Global Regulator & Central Bank News Roundup
Edition 392026Week of September 28
Global developments
SWIFT is developing a cross-border pay by alias capability that would allow consumers to send money internationally using mobile numbers, email addresses and other familiar identifiers. The initiative connects participants from domestic systems such as Bizum, PayID and Pix and builds on Swift’s consumer payments framework, which now involves more than 100 banks.
SWIFT and its global community are developing a cross-border pay by alias capability that would let consumers send money internationally using identifiers such as mobile phone numbers, email addresses and virtual payment addresses rather than recipients’ account details. The initiative seeks to extend the familiar user experience of domestic systems including Spain’s Bizum, Australian Payments Plus’ PayID and Brazil’s Pix to international transactions, with aliases securely matched over Swift. Banks, payment service providers, technology companies and domestic payment systems from four continents are participating. The work is the next stage of SWIFT's consumer payments framework, which launched in June and now involves more than 100 banks, combining the new front-end capability with full-value transfers, greater predictability and faster settlement. SWIFT reported that 75% of payments over its network currently reach the receiving bank within 10 minutes and often within seconds.
The Organisation for Economic Co-operation and Development has published nonbinding guidelines to help policymakers strengthen governance frameworks for issuers of listed corporate bonds, including companies without publicly traded equity. The guidelines focus on timely disclosure, board oversight of capital structure and the effective exercise of bondholder rights. They also recommend safeguards for out-of-court restructuring, including equitable treatment in consent solicitations and clearer support for bondholder participation.
The Organisation for Economic Co-operation and Development (OECD) has published nonbinding Guidelines for Corporate Bond Issuers to help policymakers improve the legal, regulatory and institutional framework for issuers and the role of bondholders in corporate governance. The guidance covers issuers of bonds listed on a stock exchange or another trading venue, including companies without publicly traded equity, but excludes unlisted bonds. It complements the G20/OECD Principles of Corporate Governance with recommendations on disclosure, board responsibilities and the exercise of bondholder rights. Issuers should provide timely, accurate disclosure of material debt terms, covenant compliance risks and the consequences of material breaches. Issuance documents should explain the triggers and consequences of provisions that can change a bond’s economic characteristics, such as conversion into equity or principal write-downs. Reporting should follow internationally recognized accounting and disclosure standards, with financial statements subject to an independent annual external audit. Alongside these disclosure expectations, boards should assess whether capital structure aligns with strategy and risk appetite, taking bondholder interests into account while acting in the best interests of the company and shareholders. When boards know or ought reasonably to know that insolvency is imminent or unavoidable, they should minimize damage and take appropriate measures, including engaging creditors and initiating restructuring or insolvency proceedings. To support the exercise of bondholder rights, meeting procedures should provide timely information and enable effective participation and voting, including in absentia. Any appointed trustee should be independent and accountable to bondholders, with conflicted trustees excluded or replaced. Regulatory frameworks should also facilitate debt restructuring outside court where appropriate. Supporting measures could include clarifying how insider trading rules apply during restructuring or covenant waiver negotiations. To safeguard equitable treatment, all responding or voting bondholders could be given an equal opportunity to receive consent fees, regardless of whether they support the proposal. Where response periods are insufficient or retail investors hold the bonds, extending those payments to nonparticipants may be appropriate.
The Basel Committee on Banking Supervision approved G-SIB anti-window-dressing revisions and a final machine-readable Pillar 3 standard, while advancing work on IRRBB, cryptoassets and AI-related supervisory risks. It will consult on additional IRRBB Pillar 2 guidance in November 2026 and provide an update on its targeted cryptoasset-standard review by the end of 2026. The Committee also agreed to review operational-risk loss categories with a focus on cyber risk and AI developments.
The Basel Committee on Banking Supervision advanced a broad set of supervisory and regulatory initiatives, approving revisions to the global systemically important bank framework to reduce year-end window-dressing and a final standard for machine-readable Pillar 3 disclosures. It also agreed to consult on additional Pillar 2 guidance after identifying shortcomings in banks’ management of interest rate risk in the banking book, advanced its targeted review of the prudential standard for banks’ cryptoasset exposures and expanded work on supervisory implications from artificial intelligence. On digitalisation, the Committee highlighted the expanding financial footprint, leverage and interconnected financing of the AI ecosystem, alongside potential operational vulnerabilities from cyber attacks and correlated dependencies. It agreed to review whether existing operational-risk event-type loss categories remain adequate, focusing on cyber risk and AI developments. The final machine-readable Pillar 3 standard, intended to make internationally active banks’ disclosures easier to aggregate, process and compare than current PDF-based reporting, is expected around the end of 2026. The Committee approved the end-2025 G-SIB assessment results for submission to the Financial Stability Board before publication of the 2026 G-SIB list, with the anti-window-dressing framework revisions due in October 2026. It also plans an October 2026 consultation on the treatment of cross-border exposures within the European banking union in the G-SIB methodology and a November 2026 consultation on additional IRRBB guidance. Further work includes a cryptoasset-standard update by the end of 2026, possible updates to the liquidity-risk principles, voluntary supervisory tools on credit risk and governance, publication of AML/CFT supervisory survey results and leverage-ratio implementation assessments for six jurisdictions.
The Bank for International Settlements finds that 46.4% of disclosed investment deal value between artificial intelligence firms during 2021–25 involved overlapping financing and supply chain relationships. These circular links can help secure critical inputs but create macroeconomic risks and increase opacity. They can obscure underlying demand, amplify losses across investments and sales, and complicate supervision.
The Bank for International Settlements has published a bulletin assessing the macroeconomic risks of overlapping investment and supply chain relationships among artificial intelligence (AI) firms. Deals involving these circular relationships accounted for 46.4% of disclosed investment deal value between AI firms during 2021–25 and 16.1% by deal count. Such arrangements can help firms secure critical inputs and address information gaps, but also increase opacity and create risks beyond individual firms. The analysis classifies an investment relationship as circular when the investor and target also had a supplier-customer relationship at any point during 2021–25. When at least one AI investor meets that test, the value measure includes the full disclosed financing deal or round, rather than just that investor’s contribution. Suppliers can use their knowledge of customers to provide financing and stabilise demand for their products, while customers can finance suppliers to secure scarce inputs. Consistent with these incentives, compute and infrastructure providers originated 73% of circular investment relationships. Supplier financing can make revenue growth partly reflect the supplier’s own investment rather than organic final demand, making the strength of the AI boom harder for investors, lenders and supervisors to assess. A customer shock can reduce both investment values and product revenues, with concentrated exposures potentially spreading stress through financial and commercial channels simultaneously. Private credit and special purpose vehicles may add hidden leverage. Complex terms can obscure contingent obligations, including off balance sheet guarantees covering shortfalls in future asset values that materialise during downturns. Limited disclosure and relationships spanning sectors and jurisdictions further complicate monitoring and supervision.
The International Monetary Fund estimates that artificial intelligence could lift annual growth in the Middle East and Central Asia by 0.1–0.6 percentage points over a decade. Gulf Cooperation Council economies could gain most, but weak demand could leave leveraged infrastructure investments underused. Recommendations prioritize AI preparedness, prudential oversight and support for workers affected by automation.
