Skip to content

Regulatory Watch

What's coming, how mature it is,
and what it means for you

Regulatory change rarely arrives all at once. It is proposed, adopted, phased in, and only then fully felt — and its relevance shifts as each date approaches. This is a living view of the instruments that matter most for cross-border financial-crime and digital-asset work, arranged so you can see at a glance how far along each one is, who it touches, and where to go for the detail.

One rule, three readings

Many of these instruments are European in their make-up. But for a firm with clients across the EU, Switzerland and the UK, the same measure can mean three slightly different things — and sometimes the same thing. Each entry notes where that distinction bites, and points to the primary source — the EU institutions, FINMA, or the relevant authority — for the detail.

Maturity:ProposedAdoptedTransitionalIn forceFully applicable
CH
Major

Swiss AMLA revision + Transparency Register

Revised Anti-Money Laundering Act & Transparency Act (LETA)

Adopted

Enters into force: 1 Oct 2026

Switzerland's revised AMLA and the new Federal Act on the Transparency of Legal Entities create a central, non-public register of beneficial owners administered by the Federal Office of Justice, and extend due-diligence duties to certain advisory activities.

For the in-house compliance officer

Redesign onboarding and beneficial-ownership verification, build register-reporting workflows, and assess whether advisory work now falls within scope. Transition periods begin on the in-force date; newly incorporated entities must register within one month.

A Swiss measure, but groups with EU/UK arms must reconcile it with EU beneficial-ownership registers and the UK PSC regime — similar intent, different mechanics and access rules.

Source: Federal Council / SIF
EU
Major

EU AMLA — the new supervisor

EU Authority for Anti-Money Laundering (AMLA)

In force

Direct supervision begins: 1 Jan 2028

The EU's new central AML supervisor, operational in Frankfurt since 1 July 2025, with direct supervision beginning in 2028 under Regulation (EU) 2024/1620. Eligibility is gated: AMLA periodically assesses credit and financial institutions and groups only where they operate "in at least six Member States, including the home Member State" — and expressly "regardless of whether the activities are carried out through infrastructure on the territory concerned or remotely", so passporting in without local establishment counts. From those, it selects on risk profile up to 40 groups and entities "at least during the first selection process"; where more than 40 qualify, the tie-break is breadth — those operating in the highest number of Member States. The cohort is reviewed on a three-year cycle. Crypto-asset service providers are named in the supervised population, and AMLA also coordinates supervisors of the non-financial sector, including self-regulatory bodies.

For the in-house compliance officer

Two questions, and they are different. Will AMLA supervise you? Start with the gate, not the risk: fewer than six Member States and you are outside direct supervision altogether, however high your risk profile — and remote, passported activity counts toward the six. Above the gate, selection runs on risk, with breadth as the tie-break where more than 40 qualify. The live timetable: national supervisors collected data to 15 August 2026, a provisional list of eligible entities is expected by end-September 2026, selection follows in 2027. And what happens if you are selected? AMLA may impose pecuniary sanctions capped at 10% of total annual turnover for the most serious breaches (or €10m for others), adjusted by the coefficients in Annex I, with any benefit derived or third-party loss added on top of that cap — plus periodic penalty payments of up to 3% of average daily turnover to compel compliance. Model both now: eligibility is being assessed this quarter, not in 2027.

The design differs sharply from the other two regimes, before any question of how it is used. The FCA fines without a statutory ceiling (FSMA s.206); AMLA fines against a turnover-proportionate cap with a published coefficient methodology; FINMA cannot fine at all and reaches the money by confiscating profit instead, with criminal fines sitting elsewhere entirely. A group operating across all three cannot carry one mental model of "supervisory penalty". Note also that AMLA’s remit reaches self-regulatory bodies — the model Switzerland runs at its core.

Source: AMLA (europa.eu)
EU
Moderate

AMLA Guidelines — ongoing monitoring

AMLA draft Guidelines on ongoing monitoring of a business relationship

Proposed

Consultation closes: 3 Sep 2026

Draft Guidelines under Article 26(5) of Regulation (EU) 2024/1624, in three parts: cross-sectoral general principles, keeping customer information up to date, and monitoring transactions and activity to detect the unusual or suspicious. Consultation opened 3 June 2026; the public hearing was held on 2 July 2026.

For the in-house compliance officer

This will set the EU baseline for trigger events, refresh cycles and the calibration of monitoring scenarios. Compare your periodic-review and event-driven refresh policy against the draft and respond where a trigger is unworkable in practice — of the three AMLA consultations open, this one closes first.

EU obliged entities are the addressees. UK firms run the JMLSG expectation and Swiss firms the AMLO-FINMA duty over the same relationships — the substance converges, the evidence each supervisor expects to see does not.

