Home
DossiersLibraryAlerts
in
Download the iOS app

Global Regulator & Central Bank News Roundup

Edition 362026Week of September 7

Global developments

BRICSPolicy & regulation
BRICS Finance Ministers and Central Bank Governors set out priorities on global financial reform, payments and development finance

Following their first 2026 meeting in Jaipur in August, BRICS Finance Ministers and Central Bank Governors issued a joint statement, formally adopted at their September meeting in Mumbai, setting out priorities across the BRICS finance track. These include IMF and World Bank governance reform, development finance through the New Development Bank, cross-border payment interoperability and local currency settlement, and further work on the Contingent Reserve Arrangement. The statement also records initiatives on AI governance, cybersecurity, sustainable finance, insurance and customs cooperation.

Following their first meeting of 2026 in Jaipur in August, BRICS Finance Ministers and Central Bank Governors issued a joint statement, formally adopted when they reconvened in Mumbai in September, setting out the main outcomes and priorities of the BRICS finance track under India’s chairship. The statement calls for greater representation of emerging markets and developing economies in global financial institutions, including meaningful IMF quota and governance reform under the 17th General Review of Quotas and a World Bank shareholding realignment to address their historical underrepresentation. It also records progress across a wider program of cooperation spanning development finance, cross-border payments, financial stability, infrastructure, taxation, customs and emerging technologies. On development finance, the group welcomed preparatory work by the New Development Bank on a pilot phase of the BRICS Multilateral Guarantees initiative, intended to mobilize private capital, improve project creditworthiness and reduce financing costs, and supported continued technical work on a possible New Investment Platform through a consensus based, phased and member driven approach. The BRICS Payment Task Force is examining interoperability between payment and messaging channels and the use of local currencies for trade settlements and investment, with members calling for practical solutions that make cross-border payments faster, lower cost, more accessible, efficient, transparent and safe. Work is also continuing on amendments intended to improve the flexibility and responsiveness of the BRICS Contingent Reserve Arrangement. The statement also consolidates work on sustainable finance, cybersecurity and financial technology. BRICS members developed an Approach Paper on AI in Finance and an AI Governance and Enablement Toolkit, examined opportunities and risks from quantum computing, and supported further cooperation on RegTech, SupTech and the responsible deployment of emerging technologies. Other outcomes include the launch of the BRICS-NDB Knowledge Portal, continued work on a BRICS Insurance Resilience Centre and Risk Lab, and progress toward a Customs Mutual Administrative Assistance Agreement, with members able to do so giving in-principle approval subject to national processes.

MultiplePolicy & regulation
Committee on Payments and Market Infrastructures and International Organization of Securities Commissions seek input on cyber resilience toolkit and third-party risks for financial market infrastructures

The Committee on Payments and Market Infrastructures and the International Organization of Securities Commissions seek input on two publications addressing operational resilience at financial market infrastructures. The cyber resilience toolkit offers voluntary tools for governance, recovery planning and testing without changing existing standards. The third-party discussion paper examines how provider concentration, opaque supply chains and difficulties managing or exiting service relationships can amplify operational risks.

The Committee on Payments and Market Infrastructures (CPMI) and the International Organization of Securities Commissions (IOSCO) published two documents for stakeholder input on operational resilience at financial market infrastructures (FMIs). The Cyber Resilience Toolkit offers voluntary, nonbinding tools to support implementation of the Principles for Financial Market Infrastructures (PFMI) and complement the 2016 cyber resilience guidance. The accompanying discussion paper "FMIs’ Reliance on Third-Party Service Providers: Challenges and Risks" examines the difficulties FMIs face in managing their growing reliance on service providers, particularly for critical services. The cyber resilience toolkit describes how FMIs can strengthen board oversight through cyber skills assessments and use maturity models and metrics to identify weaknesses. Its approach to scenario design incorporates dependencies across an FMI’s ecosystem into extreme but plausible cyber scenarios. For response, resumption and recovery planning, the toolkit focuses on identifying the critical operations and information assets needed to resume operations safely within two hours of disruption. It also addresses scenarios in which data integrity problems prevent safe resumption within that timeframe, including contingency procedures to complete settlement by the end of the day. Clear disconnection criteria and verification before reconnection help contain contagion from compromised entities. The toolkit’s testing approaches include red team exercises, testing before and after significant system changes, and coordination with critical service providers and other interconnected entities. The third-party discussion paper shifts the focus to the structural and contractual challenges of managing service provider risks, including those arising from intragroup arrangements. It explains how interconnected operations and provider concentration can transmit disruption across the financial system, while opaque supply chains obscure critical dependencies. High switching costs and complex system architectures can make exit impracticable during stress, even where alternative providers exist. Limited bargaining power can also prevent FMIs from securing or enforcing audit rights, access to incident information and participation in provider testing. Differences in regulatory expectations across jurisdictions further complicate risk management.

Financial Action Task ForcePolicy & regulation
Financial Action Task Force publishes gaming and gambling risk indicators, highlighting threats from illegal operators

The Financial Action Task Force has published new gaming and gambling risk indicators, highlighting illegal and unlicensed offshore operators as a significant risk. Warning signs include moving funds without gambling, splitting transactions to avoid detection and unusually large or coordinated bets on events flagged for possible competition manipulation. FATF cautions that individual indicators are not conclusive and may not apply to all operators, while recommending stronger risk-based oversight, licensing controls, international cooperation and public-private information sharing.

The Financial Action Task Force (FATF) has published new risk indicators and findings on criminal abuse of gaming and gambling, identifying illegal and unlicensed offshore gambling as a significant risk. Its first detailed examination of online and illegal gambling found that illegal markets rival or exceed legal markets in some jurisdictions. Rapid, anonymous payments across borders and gaps in regulatory coverage create opportunities for abuse. Casinos and sports betting are particularly exposed to money laundering, while laundering through gaming appears smaller in scale or less sophisticated and frequent. Online gaming shows more documented terrorist financing misuse than gambling. Proliferation financing risks remain very limited in both sectors. Warning signs include moving funds through platforms with little or no gambling, splitting transactions into smaller amounts to avoid detection, and unusually large or coordinated bets on events flagged for possible competition manipulation. Other indicators include mismatches between customer and payment details and ownership arrangements that obscure beneficial ownership or bypass thresholds for regulatory checks. The indicators are primarily associated with land-based and online casinos, and to a lesser extent betting, and may therefore not be relevant to every operator or platform. FATF cautions that a single indicator does not necessarily point to money laundering, terrorist financing or proliferation financing and that some indicators may instead reflect problem gambling, although the presence of several indicators linked to a customer or transaction warrants further examination. To address the broader risks identified, FATF recommends a risk-based approach, stronger licensing and registration requirements to prevent criminals from controlling gambling operators, enhanced international cooperation particularly on online, illegal and cross-border gambling, and consideration of stronger public-private partnerships to improve information sharing and responses to emerging risks.

Bank for International SettlementsResearch
Bank for International Settlements paper finds financial authorities are reinforcing cyber resilience frameworks for frontier AI threats

A Bank for International Settlements paper finds that frontier AI is accelerating cyber threats by compressing the time between vulnerability discovery and exploitation, while also strengthening defensive capabilities. Financial authorities are responding mainly by reinforcing existing cyber resilience frameworks, with greater emphasis on faster patching, rapid decision-making, incident recovery and resilience to critical third-party dependencies.

