Financial crime regulatory developments: July 2026

July saw significant regulatory developments across virtual assets, DeFi, AML controls and APP scam reimbursement, with key updates highlighting evolving risks, regulatory expectations and industry performance.

Financial Action Task Force (FATF)

1. FATF highlights growing financial crime risks from virtual assets

Summary: FATF’s Virtual Assets: Targeted Update on Implementation of the FATF Standards highlights continued progress in the regulation and supervision of virtual assets and Virtual Asset Service Providers (VASPs), while identifying significant gaps in implementation.

More jurisdictions are conducting risk assessments and introducing licensing or registration requirements for VASPs; however, challenges remain in effectively assessing risk, identifying VASP activity and supervising offshore providers.

Progress has also been made in implementing the Travel Rule, which requires relevant information on the originator and beneficiary to accompany qualifying virtual asset transfers, with 83% of surveyed jurisdictions having implemented legislation. FATF further highlights challenges in regulating Decentralised Finance (DeFi) arrangements and the increasing use of stablecoins in illicit activity, including by the Democratic People's Republic of Korea (DPRK) and terrorist financiers.

Impact: The findings reinforce the need for firms to maintain a risk-based approach to virtual asset-related financial crime. Firms should review their financial crime risk assessments and controls to ensure they adequately address risks associated with VASPs, DeFi and stablecoins, through effective CDD/EDD, transaction monitoring, sanctions screening and Travel Rule controls.

Link: Seventh Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs

2. FATF highlights risks associated with DeFi

Summary: FATF published a targeted report on Decentralised Finance (DeFi), highlighting the growing money laundering, terrorist financing and proliferation financing risks associated with the sector. The report notes that features such as concealed user identities, permissionless access, smart contract automation and cross-border reach can be exploited by criminals to move and obscure illicit funds. FATF also highlights the challenges jurisdictions face in identifying and regulating DeFi arrangements, particularly where control or sufficient influence over a platform is difficult to determine. The report calls for a risk-based approach to implementing FATF standards and provides recommendations for regulators, DeFi arrangements, financial institutions and VASPs to strengthen controls and mitigate financial crime risks.

Impact: Firms should consider whether their risk assessments, CDD processes and transaction monitoring controls appropriately capture DeFi-related risks. This is particularly relevant where firms have customers or counterparties involved in crypto assets or decentralised platforms. Risk assessments and monitoring scenarios may need to evolve as criminals adopt increasingly complex and sophisticated methods of moving and layering funds.

Link: FATF – Targeted Report on Decentralised Finance⁠

Financial Conduct Authority (FCA)

3. FCA highlights good and poor practice in asset management financial crime controls

Summary: The FCA published findings from its engagement with 242 asset management and alternative firms, highlighting examples of good and poor practice in financial crime controls. The FCA identified that some firms, particularly those active in private markets, were exposed to heightened financial crime risks due to complex ownership structures which can cross jurisdictions, high-risk customers and international transactions. The FCA also found weaknesses in some firms' business-wide risk assessments, customer risk assessments, beneficial ownership verification processes and oversight of outsourced CDD activities.

Impact: The findings reinforce FCA expectations that firms maintain robust and risk-based financial crime frameworks. Firms should assess whether oversight of outsourced AML/CDD providers is effective and appropriately documented. The publication also serves as a useful benchmark for firms to evaluate their controls against examples of FCA-observed good and poor practice.

Key areas of focus linked to inherent risks include:

  • Complex ownership structures: firms should ensure due diligence measures are adequate to identify and verify Ultimate Beneficial Owners (UBOs).
  • Politically Exposed Persons (PEPs): Firms should be able to identify PEPs and apply enhanced due diligence where appropriate.
  • International transactions: Firms facilitating international transactions should assess and mitigate the associated money laundering and sanctions risks.

Link: Asset management and alternative firms’ financial crime controls: our findings | FCA

Payment Systems Regulator (PSR)

4. PSR publishes APP scams reimbursement dashboard for Q1 2026

Summary: The PSR published its latest APP scams reimbursement dashboard, covering the first 18 months of the mandatory reimbursement regime. The data indicates continued positive outcomes for consumers, with 88% (£316m) of losses from in-scope APP scams reimbursed since the policy was introduced. The PSR reported high reimbursement rates, timely claims handling and no evidence that consumers had become significantly less cautious because of the reimbursement requirements.

Impact: Payment firms should continue to ensure that reimbursement processes operate effectively and within required timeframes. Firms should monitor their performance against PSR benchmarks and use the findings to assess the effectiveness of their fraud prevention controls.

Link: APP scams reimbursement dashboard for Q1 2026 | Payment Systems Regulator

 

Get in touch for support with regulatory developments with our financial crime experts.

Contact us

Key contacts