Locating the Regulator and What It Controls
A fintech app adds a new insurance button overnight, an EV scooter company changes its battery design, and a food platform rewrites a seller policy. None of these are βjust business decisionsβ - somewhere, a regulator has defined what is allowed, what must be disclosed, and what can attract penalties.
- Do not ask only βWho is the regulator?β Ask βWhich activity is being regulated, and what does the regulator control?β
- A regulator may control entry, conduct, reporting, capital, pricing, safety, data, competition, or consumer protection.
- Map regulation by business activity, not by company name. One company can face multiple regulators.
- The clean answer structure is: sector - activity - regulator - control levers - business impact.
- In India, BFSI often involves RBI, SEBI, IRDAI, PFRDA and NPCI-linked payment rails; non-BFSI sectors may involve CCI, FSSAI, TRAI, BIS, sector ministries and consumer authorities.
- The strongest candidates explain whether regulation is a constraint, risk, cost, entry barrier, or strategic moat.
- The common mistake is naming RBI/SEBI/IRDAI and stopping there. Interviewers want the perimeter of control.
Big Picture: A Regulator Is Not a Label, It Is a Control System
Think of regulation as a control layer sitting between a business model and the public interest. The regulator is rarely interested in the company as a whole; it is interested in the specific activity that creates risk for customers, investors, public money, safety, data, markets, or competition.
Core Explanation: How to Locate the Regulator
The fastest way to locate the regulator is to move from the visible business to the regulated activity underneath it. A companyβs website may say βpaymentsβ, βloansβ, βinsuranceβ, βfoodβ, βtelecomβ, βgamingβ or βmobilityβ, but the regulator cares about the legal activity: accepting deposits, selling securities, underwriting insurance, processing personal data, certifying product safety, running a marketplace, or enabling digital payments.
Use this funnel when you are given any unfamiliar sector in an interview.
The Control Levers Regulators Commonly Use
Once you locate the regulator, explain what it actually controls. This is where average answers become sharp answers.
Entity Regulation vs Activity Regulation
A major interview trap is assuming one company equals one regulator. Modern companies bundle activities. A single app may offer payments, credit, insurance, wealth products, advertising, data processing and marketplace services. Each activity may trigger a different regulatory perimeter.
For example, a food-delivery company like Zomato can face different regulatory questions across food safety, consumer complaints, platform conduct, payments, data use, advertising claims and competition. The strategic point is not βwhich one regulator controls Zomato?β but βwhich regulator controls which part of the value chain?β
Definitions You Should Be Able to Say Clearly
- Regulator: A legally empowered public authority that sets, monitors and enforces rules for a sector, activity or market conduct.
- Regulatory perimeter: The boundary of activities, entities and risks over which a regulator has authority.
- Prudential regulation: Rules that protect financial stability by controlling capital, liquidity, solvency and risk-taking.
- Conduct regulation: Rules that protect customers or investors from unfair selling, poor disclosure, misuse and misconduct.
- Regulatory arbitrage: Structuring activity to fall under a lighter or unclear regulatory regime while performing a similar economic function.
How to Judge Regulatory Exposure: 6 Practical Measures
If the interviewer pushes you from concept to business impact, use measurable indicators. Many companies will not disclose all of these cleanly, so use them as a diagnostic checklist when reading an annual report or sector note.
Case Study: Ather Energy and the EV Regulation Map
Ather Energy shows why an EV company is not controlled by one βEV regulatorβ - its product, battery, charging, consumer promise and finance partnerships each touch different control points.

Situation: Ather Energy operates in Indiaβs electric two-wheeler market, where the customer sees a scooter, charger, app and service network. But underneath that simple experience sit multiple regulatory questions: vehicle safety, battery standards, charging infrastructure, consumer claims, warranties, data, financing partners and dealer operations.
The move: A strong regulatory map for Ather starts with the activity, not the company. Vehicle manufacturing and sale point toward transport approval and safety norms. Battery and charging choices point toward technical standards and product safety. Customer financing may involve regulated lending partners. Advertising range, warranty and service promises can attract consumer-protection scrutiny. If the company is listed or preparing for public-market activity, disclosure and governance expectations become another layer.
Outcome or lesson: Regulation is not only a compliance burden. In EVs, it shapes product architecture, supplier qualification, warranty design, dealer communication, customer trust and speed of launch. The primary driver of advantage is building compliance into product and operating design early; supporting drivers include supplier discipline, clear consumer communication, robust service processes and careful partner selection.
So what: In a sector interview, this case lets you say: βFor EVs, I would not search for one regulator. I would split the business into vehicle, battery, charging, consumer, data and financing activities, then map the authority and control lever for each.β That is a consulting-quality answer.
How AI Changes Locating the Regulator and What It Controls
First, AI speeds up regulatory scanning. Instead of manually checking ten regulator websites, teams now use AI-assisted search and document summarisation to track circulars, consultation papers, enforcement orders and sector updates. The risk is false confidence: AI may summarise a rule correctly but miss whether it applies to your exact activity.
Second, AI makes control mapping more granular. A company can feed policy documents, product notes and process SOPs into an LLM to identify which activities involve customer data, financial advice, product claims, safety risks or third-party outsourcing. This helps convert regulation from a legal memo into an operating checklist.
Third, AI itself is becoming a regulated activity. If a firm uses AI for credit scoring, hiring, fraud alerts, pricing, customer service or investment recommendations, the regulatory question shifts from βWhat product do we sell?β to βWhat decision does the model influence, and who can be harmed?β Bias, explainability, consent, audit trails and human oversight become part of the control map.
Use NotebookLM before an interview: upload the company annual report, one sector note, and relevant regulator pages; ask it to create a table with columns βbusiness activity, possible regulator, control lever, business risk, interview talking point.β Then verify every regulatory claim manually before using it.
Interview Relevance
βSuppose you are analysing a fintech, EV, telecom or food-delivery company. How will you identify the regulator, and how will regulation affect the business model?β
If the role is risk, compliance, finance or BFSI consulting, go one level deeper into filings and returns. For that, revise regulatory reporting standards in the banking sector after you understand the regulator map.
Use the sentence: βI would locate the regulator by activity, then separate what it controls - entry, conduct, prudence, disclosure, reporting and enforcement.β It sounds structured because it is structured.
Common Mistake
The mistake: Saying βRBI regulates banksβ or βSEBI regulates marketsβ and stopping there. Why it costs you: it proves you memorised names, but not business impact. One-line fix: always add the control lever - βRBI matters here because it controls licensing, prudential norms, supervision and reporting for the relevant banking or lending activity.β