Volume 10 (2026-27)

Each volume of Journal of Financial Compliance consists of four 100-page issues.

Articles included in Volume 10 will be listed here as they are published in each quarterly issue.

Volume 10 Number 1

Editorial
Dr Mario J. DiFiore, Editor

Practice papers
Navigating the crossroads: Sanctions compliance for international banks in a fragmented regulatory landscape
Philipp Harsdorf, Head of Group Sanctions, LGT Bank

Abstract ▼

This paper critically examines how international banks can navigate the increasingly complex and fragmented landscape of sanctions compliance, shaped by the expanding extraterritorial reach of US and EU regimes. It analyses the operational and legal challenges arising from overlapping obligations, such as the EU’s ‘best efforts’ requirement under Council Regulation (EU) No 833/2014 of 31st July, 2014 concerning restrictive measures in view of Russia’s actions destabilising the situation in Ukraine [2014] OJ L229/1, and the proliferation of secondary sanctions. Drawing on recent regulatory developments and enforcement trends, the paper identifies key risks such as conflicting legal duties and exposure to strategic sanctions risk. It presents a framework for managing extraterritorial risks, integrating scenario analysis, strategic exposure mapping, and the alignment of legal, compliance, and business functions. The findings highlight the necessity for banks to move beyond reactive compliance, embedding sanctions risk into strategic decision making and governance. The paper concludes that operational resilience and regulatory credibility depend on proactive, documented approaches that anticipate evolving supervisory expectations and enforcement pressures. This article is also included in The Business & Management Collection which can be accessed at http://hstalks.com.business/.
Keywords: financial sanctions; regulations; strategic risk management; multi-jurisdiction; extraterritorial

Striking the balance between innovation and risk: A practical governance framework for AI adoption in financial services
Johanna Anders, Head of Distribution Compliance, and CCO, Janus Henderson Distributors US

Abstract ▼

Artificial intelligence (AI), and generative AI in particular, is rapidly reshaping how financial services firms operate, from investment research and portfolio analytics to marketing communications, financial promotions, compliance, and risk management. While the potential efficiency and scalability gains are significant, so too are the regulatory, operational, and governance risks associated with AI adoption. This paper examines how financial services firms can strike a practical balance between innovation and risk by embedding AI within disciplined governance, compliance, and supervisory frameworks. Using marketing compliance and financial promotions as a central case study, the paper explores how AI can be deployed as a pre-review and triage mechanism — supporting global consistency, scalability, and time-to-market — while preserving human judgment, accountability, and regulatory defensibility. Drawing on regulatory expectations and practical implementation considerations, the paper outlines a pragmatic approach to AI governance designed for complex, multi-jurisdictional organisations. This article is also included in The Business & Management Collection which can be accessed at http://hstalks.com.business/.
Keywords: artificial intelligence; generative AI; governance; marketing compliance; financial promotions; supervision

The role of AI in sourcing and mining data to identify, secure and manage relevant evidence: Is it really the panacea it claims to be?
Catherine Bellsham-Revell, Head of Legal — Litigation and Contentious Regulatory, and Karalyn Twinem, Senior Lawyer — Litigation and Contentious Regulatory, Lloyds Banking Group

Abstract ▼

The rapid expansion of digital data has transformed the demands of modern legal practice, particularly in investigations, regulatory enquiries, and disputes. This paper examines the evolving role of artificial intelligence (AI) — especially generative AI (GenAI) — in sourcing, analysing, and managing evidence within this increasingly complex landscape. While traditional AI tools such as predictive coding and machine learning classifiers have long supported document review, emerging GenAI capabilities now enable the drafting of summaries, extraction of themes, and generation of structured narratives from large, diverse datasets. Against the backdrop of the UK’s sector-led, principles-based approach to AI regulation, the paper explores how legal and compliance teams can use AI responsibly while maintaining essential safeguards relating to accountability, transparency, fairness, and auditability. It outlines the benefits of AI across e-discovery, evidence triage, communication monitoring, privilege screening, and regulatory response preparation, drawing on practical examples from recent large-scale legal matters. At the same time, it offers a clear-eyed assessment of AI’s limitations. The paper highlights risks linked to data quality, admissibility, bias, privacy, and cross-border processing, as well as the inherent opacity of GenAI systems. It underscores why experienced human oversight remains indispensable, both to validate AI outputs and to ensure that nuanced legal judgments, including those on privilege and proportionality, are not compromised. Readers will gain practical insight into the capabilities and boundaries of AI in evidence management, learn how to integrate AI tools safely and effectively within governance frameworks, and understand the skills — such as prompt engineering and critical oversight — required to harness these technologies with confidence and rigour. This article is also included in The Business & Management Collection which can be accessed at http://hstalks.com.business/.
Keywords: artificial intelligence (AI); generative AI (GenAI); evidence management; legal technology; regulatory compliance; document review and disclosure