The International Monetary Fund published a departmental paper estimating that artificial intelligence (AI) adoption and related investment could add 0.1–0.6 percentage points to annual real gross domestic product (GDP) growth over a decade, depending on the economy and scenario. The analysis covers the Middle East, North Africa, Afghanistan and Pakistan (MENAP), and the Caucasus and Central Asia (CCA). Gulf Cooperation Council (GCC) economies could gain the most, reflecting stronger preparedness, greater occupational and sectoral exposure to AI, and better technology access. Alongside these opportunities, the paper identifies financial stability risks from leveraged investment and labor market pressures from automation. AI investment plans announced by Qatar, Saudi Arabia and the United Arab Emirates in 2025 totaled roughly USD 120 billion, concentrated in data centers and supporting infrastructure. Under current trade patterns, a scenario combining these investments with reforms that raise GCC preparedness to the levels of advanced economies adds about 0.1 percentage point to annual growth over 10 years. Stronger AI exports could roughly double the additional growth contribution from investment, depending on the economy. These results depend on successful preparedness reforms and increased external demand, supported by AI adoption abroad and regulatory arrangements with advanced economies. Prolonged uncertainty from the war in the Middle East could delay investment decisions and raise financing costs. Separate simulations indicate that preparedness reforms could add up to 0.1 percentage point to annual growth over a decade, including in economies not seeking to become AI hubs. Economies with weaker foundations should prioritize digital infrastructure and human capital, while more prepared economies should strengthen innovation and adapt legal frameworks. Financial safeguards should include stronger prudential oversight, better AI data collection and integration of AI scenarios into macrofinancial policy frameworks to address vulnerabilities from leveraged projects and financial sector exposures. Social protection, retraining and active labor market policies should support worker transitions, as automation could widen skill mismatches and inequality while weakening labor income tax bases and increasing social spending needs.
Active global consultations
The Committee on Payments and Market Infrastructures and the Board of the International Organization of Securities Commissions are seeking feedback on a discussion paper examining the risk management challenges arising from financial market infrastructures’ increasing reliance on third-party service providers, including for critical services. The paper reflects FMIs’ systemically important and highly interconnected role and focuses on how external and intra-group service arrangements can increase operational risk and create channels through which disruptions may be transmitted across the financial system. It does not propose additional guidance but seeks views on whether the identified challenges are comprehensive and whether further engagement or policy support would be beneficial. The paper identifies six principal challenges: increasing complexity and interconnectedness of FMI ecosystems, including cyber-related risk; concentration of third-party service providers and resulting single points of failure, vendor lock-in and systemic dependencies; complex and opaque supply chains and limited visibility of nth-party providers; difficulties designing practicable exit strategies and substituting providers, especially in stressed conditions; imbalances in bargaining power that can limit audit, information-sharing, testing and service-level rights; and variation in regulatory, supervisory and oversight expectations across jurisdictions.
The Committee on Payments and Market Infrastructures and the Board of the International Organization of Securities Commissions are seeking feedback on a discussion paper examining the risk management challenges arising from financial market infrastructures’ increasing reliance on third-party service providers, including for critical services. The paper reflects FMIs’ systemically important and highly interconnected role and focuses on how external and intra-group service arrangements can increase operational risk and create channels through which disruptions may be transmitted across the financial system. It does not propose additional guidance but seeks views on whether the identified challenges are comprehensive and whether further engagement or policy support would be beneficial. The paper identifies six principal challenges: increasing complexity and interconnectedness of FMI ecosystems, including cyber-related risk; concentration of third-party service providers and resulting single points of failure, vendor lock-in and systemic dependencies; complex and opaque supply chains and limited visibility of nth-party providers; difficulties designing practicable exit strategies and substituting providers, especially in stressed conditions; imbalances in bargaining power that can limit audit, information-sharing, testing and service-level rights; and variation in regulatory, supervisory and oversight expectations across jurisdictions.
The Committee on Payments and Market Infrastructures (CPMI) and the Board of IOSCO are consulting on a voluntary, non-binding cyber resilience toolkit intended to provide financial market infrastructures with practical, technology-neutral support for strengthening their cyber resilience frameworks and implementing operational resilience-related components of the Principles for financial market infrastructures, as informed by the 2016 CPMI-IOSCO Guidance on cyber resilience for financial market infrastructures. The toolkit is organized around four areas: (1) governance of cyber risk and resilience, including board and senior management capabilities, ecosystem risk management, maturity models and resilience metrics; (2) identification and design of extreme but plausible cyber scenarios, including scenario scope, threat intelligence, emerging risks and ecosystem dependencies; (3) response, resumption and recovery planning, covering critical operations and information assets, infrastructure and data resilience, third-party dependencies, contingency arrangements, safe resumption and the disconnection and reconnection of ecosystem entities; and (4) cyber resilience testing and exercising.
The Committee on Payments and Market Infrastructures (CPMI) and the Board of IOSCO are consulting on a voluntary, non-binding cyber resilience toolkit intended to provide financial market infrastructures with practical, technology-neutral support for strengthening their cyber resilience frameworks and implementing operational resilience-related components of the Principles for financial market infrastructures, as informed by the 2016 CPMI-IOSCO Guidance on cyber resilience for financial market infrastructures. The toolkit is organized around four areas: (1) governance of cyber risk and resilience, including board and senior management capabilities, ecosystem risk management, maturity models and resilience metrics; (2) identification and design of extreme but plausible cyber scenarios, including scenario scope, threat intelligence, emerging risks and ecosystem dependencies; (3) response, resumption and recovery planning, covering critical operations and information assets, infrastructure and data resilience, third-party dependencies, contingency arrangements, safe resumption and the disconnection and reconnection of ecosystem entities; and (4) cyber resilience testing and exercising.
Regional developments
In a new note, the Executives’ Meeting of East Asia-Pacific Central Banks assesses how expanding AI adoption could affect the real economy, financial stability and central bank operations. It finds that AI could support productivity, investment and growth but also create uneven economic effects and amplify financial stability risks through asset price volatility, leverage, common technology dependencies and cyber vulnerabilities. Among member central banks, adoption remains gradual, with a focus on human oversight, governance, supervisory monitoring and cooperation.
The Executives’ Meeting of East Asia-Pacific Central Banks (EMEAP) has published a note examining how expanding AI adoption could affect the real economy, financial stability and central bank operations, drawing in part on a 2025 survey of member institutions. It assesses AI as a potential source of multiple interacting shocks rather than a single disruption. Economic benefits could arise through higher productivity, investment and production, but may be uneven across economies, sectors and workers, while short term productivity gains remain limited. AI could also create inflationary pressures through investment and import prices before longer term productivity gains lower production costs. For financial stability, the note highlights risks from sharp movements in AI related asset prices, increasing leverage as some firms shift capital expenditure financing from retained earnings toward debt, and uneven adoption across financial institutions. Dependence on a small number of AI and cloud providers, common use of similar models and datasets, model opacity and cyber vulnerabilities could create common exposures and amplify disruptions, correlated trading and procyclical market dynamics. The note points to strong governance, risk management and supervisory oversight, alongside a system wide macroprudential perspective, as important responses. Central bank adoption remains relatively gradual. About half of EMEAP members were using AI for general tasks as of 2025, while some were extending use to specialized functions and approximately half had launched pilot research projects using generative AI for applications such as real time economic forecasting or text based sentiment indicators. Most members had established AI frameworks or guidelines and were using measures including human oversight and technical safeguards. The note identifies potential need for targeted supervisory measures on third party dependence and model risk, as well as enhanced stress testing and human oversight, while calling for greater cooperation among EMEAP members on best practices, threat intelligence and cross border cyber incident response.
The Monetary Authority of Macao and two local banks subscribed to multicurrency Hong Kong government digital green bonds through the depository link between Macao and Hong Kong. The subscriptions marked Macao institutions’ first use of mBridge for cross-border funds settlement of bond investments. This extends local use of the central bank digital currency platform beyond trade settlements and international remittances following its opening to Macao banks in June 2026.
