The CUBE Read notes 3 shifts in financial services regulation

The CUBE Read notes 3 shifts in financial services regulation

Risk and compliance functions in financial services are being asked to do more than watch the regulatory horizon, according to CUBE’s latest fortnightly briefing, The CUBE Read.

Teams are now expected to extract obligations, map them back to source law, separate proposed rules from enacted ones and judge applicability, often before any final rule exists.

CUBE notes that the operating reality has not kept pace. Its Cost of Compliance Report 2025, drawn from a survey of more than 2,000 senior compliance and risk officers, found that at 74% of institutions, moving from identifying a regulatory change to full implementation takes over a year. CUBE attributes this not to a lack of effort but to an analytical workload that has outgrown teams’ capacity to absorb it.

The consequences of misjudging that interpretation are already playing out. In the US, SEC commissioner Hester Peirce warned this month that crypto vaults and onchain lending arrangements could fall under federal securities law depending on their structure, an applicability call firms must make well ahead of any final rule. In Hong Kong, the SFC fined an asset manager HK$6.8m for failing to identify and address red flags in a questionable fund arrangement, underscoring, as CUBE points out, that missing the interpretation is no defence in enforcement.

CUBE also flags a second, quieter shift: regulated and professional-services firms are setting internal AI governance standards stricter than current rules demand, including sign-off requirements before AI touches sensitive data. This is happening even as the formal timeline moves. The EU AI Act’s high-risk obligations for financial services are set to be pushed back to December 2027 under the provisional Digital Omnibus agreement, pending formal adoption. For risk and compliance teams, CUBE argues, AI governance is already a live workstream, and vendor tooling is being judged against these internal policies now, not against a future mandate.

The third pressure point CUBE identifies is volume. Firms with global or specialist mandates are contending with regulatory change that ignores fixed, jurisdiction-count coverage models, including informal local guidance, non-English source material and data-residency rules in smaller markets. Recent weeks illustrate the point: the US Treasury’s second sanctions-list modernisation action removed 84 names from the SDN list in one pass, the Wolfsberg Group extended its financial-crime framework to non-bank payment providers, and ESMA credited BaFin and CySEC with progress on cross-border investment-firm supervision while pushing for enforcement calibrated to firms’ scale.

For more, read the full report here.

Read the daily FinTech news

Copyright © 2026 FinTech Global

Enjoying the stories?

Subscribe to our daily FinTech newsletter and get the latest industry news & research

Investors

The following investor(s) were tagged in this article.