Volume 9 (2025-26)

Each volume of Journal of Financial Compliance consists of four 100-page issues.

Articles included in Volume 9 will be listed here as they are published in each quarterly issue.

Volume 9 Number 4

Editorial
Compliance at the edge: Tectonic plates and the expanding frontiers of risk
Dr Mario J. DiFiore, Editor

Practice papers
SFTR revisited: How can European markets benefit from digital regulatory reporting?
Leo Labeis, CEO, REGnosys, and Adrian Dale, Head of Regulation and Markets, International Securities Lending Association

Abstract ▼

This paper evaluates the structural limitations of the Securities Financing Transactions Regulation (SFTR) and presents digital regulatory reporting (DRR), supported by the common domain model (CDM), as a viable framework for improving regulatory data quality and reducing the cost and complexity of compliance. SFTR’s dual-sided reporting framework was introduced to enhance transparency in securities financing markets but has led to widespread operational challenges, including inconsistent life cycle event reporting, data granularity issues, valuation mismatches, schema constraints and regulatory divergence. These shortcomings have produced persistent reconciliation breaks and inflated compliance expenditures across European financial institutions. The paper positions DRR as a transformative alternative to text-based regulation. By expressing regulatory rules as machine-executable code, DRR standardises interpretation and eliminates ambiguity in reporting logic, ensuring that identical transactions yield consistent outputs across firms. When combined with the CDM — a standardised, open-source representation of financial products and life cycle events — DRR enables a uniform, business-aligned view of transaction inputs and codified reporting instructions. The paper demonstrates how this approach directly addresses key SFTR problem areas, from collateral classification to timestamp tolerances, by exposing and harmonising the underlying business logic. While the CDM already supports derivatives reporting across multiple jurisdictions, extending it to SFTR requires additional modelling of securities-finance-specific trade events such as recalls and reallocations. The paper concludes with a proposed transition pathway combining market-driven adoption, incremental implementation and regulatory encouragement through guidance rather than prescriptive reform, arguing that a DRR-enabled framework would yield higherquality supervisory data and strengthen the resilience and competitiveness of European capital markets. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  Securities Financing Transactions Regulation (SFTR); data quality; regulatory reporting; standardisation; digital regulatory reporting (DRR); CDM

Strengthening AML and sanctions controls in the digital assets era
Satish M. Kini, Partner, Aseel M. Rabie, Counsel, and Jonathan R. Wong, Associate, Debevoise & Plimpton

Abstract ▼

This paper explores the anti-money laundering (AML) and sanctions regulatory environment for digital assets in the US, with particular emphasis on the emerging digital asset policy framework under the current presidential administration. The paper considers the principal illicit finance risks presented by digital asset activities and addresses key implications for AML and sanctions compliance controls for both digital asset firms and traditional financial institutions entering the digital asset ecosystem. Although US authorities have endorsed a more supportive approach to innovation and digital asset activities, regulators have simultaneously reaffirmed the importance of AML and sanctions compliance and risk management as key priorities. Among other topics, the paper discusses practical considerations and challenges related to leveraging blockchain analytics tools, structuring risk-based transaction monitoring procedures and addressing sanctions compliance obligations for digital asset transactions. The paper then addresses similar AML and sanctions control considerations from the perspective of traditional financial institutions that have dealings with digital asset firms or digital asset activities. For compliance teams and legal practitioners, this paper provides an actionable understanding of the AML and sanctions framework for digital assets and how to operationalise a compliance programme that appropriately addresses relevant risks and regulatory obligations. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/ business/.
Keywords:  anti-money laundering (AML); sanctions; financial crime; digital assets; blockchain; crypto; illicit finance

The future of AI in banking compliance and internal controls: A UK practitioner’s view
Marili Anderson, Head of UK Compliance, Rabobank

Abstract ▼

The rapid evolution of artificial intelligence (AI) is transforming the banking sector, particularly in compliance and internal controls. This paper explores the future role of AI in enhancing regulatory adherence across jurisdictions, mitigating risks and streamlining operational processes. It examines how advanced technologies — such as machine learning, natural language processing and predictive analytics — are reshaping compliance frameworks and enabling proactive risk management. The scope includes practical examples of AI applications in transaction monitoring, fraud detection, regulatory reporting and internal audit functions, as well as the ethical and governance challenges that accompany these innovations. Readers will gain insights into emerging trends, regulatory expectations and implementation strategies that balance innovation with accountability. By the end of the paper, compliance professionals and banking leaders will have a better understanding of how AI can drive efficiency, accuracy and resilience in internal control systems while maintaining trust and meeting stringent regulatory standards. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  Artificial intelligence (AI) in banking compliance; AI in financial services; AI-driven internal controls; future of AI and agentic AI in banking; regulatory technology (RegTech); machine learning for compliance; predictive analytics in banking; AI for fraud detection; automated regulatory reporting; governance and ethics in AI

Non-financial regulatory reporting: Operating model conundrums in an era of regulatory proliferation
Hussain Abdullah, Director, Data and Regulatory Operations, Citigroup

