Global Regulator & Central Bank News Roundup
Edition 402026Week of October 5
Global developments
The Financial Stability Board has released a thematic review of public sector backstop funding mechanisms for systemic bank resolution. It found material gaps in 10 of 19 jurisdictions, with only four fully compliant. Six recommendations call for clearer, scalable and operationally ready funding arrangements, stronger safeguards against taxpayer losses and moral hazard, and improved cross-border and foreign currency liquidity coordination.
The Financial Stability Board (FSB) published a thematic review of public sector backstop funding (PBF) mechanisms, identifying material gaps in about half of member jurisdictions. Only four of the 19 jurisdictions assessed were fully compliant with Key Attribute 6 on funding in resolution. These mechanisms provide temporary liquidity to systemic banks in resolution as a last resort when private sources are exhausted or cannot support an orderly resolution. The main weaknesses concern funding scale and the ability to deploy resources quickly. Many jurisdictions have not clearly established how much funding would be available or how multiple sources would work together. Some cannot demonstrate how resources would be converted into cash or lack testing and coordination across authorities. Six recommendations call for urgent action by jurisdictions. First, on establishment and coordination, jurisdictions should clarify in advance what temporary public funding would be available, how multiple arrangements would work together and how they fit within the broader financial safety net. Public communication should build confidence without implying an entitlement to support. Second, on scale and flexibility, mechanisms should provide liquidity at the scale required for the resolution of one or more systemic banks. Where banking sector size and structure warrant it, jurisdictions should consider arranging access to additional public resources, including guarantees or indemnities, subject to strong safeguards and taking account of available private funding and public resource capacity. Third, on operational readiness, authorities should establish governance arrangements across relevant agencies, including central banks, set expectations for systemic banks’ ability to access liquidity and regularly test arrangements against rapid failure scenarios. Fourth, on loss recovery, public funding should be supported by a clear legal basis and operational powers to allocate losses to shareholders and unsecured creditors, with subsequent industry assessments where earlier recovery tools prove insufficient. Fifth, on moral hazard mitigation, principles governing access and funding terms should be defined in advance to limit moral hazard without impeding timely liquidity, while individual terms may be determined case by case. Sixth, on cross-border coordination, jurisdictions with systemic banks that have material international operations or foreign currency funding needs could strengthen preparations with home, host and other relevant authorities for liquidity provision and distribution. This includes clarifying coordination channels, reducing ringfencing risks and discussing how foreign currency funding would be provided under acute resolution timelines. The report also recommends that the FSB support implementation by sharing practices, building on existing implementation materials where necessary and closely monitoring progress.
The Basel Committee on Banking Supervision reported that, as of 30 September 2026, three quarters of its 27 member jurisdictions have published rules adopting the full final Basel III standards and 47% have completed implementation. With few exceptions, all members require banks to apply the standards by April 2027 or earlier.
The Basel Committee on Banking Supervision published its latest progress update on Basel III adoption. As of 30 September 2026, three quarters of its 27 member jurisdictions have published rules adopting the full set of final Basel III standards. Implementation is completed in 47% of members, and with few exceptions, all members have announced that banks must apply the standards by April 2027 or earlier. Progress varies by standard. The revised credit risk and operational risk standards and the output floor are effective in around 85% of member jurisdictions, up from around 80% a year earlier. The credit valuation adjustment (CVA) standard is effective in nearly 70% and the revised market risk standards in more than 40%. Over the past 12 months, three jurisdictions published additional Basel III standards. The Group of Central Bank Governors and Heads of Supervision (GHOS) had set 1 January 2023 as the implementation date, and the Committee now expects implementation to be nearly complete by the first half of 2027.
The International Monetary Fund (IMF) calls for stronger monitoring and targeted safeguards as hedge fund gross notional exposures reach about USD 40 trillion. Its analysis finds that leverage, crowded trades and correlated investor withdrawals can amplify market losses and transmit stress through banks and across borders. Recommended measures include improved reporting, risk-based leverage constraints, stronger prime broker oversight and system-wide stress testing.
In a new blog post, the International Monetary Fund (IMF) highlights growing financial stability risks from hedge funds. Hedge fund gross assets have tripled since 2013 to USD 13 trillion, while gross notional exposures have reached about USD 40 trillion. The IMF calls for stronger monitoring of hedge fund leverage and interconnectedness, alongside policy measures tailored to the sources of systemic risk. The analysis finds that leverage can trigger forced asset sales when volatility increases or financing conditions tighten, particularly where funds hold similar positions or face simultaneous investor redemptions. During periods of market stress, the most crowded stocks experience 10 percentage points higher volatility and 4 percentage points deeper peak-to-trough losses than the least crowded stocks, with leverage amplifying these effects. Risks can also spread through prime brokers, typically large dealer banks providing financing to hedge funds, and across borders. Markets with greater hedge fund ownership experience larger equity declines following global shocks, particularly where liquidity is limited. Hedge funds also held approximately 9% of US Treasurys in 2025, underscoring their role in sovereign bond markets and the potential for rapid unwinding of leveraged basis trades to disrupt market liquidity. The IMF recommends addressing gaps in regulatory reporting and information sharing, particularly concerning leverage, derivatives exposures, prime broker relationships and cross-border activities. Where risks stem from synchronized deleveraging, market-wide minimum margins and haircuts, alongside stronger collateral management, could help contain vulnerabilities. More concentrated risks may warrant risk-based leverage limits, margin or capital add-ons, and large-exposure limits. The IMF also advocates stronger counterparty risk management by prime brokers and system-wide stress testing to assess how shocks could propagate across hedge funds, financial institutions and markets.
The Islamic Financial Services Board (IFSB) has issued for consultation a revised risk management Standard for takāful undertakings to replace IFSB-14, issued in 2013. The draft requires operator fees based on actuarial assessment, minimum retained reserves in the Participants' Risk Fund, and limits on surplus distribution and qarḍ. Supervisors would assess each segregated fund separately.
The Islamic Financial Services Board (IFSB) has published for consultation a revised Standard on risk management for takāful undertakings. It will supersede IFSB-14, issued in December 2013. The revision aligns the Standard with the IFSB's Core Principles for Islamic Finance Regulation for the takāful segment (IFSB-27) and with developments in international insurance standards. The draft is addressed to supervisors and focuses on risks arising from the distinct structure of takāful. It moves risk management and supervision to the level of each segregated fund, particularly the Participants' Risk Fund (PRF). It also addresses conflicts between the fiduciary duty of the takāful operator (TO) toward participants and its commercial interest in its remuneration. Supervisors should require each PRF to hold retained reserves above a set minimum. The TO's management fee should rest on an independent actuarial assessment rather than any regulatory ceiling. Where contributions are set below actuarially recommended levels, the adjustment should fall on the fee rather than reduce the PRF's allocation. Surplus may be distributed only where reserve requirements continue to be met, and not while the PRF is in deficit or reliant on financial support. Qarḍ is a loan from the Shareholders' Fund to the PRF, repayable from future surpluses. It should not substitute for addressing recurring deficits, and TOs should rectify deficits caused by their own decisions without recourse to it. Supervisors should assess each segregated fund separately. This assessment should draw on reporting on the PRF's underwriting result, reserves, liquidity and outstanding qarḍ, and on peer comparisons of contributions, expenses and remuneration. Early warning indicators include persistent PRF deficits and repeated Sharīʻah compliance incidents. Corrective measures range from adjusting contribution levels and limiting surplus distribution to the run-off of structurally unviable funds. TOs should also integrate Sharīʻah governance into routine controls and document how expenses and revenues are allocated between funds.
The International Organization of Securities Commissions has named South Africa's Altara and India's SwipeWise as winners of its inaugural TechSprint on AI investor education. Altara developed tools to help retail investors identify AI-enabled scams, while SwipeWise uses game-based learning to strengthen investors' ability to evaluate AI-generated financial information.
Against the backdrop of the annual World Investor Week, the International Organization of Securities Commissions (IOSCO) has named South Africa's Altara and India's SwipeWise, a team from the Securities and Exchange Board of India (SEBI), as winners of its first TechSprint focused on investor education in the age of artificial intelligence (AI). Both teams received Pilot Pathway Awards for solutions addressing two key challenges facing retail investors: identifying and avoiding AI-enabled fraud and using AI as a financial learning tool while understanding its risks. The awards recognize solutions with the clearest potential for further regulatory testing, pilot projects or practical deployment. Altara's solution combines verification tools, contextual investor education and scam-risk intelligence to help investors identify fraudulent activities and trusted financial interactions, while enabling financial institutions to demonstrate fair consumer outcomes. SwipeWise uses game-based learning to train investors to recognize AI hallucinations, assess explainability, verify claims and evaluate confidence in AI-generated information. Its configurable architecture allows regulators across jurisdictions to deploy locally relevant educational content without rebuilding the platform. Developed with support from the UK Financial Conduct Authority's AI Lab, the TechSprint attracted 65 applications, with 14 teams from 11 jurisdictions presenting their solutions. Four additional awards recognized projects from SEBI, the Monetary Authority of Singapore and South Korea's Financial Supervisory Service for their approaches to accessible investor protection, AI transparency, global transferability and behavioural impact.
The Financial Planning Standards Board’s second global survey found that eight in 10 planners reported their firms were using, testing or planning to adopt artificial intelligence within 12 months, up from six in 10 in 2025. Some 93% reported efficiency improvements, while majorities expected better advice quality, wider access and lower costs. However, only 23% reported comprehensive firm policies, with gaps in coverage of human review, third-party AI vendor assessment and record-keeping of AI-assisted advice.
