Global Regulator & Central Bank News Roundup
Edition 242026Week of June 15
Global developments
The Financial Action Task Force’s latest plenary under the Mexican Presidency, ahead of the transition to the UK Presidency, updated Recommendation 6 to incorporate United Nations humanitarian exemptions, revised the grey list by adding Bosnia and Herzegovina and Iraq and removing Algeria and Namibia, and adopted new-round mutual evaluations for Canada and Türkiye. The plenary also advanced work on payment transparency, public-private information sharing, and technology-related risks as well as previewed the incoming UK Presidency’s priorities and launched a Global Strategy Group to deepen coordination across the FATF Global Network."
The Financial Action Task Force's (FATF) latest plenary under the Mexican Presidency, ahead of the transition to the UK Presidency, saw several key outcomes. The FATF updated Recommendation 6 to incorporate United Nations humanitarian exemptions, ensuring targeted financial sanctions do not obstruct funds, assets, goods or services required for humanitarian assistance and basic human needs. In relation to its monitoring list, it added Bosnia and Herzegovina and Iraq to its list of jurisdictions under increased monitoring, while removing Algeria and Namibia after both completed their action plans and successful on-site visits. The plenary adopted new-round mutual evaluation reports for Canada and Türkiye. Beyond this, the plenary advanced initiatives on payment transparency, information sharing and technology-related risks. These include a forthcoming overview of public-private information-sharing arrangements, a consultation on guidance for the strengthened cross-border payment transparency standard, and publications on terrorist financing through digital platforms, underground banking and hawala, virtual assets and decentralised finance. Further work will assess illicit-finance risks in the gaming and gambling sectors. In relation to the incoming UK Presidency, running from July 2026 to June 2028 under the leadership of Giles Thomson, the FATF shared a preview on strategic objectives. These include focus on fraud and scam compounds, implementation of the risk-based approach and risk-based supervision, and stronger information sharing and public-private partnerships. Finally, the plenary also saw the launch of a new Global Strategy Group, a new consultative body intended to bring together the Chairs of FATF-Style Regional Bodies and deepen coordination and advise on key matters such as cross-regional risks and opportunities.
The International Organization of Securities Commissions found that SupTech is becoming embedded in supervision, although implementation remains uneven across 49 surveyed jurisdictions. Use is concentrated in consumer protection and capital markets, while digital assets are a leading area for future development. Cyber risk and limited funding remain the main constraints on adoption.
The International Organization of Securities Commissions published its first global survey of supervisory technology, covering 49 authorities representing more than 75% of global securities market value. The findings show that SupTech has moved beyond experimentation but remains unevenly implemented. Efficiency was the leading adoption driver, cited by 92% of respondents, followed by timeliness at 80%, while artificial intelligence, data access and cloud infrastructure were the main technological enablers. Current applications are concentrated in consumer protection and capital markets supervision, used by more than 75% and 67% of authorities, respectively. Digital assets represent the clearest area for expansion, with 35% expressing interest compared with 18% reporting current use. Cyber and data security was the principal implementation risk, identified as high or critical by 86%, while limited funding was the main barrier to closing the gap between current mid-level technologies and authorities’ ambitions for advanced analytics and machine learning. Most authorities remain at the partial implementation stage, although 51% have dedicated SupTech budgets and responsibility commonly sits with senior leadership. International cooperation is widespread but focuses mainly on sharing experience rather than code or technical tools. Workforce development also remains relatively informal, relying heavily on online and ad hoc training alongside external recruitment.
The Financial Stability Institute of the Bank for International Settlements and the International Association of Insurance Supervisors found that cyber insurance can act as a digital safety net but cannot replace sound cyber resilience. The paper highlights a large protection gap, persistent coverage ambiguity, pricing challenges and accumulation risk from correlated cyber events. It calls for prudent market growth based on risk-based pricing, disciplined underwriting, clearer policy terms and broader public-private action.
The Financial Stability Institute of the Bank for International Settlements and the International Association of Insurance Supervisors published an analysis of cyber insurance, finding that the market can support firms’ preparation for and recovery from cyber incidents but cannot fully absorb the scale, complexity and systemic nature of cyber risk. The paper highlights a major disconnect between rising cyber risk and insurance uptake, with only about 1% of global economic cyber losses estimated to be covered by cyber insurance and small and medium-sized enterprises among the most underinsured commercial customers. The analysis identifies persistent coverage ambiguity, non-affirmative cyber exposure, pricing challenges and accumulation risk as core constraints on sustainable market growth. Cyber policies typically cover first-party losses and third-party liabilities, but exclusions and gaps remain around contingent business interruption, cyber theft or fraud, state-sponsored attacks, terrorism and systemic vulnerabilities. Pricing is constrained by limited historical data, fast-changing threats, digital interdependencies and reliance on scenario analysis and cyber catastrophe models. Accumulation risk is a central prudential concern because cloud outages, widely exploited vulnerabilities, ransomware, destructive malware or critical infrastructure attacks could trigger correlated claims across many policyholders, insurers and lines of business. The paper calls for prudent cyber underwriting market growth supported by risk-based pricing, disciplined underwriting, clearer policy wording, improved cyber incident data, stronger cyber hygiene and multistakeholder action to narrow the protection gap. It also notes that public-private arrangements may be needed for risks that are difficult or impossible for private insurers to cover, including catastrophic state-sponsored or systemic cyber events.
A new Bank for International Settlements staff bulletin identifies two models for stablecoin yields on centralised exchanges: reserve-based remuneration, where yields broadly track policy rates, and activity-based remuneration, where yields are driven more by crypto lending and trading demand. The model used could shape the macrofinancial effects of wider stablecoin adoption by making stablecoins closer substitutes for bank deposits and money market funds or by linking them more directly to exchanges’ riskier market activities.
