Regulatory Watch
What's coming, how mature it is,
and what it means for you
Regulatory change rarely arrives all at once. It is proposed, adopted, phased in, and only then fully felt — and its relevance shifts as each date approaches. This is a living view of the instruments that matter most for cross-border financial-crime and digital-asset work, arranged so you can see at a glance how far along each one is, who it touches, and where to go for the detail.
One rule, three readings
Many of these instruments are European in their make-up. But for a firm with clients across the EU, Switzerland and the UK, the same measure can mean three slightly different things — and sometimes the same thing. Each entry notes where that distinction bites, and points to the primary source — the EU institutions, FINMA, or the relevant authority — for the detail.
Swiss AMLA revision + Transparency Register
Revised Anti-Money Laundering Act & Transparency Act (LETA)
Enters into force: 1 Oct 2026
Switzerland's revised AMLA and the new Federal Act on the Transparency of Legal Entities create a central, non-public register of beneficial owners administered by the Federal Office of Justice, and extend due-diligence duties to certain advisory activities.
For the in-house compliance officer
Redesign onboarding and beneficial-ownership verification, build register-reporting workflows, and assess whether advisory work now falls within scope. Transition periods begin on the in-force date; newly incorporated entities must register within one month.
A Swiss measure, but groups with EU/UK arms must reconcile it with EU beneficial-ownership registers and the UK PSC regime — similar intent, different mechanics and access rules.
Source: Federal Council / SIF →EU AMLA — the new supervisor
EU Authority for Anti-Money Laundering (AMLA)
Direct supervision begins: 1 Jan 2028
The EU's new central AML supervisor, operational in Frankfurt since 1 July 2025, with direct supervision beginning in 2028 under Regulation (EU) 2024/1620. Eligibility is gated: AMLA periodically assesses credit and financial institutions and groups only where they operate "in at least six Member States, including the home Member State" — and expressly "regardless of whether the activities are carried out through infrastructure on the territory concerned or remotely", so passporting in without local establishment counts. From those, it selects on risk profile up to 40 groups and entities "at least during the first selection process"; where more than 40 qualify, the tie-break is breadth — those operating in the highest number of Member States. The cohort is reviewed on a three-year cycle. Crypto-asset service providers are named in the supervised population, and AMLA also coordinates supervisors of the non-financial sector, including self-regulatory bodies.
For the in-house compliance officer
Two questions, and they are different. Will AMLA supervise you? Start with the gate, not the risk: fewer than six Member States and you are outside direct supervision altogether, however high your risk profile — and remote, passported activity counts toward the six. Above the gate, selection runs on risk, with breadth as the tie-break where more than 40 qualify. The live timetable: national supervisors collected data to 15 August 2026, a provisional list of eligible entities is expected by end-September 2026, selection follows in 2027. And what happens if you are selected? AMLA may impose pecuniary sanctions capped at 10% of total annual turnover for the most serious breaches (or €10m for others), adjusted by the coefficients in Annex I, with any benefit derived or third-party loss added on top of that cap — plus periodic penalty payments of up to 3% of average daily turnover to compel compliance. Model both now: eligibility is being assessed this quarter, not in 2027.
The design differs sharply from the other two regimes, before any question of how it is used. The FCA fines without a statutory ceiling (FSMA s.206); AMLA fines against a turnover-proportionate cap with a published coefficient methodology; FINMA cannot fine at all and reaches the money by confiscating profit instead, with criminal fines sitting elsewhere entirely. A group operating across all three cannot carry one mental model of "supervisory penalty". Note also that AMLA’s remit reaches self-regulatory bodies — the model Switzerland runs at its core.
Source: AMLA (europa.eu) →AMLA Guidelines — ongoing monitoring
AMLA draft Guidelines on ongoing monitoring of a business relationship
Consultation closes: 3 Sep 2026
Draft Guidelines under Article 26(5) of Regulation (EU) 2024/1624, in three parts: cross-sectoral general principles, keeping customer information up to date, and monitoring transactions and activity to detect the unusual or suspicious. Consultation opened 3 June 2026; the public hearing was held on 2 July 2026.
For the in-house compliance officer
This will set the EU baseline for trigger events, refresh cycles and the calibration of monitoring scenarios. Compare your periodic-review and event-driven refresh policy against the draft and respond where a trigger is unworkable in practice — of the three AMLA consultations open, this one closes first.
EU obliged entities are the addressees. UK firms run the JMLSG expectation and Swiss firms the AMLO-FINMA duty over the same relationships — the substance converges, the evidence each supervisor expects to see does not.