The Financial Planning Standards Board (FPSB) has published its second global report on artificial intelligence (AI) in financial planning, based on a survey of 8,095 planners. Eight in 10 respondents reported that their firms were using, testing or planning to adopt AI within 12 months, up from six in 10 in 2025. This comprised 51% already using AI, 22% piloting or testing it and 7% planning adoption. Client communication was the leading use at 51%, while market analysis and product research reached 42%, up from 28%. Across the survey, 93% reported improved work efficiency, while 52% cited operational efficiency gains and 49% an increased ability to serve clients. Expectations for client benefits also strengthened: 75% expected AI to improve advice quality, up from 60%, while 70% expected greater access for underserved populations and 68% lower advice costs. Firm policies have developed alongside adoption but remain limited. Comprehensive AI policies were reported by 23% of respondents, up from 17%, while those reporting no guidance fell from 28% to 22%. Among respondents whose firms had policies or guidance, 48% said these covered human review before AI outputs reached clients, 22% third-party AI vendor assessment and 18% record-keeping of AI-assisted advice. Data privacy and cybersecurity, cited by 53%, and output accuracy and reliability, cited by 48%, remained the leading concerns. Client use of AI was also changing advice conversations, with 21% of planners reporting an increased need to contextualize or correct AI-generated information. The report distinguishes AI assistance with technical and administrative tasks from the continuing role of professional judgment, ethical reasoning and accountability. Education and training was the most frequently selected initiative for safer and more responsible AI use, chosen by 34%, while 50% wanted further professional development in data analysis and interpretation.
In a new departmental paper, International Monetary Fund staff warn that wider use of foreign currency stablecoins issued abroad could help residents of recipient countries circumvent capital flow management measures and accelerate currency substitution. Staff call for sound macroeconomic frameworks, comprehensive regulation, better data and closer international cooperation. Where financial frictions are high, they also call for larger foreign exchange reserves.
In a new departmental paper, staff of the International Monetary Fund (IMF) assess how wider adoption of stablecoins issued abroad and pegged to a foreign currency (FX stablecoins) could affect recipient countries. The analysis draws on the IMF's Institutional View on the Liberalization and Management of Capital Flows (IV) and its Integrated Policy Framework (IPF). FX stablecoins make up 99 percent of a stablecoin market worth USD 317 billion as of June 2026. Their current macrofinancial effects are limited, but broader use could weaken capital flow management measures (CFMs), deepen currency substitution and raise exposure to shocks, especially where policy frameworks and data are weak. Unregulated local crypto exchanges and unhosted wallets let residents bypass CFMs. This could trigger a de facto "big bang" capital account liberalization with large and sustained outflows. Greater currency substitution could drain bank deposits, weaken monetary policy transmission and shift seigniorage to private issuers. Over the medium term, stablecoins used for foreign exchange (FX) borrowing could widen FX mismatches. Use for FX savings and market arbitrage, by contrast, could reduce mismatches and deepen FX markets. Sound monetary and fiscal frameworks remain the first line of defense. Staff prefer comprehensive regulation to blanket bans, supported by clear legal classification and mandatory reporting. The IV does not envisage new outflow CFMs outside actual or imminent crises. For such crises, CFM laws should explicitly cover FX stablecoin transactions and be prepared in advance. In the near term, countries with significant financial frictions, high adoption and reliance on outflow CFMs may need larger FX reserves and more FX intervention. Over the medium term, the policy mix depends on whether stablecoins amplify or reduce those frictions. Closer international cooperation on regulation and data sharing is also needed.
In a new paper, the Bank for International Settlements assesses how rising energy use and rebound effects could offset the climate benefits of AI. These interactions could complicate monetary policy and create financial vulnerabilities through investment in AI and energy infrastructure. The policy discussion highlights harmonised environmental reporting, more efficient AI systems and incentives for additional renewable generation and storage.
The Bank for International Settlements (BIS) has published a new paper assessing the uncertain net climate impact of artificial intelligence (AI) and its implications for central banks. Improvements in energy efficiency, climate forecasting and cleaner technologies could be offset by rising electricity demand and rebound effects as lower costs stimulate AI use and resource consumption. The balance depends on computational efficiency, the carbon intensity of additional electricity and how productivity gains affect economic activity. Benefits and environmental costs are likely to accumulate more gradually under an AI copilot scenario, while artificial general intelligence, with cognitive capabilities comparable to humans across a broad range of tasks, could amplify both. For central banks, productivity gains could expand supply and lower production costs, but investment and energy pressures may emerge before those gains materialise, complicating assessments of inflation and economic slack. Investment in data centres and related infrastructure increasingly relies on private credit and bond markets. Disappointing returns could weaken credit quality and trigger asset price corrections. Investments that lock in carbon emissions could increase transition risks if climate policies tighten, while grid disruptions and extreme weather could impair borrowers’ cash flows. Conversely, AI could improve climate risk forecasting, insurance pricing and risk measurement. The policy discussion highlights the absence of a common international standard for measuring and disclosing AI’s environmental footprint. Harmonised reporting would help firms and investors assess emissions and policymakers monitor transition plans, while more efficient models, hardware and cooling could lower the energy intensity of AI applications. Public incentives could encourage additional renewable generation and storage rather than redirect existing clean electricity towards data centres. Continued investment in fossil fuel generation to power AI could instead lock economies into infrastructure with high carbon emissions for decades.
In a new technical note, International Monetary Fund staff find financial stability risks from the artificial intelligence (AI) boom manageable, as highly profitable incumbents lead the investment. Growing reliance on external debt and circular financing, combined with high market concentration, could however amplify shocks if AI monetization or productivity gains disappoint.
In a new technical note, International Monetary Fund (IMF) staff mapped the artificial intelligence (AI) ecosystem through an AI Value Stack of 74 firms and assessed its financial stability implications. Current risks appear manageable as highly profitable incumbents with strong balance sheets anchor the cycle. However, investment increasingly relies on external and circular financing. Together with asset obsolescence, high market concentration and rising co-movement among AI stocks, these linkages could amplify shocks if AI monetization or productivity gains disappoint. Vulnerabilities sit mainly outside core AI. Hyperscalers and chip developers, with an aggregate operating margin near 30%, have sustained heavy investment without materially raising leverage. The graphics processing unit (GPU)/Neocloud layer is the weakest, with leverage above 600% and negative profitability. Total AI capital expenditure is projected to exceed USD 4 trillion by 2029. Firms in the stack have issued over USD 530 billion of bonds since 2023, and private credit is among the fastest growing channels. Circular financing is a key amplification channel. In these deals, large firms fund suppliers and developers while also acting as their customers. Across 14 large US deals, about USD 300 billion of equity is tied to USD 1.4 trillion of revenue commitments, and nine of the deals were followed by more than USD 650 billion of additional debt. Vulnerabilities are concentrated among investees, and limited disclosure obscures where exposures ultimately reside. Shorter asset lives could further raise financing needs. Rising correlations among AI stocks mean a repricing could spread quickly across the market. The note highlights the growing importance of transparency, of monitoring interconnected exposures, and of attention to leverage at bank and nonbank financial institutions.
Active global consultations
The Islamic Financial Services Board is seeking feedback on a revised Standard on risk management for takāful undertakings that would supersede IFSB-14. It addresses risks arising from the distinctive structure of takāful, in which participants collectively bear underwriting risk through the Participants’ Risk Fund without being directly represented in its governance. The fund is instead managed by the takāful operator, which must act in participants’ interests while being paid out of the same funds it manages, which can create conflicts of interest. Supervisors would require each Participants’ Risk Fund to hold retained reserves in addition to technical provisions, management fees to be based on independent actuarial assessment, and surplus not to be distributed while the fund is in deficit, below minimum reserves or reliant on financial support. Operators would have to rectify, without recourse to qarḍ, deficits caused by their own decisions that inappropriately reduced the fund’s resources. Risk management, internal controls and supervisory assessment would operate at fund as well as enterprise level, with Sharīʻah non-compliance risk integrated throughout.
The Islamic Financial Services Board is seeking feedback on a revised Standard on risk management for takāful undertakings that would supersede IFSB-14. It addresses risks arising from the distinctive structure of takāful, in which participants collectively bear underwriting risk through the Participants’ Risk Fund without being directly represented in its governance. The fund is instead managed by the takāful operator, which must act in participants’ interests while being paid out of the same funds it manages, which can create conflicts of interest. Supervisors would require each Participants’ Risk Fund to hold retained reserves in addition to technical provisions, management fees to be based on independent actuarial assessment, and surplus not to be distributed while the fund is in deficit, below minimum reserves or reliant on financial support. Operators would have to rectify, without recourse to qarḍ, deficits caused by their own decisions that inappropriately reduced the fund’s resources. Risk management, internal controls and supervisory assessment would operate at fund as well as enterprise level, with Sharīʻah non-compliance risk integrated throughout.