A new Bank for International Settlements staff bulletin analyses stablecoin yields offered by centralised exchanges using data from 2023–25. It identifies a reserve-based model, under which exchanges pass through income from issuers’ reserve assets and yields broadly track policy rates, and an activity-based model, under which exchanges fund remuneration from lending, trading and other market activity, producing more volatile yields. Coinbase and Binance are examined as prominent examples of the respective models. The remuneration model could determine how widespread stablecoin adoption affects financial stability and monetary policy transmission. Reserve-based remuneration may make stablecoins closer substitutes for bank deposits or money market funds, potentially changing bank funding sensitivity and core bond market dynamics. Activity-based remuneration may turn stablecoin balances into funding for exchanges’ riskier activities, increasing the potential for boom-bust inflows, abrupt redemptions and spillovers to issuers and markets for reserve assets
INTERPOL reported that Operation CyberProtect III, a four-day law enforcement hackathon, uncovered 34 suspicious cases, 18 suspect profiles and 27 potential victims linked to trafficking and sexual exploitation on subscription content platforms. The co-organized operation with the Organization for Security and Co-operation in Europe found traffickers using encrypted messaging, paywalled sites, crypto-linked payments and fake AI profiles to recruit and control victims.
INTERPOL published the results of Operation CyberProtect III, a four-day law enforcement hackathon co-organized with the Organization for Security and Co-operation in Europe that targeted the use of subscription-based content platforms to facilitate human trafficking and sexual exploitation. The operation involved seven European countries and produced 34 suspicious cases, 18 suspect profiles and 27 potential victims. It reinforced an INTERPOL Purple Notice issued in February 2026 that warned of criminal groups posing as modelling agencies, taking control of victims' accounts and coercing women, minors and vulnerable adults into increasingly explicit content production. During the operation, 14 officers reviewed websites, social media, messaging apps and subscription platforms to detect red flags linked to what INTERPOL described as "e-pimping." The findings pointed to recruiters using encrypted messaging services to target victims, including requests for nude images without age verification, and to traffickers exploiting the paywalled structure and coded language of subscription sites to avoid detection. INTERPOL also highlighted evidence of content producers being bought and sold through large messaging groups, the use of cryptocurrencies and diamond emojis as payment mechanisms, social media exchanges of exploitation tactics among managers, and the use of artificial intelligence to generate fake profiles. South America featured prominently in advertisements involving female models, indicating a key region of origin for both real-life and virtual sexual exploitation.
Active global consultations
The Financial Stability Board is seeking feedback on a proposed, non-binding set of 12 proportionate sound practices to support responsible artificial intelligence adoption by all types of financial institutions while enabling sustained value creation and limiting risks to financial stability. The consultation responds to the accelerating use of traditional AI, generative AI and agentic AI across financial services, and to the risks and vulnerabilities that may arise as adoption scales. The practices are organized around two areas: (1) Practices addressing organization-wide governance including board and senior management oversight, alignment with business strategy and risk appetite, clear accountability, incorporation of AI risks into risk management frameworks, effective documentation and organizational adaptability as AI evolves. (2) Practices across the AI lifecycle, covering how financial institutions assess, select, deploy, monitor and retire AI models and systems. These practices focus on materiality and risk assessment, data governance, explainability, transparency, performance management and human oversight. They also address AI-related cyber and ICT risks and third-party AI risks, including those linked to performance, data quality, supply chains, concentration and business continuity.
The Financial Stability Board is seeking feedback on a proposed, non-binding set of 12 proportionate sound practices to support responsible artificial intelligence adoption by all types of financial institutions while enabling sustained value creation and limiting risks to financial stability. The consultation responds to the accelerating use of traditional AI, generative AI and agentic AI across financial services, and to the risks and vulnerabilities that may arise as adoption scales. The practices are organized around two areas: (1) Practices addressing organization-wide governance including board and senior management oversight, alignment with business strategy and risk appetite, clear accountability, incorporation of AI risks into risk management frameworks, effective documentation and organizational adaptability as AI evolves. (2) Practices across the AI lifecycle, covering how financial institutions assess, select, deploy, monitor and retire AI models and systems. These practices focus on materiality and risk assessment, data governance, explainability, transparency, performance management and human oversight. They also address AI-related cyber and ICT risks and third-party AI risks, including those linked to performance, data quality, supply chains, concentration and business continuity.
The Board of the International Organization of Securities Commissions is consulting on proposed good practices for regulators and equity trading venues to address how market liquidity is evolving during the trading day, especially the growing concentration of trading in end-of-day auctions. The consultation is based on a global stocktake of equity market liquidity patterns and responds to potential implications for market integrity, operational resilience and investor protection, including reduced liquidity during continuous trading, heightened volatility around the close, risks of “marking the close,” cross-asset manipulation and pressure on trading venues during concentrated trading windows. IOSCO’s proposed good practices cover five areas: continued assessment of trades executed in end-of-day auctions, post-close sessions and other mechanisms that guarantee execution at the closing price; stronger operational risk and resilience arrangements, including business continuity and disaster recovery plans, capacity headroom, cybersecurity programs and real-time system monitoring; risk-based market surveillance that incorporates intraday liquidity metrics and addresses manipulation risks across trading phases and related derivatives markets; calibration and review of volatility control mechanisms to account for liquidity concentrations and significant shifts in liquidity dynamics; and supervisory approaches that assess how trading venues monitor and respond to risks arising from changing intraday liquidity patterns.
The Board of the International Organization of Securities Commissions is consulting on proposed good practices for regulators and equity trading venues to address how market liquidity is evolving during the trading day, especially the growing concentration of trading in end-of-day auctions. The consultation is based on a global stocktake of equity market liquidity patterns and responds to potential implications for market integrity, operational resilience and investor protection, including reduced liquidity during continuous trading, heightened volatility around the close, risks of “marking the close,” cross-asset manipulation and pressure on trading venues during concentrated trading windows. IOSCO’s proposed good practices cover five areas: continued assessment of trades executed in end-of-day auctions, post-close sessions and other mechanisms that guarantee execution at the closing price; stronger operational risk and resilience arrangements, including business continuity and disaster recovery plans, capacity headroom, cybersecurity programs and real-time system monitoring; risk-based market surveillance that incorporates intraday liquidity metrics and addresses manipulation risks across trading phases and related derivatives markets; calibration and review of volatility control mechanisms to account for liquidity concentrations and significant shifts in liquidity dynamics; and supervisory approaches that assess how trading venues monitor and respond to risks arising from changing intraday liquidity patterns.