Abstract ▼

Nonfinancial regulatory reporting (NFRR) has evolved from a discrete compliance obligation into a complex, multijurisdictional challenge consuming significant resources across financial institutions. As reporting obligations proliferate — with European Markets Infrastructure Regulation requiring 203 fields, Markets in Financial Instrument Directive II requiring 65 fields and Securities Financing Transaction Regulation demanding 155 fields — institutions face critical strategic decisions about how to structure, govern and execute their reporting obligations. This paper examines the fundamental operating model choices confronting institutions, from fully centralised to decentralised to functionally federated approaches. Drawing on a decade of implementation experience, the inherent trade-offs between cost and control, flexibility and efficiency, and expertise and standardisation are analysed. The analysis reveals that while sophisticated models such as functional federation promise significant efficiency gains, they carry substantial implementation risks when stress points remain unmanaged. Particular attention is given to the dangers of insufficient technical expertise, inadequate data governance and cultural immaturity. The paper concludes that operating model success depends critically on matching architectural ambition to organisational reality, with poorly implemented federated models often performing worse than well-executed centralised approaches. For practitioners, the key insight is that sophisticated efficiency can become sophisticated fragility when foundational requirements go unmet. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  transaction reporting; nonfinancial regulatory reporting (NFRR); operating model; risk; Markets in Financial Instruments Regulation; European Markets Infrastructure Regulation; Securities Financing Transaction Regulation

Opening pan-DORA’s box: Navigating the practical challenges of the EU’s Digital Operational Resilience Act
Nathaniel Lalone, Partner, Financial Markets and Funds, and Ciara Watson, Associate, Financial Markets and Funds, Katten Muchin Rosenman UK

Abstract ▼

The Digital Operational Resilience Act (DORA) establishes comprehensive information and communication technology (ICT) risk management requirements for EU financial entities, applying from 17th January, 2025. It mandates new frameworks for operational resilience testing, third party risk management and incident reporting, while requiring extensive provisions to be embedded in contractual arrangements with ICT third party service providers. Implementation challenges include regulatory delays, complex register of information requirements and difficult contract negotiations. To navigate DORA’s complexities, financial entities should establish cross-functional governance, prioritise contract remediation by criticality and implement proportionate compliance approaches tailored to their specific risk profiles and operational circumstances. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  Digital Operational Resilience Act; DORA; operational resilience; third party service providers; information and communication technology; ICT; risk management; contract remediation; register of information; threat-led penetration testing; TLPT; EU financial regulation

Fighting market abuse in the age of AI: Five strategic shifts every financial services executive must address
Chris DeNigris, Director of Product Marketing, NICE Actimize

Abstract ▼

Market abuse has entered a new era. What was once episodic, localised and largely detectable is now growing in frequency and magnitude, cross-border and increasingly difficult to detect. Insider trading, spoofing and manipulation no longer necessarily occur within a single asset class, venue or communication channel. They can unfold across markets, platforms and jurisdictions. Technology has accelerated this shift. Algorithmic trading compresses reaction times to milliseconds. Digital assets trade 24/7 across fragmented venues. Social media and encrypted messaging enable rapid coordination outside traditional surveillance perimeters. Meanwhile, regulators are raising expectations, not lowering them, using advanced analytics of their own and imposing record-breaking penalties for failures in supervision, recordkeeping and detection. For senior executives, the implication is clear: market abuse has evolved beyond a traditional compliance issue. It is a strategic risk that tests the resilience of a firm’s governance, data architecture, operating model and culture. As markets accelerate, AI is no longer optional. It has become the foundation of effective surveillance, while simultaneously introducing new governance, explainability and accountability expectations from regulators. This paper explores five structural trends redefining market abuse risk and outlines the decisions leaders must make to adopt AI-driven surveillance in a way that is defensible, scalable and aligned with regulatory expectations. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  Market abuse, artificial intelligence (AI); market surveillance; financial compliance; regulatory enforcement; cross-market manipulation; off-channel communications; crypto assets; natural language processing (NLP); anomaly detection

The nature and art of financial supervision: Reflections on a 25-year journey
Christopher P. Buttigieg, Chief Officer, Supervision, Malta Financial Services Authority, and Associate Professor, University of Malta, Malta

Abstract ▼

This paper reflects on 25 years of experience in financial regulation and supervision, emphasising key lessons for future professionals. It underscores that effective supervision requires adaptability, independence, accountability, proactive intervention and international cooperation. The evolution from principles- based to rules-based and now outcomes-based regulation highlights the need for regulators to be flexible amidst global crises, technological advances and emerging asset classes such as crypto assets. Independence is vital to resist political and industry pressures, ensuring long-term stability and credibility. Accountability and due process, supported by comprehensive audit trails and collective decision making, reinforce transparency and public trust. Proactive intervention is essential in detecting and addressing market malpractice early, preventing systemic crises. Lastly, international cooperation is indispensable given the interconnectedness of today’s financial markets, requiring trust, knowledge sharing and coordinated oversight across borders. The paper advocates for a professional and ethical approach among regulators, emphasising that integrity builds confidence in the system. These lessons aim to guide upcoming professionals in navigating complexities, fostering resilience and maintaining the integrity and competitiveness of the global financial landscape. The overarching message is that adaptability, independence, accountability, proactive action and international collaboration are fundamental to robust financial supervision in an ever-evolving environment. This article is also included in The Business & Management Collection which can be accessed at https://hstalks. com/business/.
Keywords:  financial supervision; compliance; regulation; supervisory experience; knowledge sharing