The Committee on Payments and Market Infrastructures and the Board of the International Organization of Securities Commissions are seeking feedback on a discussion paper examining the risk management challenges arising from financial market infrastructures’ increasing reliance on third-party service providers, including for critical services. The paper reflects FMIs’ systemically important and highly interconnected role and focuses on how external and intra-group service arrangements can increase operational risk and create channels through which disruptions may be transmitted across the financial system. It does not propose additional guidance but seeks views on whether the identified challenges are comprehensive and whether further engagement or policy support would be beneficial. The paper identifies six principal challenges: increasing complexity and interconnectedness of FMI ecosystems, including cyber-related risk; concentration of third-party service providers and resulting single points of failure, vendor lock-in and systemic dependencies; complex and opaque supply chains and limited visibility of nth-party providers; difficulties designing practicable exit strategies and substituting providers, especially in stressed conditions; imbalances in bargaining power that can limit audit, information-sharing, testing and service-level rights; and variation in regulatory, supervisory and oversight expectations across jurisdictions.
The Committee on Payments and Market Infrastructures and the Board of the International Organization of Securities Commissions are seeking feedback on a discussion paper examining the risk management challenges arising from financial market infrastructures’ increasing reliance on third-party service providers, including for critical services. The paper reflects FMIs’ systemically important and highly interconnected role and focuses on how external and intra-group service arrangements can increase operational risk and create channels through which disruptions may be transmitted across the financial system. It does not propose additional guidance but seeks views on whether the identified challenges are comprehensive and whether further engagement or policy support would be beneficial. The paper identifies six principal challenges: increasing complexity and interconnectedness of FMI ecosystems, including cyber-related risk; concentration of third-party service providers and resulting single points of failure, vendor lock-in and systemic dependencies; complex and opaque supply chains and limited visibility of nth-party providers; difficulties designing practicable exit strategies and substituting providers, especially in stressed conditions; imbalances in bargaining power that can limit audit, information-sharing, testing and service-level rights; and variation in regulatory, supervisory and oversight expectations across jurisdictions.
The Committee on Payments and Market Infrastructures (CPMI) and the Board of IOSCO are consulting on a voluntary, non-binding cyber resilience toolkit intended to provide financial market infrastructures with practical, technology-neutral support for strengthening their cyber resilience frameworks and implementing operational resilience-related components of the Principles for financial market infrastructures, as informed by the 2016 CPMI-IOSCO Guidance on cyber resilience for financial market infrastructures. The toolkit is organized around four areas: (1) governance of cyber risk and resilience, including board and senior management capabilities, ecosystem risk management, maturity models and resilience metrics; (2) identification and design of extreme but plausible cyber scenarios, including scenario scope, threat intelligence, emerging risks and ecosystem dependencies; (3) response, resumption and recovery planning, covering critical operations and information assets, infrastructure and data resilience, third-party dependencies, contingency arrangements, safe resumption and the disconnection and reconnection of ecosystem entities; and (4) cyber resilience testing and exercising.
The Committee on Payments and Market Infrastructures (CPMI) and the Board of IOSCO are consulting on a voluntary, non-binding cyber resilience toolkit intended to provide financial market infrastructures with practical, technology-neutral support for strengthening their cyber resilience frameworks and implementing operational resilience-related components of the Principles for financial market infrastructures, as informed by the 2016 CPMI-IOSCO Guidance on cyber resilience for financial market infrastructures. The toolkit is organized around four areas: (1) governance of cyber risk and resilience, including board and senior management capabilities, ecosystem risk management, maturity models and resilience metrics; (2) identification and design of extreme but plausible cyber scenarios, including scenario scope, threat intelligence, emerging risks and ecosystem dependencies; (3) response, resumption and recovery planning, covering critical operations and information assets, infrastructure and data resilience, third-party dependencies, contingency arrangements, safe resumption and the disconnection and reconnection of ecosystem entities; and (4) cyber resilience testing and exercising.
Regional developments
The Securities and Exchange Commission of the Philippines has proposed revised Green Equity guidelines requiring labeled listed companies to derive more than 50% of revenue and investments from taxonomy Green Activities and less than 5% of revenue from fossil fuels. The stock exchange would grant and monitor the label and accredit external reviewers, while labeled companies must publish annual externally reviewed assessment reports. Full alignment with the Philippine or ASEAN sustainable finance taxonomy becomes mandatory from FY 2027, following a transition period until end 2026.
The Securities and Exchange Commission (SEC) of the Philippines has released for public comment a draft Memorandum Circular revising its Guidelines on Philippine Green Equity, a voluntary label for publicly listed companies whose business is predominantly green. The draft sets four eligibility criteria for the label and gives the stock exchange responsibility for granting and monitoring it and for accrediting external reviewers. It also phases in mandatory alignment with the Philippine Sustainable Finance Taxonomy Guidelines (SFTG) or the ASEAN Taxonomy for Sustainable Finance (ATSF) from FY 2027. To qualify, a company must derive more than 50% of its revenue from Green Activities as classified under the SFTG or ATSF, and channel more than 50% of its investments, measured as the sum of capital and operating expenditure, into such activities, both based on the latest audited annual financial statements. Revenue from fossil fuels must stay below 5%, and the activities counted towards the thresholds must meet the eligibility criteria of either taxonomy. Failing any one criterion disqualifies a company from obtaining or keeping the label. Until end 2026, full taxonomy alignment will not be mandatory, and gaps in technical alignment will not trigger penalties, fines or label revocation. Applicants must nonetheless disclose how their Green Activities substantially contribute to at least one environmental objective and confirm, to the best of their knowledge, that they cause no significant harm and do not materially breach minimum social safeguards. From FY 2027, full alignment becomes mandatory for the initial grant, retention or renewal of the label.Companies, including those already listed, must apply to the Exchange, which covers the Philippine Stock Exchange (PSE) and other exchanges registered with the SEC. The Exchange would grant the label, flag labeled companies in its index or a separate index, publish a public registry and monitor ongoing compliance, with powers to withdraw, suspend or cancel the label. Labeled companies must publish an annual, externally reviewed assessment report on their green revenue and investment shares, taxonomy alignment and fossil fuel exposure. External reviewers would be accredited by the Exchange under implementing guidelines approved by the SEC, which may direct the suspension or revocation of an accreditation for cause.
Following consultation, the Monetary Authority of Singapore has issued artificial intelligence (AI) risk management guidelines for all financial institutions, with controls proportionate to risk. Institutions should establish board and senior management oversight and manage risks across the AI life cycle, including accountability for third-party AI. Oversight and core risk management expectations apply from 7 October 2027, with life cycle controls and capability and capacity expectations to be met by 7 October 2028.
The Monetary Authority of Singapore (MAS) has issued Guidelines on Artificial Intelligence (AI) Risk Management for all financial institutions and all forms of AI, including generative AI and AI agents. Institutions should manage risks at enterprise and individual use case levels through proportionate governance, life cycle controls and oversight of third-party AI. Oversight and core risk management expectations apply from 7 October 2027, while expectations for life cycle controls, capabilities and capacity should be met by 7 October 2028. Boards and senior management should establish clear responsibilities and risk appetite. Existing governance structures may be used where they provide adequate oversight and coordination, without establishing a dedicated AI committee. Institutions should identify and inventory AI use and assess each use case’s impact, complexity and reliance on AI. Identification should, at a minimum, cover AI embedded in or used to deliver services from material third-party providers. Basic governance policies and procedures may suffice where poor performance or unavailability of an institution’s AI services or tools is unlikely to materially affect the institution, its customers or other stakeholders. These arrangements should still provide clear accountability and human oversight, with controls over permitted uses and approved tools. Life cycle controls should protect data and systems and provide for testing, human oversight and ongoing monitoring. Use cases with high risk materiality should undergo independent validation before deployment and regular independent revalidation. Monitoring should track performance against defined thresholds, while significant changes should trigger review and reapproval. Institutions remain accountable for third-party AI and should assess its suitability for their intended use, obtain sufficient assurance and apply compensating controls where assurance gaps arise. Where residual risks cannot be brought within risk appetite, institutions should consider limiting, suspending or replacing the service. MAS intends to consult the sector in 2027 on what additional guidance on agentic AI would be useful.
South Korea's Financial Services Commission and Financial Supervisory Service have directed the entire financial sector to conduct comprehensive cybersecurity checks following a series of recent attacks, extending the measures initiated on October 2. Firms must tighten external access, authentication and monitoring, strengthen consumer protection and compensation arrangements, and rapidly share threat intelligence across the sector. The authorities also called for stronger cross-government coordination and greater use of AI-based and zero-trust security approaches.
South Korea's Financial Services Commission (FSC), together with the Financial Supervisory Service, convened an emergency sector-wide review after signs of repeated cyberattacks on major financial companies. The authorities directed all financial institutions, including smaller mutual finance, savings bank, insurance, securities and fintech firms, to complete comprehensive checks of externally exposed IT assets, vulnerabilities, authentication, access controls and intrusion-detection systems, apply previously shared threat intelligence and security patches, and report the results to the regulators. The measures broaden the response initiated at the October 2 emergency meeting following the Shinhan Bank incident and subsequent attacks on financial companies. Financial companies are expected to block unnecessary external access, restrict unavoidable access to the minimum permissions and information required, and scrutinize systems used by employees and external personnel such as loan agents and contractors to prevent unnecessary access to personal credit information or authentication bypasses. Where an incident occurs, firms should rapidly determine the scope of exposed information, implement protective measures, arrange relief and compensation where consumer losses are confirmed, and strengthen measures against secondary fraud such as voice phishing and smishing. The authorities also called for faster sharing of attack IP addresses, methods and intrusion attempts across the sector, stronger cross-government coordination and a transition toward AI-based security systems, including approaches based on zero-trust principles. The authorities are continuing investigations into the causes and scope of reported incidents and will monitor sector-wide threats for new attack indicators. The Financial Services Commission also warned that firms that fail to act on already shared threat information and suffer similar incidents may face strict action under applicable law, while analysis of recent attacks and losses will inform potential regulatory improvements.
