Latest news
FATF publishes targeted update on implementation of the FATF Standards on Virtual Assets and Virtual Asset Service Providers
On 16 July 2026, the Financial Action Task Force (FATF) published a targeted update on implementation of the FATF standards on Virtual Assets (VAs) and Virtual Asset Service Providers (VASPs).BackgroundThis targeted update assesses progress and remaining gaps in the implementation of Recommendation 15 (R.15) across the FATF Global Network, following the extension of the FATF’s anti-money laundering and the combatting the financing of terrorism standards for VAs and VASPs.SummaryFATF set out the following key findings:
There has been some improvement in the implementation of R.15 since 2025. More jurisdictions reported having conducted VA/VASP risk assessments but effectively using these assessments to inform risk-based preventive, mitigation, supervisory and enforcement measures continue to be a challenge for many jurisdictions.
Jurisdictions are increasingly determining how to regulate their VA/VASP sector, but significant gaps remain. More jurisdictions have identified their regulatory approach, including by permitting VA/VASP activity or adopting full or partial prohibitions. However, further analysis is needed to understand the extent to which these frameworks have been effectively operationalised.
Jurisdictions taking a prohibition approach have not progressed in taking supervisory or enforcement actions to sanction VASPs operating illegally within their jurisdictions. The use of prohibition frameworks, while allowed by the FATF Standards, can represent significant risks to the VASP and global financial system if not enforced effectively.
Progress has continued in licensing and registering VASPs, including in supervisory inspections and enforcement actions. Nevertheless, further progress is needed in licensing and registration in practice, and jurisdictions continue to face difficulties in identifying natural or legal persons that conduct VASP activities. Offshore VASPs also remain a significant challenge, with more than a third of jurisdictions with licensing or registration frameworks applying a broader approach to require certain offshore VASPs to be licensed or registered.
Jurisdictions have made progress on implementing the Travel Rule. However, enforcement experience remains limited, with almost half of jurisdictions that have introduced Travel Rule legislation not yet having taken Travel Rule-related supervisory or enforcement action.
Similar to findings in previous Targeted Update reports, identifying individuals or entities exercising control or sufficient influence over DeFi arrangements continues to be challenging.
Since 2025, VA-enabled illicit activity has become more complex and convergent, including through Organised Crime Groups-linked scam centre operations.
ESMA publishes statement on T+1 preparations
On 20 July 2026, the European Securities and Markets Authority (ESMA) published a statement on preparing for the EU T+1 settlement cycle.BackgroundOn 11 October 2027, the EU financial markets will move to a T+1 settlement cycle. As a result, ESMA sets out that it considers that implementation of the changes required for a smooth transition to T+1 must therefore be a key priority for EU market participants in 2026.SummaryESMA sets out the following key points in relation to implementation:
Different implementation strategies are possible: Thorough analysis and planning should help market participants making the appropriate choices, considering all specific circumstances. Automation and standardisation are essential, so firms are encouraged to review all their trading and settlement processes and where relevant, to consider new partnerships. Ensuring data quality in a timely manner is also important, such as using the correct reference data.
Insufficient preparedness among market participants could trigger significant operational and reputational risks: These can include flawed interdependencies with financial market infrastructures and IT providers, inability to meet client demands, and higher IT and training costs stemming from last‑minute remediation efforts. Ultimately, a persistent inability to meet T+1 settlement deadlines and other requirements could reduce the willingness of counterparties to trade, as they seek to avoid the operational risk of late settlement and associated settlement discipline measures.
No one can be ready in isolation: Firms assessing their own readiness is not enough and so firms should check the readiness of their entire ecosystem, up and down the trading and settlement chain, i.e. clients, brokers, custodians, Central Securities Depositary (CSD) participants, CSDs, CCPs, trading venues, vendors and outsourcing providers.
Next stepsESMA highlights that market participants will have to be fully compliant by the following deadlines:
First deadline: 7 December 2026, with the requirements to improve the first post-trade step, the exchange of allocations and confirmations, in terms of timing and through the default use of international communication standards.
Final deadline: 11 October 2027, with the requirements to optimise the settlement layer, including sending instructions early enough to securities settlement systems, and the generalisation of certain functionalities in CSDs, such as auto-partial settlement, hold & release, and auto-collateralisation.
ESMA publishes follow-up report to the peer review on the supervision of cross-border activities of investment firms
On 20 July 2026, the European Securities and Markets Authority (ESMA) published its follow-up report to the Peer Review on the supervision of cross-border activities of investment firms.BackgroundThis follow-up report updates on the actions taken by six National Competent Authorities (NCAs) to address the findings and recommendations of the 2022 peer review on the supervision of cross-border activities of investment services.SummaryThe follow-up report focuses on the home-state supervisory responsibilities of the six NCAs reviewed: Czechia (CNB), Cyprus (CySEC), Germany (BaFin), Luxembourg (CSSF), Malta (MFSA) and the Netherlands (AFM). It assesses progress in areas where expectations were only partially met or not met, and makes the following key observations:
Authorisations: Most NCAs strengthened their authorisation processes to better assess firms intending to provide cross-border services. CNB, BaFin and CSSF introduced more structured requirements covering governance, business models, language capabilities, compliance arrangements, risk management and operational readiness for cross-border activity. CySEC enhanced its application process through additional questions, revised checklists, updated guidance and greater scrutiny of cross-border capabilities before licensing firms. AFM continues to examine cross-border plans during authorisation but relies largely on supervisory judgement rather than documented criteria, the report recommended introducing more formal guidance and consistent assessment criteria.