Source: AMLA — consultation page
EU
Major

AMLA ITS — the EU-wide SAR template

AMLA draft implementing technical standards on the format for reporting suspicions and providing transaction records

Proposed

Consultation closes: 20 Sep 2026

Draft ITS under Article 69(3) of Regulation (EU) 2024/1624 setting a single EU-wide template for reporting suspicions, differentiated by category of obliged entity, together with a standard format for credit and financial institutions to provide transaction records to FIUs. Consultation opened 2 July 2026; public hearing 9 September 2026.

For the in-house compliance officer

Model the field-level requirements against your current SAR workflow now. The templates are drafted so a firm can automate submission from its own case-management system rather than rekeying into an FIU portal — but only where the data already sits in the right fields. Retrofitting reporting data after the standards are final is materially harder than shaping it now.

Bites on EU obliged entities when the AML Regulation applies from 10 July 2027. A group with UK and Swiss arms will hold one suspicion and file it three ways — this format, the NCA's SAR regime, and MROS reporting.

Source: AMLA — consultation page
EU
Major

AMLA RTS — risk scoring outside the financial sector

AMLA draft regulatory technical standards on the inherent and residual risk profile of obliged entities in the non-financial sector

Proposed

Consultation closes: 27 Sep 2026

Draft RTS under Article 40(2) of Directive (EU) 2024/1640 setting the harmonised methodology supervisors will use to assess and classify the ML/TF risk profile of non-financial obliged entities, with the data points those entities must report to feed the assessment. Consultation opened 13 July 2026; public hearing 10 September 2026.

For the in-house compliance officer

Lawyers, accountants, trust and company service providers, estate agents and high-value dealers are the direct addressees: the resulting score will drive supervisory intensity and inspection frequency. Read the data-point annexes first — they decide what you will be reporting every year — and answer the proportionality questions if the burden does not scale to your size.

The EU is standardising risk scoring for precisely the professions the UK is moving under FCA supervision and Switzerland supervises through SRO affiliation. Same population, three supervisory designs, diverging further.

Source: AMLA — consultation page
EU
Major

EU AMLR — the single rulebook

EU Anti-Money Laundering Regulation (single rulebook)

Adopted

Most provisions apply: 10 Jul 2027

A directly-applicable single rulebook harmonising customer due diligence, beneficial ownership and reporting across member states, replacing much of the patchwork left by successive directives.

For the in-house compliance officer

Plan for a single, directly-applicable standard from July 2027 — uniform CDD methods, verification and ongoing monitoring set out in binding technical standards, reducing (but not removing) national variation.

EU-wide by design; CH/UK firms serving EU clients will need to meet it for that book of business even where home rules differ.

Source: EUR-Lex — Regulation (EU) 2024/1624
EU
Major

MiCA — crypto-asset framework

Markets in Crypto-Assets Regulation (MiCA)

Fully applicable

Transition window closed: 1 Jul 2026

The EU's comprehensive regime for crypto-asset service providers and token issuers. The last national transitional regimes closed on 1 July 2026: a provider without MiCA authorisation may no longer serve EU clients, and reverse solicitation is the only — narrow, closely-scrutinised — residual route.

For the in-house compliance officer

The cliff has passed. Verify your own and your counterparties' authorisation against the ESMA register; wind down any EU book still running on a lapsed national regime; document why any remaining EU-client contact is genuine reverse solicitation. Expect early enforcement to target exactly these two gaps.

An EU passport regime: CH-based providers reach EU clients only via an EU-authorised entity; UK firms face a separate domestic perimeter.

Source: ESMA
EU
Moderate

DORA — operational resilience

Digital Operational Resilience Act (DORA)

Fully applicable

Applies: 17 Jan 2025

EU framework for ICT risk management, incident reporting and oversight of critical third-party providers across the financial sector — applicable since January 2025.

For the in-house compliance officer

Treat as live: ICT risk registers, incident-reporting pathways and third-party (including cloud) oversight must be operational. Relevant to any platform handling regulated data, including evidence and case material.

EU-anchored, but its third-party oversight reaches CH/UK vendors serving EU financial entities.

Source: EU / ESAs
EU
Moderate

EU AI Act — high-risk regime

EU AI Act — high-risk obligations

Transitional

High-risk baseline date (deferral pending): 2 Aug 2026

Obligations for high-risk AI systems — capturing AI used in credit scoring, KYC and agentic tools in finance. The 2 August 2026 baseline date has now passed, but the EU 'Digital Omnibus' may defer stand-alone Annex III obligations to December 2027 — which date governs depends on its outcome.

For the in-house compliance officer

Inventory AI used in compliance and onboarding and have conformity-assessment and transparency workstreams running: the 2 August 2026 baseline has passed, and whether deferral to December 2027 applies turns on the Digital Omnibus. Verify its current status before relying on either date, and reconcile with GDPR/FADP throughout.

EU product-safety logic: CH/UK developers placing AI on the EU market are caught; purely domestic use may not be.