The Monetary Authority of Macao reported that it, Bank of China (Macau) and Industrial and Commercial Bank of China (Macau) subscribed to multicurrency digital green bonds issued by the Hong Kong Special Administrative Region government. The subscriptions marked Macao institutions’ first use of mBridge, a central bank digital currency platform, for cross-border funds settlement of bond investments. The transactions used the link between Macao’s Central Securities Depository and Hong Kong’s Central Moneymarkets Unit. Macao Central Securities Depository and Clearing Limited handled bond settlement, while mBridge provided cross-border funds settlement. The transaction extends local use of mBridge beyond trade settlements and international remittances following the platform’s opening to Macao banks on June 2, 2026. On that first day, three of the 11 initially approved banks completed 23 cross-border transactions totaling nearly MOP 13 billion, involving mainland China, Hong Kong and the United Arab Emirates. The bond subscriptions bring this payment capability into securities investment through the existing link between the two markets’ depositories.
The Financial Services Commission has proposed implementing rules for token securities covering eligible securities, distributed ledger standards, issuer account manager requirements and OTC trading. The proposals would require issuer account management institutions to hold at least KRW 4 billion in equity and would cap retail investors' annual net purchases at KRW 100 million per OTC exchange. The rules are scheduled to take effect on February 4, 2027.
The South Korea Financial Services Commission (FSC) has proposed implementing rules for South Korea's token securities framework ahead of the underlying Electronic Securities Act and Capital Markets Act amendments taking effect on February 4, 2027. The proposals would define which securities may be tokenized, establish requirements for distributed ledgers and issuer account management institutions, create an OTC exchange licensing category that includes debt securities and set an annual KRW 100 million net purchase limit for retail investors on each OTC exchange. Eligible tokenized securities would include fractional investment securities, comprising non-monetary trust beneficiary securities and investment contract securities, as well as conventional securities such as shares, bonds and funds. Distributed ledgers used for electronic registration would need to include the electronic registration institution and at least two account management institutions, including issuer account management institutions, and direct compensation for use of the ledger for electronic registration would be prohibited. Issuers seeking registration as issuer account management institutions would need at least KRW 4 billion in equity and specified account management, internal control and IT personnel. The Capital Markets Act implementing rules would add debt securities to the OTC exchange licensing category alongside unlisted shares and non-monetary trust beneficiary securities. The retail investor limit would be calculated as annual net purchases, defined as total purchases minus total sales, separately for each OTC exchange. The implementing rules are scheduled to take effect on February 4, 2027, following the remaining approval and legislative review procedures.
New Zealand's Financial Markets Authority has extended climate reporting no action relief pending legislation to narrow the regime. Covered entities are listed issuers below NZD 1 billion in market capitalisation, investment scheme managers, and health and life insurers. The extension covers five 2026/2027 reporting periods with balance dates from March 31, 2027, to Jan. 31, 2028.
New Zealand's Financial Markets Authority (FMA) has extended its existing no action relief from climate reporting obligations for listed issuers with market capitalisation below NZD 1 billion, investment scheme managers, and health and life insurers. The Financial Markets Conduct Amendment Bill, which would remove these entities from the regime, did not pass before the House's final sitting ahead of the November election, leaving their future reporting obligations uncertain. The extension covers all requirements under Part 7A of the Financial Markets Conduct Act for five 2026/2027 reporting periods with balance dates from March 31, 2027, to Jan. 31, 2028, inclusive. It does not cover the reporting period ending March 31, 2028. Under the no action approach, the FMA will not take action for breaches covered by the relief, but third parties may still take legal action. Further relief may follow if the incoming government progresses the proposed changes, depending on the timing of reform. If it does not support passage of the bill, the FMA will work with affected entities on a return to reporting, recognising that they may be unable to provide comparative information for the previous reporting year.
The Reserve Bank of New Zealand reported that 90% of individual respondents to its Keeping Cash Local consultation supported a minimum cash services standard. Banks supported continued cash access but questioned the proposed approach and costs, favouring voluntary implementation. The central bank is working with banks to improve cash services and prefers exploring a voluntary solution.
The Reserve Bank of New Zealand (RBNZ) has published findings from its Keeping Cash Local consultation showing strong support among individual respondents for a minimum cash services standard, alongside banks’ concerns about the proposed design and costs. The consultation received 6,106 submissions, with 90% of individual respondents supporting a standard and around half dissatisfied with cash services in their district. Retail and civic organisations and cash system providers also generally supported a standard. The proposal focused on geographic access to free cash withdrawals, deposits and exchanges of notes and coins. It envisaged at least 2.5 cash service sites per 10,000 people in each district and 95% coverage within travel limits of 3 kilometers in urban areas, 15 kilometers in rural settlements and 30 kilometers outside rural settlements. Feedback highlighted the need to address service quality as well as proximity, with respondents calling for reliable machines, safe and accessible sites, and staff assistance. Separate workshops reinforced these concerns and highlighted the need for site locations to reflect local economic activity and seasonal demand rather than population distribution alone. The three responding banks supported continued cash access but questioned whether the proposed geographic requirements reflected customer needs and called for further assessment of costs and benefits. Digital payments providers raised separate concerns about prioritising cash infrastructure and potential impacts on banks offering only digital services. On implementation, the banks favoured a voluntary approach in collaboration with RBNZ. This aligns with the central bank’s preference to explore a voluntary solution, and it is now engaging with a bank working group to improve cash services. Further consultation is planned on other service dimensions and implementation, including which banks would be covered.
The Australian Securities and Investments Commission has released its 2026–27 supervisory priorities for banking, superannuation, general and life insurance, and markets. They emphasize customer and member services, protection from harmful conduct, technology risks and market integrity. Sector priorities cover inter alia banks’ artificial intelligence use and lending practices, trustees’ advice fee oversight and retirement obligations, insurers’ claims and services, and private credit scrutiny and market infrastructure resilience.
The Australian Securities and Investments Commission (ASIC) has released its 2026–27 supervisory priorities for banking, superannuation, general insurance, life insurance and markets. The priorities emphasize improving customer and member services, addressing harmful conduct and strengthening oversight of artificial intelligence (AI) and operational risks. Across markets, the focus also includes transparency, infrastructure resilience and reducing barriers to capital raising. For banks, new reviews will examine AI use affecting customers and lender conduct, with remuneration incentives, referrer arrangements and broker oversight likely areas of focus. Continuing supervision will address whether customers receive promised mortgage offset benefits and appropriate treatment during debt collection and financial hardship. In superannuation, the ongoing member services review will be complemented by new assessments of trustee oversight of advice fee deductions and performance under the Retirement Income Covenant. For general insurance, a review already under way will examine potential consumer harm from for-profit claims management firms, including their sales practices, fees and relationships with repairers. Insurers are also expected to improve premium disclosure and cash settlement practices. In life insurance, the ongoing service review addresses failures involving policy records, premium calculations and benefit payments. A separate funeral insurance review is expected in the second half of 2026–27, following concerns about costs exceeding benefits. In financial markets, ASIC will maintain intensive oversight of ASX’s existing commitments and major technology upgrades, alongside work on operational resilience and manipulation risks involving AI. Further private credit surveillance will examine distribution practices, fees and incentives, with closer supervision of business models exposed to leverage and liquidity pressures. Measures to support capital raising include continuing the trial to shorten eligible initial public offering timetables and clarifying prospectus forecast guidance. Preparations for the digital asset and tokenised custody platform regime commencing in April 2027 will include guidance and draft rules. ASIC will also consult on targeted amendments to the contracts for difference product intervention order and its extension beyond May 2027.