Volume 9 Number 3

Editorial
Compliance at the edge: Tectonic plates and the expanding frontiers of risk
Dr Mario J. DiFiore, Editor

Papers
Lessons from Russia’s full-scale invasion of Ukraine for sanctions-related litigation
Satindar Dogra, Partner, and Michael Munk, Managing Associate, Linklaters

Abstract ▼

In response to Russia’s full-scale invasion of Ukraine, the UK imposed sweeping sanctions on ‘designated persons’. At the time of writing, the conflict continues, many firms hold frozen funds owed to designated persons and will continue to do so for some time. Russian law permits claims to be brought in Russia despite exclusive choice of forum clauses, which gives rise to strategic challenges for international firms with operations and assets in jurisdictions that may be liable to enforcement. In recent cases before the English courts, Western firms have obtained anti-suit injunctions (ASIs) and related declarations in England, only later to have been coerced by Russian anti-ASIs (AASIs) into applying to withdraw that relief. In such cases, this has left firms with no effective legal orders to restrain designated persons from pursuing claims in Russia (although some declarations have been left in place). This paper reflects on tactical considerations for cross-border sanctions-related litigation in the context of the Russia sanctions regime. It seeks to highlight what further steps could be taken by the government to protect and uphold English antisuit and anti-enforcement injunctions when designated persons take matters into their own hands. This paper also suggests that it may be beneficial to update sanctions legislation to reduce the effectiveness of Russian AASIs. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  anti-suit injunction; ASI; sanctions litigation; contempt of court; conflict of laws

Elevating board reporting: Putting purpose at the heart of the compliance story
Natalie McManus-Barnett, Managing Director, Innovate Compliance

Abstract ▼

Legal and regulatory expectations on board reporting are evolving, and reporting on compliance matters needs to keep up. In an environment increasingly defined by cross-risk contagion, regulatory scope creep and fast-moving threats, data, insights and narratives need to blend together to tell a compelling and faithful compliance story while also informing proactive and strategic risk decisions. This paper explains why a strategic and purposeful approach to compliance reporting, building on board needs and governance first principles, is essential. It explores what this looks like and how to balance competing interests, offering takeaways for the modern practitioner and shaping expectations for board audiences. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  compliance risk reporting; compliance data; compliance analytics; nonfinancial data; board reporting; management information; key compliance risk indicators; emerging risk; datainformed decision making; corporate governance; fiduciary duty; stewardship

Leveraging technology in third party risk management
Vrushali Lakhpati, Vice President of Third Party Program, AmTrust Financial Services

Abstract ▼

In today’s increasingly interconnected and digital business environment, third party risk management (TPRM) has become a crucial component of enterprise risk strategies. The expansion of outsourced services, strategic partnerships and extended supply chains has increased reliance on third parties for essential business functions. While this reliance enhances operational capabilities, it simultaneously introduces significant exposure to data breaches, regulatory non-compliance, reputational damage and operational disruption. Traditional TPRM methods, often manual, reactive and inefficient, struggle to keep pace with the scale and complexity of today’s third party ecosystems. Recent events, including cyberattacks, supply chain disruptions, and evolving regulatory landscapes, have underscored the need for robust frameworks and scalable solutions. This paper examines how technology is revolutionising TPRM by offering integrated risk management platforms, automation, artificial intelligence and advanced analytics. These tools provide organisations with greater visibility, efficiency and agility in identifying, assessing and mitigating third party risks. Recent studies indicate that the number of third party relationships is rising, with over 60 per cent of organisations managing more than 1,000 third parties, accompanied by a surge in third party data breaches and emerging threats.1 Despite heightened regulatory scrutiny, many organisations still lack effective oversight of these diverse risk domains. By leveraging technology, organisations can overcome the limitations of manual, siloed approaches and develop resilient, proactive TPRM programmes. The adoption of digital solutions not only enhances risk mitigation and compliance but also strengthens strategic decision making and supports business continuity in an unpredictable global environment. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  third party risk management; TPRM; technology; TPRM trends

Using AI to future-proof sanctions screening
Marketa Piecuchova, Compliance Officer, David Mayo, Head of Compliance Programme, Policy and Awareness, and Daniel Ueltschi, Head of Compliance Digital and Analytics, Swiss Re