Regional developments
The Australian Prudential Regulation Authority has set minimum expectations for banks, insurers and superannuation trustees to integrate geopolitical risk into governance, operational and financial resilience, personnel controls, sanctions preparedness and crisis planning. Boards should oversee gap remediation and exposure reporting, with clear accountability assigned to relevant accountable persons. APRA will conduct targeted assessments of larger entities with heightened exposure under its 2026-27 supervisory plans
The Australian Prudential Regulation Authority (APRA) has set minimum expectations for banks, insurers and superannuation trustees to manage geopolitical shocks through their existing governance, risk management and crisis preparedness frameworks. Boards should ensure geopolitical risk is reflected in strategy, risk appetite and oversight, while management identifies and remediates material gaps with clear accountabilities and timelines. Management reporting should cover financial and non-financial exposures, offshore dependencies and vulnerabilities involving service providers. The expectations are structured across six areas. Enterprise risk frameworks should incorporate geopolitical risk, monitor emerging threats and support coordinated decision-making and communications, including responses to disinformation. Operational resilience arrangements should maintain critical operations and address service provider vulnerabilities, while personnel controls should manage insider threats and foreign interference and provide for staffing continuity. Entities should also maintain processes for sanctions and other international policy measures, identify at-risk offshore exposures and prepare for freezes, restrictions or loss of access. Capital, liquidity and investment stress testing should routinely include severe but plausible geopolitical scenarios, and crisis capabilities should include proportionate playbooks, plans and exercises. Application should reflect each entity’s size, business model, complexity and material exposures. APRA will incorporate targeted readiness assessments into its 2026-27 supervisory plans for a broader group of larger entities with heightened exposure, focusing on crisis preparedness, personnel risk and political risk.
The New Zealand Financial Markets Authority will not take action against life and health insurers that do not lodge climate statements for the 2025/2026 reporting period, pending legislation to remove them from the climate-related disclosures regime. The relief starts on 19 June 2026 and covers insurers with 31 March 2026 balance dates onwards. It will revisit the position if the law is not changed before preparation begins for the 2026/2027 reporting period.
The New Zealand Financial Markets Authority has said it will take a no action approach for life and health insurers that are expected to leave the climate-related disclosures regime under proposed legislative changes. Pending passage of the amendments, affected insurers will no longer be expected to lodge annual climate statements for the 2025/2026 reporting period, avoiding lodgement where the government has already announced that these entities will be removed from the regime. The relief starts on 19 June 2026 and applies to life and health insurers with upcoming lodgement dates for the 2025/2026 reporting period. In practice, insurers with 31 March 2026 balance dates onwards are not required to lodge climate statements. Firms do not need to apply for the relief or notify the regulator that they are relying on it. The Financial Markets Authority also noted that a no action position reflects its enforcement intent and does not necessarily prevent third parties from taking legal action. The regulator said it will monitor the progress of the amending legislation. If the changes are not in place by the time affected insurers need to start preparing statements for the 2026/2027 reporting period, it will revisit the no action approach. It also noted that some insurers may continue voluntary climate reporting after the law changes, and that the fair dealing provisions in Part 2 of the Financial Markets Conduct Act will continue to apply to statements made in that reporting.
Hong Kong Exchanges and Clearing Limited and the Hong Kong Monetary Authority launched a pilot to test e-HKD for advance margin payments in derivatives after-hours trading. The initiative would give HKCC clearing participants a more flexible payment option than the current 3:00 p.m. submission deadline. Optional real-value trial transactions and any wider rollout remain subject to regulatory approval, market readiness and other considerations.
Hong Kong Exchanges and Clearing Limited and the Hong Kong Monetary Authority launched a joint pilot project to explore a digital payment solution for the after-hours trading session in Hong Kong’s derivatives market. The pilot will test the use of e-HKD for advance margin payments outside regular banking hours while maintaining existing operational workflows. The initiative is intended to give HKFE Clearing Corporation Limited clearing participants more flexibility than the current arrangement, under which advance margin deposit requests must be submitted by 3:00 p.m. for funds to count toward the subsequent after-hours trading session. The use of e-HKD would provide a more timely payment option and support derivatives market risk management outside regular banking hours. HKEX is inviting HKCC clearing participants to take part in optional real-value trial transactions. The trials and any wider adoption remain subject to regulatory approval, market readiness and other relevant considerations.
The Bank of Japan has asked financial institutions to urgently strengthen short-term cybersecurity measures to address the risk that frontier AI will accelerate vulnerability discovery and exploitation. Firms are expected to treat the issue as a management priority, focus patching and defenses on critical systems, and ensure vendors, contracts and contingency plans can support rapid response. The measures are framed as immediate actions, with about one month as a general guideline and ongoing review as threats evolve.
The Bank of Japan has published a request urging financial institutions to take immediate cybersecurity measures in response to the changing threat posed by frontier AI. The core message is that firms should prepare for a potential sharp increase in vulnerability discovery and patch releases, with senior management directly involved in decisions on prioritization, resourcing and implementation. The request frames the issue as a firm-wide management priority rather than a matter for IT and cybersecurity teams alone. The attached measures call on institutions to identify priority services and systems, especially externally accessible systems supporting critical services such as internet banking, and to focus resources on those assets. Firms are asked to reduce technical debt so patching targets can be identified quickly, secure staff capacity for patching and vulnerability triage, and confirm that vendors and maintenance contracts can support timely remediation, including during nights and holidays. The guidance also pushes firms to move beyond reliance on CVSS scores alone by prioritizing vulnerabilities based on their potential effect on the institution's own services and likelihood of exploitation, while strengthening layered defenses where patching is difficult through tools such as web application firewalls, bot mitigation, network segmentation, multi-factor authentication for privileged accounts and endpoint detection and response. It also tells firms to prepare for service disruption scenarios, including possible proactive suspension of critical services or systems, and to maintain information-sharing through industry and regulatory channels. The request says these actions should be pursued on a short-term basis with approximately one month as a general guideline, while institutions continue to review and update their approach as AI-related threats evolve. It also notes that the measures were developed through a working group following Financial Services Agency-led public-private discussions on AI-related cyber risks in the financial sector.
