August 2026
CONTENT
EUROPEAN UNION
COLLATERAL MANAGEMENT
ESAs publish Final Report on draft RTS amending bilateral margin requirements for uncleared OTC derivatives
![]()
BACKGROUND
On 3 August 2026, the European Supervisory Authorities (ESAs) published a Final Report containing draft regulatory technical standards (RTS) amending Commission Delegated Regulation (EU) 2016/2251 regarding initial margin requirements for non-centrally cleared OTC derivatives. The Delegated Regulation supplements EMIR by specifying risk-management procedures for the exchange of collateral, including collateral levels, eligible collateral and segregation arrangements. The amendments concern counterparties whose aggregate month-end average notional amount (AANA) of non-centrally cleared OTC derivatives falls below EUR 8 billion.
WHAT'S NEW?
Extension of the initial margin derogation
The draft RTS extend the existing initial margin derogation to outstanding contracts. Currently, where one counterparty falls below the EUR 8 billion threshold, the derogation applies only to new OTC derivative contracts entered into during the relevant calendar year.
Where either counterparty has an AANA below EUR 8 billion for March, April and May of a given year, initial margins would no longer be collected for non-centrally cleared OTC derivative contracts between them. Initial margins already collected for outstanding contracts would also be released.
Application timeline and AANA calculation
Counterparties could apply the exemption from 1 June of the relevant year. They could nevertheless continue collecting initial margins or implement the exemption at a later date.
Where both counterparties exceed the threshold, initial margin requirements would apply to new contracts no later than 1 January of the following year. The AANA would continue to be calculated at counterparty level or, where the counterparty belongs to a group, at group level.
Treatment of equity options
The draft RTS also remove outdated transitional provisions concerning single-stock options and equity-index options. These instruments remain exempt from margin requirements under Article 11(3a) EMIR.
WHAT'S NEXT?
The ESAs have submitted the draft RTS to the European Commission for endorsement as a Delegated Regulation. Following endorsement, the text will be subject to non-objection by the European Parliament and the Council before publication in the Official Journal. The Regulation will enter into force 20 days after its publication and will be directly applicable in all EU Member States.
EU publishes Delegated Regulation (EU) 2026/1000 specifying EBA fees for the validation of EMIR pro forma models
![]()
BACKGROUND
On 17 August 2026, the European Commission published Commission Delegated Regulation (EU) 2026/1000, adopted on 5 May 2026, specifying the methodology and payment arrangements for fees charged by the European Banking Authority (EBA) for validating pro forma initial-margin models under EMIR. The validation requirement was introduced by Regulation (EU) 2024/2987 (EMIR 3). The Regulation applies to counterparties using, or applying to use, pro forma models for non-centrally cleared OTC derivatives that are subject to EBA validation.
WHAT'S NEW?
Principles for determining annual fees
Annual fees must be based on full cost recovery and the counterparties’ average notional amount. The EBA must consider the direct and indirect costs associated with model validation, supporting statistical and IT tools, fee calculation and collection, and other validation-related activities.
Calculation of the average notional amount
Counterparties must calculate their average notional amount by averaging the monthly notional amounts of derivatives using the relevant model over the applicable reference period. The equivalent portfolio notional method applies by default, although alternative methods may be used where the counterparty can justify its choice to the competent authority.
Counterparties with a 12-month average notional amount below EUR 3,000 billion may use specified regulatory-threshold estimates, provided they can demonstrate that their actual notional amount is lower than the selected amount.
Fee methodologies
The Regulation establishes separate fee methodologies for:
- models validated as of 1 January of a given year;
- models already used before 24 December 2024; and
- new models not used before that date, for which up to EUR 500,000 may be allocated among the relevant counterparties.
Information requirements
Counterparties must provide the EBA annually with the average notional amount and other information required to calculate and invoice the applicable fees.
WHAT'S NEXT?
The Regulation enters into force on 6 September 2026 and is directly applicable in all Member States. Following the EBA readiness date, counterparties must generally submit fee-calculation information by 31 March each year. The EBA must issue invoices for the readiness year by 31 October. Fees are payable in euro within 45 calendar days of registration of the amount receivable in the EBA’s accounts.
MARKET RISK
EBA publishes no-action letter and technical considerations on the implementation of the market risk framework for EU banks
![]()
On 3 August 2026, the European Banking Authority (EBA) published a No Action Letter on the boundary between trading book and banking book, and on the internal risk transfer between books and accompanying EBA considerations on the application of the FRTB from 1 January 2027, which support the implementation of the revised market risk framework under the Fundamental Review of the Trading Book (FRTB).
The publications address implementation issues arising from the European Commission's third Delegated Act on FRTB, adopted on 4 June 2026 and currently under scrutiny by the European Parliament and Council. The Delegated Act modifies the calculation of own funds requirements for market risk from 1 January 2027 until 31 December 2029 and introduces targeted operational relief measures and multipliers intended to preserve an international level playing field.
In the no-action letter, the EBA recommends that competent authorities do not prioritise supervisory or enforcement action regarding the FRTB boundary framework, including provisions governing the allocation of instruments between the banking book and trading book, internal risk transfers, and related reporting requirements. The recommendation would apply until 31 December 2029 or until legislative amendments providing legal certainty become effective.
The EBA notes that institutions applying the multiplier introduced by the Delegated Act would otherwise face operational complexity from maintaining parallel boundary frameworks. To ensure a level playing field, the EBA considers that both multiplier and non-multiplier institutions should be allowed to continue using the pre-FRTB ("CRR2") boundary framework for market risk calculations during the transitional period.
The technical considerations document provides clarification on eligibility and notification requirements for institutions wishing to apply the overall multiplier, treatment of market risk calculations under the output floor, structural foreign exchange positions, disclosure obligations, supervisory reporting expectations, and implications for supervisory benchmarking exercises. Institutions eligible for the multiplier must assess eligibility based on the 31 March 2027 reference date and notify competent authorities accordingly.
The measures become relevant only if and when the Commission Delegated Act enters into force. The EBA also indicates that further regulatory clarifications and amendments to reporting requirements may follow.
OTHER - PRUDENTIAL REQUIREMENTS
ECB publishes article on timely remediation for more resilient banks
![]()
On 12 August 2026, the European Central Bank (ECB) published “Timely remediation for more resilient banks”, which outlines enhancements to the ECB Banking Supervision approach for managing supervisory findings and remediation measures, with the objective of making supervision more risk-based, efficient and proportionate while maintaining banking sector resilience.
The publication explains the ECB’s revised approach to the lifecycle of supervisory findings and measures. Supervisors identify prudential weaknesses, communicate expectations and measures to banks, and monitor remediation. Banks remain responsible for addressing findings in a timely manner, while supervisors may escalate unresolved issues through binding requirements or enforcement measures where necessary.
The ECB highlights the implementation in 2025 of a tiered approach for findings and measures. For low-severity findings, banks may close measures once actions have been taken, without additional supervisory scrutiny, and are no longer required to provide supporting documentation. The ECB states that this has enabled both banks and supervisors to focus resources on the most material risks.
The ECB plans to launch a refocusing exercise in October 2026 to review the stock of open findings and measures. The review will assess measures based on severity, age, prudential relevance, remediation status and the likelihood of requiring further supervisory intervention. The exercise may result in the discontinuation or simplification of follow-up for findings with limited prudential relevance and increased focus on issues with the greatest prudential impact. Additional simplifications will include reduced requirements for low-severity internal model findings and a more selective creation of low-severity measures.
The ECB will monitor the effects of the refocusing exercise and provide further updates to both the industry and individual banks in the coming months.
EU publishes ECB Decision on the processing of personal data in the prudential supervision of credit institutions
![]()
On 14 August 2026, the Official Journal of the European Union published European Central Bank Decision (EU) 2026/1942 (ECB/2026/18) on the processing of personal data in the context of the prudential supervision of credit institutions. The Decision establishes how responsibilities are allocated between the ECB and national competent authorities (NCAs) when they process personal data in the exercise of supervisory tasks within the Single Supervisory Mechanism (SSM).
The Decision establishes the framework under which the ECB and NCAs act as joint controllers for personal data processing carried out in supervisory activities, including fit and proper assessments, authorisation procedures, ongoing supervision, enforcement and sanctions, on-site inspections, oversight of less significant institutions, and supervision of less significant institutions.
The Decision allocates responsibilities for providing information to data subjects, handling data subject requests, managing personal data breaches, conducting data protection impact assessments, maintaining records of processing, and ensuring compliance with Regulation (EU) 2018/1725 and Regulation (EU) 2016/679 (GDPR).
The annexes define, for each supervisory activity, the purposes of processing, legal basis, categories of data subjects, and categories of personal data that may be processed. The Decision also establishes cooperation arrangements between joint controllers and mechanisms for resolving disputes relating to liability and compensation.
The Decision takes effect on the day of its notification to the addressees, namely the national competent authorities of participating Member States, and the ECB Governing Council will review the arrangements no later than five years after the Decision takes effect.
PRIMARY MARKET
EU publishes Delegated Regulation (EU) 2026/1061 amending prospectus format, content, scrutiny and approval requirements
![]()
On 13 August 2026, the European Commission published Regulation (EU) 2026/1061, which amends Delegated Regulation (EU) 2019/980 regarding the standardised format and sequence, streamlined content, scrutiny and approval of prospectuses.
The Regulation applies to prospectuses published under Regulation (EU) 2017/1129 for securities offered to the public or admitted to trading on a regulated market in the European Union. It amends disclosure, format, approval and scrutiny requirements for equity and non-equity prospectuses and is directly applicable in all Member States.
The Regulation streamlines prospectus requirements by reducing the number of disclosure schedules and introducing a single registration document and a single securities note for non-equity securities, replacing separate retail and wholesale frameworks. It also introduces standardised prospectus formats for equity and non-equity securities and creates a new category of EU IPO prospectus for first-time admissions of shares to trading on a regulated market.
The Regulation establishes additional disclosure requirements for non-equity securities advertised as taking into account ESG factors or pursuing ESG objectives through a dedicated new Annex 23. It also enables competent authorities, in consultation with issuers, offerors or persons seeking admission to trading, to determine appropriate disclosure requirements for securities, issuers or transactions not covered by existing annexes.
The Regulation further introduces new timelines for prospectus approval procedures. Competent authorities may impose deadlines for revised submissions and must generally decide whether to approve a prospectus within 90 working days of the initial application, or 100 working days for SMEs, subject to limited extensions.
The Regulation enters into force on the third day following its publication in the Official Journal of the European Union.
REPORTING
ESMA publishes Public Statement on Transitional Provisions under the BMR Review
![]()
On 10 August 2026, the European Securities and Markets Authority (ESMA) published the Public Statement on Transitional Provisions under the BMR Review, which outlines the transitional arrangements applicable under the revised Benchmark Regulation (BMR), including the treatment of pending third-country benchmark administrator applications and upcoming changes to the ESMA benchmark register.
Benchmarks provided by third-country administrators that submitted an application for recognition or endorsement to ESMA by 31 December 2025 may continue to be used in the EU until ESMA reaches a decision on the application. The statement includes a list of applications for which ESMA's decision remains pending as of the publication date.
Administrators already authorised, registered, recognised or endorsing under the BMR will retain their status until 30 September 2026 and are not required to re-apply if they fall within the scope of the revised BMR by that date. Benchmarks that fall outside the scope of the revised BMR but were provided by administrators authorised, registered, recognised or endorsing before 1 January 2026 may continue to be used in the Union after 30 September 2026.
The statement clarifies which benchmarks remain within the scope of the revised BMR, including critical benchmarks, significant benchmarks, opted-in benchmarks, and certain EU climate, Paris-aligned, climate transition or commodity benchmarks meeting specified thresholds. ESMA also publishes a list of administrators expected to be removed from the register as of 1 October 2026 unless specified conditions are met.
The next key milestone identified in the statement is 30 September 2026, by which competent authorities or ESMA may designate benchmarks as significant and after which relevant register changes will take effect.
ESMA publishes weekly position data reporting instructions for commodity derivatives reporting under MiFID II
![]()
On 14 August 2026, ESMA published updated technical instructions for weekly position reporting in commodity derivatives and emission allowance derivatives under Article 58 of MiFID II, setting out the operational, reporting and data validation requirements applicable to reporting entities.
The new reporting framework becomes operational on 3 September 2026, from which date relevant market participants must submit weekly position reports using XML Schema v2.0 and the associated validation rules.
The instructions apply to market operators and investment firms operating trading venues where commodity derivatives and emission allowance derivatives are traded. Reports must be submitted on a weekly basis covering the Monday-Friday period, reflecting positions at the close of trading on Friday. Submission is made through the HUBEX system using the standardised ISO 20022 XML format.
Trading venues are required to submit reports where at least 20 position holders are present and, for physically settled commodity derivatives, where the additional open interest threshold is met. The reporting dataset includes venue identification, report and publication dates, derivative identifiers, report status, position metrics, open interest percentages and participant-category data. ESMA will perform both technical and business validation checks and will generate feedback files indicating acceptance or reporting errors requiring correction.
The next step is the implementation of XML Schema v2.0 and alignment of reporting processes with the technical requirements before the go-live date of 3 September 2026.
BELGIUM
ANTI-MONEY LAUNDERING / COMBATING TERRORISM FINANCING / COMBATTING PROLIFERATION FINANCING (AML/CFT/CPF)
NBB publishes AML/CFT enforcement decision against Wise Europe S.A.
![]()
On 25 August 2026, the National Bank of Belgium (NBB) published a decision concerning Wise Europe S.A. under Belgium’s Anti-Money Laundering and Counter-Terrorist Financing (AML/CFT) framework.
The decision follows an assessment conducted by the NBB in its capacity as the authority responsible for supervising compliance with the Law of 18 September 2017 on the prevention of money laundering and terrorist financing and the limitation of the use of cash.
During its review, the NBB identified serious deficiencies in Wise Europe’s AML/CFT control framework. The shortcomings related to several core compliance obligations, including the sharing of AML-related information within a financial group, customer and beneficial owner identification and verification procedures, ongoing monitoring of business relationships and occasional transactions, and the analysis of atypical or unusual transactions. According to the NBB, these weaknesses constituted breaches of multiple provisions of the Belgian AML law.
While acknowledging that Wise Europe had already implemented corrective actions and additional risk mitigation measures, the NBB concluded that further remediation was necessary to achieve full compliance with the applicable legal requirements. Consequently, the regulator exercised its supervisory powers and formally instructed Wise Europe to implement all measures required to ensure complete compliance with the relevant AML/CFT provisions. The company has been given until 31 January 2027 to address the identified deficiencies and bring its framework fully into line with regulatory expectations.
The publication serves as a reminder of the supervisory focus placed on robust AML/CFT governance, customer due diligence, beneficial ownership verification, transaction monitoring, and group-wide information-sharing mechanisms. It also illustrates the NBB’s willingness to take formal supervisory action where financial institutions’ controls are considered insufficient, even where remediation efforts are already underway.