The Reserve Bank of Australia has published payments review feedback highlighting calls for greater merchant choice, stronger mobile wallet competition and proportionate regulation of American Express. Views differed on whether regulation or industry initiatives should address barriers to account-to-account payments. The RBA intends to publish regulatory priorities by the end of 2026 and begin further consultation from mid-2027.
The Reserve Bank of Australia (RBA) has published a summary of 75 submissions to its Review of Payments System Regulation, which is identifying priorities for regulatory action to promote competition, efficiency and financial safety. The review follows legislative changes extending the RBA's remit to additional payment systems and participants. The issues paper covered merchant choice of payment methods and providers, mobile wallets, non-designated card networks and buy now pay later services. It also examined account-to-account (A2A) payments and their competition with cards, alongside cryptography and overseas card fraud. Respondents called for greater merchant choice in debit routing and payment providers, stronger mobile wallet competition and regulation of American Express. Views differed on whether regulation or industry initiatives should address barriers to A2A payments. On merchant choice, many respondents proposed requiring support for both networks on dual-network debit cards in mobile wallets and online payments, allowing merchants to choose their preferred routing network. Other proposals sought to remove platform barriers to alternative payment providers and strengthen token portability to ease switching. For mobile wallets, respondents called for fair, reasonable and non-discriminatory access to near field communication technology and greater fee transparency. Some also proposed controls where fees do not reflect costs. Apple opposed wallet-specific regulation, arguing that its existing arrangements support competition and security. For American Express, supporters of intervention favoured greater fee transparency and proportionate regulation equivalent in effect to that for four-party networks. Opponents argued that its three-party model raises different policy concerns and provides competition to those networks. On A2A payments, submissions highlighted access barriers, opaque sponsorship terms, gaps in New Payments Platform account coverage and inconsistent PayTo implementation. Proposed remedies included clearer sponsorship conditions and stronger refund, dispute and liability arrangements to support adoption. Other respondents favoured allowing the A2A Payments Roadmap and pending licensing reforms to progress before considering regulation. The RBA intends to publish regulatory priorities by the end of 2026 and begin further consultation on prioritised issues from mid-2027.
The European Insurance and Occupational Pensions Authority has set expectations for supervising insurers and reinsurers related to private equity. Before approving acquisitions, supervisors should scrutinize financing structures and whether owners’ investment horizons align with policyholder obligations. Ongoing supervision should preserve independent management and assess whether investment and reinsurance strategies create risks that are inadequately managed or reflected in capital requirements.
The European Insurance and Occupational Pensions Authority (EIOPA) has set expectations for national supervisors to assess whether private equity (PE) financing arrangements and business strategies could undermine insurers’ and reinsurers’ ability to meet their obligations to policyholders. Its supervisory statement connects scrutiny of acquisition financing and owners’ investment horizons with ongoing oversight of governance and the prudential risks arising from changes to the business model. The expectations cover acquisitions of qualifying holdings, portfolio transfers and mergers, as well as ongoing supervision, with oversight proportionate to each undertaking’s risks. Before approving acquisitions, supervisors should examine business plans covering at least three years and assess whether owners’ investment horizons align with policyholder obligations. Significant mismatches, particularly when combined with high initial shareholder distributions or incentives for an early exit, may lead supervisors to conclude that a business model is not viable. This assessment should extend to the entire acquisition financing structure, including debt held by parent companies, using realistic repayment assumptions and adverse scenarios, including reverse stress tests. To ensure that ownership arrangements allow effective supervision, supervisors should also request justification for each level of complex or opaque ownership chains. After acquisition, supervisors should ensure that management decisions remain independent and that intragroup transactions take place at arm’s length, with commissions at fair value. Where undertakings hold material alternative or illiquid investments, reviews should assess valuation capabilities, compliance with the prudent person principle and whether capital requirements capture the underlying risks. Reinsurance used to reduce capital requirements should receive similar scrutiny, focusing on effective risk transfer and counterparty and liquidity exposures. Undertakings must also have sufficient funds to meet higher capital requirements if ceded assets return to their balance sheets. Alongside these investment and reinsurance assessments, supervisors should examine whether material changes to solvency assumptions, methodologies or models have sufficient supporting evidence and appropriate validation. Significant balance sheet optimization should prompt undertakings to reassess whether the standard formula remains suitable for calculating the Solvency Capital Requirement.
The European Securities and Markets Authority expects MiCA-authorised crypto-asset service providers to cease all services involving non-MiCA-compliant stablecoins for EU clients. Providers should implement controls preventing access to these tokens and new or increased exposures. Supervisors should require remediation of existing exposures within three months, allowing only strictly limited and supervised wind-down activities.
The European Securities and Markets Authority (ESMA) has issued an opinion setting out supervisory expectations for crypto-asset service providers (CASPs) authorised under the Markets in Crypto-Assets Regulation (MiCA) in relation to noncompliant stablecoins. ESMA expects CASPs to cease providing services to EU clients involving asset-referenced tokens (ARTs) and e-money tokens (EMTs) that do not meet MiCA's requirements for a lawful public offer or admission to trading. This expectation applies to all crypto-asset services, individually or in combination, regardless of whether the services themselves constitute a public offer or admission to trading. ESMA considers that providing services involving noncompliant ARTs and EMTs is presumptively incompatible with CASPs' obligation to act in clients' best interests, as the absence of issuer-level safeguards creates risks that cannot be adequately mitigated through disclosures, warnings or other measures available to CASPs. National competent authorities (NCAs) are therefore expected to ensure that CASPs neither maintain nor facilitate EU clients' access to these tokens. This encompasses trading, exchange, order execution, advice, transfers, custody and portfolio management, among other services. CASPs should implement appropriate technical, contractual and organisational controls to prevent the availability of noncompliant tokens, including measures preventing clients from acquiring or increasing exposures to them. NCAs should require any remaining legacy exposures to be remediated as soon as possible and no later than three months following publication of the opinion. Strictly limited residual services may be permitted to facilitate an orderly wind-down of existing holdings, including liquidation, conversion, withdrawal, transfer or safekeeping. Such arrangements must be time-limited, subject to close supervisory oversight and must not enable new acquisitions or continued market availability of noncompliant tokens.
The European Securities and Markets Authority (ESMA) launched a Call for Evidence on whether, and under what conditions, EU central counterparties could safely accept tokenised collateral. The key test is whether such collateral can be turned into liquidity as reliably as its traditional form, which depends on legal enforceability, segregation, settlement finality and liquidity under stress. ESMA will assess the feedback in the first quarter of 2027 before deciding on any regulatory or supervisory convergence action.
The European Securities and Markets Authority (ESMA) launched a Call for Evidence on whether, and under what conditions, EU central counterparties (CCPs) could safely accept tokenised collateral. Rather than revisiting which assets are eligible, ESMA wants to understand whether tokenisation changes how eligible assets are transferred, protected and realised, and whether the European Market Infrastructure Regulation (EMIR) and related EU rules can accommodate such arrangements. Its premise is that tokenisation leaves the underlying risks intact, so collateral must remain legally enforceable, highly liquid and available when a clearing member defaults. The central test is whether tokenised collateral can be turned into usable liquidity as reliably as its traditional equivalent. ESMA applies this test to digital twins of assets still held in conventional infrastructures, to assets issued natively on distributed ledger technology (DLT), and to hybrids of the two. Legal robustness is the first hurdle. A token transfer may not by itself confer ownership or a security interest, wallet separation may fall short of legally enforceable segregation, and technical settlement may not coincide with legal finality. Liquidity is the second. A tokenised bond should in principle carry the same risk as its traditional form, but redemption processes or platform dependencies could slow its conversion into cash and justify adjusted haircuts. Tokenised cash raises separate concerns, as stablecoins may not qualify as cash equivalents given potential deviation from par. Beyond individual assets, ESMA asks whether reliance on a few specialist providers or a lack of interoperability could concentrate or fragment the market, and whether existing rules implicitly assume conventional intermediaries. ESMA will assess the feedback in the first quarter of 2027 and then decide on any regulatory or supervisory convergence action within its remit.
The European Anti-Money Laundering Authority (AMLA) and the Single Resolution Board (SRB) have responded to the European Commission's consultation on the review of the Markets in Crypto-Assets Regulation (MiCA). AMLA calls for closing AML/CFT gaps covering staking and lending, decentralised finance, unauthorised stablecoins and issuers of asset-referenced tokens. The SRB seeks better information sharing with resolution authorities, clearer bail-in treatment of stablecoin reserve deposits and a crisis management regime for significant tokens issued by non-banks.