The Australian Prudential Regulation Authority has proposed eight changes to strengthen superannuation investment governance, including member-level limits for concentrated higher-risk investments, stronger controls over third-party conflicts and requirements to align investment menus with trustee capability. The package would also strengthen or codify requirements for onboarding, monitoring, remediation, valuations and accountability, with the greatest impact expected on platform trustees. The new framework is expected to commence on January 1, 2028, subject to consultation.
The Australian Prudential Regulation Authority (APRA) has proposed eight changes to superannuation investment governance that would apply to all trustees but are expected to have the greatest impact on platform trustees. The package introduces three stronger safeguards: member-level investment limits for concentrated higher-risk options, tighter management of conflicts involving advisers, promoters and other third parties, and requirements to align the size and complexity of investment menus with trustee capability and resources. It also codifies or strengthens expectations for investment onboarding, monitoring, remediation, valuations and accountability, following persistent governance weaknesses identified through supervision and enforcement, particularly in platform models. Under the proposed member-level limits, trustees would set and enforce limits for concentrated higher-risk options, subject to an APRA-set maximum. APRA's preliminary view is that a maximum of 20% to 30% for each option or group of options may be appropriate. The limits would apply when members acquire or add to investments, rather than generally forcing sell-downs after market movements, and would apply to both advised and unadvised members. Further proposals would require objective onboarding thresholds and ongoing monitoring against the same criteria, time-bound remediation and active member consent to remain in options subject to material or persistent concerns. Trustees would also have to undertake valuations at least quarterly, obtain external valuations where directed by APRA, and obtain an annual investment governance attestation that must be considered when determining variable remuneration. APRA expects to finalise the standard and release draft prudential guidance in the first half of 2027, with the new framework expected to commence on January 1, 2028, subject to consultation. APRA will also continue heightened supervision of platform trustees and is considering whether certain trustee remuneration requirements currently applying to large trustees should extend to complex trustees of all sizes.
Malaysia's Securities Commission and the Hong Kong Securities and Futures Commission have activated a single submission process for simultaneous dual listings. Applicants may use one application and listing document for a primary listing in one market and a secondary listing in the other, supported by coordinated reviews and dedicated regulatory teams.
Securities Commission Malaysia and the Hong Kong Securities and Futures Commission (SFC) have implemented simplified procedures for companies seeking simultaneous listings in Malaysia and Hong Kong. Under the framework agreed in their July 2026 memorandum of understanding, an applicant can make a single submission using one listing document for a primary listing on either the Main Board of the Stock Exchange of Hong Kong or Bursa Malaysia’s MAIN Market, alongside a secondary listing on the other market. Dedicated dual listing teams and coordinated reviews will align regulatory timelines, streamline queries and reduce duplicate submissions and compliance costs at the initial public offering application stage. Securities Commission Malaysia has issued guidance for Hong Kong companies listing on Bursa Malaysia’s MAIN Market, while the Hong Kong regulator has published a circular governing the arrangement.
The Monetary Authority of Singapore is consulting on tighter governance requirements for banks, insurers and designated financial holding companies. Proposals include larger boards for systemically important institutions and full banks, and an aggregate limit of nine years on director independence. Prior approval would expand to additional key appointments but be removed for selected roles at institutions with less retail reach or lower systemic importance.
The Monetary Authority of Singapore (MAS) has launched a consultation on changes to corporate governance requirements for banks, insurers and designated financial holding companies (DFHCs). The proposals would tighten director independence and board composition requirements, expand prior approval for selected key appointments and remove some approvals for institutions with less retail reach or lower systemic importance. DFHCs would generally follow the governance standards applicable to their bank or insurer subsidiaries. Director independence assessments would cover additional management relationships involving parent and sister companies, taking account of directors’ or immediate family members’ responsibilities over the institution. Business relationship assessments would also extend to related corporations and immediate family members, while payments involving entities linked to directors would be assessed against significance criteria set by nominating committees. Directors would cease to qualify as independent once aggregate board service reaches nine years, replacing the current continuous service test, with no exceptions. Minimum board sizes would rise to seven directors for domestic systemically important banks (DSIBs) and five for full banks and domestic systemically important insurers (DSIIs), with corresponding requirements for their DFHCs. These institutions would require a majority of fully independent directors. Separate risk management committees would become mandatory for all locally incorporated banks, DSIIs and Tier 1 insurers, including subsidiaries of other banks or insurers. Prior approval would extend to nominating committee chairpersons at locally incorporated banks, DSIIs, Tier 1 insurers and their DFHCs. Approval requirements for other nominating committee members would be removed for wholesale banks, Tier 1 insurers and their DFHCs. DSIBs and their DFHCs would need approval for chief information officers, while DSIB branches would also require approval for chief financial officers and chief risk officers. Approval for heads of treasury would be retained only for DSIBs. A transition period of two years from the revised regulations’ effective date is proposed in general. The aggregate director tenure limit and appointment approval changes would be among the measures applying immediately upon amendment.
Brunei Darussalam Central Bank launched its Financial Sector Blueprint 2026–2035 to broaden financial access and funding options, advance sustainable finance and modernize financial infrastructure while maintaining monetary and financial stability. Market and sustainability initiatives include a stock exchange, support for Islamic finance innovation and a national sustainable finance taxonomy. Infrastructure and technology plans cover payment and credit system improvements, stronger cybersecurity, responsible artificial intelligence use, and digital asset regulation and sandbox testing.
Brunei Darussalam Central Bank (BDCB) launched the Brunei Darussalam Financial Sector Blueprint 2026–2035, setting three strategic priorities for the next decade: broadening financial access and financing options through market development and product innovation, integrating sustainability into financial regulation and investment, and modernizing financial infrastructure to support secure digital services and responsible technology adoption. Maintaining monetary and financial stability is the core principle underpinning these priorities. To broaden financial access, planned initiatives include products tailored to underserved groups and micro and small businesses, supported by financial and digital financial literacy programs. To diversify financing beyond traditional banking, market development plans include establishing a stock exchange and expanding asset management and sukuk and bond markets. Regulatory reviews would support the development of Islamic finance products and services. The sustainable finance priority centers on a national taxonomy and disclosure and reporting standards. Planned regulatory frameworks would require financial institutions and market participants to integrate environmental, social and governance (ESG) factors into their operations, risk management and decisions. An ESG data repository would support risk assessment, while incentives would encourage sustainable financial products and investments. To modernize financial infrastructure, plans include upgrading payment systems, expanding credit bureau data coverage and promoting wider acceptance of movable assets as collateral. Stronger safeguards for digital services would include mandatory cybersecurity standards for financial institutions and standards for system interoperability and secure data exchange, supported by consent controls. Alongside these infrastructure improvements, regulatory development would support ethical and responsible use of artificial intelligence. Digital asset initiatives include strengthening legal, regulatory and supervisory frameworks, including safeguards against money laundering and terrorist financing. Plans also call for assessing the feasibility and commercial applications of digital assets and distributed ledger technology, and encouraging regulatory sandbox testing before market entry.
The Indonesia Financial Services Authority launched RP3I 2026–2030, setting five strategic priorities spanning stronger institutions, digital resilience, deeper intermediation, sustainable finance and more integrated licensing and supervision, with concrete work on universal banking, AI and Open Banking–Open Finance. OJK also issued CRMS 2026, updating climate scenarios, emissions methodology and physical risk coverage and introducing standardized implementation solutions for banks.
