July 2026
CONTENT
EUROPEAN UNION
ANTI-MONEY LAUNDERING / COMBATING TERRORISM FINANCING / COMBATTING PROLIFERATION FINANCING (AML/CFT/CPF)
AMLA publishes consultation on draft ITS on the format for reporting suspicions and providing transaction records
![]()
On 2 July 2026, the Anti-Money Laundering Authority (AMLA) published a press release announcing a public consultation on draft technical standards establishing a common EU format for reporting suspicions and providing transaction records. The initiative aims to harmonise reporting practices across Member States and support a more consistent approach to the fight against financial crime throughout the European Union.
According to AMLA, current reporting requirements vary significantly between jurisdictions, creating operational complexity for entities operating cross-border and limiting the effectiveness of information exchange between Financial Intelligence Units (FIUs). The proposed standards seek to address these challenges by introducing common templates and harmonised data requirements for reporting suspicions and related transaction records.
Under the proposed framework, entities subject to anti-money laundering obligations would report information using a common set of standardised data fields across the EU. Reporting entities would only be required to complete the data points relevant to their business activities and the specific type of suspicion being reported. AMLA states that this approach is intended to accommodate sector-specific characteristics while ensuring a consistent reporting framework at EU level.
For reporting entities, AMLA expects the initiative to improve clarity and consistency, particularly for organisations operating in multiple Member States. For FIUs, the use of standardised reporting formats is intended to facilitate the receipt of more structured and comparable information, supporting more efficient analysis and information-sharing processes.
AMLA has invited feedback from stakeholders across both the financial and non-financial sectors, as well as from competent authorities and European and international organisations. A public hearing on the draft standards is scheduled for 9 September 2026, and interested parties are encouraged to participate in the consultation process and submit comments on the proposed framework.
The consultation represents an early stage in the development of harmonised EU reporting standards and seeks stakeholder input on the proposed common format before the standards are finalised.
AMLA publishes Final Report on draft ITS for cooperation within the AML/CFT supervisory system for direct supervision
![]()
On 21 July 2026, the Anti-Money Laundering Authority (AMLA) published a Final Report containing draft Implementing Technical Standards (ITS) under Article 15(3) of Regulation (EU) 2024/1620 (AMLAR) which establish detailed procedures for cooperation between AMLA and national AML/CFT financial supervisors in the context of AMLA's direct supervision regime.
The draft ITS support the implementation of the EU AML supervisory framework under which AMLA will directly supervise selected high-risk cross-border financial institutions from 2028. The standards set out operational arrangements governing cooperation between AMLA and national supervisors throughout the direct supervision lifecycle.
The ITS cover five main areas:
(i) general cooperation requirements, including obligations to cooperate in good faith, information exchange and use of secure communication channels;
(ii) the periodic assessment and selection process for entities eligible for direct AMLA supervision;
(iii) procedures for notifying and publishing decisions on selected obliged entities;
(iv) arrangements for transferring supervisory tasks and powers between national supervisors and AMLA;
(v) the composition and functioning of Joint Supervisory Teams (JSTs).
The framework introduces a sequential selection process under which national supervisors collect eligibility information and risk-related data, perform quality checks and transmit information to AMLA, while AMLA conducts risk assessments and determines which entities will be selected for direct supervision.
The ITS also establish timelines for data collection and reporting, procedures for publication of selected entities, requirements for maintaining supervisory continuity during transfers of responsibility, and rules supporting information sharing within JSTs.
The final report highlights AMLA's objective of balancing legal certainty with proportionality and operational flexibility. Following consultation feedback, AMLA introduced measures intended to reduce reporting burdens, including exemptions from eligibility data collection where supervisors can reliably determine that entities are not eligible. The draft ITS will now be submitted to the European Commission for adoption and subsequent publication in the Official Journal.
AMLA publishes Final Report on draft RTS on pecuniary sanctions, administrative measures and periodic penalty payments under AMLD6
![]()
On 8 July 2026, the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) published a Final Report containing draft Regulatory Technical Standards (RTS) under Article 53(10) of Directive (EU) 2024/1640, which specify indicators for classifying the gravity of AML/CFT breaches, criteria for determining pecuniary sanctions and administrative measures, and a methodology for imposing periodic penalty payments.
The draft RTS establish a harmonised EU framework for AML/CFT enforcement applicable across both financial and non-financial sectors. Supervisors will follow a three-step approach. First, they must assess breaches using common indicators including duration, repetition, conduct, impact, exposure to money laundering and terrorist financing risks, structural failures, and effects on financial stability. Second, breaches must be classified into one of four severity categories. Third, supervisors must apply common criteria when determining sanctions or administrative measures. Breaches classified as category three or four are deemed serious, repeated or systematic within the meaning of the AMLD.
The RTS provide criteria for increasing or decreasing pecuniary sanctions, taking into account factors such as cooperation with supervisors, remedial actions, intentionality, benefits derived from the breach, losses caused to third parties, and previous compliance history. They also introduce common criteria for applying severe administrative measures, including business restrictions, withdrawal or suspension of authorisation, and governance changes.
In addition, the RTS establish procedural requirements for periodic penalty payments (PePPs), a new AML/CFT enforcement tool intended to compel compliance with administrative measures. The standards set out requirements relating to the right to be heard, decision-making processes, payment calculations, and limitation periods.
Following public consultations conducted by the EBA in 2025 and AMLA in 2026, the Final Report will be submitted to the European Commission for adoption and subsequent publication in the Official Journal of the European Union. The draft RTS provide that the regulation would apply from 10 July 2027, with a deferred application date of 10 July 2029 for football clubs and football agents.
EDPB publishes news on development of Joint Guidelines on AML information-sharing partnerships
![]()
On 1 July 2026, the European Data Protection Board (EDPB) published the news item “EDPB and AMLA to develop Joint Guidelines on partnerships for information sharing”, which announces a joint initiative between the EDPB and the Anti-Money Laundering Authority (AMLA) to develop Joint Guidelines on information-sharing partnerships in the context of anti-money laundering and counter-terrorist financing efforts.
The publication explains that cooperation and information sharing are important tools in detecting and preventing money laundering and terrorist financing. It notes that Article 75 of the AML Regulation allows entities subject to anti-money laundering requirements to share information with one another and with public authorities, within defined limits. According to the publication, this new information-sharing framework will become applicable from 10 July 2027.
The EDPB and AMLA state that because such information sharing involves the processing of personal data, appropriate data protection safeguards are essential. The planned Joint Guidelines are intended to provide practical clarification on how information-sharing partnerships can be structured so that the objective of combating financial crime is balanced with the protection of personal data. The Guidelines are expected to provide greater clarity for private-sector entities, supervisory authorities, Financial Intelligence Units (FIUs), and data protection authorities regarding the establishment and operation of such partnerships.
The publication further indicates that stakeholder engagement will form part of the development process. The EDPB and AMLA plan to organise a stakeholder event later in 2026 to gather views on areas requiring clarification. They also intend to launch a public consultation on draft Guidelines during the first half of 2027. A joint drafting team composed of representatives from both authorities will lead the work, with additional information on the scope and content of the Guidelines to be provided as the project progresses.
ARTIFICIAL INTELLIGENCE
European Parliament and Council publish EU Regulation amending the AI Act (Digital Omnibus on AI)
![]()
BACKGROUND
On 24 July 2026, the Official Journal of the European Union published Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 (AI Act), Regulation (EU) 2018/1139 on civil aviation and Regulation (EU) 2023/1230 on machinery. The Regulation introduces targeted amendments to simplify the implementation of the EU artificial intelligence framework, reduce administrative burdens and increase legal certainty while maintaining the level of protection for health, safety and fundamental rights.
The amendments concern providers, deployers and other operators of AI systems subject to the AI Act, including SMEs and small mid-cap enterprises, as well as high-risk AI systems falling within the relevant product safety and sectoral frameworks.
WHAT'S NEW?
Proportionality and high-risk AI requirements
The Regulation clarifies the definition of a safety component and introduces additional proportionality measures for SMEs and SMCs. It also simplifies technical documentation and quality management requirements and provides mechanisms to limit duplication where equivalent or higher requirements already exist under sector-specific Union harmonisation legislation.
AI literacy and bias detection
The AI literacy obligation is revised so that providers and deployers must take measures to support the development of AI literacy rather than guarantee a specific level. The Regulation also extends the legal basis for processing special categories of personal data for bias detection and correction, subject to specified safeguards.
Prohibited AI practices and supervision
New prohibitions cover certain AI systems generating or manipulating non-consensual intimate material and child sexual abuse material. The Regulation also:
- strengthens the supervisory and enforcement powers of the AI Office;
- clarifies the allocation of supervisory competences;
- expands AI regulatory sandboxes and real-world testing arrangements.
WHAT'S NEXT?
The application of requirements for high-risk AI systems under Article 6(2) and Annex III is postponed to 2 December 2027.
For high-risk AI systems under Article 6(1) and Annex I, the relevant requirements will apply from 2 August 2028.
The Regulation also mandates further Commission guidance and delegated acts and provides for transitional arrangements for generative AI providers.
DEPOSIT GUARANTEE
EBA publishes Consultation Paper on Draft Guidelines on Investment of Available Financial Means under DGSD3
![]()
On 23 July 2026, the European Banking Authority (EBA) published a Consultation Paper on Draft Guidelines on Investment of Available Financial Means under Directive 2014/49/EU on Deposit Guarantee Schemes, as amended by DGSD3, which proposes a harmonised framework for how Deposit Guarantee Schemes (DGSs) should invest, diversify, manage liquidity, and govern the investment of their available financial resources.
The draft Guidelines are developed pursuant to Article 10(13) of DGSD3, which mandates the EBA to provide guidance on the diversification of DGS funds and investment in low-risk assets. The proposals aim to ensure that DGS funds remain immediately available for depositor reimbursements, resolution actions, preventive measures and other interventions under the revised depositor protection framework.
The consultation introduces minimum standards for DGS investment strategies, requiring formal documentation, governance arrangements, monitoring processes, liquidity management mechanisms and regular reviews. DGSs would be expected to establish diversification frameworks based on at least two criteria, including issuer, geography, maturity, duration, asset class or ESG factors, while a risk-based "comply or explain" approach would allow justified deviations.
The Guidelines further require DGSs to assess low-risk assets against their liquidity objectives and to conduct regular liquidity stress testing. Where stress-testing identifies liquidity shortfalls, DGSs would need to maintain at least one liquidity mechanism, such as repo facilities, collateralised loans, asset-backed credit lines or similar arrangements, to ensure timely access to funds.
In addition, the draft framework introduces governance requirements where implementation of the investment strategy is delegated to third parties, including delegation policies, oversight arrangements, monitoring processes and accountability provisions.
The consultation remains open until 23 October 2026, with a public hearing scheduled for 24 September 2026. Following the consultation, the EBA will assess stakeholder feedback and finalise the Guidelines. The draft Guidelines are proposed to apply from 11 May 2028.
DIGITAL OPERATIONAL RESILIENCE
European Parliament publishes amendments to draft report on the Digital Omnibus Regulation
![]()
On 27 July 2026, the European Parliament Committee on Industry, Research and Energy (ITRE) and Committee on Civil Liberties, Justice and Home Affairs (LIBE) published Amendments 1741–1840 to the Draft Report on the Proposal for a Regulation amending several EU digital acts (Digital Omnibus), which proposes changes to the Commission’s Digital Omnibus proposal and the related amendments to NIS2, DORA, eIDAS, the CER Directive, the AI Act and other digital legislation.
The amendments focus primarily on the proposed creation of a cybersecurity incident reporting “single-entry point” managed by ENISA and the harmonisation of reporting obligations across multiple EU legal frameworks. Various amendments seek to clarify the respective roles of ENISA, national authorities and national reporting portals, including proposals requiring Member States to establish national single-entry points and ensure interoperability among them.
Several amendments also propose harmonised incident reporting templates, common technical standards, common reporting taxonomies, streamlined reporting procedures and mechanisms to reduce duplicative reporting obligations across different EU laws.
The amendments further address incident reporting under NIS2, DORA, eIDAS, the Critical Entities Resilience (CER) Directive, the Cyber Resilience Act (CRA) and the AI Act. Some proposals would allow a single notification to satisfy multiple reporting obligations, while others introduce requirements concerning interoperability, reporting deadlines, technical specifications, reporting formats, incident classifications and supervisory coordination. Several amendments also address governance arrangements, stakeholder consultation, security measures, cross-border reporting and the concept of a “main establishment” for cybersecurity reporting purposes.
In addition, a number of amendments challenge or modify the Commission’s proposed repeal of certain digital legislation, including Regulation (EU) 2019/1150 (Platform-to-Business Regulation), Regulation (EU) 2022/868 (Data Governance Act), Regulation (EU) 2018/1807 and Directive (EU) 2019/1024. These amendments form part of the European Parliament’s ongoing consideration of the proposed Digital Omnibus Regulation and do not constitute final legislative text.
GOVERNANCE & ORGANISATION
ESMA publishes Common Supervisory Action on the risk management function of UCITS management companies and AIFMs
![]()
On 3 July 2026, the European Securities and Markets Authority (ESMA) published a communication launching a Common Supervisory Action (CSA) on the risk management function of UCITS management companies and Alternative Investment Fund Managers (AIFMs), to be conducted across the European Union in cooperation with National Competent Authorities (NCAs) throughout 2026 and 2027.
The objective of the CSA is to assess how market participants comply with key risk-management requirements under the UCITS and AIFMD frameworks. In particular, the exercise will evaluate the effectiveness, independence and expertise of the risk management function within UCITS management companies and AIFMs.
ESMA highlights that risk management is a core component of investor protection and financial stability. The function is expected to ensure that material risks, including market, credit, liquidity, counterparty and operational risks, are properly identified, measured, monitored and managed.
During the supervisory exercise, NCAs will focus on three main areas:
- Governance and organisation of the risk management function;
- Risk identification, measurement and monitoring processes; and
- Reporting arrangements to senior management and governing bodies.
The CSA will be based on a common assessment framework developed by ESMA. The framework establishes the scope, methodology, supervisory expectations and timeline for the exercise, with the objective of promoting a convergent supervisory approach across the European Union.
Throughout the exercise, NCAs will exchange supervisory experiences and findings through ESMA to support supervisory convergence and improve oversight of risk management functions across the investment management sector. ESMA states that it intends to publish a final report on the results of the exercise in 2028.
MARKET ABUSE
European Commission publishes Delegated Regulation amending MAR delegated rules on closed periods, market abuse supervision and market manipulation indicators
![]()
On 16 July 2026, the Official Journal of the European Union published Commission Delegated Regulation (EU) 2026/788, which amends Delegated Regulation (EU) 2016/522 supplementing the Market Abuse Regulation (MAR).
The Delegated Regulation updates provisions concerning permission for trading during closed periods, the designation of trading venues with a significant cross-border dimension for market abuse supervision, and indicators of market manipulation.
The Regulation aligns Delegated Regulation (EU) 2016/522 with amendments introduced by Regulation (EU) 2024/2809. In particular, it extends existing provisions governing exemptions from MAR closed-period trading restrictions to cover financial instruments other than shares. Persons discharging managerial responsibilities (PDMRs) seeking to trade during a closed period must submit a reasoned written request to the issuer, explaining why the sale of shares or other financial instruments is the only reasonable means of obtaining necessary financing. Issuers must assess such requests on a case-by-case basis and may grant permission only where circumstances are considered exceptional.
The Regulation also introduces a new Annex III identifying trading venues deemed to have a significant cross-border dimension in the supervision of market abuse with respect to shares. The designated venues are Aquis Exchange Europe, TP ICAP (Europe) SA, Cboe Europe B.V., and Turquoise Global Holdings Europe B.V. The designation supports the MAR framework requiring competent authorities to establish mechanisms for ongoing exchange of order data relating to cross-border market abuse supervision.
In addition, the Regulation updates Annex II on market manipulation indicators. The amendments clarify that supervisory assessments may be conducted over periods longer or shorter than a trading day or session, particularly for less liquid instruments and algorithmic trading environments. The Regulation further expands guidance relating to significant volume changes, indirect economic exposures, position reversals, layering and spoofing practices, and other market manipulation indicators in order to support more consistent supervisory application.
The Regulation enters into force on the twentieth day following its publication in the Official Journal of the European Union.
OPERATIONAL RISK
ECB publishes final results of 2026 geopolitical risk reverse stress test
![]()
On 31 July 2026, the European Central Bank (ECB) published the final results of the "Geopolitical risk reverse stress test of euro area banks – 2026 SSM thematic stress test", which assessed the ability of 110 significant institutions directly supervised by the ECB to identify and evaluate severe geopolitical scenarios capable of materially reducing their capital positions.
The exercise forms part of the ECB's supervisory priority on geopolitical risk for 2026-2028 and aimed to enhance banks' forward-looking risk management, stress-testing capabilities, capital planning and recovery planning under conditions of elevated geopolitical uncertainty. Rather than applying a common adverse scenario, the ECB required each participating bank to design its own plausible geopolitical reverse stress test scenario capable of generating at least a 300 basis point depletion of its Common Equity Tier 1 (CET1) ratio.
Participating institutions developed a broad range of scenarios involving military conflicts, energy and supply chain disruptions, trade restrictions, sanctions, cyberattacks, political instability and macroeconomic shocks. Banks were required to assess the transmission of these events through financial market, real economy and safety/security channels, as well as their impact on solvency, liquidity and non-financial risks.
The ECB concluded that banks generally demonstrated the capability to produce economically meaningful scenarios reflecting their individual risk profiles and vulnerabilities. However, the exercise identified several weaknesses in stress-testing frameworks, including insufficient granularity and sensitivity of risk assessments, inconsistencies between scenario narratives and risk impacts, unrealistic assumptions regarding mitigating management actions, inadequate treatment of solvency-liquidity interactions, and shortcomings in modelling liquidity and foreign-exchange funding stress.
The ECB also highlighted the importance of incorporating operational resilience and cyber risk considerations into stress-testing frameworks. Cyber incidents and disruption of third-party services emerged as the most frequently identified non-financial risks.
Results will feed into ongoing supervisory dialogue and may inform qualitative assessments within the Supervisory Review and Evaluation Process (SREP). The exercise itself will not lead to changes in Pillar 2 Guidance or leverage ratio Pillar 2 Guidance.
OTHER - CAPITAL MARKETS
EC publishes Delegated Regulation amending EMIR clearing thresholds and review mechanisms
![]()
BACKGROUND
On 14 July 2026, the European Commission adopted a Commission Delegated Regulation amending Delegated Regulation (EU) No 149/2013 as regards clearing thresholds and the mechanisms triggering their review. The Regulation supplements Regulation (EU) No 648/2012 on OTC derivatives, central counterparties and trade repositories (EMIR), as amended by Regulation (EU) 2024/2987 (EMIR 3).
EMIR 3 introduced changes to the clearing threshold framework, including an aggregate clearing threshold for financial counterparties and a revised methodology for calculating uncleared positions. The Delegated Regulation, based on draft regulatory technical standards submitted by the European Securities and Markets Authority (ESMA) on 25 February 2026, specifies the values of the aggregate and uncleared clearing thresholds and establishes mechanisms for their review. The thresholds apply, as relevant, to financial and non-financial counterparties subject to the EMIR clearing obligation.
WHAT'S NEW?
Aggregate clearing thresholds
For financial counterparties, the Regulation introduces clearing thresholds for aggregate OTC derivative positions in asset classes subject to the clearing obligation:
- OTC credit derivatives: EUR 1 billion in gross notional value.
- OTC interest rate derivatives: EUR 3 billion in gross notional value.
Uncleared position thresholds
The Regulation recalibrates thresholds applicable to uncleared OTC derivative positions:
- Credit: EUR 0.8 billion; equity: EUR 0.7 billion; interest rate: EUR 2.2 billion.
- Foreign exchange: EUR 3 billion.
- Commodity and emission allowance derivatives combined: EUR 4 billion.
Threshold review mechanism
ESMA must assess, at least annually, indicators including underlying prices and volatility, clearing rates, the proportion of entities clearing OTC derivatives, inflation, global financial conditions, and geopolitical and economic policy uncertainty. Where ESMA identifies significant changes in these indicators, it must initiate a review of the aggregate and uncleared clearing thresholds in accordance with EMIR.
The existing criteria in Article 10 of Delegated Regulation (EU) No 149/2013 for identifying OTC contracts objectively measurable as reducing risks remain unchanged.
WHAT'S NEXT?
The Delegated Regulation will enter into force on the 20th day following its publication in the Official Journal of the European Union.
No separate application or transitional date is specified. The Regulation will be binding in its entirety and directly applicable in all Member States following its entry into force.
ESMA will assess the specified indicators at least annually and initiate a review of the clearing thresholds where significant changes are identified.
OTHER - PRUDENTIAL REQUIREMENTS
EBA publishes Final Report on RTS and ITS for material acquisitions, material transfers, mergers and divisions
![]()
On 17 July 2026, the European Banking Authority (EBA) published a Final Report on Draft Regulatory Technical Standards (RTS) and Draft Implementing Technical Standards (ITS) which specifies the prudential framework for material acquisitions, material transfers of assets or liabilities, mergers and divisions under CRD6.
The report delivers draft RTS and ITS mandated by Directive (EU) 2024/1619 (CRD6), establishing a harmonised EU framework for notifications, assessments and supervisory cooperation relating to these prudentially material transactions. The RTS set out the minimum information that institutions must provide, the assessment methodologies to be applied by competent authorities, and the procedures governing notifications and prudential assessments. The ITS establish common procedures, forms and templates for consultation between competent authorities involved in reviewing such transactions.
The RTS are structured into four chapters covering material acquisitions, material transfers, mergers and divisions. The framework introduces harmonised methodologies for determining materiality thresholds, including a 15% eligible capital threshold for material acquisitions and specific thresholds for material transfers. To prevent avoidance of notification requirements, transactions executed within a 12‑month period must be aggregated when assessing materiality.
A key feature of the framework is proportionality. The RTS provide simplified information requirements and assessment approaches for intra-group transactions, institutional protection schemes and certain smaller or less complex mergers. The standards also allow competent authorities to rely on information already available through supervisory processes and on documentation prepared under the Company Law Directive.
For material acquisitions, mergers and divisions, assessments focus on ongoing compliance with prudential requirements, governance arrangements, business model sustainability, financial forecasts and AML/CFT considerations. The ITS further define consultation processes among supervisory authorities, including joint-decision mechanisms where consolidated and solo supervisors are both involved.
The draft RTS and ITS will now be submitted to the European Commission for endorsement, followed by scrutiny by the European Parliament and Council before publication in the Official Journal of the European Union.
ECB publishes Guide on the Internal Capital Adequacy Assessment Process (ICAAP)
![]()
On 15 July 2026, the European Central Bank (ECB) published the ECB Guide to the Internal Capital Adequacy Assessment Process (ICAAP), which sets out the ECB’s supervisory expectations regarding how significant institutions should implement, maintain and govern their ICAAP frameworks under Article 73 of the Capital Requirements Directive (CRD). The Guide is intended to provide transparency on the ECB’s interpretation of ICAAP requirements and to promote consistent supervisory practices across the Single Supervisory Mechanism (SSM).
The Guide establishes seven supervisory principles that the ECB considers when assessing ICAAPs within the Supervisory Review and Evaluation Process (SREP). These principles cover governance and management body responsibilities, integration of ICAAP into the overall management framework, maintenance of capital adequacy through both economic and normative perspectives, comprehensive risk identification, internal capital definitions, risk quantification methodologies, and stress testing.
The Guide emphasizes that institutions should operate ICAAPs based on two complementary perspectives. The normative perspective assesses a bank’s ability to meet regulatory and supervisory capital requirements over a multi-year horizon, while the economic perspective assesses whether internal capital adequately covers all material risks from an economic value viewpoint. The ECB expects both perspectives to inform one another and be integrated into strategic decision-making, risk management, capital planning, recovery planning, and risk appetite frameworks.
The Guide sets expectations regarding management body accountability, including annual approval of key ICAAP elements and issuance of a Capital Adequacy Statement (CAS). It also outlines requirements for annual risk identification processes, maintenance of risk inventories, prudent internal capital definitions, independent validation of risk quantification methodologies, robust data quality frameworks, and regular stress testing, including reverse stress testing.
The Guide applies to significant supervised credit institutions within the SSM and follows a principles-based approach. It does not replace applicable legislation and acknowledges that implementation remains the responsibility of each institution, subject to proportionality based on the nature, scale and complexity of its activities. The ECB states that the Guide will be updated periodically to reflect supervisory experience and regulatory developments.
PAYMENTS
ECB publishes in the Official Journal of the EU its Decision amending TARGET-ECB terms and conditions for TIPS instant payments and liquidity management.
![]()
On 24 July 2026, the Official Journal of the European Union published Decision (EU) 2026/1754 of the European Central Bank, which amends Decision (EU) 2022/911 concerning the terms and conditions of TARGET-ECB and repeals Decision ECB/2007/7.
The Decision updates the contractual and operational framework governing TARGET-ECB to reflect amendments previously introduced into the TARGET Guideline. The changes primarily concern the TARGET Instant Payment Settlement (TIPS) service, liquidity management functionalities, participation requirements, and fee arrangements.
A key amendment introduces support within TIPS for the European Payments Council's SEPA One-Leg Out Instant Credit Transfer (OCTs Inst) scheme, allowing participants to send and receive relevant instant payments from 14 November 2026. The Decision incorporates participation and adherence requirements for TIPS participants, reachable parties and ancillary systems wishing to use the OCTs Inst functionality. It also updates definitions, messaging requirements and operational procedures associated with these payments.
The Decision additionally introduces rule-based liquidity transfer orders, enabling participants to define floor and ceiling limits on accounts and automate liquidity movements between Main Cash Accounts (MCAs), RTGS Dedicated Cash Accounts (RTGS DCAs) and TIPS Dedicated Cash Accounts (TIPS DCAs) when predefined thresholds are breached. The changes are intended to support more efficient liquidity management within TARGET.
Further amendments revise TARGET-ECB account and settlement provisions, update the treatment of instant payment orders and recall responses, amend TIPS directory information requirements, and modify technical messaging specifications. The Decision also updates the pricing structure applicable to RTGS DCA holders and confirms charging arrangements for TIPS transactions.
The Decision enters into force on the fifth day following publication in the Official Journal of the European Union, while a number of provisions related to OCTs Inst participation and associated TIPS functionality apply from 14 November 2026.
RECOVERY & RESOLUTION
SRB publishes Operational Guidance on the Business Reorganisation Plan Analysis Report
![]()
On 30 July 2026, the Single Resolution Board (SRB) published the document Operational Guidance on the Business Reorganisation Plan Analysis Report (Version 1.1), which provides operational guidance for banks to develop and maintain capabilities to prepare Business Reorganisation Plans (BRPs) following the application of the open-bank bail-in (OBBI) resolution tool. The guidance aims to support institutions in demonstrating their ability to restore long-term viability after resolution and to meet existing resolution planning expectations.
The document explains how institutions should prepare a Business Reorganisation Plan Analysis Report (BRP AR), a preparatory document intended to evidence governance arrangements, operational readiness, business reorganisation capabilities and the institution's capacity to restore viability following resolution. The guidance is designed to support implementation of requirements stemming from the Bank Recovery and Resolution Directive (BRRD), the Single Resolution Mechanism Regulation (SRMR), related RTS, and existing EBA and SRB guidance.
The guidance establishes expectations regarding governance arrangements, stakeholder responsibilities, operational processes, scenario design, identification of recovery options and other reorganisation measures, implementation timelines, assessment of constraints, and financial impact analysis. Institutions are expected to identify a "Core Bank" representing the minimum viable activities and business lines to be preserved following resolution and to develop a catalogue of business reorganisation measures that could support post-resolution viability.
The document also introduces expectations regarding the determination of Maximum Reorganisation Capacity (MRC), requiring institutions to assess compatible reorganisation measures, develop implementation roadmaps, prepare financial projections, conduct sensitivity analyses, and demonstrate post-OBBI long-term viability within a maximum five-year reorganisation period. Viability assessments are expected to consider profitability, cost efficiency, prudential compliance, capital and liquidity positions.
The guidance is explicitly described as operational guidance and is not legally binding. It does not amend existing legal requirements but seeks to promote convergence of practices and support resolution readiness within the Banking Union. Institutions are expected to implement the guidance within their normal resolution planning cycle and update BRP ARs when material changes occur.
REPORTING
EBA publishes draft technical package on Reporting Framework 4.4 covering IFRS 18 reporting, Pillar 3 ESG disclosures and technical reporting amendments
![]()
On 24 July 2026, the European Banking Authority (EBA) published the draft technical package for version 4.4 of its reporting and disclosure framework, which introduces technical specifications and reporting updates relating to IFRS 18 reporting, Pillar 3 ESG disclosures, Fundamental Review of the Trading Book (FRTB) disclosures, resolution planning, AMLA reporting requirements, and other technical amendments.
The draft package includes validation rules, the Data Point Model (DPM), XBRL taxonomies and a draft glossary intended to support institutions in preparing for forthcoming reporting and disclosure requirements before publication of the final package in September 2026.
Key elements of the package include:
Amendments to the Implementing Technical Standards (ITS) on Pillar 3 disclosures concerning ESG risks, equity exposures and aggregate exposure to shadow banking entities, with a first reference date of 31 December 2026 (or 31 December 2027 for SNCIs).
Introduction of new FINREP templates aligned with IFRS 18, with a first reference date of 31 March 2027.
Integration of FRTB-related disclosure templates into the DPM, with a first reference date of 31 March 2027.
Technical amendments to the DPM and taxonomy related to resolution planning, MREL decisions and Pillar 3 disclosures, with a first reference date of 31 December 2026.
Introduction of DPM and taxonomy requirements for AMLA eligibility templates, with a first reference date of 31 December 2026.
The EBA stated that the publication is intended to provide stakeholders with additional implementation time and facilitate early feedback before finalisation. Stakeholders are invited to submit comments on the draft technical package and glossary by 24 August 2026. The final technical package is expected in September 2026. The draft package also continues the transition towards DPM 2.0 and includes a revised conversion file between DPM 1.0 and DPM 2.0 glossary structures. The EBA notes that the document is for information purposes only and that additional elements will be included in the final release.
EBA publishes Final Report on draft ITS and Opinion on the implementation of IFRS 18 in FINREP
![]()
On 8 July 2026, the European Banking Authority (EBA) published its Final Report on draft Implementing Technical Standards (ITS) on the implementation of IFRS 18 in supervisory financial reporting (FINREP). The Final Report sets out the revised FINREP templates and instructions affected by IFRS 18, with the objective of aligning supervisory reporting requirements with the new presentation requirements introduced by IFRS 18.
IFRS 18, endorsed in the European Union through Commission Regulation (EU) 2026/338, replaces IAS 1 and introduces a revised structure for the statement of profit or loss. Institutions will apply IFRS 18 to public financial statements from 1 January 2027, while the amended FINREP ITS incorporating IFRS 18 are currently expected to become mandatory only from the end of September 2027.
The amendments include updates to the Statement of Profit or Loss (F 02.00), the introduction of operating, investing and financing categories consistent with IFRS 18, the maintenance of existing reporting granularity through templates F 16 and F 45, and technical adjustments intended to preserve comparability and avoid divergent reporting requirements.
Alongside the Final Report, the EBA also published an Opinion on the implementation of IFRS 18 in FINREP. The Opinion provides guidance on the reporting of profit or loss information during the period between the first application of IFRS 18 and the expected application of the amended FINREP ITS.
The Opinion aims to support institutions by avoiding the operational burden of maintaining two different profit or loss reporting formats during the transitional period and by ensuring consistency between IFRS financial statements and supervisory reporting requirements.
To bridge this timing gap, the EBA advises competent authorities to permit institutions to voluntarily use IFRS 18-aligned FINREP templates during the interim period. These templates are based on the finalised amendments developed under the EBA’s draft ITS package and reflect feedback received during the related public consultation.
The EBA plans to publish the technical package containing the Data Point Model, validation rules and XBRL taxonomy for these templates during 2026. The final amended ITS is expected to be submitted to the European Commission by the end of 2026, with mandatory application currently expected from the end of September 2027.
EBA publishes final technical package for Reporting Framework 4.3 covering Third-Country Branch reporting and AMLA risk assessment reporting
![]()
On 9 July 2026, the European Banking Authority (EBA) published the final technical package for version 4.3 of its reporting framework, which implements new reporting requirements for Third-Country Branches (TCBs) under the Capital Requirements Directive (CRD) and supports the implementation of a risk assessment data collection exercise by the Anti-Money Laundering Authority (AMLA).
The final technical package provides the standard technical specifications necessary to support the relevant reporting obligations. These specifications include validation rules, the Data Point Model (DPM), and XBRL taxonomies. The package covers two principal reporting streams.
First, it supports the final draft Implementing Technical Standards (ITS) on supervisory reporting for Third-Country Branches, developed pursuant to Article 48l(1) of the CRD. The framework establishes the reporting architecture required for supervisory reporting by TCBs, with the first reporting reference date set for 31 March 2027.
Second, the package introduces DPM and taxonomy components to support AMLA risk assessment reporting. These components facilitate the methodology used to identify obliged entities that may fall under the direct supervision of AMLA. The first reporting reference date for this exercise is 31 December 2026.