The European Anti-Money Laundering Authority (AMLA) and the Single Resolution Board (SRB) have published their responses to the European Commission's targeted consultation on the review of the Markets in Crypto-Assets Regulation (MiCA). AMLA identifies gaps in the regulatory perimeter that leave activities posing money laundering and terrorist financing (ML/TF) risks outside anti-money laundering and countering the financing of terrorism (AML/CFT) requirements. The SRB focuses on how stablecoin linkages could undermine the resolvability of credit institutions and on the absence of a crisis management regime for significant tokens issued by non-banks. Both authorities urge caution on third-country multi-issuer stablecoin arrangements, citing limited visibility over token flows and over access to reserves held outside the EU. AMLA asks the Commission to consider dedicated requirements for crypto-asset staking, lending and borrowing, which MiCA currently captures only through the custody provisions of Article 75. The legal framework should also define a "DeFi arrangement" and set common criteria for identifying effective control, such as concentrated governance tokens or the ability to pause or modify smart contracts, since arrangements currently self-assess whether they fall outside MiCA. AMLA further calls for legislative measures to remove legal uncertainty over services involving non-authorised asset-referenced tokens (ARTs) and electronic money tokens (EMTs). Because the Anti-Money Laundering Regulation (AMLR) does not list ART issuers as obliged entities, issuers that issue and redeem tokens without another obliged entity perform no customer due diligence, and the Commission should consider bringing them into scope. Additional passporting information should allow authorities to distinguish whether crypto-asset service providers (CASPs) operate through an establishment or under the freedom to provide services. The SRB warns that MiCA's requirement for token issuers to hold reserves as bank deposits creates a potentially volatile funding source, as redemption pressure at an issuer could trigger rapid outflows at the credit institution holding the deposits. It points to the failures of Silicon Valley Bank in 2023 and FlowBank in 2024 as illustrations of these risks. The SRB proposes making information sharing between MiCA supervisors and resolution authorities explicit under the report-once principle, and requiring notification of resolution authorities when a redemption plan is activated. It also calls for clarifying how MiCA interacts with the Bank Recovery and Resolution Directive (BRRD) and the Single Resolution Mechanism Regulation (SRMR), including the treatment of reserve deposits in insolvency and bail-in, since Article 44(2) BRRD contains no specific exclusion for stablecoin reserve deposits. Finally, the SRB argues that orderly liquidation may not suffice if tokens become systemic, and proposes a tailored, proportionate crisis management regime for significant ARTs and EMTs issued by non-credit institutions
The European Insurance and Occupational Pensions Authority is consulting on a draft Supervisory Statement proposing more proportionate and outcomes-focused supervision of insurance-based investment product sales and disclosures. National supervisors would assess whether customer assessments, product recommendations and disclosures effectively support informed consumer decisions rather than focusing solely on procedural compliance. The approach would also strengthen scrutiny of distribution oversight and post-sale indicators, with supervisory intensity calibrated to identified risks.
The European Insurance and Occupational Pensions Authority (EIOPA) has launched a consultation on a draft Supervisory Statement proposing a more proportionate and outcomes-focused approach to supervising sales processes and pre-contractual disclosures of insurance-based investment products (IBIPs). The proposed approach would encourage national competent authorities to complement compliance checks with assessments of whether existing safeguards effectively support informed consumer decision-making. It responds to concerns about mechanically driven sales processes, complex disclosures that obscure essential information and customer assessments that do not meaningfully influence sales outcomes. The aim is to promote more consistent, risk-based supervision while reducing unnecessary procedural burdens within the existing regulatory framework. Under the proposals, supervisors would assess whether demands-and-needs tests, suitability assessments and, where applicable, appropriateness assessments collect sufficient and relevant customer information and meaningfully inform product selection or recommendations. They would distinguish minor documentation deficiencies from shortcomings that could materially undermine consumer protection. Supervisors would also examine whether disclosures clearly communicate key product features, risks and costs, including whether information is presented prominently and sufficiently early to inform purchasing decisions. For advised sales, supervisory assessments would consider whether personal recommendations reflect customers' individual circumstances, objectives and risk profiles rather than relying on generic justifications. The draft also addresses oversight of manufacturers, distributors and intermediaries, including the effectiveness of distribution controls, remuneration incentives and training arrangements. Supervisors would consider whether firms use complaints, early surrender rates, post-sale corrections and other indicators to identify and address potential weaknesses in sales practices. Such indicators would inform supervisory scrutiny rather than automatically establish non-compliance. The intensity of supervision would be calibrated to product complexity, distribution models, customer characteristics and identified risks, with attention focused on material consumer protection concerns rather than additional documentation or procedural steps.
The Dutch Authority for the Financial Markets and De Nederlandsche Bank concluded in a joint study that Dutch law does not allow securities to be issued, held and transferred solely as tokens, because the Securities Giro Transfer Act and the Dutch Civil Code do not recognise direct issuance or DLT transfers. Market participants are therefore confined to indirect tokenisation and hybrid models, which limits efficiency gains and risks pushing activity to other EU jurisdictions. The authorities recommend that government, supervisors and industry jointly test concrete use cases to decide between guidance and legislative amendments.
The Dutch Authority for the Financial Markets (AFM) and De Nederlandsche Bank (DNB) concluded in a joint exploratory study that Dutch law does not allow securities to exist solely as tokens. Without a legal basis for issuing, holding and transferring securities directly on distributed ledger technology (DLT), the Netherlands risks losing activity to jurisdictions such as Germany, Luxembourg and France, which have already adapted their legal frameworks. The obstacle lies in national law rather than EU rules. The Central Securities Depositories Regulation (CSDR) permits direct issuance of securities in dematerialised form, but the Securities Giro Transfer Act (Wge) only admits existing securities into a giro depot, and transfer formalities under the Dutch Civil Code (BW) do not fit DLT transfers. Only indirect tokenisation is therefore possible, with DLT serving as the depot administration for securities created by traditional means. Market participants must keep DLT and traditional records in parallel, which erodes efficiency gains and leaves the legal status of the token register unclear. The DLT Pilot Regime offers no remedy, as it leaves national property law untouched. To close the gap, the study proposes targeted modernisation of the BW and Wge, which could precede longer term EU harmonisation such as the proposed 28th Regime. The authorities recommend a joint process with the Ministry of Finance, the Ministry of Justice and Security and market participants to test concrete use cases and determine whether guidance suffices or legislative amendments are needed, in line with EU developments including the DLT Pilot Regime review.
The United Kingdom's Cross-Market Operational Resilience Group completed SIMEX26, a sector-wide simulation of global cloud services disruption involving 38 major banks and market infrastructure operators. The exercise tested coordinated crisis response arrangements, including the Cross Market Business Continuity Group.
The Cross-Market Operational Resilience Group (CMORG), co-chaired by the Bank of England and UK Finance, completed its biennial simulation exercise, SIMEX26, on 8 October 2026. The exercise tested the UK financial sector's collective crisis response to a simulated global disruption of cloud-based services, involving 38 of the largest and most systemically important banks and market infrastructure operators alongside financial authorities. The exercise involved HM Treasury, the Financial Conduct Authority and wider industry participants, and included a live meeting of the Bank of England-chaired Cross Market Business Continuity Group, which provides strategic direction during systemic incidents. It also tested the sector's coordinated response arrangements under the Sector Response Framework.
The Guernsey Financial Services Commission is supporting the island’s first AI Sprint through an anti-money laundering hackathon and a data readiness session. The events will examine how firms can use AI and synthetic data effectively while maintaining regulatory safeguards and strengthening the data, processes, skills and culture needed for wider adoption.
The Guernsey Financial Services Commission (GFSC) is supporting Guernsey’s first island-wide AI Sprint through two events focused on applying artificial intelligence in financial services. The six-week programme brings together the business and technology communities for more than 50 events, reflecting priorities in Guernsey’s Finance Sector Strategy 2035 around innovation, digital capability and a supportive regulatory environment. At the AI for AML Hackathon on Oct. 12, participants will explore how AI and synthetic data can improve the usability and efficiency of anti-money laundering processes and controls while firms continue to meet their regulatory responsibilities. The event follows the Commission’s May update to its Handbook on Countering Financial Crime, which clarified firms’ responsible use of technology and the safeguards expected. The Commission will also host a data readiness session on Oct. 29 examining whether firms have the data quality, processes, skills and organizational culture needed to move from AI experimentation to wider adoption while managing implementation risks.
The Swiss Financial Market Supervisory Authority has adopted revised digital client identification rules allowing electronic identity credentials and QR-coded official documents to be used for anti-money laundering identification. The changes strengthen liveness detection and residential address verification requirements while permitting reliable digital verification methods. The revisions take effect on 1 November 2026, with a one-year transition for specified adjustments to identification using qualified electronic signatures.
The Swiss Financial Market Supervisory Authority (FINMA) has adopted a partial revision of Circular 2016/7 on video and online identification, finalising changes proposed in December 2025 to accommodate technological developments and Switzerland's forthcoming electronic identity credentials (e-ID) framework. The revised rules allow financial intermediaries to use e-ID issued under the Federal Act on Electronic Identity Credentials and Other Electronic Credentials for client identification under the Anti-Money Laundering Act. Financial intermediaries must verify that the credential is valid and belongs to the contracting party, confirm the party's residential address, conduct liveness detection and document the identification process. The revisions also recognise official identification documents containing QR codes as equivalent to those with machine-readable zones, subject to applicable security requirements. Following consultation feedback, FINMA has incorporated additional safeguards against identity fraud associated with emerging technologies, particularly artificial intelligence. These include liveness detection for online identification using qualified electronic signatures, alongside residential address verification. Financial intermediaries may use digital processes that reliably link the contracting party and its infrastructure to a place of residence. The rules also permit representatives of legal entities and partnerships to be identified using e-ID, qualified electronic signatures or digital authentication. The revised circular enters into force on 1 November 2026. A one-year transitional period applies to technical adjustments required for residential address verification and liveness detection in online identification processes using qualified electronic signatures.