The Bank for International Settlements has published a Financial Stability Institute paper assessing how frontier artificial intelligence is changing cyber risk for financial institutions and how authorities are responding. Frontier AI can autonomously identify vulnerabilities, develop working exploits and execute increasingly complex cyber operations, reducing the time, expertise and resources required for attacks and sharply compressing the window available for remediation. The same capabilities can strengthen vulnerability discovery, threat detection and incident response. While recent evaluations show that frontier models can autonomously compromise small, weakly defended systems, they do not establish that such models can independently breach well defended environments. Financial authorities are largely responding by adapting existing cyber risk management and operational resilience frameworks rather than creating separate AI-specific cyber regimes. The central shift is toward faster execution of established practices, with greater emphasis on governance that supports rapid decisions, accelerated patching, continuous reassessment of controls and stronger incident response, recovery and business continuity capabilities. Authorities are also focusing more closely on dependencies on cloud, software and frontier AI providers, including concentration and sovereign access risks. Institutions therefore need to understand critical third-party dependencies, test recovery arrangements with providers and maintain credible continuity and exit options, supported by timely information-sharing across firms, supervisors, cyber agencies and technology providers.

Active global consultations

BodyTitleStart dateClosing dateConsultation PaperFact Sheet
IOSCO, CPMIIOSCO, CPMIRisk managementFMIs’ reliance on third-party service providers: challenges and risks

The Committee on Payments and Market Infrastructures and the Board of the International Organization of Securities Commissions are seeking feedback on a discussion paper examining the risk management challenges arising from financial market infrastructures’ increasing reliance on third-party service providers, including for critical services. The paper reflects FMIs’ systemically important and highly interconnected role and focuses on how external and intra-group service arrangements can increase operational risk and create channels through which disruptions may be transmitted across the financial system. It does not propose additional guidance but seeks views on whether the identified challenges are comprehensive and whether further engagement or policy support would be beneficial. The paper identifies six principal challenges: increasing complexity and interconnectedness of FMI ecosystems, including cyber-related risk; concentration of third-party service providers and resulting single points of failure, vendor lock-in and systemic dependencies; complex and opaque supply chains and limited visibility of nth-party providers; difficulties designing practicable exit strategies and substituting providers, especially in stressed conditions; imbalances in bargaining power that can limit audit, information-sharing, testing and service-level rights; and variation in regulatory, supervisory and oversight expectations across jurisdictions.

FMIs’ reliance on third-party service providers: challenges and risks

The Committee on Payments and Market Infrastructures and the Board of the International Organization of Securities Commissions are seeking feedback on a discussion paper examining the risk management challenges arising from financial market infrastructures’ increasing reliance on third-party service providers, including for critical services. The paper reflects FMIs’ systemically important and highly interconnected role and focuses on how external and intra-group service arrangements can increase operational risk and create channels through which disruptions may be transmitted across the financial system. It does not propose additional guidance but seeks views on whether the identified challenges are comprehensive and whether further engagement or policy support would be beneficial. The paper identifies six principal challenges: increasing complexity and interconnectedness of FMI ecosystems, including cyber-related risk; concentration of third-party service providers and resulting single points of failure, vendor lock-in and systemic dependencies; complex and opaque supply chains and limited visibility of nth-party providers; difficulties designing practicable exit strategies and substituting providers, especially in stressed conditions; imbalances in bargaining power that can limit audit, information-sharing, testing and service-level rights; and variation in regulatory, supervisory and oversight expectations across jurisdictions.

Start date:2026-09-08Closing date:2026-12-012026-09-082026-12-01LinkView fact sheetView
IOSCO, CPMIIOSCO, CPMIOperational resilienceCyber resilience toolkit: practical considerations for FMIs

The Committee on Payments and Market Infrastructures (CPMI) and the Board of IOSCO are consulting on a voluntary, non-binding cyber resilience toolkit intended to provide financial market infrastructures with practical, technology-neutral support for strengthening their cyber resilience frameworks and implementing operational resilience-related components of the Principles for financial market infrastructures, as informed by the 2016 CPMI-IOSCO Guidance on cyber resilience for financial market infrastructures. The toolkit is organized around four areas: (1) governance of cyber risk and resilience, including board and senior management capabilities, ecosystem risk management, maturity models and resilience metrics; (2) identification and design of extreme but plausible cyber scenarios, including scenario scope, threat intelligence, emerging risks and ecosystem dependencies; (3) response, resumption and recovery planning, covering critical operations and information assets, infrastructure and data resilience, third-party dependencies, contingency arrangements, safe resumption and the disconnection and reconnection of ecosystem entities; and (4) cyber resilience testing and exercising.

Cyber resilience toolkit: practical considerations for FMIs

The Committee on Payments and Market Infrastructures (CPMI) and the Board of IOSCO are consulting on a voluntary, non-binding cyber resilience toolkit intended to provide financial market infrastructures with practical, technology-neutral support for strengthening their cyber resilience frameworks and implementing operational resilience-related components of the Principles for financial market infrastructures, as informed by the 2016 CPMI-IOSCO Guidance on cyber resilience for financial market infrastructures. The toolkit is organized around four areas: (1) governance of cyber risk and resilience, including board and senior management capabilities, ecosystem risk management, maturity models and resilience metrics; (2) identification and design of extreme but plausible cyber scenarios, including scenario scope, threat intelligence, emerging risks and ecosystem dependencies; (3) response, resumption and recovery planning, covering critical operations and information assets, infrastructure and data resilience, third-party dependencies, contingency arrangements, safe resumption and the disconnection and reconnection of ecosystem entities; and (4) cyber resilience testing and exercising.

Start date:2026-09-08Closing date:2026-12-012026-09-082026-12-01LinkView fact sheetView

Regional developments

Asia & PacificMultiple
Hong Kong's Insurance Authority launches Climate Insurance Lab and Hong Kong Monetary Authority consults on Phase 2B expansion of sustainable finance taxonomy

Hong Kong authorities advanced separate climate finance initiatives focused on strengthening the financial sector's response to climate risks and supporting the low-carbon transition. The Insurance Authority launched the Climate Insurance Lab to strengthen insurer data, regulatory readiness and product development, while the Hong Kong Monetary Authority is consulting on Phase 2B of the Hong Kong Taxonomy for Sustainable Finance, which expands covered economic activities and introduces a process approach to climate adaptation.

Policy & regulationClimate risk and sustainable finance

Hong Kong authorities advanced separate initiatives aimed at strengthening the financial sector's response to climate risks and supporting the transition to a low-carbon economy. The Insurance Authority (IA) unveiled its Climate Strategy and launched the Climate Insurance Lab (CIL) to strengthen insurer capabilities in climate risk data, regulatory readiness and product development. Separately, the Hong Kong Monetary Authority (HKMA) launched consultation on the Phase 2B prototype of the Hong Kong Taxonomy for Sustainable Finance, expanding the framework's coverage of green and transition activities and climate adaptation. The CIL is designed around shared data infrastructure, practical regulatory guidance and a Product Innovation Platform. Its components include a Climate Risk Portal to narrow data gaps, support scenario testing and provide actuarial models for pricing and product development, alongside work to enhance the ORSA process and develop a comprehensive regulatory framework for sustainability disclosures. The Product Innovation Platform will use cross sector dialogue, workshops and pilot projects to identify priority areas and test viable product concepts. The IA also presented findings from a Climate Modelling Project with the Hong Kong Federation of Insurers and The Hong Kong University of Science and Technology that uses high resolution climate models to support spatial climate risk assessment, underwriting and product innovation. Phase 2B adds 10 economic activities and, after reclassifying some existing activities, increases the total number of activities from 25 to 39. It adds enabling technologies such as battery manufacture and recycling and the manufacture of low carbon technologies, provides transition pathways for sectors including air transport and iron and steel, and introduces a process approach for climate adaptation with 24 measures, comprising 11 whitelist and 13 non-whitelist measures, initially focused on shoreline protection and flood management. Phase 2B also defines four additional environmental objectives covering biodiversity and ecosystems, water resources, pollution prevention and control, and resource efficiency and the circular economy, completing a six objective framework, although the current phase remains focused on climate mitigation and adaptation. The taxonomy is currently designed for voluntary adoption, with incorporation into banking supervisory policies to be explored over the longer term.