In addition, the EBA has published a new Glossary Usage Exploration file intended to improve the usability and interpretation of the reporting framework. The file allows users to navigate glossary concepts, definitions and relationships within the DPM, thereby supporting impact assessments and promoting a more consistent understanding of the reporting framework’s semantic model.
The final package incorporates stakeholder feedback received following publication of the draft version on 17 April 2026. It includes updated DPM annotated templates, common data points, validation rules, glossary content and the related XBRL taxonomy. The EBA also notes that a targeted “hotfix” update may be issued at the end of September 2026 should critical clarifications or adjustments be required following early implementation feedback.
EC publishes Delegated Regulation amending MiFIR RTSs on derivatives transparency, package orders and OTC derivatives consolidated tape
![]()
On 13 July 2026, the European Commission published a Commission Delegated Regulation which amends the regulatory technical standards (RTS) under MiFIR relating to derivatives transparency, package orders and the OTC derivatives consolidated tape, and corrects an error in Delegated Regulation (EU) 2017/587.
The Delegated Regulation forms part of the implementation of the MiFIR Review (Regulation (EU) 2024/791), which introduced amendments to the transparency requirements applicable to trading venues and investment firms, aiming at enhancing market data transparency and supporting the establishment of consolidated tapes across the EU.
The present amendments to Commission Delegated Regulations (EU) 2017/583, (EU) 2017/2194, (EU) 2025/1155, and the corrections to Commission Delegated Regulation (EU) 2017/587 are made to achieve an effective transparency regime and for the successful establishment of the consolidated tape for OTC derivatives.
Article 1 brings amendments to Delegated Regulation (EU) 2017/583 that affect in priority market operators and investment firms operating an MTF or an OTF and investment firms trading outside of a trading venue. The changes brought:
- revise the definition of a "package transaction"
- introduce static liquidity determinations and static large-in-scale thresholds to be considered by market operators and investment firms operating a trading venue
- specify how to flag a package transaction in the context of post trade transparency obligations of market operators and investment firms operating a trading venue
- specify circumstances under which market operators and investment firms operating an MTF or an OTF and investment firms trading outside of a trading venue may defer the publication of the details of transactions
- revise the methodology market operators operating a regulated market shall apply to determine the transparency thresholds for equity derivatives
- revise transparency exemptions for monetary, foreign exchange and financial stability policy related transactions of a member of the European System of Central Banks (ESCB) that is not a member of the Eurosystem
- revise the methodology competent authorities shall apply to decide temporary exemptions of transparency obligations
Article 2 brings amendments to Delegated Regulation (EU) 2017/2194 that specify how Counterparties and CCPs shall report OTC derivative package orders to trade repositories.
Under this revised framework, package orders are only subject to pre-trade transparency where all components are themselves subject to transparency requirements.
Article 3 brings amendments to Delegated Regulation (EU) 2025/1155 that specify input and output data requirements for the future OTC derivatives consolidated tape provider (CTP) and excludes exchange-traded commodities (ETCs) and exchange-traded notes (ETNs) from the bond consolidated tape. This is primarily relevant for data contributors, i.e., trading venues and approved publication arrangements (APAs) who provide input data to the CTP.
Article 4 corrects an unintended deletion in Delegated Regulation (EU) 2017/587 by restoring requirements for investment firms to ensure certain transactions are made public as a single transaction.
The Regulation enters into force 20 days after publication in the Official Journal of the European Union, while the substantive amendments contained in Articles 1, 2 and 3(1)-(5) will apply from 1 March 2027.
ECB publishes clarification document on ICAAPs, ILAAPs and supervisory package submissions
![]()
On 15 July 2026, the European Central Bank (ECB) published “ECB clarification on ICAAPs and ILAAPs and respective package submissions”, which provides clarifications on supervisory expectations relating to banks’ internal capital adequacy assessment processes (ICAAPs), internal liquidity adequacy assessment processes (ILAAPs), and associated submissions to Joint Supervisory Teams (JSTs).
The document reiterates existing supervisory expectations established in the ECB ICAAP and ILAAP Guides and related EBA Guidelines, while stating that it does not introduce new requirements or expectations. Instead, it aims to clarify sound practices for capital and liquidity adequacy assessments, governance arrangements, capital and liquidity planning, stress testing, management actions, and supervisory reporting.
The ECB emphasises that ICAAPs and ILAAPs should be continuous processes supported by robust governance, regular reviews, and documented management body oversight. Capital and liquidity adequacy statements are expected to be approved and signed by the management body prior to submission. Banks are expected to maintain comprehensive risk inventories and provide evidence of the integration of capital and liquidity planning into risk management and decision-making processes.
The clarification sets out expectations for forward-looking assessments covering both normative and economic perspectives over at least a three-year horizon, using baseline and adverse scenarios. It also addresses stress testing methodologies, internal capital eligibility assessments, treatment of internal capital components, management actions, distribution policies, and the use of ICAAP outcomes in strategic decisions, remuneration, risk appetite, and capital allocation.
The document further confirms technical arrangements for ICAAP and ILAAP submissions. Since SREP 2025, institutions are expected to make annual submissions of key documents by 15 March and continuously submit new or significantly revised ICAAP/ILAAP-related documents throughout the year. Detailed guidance is also provided regarding required documentation, templates, reader’s manuals, reconciliation exercises, and the content of Capital Adequacy Statements and Liquidity Adequacy Statements.
ESMA publishes Final Report on simplifying EU transaction reporting
![]()
On 2 July 2026, the European Securities and Markets Authority (ESMA) published a Final Report on the Call for Evidence on a comprehensive approach for the simplification of financial transaction reporting, which sets out recommendations for reducing complexity, duplication and costs associated with EU transaction reporting requirements.
The report forms part of ESMA’s broader Simplification and Burden Reduction (SBR) initiative and assesses ways to streamline reporting obligations under key EU frameworks, notably MiFIR, EMIR and SFTR. ESMA’s review found that major sources of reporting costs and operational complexity include frequent and unsynchronised regulatory changes, duplication of reporting across multiple frameworks and reporting channels, and dual-sided reporting obligations together with related reconciliation processes.
To address these issues, ESMA recommends a staged approach combining short-term burden-reduction measures with a longer-term structural reform. The central recommendation is the development of a single integrated transaction reporting framework across MiFIR, EMIR and SFTR based on a “report once” principle. Under this model, transaction information would be submitted once through a common modular reporting structure and subsequently reused by relevant authorities for supervisory purposes, reducing duplication while maintaining supervisory access to required data.
ESMA’s accompanying cost-benefit analysis indicates that the proposed approach could generate annual net savings of €250 million to €1 billion, reduce recurring reporting costs by approximately 22%–24%, and deliver 10-year discounted cumulative net benefits of €1.2 billion to €4.9 billion. Implementation costs are expected to be recovered within three to four years.
In addition to the longer-term reform, ESMA proposes intermediate measures including expanded use of delegated reporting arrangements, streamlined intragroup exemption procedures and targeted reductions of low-value or duplicative reporting requirements. Following publication of the report, ESMA will engage with EU institutions regarding the recommendations. Implementation of the “report once” framework would require targeted legislative changes, phased implementation and further engagement with industry experts on reporting templates, data standards and infrastructure development.
ESMA publishes preliminary findings on the Active Account Requirement and the first Annual Report of the Joint Monitoring Mechanism
![]()
On 6 July 2026, the European Securities and Markets Authority (ESMA) published the Interim Report of the Effectiveness of the Active Account Requirement (AAR) and the First Annual Report of the Joint Monitoring Mechanism (JMM), which present preliminary findings on the implementation of the Active Account Requirement and the first year of cross-sectoral monitoring of the EU clearing ecosystem.
The Interim Report assesses the early effectiveness of the AAR during 2025 and early 2026 based on available supervisory data, analytics and industry feedback. ESMA reports that approximately 500 entities had notified ESMA and national competent authorities that they are subject to the AAR as of February 2026. Those entities account for more than 90% of notional outstanding held by EU entities in the relevant derivatives markets. Notifications were distributed across most Member States, with banks representing around half of notifying entities.
The report identifies early evidence of increased clearing activity at EU central counterparties (CCPs), particularly among smaller entities, and notes that some firms have fully relocated relevant clearing positions to EU CCPs. It also observes a gradual but limited shift in market share from systemically important third-country CCPs (Tier 2 CCPs) to EU CCPs in certain AAR-related products.
The First Annual Report of the JMM summarises monitoring activities conducted during 2025. It includes the results of AAR monitoring activities, analysis of cross-border clearing dependencies—particularly involving the United States—an assessment of trends affecting EU CCPs, and a review of existing EU-wide stress testing exercises. The report highlights the expansion of asset classes and products cleared within the EU and examines potential financial stability implications stemming from global clearing linkages.
ESMA notes that the AAR entered into force recently and that data gaps remain. Consequently, the effectiveness assessment will be carried out in two stages. This Interim Report represents the first stage, while a dedicated assessment methodology will be developed to support a final comprehensive assessment planned for 2027.
REPORTING & DISCLOSURES
EC publishes Delegated Regulation on Simplified ESRS Sustainability Reporting Standards
![]()
On 3 July 2026, the European Commission published a Commission Delegated Regulation amending Delegated Regulation (EU) 2023/2772 as regards the simplification of certain sustainability reporting standards. The delegated act revises the European Sustainability Reporting Standards (ESRS) used for sustainability reporting under Articles 19a and 29a of the Accounting Directive, as amended by the Corporate Sustainability Reporting Directive (CSRD).
The delegated regulation implements the simplification objectives introduced through the Omnibus I Directive (Directive (EU) 2026/470). The revised ESRS reduce reporting complexity while maintaining the overall objectives of sustainability reporting. Key changes include a reduction in the number of mandatory datapoints, prioritisation of quantitative disclosures over narrative disclosures, clearer differentiation between mandatory and voluntary datapoints, clarification of the materiality assessment process, improved consistency with EU legislation, and enhanced interoperability with international sustainability reporting standards.
According to the explanatory memorandum, EFRAG's proposed revisions reduced mandatory datapoints by approximately 61% and introduced additional flexibility measures, reliefs and phase-in provisions. The Commission further modified the draft standards to clarify materiality requirements, fair presentation principles, reporting aggregation levels, omission of information provisions, anticipated financial effects disclosures, greenhouse gas emissions reporting, climate transition plans, due diligence disclosures, and reporting requirements relating to asset management activities.
A specific provision relevant to financial institutions allows entities that manage investments on behalf of clients under fiduciary mandates not to disclose information concerning those investments in their own sustainability statements, recognising that such sustainability matters are primarily relevant to the clients and already addressed by separate EU disclosure frameworks.
The revised ESRS will apply to financial years beginning on or after 1 January 2027. For financial years beginning between 1 January 2026 and 31 December 2026, undertakings may voluntarily apply the revised ESRS or continue using the existing framework while benefiting from certain reliefs introduced by the delegated act. Undertakings must clearly state which version they apply during this transitional period.
EC publishes Delegated Regulation on voluntary sustainability reporting standards for undertakings protected by the value chain cap
![]()
BACKGROUND
On 3 July 2026, the European Commission adopted a Commission Delegated Regulation supplementing Directive 2013/34/EU (Accounting Directive) by establishing sustainability reporting standards for voluntary use by undertakings protected by the value chain cap. The Regulation follows the amendments introduced by Directive (EU) 2026/470 (Omnibus I Directive) to the Accounting Directive and the Corporate Sustainability Reporting Directive (CSRD – Directive (EU) 2022/2464) framework.
The Regulation establishes a voluntary sustainability reporting standard for undertakings not subject to mandatory sustainability reporting under Articles 19a and 29a of the Accounting Directive. It also establishes the reference level for the value chain cap, which limits the sustainability information that mandatory reporting undertakings may request, for sustainability reporting purposes, from undertakings in their value chain with no more than 1,000 employees.
WHAT'S NEW?
Voluntary sustainability reporting standard
The Regulation establishes a Voluntary Standard, set out in Annex I, based on the VSME standard and aligned with the revised ESRS. It maintains two modules:
- Basic Module: general information and core environmental, social and governance disclosures, including GHG emissions, pollution, biodiversity, water, circular economy, workforce and corruption and bribery.
- Comprehensive Module: additional disclosures covering strategy, climate transition and risks, workforce and human rights, certain revenues and governance diversity.
Value chain cap
The Regulation defines the value chain cap as the maximum sustainability information that mandatory reporting undertakings may request from protected value-chain undertakings for Accounting Directive reporting purposes. The cap comprises only the essential datapoints listed in Annex II and distinguishes between undertakings with more than 10 employees and those with 10 employees or fewer, for which certain datapoints are voluntary. It does not apply to information requests arising from other Union or national legal obligations.
Assurance and financial institutions
Undertakings applying the Voluntary Standard are not required to obtain assurance over the reported information. Financial institutions, financial market participants, insurers and credit institutions are also encouraged to limit sustainability information requests from undertakings with 1,000 employees or fewer, for purposes beyond Accounting Directive reporting, to the information specified in Annex I.
WHAT'S NEXT?
The Regulation will enter into force on the third day following its publication in the Official Journal of the European Union. From that date, undertakings outside the mandatory sustainability reporting scope may use the voluntary standard.
The value chain cap under Article 3 will apply to financial years beginning on or after 1 January 2027. From the Regulation's entry into force, Commission Recommendation (EU) 2025/1710 will be considered as no longer producing legal effects.
SECONDARY MARKET/TRADING
EC publishes Delegated Regulation on best execution policies under MiFID II
![]()
BACKGROUND
On 23 July 2026, the European Commission published Commission Delegated Regulation (EU) 2026/825 supplementing Directive 2014/65/EU (MiFID II) with regulatory technical standards on the establishment and assessment of order execution policies. The Regulation specifies the criteria investment firms must apply when selecting execution venues, routing client orders, monitoring execution quality and assessing the effectiveness of their order execution policies. It applies to investment firms executing client orders, including firms dealing on own account when executing client orders, and reflects amendments introduced by Directive (EU) 2024/790 to the MiFID II execution framework.
WHAT'S NEW?
Order execution policies and venue selection
Investment firms must document governance arrangements for selecting execution venues and maintain an internal list containing information on each venue, including approved financial instrument classes, transaction types and client categories. Venue selection must consider factors such as price, costs, order size, order frequency and available order types, supported by reliable reference data, including consolidated tape data where available.
Order routing and client instructions
Firms must specify the criteria and relative importance used to route orders where several execution venues are available. Automatic order routing systems must incorporate those criteria. Policies must also explain the treatment of specific client instructions, including that only the instructed part of an order is excluded from the ordinary best execution process.
Monitoring and assessment
The Regulation strengthens monitoring of execution quality through predefined thresholds and reference data. Investment firms must:
- assess execution quality for granular classes and, where necessary, subclasses of financial instruments;
- review the effectiveness of their execution policy at least annually and following material changes or identified deficiencies;
- periodically compare alternative venues where only one execution venue is selected; and
- correct identified deficiencies within a reasonable period.
For orders executed by dealing on own account, firms must address conflicts of interest and assess price fairness using market prices, comparable instruments or, where necessary, internal pricing models.
WHAT'S NEXT?
The Regulation entered into force on the 20th day following its publication in the Official Journal of the European Union. It will apply from 12 February 2028.
From that date, Delegated Regulations (EU) 2017/575 and (EU) 2017/576 will be repealed.
ESMA publishes Supervisory Briefing on Triangular Passporting under MiFID II
![]()
On 7 July 2026, the European Securities and Markets Authority (ESMA) published a Supervisory Briefing on Triangular Passporting under MiFID II, which aims to promote common supervisory approaches and practices among National Competent Authorities (NCAs) and provide supervisory expectations for firms engaging in triangular passporting arrangements.
The briefing addresses the practice of “triangular passporting”, whereby an investment firm authorised in one Member State uses a branch or tied agent established in a second Member State under the freedom of establishment to provide investment services into a third Member State under the freedom to provide services. ESMA notes that this business model may create challenges relating to supervisory responsibilities, firms’ compliance obligations and investor protection.
The document clarifies ESMA’s and NCAs’ common understanding of the MiFID II framework and sets out supervisory expectations covering firms’ responsibilities, supervisory competences, information provided to clients and access to dispute resolution mechanisms and investor compensation schemes. ESMA expects firms relying on triangular passporting to:
- notify competent authorities appropriately,
- conduct risk assessments relating to the model,
- monitor tied agents effectively and
- ensure that the arrangement is not used to circumvent supervisory requirements or engage in regulatory arbitrage.
The briefing also contains expectations regarding transparency towards clients, including informing clients about the entity providing services, the competent supervisory authority and available complaint-handling and redress mechanisms. Firms are expected to ensure that clients have clear access to complaint procedures and relevant information irrespective of the cross-border structure used.
For NCAs, ESMA outlines expectations regarding passport notifications, cooperation between authorities and the allocation of supervisory responsibilities. The briefing emphasises cooperation and information exchange among competent authorities to support effective supervision of cross-border activities. ESMA states that the briefing is intended to foster supervisory convergence and investor protection while clarifying the application of existing MiFID II requirements. The document does not create new legal obligations and is non-binding.
SETTLEMENT
EC publishes Delegated Regulation on amendments to the CSDR settlement discipline RTS
![]()
BACKGROUND
On 6 July 2026, the European Commission adopted a Commission Delegated Regulation amending Commission Delegated Regulation (EU) 2018/1229 on regulatory technical standards for settlement discipline under Regulation (EU) No 909/2014 on central securities depositories (CSDR). The amendments follow the CSDR Refit, Regulation (EU) 2023/2845, and support the forthcoming shortening of the EU securities settlement cycle from T+2 to T+1 from 11 October 2027 under Regulation (EU) 2025/2075.
The Regulation is based on draft regulatory technical standards submitted by the European Securities and Markets Authority (ESMA) on 13 October 2025. It introduces measures aimed at increasing settlement efficiency, preventing and addressing settlement fails, and supporting the operational changes required for T+1 settlement. The requirements concern central securities depositories (CSDs), CSD participants, investment firms and their professional and retail clients.
WHAT'S NEW?
Allocation, confirmation and settlement instructions
The Regulation strengthens requirements for pre-settlement processes and standardisation. Professional clients must transmit allocations and confirmations electronically in a standardised, machine-readable format using international open communication procedures and standards. Relevant allocations and confirmations must be received by investment firms by 23:00 CET on trade date, while retail clients must provide settlement information by the same deadline. CSD participants must send settlement instructions as soon as possible and, where feasible, by 23:59 CET on trade date.
Settlement functionalities
The Regulation introduces or strengthens several CSD functionalities:
- CSDs must offer automatic partial settlement, unless a participant opts out.
- CSDs must offer real-time gross settlement, at least three settlement batches per business day, or a combination of both.
- CSDs must facilitate access to intra-day cash credit secured by collateral through automated collateralisation.
- Settlement instructions must include the place of trading and expanded transaction-type information, including buy-sell back and sell-buy back transactions.
Settlement fail monitoring and reporting
CSD participants with a significant impact on settlement systems must report the main reasons for settlement fails and measures taken to address them. CSDs must report settlement fail information monthly by the fifth business day of the following month, in a standardised electronic format, and monitor measures intended to improve settlement efficiency. Annexes I and III are expanded, while the existing Annex II is deleted.
WHAT'S NEXT?
The Regulation will enter into force on the 20th day following its publication in the Official Journal of the European Union.
Most provisions will apply from 7 December 2026. Certain settlement-fail monitoring, reporting and trading-place identification requirements will apply from 1 July 2027, while provisions concerning settlement instruction timing, hold and release mechanisms, auto-partial settlement, settlement batches, automated collateralisation and partial settlement will apply from 11 October 2027, coinciding with the EU transition to T+1 settlement.
ESMA publishes Statement on Preparing for the EU T+1 Settlement Cycle
![]()
On 20 July 2026, ESMA published a Statement on Preparing for the EU T+1 Settlement Cycle which sets out key deadlines, regulatory expectations, and implementation priorities for market participants ahead of the EU's transition to a T+1 securities settlement cycle on 11 October 2027.
The statement highlights that the EU financial markets will move from a T+2 to a T+1 settlement cycle on 11 October 2027, requiring market participants to accelerate preparations during 2026 and 2027. ESMA notes that readiness surveys conducted by the EU T+1 Industry Committee indicate increasing awareness and commitment across the industry, although implementation progress remains uneven across sectors, firms, and markets.
ESMA emphasises that the legal and regulatory framework supporting the transition has been known since October 2025 and references amendments to the settlement discipline RTS that have been endorsed by the European Commission and are undergoing scrutiny by the European Parliament and Council. Firms are encouraged to consider these requirements alongside the recommendations issued by the EU T+1 Industry Committee.
The statement identifies two key compliance milestones.
The first deadline is 7 December 2026, when requirements relating to the exchange of allocations and confirmations become applicable, including stricter timing expectations and the default use of international communication standards.
The second and final deadline is 11 October 2027, when requirements aimed at optimising the settlement layer become applicable, including the timely submission of settlement instructions and broader use of functionalities such as auto-partial settlement, hold and release, and auto-collateralisation.
ESMA further explains that automation, standardisation, and data quality improvements are key enablers of successful implementation. Firms are encouraged to review trading and settlement processes, assess dependencies across their operational ecosystem, and begin testing as early as possible. The statement warns that insufficient preparedness may create operational, reputational, and settlement risks, potentially affecting market participants' ability to meet client expectations and settlement deadlines.
SUPERVISION
ESMA publishes Follow-up Report to the Peer Review on the supervision of cross-border activities of investment firms
![]()
On 20 July 2026, the European Securities and Markets Authority (ESMA) published its Follow-up Report to the Peer Review on the supervision of cross-border activities of investment firms, which assesses the actions taken by six National Competent Authorities (AFM, BaFin, CNB, CSSF, CySEC and MFSA) to address recommendations issued following ESMA's 2022 peer review on cross-border supervision of investment services.
The report evaluates improvements in four key supervisory areas: authorisations, ongoing supervision, cooperation among authorities, and enforcement and sanctioning. ESMA notes that cross-border provision of investment services to retail clients continues to increase in scale and complexity, with more than 10.5 million retail clients receiving cross-border investment services across the EU/EEA in 2024.
Regarding authorisations, ESMA finds that several NCAs have introduced more structured assessments of firms' cross-border business models, governance arrangements, internal controls, language capabilities and risk management processes. Improvements were particularly noted in the Czech Republic, Germany, Luxembourg and Cyprus.
For ongoing supervision, ESMA highlights enhanced collection and use of cross-border data, the integration of cross-border risk indicators into supervisory frameworks, and more targeted monitoring of firms providing services across Member States. Several authorities have introduced dedicated monitoring activities, risk-scoring methodologies and supervisory tools designed to identify cross-border risks more effectively.
The report also identifies improvements in cooperation among national authorities, particularly regarding information exchange and handling of supervisory requests. In the area of enforcement, ESMA notes increased use of supervisory and enforcement measures by some authorities but indicates that further efforts remain necessary in certain jurisdictions.
ESMA concludes that the peer review has positively influenced supervisory convergence across the EU by strengthening the oversight of cross-border investment services. However, given the continued growth of cross-border business models and increasing digitalisation, ESMA emphasises the need for national supervisors to continue enhancing supervisory resources, monitoring activities and enforcement practices to ensure adequate investor protection and effective functioning of the EU Single Market.
SUSTAINABLE FINANCE / GREEN FINANCE
EC publishes Delegated Regulation on ESG rating product disclosure requirements
![]()
On 28 July 2026, the Official Journal of the European Union published Commission Delegated Regulation (EU) 2026/871, which supplements Regulation (EU) 2024/3005 on the transparency and integrity of ESG rating activities by specifying the elements that ESG rating providers must disclose to the public, users of ESG ratings, rated entities, and issuers of rated items.
The Delegated Regulation establishes detailed regulatory technical standards (RTS) concerning disclosure obligations applicable to ESG rating products. It aims to enhance transparency, facilitate due diligence, and improve comparability across ESG rating products by introducing harmonised disclosure requirements. The Regulation requires ESG rating providers to disclose comprehensive information for each ESG rating product, including methodologies, models, key assumptions, data quality measures, materiality approaches, factors assessed under environmental, social and governance dimensions, and the treatment of international agreements such as the Paris Agreement where relevant.
The Regulation also introduces detailed requirements relating to methodological disclosures, including information about rating methodologies, ranking systems, industry classifications, engagement processes with rated entities, methodological updates, and supporting models. ESG rating providers must additionally disclose limitations relating to data availability, completeness, timeliness, accuracy, assumptions, proxies, and estimation techniques.
Organisational disclosures are required regarding ownership structures, fee models, business models, potential conflicts of interest, and links with parent or subsidiary undertakings. Furthermore, ESG rating providers must explain processes for collecting non-public data, revising methodologies, conducting stakeholder consultations where applicable, assessing the impact of methodology changes, and ensuring consistency in data revision procedures.
The Regulation also prescribes the presentation order for disclosures and permits cross-references to relevant information available on providers’ websites. The measure is based on draft RTS developed by ESMA following public consultation. The Regulation entered into force on the twentieth day following publication in the Official Journal and applies from 2 July 2026, aligning with the application date of the underlying ESG Ratings Regulation.
EC publishes Delegated Regulation on organisational safeguards for ESG rating providers
![]()
On 28 July 2026, the Official Journal of the European Union published Commission Delegated Regulation (EU) 2026/872, which supplements Regulation (EU) 2024/3005 on the transparency and integrity of ESG rating activities by specifying the measures and safeguards that ESG rating providers must implement to separate their ESG rating activities from other business activities.
The Delegated Regulation establishes organisational, operational and governance requirements intended to prevent conflicts of interest where ESG rating providers also perform other regulated activities. ESG rating providers must implement decision-making procedures, reporting lines, organisational structures and responsibility allocations ensuring that employees directly involved in ESG rating assessments are not involved in other activities referred to in Article 16(1) of Regulation (EU) 2024/3005. They must also introduce physical separation measures and require annual self-declarations from relevant staff confirming they are not engaged in incompatible activities.
Where ESG rating providers engage in investment services, credit institution activities or insurance/reinsurance activities covered by Article 16(1), they must implement additional safeguards including role-based access controls, information-security controls, confidential information policies, employee training, contractual requirements and compliance monitoring activities. The adequacy of these safeguards must be assessed at least every 24 months, with management bodies overseeing any necessary remedial actions.
The Regulation also introduces additional requirements for ESG rating providers authorised to provide benchmarks. These include measures ensuring remuneration and performance assessments are not influenced by benchmark-related conflicts of interest, preventing mechanistic reliance on benchmark constituents or outputs when producing ESG ratings, and requiring documented assessments of actual or potential conflicts before entering into service contracts with rated entities, issuers or certain investors.
The Regulation is based on draft regulatory technical standards developed by ESMA following public consultation. It enters into force on the twentieth day after publication in the Official Journal and applies from 2 July 2026, aligning with the application date of Regulation (EU) 2024/3005.
BELGIUM
ALTERNATIVE PRODUCTS
Chambre des représentants de Belgique publishes draft law transposing AIFMD II and UCITS amendments under Directive (EU) 2024/927
![]()
On 9 July 2026, the Chambre des représentants de Belgique published a draft law to transpose Directive (EU) 2024/927, which amends the AIFMD and UCITS frameworks.
The proposal updates Belgium’s laws governing UCITS and alternative investment funds (AIFs), introducing new rules on delegation arrangements, liquidity risk management, supervisory reporting, depositary services, and loan origination by AIFs.
The draft law expands the range of activities permitted for UCITS management companies and AIF managers, including benchmark administration and the provision of certain services to third parties. It introduces a dedicated framework for loan-originating AIFs, including risk-management requirements, borrower concentration limits, leverage restrictions, and retention obligations for transferred loans. The proposal also strengthens liquidity risk management by requiring open-ended funds to implement liquidity management tools and establish procedures governing their activation and use.
In addition, the legislation enhances reporting and disclosure obligations to the Belgian Financial Services and Markets Authority (FSMA), investors, ESMA and other supervisory authorities. It revises delegation requirements, clarifies depositary responsibilities, and introduces conflict-of-interest provisions where funds are established or managed at the initiative of third parties. The bill is intended as a faithful transposition of the EU directive while also simplifying certain existing Belgian rules to reduce administrative burdens and improve the competitiveness of Belgian fund managers.
Most provisions entered into force on 16 April 2026 in line with the EU directive, while certain reporting-related requirements are scheduled to apply from 16 April 2027.
OTHER - PRUDENTIAL REQUIREMENTS
Belgium publishes draft law transposing CRD VI, ESAP and CCP exposure reforms
![]()
On 13 July 2026, the Chambre des représentants de Belgique published a draft law to transpose several major EU financial sector reforms into Belgian law, primarily Directive (EU) 2024/1619 (CRD VI), alongside legislation relating to the European Single Access Point (ESAP) and the prudential treatment of exposures to central counterparties (CCPs).
The proposal introduces extensive amendments to Belgium’s prudential supervisory framework for credit institutions, investment firms, insurance undertakings, payment institutions and electronic money institutions.
The draft law implements key CRD VI reforms covering supervisory powers, sanctions, governance requirements, third-country branches, ESG risk management and crypto-asset related risks. It strengthens the independence of the National Bank of Belgium (NBB), enhances fit-and-proper requirements for management and key function holders, introduces new governance expectations, and establishes a harmonised framework for the supervision and authorisation of third-country bank branches operating in Belgium. The legislation also integrates ESG risks and crypto-asset exposures more explicitly into the prudential framework.
In addition, the proposal implements provisions relating to the European Single Access Point (ESAP), requiring amendments to numerous Belgian financial services laws to facilitate the future collection, transmission and publication of financial, prudential and sustainability-related information through ESMA’s centralised European disclosure platform. The draft law designates relevant Belgian authorities as information collection bodies and establishes the framework necessary to support ESAP reporting obligations.
The bill also transposes Directive (EU) 2024/2994, introducing measures relating to concentration risk arising from exposures to CCPs and the treatment of counterparty risk in centrally cleared derivative transactions. Additional provisions include technical amendments to the NBB’s institutional framework, administrative simplifications and corrections to existing prudential legislation following reviews by the European Commission. Overall, the draft law represents a significant update to Belgium’s banking and prudential regulatory framework and aligns national legislation with recent EU banking reforms.
SANCTIONS/RESTRICTIVE MEASURES
Chambre des représentants de Belgique publishes draft law on criminal enforcement of EU sanctions and restrictive measures
![]()
On 13 July 2026, the Chambre des représentants de Belgique published a draft law to transpose Directive (EU) 2024/1226 into Belgian law, establishing a harmonised framework for criminal offences and sanctions relating to breaches of EU restrictive measures (sanctions).
The proposal aims to strengthen Belgium's ability to detect, investigate and prosecute sanctions violations, while aligning national legislation with new EU minimum standards on criminal liability, enforcement powers and penalties.
The draft law introduces a comprehensive regime covering sanctions circumvention, failure to freeze assets, prohibited transactions with sanctioned persons or entities, breaches of trade restrictions and other violations of EU sanctions measures. It provides for enhanced investigative powers, stronger cooperation between authorities, new administrative and criminal penalties, and a harmonised framework for prosecuting both individuals and legal entities. The proposal also establishes mechanisms for coordination among competent authorities and strengthens whistleblower protections related to sanctions breaches.
In addition, the legislation amends Belgium’s anti-money laundering framework by explicitly recognising violations of restrictive measures as predicate offences for money laundering. Financial institutions and other obliged entities will therefore need to maintain effective sanctions screening, monitoring and reporting processes. The draft also updates existing Belgian laws relating to sanctions implementation, asset freezing, supervisory cooperation and information sharing to ensure consistency with the EU directive.
The main provisions of the draft law are scheduled to enter into force on 1 September 2026, aligned with the entry into force of Belgium's new Criminal Code.
BRAZIL
ANTI-MONEY LAUNDERING / COMBATING TERRORISM FINANCING / COMBATTING PROLIFERATION FINANCING (AML/CFT/CPF)
BCB publishes Normative Instruction No. 761 on AML/CFT guidance for dealings with FATF high-risk jurisdictions
![]()
BACKGROUND
On 9 July 2026, the Central Bank of Brazil (BCB) issued BCB Normative Instruction No. 761, providing guidance on enhanced measures under Circular No. 3,978 of 23 January 2020 for operations and business relationships involving customers, correspondent financial institutions and partners located in countries or territories identified by the Financial Action Task Force (FATF) as having strategic deficiencies.
Circular No. 3,978 establishes AML/CFT policies, procedures and controls for institutions authorised by the BCB and applies a risk-based approach. The Instruction follows findings from Brazil’s 2023 FATF Mutual Evaluation, which highlighted the need for more explicit guidance on enhanced procedures and controls for relationships involving higher-risk jurisdictions. The BCB states that the Instruction does not create autonomous obligations beyond Circular No. 3,978 or modify the applicable sanctions regime.
WHAT'S NEW?
Scope of enhanced measures
Enhanced procedures and internal controls apply to transactions and business relationships involving customers, correspondent financial institutions and partners located in FATF-listed jurisdictions. These measures cover internal risk assessment, customer due diligence, transaction monitoring and analysis, and due diligence on partners and outsourced service providers.
Minimum risk-mitigation measures
Institutions must apply, at a minimum:
- additional collection, verification and validation of information concerning customers, correspondent institutions and partners;
- additional analysis of the economic or legal rationale for transactions and the nature of business relationships;
- enhanced transaction monitoring and more frequent updating of customer information;
- documentation of analyses, conclusions and decisions, including supporting evidence.
