Global Regulator & Central Bank News Roundup
Edition 222026Week of June 1
Global developments
The Basel Committee on Banking Supervision published a range of practices report on information and communication technology risk management, focusing on non-malicious ICT incidents that disrupt banks’ critical operations and services. The report identifies weak change controls, design and testing gaps, capacity failures, and external provider issues as key drivers, and stresses that resilience depends on disciplined technology controls before incidents occur. It also finds that supervisory frameworks are broadly mature but uneven, with differences in incident reporting definitions, thresholds, and timelines limiting comparability across jurisdictions.
The Basel Committee on Banking Supervision published a range of practices report on information and communication technology risk management, focusing on non-malicious ICT incidents that disrupt banks’ critical operations and services. The report complements the Committee’s earlier work on cyber resilience by shifting the focus from malicious cyber incidents to operational failures. It draws on input from 16 jurisdictions, selected case studies and industry engagement. The report frames non-malicious ICT incidents as an operational resilience issue: banks’ ability to keep critical services running depends on how well they control system changes, test new designs, manage capacity and understand third-party dependencies. Its core message is that resilience is not delivered by incident response alone, but by disciplined control over the technology environment before failures occur. The report points to change control as the central pressure point. Across surveyed jurisdictions, the most frequently reported root causes of non-malicious ICT incidents were weak change controls, gaps in system design, development and testing, capacity and performance failures, and operational failures at external providers. Case examples show how these weaknesses can move quickly from technical defects to public service disruption, including failed migrations, prolonged outages and third-party infrastructure failures affecting multiple banks. The report also highlights a practical constraint for both firms and supervisors: banks may have formal frameworks in place, but resilience is harder to evidence where asset inventories, service-to-system mapping, third-party supply-chain visibility and production-like testing remain incomplete. For supervisors, the report shows a broadly mature but uneven landscape. All surveyed jurisdictions have ICT risk management rules or guidance, and most use risk-based supervision through examinations, thematic reviews, off-site assessments and incident reporting. However, differences in reporting definitions, thresholds and timelines limit comparability across jurisdictions.
At its latest meeting on 1 June, the Financial Stability Board Plenary identified heightened risks to global financial stability, including the potential for concurrent shocks to trigger multiple vulnerabilities. Members highlighted risks linked to elevated sovereign debt, leveraged trading in government bond markets, rapid private credit growth, operational outages, Middle East-related commodity pressures, and frontier AI-driven cyber risks. The Financial Stability Board also plans to consult on sound practices for responsible AI adoption by financial institutions.
At its latest meeting on 1 June, the Financial Stability Board Plenary identified heightened risks to global financial stability, including the possibility that concurrent shocks could trigger multiple vulnerabilities. Members pointed to high asset valuations, compressed risk premiums, elevated sovereign debt, shorter debt maturities, leveraged trading in government bond markets, rapid growth in private credit, operational outages at critical financial system nodes, and pressures on emerging market economies. The Plenary highlighted two developments that have further complicated the risk landscape: the conflict in the Middle East, which has increased concern over energy and commodity markets, inflation and bond yields, and the unveiling of powerful frontier artificial intelligence models, which may sharply increase cyber risks. Against this backdrop, it noted plans for the publication of a report on sound practices for responsible AI adoption for consultation in the coming weeks, with a final report due to be delivered to the G20 Finance Ministers and Central Bank Governors in October. Members also reviewed widespread regulatory and supervisory modernisation initiatives, implementation monitoring processes, and data challenges related to leveraged strategies in sovereign bond markets and nonbank financial intermediation.
The International Organization of Securities Commissions finalized 13 updated valuation recommendations for registered or authorized public open-ended funds, including exchange-traded funds, while excluding money market funds. The framework requires stronger valuation governance, fair value methodologies, conflict controls, oversight of third-party valuation service providers, pricing error processes, timely net asset value calculation and record keeping.
The International Organization of Securities Commissions has published final recommendations that modernize valuation standards for collective investment schemes by consolidating and superseding its 2007 hedge fund valuation principles and 2013 collective investment scheme valuation principles. The 13 recommendations apply to registered or authorized public open-ended funds, including exchange-traded funds, but exclude money market funds. They may also serve as good practices for other funds. The framework responds to greater fund exposure to less liquid, illiquid and private assets, increased retail investment in such schemes, and valuation challenges observed during recent market stress. The recommendations require the responsible entity to maintain documented valuation policies and procedures tailored to the fund structure and strategy, with appropriate independence or oversight of the valuation function. They cover governance under normal and stressed market conditions, identification and management of valuation conflicts, consistent use of methodologies, annual review of valuation arrangements, and documented processes for price overrides. Assets should be valued at fair value, using reliable market prices where available and other valuation techniques where quotations are unavailable or unreliable, with observable inputs prioritized where possible. The framework also highlights back testing, calibration, sensitivity analysis and cross-method checks as tools to assess whether valuation methodologies remain appropriate. IOSCO also strengthens expectations for operational controls around valuation. Responsible entities should conduct initial and periodic due diligence on third-party valuation service providers while retaining responsibility for valuation outcomes. Open-ended funds should generally process subscriptions and redemptions using forward pricing, value assets on any day units are subscribed or redeemed, address stale or inaccurate valuations, make net asset value available to investors at no fee, disclose valuation arrangements appropriately, and maintain procedures to detect, correct and compensate material pricing errors. A new record-keeping recommendation requires documentation sufficient to demonstrate compliance with valuation obligations and support oversight by regulators, auditors and other relevant parties.
The Bank for International Settlements Innovation Hub has launched Project Logos with the Bank of England and Deutsche Bundesbank to study how large language model based agents behave as portfolio managers in a simulated financial market. The project will build an agent based modelling environment to compare rules based asset managers with LLM based agents, examining how they interpret information, allocate capital and respond to constraints, including conditions that may amplify or dampen correlated decision making.
The Bank for International Settlements Innovation Hub has launched Project Logos, a collaboration involving its London Centre and Eurosystem Centre, the Bank of England and the Deutsche Bundesbank, to help central banks observe and analyse how large language model based agents behave as portfolio managers in a simulated financial market environment. The project is intended to examine risks that could arise as common artificial intelligence infrastructure, including LLMs, becomes more widely used in financial services and could lead to more homogeneous or hard to anticipate market behaviour. Project Logos will build an agent based modelling environment focused on portfolio allocation and compare the decisions of heuristic, rules based asset managers with those of LLM based agents under controlled conditions. The work will examine how LLM based agents interpret information, allocate capital and respond to constraints over time, including the conditions that could amplify or dampen correlated decision making, and is intended to give central banks a reusable basis for further exploratory analysis.