FINANCIAL EDUCATION & INCLUSION
Chambre des représentants de Belgique publishes draft law to strengthen access to banking services and address financial exclusion
![]()
On 20 August 2026, Chambre des représentants de Belgique published a legislative proposal to amend the Code of Economic Law and Belgium’s anti-money laundering framework with the objective of combating financial exclusion and improving access to banking services.
The proposal responds to concerns that individuals, businesses, non-profit organisations, diplomatic missions and other entities continue to face refusals to open bank accounts or the closure of existing accounts without sufficient explanation, often as a result of de-risking practices linked to AML/CFT compliance requirements.
The proposal would introduce new obligations for banks, payment institutions and electronic money institutions when refusing to provide payment account services or terminating existing banking relationships. Financial institutions would be required to base such decisions on individual, objective, non-discriminatory and proportionate grounds and to retain a written justification for a specified period. A designated authority, expected to be the Belgian Federal Public Service Economy, would be empowered to review complaints from affected customers and assess whether a refusal or account closure is adequately justified. Where the authority concludes that the rationale is insufficient, it could require the institution to provide or maintain the banking service.
The proposal also seeks to enhance awareness of Belgium’s basic banking service regime by requiring institutions to provide more proactive information and support to eligible consumers, particularly vulnerable and unbanked individuals. In addition, amendments to the AML/CFT legislation would allow relevant information to be shared with the reviewing authority while maintaining safeguards around confidential anti-money laundering information. The draft ljppaw would apply to consumers, Belgian nationals living abroad, businesses, non-profit organisations, diplomatic missions and associations of co-owners.
If adopted, the new framework would enter into force six months after publication in the Belgian Official Gazette.
OTHER - PRUDENTIAL REQUIREMENTS
Moniteur Belge publishes law implementing CRD VI, ESAP and related financial sector reforms
![]()
On 7 August 2026, the Moniteur Belge published a law transposing several EU financial services measures into Belgian legislation, including provisions related to CRD VI, the European Single Access Point (ESAP), the treatment of concentration risk arising from exposures to central counterparties, and various supervisory, governance and ESG-related requirements applicable across the Belgian financial sector.
The law amends a broad range of sectoral legislation governing credit institutions, investment firms, UCITS, AIFMs, payment institutions, electronic money institutions, insurance undertakings and crypto-asset service providers. It also implements elements of the ESAP framework by establishing mechanisms for transmitting regulatory disclosures and supervisory information to the European Single Access Point.
The law introduces extensive amendments to the Belgian Banking Act to incorporate CRD VI requirements, including enhanced supervisory powers, updated governance and fit-and-proper requirements, new rules concerning significant acquisitions, mergers, transfers of assets and liabilities, and strengthened oversight of third-country branches. It also introduces new obligations related to ESG risk management, requiring credit institutions to integrate environmental, social and governance risks into governance arrangements, risk management frameworks and supervisory planning processes. Additional provisions address supervisory cooperation, AML/CFT-related assessments, concentration risks towards central counterparties and reporting obligations.
The law further implements the ESAP framework across multiple financial-sector regimes by requiring information such as fund disclosures, regulatory reports, sanctions, approvals and other regulated disclosures to be transmitted through designated Belgian authorities for publication on ESAP. Amendments also affect UCITS management companies, AIFMs, investment firms, pension institutions, insurers and certain crypto-asset related provisions.
The law enters into force on 17 August 2026, unless otherwise specified for particular provisions. As a final legislative act, the measures are now part of the Belgian regulatory framework and apply in accordance with the implementation timelines set out in the law.
BRAZIL
OTHER - FINANCIAL CRIME
BCB publishes resolution strengthening fraud prevention requirements for payment and virtual asset service providers
![]()
On 7 August 2026, the Central Bank of Brazil (BCB) published Resolution No. 584, amending BCB Resolution No. 142/2021 to expand fraud prevention requirements beyond payment services to include virtual asset services.
The revised framework applies to financial institutions, payment institutions, and virtual asset service providers (VASPs), including firms operating during the regulatory adaptation phase. The regulation strengthens fraud risk management requirements in both the payments and digital assets sectors and reflects the growing supervisory focus on crypto-related financial crime risks.
A key change is the introduction of a mandatory 24-hour retention period for certain virtual asset transfers. Institutions must delay transfers of virtual assets when transactions exceed the equivalent of USD 10,000 or where internal risk assessments identify heightened fraud concerns. The requirement applies to transfers directed to foreign virtual asset entities and self-custody wallets, giving institutions additional time to perform fraud and risk analysis before assets leave the platform. The resolution explicitly confirms that the measure also applies to stablecoins. Institutions remain responsible for documenting decisions, maintaining records and ensuring that risk-management frameworks incorporate criteria linked to customer, transaction, counterparty and jurisdictional risk profiles.
The amendments also reinforce governance and reporting expectations. Covered institutions are required to maintain detailed daily records of fraud incidents and attempted fraud involving payment services and virtual asset services, including corrective actions taken. The BCB is granted enhanced supervisory powers, including the ability to require longer retention periods, impose the controls on lower-value transactions, or restrict an institution’s discretion to release transfers early where deficiencies are identified. These measures complement existing obligations related to anti-money laundering, counter-terrorist financing and other financial crime controls.
The resolution will enter into force on 1 January 2027 and represents a significant strengthening of Brazil’s regulatory framework for payment services and digital assets. The reforms are particularly relevant for payment service providers, banks engaged in payment activities, and crypto service providers, as they will require updates to fraud prevention frameworks, transaction monitoring processes and operational controls. The publication also signals increasing regulatory convergence between payment security, fraud prevention and digital asset oversight as the Brazilian authorities seek to mitigate risks associated with cross-border crypto transactions and self-custody arrangements.
PAYMENTS
BCB introduces Resolution No. 585 on IBAN standard for international fund transfers in Brazil
![]()
On 24 August 2026, the Central Bank of Brazil (BCB) published Resolution No. 585, establishing the International Bank Account Number (IBAN) as the standard format for identifying bank accounts held in Brazil for the purpose of international fund transfers.
The measure aims to align Brazil's account identification framework with the internationally recognized ISO 13616 standard, facilitating the processing and automation of cross-border payments.
Under the new framework, Brazilian IBANs will consist of 29 characters, including the country code, check digits, the participant identifier used in the Brazilian Payment System, branch and account identifiers, account type information, and an identifier for the account holder. The resolution also sets out technical requirements for validation and presentation, including the use of uppercase characters and grouping characters into blocks of four to improve readability and electronic processing.
The resolution imposes obligations on financial institutions and other entities authorised by the BCB. Institutions must provide customers with their account identification in IBAN format upon request and must accept international transfers that use the IBAN format, while performing the necessary validations within their area of responsibility. The measure is intended to improve interoperability between the Brazilian financial system and international payment infrastructures, supporting more efficient cross-border transactions.
The resolution also revokes Circular No. 3,625 of 14 February 2013 and entered into force on the date of its publication, 24 August 2026.
BCB publishes Normative Instruction No. 769 on version 2.10.0 of the Pix Initiation Standards Manual
![]()
On 19 August 2026, BCB published Normative Instruction No. 769, which releases version 2.10.0 of the Manual of Standards for Pix Initiation, an integral component of Brazil's Pix Regulation.
The instruction revokes BCB Normative Instruction No. 658/2025 and brings the updated technical and operational standards into force on the date of publication.
The revised manual introduces updates to the framework governing Pix payment initiation services and reflects ongoing developments in the Pix ecosystem. Key changes include the addition of the initiation method "AUTO" within the mandatory information requirements for payment initiation services, adjustments relating to the identification of the payer's municipality in dynamic QR Code transactions with due dates, and amendments concerning recurring payment functionalities (Pix Automático). The update also incorporates new information requirements for the termination of recurring payment arrangements and recurring payment requests.
The manual forms part of the contractual and operational framework underpinning Pix and provides detailed standards for payment initiation, QR code-based transactions, recurring payments, and the technical interfaces supporting these services. The amendments are intended to maintain consistency across the Pix ecosystem and support the continued development of payment initiation and recurring payment functionalities.
The instruction applies to participants subject to the Pix regulatory framework and requires the use of the updated version 2.10.0 standards. BCB noted that amendments to Pix manuals and related documents are not considered regulatory acts requiring a regulatory impact assessment, as the Pix Regulation and its supporting documents are regarded as contractual rather than coercive regulatory instruments.
The updated standards entered into force on 19 August 2026.
REPORTING & DISCLOSURES
CVM publishes clarifications on sustainability-related financial reporting requirements under resolutions 244/2026 and 193/2023
![]()
On 27 August 2026, CVM published Ofício-Circular nº 2/2026/CVM/SNC/SEP, providing clarifications on the application of Resolução CVM nº 244/2026, which amended Resolução CVM nº 193/2023 regarding the disclosure of sustainability-related financial information reports prepared in accordance with the CBPS/ISSB sustainability disclosure standards.
The circular clarifies the scope of the sustainability reporting framework and confirms that only reports prepared in full compliance with the CBPS/ISSB standards may be presented as sustainability-related financial information reports under Resolution 193/2023. The CVM explains that reports prepared under other frameworks, such as GRI, fall outside this regime unless they are presented in a way that suggests compliance with CBPS/ISSB standards. The regulator further states that references such as “based on”, “aligned with”, “inspired by”, or similar wording may trigger the application of the requirements where they imply adherence to the CBPS/ISSB framework.
The publication also addresses the treatment of voluntary disclosures made under the previous version of Resolution 193/2023. CVM clarifies that companies that voluntarily adhered to the former regime before the adoption of Resolution 244/2026 are not required to continue reporting in subsequent years. In addition, reporting deadlines applicable to voluntary disclosures for financial years beginning on or after 1 January 2025 remain unchanged, including the deadline of 30 September 2026 for entities whose financial year ended on 31 December 2025.
Finally, the circular provides guidance on the use of transition reliefs and explains that, from 1 January 2027, listed companies choosing not to file a sustainability-related financial information report must disclose a market communication explaining the reasons for that decision. The justification should be clear, specific, and sufficiently detailed to enable investors and other stakeholders to understand the basis for management’s decision.
COLOMBIA
CUSTODY
URF publishes Decree No. 1013 amending Decree 2555 of 2010 on market infrastructure and securities market competitiveness
![]()
On 6 August 2026, the Ministerio de Hacienda y Crédito Público de Colombia published Decreto No. 1013, which modifies multiple provisions of Decree 2555 of 2010 to strengthen securities market infrastructure, improve market competitiveness, enhance transparency, facilitate liquidity, and update rules applicable to various market participants and infrastructures.
Key Requirements:
- The decree introduces a framework for the registration of OTC transactions involving listed shares and mandatory convertible bonds into shares, requiring registration and establishing conditions for compensation and settlement.
- It establishes rules for special off-exchange sales of equity securities, including disclosure obligations, transparency requirements, payment mechanisms, and publication of transaction results.
- The decree updates the regime applicable to agricultural commodity exchanges, including governance, membership, affiliates, self-regulation, disclosure, risk management, business continuity, and operational requirements.
It enables interoperability agreements between central counterparties (CCPs), setting minimum requirements on governance, risk management, guarantees, crisis management, supervision cooperation, and business continuity.
Additional amendments cover derivatives and structured products traded through voice and hybrid systems, OTC repo, securities lending and temporary transfer transactions, margin accounts, admissible collateral, dividend payment periods, and reporting obligations.
The decree also authorizes Colombian collective investment fund managers and private equity fund managers to provide management-related services to foreign investment vehicles, subject to notification obligations to the Superintendencia Financiera de Colombia.
The decree enters into force on the day following its publication and amends and adds numerous provisions of Decree 2555 of 2010.
The next step is the implementation of the amended and newly introduced provisions upon the decree’s entry into force.
FRANCE
DATA PROTECTION FRAMEWORK
CNIL publishes guidance on identifying and managing conflicts of interest affecting DPOs / La CNIL publie des recommandations sur l'identification et la gestion des conflits d'intérêts concernant les délégués à la protection des données
![]()
On 10 August 2026, the CNIL published “Data Protection Officer: identify and manage conflicts of interest related to the DPO function”, providing practical guidance on how organisations can identify and manage potential conflicts of interest affecting their DPOs.
Key Takeaways:
- CNIL recalls that a DPO may perform other functions within the organisation in addition to those set out in Article 39 of the GDPR, provided that these additional tasks do not interfere with the performance of the DPO’s duties or place the DPO in a conflict of interest. A conflict of interest may arise where the DPO’s other functions undermine their independence or give them decision-making powers over the purposes and/or means of processing that they are responsible for overseeing. In other words, the DPO must not be in a position to act as both “judge and party”. CNIL recommends that potential conflicts of interest be assessed on a case-by-case basis, preferably before appointing a DPO or assigning them new functions.
- To help identify potential conflicts, CNIL provides a series of questions covering internal, outsourced and shared DPO arrangements. For internal DPOs, it highlights risks where the DPO holds management functions (e.g. senior management or HR), has decision-making powers over the purposes and/or means of processing (e.g. certain CISO roles), participates in ethics or professional conduct bodies, or holds employee representative or trade union mandates involving decisions on data protection-related matters. For outsourced DPOs, CNIL highlights potential conflicts where the DPO (e.g. a lawyer) has represented the organisation in data protection-related litigation, or is employed by an entity whose interests may conflict with those of the appointing organisation, such as a processor, joint controller, or source or recipient of processed data. Similar considerations apply to DPOs shared between several organisations.
- Where a conflict of interest is identified, CNIL indicates that it must be brought to an end, for example by replacing the DPO, withdrawing the conflicting functions, or implementing other effective remedial measures. One possible measure is the DPO’s recusal from the conflicted scope, with a deputy DPO effectively performing the DPO functions for that scope. The deputy DPO must benefit from the safeguards provided under Articles 37 to 39 of the GDPR, including adequate resources, involvement in relevant data protection matters and independence from the conflicted DPO. For external DPOs that are legal entities and are appointed by both a controller and its processor, CNIL also indicates that the functions may be allocated to separate employees within the same firm, subject to appropriate safeguards.
The guidance provides further clarity on the circumstances that may give rise to conflicts of interest and the safeguards available to preserve the DPO’s independence.
Version française
Le 10 août 2026, la CNIL a publié un document intitulé « Délégué à la protection des données : identifier et gérer les conflits d’intérêts liés à la fonction de DPD », qui fournit des conseils pratiques sur la manière dont les organisations peuvent identifier et gérer les conflits d’intérêts potentiels affectant leurs DPD.
