The controlled set prioritises developments with clear primary evidence and a direct connection to Financial Crime control design, data, technology, governance or effectiveness. It deliberately mixes effective requirements with supervisory findings and live/draft instruments — with status shown on every item. Discovery may begin with industry or news signals, but publication is based on the issuing authority's own material.
UK · FCA01. Wholesale-bank data management and Financial Crime control dependencies
Status: Supervisory findings · Primary publication / milestone: 24 Apr 2026
Regulatory position. The FCA’s updated wholesale-bank supervision material describes Financial Crime and market-conduct control failures linked to data migration, incomplete feeds, weak lineage/completeness controls and fragmented change management.
Framework mapping. Population & Boundary · Data & Context · Governance & Assurance
FCRisk control implication. For firms, the practical question is not only whether a monitoring or screening control runs, but whether source-to-consumption completeness, reconciliation and downstream impacts can be evidenced through change and BAU.
Open primary source ↗
UK · FCA02. Sanctions systems and controls: control effectiveness beyond name matching
Status: Supervisory findings · Primary publication / milestone: 28 May 2026
Regulatory position. The FCA published good and poor practice across sanctions governance, risk assessment, screening, list/data feeds, calibration, alert management, asset freezing and breach reporting.
Financial Crime Risk Assessment — evidence, control scope and management action →
Framework mapping. Risk & Scope · Data & Context · Design & Configuration · Decision & Escalation · Governance & Assurance
FCRisk control implication. The development reinforces that sanctions compliance is an end-to-end control architecture: list screening is necessary but cannot substitute for ownership/control analysis, escalation, restriction and reporting.
Open primary source ↗
UK · OFSI03. OFSI strengthens its civil enforcement framework
Status: Guidance revised · Primary publication / milestone: 9 Feb 2026
Regulatory position. OFSI revised its financial-sanctions enforcement and monetary-penalties guidance, adding an Early Account Scheme, revised seriousness assessment, updated disclosure/co-operation and settlement discounts, and fixed monetary penalties for certain information, reporting and licensing offences.
Framework mapping. Decision & Escalation · Governance & Assurance · Remediation & Sustainability
FCRisk control implication. Sanctions incident response should be designed before a breach occurs: evidence preservation, escalation, disclosure quality, co-operation and management of reporting/licensing obligations can materially affect the enforcement pathway.
Open primary source ↗
UK · Government04. Failure to prevent fraud becomes an operational control obligation for large organisations
Status: Effective requirement · Primary publication / milestone: 1 Sep 2025
Regulatory position. The ECCTA corporate offence applies where specified fraud is committed by an associated person intending to benefit the organisation and reasonable fraud-prevention procedures were not in place.
Framework mapping. Risk & Scope · Design & Configuration · Operation & Capacity · Governance & Assurance
FCRisk control implication. The control question moves from reactive fraud detection alone to demonstrable prevention architecture: risk assessment, proportionate procedures, due diligence, communication, monitoring and review become evidence of organisational prevention capability.
Open primary source ↗
EU · AMLR05. EU AML Regulation moves core private-sector AML/CFT requirements into a directly applicable rulebook
Status: Adopted / future application · Primary publication / milestone: 10 Jul 2027
Regulatory position. Regulation (EU) 2024/1624 will apply from 10 July 2027 for most obliged entities, creating the legal base for the detailed AMLA standards now being developed.
Framework mapping. Risk & Scope · Data & Context · Design & Configuration · Governance & Assurance
FCRisk control implication. The implementation challenge is not a single policy refresh. Firms need traceability from the directly applicable requirements into customer risk, CDD, ongoing monitoring, group controls, reporting, data and evidence of effectiveness.
Open primary source ↗
EU · AMLA06. Customer Due Diligence RTS starts specifying the operating detail beneath the AMLR
Status: Draft RTS · consultation closed · Primary publication / milestone: 9 Feb 2026
Regulatory position. AMLA consulted on draft technical standards specifying how CDD requirements should be applied, including information and documents to be collected.
Framework mapping. Data & Context · Design & Configuration · Decision & Escalation · Governance & Assurance
FCRisk control implication. CDD implementation should be treated as a decision-data architecture: required information, verification, risk sensitivity and refresh logic must connect consistently to downstream monitoring and escalation.
Open primary source ↗
EU · AMLA07. Business-wide risk assessment becomes a more explicit operating foundation
Status: Draft Guidelines · consultation closed · Primary publication / milestone: 16 Apr 2026
Regulatory position. AMLA’s draft BWRA guidelines propose minimum requirements for obliged entities to understand risks arising from business model, customers, products, services, transactions, delivery channels and geography.
Framework mapping. Risk & Scope · Governance & Assurance
FCRisk control implication. The BWRA should function as an input to control design and prioritisation, not a standalone compliance document. FCRisk would expect a demonstrable path from assessed risk into controls, monitoring coverage and management challenge.
Open primary source ↗
EU · AMLA08. Ongoing monitoring guidance puts continuous customer understanding and activity review in focus
Status: Draft Guidelines · consultation open · Primary publication / milestone: 3 Jun 2026
Regulatory position. AMLA is consulting on principles for ongoing monitoring under the AMLR; the consultation closes on 3 September 2026.
Framework mapping. Data & Context · Design & Configuration · Operation & Capacity · Decision & Escalation
FCRisk control implication. The likely implementation question is how customer knowledge, expected activity, transaction behaviour and risk changes are connected over time — including which events trigger reassessment and how evidence flows into monitoring decisions.