China's National Financial Regulatory Administration has set governance and safety requirements for AI across banking and insurance, including board oversight, lifecycle controls and risk-tiering. High-risk uses such as credit approval, underwriting, claims and funds trading require risk management committee approval, human oversight and fallback arrangements. Public-facing or high-risk generative AI uses must be reported to the regulator, while institutions must label AI-generated content, protect personal data and control outsourcing and supply-chain risks.
China's National Financial Regulatory Administration has issued guidelines for the safe development and use of artificial intelligence by banking and insurance institutions. The framework makes institutions accountable for the AI they use and requires board-level oversight, lifecycle controls, risk classification and the integration of AI risk into comprehensive risk management. Generative AI models are subject to internal admission reviews covering performance, safety and compliance, while externally sourced models must have completed filing with the cyberspace authorities. Applications involving funds trading, asset valuation, credit approval, underwriting and claims, risk management, or other uses directly affecting customer interests or financial contracts are classified as high risk and require approval by the institution's risk management committee. These uses must include human supervision, emergency shutdown conditions and fallback systems or manual processes. Where explainability is insufficient, AI may only support the final decision, while decisions affecting customer rights or having a material financial impact must include human review and retain the underlying data, reasoning path and threshold records. Institutions must label AI-generated content and explain its use to financial consumers, retain development, change and training records for at least the duration of the relevant business, and prevent personal identifiers and private data from being used to train or optimize generative AI models. They must also manage outsourcing, supply-chain, open-source, cybersecurity and business continuity risks. Public-facing or high-risk generative AI applications must be reported to the National Financial Regulatory Administration or its local offices, which will focus supervision on high-risk uses and conduct annual assessments of the policy and its regulatory effectiveness.
The South Korea Financial Services Commission has issued revised AI guidelines for the financial sector, setting out seven principles for AI use by financial companies and fintech firms. The self-regulatory framework takes effect on June 22, 2026, with supporting risk management and security guidance to follow. The commission also outlined further work on regulatory easing, AI accountability rules and phased sandbox testing for AI agents in the second half of 2026.
The South Korea Financial Services Commission introduced revised AI guidelines for the financial sector at a meeting on AI transformation with industry and research participants, setting out a self-regulatory framework for all financial companies, including fintech businesses. The update centers on seven principles for AI use covering governance, legality, human-supervised use, model and data credibility, financial stability, good faith toward consumers, and security. The guidelines are intended to be applied proportionately based on each firm's resources, AI use case and service risk, while high-impact AI and other AI subject to the Framework Act on the Development of Artificial Intelligence and the Creation of a Foundation for Trust must follow applicable regulatory requirements. The guidelines will take effect on June 22, 2026. They state that AI should currently be used as an assistive tool under human oversight, with ultimate decision-making responsibility resting with the AI supervisor. Supporting measures will include an AI risk management framework from the Financial Supervisory Service and an AI security guidebook from the Financial Security Institute, alongside an AI guidelines helpdesk for firms. In remarks at the meeting, Vice Chairman Kwon Dae-young also outlined a broader policy direction that includes easing network separation requirements for AI cybersecurity purposes, upgrading rules on personal credit data consent and data pseudonymization, developing standards on AI behavior, and considering rules on AI responsibility and authority as AI agents take on larger roles in product recommendations, product subscriptions and payments. The Financial Services Commission said it will review areas requiring regulatory reform, seek AI risk management measures and consider staged test operations for AI agents through the financial regulatory sandbox program from the second half of 2026
The Australian Prudential Regulation Authority has launched the final consultation on a consolidated governance standard for banks, insurers and superannuation entities. The draft CPS 510 would strengthen board, conflicts and fit and proper requirements while removing duplicative reporting for about 6,000 individuals. Final requirements are planned for late 2026, with commencement expected in early 2028.
The Australian Prudential Regulation Authority has published an updated draft of Prudential Standard CPS 510 Governance for further consultation, marking the final phase of its review of governance requirements across banking, superannuation and insurance. The draft standard would consolidate five existing prudential standards into one cross-industry standard, strengthen requirements for board governance, conflicts management and fitness and propriety, and reduce duplication with the Financial Accountability Regime by removing routine fit and proper reporting for about 6,000 individuals. The proposed framework clarifies core board responsibilities while allowing delegation of non-core APRA requirements to board committees or senior managers subject to documented guardrails. It would set consistent minimums on board size and Australian residency, extend conflicts management requirements across APRA-regulated entities, require board skills matrices, strengthen annual performance assessments and introduce triennial independent board reviews for significant financial institutions. APRA has adjusted earlier proposals by moving from a proposed 10-year non-executive director tenure limit to a 12-year default limit, removing a planned requirement for significant financial institutions to submit independent board review reports to APRA, and dropping mandatory early engagement with APRA on potential appointments. APRA is seeking feedback on the draft CPS 510, related changes to Prudential Standard CPS 001 Defined terms, and the implications of removing routine fit and proper reporting. Submissions are due by 28 August 2026, with final CPS 510 and related guidance planned for release in the fourth quarter of 2026 and the new requirements expected to take effect from early 2028.