Unacceptable or non-mitigable risks
Where such risks are identified, additional measures apply. For partners and correspondent institutions, the responsible director must assess whether the relationship can be initiated or continued, and operational limits may be imposed. For customers, institutions must assess whether the relationship can be initiated and may impose operational limits.
WHAT'S NEXT?
BCB Normative Instruction No. 761 enters into force on the date of its publication, 9 July 2026. The enhanced measures therefore apply within the existing framework established by Circular No. 3,978 from that date. The Instruction does not establish a separate transitional period or modify the existing sanctioning regime.
COLOMBIA
CREDIT RISK
Ministerio de Hacienda y Crédito Público publishes draft decree on exceptions to large exposure calculations and concentration risk limits for credit institutions
![]()
On 7 July 2026, the Ministerio de Hacienda y Crédito Público published a draft decree which proposes amendments to Decree 2555 of 2010 regarding the identification and management of large exposures and risk concentration for Colombian credit institutions.
The proposal aims to refine the prudential treatment of certain short-term operational exposures that are currently included in the calculation of large exposure limits. According to the publication, credit institutions regularly generate temporary balances arising from: (i) foreign exchange transactions processed through compensation accounts, (ii) receivables linked to acquiring activities and payment processing, and (iii) payment flows related to tax collection. The document states that these exposures are operational, transitory and short-term in nature and do not represent discretionary lending decisions or permanent credit exposures.
The draft decree introduces new exemptions from the large exposures framework. Foreign exchange transactions channelled through compensation accounts registered with the Banco de la República would be excluded from large exposure calculations, provided they do not remain outstanding beyond three business days after the transaction date (T+3). Similarly, acquiring-related payment flows and operations linked to tax payments would be excluded, provided they do not exceed one business day following settlement (T+1).
The proposal would also require credit institutions to establish internal policies, controls and limits for managing the risks associated with these exempted exposures, subject to future supervisory instructions from the Superintendencia Financiera de Colombia (SFC).
In addition, the draft introduces a special provision for the Financiera de Desarrollo Nacional (FDN). The FDN's Board of Directors would be allowed to approve exposure limits of up to 45% of regulatory capital for infrastructure financing projects, subject to technical documentation, governance requirements and supervisory oversight.
The draft provides that the SFC will issue implementing instructions within six months after the decree enters into force. The decree would become effective on the day following its publication.
FRANCE
ALTERNATIVE PRODUCTS
AMF issues updated Instruction DOC-2008-03 following the revision of the Benchmarks Regulation / L'AMF publie une version mise à jour de l'instruction DOC-2008-03 à la suite de la révision de la réglementation sur les indices de référence
![]()
On 23 July 2026, the Autorité des marchés financiers (AMF) updated Instruction DOC-2008-03, which sets out the authorisation, information and passporting procedures applicable to French management companies managing UCITS, AIFs or other collective investment schemes. It also covers foreign management companies seeking to manage UCITS or AIFs or provide investment services in France under an EEA passport.
The amendment reflects the revised scope of the EU Benchmarks Regulation following the application of Regulation (EU) 2025/914 from 1 January 2026. The instruction now clarifies that a management company carrying out benchmark administration activities requires authorisation or registration only in the circumstances specified in Article 34 of the Benchmarks Regulation, namely where it administers benchmarks that remain within the revised BMR scope.
An application for authorisation or registration as a benchmark administrator may be examined alongside the management company’s initial authorisation application. Where the activity is added subsequently, the application is treated as an extension of the management company’s authorisation. In both cases, the assessment is subject to the deadlines established under the Benchmarks Regulation.
The remainder of the instruction continues to govern the initial authorisation of management companies, their programmes of activity, changes to ownership and governance, regulatory information submitted through ROSA, extensions and withdrawals of authorisation, and inbound and outbound passporting for the management of UCITS and AIFs and the provision of permitted investment services.
Version française
Le 23 juillet 2026, l’Autorité des marchés financiers (AMF) a mis à jour l’instruction DOC-2008-03, qui définit les procédures d’agrément, d’information et de passeport applicables aux sociétés de gestion françaises gérant des OPCVM, des FIA ou d’autres organismes de placement collectif. Elle s’applique également aux sociétés de gestion étrangères souhaitant gérer des OPCVM ou des FIA, ou fournir des services d’investissement en France au titre d’un passeport EEE.
Cette modification tient compte du champ d’application révisé du règlement de l’UE sur les indices de référence (BMR) suite à l’entrée en vigueur du règlement (UE) n° 2025/914 à compter du 1er janvier 2026. L’instruction précise désormais qu’une société de gestion exerçant des activités d’administration d’indices de référence n’est soumise à une obligation d’agrément ou d’enregistrement que dans les cas prévus à l’article 34 du règlement sur les indices de référence, à savoir lorsqu’elle administre des indices de référence qui relèvent toujours du champ d’application révisé dudit règlement.
Une demande d’agrément ou d’enregistrement en tant qu’administrateur d’indices de référence peut être examinée parallèlement à la demande d’agrément initiale de la société de gestion. Lorsque l’activité est ajoutée ultérieurement, la demande est traitée comme une extension de l’agrément de la société de gestion. Dans les deux cas, l’évaluation est soumise aux délais fixés par le règlement sur les indices de référence.
Le reste de l’instruction continue de régir l’agrément initial des sociétés de gestion, leurs programmes d’activité, les changements de structure de propriété et de gouvernance, les informations réglementaires transmises via ROSA, les extensions et les retraits d’agrément, ainsi que le passeport entrant et sortant pour la gestion d’OPCVM et de FIA et la prestation de services d’investissement autorisés.
AMF publishes updated guide for UCITS and AIF depositaries / L'AMF publie une mise à jour de son guide destiné aux dépositaires d'OPCVM et de FIA
![]()
BACKGROUND
On 24 July 2026, the Autorité des marchés financiers (AMF) published an updated guide for UCITS and AIF depositaries. The guide replaces the 2018 guidance on the implementation of UCITS V depositary obligations, extends certain guidance to AIF depositaries and incorporates recent developments concerning crypto-assets and distributed ledger technology (DLT). It provides practical clarifications on depositaries’ cash-flow monitoring, safekeeping, ownership verification and oversight duties. The guide is educational and does not constitute formal AMF doctrine or introduce additional legal requirements.
WHAT'S NEW?
Depositary governance and controls
The guide provides clarifications on independence requirements between management companies and depositaries, including governance structures, independent board members and group relationships. It also addresses:
- independent legal opinions where safekeeping is delegated to third-country sub-custodians;
- oversight of sub-custodians and separation between compliance and operational depositary controls;
- calculation and monitoring of regulatory and statutory investment ratios by the depositary itself.
Crypto-assets and DLT
For AIFs investing in crypto-assets, depositaries do not safekeep the crypto-assets but must verify ownership and maintain records. The guide also clarifies information flows with management companies and CASP custodians, treatment of anomalies and the combination of depositary and CASP custody functions within the same entity.
For DLT-registered financial instruments, depositaries must likewise verify ownership and maintain records, while ensuring that information obtained from the DLT is sufficiently reliable.
E-money tokens
The guide clarifies that EMTs may be used for subscription and redemption settlements under specified conditions. For UCITS and MMFs, EMTs may only remain temporarily in the portfolio where used exclusively for payment purposes.
Escalation procedures
Depositaries may define objective escalation criteria, timelines, responsible persons and remediation processes. Records of identified anomalies must be retained for five years.
WHAT'S NEXT?
Depositaries should review their existing governance, control frameworks and operational procedures against the AMF's updated guidance, particularly in relation to investment restriction monitoring, crypto-assets and DLT arrangements, relationships with third-party custodians and escalation procedures.
Portfolio management companies and crypto-asset service providers should also consider the relevant sections of the guide where their activities and information-sharing arrangements interact with depositaries' regulatory obligations.
Version française
BACKGROUND
Le 24 juillet 2026, l’Autorité des marchés financiers (AMF) a publié une mise à jour du guide destiné aux dépositaires d’OPCVM et de FIA. Ce guide remplace les recommandations de 2018 relatives à la mise en œuvre des obligations des dépositaires au titre de la directive OPCVM V, étend certaines recommandations aux dépositaires de FIA et intègre les évolutions récentes concernant les crypto-actifs et la technologie des registres distribués (DLT). Il apporte des précisions pratiques sur les obligations des dépositaires en matière de suivi des flux de trésorerie, de conservation, de vérification de la propriété et de surveillance. Ce guide a un caractère pédagogique et ne constitue pas une doctrine officielle de l’AMF ni n’introduit d’exigences juridiques supplémentaires.
WHAT'S NEW?
Gouvernance et contrôles du dépositaire
Le guide apporte des précisions sur les exigences d’indépendance entre les sociétés de gestion et les dépositaires, notamment en ce qui concerne les structures de gouvernance, les administrateurs indépendants et les relations au sein du groupe. Il aborde également les points suivants :
- les avis juridiques indépendants lorsque la conservation est déléguée à des sous-dépositaires de pays tiers ;
- la surveillance des sous-dépositaires et la séparation entre les contrôles de conformité et les contrôles opérationnels du dépositaire ;
- le calcul et le suivi des ratios d’investissement réglementaires et statutaires par le dépositaire lui-même.
Crypto-actifs et DLT
Pour les FIA investissant dans des crypto-actifs, les dépositaires n’assurent pas la conservation des crypto-actifs mais doivent vérifier la propriété et tenir des registres. Le guide clarifie également les flux d’informations avec les sociétés de gestion et les dépositaires CASP, le traitement des anomalies et la combinaison des fonctions de dépositaire et de dépositaire CASP au sein d’une même entité.
Pour les instruments financiers enregistrés sur une DLT, les dépositaires doivent également vérifier la propriété et tenir des registres, tout en s’assurant que les informations obtenues à partir de la DLT sont suffisamment fiables.
Jetons de monnaie électronique
Le guide précise que les jetons de monnaie électronique (EMT) peuvent être utilisés pour le règlement des souscriptions et des rachats sous certaines conditions. Pour les OPCVM et les OPC monétaires, les EMT ne peuvent rester que temporairement dans le portefeuille lorsqu’ils sont utilisés exclusivement à des fins de paiement.
Procédures d’escalade
Les dépositaires peuvent définir des critères d’escalade objectifs, des délais, les personnes responsables et les processus de correction. Les registres des anomalies identifiées doivent être conservés pendant cinq ans.
WHAT'S NEXT?
Les dépositaires doivent réexaminer leurs dispositifs de gouvernance, leurs cadres de contrôle et leurs procédures opérationnelles existants à la lumière des orientations actualisées de l’AMF, notamment en ce qui concerne le suivi des restrictions d’investissement, les crypto-actifs et les dispositifs de technologie des registres distribués (DLT), les relations avec les dépositaires tiers et les procédures d’escalade.
Les sociétés de gestion de portefeuille et les prestataires de services liés aux crypto-actifs doivent également prendre en compte les sections pertinentes du guide lorsque leurs activités et leurs dispositifs de partage d’informations recoupent les obligations réglementaires des dépositaires.
DIGITAL ASSETS
AMF confirms the end of France’s MiCA transition period for crypto-asset service providers / L'AMF confirme la fin de la période de transition française prévue par la directive MiCA pour les prestataires de services liés aux crypto-actifs
![]()
On 6 July 2026, the Autorité des marchés financiers (AMF) confirmed that the transitional period allowing digital asset service providers operating under the French Pacte Law regime to continue their activities without a MiCA authorisation ended on 1 July 2026.
Since 2 July 2026, the MiCA framework applies to all crypto-asset service providers operating in France. Firms must therefore hold a MiCA authorisation, whether granted by the AMF or passported from another EU Member State, to provide crypto-asset services in the European Union.
The AMF indicated that France had authorised 31 crypto-asset service providers, while 283 providers had been authorised across the EU. Its role will now increasingly focus on supervising authorised providers’ compliance with MiCA requirements, including operational and prudential obligations, conduct of business, market abuse prevention, ICT security, safeguarding of clients’ assets and funds, and complaints handling.
In coordination with ESMA and other national competent authorities, the AMF will closely monitor the orderly wind-down plans of firms that have not obtained a MiCA authorisation. The protection of clients affected by such cessations will be a supervisory priority.
Authorised providers receiving clients or assets transferred from firms ceasing their activities must conduct the required regulatory checks, particularly those relating to anti-money laundering and counter-terrorist financing. The AMF also reminds investors to use only providers authorised in the EU, as MiCA does not provide for a third-country equivalence regime.
Version française
Le 6 juillet 2026, l’Autorité des marchés financiers (AMF) a confirmé que la période transitoire permettant aux prestataires de services liés aux crypto-actifs opérant sous le régime de la loi « Pacte » française de poursuivre leurs activités sans autorisation MiCA avait pris fin le 1er juillet 2026.
Depuis le 2 juillet 2026, le cadre MiCA s’applique à tous les prestataires de services liés aux crypto-actifs opérant en France. Les entreprises doivent donc détenir une autorisation MiCA, qu’elle soit délivrée par l’AMF ou obtenue au titre du passeport européen depuis un autre État membre de l’UE, pour fournir des services liés aux crypto-actifs au sein de l’Union européenne.
L’AMF a indiqué que la France avait agréé 31 prestataires de services liés aux crypto-actifs, tandis que 283 prestataires avaient été agréés dans l’ensemble de l’UE. Son rôle consistera désormais de plus en plus à veiller au respect, par les prestataires agréés, des exigences de la MiCA, notamment en matière d’obligations opérationnelles et prudentielles, de conduite des activités, de prévention des abus de marché, de sécurité des technologies de l’information et de la communication, de protection des actifs et des fonds des clients, ainsi que de traitement des réclamations.
En coordination avec l’AEMF et les autres autorités nationales compétentes, l’AMF suivra de près les plans de liquidation ordonnée des entreprises n’ayant pas obtenu d’agrément MiCA. La protection des clients concernés par ces cessations d’activité constituera une priorité en matière de surveillance.
Les prestataires agréés qui reçoivent des clients ou des actifs transférés par des entreprises cessant leurs activités doivent effectuer les vérifications réglementaires requises, notamment celles relatives à la lutte contre le blanchiment de capitaux et le financement du terrorisme. L’AMF rappelle également aux investisseurs de n’avoir recours qu’à des prestataires agréés dans l’UE, la MiCA ne prévoyant pas de régime d’équivalence pour les pays tiers.
AMF publishes guidance on the consequences of MiCA for crypto holders / L'AMF publie des recommandations sur les conséquences de la directive MiCA pour les détenteurs de cryptomonnaies
![]()
On 27 July 2026, the Autorité des Marchés Financiers (AMF) published “Entry into force of the European MiCA regulation: what are the consequences for crypto holders?”, which explains the consequences of the end of the French transitional regime and the full application of the MiCA framework for crypto-asset holders.
The publication states that 1 July 2026 marked the end of the transition period from the French national regime to the harmonised European Markets in Crypto-Assets Regulation (MiCA) regime. Under this framework, companies providing crypto-asset services in France must operate as authorised Crypto-Asset Service Providers (CASPs).
The communication is directed primarily at crypto-asset holders and prospective investors using crypto-asset service providers in France. It refers to CASPs operating under MiCA and to the possibility of cross-border service provision within the European Union through the European passport mechanism.
The AMF explains that only authorised CASPs may provide crypto-asset services in France. Firms that did not obtain authorisation before the end of the transitional period must inform customers about the treatment of their crypto-assets.
The publication notes that customers may transfer crypto-assets to:
- An authorised CASP;
- A self-hosted wallet; or
- Convert holdings into euros, subject to the provider's applicable conditions, fees and timelines.
The AMF stresses that firms claiming to have submitted a CASP authorisation application should not be considered authorised unless they appear on the AMF whitelist.
The MiCA framework is described as strengthening investor protection through:
- Authorisation and supervision requirements;
- Organisational, governance and cybersecurity requirements;
- Enhanced disclosure regarding services, fees and risks.
Version française
Le 27 juillet 2026, l’Autorité des marchés financiers (AMF) a publié un document intitulé « Entrée en vigueur du règlement européen MiCA : quelles conséquences pour les détenteurs de crypto-actifs ? », qui explique les conséquences de la fin du régime transitoire français et de la pleine application du cadre MiCA pour les détenteurs de crypto-actifs.
Cette publication précise que le 1er juillet 2026 a marqué la fin de la période de transition entre le régime national français et le régime harmonisé du règlement européen sur les marchés des crypto-actifs (MiCA). Dans ce cadre, les entreprises fournissant des services liés aux crypto-actifs en France doivent exercer leur activité en tant que prestataires de services de crypto-actifs (CASPs) agréés.
Cette communication s’adresse principalement aux détenteurs de crypto-actifs et aux investisseurs potentiels recourant à des prestataires de services de crypto-actifs en France. Elle fait référence aux CASP opérant sous le régime MiCA et à la possibilité de fournir des services transfrontaliers au sein de l’Union européenne grâce au mécanisme du passeport européen.
L’AMF précise que seuls les CASP agréés peuvent fournir des services liés aux crypto-actifs en France. Les entreprises qui n’ont pas obtenu d’agrément avant la fin de la période de transition doivent informer leurs clients du sort réservé à leurs crypto-actifs.
La publication précise que les clients peuvent transférer leurs crypto-actifs vers :
- un CASP agréé ;
- un portefeuille auto-hébergé ; ou
- convertir leurs avoirs en euros, sous réserve des conditions, frais et délais applicables fixés par le prestataire.
L’AMF souligne que les entreprises affirmant avoir déposé une demande d’agrément CASP ne doivent pas être considérées comme agréées tant qu’elles ne figurent pas sur la liste blanche de l’AMF.
Le cadre MiCA est présenté comme renforçant la protection des investisseurs grâce à :
- des exigences en matière d’agrément et de surveillance ;
- des exigences en matière d’organisation, de gouvernance et de cybersécurité ;
- une transparence accrue concernant les services, les frais et les risques.
AMF publishes updated doctrine on crypto-asset advisory services under MiCA / L'AMF publie une mise à jour de sa doctrine relative aux services de conseil en matière de crypto-actifs dans le cadre de la MiCA
![]()
On 27 July 2026, the Autorité des Marchés Financiers (AMF) published an update to its Position-Recommendation DOC-2006-23, which clarifies when Financial Investment Advisers (FIAs/CIFs) must obtain authorisation as a Crypto-Asset Service Provider (PSCA/CASP) to provide crypto-asset advisory services under Regulation (EU) 2023/1114 (MiCA).
The AMF explains that its previous 2022 clarifications regarding CIF activities involving digital assets are no longer applicable following the entry into force of the MiCA regime and the end of the transitional period. Under MiCA, providing advice on crypto-assets constitutes a regulated crypto-asset service requiring PSCA authorisation. FIAs/CIFs are not eligible for the notification procedure available to certain already authorised entities and must obtain the relevant authorisation where required.
The update applies to French Financial Investment Advisers (CIFs/FIAs) that provide or intend to provide advice relating to crypto-assets or crypto-asset services. The AMF reiterates that the CIF regime covers investment advice on financial instruments, investment services and certain other regulated activities, but does not cover crypto-assets or crypto-asset services.
The AMF added a new Q&A (section 2.5 of DOC-2006-23) explaining that advice on crypto-assets is a crypto-asset service under MiCA and therefore requires PSCA authorisation. The doctrine incorporates ESMA Q&A clarifications and states that the scope of crypto-asset advice is broader than MiFID II investment advice because it includes personalised recommendations concerning crypto-asset transactions and the use of crypto-asset services.
The AMF provides non-exhaustive examples of activities that constitute crypto-asset advice, including personalised recommendations on purchasing, holding or selling identified crypto-assets and recommendations on using a specific crypto-asset service. It also provides examples that do not require PSCA authorisation, including non-personalised public information, educational communications and advice concerning financial instruments whose underlying assets include crypto-assets.
The doctrine was modified on 27 July 2026. The publication states that MiCA has entered into force and that the transitional period has ended, but does not specify the relevant dates.
CIFs must assess whether their activities constitute crypto-asset advice under MiCA and, where applicable, obtain PSCA authorisation before providing such services. The AMF notes that situations should be analysed on a case-by-case basis and that further European-level clarifications may emerge.
Version française
Le 27 juillet 2026, l’Autorité des marchés financiers (AMF) a publié une mise à jour de sa prise de position-recommandation DOC-2006-23, qui précise dans quels cas les conseillers en investissement financier (CIF) doivent obtenir une autorisation en tant que prestataire de services liés aux crypto-actifs (PSCA) pour fournir des services de conseil en matière de crypto-actifs en vertu du règlement (UE) 2023/1114 (MiCA).
L’AMF précise que ses clarifications antérieures de 2022 concernant les activités des CIF liées aux actifs numériques ne sont plus applicables suite à l’entrée en vigueur du régime MiCA et à la fin de la période transitoire. En vertu du MiCA, la fourniture de conseils en matière de crypto-actifs constitue un service de crypto-actifs réglementé nécessitant une autorisation de PSCA. Les FIA/CIF ne peuvent pas bénéficier de la procédure de notification réservée à certaines entités déjà agréées et doivent obtenir l’agrément correspondant lorsque cela est requis.
Cette mise à jour s’applique aux conseillers en investissement financiers (CIF/FIA) français qui fournissent ou ont l’intention de fournir des conseils relatifs aux crypto-actifs ou aux services liés aux crypto-actifs. L’AMF rappelle que le régime des CIF couvre le conseil en investissement sur les instruments financiers, les services d’investissement et certaines autres activités réglementées, mais ne couvre pas les crypto-actifs ni les services liés aux crypto-actifs.
L’AMF a ajouté une nouvelle question-réponse (section 2.5 du DOC-2006-23) expliquant que le conseil en matière de crypto-actifs est un service lié aux crypto-actifs au sens de la MiCA et nécessite donc une autorisation de la PSCA. La doctrine intègre les précisions apportées par l’AESF dans ses questions-réponses et précise que le champ d’application du conseil en crypto-actifs est plus large que celui du conseil en investissement au sens de la directive MiFID II, car il inclut les recommandations personnalisées concernant les transactions sur crypto-actifs et l’utilisation de services liés aux crypto-actifs.
L’AMF fournit des exemples non exhaustifs d’activités constituant un conseil en crypto-actifs, notamment les recommandations personnalisées concernant l’achat, la détention ou la vente de crypto-actifs identifiés, ainsi que les recommandations relatives à l’utilisation d’un service spécifique lié aux crypto-actifs. Elle fournit également des exemples ne nécessitant pas d’agrément au titre de la PSCA, notamment les informations publiques non personnalisées, les communications à vocation pédagogique et les conseils concernant des instruments financiers dont les actifs sous-jacents comprennent des crypto-actifs.
La doctrine a été modifiée le 27 juillet 2026. La publication indique que la MiCA est entrée en vigueur et que la période transitoire a pris fin, mais ne précise pas les dates correspondantes.
Les CIF doivent évaluer si leurs activités constituent des conseils en crypto-actifs au sens du MiCA et, le cas échéant, obtenir l’autorisation de la PSCA avant de fournir de tels services. L’AMF souligne que les situations doivent être analysées au cas par cas et que des précisions supplémentaires au niveau européen pourraient être apportées.
OTHER - PRUDENTIAL REQUIREMENTS
ACPR extends EBA/GL/2026/01 on identifying ancillary services undertakings / L'ACPR prolonge la validité de la directive EBA/GL/2026/01 relative à l'identification des entreprises de services auxiliaires
![]()
On 23 July 2026, the Autorité de contrôle prudentiel et de résolution (ACPR) announced its compliance with EBA Guidelines EBA/GL/2026/01, which specify the criteria for identifying activities performed by ancillary services undertakings under Article 4(1)(18) of the Capital Requirements Regulation. The ACPR also published a separate notice extending the Guidelines to French finance companies.
The Guidelines establish a harmonised approach for determining whether an undertaking’s principal activity constitutes a direct extension of banking, an activity ancillary to banking, or another similar activity. The assessment may cover activities such as operational leasing, ownership or management of property, data-processing services and certain fintech or technology-driven services.
Identifying an entity as an ancillary services undertaking is relevant for determining whether it must be included within the scope of a group’s prudential consolidation and, consequently, the consolidated application of CRR prudential requirements. The Guidelines are intended to promote consistent assessments by institutions and competent authorities across the EU.
The Guidelines apply to institutions directly supervised by the ACPR, which must make every effort to comply with them. Although French finance companies do not fall within the EBA Regulation’s definition of institutions directly subject to EBA guidelines, the ACPR expects them to apply EBA/GL/2026/01 because the relevant CRD and CRR requirements apply to them under French law.
Version française
Le 23 juillet 2026, l’Autorité de contrôle prudentiel et de résolution (ACPR) a annoncé qu’elle se conformait aux lignes directrices de l’ABE EBA/GL/2026/01, qui précisent les critères permettant d’identifier les activités exercées par les entreprises de services auxiliaires au sens de l’article 4, paragraphe 1, point 18, du règlement sur les exigences de fonds propres. L’ACPR a également publié un avis distinct étendant l’application de ces lignes directrices aux sociétés de crédit françaises.
Ces lignes directrices établissent une approche harmonisée permettant de déterminer si l’activité principale d’une entreprise constitue un prolongement direct de l’activité bancaire, une activité auxiliaire à l’activité bancaire ou une autre activité similaire. L’évaluation peut porter sur des activités telles que le crédit-bail opérationnel, la propriété ou la gestion immobilière, les services de traitement de données et certains services liés aux technologies financières ou axés sur la technologie.
Le fait de qualifier une entité d’entreprise de services auxiliaires est pertinent pour déterminer si elle doit être incluse dans le périmètre de la consolidation prudentielle d’un groupe et, par conséquent, dans l’application consolidée des exigences prudentielles du CRR. Les lignes directrices visent à favoriser la cohérence des évaluations réalisées par les établissements et les autorités compétentes dans l’ensemble de l’Union européenne.
Les lignes directrices s’appliquent aux établissements directement supervisés par l’ACPR, qui doivent tout mettre en œuvre pour s’y conformer. Bien que les sociétés financières françaises ne relèvent pas de la définition, donnée par le règlement de l’ABE, des établissements directement soumis aux lignes directrices de l’ABE, l’ACPR attend d’elles qu’elles appliquent la ligne directrice EBA/GL/2026/01, car les exigences pertinentes de la CRD et du CRR leur sont applicables en vertu du droit français.
REPORTING
AMF updates doctrine on the Benchmarks Regulation and unclaimed fund liquidation proceeds / L'AMF actualise sa doctrine relative au règlement sur les indices de référence et au produit de la liquidation des fonds non réclamés
![]()
On 23 July 2026, the Autorité des marchés financiers (AMF) updated several instructions to reflect the revised scope of the EU Benchmarks Regulation (BMR) and to specify the notification procedure applicable to unclaimed amounts arising from the liquidation of investment funds.
Following the application of Regulation (EU) 2025/914 from 1 January 2026, non-significant benchmarks are generally excluded from BMR unless they are Paris-aligned benchmarks, climate-transition benchmarks or certain commodity benchmarks. The AMF therefore clarifies that management companies and investment firms acting as benchmark administrators require authorisation or registration only when they administer benchmarks that remain within the revised BMR scope.
The AMF also updated the standard prospectus and fund-rule templates applicable to UCITS and AIFs. Existing funds using benchmarks that are no longer within the scope of BMR must remove references to the administrator’s regulatory status by 1 October 2026, or as soon as possible thereafter. Certain professional AIFs and AIFs whose units or shares are reserved for professional clients will no longer be subject to this disclosure requirement.
In addition, UCITS and relevant AIFs using a significant benchmark must include a clear and prominent warning in their prospectus where the ESMA register indicates that the benchmark does not comply with BMR requirements.
Regarding fund liquidations, liquidators of UCITS and AIFs must notify the AMF using the new prescribed form where amounts cannot be paid to unidentified holders of registered units or shares. This notification starts a one-year period after which any remaining amounts must be deposited with the Caisse des dépôts et consignations.
Version française
Le 23 juillet 2026, l’Autorité des marchés financiers (AMF) a mis à jour plusieurs instructions afin de tenir compte du champ d’application révisé du règlement de l’UE sur les indices de référence (BMR) et de préciser la procédure de notification applicable aux montants non réclamés résultant de la liquidation de fonds d’investissement.
Suite à l’entrée en vigueur du règlement (UE) n° 2025/914 au 1er janvier 2026, les indices de référence non significatifs sont généralement exclus du champ d’application du BMR, sauf s’il s’agit d’indices alignés sur l’initiative de Paris, d’indices de transition climatique ou de certains indices de matières premières. L’AMF précise donc que les sociétés de gestion et les entreprises d’investissement agissant en tant qu’administrateurs d’indices de référence ne sont tenus d’obtenir un agrément ou un enregistrement que lorsqu’ils administrent des indices de référence qui restent dans le champ d’application révisé du BMR.
L’AMF a également mis à jour les modèles types de prospectus et de règlement de fonds applicables aux OPCVM et aux FIA. Les fonds existants utilisant des indices de référence qui ne relèvent plus du champ d’application du BMR doivent supprimer toute référence au statut réglementaire de l’administrateur au plus tard le 1er octobre 2026, ou dès que possible par la suite. Certains FIA professionnels et les FIA dont les parts ou actions sont réservées à des clients professionnels ne seront plus soumis à cette obligation d’information.
En outre, les OPCVM et les FIA concernés utilisant un indice de référence significatif doivent inclure dans leur prospectus un avertissement clair et bien visible lorsque le registre de l’AEMF indique que l’indice de référence n’est pas conforme aux exigences du BMR.
En ce qui concerne les liquidations de fonds, les liquidateurs d’OPCVM et de FIA doivent notifier l’AMF à l’aide du nouveau formulaire prescrit lorsque des montants ne peuvent être versés à des détenteurs non identifiés de parts ou d’actions nominatives. Cette notification marque le début d’un délai d’un an à l’issue duquel tout montant restant doit être déposé auprès de la Caisse des dépôts et consignations.
SECONDARY MARKET/TRADING
AMF publishes updated Instruction DOC-2019-21 on prospectus filing and publication procedures / L'AMF publie la version mise à jour de l'instruction DOC-2019-21 relative aux procédures de dépôt et de publication des prospectus
![]()
On 10 July 2026, the Autorité des marchés financiers (AMF) updated Instruction DOC-2019-21 following the application of the final Listing Act measures. The instruction sets out the procedures for filing and publishing prospectuses, universal registration documents, supplements and related promotional materials, as well as the supporting documents to be submitted to the AMF.
The update concerns the standard notices required on the cover of prospectuses approved by the AMF when an issuer uses one of the new simplified prospectus formats introduced by the Listing Act. An additional statement must identify the document as forming part of either an EU Follow-on Prospectus under Article 14a of the Prospectus Regulation or an EU Growth Issuance Prospectus under Article 15a.
The amendment aligns the AMF’s filing documentation with the new prospectus formats applicable since 5 March 2026. It is particularly relevant to issuers preparing secondary issuances or growth issuances under the simplified regimes and to advisers supporting the preparation and submission of prospectus documentation.
Version française
Le 10 juillet 2026, l’Autorité des marchés financiers (AMF) a mis à jour l’instruction DOC-2019-21 à la suite de la mise en œuvre des dispositions définitives de la loi sur la cotation. Cette instruction définit les procédures de dépôt et de publication des prospectus, des documents d’enregistrement universels, des suppléments et des supports promotionnels associés, ainsi que des pièces justificatives à transmettre à l’AMF.
Cette mise à jour concerne les mentions standard requises sur la page de garde des prospectus approuvés par l’AMF lorsqu’un émetteur utilise l’un des nouveaux formats de prospectus simplifiés introduits par la loi sur la cotation. Une mention supplémentaire doit préciser que le document fait partie soit d’un prospectus de suivi européen au titre de l’article 14 bis du règlement Prospectus, soit d’un prospectus d’émission « Growth » européen au titre de l’article 15 bis.
Cette modification aligne la documentation de dépôt auprès de l’AMF sur les nouveaux formats de prospectus applicables depuis le 5 mars 2026. Elle concerne tout particulièrement les émetteurs préparant des émissions secondaires ou des émissions de croissance dans le cadre des régimes simplifiés, ainsi que les conseillers intervenant dans la préparation et le dépôt de la documentation relative aux prospectus.
GERMANY
ANTI-MONEY LAUNDERING / COMBATING TERRORISM FINANCING / COMBATTING PROLIFERATION FINANCING (AML/CFT/CPF)
BaFin publishes Circular on high-risk third countries and FATF AML/CFT country lists.
![]()
On 13 July 2026, BaFin published Circular 07/2026 (GW) which sets out the regulatory consequences for obliged entities supervised by BaFin regarding third countries identified as having strategic deficiencies in their anti-money laundering, counter-terrorist financing and counter-proliferation financing frameworks.
The circular reflects the countries identified under Commission Delegated Regulation (EU) 2016/1675 and the latest FATF statements of 19 June 2026. It outlines the applicable supervisory expectations and legal consequences for German obliged entities under the German Money Laundering Act (GwG).
The circular notes that the European Commission's high-risk third-country list continues to apply and highlights that the Russian Federation remains listed as a high-risk third country under the Delegated Regulation. The document also summarizes the FATF's statements regarding North Korea, Iran and Myanmar, including FATF calls for enhanced due diligence and, in the case of North Korea and Iran, countermeasures intended to protect the international financial system.