Asia & PacificPhilippines Securities and Exchange Commission
Philippines' Securities and Exchange Commission consults on revised crowdfunding rules and investor safeguards

The Philippines' Securities and Exchange Commission is consulting on revised crowdfunding rules covering offering limits and investor safeguards. The draft would allow offerings up to PHP 100 million, with offerings above PHP 25 million restricted to qualified investors. Proposed protections include segregated investor funds, a retail cooling-off period of at least five business days, and credit assessment and backup servicing requirements for debt platforms.

Policy & regulationCrowdfunding

he Philippines' Securities and Exchange Commission (SEC) has opened a consultation on revisions to its 2019 crowdfunding rules, covering offering limits and safeguards for online equity and debt crowdfunding. Under the proposed securities registration exemption, eligible issuers could offer an aggregate of up to PHP 25 million to any investors over 12 months, while offerings above PHP 25 million and up to PHP 100 million would be restricted to qualified investors. Retail investors' aggregate purchases across issuers over 12 months would be capped at 5% of total annual income for those earning up to PHP 2 million and 10% for those earning more. Qualified investors would be exempt from these investor limits. Intermediaries would have to hold investor funds in segregated trust or escrow accounts and reconcile them daily. Retail investors would receive a cooling-off period of at least five business days before funds could be released. The draft would prohibit intermediaries from acquiring interests in offerings on their platforms or hosting offerings by specified connected parties. Debt platforms would have to publish their credit assessment methodologies and make each issuer's assessment result or grade available before accepting investment commitments. Each offering would disclose effective interest rates, all fees and total borrowing costs. Investors would have to be notified within five business days of defaults or arrears exceeding 30 days, with platforms required to pursue recovery on investors' behalf and provide regular updates. A regulated backup servicer would have to be appointed before any debt offering. Quarterly disclosures would show loans or debt securities more than 90 days past due as a share of total outstanding debt, alongside default and recovery rates.

Asia & PacificSecurities and Exchange Board of India
Securities and Exchange Board of India launches Demat 2.0 pilot for tokenised corporate bonds with INR 1,025 crore issued by three companies

The Securities and Exchange Board of India has launched Demat 2.0, a pilot for tokenised corporate bonds that uses distributed ledger technology and wholesale central bank digital currency to enable atomic settlement and automated servicing. Three companies have issued INR 1,025 crore of bonds so far. Later phases are expected to add secondary-market trading through existing request-for-quote platforms and retail investor access.

Implementation, projects & pilotsTokenization

The Securities and Exchange Board of India (SEBI) has launched Demat 2.0, a pilot market infrastructure for issuing, holding, trading and settling corporate bonds as digital tokens on a distributed ledger maintained by statutory depositories. The infrastructure connects to the Reserve Bank of India’s wholesale central bank digital currency through its Unified Market Interface, enabling atomic settlement of the securities and funds legs. Smart contracts can also automate interest and redemption payments to bondholders’ CBDC wallets. Three companies have issued tokenised bonds totaling INR 1,025 crore. REC Limited raised INR 500 crore from 18 investors, L&T Limited raised INR 500 crore from four investors, and IIFL raised INR 25 crore from one investor. The model allows issuers to receive funds on the day of bidding rather than two to three days later, provides investors with immediate funds in secondary-market transactions, reduces manual processing and reconciliation, and eliminates settlement risk through atomic settlement. The underlying bonds and investor protections remain unchanged, including requirements for credit ratings, debenture trustees, listing and disclosures. First-phase issuances are ongoing. Later phases are expected to extend the pilot to secondary-market trading through existing request-for-quote platforms and to retail investors, with experience from the pilot informing any wider rollout. Investors will hold the tokenised bonds in their existing demat accounts without a new account or fresh know-your-customer process, but must enable Demat 2.0 with their depository and maintain a wholesale CBDC wallet with a participating bank.

Asia & PacificAustralian Prudential Regulation Authority
Australian Prudential Regulation Authority revises Retirement Reporting Framework proposals for final consultation

The Australian Prudential Regulation Authority has substantially revised its proposed Retirement Reporting Framework standards, reducing reporting complexity and refining retirement status, drawdown, balance utilisation, lifetime income product and financial advice measures. The standards are expected to be finalised by the end of 2026, with data collection beginning in late 2027 and the first Framework results published in 2028.

Policy & regulationRegulatory reporting

The Australian Prudential Regulation Authority (APRA) has substantially revised its proposed reporting standards for the Government’s Retirement Reporting Framework following industry feedback, reducing reporting complexity while refining the metrics and indicators used to assess member outcomes in retirement. The changes restructure the proposed retirement member profile reporting requirements to reduce reporting granularity and reliance on event-based transaction data, simplify age and member benefit cohorts, and replace broad retirement status classifications with a distinction based on whether members commenced a retirement income stream during the reporting period. APRA has also issued a draft reporting practice guide to support consistent reporting. APRA has revised several methodologies and data requirements. Average pension drawdown will be calculated using actual pension payments rather than selected drawdown rates, while purchase price will remain the denominator for the balance utilisation metric, supplemented by a new years pension held attribute and a derived average balance at death. The investment-linked indicator will extend beyond annuities to other lifetime income products, with additional indicators for deferred products and innovative retirement income streams. APRA has also refined reporting on access to personal financial advice and made targeted exclusions and structural changes affecting legacy products, defined benefit pensions and product access pathways. Publication design and contextualisation will be developed through further industry engagement in 2027, with masking and aggregation used to protect member information. APRA intends to finalise the reporting standards and supporting guidance by the end of 2026, with the first data collection expected in late 2027 and the first Framework indicators and metrics published in 2028. It also intends to revoke an existing retirement income reporting standard by 30 June 2027, with transition guidance to accompany the change.

Asia & PacificDepartment of Internal Affairs
New Zealand's Department of Internal Affairs identifies elevated trust and company service risks and persistent AML control weaknesses in accounting sector

New Zealand's Department of Internal Affairs rates trust and company services and trust accounts as the accounting sector's most vulnerable activities, citing misuse of complex legal structures, nominees, shell companies and client accounts to conceal ownership, obscure fund origins and give transactions apparent legitimacy. The assessment also flags rising cyber-enabled fraud, increasing cryptocurrency use and cross-border laundering exposures, while trust and company services face elevated terrorism and proliferation financing vulnerability. Controls are only moderately effective, with recurring weaknesses in ongoing monitoring, enhanced due diligence and documentation, and very low suspicious activity reporting.

SupervisionAML and CFT

New Zealand's Department of Internal Affairs has assessed the accounting sector as having Medium inherent money laundering vulnerability and Low-Medium residual risk, with trust and company services and trust accounts rated Medium-High. Trust and company services are particularly exposed because legal persons, trusts, nominee arrangements, shell companies and cross-border structures can obscure beneficial ownership and effective control, create distance between criminals and illicit assets, and lend apparent legitimacy through professional involvement. Trust accounts create a more direct exposure by allowing criminal proceeds already in the financial system to be routed through an accounting practice, obscuring the origin of funds and making onward payments appear to come from a trusted professional. Insolvency services and other management of client funds or assets are rated Medium, reflecting risks including concealment of audit trails, asset stripping, manipulation of creditor payments and misuse of an accountant's authority over client accounts. The assessment also points to evolving exposures. Cyber-enabled fraud volumes and values are expected to rise, with cryptocurrency increasingly used to move fraud proceeds, while accounting practices have significant exposure to the subsequent layering and integration of fraud and drug proceeds and to transnational laundering involving high-value transactions, foreign clients and New Zealand legal structures. Complex international money laundering networks may combine legal persons, multiple financial institutions, gatekeepers and trade-based laundering techniques. Proliferation financing remains Low overall, but trust and company services are rated Medium-High because shell companies and non-transparent corporate structures can support procurement, trade and revenue-raising activities, particularly where clients, transactions or intermediaries have links to North Korea or Iran. Controls are rated only Moderate, with recurring weaknesses in implementation rather than the absence of formal frameworks. Ongoing customer due diligence and account monitoring are less consistently applied than standard due diligence, alongside deficiencies in enhanced due diligence and in examining and documenting high-risk clients, activities and transactions. Some trust and company service providers still identify an instructing law firm, service provider or accounting practice as the customer instead of the legal person or arrangement being acted for. Suspicious activity reporting is also persistently low: only 111 reports were filed between October 1, 2018, and December 31, 2025, by about 6% of practices, with relatively few concerning trust and company services, leading DIA to conclude that some reportable activity is likely not being identified. Wider supervisory gaps remain because there is no mandatory registration with DIA, some reporting entities are likely unknown and outside active supervision.