The Hong Kong Mandatory Provident Fund Schemes Authority has launched an AI chatbot on its MPF investment education website to give scheme members real-time, personalized information based on official MPFA resources. The tool explains MPF investment concepts, provides source references and visual aids, and suggests related questions. It does not provide investment advice, recommend funds, or assess suitability, and will later be extended to other education tools including the retirement planning mobile app.
The Hong Kong Mandatory Provident Fund Schemes Authority has launched the MPF Investment Education AI Assistant on its MPF investment education thematic website to provide scheme members with instant, personalized educational support on MPF investment matters. Using generative artificial intelligence and the authority’s official investment education resources, the chatbot is designed to answer user queries in real time and help members better understand how to manage their MPF investments. The tool provides evidence-based responses tailored to specific enquiries, explains investment concepts in conversational language, and includes references linking back to official information sources. For more complex topics, it can use simple visual aids, and it suggests frequently asked questions based on different scenarios to guide users through related topics. The authority said the chatbot provides only objective and official information and does not give investment advice, recommend specific MPF schemes or funds, or assess product suitability for individual members. The authority plans to extend the AI Assistant to other MPF investment education tools, including its retirement planning mobile app, to broaden access to the service.
Mexico's National Commission for the Protection and Defense of Financial Services Users and the Banking Protection Service signed an agreement to improve information sharing and support investigations into financial fraud. The move follows more than 35,000 possible fraud claims from January to May 2026 and early use of the Consult and Report tool, which is designed to identify and report phone numbers associated with potential fraud and registered nearly 5,000 phone numbers within one week.
Mexico's National Commission for the Protection and Defense of Financial Services Users (CONDUSEF) and the Banking Protection Service signed a collaboration agreement to strengthen user protection and help prevent and combat financial fraud conducted through phone calls, messages and other deceptive mechanisms. The agreement will support strategic information sharing on fraud methods, identification of trends and operating patterns used by criminal groups, and the provision of information useful to authorities investigating financial crimes. The agreement follows initial results from the Consult and Report tool,which is designed to identify and report phone numbers associated with potential fraud and received more than 11,000 inquiries and registered nearly 5,000 phone numbers within one week of launch. CONDUSEF registered more than 35,000 claims for possible financial fraud between January and May 2026, with potential fraud complaints up 18% in commercial banking and nearly 49% for Popular Financial Societies and Multiple Purpose Financial Societies compared with the same period of the previous year. The claims data also show growth across age groups, with increases of about 25% among users aged 50 to 59, 22% among those aged 40 to 49, and nearly 20% among young adults aged 18 to 29.
The Central Bank of Brazil has changed the rules for contactless Pix by removing the fixed BRL 500 ceiling and applying the same limit-management model used for other Pix payments. Under the update, contactless Pix transactions and payments initiated through the no-redirect journey in Open Finance will follow user-defined daily and per-transaction limits, which customers can ask their bank to increase or reduce through the limit-management tools that banks must make available in their apps. The change allows higher-value contactless Pix payments, subject to the limits set by the user, and makes the experience closer to the existing Pix payment journeys based on keys or QR codes. It also extends to Open Finance payments made without redirection, including transactions through compatible digital wallets, with the aim of unifying the rules and reducing regulatory differences across payment journeys that serve the same function in physical and digital commerce. The rule takes effect on 1 October 2026.
The Central Bank of Brazil has changed the rules for contactless Pix by removing the fixed BRL 500 ceiling and applying the same limit-management model used for other Pix payments. Under the update, contactless Pix transactions and payments initiated through the no-redirect journey in Open Finance will follow user-defined daily and per-transaction limits, which customers can ask their bank to increase or reduce through the limit-management tools that banks must make available in their apps. The change allows higher-value contactless Pix payments, subject to the limits set by the user, and makes the experience closer to the existing Pix payment journeys based on keys or QR codes. It also extends to Open Finance payments made without redirection, including transactions through compatible digital wallets, with the aim of unifying the rules and reducing regulatory differences across payment journeys that serve the same function in physical and digital commerce. The rule takes effect on 1 October 2026, giving financial and payment institutions time to make the necessary operational adjustments.
The Central Bank of Oman will waive fees on local digital transfers for retail customers and SMEs from 1 July 2026 across RTGS, ACH and the Instant Payment System when used through digital channels. It also cut the maximum merchant fee for QR code person-to-merchant payments to 0.50% from 0.75%, capped at OMR 2.000, and simplified Wage Protection System salary file fees to a maximum of OMR 1.000 per month. The central bank will monitor adoption through 2026 and may take further measures.
The Central Bank of Oman has announced reforms to National Payment Systems fees that will remove charges on local digital fund transfers for retail customers and small and medium-sized enterprises from 1 July 2026. The zero-charge policy applies to transfers through the Real-Time Gross Settlement System, Automated Clearing House and Instant Payment System when made through digital banking and payment channels, including e-wallets, and will be implemented by licensed banks and Payment Service Providers. The package also keeps person-to-person payments through the Instant Payment System free for all customers, whether the beneficiary uses the same or a different bank or Payment Service Provider. For private sector employers using the Ministry of Labour's Wage Protection System, processing fees for salary payment files have been simplified to a maximum of OMR 1.000 per month regardless of the number of employees, salary files or beneficiary banks. In addition, the maximum Merchant Service Fee for QR code-based Scan and Pay person-to-merchant transactions has been reduced to 0.50% of the transaction value from 0.75%, subject to a cap of OMR 2.000 per transaction. The central bank said it will work with banks, Payment Service Providers and other stakeholders on implementation and will monitor digital payment adoption through 2026, including effects on customer behavior, cash usage, cheque dependency and payment service efficiency.
The Central Bank of Iraq said FATF has adopted a joint action plan with Iraq and acknowledged progress in the country’s AML/CFT and proliferation financing framework. The plan targets remaining gaps including informal transfer services, virtual asset providers, targeted financial sanctions, suspicious transaction reporting, beneficial ownership, and more money laundering and terrorist financing enforcement.