The Indonesia Financial Services Authority (OJK) launched the 2026–2030 Indonesian Banking Development and Strengthening Roadmap (RP3I), setting a five-year direction for a modern, resilient and inclusive banking system. The roadmap is organized around five priorities covering institutional strengthening and integrity, technology modernization and digital resilience, financial market deepening and stronger intermediation, sustainable finance and sustainability risk resilience, and integrated licensing and adaptive supervision. Four cross-cutting enablers support implementation: the economic ecosystem, data and digital infrastructure, human capital, and cross-sector and cross-authority coordination. RP3I also follows the amended Financial Sector Development and Strengthening Law and aligns with the 2025–2029 National Medium-Term Development Plan. The roadmap translates these priorities into more specific regulatory and supervisory work. Technology initiatives include an AI maturity index and readiness assessments for areas such as the crypto-bank interface, interbank blockchain networks and post-quantum readiness. Under financial market deepening, OJK plans phased implementation of a universal banking framework covering areas including investment banking, wealth management, offshore products and digital asset activities, alongside Open Banking–Open Finance architecture and non-payment API standards. Licensing and supervision initiatives include a proportional risk-based licensing framework, an integrated licensing information system, stronger SupTech capabilities and greater use of machine-readable data and advanced analytics or AI in supervision. As part of RP3I implementation, OJK also published the 2026 Climate Risk Management and Scenario Analysis Guidelines (CRMS 2026). The revised framework updates the carbon emissions calculation methodology, macroeconomic assumptions and climate scenarios, and the scope of physical risks, while adding Book 7 Standardized Solutions to support more structured and consistent implementation by banks. CRMS integrates climate risk across governance, business strategy, risk management, measurement and targeting, and disclosure.
South Korea's Financial Services Commission has ordered immediate checks of all externally accessible systems following data breaches at major banks. Financial companies must examine authentication and access controls, limit unnecessary information exposure and promptly share threat intelligence. Authorities plan to require inspection results and oversee consumer protection and compensation at affected firms.
South Korea's Financial Services Commission (FSC) has directed financial companies to begin immediate security checks, strengthen authentication and access controls, and accelerate threat intelligence sharing following data breaches at major banks. The instructions came at an emergency meeting chaired by Secretary General Shin Jin-chang. Shinhan Bank reported exposure of personal and credit information belonging to about 25,000 customers, while KB Kookmin Bank confirmed a breach affecting 119 customers through its mobile work support system for employees. Security checks must cover every externally accessible IT asset and service, including systems that do not serve customers directly. Firms must identify vulnerabilities and access control weaknesses, reduce unnecessary information exposure and check for routes that allow access to internal information without adequate authentication. They must also promptly share attacker IP addresses, attack methods and attempted intrusions with relevant agencies and other financial companies to support a coordinated response. The FSC plans to provide vulnerability checklists and require firms to submit inspection results as soon as possible. The FSC, Financial Supervisory Service and Financial Security Institute have already launched investigations at affected firms and shared threat information with relevant agencies to prevent further damage. Authorities will supervise affected companies' handling of consumer protection and compensation, while analysis of the incidents and attack methods will inform further measures.
The European Central Bank is inviting a broad range of stakeholders to develop and explore digital euro innovations. Work in 2027 will cover payment features such as integrated receipts and conditional payments, as well as artificial intelligence and public sector uses. Any decision to issue a digital euro remains contingent on the adoption of relevant EU legislation.
The European Central Bank (ECB) has launched a call for expressions of interest for companies and organizations to help develop and assess potential digital euro innovations. Building on the digital euro innovation platform launched in 2024, the initiative expands stakeholder involvement in the Eurosystem’s preparations while remaining separate from any decision to issue a digital euro, which will follow only after relevant EU legislation is adopted. An experimentation workstream will turn earlier ideas into proofs of concept for integrated electronic receipts, transactions involving multiple payers or payees, conditional payments and payment app features. Conditional payments would execute automatically when predefined conditions are met and would not make the digital euro programmable money. An exploration workstream will examine possible future uses of artificial intelligence in payments and applications for public services, financial inclusion, automation and resilience, subject to privacy, user control and data protection principles. Experimentation is expected to run from January to June 2027, with participants developing and testing solutions and submitting outcome reports. Exploration workshops will take place at the ECB in the first and second quarters of 2027.
The European Union’s Authority for Anti-Money Laundering and Countering the Financing of Terrorism has finalised four sets of draft regulatory technical standards. These cover criteria for identifying business relationships and occasional or linked transactions, customer due diligence requirements, and minimum requirements for controls across groups. The fourth addresses cooperation between home and host supervisors, including information exchange, cross-border inquiries and coordinated supervision.
The European Union’s Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) has finalised three sets of draft regulatory technical standards (RTS) clarifying when and how obliged entities must conduct customer due diligence and organise controls across groups. A fourth establishes cooperation arrangements for supervisors of groups operating across borders. The drafts remain subject to European Commission adoption and publication in the Official Journal of the European Union. The standard on business relationships and occasional transactions clarifies how customer engagements should be classified to determine the applicable due diligence obligations. Linked occasional transactions would be assessed against thresholds using their combined value. Money remittance, currency exchange and crypto-asset exchange providers would consider three or more transactions within 12 months as an indicator of repetition when identifying business relationships, and two or more within one month when assessing linkage. The customer due diligence standard specifies the information obliged entities must collect and verify, including simplified checks and alternatives to verification in person. Simplified checks for low-risk individuals would omit address collection and verification. Alternative remote verification would be permitted, subject to safeguards, where customers cannot present identification in person and lack access to qualifying electronic identification and trust services. For relationships existing when the due diligence RTS enter into force, records would require updating within one year for higher-risk customers and five years for others. The group arrangements standard sets minimum requirements for governance, risk management and information sharing across groups, also covering certain structures with common ownership, management or compliance control. The EU parent undertaking would maintain common risk assessments and controls, supported by secure information sharing on a need-to-know basis. Where third-country laws obstruct compliance, groups would notify supervisors and mitigate risks, potentially restricting relationships or closing operations if risks remain unmanaged. Complementing these controls, the supervisory cooperation standard defines how home and host supervisors should coordinate oversight of groups operating across borders in the financial and nonfinancial sectors. Supervisors would exchange information on request and proactively where it could significantly affect risk assessments in another member state. The standard also sets procedures for cross-border inquiries and coordinated or joint inspections. Before requesting information, supervisors would check whether it is already accessible. Onward disclosure within the EU supervisory system would require notification of the originating supervisor rather than prior consent, except for information originating from third-country counterparts, which would remain subject to consent.
The European Securities and Markets Authority has proposed targeted MiCA amendments to strengthen investor protection and supervision while clarifying the treatment of DeFi, token classification, staking, lending and borrowing. The package includes tighter marketing and cost-disclosure rules, stronger powers against fraud, unauthorised third-country firms and non-compliant stablecoins, and simplifications to white-paper and authorisation processes. It also calls for a longer-term EU framework for tokenised securities and on-chain settlement.
The European Securities and Markets Authority (ESMA) has recommended targeted amendments to MiCA that would tighten investor protection and EU supervisory tools while clarifying the treatment of emerging crypto services and simplifying parts of the framework. Drawing on early implementation experience, ESMA wants clearer token classification, stronger convergence powers and a firmer regulatory perimeter for DeFi-related intermediation, staking, lending and borrowing. The proposals add to recent European Banking Authority and European System of Central Banks calls for clearer MiCA boundaries and regulatory treatment of crypto lending and DeFi. On investor protection, ESMA proposes tighter controls on crypto marketing, including obligations for influencers and third parties, fuller cost disclosure, and proportionate conduct, disclosure and safeguarding requirements for staking, lending and borrowing. It also seeks stronger powers to remove scam or unauthorised websites, freeze suspicious crypto-assets, act against unauthorised third-country firms soliciting EU investors, and prevent crypto-asset service providers from providing MiCA services involving non-compliant asset-referenced tokens or electronic money tokens. For DeFi, ESMA recommends clearer and narrow criteria for genuine decentralisation and a new regulated gateway service for crypto-asset service providers that give clients access to DeFi protocols, alongside binding ESMA opinions on token classification to reduce divergent treatment across member states. ESMA also proposes streamlining crypto-asset white-paper notifications by centralising the process at ESMA, removing duplicate authorisation for certain transfer services already covered by investment firms' existing MiFID II permissions, and aligning prudential requirements more closely with other EU frameworks. Beyond the immediate MiCA review, it calls for clearer rules for tokenised securities and on-chain settlement, potentially including an optional EU-level 28th regime to support cross-border tokenised capital markets.