Ongoing Supervision: All NCAs enhanced their supervisory frameworks by collecting more information on firms’ cross-border activities and integrating that information into risk-based supervision. Most authorities now incorporate factors such as client numbers, complaints, geographic reach, revenues and product risks into supervisory risk scoring. It was recommended in the report that AFM should better integrate cross-border risks into supervisory planning and ensure adequate representation of cross-border firms in inspections, CNB should monitor whether a more systematic approach becomes necessary for credit institutions, and BaFin should increase intrusive supervisory activity, including proactive examinations of higher-risk firms.
Cooperation Among Authorities: Following criticism of delays in responding to requests from other regulators, CySEC introduced performance monitoring, automated tracking, regular management reviews and process improvements. Average response times have improved significantly since 2022, with fewer cases exceeding three months and overall handling times reduced. However, it was recommended in the report that CySEC should continue monitoring response times and take further action if necessary.
Enforcement and Sanctioning: The report found evidence of stronger enforcement activity in several jurisdictions but recommended that CySEC should continue using enforcement proportionately and strengthen analysis of firms’ supervisory histories when determining sanctions and BaFin should ensure enforcement activity remains proportionate to the scale and risks of German firms’ cross-border operations.
Cross-Cutting Considerations: The report found that concerns about rapid growth in Maltese cross-border activity have not materialised. Nevertheless, MFSA has increased staffing and supervisory resources to ensure appropriate oversight. ESMA has also supported convergence through several initiatives, including a 2022 supervisory briefing on cross-border supervision, a new inter-authority fitness and propriety information-sharing system and ongoing cooperation initiatives. Since its launch in 2025, the information-sharing system has facilitated more than 650 exchanges between authorities.
New briefing note: Whistleblowing – a timely reminder for regulated businesses
The allegations concerning the National Energy System Operator that have been brought into the public spotlight by Shadow Energy Secretary Claire Coutinho over the past week continue to attract significant attention. While the facts remain unclear and it would be wrong to speculate on the merits of the allegations, the episode serves as a timely reminder for all regulated businesses of the importance of robust whistleblowing arrangements.As with many aspects of regulatory compliance, preparedness matters. Organisations that can identify concerns early, investigate them effectively and engage constructively with regulators are generally better placed to manage the legal, regulatory and reputational risks that may follow.Whistleblowing should no longer be viewed solely through an employment law lens. While the employment law dimensions remain important, including the potentially significant liability that can arise from the mistreatment of whistleblowers, whistleblowing is increasingly a matter of regulatory risk management. Effective arrangements can help organisations identify and address concerns internally before they escalate into regulatory investigations, political scrutiny or reputational damage.More details, including our review of the prevalence of whistleblowing engagement, can be found here.
Government publishes call for evidence in relation to unauthorised fraud in the UK
On 15 July 2026, the government published a call for evidence in relation to unauthorised fraud in the UK.BackgroundThe government sets out that unauthorised fraud refers to fraudulent transactions made without the account holder’s knowledge or consent where access is gained to a bank account, payment card, or remote banking channel and make transactions or withdraw funds without the victim’s participation or approval. Unlike authorised push payment (APP) fraud, where victims are deceived into making the payment themselves, unauthorised fraud occurs without the victim doing anything to initiate, approve, or enable the transaction.For the purposes of this Call for Evidence the government notes that unauthorised card fraud, unauthorised remote banking fraud and unauthorised cheque fraud are treated as the main categories of unauthorised fraud.SummaryThe government explains that it is undertaking a comprehensive review of the UK’s response to unauthorised fraud and is seeking data, intelligence, case studies, operational insights, technical assessments, and evaluations of existing or proposed prevention measures, including setting out questions in relation to the following:
Criminal Methodologies & Emerging Threats: The government is asking for information such as what respondents consider to be unauthorised fraud; how organisations differentiate unauthorised fraud from authorised fraud; what types of unauthorised fraud organisations been exposed to; methodologies criminals use to commit unauthorised fraud; for evidence on the scale and nature of first‑party fraud within unauthorised fraud,, and on emerging threats.
Drivers of Unauthorised Fraud: The government asks for information on the following issues includingwhat factors are causing or enabling unauthorised fraud to happen; what technologies or digital developments are being exploited to enable unauthorised fraud; what role has the growth of digital wallets played. and how is artificial intelligence used to enable and prevent unauthorised fraud and how is this likely to evolve.
Origins of Unauthorised Fraud: The government asks for evidence on where unauthorised fraud attacks most commonly originate and whether criminals use more than one step or channel to carry out unauthorised fraud, and how do these stages interact.
