bcm

Same activity, same risks, same rules

The 'same activity, same risks, same rules' principle in EU digital finance regulation requires consistent regulation for identical activities regardless of technological implementation. This principle is central to MiCAR and DORA, ensuring risks are managed uniformly across the financial ecosystem.

Curated by Winners Consulting Services Co., Ltd.

Questions & Answers

What is Same activity, same risks, same rules?

The principle of 'same activity, same risks, same rules' is a cornerstone of the EU's digital finance regulatory framework, as seen in MiCAR and DORA. It dictates that regulated activities must be governed by consistent rules regardless of the underlying technology used. This aligns with ISO 31000's risk-based approach, ensuring that innovation does not create regulatory blind spots. For enterprises, this means that even as they adopt blockchain or AI-driven financial services, the regulatory scrutiny will be as stringent as traditional banking oversight. The principle aims to prevent regulatory arbitrage, where firms might seek less regulated technologies to bypass existing obligations. This requires a deep understanding of both the economic substance of the business and the specific risk-adjusted regulatory requirements, which can be complex for digital-first companies.

How is Same activity, same risks, same rules applied in enterprise risk management?

Implementation typically follows three phases: Functional Deconstruction, Risk Mapping, and Control Alignment. First, the enterprise must deconstruct its digital services into economic functions (e.g., asset custody,- lending, trading) rather than technical descriptions. Second, using the ISO 31000 risk management framework, the firm must map these functions against existing regulatory requirements to identify gaps. For example, a digital asset platform must be able to demonstrate that its risk-adjusted capital requirements and cybersecurity controls are equivalent to those of a traditional bank. Third, the firm must implement these controls—such as those required by DORA for operational resilience—before the regulatory deadline. Successful implementation typically results in a 30-50% reduction in compliance-related operational delays and significantly lowers the risk of regulatory sanctions from EU authorities.

What challenges do Taiwan enterprises face when implementing Same activity, same risks, same rules? How to overcome them?

Taiwan enterprises face three primary challenges: Regulatory Ambiguity, Technical Risk Assessment Gaps, and Resource Constraints. Many firms struggle with the 'substance-over-form' approach, as they are accustomed to more descriptive, technology-specific regulations in Taiwan. To overcome this, firms should adopt a 'substance-first' compliance culture, where risk-adjusted controls are prioritized over technical novelty. Second, the complexity of quantifying digital risks (e.g., smart contract vulnerabilities) requires specialized expertise; partnering with international consultants is highly recommended. Third, the cost of compliance can be significant. A phased approach—starting with a 90-day gap analysis, followed by a 6-month control implementation phase—allows for better resource management. Taiwan's unique position as a global tech hub means domestic firms must be closely closely aligned with EU standards to maintain international competitiveness and access to the European market.

Why choose Winners Consulting for Same activity, same risks, same rules?

Winners Consulting Services Co., Ltd. specializes in Same activity, same risks, same rules for Taiwan enterprises, delivering compliant management systems within 90 days. Free consultation: https://winners.com.tw/contact

Related Services

Need help with compliance implementation?

Request Free Assessment