Regulatory Watch
What's coming, how mature it is,
and what it means for you
Regulatory change rarely arrives all at once. It is proposed, adopted, phased in, and only then fully felt — and its relevance shifts as each date approaches. This is a living view of the instruments that matter most for cross-border financial-crime and digital-asset work, arranged so you can see at a glance how far along each one is, who it touches, and where to go for the detail.
One rule, three readings
Many of these instruments are European in their make-up. But for a firm with clients across the EU, Switzerland and the UK, the same measure can mean three slightly different things — and sometimes the same thing. Each entry notes where that distinction bites, and points to the primary source — the EU institutions, FINMA, or the relevant authority — for the detail.
Swiss AMLA revision + Transparency Register
Revised Anti-Money Laundering Act & Transparency Act (LETA)
Enters into force: 1 Oct 2026
Switzerland's revised AMLA and the new Federal Act on the Transparency of Legal Entities create a central, non-public register of beneficial owners administered by the Federal Office of Justice, and extend due-diligence duties to certain advisory activities.
For the in-house compliance officer
Redesign onboarding and beneficial-ownership verification, build register-reporting workflows, and assess whether advisory work now falls within scope. Transition periods begin on the in-force date; newly incorporated entities must register within one month.
A Swiss measure, but groups with EU/UK arms must reconcile it with EU beneficial-ownership registers and the UK PSC regime — similar intent, different mechanics and access rules.
Source: Federal Council / SIF →EU AMLA — the new supervisor
EU Authority for Anti-Money Laundering (AMLA)
Direct supervision begins: 1 Jan 2028
The EU's new central AML supervisor, operational in Frankfurt since 1 July 2025. It will directly supervise around 40 selected high-risk obliged entities and coordinate national supervisors across the Union.
For the in-house compliance officer
Even before direct supervision in 2028, expect convergence: harmonised expectations, the selection process from mid-2027, and binding technical standards. Firms with EU exposure should map whether they could fall within the directly-supervised cohort.
Directly relevant to EU-established entities; for CH and UK firms it sets the supervisory tone counterparties and EU subsidiaries will be held to.
Source: AMLA (europa.eu) →EU AMLR — the single rulebook
EU Anti-Money Laundering Regulation (single rulebook)
Most provisions apply: 10 Jul 2027
A directly-applicable single rulebook harmonising customer due diligence, beneficial ownership and reporting across member states, replacing much of the patchwork left by successive directives.
For the in-house compliance officer
Plan for a single, directly-applicable standard from July 2027 — uniform CDD methods, verification and ongoing monitoring set out in binding technical standards, reducing (but not removing) national variation.
EU-wide by design; CH/UK firms serving EU clients will need to meet it for that book of business even where home rules differ.
Source: EUR-Lex — Regulation (EU) 2024/1624 →MiCA — crypto-asset framework
Markets in Crypto-Assets Regulation (MiCA)
Transition window closed: 1 Jul 2026
The EU's comprehensive regime for crypto-asset service providers and token issuers. The last national transitional regimes closed on 1 July 2026: a provider without MiCA authorisation may no longer serve EU clients, and reverse solicitation is the only — narrow, closely-scrutinised — residual route.
For the in-house compliance officer
The cliff has passed. Verify your own and your counterparties' authorisation against the ESMA register; wind down any EU book still running on a lapsed national regime; document why any remaining EU-client contact is genuine reverse solicitation. Expect early enforcement to target exactly these two gaps.
An EU passport regime: CH-based providers reach EU clients only via an EU-authorised entity; UK firms face a separate domestic perimeter.
Source: ESMA →DORA — operational resilience
Digital Operational Resilience Act (DORA)
Applies: 17 Jan 2025
EU framework for ICT risk management, incident reporting and oversight of critical third-party providers across the financial sector — applicable since January 2025.
For the in-house compliance officer
Treat as live: ICT risk registers, incident-reporting pathways and third-party (including cloud) oversight must be operational. Relevant to any platform handling regulated data, including evidence and case material.
EU-anchored, but its third-party oversight reaches CH/UK vendors serving EU financial entities.
Source: EU / ESAs →EU AI Act — high-risk regime
EU AI Act — high-risk obligations
High-risk rules apply (provisional): 2 Aug 2026
Obligations for high-risk AI systems — capturing AI used in credit scoring, KYC and agentic tools in finance. The 2 August 2026 date is subject to the EU 'Digital Omnibus', which may defer stand-alone Annex III obligations to December 2027.
For the in-house compliance officer
Inventory AI used in compliance and onboarding, plan conformity-assessment and transparency steps to the 2 August 2026 baseline, and reconcile with GDPR/FADP — but verify the Digital Omnibus status before relying on the date.
EU product-safety logic: CH/UK developers placing AI on the EU market are caught; purely domestic use may not be.
Source: EU AI Act timeline →FINMA Guidance 01/2026 — crypto custody
FINMA Guidance 01/2026 — custody of crypto-based assets
Published: 12 Jan 2026
FINMA's guidance resetting supervisory expectations on the custody of crypto-based assets — segregation, bankruptcy remoteness and client-asset protection.