The Bank of Albania presented the third and final draft of the National Green Taxonomy, following the initial draft unveiled in April 2026. The framework includes technical screening criteria and legislative adjustments to classify economic activities according to environmental and climate objectives, supporting green lending and the integration of climate considerations into banks' risk management.
The Bank of Albania, in cooperation with the European Investment Bank, presented the third and final draft of the National Green Taxonomy, establishing a framework for identifying and classifying economic activities according to environmental and climate objectives. Building on the first draft presented in April 2026, the latest version covers the taxonomy's general framework, technical screening criteria and legislative adjustments. Second Deputy Governor Natasha Ahmetaj emphasized that the taxonomy is expected to influence capital allocation and lending practices as banks increasingly incorporate environmental and climate considerations into risk assessment and management. Banks will need to develop financial products aligned with green finance principles, while businesses will need to adapt their business models and technologies to sustainability requirements. The taxonomy forms part of Albania's broader sustainable finance architecture, alongside improvements in data transparency and reporting standards, and supports alignment with European Union standards.
The Securities Commission of The Bahamas published a report reviewing its supervision and surveillance of the digital asset sector from 2021 to September 2026. Its 2026 examination programme identified 82 compliance findings across 16 thematic examinations, primarily concerning statutory reporting and preventive controls, alongside eight Travel Rule breaches involving three registrants. An earlier sector-wide diagnostic review also identified recurring weaknesses in governance, documentation and procedures for digital asset operations.
The Securities Commission of The Bahamas has published a report on its supervision and surveillance of the digital asset sector from January 2021 to September 2026, highlighting deficiencies in statutory reporting, preventive controls and record keeping. Its 2026 onsite examination programme covered 17 of the 20 active registrants, identifying 82 findings across 16 thematic examinations focused on anti-money laundering, countering the financing of terrorism and countering proliferation financing (AML/CFT/CPF). Separate Travel Rule testing identified eight breaches involving three registrants. The report also identifies common governance and operational weaknesses from an earlier sector-wide diagnostic review and provides an assessment of digital asset market activity and potential unregistered services. Of the 82 thematic examination findings, 44 concerned annual sanctions declarations and quarterly terrorist property reporting, primarily involving late filings or insufficient documentary evidence. The remaining findings concentrated on customer risk assessments, due diligence, ongoing monitoring and training. No findings indicated missed sanctions screening matches, unreported sanctioned persons or failures to freeze assets. Travel Rule testing comprised 44 examinations covering 1,831 sampled transfers from 2021 to 2026. All eight breaches involved failures to maintain or produce evidence of required originator or beneficiary information. Separately, the 2023–2025 diagnostic review of the then-registered population identified recurring weaknesses in policy documentation, governance processes and procedures for blockchain events, including hard forks and airdrops. Market surveillance indicates that estimated on-chain activity connected to The Bahamas remains substantially below its late-2022 peak. Between January and July 2026, estimated on-chain transaction volume totalled USD 70.1 million, with 97.12% of flows traced to classified destinations directed to legitimate services and 2.80% to services associated with criminal activity. Three suspected unregistered services remain under monitoring, including two still active.
Argentina's National Securities Commission has launched a consultation on revised relevant event disclosure requirements, introducing clearer materiality thresholds and reporting obligations for financial transactions, ownership changes and cybersecurity incidents. The proposal also establishes rules for addressing market rumors and sets conditions and procedures for temporarily suspending public disclosure.
Argentina's National Securities Commission (CNV) has launched a public consultation on a comprehensive revision of the relevant events disclosure regime for entities and persons subject to the public securities offering framework. The proposal clarifies the scope and timing of disclosure obligations, introduces more objective criteria for determining materiality and specifies the information that disclosures must contain. It also expands and refines the categories of reportable events, including significant cybersecurity incidents, changes in corporate control and financial developments, while establishing rules for handling market rumors and temporarily suspending disclosure obligations. The proposed framework introduces quantitative reporting thresholds for several categories of events, including related-party transactions exceeding 5% of net worth or ordinary revenue, major investments and financial transactions exceeding 15% of net worth, and acquisitions or disposals of interests in other companies exceeding 20% of net worth. Significant litigation involving claims exceeding 10% of net worth would also be reportable. Events falling below these thresholds would remain subject to disclosure where they otherwise meet the general materiality criteria. For changes in issuer control, preliminary negotiations or preparatory agreements without binding commitments would not, by themselves, trigger disclosure. Where an issuer is not involved in a transaction, its disclosure obligation would arise upon obtaining reliable knowledge of the relevant decision or agreement. The proposal also expressly covers operational, technological and cybersecurity incidents that significantly disrupt or could disrupt an entity's activities, requiring disclosure of their consequences and remedial measures. The revised regime would also require entities to clarify or deny false, inaccurate or incomplete information circulating in the market where it concerns potentially reportable events, and immediately disclose confirmed information that constitutes a relevant event. It further establishes conditions for requesting temporary suspension of disclosure where publication could harm the issuer's corporate interests, including documented justification, approval by its management body and measures to preserve confidentiality. The CNV would decide on such requests within five business days unless additional information is required. Rejection of a request, or expiry of an approved suspension, would trigger an immediate disclosure obligation.
The Central Bank of Uruguay has published a policy paper detailing its strategy to deepen financial intermediation in national currency, as foreign currency deposits remain highly prevalent despite reduced financial stability risks. The four-pillar strategy combines reserve requirement and tax incentives, prudential measures, development of financial instruments, improved consumer information and market coordination. Mandatory exchange rate risk warnings for foreign currency deposit accounts took effect on October 1, 2026.
The Central Bank of Uruguay (BCU) has published a policy paper detailing its ongoing strategy to expand financial intermediation in national currency, arguing that persistent dollarization has shifted from primarily a financial stability concern to a constraint on financial development and economic growth. Despite substantial reductions in currency mismatches and improvements in banking sector capital and liquidity, foreign currency deposits still accounted for 72% of nonfinancial private sector deposits in July 2026. Only around 37% of foreign currency deposits are channelled into lending, compared with 94% of deposits in national currency, limiting the availability of domestic financing. The strategy, strengthened since 2025, rests on four pillars. The first aligns financial intermediation incentives through lower reserve requirements and higher remuneration on reserves in national currency, reduced remuneration on foreign currency reserves, preferential tax treatment for domestic currency savings and higher capital requirements for certain foreign currency loans. The second promotes domestic currency savings and investment products alongside foreign exchange derivatives and hedging instruments. The third addresses information gaps and established saving practices through consumer disclosures, financial education and measures encouraging the use of national currency in pricing. In particular, a requirement effective October 1, 2026, obliges deposit-taking institutions to provide prominent warnings about exchange rate risks when opening foreign currency accounts, with personal notifications also required for existing account holders. The fourth pillar involves coordination with the Ministry of Economy and Finance and financial market participants to identify barriers to developing domestic currency financial products. Implementation will remain gradual, preserving households' and businesses' freedom to choose their preferred currency. Further adjustments to reserve requirements and remuneration will depend on the response of market interest rates and credit, supported by monitoring of deposit and lending composition, financial market development and macrofinancial risks.
The Caribbean Community has launched a regional sustainability bond seeking to raise up to USD 250 million for resilience and sustainable development projects. The framework will aggregate eligible projects and connect them with a broader pool of investors, with proceeds expected to finance areas including climate resilient infrastructure, renewable energy and sustainable water management.
The Caribbean Community has launched the Caribbean Sustainability Bond, a regional investment vehicle seeking to mobilize up to USD 250 million for climate resilience, sustainable development and economic transformation. Caribbean Sustainability Investments Limited will issue the bond, with the CARICOM Development Fund as project sponsor and JMMB Securities Ltd. as lead arranger and broker. The financing framework will aggregate eligible projects to create scale and connect them with local, regional and international investors. Proceeds are expected to support climate resilient infrastructure, renewable energy, sustainable water and wastewater management, environmental protection and other projects with environmental, social and economic benefits. The Climate Bonds Initiative provided technical assistance to align the framework with recognized international sustainability standards and practices.
The Financial Services Commission, Mauritius has updated its ESG fund guidelines to clarify eligibility criteria for independent external certifiers. Eligible entities include registered audit firms, licensed or recognised credit rating agencies, and qualifying assurance, specialised ESG and impact verification firms with sufficient ESG expertise. The clarification supports existing certification requirements, including independent verification of ESG schemes' annual Sustainability Reports.
The Financial Services Commission, Mauritius (FSC) has updated its Disclosure and Reporting Guidelines for ESG Funds to clarify which entities may act as independent external certifiers. Eligible certifiers must have relevant and sufficient environmental, social and governance (ESG) expertise and may include audit firms registered with the Financial Reporting Council, credit rating agencies licensed or recognised by the FSC, and assurance firms, specialised ESG firms or impact verification firms accredited or recognised by an international professional or regulatory body acceptable to the FSC. The updated guidelines define the eligible categories, including assurance firms providing verification of specialised information such as sustainability metrics, specialised ESG firms offering ESG advisory and compliance services, and impact verification firms independently assessing sustainability impacts and outcomes. Under the wider framework, ESG schemes must obtain independent third-party certification of their annual Sustainability Reports to confirm that investments comply with their offering documents. For new ESG scheme applications and existing funds adopting an ESG strategy, alignment of investment objectives and strategies with the United Nations Sustainable Development Goals or other widely accepted goals may be confirmed through either independent third-party certification or self-certification.