The Central Bank of Iraq announced that the Financial Action Task Force has adopted a joint action plan with Iraq and issued a statement recognizing progress by Iraqi authorities in strengthening the country’s anti-money laundering, counter-terrorist financing and proliferation financing framework. The plan, agreed at the close of the FATF plenary, sets out the next areas of work for Iraq following its November 2024 mutual evaluation report and its subsequent engagement with FATF and the Middle East and North Africa Financial Action Task Force. According to the release, Iraq has already taken steps including market-entry controls to stop criminals and terrorists accessing key sectors, guidance for non-bank financial institutions and designated non-financial businesses and professions, risk-mitigation measures for the real estate sector, and a stronger official understanding of how legal persons can be misused for money laundering and terrorist financing. The action plan now focuses on nine areas including sharper assessment of specific money laundering and terrorist financing risks and related preventive measures, stronger detection of informal money or value transfer services, a legislative framework for virtual asset service providers, and fuller application of targeted financial sanctions. The process is intended to support Iraq’s exit from enhanced follow-up.
The Central Bank of Egypt said Egyptian banks have adopted ISO 20022 for SWIFT messages used in interbank financial transfers from June 21, 2026. The move is intended to improve interbank settlement efficiency, enrich payment data and support more automated cross-border processing and compliance screening. It also updates Egypt's instant settlement system to align with international messaging standards.
The Central Bank of Egypt announced that the Egyptian banking sector has moved, effective June 21, 2026, to the ISO 20022 international standard for SWIFT messages used in financial transfers between Egyptian banks. The change is presented as a core upgrade to Egypt's digital payments infrastructure and is intended to improve the efficiency and accuracy of interbank instant settlement while aligning messaging with international standards. The central bank linked the shift to faster execution, better cross-border payment processing and stronger automated screening of transactions against domestic and international anti-money laundering and counter-terrorist financing recommendations. It also said the update supports newer financial services, including open banking and advanced data analytics, and brings Egypt's updated instant settlement system into line with more advanced settlement infrastructures globally.
The Commodity Futures Trading Commission is seeking input on regulatory barriers that hinder fintech partnerships with CFTC-regulated entities and on ways to streamline authorization processes. The review also examines whether existing regulatory categories appropriately cover technology-enabled activities, including decentralized finance.
The Commodity Futures Trading Commission has issued a request for information to identify regulations, guidance, orders, no-action letters and other regulatory items that may unduly restrict fintech firms from partnering with CFTC-regulated market participants and infrastructures. It is also seeking changes that could streamline registration, designation and authorization processes for eligible fintech firms. The review covers non-bank companies that use or develop technology to offer or support financial services and seeks to accommodate technology-enabled services, including digital asset-related activities. The CFTC is seeking specific examples of processes and regulatory requirements that are not fit for technology-enabled business models, barriers to partnerships with regulated entities and changes needed to make applications more efficient. It also asks whether existing regulatory categories adequately capture fintech activities, including decentralized finance protocols and applications, or are overly broad and should provide exemptions or exceptions for certain technology-based activities.
FinCEN and the federal banking regulators proposed requiring permitted payment stablecoin issuers to collect core identifying information before account opening and verify each customer shortly afterward through risk-based documentary or non-documentary methods. Issuers would need procedures for entity controllers, failed verification and account closure, Suspicious Activity Report filing, recordkeeping, government-list screening and customer notices. The proposal also permits reasonable reliance on federally regulated financial institutions and coordinated regulatory exemptions.
The U.S. Financial Crimes Enforcement Network, the Office of the Comptroller of the Currency, the Federal Reserve Board, the Federal Deposit Insurance Corporation and the National Credit Union Administration proposed requiring permitted payment stablecoin issuers to maintain written, risk-based customer identification programs as part of their anti-money laundering and countering the financing of terrorism programs. The proposal would implement the GENIUS Act’s treatment of these issuers as financial institutions under the Bank Secrecy Act and complements a separate FinCEN proposal covering additional anti-money laundering obligations. Before opening an account, an issuer would have to obtain the customer’s name, address, identification number and either date of birth for an individual or date of formation for an entity. It would then have to verify the customer’s identity within a reasonable period using documentary or non-documentary methods and form a reasonable belief that it knows the customer’s true identity. For entity customers, the issuer would also need risk-based procedures to obtain information about individuals with authority or control over the account. The program would have to specify when an account should not be opened, whether and on what terms it may be used while verification is pending, when it should be closed after verification fails and when a Suspicious Activity Report should be filed. It would also require retention of customer identification records, screening against designated federal lists of known or suspected terrorists or terrorist organizations, and notice to customers that identity information is being requested. Issuers could reasonably rely on another federally regulated financial institution to perform specified identification procedures for their customers. The appropriate federal functional regulator and the Treasury secretary could also grant exemptions for an issuer or account type with the other authority’s concurrence.
The US Securities and Exchange Commission and US Commodity Futures Trading Commission are seeking comment on clearer regulatory boundaries for swaps, security-based swaps, mixed swaps and excluded instruments, with a focus on event contracts and other emerging products. They are also considering alternative compliance where substantially similar requirements apply across the two regimes.
The US Securities and Exchange Commission and US Commodity Futures Trading Commission issued a joint request for comment on clarifying and harmonizing the treatment of derivatives and emerging products under Title VII of the Dodd-Frank Wall Street Reform and Consumer Protection Act of 2010. The agencies are considering clearer criteria for distinguishing swaps, security-based swaps, mixed swaps and instruments excluded from the swap definition, particularly where event contracts and other new product structures may implicate both regulatory regimes. The review covers definitional boundaries for products linked to securities, indexes and issuer events, as well as the treatment of structured debt instruments, physically settled security forwards, futures and cash-settled perpetual contracts referencing equities. It also seeks views on alternative compliance arrangements under which compliance with one agency’s substantially similar requirements could satisfy the other’s framework, including coordinated approaches to registration, reporting, supervision, examination, enforcement and cross-market surveillance.