Barriers to Reducing Unauthorised Fraud: The government has asked for information on the main barriers to reducing unauthorised fraud; the most effective way to address these barriers, and which actors are best placed to do so; how do organisations balance commercial interest, such as speed and accessibility, with robust security and customer protection, and what incentives exist to tackle unauthorised fraud.
Existing measures to address Unauthorised Fraud: The government also wants to understand what steps organisations have taken to prevent or reduce unauthorised fraud, and how effective have these measures been in practice; what are firms’ current transaction risk monitoring and analysis capabilities to identify and prevent unauthorised fraud, and how can they be improved, and sre there any examples of best practice, in the UK or internationally.
Technical Standards, Controls & Authentication: The government has also asked for evidence in relation to how effective current authentication methods are and what weaknesses in technical standards and regulatory requirements are most commonly exploited.
Future Policy & Regulatory Intervention: Finally, the government asks questions in relation to what options it should consider to close vulnerabilities and strengthen defences.
Next stepsThe government has asked for responses by 7 October 2026.
European Commission communication on competitiveness in single banking market
On 17 July 2026, the European Commission (the Commission) adopted a communication on strengthening the competitiveness of the EU banking sector.BackgroundThe Commission emphasises that it considers that a competitive banking sector is essential to finance growth, innovation, strategic autonomy and the EU’s major investment needs and sets out that this communication is linked to the Savings and Investments Union (SIU), the Competitiveness Compass and the recommendations of the Letta and Draghi reports.SummaryThe Commission highlights the following areas that it considers need to be addressed to improve competitiveness of the Banking sector:
Progress and Remaining Challenges in the EU Single Banking Market: The Commission sets out that since the global financial crisis, the EU has strengthened its banking framework through the single rulebook, the Single Supervisory Mechanism, the Single Resolution Mechanism and stronger capital and liquidity requirements. Despite this progress, the Commission identifies three major challenges:
Fragmentation Along National Borders: Cross-border banking activity remains limited. Prudential requirements often require capital and liquidity to be maintained at both group and subsidiary levels, restricting efficient resource allocation. National gold-plating, divergent implementation of EU rules, barriers to mergers and differences in insolvency, taxation, consumer protection and anti-money laundering regimes also hinder integration.
International Standards and EU Specificities: The EU remains committed to Basel standards but recognises that Europe’s banking sector has unique characteristics, including a large number of banks and a greater reliance on bank lending than capital markets. The Commission argues that international standards should be applied in a way that better reflects these specificities and avoids disproportionate burdens on some institutions and activities.
Regulatory Complexity: The banking framework has become increasingly complex due to multiple layers of legislation, guidance and supervisory expectations. Reporting requirements are costly and often duplicative, while overlaps between microprudential, macroprudential and resolution frameworks create inefficiencies and increase compliance costs.
A Way Forward for the EU Banking Sector: The Commission proposes measures to remove barriers to cross-border banking, including allowing more efficient allocation of capital and liquidity within banking groups, aligning the treatment of intragroup exposures, encouraging diversification of sovereign bond holdings and challenging unjustified national intervention in mergers.
International Standards and Proportionality: The Commission will review important aspects of the prudential framework, including the Basel output floor, the treatment of unrated corporates, mortgage lending, project and trade finance, software assets and remuneration rules. The objective is to preserve resilience while ensuring banks can finance strategic sectors and compete internationally. It also proposes a more proportionate regime for small and less complex banks and targeted amendments to the prudential framework for investment firms.
Simplifying the Regulatory Framework: The Commission intends to simplify Pillar 2 requirements, streamline the Minimum Requirement for Own Funds and Eligible Liabilities (MREL), simplify macroprudential capital buffers and strengthen coordination among supervisory, resolution and macroprudential authorities. It also seeks major reductions in reporting burdens through greater automation, data sharing and integrated reporting frameworks.
Competitiveness as a Shared Responsibility: The Commission argues that improving competitiveness requires a cultural shift. Regulators, supervisors and banks should move away from excessive risk aversion and overly prescriptive compliance approaches, focusing instead on material risks and proportionate regulation. Banks are encouraged to take greater responsibility for applying rules without continually seeking additional guidance, while authorities should ensure that supervision remains supportive of innovation, growth and cross-border activity.
Next StepsThe Commission sets out that it intends to develop legislative and non-legislative reforms with the first proposals expected in the first quarter of 2027 and that stakeholder feedback will be invited as these reforms are developed.