EuropeEuropean Securities and Markets Authority
European Securities and Markets Authority warns of abrupt market corrections in latest risk assessment

In its second Trends, Risks and Vulnerabilities Risk Monitor of 2026, the European Securities and Markets Authority warns that elevated valuations and investor optimism are increasingly disconnected from weaker economic conditions and geopolitical risks, raising the prospect of abrupt market corrections. EU investors are particularly exposed through concentrated holdings of US equities, while lower fund liquidity and expanding links to private credit and crypto-assets add further transmission channels. Frontier artificial intelligence is also intensifying cyber and operational risks across the financial system.

SupervisionRisk monitoring & watch points

In its second Trends, Risks and Vulnerabilities Risk Monitor of 2026, the European Securities and Markets Authority (ESMA) warns that resilient markets are masking a widening gap between deteriorating macro-financial conditions and elevated valuations, increasing the risk of abrupt market corrections. The recurring assessment, covering developments in EU financial markets during the first half of 2026, finds that technology and artificial intelligence stocks have helped sustain market valuations despite weaker growth, persistent inflation and heightened geopolitical tensions. ESMA continues to assess market, contagion and operational risks as very high and credit risk as high, and urges retail and institutional investors to maintain robust liquidity buffers against sharp repricing. A correction in US technology stocks could transmit quickly to EU investors, with US equities accounting for 45% of EU equity fund assets and retail investors also increasingly concentrated in US shares. Vulnerabilities extend beyond equities: sovereign bond volatility has risen as yields increased, bond funds’ liquid asset holdings fell to a five-year low, and growing links to US private credit and crypto-assets create additional channels for spillovers. Operational risks are also rising as frontier artificial intelligence compresses the time between vulnerability discovery and exploitation. ESMA warns that cyberattacks affecting systemic financial institutions, market infrastructures or shared technology providers could propagate across the financial system, reinforcing the need for stronger operational resilience, third-party oversight, incident reporting and coordinated testing.

EuropeEuropean Securities and Markets Authority
European Securities and Markets Authority issues Listing Act prospectus package, consults on disclosure guidance and finalizes product supplement rules

The European Securities and Markets Authority has issued a Listing Act package covering prospectus disclosure guidance, Q&As, product supplements and summary financial information. Proposed disclosure guidelines remove obsolete material and add targeted guidance on management reports, profit forecasts and related party transactions. Final product supplement rules define when a new base prospectus is required, while revised technical standards reduce historical financial information requirements.

Policy & regulationSecurities offerings and listings

The European Securities and Markets Authority (ESMA) has issued a package aligning prospectus guidance and technical standards with the Listing Act’s streamlined disclosure framework. Building on its earlier clarification of transitional arrangements, the package consults on revised disclosure guidelines, updates prospectus Q&As, finalizes guidelines on when a supplement introduces a new type of security and submits revised requirements for key financial information in prospectus summaries to the European Commission. The proposed disclosure guidelines would remove guidance tied to deleted requirements, add rules for ensuring consistency between management reports and the rest of a prospectus, and require issuers without management reports to include equivalent material information needed for an informed investment decision. They would also consolidate guidance on profit forecasts and risk factors, delete the historical financial information bridge approach following the reduction in required reporting periods, and clarify related party transactions by reference to International Accounting Standard 24. ESMA proposes reducing the framework from 57 guidelines in 18 sections to 49 guidelines in 14 sections. The final product supplement guidelines use prospectus disclosure annexes and product classes to determine when a new base prospectus is required, with refined tests for structured products, asset-backed securities and securities linked to environmental, social and governance factors. Sustainability-linked non-equity securities cannot be introduced by supplement if absent from the base prospectus, while ESG use-of-proceeds disclosures may be added. The revised technical standards shorten historical financial information periods and remove the cash flow table for non-equity securities. The product supplement guidelines will apply two months after publication in all official EU languages, while ESMA expects to publish the final updated disclosure guidelines in the second quarter of 2027.

EuropeCentral Bank of Latvia
Central Bank of Latvia implements offline card payments up to EUR 200 for essential goods during communications outages

The Central Bank of Latvia has implemented offline card payments for essential goods during internet or mobile communications outages. Customers of four designated banks can spend up to EUR 200 per card at participating grocery, fuel and pharmacy chains by inserting a physical card and entering the PIN. The service does not support smart device payments and requires electricity at the merchant.

Policy & regulationPayments and payment systems

The Central Bank of Latvia, working with critical financial service providers and merchants, has implemented offline card payments for essential goods when internet or mobile communications are disrupted. Individuals can make purchases totaling up to EUR 200 per card at participating food retailers, petrol stations and pharmacies, extending Latvia’s crisis payment resilience framework beyond access to cash and the critical ATM network. The service covers three grocery chains, four fuel retailers and three pharmacy chains. It is available only for cards issued by Swedbank, SEB banka, Citadele banka and Luminor Bank’s Latvian branch. Customers must insert a physical card into the terminal and enter the PIN. Smart device payments are not supported, and the service cannot operate if the merchant loses electricity.

EuropeBank of France
Bank of France introduces machine learning indicator for daily market implied recession risk in the United States and euro area

The Bank of France has introduced PICON, a machine learning indicator that uses daily financial market data to measure perceived recession risk in the United States and euro area. It combines signals across asset classes and distinguishes macroeconomic concerns from purely financial stress, but is not a recession forecast. The indicator placed the probability of a euro area recession within two quarters at 21% as of April 14, 2026.

ResearchArtificial intelligence

The Bank of France has published an article introducing the market-implied probability of economic contraction indicator, or PICON, which uses machine learning to measure how financial markets perceive recession risk in the United States and euro area. The indicator applies a random forest model to daily data across equities, sovereign and corporate bonds, currencies, commodities and derivatives, allowing it to capture interactions that yield curve models alone may miss. It should be interpreted as a measure of market perceptions rather than a recession forecast. The model identified three of the four U.S. recessions since 1990 with probabilities above 50% and produced fewer false signals than a benchmark yield curve model during 2022-24. In the 2022-25 test period, it distinguished stress associated with economic concerns, including the European energy crisis, banking failures, prolonged high interest rates and U.S. tariff announcements, from episodes of mainly financial stress. Asset classes contribute differently across time horizons, with equities and credit providing more information in the short term and yield curve slopes becoming dominant after three or four quarters. Against the backdrop of the war in Iran, PICON placed the market-implied probability of a euro area recession within two quarters at 21% as of April 14, 2026.

Latin America & CaribbeanCentral Bank of Brazil
Central Bank of Brazil expands social, environmental and climate risk disclosures across

The Central Bank of Brazil has expanded social, environmental and climate risk reporting across most of the regulated financial sector, from the largest and internationally active banks to smaller institutions, with requirements scaled by institution size. Larger and medium-sized institutions will provide detailed standardized risk metrics, while smaller institutions will face a narrower set of disclosures. Most requirements take effect on January 1, 2027, with additional implementation time for specified disclosures by medium-sized and smaller institutions.