The Bank for International Settlements published a working paper modelling how prudential thresholds could reduce risks from fiat-backed stablecoin issuers. The paper finds that treating liquidity ratio and capital ratio thresholds as usable buffers can curb issuer default and bond fire sale risks, with an illustrative 5% liquidity threshold and 0.125% capital threshold reducing weekly default probability from above 15 basis points to around 0.7 basis points under stressed conditions.
The Bank for International Settlements has published a working paper modelling how prudential regulation could reduce risks from fiat-backed stablecoin issuers. The paper finds that, without regulation, an issuer optimising its balance sheet tends to hold little capital and favour interest-bearing but less liquid bonds over cash as bonds generate returns but are costly to liquidate under stress. That balance sheet choice exposes coin holders to default risk and can transmit stress to money markets when large redemptions force bond sales. he central contribution is a framework in which liquidity-ratio and capital-ratio thresholds are treated as usable buffers, not hard minimum constraints. The issuer may breach the thresholds in stress, but doing so triggers additional redemptions through coin-holder discipline. This mechanism gives the issuer an incentive to build buffers in normal times while preserving their use during redemptions. The paper finds that the two thresholds work through different channels: a liquidity threshold mainly raises cash holdings, while a capital threshold raises capital and can also increase cash because cash reduces the bond sales that erode capital. Both thresholds reduce default risk and expected price impact from bond sales, but they become complements when a regulator targets both coin-holder protection and market-spillover risk jointly. The calibrated results translate these mechanisms into policy parameters. Using observed stablecoin flow dynamics and US Treasury market depth, the paper derives a two-way mapping between liquidity and capital thresholds and regulatory targets for probability of default and expected price impact. In an illustrative stressed calibration, a 5% liquidity-ratio threshold and a 0.125% capital-ratio threshold reduce weekly issuer default probability from more than 15 basis points to around 0.7 basis points, while lowering expected price impact from around 4 basis points to 2.7 basis points.
The Bank for International Settlements published a working paper finding that the March 2023 failure of Credit Suisse weakened market confidence that bail-in would be imposed on bank creditors in a future crisis. Using bond-level data from 94 banks in 22 countries, the paper finds that bail-in spreads tightened and credit default swap subordination premia narrowed, while senior debt spreads showed no meaningful movement. Lower-rated banks saw larger funding cost declines, and investor responses to issuer-specific earnings announcements weakened, pointing to reduced market discipline.
The Bank for International Settlements has published a working paper finding that the March 2023 failure of Credit Suisse weakened market confidence that bail-in would be imposed on bank creditors in a future crisis. The paper frames the episode as the first major test of the post-crisis resolution framework for a global systemically important bank: although a resolution plan was ready, Swiss authorities instead facilitated UBS’s acquisition of Credit Suisse with public guarantees, fully wrote down Additional Tier 1 instruments and left bail-in creditors whole. Using bond-level data from 94 banks in 22 countries over the year after the event, the paper finds that markets did not simply reprice bank default risk. Senior debt spreads showed no meaningful movement, while AT1 and bail-in instruments repriced in ways that changed the expected allocation of losses across creditor classes. AT1 spreads followed jurisdiction-specific regulatory signals, rising by about 11 percent in Switzerland and falling by about 5 percent in the euro area and the United Kingdom after authorities clarified the creditor hierarchy. Bail-in spreads tightened across jurisdictions, including by about 13 percent in the euro area and 14 percent in the United Kingdom, while credit default swap subordination premia also narrowed. The paper interprets this pattern as evidence that markets assigned a lower probability to bail-in being enforced, rather than as evidence that private acquisitions had become a more credible substitute for resolution. Lower-rated banks saw larger funding cost declines, while bank size did not explain the repricing, pointing to stronger expectations of public support for institutions closer to distress. Investor responses to issuer-specific earnings announcements also fell for bail-in and senior bonds, suggesting weaker market discipline after the Credit Suisse episode.
In a new series of statements, the Hong Kong Securities and Futures Commission, the French Financial Markets Authority and the European Central Bank have warned firms to strengthen cyber resilience against AI-enabled threats, calling for measures such as faster patching, tighter access controls, stronger detection, third-party risk management, incident response and board-level ownership of operational resilience.
Following previous statements and measures by multiple authorities including the Australian Prudential Regulation Authority and UK authorities, the Hong Kong Securities and Futures Commission (SFSC), the French Financial Markets Authority (AFM) and the European Central Bank (ECB) have each warned that frontier artificial intelligence models are changing the cyber risk profile for regulated financial institutions, urging firms to reassess whether existing cyber prevention, detection, response and recovery arrangements remain effective as AI lowers the expertise, cost and time needed to identify vulnerabilities, exploit weaknesses and conduct more targeted attacks. The Hong Kong Securities and Futures Commission issued a circular to licensed entities, reiterating expectations to maintain up-to-date technology asset inventories, prioritise externally exposed and business-critical components, and strengthen controls across patching and vulnerability management, access and privilege controls, detection and monitoring, third-party supply chain risk management, as well as incident response and recovery. Speaking on behalf of the ECB, Frank Elderson said AI is a structural shift in the economics of cyber risk for banks, noting that more than 85% of significant banks under European banking supervision use artificial intelligence and that almost three-quarters of findings from its 2024 cyber resilience stress test have been addressed. He noted plans for the circulation of a dear CEO letter to banks asking them to take proactive measures and targeted follow-ups. The French Financial Markets Authority (AMF), for its part, will in July survey portfolio management companies, crowdfunding service providers and crypto-asset service providers on how AI-related cyber risks are reflected in their cybersecurity frameworks and vulnerability management processes.
The World Federation of Exchanges issued an open letter calling on authorities to reduce cross-border fragmentation in binding sustainability-related requirements. It urges alignment with leading global standards, principles-based and outcomes-focused requirements, and more predictable regulatory timelines. It also calls for deference and passporting mechanisms to support a “report once, use many” approach and reduce duplicative compliance burdens.
The World Federation of Exchanges has issued an open letter calling on regulators, standard setters, supervisors and legislators to reduce cross-border fragmentation in binding sustainability-related requirements. The letter argues that divergence across jurisdictions raises compliance costs for exchanges, listed issuers and other globally active businesses, creates barriers to international expansion, and shifts resources toward duplicative formal compliance rather than substantive sustainable outcomes. The WFE sets out four priorities. First, authorities should align domestic sustainability regimes with leading global standards and frameworks, including the ISSB Standards, the TNFD Framework and the Transition Plan Taskforce, and consider interoperability with EU measures such as the CSRD, CSDDD, EU Green Bond Standard and EU Taxonomy Framework. Second, requirements should be principles-based and outcomes-focused, with high-level obligations supported by practical guidance that can adapt to changes in science, technology and market practice. The letter also calls for proportionate expectations across sectors and firm sizes, including tailored guidance for hard-to-abate sectors and small and medium-sized enterprises. Third, authorities should provide clearer, more consistent and predictable regulatory timelines, including advance communication, public consultation, realistic deadlines and phased implementation where appropriate. The WFE also urges authorities to avoid reversing or changing requirements close to compliance deadlines where businesses have already invested in preparation. Fourth, authorities should enable a “report once, use many” approach through deference or passporting mechanisms, allowing outputs prepared under one recognised framework to satisfy comparable obligations elsewhere.