The circular reports updates to the FATF list of jurisdictions under increased monitoring. Bosnia and Herzegovina and Iraq were added, while Algeria and Namibia were removed. The FATF monitoring list now contains 22 jurisdictions.
BaFin reiterates that for business relationships and transactions involving North Korea, Iran, or other jurisdictions designated as high-risk under Delegated Regulation (EU) 2016/1675, obliged entities must apply at least the enhanced customer due diligence measures required under section 15(5) GwG.
Additional measures remain applicable for North Korea and Iran, including reporting obligations resulting from BaFin's 2020 general administrative orders.
For jurisdictions appearing only on the FATF "Jurisdictions under Increased Monitoring" list and not on the EU high-risk third-country list, the circular clarifies that no immediate additional legal obligations apply. However, institutions should appropriately consider these jurisdictions when assessing country risk within their AML/CFT frameworks.
The circular replaces previous BaFin circulars addressing EU and FATF country lists related to AML/CFT deficiencies.
BaFin publishes supervisory communication on risks of virtual IBANs linked to underground banking
![]()
On 27 July 2026, BaFin published Supervisory Communication 06/2026 (A) on the risks of virtual IBANs (vIBANs) in connection with underground banking activities.
The publication sets out BaFin's supervisory expectations regarding money laundering and terrorist financing risks arising from the use of virtual IBAN structures and aims to raise awareness among financial sector entities. The communication is based on joint findings from BaFin and the German Financial Intelligence Unit (FIU), which identified significant AML risks associated with vIBAN arrangements, particularly where they are used in informal financial transfer systems commonly referred to as underground banking.
The document applies to financial sector obliged entities and explains how vIBAN structures operate, notably where customer-specific identifiers are linked to a central master account administered by a payment service provider. BaFin highlights that multi-layered arrangements can reduce transparency because account-holding institutions may know only the payment service provider rather than the ultimate users of the vIBANs. Such structures may impair the traceability of payment flows and hinder compliance with customer due diligence obligations under the German Anti-Money Laundering Act (GwG).
The communication identifies specific risk factors, including extensive use of vIBANs linked to foreign payment service providers, incomplete customer information, high transaction volumes lacking economic rationale, suspected shell-company activity, generic payment references, complex cross-border payment routes, and fragmented transaction patterns.
BaFin states that obliged entities should adopt risk-based controls proportionate to the complexity and transparency of the relevant vIBAN structures. Suggested measures include obtaining greater transparency regarding end customers and beneficial owners, updating information on payment service providers, applying enhanced due diligence where appropriate, strengthening transaction monitoring, assessing the plausibility of payment flows, ensuring compliance with account-file obligations, and providing staff training on vIBAN-related risks.
The supervisory communication applies immediately and remains in force until the EU Anti-Money Laundering Regulation becomes applicable on 10 July 2027.
ARTIFICIAL INTELLIGENCE
BaFin publishes press release on AI supervision and new supervisory powers
![]()
On 29 July 2026, BaFin published a press release titled “Überwachung von KI: Bafin erhält neue Kompetenzen”, which announces that BaFin has been granted new powers to act as the market surveillance authority for artificial intelligence (AI) systems used in connection with regulated financial activities.
The publication explains that the German legislator has expanded BaFin’s mandate through the national law implementing the EU Artificial Intelligence Act. The law entered into force on 29 July 2026. Under the new framework, BaFin will monitor whether supervised entities comply with the requirements of the AI Act. The scope covers credit institutions, insurance undertakings and other financial sector entities supervised by BaFin where AI systems are directly linked to regulated financial services.
BaFin states that its market surveillance activities will include oversight of transparency obligations applicable to AI systems that interact directly with individuals, such as customer service chatbots. The authority will also supervise compliance with provisions concerning prohibited AI practices. In addition, BaFin will oversee high-risk AI systems, including systems used by banks for creditworthiness assessments and by insurers for risk assessments in life and health insurance.
The publication stresses that AI deployment should be transparent, non-discriminatory and supported by effective risk management. It further notes that decisions made using AI should remain subject to human correction and reversal, while responsibility for AI use remains with supervised institutions and their management bodies.
The publication outlines the phased application timetable under the AI Act. Certain prohibited AI practices have applied since 2 February 2025. Initial transparency obligations apply from 2 August 2026, while requirements for high-risk AI systems apply from 2 December 2027. BaFin also clarifies that its mandate is limited to AI systems directly connected to regulated financial activities; other AI use cases, such as human resources management, fall under the responsibility of the Federal Network Agency. BaFin may impose administrative fines for infringements of the AI Act.
BGBL publishes national law on implementation of the EU AI Act
![]()
BACKGROUND
On 28 July 2026, Germany published in the Federal Law Gazette the Act implementing Regulation (EU) 2024/1689 on artificial intelligence, dated 22 July 2026. The Act establishes the national framework for implementing the EU AI Act in Germany and introduces the AI Market Surveillance and Innovation Promotion Act (KI-MIG).
The legislation designates competent authorities, sets out market surveillance and cooperation arrangements, introduces measures to promote innovation and establishes national rules on administrative fines. It applies to AI systems within the meaning of the AI Act and covers providers, deployers and other actors falling within the respective supervisory remits. For AI systems directly connected with regulated financial activities, BaFin is designated as the competent market surveillance authority for a broad range of supervised financial institutions.
WHAT'S NEW?
Supervisory architecture
The Federal Network Agency (Bundesnetzagentur) is designated as the general market surveillance authority unless another authority is specifically competent. It also hosts the central coordination and competence centre, acts as Germany’s single point of contact and operates the central complaints office.
Financial sector supervision
BaFin is designated as the market surveillance authority for AI systems directly connected with regulated financial activities of supervised entities. The scope includes, among others:
- credit institutions, payment and e-money institutions, investment firms and crypto-asset service providers;
- management companies, CCPs, CSDs and crowdfunding service providers;
- insurance undertakings, pension funds and specified financial and insurance holding companies.
High-risk AI and enforcement
An independent AI Market Surveillance Chamber is established within the Bundesnetzagentur for specified high-risk AI systems. Competent authorities receive the market-surveillance powers provided under Regulation (EU) 2019/1020 and the AI Act. Certain infringements under the national implementing framework may result in fines of up to EUR 50,000.
Innovation and testing
The Bundesnetzagentur must establish at least one AI regulatory sandbox and provide information, training and other innovation-support measures. Providers or prospective providers testing specified high-risk AI systems in real-world conditions must submit a testing plan to the competent authority; authorisation is deemed granted where no response is received within 30 days.
WHAT'S NEXT?
The Act enters into force on the day following its publication, i.e. 29 July 2026. The Federal Government must conduct a first evaluation of the supervisory and authority structure within 18 months of entry into force and a further evaluation within three years. The AI Market Surveillance Chamber must submit its first annual activity report for 2026 to the Bundestag by 31 March 2027.
GOVERNANCE & ORGANISATION
BaFin publishes updated circular on the suitability of management body and supervisory board members under the KWG
![]()
On 30 July 2026, BaFin published an update to Circular 11/2025 (BA) on Members of the Management Board and Administrative and Supervisory Bodies under the German Banking Act (KWG), which sets out BaFin's supervisory expectations regarding the fitness and propriety of managing directors and members of administrative and supervisory bodies of institutions subject to the German Banking Act (Kreditwesengesetz – KWG).
The circular provides guidance on professional qualifications, personal reliability, integrity, time commitment, governance expectations, and notification requirements applicable to individuals appointed to management and oversight functions.
The circular incorporates into BaFin's administrative practice the Joint EBA and ESMA Guidelines on the assessment of the suitability of members of the management body and key function holders, as well as the EBA Guidelines on Internal Governance. It outlines the suitability assessment framework covering knowledge, skills and experience, reputation, integrity, independence of mind, conflicts of interest, collective suitability of management bodies, diversity considerations, and requirements relating to key function holders.
The publication also provides an overview of applicable notification obligations and supporting documentation requirements for appointments and personnel changes involving management board and supervisory board members. To facilitate regulatory notifications, BaFin makes available a series of standardized forms, including suitability matrices and notification templates for significant and less significant institutions.
The circular is relevant for institutions subject to KWG requirements when assessing the suitability of proposed and existing members of management and supervisory bodies, documenting assessments, managing conflicts of interest, demonstrating adequate governance arrangements, and submitting notifications to supervisory authorities.
The publication further clarifies that, for supervisory examination purposes, the guidance is to be applied from 1 January 2026.
SECONDARY MARKET/TRADING
BaFin publishes Supervisory Notice on the Entry into Force of the Payment for Order Flow (PFOF) Ban
![]()
On 22 July 2026, BaFin published Supervisory Notice 05/2026 (WA) on the entry into force of the Payment for Order Flow (PFOF) ban in Germany, which sets out BaFin’s supervisory expectations regarding the implementation of the prohibition under Article 39a(1) MiFIR and provides an initial assessment of business models arising in connection with the ban.
The notice follows the full application in Germany of the PFOF prohibition from 1 July 2026, after the expiry of a two-year transitional period. The ban prevents investment firms from receiving third-party payments for routing client orders to trading venues. According to the publication, the objective is to improve execution quality for retail orders by eliminating conflicts of interest that could interfere with firms’ best execution obligations.
The notice applies to investment firms within the meaning of MiFID II, including German securities institutions under the German Securities Trading Act (WpHG). It remains effective from its publication date until 30 June 2029, although BaFin may amend it earlier if further guidance is issued by the European Commission or ESMA or if supervisory practice evolves.
BaFin outlines its expectation that firms should review and, where necessary, modify business models previously based on PFOF and avoid structures that circumvent the prohibition.
The notice identifies examples of business arrangements that BaFin considers compliant, including execution of client orders through proprietary trading activities such as systematic internalisers or market makers, provided applicable MiFID II and best execution requirements are respected. It also clarifies that certain issuer-paid distribution remunerations for primary-market products are outside the scope of the PFOF prohibition.
Conversely, the notice describes several arrangements regarded as impermissible circumventions, including payments routed through clients, intermediary commission structures designed to preserve PFOF economics, and group-owned trading venues using excessive settlement fees to redirect revenues. BaFin further expects firms to consider ESMA-published European Commission Q&As and clarifies the application of the ban to instructed orders and OTC executions.
SUSTAINABLE FINANCE / GREEN FINANCE
Bundesregierung publishes draft Action Plan “Sustainability for a Modern and Future-Proof Germany”
![]()
On 16 July 2026, Bundesregierung published the draft Action Plan “Nachhaltigkeit für ein modernes und zukunftsfähiges Deutschland”, which sets out a mission-based framework for implementing Germany’s sustainability strategy and contributing to the objectives of the UN Agenda 2030.
The Action Plan complements the German Sustainability Strategy (DNS) and focuses on strengthening the long-term resilience and sustainability of the state, economy and society. It identifies five overarching action areas: (i) effective government and sustainable public finances, (ii) a competitive and sustainable economy, (iii) social cohesion and equal living conditions, (iv) protection of natural resources, and (v) international responsibility and cooperation.
The publication introduces 19 missions to be implemented during the current legislative period and beyond. These missions are assigned to specific ministries and include objectives such as increasing the digitalisation of public administration by 2029, integrating sustainability assessments into legislative processes, simplifying sustainability reporting through the German Sustainability Code (DNK), supporting sustainable supply chains and human-rights due diligence, promoting sustainable public procurement, improving social cohesion, strengthening democratic institutions, protecting ecosystems and advancing climate-friendly infrastructure.
A cross-cutting theme throughout the Action Plan is sustainable finance, which is identified as an overarching principle supporting the implementation of sustainability objectives across policy areas. One mission specifically aims to simplify sustainability reporting and facilitate financing through enhancement of the DNK platform, including the establishment of interfaces with financial market participants and banks by 2029.
The document states that each mission will be supplemented by implementation measures, milestones and, where possible, effectiveness indicators. Monitoring and reporting mechanisms will support the assessment of progress. The Plan remains subject to budgetary and financing constraints and does not itself create binding financial commitments.
The publication is issued as a consultation draft (Beteiligungsfassung) and outlines the Government’s intended sustainability priorities, implementation approach and policy missions through 2029 and beyond.
GUERNSEY
ANTI-MONEY LAUNDERING / COMBATING TERRORISM FINANCING / COMBATTING PROLIFERATION FINANCING (AML/CFT/CPF)
GFSC publishes consultation paper on AML/CFT/CPF framework amendments addressing MONEYVAL recommendations
![]()
On 30 July 2026, the Guernsey Financial Services Commission and the Policy & Resources Committee published the consultation paper Addressing MONEYVAL’s Supervisory Recommendations for Preventing Money Laundering, Terrorist Financing and Proliferation Financing, which proposes amendments to the AML/CFT/CPF supervisory framework, including the Handbook on Countering Financial Crime and related legislation, to address recommendations arising from MONEYVAL’s 2025 mutual evaluation of Guernsey.
The consultation proposes a range of targeted changes designed to strengthen customer due diligence, beneficial ownership transparency, risk assessment, monitoring and reporting obligations. Key proposals include requiring proof of existence for legal person customers and trusts, introducing enhanced requirements for identifying and verifying trustees and trust beneficiaries, removing automatic exemptions for beneficial owners that are Commission-regulated entities, and limiting simplified due diligence measures to cases where money laundering, terrorist financing and proliferation financing risks have been assessed as low.
Additional proposals address politically exposed persons in life and investment-linked insurance policies, reliable introduction arrangements, AML/CFT/CPF obligations for domestic branches and subsidiaries, wire transfer due diligence requirements for non-established customers, and consideration of risks arising from new technologies by registered directors. The consultation also introduces new expectations regarding the assessment and management of complex customer structures and seeks to strengthen firms’ monitoring and suspicious activity reporting frameworks.
The paper further proposes amendments to Schedules 1 and 4 of the Proceeds of Crime Law, including excluding certain insurance premium financing activities from AML/CFT obligations and removing certain registration requirements for firms undertaking specific virtual asset-related activities. It also seeks stakeholder views on the future of Appendix C, which lists jurisdictions considered to have AML/CFT/CPF standards equivalent to FATF requirements.
Responses are requested by 9 October 2026. Following consultation, the authorities intend to finalise amendments to legislation and the Handbook by the end of 2026 and subsequently report progress to MONEYVAL ahead of its May 2027 plenary review.
BLOCKCHAIN & DISTRIBUTED LEDGER TECHNOLOGY (DLT)
GFSC publishes feedback paper and guidance on digital finance growth and asset tokenisation
![]()
On 24 July 2026, the Guernsey Financial Services Commission (GFSC) published a Feedback Paper on Supporting Growth with Digital Finance and a Guidance Note on the Tokenisation of Investments, which set out regulatory refinements intended to simplify the digital finance framework, provide greater regulatory clarity, and support innovation in Guernsey's financial sector.
The publications follow the consultation on Supporting Growth with Digital Finance and form part of the Commission's Digital Finance Initiative and its contribution to the Finance Sector Growth Strategy 2035. According to the GFSC, consultation feedback confirmed that Guernsey's existing technology-neutral regulatory framework is generally suitable for digital finance activities. The Commission therefore proposes targeted adjustments designed to reduce complexity, improve routes to market for firms, and facilitate innovation while maintaining regulatory standards.
The measures being taken forward include the publication of new guidance on the tokenisation of investments and other assets. The guidance permits the use of public blockchains for fund tokenisation and clarifies the treatment of tokenised securities. The Commission also intends to remove rules that prevent Virtual Asset Service Provider (VASP) licensees from serving retail customers and to eliminate additional environmental reporting obligations previously applicable to such firms.
In addition, the GFSC provides regulatory clarification regarding specific activities, including confirmation that tokenised insurance-linked securities do not require VASP licensing. The package further supports the adoption of emerging technologies such as smart contracts and introduces simplified reporting requirements intended to help the regulator monitor digital finance activity in the Bailiwick.
The Commission will also work with the States of Guernsey to simplify and clarify elements of the legal and regulatory framework governing digital finance businesses. The planned changes aim to streamline licensing arrangements and allow existing investment and insurance licensees to undertake certain virtual asset activities under specified conditions without obtaining an additional VASP licence. Further feedback and rules concerning stablecoins are expected in autumn 2026.
IRELAND
ALTERNATIVE PRODUCTS
CBI publishes an updated AIF Rulebook
![]()
BACKGROUND
On 30 July 2026, the Central Bank of Ireland published an updated AIF Rulebook, effective from 29 July 2026, amending Parts III and IV of Chapter 2. The amendments introduce specific requirements for Qualifying Investor Alternative Investment Funds (QIAIFs) managed by registered Alternative Investment Fund Managers (AIFMs) and by non-EU AIFMs.
The changes extend selected requirements under the Irish AIFM Regulations and AIFMD Level 2 framework to these two categories of QIAIF manager. QIAIFs managed by fully authorised EU AIFMs remain subject to separate provisions of the AIF Rulebook.
WHAT'S NEW?
Scope of the amendments
The revised provisions apply to:
- Part III – QIAIFs managed by a registered AIFM below the AIFMD authorisation threshold in Ireland.
- Part IV – QIAIFs managed by a non-EU AIFM.
The requirements introduced in Parts III and IV are substantively parallel.
AIFM Regulations requirements
Registered and non-EU AIFMs must comply with specified provisions of the Irish AIFM Regulations covering general principles, delegation, liquidity management, valuation and transparency. The amendments also extend specified loan origination requirements, including Regulations 16(6)(d), 16(6A), 16(6B) and 17A.
Loan origination and depositary
Where a QIAIF managed by either category of AIFM qualifies as a loan originating AIF, it must be closed-ended. In both cases, the QIAIF must appoint a single depositary in accordance with Regulation 22(1) of the AIFM Regulations.
AIFMD Level 2 requirements
The managers must also comply with specified AIFMD Level 2 provisions relating to:
- counterparty and prime broker due diligence, inducements and order execution;
- alignment of investment strategy, liquidity profile and redemption policy;
- valuation policies, NAV calculation and valuation frequency;
- annual report content and format.
WHAT'S NEXT?
The updated AIF Rulebook became effective on 29 July 2026. The amendments to Parts III and IV therefore apply from that date to QIAIFs managed by registered AIFMs and non-EU AIFMs within their respective scope.
Ireland publishes S.I. No. 316/2026 on UCITS Regulation 2026
![]()
BACKGROUND
On 10 July 2026, Ireland published S.I. No. 316/2026 – Central Bank (Supervision and Enforcement) Act 2013 (Section 48(1)) (Undertakings for Collective Investment in Transferable Securities) Regulations 2026. Issued by the Central Bank of Ireland under Section 48 of the Central Bank (Supervision and Enforcement) Act 2013, the Regulations consolidate and replace the 2019 UCITS Regulations and their 2023 amendment, establishing an updated regulatory framework for UCITS, UCITS management companies and UCITS depositaries in Ireland.
The Regulations also cover EEA-passporting management companies and cross-border UCITS activities, including inward and outward passport notifications.
WHAT'S NEW?
Investment restrictions and risk management
The Regulations consolidate requirements covering eligible assets, money-market instruments, deposits, FDI and financial indices, alongside liquidity assessment documentation. They also set out requirements for global exposure calculations using commitment and VaR approaches, back-testing, stress testing and leverage monitoring.
Efficient portfolio management and share classes
Requirements cover securities lending, repurchase agreements and collateral management. In particular:
- Collateral portfolios representing 30% or more of NAV are subject to stress-testing requirements.
- Currency-hedged share classes are subject to over/under-hedging limits of 95%–105% of NAV.
Liquidity management and valuation
UCITS must select at least one quantitative and one anti-dilution liquidity management tool. The framework also covers redemption gates, side pockets and suspensions, while valuation requirements include a documented valuation policy and the valuation methods prescribed in Schedule 5.
Performance fees
Performance fees are subject to specific conditions:
- Fees may only be payable where positive net performance has accrued during the performance reference period.
- Crystallisation is generally limited to once per year, subject to specified exceptions.
- Where the reference period is shorter than the fund's life, it must cover at least five years on a rolling basis.
Management companies and depositaries
Management company requirements cover capital, ICAAP, delegation monitoring, board responsibilities, director residency and record-keeping. Depositary requirements address governance, operating conditions, financial reporting, agreements and breach notification.
Prospectus and disclosure
The Regulations consolidate disclosure requirements concerning investment policy, FDI use, risk disclosures, performance fees, distributions from capital, advertising standards and KIID/KID filing.
WHAT'S NEXT?
The Regulations revoke and replace S.I. No. 230 of 2019 and S.I. No. 565 of 2023, consolidating the applicable Central Bank UCITS requirements into a single instrument.
The notice of making of S.I. No. 316/2026 was published in Iris Oifigiúil on 10 July 2026.
ANTI-MONEY LAUNDERING / COMBATING TERRORISM FINANCING / COMBATTING PROLIFERATION FINANCING (AML/CFT/CPF)
Ireland publishes S.I. No. 335/2026 on European Union (Anti-Money Laundering: Beneficial Ownership of Trusts) (Amendment) Regulations 2026
![]()
BACKGROUND
On 17 July 2026, the Irish Minister for Finance issued S.I. No. 335 of 2026 – European Union (Anti-Money Laundering: Beneficial Ownership of Trusts) (Amendment) Regulations 2026. The Regulations amend the European Union (Anti-Money Laundering: Beneficial Ownership of Trusts) Regulations 2021 (S.I. No. 194 of 2021) to give effect to Articles 11, 12, 13 and 15 of Directive (EU) 2024/1640 on mechanisms for the prevention of the use of the financial system for money laundering or terrorist financing (AMLD6). The amendments primarily concern access to Ireland’s central register of beneficial ownership of trusts, including access by competent authorities and persons demonstrating a legitimate interest.
WHAT'S NEW?
Access by competent authorities
The list of authorities entitled to access the central register is expanded to include, among others, AMLA for joint analyses, EPPO, OLAF, Europol and Eurojust, as well as relevant Irish ministries and the Central Bank of Ireland.
Legitimate-interest access
The Regulations introduce a detailed framework allowing persons demonstrating a legitimate interest to inspect specified beneficial ownership information. Persons deemed to have such an interest include:
- journalists, media professionals and relevant civil society organisations;
- persons likely to enter into transactions with a trust and certain third-country AML/CFT entities and authorities;
- providers of AML/CFT products, subject to specified conditions.
Certificates permitting access are generally valid for three years, unless revoked earlier. Certain eligible persons may also access historical beneficial ownership information for trusts dissolved or ceased to exist during the preceding five years.
Access procedures and safeguards
The Regulations establish criteria for assessing legitimate-interest applications and grounds for refusal or revocation. They also introduce identity verification, electronic access and procedures restricting disclosure where beneficial owners are minors, lack legal capacity or face specified disproportionate risks.
Review and appeal rights
Decisions restricting access are subject to specified review procedures. Refusals or revocations may also be appealed to the District Court within the prescribed time limits.
WHAT'S NEXT?
From 10 November 2026, the Registrar must generally respond to legitimate-interest submissions within 12 working days, subject to specified extensions. Subsequent inspection requests by certificate holders must be answered within seven working days. Review requests and District Court appeals are subject to the procedural deadlines established in the Regulations.
Ireland publishes the 2026 national risk assessment on AML/CFT/CPF
![]()
On 15 July 2026, the Department of Finance published the National Risk Assessment 2026: Money Laundering, Terrorist Financing, and Proliferation Financing, which delivers a comprehensive national-level analysis of Ireland's ML, TF and PF risks, incorporating Ireland's first formal assessment of proliferation financing.
Prepared by the Anti-Money Laundering Steering Committee (AMLSC) and drawing on contributions from government departments, law enforcement, intelligence agencies, regulators and the private sector, this is Ireland's third NRA and provides the evidence base for policy development, risk-based supervision and proportionate AML/CFT/CPF measures ahead of Ireland's 2028 FATF Mutual Evaluation Report.
The NRA covers the full range of Irish obliged entities across financial services (retail and non-retail banking, funds, crypto-assets, payment and e-money institutions, life insurance, MiFID investment and markets firms, retail intermediaries, bureaux de change, retail credit firms) and designated non-financial businesses and professions (DNFBPs), including real estate, gambling, legal services, accounting, trust and company service providers, high value goods dealers, non-profit organisations, and legal persons and arrangements. Geographic scope is Ireland.
The NRA uses a four-tier scale: Low, Moderate, Significant, Very Significant.
- ML Threat: Rated moderate overall. Highest threats from drug offences and fraud, followed by theft and burglary, illicit trade and smuggling, human trafficking and tax crime. Criminal networks increasingly combine cash-based methods with crypto-assets, money mule networks and complex layering techniques.
- TF Threat: Rated low overall, with risks from domestic paramilitary groups and international networks. Small-scale self-funded operations and digital platforms (including crypto-assets) require continued vigilance.
- PF Threat: Rated low, reflecting limited direct exposure to jurisdictions of concern. Indirect exposure via complex financial flows and dual-use goods warrants vigilance.
- Highest-risk sectors: ML and TF risk in traditional retail banks, digital banks, crypto-assets, e-money institutions, money remitter payment institutions and non-securitisation SPEs rated very significant. Funds management companies upgraded to significant ML risk. Crypto-assets upgraded to very significant for both ML and TF.
Five high-level priorities are identified:
(i) risk and coordination — enhanced inter-agency collaboration and strategic analysis;
(ii) capacity building and public awareness — training for LEAs, FIU, supervisors and reporting institutions, and public education on money mule accounts;
(iii) law enforcement — strengthened risk-based, intelligence-led enforcement;
(iv) framework, policy and strategy — NRA-informed policy and resource allocation; and
(v) regulatory and preventive — entity-level risk understanding, supervision, enforcement and compliance outreach.
ARTIFICIAL INTELLIGENCE
Ireland publishes the Regulation of Artificial Intelligence Act 2026 (No. 31 of 2026)
![]()
On 21 July 2026, Ireland published the Regulation of Artificial Intelligence Act 2026 (No. 31 of 2026), which establishes the national institutional and enforcement framework for the implementation of Regulation (EU) 2024/1689 (the EU AI Act) in Ireland, creates a new supervisory body (Oifig IS na hÉireann), and amends the Central Bank Act 1942, the Competition and Consumer Protection Act 2014, the Communications Regulation Act 2002, and the Freedom of Information Act 2014.
The Act gives domestic effect to the EU AI Act (Regulation (EU) 2024/1689) in Ireland by establishing the governance, supervisory, and enforcement architecture required at national level. It follows the European Union (Artificial Intelligence) (Designation) Regulations 2025 (S.I. No. 366 of 2025), which designated the relevant market surveillance and competent authorities. The commencement date for individual provisions will be appointed by Ministerial order.
The Act applies to: all persons subject to the EU AI Act operating in Ireland; relevant market surveillance authorities and competent authorities designated under the Designation Regulations; the Central Bank of Ireland as a market surveillance authority for AI systems within its supervisory remit; the Competition and Consumer Protection Commission (CCPC) for AI systems within its remit; and Coimisiún na Meán and other sector-specific authorities.
The Act establishes five structural pillars. First, it creates Oifig IS na hÉireann — a new statutory body corporate — as the single point of contact under Article 70(2) of the EU AI Act, responsible for coordinating national AI supervision, operating the AI register, managing AI regulatory sandboxes, facilitating the co-operation forum among competent authorities, and promoting AI innovation and literacy.
The Office has a 7-member board appointed through the Public Appointments Service, a Chief Executive Officer, and operates independently in the performance of its functions.
Second, on supervision and enforcement, the Act confers broad powers on authorised officers of relevant market surveillance authorities, including premises entry, document seizure, sample acquisition (including under cover identity), contravention notices, prohibition notices, forfeiture orders, and notices for removal of online content presenting serious AI risk.
Third, on adjudication and administrative fines, for applicable market surveillance authorities (including the CCPC, the Data Protection Commission, the Health and Safety Authority, Coimisiún na Meán, and others), the Act creates an independent adjudication system with court-confirmed findings; administrative fines are aligned with Article 99 of the EU AI Act (up to EUR 35 million or 7% of global turnover for prohibited practices; lower thresholds for other infringements); fines on public bodies are capped at EUR 1 million.
Fourth, on the Central Bank of Ireland, Parts 5, 6, and 7 (the general enforcement and adjudication regime) do not apply; instead, the Central Bank may impose administrative fines under its existing Central Bank Act 1942 inquiry procedures, with the EU AI Act added to its list of designated enactments.
Fifth, on the CCPC, a new Part 2A is inserted into the Competition and Consumer Protection Act 2014 establishing a parallel investigation, decision, and administrative fine regime for AI Regulation infringements within the CCPC's market surveillance remit.
CONSUMER PROTECTION
Ireland publishes European Union (Distance Contracts for Financial Services) Regulations 2026
![]()
On 3 July 2026, Ireland published S.I. No. 309 of 2026 – European Union (Distance Contracts for Financial Services) Regulations 2026, transposing Directive (EU) 2023/2673 and amending the Consumer Rights Act 2022.
The Regulations establish a revised consumer protection framework for financial services contracts concluded remotely. Traders must provide consumers with prescribed pre-contractual information in a clear and comprehensible manner and on a durable medium, together with adequate explanations enabling consumers to assess whether the proposed service is appropriate for their needs and financial situation.
Consumers generally benefit from a 14-day cancellation period, extended to 30 days for personal pension contracts. Where contracts are concluded through an online interface, traders must provide a prominently displayed and continuously accessible online cancellation function, acknowledge cancellations without undue delay and retain evidence of compliance.
The Regulations also require traders to:
- remind consumers of their cancellation rights where information was provided less than one day before contract conclusion;
- provide access to human intervention during online contracting processes;
- disclose the main parameters used to rank offers;
- avoid online interface designs that deceive, manipulate or materially impair consumers’ decision-making; and
- provide accessible information formats upon request by consumers with disabilities.
Non-compliance with several of these requirements constitutes an offence. Enforcement responsibilities are allocated between the Competition and Consumer Protection Commission and the Central Bank of Ireland. The previous European Communities (Distance Marketing of Consumer Financial Services) Regulations 2004 are revoked.
GOVERNANCE & ORGANISATION
CBI publishes a supplemental guidance on the prohibition notices under the fitness and probity regime
![]()
On 30 July 2026, CBI published Prohibition Notices under the Fitness and Probity Regime: Supplemental Guidance, which supplements the 'Decision' chapter of the existing Main Guidance on Fitness and Probity Investigations, Suspensions and Prohibitions (April 2023) by setting out the circumstances and general principles applicable to the imposition, nature, cessation and publication of prohibition notices under the Central Bank Reform Act 2010 (the Act).
The Supplemental Guidance applies to the fitness and probity regime established under Part 3 of the Act, specifically to individuals subject to prohibition proceedings (Subjects), relevant entities (i.e. regulated financial service providers), and the Prohibition Decision Maker appointed from the Regulatory Decisions Panel. It is effective from 30 July 2026 and must be read together with the Main Guidance. Geographic scope is Ireland. The guidance applies across all regulated entities within the Central Bank's supervisory remit whose staff perform Controlled Function (CF) roles, including Pre-Approval Controlled Function (PCF) roles.
The Supplemental Guidance addresses five areas:
Prohibition Decision Maker: A member of the Regulatory Decisions Panel — comprising external experts and Bank staff — is appointed to decide on prohibitions. The appointee must be suitably qualified, have had no prior involvement in the relevant investigation, and be free of conflicts of interest.
Relevant Circumstances Guidance (Table 1): A non-exhaustive framework of seven factors the Prohibition Decision Maker must consider: (A) the extent to which the Subject lacks appropriate fitness and probity; (B) the degree of risk to the statutory objectives (protecting financial system stability and users of financial services), with specific higher-range risk indicators including fraud, money laundering, serious misconduct, criminal conviction and other serious lack of integrity; (C) previous supervisory, disciplinary and criminal record; (D) time elapsed since the relevant matters; (E) subsequent behaviour and remediation; (F) insight shown by the Subject; and (G) personal circumstances.
Nature of Prohibition: The scope (one entity, a class, or all relevant entities), duration (specified period up to 5 years for lower-risk cases; indefinite for higher-risk cases) and conditions (if any) are determined proportionately by reference to the Section 43(4) objectives. Conditions may include supervision requirements, qualification or training obligations, or restrictions on the manner of performing a CF.
Cessation and Review: A Prohibition Notice ceases upon termination of a prohibition agreement by the Bank, expiry of a specified period, or revocation/variation by the High Court. Subjects may request termination in writing; the Bank will only consider such requests where satisfied the Subject is fit and proper and the risk will not recur.
Publication: The Governor may publish a Prohibition Notice where necessary to achieve the purposes of Part 3 of the Act. Publication serves to inform the sector and public, prevent circumvention of prohibitions, uphold standards and maintain confidence. Submissions are invited before publication decisions are made; data protection obligations apply.
SANCTIONS/RESTRICTIVE MEASURES
Ireland publishes S.I No. 364 of 2026 on restrictive measures concerning certain persons and entities associated with the ISIL (Da'esh) and Al-Qaida organisations
![]()
On 23 July 2026, Ireland published S.I. No. 364 of 2026, the Criminal Justice (Terrorist Offences) Act 2005 (Section 42) (Restrictive Measures concerning Certain Persons and Entities Associated with the ISIL (Da'esh) and Al-Qaida Organisations) (No. 4) Regulations 2026, which give domestic legal effect to Council Regulation (EC) No. 881/2002 of 27 May 2002 (as amended) and revoke the previous domestic instrument on the same subject (S.I. No. 149 of 2026).
