← Back to alex-rodriguez.com
Perspective

Regulation is a moat, not a tax

Alex Rodriguez · Product & platform leader, regulated enterprise SaaS

Most people in tech treat regulation as a cost to be minimized. I understand why. It is slow, it is expensive, and it rarely shows up on a roadmap anyone is excited about. In the short term, it really is a tax.

But I have spent most of my career building in one of the most regulated corners of telecom, and over the long run I have come to believe the opposite. The compliance work everyone wants to do the bare minimum of is exactly the work that, done well and done early, becomes the thing competitors cannot easily copy. The specifics below are telecom, but the pattern is not. The cost is real, and so is the moat on the other side of it.

One example is a system we built to catch duplicate enrollments.

For years, the common approach was a straightforward match on personal information: same name, same date of birth, same address, flag it. We started there too. It was a reasonable baseline, and it met the requirements as most of the industry understood them at the time. But I did not think a simple match would hold up for long.

What made it hard is that the rules never actually defined a duplicate. That was left to interpretation, and the program was not getting much regulatory attention then. We had to thread a needle: do enough to get ahead of a problem we could see forming, without overreaching past what the rules said and denying service to eligible people.

So rather than wait for clarity that might never come, we started building toward it. We standardized addresses, limited enrollments at a single address, and required the name and date of birth to match a government ID exactly. We were investing in a problem the rules had not yet defined.

Then the standard arrived, through enforcement rather than guidance. Beginning in 2014, the industry faced significant penalties over duplicate enrollments, and almost overnight an ambiguous matter became one that could threaten a provider's standing in the program. We were ready, because we had already started, and we kept going. We built what we came to call the Duplicate Logic Engine, designed to catch the duplicates a simple match misses: a changed digit, a first and last name flipped into the wrong fields, a subscriber quietly enrolled under a slightly different version of themselves. I will not get into how it works. What matters is that the approach held up when enforcement came, and that it ended up stricter than the standard the industry was eventually held to.

The same instinct showed up in a quieter decision. When eligibility through a benefit-qualifying person, usually a dependent, entered the program, the national database did not initially screen those individuals for duplicates, which meant the same dependent could qualify more than one account. We chose not to support those enrollments at all until our own logic covered that gap, passing on revenue we could have booked rather than expose our customers to it. Sometimes the disciplined move is the one you decline.

That is the whole argument. Compliance looks like a tax, and most teams pay it grudgingly. We chose to overpay it early, before anyone made us, and occasionally to wait and forgo revenue until we could do it safely. That turned into something durable: a capability that was hard to match, that held up when the rules caught up, and that the rest of the market effectively had to follow.

Regulation slows you down. It also builds walls. The question is which side of the wall you want to be on when the rules change, because they always do.

← Back to alex-rodriguez.com Get in touch →
© 2026 Alex Rodriguez alex-rodriguez.com