The Taskforce on Nature-related Financial Disclosures and Accounting for Sustainability released a guide for Chief Financial Officers on assessing how nature-related dependencies, impacts, risks and opportunities may affect financial performance and prospects. The guide sets 11 questions to help finance teams integrate nature-related issues into risk management, capital allocation, financial planning, reporting readiness and strategic decision making.
The Taskforce on Nature-related Financial Disclosures, in partnership with Accounting for Sustainability, has released a guide for Chief Financial Officers on assessing how nature-related dependencies, impacts, risks and opportunities could affect financial performance and future prospects. The guide frames nature-related issues as financial considerations for CFOs, linking them to risk management, capital allocation, valuation, performance management, financial planning and strategic decision making. The guide sets out 11 questions for CFOs to ask finance teams and other functions across five areas: understanding the business’s dependence and impact on nature, assessing and prioritising risks and opportunities, integrating nature into governance and financial planning, responding to investor and regulatory expectations, and building finance team capacity. It points CFOs to practical actions such as using location-specific and value-chain analysis, linking nature-related risks to revenues, costs, assets, liabilities and financing, embedding nature in budgeting and capital expenditure decisions, setting credible targets, and strengthening data, controls and assurance readiness.
Active global consultations
The Board of the International Organization of Securities Commissions is consulting on proposed good practices to strengthen oversight of over-the-counter commodity derivatives markets by supporting the effective implementation of Principles 12, 15 and 16 on OTC data collection, intervention powers and responses to disorderly markets. The consultation responds to IOSCO’s finding that commodity market participants often hold linked positions across exchange-traded, OTC and physical markets, creating risks to price formation, volatility and market integrity when Market Authorities lack timely visibility over large or concentrated positions, including positions held under common ownership and control. The proposed practices address three areas: collection and aggregation of OTC and exchange trading activity, with a proportionate and risk-sensitive focus on beneficial ownership data, critical or significant contracts, related OTC contracts and factors such as market interdependence, size, liquidity and existing controls; preventing or addressing disorderly markets, including expectations that regulators have effective powers to intervene in relevant OTC markets and that exchanges use available information and position management tools to protect orderly trading; and information sharing and cooperation, including stronger communication between exchanges and regulators, among regulators and through cross-border mechanisms during market stress. The practices also emphasize stringent safeguards for sensitive OTC data and transparent intervention policies so oversight can improve market integrity without unnecessary or duplicative reporting burdens.
The Board of the International Organization of Securities Commissions is consulting on proposed good practices to strengthen oversight of over-the-counter commodity derivatives markets by supporting the effective implementation of Principles 12, 15 and 16 on OTC data collection, intervention powers and responses to disorderly markets. The consultation responds to IOSCO’s finding that commodity market participants often hold linked positions across exchange-traded, OTC and physical markets, creating risks to price formation, volatility and market integrity when Market Authorities lack timely visibility over large or concentrated positions, including positions held under common ownership and control. The proposed practices address three areas: collection and aggregation of OTC and exchange trading activity, with a proportionate and risk-sensitive focus on beneficial ownership data, critical or significant contracts, related OTC contracts and factors such as market interdependence, size, liquidity and existing controls; preventing or addressing disorderly markets, including expectations that regulators have effective powers to intervene in relevant OTC markets and that exchanges use available information and position management tools to protect orderly trading; and information sharing and cooperation, including stronger communication between exchanges and regulators, among regulators and through cross-border mechanisms during market stress. The practices also emphasize stringent safeguards for sensitive OTC data and transparent intervention policies so oversight can improve market integrity without unnecessary or duplicative reporting burdens.
The Committee on Payments and Market Infrastructures and the Board of the International Organization of Securities Commissions are consulting on a 2026 update to the public quantitative disclosure standards for central counterparties, with a focused aim of adding margin-related disclosures to support transparency and comparability under the Principles for financial market infrastructures. The standards set the minimum public quantitative disclosures expected of central counterparties alongside the Disclosure framework, helping authorities, participants and the public compare risk controls, understand financial resources and financial condition, assess systemic importance and evaluate the risks of direct or indirect participation. The update responds to earlier work on margining practices and the transparency and responsiveness of initial margin in centrally cleared markets, and adds new disclosures in Principle 6 and Annex 1 on initial margin responsiveness and associated volatility for the most relevant products by clearing service. The broader matrix continues to organize disclosures by relevant principles, covering credit risk, collateral, margin, liquidity risk, exchange-of-value settlement, defaults, segregation and portability, general business risk, custody and investment risk, operational risk, access and participation, tiered participation, FMI links and market data, with explanatory notes to promote accurate, comparable and appropriately contextualized reporting by central counterparties.
The Committee on Payments and Market Infrastructures and the Board of the International Organization of Securities Commissions are consulting on a 2026 update to the public quantitative disclosure standards for central counterparties, with a focused aim of adding margin-related disclosures to support transparency and comparability under the Principles for financial market infrastructures. The standards set the minimum public quantitative disclosures expected of central counterparties alongside the Disclosure framework, helping authorities, participants and the public compare risk controls, understand financial resources and financial condition, assess systemic importance and evaluate the risks of direct or indirect participation. The update responds to earlier work on margining practices and the transparency and responsiveness of initial margin in centrally cleared markets, and adds new disclosures in Principle 6 and Annex 1 on initial margin responsiveness and associated volatility for the most relevant products by clearing service. The broader matrix continues to organize disclosures by relevant principles, covering credit risk, collateral, margin, liquidity risk, exchange-of-value settlement, defaults, segregation and portability, general business risk, custody and investment risk, operational risk, access and participation, tiered participation, FMI links and market data, with explanatory notes to promote accurate, comparable and appropriately contextualized reporting by central counterparties.
The Board of the International Organization of Securities Commissions is consulting on proposed good practices for regulators and equity trading venues to address how market liquidity is evolving during the trading day, especially the growing concentration of trading in end-of-day auctions. The consultation is based on a global stocktake of equity market liquidity patterns and responds to potential implications for market integrity, operational resilience and investor protection, including reduced liquidity during continuous trading, heightened volatility around the close, risks of “marking the close,” cross-asset manipulation and pressure on trading venues during concentrated trading windows. IOSCO’s proposed good practices cover five areas: continued assessment of trades executed in end-of-day auctions, post-close sessions and other mechanisms that guarantee execution at the closing price; stronger operational risk and resilience arrangements, including business continuity and disaster recovery plans, capacity headroom, cybersecurity programs and real-time system monitoring; risk-based market surveillance that incorporates intraday liquidity metrics and addresses manipulation risks across trading phases and related derivatives markets; calibration and review of volatility control mechanisms to account for liquidity concentrations and significant shifts in liquidity dynamics; and supervisory approaches that assess how trading venues monitor and respond to risks arising from changing intraday liquidity patterns.