FCA closes investigation into Drax Group plc: what it tells us about the FCA’s new enforcement transparency regime and lessons for firms
Last month the Financial Conduct Authority (FCA) announced that it had closed its investigation into Drax Group plc (Drax), having found no evidence that justified any further action. The closure is a noteworthy development, not only for Drax but also in the broader context of the FCA’s new framework for publicising enforcement investigations. When the FCA was consulting around proposals to increase transparency through announcements of investigations, one concern in the market was that publicity at this stage before any findings had been made, could cause reputational damage which would not be adequately redressed when the investigation was closed. BackgroundDrax announced the FCA investigation via RNS on 28 August 2025, stating that the FCA had commenced an investigation covering the period from January 2022 to March 2024, in relation to its statements to the market on biomass sourcing and the compliance of its 2021, 2022 and 2023 Annual Reports with the Listing Rules and Disclosure Guidance and Transparency Rules.On the same day, the FCA confirmed it had opened an investigation into Drax, following enquiries made in the wake of Ofgem’s closure in August 2024 of its investigation into Drax’s reporting of biomass profiling data under the Renewables Obligation scheme. Whilst Ofgem did not find evidence of deliberate misreporting, it concluded that the company had inadequate governance and data controls. The Ofgem investigation in turn followed public criticism of Drax by environmental groups and campaigners and in the media. The FCA’s confirmation of the Drax investigation was a “reactive confirmation” – one of the new categories of announcement introduced under Policy Statement PS25/5 and the revised Enforcement Guide, which we covered in detail in our November 2025 briefing. The reactive confirmation category permits the FCA to confirm that it is investigating where the investigation has already been made public by the firm itself, an affiliate, or another UK or overseas authority.The FCA’s findingsThe FCA has now confirmed, around ten months after the investigation had commenced, that it undertook an extensive investigation following “concerns raised” regarding disclosures to the market about the sustainability of Drax’s Canadian biomass. The FCA says that thousands of pages of complex material were reviewed as part of the investigation, and that individuals from the company were interviewed. The FCA’s focus was on areas within its remit – specifically, whether Drax’s Annual Reports and Accounts between 2021 and 2023 contained misleading statements or omitted important information that investors needed to know. Following all this activity, the FCA did not find evidence that they considered justified any further action.Why is this significant?This is one of the first publicly confirmed investigations to be closed under the FCA’s new transparency framework. While the FCA’s revised approach to publicising enforcement investigations attracted significant attention – and, initially, considerable controversy – when it was first proposed, the Drax closure demonstrates the new framework in practice: announcement, investigation, and closure, all in the public domain. In this case the FCA investigation was closed after ten months and the FCA reiterated that it will close cases “as swiftly as possible” where evidence does not support proportionate action.As we noted in our November 2025 briefing, the FCA’s enforcement transparency initiative signals a continued focus on accuracy of disclosures and governance, including in respect of ESG-related matters. The FCA’s emphasis on the importance of accurate reporting to market integrity – “Accurate reporting is crucial to the integrity of our markets, and vital so investors can make informed decisions” – reinforces the message that the regulator takes listed company disclosure obligations seriously, even where the subject entity is not a regulated financial services firm. Listed companies, and those advising them, should continue to pay close attention to the accuracy and completeness of their annual reports and market-facing statements, particularly in areas attracting public and political scrutiny such as ESG and sustainability.Key takeaways for firmsThe Drax case is a useful reminder of the FCA’s new enforcement transparency regime and an illustration of how it works in practice where an investigation is publicly confirmed but then closed. Firms facing potential or actual FCA scrutiny may take comfort from the fact that the FCA remains committed to closing cases swiftly where the evidence does not justify further action.However, the reputational impact of a public investigation announcement cannot be underestimated and even ten months of scrutiny involving responding to requests for information and a series of interviews with the senior management team can represent a significant burden for firms and their staff. In this case, those ten months followed a previous regulatory investigation itself lasting for over a year.In addition, whilst neither Ofgem nor the FCA confirms the origin of the investigation, the FCA announcement refers to “concerns raised”. Companies face significant exposure from whistleblowers and environmental and other campaign groups across a range of issues particularly when they prompt enquiries from a number of different regulators. The process of dealing with these can take years and involve the company in significant time and expense. Practical steps that firms can take with a view to mitigating such risks include:
maintaining good governance around public disclosures and reporting, including the rationale for decisions and internal check and challenge, so that materials are readily available and can be provided to regulators in the event of any enquiries;
ensuring they have robust speak up, investigation and crisis management plans and regulatory engagement strategies in place;
taking seriously and responding promptly to any issues or concerns that are raised internally or externally (see our May 2026 briefing on whistleblowing); and
engaging proactively with the FCA and other regulators at an early stage with a view to managing regulatory expectations, influencing the narrative, and mitigating the reputational impact.
Podcast | Global Regulation Tomorrow Plus – Crypto under the FCA – Operational Resilience
Our podcast mini-series on ‘Crypto under the FCA’ examines the FCA’s highly anticipated policy statements published on 30 June 2026, which collectively shape the new regulatory regime for cryptoassets in the United Kingdom. This podcast in the series focuses on the FCA’s approach to operational resilience, one of the core cross-cutting requirements the FCA has finalised for all cryptoasset firms entering the new regime.Listen to this episode here.
EBA publishes official translation of amended guidelines on application of definition of default under CRR
On 16 July 2026, the European Banking Authority (EBA) published the official translations of its amended guidelines on the application of the definition of default required under Article 178 of the Capital Requirements Regulation (CRR), as amended by CRR III. The final report on the guidelines had been published in May 2026.SummaryThe EBA has introduced targeted amendments to the guidelines to address specific technical aspects of the past-due treatment of non-recourse factoring and provided updates to align with amendments introduced by the CRR III. It also confirms that the 1% threshold applied to reductions in net present value loss (NPV threshold) in debt restructuring remains appropriate for prudential default recognition.Next stepsThe guidelines will apply from 19 October 2026.Competent authorities must notify the EBA as to whether they comply or intend to comply with these guidelines, or otherwise with reasons for non-compliance, by 17 September 2026.