The European Insurance and Occupational Pensions Authority reviewed progress and next steps under its simplification agenda for insurance and occupational pensions. Work so far includes proposed Solvency II reporting cuts and a review of 25 sets of guidelines that shortened their overall content by around a third. Further measures include postponing the next European Union-wide insurance stress test from 2027 to 2028 and reusing existing data to limit new reporting.
The European Insurance and Occupational Pensions Authority (EIOPA) published a follow-up to its simplification agenda, taking stock of measures to reduce regulatory and supervisory burdens across insurance and occupational pensions and setting out further plans. The update covers progress in simplifying reporting and guidance and applying proportionality. Further work focuses on easing implementation pressure, reusing existing data and reducing fragmented supervision across the European Union. Work undertaken so far includes revised Solvency II reporting proposals providing for 26% fewer quarterly templates and 30% fewer annual templates for solo undertakings. For small and non-complex undertakings, the corresponding reductions are 36% and 44%. Overall, the proposals reduce data points by 22%. EIOPA also reviewed 25 sets of guidelines, shortening their overall content by around a third, and finalized technical specifications for the new proportionality framework. Its assessment suggests around 660 undertakings, representing 28% of undertakings in the European Economic Area, may fall within the small and non-complex framework. To ease pressure during implementation of revised Solvency II rules and the Insurance Recovery and Resolution Directive, EIOPA will postpone the next European Union-wide bottom-up insurance stress test from 2027 to 2028. It will strengthen top-down analysis to support consideration of intervals of four years or longer between bottom-up tests. The upcoming occupational pensions stress test will also be postponed. Further reporting work will examine whether existing Solvency II data could reduce or replace separate liquidity reporting, with a report on integrated data reporting due by the end of 2026. Implementation of the Retail Investment Strategy will seek to align new disclosures with existing templates and prioritize existing data for value-for-money benchmarking. On supervisory coordination, the note raises the possibility of empowering EIOPA’s Board of Supervisors to adopt directly enforceable measures in exceptional circumstances when a national supervisor is unable or unwilling to act. More centralized supervision could be considered where harmonization is insufficient, including for cross-border insurance business.
The European Insurance and Occupational Pensions Authority's report identifies extreme heat as the leading climate liability risk for life and health insurers and occupational pension providers. Financial effects remain limited, but growing risks could affect claims, pension funding and insurance affordability. The report presents an illustrative assessment framework, with data and modelling gaps still preventing firm conclusions on financial materiality.
The European Insurance and Occupational Pensions Authority (EIOPA) published a report identifying extreme heat as the leading climate liability risk for life and health insurers, reinsurers and occupational pension providers. Financial effects remain limited, but more frequent and severe heatwaves are expected to increase risks over the coming decades. The report highlights the implications for mortality, morbidity and longevity assumptions, while finding that data and modelling gaps constrain assessments of the resulting financial exposure. Public healthcare coverage and offsetting effects across insurance products help explain the limited financial impact so far. Higher mortality can increase death benefit payments while reducing annuity liabilities, partly cushioning insurers offering both products. Rising illness and disability could nevertheless increase health claims. For occupational pension providers, changes in healthy working lives and retirement patterns could affect contributions and funding. As insurers adjust pricing and underwriting to reflect higher expected claims, coverage could become less affordable and protection gaps could widen. These risks remain unevenly reflected in prudential assessments. Among 90 life insurers examined in an own risk and solvency assessment survey, 68 considered physical risks nonmaterial, and few explicitly mentioned life or health risks. To support analysis of insurance exposures, EIOPA developed an illustrative framework combining heatwave projections, population vulnerability indicators and Solvency II technical provisions. However, its reliance on a single climate scenario and broad reporting categories prevents firm conclusions on materiality. Stronger assessments require more detailed data on individual products and insured populations, alongside scenarios that account for adaptation and demographic change.
The Swiss Financial Market Supervisory Authority found serious credit risk and anti-money laundering breaches at Julius Bär in its fifth concluded enforcement case against the bank in less than 10 years. Julius Bär must hold CHF 250 million in additional capital, obtain approval for shareholder payments and report on its risk and compliance culture through 2032. FINMA is also confiscating about CHF 10 million in profits and has opened proceedings against three former employees.
The Swiss Financial Market Supervisory Authority (FINMA) concluded a combined enforcement proceeding against Julius Bär, finding serious failings in credit risk management and compliance with anti-money laundering obligations. The case, its fifth concluded enforcement proceeding against the bank in less than 10 years, resulted in extended reporting, capital and shareholder payment controls, as well as the confiscation of about CHF 10 million in profits. Some earlier restrictions were lifted or relaxed following changes to the bank’s risk profile and remedial action. In its private debt business, Julius Bär granted eight loans to a European group and its founder from 2019, with total lending exceeding CHF 1 billion in 2022 and 2023. The bank lacked adequate governance, controls and trained staff, disregarded internal debtor limits and concentration risk reporting requirements, and failed to address conflicts of interest and warning signs. An outstanding CHF 586 million exposure was fully written down at the end of 2023. Separately, the bank inadequately examined the source of assets and suspicious behavior involving clients linked to two Russian politically exposed persons, failed to scrutinize negative media reports and breached statutory reporting obligations. Julius Bär must report on its risk, error and compliance culture through 2032. A ban on new relationships with politically exposed persons from high-risk countries will be phased out as the bank completes the divestment of client assets outside its revised risk appetite, and the bank must hold an additional CHF 250 million in capital until then. Shareholder payments, including dividends, require prior FINMA approval. The ruling is not yet legally binding. FINMA has also opened proceedings against three former employees who may bear responsibility for the violations.
The Swedish Financial Supervisory Authority has launched a review of financial firms’ defenses against cyber threats from advanced artificial intelligence models. Visits will assess how firms address emerging risks and adapt safeguards. Earlier National Cyber Security Center recommendations called for prompt security updates and controls on autonomous AI systems, including human confirmation before sensitive or irreversible actions.
The Swedish Financial Supervisory Authority (FI) has launched a detailed review of how financial firms protect themselves against cyber threats from advanced artificial intelligence (AI) models. Visits to firms will examine how they account for emerging threats and risks and their ability to adapt protective measures. The review follows dialogue with firms since spring 2026 and earlier calls to strengthen operational resilience. FI and Sweden’s central bank previously urged firms to consider the National Cyber Security Center’s June 2026 recommendations. These call for risk assessments covering both external attacks enhanced by AI and risks from internal AI systems. They prioritize prompt security updates for systems exposed to the internet and critical business systems, alongside reducing unnecessary internet exposure. For AI systems that act autonomously, recommended safeguards include limiting access and permissions and requiring human confirmation before sensitive or irreversible actions. Decisions and actions should be traceable, with a means to stop systems quickly if they behave unexpectedly.
The Dutch Authority for the Financial Markets found that five large institutional asset managers are broadly prepared for ICT outages but need stronger alignment between critical functions, recovery objectives, ICT assets, external providers and testing. It calls for consistent classification of critical functions, function-level recovery objectives, aligned contractual recovery requirements and testing across varied severe scenarios.