The Board of the International Organization of Securities Commissions is consulting on proposed good practices for regulators and equity trading venues to address how market liquidity is evolving during the trading day, especially the growing concentration of trading in end-of-day auctions. The consultation is based on a global stocktake of equity market liquidity patterns and responds to potential implications for market integrity, operational resilience and investor protection, including reduced liquidity during continuous trading, heightened volatility around the close, risks of “marking the close,” cross-asset manipulation and pressure on trading venues during concentrated trading windows. IOSCO’s proposed good practices cover five areas: continued assessment of trades executed in end-of-day auctions, post-close sessions and other mechanisms that guarantee execution at the closing price; stronger operational risk and resilience arrangements, including business continuity and disaster recovery plans, capacity headroom, cybersecurity programs and real-time system monitoring; risk-based market surveillance that incorporates intraday liquidity metrics and addresses manipulation risks across trading phases and related derivatives markets; calibration and review of volatility control mechanisms to account for liquidity concentrations and significant shifts in liquidity dynamics; and supervisory approaches that assess how trading venues monitor and respond to risks arising from changing intraday liquidity patterns.
Regional developments
The Australian Prudential Regulation Authority finalised a simpler and more flexible pathway for authorised deposit-taking institutions to gain internal ratings-based accreditation for calculating credit risk-weighted assets. The pathway is aimed at medium-sized institutions and allows phased progress over three years, with capital benefits realised at each phase. APRA will also phase in the interest rate risk in the banking book capital charge and consider the 25 basis point Common Equity Tier 1 increase when calibrating Pillar 2 adjustments for medium-sized institutions accredited after 1 January 2027.
The Australian Prudential Regulation Authority has finalised a simpler and more flexible pathway for authorised deposit-taking institutions to gain accreditation to use the internal ratings-based approach for calculating credit risk-weighted assets. The changes address the limited uptake of the IRB approach beyond Australia’s largest banks by making APRA’s expectations more transparent and allowing medium-sized institutions to progress toward accreditation in phases, rather than meeting all requirements upfront. The new pathway gives applicants three years to meet the required standards gradually while realising capital benefits at each phase. Following consultation feedback, APRA will allow the capital charge for interest rate risk in the banking book to be phased in on a proportional basis and has clarified expectations on permanent partial use, operational risk management, model validation and governance, phased roll-out sequencing and supervision of new IRB institutions. APRA also confirmed that, after the phase-out of Additional Tier 1 capital instruments, it will take into account the 25 basis point increase in the additional Common Equity Tier 1 capital requirement when calibrating Pillar 2 adjustments for medium-sized institutions accredited after 1 January 2027. The revised Prudential Standard APS 113 Capital Adequacy: Internal Ratings-based Approach to Credit Risk and Prudential Practice Guide APG 113 Capital Adequacy: Internal Ratings-based Approach to Credit Risk take effect on 30 June 2026.
The Monetary Authority of Macao has activated mBridge, enabling participating banks to conduct cross-border transactions on the multilateral central bank digital currency platform. Three banks completed 23 trade settlement and remittance transactions on day one totaling nearly MOP13 billion involving mainland China, Hong Kong and the United Arab Emirates. The authority reported stable system performance and said the remaining eight banks are finalizing implementation. It plans to explore linking the digital pataca infrastructure with other central bank digital currencies or international financial infrastructures to broaden cooperation and strengthen Macao’s role as a financial services platform between China and Portuguese-speaking countries.
The Monetary Authority of Macao has officially activated mBridge in Macao, enabling cross-border transactions on the multilateral central bank digital currency platform after joining it earlier this year. On the first day of live operation, three of the 11 initially approved participating banks completed 23 cross-border transactions covering trade settlement and international remittances. Bank of China (Macau), S.A. Macau Branch, Industrial and Commercial Bank of China (Macau), S.A. and Bank of Communications Co., Ltd. Macau Branch carried out the initial transactions. These involved mainland China, Hong Kong and the United Arab Emirates, with a total value equivalent to nearly MOP13 billion. The authority said the system operated stably on day one, while the other eight participating banks are continuing preparations and are expected to complete implementation of their operations in the near future. mBridge is based on central bank digital currencies and distributed ledger technology and supports real-time peer-to-peer clearing and settlement between participating commercial banks. The Monetary Authority of Macao said it will next explore linking the digital pataca infrastructure with central bank digital currencies in other countries and regions, or with other international financial infrastructures. It said this is intended to broaden international cooperation links and strengthen the financial services platform between China and Portuguese-speaking countries.
The Hong Kong Monetary Authority has announced the establishment of a Tokenised Bond Expert Group to support wider use of tokenised bonds, consisting of industry, legal and technology stakeholders. Initial discussions of the Group focused on applying Hong Kong’s legal and regulatory regime to tokenised bond issuance and transactions, with feedback informing the HKMA’s work with the Financial Services and the Treasury Bureau on potential framework enhancements.
The Hong Kong Monetary Authority has set up a Tokenised Bond Expert Group to support broader use of tokenised bonds in Hong Kong. The group brings together industry associations, financial institutions, legal advisory firms, and financial infrastructure and technology providers to examine policy measures, market practices, and innovation, building on the HKMA’s existing tokenised bond initiatives. The first round of discussions took place in May and focused on Hong Kong’s legal and regulatory regime and how it applies to tokenised bond issuance and transactions. Feedback from those discussions is informing the HKMA’s ongoing work with the Financial Services and the Treasury Bureau to review and identify possible enhancements to the legal and regulatory framework to facilitate wider use of tokenisation in the fixed income market. The HKMA will continue topic-specific discussions with Expert Group members, review the group’s composition as needed, and announce details of the legal and regulatory exercise separately.
The Central Bank of the Philippines has clarified coin and token listing expectations for virtual asset service providers, requiring robust due diligence and accreditation for virtual assets offered on their platforms. The guidance sets a six-pillar review framework covering issuer background, market maturity, use cases, technical security, reserves and legal compliance. VASPs must monitor listing criteria, set delisting triggers, and must not list or support anonymity-enhancing virtual assets.