EBA final report on RTS and ITS on material acquisitions, transfers, mergers and divisions under CRD IV Directive
On 17 July 2026, the European Banking Authority (EBA) published its final report on draft regulatory technical standards (RTS) and draft implementing technical standards (ITS) on new supervisory tools relating to material operations under Capital Requirements Directive (EU) 2024/1619 (CRD VI), amending Capital Requirements Directive 2013/36/EU (CRD), which introduced new tools in relation to material operations carried out by credit institutions, financial holding companies or mixed financial holding companies.• The draft RTS specify, in respect of each of the material operations, the minimum list of information to be provided, the assessment methodology and the process for the notification and the assessment.• The draft ITS reflect concern common procedures, forms and templates for the consultation process between the relevant authorities concerning material operations.Next stepsThe draft RTS, together with the draft ITS, will be submitted to the European Commission for endorsement, following which the RTS will be subject to scrutiny by the European parliament and the Council, before being published in the Official Journal of the European Union.
FCA publishes explanatory statement relating to its direction on the UK DTO
On 9 July 2026, the Financial Conduct Authority (FCA) published an explanatory statement under Article 28a(9) of the UK Markets in Financial Instruments Regulation (UK MiFIR) relating to the FCA direction on the derivatives trading obligation (UK DTO).BackgroundOn 31 December 2024, the FCA issued a new direction under Article 28a of UK MiFIR to modify the UK DTO, replacing the expiring transitional direction. The direction allows firms subject to the UK DTO, trading with or on behalf of EU clients subject to the EU DTO, to execute those trades on EU trading venues, provided certain conditions are met, which includes that firms must take reasonable steps to be satisfied the client does not have arrangements in place to execute the trade on a trading venue to which both the UK and EU have granted equivalence.SummaryUnder Article 28a(9) of UK MiFIR, where a direction remains in effect for longer than 6 months, the FCA must publish as soon as reasonably practicable after each 6-month period, a statement explaining why the conditions under Article 28a(1)(a) and (b) continue to be met in order to extend it for a further six months. As a result, the FCA has published the following explanation covering the six-month period to 31 December 2026:
Article 28a(1)(a) – Ongoing need to prevent or mitigate market disruption: In the absence of mutual equivalence between the UK and EU, the FCA considers that maintaining the direction is necessary to prevent or mitigate disruption for market participants caught by a conflict of law between the EU and UK DTOs, in particular branches of EU firms in UK.
Article28a(1)(b) – Advancement of FCA’s operational objectives: The FCA sets out that it is of the view that the direction continues to advance its operational objectives under section 1B(3) of the Financial Services and Markets Act 2000 by preventing or mitigating disruption for market participants caught by a conflict of law between the EU and UK DTOs in the absence of mutual equivalence between the UK and EU.
Next stepsThe FCA confirms that a further review will be conducted at the conclusion of the next six-month period, after which, if the direction is still in force the FCA will issue a new statement.
Crypto under the FCA – New video and podcasts
The FCA has published a major package of finalised rules, guidance and consultations establishing the UK’s new crypto assets regulatory regime, effective from 25 October 2027, with firms needing to prepare authorisation or variation of permission applications from September this year.In this latest video Hannah Meakin and Haney Saadah outline a six-point plan for firms seeking authorisation or variation of permission. They also flag upcoming podcasts that will examine the individual FCA publications in more detail.The first in the podcast series covers trading.Further podcasts will cover:
Overseas firms
Prudential requirements
Consumer Duty
Crypto-custody
Crypto-staking
Operational resilience
Lending
Market abuse
Stablecoins
FCA publishes good practice and areas of improvement in relation to products and services
On 10 July 2026, the Financial Conduct Authority (FCA) published findings of its review into firms’ approaches to products and services.BackgroundThe FCA explains that the Consumer Duty (the Duty) sets a higher standard for retail consumer protection and that, to support firms in meeting the requirements of the Duty, the FCA are continuing to provide firms with examples of good practice and areas for improvement. The FCA further sets out that the examples in this report are intended to help firms learn from each other and improve compliance with the products and services outcome and are not intended to introduce new regulatory requirements.SummaryThe FCA highlights the following findings, in particular:
Product and service design, and target market: The FCA explains that firms demonstrated good practice by designing products and services around a detailed understanding of customer needs, often using customer profiles and negative target markets to assess suitability. Many tested target market compatibility through customer journey and vulnerability impact assessments, identifying and mitigating potential harms. Firms also adapted products, services and customer journeys to be more inclusive, including through accessible digital design, clearer communications and tailored support for vulnerable customers. Smaller firms effectively used customer feedback and frontline staff insights. However, some firms need to improve target market granularity, particularly for higher-risk products, and focus not only on identifying vulnerable customers but also on adapting products and services to meet their needs.