Points clés :
- La CNIL rappelle qu’un DPD peut exercer d’autres fonctions au sein de l’organisation en plus de celles prévues à l’article 39 du RGPD, à condition que ces missions supplémentaires n’entravent pas l’exercice de ses fonctions ni ne le placent en situation de conflit d’intérêts. Un conflit d’intérêts peut survenir lorsque les autres fonctions du DPD compromettent son indépendance ou lui confèrent des pouvoirs de décision sur les finalités et/ou les moyens du traitement qu’il est chargé de superviser. En d’autres termes, le DPD ne doit pas être en mesure d’agir à la fois en tant que « juge et partie ». La CNIL recommande d’évaluer les conflits d’intérêts potentiels au cas par cas, de préférence avant de nommer un DPD ou de lui attribuer de nouvelles fonctions.
- Afin de faciliter l’identification des conflits potentiels, la CNIL propose une série de questions portant sur les modalités de mise en place du DPD, qu’il soit interne, externalisé ou partagé. Pour les DPD internes, elle met en évidence les risques lorsque le DPD exerce des fonctions de direction (par exemple, cadre supérieur ou responsable des ressources humaines), dispose de pouvoirs de décision sur les finalités et/ou les moyens du traitement (par exemple, certains rôles de RSSI), participe à des instances chargées de l’éthique ou de la déontologie, ou exerce des mandats de représentation du personnel ou syndicaux impliquant des décisions sur des questions liées à la protection des données. Pour les DPD externalisés, la CNIL met en évidence des conflits potentiels lorsque le DPD (par exemple un avocat) a représenté l’organisation dans un litige lié à la protection des données, ou est employé par une entité dont les intérêts peuvent entrer en conflit avec ceux de l’organisation qui l’a désigné, telle qu’un sous-traitant, un responsable conjoint du traitement, ou une source ou un destinataire des données traitées. Des considérations similaires s’appliquent aux DPD partagés entre plusieurs organisations.
- Lorsqu’un conflit d’intérêts est identifié, la CNIL indique qu’il doit être résolu, par exemple en remplaçant le DPD, en supprimant les fonctions source de conflit ou en mettant en œuvre d’autres mesures correctives efficaces. Une mesure possible consiste à écarter le DPD du domaine concerné par le conflit, un DPD adjoint assumant alors effectivement les fonctions de DPD pour ce domaine. Le DPO adjoint doit bénéficier des garanties prévues aux articles 37 à 39 du RGPD, notamment des ressources adéquates, une implication dans les questions pertinentes relatives à la protection des données et une indépendance vis-à-vis du DPO en situation de conflit. Pour les DPO externes qui sont des personnes morales et qui sont désignés à la fois par un responsable du traitement et par son sous-traitant, la CNIL indique également que les fonctions peuvent être attribuées à des salariés distincts au sein du même cabinet, sous réserve de garanties appropriées.
Ces lignes directrices apportent des précisions supplémentaires sur les circonstances susceptibles de donner lieu à des conflits d’intérêts et sur les garanties disponibles pour préserver l’indépendance du DPD.
GOVERNANCE & ORGANISATION
AMF updates Recommendation DOC-2012-02 on corporate governance and executive remuneration / L'AMF met à jour la recommandation DOC-2012-02 relative au gouvernement d'entreprise et à la rémunération des dirigeants
![]()
On 4 August 2026, the Autorité des marchés financiers (AMF) published an updated and restructured version of Recommendation DOC-2012-02 on corporate governance and executive remuneration of listed companies referring to the AFEP-MEDEF Code. Applicable from 4 August 2026, the revised Recommendation consolidates the AMF’s current doctrine while removing provisions already incorporated into the AFEP-MEDEF Code or the HCGE implementation guide.
The Recommendation primarily applies to French listed companies referring to the AFEP-MEDEF Code and covers corporate governance arrangements, board composition and independence, succession planning, conflicts of interest, executive remuneration and related disclosures.
Key Takeaways:
The updated Recommendation incorporates developments from the AMF’s 2024 and 2025 corporate governance reports, including strengthened expectations regarding:
- Director independence, including the assessment of significant business relationships and long-serving directors;
- Executive succession planning, with increased transparency regarding the existence, review and governance of succession plans;
- Non-executive chair remuneration, with the AMF recommending that a chair without management powers should not receive variable remuneration unless specifically justified by particular duties;
- Executive departures and remuneration, including clearer expectations regarding termination payments and disclosure of related financial arrangements;
- Honorary chairpersons, including transparency regarding their role and appointment, as well as safeguards concerning conflicts of interest and market abuse.
- The AMF has also removed 45 elements of doctrine already reflected in the AFEP-MEDEF Code or the HCGE implementation guide. The AMF clarifies that this does not lower existing expectations, as these provisions continue to apply to companies referring to these standards under the “comply or explain” principle.
The revised Recommendation therefore streamlines and updates the AMF’s doctrine while maintaining its expectations regarding corporate governance and executive remuneration practices.
Version française
Le 4 août 2026, l’Autorité des marchés financiers (AMF) a publié une version actualisée et remaniée de la Recommandation DOC-2012-02 relative au gouvernement d’entreprise et à la rémunération des dirigeants des sociétés cotées, qui fait référence au Code AFEP-MEDEF. Applicable à compter du 4 août 2026, la recommandation révisée consolide la doctrine actuelle de l’AMF tout en supprimant les dispositions déjà intégrées au Code AFEP-MEDEF ou au guide de mise en œuvre du HCGE.
La recommandation s’applique principalement aux sociétés cotées françaises se référant au Code AFEP-MEDEF et porte sur les dispositifs de gouvernance d’entreprise, la composition et l’indépendance du conseil d’administration, la planification de la succession, les conflits d’intérêts, la rémunération des dirigeants et les obligations d’information y afférentes.
Points clés :
La recommandation mise à jour intègre les évolutions issues des rapports de l’AMF sur le gouvernement d’entreprise de 2024 et 2025, notamment des attentes renforcées concernant :
- l’indépendance des administrateurs, y compris l’évaluation des relations d’affaires significatives et des administrateurs de longue date ;
- la planification de la succession des dirigeants, avec une transparence accrue quant à l’existence, à la révision et à la gouvernance des plans de succession ;
- la rémunération des présidents non exécutifs, l’AMF recommandant qu’un président dépourvu de pouvoirs de direction ne perçoive pas de rémunération variable, sauf si cela est spécifiquement justifié par des missions particulières ;
- les départs des dirigeants et leur rémunération, y compris des attentes plus claires concernant les indemnités de départ et la publication des dispositions financières associées ;
- les présidents d’honneur, notamment la transparence concernant leur rôle et leur nomination, ainsi que les garanties relatives aux conflits d’intérêts et aux abus de marché.
- L’AMF a également supprimé 45 éléments de doctrine déjà repris dans le Code AFEP-MEDEF ou dans le guide de mise en œuvre du HCGE. L’AMF précise que cela n’affaiblit pas les attentes existantes, car ces dispositions continuent de s’appliquer aux entreprises se référant à ces normes en vertu du principe « se conformer ou s’expliquer ».
La recommandation révisée rationalise et actualise donc la doctrine de l’AMF tout en maintenant ses attentes en matière de gouvernance d’entreprise et de pratiques de rémunération des dirigeants.
MARKET ABUSE
AMF publishes communication on managers’ transaction disclosures under Article 19 of MAR / L'AMF publie une communication relative à la déclaration des opérations effectuées par les dirigeants en vertu de l'article 19 du règlement MAR
![]()
On 28 August 2026, the Autorité des marchés financiers (AMF) announced that transactions reported by persons discharging managerial responsibilities (PDMRs) and persons closely associated with them under Article 19 of the Market Abuse Regulation (MAR) will now be published in both French and English in its Base des décisions et informations financières (BDIF).
The change follows an exemption granted by the US Securities and Exchange Commission (SEC) on 5 March 2026 to directors and officers of certain foreign private issuers (FPIs) subject to transaction-reporting regimes considered substantially similar to the US Section 16(a) requirements. For EEA issuers, the SEC recognised the MAR Article 19 regime as substantially similar, provided that the relevant disclosures are publicly available in English within two business days of publication.
Key Takeaways:
- Declarations submitted to the AMF in French under Article 19 MAR are now also published in English.
- The change is intended to allow eligible directors and officers of EEA foreign private issuers registered with the SEC to rely on the US exemption from Section 16(a) reporting requirements.
- The underlying MAR notification obligations remain unchanged: PDMRs and closely associated persons must continue to submit required transaction notifications through the AMF’s ONDE platform where the AMF is the competent authority.
- Persons not subject to Article 19 MAR cannot rely on the AMF publication mechanism and remain responsible for complying with any applicable US reporting requirements.
The change facilitates compliance with the SEC exemption for eligible EEA foreign private issuers while leaving the underlying MAR transaction reporting obligations unchanged.
Version française
Le 28 août 2026, l’Autorité des marchés financiers (AMF) a annoncé que les transactions déclarées par les personnes exerçant des responsabilités dirigeantes (PDMR) et les personnes qui leur sont étroitement liées, en vertu de l’article 19 du règlement sur les abus de marché (MAR), seront désormais publiées en français et en anglais dans sa Base des décisions et informations financières (BDIF).
Ce changement fait suite à une dérogation accordée le 5 mars 2026 par la Securities and Exchange Commission (SEC) américaine aux administrateurs et dirigeants de certains émetteurs privés étrangers (FPI) soumis à des régimes de déclaration des transactions jugés substantiellement similaires aux exigences de la section 16(a) de la législation américaine. Pour les émetteurs de l’EEE, la SEC a reconnu que le régime prévu à l’article 19 du MAR était substantiellement similaire, à condition que les informations concernées soient accessibles au public en anglais dans les deux jours ouvrables suivant leur publication.
Points clés à retenir :
- Les déclarations transmises à l’AMF en français en vertu de l’article 19 du MAR sont désormais également publiées en anglais.
- Ce changement vise à permettre aux administrateurs et dirigeants éligibles d’émetteurs privés étrangers de l’EEE enregistrés auprès de la SEC de se prévaloir de l’exemption américaine des obligations de déclaration prévues à la section 16(a).
- Les obligations de notification au titre du règlement MAR restent inchangées : les personnes exerçant des responsabilités dirigeantes (PDMR) et les personnes étroitement liées doivent continuer à soumettre les notifications de transactions requises via la plateforme ONDE de l’AMF lorsque celle-ci est l’autorité compétente.
- Les personnes non soumises à l’article 19 du règlement MAR ne peuvent pas se prévaloir du mécanisme de publication de l’AMF et restent tenues de se conformer à toutes les obligations de déclaration américaines applicables.
Cette modification facilite la mise en conformité avec l’exemption accordée par la SEC aux émetteurs privés étrangers de l’EEE éligibles, tout en laissant inchangées les obligations sous-jacentes de déclaration des transactions prévues par le règlement MAR.
OTHER - PRUDENTIAL REQUIREMENTS
France publishes Arrêté of 29 July 2026 transposing the Capital Requirements Directive VI (CRD VI) / La France publie l'arrêté du 29 juillet 2026 transposant la directive sur les exigences de fonds propres VI (CRD VI)
![]()
On 1 August 2026, France published the Arrêté of 29 July 2026 on the transposition of Directive (EU) 2024/1619 amending Directive 2013/36/EU (Capital Requirements Directive VI – CRD VI). The Arrêté completes the French CRD VI implementation framework by amending several existing prudential, internal-control, supervisory and authorisation rules applicable to credit institutions, financing companies, investment firms and third-country branches supervised in France.
The text complements Ordonnance No. 2026-255 of 8 April 2026 and Decree No. 2026-309 of 24 April 2026, which also transpose CRD VI into French law.
Key Takeaways:
- Internal governance and risk management: the Arrêté strengthens the role of compliance and risk-management functions in significant risk decisions and requires institutions to ensure that material risks are appropriately identified, assessed and reported to management and supervisory bodies. It also incorporates model risk and ICT risk more explicitly within the internal-control framework.
- ESG risks: the prudential supervisory and evaluation process now expressly covers institutions' governance, risk-management arrangements and exposures to environmental, social and governance risks. The Autorité de contrôle prudentiel et de résolution (ACPR) will also assess institutions' plans and progress in addressing risks arising from the transition towards climate neutrality and other relevant EU ESG objectives.
- Crypto-asset exposures: institutions must assess the risks associated with any new type of crypto-asset exposure before undertaking it and maintain processes covering, among others, market, liquidity, concentration, credit and operational risks.
- Capital buffers and supervisory review: the Arrêté adjusts the rules governing systemic-risk and other systemically important institution buffers, including their interaction with the output floor, and expressly recognises climate-related risks within the systemic-risk buffer framework.
- Third-country branches: a substantially revised prudential regime is introduced for French branches of credit institutions headquartered outside the EU/EEA. Branches will be classified into Category 1 or Category 2, including according to their asset size, deposit-taking activities and the regulatory status of their home country.
- Capital and liquidity requirements for third-country branches: Category 1 branches will generally be subject to a capital endowment of at least 2.5% of average liabilities, with a EUR 10 million minimum, while Category 2 branches will generally be subject to 0.5%, with a EUR 5 million minimum. The Arrêté also introduces specific liquidity and asset-location requirements.
- Third-country branch reporting and supervision: branches must provide the ACPR with information on their French assets and liabilities, significant exposures and intragroup transactions, compliance with applicable requirements and certain information concerning their parent undertaking. The ACPR may impose additional prudential requirements and, in specified circumstances, require a branch to convert into a subsidiary.
- Significant transactions: new notification and supervisory assessment procedures are introduced for credit institutions and financing companies undertaking significant acquisitions or disposals of holdings, transfers of assets or liabilities, mergers and demergers. The framework specifies information requirements and supervisory assessment periods.
- The Arrêté also updates French rules on authorisation, internal control, prudential benchmarking, investment firms and the application of these requirements in French overseas territories.
Most provisions entered into force on 2 August 2026, the day following publication. Certain provisions, including significant parts of the revised regime for third-country branches, will apply from 11 January 2027.
Version française
Le 1er août 2026, la France a publié l’arrêté du 29 juillet 2026 portant transposition de la directive (UE) 2024/1619 modifiant la directive 2013/36/UE (directive sur les exigences de fonds propres VI – CRD VI). Cet arrêté complète le cadre français de mise en œuvre de la CRD VI en modifiant plusieurs règles existantes en matière de prudence, de contrôle interne, de surveillance et d’agrément applicables aux établissements de crédit, aux sociétés de financement, aux entreprises d’investissement et aux succursales de pays tiers soumises à surveillance en France.
Ce texte complète l’ordonnance n° 2026-255 du 8 avril 2026 et le décret n° 2026-309 du 24 avril 2026, qui transposent également la CRD VI en droit français.