The Central Bank of the Philippines has issued a memorandum clarifying regulatory expectations for virtual asset service providers (VASPs) conducting due diligence on coins and tokens offered to customers. The guidance builds on Section 161-M of the Manual of Regulations for Non-bank Financial Institutions, which requires VASPs to maintain robust due diligence and accreditation processes for virtual assets listed or traded on their platforms. VASPs may develop their own listing frameworks, but these must consider the guidance and support safe, sound and consumer-centric virtual asset services. The listing review is structured around six pillars covering issuer background, market capitalization and maturity, use cases, transparency, traceability and security, redemption, liquidity and reserves, and legal and compliance matters. The guidance points to issuer governance, financial information, market indicators, token utility, technical security, reserve arrangements and regulatory status as relevant assessment areas. VASPs must also monitor listing criteria on an ongoing basis, set deviation thresholds that trigger delisting, and suspend or delist assets where customer protection concerns arise, including liquidity or capitalization breaches, issuer insolvency, regulatory non-compliance, cybersecurity issues, misleading disclosures, market abuse or abnormal market or price movements. Anonymity-enhancing virtual assets, also referred to as privacy virtual assets, are prohibited from being listed or supported.
The Eurosystem is inviting financial market stakeholders and public sector bodies to join the Appia contact group, which will provide market input on the Pontes and Appia projects for tokenised wholesale financial markets. The group will advise on the Pontes DLT-based settlement solution, contribute to the Appia blueprint for a European tokenised financial ecosystem, and support work on standardisation and key technical and business issues.
The Eurosystem is inviting financial market stakeholders and public sector bodies to express interest in joining the Appia contact group, which will act as a forum for market input on its Pontes and Appia projects for tokenised wholesale financial markets. The group will provide feedback on the operation and evolution of Pontes, the DLT-based settlement solution linking market DLT platforms with TARGET Services, and contribute to the Appia blueprint for a European tokenised financial ecosystem. The group will discuss business and technical matters for the Pontes Pilot, including user requirements, system functionality, testing, migration, operations and risk. Its Appia-related work will cover developments in distributed ledger technology, standardisation and roadmap topics including confidentiality, privacy, cross-chain interoperability and synchronisation, collateral mobilisation, secondary-market structure and cross-border issuance flows. Members will be selected based on institutional engagement and expertise, with the Market Infrastructure Board and Market Infrastructure and Payments Committee deciding the group’s composition. Applications from interested financial market stakeholders are due by 19 June 2026. The group will be chaired by the European Central Bank and is expected to meet quarterly.
The European Supervisory Authorities published their first annual overview of major ICT-related incidents under the Digital Operational Resilience Act, covering 3,383 major incidents reported across the EU financial sector in 2025. The report finds that ICT risk is becoming more interconnected, with most incidents concentrated in the credit and payments sectors and around one third having cross-border impact. System failures, external events and third-party dependencies drove the incident profile, while most cases caused limited disruption to clients, transactions and financial counterparts.
The European Supervisory Authorities published their first annual overview of major ICT-related incidents in the EU financial sector under the Digital Operational Resilience Act, covering 3,383 major incidents reported for 2025. The findings show that ICT risk is increasingly cross-border and interconnected, but that most reported incidents did not translate into material disruption for clients, transactions or financial counterparties. More than 60% of incidents occurred in the credit sector and 16% in the payments sector, reflecting market structure, pre-existing incident reporting obligations and the scale of digital, customer-facing services, rather than evidence of sector-specific weakness. The incident profile points mainly to operational and third-party dependencies. Around one third of incidents had a cross-border impact, and about 8% affected more than 10 countries, highlighting the role of shared infrastructures, common ICT services and cross-border business models. System failures accounted for 51% of major incidents, external events for 27%, payment-related incidents for 18% and cybersecurity-related incidents for 10%. Root-cause reporting showed system failures or malfunctions in about half of incidents, external events in 32%, process failures in 19% and human error in 12%. Almost one third originated from third-party failures, including ICT third-party service providers, other financial entities and infrastructure providers. Within cybersecurity incidents, distributed denial-of-service attacks represented 33%, while data exfiltration and manipulation, including identity theft, represented 31%. The impact data suggests that incident response and containment measures often limited spillovers. Almost 60% of incidents either did not affect clients or affected fewer than 1,000 clients, while 32% did not affect transactions and 26% affected fewer than 1,000 transactions. Only around 1% affected more than one million transactions, mainly in the credit and payments sectors, and fewer than 18% affected financial counterparts. The report also identifies divergent reporting practices and data-quality constraints in the first year of DORA reporting. However, a new IT tool for competent authority reporting to the ESAs, automated validation checks and the DORA Register of Information are expected to improve data quality and support analysis of systemic ICT risk concentrations.
The Authority for Anti-Money Laundering and Countering the Financing of Terrorism is consulting on draft guidelines for risk-based ongoing monitoring of business relationships under Article 26(5) of Regulation (EU) 2024/1624. The framework would require obliged entities to keep customer due diligence information current through periodic and event-driven reviews, including a risk-based approach to expired identity documents. It would also require transaction and activity monitoring frameworks that detect unusual or suspicious behaviour and feed outputs into customer due diligence, risk classification and escalation processes.
The Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) has launched a consultation on draft guidelines specifying how obliged entities should conduct ongoing monitoring of business relationships under Article 26(5) of Regulation (EU) 2024/1624. The draft guidelines apply across financial and non-financial sectors and set out a proportionate, risk-based framework for keeping customer information up to date and monitoring transactions, activities, behaviours and events that may indicate money laundering or terrorist financing risks, including risks linked to the non-implementation or evasion of targeted financial sanctions where these arise in a business relationship. The framework would require obliged entities to treat ongoing monitoring as part of customer due diligence rather than as a standalone transaction-control exercise. Customer information would need to remain accurate through periodic reviews calibrated to risk and event-driven reviews when changes in the relationship, customer profile or external information point to a possible shift in risk. The draft also takes a risk-based approach to expired identity documents: obliged entities would not need to re-collect them automatically, but would have to assess whether an updated document is necessary to maintain reliable customer information. For transaction and activity monitoring, the draft expects obliged entities to build frameworks that reflect their business-wide risk assessment, customer knowledge and access to relevant data. Monitoring may be manual, automated or semi-automated, and may operate before, during or after a transaction or activity depending on the business model. The focus is on detecting unusual or suspicious behaviour in context, including patterns that emerge over time or across products, channels or counterparties. Monitoring outputs should feed back into customer due diligence, risk classification and escalation processes, supported by documentation, testing, data-quality controls, staff training and governance for advanced analytical tools, including artificial intelligence.
The European Banking Authority has signed a Memorandum of Understanding with the New York State Department of Financial Services under the Markets in Crypto-Assets Regulation to strengthen supervision of cross-border stablecoin activities involving issuers in the European Union and New York State. The framework sets principles and procedures for information exchange, supervisory coordination and mutual assistance, including quarterly data sharing, participation in investigations and on-site inspections, and notification of material infringements and major ICT-related security incidents.