Open primary source ↗
EU · AMLA09. Group-wide AML/CFT requirements target consistency across subsidiaries and third-country branches
Status: Draft RTS · consultation closed · Primary publication / milestone: 16 Apr 2026
Regulatory position. AMLA consulted on group-wide minimum requirements and additional measures where subsidiaries or branches operate in third countries.
Framework mapping. Risk & Scope · Population & Boundary · Governance & Assurance
FCRisk control implication. For cross-border groups, global policy is not enough: firms need evidence that local legal constraints, data flows, group standards, escalation and compensating measures still produce a coherent group control outcome.
Open primary source ↗
EU · AMLA10. Harmonised formats proposed for suspicious-activity reporting and transaction records
Status: Draft ITS · consultation open · Primary publication / milestone: 2 Jul 2026
Regulatory position. AMLA is consulting on an implementing standard establishing the format for reporting suspicions and providing transaction records to FIUs; the consultation closes on 20 September 2026.
Framework mapping. Data & Context · Decision & Escalation · Governance & Assurance
FCRisk control implication. Reporting quality depends on structured data, evidential consistency and traceability from investigation to external report. Standardisation can expose upstream weaknesses in case data and transaction-record completeness.
Open primary source ↗
Global · FATF11. Strengthened Recommendation 16 moves payment transparency toward richer data and fraud/error controls
Status: Guidance consultation closed · Primary publication / milestone: 24 Jun 2026
Regulatory position. FATF consulted on guidance for the strengthened Recommendation 16 standard, which increases transparency of information accompanying cross-border payments and introduces tools intended to protect against fraud and error. The consultation closed on 21 August 2026; implementation of the revised standard is expected globally by end-2030.
Framework mapping. Population & Boundary · Data & Context · Design & Configuration · Governance & Assurance
FCRisk control implication. Payment-transparency change should be viewed as a data-integrity and interoperability programme as much as a messaging requirement: information completeness, alignment checks, new payment methods and privacy constraints all affect control outcomes.
Open primary source ↗
US · FinCEN12. US AML/CFT programme reform proposal shifts emphasis toward effectiveness and higher-risk activity
Status: Proposed rule · comments closed · Primary publication / milestone: 7 Apr 2026
Regulatory position. FinCEN proposed a revised AML/CFT programme framework intended to emphasise risk-based, reasonably designed programmes, distinguish design from implementation deficiencies and place greater focus on effectiveness. Comments closed on 9 June 2026.
Framework mapping. Risk & Scope · Design & Configuration · Governance & Assurance · Remediation & Sustainability
FCRisk control implication. If finalised broadly as proposed, firms would need stronger evidence connecting risk assessment, resource allocation, independent testing and programme effectiveness — not simply evidence that prescribed activities were completed.
Open primary source ↗
EU · AMLA13. AMLA finalises a common EU approach to classifying AML/CFT breaches and enforcement outcomes
Status: Final draft RTS · awaiting European Commission adoption · Primary publication / milestone: 8 Jul 2026
Regulatory position. AMLA's final draft technical standard under Article 53(10) AMLD sets a common step-by-step approach for supervisors to assess breach gravity against shared indicators, classify breaches into four gravity levels and apply common criteria when determining the enforcement outcome. AMLA states that the objective is greater supervisory convergence while preserving proportionality, effectiveness and dissuasiveness.
Framework mapping. Decision & Escalation · Governance & Assurance · Remediation & Sustainability
FCRisk control implication. Firms should expect the quality of breach evidence, duration and recurrence analysis, governance records and remediation history to matter increasingly in a more structured enforcement environment. This item concerns AMLA's Article 53(10) convergence standard; FCRisk does not treat it as evidence that national fine levels have already been fully harmonised.
Open primary source ↗ · Open final report ↗
UK · Companies House14. ACSP fit-and-proper criteria add continuing suitability to the corporate-gatekeeper control environment
Status: Effective registrar criteria / ongoing monitoring · Primary publication / milestone: 11 Aug 2026
Regulatory position. Companies House must refuse an Authorised Corporate Service Provider application where the applicant is not fit and proper, and will continue to monitor registered ACSPs. The published criteria cover matters including AML supervision, competence, criminal/regulatory/financial history, honesty and integrity, verification and filing activity, repeated concerns and steps taken to remediate issues.
Framework mapping. Risk & Scope · Governance & Assurance · Decision & Escalation
FCRisk control implication. Corporate-service gatekeeping is becoming a continuing-control obligation rather than a one-off registration event. Firms acting as, or relying on, ACSPs should be able to evidence ongoing AML-supervision status, identity-verification and filing controls, issue escalation and continued suitability.
Open primary source ↗
UK · HMRC15. Trust Registration Service scope expands for certain non-UK trusts holding historic UK land
Status: Effective scope change · implementation window · Primary publication / milestone: 30 Jun 2026
Regulatory position. HMRC guidance now brings certain non-UK resident express trusts into Trust Registration Service scope where they acquired an interest in UK land before 6 October 2020 and still held that land on 30 June 2026. HMRC gives those trusts a registration deadline of 1 September 2027 and notes that the service is still being updated to accept these registrations.
Framework mapping. Risk & Scope · Data & Context · Governance & Assurance
FCRisk control implication. Trust and beneficial-ownership controls should identify affected structures, capture the relevant property and ownership context and track the registration obligation through the implementation window. During the service update, absence from the register should not automatically be treated as evidence that a trust is outside scope.
Open primary source ↗