Abstract ▼

This paper explores the application of artificial intelligence (AI) in sanctions screening, focusing on how the technology can address the growing challenges posed by increasingly complex regulatory environments, limitations of the traditional rules-based sanctions screening systems, dynamic changes in sanctions lists and the need for greater operational efficiency and consistency in alert handling. The discussion centres on challenges faced by financial services firms in particular, but also by any organisation subject to sanctions compliance obligations. The paper explores how AI, in particular the current capabilities of generative AI powered by large language models (LLMs), can potentially offer significant enhancements to traditional rule-based sanctions screening systems and provide guidance on how an organisation can prepare for the use of AI in sanctions screening. It also outlines the technical, organisational and regulatory prerequisites for successful AI integration, including robust governance, technological maturity, model explainability, transparency and fairness and workforce upskilling. Early adopters are already demonstrating measurable benefits in efficiency and risk detection, signalling that AI is beginning to shift from experimental to practical use in early-adopter organisations. This paper further offers practical strategies for implementation, from defining success metrics to training operations and compliance teams to interpret and challenge AI decisions. It concludes that realising AI’s potential will depend not only on technological readiness but also on alignment with regulatory expectations, cross-functional expertise and strong governance, all of which are crucial to embedding AI into sanctions compliance programmes. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  sanctions; sanctions screening; artificial intelligence; AI; gen AI; counterparty due diligence; financial crime compliance

EMIR Refit: Lessons learned from the EU and UK implementations
Andrew Leonard, Regulatory Reporting Lead SME, BBPLC COO and Global Cross Border Compliance, BBPLC, BCSL and PBWM, Barclays

Abstract ▼

The European Market Infrastructure Regulation (EMIR) was introduced to enhance the transparency and stability of over-the-counter (OTC) derivatives markets in the wake of the 2008 financial crisis. Since its implementation in 2014, EMIR has undergone several updates, including the 2024 EMIR Refit, aimed at simplifying reporting requirements, reducing compliance burdens and ensuring better market transparency. This paper explores lessons learned from the implementation of EMIR Refit in both the European Union (EU) and the UK, highlighting key changes in regulatory requirements, such as simplified reporting, harmonised data standards and intragroup exemptions. Despite the goals of simplifying compliance, firms continue to face significant challenges in adapting to the 2024 Refit, including issues related to system upgrades, ambiguous regulatory language and data reconciliation. The paper discusses common hurdles such as inconsistent implementations, inadequate project planning and the complexity of transitioning to new data standards such as ISO 20022.1 It also examines the importance of clear governance, effective testing and the need for cross-functional collaboration within firms to meet regulatory expectations. The findings emphasise the necessity of early preparation, robust technical frameworks and continuous regulatory engagement to navigate the evolving regulatory landscape. Ultimately, the paper offers practical recommendations for firms to improve compliance, operational efficiency and adaptability in future regulatory transitions, including the development of an implementation blueprint for ongoing regulatory evolution. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  European Market Infrastructure Regulation; EMIR; Refit; regulatory compliance; reporting requirements; ISO 20022; project governance

The money laundering reporting officer: Some reflections from Malta
Christopher P. Buttigieg, Chief Officer of Supervision, and Eric Micallef, Assistant Manager of Financial Crime Compliance Function, Malta Financial Services Authority

Abstract ▼

The role of the money-laundering reporting officer (MLRO) has become increasingly complex and crucial in the face of evolving regulatory frameworks and rapid technological advancements. This paper examines the expanding responsibilities of MLROs, particularly within the context of the European Union’s new anti-money laundering (AML) supervisory framework and the proliferation of financial technology. It explores the multifaceted challenges faced by MLROs, including the need for technical expertise, regulatory compliance and proactive risk management in an era of heightened personal liability. The paper also highlights the transformative potential of artificial intelligence and data-driven solutions in enhancing AML/countering the financing of terrorism (CFT) processes, while emphasising the irreplaceable role of human judgement in addressing emerging risks. Furthermore, it underscores the ethical and legal considerations associated with the adoption of advanced technologies, particularly in relation to data privacy and civil liberties. Ultimately, this paper argues that the successful navigation of these dynamic challenges by AML/CFT professionals is essential to maintaining the integrity and resilience of the global financial system in an increasingly complex and high-stakes environment. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  money-laundering reporting officer; MLRO; anti-money laundering; AML; artificial intelligence; AI; regulatory compliance; financial crime; financial crime compliance

Leveraging AI to navigate the evolving sanctions landscape: A guide for financial institutions
Igor Sumkovski, Senior Compliance Manager of Anti-Money Laundering/Counter-Terrorist Financing/Counter Proliferation and Sanctions, Euroclear

Abstract ▼

The global sanctions landscape has grown increasingly complex amid recent geopolitical shifts, particularly following the escalation of sanctions against Russia since 2022. Financial institutions (FIs) are now facing unprecedented challenges in maintaining compliance with rapidly evolving and, at times, conflicting sanctions regimes, while simultaneously managing operational pressures, rising compliance costs and heightened risks of fines. Artificial intelligence (AI) presents a compelling opportunity to support FIs in building compliance frameworks that are both more robust and more efficient, not only for sanctions compliance but across all areas of financial crime risk. This paper examines how, by adopting AI solutions, FIs can enhance the effectiveness and efficiency of sanctions compliance while navigating the multifaceted challenges of modern sanctions requirements. The paper also analyses the main barriers to the adoption of AI-driven solutions, offering practical advice on overcoming these obstacles, with a focus on data quality, legacy systems and the evolving role of compliance practitioners. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  sanctions; financial crime; compliance; risk management; screening; artificial intelligence; AI; machine learning; data quality

Volume 9 Number 2

Editorial
Mario J. DiFiore

Communications surveillance in financial institutions: What’s new, what’s changed and why it’s still broken
Alexander Aronov, Head of Surveillance and Employee Compliance Intelligence, Citigroup