The European Banking Authority finds EU and EEA banks remain resilient, with a 16.3% Common Equity Tier 1 ratio and a 1.82% non-performing loan ratio, but face rising geopolitical, energy, non-bank and cyber risks. Direct Middle East exposures are limited, although concentrated energy-sensitive, private credit and sovereign exposures could transmit wider shocks. Banks should maintain credible funding plans, flexible payouts and stronger credit and AI-related cyber controls.
The European Banking Authority has published its latest Risk Assessment Report, finding that EU and EEA banks remain resilient, with strong capital, low non-performing loan ratios and continued lending growth, but face a more fragile environment driven by the Middle East conflict, energy price shocks, rising sovereign exposures, deeper links with non-bank financial institutions and rapidly evolving cyber threats. Loans to households and non-financial corporations rose 2.7% in 2025, while the aggregate non-performing loan ratio remained at 1.82% and the Common Equity Tier 1 ratio reached 16.3% at year-end. Risks are concentrated rather than broad-based. Direct Middle East exposures were about EUR 130 billion, less than 0.5% of assets, but banks held about EUR 1 trillion of exposures to particularly energy-sensitive sectors, or roughly 17% of corporate exposures. Non-bank financial institution exposures reached around 10% of total assets, while private credit links remain limited in aggregate but concentrated at larger banks. Funding and liquidity ratios are expected to decline modestly in 2026 but remain above regulatory minima, although ambitious deposit and bond issuance plans could be harder to execute in volatile markets. Profitability remains supported by net interest income, but projected gains rely heavily on cost reductions that may be difficult to deliver as information and communication technology investment needs rise. The EBA urges banks to conduct granular stress testing and early-warning monitoring of energy-sensitive, small and medium-sized enterprise, consumer and commercial real estate exposures. It also calls for stronger aggregation and valuation controls for non-bank and private credit risks, credible funding plans, flexible payouts, robust capital and liquidity buffers, enhanced AI and cyber governance, and continued improvements in climate transition planning.
The European Banking Authority proposed targeted simplification of the EU bank prudential and resolution capital framework without redesigning or recalibrating it. Key measures include preserving Pillar 2 tools, creating one releasable macroprudential buffer from the countercyclical and systemic risk buffers, simplifying the leverage ratio stack, and standardizing selected MREL elements. More structural resolution options are left for further consideration.
The European Banking Authority published a comprehensive review of the EU bank microprudential, macroprudential and resolution capital framework, setting out targeted proposals to reduce complexity while preserving resilience, resolvability and supervisory tools. The report does not recommend a fundamental redesign or recalibration of the framework, but focuses on simplifying capital stacks, improving consistency and keeping the framework focused on material and emerging risks. For the microprudential framework, the EBA recommends preserving Pillar 2 requirements and Pillar 2 guidance, while further harmonizing their use and keeping them focused on risks not sufficiently covered by Pillar 1 and on capital adequacy under stress. It proposes removing macroprudential adjustments from total risk exposure amount calculations, not merging the capital conservation buffer with Pillar 2 requirements or guidance, removing leverage ratio Pillar 2 guidance, converting any retained leverage ratio Pillar 2 requirement into a buffer, and leaving the composition of capital unchanged. For macroprudential policy, the EBA proposes a single releasable macroprudential buffer that would consolidate the countercyclical capital buffer and systemic risk buffer, supported by a high-level common methodology, and recommends updating the methodology for other systemically important institution scoring and considering buffer calibration options. For resolution, the EBA recommends aligning the definitions of total loss-absorbing capacity and minimum requirement for own funds and eligible liabilities resources, replacing the 8% total liabilities and own funds input for subordination requirements with an equivalent total exposure measure-based metric, moving toward more standardized MREL adjustments, and exploring a cooperation framework between resolution and competent authorities for MREL breaches. More far-reaching options, including a single fully subordinated MREL metric, a TLAC-style resolution Pillar 1 and Pillar 2 structure, or a single going and gone concern stack, are presented only for further consideration given their broader and more uneven effects.
French authorities have published the methodology for their first system-wide stress test, covering more than 20 banks, insurers and asset managers. The 10-day exercise combines participants’ intended responses with authority-led modelling to assess cross-exposures, fire sales and liquidity amplification. A second round will run in June and July 2026, with a final report due in autumn 2026.
French authorities have published an interim methodological report on France’s first integrated system-wide stress test. The voluntary, exploratory exercise covers more than 20 banks, insurers and asset managers and assesses how institutions’ defensive actions could transmit or amplify a severe market shock, particularly through liquidity pressures. The scenario runs for 10 business days and is calibrated to at least a one-in-500 two-week market event, with stress peaking on Day 3. Participants report their intended management actions, timing, volumes, markets and counterparties under a static balance sheet and without extraordinary policy support. The authorities combine these bottom-up responses with top-down modelling of non-participants and second-round effects, focusing on cross-exposures, common-asset fire sales and chains of liquidity needs, margin calls and repurchase transactions. First-round submissions are being checked for internal consistency, bilaterally reconciled and aggregated to assess whether participants’ planned actions are collectively feasible. A second round will run in June and July 2026 and may incorporate reduced market depth, price impacts or targeted sensitivities based on the findings. A joint final report is due in autumn 2026, and the exercise will not affect individual supervisory assessments.
The United Kingdom's Prudential Regulation Authority is consulting on targeted changes to the Basel 3.1 market risk internal model approach. The package would extend nonbinding model-test monitoring, make modellability requirements more proportionate and remove barriers to gradual model adoption. Responses are due September 18, 2026, with implementation remaining set for January 1, 2028.