Council Regulation (EC) No. 881/2002 establishes restrictive measures — including asset freezing and related prohibitions — against persons, groups, and entities associated with ISIL (Da'esh) and Al-Qaida. The Regulation is directly applicable in Ireland as EU law but requires domestic implementing legislation under Section 42 of the Criminal Justice (Terrorist Offences) Act 2005 to create criminal offences for breach and to confer enforcement powers on the Central Bank of Ireland. The 2026 (No. 4) Regulations consolidate all amendments to Council Regulation (EC) No. 881/2002 up to and including Commission Implementing Regulation (EU) 2026/1812 of 16 July 2026 (the most recent listed amendment), replacing the (No. 3) Regulations made earlier in 2026 (S.I. No. 149 of 2026).
The Regulations apply to all persons in Ireland subject to the obligations of Council Regulation (EC) No. 881/2002, including financial institutions and all other natural and legal persons who must comply with asset freezing and related prohibitions in respect of listed persons and entities associated with ISIL and Al-Qaida. The Central Bank of Ireland is empowered to issue written directions to any person for the purposes of the Regulations and the Council Regulation. The geographic scope is Ireland. The Regulations entered into force on their making on 23 July 2026 (notice published in Iris Oifigiúil of 24 July 2026).
The Regulations impose three core requirements.
First, it is a requirement — breach of which constitutes a criminal offence under Section 42 of the Criminal Justice (Terrorist Offences) Act 2005 — that no person contravene Council Regulation (EC) No. 881/2002 as amended.
Second, the Central Bank of Ireland may issue written directions to any person for the purposes of the Regulations and the Council Regulation, and compliance with such directions is mandatory.
Third, the previous domestic implementing instrument (S.I. No. 149 of 2026) is revoked and replaced by these Regulations, which incorporate all 366 amendments to the Council Regulation listed in the Schedule, through to Commission Implementing Regulation (EU) 2026/1812 of 16 July 2026.
ITALY
OTHER - PRUDENTIAL REQUIREMENTS
Banca d’Italia publishes consultation document on CRD VI implementation across prudential rules, ownership structures and material transactions
![]()
On 22 July 2026, Banca d’Italia published a Consultation Document on amendments to its supervisory provisions concerning material transactions, real estate investments, cooperative banks, capital buffers and ownership structures, which aim to implement the requirements introduced by Directive (EU) 2024/1619 (CRD VI).
The consultation proposes amendments to Circular No. 285/2013 and related supervisory provisions to align the Italian prudential framework with CRD VI. The proposed changes cover five main areas: (i) material transactions, (ii) real estate investments, (iii) cooperative banks (BCCs), (iv) capital buffers, and (v) ownership structures.
For material transactions, the proposals introduce authorization requirements for acquisitions of significant participations, notification requirements for disposals of significant participations, authorization frameworks for mergers and demergers, and notification obligations for significant transfers of assets and liabilities. Detailed procedures, assessment criteria, supervisory cooperation arrangements and timelines are established.
For real estate investments and participations, the consultation removes existing national limits that are no longer compatible with CRD VI. However, prudential concentration and aggregate limits applicable under the CRR continue to apply to qualifying participations in non-financial undertakings.
For cooperative banks, certain national restrictions on acquiring participations are removed to align with CRD VI, while preserving mutuality and territoriality principles applicable to BCCs.
For capital buffers, the consultation introduces amendments concerning the review of systemic risk buffers and O-SII buffers where institutions become constrained by the output floor, clarifies that systemic risk buffers may address climate-related systemic risks, and simplifies certain notification procedures between authorities.
For ownership structures, procedural changes include extending certain supervisory timelines, introducing mandatory AML/CFT consultation during qualifying holding assessments, updating rules on acting in concert, and introducing reporting obligations regarding events affecting the suitability of qualified shareholders.
Stakeholders may submit comments within 60 days after publication. Following the consultation, Banca d’Italia will assess feedback and publish final provisions through updates to Circular No. 285/2013 and related ownership structure rules.
REPORTING
CONSOB publishes Consultation Document on amendments to MiFID II, MiFIR, AIFMD and UCITS implementing regulations.
![]()
On 17 July 2026, CONSOB published a Consultation Document which proposes amendments to the Intermediaries Regulation, Markets Regulation and Issuers Regulation to implement recent EU changes to the MiFID II, MiFIR, AIFMD and UCITS frameworks, while also introducing targeted amendments concerning insurance-based investment products (IBIPs), financial advisers and intermediary authorisation procedures.
The consultation aims to align Italian secondary legislation with EU Directive 2024/790, Regulation 2024/791, Directive 2024/927 (AIFMD2/UCITS changes), the Listing Act package and related delegated legislation. The proposed amendments cover market infrastructures, transparency requirements, best execution, systematic internalisers, market data reporting, investment research, collective investment management and cross-border fund distribution.
For market participants, the proposals would update rules on systematic internalisers, pre- and post-trade transparency, market data disclosure, position limits, publication arrangements and best execution obligations. Certain MiFID reporting obligations would be simplified in line with the revised EU framework.
For asset managers and funds, the consultation would implement AIFMD2 requirements, including expanded fund manager activities, harmonised liquidity management tools (LMTs), additional investor disclosures, new requirements for credit funds, and conflict-of-interest provisions for “white label” fund structures.
Regarding insurance-based investment products, CONSOB proposes to simplify pre-contractual disclosure obligations, align aspects of the framework with IVASS requirements, clarify digital distribution disclosures and remove rules on third-party investment research relating to IBIP distribution.
The consultation also proposes amendments to the sanctions framework applicable to financial advisers, including clearer criteria for increasing or reducing sanctions and enhanced requirements for justification of sanctioning decisions. Additional “fine-tuning” measures would increase transparency of the SIM register and streamline authorisation procedures.
Stakeholders may submit comments until 15 September 2026. Following the review of consultation responses, CONSOB will decide whether to adopt final regulatory amendments.
LUXEMBOURG
ALTERNATIVE PRODUCTS
Chambre des députés publishes Draft Law 8814 amending the AIFM Law of 12 July 2013 / La Chambre des députés publie le projet de loi n° 8814 modifiant la loi du 12 juillet 2013 relative aux gestionnaires de fonds d'investissement alternatifs (AIFM)
![]()
On 30 July 2026, Chambre des députés published draft law 8814 amending the amended Law of 12 July 2013 on alternative investment fund managers (the AIFM Law), which introduces the possibility for Luxembourg-based alternative investment funds (AIFs) constituted as limited partnerships (sociétés en commandite simple, SCS) or special limited partnerships (sociétés en commandite spéciale, SCSp), and not subject to any product law, to adopt a multi-compartment structure. The stated objective is to modernise Luxembourg's investment fund toolbox and strengthen the attractiveness of the financial centre.
The draft law applies to Luxembourg AIFs constituted as SCS or SCSp that are not subject to any existing product law (i.e. the SICAR Law, the SIF Law, the RAIF Law or Part II of the UCI Law), provided they are managed by a Luxembourg-authorised AIFM under the AIFM Law or by an EU-authorised AIFM under Directive 2011/61/EU (AIFMD). The draft expressly clarifies that the new framework does not affect the equivalent multi-compartment provisions available under the existing product laws, which continue to prevail.
The draft introduces a new Article 28bis into Chapter 5 of the AIFM Law, modelled on Article 49 of the RAIF Law:
- Multi-compartment structure: Each compartment corresponds to a distinct portion of the AIF's assets. The use of a multi-compartment structure and its terms must be expressly provided for in the constitutive documents, and the specific investment policy of each compartment must be described in accordance with Article 21 of the AIFM Law.
- Asset segregation: Investors' and creditors' rights are limited to the assets of the relevant compartment, unless the constitutive documents provide otherwise; in relations between investors, each compartment is treated as a separate entity.
- Independent liquidation: Each compartment may be wound up separately without triggering the liquidation of other compartments; only the liquidation of the last compartment results in the liquidation of the AIF as a whole.
- Cross-compartment investments: A compartment may subscribe, acquire or hold interests in other compartments of the same AIF, subject to no circular investment and suspension of associated voting rights.
- Reporting: A separate annual report may be prepared per compartment, provided it includes aggregated data for all compartments.
Version française
Le 30 juillet 2026, la Chambre des députés a publié le projet de loi n° 8814 modifiant la loi modifiée du 12 juillet 2013 relative aux gestionnaires de fonds d’investissement alternatifs (loi AIFM), qui introduit la possibilité pour les fonds d’investissement alternatifs (FIA) domiciliés au Luxembourg et constitués sous la forme de sociétés en commandite simple (SCS) ou de sociétés en commandite spéciale (sociétés en commandite spéciale, SCSp), et non soumises à une loi sur les produits, d’adopter une structure à compartiments multiples. L’objectif déclaré est de moderniser la panoplie des fonds d’investissement luxembourgeois et de renforcer l’attractivité de la place financière.
Le projet de loi s’applique aux FIA luxembourgeois constitués sous la forme de SCS ou de SCSp qui ne sont soumis à aucune loi existante relative aux produits (à savoir la loi sur les SICAR, la loi sur les SIF, la loi sur les RAIF ou la partie II de la loi sur les OPC), à condition qu’ils soient gérés par un gestionnaire de FIA (AIFM) agréé au Luxembourg en vertu de la loi sur les gestionnaires de FIA ou par un gestionnaire de FIA agréé dans l’UE en vertu de la directive 2011/61/UE (directive AIFM). Le projet précise expressément que le nouveau cadre n’affecte pas les dispositions équivalentes relatives aux compartiments prévues par les lois existantes sur les produits, qui continuent de prévaloir.
Le projet introduit un nouvel article 28 bis au chapitre 5 de la loi sur les gestionnaires de FIA, calqué sur l’article 49 de la loi RAIF :
- Structure à compartiments multiples : chaque compartiment correspond à une partie distincte des actifs du FIA. Le recours à une structure à compartiments multiples et ses modalités doivent être expressément prévus dans les documents constitutifs, et la politique d’investissement spécifique de chaque compartiment doit être décrite conformément à l’article 21 de la loi sur les gestionnaires de FIA.
Séparation des actifs : les droits des investisseurs et des créanciers sont limités aux actifs du compartiment concerné, sauf disposition contraire des documents constitutifs ; dans les relations entre investisseurs, chaque compartiment est considéré comme une entité distincte.
- Liquidation indépendante : chaque compartiment peut être liquidé séparément sans entraîner la liquidation des autres compartiments ; seule la liquidation du dernier compartiment entraîne la liquidation de l’AIF dans son ensemble.
Investissements entre compartiments : un compartiment peut souscrire, acquérir ou détenir des participations dans d’autres compartiments du même FIA, sous réserve de l’absence d’investissement circulaire et de la suspension des droits de vote associés.
Rapports : un rapport annuel distinct peut être établi pour chaque compartiment, à condition qu’il comprenne des données agrégées pour l’ensemble des compartiments.
ANTI-MONEY LAUNDERING / COMBATING TERRORISM FINANCING / COMBATTING PROLIFERATION FINANCING (AML/CFT/CPF)
LBR publishes notice on the collection of reasons for consulting the Beneficial Owners Register / Le LBR publie une note d'information concernant la collecte des motifs justifiant la consultation du registre des bénéficiaires effectifs
![]()
On 24 July 2026, Luxembourg Business Registers published an information notice clarifying the implementation of the requirement to record the reason for each consultation of the Luxembourg Beneficial Owners Register.
Persons authorised to consult the RBE must now indicate the reason for each search before accessing the registered information. This implements Article 13(2bis) of the amended Law of 13 January 2019, as introduced by the Law of 23 January 2025, which requires the RBE system to trace:
- the identity of the person conducting the search;
- the information consulted;
- the date, time and file reference; and
- the precise reason for the consultation.
The corresponding logging data must be retained for five years and subsequently deleted.
LBR specifies that no particular level of detail is required when entering the reason for consultation. The information is collected solely for logging and traceability purposes and is not systematically reviewed or assessed by LBR. Where necessary, the CNPD or the competent courts may determine whether a stated reason complies with the applicable legal requirements.
Registered entities and beneficial owners cannot directly access information concerning consultations of their files. Their access right may only be exercised indirectly through the CNPD, which will confirm that the right has been exercised without disclosing the identity of the person who conducted the search or the reason provided.
The new step does not modify the conditions for obtaining access to the RBE. It constitutes an operational adjustment to the LBR portal intended to comply with the statutory traceability requirements.
Version française
Le 24 juillet 2026, les Registres du commerce luxembourgeois ont publié une note d’information précisant les modalités de mise en œuvre de l’obligation d’enregistrer le motif de chaque consultation du Registre des bénéficiaires effectifs luxembourgeois (RBE).
Les personnes autorisées à consulter le RBE doivent désormais indiquer le motif de chaque recherche avant d’accéder aux informations enregistrées. Cette mesure met en œuvre l’article 13, paragraphe 2 bis, de la loi modifiée du 13 janvier 2019, telle qu’introduite par la loi du 23 janvier 2025, qui impose au système du RBE de consigner :
- l’identité de la personne effectuant la recherche ;
- les informations consultées ;
- la date, l’heure et la référence du dossier ; et
- le motif précis de la consultation.
Les données de journalisation correspondantes doivent être conservées pendant cinq ans, puis supprimées.
LBR précise qu’aucun niveau de détail particulier n’est requis lors de la saisie du motif de consultation. Ces informations sont collectées uniquement à des fins de journalisation et de traçabilité et ne font pas l’objet d’un examen ou d’une évaluation systématique par LBR. Le cas échéant, la CNPD ou les juridictions compétentes peuvent déterminer si un motif invoqué est conforme aux exigences légales applicables.
Les entités enregistrées et les bénéficiaires effectifs ne peuvent pas accéder directement aux informations relatives aux consultations de leurs dossiers. Leur droit d’accès ne peut être exercé qu’indirectement par l’intermédiaire de la CNPD, qui confirmera que ce droit a été exercé sans divulguer l’identité de la personne ayant effectué la recherche ni le motif invoqué.
Cette nouvelle mesure ne modifie pas les conditions d’accès au RBE. Elle constitue un ajustement opérationnel du portail de la LBR visant à se conformer aux exigences légales en matière de traçabilité.
Legilux publishes the law of 16 July 2026 amending the law of 12 November 2004 on AML/CFT / Legilux publie la loi du 16 juillet 2026 modifiant la loi du 12 novembre 2004 relative à la lutte contre le blanchiment d'argent et au financement du terrorisme
![]()
On 23 July 2026, the Law of 16 July 2026 amending the amended Law of 12 November 2004 on combating money laundering and terrorist financing was published in the Official Journal of the Grand Duchy of Luxembourg (Mémorial A, No. 371), which strengthens the institutional framework for national AML/CFT coordination by reinforcing the mandate of the Prevention Committee (Comité de prévention), introducing a National Coordinator function, codifying risk assessment obligations and establishing a statistics collection and reporting framework aligned with EU requirements, including those of the newly established EU Anti-Money Laundering Authority (AMLA).
The law amends Articles 9-1quater, and introduces Articles 9-1quinquies and 9-1sexies, of the Law of 12 November 2004. It applies to Luxembourg public authorities and the national AML/CFT institutional framework. It does not directly impose new obligations on private sector obliged entities (financial institutions, lawyers, notaries, etc.), but reinforces the national coordination, risk assessment and statistical infrastructure within which those entities operate.
Three areas of reform are introduced:
Reinforced Prevention Committee mandate (Article 9-1quater): The Prevention Committee is formally designated as the national mechanism for coordinating Luxembourg's response to ML/TF risks. Its existing mission to identify and understand risks is extended to include mitigating those risks and adopting measures accordingly. A new seventh mission is added: coordinating AML/CFT statistics. Governance provisions are also strengthened: (i) the minister responsible for AML/CFT designates a National Coordinator to act as representative; (ii) the Committee is chaired by that minister (or the National Coordinator in case of impediment); (iii) decisions are taken according to modalities set by Grand-Ducal regulation; and (iv) the Committee is assisted by an Executive Secretariat, whose composition is determined by Grand-Ducal regulation.
National and Sectoral Risk Assessments (Article 9-1quinquies): The Prevention Committee must keep the national AML/CFT risk assessment up to date and review it at least every four years, or more frequently if the risk situation warrants, including through ad hoc sectoral risk assessments. The national risk assessment must take into account the European Commission's supranational risk assessment of ML/TF risks affecting the internal market and cross-border activities. The responsible minister must publish a report on the results of the national risk assessment, its updates and any reviews.
Statistics (Article 9-1sexies): The Executive Secretariat must collect and consolidate statistics on aspects relevant to the effectiveness of the national AML/CFT framework, and transmit them annually to the European Commission and, as regards required data, to AMLA (established by Regulation (EU) 2024/1620 of 31 May 2024).
Version française
Le 23 juillet 2026, la loi du 16 juillet 2026 modifiant la loi modifiée du 12 novembre 2004 relative à la lutte contre le blanchiment d’argent et le financement du terrorisme a été publiée au Journal officiel du Grand-Duché de Luxembourg (Mémorial A, n° 371). Cette loi renforce le cadre institutionnel de la coordination nationale en matière de lutte contre le blanchiment de capitaux et le financement du terrorisme en consolidant le mandat du Comité de prévention, en instaurant la fonction de coordinateur national, en codifiant les obligations en matière d’évaluation des risques et en établissant un cadre de collecte et de communication des statistiques conforme aux exigences de l’Union européenne, y compris celles de l’Autorité européenne de lutte contre le blanchiment de capitaux (AMLA) nouvellement créée.
La loi modifie les articles 9-1quater et introduit les articles 9-1quinquies et 9-1sexies de la loi du 12 novembre 2004. Elle s’applique aux autorités publiques luxembourgeoises et au cadre institutionnel national de lutte contre le blanchiment de capitaux et le financement du terrorisme. Elle n’impose pas directement de nouvelles obligations aux entités assujetties du secteur privé (établissements financiers, avocats, notaires, etc.), mais renforce la coordination nationale, l’évaluation des risques et l’infrastructure statistique au sein desquelles ces entités opèrent.
Trois axes de réforme sont introduits :
Renforcement du mandat du Comité de prévention (article 9-1quater) : le Comité de prévention est officiellement désigné comme le mécanisme national chargé de coordonner la réponse du Luxembourg aux risques de blanchiment de capitaux et de financement du terrorisme. Sa mission actuelle, qui consiste à identifier et à comprendre les risques, est étendue à l’atténuation de ces risques et à l’adoption de mesures en conséquence. Une septième mission est ajoutée : la coordination des statistiques en matière de lutte contre le blanchiment de capitaux et le financement du terrorisme. Les dispositions relatives à la gouvernance sont également renforcées : (i) le ministre chargé de la lutte contre le blanchiment de capitaux et le financement du terrorisme désigne un coordinateur national pour agir en tant que représentant ; (ii) le Comité est présidé par ce ministre (ou par le coordinateur national en cas d’empêchement) ; (iii) les décisions sont prises selon les modalités fixées par un règlement grand-ducal ; et (iv) le Comité est assisté par un secrétariat exécutif, dont la composition est déterminée par un règlement grand-ducal.
Évaluations nationales et sectorielles des risques (article 9-1quinquies) : Le Comité de prévention doit tenir à jour l’évaluation nationale des risques en matière de lutte contre le blanchiment de capitaux et le financement du terrorisme et la réexaminer au moins tous les quatre ans, ou plus fréquemment si la situation en matière de risques le justifie, y compris par le biais d’évaluations sectorielles ad hoc des risques. L’évaluation nationale des risques doit tenir compte de l’évaluation supranationale des risques de blanchiment de capitaux et de financement du terrorisme (BC/FT) réalisée par la Commission européenne, qui porte sur les risques affectant le marché intérieur et les activités transfrontalières. Le ministre compétent doit publier un rapport sur les résultats de l’évaluation nationale des risques, ses mises à jour et ses éventuelles révisions.
Statistiques (article 9-1sexies) : Le Secrétariat exécutif doit collecter et consolider les statistiques relatives aux aspects pertinents pour l’efficacité du cadre national de lutte contre le blanchiment de capitaux et le financement du terrorisme, et les transmettre chaque année à la Commission européenne ainsi qu’à l’AMLA (créée par le règlement (UE) n° 2024/1620 du 31 mai 2024) en ce qui concerne les données requises.
CYBERSECURITY
CSSF highlights AI-related cybersecurity risks and resilience expectations / La CSSF met en avant les risques liés à la cybersécurité liés à l'intelligence artificielle et les attentes en matière de résilience pour les établissements financiers
![]()
On 7 July 2026, CSSF published a communiqué on the evolving opportunities and risks associated with artificial intelligence (AI), highlighting the growing cybersecurity challenges posed by increasingly capable frontier AI models.
The regulator noted that AI can enable malicious actors to conduct cyberattacks faster, at greater scale, and with increased sophistication, significantly reducing the time between the discovery of vulnerabilities and their exploitation.
CSSF observed that many supervised entities continue to exhibit weaknesses in key cybersecurity areas, including vulnerability scanning, patch management, network security reviews, and secure configuration monitoring. The authority warned that relying solely on faster patching is no longer sufficient in an AI-enhanced threat environment and stressed that firms should assume that some cyberattacks will succeed, focusing not only on prevention but also on containment and resilience.
In line with the Digital Operational Resilience Act (DORA), CSSF expects management bodies to establish governance structures capable of effectively overseeing AI-related risks and strengthening organisational resilience against AI-enabled cyber threats. The communiqué encourages institutions to adopt a holistic cybersecurity strategy covering identification, protection, detection, response, and recovery capabilities.
Recommended measures include:
- reducing internet-exposed attack surfaces,
- prioritising patching based on exploitability and exposure,
- securing software development pipelines,
- implementing network segmentation and zero-trust principles,
- conducting proactive threat hunting, preparing contingency measures for vulnerabilities without available patches,
- leveraging AI for defensive purposes, and regularly testing cybersecurity defences and incident response plans.
The CSSF also drew attention to recent ESRB and FSB publications addressing AI-driven cyber risks and the responsible adoption of AI.
Version française
Le 7 juillet 2026, la CSSF a publié un communiqué sur l’évolution des opportunités et des risques liés à l’intelligence artificielle (IA), soulignant les défis croissants en matière de cybersécurité posés par des modèles d’IA de pointe de plus en plus performants.
L’autorité de régulation a noté que l’IA peut permettre à des acteurs malveillants de mener des cyberattaques plus rapidement, à plus grande échelle et avec une sophistication accrue, réduisant ainsi considérablement le délai entre la découverte des vulnérabilités et leur exploitation.
La CSSF a constaté que de nombreuses entités soumises à sa surveillance continuent de présenter des faiblesses dans des domaines clés de la cybersécurité, notamment le scan des vulnérabilités, la gestion des correctifs, les audits de sécurité des réseaux et la surveillance des configurations sécurisées. L’autorité a averti que se contenter d’accélérer l’application des correctifs n’était plus suffisant dans un environnement de menaces renforcé par l’IA et a souligné que les entreprises devaient partir du principe que certaines cyberattaques aboutiraient, en se concentrant non seulement sur la prévention, mais aussi sur le confinement et la résilience.
Conformément à la loi sur la résilience opérationnelle numérique (DORA), la CSSF attend des organes de direction qu’ils mettent en place des structures de gouvernance capables de superviser efficacement les risques liés à l’IA et de renforcer la résilience organisationnelle face aux cybermenaces basées sur l’IA. Le communiqué encourage les institutions à adopter une stratégie globale de cybersécurité couvrant les capacités d’identification, de protection, de détection, de réponse et de reprise.
Les mesures recommandées comprennent :
- la réduction des surfaces d’attaque exposées à Internet,
- la priorisation des correctifs en fonction de l’exploitabilité et de l’exposition,
- la sécurisation des pipelines de développement logiciel,
- la mise en œuvre de la segmentation du réseau et des principes « zero-trust »,
- la recherche proactive de menaces, ainsi que la préparation de mesures d’urgence pour les vulnérabilités pour lesquelles aucun correctif n’est disponible,
- l’utilisation de l’IA à des fins défensives, et le test régulier des défenses de cybersécurité et des plans de réponse aux incidents.
La CSSF a également attiré l’attention sur les récentes publications de l’ESRB et du FSB traitant des cyberrisques liés à l’IA et de l’adoption responsable de l’IA.
DATA PROTECTION FRAMEWORK
Chambre des députés publishes draft law 8809 implementing certain provisions of Regulation (EU) 2023/2854 / La Chambre des députés publie le projet de loi n° 8809 portant mise en œuvre de certaines dispositions de la Réglementation (UE) 2023/2854 (Data Act)
![]()
On 28 July 2026, Chambre des députés published draft law 8809 implementing certain provisions of Regulation (EU) 2023/2854 (the EU Data Act) at national level, designating competent authorities, defining their powers, establishing cooperation mechanisms, certifying dispute resolution bodies, and setting out the administrative sanctions regime.
Regulation (EU) 2023/2854 entered into force for most of its provisions on 12 September 2025. It governs fair access to and use of data generated by connected products and related services, establishes data sharing obligations between businesses and from businesses to public sector bodies in exceptional circumstances, addresses cloud switching, and sets interoperability requirements. The draft law fulfils Luxembourg's obligation to designate competent authorities and establish an enforcement framework at national level.
The draft law applies to data holders, data users, data recipients, data processing service providers, manufacturers and sellers/lessors of connected products, providers of related services, public sector bodies, and designated gatekeepers under the Digital Markets Act (Regulation (EU) 2022/1925). The geographic scope is Luxembourg. The law designates three national authorities: the Institut Luxembourgeois de Régulation (ILR) for Chapters II, III, VI and VII of the Data Act (data sharing between businesses and B2B obligations); the Commissariat du Gouvernement à la souveraineté des données for Chapter V and Article 33 (public sector access to data); and the Commission nationale pour la protection des données (CNPD) for personal data protection aspects. The ILR is also designated as the national data coordinator.
The draft law establishes five substantive frameworks:
- On competent authority powers, both the ILR and the Commissariat may: require access to all data and information; order compliance within specified deadlines; order cessation of infringing conduct; order suspension of data flows to third-country recipients; and impose administrative sanctions.
- On cooperation, the ILR and Commissariat may request CNPD opinions on GDPR applicability and are bound by them; cooperation agreements must be concluded between authorities and with CNPD; professional secrecy obligations do not prevent inter-authority information exchange for the purposes of the Data Act.
- On data coordinator, the ILR facilitates cross-border cooperation, reports to the European Commission, and certifies — and may revoke certification of — dispute resolution bodies under Article 10 of the Data Act.
- On sanctions, a three-tier administrative sanction regime is established:
(1) EUR 500–100,000 for procedural and notification violations;
(2) EUR 500–500,000 for data sharing refusals and certain substantive violations;
(3) EUR 500–1,000,000 for the most serious violations including breaches of the core data sharing obligation (Art. 3(1)), denial of access to data (Art. 4), unlawful use by third parties (Art. 6), and non-compliance by cloud service providers with switching obligations (Art. 23).
- Obstructing competent authority investigations carries a fine of EUR 500–50,000.
On appeals, decisions of competent authorities are subject to appeal before the Administrative Tribunal, sitting as a court of full jurisdiction.
Version française
Le 28 juillet 2026, la Chambre des députés a publié le projet de loi n° 8809 transposant au niveau national certaines dispositions du règlement (UE) 2023/2854 (le règlement sur les données – Data Act), désignant les autorités compétentes, définissant leurs pouvoirs, établissant des mécanismes de coopération, certifiant les organismes de règlement des litiges et fixant le régime des sanctions administratives.
Le règlement (UE) n° 2023/2854 est entré en vigueur, pour la plupart de ses dispositions, le 12 septembre 2025. Il régit l’accès équitable aux données générées par les produits connectés et les services associés, ainsi que leur utilisation ; il établit des obligations de partage des données entre les entreprises et, dans des circonstances exceptionnelles, entre les entreprises et les organismes du secteur public ; il traite du changement de fournisseur de services cloud et fixe des exigences en matière d’interopérabilité. Ce projet de loi répond à l’obligation qui incombe au Luxembourg de désigner les autorités compétentes et de mettre en place un cadre d’application au niveau national.
Le projet de loi s’applique aux détenteurs de données, aux utilisateurs de données, aux destinataires de données, aux prestataires de services de traitement de données, aux fabricants et vendeurs/bailleurs de produits connectés, aux prestataires de services associés, aux organismes du secteur public et aux contrôleurs d’accès (« gatekeepers ») désignés en vertu de la loi sur les marchés numériques (règlement (UE) 2022/1925). Son champ d’application géographique est le Luxembourg. La loi désigne trois autorités nationales : l’Institut luxembourgeois de régulation (ILR) pour les chapitres II, III, VI et VII de la loi sur les données (partage de données entre entreprises et obligations B2B) ; le Commissariat du gouvernement à la souveraineté des données pour le chapitre V et l’article 33 (accès du secteur public aux données) ; et la Commission nationale pour la protection des données (CNPD) pour les aspects relatifs à la protection des données à caractère personnel. L’ILR est également désigné comme coordinateur national des données.
Le projet de loi établit cinq grands volets :
- En ce qui concerne les pouvoirs des autorités compétentes, tant l’ILR que le Commissariat peuvent : exiger l’accès à toutes les données et informations ; ordonner la mise en conformité dans des délais précis ; ordonner la cessation des pratiques illicites ; ordonner la suspension des flux de données vers des destinataires situés dans des pays tiers ; et imposer des sanctions administratives.
- En matière de coopération, l’ILR et le Commissariat peuvent solliciter l’avis de la CNPD sur l’applicabilité du RGPD et sont liés par cet avis ; des accords de coopération doivent être conclus entre les autorités et avec la CNPD ; les obligations de secret professionnel n’empêchent pas l’échange d’informations entre autorités aux fins de la loi sur les données.
- En ce qui concerne le coordinateur des données, l’ILR facilite la coopération transfrontalière, rend compte à la Commission européenne et certifie — et peut révoquer la certification de — les organismes de règlement des litiges en vertu de l’article 10 de la loi sur les données.
- En matière de sanctions, un régime de sanctions administratives à trois niveaux est mis en place :
(1) 500 à 100 000 euros pour les infractions de procédure et les manquements aux obligations de notification ;
(2) 500 à 500 000 euros pour les refus de partage de données et certaines infractions de fond ;
(3) de 500 à 1 000 000 d’euros pour les infractions les plus graves, notamment les manquements à l’obligation fondamentale de partage des données (art. 3, paragraphe 1), le refus d’accès aux données (art. 4), l’utilisation illicite par des tiers (art. 6) et le non-respect par les fournisseurs de services cloud des obligations de changement de fournisseur (art. 23).
- Le fait d’entraver les enquêtes menées par les autorités compétentes est passible d’une amende comprise entre 500 et 50 000 euros.
En matière de recours, les décisions des autorités compétentes sont susceptibles de recours devant le Tribunal administratif, statuant en pleine juridiction.
OTHER - FINANCIAL PRODUCTS
CSSF updates notification templates for cross-border management and marketing activities / La CSSF met à jour les modèles de notification relatifs aux activités transfrontalières de gestion et de commercialisation
![]()
On 30 July 2026, the CSSF published a communiqué informing Luxembourg-domiciled investment fund managers (IFMs) that updated notification letter templates for cross-border management activities and related passported services within the EEA must be used from 31 July 2026. The changes follow the transposition of Directive (EU) 2024/927 (AIFMD II) through the Luxembourg Law of 3 March 2026.
The Law of 3 March 2026 introduced additional activities, functions and services that may be performed by UCITS management companies and authorised alternative investment fund managers (AIFMs). The updated templates and submission procedures enable IFMs to include these activities and services in their European passport notifications, provided that they have first been authorised by the CSSF to perform them in Luxembourg.
The communication applies to:
- Luxembourg-domiciled UCITS management companies wishing to exercise authorised activities or services in another EEA Member State through a branch or under the freedom to provide services; and
- Luxembourg-authorised AIFMs wishing to manage an AIF established in another EEA Member State, establish a branch, or provide authorised services cross-border.
The updated procedures concern management notifications, amendments and de-notifications under Articles 17 and 18 of Directive 2009/65/EC and Article 33 of Directive 2011/61/EU. They should be distinguished from the separate notification procedures applicable to the cross-border marketing of fund units or shares.
The CSSF introduces the following operational changes from 31 July 2026:
- The updated UCITS management company notification template, Version 4.1, and AIFM notification template, Version 3.1, must be used for the relevant European passport notifications.
- The dedicated eDesk module for cross-border management notifications and de-notifications, as well as the equivalent CSSF API solution using S3 technology, has been updated. Version 3.0 of the IFM Guidelines provides the applicable submission, documentation and technical requirements.
- Before passporting an activity, function or service introduced by AIFMD II into another Member State, the IFM must first be authorised by the CSSF to perform that activity, function or service in Luxembourg.
- A Super ManCo must submit separate notifications under the UCITS Directive and the AIFMD. Separate notifications are also required where an IFM intends to operate in the same Member State both through a branch and under the freedom to provide services.
- Notification files must contain the documents required for the relevant notification type. Where the technical submitter is not the IFM itself, a mandate from the IFM must be included.
- The API channel may be used only to initiate a notification request. Subsequent amendments, responses to CSSF comments and procedural follow-up must be completed through eDesk.