Abstract ▼

This paper explores the persistent challenges in communications surveillance within the financial services industry, highlighting how, despite technological advancements, these systems often fail to achieve a balance between precision and scalability. The paper examines three core pillars of modern surveillance: data governance, detection and alert generation and alert disposition and analytics. Furthermore, the paper provides practical recommendations for compliance and regulatory professionals. It delves into the strategic ‘build versus buy’ decision for surveillance technology and outlines best practices for data management, model validation and alert handling. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  communications; surveillance; data; governance; artificial intelligence; AI; machine learning; ML; natural language processing; NLP

Third party risk management and M&A: What third party risks did you just buy?
James P. Bergin, Partner, Arnold & Porter, Beate Parra, Managing Director and Head of Legal Americas, UniCredit and Trevor Kirby, Associate, Arnold & Porter

Abstract ▼

Under the Trump Administration, the regulatory priorities of the US federal banking agencies appear to be shifting to a more open stance towards approval of bank mergers and acquisitions (M&A). Notwithstanding that shift, the US federal banking agencies will likely continue to prioritise enhanced third party risk management (TPRM) as an important principle of safe and sound banking policy. Regardless of the winds in Washington, banks engaging in M&A need to effectively integrate vendors into the combined organisation. This paper aims to bridge the gap between bank M&A activity and TPRM by providing practical guidance into TPRM for banks engaging in M&A transactions. The authors have conducted a series of interviews with banking institutions of varying sizes and have surveyed applicable literature and regulatory guidance to discern best practices for TPRM in the context of bank M&A. The authors conclude that even in a regulatory environment friendlier to bank M&A activity, banks should consider third party contractual relationships in the context of each of the following deal-making phases: (1) strategy; (2) due diligence and (3) integration. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  financial crimes; artificial intelligence; AI; AI governance; governance; compliance; AML; anti-money laundering; AI policy; machine learning; AI/machine learning; ML; AI and ML

The importance of governance in artificial intelligence and machine learning technology
Stacey Chieng, Chief Anti-Money Laundering Officer and Sourit Dasgupta, Global Head of Model Risk and Analytics, Interactive Brokers

Abstract ▼

Financial institutions increasingly deploy artificial intelligence (AI) and machine learning (ML) solutions to enhance compliance processes. While this trend promises significant efficiency gains, it also introduces complex governance challenges that compliance executives must effectively address. Drawing on regulatory developments, technical considerations and industry best practices, this paper presents the process to develop a comprehensive governance framework for mitigating risks associated with AI/ML implementation in compliance functions. This paper concludes with a forward-looking perspective on evolving governance requirements as AI/ML technologies continue to transform financial compliance. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  financial crimes; artificial intelligence; AI; AI governance; governance; compliance; AML; anti-money laundering; AI policy; machine learning; AI/machine learning; ML; AI and ML

When traditional finance adopts crypto: Updating risk assessments and controls
Meredith Fitzpatrick, Director of Cryptocurrency, Investigations and Compliance, Forensic Risk Alliance et al

Abstract ▼

As regulatory clarity around digital assets improves and enforcement eases ߞ especially in the USA ߞ traditional financial institutions may find the time right to enter the crypto market. However, To maintain their positions as trusted institutions, the most successful institutions will be updating legacy risk frameworks to capture the distinctive risks and challenges inherent to cryptocurrency products and services. This paper examines how financial institutions can adapt their risk and compliance functions to leverage opportunities in the crypto space while mitigating threats to their overall regulatory obligations and financial crime exposure. Beginning with a brief overview of recent regulatory developments that are encouraging greater institutional participation, the paper then outlines how crypto introduces new and evolving risks that require specialist attention. The paper concludes with practical guidance on embedding crypto into enterprise-wide risk assessments (EWRAs). Institutions that wish to innovate responsibly must ensure these controls are designed to meet regulatory expectations while maintaining trust with clients and stakeholders. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  cryptocurrency; blockchain; regulatory compliance; financial institutions; risk assessments

Managing unintended cultural implications of investigations
Chantal Peters, Partner, Financial Services Disputes and Investigations and James Chadwick, Partner and Head of Financial Services Investigations and Contentious Regulatory, TLT