Points clés :
- Gouvernance interne et gestion des risques : l’arrêté renforce le rôle des fonctions de conformité et de gestion des risques dans les décisions relatives aux risques significatifs et impose aux établissements de veiller à ce que les risques importants soient correctement identifiés, évalués et communiqués à la direction et aux organes de surveillance. Il intègre également de manière plus explicite le risque lié aux modèles et le risque informatique dans le cadre de contrôle interne.
- Risques ESG : le processus de surveillance et d’évaluation prudentielle couvre désormais expressément la gouvernance des établissements, leurs dispositifs de gestion des risques et leurs expositions aux risques environnementaux, sociaux et de gouvernance. L’Autorité de contrôle prudentiel et de résolution (ACPR) évaluera également les plans et les progrès des établissements dans la gestion des risques découlant de la transition vers la neutralité climatique et d’autres objectifs ESG pertinents de l’Union européenne.
- Expositions aux crypto-actifs : les établissements doivent évaluer les risques associés à tout nouveau type d’exposition aux crypto-actifs avant de s’y engager et mettre en place des processus couvrant, entre autres, les risques de marché, de liquidité, de concentration, de crédit et opérationnels.
- Réserves de fonds propres et examen prudentiel : l’arrêté adapte les règles régissant les réserves de fonds propres liées au risque systémique et celles des autres établissements d’importance systémique, y compris leur interaction avec le seuil minimal de sortie, et reconnaît expressément les risques liés au climat dans le cadre de la réserve de fonds propres pour risque systémique.
- Succursales de pays tiers : un régime prudentiel considérablement remanié est mis en place pour les succursales françaises d’établissements de crédit dont le siège social est situé en dehors de l’UE/EEE. Les succursales seront classées en catégorie 1 ou en catégorie 2, notamment en fonction de la taille de leur actif, de leurs activités de collecte de dépôts et du statut réglementaire de leur pays d’origine.
- Exigences de fonds propres et de liquidité pour les succursales de pays tiers : les succursales de catégorie 1 seront généralement soumises à une dotation en fonds propres d’au moins 2,5 % du passif moyen, avec un minimum de 10 millions d’euros, tandis que celles de catégorie 2 seront généralement soumises à une exigence de 0,5 %, avec un minimum de 5 millions d’euros. L’arrêté introduit également des exigences spécifiques en matière de liquidité et de localisation des actifs.
- Déclaration et surveillance des succursales de pays tiers : les succursales doivent fournir à l’ACPR des informations sur leurs actifs et passifs français, leurs expositions significatives et leurs opérations intragroupe, le respect des exigences applicables ainsi que certaines informations concernant leur entreprise mère. L’ACPR peut imposer des exigences prudentielles supplémentaires et, dans certaines circonstances, exiger qu’une succursale se transforme en filiale.
- Opérations significatives : de nouvelles procédures de notification et d’évaluation prudentielle sont mises en place pour les établissements de crédit et les sociétés de financement qui réalisent des acquisitions ou des cessions significatives de participations, des transferts d’actifs ou de passifs, ainsi que des fusions et scissions. Le dispositif précise les obligations d’information et les délais d’évaluation prudentielle.
- L’arrêté actualise également les règles françaises en matière d’agrément, de contrôle interne, d’évaluation prudentielle, d’entreprises d’investissement et d’application de ces exigences dans les territoires français d’outre-mer.
La plupart des dispositions sont entrées en vigueur le 2 août 2026, le lendemain de leur publication. Certaines dispositions, notamment des parties importantes du régime révisé applicable aux succursales de pays tiers, s’appliqueront à compter du 11 janvier 2027.
SUPERVISION
France publishes Arrêté of 30 July 2026 on regulated markets under foreign investment screening / La France publie l'arrêté du 30 juillet 2026 relatif aux marchés réglementés dans le cadre du contrôle des investissements étrangers
![]()
On 2 August 2026, France published the Arrêté of 30 July 2026 on foreign investments in France, which complements the French foreign investment screening framework by specifying which EU/EEA and foreign markets qualify as regulated markets for the purposes of Article R. 151-2 of the Monetary and Financial Code.
The Arrêté operationalises the clarification introduced by Decree No. 2026-718 of 30 July 2026, which addresses foreign investments in French companies whose shares are admitted to trading on foreign markets.
Key Takeaways:
- Scope: the Arrêté identifies the regulated markets to be taken into account under the French foreign investment screening regime where the relevant French company has shares admitted to trading on such a market.
- EU/EEA markets: regulated markets located in an EU Member State or EEA country and included in the list maintained by the European Securities and Markets Authority (ESMA) under Article 56 of Directive 2014/65/EU on markets in financial instruments (MiFID II) are recognised.
- Equivalent third-country markets: markets located in third countries benefiting from an equivalence decision adopted by the European Commission under Article 25(4)(a) of MiFID II are also recognised.
- Additional third-country markets: the Arrêté expressly recognises the London Stock Exchange, SIX Swiss Exchange, Toronto Stock Exchange, Singapore Exchange, Japan Exchange and Korea Exchange.
- Overseas application: the Arrêté also sets out adaptations for its application in Saint-Barthélemy, Saint-Pierre-et-Miquelon, New Caledonia, French Polynesia and Wallis and Futuna.
Article 1, establishing the list of recognised regulated markets, applies from the eleventh business day following publication. The Arrêté therefore provides the market list needed to apply the foreign investment screening rules clarified by Decree No. 2026-718.
Version française
Le 2 août 2026, la France a publié l’arrêté du 30 juillet 2026 relatif aux investissements étrangers en France, qui complète le dispositif français de contrôle des investissements étrangers en précisant quels marchés de l’UE/EEE et étrangers sont considérés comme des marchés réglementés au sens de l’article R. 151-2 du Code monétaire et financier.
Cet arrêté met en œuvre la précision apportée par le décret n° 2026-718 du 30 juillet 2026, qui traite des investissements étrangers dans des sociétés françaises dont les actions sont admises à la négociation sur des marchés étrangers.
Points clés :
- Champ d’application : l’arrêté identifie les marchés réglementés à prendre en compte dans le cadre du régime français de contrôle des investissements étrangers lorsque la société française concernée a des actions admises à la négociation sur un tel marché.
- Marchés de l’UE/EEE : sont reconnus les marchés réglementés situés dans un État membre de l’UE ou un pays de l’EEE et figurant sur la liste tenue par l’Autorité européenne des marchés financiers (AEMF) en vertu de l’article 56 de la directive 2014/65/UE concernant les marchés d’instruments financiers (MiFID II).
- Marchés équivalents de pays tiers : les marchés situés dans des pays tiers bénéficiant d’une décision d’équivalence adoptée par la Commission européenne en vertu de l’article 25, paragraphe 4, point a), de la directive MiFID II sont également reconnus.
- Marchés supplémentaires de pays tiers : l’arrêté reconnaît expressément la Bourse de Londres, la SIX Swiss Exchange, la Bourse de Toronto, la Bourse de Singapour, la Bourse du Japon et la Bourse de Corée.
- Application outre-mer : l’arrêté prévoit également des adaptations pour son application à Saint-Barthélemy, à Saint-Pierre-et-Miquelon, en Nouvelle-Calédonie, en Polynésie française et à Wallis-et-Futuna.
L'article 1er, qui établit la liste des marchés réglementés reconnus, s'applique à compter du onzième jour ouvrable suivant sa publication. L'arrêté fournit ainsi la liste des marchés nécessaire à l'application des règles de contrôle des investissements étrangers précisées par le décret n° 2026-718.
GERMANY
OPERATIONAL RISK
BaFin publishes Minimum Requirements for the Risk Management of Investment Firms (WpI MaRisk)
![]()
On 24 August 2026, the German Federal Financial Supervisory Authority (BaFin) published the Minimum Requirements for the Risk Management of Investment Firms (WpI MaRisk), which establish a supervisory framework for the governance, internal controls, and risk management of small and medium-sized investment firms under the German Investment Firm Act (WpIG).
The circular sets out comprehensive requirements covering governance, risk inventory, risk-bearing capacity, capital planning, risk strategy, compliance, internal audit, outsourcing, business continuity, new product approval processes, risk reporting, and the management of operational, liquidity, market, customer-related, and wind-down risks. It also incorporates relevant EBA guidelines on internal governance and suitability.
Investment firms must identify and assess material risks through a risk inventory process, explicitly consider ICT risks, appropriately incorporate ESG risks into risk assessments and reporting, and establish governance arrangements proportionate to their size, complexity, and business model.
The circular introduces detailed outsourcing requirements, including risk analysis, contractual standards, oversight arrangements, outsourcing registers, and safeguards to prevent firms from becoming “empty shells.” It also requires medium-sized investment firms to assess the risk of disorderly wind-down and maintain processes for capital planning, stress testing, and liquidity risk management.
IRELAND
ANTI-MONEY LAUNDERING / COMBATING TERRORISM FINANCING / COMBATTING PROLIFERATION FINANCING (AML/CFT/CPF)
Department of Finance publishes Ireland's National AML/CFT/CPF Reform Package
![]()
BACKGROUND
On 17 August 2026, Ireland’s Department of Finance published the National Anti-Money Laundering, Countering the Financing of Terrorism and Countering Proliferation Financing Strategy 2026–2030, supported by the National Risk Assessment 2026 and the Priority Actions Implementation Plan 2026. The publications establish Ireland’s AML/CFT/CPF priorities in the context of the EU AML Package and the country’s FATF Mutual Evaluation scheduled for 2028. They concern competent authorities and sectors exposed to money laundering, terrorist financing and proliferation financing risks, including banks, crypto-asset businesses, investment funds and fund service providers.
WHAT'S NEW?
National Risk Assessment
The National Risk Assessment classifies Ireland’s overall money-laundering threat as moderate, with drug offences and fraud identified as the principal drivers. Retail banking, digital banking, crypto-assets and money-remittance businesses are assessed as presenting very significant money-laundering and terrorist-financing risks.
Fund management companies are classified as presenting a significant money-laundering risk, while investment funds, fund administrators and depositaries continue to present material financial-crime risks.
Strategic goals
The Strategy establishes five goals covering national coordination, risk assessment, regulatory measures, capacity building and international cooperation. It focuses on implementing the EU AML Package, preparing for AMLA supervision, improving beneficial-ownership transparency, strengthening sanctions implementation and financial intelligence, and enhancing public-private cooperation.
Priority actions
The Implementation Plan sets out 30 actions, including:
- enhancing the Financial Intelligence Unit’s analytical capabilities;
- collecting additional data on ML/TF and sanctions-evasion risks;
- analysing cross-border financial flows and strengthening beneficial-ownership requirements; and
- reviewing supervisory approaches annually and addressing emerging technologies and artificial intelligence within AML/CFT frameworks.
WHAT'S NEXT?
Competent authorities will implement the measures included in the Priority Actions Implementation Plan during 2026 and 2027. Ireland will undergo its next FATF Mutual Evaluation in 2028. The Strategy will guide Ireland’s AML/CFT/CPF framework until 2030.
Irish Statute Book publishes S.I. No. 406/2026 amending beneficial ownership requirements for corporate entities
![]()
On 7 August 2026, the Irish Statute Book published the European Union (Anti-Money Laundering: Beneficial Ownership of Corporate Entities) (Amendment) Regulations 2026, which amend the European Union (Anti-Money Laundering: Beneficial Ownership of Corporate Entities) Regulations 2019 to give effect to Articles 11, 12, 13 and 15 of Directive (EU) 2024/1640 concerning access to beneficial ownership information and cooperation among competent authorities for AML/CFT purposes.
The Regulations apply in Ireland to the central register of beneficial ownership of corporate entities and to persons and authorities seeking access to beneficial ownership information held in that register. They affect competent authorities, public authorities, persons demonstrating a legitimate interest in the prevention and combating of money laundering and terrorist financing, and other entities granted access rights under the amended framework. The amendments also apply to the Registrar's administration of access requests, certificates, reviews and appeals relating to beneficial ownership information.
Key Requirements:
- The Regulations expand the categories of authorities entitled to access beneficial ownership information, including AMLA, the European Public Prosecutor's Office (EPPO), OLAF, Europol, Eurojust, the Central Bank of Ireland and additional government authorities. They introduce a formal legitimate-interest framework allowing access to beneficial ownership information where applicants demonstrate a legitimate interest in preventing and combating money laundering, predicate offences and terrorist financing.
- The amendments establish detailed procedures governing applications, certification, reviews, appeals, revocations, identity verification requirements and access to historical beneficial ownership information. They also specify categories of persons deemed to possess a legitimate interest, including journalists, civil society organisations, certain prospective counterparties, third-country authorities and AML/CFT product providers.
- The Regulations further introduce safeguards restricting access where disclosure could expose beneficial owners to disproportionate risks and provide that fees for inspecting information must be limited to costs strictly necessary to maintain information quality and facilitate access
New deadlines governing the Registrar’s consideration of legitimate-interest submissions will apply from 10 November 2026.
The next step is the implementation and operation of the amended access and disclosure regime by the Registrar in accordance with the new requirements.
ARTIFICIAL INTELLIGENCE
Irish Statute Book publishes European Union (Artificial Intelligence) (Designation) (Amendment) Regulations 2026
![]()
On 31 July 2026, the Irish Statute Book (ISB) published the European Union (Artificial Intelligence) (Designation) (Amendment) Regulations 2026, which amend the European Union (Artificial Intelligence) (Designation) Regulations 2025 and designate additional competent and market surveillance authorities for the supervision of AI systems under Regulation (EU) 2024/1689 (Artificial Intelligence Act). The Regulations were made by the Minister for Enterprise, Tourism and Employment.
Key Takeaways:
- The Regulations expand the Irish supervisory framework for the AI Act by assigning national competent authorities and market surveillance authorities across a range of sectors and use cases. Designations are made for authorities responsible for machinery, consumer products, communications, transport, healthcare, employment, data protection, financial services, and digital services.
- The Central Bank of Ireland is designated as the market surveillance authority for high-risk AI systems placed on the market, put into service, or used by regulated financial service providers in direct connection with the provision of financial services. The Central Bank is also designated for certain prohibited AI practices under Article 5 of the AI Act where these involve regulated financial service providers.
- Additional authorities are designated for specific sectors, including Coimisiún na Meán for certain digital and media services, the Data Protection Commission for several AI use cases under Annex III and Article 5, and other sectoral authorities for critical infrastructure, employment, healthcare, communications, and transport.
The Regulations take effect upon their making and form part of Ireland’s implementation of the EU Artificial Intelligence Act through the establishment of the national supervisory architecture.
JERSEY
OTHER - PRUDENTIAL REQUIREMENTS
JFSC publishes industry update on final Basel III prudential rules
![]()
On 3 August 2026, the Jersey Financial Services Commission published a feedback statement on its near-final Basel III prudential rules, which summarises industry feedback received during consultation on the detailed prudential requirements and confirms that the regulator will proceed with the proposed Basel III framework, subject to limited amendments and clarifications.