For the in-house compliance officer
Custodians should translate the guidance into concrete segregation policies, custody agreements and bankruptcy-remoteness analysis, and be ready to defend them to the regulator and banking counterparties.
Swiss-specific, but informs how CH custodians service EU/UK institutional clients with their own custody expectations.
Source: FINMA — Guidance 01/2026 →UK crypto regime — FSMA authorisation
UK cryptoasset regime — full FSMA authorisation
Crypto activities fully within FSMA: 25 Oct 2027
The FCA's final cryptoasset regime (published 30 June 2026) brings crypto activities fully within FSMA. AML-only registration ends: every UK-facing crypto firm needs full authorisation. A joint FCA–Bank of England approach covers systemic stablecoin issuers.
For the in-house compliance officer
The application window opens 30 September 2026. Current MLR-only registrants must prepare a full authorisation application — governance, prudential and conduct standards, not just AML controls.
A separate perimeter from MiCA: authorisation in one bloc gives no rights in the other. Firms serving both markets run two applications and two rulebooks.
Source: FCA →UK MLRs — 2026 amendment (SI 2026/621)
Money Laundering and Terrorist Financing (Amendment) Regulations 2026
In force: 30 Jun 2026
Recasts the UK MLRs: enhanced due diligence narrowed from all 'complex' to 'unusually complex' transactions, automatic EDD confined to FATF Call-for-Action countries, euro thresholds converted to sterling, and trust registration extended to certain non-UK trusts holding UK land.
For the in-house compliance officer
Re-paper risk assessments and CDD policies against the new EDD triggers and thresholds; trustees of non-UK trusts holding UK land acquired before October 2020 face new registration duties.
Loosens the UK's EDD triggers just as the EU's AMLR tightens toward a single rulebook — cross-border groups now manage a wider EU/UK delta, and Swiss firms serving both face three sets of triggers.
Source: legislation.gov.uk — SI 2026/621 →ECCTA — failure to prevent fraud
ECCTA — failure to prevent fraud offence
Offence in force: 1 Sep 2025
The Economic Crime and Corporate Transparency Act 2023's corporate offence: a large organisation is criminally liable where an associated person commits fraud for its benefit and it lacked reasonable fraud-prevention procedures. No knowledge by management is required.
For the in-house compliance officer
Large organisations (two of: 250+ employees, £36m+ turnover, £18m+ assets) need documented fraud-prevention procedures mapped to the government guidance — risk assessment, proportionate controls, training, monitoring. The reasonable-procedures defence is only as good as its paper trail.
Reaches non-UK organisations where the fraud has a UK nexus; EU and Swiss groups with UK business should treat it as in scope.
Source: GOV.UK guidance →UK SPSS reform — FCA takes over AML supervision
UK AML supervision reform — FCA as single professional-services supervisor
Transfer timing pending legislation: TBC
HM Treasury decided (21 October 2025) that the FCA will become the single AML/CTF supervisor for legal and accountancy firms and trust and company service providers, replacing the professional-body supervisors. OPBAS will be wound up. The transfer takes several years and needs enabling legislation.
For the in-house compliance officer
Law and accountancy firms and TCSPs should expect FCA-style supervision: data returns, systems expectations, and a different fee and enforcement culture than their professional body. Watch the transition consultations; nothing changes until the legislation lands.
Moves the UK toward a concentrated supervision model as the EU centralises under AMLA — while Switzerland keeps SRO delegation. Three models, drifting further apart.
Source: HM Treasury consultation response →Berne Agreement — UK–Swiss mutual recognition
Berne Financial Services Agreement (UK–Switzerland)
In force: 1 Jan 2026
A UK–Swiss treaty recognising each other's regulation as delivering equivalent outcomes across five wholesale sectors, including banking and investment services. Firms serve the other market under their home rules and home supervisor — regulator deference by treaty.
For the in-house compliance officer
Check eligibility first: the corridor covers wholesale and sophisticated clients only, sector by sector. Map which services ride on the Agreement, follow the notification routes, and hold a contingency plan — the treaty has its own suspension and termination machinery.
The direct London–Zurich rail. FINMA and the FCA/Bank of England operate it through cooperation arrangements; it is treaty-based and mutual, unlike unilateral EU equivalence decisions.
Source: GOV.UK — treaty text →Deep Analysis
Reports & long-form analysis
Where the watch above tracks what is changing, these pieces work through what it means — longer analysis on the questions that do not fit on a card.
Switzerland's Financial Supervisor Under Scrutiny: FINMA's Powers and the Credit Suisse Reckoning
An examination of FINMA's enforcement toolkit and the supervisory questions exposed by the Credit Suisse failure.
FATF and FINMA on Crypto SRO Supervision: A Fundamental Regulatory Tension
How the self-regulatory model for crypto sits against FATF expectations, and where the tension is likely to be resolved.
EBA Supervisory Findings on Crypto-Asset Service Providers and AML/CTF Implementation
A reading of the EBA's findings on CASP supervision and what they signal for AML/CTF implementation under the incoming EU framework.
Data Privacy in Finance: Risks and Opportunities for Virtual Asset Service Providers
Where data-protection obligations and AML duties collide for virtual-asset service providers — and how to hold both.
Working on a cross-border matter where one of these applies?
Start a conversation