Abstract ▼

The last decade has seen significant societal, workplace and regulatory evolution, with financial services firms being held to increasingly higher standards. Consequently, the number, complexity and pace of investigations faced and instigated by financial services firms have risen exponentially. This has created an environment in which firms and their employees are exposed to increasing risk of regulatory, civil, criminal and disciplinary sanctions. When faced with such risks, the immediate focus is usually on responding to the specific issues under investigation (in compliance with regulatory and internal processes) and minimising the risk of sanction. However, one risk that typically gets overlooked is the fact that the investigatory process itself can lead to cultural implications, which may in turn be harmful to a firm and its employees. Such cultural implications, if not addressed, could evolve into a cycle of subsequent investigations and appeal processes scrutinising the treatment of employees, enterprise culture and impact, all of which are matters that could ultimately undermine the integrity and outcomes of the originating investigation. Firms must also not forget the importance of employees’ faith in investigatory processes and the link to psychological safety ߞ namely the need to instil an environment where healthy risk-taking and the challenge of poor conduct are encouraged without fear of victimisation or reprisals. The importance of this should not be underestimated. Psychological safety plays a key role in attracting and maintaining a wider range of individuals within an organisation and thereby driving resilience. This objective remains on the regulators’ radar, although its priorities for driving the objective have shifted from prescriptive equality, diversity and inclusion frameworks to a focus on tackling nonfinancial misconduct.1 While that shift may, in part, be driven by the political climate surrounding the issue of EDI (particularly in the USA), it may also reflect a view by the regulators that tackling nonfinancial misconduct is more immediately impactful. Workplace investigations play a key role in tackling nonfinancial misconduct, and so getting them right is crucial. The obvious areas for harm, should culture within an investigation setting not be carefully managed, are to an enterprise’s reputation, the referral of concerns to third parties and the loss of (or failure to attract) quality employees, shareholders and customers. This paper explores the importance of culture, how unintended cultural implications may arise in an investigation context and ways in which the unintended implications may appropriately be managed in order to mitigate risk. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  investigations; culture; conduct; psychological safety; financial institution; speak up; diversity of thought

Adopting a holistic approach to regulatory change management: The rise of the end-to-end RegTech solution
Susie MacKenzie, Head of Legal and Regulatory Analysis, Corlytics

Abstract ▼

Regulatory change management has become a practice in and of itself. It is a science, not an art. Regulators expect regulated entities to have systems and controls, policies and procedures in place to mitigate associated risks. At its most basic, it involves identifying, interpreting and actioning emerging risks before they manifest themselves as material risks ߞ regulatory, reputational, strategic or otherwise. Regulators require financial institutions to have zero risk appetite for regulatory risk. Mitigating controls and procedures across all three lines of defence need to reflect that position. Manual compliance processes are being replaced by automated processes, with increased incorporation of AI, as in-house teams manage the volume of regulation. This paper focuses on comprehensive end-to-end ‘RegTech’ solutions and some of the considerations and challenges of implementation. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  RegTech; regulatory change management; horizon scanning; regulatory change monitoring; AI; regulatory mapping

What are the key components of an effective methodology for conducting business-wide risk assessments for money laundering?
Matt Russell, Senior Executive, Avyse Partners

Abstract ▼

This paper explores the core components of an effective methodology for conducting business-wide risk assessments (BWRAs) for money laundering (ML), terrorist financing (TF) and proliferation financing (PF), a key regulatory requirement central to the UK’s Money Laundering Regulations (MLR) 2017. Despite the long-standing emphasis on the risk-based approach (RBA) in both UK and international standards, recent enforcement actions by the Financial Conduct Authority (FCA) reveal persistent weaknesses in regulated firms’ implementation of this obligation. Through a diagnostic framework grounded in ISO 31000, the international standard for risk management, this paper analyses FCA enforcement notices issued over the past decade to identify thematic failings in risk assessment, risk treatment and governance. The paper then evaluates the extent to which current industry guidance, namely the Joint Money Laundering Steering Group (JMLSG) Guidance Notes, adequately addresses these shortcomings. The findings suggest that although the guidance aligns with regulatory expectations, it disproportionately emphasises customer due diligence (CDD) at the expense of broader risk governance and fails to distinguish clearly between key risk assessment elements: identification, analysis and evaluation. The paper argues for a more holistic, process-oriented approach to BWRAs, with enhanced guidance on risk mapping, iterative control calibration and the integration of customer and transaction-level assessments into firm-wide risk management. Readers will gain practical insights into how to strengthen the effectiveness of their BWRAs by aligning them more closely with established risk management standards and by interpreting enforcement findings through a process-focused lens, thereby enhancing regulatory compliance and financial crime risk mitigation. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  business-wide risk assessment; BWRA; risk-based approach; RBA; Financial Conduct Authority; FCA; ISO 31000; anti-money laundering; AML; financial crime compliance

Ethical implications of artificial intelligence in financial compliance: Balancing innovation and responsibility
Vikas Kulkarni, Vice President and Lead Software Engineer, US Bank

Abstract ▼

This paper explores the ethical implications of artificial intelligence (AI) in financial compliance, focusing on key issues such as bias, data privacy, transparency and accountability. The study aims to evaluate how AI can enhance regulatory adherence while addressing ethical challenges faced by financial institutions. A qualitative methodology was employed, including a comprehensive literature review, case study analysis of institutions such as HSBC and JPMorgan Chase and a comparative analysis of AI adoption rates and cost efficiencies. Key findings indicate that while AI improves operational efficiency and reduces compliance costs by up to 30 per cent, it also introduces risks related to algorithmic bias and data privacy violations. Realworld examples demonstrate the trade-offs between innovation and ethical responsibility, emphasising the need for balanced frameworks. The study offers actionable recommendations for policymakers and industry leaders, including investments in ethical risk management, fairness-testing frameworks and transparent AI governance practices. These findings underscore the importance of aligning AI innovations with ethical principles to foster trust, ensure equitable outcomes and maintain long-term sustainability in financial services. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  artificial intelligence; AI; financial compliance; AI ethics; algorithmic bias; data privacy; transparency and explainability; ethical governance; responsible AI