Navigating the EU’s new AML regime: Practical implications of AMLR and AMLA for senior compliance and risk leaders
Adrianna Fabijanska, Global Head of Financial Crime Compliance — Investment Banking, ING

Abstract ▼

The adoption of the EU Anti-Money Laundering Regulation (AMLR)1 and the establishment of the Anti-Money Laundering Authority (AMLA)2 mark a structural reconfiguration of the European Union’s anti-money laundering/combatting the financing of terrorism (AML/CFT) framework. Together, they shift the EU from nationally mediated implementation towards a directly applicable single rulebook combined with supervisory convergence anchored in demonstrable effectiveness rather than procedural compliance. This paper examines the new regime through a practitioner-informed analytical lens, focusing on how AMLR and AMLA are likely to reshape supervisory behaviour, institutional accountability, and the practical application of the risk-based approach. It argues that the reforms represent not merely legal harmonisation, but a recalibration of the relationship between regulation, supervision, and institutional decision making, in which supervisory credibility increasingly depends on the quality of risk judgment and escalation logic. Drawing on comparative insights from the Single Supervisory Mechanism, the article situates AMLA as a de facto ‘fourth line of defence’, driving convergence through common methodologies, peer-based assessment, and data-driven supervision. Particular attention is given to Article 75 AMLR and the expansion of public–private partnerships, as well as the need to reconcile enhanced information sharing with General Data Protection Regulation (GDPR) constraints. The analysis highlights reduced tolerance for national gold-plating, heightened scrutiny of proportionality, and increased visibility of inconsistencies across jurisdictions and business lines. Finally, the EU reforms are placed in a global context, assessing alignment with Financial Action Task Force (FATF) standards and the implications for the EU’s competitiveness as a financial centre. This article is also included in The Business & Management Collection which can be accessed at http://hstalks.com.business/.
Keywords: EU AML Regulation (AMLR); Anti-Money Laundering Authority (AMLA); risk-based approach; supervisory convergence; public–private partnerships; FATF alignment

A unified architecture for sanctions intelligence in digital asset markets
Aniket Mandavkar, and Tony Gagliardi

Abstract ▼

Sanctions compliance in digital asset markets raises challenges that differ materially from those encountered in traditional financial systems. Public blockchains introduce pseudonymity, indirect exposure, timing effects, and a rapidly evolving landscape of cross-chain movement and decentralised finance activity that complicate the use of entity-centric screening approaches. In practice, virtual asset service providers often address these challenges through fragmented tooling and bespoke logic that is difficult to govern, explain, or scale. This paper presents a unified architecture for sanctions intelligence in digital asset markets. The architecture integrates blockchain data, sanctions designations, analytical enrichment, and governance controls within a modular system design. Rather than proposing a new detection algorithm, the paper focuses on architectural principles that support consistent risk interpretation, explainable decisions, and regulatory defensibility across diverse blockchain environments. Sanctions intelligence is organised into distinct but integrated layers covering data ingestion, enrichment, risk propagation, decision orchestration, and auditability. A lightweight and interpretable risk propagation model is used to demonstrate how indirect exposure, temporal sensitivity, and designation severity can be operationalised without reliance on opaque techniques. The paper also addresses practical deployment considerations within virtual asset service providers, including alert handling, investigator transparency, and supervisory oversight. By offering an implementation-agnostic reference architecture grounded in operational realities, this work provides a foundation for practitioners, system designers, and regulators evaluating scalable and auditable approaches to sanctions compliance in digital asset markets. This article is also included in The Business & Management Collection which can be accessed at http://hstalks.com.business/.
Keywords: sanctions compliance; digital assets; blockchain analytics; sanctions intelligence; governance; auditability