Source: EU AI Act timeline
CH
Moderate

FINMA Guidance 01/2026 — crypto custody

FINMA Guidance 01/2026 — custody of crypto-based assets

In force

Published: 12 Jan 2026

FINMA's guidance resetting supervisory expectations on the custody of crypto-based assets — segregation, bankruptcy remoteness and client-asset protection.

For the in-house compliance officer

Custodians should translate the guidance into concrete segregation policies, custody agreements and bankruptcy-remoteness analysis, and be ready to defend them to the regulator and banking counterparties.

Swiss-specific, but informs how CH custodians service EU/UK institutional clients with their own custody expectations.

Source: FINMA — Guidance 01/2026
UK
Major

UK crypto regime — FSMA authorisation

UK cryptoasset regime — full FSMA authorisation

Adopted

Crypto activities fully within FSMA: 25 Oct 2027

The FCA's final cryptoasset regime (published 30 June 2026) brings crypto activities fully within FSMA. AML-only registration ends: every UK-facing crypto firm needs full authorisation. A joint FCA–Bank of England approach covers systemic stablecoin issuers.

For the in-house compliance officer

The application window opens 30 September 2026. Current MLR-only registrants must prepare a full authorisation application — governance, prudential and conduct standards, not just AML controls.

A separate perimeter from MiCA: authorisation in one bloc gives no rights in the other. Firms serving both markets run two applications and two rulebooks.

Source: FCA
UK
Moderate

UK MLRs — 2026 amendment (SI 2026/621)

Money Laundering and Terrorist Financing (Amendment) Regulations 2026

In force

In force: 30 Jun 2026

Recasts the UK MLRs: enhanced due diligence narrowed from all 'complex' to 'unusually complex' transactions, automatic EDD confined to FATF Call-for-Action countries, euro thresholds converted to sterling, and trust registration extended to certain non-UK trusts holding UK land.

For the in-house compliance officer

Re-paper risk assessments and CDD policies against the new EDD triggers and thresholds; trustees of non-UK trusts holding UK land acquired before October 2020 face new registration duties.

Loosens the UK's EDD triggers just as the EU's AMLR tightens toward a single rulebook — cross-border groups now manage a wider EU/UK delta, and Swiss firms serving both face three sets of triggers.

Source: legislation.gov.uk — SI 2026/621
UK
Major

ECCTA — failure to prevent fraud

ECCTA — failure to prevent fraud offence

In force

Offence in force: 1 Sep 2025

The Economic Crime and Corporate Transparency Act 2023's corporate offence: a large organisation is criminally liable where an associated person commits fraud for its benefit and it lacked reasonable fraud-prevention procedures. No knowledge by management is required.

For the in-house compliance officer

Large organisations (two of: 250+ employees, £36m+ turnover, £18m+ assets) need documented fraud-prevention procedures mapped to the government guidance — risk assessment, proportionate controls, training, monitoring. The reasonable-procedures defence is only as good as its paper trail.

Reaches non-UK organisations where the fraud has a UK nexus; EU and Swiss groups with UK business should treat it as in scope.

Source: GOV.UK guidance
UK
Major

UK SPSS reform — FCA takes over AML supervision

UK AML supervision reform — FCA as single professional-services supervisor

Proposed

Transfer timing pending legislation: To be confirmed

HM Treasury decided (21 October 2025) that the FCA will become the single AML/CTF supervisor for legal and accountancy firms and trust and company service providers, replacing the professional-body supervisors. OPBAS will be wound up. The transfer takes several years and needs enabling legislation.

For the in-house compliance officer

Law and accountancy firms and TCSPs should expect FCA-style supervision: data returns, systems expectations, and a different fee and enforcement culture than their professional body. Watch the transition consultations; nothing changes until the legislation lands.

Moves the UK toward a concentrated supervision model as the EU centralises under AMLA — while Switzerland keeps SRO delegation. Three models, drifting further apart.

Source: HM Treasury consultation response
UKCH
Major

Berne Agreement — UK–Swiss mutual recognition

Berne Financial Services Agreement (UK–Switzerland)

In force

In force: 1 Jan 2026

A UK–Swiss treaty recognising each other's regulation as delivering equivalent outcomes across five wholesale sectors, including banking and investment services. Firms serve the other market under their home rules and home supervisor — regulator deference by treaty.

For the in-house compliance officer

Check eligibility first: the corridor covers wholesale and sophisticated clients only, sector by sector. Map which services ride on the Agreement, follow the notification routes, and hold a contingency plan — the treaty has its own suspension and termination machinery.

The direct London–Zurich rail. FINMA and the FCA/Bank of England operate it through cooperation arrangements; it is treaty-based and mutual, unlike unilateral EU equivalence decisions.

Source: GOV.UK — treaty text

Looking for the long-form analysis? The worked pieces live with the dossiers, alongside the reports available on request.

Working on a cross-border matter where one of these applies?

Start a conversation