Version française
Le 30 juillet 2026, la CSSF a publié un communiqué informant les gestionnaires de fonds d’investissement (GFI) domiciliés au Luxembourg que les modèles de lettres de notification mis à jour relatifs aux activités de gestion transfrontalières et aux services associés bénéficiant du passeport au sein de l’EEE devaient être utilisés à compter du 31 juillet 2026. Ces modifications font suite à la transposition de la directive (UE) 2024/927 (AIFMD II) par la loi luxembourgeoise du 3 mars 2026.
La loi du 3 mars 2026 a introduit des activités, fonctions et services supplémentaires pouvant être exercés par les sociétés de gestion d’OPCVM et les gestionnaires de fonds d’investissement alternatifs (GFIA) agréés. Les modèles et procédures de soumission mis à jour permettent aux gestionnaires de fonds d’investissement d’inclure ces activités et services dans leurs notifications au titre du passeport européen, à condition qu’ils aient préalablement été autorisés par la CSSF à les exercer au Luxembourg.
La communication s’applique :
- aux sociétés de gestion d’OPCVM domiciliées au Luxembourg souhaitant exercer des activités ou des services autorisés dans un autre État membre de l’EEE par l’intermédiaire d’une succursale ou au titre de la libre prestation de services ; et
- aux gestionnaires de FIA agréés au Luxembourg souhaitant gérer un FIA établi dans un autre État membre de l’EEE, établir une succursale ou fournir des services agréés à l’étranger.
Les procédures mises à jour concernent les notifications de gestion, les modifications et les retraits de notification en vertu des articles 17 et 18 de la directive 2009/65/CE et de l’article 33 de la directive 2011/61/UE. Il convient de les distinguer des procédures de notification distinctes applicables à la commercialisation transfrontalière de parts ou d’actions de fonds.
La CSSF introduit les changements opérationnels suivants à compter du 31 juillet 2026 :
- Le modèle actualisé de notification des sociétés de gestion d’OPCVM, version 4.1, et le modèle de notification des gestionnaires de FIA, version 3.1, doivent être utilisés pour les notifications relatives au passeport européen.
- Le module eDesk dédié aux notifications et aux retraits de notification transfrontaliers en matière de gestion, ainsi que la solution API équivalente de la CSSF utilisant la technologie S3, ont été mis à jour. La version 3.0 des lignes directrices relatives aux IFM précise les exigences applicables en matière de soumission, de documentation et d’aspects techniques.
- Avant de bénéficier du passeport pour une activité, une fonction ou un service introduit par la directive AIFMD II dans un autre État membre, l’IFM doit d’abord être agréé par la CSSF pour exercer cette activité, cette fonction ou ce service au Luxembourg.
- Une société de gestion de fonds (Super ManCo) doit soumettre des notifications distinctes au titre de la directive OPCVM et de la directive AIFMD. Des notifications distinctes sont également requises lorsqu’un IFM a l’intention d’opérer dans le même État membre à la fois par le biais d’une succursale et au titre de la libre prestation de services.
- Les dossiers de notification doivent contenir les documents requis pour le type de notification concerné. Lorsque le déposant technique n’est pas le gestionnaire de fonds d’investissement lui-même, un mandat de ce dernier doit être joint.
- Le canal API ne peut être utilisé que pour lancer une demande de notification. Les modifications ultérieures, les réponses aux commentaires de la CSSF et le suivi procédural doivent être effectués via eDesk.
OTHER - TAX
Chambre des députés publishes Draft Law 8815 amending the Electronic Invoicing Law and VAT Law / La Chambre des députés publie le projet de loi n° 8815 modifiant la loi sur la facturation électronique et la loi sur la TVA
![]()
On 30 July 2026, the Government of the Grand Duchy of Luxembourg submitted to the Chamber of Deputies a draft law amending the Law of 16 May 2019 on electronic invoicing and the amended Law of 12 February 1979 on value added tax, which extends the mandatory use of electronic invoicing from business-to-government (B2G) transactions to domestic business-to-business (B2B) transactions, and adapts the Luxembourg VAT framework accordingly. The draft partially transposes Article 1 of Council Directive (EU) 2025/516 of 11 March 2025 (the VIDA Directive). Luxembourg follows Belgium (mandatory B2B e-invoicing since 1 January 2026), France (by 1 September 2027) and Germany (by 1 January 2028) in introducing this obligation.
The B2B e-invoicing obligation applies to invoices: (i) issued by a VAT-registered issuer established in Luxembourg; (ii) addressed to a Luxembourg-established recipient; (iii) for supplies of goods or services taxable in Luxembourg; and (iv) subject to a VAT invoicing obligation. Intra-Community transactions subject to Article 262 of Directive 2006/112/EC are excluded, as are invoices issued by or addressed to entities qualifying under specific VAT exemption provisions.
Main changes:
- Compliant electronic invoice: A new definition is introduced — a structured e-invoice conforming to the European e-invoicing standard (EN 16931) and one of the XML syntaxes published in the EU Official Journal pursuant to Directive 2014/55/EU. Only compliant e-invoices have evidentiary value; attachments are not considered invoices.
- Mandatory B2B e-invoicing: All in-scope B2B invoices must be issued, transmitted and received as compliant electronic invoices via the common delivery network (réseau de livraison commun). No surcharge may be levied for issuing a compliant e-invoice instead of a paper or unstructured format.
- Common delivery network: A single network is mandated for all e-invoice transmission, meeting nine prescribed criteria including interoperability, security, data protection by default and eIDAS conformity. Technical parameters may be specified by Grand-Ducal regulation.
- Alternative solutions and usage fees: Derogations are available for limited-volume issuers/recipients (thresholds set by Grand-Ducal regulation) and, transitionally, for B2B recipients. Progressive usage fees apply when thresholds are exceeded (€2 to €5 per invoice excl. VAT).
- VAT law adaptation: Aligned definitions of "invoice", "electronic invoice" and "compliant electronic invoice" are introduced in the VAT Law; issuers subject to the e-invoicing law must issue compliant e-invoices; recipient acceptance is not required.
Version française
Le 30 juillet 2026, le gouvernement du Grand-Duché de Luxembourg a soumis à la Chambre des députés un projet de loi modifiant la loi du 16 mai 2019 relative à la facturation électronique et la loi modifiée du 12 février 1979 relative à la taxe sur la valeur ajoutée, qui étend l’utilisation obligatoire de la facturation électronique des transactions « entreprise- -administration (B2G) aux transactions nationales entre entreprises (B2B), et adapte en conséquence le cadre luxembourgeois de la TVA. Ce projet transpose partiellement l’article 1er de la directive (UE) 2025/516 du Conseil du 11 mars 2025 (la directive VIDA). Le Luxembourg emboîte le pas à la Belgique (facturation électronique B2B obligatoire depuis le 1er janvier 2026), à la France (à compter du 1er septembre 2027) et à l’Allemagne (à compter du 1er janvier 2028) en introduisant cette obligation.
L’obligation de facturation électronique B2B s’applique aux factures : (i) émises par un émetteur assujetti à la TVA et établi au Luxembourg ; (ii) adressées à un destinataire établi au Luxembourg ; (iii) relatives à des livraisons de biens ou à des prestations de services imposables au Luxembourg ; et (iv) soumises à une obligation de facturation TVA. Les opérations intracommunautaires relevant de l’article 262 de la directive 2006/112/CE sont exclues, tout comme les factures émises par ou adressées à des entités bénéficiant de dispositions spécifiques d’exonération de TVA.
Principaux changements:
- Facture électronique conforme : une nouvelle définition est introduite : il s’agit d’une facture électronique structurée conforme à la norme européenne de facturation électronique (EN 16931) et à l’une des syntaxes XML publiées au Journal officiel de l’Union européenne conformément à la directive 2014/55/UE. Seules les factures électroniques conformes ont valeur probante ; les pièces jointes ne sont pas considérées comme des factures.
- Facturation électronique B2B obligatoire : toutes les factures B2B concernées doivent être émises, transmises et reçues sous forme de factures électroniques conformes via le réseau de livraison commun. Aucun supplément ne peut être facturé pour l’émission d’une facture électronique conforme à la place d’une facture papier ou d’un format non structuré.
- Réseau de livraison commun : un réseau unique est imposé pour toute transmission de factures électroniques ; il doit répondre à neuf critères prescrits, notamment l’interopérabilité, la sécurité, la protection des données par défaut et la conformité à l’eIDAS. Les paramètres techniques peuvent être précisés par un règlement grand-ducal.
- Solutions alternatives et frais d’utilisation : des dérogations sont prévues pour les émetteurs/destinataires à faible volume (seuils fixés par règlement grand-ducal) et, à titre transitoire, pour les destinataires B2B. Des frais d’utilisation progressifs s’appliquent lorsque les seuils sont dépassés (de 2 à 5 € par facture, hors TVA).
- Adaptation de la loi sur la TVA : des définitions harmonisées des termes « facture », « facture électronique » et « facture électronique conforme » sont introduites dans la loi sur la TVA ; les émetteurs soumis à la loi sur la facturation électronique doivent émettre des factures électroniques conformes ; l’acceptation par le destinataire n’est pas requise.
REPORTING & DISCLOSURES
CSSF publishes communication on ESG Ratings Regulation and SFDR disclosure requirements / La CSSF publie une communication sur la réglementation relatif aux notations ESG et les obligations d'information prévues par le SFDR
![]()
On 1 July 2026, the Commission de Surveillance du Secteur Financier (CSSF) published a communication which informs market participants about the application of Regulation (EU) 2024/3005 on the transparency and integrity of ESG rating activities (the ESG Ratings Regulation) and the resulting new disclosure requirements introduced under the Sustainable Finance Disclosure Regulation (SFDR).
The CSSF highlights that the ESG Ratings Regulation will start applying from 2 July 2026. The Regulation introduces a new disclosure obligation through Article 49, which amends Article 13 of the SFDR. Under these amendments, financial market participants and financial advisers that are within the scope of the SFDR and that issue and disclose ESG ratings to third parties as part of their marketing communications must publish specific information on their websites. The information to be disclosed corresponds to the requirements set out in point 1 of Annex III of the ESG Ratings Regulation. In addition, those marketing communications must contain a link directing users to the relevant website disclosures.
The CSSF states that it expects financial market participants and financial advisers to comply with these requirements from 2 July 2026. The authority further notes that it will continue monitoring EU regulatory developments concerning the SFDR and that it will apply a proportionate supervisory approach, taking into account ongoing uncertainties and possible future developments in the regulatory framework.
The communication also refers to an ESMA public statement addressing the transitional period between 2 July 2026 and 2 November 2026. According to the statement, third parties may continue publishing or distributing ESG ratings provided by existing ESG rating providers that have notified ESMA of their intention to continue operating in the EU, pending ESMA's decision on authorisation, recognition or registration.
The communication is addressed to market participants and focuses on ensuring awareness and compliance with the new ESG rating-related disclosure obligations arising from the application of the ESG Ratings Regulation and its interaction with the SFDR.
Version française
Le 1er juillet 2026, la Commission de surveillance du secteur financier (CSSF) a publié une communication visant à informer les acteurs du marché de l’application du règlement (UE) 2024/3005 relatif à la transparence et à l’intégrité des activités de notation ESG (le « règlement sur les notations ESG ») ainsi que des nouvelles obligations d’information qui en découlent, introduites par le règlement sur la publication d’informations en matière de finance durable (SFDR).
La CSSF souligne que le règlement sur les notations ESG entrera en vigueur le 2 juillet 2026. Ce règlement introduit une nouvelle obligation d’information par le biais de son article 49, qui modifie l’article 13 du SFDR. En vertu de ces modifications, les acteurs des marchés financiers et les conseillers financiers relevant du champ d’application du SFDR qui émettent et communiquent des notations ESG à des tiers dans le cadre de leurs communications commerciales doivent publier des informations spécifiques sur leurs sites Internet. Les informations à publier correspondent aux exigences énoncées au point 1 de l’annexe III du règlement sur les notations ESG. En outre, ces communications commerciales doivent comporter un lien renvoyant les utilisateurs vers les informations publiées sur le site web concerné.
La CSSF précise qu’elle attend des acteurs des marchés financiers et des conseillers financiers qu’ils se conforment à ces exigences à compter du 2 juillet 2026. L’autorité précise en outre qu’elle continuera à suivre l’évolution de la réglementation européenne relative au SFDR et qu’elle appliquera une approche de surveillance proportionnée, en tenant compte des incertitudes actuelles et des éventuelles évolutions futures du cadre réglementaire.
La communication fait également référence à une déclaration publique de l’AEMF concernant la période de transition comprise entre le 2 juillet 2026 et le 2 novembre 2026. Selon cette déclaration, les tiers peuvent continuer à publier ou à diffuser des notations ESG fournies par des agences de notation ESG existantes qui ont notifié à l’AEMF leur intention de poursuivre leurs activités dans l’UE, dans l’attente de la décision de l’AEMF concernant leur autorisation, leur reconnaissance ou leur enregistrement.
La communication s’adresse aux acteurs du marché et vise à garantir la sensibilisation et le respect des nouvelles obligations d’information relatives aux notations ESG découlant de l’application du règlement sur les notations ESG et de son interaction avec le SFDR.
SETTLEMENT
Chambre des députés publishes draft law 8797 amending the amended Law of 1 August 2001 on the transfer of securities / La Chambre des députés publie le projet de loi n° 8797 modifiant la loi modifiée du 1er août 2001 relative au transfert de titres
![]()
On 20 July 2026, the Government of the Grand Duchy of Luxembourg published the Draft Law amending the amended Law of 1 August 2001 on the transfer of securities, which introduces targeted amendments to that law with a view to clarifying and updating it in light of the current legal framework. The draft was approved by the Council of Government on 17 July 2026 on the proposal of the Minister of Finance, Gilles Roth. It has been tabled before the Chamber of Deputies and submitted for opinion to the Council of State. The ABBL, ACA, ALFI, CAA, CSSF and HCPF were consulted during the preparation of the text.
The draft law applies to all actors involved in the securities holding chain in Luxembourg: account keepers (credit institutions, investment firms, domestic and foreign central securities depositories), account holders (investors, funds, intermediaries) and, by extension, any securities settlement system governed by Luxembourg law. The geographic scope is national, with cross-border implications arising from the clarified private international law rules. No formal entry-into-force date is specified in the text; the law will enter into force following the ordinary Luxembourg legislative procedure (vote by the Chamber of Deputies, opinion of the Council of State, grand-ducal promulgation).
The draft comprises eight amending articles covering the following points:
- Article 1 (Art. 3(1) of the 2001 Law): Clarification of the nature of the account holder's real right, by explicitly incorporating the various modes of securities delivery (physical deposit, registration as nominee, credit to an account held with a domestic or foreign account keeper).
- Article 2 (Art. 4 of the 2001 Law): Insertion of a new paragraph 1bis specifying that, where the relevant account keeper holds securities with a foreign account keeper, the account holder acquires rights that are "functionally equivalent" to those obtained by the relevant account keeper. Terminological harmonisation in paragraph 2 (replacement of "its account keeper" with "the relevant account keeper").
- Article 3 (Art. 5(2) of the 2001 Law): Alignment with the requirements introduced by the Law of 28 July 2014 on the immobilisation of bearer shares and units; addition of the possibility for the account keeper to register the account holder in the securities register where such registration is required.
- Article 4 (Art. 7(2) of the 2001 Law): Introduction, in the absence of contractual agreement between the parties, of a default point of irrevocability for instructions, set at the moment the account keeper debits the account holder's securities account, for the purposes of legal certainty.
- Article 5 (Art. 12 of the 2001 Law): Insertion of a new paragraph 6 authorising the relevant account keeper to reverse a defective entry arising from the invalidity of a securities credit or from an absence of deposit or account-keeping, without prejudice to its liability towards the account holder.
- Article 6 (Art. 14 of the 2001 Law): Editorial alignment with the new paragraph 6 of Article 12 (reservation of the provisions of that paragraph).
- Article 7 (Art. 17 of the 2001 Law): Full replacement of Article 17 with a modernised private international law rule, aligned with EU terminology and the PRIMA approach (Place of the Relevant Intermediary Approach) as reflected in Article 9 of Directive 2002/47/EC and Article 24 of Directive 2001/24/EC. The article now sets out in a non-exhaustive manner the substantive (real) aspects governed by the law of the country where the securities account is located (transfer of title, third-party enforceability, priority conflicts, creation and effects of security interests). The first two limbs of the current Article 17 (right to sub-deposit, segregation obligation) are deleted as redundant with MiFID II and the Grand-Ducal Regulation of 30 May 2018.
- Article 8 (Art. 18bis(2) of the 2001 Law): Alignment of the private international law rule applicable to secure electronic recording devices (including distributed ledgers / DLT) with the new wording of Article 17.
The aim is to strengthen the security and clarity of the Luxembourg framework for securities transfers, consolidate Luxembourg’s position as a reference jurisdiction for the holding of book-entry securities, and improve its interaction with foreign laws in international holding chains.
Version française
Le 20 juillet 2026, le gouvernement du Grand-Duché de Luxembourg a publié le projet de loi modifiant la loi modifiée du 1er août 2001 relative au transfert de titres, qui apporte des modifications ciblées à cette loi en vue de la clarifier et de l’actualiser à la lumière du cadre juridique en vigueur. Ce projet a été approuvé par le Conseil de gouvernement le 17 juillet 2026 sur proposition du ministre des Finances, Gilles Roth. Il a été déposé devant la Chambre des députés et soumis pour avis au Conseil d’État. L’ABBL, l’ACA, l’ALFI, la CAA, la CSSF et la HCPF ont été consultées lors de l’élaboration du texte.
Le projet de loi s’applique à tous les acteurs intervenant dans la chaîne de détention des titres au Luxembourg : les teneurs de comptes (établissements de crédit, entreprises d’investissement, dépositaires centraux de titres nationaux et étrangers), les titulaires de comptes (investisseurs, fonds, intermédiaires) et, par extension, tout système de règlement de titres régi par le droit luxembourgeois. Le champ d’application géographique est national, avec des implications transfrontalières découlant des règles clarifiées de droit international privé. Aucune date officielle d’entrée en vigueur n’est précisée dans le texte ; la loi entrera en vigueur à l’issue de la procédure législative ordinaire luxembourgeoise (vote par la Chambre des députés, avis du Conseil d’État, promulgation grand-ducale).
Le projet comprend huit articles modificatifs couvrant les points suivants :
- Article 1 (art. 3, alinéa 1, de la loi de 2001) : clarification de la nature du droit réel du titulaire de compte, en intégrant explicitement les différents modes de remise des titres (dépôt physique, inscription au nom d’un nominee, inscription en compte auprès d’un teneur de compte national ou étranger).
- Article 2 (art. 4 de la loi de 2001) : insertion d’un nouveau paragraphe 1 bis précisant que, lorsque le teneur de compte concerné détient des titres auprès d’un teneur de compte étranger, le titulaire du compte acquiert des droits « fonctionnellement équivalents » à ceux obtenus par le teneur de compte concerné. Harmonisation terminologique au paragraphe 2 (remplacement de « son teneur de compte » par « le teneur de compte concerné »).
- Article 3 (art. 5, alinéa 2, de la loi de 2001) : Alignement sur les exigences introduites par la loi du 28 juillet 2014 relative à l’immobilisation des actions et parts au porteur ; ajout de la possibilité pour le teneur de compte d’inscrire le titulaire du compte au registre des titres lorsque cette inscription est requise.
- Article 4 (art. 7, alinéa 2, de la loi de 2001) : introduction, en l’absence d’accord contractuel entre les parties, d’un moment par défaut d’irrévocabilité des instructions, fixé au moment où le teneur de compte débite le compte-titres du titulaire de compte, à des fins de sécurité juridique.
- Article 5 (art. 12 de la loi de 2001) : Insertion d’un nouveau paragraphe 6 autorisant le teneur de compte concerné à annuler une inscription viciée résultant de l’invalidité d’une inscription de titres au crédit du compte ou de l’absence de dépôt ou de tenue de compte, sans préjudice de sa responsabilité envers le titulaire du compte.
- Article 6 (art. 14 de la loi de 2001) : Alignement rédactionnel sur le nouveau paragraphe 6 de l’article 12 (sous réserve des dispositions dudit paragraphe).
- Article 7 (art. 17 de la loi de 2001) : Remplacement intégral de l’article 17 par une règle de droit international privé modernisée, alignée sur la terminologie de l’UE et l’approche PRIMA (Place of the Relevant Intermediary Approach), telle qu’elle est reflétée à l’article 9 de la directive 2002/47/CE et à l’article 24 de la directive 2001/24/CE. Cet article énonce désormais, de manière non exhaustive, les aspects substantiels (réels) régis par la loi du pays où se trouve le compte-titres (transfert de propriété, opposabilité aux tiers, conflits de priorité, constitution et effets des sûretés). Les deux premiers alinéas de l’actuel article 17 (droit de sous-dépôt, obligation de ségrégation) sont supprimés car redondants au regard de la directive MiFID II et du règlement grand-ducal du 30 mai 2018.
- Article 8 (art. 18 bis, paragraphe 2, de la loi de 2001) : Alignement de la règle de droit international privé applicable aux dispositifs d’enregistrement électroniques sécurisés (y compris les registres distribués / DLT) sur la nouvelle formulation de l’article 17.
L’objectif est de renforcer la sécurité et la clarté du cadre luxembourgeois applicable aux transferts de titres, de consolider la position du Luxembourg en tant que juridiction de référence pour la détention de titres dématérialisés, et d’améliorer son articulation avec les législations étrangères dans les chaînes de détention internationales.
NETHERLANDS
CYBERSECURITY
Rijksoverheid publishes Cybersecurity Act and Critical Entities Resilience Act to enter into force from 15 August 2026
![]()
On 7 July 2026, the Rijksoverheid, Dutch Ministry of Justice and Security announced that the Cybersecurity Act and the Critical Entities Resilience Act were approved by the Dutch Senate and will enter into force on 15 August 2026. The legislation implements Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2 Directive) and Directive (EU) 2022/2557 on the resilience of critical entities (Critical Entities Resilience (CER) Directive) into Dutch law, strengthening the digital and physical resilience of organisations providing essential and important services.
The Cybersecurity Act replaces the existing Network and Information Systems Security Act and expands the scope of cybersecurity obligations to more than 8,000 organisations across 18 sectors, including banking, digital infrastructure, healthcare, government, transport and energy. Organisations falling within scope are responsible for determining whether they are subject to the legislation and must comply with several new obligations from 15 August 2026. These include registering with the National Cyber Security Centre (NCSC), implementing cybersecurity risk management measures, reporting significant incidents to the competent Computer Security Incident Response Team (CSIRT) within the prescribed deadlines, and ensuring that management bodies assume responsibility for cyber risk management and receive appropriate cybersecurity training. Competent authorities will supervise compliance and enforce the new requirements.
The Critical Entities Resilience Act applies to approximately 500 organisations designated as critical entities by the relevant minister. The legislation establishes a framework to strengthen resilience against threats including cyber incidents, terrorism, sabotage and natural disasters across critical sectors such as banking, financial market infrastructure, energy, transport, healthcare and digital infrastructure.
The Ministry encourages organisations to prepare for the new framework ahead of its application by completing the required registration process and implementing the necessary governance, risk management and incident reporting arrangements.
DIGITAL OPERATIONAL RESILIENCE
AFM publishes press release on regulators accelerating the transition to greater digital autonomy
![]()
On 10 July 2026, the Netherlands Authority for Consumers and Markets (ACM), together with the Netherlands Authority for the Financial Markets (AFM), the Dutch Data Protection Authority (AP), De Nederlandsche Bank (DNB) and the National Inspectorate of Digital Infrastructure (RDI), published the report "The Route to Digital Autonomy", which sets out joint recommendations to accelerate the transition towards greater digital autonomy for governments and businesses.
The report highlights that reliance on a limited number of information technology (IT) service providers creates risks for the continuity and resilience of digital services. According to the regulators, disruptions, cyber incidents and geopolitical developments may have significant consequences for organisations and society, while dependence on a small number of predominantly non-European providers may reduce freedom of choice and increase the complexity and cost of switching suppliers.
The report explains that digital autonomy is not intended to achieve complete technological independence but rather to increase organisations' freedom of choice and control over their IT services through more open architectures, interoperability, supplier diversity and enhanced switching capabilities.
To support this objective, the regulators recommend that governments promote European digital services by aggregating demand and acting as early adopters. Governments and private-sector organisations are encouraged to incorporate digital autonomy considerations into procurement processes by requiring open standards, interoperability and contractual provisions that facilitate switching between providers. The report also notes that companies may collaborate within sectors to develop sector-specific digital solutions where permitted under competition law, while IT providers are encouraged to cooperate in developing stronger European alternatives.
The regulators further note that these recommendations complement the objectives of the Digital Operational Resilience Act (Regulation (EU) 2022/2554) (DORA) and the Directive on measures for a high common level of cybersecurity across the Union (Directive (EU) 2022/2555) (NIS2 Directive), both of which emphasise supply chain risk management and operational resilience. The report concludes by encouraging organisations to engage with the regulators regarding the implementation of the recommendations.
SETTLEMENT
AFM publishes communication urging market participants to accelerate preparations for the transition to T+1 settlement
![]()
On 27 July 2026, the AFM published a communication urging market participants to continue or accelerate their preparations for the transition to a T+1 settlement cycle, following the European Commission's adoption of the detailed technical rules supporting the implementation of the new settlement regime.
The T+1 settlement cycle will apply across the European Union (EU) from 11 October 2027, reducing the standard settlement period for transactions in listed securities from two business days (T+2) to one business day (T+1). According to the AFM, the shorter settlement cycle is intended to improve settlement efficiency and reduce risks within the post-trade settlement chain. The transition will affect a broad range of market participants, including trading venues, investment firms, credit institutions, central counterparties and central securities depositories.
The AFM notes that the legal framework for the transition is now largely established following the European Commission's adoption of the detailed implementation rules, with formal adoption by the European Parliament and the Council of the European Union still pending. The authority encourages firms to take these detailed requirements into account when planning implementation activities and to make use of the recommendations published by the EU T+1 Industry Committee, which provide practical guidance for implementation and testing.
The communication highlights 7 December 2026 as the first key implementation milestone, from which new detailed requirements relating to faster transaction processing, data exchange and the use of standardised communication will apply.
The AFM recommends that firms complete impact assessments, develop implementation and testing plans, further automate and standardise settlement processes, review arrangements with suppliers and market infrastructures, and improve the quality of reference data and settlement instructions. The authority warns that delaying preparations may result in operational disruptions, increased implementation costs and customer service issues once the T+1 settlement cycle becomes effective.
SPAIN
ANTI-MONEY LAUNDERING / COMBATING TERRORISM FINANCING / COMBATTING PROLIFERATION FINANCING (AML/CFT/CPF)
Ministry of Economic Affairs and Digital Transformation publishes consultation on establishing national AML/CFT and proliferation financing council
![]()
On 16 July 2026, the Ministry of Economic Affairs and Digital Transformation published a draft order to establish and regulate the National Council for the Prevention of Money Laundering, Terrorist Financing and Proliferation Financing.
The proposal aims to strengthen Spain’s AML/CFT framework by creating a permanent and structured mechanism for cooperation between public authorities and private-sector obliged entities. The initiative supports the objectives of Spain’s National Strategic Plan against Money Laundering, which identified enhanced public-private collaboration as a key means of improving the effectiveness of risk detection, prevention measures and information sharing.
The proposed Council would operate as an advisory and consultative body attached to the Commission for the Prevention of Money Laundering and Monetary Offences. Its functions would include facilitating the exchange of strategic, tactical and operational information, contributing to national risk assessments and AML/CFT strategy development, identifying emerging threats and vulnerabilities, promoting best practices, and issuing reports, guidance and recommendations. The Council would bring together representatives from financial supervisors, law enforcement authorities, government bodies and private-sector obliged entities, creating a formal forum for ongoing dialogue and coordination.
The draft order also provides for the creation of specialised technical committees focused on sector-specific issues and information-sharing initiatives. It establishes safeguards governing information exchanges, including requirements relating to confidentiality, proportionality, security and data protection. The Council would meet at least annually and would be formally established within one month of the order entering into force. Stakeholders can submit comments until 27 July 2026.
FINTECH / REGTECH / BIGTECH / SUPTECH
Ministry of Economic Affairs and Digital Transformation approves financial sector modernisation bill covering MiCA, DORA, payments and ESAP
![]()
On 14 July 2026, the Ministry of Economic Affairs and Digital Transformation approved a bill to modernise the financial sector and adapt Spain’s regulatory framework to the opportunities and risks arising from digitalisation.
The proposal has been submitted to Parliament and introduces a broad package of measures covering crypto-assets, operational resilience, payments, capital markets transparency and financial innovation. The objective is to strengthen competitiveness, innovation and user protection while reducing administrative burdens and aligning national legislation with recent EU regulatory developments.
The bill completes the implementation of the Markets in Crypto-Assets Regulation (MiCA) in Spain by placing crypto-asset service providers under the supervision of the CNMV and subjecting them to anti-money laundering obligations. It also grants the CNMV powers over crypto-asset advertising and strengthens investor protection measures. In addition, the legislation establishes a national enforcement and sanctions framework for the Digital Operational Resilience Act (DORA), enhancing supervisory powers for the Bank of Spain, the CNMV and the Directorate General of Insurance and Pension Funds in relation to ICT and cyber resilience.
The proposal introduces measures to increase competition in payments by allowing payment institutions and electronic money institutions to access payment systems directly without relying on banks. It also strengthens oversight of Spain’s critical payments infrastructure by requiring prior government authorisation for acquisitions resulting in control of Iberpay. Furthermore, the bill transposes the European Single Access Point (ESAP) framework to improve access to financial and sustainability-related information across the EU and reforms Spain’s Financial Sandbox by introducing a permanent application window and reducing participation costs to encourage innovation.
Overall, the bill represents a significant step in Spain’s digital financial transformation, combining MiCA, DORA, ESAP, payments and innovation measures within a single legislative package.
SWEDEN
ANTI-MONEY LAUNDERING / COMBATING TERRORISM FINANCING / COMBATTING PROLIFERATION FINANCING (AML/CFT/CPF)
Regeringskansliet publishes memorandum and draft legislation implementing the EU AML Package in Sweden
![]()
On 6 July 2026, the Regeringskansliet and Swedish Ministry of Finance published a memorandum containing the legislative proposals required to implement the European Union Anti-Money Laundering (AML) Package into Swedish law. The proposals seek to align Sweden's AML/CFT framework with the new EU legislative package by replacing existing legislation, expanding the scope of regulated entities and strengthening supervisory, enforcement and transparency measures. The proposed legislative amendments are expected to enter into force on 10 July 2027.
The memorandum proposes repealing the current Money Laundering Act, the Registers Act and the Act on Account and Safe Deposit Box Systems, replacing them with new legislation reflecting the EU AML framework. The proposals would extend AML, counter-terrorist financing and targeted financial sanctions obligations to additional categories of businesses and consolidate supervisory and enforcement provisions within a new Anti-Money Laundering Act.
The memorandum also introduces significant changes to the beneficial ownership register, requiring additional information to be maintained and assigning the Swedish Companies Registration Office enhanced responsibility for ensuring the accuracy and quality of registered information. Furthermore, the County Administrative Board of Stockholm County would become responsible for supervising AML oversight of lawyers and law firms.
In addition, the proposals would strengthen the powers of the Swedish Financial Intelligence Unit, enabling it to share information with obliged entities notwithstanding confidentiality restrictions and to order monitoring measures and prohibit access to accounts and business relationships where appropriate. The memorandum also proposes replacing the existing account and safe deposit box register with a broader register covering accounts, safe deposit boxes, virtual IBANs and gaming accounts, thereby expanding the information available to competent authorities for AML/CFT purposes.
Overall, the proposals represent a comprehensive overhaul of Sweden's AML/CFT regime to implement the new EU AML legislative framework.
CYBERSECURITY
FI publishes news on ESRB warning vulnerabilities in the financial system linked to advanced AI models
![]()
On 7 July 2026, the Swedish Financial Supervisory Authority (Finansinspektionen) published a news item on the European Systemic Risk Board (ESRB) warning concerning vulnerabilities in the financial system associated with advanced Artificial Intelligence (AI) models. The warning calls on relevant European Union (EU) authorities to incorporate AI-related cyber risks into their supervisory activities and ongoing financial stability monitoring to strengthen the resilience of the financial system.
According to the ESRB, increasingly capable AI models are transforming the cyber threat landscape by enabling malicious actors to identify vulnerabilities in critical software more rapidly and develop more sophisticated, large-scale cyberattacks. The warning highlights that AI is increasing the speed, scale and complexity of cyber threats, creating potential systemic risks for the EU financial sector. The ESRB therefore urges supervisory authorities to consider these evolving risks when assessing the resilience of financial institutions and the broader financial system.
The publication also notes that, in parallel with the ESRB warning, the European Central Bank (ECB), through the Single Supervisory Mechanism (SSM), issued a letter to supervised institutions drawing attention to risks arising from advanced AI models. In addition, the National Cyber Security Centre (NCSC) recently published recommendations on managing AI-related cybersecurity risks from a Swedish perspective.