The Central Bank of Morocco has published two working papers on a retail digital dirham. A model calibrated on Morocco finds that a central bank digital currency paying no interest would raise long run output by 0.7% and cushion some financial shocks with limited risk to bank lending. The papers favor a hybrid design distributed by banks and payment institutions with holding limits, and report that a proof of concept with the International Monetary Fund and the World Bank confirmed technical feasibility.
The Central Bank of Morocco has published two working papers assessing a potential retail central bank digital currency (CBDC) for Morocco. A macroeconomic model calibrated on the Moroccan economy finds that a digital dirham paying no interest would raise output by 0.7% above trend in the long run and modestly improve resilience to financial shocks. A companion policy paper sets out a preferred design and reports that a proof of concept confirmed technical feasibility. The model confirms the policy rate as the main stabilization tool and, like the policy paper, finds that a CBDC alone cannot resolve financial exclusion. The dynamic stochastic general equilibrium (DSGE) model distinguishes banked households, matching the 54% of Moroccans with a bank account, from unbanked households who rely on cash. In the simulated transition, households hold CBDC worth 6.6% of GDP, drawn from cash and retail deposits, while banks replace lost deposits with wholesale funding and central bank credit, against which the CBDC is issued. Easier payments add 0.1% to 0.2% to annual growth in the following years, although an initial rise in inflation and the real policy rate delays the benefits of lower interest rates and taxes by several years. CBDC dampens the impact of credit supply and money demand shocks but makes little difference to other shocks. It raises the quality of money for unbanked households but not its quantity, since they must still save to accumulate it, and the results depend on banks' access to central bank refinancing. The policy paper ties the case for a digital dirham to currency in circulation above MAD 500 billion, bank account ownership of 62% and an informal economy of about 30% of GDP. Drawing on international pilots, it favors a hybrid model in which Bank Al-Maghrib issues the currency while banks, payment institutions and fintechs distribute it. The digital dirham would pay no interest, carry holding limits tied to identification levels, work offline and could connect with foreign platforms to cut remittance costs. Simulations with the International Monetary Fund (IMF) and the World Bank show limited effects on banks if the CBDC mainly replaces cash, and while a CBDC competing with deposits would raise bank funding costs, banks could absorb a partial deposit shift at moderate adoption levels. The proof of concept, also developed with both institutions, tested issuance, distribution, wallets and payments on distributed and centralized platforms, and a separate experiment on payments across borders is under way with the Central Bank of Egypt. Any issuance is framed as a gradual, long term project.
The Financial Services Regulatory Authority (FSRA) of Abu Dhabi Global Market has proposed guidance on managing risks arising from regulated firms' engagement with decentralised finance (DeFi) within the existing regulatory framework. The proposals set out expectations for governance, due diligence, ongoing monitoring, infrastructure risks, financial crime controls and asset safeguards. Firms are also expected to assess specific DeFi exposures and determine the applicable regulatory requirements based on the nature of the underlying assets and activities.
The Financial Services Regulatory Authority (FSRA) of Abu Dhabi Global Market has proposed guidance setting out supervisory expectations for how Authorised Persons and Recognised Bodies should manage risks arising from their engagement with decentralised finance (DeFi) arrangements. The guidance focuses on strengthening firms' governance, risk management and controls within the existing regulatory framework, rather than establishing a separate regime for DeFi protocols, new categories of regulated activities or digital assets. It builds on the FSRA's 2022 discussion paper on DeFi policy considerations. Under the proposals, firms should maintain risk management arrangements proportionate to the nature, scale and complexity of their DeFi engagements. These should include senior management oversight, approval and due diligence of material engagements, assessment of third-party dependencies and concentration risks, continuous monitoring, recordkeeping and incident escalation. Firms should also assess the specific risks associated with DeFi infrastructure, including custody and wallet arrangements, smart contracts, protocol governance, oracles, bridges and transaction execution. Particular emphasis is placed on firms' ability to safeguard assets, maintain transaction traceability and comply with applicable anti-money laundering, sanctions, conduct, prudential and technology requirements. The guidance further addresses risks associated with specific forms of DeFi exposure, including Fiat-Referenced Tokens, synthetic and derivative-like exposures, receipt tokens and tokenised claims, and wrapped, bridged or cross-chain assets. Firms must assess the nature of each exposure and determine which existing regulatory requirements apply, including those relating to prudential standards, conduct, market integrity, asset safeguarding and anti-money laundering. This requires considering whether an exposure falls within the FSRA's existing frameworks for Virtual Assets, Fiat-Referenced Tokens, Digital Securities, derivatives, staking-related exposures or other digital asset arrangements. The proposed guidance does not determine the regulatory classification of these exposures. Instead, firms must assess each exposure under the relevant existing frameworks, taking into account the substance and operation of the underlying asset, activity or arrangement. The use of DeFi does not, in itself, determine or alter the applicable regulatory treatment.
The Dubai Virtual Assets Regulatory Authority has clarified minimum expectations for independent audits of reserve assets following its review of 2025 Proof of Reserve Assets reports. Audits should verify full one to one reserve coverage, segregation, wallet control, daily reconciliation and any use of client assets, while reports must clearly document evidence, methodology, limitations and conclusions. Management representations alone are insufficient where independent evidence is reasonably available.
The Dubai Virtual Assets Regulatory Authority has issued a circular clarifying its minimum expectations for independent audits of reserve assets following a thematic review of all Proof of Reserve Assets reports submitted in 2025. Auditors should assess whether virtual asset service providers maintained reserve assets equal to at least 100% of aggregate client liabilities throughout the review period, held them one to one in the same virtual asset as the corresponding liability, segregated client assets from proprietary or operational assets, and performed effective daily reconciliation. The audit must cover all wallets holding client virtual assets, including assets held through wallet infrastructure providers and third party custodians, and determine whether any rehypothecation, lending, pledging or other use of client assets occurred. Auditors should also establish whether the VASP maintained control over each client asset wallet and describe the applicable custody arrangement. Audit reports are expected to document the procedures performed, evidence obtained, sampling methodology, reliance on third parties and any scope limitations. They should provide a clear conclusion against each element of the minimum audit scope and distinguish compliant outcomes from exceptions, scope limitations and matters that could not be independently verified. Where independent evidence is reasonably available, management representations alone should not be treated as sufficient audit evidence. The circular also reinforces that appointing an external auditor does not reduce the responsibility of the VASP, its board, Senior Executive Officer or control functions for ongoing compliance and effective safeguarding of client virtual assets.
The Dubai Financial Services Authority has revised its credit rating agency rules to focus employee conflict of interest assessments on relationships that may create actual or perceived conflicts, rather than predefined family relationships. It has also removed certain prescriptive disclosure requirements while retaining broader transparency obligations. The amendments take effect on 1 January 2027.
The Dubai Financial Services Authority (DFSA) has finalized amendments to its credit rating agency (CRA) framework, introducing a more principles-based approach to identifying conflicts of interest and simplifying disclosure requirements. The changes focus restrictions on employees' involvement in credit ratings on relationships that may create actual or perceived conflicts, rather than predefined family relationships. They also remove certain prescriptive disclosures while preserving broader transparency obligations. The amendments take effect on 1 January 2027. Under the revised conflict of interest rules, CRAs must assess whether an employee's relationship with someone employed by a rating subject or its related party may cause, or reasonably be perceived as causing, a conflict of interest. Family relationships will therefore not automatically trigger restrictions, while other personal relationships may warrant them. CRAs must determine and document how they assess and manage relevant relationships, including through escalation, disclosure or recusal where appropriate. On transparency, CRAs will no longer be required to disclose fees and charges in every rating announcement, although annual report and website disclosure obligations remain. The DFSA has also removed the requirement to specify whether information used to rate structured financial products is publicly available. However, CRAs must continue to explain any material reliance on non-public information where necessary for users to understand how a rating was determined.
The Canadian Securities Administrators published final amendments to National Instrument 31-103 that ban chargebacks, under which a dealing representative must repay an upfront commission when a client redeems securities of an investment fund that is a reporting issuer. Subject to ministerial approvals, the ban takes effect on October 1, 2028, following an implementation period extended from six to 24 months. Redemptions of securities purchased before that date are exempt.
The Canadian Securities Administrators (CSA) published final amendments to National Instrument 31-103 Registration Requirements, Exemptions and Ongoing Registrant Obligations (NI 31-103) that ban chargebacks in the distribution of securities of investment funds that are reporting issuers. The prohibition targets what the CSA views as an inherent conflict of interest in advisor compensation. Subject to ministerial approvals, it takes effect on October 1, 2028, after a longer transition than originally proposed. The Canadian Investment Regulatory Organization (CIRO) expects to amend its member rules to align. Chargebacks arise when a dealing representative receives an upfront commission on a client's fund purchase and must repay all or part of it if the client redeems before the end of a fixed schedule. This gives representatives an incentive to discourage redemptions or to recommend that clients keep holding securities that may no longer suit them. The new rule bars registrants from requiring, or causing an affiliate to require, a registered firm or individual to repay such compensation in connection with a redemption. Although current use is limited, the CSA chose an outright ban over guidance or prescriptive controls to act before the practice becomes entrenched. Following consultation on the June 2025 proposal, the CSA extended the implementation period from six to 24 months, mainly to give two scholarship plan dealers that rely on chargebacks time to redesign their compensation models. A legacy provision exempts redemptions of securities purchased before October 1, 2028. The CSA also clarified that commission recoveries triggered by cancelled pre-authorized contributions (PACs), auto-switches or transfers to another financial institution fall outside the ban where no redemption is involved, although a redemption preceding a transfer is covered. Firms must still address these conflicts in the best interest of clients, which for PACs may mean avoiding such structures altogether. Extending the ban to investment funds that are not reporting issuers or to other securities would be a separate project.