In May 2026, the regulator published near-final draft Basel III prudential requirements and invited feedback until 12 July 2026. According to the feedback statement, respondents were broadly supportive of both the proposed framework and the approach of aligning Jersey's implementation with the UK Prudential Regulation Authority (PRA) Basel III framework while incorporating Jersey-specific adjustments where appropriate.
The publication relates to the implementation of Basel III prudential requirements in Jersey. The feedback and final requirements address prudential areas including operational risk, credit risk (standardised approach), capital requirements and own funds, large exposures, leverage ratio, market risk, counterparty credit risk and the Net Stable Funding Ratio (NSFR). The publication specifically references implementation for Jersey Incorporated Banks.
The regulator confirmed it will proceed with the proposed framework. Feedback predominantly concerned technical clarifications and implementation matters rather than objections to the policy direction. Key topics raised by respondents included:
- Operational risk, including loss data, common operational risk events and treatment of the Internal Loss Multiplier (ILM).
- Credit risk matters such as public sector entities, SME definitions, ADC exposures, real estate exposures and foreign currency mismatch provisions.
- Capital requirements and own funds, including transactional accounts, dividends and unverified profits.
- Large exposures, including transitional arrangements, exemptions and reporting considerations.
- Other prudential frameworks including leverage ratio, market risk, counterparty credit risk and NSFR.
The regulator intends to issue additional guidance, clarifications, glossary updates and limited drafting amendments where necessary.
Near-final consultation published: May 2026.
Feedback deadline: 12 July 2026.
Final Basel III prudential rules published: 3 August 2026.
Optional early transition: 1 January 2027.
Effective date: 1 July 2027.
All aspects for Jersey Incorporated Banks live in H2 2027.
LUXEMBOURG
ANTI-MONEY LAUNDERING / COMBATING TERRORISM FINANCING / COMBATTING PROLIFERATION FINANCING (AML/CFT/CPF)
CRF publishes strategic analysis on crypto-asset misuse in financial crime / Le CRF publie une analyse stratégique sur l'utilisation abusive des crypto-actifs dans le cadre de la criminalité financière
![]()
On 13 August 2026, Luxembourg's Financial Intelligence Unit (CRF) published a strategic analysis based on a sample of Suspicious Activity and Transaction Reports (SARs/STRs) submitted during 2025, identifying the main typologies, emerging trends and risk indicators relating to the misuse of crypto-assets for money laundering and terrorist financing purposes.
The analysis responds to the significant increase in suspicious reports involving crypto-assets, originating not only from Crypto-Asset Service Providers (CASPs/VASPs) but also from other reporting entities, including credit institutions, payment institutions and the investment sector. The purpose is to contribute to a better understanding of the ML/TF risk landscape relating to crypto-assets from an FIU perspective and to support reporting entities and competent authorities in their risk assessment.
Cryptocurrencies (BTC, ETH) remain dominant in ML/TF suspicion cases, accounting for over 60% of cases analysed. Stablecoins (USDT, USDC) are the second most used type of crypto-asset, due to their price stability and increasing use for cross-border transfers and on/off-ramp operations. Fraud schemes, particularly investment scams, represent a prominent source of illicit funds entering the crypto-asset ecosystem. Suspicious activity is largely cross-border, involving non-resident individuals using accounts and products domiciled in Luxembourg.
The analysis identifies five typology categories:
- Money laundering through crypto-assets covers the conversion of fiat funds of suspicious origin into crypto-assets by commercial companies using notably vIBANs to CEX accounts,
- Laundering via real estate investments and professional-to-personal asset diversion. Crypto-asset-based fraud and abuse includes the rapid transfer of defrauded funds through multiple wallets (wallet hopping),
- Account takeover, fake crypto platforms, investment scams and identity theft for account opening,
- Illicit fund movement via intermediaries concerns the use of transit accounts on centralised platforms displaying recurrent FICO/CIFO patterns, money mule networks and, in more specific cases, NFT acquisitions.,
- Indirect and direct exposure to illicit addresses covers transactional links with sanctioned entities, child sexual abuse material, darknet markets, ransomware and addresses linked to terrorist financing.
The analysis highlights the growing sophistication of techniques employed, including no-KYC swap services, decentralised platforms, cross-chain bridges and Layer-2 networks. The increasing interconnection between the traditional financial system and the crypto-asset ecosystem, notably through vIBANs, is also underlined. The CRF stresses the importance of blockchain analytics capabilities, cross-border cooperation and cross-sectoral approaches to detect and disrupt these illicit activities.
Version française
Le 13 août 2026, la Cellule de renseignement financier (CRF) du Luxembourg a publié une analyse stratégique fondée sur un échantillon de déclarations d’opérations et d’activités suspectes (SAR/STR) transmises au cours de l’année 2025, identifiant les principales typologies, les tendances émergentes et les indicateurs de risque liés à l’utilisation abusive des crypto-actifs à des fins de blanchiment de capitaux et de financement du terrorisme.
Cette analyse fait suite à l’augmentation significative du nombre de déclarations de soupçons impliquant des crypto-actifs, émanant non seulement des prestataires de services de crypto-actifs (CASP/VASP), mais également d’autres entités déclarantes, notamment les établissements de crédit, les établissements de paiement et le secteur de l’investissement. Elle a pour objectif de contribuer à une meilleure compréhension du paysage des risques de blanchiment de capitaux et de financement du terrorisme liés aux crypto-actifs du point de vue de la CRF, ainsi que d’aider les entités déclarantes et les autorités compétentes dans leur évaluation des risques.
Les cryptomonnaies (BTC, ETH) restent prédominantes dans les cas de soupçons de BC/FT, représentant plus de 60 % des cas analysés. Les stablecoins (USDT, USDC) constituent le deuxième type de crypto-actif le plus utilisé, en raison de leur stabilité des prix et de leur utilisation croissante pour les transferts transfrontaliers et les opérations de conversion (on/off-ramp). Les stratagèmes frauduleux, en particulier les escroqueries à l’investissement, représentent une source majeure de fonds illicites entrant dans l’écosystème des crypto-actifs. Les activités suspectes sont en grande partie transfrontalières et impliquent des personnes physiques non résidentes utilisant des comptes et des produits domiciliés au Luxembourg.
L’analyse identifie cinq catégories de typologies :
- Le blanchiment d’argent via les crypto-actifs couvre la conversion de fonds fiduciaires d’origine suspecte en crypto-actifs par des sociétés commerciales utilisant notamment des vIBAN vers des comptes CEX,
- Le blanchiment via des investissements immobiliers et le détournement d’actifs professionnels vers des comptes personnels. Les fraudes et abus liés aux crypto-actifs incluent le transfert rapide de fonds escroqués via plusieurs portefeuilles (wallet hopping),
- la prise de contrôle de comptes, les fausses plateformes de crypto-actifs, les escroqueries à l’investissement et l’usurpation d’identité lors de l’ouverture de comptes,
- les mouvements illicites de fonds via des intermédiaires, qui concernent l’utilisation de comptes de transit sur des plateformes centralisées présentant des schémas FICO/CIFO récurrents, les réseaux de « mules financières » et, dans des cas plus spécifiques, les acquisitions de NFT,
- l’exposition indirecte et directe à des adresses illicites, qui couvre les liens transactionnels avec des entités sanctionnées, les contenus pédopornographiques, les marchés du darknet, les ransomwares et les adresses liées au financement du terrorisme.
L’analyse met en évidence la sophistication croissante des techniques utilisées, notamment les services d’échange sans KYC, les plateformes décentralisées, les ponts inter-chaînes et les réseaux de couche 2. L’interconnexion croissante entre le système financier traditionnel et l’écosystème des crypto-actifs, notamment via les vIBAN, est également soulignée. Le CRF insiste sur l’importance des capacités d’analyse de la blockchain, de la coopération transfrontalière et des approches intersectorielles pour détecter et perturber ces activités illicites.
LBR publishes Circular 26/01 on beneficial owners of companies held by trusts or foundations / La LBR publie la circulaire n° 26/01 relative aux bénéficiaires effectifs des sociétés détenues par des trusts ou des fondations
![]()
On 19 August 2026, Luxembourg Business Registers (LBR) published Circular LBR 26/01, which clarifies the procedures to be followed when registering beneficial owners in the Luxembourg Beneficial Owners Register (Registre des Bénéficiaires Effectifs, RBE) for companies subject to the amended Law of 13 January 2019 that are held by a trust or foundation. The circular addresses a gap in practical guidance on the application of the beneficial ownership definition where the immediate shareholder of a Luxembourg company is not a natural person but a legal arrangement (trust or foundation).
The circular applies to all Luxembourg companies subject to the Law of 13 January 2019 establishing the RBE whose shares or ownership interests are held directly or indirectly by a trust or foundation. It is addressed to registered entities responsible for carrying out the necessary enquiries to identify their beneficial owners and register them in the RBE.
The circular establishes two key principles:
General rule: Beneficial owners of a Luxembourg company are identified pursuant to Article 1(7)(a) of the amended Law of 12 November 2004 on AML/CFT i.e. any natural person who ultimately owns or controls the company through direct or indirect ownership of a sufficient percentage of shares, voting rights or ownership interest, or through control by other means. Where no such person can be identified despite the required enquiries, the senior managing official(s) must be registered as beneficial owners.
Exception, companies held by trusts or foundations: Where a Luxembourg company is held by a trust or foundation, LBR takes the position that the beneficial owners to be reported to the RBE are the beneficial owners of the underlying trust or foundation rather than of the company itself. In such cases, Article 1(7)(b) and (c) of the amended Law of 12 November 2004 applies, and the following natural persons must be registered:
- the settlor(s);
- the trustee(s);
- the protector(s), if any;
- the beneficiaries or, where beneficiaries are yet to be determined, the category of persons in whose main interest the arrangement operates;
- any other natural person exercising ultimate control.
LBR notes that this position is consistent with Article 55 of the forthcoming AML Regulation (EU) 2024/1624, which, while not yet mandatory, usefully guides interpretation.
The information to be registered for each beneficial owner is that set out in Article 3 of the Law of 13 January 2019: surname and first name(s), nationality, date of birth, place of birth, country of residence, precise private or professional address, national or foreign identification number, and the nature and extent of the beneficial interests held.
Version française
Le 19 août 2026, les Registres du commerce du Luxembourg (LBR) ont publié la circulaire LBR 26/01, qui précise les procédures à suivre pour l’inscription des bénéficiaires effectifs au Registre des bénéficiaires effectifs (RBE) du Luxembourg, pour les sociétés soumises à la loi modifiée du 13 janvier 2019 et détenues par un trust ou une fondation. Cette circulaire comble une lacune dans les orientations pratiques relatives à l'application de la définition du bénéficiaire effectif lorsque l'actionnaire direct d'une société luxembourgeoise n'est pas une personne physique, mais une entité juridique (trust ou fondation).
La circulaire s'applique à toutes les sociétés luxembourgeoises soumises à la loi du 13 janvier 2019 instituant le RBE dont les actions ou les participations sont détenues, directement ou indirectement, par un trust ou une fondation. Elle s'adresse aux entités enregistrées chargées de mener les enquêtes nécessaires pour identifier leurs bénéficiaires effectifs et les inscrire au RBE.
La circulaire établit deux principes clés:
Règle générale: les bénéficiaires effectifs d’une société luxembourgeoise sont identifiés conformément à l’article 1, paragraphe 7, point a), de la loi modifiée du 12 novembre 2004 relative à la lutte contre le blanchiment d’argent et au financement du terrorisme (LBC/FT), c’est-à-dire toute personne physique qui détient ou contrôle en dernier ressort la société par le biais d’une participation directe ou indirecte représentant un pourcentage suffisant d’actions, de droits de vote ou de parts sociales, ou par le biais d’un contrôle exercé par d’autres moyens. Lorsqu’aucune telle personne ne peut être identifiée malgré les recherches requises, le ou les dirigeants principaux doivent être enregistrés en tant que bénéficiaires effectifs.
Exception: sociétés détenues par des trusts ou des fondations : lorsqu’une société luxembourgeoise est détenue par un trust ou une fondation, le LBR considère que les bénéficiaires effectifs à déclarer au RBE sont les bénéficiaires effectifs du trust ou de la fondation sous-jacente plutôt que ceux de la société elle-même. Dans de tels cas, l’article 1, paragraphe 7, points b) et c), de la loi modifiée du 12 novembre 2004 s’applique, et les personnes physiques suivantes doivent être déclarées :
- le ou les constituants ;
- le ou les administrateurs ;
- le ou les protecteurs, le cas échéant ;
- les bénéficiaires ou, lorsque ceux-ci n’ont pas encore été désignés, la catégorie de personnes dans l’intérêt principal desquelles le dispositif opère ;
- toute autre personne physique exerçant un contrôle ultime.
La LBR note que cette position est conforme à l’article 55 du futur règlement (UE) 2024/1624 relatif à la lutte contre le blanchiment de capitaux, qui, bien qu’il ne soit pas encore contraignant, constitue un guide utile pour l’interprétation.
Les informations à enregistrer pour chaque bénéficiaire effectif sont celles prévues à l’article 3 de la loi du 13 janvier 2019 : nom et prénom(s), nationalité, date de naissance, lieu de naissance, pays de résidence, adresse privée ou professionnelle précise, numéro d’identification national ou étranger, ainsi que la nature et l’étendue des intérêts bénéficiaires détenus.
Legilux publishes Law of 22 July 2026 amending judicial organisation and AML/CFT / Legilux publie la loi du 22 juillet 2026 modifiant l'organisation judiciaire et la lutte contre le blanchiment d'argent et le financement du terrorisme
![]()
On 4 August 2026, the Journal officiel du Grand-Duché de Luxembourg published the Law of 22 July 2026, which amends the amended law of 7 March 1980 on judicial organisation and the amended law of 12 November 2004 on combating money laundering and terrorist financing.
The law introduces a new mechanism allowing the Financial Intelligence Unit (CRF – Cellule de Renseignement Financier) to report certain fraud typologies and related information to professionals subject to anti-money laundering obligations, in order to strengthen their prevention frameworks.
The mechanism is intended to benefit the professionals referred to in Article 2, paragraph 1, points 1 and 20, of the amended law of 12 November 2004. These include credit institutions, professionals of the financial sector (PFSs), payment institutions, electronic money institutions, tied agents, payment service agents and crypto-asset service providers (CASPs).
Key takeaways:
- A new Article 74-4bis is inserted into the law of 7 March 1980: the CRF may report to relevant professionals typologies presenting a significant fraud risk — frauds and attempted frauds within the meaning of Book II, Title IX, Chapter II of the Penal Code, including the laundering of proceeds from such offences, carried out on a large scale against unidentified victims or using social engineering techniques targeting specific victims.
- Reports include account numbers brought to the CRF's attention that present such a risk, together with the associated fraud typologies.
