Insights & Library · Regulatory
Regulatory
Regulatory strategy, authorisations, supervisory expectations, licensing, regulatory change and readiness for scrutiny across regulated markets.
Regulatory collection
19 publications
DORA and Operational Resilience Top EU Regulatory Focus
A practitioner view of DORA as an enterprise-risk and governance issue, using 2026 incident data to challenge the idea that operational resilience is primarily a cyber or IT programme.
UK Crypto Authorisation Gateway Opens 30 September 2026: FCA Expectations
A readiness-focused review of the FCA crypto authorisation gateway, the application window and the evidence firms should already be able to produce around permissions, governance, controls and accountable ownership.
At What Point Does Professional Loyalty Stop Making Commercial Sense?
A practical look at regulated accountability, senior management responsibility and the point at which professional loyalty can conflict with personal and regulatory exposure.
UK Crypto Regulation Enters a More Serious Phase
A policy-focused reflection on the shift in UK digital-asset regulation from broad intent toward perimeter, authorisation, prudential consequence, governance, safeguarding and business-model scrutiny.
Part 4 of 4: Closing the GRC Loop, What Regulatory Readiness Looks Like in 2025 and Beyond
A framework for moving beyond policy ownership to living regulatory systems across technology, people, controls and evidence.
Part 3/4 From Regulation to Reality: Applied Governance, Risk, and Compliance in Practice
How to translate regulatory design into operational execution through procedures, workflows, accountability and culture.
Can a Compliance Officer/MLRO Be Too Good at Their Job?
A cautionary reflection on compliance independence, organisational culture and what happens when accountable control functions lack genuine authority, resources or access to decision-making.
Part 2: Advancing Governance, Compliance, and Operational Resilience in Swiss Fintech and Small Banking Institutions
A deeper look at FINMA, governance, compliance and operational-resilience expectations for Swiss fintech and smaller financial institutions, grounded in practical implementation experience.
Governance, IT Frameworks, and Compliance in Financial Services: A Young Professional Guide
An accessible guide to governance, compliance, operational resilience and the frameworks that connect them in financial services.
Jurisdiction Whitelisting & Regulatory Strategy: Navigating Global VASP Compliance
A practical account of combining country-risk scoring, sanctions, AML standards, licence permissions and commercial strategy when deciding where a digital-asset business can operate.
Truth Terminal: AI Meets Virtual Assets
A regulatory and financial-crime reflection on autonomous AI agents holding cryptoassets, asking who carries AML, tax and legal responsibility when an AI-controlled wallet accumulates value.
Shein Fined €150M for GDPR Consent Breaches
A regulatory update on consent, cookie placement and transparency failures, with a wider lesson on embedding compliance requirements into product and technology design.
Why every SMF16 and Head of Compliance needs a CMP
A practitioner argument for linking policies, procedures, registers, monitoring and reporting through a coherent Compliance Management Programme.
Danske Bank Estonia GRC Technical Annex (Case #1)
A GRC technical annex applying governance, risk, compliance and control analysis to the Danske Bank Estonia money-laundering case.
Market Risk, Financial Risk Part 2: Methods, Governance, FRTB and P&L Explain
A technical market-risk chapter covering common methods, governance, VaR, expected shortfall, FRTB and the role of P&L attribution and explanation.
Financial Risk Part 3: Liquidity Risk, Funding Resilience and IRRBB
The third financial-risk chapter, connecting liquidity, funding resilience and interest-rate risk in the banking book to governance and stress-testing expectations.
Compliance: Its Definition, Role, Purpose and Lifecycle
A foundation chapter treating compliance as an operating and management discipline, from obligations and control design through monitoring, reporting and improvement.
Regulatory Compliance vs Ethical Compliance
A practical distinction between meeting formal obligations and making defensible ethical decisions, with an evidence-led framework for difficult judgement calls.
Third Party Risk and Outsourcing Governance [UK / EEA]
A practical UK and EEA guide to the vendor lifecycle, due diligence, contracting, monitoring, evidence and exit planning across regulated outsourcing relationships.