Source: AMLA — consultation page →AMLA ITS — the EU-wide SAR template
AMLA draft implementing technical standards on the format for reporting suspicions and providing transaction records
Consultation closes: 20 Sep 2026
Draft ITS under Article 69(3) of Regulation (EU) 2024/1624 setting a single EU-wide template for reporting suspicions, differentiated by category of obliged entity, together with a standard format for credit and financial institutions to provide transaction records to FIUs. Consultation opened 2 July 2026; public hearing 9 September 2026.
For the in-house compliance officer
Model the field-level requirements against your current SAR workflow now. The templates are drafted so a firm can automate submission from its own case-management system rather than rekeying into an FIU portal — but only where the data already sits in the right fields. Retrofitting reporting data after the standards are final is materially harder than shaping it now.
Bites on EU obliged entities when the AML Regulation applies from 10 July 2027. A group with UK and Swiss arms will hold one suspicion and file it three ways — this format, the NCA's SAR regime, and MROS reporting.
Source: AMLA — consultation page →AMLA RTS — risk scoring outside the financial sector
AMLA draft regulatory technical standards on the inherent and residual risk profile of obliged entities in the non-financial sector
Consultation closes: 27 Sep 2026
Draft RTS under Article 40(2) of Directive (EU) 2024/1640 setting the harmonised methodology supervisors will use to assess and classify the ML/TF risk profile of non-financial obliged entities, with the data points those entities must report to feed the assessment. Consultation opened 13 July 2026; public hearing 10 September 2026.
For the in-house compliance officer
Lawyers, accountants, trust and company service providers, estate agents and high-value dealers are the direct addressees: the resulting score will drive supervisory intensity and inspection frequency. Read the data-point annexes first — they decide what you will be reporting every year — and answer the proportionality questions if the burden does not scale to your size.
The EU is standardising risk scoring for precisely the professions the UK is moving under FCA supervision and Switzerland supervises through SRO affiliation. Same population, three supervisory designs, diverging further.
Source: AMLA — consultation page →EU AMLR — the single rulebook
EU Anti-Money Laundering Regulation (single rulebook)
Most provisions apply: 10 Jul 2027
A directly-applicable single rulebook harmonising customer due diligence, beneficial ownership and reporting across member states, replacing much of the patchwork left by successive directives.
For the in-house compliance officer
Plan for a single, directly-applicable standard from July 2027 — uniform CDD methods, verification and ongoing monitoring set out in binding technical standards, reducing (but not removing) national variation.
EU-wide by design; CH/UK firms serving EU clients will need to meet it for that book of business even where home rules differ.
Source: EUR-Lex — Regulation (EU) 2024/1624 →MiCA — crypto-asset framework
Markets in Crypto-Assets Regulation (MiCA)
Transition window closed: 1 Jul 2026
The EU's comprehensive regime for crypto-asset service providers and token issuers. The last national transitional regimes closed on 1 July 2026: a provider without MiCA authorisation may no longer serve EU clients, and reverse solicitation is the only — narrow, closely-scrutinised — residual route.
For the in-house compliance officer
The cliff has passed. Verify your own and your counterparties' authorisation against the ESMA register; wind down any EU book still running on a lapsed national regime; document why any remaining EU-client contact is genuine reverse solicitation. Expect early enforcement to target exactly these two gaps.
An EU passport regime: CH-based providers reach EU clients only via an EU-authorised entity; UK firms face a separate domestic perimeter.
Source: ESMA →DORA — operational resilience
Digital Operational Resilience Act (DORA)
Applies: 17 Jan 2025
EU framework for ICT risk management, incident reporting and oversight of critical third-party providers across the financial sector — applicable since January 2025.
For the in-house compliance officer
Treat as live: ICT risk registers, incident-reporting pathways and third-party (including cloud) oversight must be operational. Relevant to any platform handling regulated data, including evidence and case material.
EU-anchored, but its third-party oversight reaches CH/UK vendors serving EU financial entities.
Source: EU / ESAs →EU AI Act — high-risk regime
EU AI Act — high-risk obligations
High-risk baseline date (deferral pending): 2 Aug 2026
Obligations for high-risk AI systems — capturing AI used in credit scoring, KYC and agentic tools in finance. The 2 August 2026 baseline date has now passed, but the EU 'Digital Omnibus' may defer stand-alone Annex III obligations to December 2027 — which date governs depends on its outcome.
For the in-house compliance officer
Inventory AI used in compliance and onboarding and have conformity-assessment and transparency workstreams running: the 2 August 2026 baseline has passed, and whether deferral to December 2027 applies turns on the Digital Omnibus. Verify its current status before relying on either date, and reconcile with GDPR/FADP throughout.
EU product-safety logic: CH/UK developers placing AI on the EU market are caught; purely domestic use may not be.