The United Kingdom's Prudential Regulation Authority has launched a consultation on targeted adjustments to the Basel 3.1 internal model approach for market risk, the final outstanding element of the UK's Basel 3.1 implementation. The proposals apply to PRA-authorised banks, building societies, PRA-designated investment firms and relevant holding companies, particularly firms using or seeking internal model approval. Key changes would extend the nonbinding monitoring period for the profit and loss attribution test from one year to three years. They would also reduce the minimum number of verifiable prices from 24 to 16 for risk factors with liquidity horizons above 20 days and introduce proportionate testing for new issuances. The PRA would create a Type 1 category for risk factors that fail the quantitative test but meet qualitative data standards, retaining them in the expected shortfall model while applying a capital add-on. Further proposals would recognise diversification between internal model and advanced standardised approach portfolios during gradual model approval, introduce a 90% look-through threshold for collective investment undertakings and simplify related operational, reporting and disclosure requirements. Responses are due by September 18, 2026. The PRA plans to implement the adjusted internal model framework on January 1, 2028, while the remaining Basel 3.1 rules are still scheduled to take effect on January 1, 2027.
A European Central Bank working paper finds that on-site inspections were followed by persistent increases in banks’ commercial real estate coverage ratios, while targeted reviews produced only short-lived gains. The authors present the tools as complementary: targeted reviews broaden supervisory reach, while on-site inspections support more durable remediation.
The European Central Bank has published a working paper assessing whether Single Supervisory Mechanism activities strengthened banks’ management of commercial real estate credit risk. Using quarterly confidential supervisory data for 81 significant euro area institutions from 2020 Q1 to 2024 Q4, the paper finds that on-site inspections were followed by larger and more persistent increases in commercial real estate coverage ratios, while targeted reviews produced shorter-lived improvements. The fully specified model estimates that on-site inspections were associated with an average 12.1 percentage point increase in coverage ratios, measured as provisions relative to non-performing commercial real estate exposures. Dynamic estimates show the effect appearing in the quarter of the intervention and remaining statistically significant through most of the following nine quarters. Targeted reviews showed no statistically significant average effect in the static estimates, although the dynamic analysis indicates increases of about 9 and 12 percentage points in the first and second post-intervention quarters before the effect faded. The authors link the stronger on-site inspection effect to the tool’s greater intrusiveness, more formal follow-up and higher share of high-severity remedial measures. The findings support using targeted reviews for broader surveillance and early vulnerability detection, while using on-site inspections to secure more durable remediation. Because supervisory interventions were risk-based rather than randomly assigned, the results are presented as conditional associations rather than definitive causal effects, and the paper does not represent the views of the ECB.
The Belgium Financial Services and Markets Authority has warned that frontier AI systems are making cyberattacks easier, faster and more scalable, requiring regulated firms to reassess ICT risk even if they were previously seen as lower-risk targets. It says DORA provides the core response framework and expects in-scope firms to strengthen asset inventories, patching, detection and incident response, and oversight of ICT service providers.
The Belgium Financial Services and Markets Authority has issued a communication warning that frontier artificial intelligence systems are materially increasing cyber risk for regulated firms and lowering the threshold for attacks, including for firms that may previously have viewed themselves as less exposed because of their size or activities. It says the European Digital Operational Resilience Act, or DORA, provides the main framework for addressing those risks and expects firms subject to DORA to reassess their exposure and strengthen their digital operational resilience accordingly. The communication highlights that advanced AI models can identify and exploit vulnerabilities across ICT systems, including legacy and widely used applications, at speed and at scale, without requiring deep specialist expertise. As a result, firms should assume shorter patching cycles and focus on four areas: identifying ICT assets; protecting them through measures such as securing external touchpoints, access controls, vulnerability scanning, rapid patching, backups, network segmentation and testing; detecting and responding quickly to incidents, including major-incident reporting to the FSMA where required; and pressing ICT service providers to apply equivalent safeguards. The FSMA also notes that the European Supervisory Authorities had identified 19 critical ICT third-party providers by the end of 2025, but stresses that firms remain responsible for supply-chain cyber resilience, particularly where providers are not designated critical. The FSMA expects all firms subject to DORA to implement these measures swiftly and says the same recommendations are relevant for firms outside DORA's scope.
Monetary policy developments
Rate decisions during the week of June 15–21 remained mostly unchanged, with 15 central banks maintaining rates, while eight raised them as broader inflation pressures and currency risks prompted more selective tightening. The Federal Reserve kept the fed funds range at 3.50–3.75%, citing solid activity but inflation still elevated partly because of energy-related supply shocks. The Bank of Japan raised its rate 25 bp to 1.0% as higher crude-oil costs were passing through business prices and medium-term inflation expectations continued to rise. Indonesia and the Philippines also increased rates by 25 bp, with Indonesia prioritising rupiah stability and the Philippines responding to inflation projected above its tolerance ceiling. Australia maintained the cash rate at 4.35% after three increases this year, judging that tighter financial conditions were beginning to slow demand while inflation remained too high and oil-supply disruption continued to affect prices. In Europe, the Bank of England held at 3.75% in a 7–2 vote, balancing weaker demand and a loosening labour market against the risk that higher energy costs could become more persistent. Switzerland kept its rate at 0%, with low inflation and a stronger franc limiting imported price pressure, while Sweden and Norway also maintained rates but indicated a greater likelihood of later increases if inflation pressures remain elevated. The announced U.S.-Iran memorandum lowered oil and gas prices ahead of several meetings, but central banks generally treated this as partial relief rather than evidence that the shock had fully passed. The Bank of England noted that energy prices remained above pre-conflict levels and continued to assess whether earlier increases would feed into wage- and price-setting, while the RBA stressed that restoring global oil supply would take time even if the conflict eased. The Bank of Japan judged that government support and alternative sources of supply had reduced downside risks to activity, but still raised rates because oil-related costs were spreading rapidly through business prices. Elsewhere, Chile noted that oil had fallen below USD 80 following the ceasefire announcement, but that longer-dated prices had declined much less and global supply had not normalised. Norges Bank similarly viewed the memorandum as a potential source of lower external price pressure if the Strait of Hormuz reopens and energy markets normalise, while Georgia and Moldova continued to emphasise uncertainty around the negotiations, the restoration of damaged infrastructure and the return of normal transit.