Eight compliance rules reshaping financial services in 2026

Eight compliance rules reshaping financial services in 2026

Financial services remains one of the most tightly regulated sectors in the world, and the challenge for compliance teams goes well beyond the volume of rules.

Requirements shift constantly, deadlines overlap and the penalties for falling behind can include fines, reputational harm or the loss of a licence. Regulatory change management platform Vixio has outlined eight developments firms should be watching closely this year.

First is the EU’s Digital Operational Resilience Act (DORA), which has applied since January 2025 and sets rules on ICT risk management, incident reporting, resilience testing and oversight of critical third-party providers. Attention has now turned to national interpretation and enforcement. Norway’s regulator updated its incident reporting guidance in May 2026, while Austria’s first DORA fines show that supervisors will act on procedural failings as well as major incidents.

PSD3 and the Payment Services Regulation (PSR) are set to replace the PSD2/EMD2 framework, with final publication expected in Q2 or Q3 2026. The reforms aim to strengthen digital payments and level the field between banks and non-bank providers such as FinTech firms and EMIs. Because PSD3 must be transposed into national law while PSR applies directly, firms could face uneven timelines affecting licensing, reauthorisation and passporting.

The EU’s Anti-Money Laundering Regulation (AMLR), published in June 2024, will apply from July 10th, 2027, creating a single rulebook across member states. The new Frankfurt-based Anti-Money Laundering Authority (AMLA) is shaping how it works in practice, launching a consultation in July 2026 on a common format for suspicious activity reporting.

The Markets in Crypto-Assets Regulation (MiCA) reached a milestone when its transitional backstop deadline passed on July 1st, 2026, meaning covered firms must now comply in full. Crypto-asset service providers will also take on full AML/CTF obligations under the AMLR from July 2027.

In the UK, the FCA’s Consumer Duty is moving firmly into enforcement, with the regulator reporting 11 open investigations into potential breaches in July 2026. A May 2026 policy statement also proposed moving Consumer Credit Act requirements into FCA rules.

The FCA’s Supplementary Regime for safeguarding came into force on May 7th, 2026, introducing daily reconciliations, monthly returns, annual audits and resolution packs. It is seen as a step towards a CASS-style statutory trust model. FCA director Matthew Long said the regulator would be “watching closely”.

PS26/2, published in March 2026 by the FCA, PRA and Bank of England, creates a unified regime for operational incident and third-party reporting from March 18th, 2027. Finally, Basel 3.1 takes effect in the UK on January 1st, 2027, reshaping capital requirements, risk models and reporting for banks.

Vixio argues that tracking this landscape manually through spreadsheets and email is no longer sustainable, and that purpose-built RegTech combining automation with human expertise offers the most effective path forward.

Read the full Vixio post here. 

Read the daily RegTech news

Copyright © 2026 RegTech Analyst

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2026 RegTech Analyst

Investors

The following investor(s) were tagged in this article.