The Office of the Superintendent of Financial Institutions (OSFI) published its 2026 Semi-Annual Risk Outlook, confirming that the key risks set out in April remain in focus while geopolitical, economic and technological pressures have intensified. The update concludes that frontier AI amplifies cyber, technology, third party and reputational risks, citing faster vulnerability exploitation and concentration among a few largely foreign providers.
The Office of the Superintendent of Financial Institutions (OSFI) published its 2026 Semi-Annual Risk Outlook, updating the 2026-2027 Annual Risk Outlook (ARO) released in April 2026. The four key risks identified in April, namely real estate secured lending and mortgage, non-bank financial institution, funding and liquidity, and other risks, remain OSFI's regulatory focus, but geopolitical tensions, softer domestic growth and the Canada-US trade war have intensified pressures since then. The update concentrates on frontier artificial intelligence (AI), previously one element of the ARO's other risks category, and concludes that it amplifies cyber, technology, third party and reputational risks. Institutions should strengthen governance, controls and testing as capabilities advance, with boards and senior management accountable for managing these risks. Consistent with other authorities, OSFI noted that frontier AI models can locate and exploit more vulnerabilities and autonomously chain minor weaknesses into serious attacks, while lower expertise barriers widen the pool of threat actors. The shrinking gap between vulnerability discovery and exploitation leaves institutions less time to respond, although the same tools can improve detection and patching. Third party risk rises because a few providers dominate frontier models and the cloud infrastructure behind them, increasing the potential for correlated disruptions. Many of these providers sit outside Canada, exposing institutions to foreign technology restrictions, and visibility into AI use at critical providers may decline. Reputational risk now also stems from delayed adoption, and OSFI identifies keeping pace with cyber security and vulnerability identification as the most important area of innovation. OSFI is building internal capacity to supervise frontier AI deployments and will assess the systemic implications of technology concentration and common dependencies on critical service providers. This builds on steps taken in 2026, including technology risk bulletins on Generative and Agentic AI and on Frontier AI and joint industry sessions with the Canadian Centre for Cyber Security.
The Commodity Futures Trading Commission is seeking comment on a federal framework for retail crypto asset transactions subject to section 2(c)(2)(D) of the Commodity Exchange Act. Regulation CTX would clarify when such transactions enter and leave the CEA framework, while Regulation CAM would create a tailored crypto asset market subcategory of designated contract market registration. The framework also contemplates FCM intermediation, adapted clearing and margin arrangements, and integrated market structures.
The Commodity Futures Trading Commission issued an advanced notice of proposed rulemaking seeking input on a comprehensive federal framework for crypto asset transactions subject to section 2(c)(2)(D) of the Commodity Exchange Act. The framework has two main components. Regulation CTX would clarify when retail crypto asset transactions fall within section 2(c)(2)(D), including the treatment of offers of leverage, margin or financing and the meaning of actual delivery. Regulation CAM would establish a tailored subcategory of designated contract market registration for exchanges dealing in such transactions and adapt the existing futures market framework to their commercial structure and risks. Under the first component, Regulation CTX, the CFTC would clarify when retail crypto asset transactions fall within section 2(c)(2)(D) and when they cease to be subject to its requirements. A covered offer of leverage, margin or financing could apply across transactions made available through relevant customer documentation or an account, even where a customer declines financing and pays in full. A fully paid, open CTX would therefore remain subject to the CEA and the on exchange requirement until actual delivery or another statutory exception occurs. For crypto assets, actual delivery would require meaningful possession or control, potentially including control of wallet credentials and unfettered access to governance or staking rights. The CFTC also preliminarily considers that many onchain transactions delivering assets directly to a purchaser's wallet may satisfy that standard. Under the second component, Regulation CAM, the CFTC would create a purpose built market structure for CTXs by allowing an exchange dealing only in such transactions to register as a tailored subcategory of designated contract market. The framework would require FCM intermediation under a modified regime and adapt DCO clearing and settlement requirements to the structure and risks of CTXs. It would also accommodate integrated CAM, FCM and DCO structures and limit retail leverage arrangements to FCMs or qualified banking institutions sponsored by an FCM. The CFTC is seeking input on how the framework should address market integrity, financial safeguards, operational and blockchain risks, and potential exemptions.
The U.S. Securities and Exchange Commission proposed amendments to Rule 17a-7 that would restore registered funds' ability to cross trade most fixed income securities with affiliates, largely blocked since the 2020 fund valuation rule. The proposal would also modernize pricing conditions, require a best interest determination for each trade and add quarterly compliance reviews, annual back testing and aggregated reporting by asset class.
The U.S. Securities and Exchange Commission (SEC) proposed amendments to Rule 17a-7 under the Investment Company Act of 1940, which permits cross trades between registered funds and their affiliates under certain conditions. The proposal would restore funds' ability to cross trade most fixed income securities, modernize pricing and oversight conditions and introduce aggregated reporting of cross trading activity. SEC Chairman Paul S. Atkins said the changes would let funds avoid open market trading costs and pass the savings on to investors. Most fixed income securities have been ineligible for cross trading since the compliance date of Rule 2a-5, the fund valuation rule adopted in December 2020, because Rule 17a-7 relies on its definition of "readily available market quotations". The proposal would extend eligibility to securities valued using directly or indirectly observable inputs, consistent with level 2 inputs under US generally accepted accounting principles. Funds could price cross trades either at the value set in their next net asset value computation on the trade date, or at a price the adviser determines reasonably reflects the current market price based on unaffiliated sources. Advisers would also need to determine before each trade that it is in the best interest of every participating fund. To reduce the burden on fund boards, the chief compliance officer (CCO) would conduct quarterly compliance reviews and annual back testing of realized prices to detect patterns that disadvantage funds relative to affiliates, reporting results to the board. Funds that cross trade would report monthly aggregate data by asset class on Form N-PORT and Form N-MFP.
The Financial Crimes Enforcement Network has withdrawn proposed requirements for certain transactions involving unhosted digital asset wallets and a separate proposed special measure targeting convertible virtual currency mixing. The withdrawn measures would have imposed additional reporting, recordkeeping and customer verification obligations, while the mixing proposal would also have designated international mixing as a class of transactions of primary money laundering concern.
The Financial Crimes Enforcement Network has withdrawn two proposed rules that would have imposed additional requirements on financial institutions for certain digital asset transactions. One would have required banks and money services businesses to report, keep records and verify customer identities for certain transactions involving convertible virtual currency or digital assets with legal tender status and unhosted or otherwise covered wallets. The other would have designated international convertible virtual currency mixing as a class of transactions of primary money laundering concern and imposed enhanced recordkeeping and reporting requirements. FinCEN is withdrawing both proposals as part of efforts to ensure digital asset regulation is fit for purpose. Under the unhosted wallet proposal, banks and money services businesses would have been required to report and verify customer identity for covered transactions exceeding USD 10,000, including transactions aggregating above that amount within 24 hours. Recordkeeping and customer identity verification would have applied above USD 3,000. FinCEN will take no further action on that proposal. For the mixing proposal, FinCEN also withdrew its underlying finding that international convertible virtual currency mixing is a class of transactions of primary money laundering concern. The withdrawal reflects concerns that the proposal's broad definition of mixing could chill legitimate activity and impose a substantial reporting burden on covered financial institutions. FinCEN continues to view mixers as potentially facilitating money laundering, terrorist financing and other illicit finance and may take further steps in response to such activity.
Monetary policy developments
Decisions during the week of October 5–11 continued the recent trend towards more restrictive monetary policy, although further tightening remained selective as central banks assessed the persistence of external price pressures against domestic inflation and growth conditions. India raised its repo rate by 25 bp to 5.50%, its first increase since February 2023, and adopted a “calibrated tightening” stance, ruling out near-term cuts as resilient growth coincided with rising underlying inflation and continued energy and food price risks. Uruguay also increased its rate by 25 bp to 6.00%, acting pre-emptively against persistent geopolitical and weather-related shocks despite inflation expectations remaining close to its 4.5% target and limited evidence of broader price pressures. Elsewhere, central banks generally maintained rates where underlying inflation remained more contained or weaker demand limited the need for additional tightening. Iceland held at 8.00% as economic activity slowed and underlying inflation remained broadly stable, despite headline inflation reaching 5.9%. Poland and Peru also kept rates unchanged, with recent inflation increases still largely attributable to fuel and transport costs rather than a broader acceleration in prices. Romania maintained 6.50% as substantial disinflation and weak domestic demand offset renewed energy and exchange-rate risks, while Albania held at 2.50% but signalled that rising inflation risks could warrant future tightening. In Kenya, Serbia and Tanzania, government measures to cushion higher energy costs also supported unchanged policy settings, allowing central banks to continue assessing the effects of prolonged external shocks without further rate increases.