- Reports are made upon prior request by the professional, via a secure channel, and this request remains valid for all future reports unless explicitly withdrawn.
- The CRF organises meetings with the professionals concerned at least every six months to discuss the relevance of the reports made, and adapts future reporting based on feedback received.
- A new Article 5-1 is inserted into the law of 12 November 2004: professionals requesting these reports must use them exclusively for AML/CFT purposes, at their own responsibility, may not disclose them to the client concerned or to third parties, and must delete all information received within six months of receipt.
The law enters into force on 8 August 2026.
Version française
Le 4 août 2026, le Journal officiel du Grand-Duché de Luxembourg a publié la loi du 22 juillet 2026, qui modifie la loi modifiée du 7 mars 1980 relative à l'organisation judiciaire et la loi modifiée du 12 novembre 2004 relative à la lutte contre le blanchiment d'argent et le financement du terrorisme.
Cette loi instaure un nouveau mécanisme permettant à la Cellule de renseignement financier (CRF) de signaler certaines typologies de fraude et les informations y afférentes aux professionnels soumis aux obligations en matière de lutte contre le blanchiment de capitaux, afin de renforcer leurs dispositifs de prévention.
Ce mécanisme est destiné aux professionnels visés à l’article 2, paragraphe 1, points 1 et 20, de la loi modifiée du 12 novembre 2004. Il s’agit notamment des établissements de crédit, des professionnels du secteur financier (PSF), des établissements de paiement, des établissements de monnaie électronique, des agents liés, des agents de services de paiement et des prestataires de services liés aux crypto-actifs (CASP).
Points clés :
- Un nouvel article 74-4 bis est inséré dans la loi du 7 mars 1980 : la CRF peut signaler aux professionnels concernés les typologies présentant un risque significatif de fraude — fraudes et tentatives de fraude au sens du livre II, titre IX, chapitre II du Code pénal, y compris le blanchiment des produits de ces infractions, commises à grande échelle à l’encontre de victimes non identifiées ou en recourant à des techniques d’ingénierie sociale ciblant des victimes spécifiques.
- Les signalements comprennent les numéros de compte portés à la connaissance de la CRF qui présentent un tel risque, ainsi que les typologies de fraude associées.
- Les signalements sont effectués sur demande préalable du professionnel, via un canal sécurisé, et cette demande reste valable pour tous les signalements futurs sauf retrait explicite.
- La CRF organise des réunions avec les professionnels concernés au moins tous les six mois afin de discuter de la pertinence des signalements effectués, et adapte les signalements futurs en fonction des retours reçus.
- Un nouvel article 5-1 est inséré dans la loi du 12 novembre 2004 : les professionnels sollicitant ces rapports doivent les utiliser exclusivement à des fins de lutte contre le blanchiment d’argent et le financement du terrorisme (LBC/FT), sous leur propre responsabilité ; ils ne peuvent les divulguer ni au client concerné ni à des tiers, et doivent supprimer toutes les informations reçues dans un délai de six mois à compter de leur réception.
La loi entre en vigueur le 8 août 2026.
DIGITAL OPERATIONAL RESILIENCE
CSSF publishes circular 26/915 on the applicability of DORA to third country branches / La CSSF publie la circulaire n° 26/915 relative à l'applicabilité de la directive DORA aux succursales de pays tiers
![]()
On 27 August 2026, the CSSF published Circular 26/915, amending seven existing CSSF circulars to clarify and align the Luxembourg regulatory framework with the application of the Digital Operational Resilience Act (DORA) to certain third-country branches (TCBs) established in Luxembourg. The Circular implements the European Commission’s position, relayed by EIOPA under Q&A DORA102-3097, that DORA applies to TCBs where their third-country head office would qualify as a DORA-covered financial entity if established in the EU. The Circular applies with immediate effect.
Circular 26/915 applies to financial entities supervised by the CSSF, as well as to TCBs of financial entities whose head office is established in a third country and which would fall within DORA’s scope if established in the EU. This includes TCBs of credit institutions, investment firms, payment institutions, electronic money institutions, crypto-asset service providers, management companies, AIFMs and other financial entities covered by DORA.
- Application of DORA to TCBs: TCBs meeting the above criteria are now considered financial entities subject to DORA and must comply with the applicable DORA requirements.
- ICT risk management and outsourcing: For TCBs subject to DORA, ICT risk management and ICT outsourcing requirements are governed by DORA and the related CSSF framework. Accordingly, the ICT-related requirements under Circulars CSSF 20/750 and 22/806 no longer apply to these TCBs, while non-ICT outsourcing requirements under Circular 22/806 remain applicable.
- ICT third-party services: TCBs are included within the scope of Circular CSSF 25/882 and must comply with the applicable requirements relating to ICT third-party service providers.
- ICT incident reporting: TCBs are also brought within the scope of the CSSF framework for the estimation and reporting of major ICT-related incidents and significant cyber threats under Circulars CSSF 25/892 and 25/893. An alternative communication channel is available where technical issues prevent reporting through the standard CSSF channels.
Circular CSSF 26/915 applies with immediate effect from 27 August 2026.
The Circular therefore primarily clarifies that certain third-country branches established in Luxembourg are subject to DORA, while aligning the existing CSSF circular framework accordingly.
Version française
Le 27 août 2026, la CSSF a publié la circulaire n° 26/915, modifiant sept circulaires existantes de la CSSF afin de clarifier et d’aligner le cadre réglementaire luxembourgeois sur l’application de la loi sur la résilience opérationnelle numérique (DORA) à certaines succursales de pays tiers (TCB) établies au Luxembourg. Cette circulaire met en œuvre la position de la Commission européenne, relayée par l’EIOPA dans la foire aux questions DORA102-3097, selon laquelle la DORA s’applique aux succursales de pays tiers dont le siège social situé dans un pays tiers serait considéré comme une entité financière couverte par la DORA s’il était établi dans l’UE. La circulaire s’applique avec effet immédiat.
La circulaire 26/915 s’applique aux entités financières supervisées par la CSSF, ainsi qu’aux succursales de pays tiers (TCB) d’entités financières dont le siège social est établi dans un pays tiers et qui relèveraient du champ d’application de la DORA si elles étaient établies dans l’UE. Cela inclut les succursales de pays tiers d’établissements de crédit, d’entreprises d’investissement, d’établissements de paiement, d’établissements de monnaie électronique, de prestataires de services liés aux crypto-actifs, de sociétés de gestion, de gestionnaires de fonds d’investissement alternatifs (AIFM) et d’autres entités financières couvertes par la DORA.
- Application de la directive DORA aux TCB : les TCB répondant aux critères susmentionnés sont désormais considérés comme des entités financières soumises à la directive DORA et doivent se conformer aux exigences applicables de cette dernière.
- Gestion des risques liés aux TIC et externalisation : pour les TCB soumis à la directive DORA, les exigences en matière de gestion des risques liés aux TIC et d’externalisation des services TIC sont régies par la directive DORA et le cadre réglementaire de la CSSF qui s’y rapporte. En conséquence, les exigences relatives aux TIC prévues par les circulaires CSSF 20/750 et 22/806 ne s’appliquent plus à ces TCB, tandis que les exigences en matière d’externalisation non liées aux TIC prévues par la circulaire 22/806 restent applicables.
- Services informatiques fournis par des tiers : les TCB relèvent du champ d’application de la circulaire CSSF 25/882 et doivent se conformer aux exigences applicables relatives aux prestataires de services informatiques tiers.
- Déclaration des incidents informatiques : les TCB relèvent également du champ d’application du cadre de la CSSF pour l’évaluation et la déclaration des incidents informatiques majeurs et des cybermenaces significatives, conformément aux circulaires CSSF 25/892 et 25/893. Un canal de communication alternatif est disponible lorsque des problèmes techniques empêchent la déclaration via les canaux standard de la CSSF.
La circulaire CSSF 26/915 s’applique avec effet immédiat à compter du 27 août 2026.
La circulaire précise donc principalement que certaines succursales de pays tiers établies au Luxembourg sont soumises à la DORA, tout en alignant en conséquence le cadre réglementaire existant de la CSSF.
GOVERNANCE & ORGANISATION
CSSF launches dedicated webpage clarifying the notification and assessment of material operations / La CSSF lance une page web dédiée visant à clarifier les modalités de notification et d'évaluation des opérations significatives
![]()
On 3 August 2026, the CSSF published announcing the launch of a dedicated webpage to clarify the process to notify and assess notifying material operations," which announces a new dedicated webpage clarifying the regulatory framework applicable to material operations under the Law of 5 May 2026.
Following the publication of the Law of 5 May 2026, amending the Law of 5 April 1993 on the financial sector ("LFS") and transposing Directive (EU) 2024/1619 ("CRD VI"), new obligations were introduced regarding material operations planned by credit institutions or (mixed) financial holding companies ("institutions"). To assist market participants, the CSSF created a dedicated webpage detailing the practical implementation of these requirements.
The framework applies to credit institutions and (mixed) financial holding companies. It covers three categories of material operations: (i) acquisitions and divestitures of a material holding (equal to or above 15% of eligible capital, or subject to Article 6 LFS if a qualifying holding is involved); (ii) material transfers of assets/liabilities (at least 10% of total assets/liabilities, or 15% for intragroup transfers); and (iii) mergers and divisions (deemed material by default, except where a new entity is created, in which case standard authorisation procedures apply instead).
Main requirements:
- Institutions must notify their competent authority in writing in advance of any material operation, and, for operations likely to significantly impact prudential position or raise money-laundering/terrorist-financing concerns, obtain CSSF approval. Notifications must follow the EBA's draft RTS (EBA/RTS/2026/06) pending publication of the delegated act.
- The CSSF supervises "less significant institutions" (notified by email to the line supervisor); the ECB supervises "significant institutions" (notified via the SSM Portal). Preliminary discussions with the CSSF are strongly recommended.
Version française
Le 3 août 2026, la CSSF a publié un communiqué annonçant le lancement d’une page web dédiée visant à clarifier la procédure de notification et d’évaluation des « opérations significatives », qui présente une nouvelle page web dédiée précisant le cadre réglementaire applicable aux opérations significatives en vertu de la loi du 5 mai 2026.
À la suite de la publication de la loi du 5 mai 2026, modifiant la loi du 5 avril 1993 relative au secteur financier (« LFS ») et transposant la directive (UE) 2024/1619 (« CRD VI »), de nouvelles obligations ont été introduites concernant les opérations significatives envisagées par les établissements de crédit ou les holdings financiers (mixtes) (« établissements »). Afin d’aider les acteurs du marché, la CSSF a créé une page web dédiée détaillant la mise en œuvre pratique de ces exigences.
Ce cadre s’applique aux établissements de crédit et aux holdings financiers (mixtes). Il couvre trois catégories d’opérations significatives : (i) les acquisitions et cessions d’une participation significative (égale ou supérieure à 15 % du capital éligible, ou soumise à l’article 6 de la LFS si une participation qualifiée est en jeu) ; (ii) les transferts significatifs d’actifs/passifs (représentant au moins 10 % du total des actifs/passifs, ou 15 % pour les transferts intragroupe) ; et (iii) les fusions et scissions (considérées par défaut comme significatives, sauf en cas de création d’une nouvelle entité, auquel cas les procédures d’autorisation standard s’appliquent).
Principales exigences :
- Les établissements doivent notifier par écrit et à l’avance à leur autorité compétente toute opération significative et, pour les opérations susceptibles d’avoir un impact significatif sur leur situation prudentielle ou de soulever des préoccupations en matière de blanchiment de capitaux ou de financement du terrorisme, obtenir l’agrément de la CSSF. Les notifications doivent respecter le projet de RTS de l’ABE (EBA/RTS/2026/06) en attendant la publication de l’acte délégué.
- La CSSF supervise les « établissements d’importance mineure » (notification par e-mail à l’autorité de surveillance compétente) ; la BCE supervise les « établissements d’importance significative » (notification via le portail du MSU). Il est vivement recommandé de mener des discussions préliminaires avec la CSSF.
MEXICO
ANTI-MONEY LAUNDERING / COMBATING TERRORISM FINANCING / COMBATTING PROLIFERATION FINANCING (AML/CFT/CPF)
CNBV publishes General Rules under the LFPIORPI
![]()
On 10 August 2026, the Comisión Nacional Bancaria y de Valores (CNBV) published the General Rules issued under the Federal Law for the Prevention and Identification of Operations with Illicit Proceeds (LFPIORPI), which develop the provisions of the law and its regulation, establish application criteria, and clarify the obligations of entities conducting Vulnerable Activities, as well as the powers of the authorities responsible for implementation, supervision and verification.
Key Takeaways
- The Rules introduce a Risk-Based Approach (Enfoque Basado en Riesgo, EBR) as the guiding principle for compliance with LFPIORPI obligations. Entities conducting Vulnerable Activities must identify, assess, classify and document risks associated with clients/users, operations, products, services, distribution channels and geographic areas.
- The Rules strengthen requirements relating to customer due diligence, identification of the beneficial owner (beneficiario controlador), identification of Politically Exposed Persons (PEPs), internal controls, record retention and reporting obligations.
- The Rules establish a proportional compliance model, under which supervisory actions and compliance obligations will be applied according to the risk level of each Vulnerable Activity. SHCP will also conduct supervision and verification activities under a Risk-Based Approach.
The publication states that implementation will occur gradually to allow obligated entities to update internal processes and develop the capabilities necessary to comply with the new regulatory framework. No specific implementation dates are provided in the publication.
NETHERLANDS
CYBERSECURITY
Government of the Netherlands publishes news item announcing that the Cybersecurity Act and the Critical Entities Resilience Act apply as of 15 August 2026
![]()
BACKGROUND
On 15 August 2026, the Government of the Netherlands published a news item announcing the application of the Cybersecurity Act and the Critical Entities Resilience Act from that date. The Cybersecurity Act implements the EU NIS2 Directive and replaces the Network and Information Systems Security Act, while the Critical Entities Resilience Act implements the EU Critical Entities Resilience Directive. The two laws strengthen the digital and physical resilience of organisations and support the continuity of essential services in the Netherlands. They apply to organisations operating in designated sectors, including banking, financial market infrastructure, energy, transport, healthcare, government and digital infrastructure.
WHAT'S NEW?
Cybersecurity Act
The Cybersecurity Act applies to organisations providing essential or important services across 18 sectors. Organisations are responsible for determining whether they fall within its scope. In-scope organisations are subject to:
- registration in the national register of entities managed by the National Cyber Security Centre;
- implementation of appropriate and proportionate cybersecurity risk-management measures;
- reporting of significant incidents to the relevant CSIRT and competent authority within the applicable deadlines; and
- management-body responsibility for approving and overseeing cybersecurity measures, supported by appropriate knowledge and training.