Source: EU AI Act timeline →FINMA Guidance 01/2026 — crypto custody
FINMA Guidance 01/2026 — custody of crypto-based assets
Published: 12 Jan 2026
FINMA's guidance resetting supervisory expectations on the custody of crypto-based assets — segregation, bankruptcy remoteness and client-asset protection.
For the in-house compliance officer
Custodians should translate the guidance into concrete segregation policies, custody agreements and bankruptcy-remoteness analysis, and be ready to defend them to the regulator and banking counterparties.
Swiss-specific, but informs how CH custodians service EU/UK institutional clients with their own custody expectations.
Source: FINMA — Guidance 01/2026 →UK crypto regime — FSMA authorisation
UK cryptoasset regime — full FSMA authorisation
Crypto activities fully within FSMA: 25 Oct 2027
The FCA's final cryptoasset regime (published 30 June 2026) brings crypto activities fully within FSMA. AML-only registration ends: every UK-facing crypto firm needs full authorisation. A joint FCA–Bank of England approach covers systemic stablecoin issuers.
For the in-house compliance officer
The application window opens 30 September 2026. Current MLR-only registrants must prepare a full authorisation application — governance, prudential and conduct standards, not just AML controls.
A separate perimeter from MiCA: authorisation in one bloc gives no rights in the other. Firms serving both markets run two applications and two rulebooks.
Source: FCA →UK MLRs — 2026 amendment (SI 2026/621)
Money Laundering and Terrorist Financing (Amendment) Regulations 2026
In force: 30 Jun 2026
Recasts the UK MLRs: enhanced due diligence narrowed from all 'complex' to 'unusually complex' transactions, automatic EDD confined to FATF Call-for-Action countries, euro thresholds converted to sterling, and trust registration extended to certain non-UK trusts holding UK land.
For the in-house compliance officer
Re-paper risk assessments and CDD policies against the new EDD triggers and thresholds; trustees of non-UK trusts holding UK land acquired before October 2020 face new registration duties.
Loosens the UK's EDD triggers just as the EU's AMLR tightens toward a single rulebook — cross-border groups now manage a wider EU/UK delta, and Swiss firms serving both face three sets of triggers.
Source: legislation.gov.uk — SI 2026/621 →ECCTA — failure to prevent fraud
ECCTA — failure to prevent fraud offence
Offence in force: 1 Sep 2025
The Economic Crime and Corporate Transparency Act 2023's corporate offence: a large organisation is criminally liable where an associated person commits fraud for its benefit and it lacked reasonable fraud-prevention procedures. No knowledge by management is required.
For the in-house compliance officer
Large organisations (two of: 250+ employees, £36m+ turnover, £18m+ assets) need documented fraud-prevention procedures mapped to the government guidance — risk assessment, proportionate controls, training, monitoring. The reasonable-procedures defence is only as good as its paper trail.
Reaches non-UK organisations where the fraud has a UK nexus; EU and Swiss groups with UK business should treat it as in scope.
Source: GOV.UK guidance →UK SPSS reform — FCA takes over AML supervision
UK AML supervision reform — FCA as single professional-services supervisor
Transfer timing pending legislation: To be confirmed
HM Treasury decided (21 October 2025) that the FCA will become the single AML/CTF supervisor for legal and accountancy firms and trust and company service providers, replacing the professional-body supervisors. OPBAS will be wound up. The transfer takes several years and needs enabling legislation.
For the in-house compliance officer
Law and accountancy firms and TCSPs should expect FCA-style supervision: data returns, systems expectations, and a different fee and enforcement culture than their professional body. Watch the transition consultations; nothing changes until the legislation lands.
Moves the UK toward a concentrated supervision model as the EU centralises under AMLA — while Switzerland keeps SRO delegation. Three models, drifting further apart.
Source: HM Treasury consultation response →Berne Agreement — UK–Swiss mutual recognition
Berne Financial Services Agreement (UK–Switzerland)
In force: 1 Jan 2026
A UK–Swiss treaty recognising each other's regulation as delivering equivalent outcomes across five wholesale sectors, including banking and investment services. Firms serve the other market under their home rules and home supervisor — regulator deference by treaty.
For the in-house compliance officer
Check eligibility first: the corridor covers wholesale and sophisticated clients only, sector by sector. Map which services ride on the Agreement, follow the notification routes, and hold a contingency plan — the treaty has its own suspension and termination machinery.
The direct London–Zurich rail. FINMA and the FCA/Bank of England operate it through cooperation arrangements; it is treaty-based and mutual, unlike unilateral EU equivalence decisions.
Source: GOV.UK — treaty text →Looking for the long-form analysis? The worked pieces live with the dossiers, alongside the reports available on request.
Working on a cross-border matter where one of these applies?
Start a conversation