The Dutch Authority for the Financial Markets (AFM) has identified four areas where asset managers should strengthen ICT recovery after a review of five large institutional asset managers found that they are broadly prepared for ICT outages but have scope to improve the coherence of their recovery arrangements. Key processes, recovery plans and testing programs are generally in place, but the AFM found weaknesses in how critical functions, recovery objectives, ICT assets, external service providers and testing are linked. The findings are considered relevant to asset managers more broadly, subject to their nature, size and complexity. The AFM calls for more consistent identification and classification of critical functions, noting that classifications were not always aligned with those used for the 2026 DORA information register. It also found that recovery objectives were often set for individual ICT assets rather than for the functions they support. Asset managers should therefore define function-level Recovery Time Objectives and Recovery Point Objectives and ensure they understand which ICT assets and services are needed to meet them. The AFM also expects recovery requirements to be reflected in contracts with ICT service providers so that outsourced services support the institution's recovery objectives. Testing should cover a sufficiently broad range of severe but plausible scenarios. Although all firms had testing programs and tested failover between data centers, the scope and depth varied, with some focusing mainly on recurring system-outage tests. The AFM expects firms to test recovery plans and objectives against varied scenarios over time and to assess whether critical or important functions can be restored within defined recovery objectives.
The Arab Monetary Fund’s 50th anniversary in Abu Dhabi coincided with regional meetings on fiscal policy, financial stability and artificial intelligence. The UAE reviewed its public administration artificial intelligence target and reaffirmed minimum top-up tax application from 2025. Central Bank of Syria Governor Safwat Raslan assumed the Arab central bank governors’ council chairmanship and chaired its 50th session.
The Arab Monetary Fund (AMF) marked its 50th anniversary in Abu Dhabi alongside regional meetings addressing fiscal policy, financial stability and the use of artificial intelligence in public finance. The 17th Ordinary Session of the Council of Arab Finance Ministers reviewed regional and global economic developments. Central Bank of Syria Governor Safwat Raslan assumed the chairmanship of the Council of Governors of Arab Central Banks and Monetary Authorities for the year and chaired its 50th session, which discussed monetary and banking stability, payment systems and regional economic challenges. At the finance ministers’ session, the AMF assessed fiscal conditions and policies across Arab countries and presented applications of artificial intelligence in tax administration. UAE Minister of State for Financial Affairs Mohamed bin Hadi Al Hussaini reviewed the government’s target to convert 50% of federal operations and services to agentic artificial intelligence models within two years. He outlined their use across the Ministry of Finance and reported a 90% reduction in requirements and a 73% reduction in processing times under the Zero Bureaucracy Programme. Discussions also addressed blended finance for sustainable infrastructure and implementation of Base Erosion and Profit Shifting standards. The UAE reaffirmed its application of the UAE Domestic Minimum Top-up Tax from 2025 in line with the Global Anti-Base Erosion Rules. A related workshop on September 29 examined how geopolitical disruptions and economic uncertainty affect policymaking, alongside ways to strengthen fiscal and monetary policy coordination. The UAE presented its experience in establishing the Financial Stability Council and adopting plans to integrate artificial intelligence into financial stability monitoring. The anniversary programme also reviewed the AMF’s historical contribution, including more than USD 11.8 billion in financing over five decades, a doubling of its capital to nearly USD 10 billion and the development of regional payment infrastructure, including the Buna Payment System.
Saudi Arabia's Capital Market Authority has approved stronger audit quality and transparency requirements, effective upon publication. Registered accounting firms must have sufficient qualified audit managers, disclose quality management evaluations and implement approved corrective action plans where inspections warrant them. Firms must share final inspection results on listed company audit files with the relevant audit committees within 10 days of receiving them.
Saudi Arabia's Capital Market Authority (CMA) has approved amendments strengthening staff qualifications, quality management, inspection compliance and transparency disclosures for accounting firms auditing entities under its supervision. Registered accounting firms must have sufficient audit managers holding the Saudi Organization for Chartered and Professional Accountants fellowship, or equivalent professional fellowships accepted by the CMA, proportionate to the nature, scale and complexity of their activities. Firms must further maintain appropriate quality management systems for audits and reviews of financial statements. Reviews of interim financial statements and audits of annual financial statements must comply with professional standards. Firms must also cooperate with CMA inspections and provide complete and accurate information and documents. Where inspection results require a corrective action plan, firms must prepare and submit it within CMA deadlines and implement it after approval. They must share final inspection results on a listed company's audit file with its audit committee within 10 days of receiving them. Transparency reports must disclose firms' profiles, governance and leadership, describe their quality management systems and identify those responsible for oversight and operation. They must also disclose the results of annual evaluations of those systems' design and effectiveness.
Saudi Arabia's Insurance Authority has launched Sector Voice to gather insurance sector ideas from industry participants and beneficiaries on an ongoing basis. Suitable proposals will be directed to innovation programs covering technical ideas, entrepreneurial models and complex regulatory challenges. Participants will receive updates on progress and outcomes.
Saudi Arabia's Insurance Authority has launched Sector Voice, a program accepting ideas on an ongoing basis from insurance companies, intermediaries, experts and beneficiaries to identify sector needs and opportunities for improvement. The program forms part of the authority's innovation ecosystem, with suitable proposals directed to other programs for development into practical solutions. Submissions will be analyzed, evaluated and classified by their nature, importance and impact. Technical ideas may be referred to a hackathon, entrepreneurial models to an incubator or accelerator, and complex regulatory challenges to a solutions studio. Participants will receive updates on the progress of their ideas and resulting outcomes.
The Canadian Securities Administrators is consulting on a single rule consolidating existing information technology system requirements for market infrastructure entities. Targeted changes would extend governance, incident update and testing obligations and require annual independent system review reports to reach regulators within 60 days of completion. A planned second phase would consider broader coverage and stronger controls for cybersecurity, outsourcing and emerging technologies.
The Canadian Securities Administrators (CSA) has published a proposal to consolidate and harmonize existing information technology (IT) system requirements for market infrastructure entities, with targeted changes to governance, incident updates and testing. Proposed National Instrument 26-101 Information Technology System Integrity would cover marketplaces, recognized clearing agencies and trade repositories. Information processors and matching service utilities would also be covered. The framework would retain differences reflecting entities’ roles and preserve existing exemptions for marketplaces already exempt from IT system requirements. The proposal would extend explicit operational risk controls and board oversight requirements for critical systems to all covered entities. Trade repositories and matching service utilities would have to provide timely regulatory updates on material failures, malfunctions, delays and security incidents affecting critical systems. Matching service utilities would also have to test business continuity and disaster recovery plans at least annually, while their annual vulnerability assessment obligations under existing recognition orders would be incorporated into the rule. Annual independent system review reports would be submitted to regulators within a common deadline of 60 days after completion. For trade repositories, the existing expectation to maintain policies and procedures reasonably designed to restore critical systems within two hours of a disruptive event would become a rule requirement. Related marketplace amendments would remove the requirement for alternative trading systems to notify regulators when specified market share thresholds are reached, alongside duplicative reporting requirements. A second phase, planned after the instrument takes effect, would consider broader entity coverage and closer alignment with international standards. Consultation questions seek views on strengthening cybersecurity and outsourcing controls, addressing cloud concentration risk and establishing specific oversight requirements for artificial intelligence and other emerging technologies.
The United States Securities and Exchange Commission has proposed conditional crypto self-custody and state trust company custody for registered investment advisers and regulated funds. Self-custody would require the absence of a permitted custodian and specified safeguards, with board oversight for regulated funds. Broader amendments would revise adviser audit obligations and ease certain broker-dealer custody requirements.