The European Banking Authority (EBA) has signed a Memorandum of Understanding with the New York State Department of Financial Services under the Markets in Crypto-Assets Regulation to strengthen supervision of cross-border stablecoin activities. The arrangement covers stablecoins issued in the European Union and New York State, including entities directly supervised by the EBA under MiCA. Under MiCA, the EBA has direct supervisory responsibility for issuers of significant asset-referenced tokens and electronic money tokens. The framework sets principles and procedures for information exchange and supervisory coordination, including mutual assistance in ongoing supervision and in crisis or emergency situations. It covers information on authorisations, reserve assets, governance, liquidity, stress testing, outsourcing, business model changes, sanctions and recovery, redemption or resolution planning, and provides for quarterly exchanges of specified data where available. It also allows participation in investigations and on-site inspections, requires notification of material infringements and major ICT-related security incidents, and enables the sharing of confidential information because the EBA has assessed the NYDFS confidentiality and professional secrecy regime as equivalent to MiCA standards.
The European Commission adopted temporary adjustments to the EU implementation of the Fundamental Review of the Trading Book to preserve the international level playing field for EU banks. The three-year package covers both internal model and standardised approaches and includes a multiplier to neutralise FRTB capital impacts for adversely affected banks.
The European Commission has adopted a delegated act introducing targeted, temporary adjustments to the EU implementation of the Fundamental Review of the Trading Book, the Basel III market risk capital framework for banks. The measures are designed to preserve the international level playing field for EU banks active in global capital markets as some major jurisdictions are expected to delay FRTB implementation beyond 1 January 2027. They include a multiplier allowing adversely affected banks to scale down FRTB capital requirements to the level of their pre-FRTB capital requirements, after applying the targeted amendments and the output floor. The amendments cover both the internal model and standardised approaches. They temporarily relax aspects of the profit and loss attribution test and the risk factor eligibility test, introduce more flexible treatment for Collective Investment Undertaking exposures, and provide specific flexibilities for default risk capital requirements for sovereign exposures under the internal model approach and hedged equity exposures under the standardised approach. Banks using the multiplier must also comply with specified market risk reporting and disclosure requirements, calibrate the multiplier consistently with capital neutrality, and use the pre-FRTB trading book and non-trading book boundary requirements during the three-year period. The delegated act is subject to scrutiny by the European Parliament and the Council. If no objection is raised, the measures will apply from 1 January 2027 through the end of 2029.
The European Commission published the Gas Market Task Force report, finding that EU gas and gas derivatives markets are functioning well, with low market concentration and no concerns from Title Transfer Facility derivatives positions. The report favours targeted improvements over broad new regulation, including closer monitoring of supply chains and algorithmic trading, better REMIT and MiFID data use, stronger Member State implementation, and deeper cooperation between the Agency for the Cooperation of Energy Regulators and the European Securities and Markets Authority.
The European Commission has published the Gas Market Task Force report on EU gas and gas derivatives markets, concluding that both markets are functioning well while identifying further work to strengthen monitoring, enforcement and supervisory cooperation. The report finds low concentration in EU upstream and downstream wholesale gas supply markets, no concerns from concentration in Title Transfer Facility derivatives positions, and broadly fit-for-purpose commodity derivatives rules based on stakeholder feedback. The report points to targeted improvements rather than broad new regulation. These include closer monitoring of gas supply chains and algorithmic trading, new data-screening tools using REMIT data - transactional and other wholesale energy market information reported to the Agency for the Cooperation of Energy Regulators - timely compliance with the revised REMIT Implementing Regulation, stronger Member State implementation of REMIT, and adequate resources for national regulatory authorities. It also identifies scope to improve MiFID position reporting, give trading venues access to a broader set of over-the-counter derivatives data for position management controls, clarify position limit reporting for third-country venue activity, streamline hedging and liquidity provision exemptions, and introduce a one-off notification for entities using the ancillary activity exemption. The report also calls for Member States to minimise the impact of storage obligations on derivatives markets and for ACER and ESMA to improve data use and supervisory cooperation, including through a dedicated data workstream and possible joint guidance or more institutionalised cooperation.
he House of Lords Financial Services Regulation Committee warned that uncertainty over the UK stablecoin regime has held back GBP stablecoin development and could leave the UK behind the United States and European Union. It supports core Financial Conduct Authority and Bank of England safeguards but calls for recalibration of backing asset, holding limit, redemption, capital and bank-issuance proposals that could weaken issuer viability or limit competition. It also urges clearer financial crime responsibilities and regulatory ownership across HM Treasury, the Financial Conduct Authority and the Bank of England.
The House of Lords Financial Services Regulation Committee published a report on the growth and proposed regulation of stablecoins in the UK, warning that uncertainty over the final regulatory regime has suppressed the development of GBP stablecoins and could leave the UK behind the United States and European Union. The Committee argues that regulation should not seek to decide which stablecoin use cases will succeed, but should provide a clear, flexible framework that allows stablecoins to compete with other forms of payment and support emerging uses such as cross-border payments, programmable payments and tokenised asset settlement, while addressing risks to financial stability, consumer protection and financial crime. The report supports core safeguards in the Financial Conduct Authority and Bank of England proposals, including 1:1 backing, statutory trust arrangements for backing assets, audited disclosures and the Bank’s proposed backstop lending facility for systemic issuers. It recommends further work on the calibration of several key measures, including the Bank’s proposed requirement for systemic stablecoin issuers to hold at least 40% of backing assets in unremunerated central bank deposits, temporary holding limits of GBP 20,000 for individuals and GBP 10 million for businesses, redemption requirements, issuance-linked capital requirements, and restrictions on deposit-takers issuing stablecoins. The Committee says these measures risk weakening issuer viability, limiting competition or creating operational burdens unless supported by clearer analysis and adjusted as the market develops. The Committee further calls for clearer anti-money laundering and know-your-customer responsibilities across issuers, exchanges and custodians, including the legal basis for freezing stablecoins or blocking transactions, and recommends that HM Treasury consider whether existing rules are sufficient for private unhosted and unregulated wallets. Finally, it also urges for clearer regulatory ownership across HM Treasury, the FCA and the Bank, demanding clarification how stablecoins will enter the payments regulatory perimeter, how systemic designation will be determined, how firms will move from FCA-only to dual regulation, and whether stablecoin-specific insolvency legislation is needed.
The UK Financial Conduct Authority has proposed removing product-level Task Force on Climate-related Financial Disclosures reporting for investment products and replacing it with targeted climate information for retail and institutional clients. Retail disclosures would cover materially relevant climate risks or opportunities in risk and return communications, while institutional clients could request scope 1, 2 and 3 greenhouse gas emissions data for their own reporting obligations. The Financial Conduct Authority estimates the changes would save firms around GBP 20 million a year.
