full range of requirements that come with our licence. Ultimately, by embedding strong governance, practical oversight, and a compliance-by-design mindset into everything we do, we are able to support a wide range of international clients responsibly and with confidence,” she concludes.

This interview forms part of the Companies to Watch in 2025, a business serialisation of BusinessNow.mt, Malta’s fastest-growing, cutting-edge business news portal, aimed at companies achieving their goals, marking important milestones, or planning to announce major business news.

Want to know more? Please drop us a line at info@BusinessNow.mt

Companies to Watch: How Veracloud is redefining IT excellence from Malta

November 26, 2025
by Sarah Muscat Azzopardi

Fresh from being crowned the 2025 Microsoft Malta Partner of the Year, Co-Founder John Ellul discusses the future.

Sabi and Kora bring two unique concepts to the DoubleTree by Hilton Malta

July 21, 2025
by Ramona Depares

From barefoot luxury to family fun, Director of Operations Sandro Deguara details the distinctive energy behind each venue

Companies to Watch: Arringo drives innovation in Malta’s fintech landscape

May 6, 2025
by BN Writer

Fast becoming a major player in fintech outsourcing, Arringo's growth reflects a commitment to innovation and a people-first culture.