Advancing third party risk management through blockchain-based smart contracts: Impacts on assessment and management of money laundering in third party ecosystem
Jessica Kim, Director of Third Party Risk Management, Sun Life

Abstract ▼

Financial institutions continue their reliance on third parties for critical operations and digitalisation efforts to support innovation and flexibility in their operations and service offerings. With the increasing dependency on third parties, financial institutions are subject to greater risk exposure; consequently, regulatory bodies across jurisdictions are enhancing and increasing supervisory oversight on financial institutions’ management of third party risks. This paper explores the adoption of blockchain-based smart contracts to enhance financial institutions’ management of third party risks, with a focus on assessment and management of money laundering. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  third party risk management; TPRM; risk assessment; anti-money laundering; AML; blockchain; smart; contracts

Volume 9 Number 1

Editorial
Mario J. DiFiore

Papers
Financial compliance in the AI era: Overcoming risks and seizing opportunities
Micaela Madureira, Head of Compliance, Banco Carregosa

Abstract ▼

Risk management is a cornerstone of financial compliance, requiring institutions to integrate risk considerations into their strategic frameworks. This paper advocates for a holistic approach to compliance risk management, emphasising the importance of cultivating an appropriate organisational culture, utilising advanced tools and ensuring the presence of skilled human resources. By fostering collaboration, selecting relevant structured and unstructured data and leveraging emerging technologies, financial institutions can strengthen their resilience and effectively navigate evolving regulatory demands. This paper delves into the pivotal role of compliance specialists in shaping the future of financial risk management, offering a structured framework to enhance organisational resilience and compliance in the face of new challenges. It also explores the role of artificial intelligence (AI) and its application in compliance risk management, including the regulatory frameworks governing AI technologies and their role in minimising compliance risks. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  artificial intelligence (AI); compliance risk; risk management; new systems

Putting the science in compliance: Using non-financial data to re-engineer compliance risk assessment
Natalie McManus-Barnett, Managing Director, Innovate Compliance

Abstract ▼

Risk assessment is essential to the compliance toolkit, but it is in need of a rethink. Often annually performed, manually compiled and lacking in credible data, its insights can quickly become obsolete, divorced from day-to-day compliance practices. To manage the reach, complexity and interconnectivity of modern compliance risks, it is paramount that firms evolve their approach, repositioning risk assessment at the heart of decision making and cultivating a model based on real-time, data-informed insight. This essay provides the foundations for such a model, providing future blueprints for an AI-integrated compliance risk assessment centred on nonfinancial data and analytics. This article is also included in The Business & Management Collection which can be accessed at https:// hstalks.com/business/.
Keywords:  compliance risk assessment; data-informed risk assessment; compliance risk modelling; compliance risk metrics; real-time compliance; compliance analytics; nonfinancial data

Securing the future of the EU digital identity wallet: Why we need corporate digital identity standards now
Henry Balani, Clinical Professor, Quinlan School of Business, Loyola University Chicago

Abstract ▼

This paper explores the critical necessity for establishing corporate digital identity (CDI) standards in the digital economy of the European Union. As online services proliferate, the need for secure digital identities (IDs) becomes paramount, particularly within the European Union, which has advanced initiatives such as the electronic IDentification, Authentication and trust Services (eIDAS) regulation and the proposed EU Digital Identity Wallet. The discussion differentiates CDI from individual digital IDs, emphasising unique complexities such as dynamic corporate structures and distinct data privacy requirements. This paper argues that robust CDI frameworks can significantly enhance security, streamline processes and ensure regulatory compliance, particularly in financial transactions. It underscores the imperative of developing common standards for both referential and transactional data exchange, facilitating seamless and secure cross-border interactions. The creation of such standards necessitates collaboration among regulatory bodies, financial institutions and industry participants, with an eye towards global interoperability. By establishing these standards, this paper posits that it will be possible to foster greater trust, efficiency and transparency in digital ecosystems, ultimately benefiting both corporates and individuals. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  digital identity wallet; corporate digital identity (CDI); regulations; EU; banking; financial crime

Reverse solicitation: Rules of the Road and International Enforcement Trends
Andrea Vianelli, COO Asset Management and Strategic Advisory, and Antonio Appon, Legal and Compliance Officer, Laser Digital

Abstract ▼

This paper discusses the concept of reverse solicitation in the context of cross-border provision of financial services, seeking to combine a theoretical and a pragmatic approach to a topic that has not been — to the authors’ knowledge — subject of in-depth analyses leading to actionable insights. In particular, it offers a practitioner’s perspective on how reverse solicitation is often invoked as a silver bullet to enable a cost-effective market access route, despite being a very narrow (and often without exit) alley. After introducing the concept of reverse solicitation as ‘exception to the rule’ rather than as a de facto alternative to licencing, the author(s) offers an overview of the most recent legal and regulatory sources on reverse solicitation in the EU as well as in other selected markets. The final section concludes with observations on some of the open challenges around the concrete application, both from an investment firm as well as from a supervisory perspective, of reverse solicitation. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  crypto assets; digital assets; Market in Crypto Asset Regulation (MiCAR); regulation; reverse solicitation; DeFi; financial instruments; financial law; investment services; cross-border; regulation