Critical Entities Resilience Act
The Critical Entities Resilience Act applies to approximately 500 organisations designated as critical entities by the responsible ministry. Designated entities must assess risks affecting the continuity of their essential services and implement appropriate technical, organisational and physical resilience measures.
They must also report incidents that cause or may cause significant disruption to their essential services.
Supervision and enforcement
Supervisors and competent authorities are responsible for monitoring and enforcing compliance with the respective frameworks.
WHAT'S NEXT?
Both Acts apply from 15 August 2026. Under the Critical Entities Resilience Act, designated entities must complete their risk assessment within nine months of designation and implement the required resilience measures within ten months. Significant incidents must be reported within 24 hours. A webinar on supervision under the Cybersecurity Act is scheduled for 3 September 2026.
SPAIN
ANTI-MONEY LAUNDERING / COMBATING TERRORISM FINANCING / COMBATTING PROLIFERATION FINANCING (AML/CFT/CPF)
Ministry of Economic Affairs and Digital Transformation publishes draft law to overhaul Spain’s AML and CTF Framework
![]()
On 5 August 2026, the Ministry of Economic Affairs and Digital Transformation published the Draft Law on Comprehensive Measures for the Prevention of Money Laundering, the Financing of Terrorism and the Financing of the Proliferation of Weapons of Mass Destruction.
The proposal represents a major overhaul of Spain’s anti-money laundering and counter-terrorist financing framework, replacing the existing Law 10/2010 and aligning the national regime with the EU Anti-Money Laundering Package adopted in 2024. The reform seeks to address increasingly sophisticated financial crime threats, strengthen the integrity of the financial system, and ensure compliance with updated international standards issued by the Financial Action Task Force (FATF).
The draft law introduces a comprehensive risk-based framework designed to improve the detection, prevention and reporting of money laundering, terrorist financing and proliferation financing activities. The government highlights that criminal networks are becoming more complex, frequently operating across multiple jurisdictions and increasingly exploiting technological innovation and non-financial intermediaries. As a result, the legislation broadens and clarifies the categories of obliged entities subject to AML/CFT requirements and enhances obligations relating to customer due diligence, beneficial ownership transparency and suspicious transaction reporting. Particular emphasis is placed on strengthening the monitoring of complex ownership structures and improving the effectiveness of the Central Registry of Beneficial Owners.
A central feature of the reform is the creation of the National Authority for Financial Integrity (ANIFI), a new independent body responsible for consolidating supervisory, coordination and financial intelligence functions that are currently distributed across different authorities. The proposed authority would have its own legal personality, budget and governance structure, enabling a more integrated and efficient approach to combating financial crime. The draft also reallocates certain financial resolution responsibilities previously held by the FROB to the Bank of Spain and the National Securities Market Commission (CNMV), thereby adapting Spain’s institutional architecture to the evolving European regulatory framework.
The legislation contains extensive provisions on governance, compliance and risk management for obliged entities. It expands due diligence requirements, strengthens controls relating to politically exposed persons, and requires the appointment of compliance officers across a broader range of organisations. The proposal also introduces stricter suitability requirements for owners and managers of obliged entities, preventing individuals convicted of money laundering or other serious financial crimes from exercising ownership or management functions. In addition, the framework enhances supervisory powers and provides authorities with greater tools to assess, investigate and mitigate emerging risks.
The draft law further addresses areas beyond the traditional financial sector. It introduces enhanced controls over high-value transactions, reinforces requirements applicable to certain non-profit and religious organisations, and strengthens the implementation of United Nations and EU financial sanctions. The framework also supports greater information sharing among competent authorities while maintaining safeguards for data protection and privacy. Moreover, the proposal incorporates elements of Directive (EU) 2024/1174 (Daisy Chains II), simplifying aspects of the minimum requirement for own funds and eligible liabilities (MREL) applicable to banking groups and ensuring consistency with broader EU prudential reforms.
Overall, the draft law represents a significant modernisation of Spain’s AML/CFT regime. By transposing key elements of the EU AML package, strengthening beneficial ownership transparency, creating a new national supervisory authority and reinforcing risk-based compliance obligations, the proposal seeks to establish a more coherent, integrated and effective framework for combating financial crime. The consultation remains open until 30 September 2026, providing stakeholders with an opportunity to comment on one of the most significant financial crime reforms in Spain in recent years.
SWITZERLAND
ANTI-MONEY LAUNDERING / COMBATING TERRORISM FINANCING / COMBATTING PROLIFERATION FINANCING (AML/CFT/CPF)
Le Conseil Fédéral publishes the National Risk assessment on legal entities and legal arrangements / Le Conseil fédéral publie l'évaluation nationale des risques relatifs aux personnes morales et aux constructions juridiques
![]()
On 14 August 2026, the federal council published National Risk Assessment on legal entities and legal arrangements, which assesses the ML/TF risks associated with Swiss and foreign legal entities, trusts and fiduciary arrangements, updates the findings of the 2017 sectoral NRA, and provides recommendations to further strengthen Switzerland's AML/CFT framework. The report incorporates for the first time qualitative data from police authorities, prosecuting authorities and FINMA alongside MROS SAR data.
The report covers Swiss legal entities (AG, GmbH, cooperative, SICAV, SICAF, association, foundation), foreign legal entities with a sufficient link to Switzerland (branch offices, place of effective management, bank accounts), and foreign-law trusts administered in or linked to Switzerland. It is addressed to Swiss authorities, financial intermediaries, advisors and DNFBPs subject to AML/CFT obligations.
Key findings:
- Using a quantitative SAR-based methodology supplemented by qualitative intelligence, the report confirms and updates the 2017 findings:
- Foreign legal entities remain higher risk than Swiss ones (risk index: 2.5 vs 1.6 on a 0–5 scale). Foreign entities more frequently involve domiciliary companies, PEPs, high-risk jurisdictions and large asset amounts. Corruption and serious tax offences are the most prevalent predicate offences for foreign entities.
- Swiss AGs pose the highest domestic risk, being over-represented in SARs relative to their prevalence, due to their internationally oriented, purely capital-based structure. Swiss GmbHs are underrepresented.
- Trusts carry high inherent risk, particularly discretionary trusts with undisclosed or changing beneficiaries used in multi-level, cross-border structures. However, Swiss-supervised commercial trustees are subject to FINMA oversight and AMLA obligations, reducing residual risk.
- Domiciliary companies remain a primary vehicle for ML; around 14.4% of Swiss-domiciled entities reported as suspicious qualify as domiciliary companies. Shell companies, fiduciary arrangements and straw men/women are recurring concealment mechanisms.
- Associations pose low ML risk but elevated TF risk. Foundations carry medium ML/TF risk, with overrepresentation in corruption-related SARs.
- Advisory services (lawyers, notaries, fiduciaries) are identified as key facilitators; very few SARs are submitted by this sector despite their frequent appearance in cases handled by prosecuting authorities. The AMLA revision of September 2025 extends due diligence obligations to certain high-risk advisory activities.
Version française
Le 14 août 2026, le Conseil fédéral a publié l'Évaluation nationale des risques relative aux personnes morales et aux constructions juridiques, qui évalue les risques de blanchiment d'argent et de financement du terrorisme associés aux personnes morales suisses et étrangères, aux trusts et aux constructions fiduciaires, actualise les conclusions de l'évaluation sectorielle de 2017 et formule des recommandations visant à renforcer encore le cadre suisse de lutte contre le blanchiment d'argent et le financement du terrorisme. Le rapport intègre pour la première fois des données qualitatives provenant des autorités de police, des autorités de poursuite pénale et de la FINMA, en plus des données des communications d’opérations suspectes (COS) du MROS.
Le rapport porte sur les personnes morales suisses (SA, Sàrl, coopérative, SICAV, SICAF, association, fondation), les personnes morales étrangères présentant un lien suffisant avec la Suisse (succursales, siège de direction effective, comptes bancaires) et les trusts de droit étranger administrés en Suisse ou liés à la Suisse. Il s’adresse aux autorités suisses, aux intermédiaires financiers, aux conseillers et aux professions non financières soumises aux obligations en matière de lutte contre le blanchiment d’argent et le financement du terrorisme.
Principales conclusions :
- À l’aide d’une méthodologie quantitative fondée sur les déclarations d’opérations suspectes (DOS), complétée par des renseignements qualitatifs, le rapport confirme et actualise les conclusions de 2017 :
- Les personnes morales étrangères présentent toujours un risque plus élevé que les personnes morales suisses (indice de risque : 2,5 contre 1,6 sur une échelle de 0 à 5). Les entités étrangères impliquent plus fréquemment des sociétés de domicile, des personnes politiquement exposées (PPE), des juridictions à haut risque et des montants d’actifs importants. La corruption et les infractions fiscales graves constituent les infractions principales les plus courantes pour les entités étrangères.
- Les SA suisses présentent le risque national le plus élevé ; elles sont surreprésentées dans les déclarations de soupçons (SAR) par rapport à leur prévalence, en raison de leur structure orientée vers l’international et purement capitalistique. Les Sàrl suisses sont sous-représentées.
- Les trusts comportent un risque inhérent élevé, en particulier les trusts discrétionnaires dont les bénéficiaires ne sont pas divulgués ou changent fréquemment, utilisés dans des structures transfrontalières à plusieurs niveaux. Toutefois, les trustees commerciaux soumis à la surveillance suisse sont soumis au contrôle de la FINMA et aux obligations de la LBA, ce qui réduit le risque résiduel.
- Les sociétés de domicile restent un vecteur majeur du blanchiment d’argent ; environ 14,4 % des entités domiciliées en Suisse signalées comme suspectes relèvent de cette catégorie. Les sociétés écrans, les montages fiduciaires et les prête-noms constituent des mécanismes de dissimulation récurrents.
- Les associations présentent un faible risque de blanchiment d’argent, mais un risque élevé de financement du terrorisme. Les fondations présentent un risque moyen de blanchiment d’argent et de financement du terrorisme, et sont surreprésentées dans les déclarations d’opérations suspectes (DOS) liées à la corruption.
- Les services de conseil (avocats, notaires, fiduciaires) sont identifiés comme des facilitateurs clés ; très peu de DOS sont transmises par ce secteur malgré leur présence fréquente dans les affaires traitées par les autorités de poursuite pénale. La révision de la LBA de septembre 2025 étend les obligations de diligence raisonnable à certaines activités de conseil à haut risque.
RECOVERY & RESOLUTION
FINMA welcomes consultation drafts strengthening Switzerland’s “too big to fail” framework / La FINMA salue les projets de consultation visant à renforcer le cadre réglementaire suisse relatif aux établissements « trop grands pour faire faillite »
![]()
On 12 August 2026, FINMA published a press release welcoming the Federal Council's consultation drafts for a legislative package to strengthen Switzerland's "too big to fail" (TBTF) framework, which proposes targeted amendments to the Banking Act and the Liquidity Ordinance to implement measures identified in the Federal Council's TBTF report and the Parliamentary Investigation Committee (PInC) report on the Credit Suisse crisis. FINMA supports the package and advocates for its implementation as a comprehensive set of measures, with particular emphasis on instruments with preventive effect. FINMA notes that it has been seeking new statutory powers since early 2022 and has publicly advocated for the strengthening of its instruments for three years.
Main requirements / proposed measures:
The Federal Council's consultation drafts propose the following categories of measures, which FINMA supports:
- Preventive and disciplinary instruments: Including the power for FINMA to communicate more actively with the public about concluded enforcement proceedings; the introduction of an accountability regime; the ability to impose proportionate corrective measures in the event of imminent breaches of financial market law; and the authority to impose fines.
- Resolution options: Additional resolution tools in the event of a banking crisis.
- Liquidity measures: Proposed changes including Lender of Last Resort (LOLR) preparatory requirements, intended to make it easier for larger banks to access liquidity support in times of stress.
FINMA recommends that all proposed measures be implemented as a comprehensive package to achieve the greatest possible impact on financial centre resilience.
Version française
Le 12 août 2026, la FINMA a publié un communiqué de presse dans lequel elle salue les projets de consultation du Conseil fédéral relatifs à un paquet législatif visant à renforcer le cadre suisse « trop grand pour faire faillite » (TBTF). Ce paquet propose des modifications ciblées de la loi sur les banques et de l’ordonnance sur la liquidité afin de mettre en œuvre les mesures identifiées dans le rapport du Conseil fédéral sur le TBTF et dans le rapport de la commission d’enquête parlementaire (PInC) sur la crise du Credit Suisse. La FINMA soutient ce paquet et plaide en faveur de sa mise en œuvre en tant qu’ensemble complet de mesures, en mettant particulièrement l’accent sur les instruments à effet préventif. La FINMA rappelle qu’elle sollicite de nouvelles compétences légales depuis début 2022 et qu’elle plaide publiquement depuis trois ans en faveur du renforcement de ses instruments.
Principales exigences / mesures proposées :
Les projets de consultation du Conseil fédéral proposent les catégories de mesures suivantes, que la FINMA soutient :
- Instruments préventifs et disciplinaires : notamment la possibilité pour la FINMA de communiquer plus activement avec le public au sujet des procédures d’exécution clôturées ; l’introduction d’un régime de responsabilité ; la possibilité d’imposer des mesures correctives proportionnées en cas de violations imminentes de la législation sur les marchés financiers ; et le pouvoir d’infliger des amendes.
- Options de résolution : outils de résolution supplémentaires en cas de crise bancaire.
- Mesures de liquidité : modifications proposées, notamment des exigences préparatoires relatives au prêteur de dernier recours (LOLR), destinées à faciliter l’accès des grandes banques à un soutien en matière de liquidité en période de tension.
La FINMA recommande que toutes les mesures proposées soient mises en œuvre sous la forme d’un ensemble complet afin d’obtenir le plus grand impact possible sur la résilience de la place financière.
SNB welcomes proposals to strengthen the “too big to fail” framework / La BNS salue les propositions visant à renforcer le dispositif relatif aux établissements « trop grands pour faire faillite »
![]()
On 12 August 2026, the Swiss National Bank (SNB) published a press release welcoming the Federal Council's proposals to strengthen the too big to fail (TBTF) regulatory framework in Switzerland, announced on the same date. The SNB considers the measures decisive in addressing the regulatory gaps revealed by the Credit Suisse crisis and an important step in further reinforcing the stability of the Swiss financial system. The SNB's statement complements the FINMA press release of the same date welcoming the same Federal Council consultation drafts.
The measures primarily target systemically important banks and medium-sized banking institutions in Switzerland. The SNB notes that the broadest possible participation of banks in the preparatory measures is desirable from a financial stability perspective.
The SNB highlights two categories of measures it particularly welcomes:
Liquidity Ordinance, LOLR preparatory requirements: The draft Liquidity Ordinance provides that systemically important banks and medium-sized banking institutions must prepare sufficient collateral to be able to access central bank liquidity support. The SNB notes that it can only provide emergency liquidity assistance if banks are able to transfer assets to it as collateral. The SNB underlines the importance of the broadest possible participation of banks in preparatory arrangements for the Extended Liquidity Facility (ELF — Facilité étendue de liquidités, FEL), which will be made available from the beginning of 2027.