Monitoring and review: The FCA emphasised that firms are increasingly using outcome-focused, customer-centric management information (MI) to monitor whether customers receive good outcomes. Good practice includes combining customer feedback, complaints, root-cause analysis and behavioural data into dashboards that identify emerging risks and trends. Firms monitor indicators such as product usage, cancellations and service outcomes, and use these insights to make targeted improvements. Examples include clearer customer communications, new product features, operational process improvements and enhanced investment options, all of which led to measurable reductions in complaints or improved customer engagement. However, some firms rely too heavily on complaints data and fail to use MI proactively to identify risks. Others make product or service changes without adequately measuring whether those interventions have actually improved customer outcomes.
Distribution and third parties: The FCA also sets out that firms demonstrated good practice by tailoring distribution strategies to the needs of their target market, particularly for customers in vulnerable circumstances, through accessible channels, fee waivers and alternative ways to access products and services. Many also adapted distribution arrangements to reflect product complexity and reduce the risk of poor outcomes. Effective engagement with distributors, supported by regular management information and feedback, helped firms identify and address issues such as mis-selling and out-of-target-market sales. Firms also took corrective action where distribution issues arose, often using root-cause analysis and ongoing monitoring. Areas for improvement include providing stronger evidence to justify distribution strategies and better measuring whether changes to distribution approaches have successfully improved customer outcomes.
Government announces first CTP designations
On 10 July 2026, HM Treasury (HMT) announced that four major global cloud services and technology providers will be designated as Critical Third Parties (CTPs) from 13 July 2026.The Critical Third Parties (Designation) Regulations 2026 have also been made which designate the four entities as CTPs.The CTPs regime was established through the Financial Services and Markets Act 2023 to strengthen the operational resilience of the UK financial system. HMT makes designation decisions following consultation with third parties, the Bank of England, Prudential Regulation Authority (PRA) and Financial Conduct Authority (FCA). The regulators have made rules that set the outcomes that they expect from designated CTPs (see PRA Policy Statement 16/24 and FCA Policy Statement 24/16). Such CTPs must identify and manage risks to the systemic services they provide, and maintain open, timely communication with regulators and the firms that rely on them, particularly during major incidents.
FCA publishes Enforcement Watch 2 – Supervising and enforcing the Consumer Duty
On 7 July 2026, the Financial Conduct Authority (FCA) published the second edition of its enforcement newsletter – Enforcement Watch 2 – in which it covers its recent approach to supervising and enforcing the Consumer Duty (the Duty).The FCA introduced the Enforcement Watch newsletters in light of a suggestion made in response to its consultation on publicising enforcement investigations (CP24/2). The newsletters provide detail on the topics and trends in the FCA’s investigations and enforcement work, aiming to help firms identify areas of potential vulnerability in their business. The publication of this second edition follows the FCA’s first newsletter in January (see our briefing on Enforcement Watch 1 here). Enforcement Watch 1 covered a range of issues and sectors so it is notable that the FCA has now chosen to concentrate their attention on the Duty only.The second edition of the newsletter: (i) reminds firms of the FCA’s expectations in relation to the Duty; (ii) provides an update on the FCA’s interventions work in this area; and (iii) discusses enforcement action connected with the Duty, including setting out information on the 11 matters currently under investigation. We set out the key points from the newsletter below.The FCA’s expectations in relation to the DutyPrinciple 12 reflects the FCA’s expectation that firms consider customer outcomes and put customers’ interests at the heart of their activities. The FCA is clear that firms should: (i) continually challenge themselves to make sure their actions are compatible with their customers’ interests and financial objectives; and (ii) work to identify and prevent harm from occurring, and provide evidence of good consumer outcomes.From a supervisory perspective, the FCA supports firms in this area by publishing examples of good practice and areas for improvement, often following multi-firm work. In more assertive supervision, since it was introduced, the FCA has commissioned around 30 skilled person reviews which reference the Duty.Interventions concerning the DutyLast year the FCA intervened 382 times. It can use formal powers such as imposing requirements on firms, but it does not always need to, to achieve the right outcome. Once it has intervened, the FCA will continue its supervisory engagement with a firm, including ensuring that any deficiencies in the firm are remedied and that the restrictions put in place are complied with.The newsletter sets out some of the ways in which the FCA has intervened and used the Duty or rules that work alongside it, including examples involving insurance firms, wealth management firms, a fund manager, a financial advice firm, a CFD trading platform and claims management companies.In terms of publicity regarding interventions, the FCA notes that it usually publishes VREQs on the Financial Services Register for reasons of transparency and consumer protection, though it may remove the restrictions once the issues are resolved and it is not possible to search the Register to identify which firms have been the subject of requirements. The FCA almost always publicises OIREQs through issuing Supervisory Notices, unless there is a strong reason not to, such as where a firm exercises its right to challenge an OIREQ in the Upper Tribunal and makes a privacy application.Enforcement in relation to the DutyThe FCA opens investigations where its Supervision team has detected serious misconduct and it considers that an enforcement investigation is necessary, proportionate, and likely to create impactful deterrence. In assessing whether to open an enforcement investigation, the FCA considers factors including its regulatory priorities, the seriousness of the misconduct, the harm (or potential harm) it has caused, and whether other regulatory responses might be more effective.The FCA is currently investigating 11 matters involving potential Duty breaches, including investigations in the insurance, pensions, wealth management, consumer investments, peer-to-peer lending and claims management sectors and the newsletter provides some further detail on some of these open cases. With regards to the insurance sector, in September 2025 the consumer advocacy group Which? submitted a super-complaint to the FCA regarding home and travel insurance and in the FCA’s response it mentioned investigations in this area. In our briefing on the response we set out our thoughts on considerations for firms in light of the FCA’s response to the super-complaint, including what this signifies in terms of the FCA’s approach to the Duty.In several cases, the FCA is investigating whether consumers received fair value for a product or service in line with PRIN 2A and/or its PROD Rules which work alongside the Duty. The FCA explains that fair value is about more than just price – for example, there is unlikely to be fair value provided where a product or service doesn’t meet any of the customer’s needs, causes foreseeable harm, or frustrates their objectives, whatever the price. In some investigations, the FCA is looking at whether firms have properly assessed whether the price consumers paid was reasonable compared to the overall benefits.The FCA emphasises however that it is not only interested in price and value. The different parts of the Duty often overlap, and a product or service that does not meet its customers’ needs may fall short of the Duty in several ways. For example, the FCA may look at: whether the features of the product or service were made clear to customers before, during and after sale to help them make an informed choice about purchasing or continuing with the product or service; and/ or what support was given to customers when things went wrong.For further updates in relation to these areas please see our Interventions and Investigations Hub and our Consumer Duty Hub.
