Financial services remains one of the world’s most tightly regulated sectors, and the challenge for compliance teams goes well beyond the volume of rules. Regulations shift constantly, deadlines collide, and falling behind can bring fines, reputational harm or even the loss of a licence.
RegTech firm Vixio, which runs a regulatory change management platform for financial services, has outlined eight developments firms should be watching this year.
First is the EU’s Digital Operational Resilience Act (DORA), which has applied since January 2025 and covers ICT risk management, incident reporting, resilience testing and oversight of critical third-party providers.
National interpretation is still evolving, with Norway updating its incident reporting guidance in May 2026, while Austria’s first DORA fines show regulators will punish procedural failings, not just major incidents.
PSD3 and the Payment Services Regulation (PSR) are set to replace the PSD2/EMD2 framework, with final publication expected in Q2/Q3 2026. While PSR will apply directly, PSD3 must be transposed into national law, which could create uneven timelines affecting licensing, reauthorisation and passporting.
The EU’s Anti-Money Laundering Regulation (AMLR) will apply from 10 July 2027, creating a single rulebook across member states. Firms should track the new Frankfurt-based Anti-Money Laundering Authority (AMLA), which in July 2026 opened a consultation on a common format for suspicious activity reporting.
Under the Markets in Crypto-Assets Regulation (MiCA), the transitional backstop expired on 1 July 2026, so covered firms must now comply in full. Crypto-asset service providers will also face full AML/CTF obligations under AMLR from July 2027.
In the UK, the FCA’s Consumer Duty is entering a tougher enforcement phase, with 11 open investigations reported in July 2026. A May 2026 policy statement also proposed moving Consumer Credit Act requirements into FCA rules.
The FCA’s safeguarding Supplementary Regime took effect on 7 May 2026, introducing daily reconciliations, monthly returns, annual audits and resolution packs for payment and e-money firms. Back in August 2025, FCA director Matthew Long said the regulator would be “watching closely”.
PS26/2, published in March 2026 by the FCA, PRA and Bank of England, creates a unified operational incident and third-party reporting regime from 18 March 2027. Finally, Basel 3.1 takes effect in the UK on 1 January 2027, reshaping capital requirements and introducing output floors on internal models.
Vixio argues that manual monitoring through spreadsheets and email cannot keep pace with multiple regulators, rising volumes and the difficulty of working out what actually applies. Generic AI tools risk hallucinations and outdated information, so the firm advocates purpose-built automation drawing on vetted sources, with human experts retaining judgement over interpretation and response.
Read the full Vixio post here.
Copyright © 2026 FinTech Global









