Financial services organizations adopting agile face a specific tension: agile's assumptions about adaptive, iterative work sit in real friction with regulatory requirements for documentation, approval trails, and predictable, auditable process.

The genuine tension

Regulatory frameworks typically require detailed upfront documentation, clear approval trails, and predictable, traceable processes. Agile's core practices (evolving requirements, working software over comprehensive documentation, embracing change late in development) sit in direct tension with several of these, at least on the surface.

How this tension actually gets resolved, not avoided

Documentation shifts in timing and form, not in whether it exists. Decisions and their rationale get captured continuously as they're made, rather than pre-specified upfront, satisfying audit requirements while still supporting iterative development.

Compliance and risk expertise gets embedded directly in delivery teams, rather than treated as an external gate the output passes through afterward.

Change management processes get adapted, not eliminated. Formal, auditable change approval remains necessary, but gets redesigned to fit shorter cycles rather than assuming the traditional process transfers unchanged.

Risk-based prioritization replaces attempting comprehensive upfront risk assessment, allowing risk assessment to happen continuously as understanding develops.

What genuine organizational flexibility looks like here

Financial organizations that navigate this well don't eliminate regulatory rigor: they redesign how that rigor is achieved, integrating compliance into agile workflows rather than treating the two as fundamentally incompatible. The resulting flexibility is the same discipline, achieved through a more continuous process.