The Crime and Policing Act 2026: Key concepts for businesses to understand
From 29 June 2026, organisations can be held liable in the UK where a senior manager commits an offence while acting within the actual or apparent scope of their authority. This represents a significant expansion of corporate criminal liability in the UK, building on the regime introduced by the Economic Crime and Corporate Transparency Act 2023, which was limited to certain economic crime offences.This is the second article in our series on the Crime and Policing Act 2026 for businesses. In our previous article, we focused on four practical implications of the new law, including the increased risk of corporate liability, the need for effective compliance programmes and training, and the greater scrutiny that businesses can expect from stakeholders.In this article, we examine three of the key concepts underpinning the new regime under the Crime and Policing Act 2026:
The expanded scope of offences: The new statutory attribution model is no longer limited to specified economic crimes and can apply to any criminal offence committed by a senior manager acting within the scope of their authority.
Who qualifies as a “senior manager”: The definition is broad and focuses on the role an individual plays in managing or organising all or a substantial part of an organisation’s activities, rather than on job title alone.
Extraterritorial implications: Businesses with international operations should carefully consider how the new attribution rules may apply in a cross-border context.
For a fuller discussion of these issues, including practical considerations for businesses, see the full article here.Please contact any of the authors listed above if you would like to discuss how these changes may affect your business.
Financial Services and Markets Bill concludes Lords committee stage
On 8 July 2026, members of the House of Lords reached the end of detailed examination of the Financial Services and Markets Bill (the Bill) in committee stage.Topics considered during the committee stage regarding amendments to the Bill included:
Tokenisation in UK wholesale financial markets.
FCA rules on AI in financial services.
Regulation of the digital asset industry.
Increasing public understanding of financial services.
Financial services dispute resolution.
An amendment paper has also been published.The Bill will now move to the report stage for further examination, which has yet to be scheduled.
House of Lords Financial Services Regulation Committee publishes FCA and PRA correspondence in relation to the FCA and PRA secondary competitiveness and growth objective
On 9 July 2026, the House of Lords Financial Services Regulation Committee (the Committee) published correspondence from the Financial Conduct Authority (FCA) and Prudential Regulation Authority (PRA) providing a one-year update in relation to the FCA’s and PRA’s secondary competitiveness and growth objective.The FCA highlighted the following it its letter to the Committee:
Policy changes in pursuit of economic growth: The FCA has implemented major capital markets reforms, including changes to listing and prospectus rules, bond market transparency, and retail access to corporate bonds. It has introduced innovations such as PISCES and plans further reforms, including an equities consolidated tape, T+1 settlement and securitisation changes. Consumer-focused measures include mortgage affordability reforms, greater flexibility for lenders, changes to contactless payment limits, and proposals to broaden pension investment opportunities while maintaining consumer protections.
Supporting innovation and firms seeking to grow: The FCA has expanded innovation initiatives, including its AI-focused Supercharged Sandbox and AI Live Testing services. Support for firms has been enhanced through the Pre-application SupportServices (PASS), the Scale Up Unit and increased Early and High Growth Oversight (EHGO) capacity. The FCA is also promoting UK financial services exports and inward investment through international engagement and an expanded overseas presence.
Supervision and proportionality: The FCA has streamlined supervision to focus on fewer, higher-impact priorities and improved communication through Regulatory Priorities Reports. Automation has reduced processing times for lower-value cases. Proportionality initiatives include reducing certification roles under the Senior Manager and Certification Regime (SM&CR) and easing certain application requirements. The FCA has also reviewed Consumer Duty requirements for wholesale firms and committed to reforms, while emphasising responsiveness to market feedback when developing regulatory rules.