Other Federal Council measures: The SNB also welcomes proposals to improve stabilisation plans and the recovery and resolution capacity of systemically important banks, to strengthen FINMA's early intervention powers, and to enhance cooperation between authorities in the prevention and resolution of financial crises.
The SNB notes that the 12 August 2026 measures, together with those announced by the Federal Council on 22 April 2026, are collectively decisive for improving TBTF regulation and strengthening the resilience of the Swiss financial system.
Version française
Le 12 août 2026, la Banque nationale suisse (BNS) a publié un communiqué de presse saluant les propositions du Conseil fédéral visant à renforcer le cadre réglementaire relatif aux établissements « trop grands pour faire faillite » (TBTF) en Suisse, annoncées le même jour. La BNS considère ces mesures comme décisives pour combler les lacunes réglementaires mises en évidence par la crise du Credit Suisse et comme une étape importante pour renforcer encore la stabilité du système financier suisse. La déclaration de la BNS complète le communiqué de presse de la FINMA publié le même jour, qui saluait les mêmes projets de consultation du Conseil fédéral.
Ces mesures visent principalement les banques d'importance systémique et les établissements bancaires de taille moyenne en Suisse. La BNS souligne que, du point de vue de la stabilité financière, il est souhaitable que le plus grand nombre possible de banques participent aux mesures préparatoires.
La BNS met en avant deux catégories de mesures qu’elle salue tout particulièrement :
Ordonnance sur la liquidité, exigences préparatoires relatives à la LOLR : le projet d’ordonnance sur la liquidité prévoit que les banques d’importance systémique et les établissements bancaires de taille moyenne doivent constituer des garanties suffisantes pour pouvoir accéder au soutien de liquidité de la banque centrale. La BNS souligne qu’elle ne peut fournir une aide d’urgence en matière de liquidités que si les banques sont en mesure de lui transférer des actifs à titre de garantie. La BNS insiste sur l’importance d’une participation aussi large que possible des banques aux dispositions préparatoires relatives à la Facilité étendue de liquidités (ELF — Extended Liquidity Facility, FEL), qui sera mise à disposition dès le début de l’année 2027.
Autres mesures du Conseil fédéral : La BNS salue également les propositions visant à améliorer les plans de stabilisation ainsi que les capacités de redressement et de résolution des banques d’importance systémique, à renforcer les pouvoirs d’intervention précoce de la FINMA et à améliorer la coopération entre les autorités en matière de prévention et de résolution des crises financières.
La BNS constate que les mesures du 12 août 2026, conjuguées à celles annoncées par le Conseil fédéral le 22 avril 2026, sont globalement déterminantes pour améliorer la réglementation «too big to fail» et renforcer la résilience du système financier suisse.
REPORTING
Swiss Official Journal published the ordinance on the data standard for the MROS information system / La Feuille officielle suisse a publié l'ordonnance relative à la norme de données applicable au système d'information du MROS
![]()
On 28 August 2026, the Swiss Federal Police Office (FedPol) published the Ordinance on the Data Standard for the Information System of the Money Laundering Reporting Office (Bureau de communication en matière de blanchiment d'argent, MROS) (ONSBA, RS 955.034.1), adopted on 1 July 2026, which enters into force on 1 October 2026. The ordinance is issued pursuant to Article 23(7) of the Swiss Anti-Money Laundering Act (AMLA, RS 955.0) and establishes binding technical specifications for all persons, authorities and organisations required to exchange information with MROS through its information system (goAML).
The ordinance applies to:
- Persons subject to the AMLA under Article 2(1) AMLA (financial intermediaries including banks, payment institutions, asset managers, insurance companies, casinos, dealers and other obliged entities);
- Audit firms under Article 15 AMLA;
- Swiss authorities under Articles 29(1), 29(2) and 29a AMLA;
- Supervisory organisations and self-regulatory organisations under Article 29b AMLA.
Main requirements:
The ordinance establishes two interconnected obligations:
- Mandatory use of the MROS information system: All persons, authorities and organisations listed above must exchange information with MROS exclusively through its information system (goAML). MROS uses the same system for return communications.
- Technical specifications — XML schema (Annex 2): The XML schema version 2.0.25 must be used for the following communications:
- Suspicious activity reports (SARs) under Article 9(1), (1bis) and (1ter) AMLA;
- Communications under Article 9b(3) AMLA;
- Optional SARs under Article 305ter(2) of the Swiss Criminal Code;
- Communications under Articles 15(5), 16(1), 22b(2) and 27(4) AMLA;
- Communications under Article 7(1) and (2) of the Law on Illicit Assets (SR 196.1), where made by AMLA-obliged persons;
- Information exchanges under Article 11a(1), (2) and (2bis) AMLA (MROS to foreign FIUs and vice versa).
Technical manual (Annex 1): All communications and other information to MROS, as well as authority requests, must comply with the technical specifications in the goAML manual "Standard XML Reporting Instructions and Specifications for goAML", version CH 2.0.24.
Version française
Le 28 août 2026, l'Office fédéral de la police (FedPol) a publié l'ordonnance relative à la norme de données pour le système d'information du Bureau de communication en matière de blanchiment d'argent (MROS) (ONSBA, RS 955.034.1), adoptée le 1er juillet 2026 et qui entrera en vigueur le 1er octobre 2026. Cette ordonnance est édictée en vertu de l’article 23, paragraphe 7, de la loi suisse sur la lutte contre le blanchiment d’argent (LBA, RS 955.0) et établit des spécifications techniques contraignantes pour toutes les personnes, autorités et organisations tenues d’échanger des informations avec le MROS par l’intermédiaire de son système d’information (goAML).
L’ordonnance s’applique :
- aux personnes soumises à la LBA en vertu de l’article 2, paragraphe 1, de la LBA (intermédiaires financiers, notamment les banques, les établissements de paiement, les gestionnaires de fortune, les compagnies d’assurance, les casinos, les courtiers et autres entités assujetties) ;
- aux cabinets d’audit visés à l’article 15 de la LBA ;
- aux autorités suisses visées aux articles 29, paragraphes 1 et 2, et 29a de la LBA ;
- les organismes de surveillance et les organismes d’autorégulation visés à l’article 29b de la LBA.
Principales exigences :
L’ordonnance établit deux obligations interdépendantes :
- Utilisation obligatoire du système d’information du MROS : toutes les personnes, autorités et organisations énumérées ci-dessus doivent échanger des informations avec le MROS exclusivement via son système d’information (goAML). Le MROS utilise ce même système pour les communications en retour.
- Spécifications techniques — schéma XML (annexe 2) : le schéma XML version 2.0.25 doit être utilisé pour les communications suivantes :
- les communications d’activité suspecte (CAS) au titre de l’article 9, alinéas 1, 1bis et 1ter, de la LBA ;
- les communications au titre de l’article 9b, alinéa 3, de la LBA ;
- les SAR facultatifs au sens de l’article 305ter, alinéa 2, du Code pénal suisse ;
- les communications au sens des articles 15, alinéa 5, 16, alinéa 1, 22b, alinéa 2, et 27, alinéa 4, de la LBA ;
- les communications au titre de l’article 7, alinéas 1 et 2, de la loi sur les valeurs patrimoniales illicites (RS 196.1), lorsqu’elles sont effectuées par des personnes assujetties à la LBA ;
- les échanges d’informations au titre de l’article 11a, alinéas 1, 2 et 2bis, de la LBA (du MROS vers les CRF étrangères et inversement).
Manuel technique (annexe 1) : toutes les communications et autres informations adressées au MROS, ainsi que les demandes des autorités, doivent respecter les spécifications techniques figurant dans le manuel goAML « Instructions et spécifications standard de déclaration XML pour goAML », version CH 2.0.24.
UNITED KINGDOM
LIQUIDITY RISK
FCA publishes final rules to strengthen liquidity risk management for UK retail investment funds
![]()
On 13 August 2026, FCA published Policy Statement PS26/17, Enhancing Fund Liquidity Risk Management, setting out final rules and guidance to strengthen liquidity risk management for UK UCITS schemes and Non-UCITS Retail Schemes (NURS).
The changes follow Consultation Paper CP25/38 and are designed to improve investor protection, market integrity and the resilience of open-ended investment funds by aligning the UK framework with updated international standards from IOSCO and the Financial Stability Board.
A key element of the reforms is the requirement for authorised fund managers (AFMs) to have anti-dilution tools (ADTs) available for use and supported by documented policies and procedures. The FCA expects firms to assess dilution risks at each valuation point and use appropriate mechanisms, such as swing pricing, dilution levies, dilution adjustments or dual-pricing arrangements, when dilution poses a material risk to investors. The reforms also introduce expectations on the calibration of these tools, including consideration of both explicit and implicit liquidity costs and annual retrospective reviews of their effectiveness in ensuring fair treatment of investors.
The FCA is also strengthening liquidity risk management requirements by removing the assumption that a listed security is automatically sufficiently liquid, requiring AFMs to perform more robust assessments of transferable securities. In response to consultation feedback, the FCA retained an exemption for recently issued securities but shortened the period for obtaining admission to an eligible market from one year to 20 business days. The policy statement additionally incorporates revised liquidity stress testing guidance, based on ESMA standards, and introduces a new annex outlining good liquidity risk management practices, governance expectations and the alignment of fund redemption terms with underlying asset liquidity.
The new rules will come into force on 1 February 2027, with certain transitional provisions applying until 1 August 2027.
REPORTING
FCA publishes PS26/15 on improving the UK transaction reporting regime
![]()
On 3 August 2026, the Financial Conduct Authority (FCA) published Policy Statement PS26/15: Improving the UK Transaction Reporting Regime, which sets out final rules and guidance amending the UK MiFIR transaction reporting framework, following Consultation Paper CP25/32. The changes are designed to make reporting obligations more accurate, proportionate and cost-effective while preserving data quality for market abuse surveillance, market monitoring and supervisory purposes.
HM Treasury plans to repeal the underlying UK MiFIR transaction reporting legislation, enabling delivery of the new streamlined framework. The changes are expected to deliver annual savings of over £100 million for firms, reducing the total annual cost of MiFID transaction reporting from £493 million to approximately £385 million.
The policy statement affects investment firms, operators of trading venues, approved reporting mechanisms (ARMs) and other market participants involved in submitting transaction reports, instrument reference data and order book data. The changes are not aimed at consumers.
Seven targeted changes are introduced:
- Reporting fields: Reduced from 65 to 52, simplifying reporting systems and improving consistency in field population.
- EU-only instruments: Reporting obligations removed for approximately 7 million financial instruments tradeable only on EU trading venues, saving firms approximately £32 million annually.
- FX derivatives: Removed from the scope of transaction reporting requirements, reducing costs for over 400 UK firms.
- Back reporting period: Default period for correcting historical reporting errors reduced from 5 to 3 years, lowering resubmission volumes by approximately one third.
- Corporate actions: Most corporate actions exempted from reporting obligations.
- Trading venue obligations: Trading venues required to populate fewer fields in their transaction reports, simplifying information provided by over 2,200 international firms accessing UK financial markets.
- Conditional Single-Sided Reporting (CSSR): A new CSSR framework is created.
UNITED STATES
DIGITAL ASSETS
SEC Proposes New Regulation Crypto Assets
![]()
On 18 August 2026, the U.S. Securities and Exchange Commission (SEC) published a proposal for “Regulation Crypto Assets,” which would establish a tailored securities offering framework for certain investment contracts involving crypto assets and clarify the circumstances in which crypto assets may cease to be subject to an investment contract under U.S. federal securities laws.
The proposal follows the SEC’s March 2026 interpretation on the application of federal securities laws to crypto assets and related transactions. It seeks to facilitate capital formation in U.S. crypto-asset markets while maintaining investor protections.
The proposed rules would introduce two exemptions from the registration requirements of the Securities Act of 1933. The first would provide a one-time exemption for offerings of up to USD 5 million over a four-year period. The second would permit offerings of up to USD 75 million during each 12-month period. Issuers relying on either exemption would be required to provide investors with specified principles-based narrative disclosures. Issuers using the second exemption would additionally be required to provide financial statements and ongoing reporting.
The proposal would also establish a conditional safe harbor from the term “investment contract” within the definitions of “security” under the Securities Act of 1933 and the Securities Exchange Act of 1934. Where the applicable conditions are met, a crypto asset would be deemed not to be subject to an investment contract for purposes of those definitions. The SEC indicates that this could apply once an issuer has completed or permanently ceased the essential managerial efforts represented or promised under the investment contract.
In addition, the proposal would preempt certain state securities registration and qualification requirements for securities offered under Regulation Crypto Assets and for certain secondary-market transactions.
The proposal is subject to consultation. The public comment period will remain open for 60 days following publication of the proposing release in the Federal Register.
CONTACTS
This publication is produced by the Group Regulatory Watch Team with the collaboration of experts from the Legal Department and the Compliance Department of CACEIS entities, together with the close support of the Communications Department.
Editor
Gaëlle Kerboeuf, Group Regulatory Watch Senior Expert
Permanent Editorial Committee
Gaëlle Kerboeuf, Group Regulatory Watch Senior Expert
Corinne Brand, Group Content Manager
Local
François Honnay, Head of Legal (Belgium)
Fanny Thomas, Head of Legal Client Contracts (France)
Aude Levant, Group Compliance
Jeanne Laurent, Head of Unit - Business Compliance
Stefan Ullrich, Head of Legal (Germany)
Costanza Bucci, Head of Legal & Compliance (Italy)
Luciana Vertulli, Compliance Officer (Italy)
Fernand Costinha, Group Head, Legal (Luxembourg)
Julien Fetick, Senior Financial Lawyer (Luxembourg)
Gérald Stadelmann, Head of Legal (Luxcellence Luxembourg)
Alessandra Cremonesi, Head of Legal (Switzerland)
Puck Kranénburg (The Netherlands)
Raymond Boddenberg (The Netherlands)
Robin Donagh, Head of Legal (Ireland)
Olga Kitenge, Legal, Risk & Compliance (UK)
Katherine Petcher, Group Head, Legal (Common Law Countries)
Beatriz Sanchez Jete, Compliance (Spain)
Jessica Silva, Compliance (Brazil)
Luiz Fernando Silva, Compliance (Brazil)
Libia Andrea Carvajal, Compliance (Colombia)
Daiana Garcia, Compliance (Colombia)
Karim Martínez, Compliance (Mexico)
Edgar Zugasti, Compliance (Mexico)
Design
CACEIS Group Communications
Photos credit
CACEIS, Adobe Stock
CACEIS
89-91 rue Gabriel Péri
92120 Montrouge