Governing data risks in the age of AI
Xin Tu

Abstract ▼

Artificial intelligence (AI) and in particular generative AI (GenAI) has accelerated data risk in financial services by changing how data is accessed, transformed, and used to drive decisions that regulators closely scrutinise. The pace of AI adoption has outrun many organisations’ data control foundations: AI tools frequently require broad access to data systems, deepen reliance on third-party vendors, and create new pathways through which sensitive data can leak, via prompts, model outputs, automated retrieval processes, and AI-driven actions. At the same time, regulatory expectations for data accuracy, completeness, timeliness, and traceability remain uncompromising, particularly for high-stakes use cases such as capital and liquidity management, regulatory and financial reporting, and financial crime detection. This paper proposes a practical, audit-ready approach to governing data risks in the AI era. The central idea is to add a second lens to traditional data classification, one focused on business consequence rather than confidentiality alone. Specifically, it introduces the concept of critical data elements (CDEs): data elements whose inaccuracy, unavailability, or misuse can produce material regulatory, financial, or customer-facing impact. Pairing CDE designation with conventional confidentiality classifications creates a dual-axis model that directs the strongest controls to the highest-consequence data, even when that data may not appear sensitive on the surface. Drawing on established regulatory frameworks including BCBS 239 (risk data aggregation and reporting), SR 26-2 (model risk management, the interagency guidance issued jointly by the Federal Reserve, Office of the Comptroller of the Currency (OCC), and Federal Deposit Insurance Corporation (FDIC) in April 2026, superseding SR 11-7), and US interagency third-party risk guidance, the paper explains why AI amplifies data risk across four dimensions (privacy, security, integrity, and accountability), and presents an eight-domain data governance framework with concrete audit evidence examples. The goal is to equip compliance, risk, and audit leaders with a repeatable structure for demonstrating that AI innovation rests on controlled, auditable data foundations. This article is also included in The Business & Management Collection which can be accessed at http://hstalks.com.business/.
Keywords: data governance; critical data elements (CDE); artificial intelligence (AI); model risk management; data lineage; third-party risk

Drifting apart: Adapting to a growing divide between EU, UK, and US sanctions
Maddalena Tovazzi, Head of Sanctions, AL Sydbank

Abstract ▼

Over the course of 2025, there has been an increasing divide between the objectives of sanction regimes imposed by the EU, the US, and the UK. All three are usually relevant for companies operating in international markets due to their relevance in global trade, the role of their respective currencies and their historical role in setting the narrative on matters of sanctions policies. The initially unified approach towards Russia has shifted, with the US willing to negotiate a peace deal (and even make major concessions to Putin’s wishes regarding Ukraine), while the EU and UK remain firm in their condemnation of the invasion. If a peace deal is achieved, it could have important implications for the current sanctions measures and drive the divergence even further. However, even within the EU, there are signs of discontent and a thinning alignment. More countries have, for instance, chosen to implement the legal basis for autonomous sanctions, an evolution that could potentially put the common regimes of the EU into question. Finally, the US is a firm supporter of Israel and its war against Hamas, which has resulted in controversial sanctions imposed against the International Criminal Court (ICC). Neither the EU nor the UK supports this approach and has spoken openly against it. But despite the increasing divergence on multiple matters, instances of convergence have also taken place in recent times. All major jurisdictions have suspended and lifted most sanctions against Syria in the wake of the fall of al-Assad’s regime and the historically divided stance on Iran has recently reached a more unified front with the snapback of United Nations sanctions and the subsequent reintroduction of previously suspended measures. It is also interesting to note how the EU, notoriously critical of the USA’s extraterritorial reach, appears to have recognised the potential of secondary sanctions and is beginning to implement them (albeit under the name ancillary sanctions). In an increasingly complex regulatory landscape, it is paramount for companies to take active steps to ensure compliance and the ability to quickly adapt to change. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords: sanctions; geopolitics; compliance; divergence; risk assessment; corporate governance

Back to Journal