The UK Financial Conduct Authority has proposed replacing product-level Task Force on Climate-related Financial Disclosures reporting for investment products with a simpler, more targeted regime that distinguishes between retail and institutional investor needs. The product-level TCFD reports would be removed, while the overall product scope would remain broadly unchanged. Entity-level TCFD reporting is not included in the proposals, although the FCA will continue to consider whether those rules can also be streamlined. For retail clients, firms would need to periodically consider whether climate risks or opportunities could be materially relevant to a product’s financial performance or returns. Where they are material, firms would disclose them in retail communications that provide general information on risk and financial returns, including through the product summary where the product is also in scope of the Consumer Composite Investment regime. The FCA does not expect climate information to be disclosed for every product, and firms may use their usual risk assessment processes rather than create new systems. For institutional clients, firms would have to provide, on request, at least scope 1, 2 and 3 greenhouse gas emissions data to clients that need the information for their own climate disclosure obligations. Eligible clients could request the information once per calendar year per product. Guidance would encourage firms to provide other metrics where reasonably required, feasible and supported by contractual arrangements, while avoiding disclosures where data gaps or methodological limitations would make the information misleading. The FCA estimates the changes would produce ongoing industry savings of approximately GBP 20 million per year.
De Nederlandsche Bank published sector-wide findings from an exploratory review of how seven banks, payment institutions and electronic money institutions manage external payment fraud. It found clear operational focus on fraud prevention, but scope to strengthen risk appetite setting, key risk indicators and risk-based steering of detection and alert-handling capacity. The review also identified differences in detection models, customer warnings and decisions to refuse potentially fraudulent transactions.
De Nederlandsche Bank has published sector-wide observations from an exploratory review of how seven banks, payment institutions and electronic money institutions manage external payment fraud. The review found that institutions devote clear operational attention to fraud prevention and customer protection, but that their approaches could be strengthened through more targeted risk appetite setting, better substantiation of key risk indicators and stronger risk-based steering of detection and alert-handling capacity. The review focused on non-bank fraud, where victims authorize payments under false pretenses, because these cases are widespread and are generally not subject to mandatory compensation. DNB found that fraud controls are often driven by operational teams focused on signal processing, triage and follow-up, while strategic choices on prioritization, investment and capacity deployment are less developed. Some institutions have key risk indicators, but these are not always well substantiated or used to steer decisions. DNB also observed that institutions use different combinations of business rules, machine learning and model architectures, but some give limited attention to periodically testing alternative or complementary detection methods. In some cases, detection systems are constrained by the capacity available to handle alerts, which can affect the ability to identify potentially fraudulent transactions. The findings also point to differences in how institutions balance customer instructions against fraud prevention. Several banks refuse potentially fraudulent transactions even where the customer insists on proceeding, while others take different approaches. Customer warnings, push notifications and public campaigns are widely used, but institutions often find it difficult to measure their effectiveness.
As part of a study, the Dutch Authority for the Financial Markets found that firms do not always tailor due diligence for politically exposed persons under the Anti-Money Laundering and Anti-Terrorist Financing Act. The review highlights weaknesses in risk classification, PEP definitions, use of external providers and tooling, staff training, monitoring of status changes, and traceable recordkeeping.
The Dutch Authority for the Financial Markets has published findings from a thematic review of how financial firms identify, assess and monitor politically exposed persons (PEPs) under the Anti-Money Laundering and Anti-Terrorist Financing Act. The review found that firms do not always apply tailored due diligence to PEPs, even though each PEP must be assessed on the basis of their specific risk profile and PEP status does not automatically imply a high risk of money laundering or terrorist financing. The review covered three investment institutions, two investment firms and nine financial service providers that mediate in life insurance or operate under the national regime. The main findings concern four areas. First, firms should assess PEP risks using relevant indicators, such as country corruption risk, and should not use nationality as a standalone risk criterion because this may create a risk of unjustified discrimination. Second, firms need a consistent legal understanding of the PEP definition, including domestic PEPs, family members and close associates, and should ensure that policies, screening lists and actual procedures are aligned. Third, firms that use external providers or tooling for PEP identification and monitoring must define their role, sources and methods clearly, while retaining responsibility for the quality and reliability of outcomes. Tooling may not always detect PEP status changes fully or promptly, including after political changes such as elections. The AFM also found weaknesses in training and recordkeeping. Some firms referred to the Wft advisory diploma as training on the PEP concept, but this may not be sufficient for staff responsible for identifying, assessing and monitoring PEPs under the Wwft. In some cases, firms did not record PEP identification, verification, client due diligence and screening results in a sufficiently traceable way, making it unclear which additional measures had been taken and which data or documents had been used.
The Swiss Financial Market Supervisory Authority supplemented its guidance on money laundering risk analysis for banks and FinIA institutions after finding further weaknesses despite progress. It expects institutions to better define and monitor risk tolerance, strengthen exception processes and key risk indicators, and assess inherent, control and net money laundering risks with sufficient granularity.
The Swiss Financial Market Supervisory Authority (FINMA) has supplemented its earlier guidance on money laundering risk analysis for banks and FinIA institutions after reviewing analyses from more than 30 banks inspected in spring 2023, as well as numerous other banks and FinIA institutions. FINMA found progress in how banks define risk tolerance and structure their analyses, but concluded that further improvements are needed for risk analysis to operate as an effective central tool for managing anti-money laundering risks. The main weaknesses relate to the practical design and use of risk tolerance, risk monitoring and residual risk assessment. FINMA identified insufficient deliberate exclusions from business models, overly permissive or poorly monitored exception-to-policy processes, and key risk indicators that do not give management a clear view of exposure. It also found that some analyses omit relevant client, domicile, product or service risks, use insufficient granularity for higher-risk business models, or fail to distinguish properly between inherent risk, control risk and net risk. Institutions are expected to use meaningful quantitative measures, compare net risk with risk tolerance at both individual and aggregate levels, and assess whether anti-money laundering resources remain adequate.
The Malta Financial Services Authority has set supervisory expectations for licence holders on AI governance, prudential risk management and oversight. Firms are expected to assess AI use, strengthen board accountability and controls, and complete a self-assessment that can be reviewed during future supervisory work.
The Malta Financial Services Authority has issued a supervisory letter to licence holders setting out expectations for the governance, risk management and oversight of artificial intelligence. The letter frames AI as a prudentially relevant risk area and expects firms to assess how current and anticipated AI use affects their risk profile, decision-making, resilience, consumer outcomes, financial stability and market integrity. The authority’s observations from a 2025 cross-sectoral assessment indicate that AI adoption in Malta’s financial sector remains limited, but that many firms lack formal or board-approved AI strategies, rely heavily on external tools, particularly generative AI solutions, and have limited internal expertise and governance structures. The MFSA expects boards and senior management to retain accountability for AI use, including third-party systems, and to strengthen controls over model risk, data governance, outsourcing, concentration risk, operational resilience, customer-facing use cases and financial crime applications. Licence holders are expected to complete a structured self-assessment covering AI use cases, dependencies, governance, accountability, oversight and controls. They do not need to submit the assessment at this stage, but must be able to evidence that it has been performed, considered by the board and senior management, and followed by remediation where gaps are identified.