Enhancements in the regulation of company service providers: A Maltese perspective
Christopher P. Buttigieg, Chief Officer Supervision, Malta Financial Services Authority, Malta and University of Malta, and Alison Cortis, Head of CSP Supervision, Malta Financial Services Authority

Abstract ▼

This paper explores the essential role of company service providers (CSPs) in Malta’s financial sector, particularly regarding regulatory frameworks aimed at combatting money laundering and terrorist financing. It reviews the historical evolution of CSP regulation, focusing on the CSP Act and subsequent reforms designed to enhance compliance and eliminate exemptions. While significant progress has been made, ongoing challenges related to proportionality highlight the need for further refinements to the regulatory framework. The analysis emphasises the importance of balancing effective oversight with the facilitation of legitimate business activities, particularly within the Class B under-threshold CSP segment. Proposed improvements, including a registration and notification system, aim to streamline compliance processes and strengthen risk assessment capabilities. Finally, this paper suggests future research directions, such as comparative studies and the evaluation of current oversight practices, to deepen understanding of CSP regulation. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  financial crime; company service providers (CSPs); anti-money laundering (AML)

Navigating the path to GenAI for enterprise compliance
Jas Randhawa, Managing Partner, Jon Lo, Managing Director, and Will Hayk Karapetyan, Consulting Manager, StrategyBRIX Canada Inc

Abstract ▼

Generative artificial intelligence (GenAI) represents a paradigm shift in today’s reality, influencing every major area of the enterprise function. Organisations in every sector look for ways to capitalise on the operational and functional efficiencies that the tool enables. Compliance represents one of the more challenging yet vital functions in enterprises, often pressured with ever-evolving regulatory requirements across industries; the complexity, resource intensity and the high cost of failure emphasise the high risk of the function. Artificial intelligence offers the opportunity to automate, standardise and streamline the organisation’s compliance areas, such as data governance, risk detection and response, policy management, continued monitoring and reporting, compliance and risk assessment. This paper provides a highlevel guideline for evaluating the enterprise compliance function for GenAI implementation while addressing its regulatory requirements and implementation challenges. It summarises key areas of AI implementation in compliance with an example of GenAI implementation at StrategyBRIX. This paper covers best practices for implementing GenAI, including data readiness assessment, organisational fit test, data privacy, security and scalability, challenges and regulatory requirements and maintenance of an AI programme. This paper concludes with practical next steps and further considerations for a GenAI enterprise adoption. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  AI in compliance; GenAI implementation challenges; AI regulatory requirements; enterprise AI implementation; AI risk management; AI governance considerations

How the Russia/Ukraine experience will inform possible future sanctions strategies
Neil Whiley, Head of Sanctions, Bank ABC

Abstract ▼

The Russian invasion of Ukraine has led to an unprecedented expansion of sanctions against a major economy, physically and economically connected to Europe. The expansion of designation criteria and the increase in trade-based measures targeting specific sectors of the Russian economy have blurred the lines between sanctions and export controls. Trade sanctions now account for 80 per cent of the sanctions imposed against Russia. This is creating new challenges for those that have an obligation to comply with the measures. The introduction of measures, such as ‘person connected with Russia’ and the focus on preventing circumvention and evasion, has highlighted the need for sanctions teams to understand politically exposed person (PEP) risk rating and trade-based moneylaundering (TBML) methodologies, highlighting the need for collaboration between sanctions and anti-money laundering (AML) teams. Innovative measures such as the Oil Price Cap exception show new ground being broken for Russia sanctions and it is possible that some of these measures will be issued under additional regimes in future. While Russia remains a significant focus, it is only one of the nearly 40 regimes enacted; there is a growing emphasis on targeting enablers in various countries, including Iran, the Democratic People’s Republic of Korea (DPRK) and China. The UK autonomous sanctions landscape, while still recent is evolving quickly and testing the ability of regulators and government departments to provide clear legislation, regulation and guidance to ensure that UK sanctions achieve their aims effectively. Effective sanctions are a whole society challenge, involving multiple sectors and jurisdictions. Sanctions is a team sport, which will only work if we all work together. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  sanctions; Russia; measures; financial; trade; oil

Navigating the UK’s new offence for failure to prevent fraud
Ann Ðoàn, Director of Financial Crime Consulting, and Claire Lipworth, Partner, Hogan Lovells International LLP

Abstract ▼

On 6th November, 2024, the Home Office published guidance on the new corporate failure to prevent fraud offence, which was introduced by the Economic Crime and Corporate Transparency Act 2023. The guidance confirms that the new offence will come into effect on 1st September, 2025 and states that it will ‘make it easier to hold organisations to account for fraud committed by employees or other associated persons … [and] will also encourage more organisations to implement or improve prevention procedures, driving a major shift in corporate culture to help prevent fraud’. Companies need to carefully consider the guidance to ensure that they understand the extensive scope of the offence and the appropriate measures that need to be taken to protect themselves against corporate criminal liability. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords:  failure to prevent; corporate criminal liability; financial crime; fraud; mis-selling; market abuse; conduct

Back to Journal