Finansinspektionen and the Sveriges Riksbank jointly encourage Swedish financial institutions to prioritise the identification, assessment and mitigation of AI-related cyber risks and to continue strengthening their operational resilience. The authorities emphasise that organisations should assume that operational disruptions may occur and ensure that appropriate resilience measures are in place. The publication further notes that AI presents significant opportunities for the financial sector while also introducing cross-border risks that require coordinated supervisory attention at both European and international levels.
DIGITAL OPERATIONAL RESILIENCE
FI publishes news on joint report issued by the ESAs on serious ICT-related incidents reported under DORA
![]()
On 3 July 2026, the Swedish Financial Supervisory Authority (Finansinspektionen) published a news item highlighting the joint report issued by the European Supervisory Authorities (ESAs) on serious Information and Communication Technology (ICT)-related incidents reported under Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (Digital Operational Resilience Act – DORA). The report analyses incident data reported by financial entities across the European Union (EU) during 2025 and provides an overview of the main sources of operational disruption affecting the financial sector.
The publication recalls that DORA requires financial entities to establish robust ICT risk management frameworks, test their digital operational resilience, manage risks arising from third-party ICT service providers and report serious ICT-related incidents to their competent supervisory authorities. The report, which will be published annually, aims to provide a comprehensive assessment of the ICT incident landscape across the EU.
According to the findings, failures in internal systems and operational processes, together with external events, account for the majority of reported ICT-related incidents. The report also shows that ICT risks are becoming increasingly cross-border and interconnected, reflecting the growing reliance of financial institutions on complex digital infrastructures and third-party ICT providers. In Sweden, Finansinspektionen observes that a significant proportion of reported incidents involve third-party suppliers, while internal process and system failures remain the most common underlying causes. Cybersecurity incidents are also reported but represent a smaller proportion of total incidents both in Sweden and across the EU.
The publication concludes that financial institutions should continue strengthening their digital operational resilience by addressing both internal operational weaknesses and dependencies on external ICT service providers. Finansinspektionen notes that DORA has applied fully since January 2025 and confirms that it remains responsible for supervising compliance with the Regulation in Sweden.
REPORTING & DISCLOSURES
FI publishes new rules on ESG ratings coming into effect
![]()
On 2 July 2026, the Swedish Financial Supervisory Authority (Finansinspektionen) published a news item announcing the application of Regulation (EU) 2024/3005 on the transparency and integrity of Environmental, Social and Governance (ESG) rating activities. The Regulation establishes a harmonised European Union (EU) framework governing providers of Environmental, Social and Governance (ESG) ratings, with the objective of improving the transparency, comparability and reliability of ESG ratings used by investors and market participants.
Under the new framework, providers of ESG ratings are required to obtain authorisation, comply with organisational and governance requirements, and disclose transparent information regarding the methodologies, models and assumptions used to produce ESG ratings. The Regulation seeks to reduce conflicts of interest affecting ESG rating providers and enable investors and other users to better understand the basis of sustainability assessments used in investment decisions.
The publication explains that the European Securities and Markets Authority (ESMA) is responsible for authorising ESG rating providers and carrying out the primary supervisory activities under the Regulation. Finansinspektionen, acting as the competent national authority under the Regulation, will support ESMA's supervisory activities by conducting investigative measures and providing enforcement assistance where required.
In addition, the Regulation introduces specific transparency obligations for regulated financial institutions that use proprietary ESG ratings in connection with the marketing of financial instruments or financial products. Such firms are responsible for assessing whether their activities fall within the scope of the Regulation and, where applicable, ensuring compliance with the relevant transparency requirements.
Finansinspektionen notes that the new framework strengthens transparency regarding the production and use of ESG ratings, supports greater comparability between sustainability assessments and contributes to reducing the risk of misleading sustainability claims. The authority further states that compliance with the new transparency obligations, particularly in relation to greenwashing risks, will form part of its supervisory activities for regulated financial institutions.
SWITZERLAND
LIQUIDITY RISK
FINMA publishes a new ordinance on the liquidity of banks and securities firm / La FINMA publie une nouvelle ordonnance sur la liquidité des banques et des sociétés de courtage
![]()
BACKGROUND
On 7 July 2026, the Swiss Financial Market Supervisory Authority (FINMA) published the FINMA Ordinance on the Liquidity of Banks and Securities Firms (LiqO-FINMA), which transposes FINMA Circular 2015/2 “Liquidity risks – banks” into a binding ordinance, in accordance with the regulatory hierarchy requirement under Article 7(1) of the Financial Market Supervision Act (FINMASA). The Ordinance applies to FINMA-supervised banks and securities firms at both consolidated and individual institution level, with exemptions and simplifications for category 4 and 5 banks and additional requirements for systemically important banks. A public consultation on the draft Ordinance was conducted from 3 July to 29 September 2025.
WHAT'S NEW?
Liquidity risk management
The Ordinance largely carries over the qualitative requirements of Circular 2015/2, including governance, liquidity risk strategies, transfer pricing, liquidity and funding planning, intraday liquidity risk, stress testing and contingency funding plans.
LCR and NSFR requirements
The LiqO-FINMA consolidates detailed requirements concerning:
- LCR – HQLA eligibility and operational requirements, Swiss franc and foreign-currency LCR, intragroup flows, deposit outflows and inflows, derivatives, liquidity facilities and monitoring metrics;
- NSFR – encumbered assets, available stable funding and required stable funding factors, intragroup treatment and connected assets and liabilities.
Substantive changes
Compared with Circular 2015/2, the Ordinance introduces substantive changes in two areas:
- liquidity and funding planning requirements; and
- information provision obligations during liquidity stress.
These changes are aligned with concurrent amendments to the Federal Council’s Liquidity Ordinance (LiqV).
WHAT'S NEXT?
The LiqV-FINMA will enter into force on 1 January 2027.
From that date, the qualitative and quantitative liquidity requirements, reporting provisions and related proportionality measures established by the Ordinance will apply in accordance with their respective scope.
Version française
BACKGROUND
Le 7 juillet 2026, l’Autorité fédérale de surveillance des marchés financiers (FINMA) a publié l’ordonnance de la FINMA sur la liquidité des banques et des entreprises d’investissement (LiqO-FINMA), qui transpose la circulaire FINMA 2015/2 «Risques de liquidité – banques» en une ordonnance contraignante, conformément à l’exigence de hiérarchie réglementaire prévue à l’article 7, paragraphe 1, de la loi sur la surveillance des marchés financiers (LSFM). L’ordonnance s’applique aux banques et aux entreprises d’investissement soumises à la surveillance de la FINMA, tant au niveau consolidé qu’au niveau individuel, avec des exemptions et des simplifications pour les banques des catégories 4 et 5 et des exigences supplémentaires pour les banques d’importance systémique. Une consultation publique sur le projet d’ordonnance s’est déroulée du 3 juillet au 29 septembre 2025.
WHAT'S NEW?
Gestion du risque de liquidité
L'ordonnance reprend dans une large mesure les exigences qualitatives de la circulaire 2015/2, notamment en matière de gouvernance, de stratégies de gestion du risque de liquidité, de prix de transfert, de planification de la liquidité et du financement, de risque de liquidité intrajournalier, de tests de résistance et de plans de financement d'urgence.
Exigences relatives au LCR et au NSFR
La LiqO-FINMA consolide les exigences détaillées concernant :
- le LCR : éligibilité des HQLA et exigences opérationnelles, LCR en francs suisses et en devises étrangères, flux intragroupe, sorties et entrées de dépôts, produits dérivés, facilités de liquidité et indicateurs de suivi ;
- le NSFR : actifs grevés, financement stable disponible et facteurs de financement stable requis, traitement intragroupe et actifs et passifs liés.
Modifications de fond
Par rapport à la circulaire 2015/2, l’ordonnance introduit des modifications de fond dans deux domaines :
- les exigences en matière de planification de la liquidité et du financement ; et
- les obligations de communication d’informations en cas de crise de liquidité.
Ces modifications s’alignent sur les modifications concomitantes apportées à l’ordonnance du Conseil fédéral sur la liquidité (LiqV).
WHAT'S NEXT?
L'ordonnance LiqV-FINMA entrera en vigueur le 1er janvier 2027.
À compter de cette date, les exigences qualitatives et quantitatives en matière de liquidité, les dispositions relatives au reporting et les mesures de proportionnalité associées prévues par l'ordonnance s'appliqueront conformément à leur champ d'application respectif.
Swiss Official Journal publishes FINMA Liquidity Ordinance for Banks and Securities Firms / La Feuille officielle suisse publie l'ordonnance de la FINMA sur la liquidité des banques et des entreprises d'investissement
![]()
On 14 July 2026, the Swiss official journal published the FINMA Ordinance on the Liquidity of Banks and Securities Firms (OLiq-FINMA / LiqO-FINMA), adopted on 24 June 2026 by FINMA, under official systematic collection reference RS 952.061. It transposes FINMA Circular 2015/2 "Liquidity risks – banks" into a binding ordinance, fulfilling the regulatory fairness requirement under Article 7(1) of the Financial Market Supervision Act (FINMASA).
The ordinance applies to all FINMA-supervised banks and securities firms at both consolidated and individual institution level. Exemptions and simplifications are available for categories 4 and 5 banks under Annex 3 of the Banking Ordinance (OB). Systemically relevant banks are subject to additional requirements. Foreign branches and subsidiaries of foreign banks are also addressed.
The ordinance covers qualitative liquidity risk management requirements (governance, strategies, transfer pricing, liquidity and funding planning, intraday risk, stress testing and contingency funding plans); detailed LCR rules (HQLA eligibility, Swiss franc and foreign currency LCR, intragroup flows, deposit outflow and inflow categorisation, derivatives, facilities and monitoring metrics); and NSFR rules (encumbered assets, ASF and RSF factors, intragroup treatment, connected assets and liabilities). Two substantive additions relative to Circular 2015/2 concern liquidity and funding planning requirements and information provision during liquidity stress, both aligned with concurrent amendments to the Federal Council's Liquidity Ordinance (OLiq).
- 24 June 2026: Adoption by FINMA; provisional version published
- 7 July 2026: FINMA press release
- 14 July 2026: Official publication on Fedlex (RS 952.061)
- 1 January 2027: Entry into force; simultaneous repeal of Circular 2015/2
Version française
Le 14 juillet 2026, le Journal officiel suisse a publié l’ordonnance de la FINMA sur la liquidité des banques et des entreprises d’investissement (OLiq-FINMA / LiqO-FINMA), adoptée le 24 juin 2026 par la FINMA, sous la référence RS 952.061 du recueil systématique officiel. Elle transpose la circulaire FINMA 2015/2 « Risques de liquidité – banques » en une ordonnance contraignante, répondant ainsi à l’exigence d’équité réglementaire prévue à l’article 7, paragraphe 1, de la loi sur la surveillance des marchés financiers (LSFM).
L’ordonnance s’applique à toutes les banques et sociétés de valeurs mobilières soumises à la surveillance de la FINMA, tant au niveau consolidé qu’au niveau individuel de chaque établissement. Des exemptions et des simplifications sont prévues pour les banques des catégories 4 et 5 au titre de l’annexe 3 de l’ordonnance sur les banques (OB). Les banques d’importance systémique sont soumises à des exigences supplémentaires. Les succursales étrangères et les filiales de banques étrangères sont également concernées.
L’ordonnance couvre les exigences qualitatives en matière de gestion du risque de liquidité (gouvernance, stratégies, prix de transfert, planification de la liquidité et du financement, risque intrajournalier, tests de résistance et plans de financement d’urgence) ; les règles détaillées relatives au LCR (éligibilité des HQLA, LCR en francs suisses et en devises étrangères, flux intragroupe, classification des sorties et entrées de dépôts, dérivés, facilités et indicateurs de suivi) ; ainsi que des règles relatives au NSFR (actifs grevés, facteurs ASF et RSF, traitement intragroupe, actifs et passifs liés). Deux ajouts substantiels par rapport à la circulaire 2015/2 concernent les exigences en matière de planification de la liquidité et du financement ainsi que la communication d’informations en cas de crise de liquidité, tous deux alignés sur les modifications concomitantes apportées à l’ordonnance du Conseil fédéral sur la liquidité (OLiq).
- 24 juin 2026 : adoption par la FINMA ; publication de la version provisoire
- 7 juillet 2026 : communiqué de presse de la FINMA
- 14 juillet 2026 : publication officielle sur Fedlex (RS 952.061)
- 1er janvier 2027 : entrée en vigueur ; abrogation simultanée de la circulaire 2015/2
STATUTORY AUDITS
FINMA publishes prudential audit guide for banks, securities firms and financial groups / La FINMA publie un guide d'audit prudentiel destiné aux banques, aux sociétés de courtage et aux groupes financiers
![]()
On 24 July 2026, the Swiss Financial Market Supervisory Authority (FINMA) published an updated edition of its practical guide on prudential audit (guide pratique audit prudentiel banques), which provides operational guidance to prudential audit firms of banks, securities firms and financial groups on the completion of three standardised survey forms: the risk analysis, the standard audit strategy, and the prudential audit report.
The guide is a working document addressed exclusively to prudential audit firms, not to supervised institutions directly. It is structured around the FINMA Ordinance on Prudential Audit of 31 October 2024 (RS 956.161.1) and FINMA Circular 2025/1 on Audit Activities. All survey forms are submitted electronically via FINMA's digital platform (EHP). The guide supersedes previous editions and incorporates updates linked to the transition from FINMA Circular 2023/1 on operational risks and resilience.
The guide applies to prudential audit firms mandated to audit banks, securities firms (maisons de titres) and financial groups subject to FINMA supervision in Switzerland, across all supervisory categories (1 to 5). It covers both individual-level and consolidated supervision. It does not apply directly to supervised institutions, though its content shapes the audit procedures to which those institutions are subject.
The guide addresses five operational areas.
On risk analysis, audit firms must describe risks concretely and quantitatively per audit domain, classify them by inherent risk (gross) and control risk to derive a net risk score, and rank the top ten gross and net risks. Consolidated supervision requires additional treatment of material risks at group entity level.
On audit strategy, supervisory categories 3 to 5 apply the standard audit strategy under Art. 32(2)–(4) of the Prudential Audit Ordinance; deviations must be justified. Specific periodicity rules apply to key audit domains: AML compliance requires annual full audit at high/very high net risk, biennial at medium, and triennial at low net risk; ICT risk management and internal models follow four-year rolling coverage; outsourcing and internal organisation follow six-year rolling coverage; internal audit and group corporate governance require annual critical review.
On audit reporting, the prudential audit report must be comprehensive, explicit and objective, signed by qualified electronic signature by two authorised auditors; findings must be classified per Arts. 25–26 of the Prudential Audit Ordinance regardless of audit scope used.
On operational resilience audit fields, the guide provides detailed transition rules for the mapping of former IT audit fields to new fields under Circular 2023/1 (cyber risk management, critical data risk management, operational resilience), with specific transitional arrangements applicable from audit year 2024 through 2027.
On audit quality, Art. 12 of the Prudential Audit Ordinance governs quality assurance requirements covering planning, delegation, team instruction, supervision and time management.
Version française
Le 24 juillet 2026, l’Autorité fédérale de surveillance des marchés financiers (FINMA) a publié une édition mise à jour de son guide pratique sur l’audit prudentiel (guide pratique « audit prudentiel banques »), qui fournit des orientations opérationnelles aux cabinets d’audit prudentiel des banques, des sociétés de valeurs mobilières et des groupes financiers pour remplir trois formulaires d’enquête standardisés : l’analyse des risques, la stratégie d’audit standard et le rapport d’audit prudentiel.
Ce guide est un document de travail destiné exclusivement aux cabinets d’audit prudentiel, et non directement aux établissements soumis à surveillance. Il s’articule autour de l’ordonnance de la FINMA du 31 octobre 2024 sur l’audit prudentiel (RS 956.161.1) et de la circulaire FINMA 2025/1 relative aux activités d’audit. Tous les formulaires d’enquête sont transmis par voie électronique via la plateforme numérique de la FINMA (EHP). Le guide remplace les éditions précédentes et intègre les mises à jour liées à la transition depuis la circulaire FINMA 2023/1 sur les risques opérationnels et la résilience.
Le guide s’applique aux cabinets d’audit prudentiel mandatés pour auditer les banques, les maisons de titres et les groupes financiers soumis à la surveillance de la FINMA en Suisse, toutes catégories de surveillance confondues (1 à 5). Il couvre à la fois la surveillance individuelle et la surveillance consolidée. Il ne s’applique pas directement aux établissements surveillés, bien que son contenu détermine les procédures d’audit auxquelles ces établissements sont soumis.
Le guide aborde cinq domaines opérationnels.
En matière d’analyse des risques, les cabinets d’audit doivent décrire les risques de manière concrète et quantitative par domaine d’audit, les classer en fonction du risque inhérent (brut) et du risque de contrôle afin d’obtenir un score de risque net, et classer les dix principaux risques bruts et nets. La surveillance consolidée nécessite un traitement supplémentaire des risques significatifs au niveau des entités du groupe.
En matière de stratégie d’audit, les catégories de surveillance 3 à 5 appliquent la stratégie d’audit standard prévue à l’article 32, alinéas 2 à 4, de l’ordonnance sur l’audit prudentiel ; tout écart doit être justifié. Des règles de périodicité spécifiques s’appliquent aux domaines d’audit clés : la conformité en matière de lutte contre le blanchiment d’argent nécessite un audit complet annuel en cas de risque net élevé ou très élevé, bisannuel en cas de risque net moyen, et triennal en cas de risque net faible ; la gestion des risques liés aux TIC et les modèles internes font l’objet d’une couverture glissante sur quatre ans ; l’externalisation et l’organisation interne font l’objet d’une couverture glissante sur six ans ; l’audit interne et la gouvernance d’entreprise du groupe nécessitent un examen critique annuel.
En matière de rapports d’audit, le rapport d’audit prudentiel doit être exhaustif, explicite et objectif, et signé au moyen d’une signature électronique qualifiée par deux auditeurs habilités ; les constatations doivent être classées conformément aux articles 25 à 26 de l’ordonnance sur l’audit prudentiel, quelle que soit l’étendue de l’audit effectuée.
En ce qui concerne les domaines d’audit de la résilience opérationnelle, le guide fournit des règles de transition détaillées pour la mise en correspondance des anciens domaines d’audit informatique avec les nouveaux domaines prévus par la circulaire 2023/1 (gestion des risques cybernétiques, gestion des risques liés aux données critiques, résilience opérationnelle), avec des dispositions transitoires spécifiques applicables de l’année d’audit 2024 à 2027.
En matière de qualité de l’audit, l’article 12 de l’ordonnance sur l’audit prudentiel régit les exigences d’assurance qualité couvrant la planification, la délégation, la formation de l’équipe, la supervision et la gestion du temps.
UNITED KINGDOM
ALTERNATIVE PRODUCTS
UK Government and FCA launch comprehensive reform of the UK AIFM regime
![]()
On 14 July 2026, the UK Government and the Financial Conduct Authority jointly launched a comprehensive reform of the UK Alternative Investment Fund Manager (AIFM) regime, comprising draft legislation and a parallel FCA consultation designed to create a more proportionate, growth-oriented regulatory framework for the UK asset management sector.
The reforms form part of the UK's wider post-Brexit financial services agenda and seek to replace key provisions of the Alternative Investment Fund Managers Regulations 2013 with a framework that gives the FCA greater responsibility for developing and maintaining detailed regulatory requirements.
The draft legislation would remove most firm-facing requirements from legislation and transfer them to the FCA rulebook, while retaining core safeguards relating to depositaries, leverage controls, investor protection and the National Private Placement Regime. The Government also proposes clarifying the definition of an AIF, reforming the registration regime for smaller managers, simplifying private equity disclosure obligations, streamlining marketing requirements and providing the FCA with greater flexibility to redesign reporting frameworks. In parallel, the FCA proposes replacing the existing full-scope and sub-threshold categorisation with a three-tier regime based on net asset value (NAV), consisting of small, medium and large AIFMs, with regulatory requirements scaling according to firm size and risk profile.
The FCA consultation also proposes simplified risk management, liquidity management and valuation requirements, streamlined delegation arrangements, revised investor disclosure and annual reporting obligations, a new Alternative Investment Funds Sourcebook (ALTS), and the transition of most currently registered AIFMs into the authorised regime. Additional proposals affect depositaries, prime brokers, closed-ended investment companies, residual CIS operators and cross-border marketing arrangements. Together, the reforms aim to reduce unnecessary regulatory burdens, improve proportionality as firms grow, support innovation and strengthen the competitiveness of the UK asset management industry while maintaining investor protection and financial stability.
Comments on both the draft legislation and FCA consultation are requested by 14 October 2026, with implementation expected in 2028.
CREDIT RISK
UK Government publishes draft regulations establishing the Overseas Prudential Requirements Regime for credit institutions and investment firms
![]()
On 2 July 2026, the UK Government published draft Regulations establishing the Overseas Prudential Requirements Regime for credit institutions and investment firms, which is due to enter into force on 1 January 2027.
The proposed regime forms part of the UK's post-Brexit prudential framework and replaces certain third-country equivalence provisions previously contained in the EU Capital Requirements Regulation (CRR). It empowers HM Treasury to designate overseas jurisdictions whose prudential and supervisory frameworks are considered sufficiently comparable to the UK's, subject to considerations including financial stability, safety and soundness, competition and international competitiveness.
The draft regulations set out how UK CRR firms and consolidated banking groups may treat exposures to entities located in designated jurisdictions for prudential capital purposes. The regime covers exposures to overseas credit institutions, investment firms, exchanges, central governments, central banks, regional and local authorities, public sector entities and eligible covered bonds. It also provides rules governing the treatment of capital instruments issued by overseas intermediate financial holding companies.
The regulations include an initial list of jurisdictions deemed designated, including the European Union, United States, Switzerland, Japan, Canada, Singapore, Hong Kong and several other major financial centres. Firms may therefore continue to apply favourable prudential treatment to certain exposures in these jurisdictions, subject to specified conditions and PRA capital rules. The framework also contains specific provisions relating to Gibraltar entities and exposures.
Overall, the proposal seeks to preserve continuity in the prudential treatment of overseas exposures following the migration of CRR requirements into the PRA Rulebook, while providing HM Treasury with an ongoing mechanism to recognise equivalent foreign prudential regimes and support internationally active UK banking groups.
DIGITAL OPERATIONAL RESILIENCE
UK publishes the Critical Third Parties (Designation) Regulations 2026
![]()
On 8 July 2026, the UK published the Critical Third Parties (Designation) Regulations 2026, formally designating Amazon Web Services (AWS), Google Cloud, Microsoft Ireland Operations Limited, and Oracle Corporation UK Limited as Critical Third Parties (CTPs) to the UK financial sector.
The regulations were introduced under the Financial Services and Markets Act 2000, as amended by the Financial Services and Markets Act 2023.
The designation reflects the UK authorities’ assessment that a disruption or failure in the services provided by these firms could threaten the stability of, or confidence in, the UK financial system. Before making the designations, the Treasury consulted the Financial Conduct Authority (FCA), the Prudential Regulation Authority (PRA), and the Bank of England, and considered representations from the affected providers.
The publication represents a significant milestone in the UK’s operational resilience framework, recognising the systemic importance of major cloud service providers that support critical functions across banks, insurers, payment institutions, investment firms, and financial market infrastructures. By bringing these providers within the UK’s Critical Third Parties regime, regulators gain enhanced oversight of technology providers whose services are widely used by financial institutions.
Although the regulations apply directly to the designated cloud providers rather than to financial institutions themselves, they are particularly relevant for firms that rely on cloud-based infrastructure and outsourcing arrangements. The measure strengthens the broader UK approach to managing concentration risk and operational resilience in the financial sector, reflecting increasing regulatory focus on dependencies on a small number of technology providers.
The regulations enter into force on 13 July 2026.
GOVERNANCE & ORGANISATION
UK Government proposes comprehensive reform of the AIFM regulatory framework
![]()
On 14 July 2026, the UK Government published draft legislation and an accompanying policy note proposing a fundamental reform of the UK regulatory framework for Alternative Investment Fund Managers (AIFMs).
The reforms form part of the UK's post-Brexit financial services agenda and seek to replace key provisions of the existing Alternative Investment Fund Managers Regulations 2013 with a more flexible framework that places greater responsibility on the Financial Conduct Authority (FCA) to develop and maintain detailed regulatory requirements. The Government's objective is to create a more proportionate regime that supports growth in the asset management sector while maintaining investor protection and financial stability.
The draft regulations would remove most firm-facing requirements from legislation and enable the FCA to establish a tailored regulatory framework through its rulebook. Key changes include the removal of the current full-scope and sub-threshold AIFM thresholds, reform of the registration regime for smaller managers, clarification of the definition of an AIF, simplification of private equity disclosure requirements, streamlining of marketing requirements, and enhanced flexibility for the FCA to redesign reporting obligations. The Government also proposes retaining the National Private Placement Regime while preserving core safeguards relating to depositaries, leverage limits and investor protections.
The reforms are intended to support a more proportionate regulatory approach as firms grow, reduce unnecessary regulatory burdens and improve the competitiveness of the UK asset management industry.
The government welcomes any technical comments on the draft SI by 14 October 2026.
OTHER - PRUDENTIAL REQUIREMENTS
PRA publishes its approach to the publication of Solvency II technical information
![]()
On 29 July 2026, the Prudential Regulation Authority published an updated edition of Statement of Policy 1/20, which explains how the PRA fulfils its obligation to publish Solvency II technical information (TI) relevant to the calculation of technical provisions, and sets out the PRA's approach to calculating the symmetric adjustment to the equity capital charge (SAECC).
The PRA is required under Regulation 3 of the Insurance and Reinsurance Undertakings (Prudential Requirements) Regulations 2023 to publish TI appropriate for the calculation of technical provisions. This Statement of Policy (SoP) explains the PRA's methodologies and judgements in fulfilling this obligation. It updates the November 2024 edition, reflecting ongoing refinements to the PRA's approach following the UK's post-Brexit Solvency II framework. UK firms must use the PRA's published TI for regulatory reporting.
The SoP applies to all UK Solvency II firms, including the Society of Lloyd's and its managing agents. It covers PRA relevant currencies, basic risk-free rates (RFRs), extrapolation methodology, long-term average spread (LTAS) calculation, volatility adjustment (VA) reference portfolios, risk-corrected currency spread calculation, and the SAECC. The geographic scope is the UK.
The SoP sets out six substantive areas.
On PRA relevant currencies, the PRA selects currencies by materiality (covering at least 99% of group technical provisions) and by inclusion of currencies in which UK insurers hold VA or MA authorisations; the list is reviewed every three years; currencies may be added or removed subject to at least three months' notice to firms.
On basic RFRs, the PRA derives the basic RFR from interest rate swap rates adjusted for credit risk, or from government bond rates where swap markets are not deep, liquid, and transparent; credit risk adjustments reflect the credit risk inherent in the reference instrument.
On RFR extrapolation, the PRA applies consistent extrapolation principles across all relevant currencies, deriving the ultimate forward rate (UFR) using the same methodology as EIOPA's UFR Report for 2024, maintaining UFR stability and only revising it where long-term expectations change; extrapolation is applied after the VA for VA-inclusive term structures.
On LTAS calculation, historic spreads over Libor-based RFRs remain unadjusted following transition to OIS rates; spread data for government bonds is interpolated where market data is unavailable.
On VA reference portfolios, the GBP VA reference portfolio is derived from QRT data submitted by UK solo insurers; non-GBP VA reference portfolios use a weighted average of EIOPA's published RPs and PRA-derived RPs; regional government and local authority bonds are classified as corporate bonds; VA RP changes are effective from the next 31 March following publication with at least three months' notice.
On the SAECC, the PRA calculates and publishes the SAECC monthly in accordance with the Solvency Capital Requirement – Standard Formula Part of the PRA Rulebook (Sections 3D12–3D14), allowing standard formula firms to adjust the equity capital charge in the equity risk sub-module.
PAYMENTS
PSR publishes consultation paper CP26/2 on confirmation of payee
![]()
On 30 July 2026, the Payment Systems Regulator (PSR) published Consultation Paper CP26/2, which proposes to vary Specific Direction 17 (Expanding Confirmation of Payee) (SD17) by removing its fixed expiry date of 1 November 2026 and consulting on expanding its scope to cover all payment service providers (PSPs) currently offering Confirmation of Payee (CoP) on a voluntary basis.
CoP is a name-checking service for Faster Payments and CHAPS transactions that verifies whether the payee account name matches the details provided by the payer. It was introduced to reduce misdirected payments and certain types of authorised push payment (APP) fraud. The PSR notes that transactions where the expected recipient name does not match the account are 25 times more likely to be fraudulent. Since SD17 came into force, over 320 PSPs now offer CoP, over 99% of PSPs initiating Faster Payments offer CoP checks, and over 2 million checks are completed daily. Pay.UK has reported a 59% reduction in claims for payments to the wrong account and a 20–40% reduction in losses for some fraud types. The PSR acts under section 54 of FSBRA.
The consultation primarily concerns PSPs that are participants in Faster Payments or CHAPS and conduct relevant business (i.e. provide UK accounts where not all transactions are exempt). The proposals affect three groups:
- Group 1 PSPs (listed in the Schedule, including a wide range of banks, building societies, EMIs and payment institutions);
- Group 2 PSPs (participants not already in Group 1 that did not have CoP in operation when SD17 came into force);
- and the proposed new Group 3 PSPs (participants that had CoP in regular operation on 24 October 2022 but are not currently directed). The PSR confirms it will retain existing exemptions for PSPs that do not carry out relevant business.
Two proposals are put forward:
- Removing the expiry date: SD17 would continue in force indefinitely until varied or revoked by the PSR, preserving regulatory continuity and ensuring all currently directed PSPs retain an obligation to provide CoP. The PSR proposes a formal review no later than five years after the amending direction comes into force, with earlier review possible following material changes to retail payments infrastructure led by the Payments Vision Delivery Committee (PVDC) or the Retail Payments Infrastructure Board (RPIB).
- Expanding scope to Group 3 PSPs: All PSPs currently offering CoP voluntarily would be brought within SD17 via an amending direction (SD17a), placing all CoP providers on a consistent regulatory footing. Group 3 PSPs would be required to have and use a compliant CoP system from 31 December 2026. No changes to how the service operates are proposed.
PSR publishes policy statement PS26/1 on market review of card scheme and processing fees
![]()
On 30 July 2026, PSR published PS26/1, Market Review of Card Scheme and Processing Fees: Final Decision (Information, Transparency and Complexity Remedy; Pricing Governance Remedy), which sets out the PSR's final assessment of consultation responses and confirms the introduction of two binding remedies addressing poor transparency and inadequate pricing governance in the card scheme and processing fees market.
The publication concludes a process initiated with the PSR's market review in October 2022, whose Final Report (March 2025) found that Mastercard and Visa face ineffective competitive constraints on the acquiring side, do not provide acquirers with sufficiently clear fee information, and have raised fees substantially with no clear evidence of cost-based or competition-driven pricing. Evidence of profit margins higher than expected in competitive markets was noted, though the PSR did not reach firm conclusions on UK profitability given data limitations. Following a remedies consultation (CP25/1, April 2025) and a consultation on draft directions (CP25/3, December 2025), the PSR now gives two final specific directions using its powers under section 54(3)(c) of FSBRA.
The two directions apply to Mastercard and Visa as Operators of their respective UK Regulated Payment Systems. The remedies are designed to benefit acquirers and, through them, merchants and ultimately consumers. No obligations are imposed directly on acquirers or other financial institutions. Note: the PSR acknowledges Government plans to consolidate it into the FCA; future references to PSR action should be read as potentially including the FCA.
Two remedies are confirmed:
ITC Remedy (Specific Direction 22): Mastercard and Visa must provide acquirers with clear, structured information on all existing scheme and processing fees (ITC1) and advance notice of new and modified fees (ITC2), enabling acquirers to understand, reconcile and manage their fee exposure. Following consultation, the materiality threshold was raised from £100,000 net revenue to £250,000 gross revenue. The requirement for transaction-level identifiers was removed and replaced with a "fee logic" standard, requiring sufficient information for acquirers to reconcile billed fees to originating transactions.
Pricing Governance Remedy (Specific Direction 23): Mastercard and Visa must record in writing the factors considered in each Acquirer Fee Decision, apply a Pricing Decision Principle requiring due regard to service users' interests, appoint an Executive Manager, and submit annual reporting to the PSR. The same £250,000 materiality threshold applies.
A third remedy — Regulatory Financial Reporting (RFR) — was adopted separately in May 2026 and is not covered by this policy statement. A fourth remedy (publication of scheme information) was not pursued.
PSR publishes specific direction 22 on measures to improve information transparency of scheme and processing fees charged to acquirers
![]()
On 30 July 2026, the Payment Systems Regulator (PSR) published Specific Direction 22: Mastercard and Visa Information, Transparency and Complexity (the ITC Direction), which directs Mastercard and Visa to provide acquirers with minimum specified information to enable them to understand the scheme and processing fees charged in connection with UK card-based payment transactions.
The ITC Direction flows directly from the PSR's scheme and processing fees market review, formally launched in October 2022 and concluded in a Final Report published in March 2025. That Final Report found that Mastercard and Visa do not provide sufficiently clear and detailed information to acquirers on core and optional scheme and processing services and fees, impairing acquirers' ability to understand charges, avoid unwanted optional services, and mitigate costs of behavioural fees. The PSR concluded this was below the standard expected in a well-functioning market. The ITC Direction is one of several remedies decided upon alongside a separate Pricing Governance Remedy (also July 2026). The PSR exercises its powers under sections 54(1) and 54(2) of the Financial Services (Banking Reform) Act 2013 (FSBRA).