The Central Bank of Iceland, with domestic card issuers and acquirers, will enable offline credit and debit card payments of up to ISK 50,000 per card issued to adults in Iceland to reduce disruption to retail payments during internet outages. The option will apply only to chip-and-PIN transactions with physical cards and is intended primarily for essential goods, with issuers able to set higher limits or extend use to other purchases. The Central Bank will also work to enable contactless payments by smartphone and smartwatch during outages.
The Central Bank of Iceland has announced that consumers in Iceland will soon be able to make credit and debit card payments even when internet connections fail. Working with Icelandic card issuers and card acquirers, it has enabled offline payments of up to ISK 50,000 per payment card issued to a person of legal age in Iceland, to reduce disruption to domestic retail payments and allow continued purchases of essential goods. The offline option will apply only when the physical card is used, inserted into the payment terminal, and authenticated with a PIN. It is intended for necessities such as groceries, fuel, and medicine. Issuers may set higher limits for specific cards and may also allow offline payments for other goods. For existing cards, cardholders must activate offline functionality by making a chip-and-PIN purchase once so the chip stores the authorisation. Activation for existing cards should be possible from 1 July 2026, although full rollout may take time across service providers. Cards issued on or after 1 July 2026 will include offline payment authorisation automatically. Central Bank said it will continue work to strengthen payment resilience, including enabling contactless payments by smartphone and smartwatch during internet outages.
The Bermuda Monetary Authority is seeking feedback on potential banking models as an initial step toward updating Bermuda’s banking and deposit-taking framework. The paper examines wholesale, domestic retail and commercial models, and asks whether they would benefit Bermuda, attract new entrants, address unmet banking needs, support innovation, or introduce disruption and risks.
The Bermuda Monetary Authority (BMA) has published a discussion paper on potential new banking models for Bermuda, marking an initial step toward updating the banking and deposit-taking framework. The review is intended to inform future licensing and authorisation proposals, with the Authority seeking models that could diversify the banking sector, improve access to banking services, support innovation and preserve alignment with Basel standards and anti-money laundering and anti-terrorist financing requirements. The paper considers wholesale models such as depositary and custodian banks, merchant and investment banks, brokerages and broker-dealers, digital asset banks, and international agent or representative banks. It also examines domestic retail and commercial models, including mutual societies, mortgage corporations and finance companies, publicly owned savings banks, and development banks. The consultation asks whether these models would benefit Bermuda, attract new business, create disruption or introduce risks. It also seeks views on demand for new entrants, growth segments with unmet banking needs, factors that would support new products and emerging technologies, whether additional banking models should be considered, and which criteria the Authority should prioritise when selecting models for Bermuda. The Authority aims to follow with a consultation paper that reflects the feedback received and presents refined proposals for an updated banking and deposit-taking regime.
The U.S. Securities and Exchange Commission is consulting on its draft fiscal years 2026 to 2030 strategic plan, which sets three priorities: renewing regulatory policy, shifting regulatory practices, and improving operational efficiency. The plan covers clearer rules for digital assets and distributed ledger technologies, broader capital-raising pathways, stronger stakeholder engagement and compliance support, enforcement focused on established law, and reforms to organization, technology, artificial intelligence, and performance management.
The U.S. Securities and Exchange Commission published its draft strategic plan for fiscal years 2026 to 2030 for public comment, setting out a return to its core statutory mission of protecting investors, maintaining fair, orderly, and efficient markets, and facilitating capital formation. The plan is structured around three goals: renewing regulatory policy to support innovation, capital formation, market efficiency, and investor protection; shifting regulatory practices toward greater stakeholder engagement, compliance support, and enforcement focused on established law; and improving operational efficiency through organizational, technology, and performance management reforms. The policy agenda includes providing a clearer regulatory foundation for digital assets and distributed ledger technologies, including securities law boundaries, tokenized offerings, custody, trading, staking, and coordination with the Commodity Futures Trading Commission. It also includes expanding capital-raising pathways for entrepreneurs and smaller issuers, modernizing disclosure and shelf registration processes, reviewing legacy rules, and grounding rulemaking in cost-benefit analysis. The enforcement and supervisory agenda emphasizes fraud, deception, and market manipulation, retrospective reviews of existing rules, and an evaluation of the SEC’s administrative law framework. Operational priorities include a targeted reorganization to reduce duplication and improve collaboration, a review and modernization of technology systems including EDGAR, expanded responsible use of artificial intelligence, and reforms to performance management and internal reporting. The SEC requested public comment on the draft plan.
The Federal Reserve Board published an overview of the U.S. buy now, pay later credit market, estimating that major providers originated USD 156.7 billion in consumer credit products in 2025. The analysis covers “pay in 4” plans and other short- and longer-term installment loans, with “pay in 4” accounting for USD 78.3 billion, or half of total issuance. “Pay in 4” volumes rose nearly 80% from the Consumer Financial Protection Bureau’s 2023 estimate.
The Federal Reserve Board has published a product overview of the broader U.S. buy now, pay later credit market, estimating that major providers originated USD 156.7 billion in consumer credit products in 2025. The analysis extends beyond the commonly studied “pay in 4” model to include other short-term and longer-term installment loans, with “pay in 4” plans accounting for USD 78.3 billion, or about half of total issuance. The estimates cover Affirm, Afterpay/Block, Klarna, PayPal, Sezzle and Zip, using publicly disclosed firm information from 2019 through 2025. More than 60% of total issuance carried 0% annual percentage rate, while APR-bearing products accounted for 37%. “Pay in 4” volumes increased nearly 80% from the Consumer Financial Protection Bureau’s most recent 2023 estimate, while other short- and longer-term installment products expanded at comparable rates. Afterpay/Block and PayPal represented 70% of “pay in 4” issuance, while Afterpay/Block and Affirm together accounted for 60% of total BNPL credit issuance.
Monetary policy developments
Rate decisions during the week of June 1-7 were limited but remained broadly cautious, with Poland and India keeping rates unchanged while assessing the inflation impact of higher energy and commodity costs linked to the Middle East conflict. Poland held the reference rate at 3.75%, with CPI easing slightly to 3.1% in May and Q1 GDP growth slowing to 3.5%, but the Council continued to flag geopolitical uncertainty, global commodity prices and domestic wage/activity trends as key risks. The Reserve Bank of India kept the repo rate at 5.25% and retained a neutral stance, noting that domestic activity had been resilient but that prolonged supply disruption, higher fuel prices and a weak monsoon outlook had lifted the inflation forecast to 5.1% for FY2026/27. Kazakhstan lowered the base rate by 100 bp to 17.0% after inflation slowed to 10.4% and the inflation forecast was revised slightly lower.