Being a smarter regulator: The FCA is using technology and data to improve efficiency while keeping headcount flat. Reporting reforms have reduced industry costs by over £16 million annually, with further savings expected from transaction reporting changes. The FCA has simplified regulatory interactions and improved compliance. Authorisation processes have become faster, with most applications meeting target timelines. The FCA is also using AI and tech sprints to improve decision-making and investing in staff skills to meet future technological challenges.
Savings and investment: The FCA is promoting savings and investment through reforms arising from the Advice Guidance Boundary Review, including simplified advice and targeted support that could benefit millions of consumers. It is supporting the mutuals sector through dedicated development initiatives and faster registration processes. The FCA also aims to facilitate defence-related investment by clarifying sustainability rules, engaging industry stakeholders and prioritising the authorisation of defence-focused investment funds.
Future plans and prioritisation: The FCA’s 2026/27 programme focuses on growth, investment, pensions reform, Open Banking, Open Finance and tokenised funds. While maintaining market integrity and addressing risks such as consumer vulnerability, volatility and financial crime, it intends to keep headcount flat and fee increases low. The FCA emphasises that growth requires coordinated action across government and regulators, and supports ongoing dialogue on how regulatory and legislative frameworks can adapt to future economic and technological change.
The PRA highlighted the following in its letter to the Committee:
Final rules implementing our Strong and Simple capital framework: This will apply to smaller, domestic-focused lenders from the start of 2027. The PRA sets out that the new rules are intended to radically simplify the regime for these firms. This will cut costs for Small Domestic Deposit Takers (SDDTs), facilitate competition and support lending to UK households and businesses. The PRA have also made progress in delivering significant simplifications for a wider population of firms addressing some key areas of concern for mid-tier firms including through the finalisation of Basel 3.1 standards and changes relating to the minimum requirements for own funds and eligible liabilities (MREL) framework. The PRA also published a discussion paper which sets out its exploratory thinking on the design of a potential simplified internal ratings-based approach (IRB) for residential mortgages for medium-sized firms.
Insurance Matching Adjustment Investment Accelerator (MAIA): This is intended to support growth by enabling insurers to seize investment opportunities and recognise a capital benefit from their investments more quickly. This should help the insurance industry deliver on the pledge it made to the Government, in the context of the introduction of the Solvency UK regime, in relation to investment in UK assets.
Reporting requirements for banks: These reductions are being introduced through the Future Banking Data (FBD) programme. The first stage of the reporting reductions, which were implemented with effect from 31 December 2025, should cut costs by around £26 million annually. The PRA are now engaging closely with industry to develop this work further, including through its recent discussion paper DP1/26.
Financial Policy Committee’s updated assessment of bank capital requirements: Following the updated FPC assessment, the PRA are taking forward work to ensure the capital framework supports growth and competitiveness, while maintaining resilience. This includes work on the UK’s approach to regulatory buffers, leverage ratio requirements and the interaction of elements of the capital framework which attach mainly to domestic exposures.
Podcast | Global Regulation Tomorrow Plus – Crypto under the FCA – Trading
Our podcast mini-series on ‘Crypto under the FCA’ examines the FCA’s highly anticipated policy statements published on 30 June 2026, which collectively shape the new regulatory regime for cryptoassets in the United Kingdom. This first podcast in the series focuses specifically on the regulatory aspects governing cryptoasset trading.Listen to this episode here.
ESMA Final Report on draft RTS on CCP admission criteria elements
On 8 July 2026, the European Securities and Markets Authority (ESMA) issued a Final Report on the regulatory technical standards (RTS) concerning the central counterparties’ (CCPs) admission criteria elements, following the review of the European Market Infrastructure Regulation (EMIR 3).BackgroundUnder Article 37(7) of EMIR (as amended) ESMA is mandated to develop draft RTS further specifying the elements to be considered when a CCP: (a) establishes its admission criteria referred to in Article 37(1) of EMIR (as amended), and (b) assesses the ability of non-financial counterparties (NFCs) acting as clearing members to meet margin requirements and default fund contributions referred to in Article 37(1a) of EMIR (as amended).When developing the draft RTS, ESMA is required to take into account: (a) the modalities and specificities through which NFCs might, or already do, access clearing services, including as direct clearing members in sponsored models; (b) the need to facilitate prudentially sound direct access of NFCs to CCP clearing services and activities; (c) the need to ensure proportionality; and (d) the need to ensure an effective management of risks.Final ReportThe Final Report presents the final draft RTS prepared by ESMA following an earlier consultation.Section 4 outlines the requirements proposed by ESMA with regard to the elements to be considered when a CCP establishes its admission criteria.Section 5 sets out the requirements proposed by ESMA with regard to elements to be considered when a CCP assesses the ability of NFCs acting as clearing members to meet margin requirements and default fund contributions.Section 6 contains various annexes including the final draft RTS.Next stepsThe Final Report, including the final draft RTS presented in it, will be submitted to the European Commission. The Commission has three months to decide whether to adopt the draft RTS in the form of a Commission Delegated Regulation. Following the adoption, they are then subject to non-objection by the European Parliament and the Council.
Showing 21 to 40 of 100 entries