The United States Securities and Exchange Commission (SEC) has proposed a crypto asset custody framework for registered investment advisers and regulated funds, comprising registered investment companies and business development companies. It would permit self-custody through advisers where a permitted custodian is unavailable and allow state trust company custody subject to safeguards. Broader amendments would revise adviser audit obligations and fund custody requirements. Advisers using self-custody would have to reassess custodian availability quarterly, keep each client’s crypto assets in separate addresses and maintain safeguards covering private key management and transaction authorization by at least two people. Safeguarding systems and cybersecurity controls would require at least annual review. Independent accountant control reports would be required within six months of taking self-custody and annually thereafter. Clients would receive statements at least quarterly and agree in writing with the adviser to treat the crypto assets as financial assets. Regulated fund boards would oversee their advisers’ self-custody arrangements. State trust company custody would require due diligence on state authorization and safeguarding policies, alongside review of annual audited financial statements and internal control reports, before appointment and annually thereafter. Client and fund crypto assets would have to remain separate from the trust company’s proprietary assets. The broader amendments would remove requirements for accountants engaged under the adviser custody rule to be registered with and regularly inspected by the Public Company Accounting Oversight Board. Deadlines for delivering audited financial statements would be extended for funds of funds and funds of funds of funds. Audited financial statements would have to follow U.S. Generally Accepted Accounting Principles, with an exception for foreign pooled investment vehicles. Exceptions to adviser custody requirements would cover specified circumstances involving discretionary trading authority and inadvertent custody. Custody arising solely from standing letters of authorization would qualify for an exception from independent verification. For regulated funds, the proposal would remove certain conditions on broker-dealer custody. Records maintained and preserved on crypto networks could satisfy recordkeeping requirements subject to conditions.
The U.S. Securities and Exchange Commission has proposed broader performance fee eligibility and more flexible regulated fund structures to expand retail access to private markets. The proposed fee framework for regulated funds would impose a 20% cap on net gains, while qualified client eligibility would expand to include accredited investors. A separate consultation considers an exam and professional credentials as additional routes to accredited investor status.
The U.S. Securities and Exchange Commission (SEC) has proposed changes to adviser compensation and regulated fund structures to broaden retail access to private market strategies. It is separately seeking comment on additional accredited investor qualifications. The proposals would expand registered investment advisers’ ability to receive compensation based on capital gains or appreciation from regulated funds, subject to a cap of 20% of net gains over a specified period. Funds would need to meet governance standards. Their boards, including a majority of independent directors, would have to determine that fee arrangements are in the best interests of the fund and its shareholders and make findings on appropriateness, structure and investor protections. Registration and reporting forms would require performance fee disclosures. The qualified client definition would also expand to include investors meeting the accredited investor definition, removing the separate net worth and assets under management tests. Interval funds could defer initial repurchase offers for longer, conduct more frequent discretionary repurchases and adopt monthly periodic intervals. A principles-based liquidity approach would replace the requirement to hold a specified amount of liquidity. Regulated closed-end funds could issue multiple share classes under a rules-based framework replacing individual exemptive orders, and enter into arrangements for asset-based distribution and service fees. Related changes would update prospectus disclosures and share class reporting, with enhanced expense disclosures for all regulated closed-end funds. The separate consultation considers additional non-financial routes to accredited investor status, including passing an exam to be developed by the Financial Industry Regulatory Authority (FINRA) or holding specified professional credentials in good standing. Credentials under consideration include U.S. certified public accountant licenses, Chartered Financial Analyst charters and U.S. Certified Financial Planner certifications. FINRA Investment Banking Representative licenses, Series 79, and Research Analyst licenses, Series 86 and Series 87, are also under consideration.
The Federal Reserve Board finalized stress test transparency rules and averaging of results from two annual tests to calculate eligible banks' stress capital buffers. Averaging begins in 2028 for buffers effective January 1, 2029. The package, including adopted and proposed model changes, is expected to halve annual buffer volatility without materially changing aggregate capital requirements.
The U.S. Federal Reserve Board (FRB) finalized two rules requiring public input on stress test scenarios and material model changes and introducing averaging of annual test results to calculate large banks' stress capital buffers. It also proposed a revised noninterest income model to better capture differences in banks' fee income businesses. Together, the adopted and proposed changes are expected to reduce annual volatility in stress capital buffer requirements by approximately 50%, without materially changing aggregate capital requirements. The transparency rule applies from the 2027 stress test and retains the December 31 starting date. Model descriptions will be published annually by May 15. Beginning with the 2028 test, material model changes must be proposed by August 31 of the preceding year. Banks with large trading books will face two global market shock scenarios using the same reference date, with the shock producing the larger loss determining each firm's results. The adopted 2027 models include an interim noninterest income model segmented by firm type. The proposed replacement would use data more directly linked to each revenue activity and could apply for the 2027 test if finalized in time. For firms tested in both of the two most recent annual supervisory tests, the buffer calculation will equally weight each test's maximum common equity tier 1 capital ratio decline, then add four quarters of planned dividends and apply the 2.5% floor. The annual effective date for new buffers moves from October 1 to January 1, first applying on January 1, 2028, giving firms three additional months to comply. Averaging begins in 2028 for buffers effective January 1, 2029, ensuring that both tests use models incorporating public input. It generally will not apply following a material business plan change.
The New York State Department of Financial Services and the Wyoming Division of Banking have agreed to coordinate oversight of digital asset entities operating in both states. The arrangement covers licensing reviews, examination schedules, potential joint examinations and the sharing of supervisory and enforcement information.
The New York State Department of Financial Services (DFS) and the Wyoming Division of Banking have signed a memorandum of understanding to coordinate licensing, supervision and enforcement involving virtual currency and digital asset entities operating in both states. The agreement formalizes information sharing and allows each regulator to draw on the other’s supervisory expertise. The regulators will coordinate reviews of entities licensed or chartered in one jurisdiction and those applying in both states, sharing analysis, subject matter reviews and historical examination data to streamline applications. They will also align examination schedules, work toward joint examinations and exchange supervisory reports, market trend data and notifications of potential enforcement actions.
Monetary policy developments
Decisions during the week of September 28–October 4 extended the recent tightening in several economies, as prolonged energy and food shocks prompted further action to contain inflation. Australia unanimously raised its cash rate by 25 bp to 4.60%, its fourth increase this year, after inflation exceeded expectations despite slowing activity. Higher fuel costs were spreading to other prices, while AI-related demand was increasing technology costs and adding to existing capacity pressures. Jamaica increased its rate by 50 bp to 6.00% after August’s hold, judging that renewed hostilities and El Niño-related crop losses would prolong inflation pressures and risk embedding higher expectations. Inflation was now projected to return to the target range by mid-2027. The Dominican Republic also raised rates by 25 bp to 5.50%, acting preventively against persistent oil, shipping and weather-related pressures even though inflation was declining and medium-term expectations remained anchored. Sri Lanka maintained 8.75%, taking account of the effects of May’s tightening and moderating credit growth. Although energy costs had lifted inflation to 8.0% and spread across several sectors, medium-term expectations remained aligned with its target. Mozambique held at 9.25% amid inflation risks and a slow recovery, but introduced reserve-requirement deductions to encourage bank lending to businesses expanding exports or replacing imports. More favourable domestic price conditions supported reductions in Zambia and Zimbabwe. Zambia cut 250 bp to 10.75% as a record maize harvest and currency appreciation helped bring inflation to 6.1%, with forecasts keeping it near the lower bound of the 6–8% target range despite continuing energy and weather risks. Zimbabwe likewise reduced its rate by 250 bp to 27.50%, citing price and exchange-rate stability, but explicitly described the reduction as aligning the policy rate with inflation rather than signalling monetary easing.