The Direction is issued to specified persons — the Operators of the Mastercard Payment System and Visa Europe Payment System — both of which are designated as Regulated Payment Systems by HM Treasury under section 43 of FSBRA.
The ITC Direction applies exclusively to two Directed Operators:
- Mastercard (Operator of the Mastercard Payment System)
- Visa (Operator of the Visa Europe Payment System)
The substantive obligations concern the provision of information to acquirers — payment service providers contracting with merchants to provide card-acquiring services — in respect of UK Transactions (card transactions involving a UK Point of Sale). The Direction does not directly impose obligations on acquirers, merchants, issuers or other payment service providers, though those entities benefit from the enhanced transparency it mandates.
The ITC Direction is built around two core requirements:
- ITC1 — Each Directed Operator must provide acquirers with information to understand all existing scheme and processing fees for UK transactions, meeting two minimum standards:
- ITC Standard A: Minimum information per fee, covering categorisation (mandatory scheme, mandatory processing, optional, or behavioural), a description and explanation (including activities covered, frequency, geography, purpose, and — for behavioural fees — how to mitigate or avoid them; for optional fees — whether opt-in or opt-out and how to exercise that choice), a unique and consistent billing identifier, and rates and units (including currency, transaction applicability, pricing structure and tiering).
- ITC Standard B: Sufficient information to enable acquirers to reconcile each fee incurred during a billing period with the transactions, behaviours or services that generated it; to be available for at least 12 months from billing date. No additional charges may be levied for providing this information.
- ITC2 — Each Directed Operator must provide acquirers with advance information on all new and modified scheme and processing fees (excluding new or modified opt-in optional fees), meeting two further standards:
- ITC Standard C: ITC Standard A information applied to new and modified fees, provided via announcements at least six months before implementation; no in-period changes to announced information are permitted except in defined exceptional circumstances.
- ITC Standard D: On request and within a reasonable timeframe, individualised information enabling each acquirer to assess the financial impact of new or modified behavioural fees and the mitigation actions available, informed by the acquirer's transactional records for the prior 12 months; to be made available at least three months before implementation.
A de minimis exemption applies to ITC2: it does not apply to any fee reasonably anticipated to generate below £250,000 in gross revenue in the full financial year following implementation. Directed Operators relying on this exemption must report actual revenues to the PSR after year-end.
Compliance, Monitoring and Governance:
- Within 3 months of the Commencement Date, each Directed Operator must write to acquirers setting out an ITC Compliance Policy and seeking their views.
- Within 6 months, each Directed Operator must respond to acquirer feedback and confirm a timetable for any remaining changes.
- Annually (from one month after the first anniversary of the Commencement Date), each Directed Operator must submit a Compliance Report to the PSR, approved by relevant UK-based executives.
- 6-year record-keeping obligation for communications and engagement records.
- Prompt self-notification to the PSR of any actual or anticipated compliance failure.
- The PSR retains the right to request documents and information for monitoring purposes.
- A non-circumvention obligation prevents direct or indirect avoidance of the Direction.
- Directed Operators may apply to the PSR for exemptions or extensions in exceptional circumstances.
- Compliance must remain consistent with IFR Article 7 separation requirements between scheme and processing activities; separate compliance policies and reports may be required accordingly.
PSR publishes specific direction 23 on Mastercard and Visa pricing governance
![]()
On 30 July 2026, the Payment Systems Regulator (PSR) published Specific Direction 23: Mastercard and Visa Pricing Governance (the PG Direction), which directs Mastercard and Visa to implement structured governance and record-keeping requirements for their UK pricing decisions on scheme and processing fees charged to acquirers. The Direction flows from the PSR's scheme and processing fees market review (Final Report, March 2025), which found that scheme revenues had risen substantially, that the fee burden falls primarily on acquirers, that there was very limited evidence linking fee changes to cost changes, and that Mastercard and Visa do not consistently record in writing the factors considered when approving fee changes. The PG Direction directly addresses this evidential gap. It is published alongside Specific Direction 22 (information transparency) and the PSR's Final Decision on Remedies (July 2026). The PSR acts under sections 54(1) and (2) of FSBRA.
The Direction applies exclusively to Mastercard and Visa as Directed Operators of their respective UK Regulated Payment Systems. Obligations concern decisions to introduce or modify fees charged to acquirers for UK Transactions (card transactions involving a UK Point of Sale). No obligations fall directly on acquirers, merchants or other financial institutions, though acquirers are the intended beneficiaries of the Direction's protections.
Interconnected obligations apply from the Effective Date (~30 November 2026):
- Acquirer Fee Decision Records: Each decision to approve a new or modified scheme and processing fee above a £250,000 gross UK revenue threshold must be documented in a written record covering the fee's purpose, structure, basis for approval, how the Pricing Decision Principle and commercial interests were weighed, and a schedule of all materials presented to senior managers or pricing committees. Records must be signed by the approving Senior Manager(s). A de minimis threshold of £250,000 applies, with cumulative calculation required where multiple related decisions are taken within 12 months.
- Pricing Decision Principle: Directed Operators must pay due regard to service users' interests by assessing the impact of each fee decision on acquirers and — where relevant information is held — merchants, on competition and innovation, and on payment system resilience, using a prescribed framework covering quantified revenue impact, cost linkage, competing services, and — for behavioural and optional fees — additional specific considerations. Where requirements cannot be satisfied, this must be recorded and reported.
- Governance and Reporting: Each Directed Operator must appoint a PSR-approved Executive Manager at board, European Management Committee or senior compliance level; establish and notify Compliance Processes to the PSR by the Effective Date; and submit annually an Overview of all Acquirer Fee Decisions and a signed Pricing Governance Compliance Report within one month of each financial year end.
- De Minimis Threshold: The substantive record-keeping and Pricing Decision Principle requirements (section 3 and Annex 1) apply only to fees reasonably anticipated to generate more than £250,000 in gross UK revenue in the full financial year following implementation. Where multiple fee decisions are adopted simultaneously or within 12 months for substantially the same reasons, anticipated revenues are calculated on a cumulative basis.
Record-Keeping:
- Acquirer Fee Decision Records: 10 years from the date of the relevant decision.
- Compliance Processes documentation: 3 years from generation.
- The PSR may request records within 10 working days (or 30 working days from the date of the relevant decision, whichever is later).
REMUNERATION
FCA consults on simplified remuneration regime for solo-regulated firms
![]()
On 14 July 2026, the Financial Conduct Authority (FCA) published Consultation Paper CP26/27 proposing a significant reform of remuneration requirements for FCA solo-regulated firms, including alternative investment fund managers (AIFMs), UCITS management companies and non-SNI MiFID investment firms.
The FCA argues that the current framework, which is based on multiple remuneration codes derived from post-financial crisis banking regulation, has become overly complex and burdensome for firms whose business models and risk profiles differ from those of banks.
The consultation proposes replacing the existing AIFM, UCITS and MIFIDPRU remuneration codes with a single consolidated remuneration framework. The new regime would adopt a more outcomes-focused and proportionate approach, relying more heavily on governance, accountability and management judgement rather than detailed prescriptive requirements. The FCA also proposes removing all small and non-interconnected (SNI) MiFID investment firms from scope, narrowing the definition of material risk takers, and reducing governance obligations by removing mandatory remuneration committees, annual independent remuneration reviews and certain remuneration reporting requirements.
In addition, the FCA proposes greater flexibility regarding variable remuneration, including replacing mandatory deferral structures with a principles-based approach and making the use of malus and clawback mechanisms discretionary rather than mandatory. The regulator estimates that the reforms could generate substantial compliance cost savings while maintaining safeguards designed to promote sound conduct, effective risk management and alignment with the interests of clients, investors and funds.
The consultation is open until 16 September 2026, with the FCA expecting to publish a policy statement in the first quarter of 2027.
REPORTING
FCA consults on new fund reporting framework for asset managers (FRAME)
![]()
On 14 July 2026, the Financial Conduct Authority (FCA) published Consultation Paper CP26/26 proposing a new reporting framework for asset managers called Fund Reporting for Asset Management Entities (FRAME).
The proposal aims to replace the current fragmented reporting regime for AIFs, UCITS and certain overseas funds with a single, more proportionate framework based on fund size, type and risk profile. The FCA estimates that the reforms could reduce overall reporting burdens by 75% while improving the quality, consistency and usefulness of regulatory data used for supervisory and market oversight purposes.
Under FRAME, funds with net asset value below £500 million would be subject to a streamlined set of “essential” reporting requirements, while larger funds would provide enhanced reporting covering areas such as investor composition, liquidity, leverage, portfolio exposures, sensitivities, counterparty risks and private market activities. The FCA also proposes new reporting requirements for private equity and loan origination funds, limited reporting for overseas recognised funds, and streamlined annual reporting for certain MiFID investment firms and collective investment scheme operators. The framework would introduce greater alignment with international reporting standards and make wider use of Legal Entity Identifiers (LEIs).
The FCA expects the reforms to generate significant annual cost savings for AIF managers while improving visibility over risks related to liquidity, leverage, valuations, concentration and retail investor exposure.
Responses to the consultation are requested by 22 September 2026, with final rules planned for the first half of 2027 and full implementation targeted for 2028.
PRA publishes policy statement PS18/26 on post-implementation reporting and disclosure amendments and own funds permission under Solvency UK
![]()
BACKGROUND
On 29 July 2026, the Prudential Regulation Authority (PRA) published Policy Statement 18/26 – Solvency UK: Post-implementation reporting and disclosure amendments and Own Funds permissions update. The Policy Statement provides feedback on CP22/25 on Solvency UK reporting and disclosure and on Proposal 1 of CP4/26 concerning Own Funds. It finalises amendments intended to address implementation issues identified following the 2024 Solvency UK reporting reforms, improve clarity and data quality, and remove certain avoidable reporting and permission requirements. The policy is relevant to UK Solvency II firms, Lloyd’s, insurance and reinsurance groups and UK holding companies, with certain reporting changes also applying to third-country branch undertakings.
WHAT'S NEW?
Reporting and disclosure amendments
The PRA finalises a number of amendments to Solvency UK templates and instructions, including corrections and clarifications introduced following industry feedback. In particular:
- the proposed IR.05.04.04 template variant will not be introduced, with total income and expenditure instead added to IR.05.04.02;
- reporting of non-life annuity information under IR.16.01 will start from the 31 December 2026 reference date;
- firms may opt to use NACE 2.1 codes from 31 December 2026, ahead of mandatory application from 1 January 2027.
Third-country branches and MALIR
Projected FSCS liabilities reporting for third-country branches is reduced from three business-plan years to one year. The Matching Adjustment Asset and Liability Information Return (MALIR) will move from Excel to XBRL, alongside removal of duplicative requirements and reductions in certain cashflow reporting.
Own Funds
The PRA removes the requirement to obtain permission for equity-accounted subordinated liabilities to be classified into own funds tiers. Such instruments remain subject to the standard pre-issuance notification process, with related reporting amendments.
WHAT'S NEXT?
The final policy and rule changes will apply to reporting reference dates on or after 31 December 2026. The Own Funds and Group Supervision amendments will take effect on the same date, with no interim reporting measures required. The PRA intends to publish the updated reporting taxonomy following the Policy Statement.
SECONDARY MARKET/TRADING
FCA publishes a press release announcing a package of equity market transparency reforms
![]()
On 31 July 2026, the Financial Conduct Authority published a press release announcing a package of equity market transparency reforms, comprising two consultation papers (CP26/30 and CP26/31), the launch of an interim market activity reporter for shares, and the confirmation of the framework for a future UK equity consolidated tape to be delivered within 18 months.
The package follows the launch of the UK bond consolidated tape in June 2026, which attracted more than 1.6 million licence subscriptions. It forms part of the FCA's wider programme of capital markets reform. The FCA's assessment is that UK equity markets are functioning effectively and that competition and innovation have delivered significant benefits including liquid and resilient markets. However, greater market fragmentation has made obtaining a complete picture of trading activity complicated and expensive, leading to market-wide data being under-used and the depth and liquidity of UK equity markets being under-appreciated.
The reforms affect participants in UK equity markets, including trading venues, data reporting service providers, investment firms, asset managers, and other market users. The consultation papers are open for feedback until 16 October 2026. The equity consolidated tape is targeted for delivery within 18 months of the package; the FCA will consider consultation feedback before beginning procurement for the tape provider.
The package contains three components.
On the equity consolidated tape framework (CP26/31), the FCA confirms the design framework for a future UK equity consolidated tape that will bring together pre- and post-trade data from across the market into a single source, improving access to market-wide data, supporting more transparent and efficient capital markets, and enhancing price formation. The FCA will begin procurement for the tape provider after considering consultation feedback.
On equity market structure and transparency (CP26/30), the FCA consults on targeted market structure reforms and sets out how market quality will be monitored, seeking views on the indicators to be tracked and the tools that could be available for proportionate future intervention if needed.
On the interim market activity reporter for shares, the FCA has launched a tool providing visibility of overall UK equity market activity each day, helping users see a full picture of trading volumes before the full consolidated tape is launched.
FCA publishes an update on exemptions from short-selling requirements
![]()
On 13 July 2026, the Financial Conduct Authority updated its guidance page on exemptions from short-selling requirements to reflect the entry into force of the new UK short selling regime (SSR), introducing an activity-based market maker exemption (MME), a new Reportable Shares List (RSL), the removal of UK sovereign debt and sovereign CDS from scope, and transitional arrangements for existing MME notifications.
The new UK SSR entered into force on 13 July 2026. The update reflects three structural changes to the exemptions framework: the replacement of the previous list of exempted shares with a new Reportable Shares List (RSL); the removal of UK sovereign debt and sovereign CDS from the scope of position reporting and covering requirements (and the associated exemptions); and the transition of the MME from an instrument-based to an activity-based exemption, simplifying how firms notify and rely on it.
The updated framework applies to investment firms, credit institutions, and equivalent overseas entities that are members of a UK trading venue or equivalent overseas trading venue and carry out market making activities in shares reportable under the UK SSR. It also applies to firms conducting stabilisation activities. Firms that notified under the previous MME regime benefit from transitional arrangements until 29 January 2027.
The publication sets out four operative frameworks.
On the activity-based MME, firms may only rely on the exemption when carrying out qualifying market making activity (SSR 5.13–5.19) and must not use it for other activities such as proprietary trading. Firms must submit a new MME notification at least 15 calendar days before relying on the exemption, confirming membership of a trading venue; the FCA will issue a non-objection within 15 calendar days of a complete notification.
Ongoing requirements include maintaining adequate records (SSR 5.10), notifying the FCA of changes in circumstances (SSR 5.7), and submitting an annual attestation by the first working day of June each year (SSR 5.6), signed by a senior person responsible for the entity's regulatory obligations in relation to short selling.
On transitional arrangements, existing MMEs notified under the previous regime are carried forward temporarily; firms must re-notify by 15 January 2027, with the transitional period ending 29 January 2027.
On stabilisation activity, short selling as part of stabilisation remains exempt subject to SSR 5.3.
On waivers and modifications, the FCA may grant waivers under SSR 7 in exceptional circumstances (including serious systems issues) or under section 138A FSMA where compliance is unduly burdensome or the rule does not achieve its intended purpose; waivers are not retrospective and may be subject to conditions.
FCA publishes an update on notification and disclosure of net short positions
![]()
On 13 July 2026, the Financial Conduct Authority updated its guidance on notification and disclosure of net short positions (NSPs) to reflect the entry into force of the new UK short selling regime (SSR), introduced by the Short Selling Regulations 2025, replacing the previous notification framework with a Reportable Shares List (RSL)-based system and updated calculation, reporting, and group reporting requirements.
The new UK SSR entered into force on 13 July 2026, following PS26/5. The update reflects the replacement of the previous list of exempted shares with the new RSL as the basis for identifying reportable shares, carries forward current NSP notifications submitted from 1 January 2021 onwards, and requires positions last notified before that date to be re-submitted. All notifications from 13 July 2026 must use the RSL from day one, including for positions relating to the previous working day (T+1).
The regime applies to all position holders — including investment firms, credit institutions, asset managers, and other investors — holding net short positions in shares of companies on the RSL at or above the 0.2% threshold of issued share capital. Group and entity-level reporting obligations apply separately. Record retention applies for 5 years. The FCA publishes aggregate net short position (ANSP) reports each working day from 12:00.
The publication sets out five substantive obligations.
On RSL and scope, the RSL identifies shares admitted to UK trading venues that are in scope; it is reviewed fully every two years (first working day of April), updated monthly (first working day), and ad hoc in exceptional circumstances. UK sovereign debt and sovereign CDS are no longer in scope.
On position reporting, position holders must calculate NSPs for each working day based on positions held at midnight; notify the FCA when NSPs reach or exceed 0.2% of a company's issued share capital, and at each 0.1 percentage point increment; submit notifications by 23:59 on the working day after the obligation is triggered (T+1); and maintain records of gross positions for 5 years. NSPs must include all short and long positions in shares and financial instruments providing a financial advantage on price movement, including ETFs, indices, baskets, and direct and indirect exposures, calculated on a delta-adjusted basis.
On covering requirements, short sales of shares admitted to UK trading venues must be covered by borrowing, agreement to borrow, or a locate arrangement.
On group reporting, NSPs must be calculated at both group and individual entity level; where the 0.2% threshold is met at group level, a group notification is required; specific dual-notification rules apply when a position transitions between group and entity reporting. Management and non-management positions must be calculated and reported separately under separate Position Holder IDs.
On ANSP publication, the FCA publishes current ANSPs at 12:00 each working day, anonymising individual positions; it may contact position holders to verify positions that appear invalid and may close positions by submitting a 0% notification where no response is received.
FCA publishes an update to reflect the entry into force of the new UK short selling regime (SSR)
![]()
On 13 July 2026, the Financial Conduct Authority updated its short selling overview page to reflect the entry into force of the new UK short selling regime (SSR), set out in the Short Selling Regulations 2025 and the Short Selling Rules Sourcebook within the FCA Handbook, replacing the assimilated EU Short Selling Regulation (Regulation (EU) No 236/2012).
The new UK SSR applies from 13 July 2026, following the FCA's final rules published in PS26/5, which introduced targeted changes to improve efficiency and reduce regulatory burdens. The overview page consolidates the main obligations, exemptions, intervention powers, and aggregate net short position (ANSP) disclosure framework applicable to firms carrying out short selling activity in shares admitted to UK trading venues.
The regime applies to all persons carrying out short selling activity in shares admitted to UK trading venues. The Reportable Shares List (RSL) determines which shares are subject to SSR requirements.
The publication identifies four core elements.
On obligations, firms must: use the RSL to determine whether a share is subject to SSR requirements; calculate net short positions (NSPs) and notify the FCA when relevant thresholds are met via the Electronic Submission System (ESS); and comply with covering requirements.
On exemptions and waivers, the SSR provides exemptions for stabilisation activity and market making (subject to specified conditions), and the FCA may grant waivers in limited circumstances including for serious systems outages.
On FCA intervention powers, the FCA can impose restrictions or prohibitions (including temporary bans) on short selling in exceptional circumstances or following a significant financial instrument price fall, and may require additional information from market participants; the FCA states it sets a high bar for the use of these powers given the benefits of short selling to orderly market functioning.
On ANSP publication, the FCA publishes daily current and historic ANSP reports, anonymising individual positions above the 0.2% threshold.
FCA publishes CP26/30 on supporting equity market transparency and considering market structure developments
![]()
On 31 July 2026, FCA published Consultation Paper CP26/30, Supporting Equity Market Transparency and Considering Market Structure Developments, which proposes targeted changes to the UK equity market transparency framework, addresses the evolution of market structure, including the growth of bilateral trading and the reduced relative share of central limit order book (CLOB) trading and sets out an approach to monitoring future market structure developments.
This CP delivers on a commitment made in CP25/20 (July 2025), specifically Chapter 4 of that paper, which discussed UK equity market structure and transparency and invited initial views on whether reforms were warranted. The FCA notes that overall secondary market trading activity has increased but has become more dispersed, with a smaller proportion of trading conducted on CLOBs operated by exchanges. The FCA's current assessment is that UK equity markets remain liquid, resilient and efficient, but that vigilance is required as structure continues to evolve.
The CP is published alongside CP26/31, which contains final rules on the framework for a UK equity consolidated tape (CT) and next steps for its delivery. The two papers are intended to be read together.
The consultation primarily applies to:
- Trading venues
- Investment firms, including systematic internalisers (SIs)
- UK branches of overseas firms undertaking investment services and activities
- It is also of interest to Approved Publication Arrangements (APAs), law firms, market data and analytics firms, consultancies, retail investors, and trade associations.
The CP sets out proposals across four broad areas:
- Post-trade transparency: Extension of the current exclusion from post-trade transparency for non-price-forming over-the-counter (OTC) transactions to equivalent transactions reported to trading venues; clarification and strengthening of back-reporting rules.
- Reference price waiver (RPW): Reformulation to allow trading venues to integrate midpoint dark orders within transparent limit order books, supporting wider use of the waiver.
- Systematic internaliser (SI) transparency: New requirement for equity SIs to publish quotes showing the price and volume at which they are prepared to buy and sell up to and including standard market size, to simplify the regime and improve pre-trade data quality while preserving SIs' ability to take risk and price-improve in justified cases.
- Market outages guidance: Introduction of guidance to clarify FCA expectations on the protocols trading venues operate during an outage, building on work under CP22/12 and the FCA's advisory committee on secondary markets.
In addition, the CP includes a chapter on the Retail Service Provider (RSP) system and confirms, without rule changes, existing expectations that: SIs should trade on risk; firms must continue to meet best execution obligations; and on-venue trades executed through the RSP system are subject to the tick size regime. The CP also sets out a proposed monitoring framework of quantitative and qualitative indicators (including CLOB share, spreads, depth, volatility, trading volumes, execution quality and qualitative intelligence) for future market structure surveillance, and discusses without proposing potential intervention options including mandating greater CLOB use or reviewing the framework within which bilateral systems operate.
FCA publishes CP26/31 on the framework for a UK equity consolidated tape (CT) (CP25/31) and next steps for delivery
![]()
On 31 July 2026, the Financial Conduct Authority published CP26/31, which sets out the final policy framework for a UK equity consolidated tape (CT) following consultation on CP25/31, consults on the inclusion of systematic internaliser (SI) quotes in the equity CT (Chapter 10), issues a Call for Input on key contractual requirements for the equity consolidated tape provider (CTP) (Chapter 11), and makes final rules establishing the main regulatory obligations of the equity CTP and the data provision obligations of trading venues and APAs.
CP26/31 follows the November 2025 consultation (CP25/31) on the proposed framework for a UK equity CT. The equity CT will bring together pre- and post-trade data from across the market into a single source. It follows the launch of the UK bond CT in June 2026. The made rules (FCA 2026/50 and FCA 2026/51) entered into force on 31 July 2026 and establish the regulatory framework for the equity CTP and the data provision obligations of trading venues and APAs. The consultation and Call for Input remain open until 16 October 2026 and 18 September 2026 respectively.
The final rules apply to: trading venues facilitating the trading of equities (shares, ETFs, depositary receipts, certificates, and similar instruments) in the UK; APAs publishing trade reports for OTC equity trades; and the equity CTP. The consultation proposals on SI quotes (Chapter 10) apply additionally to SIs and firms offering arrangements through which SIs make their quotes public.
The publication establishes six substantive elements.
- On CT design (final), the equity CT will include both post-trade data and the attributed pre-trade best bid and offer (BBO) for the first 5-year contract period; a post-implementation review will commence 2 years after the CT begins operating, including consideration of varying the level of pre-trade data.
- On income sharing (final rule), the equity CTP must share a portion of its income with data contributors (trading venues and APAs); the specific mechanism and percentage will be set in the contract with the CTP, with a further consultation on distribution among contributors planned for autumn 2026.
- On data provision obligations (final rules — MAR 9.2B.34A to 9.2B.34H), trading venues operating CLOBs or periodic auction systems must send pre-trade BBO data and post-trade data to the CTP within 50ms; APAs within 100ms; RFQ and voice trading systems within 1 minute; input and output data fields are specified in MAR 9 Annex 11.
- On CTP operational framework (final rules), SYSC 15A operational resilience standards apply to the equity CTP; governance requirements include a consultative committee; data quality reporting is quarterly; the CTP must publish historical post-trade data; the CTP may publish a historical pre-trade database at its discretion; and the 90-day notice period for price changes is retained.
- On SI quotes in the equity CT (consultation — Chapter 10, closes 16 October 2026), the FCA proposes to require the CTP to publish an attributed SI BBO displayed separately from trading venue pre-trade data; SIs would send quotes via existing Article 15 MiFIR publication arrangements meeting the same 50ms latency requirements as CLOBs; draft rules are published in Appendix 3.
- On contractual requirements (Call for Input — Chapter 11, closes 18 September 2026), the FCA is minded to require profit sharing (a fixed percentage of earnings before tax, in the range of 10–30% EBT) rather than gross revenue sharing; operating hours of at minimum 07:30–18:00; views are sought on longer operating hours and on the mechanism and governance of income sharing.
SUPERVISION
FCA publishes Handbook notice No.143
![]()
On 31 July 2026, FCA published Handbook Notice No. 143, which describes changes to the FCA Handbook made by the FCA Board on 25 June 2026 and 30 July 2026, covering six distinct sets of rule changes: periodic fees 2026/2027; a comprehensive cryptoassets regulatory framework; a technical correction to the definition of capital for investment firms; enforcement updates reflecting the Digital Markets, Competition and Consumers Act 2024 (DMCCA); clarificatory amendments to prospectus rules; and changes establishing the regulatory framework for the equity consolidated tape.
Handbook Notice No. 143 consolidates multiple instrument packages into a single publication, some of which have separate policy statements and some of which are summarised with consultation feedback in this notice. The most significant package is the cryptoassets framework, underpinned by the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 passed by Parliament on 4 February 2026, which brings a broad range of cryptoasset activities within the FCA's regulatory perimeter for the first time.
Scope of Application:
The changes affect a broad range of regulated entities: all FCA-regulated firms (fees); cryptoasset service providers; FCA investment firms subject to MIFIDPRU; insurers and consumer credit firms subject to DMCCA enforcement; issuers seeking admission to trading on regulated markets; and trading venues, APAs, and the future equity consolidated tape provider.
Main Updates:
The notice covers six substantive areas.
- On periodic fees 2026/2027 (FCA 2026/34, effective 2 July 2026), the instrument sets out the 2026/27 regulatory fees and levies for the FCA and the Financial Ombudsman Service, and enables collection of certain levies on behalf of government departments.
- On the cryptoassets framework (FCA 2026/35 to 2026/45, effective 25 October 2027), eleven instruments establish the comprehensive UK cryptoassets regulatory regime, including new sourcebooks (COREPRU, CRYPTOPRU, CRYPTO), new CASS chapters (16 and 17), and extensive amendments to COBS, SYSC, SUP, DISP, MIFIDPRU, and other modules. The regime covers stablecoins, admission of qualifying cryptoassets to trading, market abuse, intermediaries, trading platforms, transparency and records, lending/borrowing/staking, safeguarding, client assets, conduct and firm standards, and prudential requirements. Full scope applies from 25 October 2027, giving firms time to prepare.
- On the definition of capital for investment firms (FCA 2026/46, effective 31 July 2026), a minor technical amendment to MIFIDPRU 3.6A.1R corrects an unintended consequence of PS25/14: the prohibition on non-cash distributions is realigned with Article 73 UK CRR so that instruments contemplating non-cash distributions are not rendered ineligible as own funds, provided payment is only made in specified circumstances. No transitional arrangements are required as firms were advised in CP26/8 to continue treating relevant instruments as eligible from 1 April 2026.
- On DMCCA enforcement updates (FCA 2026/47 and 2026/48, effective 31 July 2026), the Enforcement Guide (ENFG), UNFCOG, ICOBS, CONC, and the Glossary are updated to reflect the FCA's powers under the DMCCA (including court-based consumer protection action, online interface orders, and referral to the CMA); references to the Enterprise Act Part 8 are removed; and clarificatory changes improve the description of the FCA's approach to non-FSMA powers and market abuse enforcement for cryptoassets.
- On prospectus rules clarifications (FCA 2026/49, effective 31 July 2026), seven amendments to PRM are made to correct unintended consequences of PS25/9: the employee/director share scheme exemption (PRM 1.4.12R) is narrowed to exclude fund-raising through third parties while preserving standard share schemes; the final terms publication cross-reference is corrected; PFLS accompanying statements are made more flexible; the cross-reference list requirement is clarified; the 3-day IPO prospectus rule is limited to offers with retail participation; the word "fungible" in PRM 10.1.9R is replaced with "manifestly the same"; and withdrawal rights notification rules are aligned.
- On the equity consolidated tape (FCA 2026/50 and 2026/51, effective 31 July 2026), changes to MAR 9 and Commission Delegated Regulation (EU) 2017/577 establish the main regulatory obligations for the equity CTP and the requirements for trading venues and APAs to provide information to the CTP.
INTERNATIONAL
ANTI-MONEY LAUNDERING / COMBATING TERRORISM FINANCING / COMBATTING PROLIFERATION FINANCING (AML/CFT/CPF)
FATF publishes Targeted Report on Regulatory Challenges from Decentralised Finance
![]()
On 21 July 2026, the Financial Action Task Force (FATF) published the "Targeted Report on Regulatory Challenges from Decentralised Finance", which examines money laundering (ML), terrorist financing (TF) and proliferation financing (PF) risks associated with decentralised finance (DeFi), clarifies the application of FATF Recommendation 15 to DeFi arrangements, and sets out non-binding good practices and recommendations for jurisdictions, financial institutions, virtual asset service providers (VASPs) and DeFi participants.
The report analyses the growth of the DeFi ecosystem and identifies structural vulnerabilities arising from pseudonymity, permissionless access, smart-contract automation, cross-border reach and complex transaction structures. FATF notes that illicit actors, including fraudsters, ransomware groups, professional money laundering networks and proliferation financing actors, increasingly exploit DeFi arrangements to conceal and transfer illicit funds.
A central focus of the report is the determination of whether a DeFi arrangement is subject to FATF standards. FATF reiterates that its standards are technology-neutral and apply where a natural or legal person exercises "control or sufficient influence" over a DeFi arrangement. The report distinguishes between:
(i) centralised DeFi arrangements with identifiable controllers;
(ii) arrangements where control exists but controllers cannot readily be identified;
(iii) truly decentralised arrangements with no identifiable controllers. The first two categories fall within the FATF framework.
The report provides extensive indicators for assessing control, including governance token concentration, administrative privileges, protocol upgrades, treasury control, front-end operation and influence over development. It also outlines supervisory practices, licensing and registration expectations, risk assessment approaches, enforcement tools, blockchain analytics practices and cross-border cooperation mechanisms.
FATF highlights that implementation remains limited globally, with few jurisdictions having assessed DeFi risks or established supervisory frameworks. The report therefore recommends that jurisdictions strengthen risk assessments, identify controllers, apply AML/CFT controls to in-scope DeFi arrangements, engage with industry, enhance supervisory capabilities and support regulated financial institutions and VASPs in managing risks arising from interactions with DeFi ecosystems. The report is expressly non-binding and should be read alongside FATF's broader virtual asset and VASP framework.
CONTACTS
This publication is produced by the Group Regulatory Watch Team with the collaboration of experts from the Legal Department and the Compliance Department of CACEIS entities, together with the close support of the Communications Department.
Editor
Gaëlle Kerboeuf, Group Regulatory Watch Senior Expert
Permanent Editorial Committee
Gaëlle Kerboeuf, Group Regulatory Watch Senior Expert
Corinne Brand, Group Content Manager
Local
François Honnay, Head of Legal (Belgium)
Fanny Thomas, Head of Legal Client Contracts (France)
Aude Levant, Group Compliance
Jeanne Laurent, Head of Unit - Business Compliance
Stefan Ullrich, Head of Legal (Germany)
Costanza Bucci, Head of Legal & Compliance (Italy)
Luciana Vertulli, Compliance Officer (Italy)
Fernand Costinha, Group Head, Legal (Luxembourg)
Julien Fetick, Senior Financial Lawyer (Luxembourg)
Gérald Stadelmann, Head of Legal (Luxcellence Luxembourg)
Alessandra Cremonesi, Head of Legal (Switzerland)
Puck Kranénburg (The Netherlands)
Raymond Boddenberg (The Netherlands)
Robin Donagh, Head of Legal (Ireland)
Olga Kitenge, Legal, Risk & Compliance (UK)
Katherine Petcher, Group Head, Legal (Common Law Countries)
Beatriz Sanchez Jete, Compliance (Spain)
Jessica Silva, Compliance (Brazil)
Luiz Fernando Silva, Compliance (Brazil)
Libia Andrea Carvajal, Compliance (Colombia)
Daiana Garcia, Compliance (Colombia)
Karim Martínez, Compliance (Mexico)
Edgar Zugasti, Compliance (Mexico)
Design
CACEIS Group Communications
Photos credit
CACEIS, Adobe Stock
CACEIS
89-91 rue Gabriel Péri
92120 Montrouge