Policy & regulationDisclosures

The Central Bank of Brazil has approved new requirements for the Social, Environmental and Climate Risks and Opportunities Report, expanding disclosures to include standardized quantitative metrics alongside enhanced qualitative information. The rules apply across the four main prudential categories covered by the framework, ranging from the largest and internationally active banks to smaller regulated institutions, although the extent of disclosure varies by institution size. The changes are intended to make institutions’ exposures and risk management practices more comparable, including through standardized disclosure of climate transition plans, where they exist, and voluntary social, environmental and climate commitments. The largest, large and medium-sized institutions will be subject to the full reporting framework, covering governance, strategy and risk management as well as detailed climate, social and environmental risk exposures. Required disclosures include exposures to greenhouse gas intensive sectors, agricultural exposures by crop and livestock activity, geographic exposure to drought and heavy rainfall risks, and exposures to counterparties subject to environmental sanctions or with tailings dams at emergency levels. Smaller institutions in the fourth prudential segment, broadly those below 0.1% of Brazil’s GDP that are not in the separate simplified regime, will face narrower requirements focused on governance and social, environmental and climate commitments. Most provisions take effect on January 1, 2027. Reports must be published annually using a December 31 reference date and generally within 90 days, with additional time permitted for the first report. Medium-sized and smaller institutions may defer specified new disclosures until the December 31, 2028 reference date. Reports must remain publicly available on institutions’ websites for five years and the required information must also be provided in open data format.

Middle East & AfricaJordan Securities Commission
Jordan Securities Commission launches ESG Code with mandatory ASE20 application from financial year 2027

The Jordan Securities Commission has launched its ESG Code, requiring ASE20 companies to apply it from financial year 2027 under an apply and explain approach, with first mandatory sustainability reports due in 2028. The framework aligns disclosures with IFRS S1 and IFRS S2 and introduces governance, board composition, risk management and sustainability reporting requirements, with transitional relief available during the first reporting period.

Policy & regulationESG

The Jordan Securities Commission has launched its Environmental, Social and Governance Code, moving from its earlier approval and announced rollout plans to a mandatory first phase for the 20 companies in the Amman Stock Exchange ASE20 index from financial year 2027. Those companies must apply the code under an apply and explain approach, while the Commission plans to extend the framework to other listed companies in later phases. The code aligns sustainability reporting with IFRS S1 and IFRS S2 and establishes broader governance, risk management and disclosure requirements around sustainability and climate related risks and opportunities. The framework requires ASE20 companies to issue a separate annual sustainability report containing IFRS S1 and IFRS S2 information, with the first reporting under the mandatory regime due in 2028. Governance requirements include at least one woman on the board, at least one board member with sustainability and climate risk expertise and at least one third independent directors. Companies must also establish board committee arrangements covering governance, sustainability, audit, risk, and nominations and remuneration, while integrating sustainability into internal controls, risk management, compliance, executive responsibilities and remuneration frameworks. Transitional relief is available in the first reporting period, including exemptions from comparative information and, where used, the option to focus initially on climate related disclosures, as well as relief for Scope 3 greenhouse gas emissions under IFRS S2. The code also allows the first year sustainability report to include an assessment plan for achieving full IFRS S1 and IFRS S2 compliance, while other issuers may adopt the framework voluntarily ahead of any later mandatory expansion.

Middle East & AfricaCentral Bank of Kenya
Central Bank of Kenya consults on revised banking rules and systemic bank capital buffers of up to 2.5%

The Central Bank of Kenya is consulting on revised banking rules and a framework for domestic systemically important banks. The risk management draft specifies minimum liquidity coverage and net stable funding ratios of 100%. Systemic banks would hold additional Common Equity Tier 1 capital of 0.5% to 2.5% of risk weighted assets and face closer supervision, including quarterly stress tests.

Policy & regulationFinancial stability and systemic risk

The Central Bank of Kenya (CBK) is consulting on revised Prudential Guidelines, Risk Management Guidelines and Guidance Notes, alongside a framework that would impose additional capital buffers and closer supervision on domestic systemically important banks (D-SIBs). The risk management draft would apply to all institutions licensed under the Banking Act, using an enterprise risk management approach and the Three Lines of Defense model. It specifies minimum Liquidity Coverage Ratio and Net Stable Funding Ratio levels of 100%. Operational risk capital would be calculated under the Basel III Standardized Approach. Institutions would establish disruption tolerances for critical operations and test their ability to withstand severe but plausible scenarios. They would also independently validate material models, maintain exit plans for material third party arrangements and incorporate material environmental, social and governance risks into internal capital and liquidity adequacy assessments. The D-SIB framework would use indicators of systemic importance and supervisory judgment to identify systemic banks. Annual assessments would allocate designated banks to three capital buckets, requiring additional Common Equity Tier 1 capital of 0.5%, 1.5% or 2.5% of risk weighted assets. These buffers would apply at both standalone and consolidated levels, in addition to minimum capital requirements and the capital conservation buffer. Designated banks would conduct quarterly stress tests and at least annual internal capital and liquidity adequacy assessments. Recovery and resolution plans would be updated and submitted to CBK annually by April 30. Newly designated banks and those moving to higher capital buckets would have up to 12 months after notification to comply, with action plans approved by the board required within three months.

Middle East & AfricaUAE Cabinet
UAE Ministerial Council for Artificial Intelligence and Development reviews second phase of Agentic AI Project, including FedAI and government use cases

The UAE Ministerial Council for Artificial Intelligence and Development reviewed the second phase of the Agentic AI Project, including FedAI, a national technical ecosystem for federal entities, and a customer experience lab. The review follows first phase work on capability building and prioritisation, with selected ministry and federal entity projects set to launch using Agentic AI in the next phase. The project forms part of the government's wider plan to deploy Agentic AI across 50% of government sectors, services and operations within two years.

Implementation, projects & pilotsArtificial intelligence

The UAE Ministerial Council for Artificial Intelligence and Development reviewed the strategy and second phase of the Agentic AI Project, including a unified national framework for expanding Agentic AI across federal government work. The project advances the government framework announced earlier in 2026 to deploy Agentic AI across 50% of government sectors, services and operations within two years. Key initiatives include FedAI, a national technical ecosystem designed to enable federal entities to develop, adopt and operate Agentic AI solutions within a flexible and secure environment, as well as a customer experience lab and internal government challenges to engage employees in developing solutions. The Council also reviewed results from the first phase, which focused on building government capabilities, assessing services, operations and tasks, and setting priorities. Projects submitted by ministries and federal entities will be launched using Agentic AI in the coming phase

Middle East & AfricaDubai Financial Services Authority,
Dubai Financial Services Authority, Hong Kong Monetary Authority and exchanges establish strategic working group

The Dubai Financial Services Authority, Hong Kong Monetary Authority, Nasdaq Dubai and Hong Kong Exchanges and Clearing Limited have formed a Strategic Working Group to strengthen links between the Dubai International Financial Centre and Hong Kong. It will pursue collaboration in sustainable and Islamic finance, innovation, capital markets development and market connectivity.

CooperationClimate risk and sustainable finance

The Dubai Financial Services Authority (DFSA), Hong Kong Monetary Authority (HKMA), Nasdaq Dubai and Hong Kong Exchanges and Clearing Limited have established a Strategic Working Group to deepen cooperation and market connectivity between the Dubai International Financial Centre and Hong Kong. The group will explore joint initiatives in sustainable finance, Islamic finance, innovation and broader capital markets development. Operating under signed terms of reference, the group will provide a formal mechanism for the regulators and exchanges to align priorities, exchange market insights and identify practical opportunities linking issuers and investors across the Middle East and Asia. The initiative builds on their existing regulatory and market dialogue and was announced at the third Hong Kong Monetary Authority and Dubai Financial Services Authority Joint Climate Finance Conference.

Middle East & AfricaSecurities and Exchange Commission Ghana
Ghana Securities and Exchange Commission launches consultation on securities lending, borrowing and short selling guidelines

The Ghana Securities and Exchange Commission is consulting on draft guidelines for securities lending and borrowing and short selling, covering eligible securities and participants, collateral, operational controls, reporting and voting practices. The framework would permit covered short selling by specified market participants and introduce notification and public disclosure thresholds for net short positions, while allowing the Commission to restrict short selling where market stability or orderly trading is at risk.

Policy & regulationShortselling

The Ghana Securities and Exchange Commission has launched a consultation on draft guidelines establishing a regulatory framework for securities lending and borrowing and short selling. The framework would apply to transactions conducted on an exchange or approved trading system and sets requirements covering eligible securities and participants, approved contractual arrangements, risk management and operational controls, collateral, settlement, record keeping and reporting. Securities lending and borrowing transactions would generally require collateral of at least 100% of the value of the loaned securities, with daily revaluation and corresponding collateral adjustments. For short selling, the draft would permit covered transactions where the seller has borrowed, arranged to borrow or otherwise has a documented basis to expect timely delivery of the securities. Short sales would generally be limited to Government of Ghana benchmark bonds and exchange traded shares with a designated market maker, and could be undertaken by licensed market makers, primary dealers and other persons approved by the Commission. Net short positions in shares would trigger notification to the Commission at 0.1% of issued share capital and each 0.1% increment above that level, while positions of 0.5% and above would also require public disclosure. Net short positions in Government of Ghana bonds would require notification at 0.5% of the relevant issue. The Commission could also suspend or impose conditions on short selling in response to significant price falls, restrictions imposed in other jurisdictions or concerns over market stability or orderly trading.

Middle East & AfricaMinistry of Finance (Madagascar)
Madagascar's Ministry of Economy and Finance sets four priorities as country assumes ESAAMLG presidency

Madagascar has assumed the ESAAMLG presidency for September 2026 through August 2027. It will prioritize the third mutual evaluation cycle, illicit financial flows involving natural resources and environmental crime, statistical management and risk based supervision of virtual asset service providers.

Policy & regulationAML and CFT

Madagascar's Ministry of Economy and Finance announced that the country has assumed the presidency of the Eastern and Southern Africa Anti-Money Laundering Group (ESAAMLG) from Rwanda for September 2026 through August 2027. Its priorities are to lead the third mutual evaluation cycle, intensify action against illicit financial flows linked to natural resources and environmental crime, establish a statistical management system and strengthen risk based supervision with a focus on virtual asset service provider compliance. Minister of Economy and Finance Ramiarison Herinjatovo Aimé has become chair of the ESAAMLG Council of Ministers, while the director general of SAMIFIN has assumed the chair of its Task Force of Senior Officials. Madagascar will host the next ESAAMLG Council of Ministers meeting in August 2027.

North AmericaCanadian Securities Administrators
Canadian Securities Administrators publishes data portability report, defers live testing pending federal consumer-driven banking framework

he Canadian Securities Administrators found that data portability could reduce Know Your Client and onboarding friction but deferred live testing while the federal consumer-driven banking framework develops. Stakeholders highlighted regulatory uncertainty over Know Your Client obligations, along with privacy, security, consent and standardization challenges, and reached no consensus on an implementation model. CSA staff will monitor the federal framework and industry standards and may use the findings to inform future regulatory and supervisory work.

Policy & regulationKYC

The Canadian Securities Administrators published a report concluding that data portability could reduce duplication in Know Your Client processes and make it easier for investors to switch providers or open accounts with multiple firms. However, CSA staff decided not to proceed with a planned live testing phase at this time, reflecting stakeholder preference to first see the development and implementation of the federal consumer-driven banking framework, which is expected to establish foundational data-sharing standards relevant to investment firms. Stakeholders broadly supported greater data portability but identified regulatory uncertainty, privacy and security risks, consent management and a lack of common data standards as key barriers. In particular, firms sought clarity on how existing Know Your Client requirements concerning delegation and meaningful client interaction would apply when third-party portability providers are used. There was no consensus on a preferred implementation model, although stakeholders generally viewed governance, security, consent management, interoperability and accountability as central considerations and favoured limiting mandatory portability to raw factual client data rather than proprietary assessments or derived analytics. CSA staff will monitor the federal framework and industry standards, while the project findings may inform future rulemaking, guidance, policy and supervisory work.

North AmericaOffice of the Superintendent of Financial Institutions
Canada's Office of the Superintendent of Financial Institutions finalizes revised interest rate risk management guideline with updated shock scenarios and earnings measures

The Office of the Superintendent of Financial Institutions has finalized revised interest rate risk management expectations, updating prescribed shock scenarios and clarifying earnings-based measures, including a constant balance sheet approach as the minimum expectation. The guideline also moves detailed disclosure requirements to the Pillar 3 framework and takes effect on November 1, 2026 or January 1, 2027 depending on institutions' fiscal year-end.

Policy & regulationRisk management

The Office of the Superintendent of Financial Institutions has published the final Guideline B-12 on interest rate risk in the banking book, updating the prescribed interest rate shock scenarios and clarifying expectations for earnings-based measures in line with the Basel Committee on Banking Supervision's 2024 targeted amendments. The guideline applies to banks, bank holding companies and federally regulated trust and loan companies. It requires institutions to assess interest rate risk using both economic value and earnings-based measures, with a constant balance sheet approach as the minimum expectation for earnings sensitivity. The revised framework retains six prescribed shock scenarios for economic value of equity and two for net interest income, with Canadian dollar shocks of 200 basis points for the parallel scenario, 275 basis points for the short-term scenario and 175 basis points for the long-term scenario. OSFI has also removed detailed public disclosure requirements from Guideline B-12 and instead refers institutions to its Pillar 3 disclosure framework. The guideline takes effect on November 1, 2026 for institutions with an October 31 fiscal year-end and January 1, 2027 for institutions with a December 31 fiscal year-end. OSFI plans to finalize the related Pillar 3 amendment for interest rate risk on November 19, 2026.

North AmericaMultiple
United States’ Federal Deposit Insurance Corporation, Federal Reserve Board, National Credit Union Administration and Office of the Comptroller of the Currency propose tailored third-party risk management guidance

U.S. banking and credit union regulators are consulting on nonbinding guidance that would replace the 2023 third-party risk management framework, calibrating oversight to the assessed risk of each relationship and allowing residual risk to be accepted within an institution’s risk appetite and tolerances. Separately, banking regulators set out transparency, contract and technology factors that will guide supervision of core providers serving community banks.

Policy & regulationOutsourcing and third-party risk management

The Federal Deposit Insurance Corporation, Federal Reserve Board, National Credit Union Administration and Office of the Comptroller of the Currency are consulting on revised third-party risk management guidance for banks and insured credit unions. The nonbinding proposal would replace the 2023 interagency guidance and related supplemental resources and is designed to address concerns that the existing framework has been applied too broadly and prescriptively. It would anchor third-party risk management in the risks of each relationship, with practices tailored to the institution’s size, complexity and risk profile and to the nature of the third-party arrangement. The proposed framework covers four areas: risk identification and assessment, risk oversight, residual risk acceptance and governance. Risk assessments would consider both the magnitude and likelihood of harm, while due diligence, contract negotiations and ongoing monitoring would be proportionate to the risks presented by the relationship. The proposal does not prescribe generally applicable contract terms, including for higher-risk relationships, and departure from the guidance or its examples would not, by itself, provide a basis for supervisory action. Institutions could also accept residual risks that remain after mitigation where those risks fall within their risk appetite and tolerances and the institution continues to operate in a safe and sound manner. Separately, the FDIC, Federal Reserve Board and OCC issued a statement on community banks’ relationships with core service providers. In allocating supervisory resources to core providers, the agencies will consider provider transparency, contract practices and technology capabilities, including access to due diligence information, pricing and billing practices, deconversion fees, restrictions on integrating alternative providers, security incidents, management of end-of-support and end-of-life assets, and operational resilience. The agencies may also determine that certain core providers qualify as institution-affiliated parties under the Federal Deposit Insurance Act and may bring appropriate actions where providers engage in, or cause a community bank to engage in, unsafe or unsound practices or violations of law. Community banks remain responsible for safe and sound operations and legal compliance where activities are outsourced.

North AmericaNew York State Department of Financial Services
New York State Department of Financial Services clarifies cybersecurity risk assessment expectations for regulated entities

The New York State Department of Financial Services clarified how regulated entities should conduct and use cybersecurity risk assessments required under its Cybersecurity Regulation. Assessments must directly inform cybersecurity controls and risk acceptance, be updated at least annually and after material changes, and address areas including assets and data flows, emerging threats, third-party and concentration risk, governance and documentation. DFS also highlighted recurring supervisory weaknesses where assessments are incomplete, inconsistently applied or insufficiently linked to cybersecurity and resource decisions.

Policy & regulationCyber resilience

The New York State Department of Financial Services issued guidance clarifying how regulated entities should conduct and use cybersecurity risk assessments required under the DFS Cybersecurity Regulation, known as Part 500. The guidance creates no new obligations but reinforces that assessments must be sufficiently detailed to inform the design and operation of cybersecurity programs, reviewed and updated at least annually and whenever changes in the business or technology materially alter cyber risk. DFS expects entities to demonstrate how identified risks inform control selection, compensating controls and risk acceptance, with assessments tailored to each entity’s size, complexity, operations and risk profile. The guidance focuses on governance and oversight, a defined and repeatable methodology, comprehensive scope, documentation and traceability, and integration of assessments into the broader cybersecurity program. Assessments should draw on relevant threat intelligence, incident trends, vulnerability testing and other available inputs and cover assets and data flows, emerging technologies and threats, third-party and supply chain exposures, and cyber interdependencies and concentration risk, including potential single points of failure. Entities should maintain documentation linking identified risks to controls, remediation or risk acceptance decisions and use mechanisms such as risk registers to track remediation and changes in residual risk over time. DFS said examinations and investigations have identified recurring weaknesses including incomplete asset coverage, inconsistent risk methodologies, insufficient treatment of evolving and interconnected risks, weak governance and failures to show how assessments influence cybersecurity policies, controls and resource decisions. Risk assessments must remain responsive to material changes, which can include major system migrations, mergers and acquisitions, significant outsourcing arrangements, developments in cybersecurity technologies and the adoption of emerging technologies.

North AmericaMultiple
Federal Deposit Insurance Corporation and other federal bank regulators expand 18-month examination cycle to qualifying institutions under USD 6 billion

--

Policy & regulationSupervision approach

The Federal Deposit Insurance Corporation, Board of Governors of the Federal Reserve System and Office of the Comptroller of the Currency jointly issued an interim final rule expanding eligibility for an 18-month on-site examination cycle. Implementing the 21st Century ROAD to Housing Act, the rule doubles the total asset threshold from USD 3 billion to less than USD 6 billion for qualifying insured depository institutions and makes parallel changes for U.S. branches and agencies of foreign banks. Eligible institutions must satisfy existing capital, management and supervisory criteria, including being well capitalized and well managed, holding an outstanding or good composite rating, having no applicable formal enforcement action and meeting change-in-control restrictions. The agencies estimate that about 188 additional institutions, including approximately 19 U.S. branches and agencies of foreign banks, may qualify, bringing the total to 4,016. Off-site monitoring will continue, and regulators retain authority to conduct more frequent examinations where necessary. The rule will take effect immediately upon publication in the Federal Register.

North AmericaFinancial Crimes Enforcement Network
U.S. Department of the Treasury’s Financial Crimes Enforcement Network clarifies use of government-issued digital credentials for customer identification

The U.S. Department of the Treasury’s Financial Crimes Enforcement Network and federal banking and credit union regulators has released new guidance, clarifying that banks and credit unions may use qualifying government-issued verifiable digital credentials, including state-issued mobile driver’s licenses, for customer identity verification where Customer Identification Program requirements are met. Institutions may also use electronic credentials for non-documentary verification subject to their programs and remain responsible for appropriate authentication when relying on non-government third parties.

Policy & regulationKYC

The U.S. Department of the Treasury’s Financial Crimes Enforcement Network, jointly with staff from the federal banking and credit union regulators, issued guidance clarifying how banks and credit unions may use state-issued mobile driver’s licenses and other government-issued verifiable digital credentials to verify natural person customers under the Customer Identification Program Rule. Institutions may choose to use these credentials where their Customer Identification Programs permit it and the applicable verification requirements are met. For documentary verification, an unexpired government-issued verifiable digital credential may qualify as government-issued identification if it evidences nationality or residence and bears a photograph or similar safeguard. The institution must also have the technology or systems needed to extract the relevant information from the credential. Banks and credit unions may generally rely on qualifying government-issued verifiable digital credentials in the same way as other forms of government identification, while remaining responsible for considering any indications of fraud when determining whether they have a reasonable belief that they know the customer’s true identity. The agencies also updated an existing FAQ on the use of electronic credentials for non-documentary verification. Where such credentials are issued and maintained by a non-government third party, the institution must ensure that the third party applies the same level of authentication the institution itself would use. The FAQs clarify how existing Customer Identification Program requirements apply to these credentials without changing Bank Secrecy Act requirements or establishing new supervisory expectations.

Monetary policy developments

Decisions during the week of September 7–13 reinforced the broader shift toward a longer period of restrictive monetary policy, as persistent energy and supply costs continued to delay the return of inflation to target in several economies. The European Central Bank (ECB) raised its deposit rate by 25 bp to 2.50% as Middle East-related cost pressures were expected to keep inflation elevated for longer, prompting upward revisions to its 2027–28 inflation forecasts while growth remained more resilient than anticipated. Most other central banks kept rates unchanged but retained restrictive settings. Russia held at 14.00% after underlying inflation accelerated and expectations remained elevated, while Poland and Georgia continued to balance supply-driven price pressures against still-contained underlying inflation. Türkiye also maintained rates as weaker domestic demand and slowing underlying inflation reduced the need for additional tightening. In Chile, Peru and Serbia, recent inflation increases remained concentrated mainly in fuel, transport and other volatile components, allowing policymakers to wait despite continued external price risks. The BCEAO likewise held rates with regional inflation remaining low.

Latest decisions

DateCentral bankDecisionNew rateRate changeStatement
2026-09-11Central Bank of RussiaDate:2026-09-11Central bank:Central Bank of RussiaDecision:MaintainNew rate:Key rate14.00%Rate change:0 bpsMaintainKey rate14.00%0 bpsViewView statement
2026-09-10Central Bank of PeruDate:2026-09-10Central bank:Central Bank of PeruDecision:MaintainNew rate:Reference rate4.25%Rate change:0 bpsMaintainReference rate4.25%0 bpsViewView statement
2026-09-10National Bank of SerbiaDate:2026-09-10Central bank:National Bank of SerbiaDecision:MaintainNew rate:Reference interest rate5.75%Rate change:0 bpsMaintainReference interest rate5.75%0 bpsViewView statement
2026-09-10Central Bank of TürkiyeDate:2026-09-10Central bank:Central Bank of TürkiyeDecision:MaintainNew rate:One-week repo auction rate40.00%Rate change:0 bpsMaintainOne-week repo auction rate40.00%0 bpsViewView statement
2026-09-10European Central BankDate:2026-09-10Central bank:European Central BankDecision:RaiseNew rate:Deposit facility rate2.50%Rate change:25 bpsRaiseDeposit facility rate2.50%25 bpsViewView statement
2026-09-09Central Bank of West African StatesDate:2026-09-09Central bank:Central Bank of West African StatesDecision:MaintainNew rate:--Rate change:0 bpsMaintain--0 bpsViewView statement
2026-09-09Central Bank of ChileDate:2026-09-09Central bank:Central Bank of ChileDecision:MaintainNew rate:Monetary policy rate4.50%Rate change:0 bpsMaintainMonetary policy rate4.50%0 bpsViewView statement
2026-09-09Central Bank of PolandDate:2026-09-09Central bank:Central Bank of PolandDecision:MaintainNew rate:Reference rate3.75%Rate change:0 bpsMaintainReference rate3.75%0 bpsViewView statement
2026-09-09National Bank of GeorgiaDate:2026-09-09Central bank:National Bank of GeorgiaDecision:MaintainNew rate:Monetary policy rate8.25%Rate change:0 bpsMaintainMonetary policy rate8.25%0 bpsViewView statement
2026-09-07Bank of Papua New GuineaDate:2026-09-07Central bank:Bank of Papua New GuineaDecision:MaintainNew rate:--Rate change:0 bpsMaintain--0 bpsViewView statement

Upcoming decisions

DateCentral bankLatest decisionCurrent rateExpectationFact sheet
2026-09-14State Bank of PakistanMaintainPolicy rate11.50%MaintainViewView fact sheetDate:2026-09-14Central bank:State Bank of PakistanLatest decision:MaintainCurrent rate:Policy rate11.50%Expectations:MaintainFact sheet:ViewView fact sheet
2026-09-15Central Bank of ArmeniaMaintainRefinancing rate6.50%MaintainViewView fact sheetDate:2026-09-15Central bank:Central Bank of ArmeniaLatest decision:MaintainCurrent rate:Refinancing rate6.50%Expectations:MaintainFact sheet:ViewView fact sheet
2026-09-15National Bank of the Republic of North MacedoniaMaintainPolicy rate4.25%Not availableViewView fact sheetDate:2026-09-15Central bank:National Bank of the Republic of North MacedoniaLatest decision:MaintainCurrent rate:Policy rate4.25%Expectations:Not availableFact sheet:ViewView fact sheet
2026-09-15National Bank of AngolaLowerBNA rate15.75%Not availableViewView fact sheetDate:2026-09-15Central bank:National Bank of AngolaLatest decision:LowerCurrent rate:BNA rate15.75%Expectations:Not availableFact sheet:ViewView fact sheet
2026-09-16Central Bank of the Republic of UzbekistanMaintainPolicy rate14.00%MaintainViewView fact sheetDate:2026-09-16Central bank:Central Bank of the Republic of UzbekistanLatest decision:MaintainCurrent rate:Policy rate14.00%Expectations:MaintainFact sheet:ViewView fact sheet
2026-09-16Federal Reserve BoardMaintainFederal funds rate3.75%RaiseViewView fact sheetDate:2026-09-16Central bank:Federal Reserve BoardLatest decision:MaintainCurrent rate:Federal funds rate3.75%Expectations:RaiseFact sheet:ViewView fact sheet
2026-09-16Central Bank of the UAEMaintainBase rate3.65%Not applicableViewView fact sheetDate:2026-09-16Central bank:Central Bank of the UAELatest decision:MaintainCurrent rate:Base rate3.65%Expectations:Not applicableFact sheet:ViewView fact sheet
2026-09-16Qatar Central BankMaintainQCB deposit rate3.85%Not applicableViewView fact sheetDate:2026-09-16Central bank:Qatar Central BankLatest decision:MaintainCurrent rate:QCB deposit rate3.85%Expectations:Not applicableFact sheet:ViewView fact sheet
2026-09-16Central Bank of BahrainMaintainOvernight interest rate4.25%Not applicableViewView fact sheetDate:2026-09-16Central bank:Central Bank of BahrainLatest decision:MaintainCurrent rate:Overnight interest rate4.25%Expectations:Not applicableFact sheet:ViewView fact sheet
2026-09-16Central Bank of BrazilLowerSelic rate14.00%LowerViewView fact sheetDate:2026-09-16Central bank:Central Bank of BrazilLatest decision:LowerCurrent rate:Selic rate14.00%Expectations:LowerFact sheet:ViewView fact sheet
2026-09-16Saudi Arabian Monetary Authority----—ViewView fact sheetDate:2026-09-16Central bank:Saudi Arabian Monetary AuthorityLatest decision:--Current rate:--Expectations:—Fact sheet:ViewView fact sheet
2026-09-16Central Bank of OmanLowerRepo rate4.25%—ViewView fact sheetDate:2026-09-16Central bank:Central Bank of OmanLatest decision:LowerCurrent rate:Repo rate4.25%Expectations:—Fact sheet:ViewView fact sheet
2026-09-17Central Bank of TaiwanMaintainDiscount rate2.00%MaintainViewView fact sheetDate:2026-09-17Central bank:Central Bank of TaiwanLatest decision:MaintainCurrent rate:Discount rate2.00%Expectations:MaintainFact sheet:ViewView fact sheet
2026-09-17Central Bank of MongoliaMaintainPolicy rate12.00%Not availableViewView fact sheetDate:2026-09-17Central bank:Central Bank of MongoliaLatest decision:MaintainCurrent rate:Policy rate12.00%Expectations:Not availableFact sheet:ViewView fact sheet
2026-09-17Bank of EnglandMaintainBank rate3.75%MaintainViewView fact sheetDate:2026-09-17Central bank:Bank of EnglandLatest decision:MaintainCurrent rate:Bank rate3.75%Expectations:MaintainFact sheet:ViewView fact sheet
2026-09-17Central Bank of JordanMaintainInterest rate5.75%Not applicableViewView fact sheetDate:2026-09-17Central bank:Central Bank of JordanLatest decision:MaintainCurrent rate:Interest rate5.75%Expectations:Not applicableFact sheet:ViewView fact sheet
2026-09-17Czech National BankMaintainTwo-week repo rate3.75%MaintainViewView fact sheetDate:2026-09-17Central bank:Czech National BankLatest decision:MaintainCurrent rate:Two-week repo rate3.75%Expectations:MaintainFact sheet:ViewView fact sheet
2026-09-17National Bank of MoldovaRaiseBase rate7.50%Not availableViewView fact sheetDate:2026-09-17Central bank:National Bank of MoldovaLatest decision:RaiseCurrent rate:Base rate7.50%Expectations:Not availableFact sheet:ViewView fact sheet
2026-09-17National Bank of UkraineRaiseKey policy rate15.50%RaiseViewView fact sheetDate:2026-09-17Central bank:National Bank of UkraineLatest decision:RaiseCurrent rate:Key policy rate15.50%Expectations:RaiseFact sheet:ViewView fact sheet
2026-09-18Bank of JapanMaintainUncollateralized overnight call rate1.00%RaiseViewView fact sheetDate:2026-09-18Central bank:Bank of JapanLatest decision:MaintainCurrent rate:Uncollateralized overnight call rate1.00%Expectations:RaiseFact sheet:ViewView fact sheet
2026-09-18Bank of Cape Verde----—ViewView fact sheetDate:2026-09-18Central bank:Bank of Cape VerdeLatest decision:--Current rate:--Expectations:—Fact sheet:ViewView fact sheet
© 2026 Regxelerator
·
About Regxelerator