• Aug 02, 2026
  • 12 min read

Compliance Digest—July 2026

Learn about all the latest compliance updates from the past month.

Every month, Sumsub’s Compliance Team prepares a digest with all the latest updates in the world of AML and beyond. We cover multiple industries, from AML to gambling.

If you want to get the latest news every month in one place, subscribe to our newsletter.

AML 

EU's🇪🇺 AMLA Launches Consultation on Draft RTS for Assessing ML/TF Risk Profiles of Non-Financial Obliged Entities

What happened?

The EU Anti-Money Laundering Authority (AMLA) has opened a public consultation on draft Regulatory Technical Standards (RTS) under Article 40(2) of Directive (EU) 2024/1640. The draft RTS proposes a harmonized methodology for supervisors to assess and classify the inherent and residual money laundering and terrorist financing (ML/TF) risk profiles of non-financial obliged entities across the EU. The consultation also seeks feedback on sector-specific data points, proportionality for small entities, operational feasibility, and implementation costs. 

Who's affected?

  • Non-financial obliged entities (e.g. law firms, accountants, notaries, trust and company service providers, real estate professionals, casinos and other designated non-financial businesses and professions)
  • National AML/CFT supervisory authorities
  • Financial Intelligence Units (FIUs)
  • Self-regulatory bodies
  • Industry associations and other stakeholders involved in the EU AML/CFT framework. 

Impact:

The draft RTS introduces a common EU methodology for the risk-based supervision of non-financial obliged entities. If adopted, it may require firms to provide additional supervisory data and strengthen their internal ML/TF risk management processes. The framework is intended to improve the consistency and proportionality of supervisory assessments across Member States while reducing regulatory fragmentation. Stakeholder feedback submitted during the consultation may shape the final RTS before its adoption.

Deadline:

September 27, 2026 (23:59 CEST) for submitting consultation responses.

Read more:

Consultation on the draft RTS on the assessment of the inherent and residual risk profile of obliged entities in the non-financial sector

Spanish🇪🇸 Council of Ministers Approves Draft AML Reform to Establish National Authority for Financial Integrity (ANIFI)

What happened?

On July 28, 2026, the Spanish Council of Ministers approved a draft bill to comprehensively reform Spain's AML/CTF, and counter-proliferation financing framework. The proposal aligns Spanish legislation with the EU's 2024 AML package and the latest Financial Action Task Force (FATF) standards, and also introduces a new institutional structure for AML/CFT supervision.

Who's affected?

  • Financial institutions
  • Gambling operators
  • Other AML/CFT obliged entities
  • Supervisory authorities and public sector bodies
  • Financial Intelligence Unit (SEPBLAC)
  • Organizations subject to international financial sanctions requirements

Impact:

The draft legislation would establish an independent National Authority for Financial Integrity, consolidating responsibilities currently shared between SEPBLAC and the Commission for the Prevention of Money Laundering. The new authority would combine financial intelligence, supervision, inspections, enforcement, sanctions, and international financial sanctions functions, while also assuming responsibility for preventing the financing of the proliferation of weapons of mass destruction. It would be funded through a levy on administratively licensed obliged entities—primarily financial institutions and gambling operators—as well as a limited share of the fines it imposes. The reform aims to strengthen Spain's AML/CFT framework and align it with the EU's new AML regime and international FATF standards.

Deadline:

The draft bill will now proceed through public consultation and further legislative review. No consultation deadline has been announced.

Read more:

REFORMA INTEGRAL DEL MARCO DE PREVENCIÓN DEL BLANQUEO DE CAPITALES Y LA FINANCIACIÓN DEL TERRORISMO

Digital Wallets

🇪🇺European Commission Updates eIDAS 2.0 Implementing Rules for the EUDI Wallet Framework

What happened?

On July 22, 2026, the European Commission published three new Implementing Regulations—(EU) 2026/1730, (EU) 2026/1731 and (EU) 2026/1735—updating the technical standards and specifications underpinning the European Digital Identity (EUDI) Wallet framework. The amendments introduce enhanced user protections, revised relying party registration requirements, stronger wallet trust mechanisms, and updated rules for verifying electronic attestations.

Suggested read: The eIDAS 2.0 Power Grab: Who Controls Digital Identity in Europe

Who's affected?

  • EUDI Wallet providers
  • Relying parties using EUDI Wallets
  • Identity and attestation issuers
  • Trust service providers
  • Supervisory authorities
  • Organizations planning to integrate EUDI Wallets into digital services

Impact:

The updated implementing rules strengthen user control through new requirements for explicit confirmation of every portrait disclosure request. They also require wallets to warn users when relying parties request more data than they are authorized to collect. They also improve the trust framework as they introduce a mandatory EU Digital Identity Wallet Trust Mark and link the validity of the Person Identification Data (PID) to the integrity of the wallet, so that revocation of a wallet attestation automatically invalidates the associated PID.

In addition, the rules streamline relying party onboarding. They require registration certificates to be issued automatically and without undue delay, introduce updated wallet-specific certificate standards, and support intermediary structures. Finally, they improve attestation verification. Verification responses may now indicate either a "match" or a "match with variation," and the rules introduce privacy-preserving revocation mechanisms alongside stricter certification requirements to strengthen the overall trust ecosystem.

Deadline:

  • January 1, 2027: Privacy-preserving revocation requirements for electronic attestations become applicable.
  • August 11, 2028: Portrait data becomes mandatory within the Person Identification Data (PID) dataset.

Read more:

New round of EU Digital Identity Wallet implementing regulations adopted

Payments

UK🇬🇧 HM Treasury Consults on Modernizing Payment Services Regulation

What happened?

HM Treasury has launched a public consultation on proposals to modernize the UK's payment services regulatory framework. The consultation seeks views on how regulation should evolve to accommodate emerging payment technologies, including tokenized payments, Open Banking, and agentic payments. It also explores how the regulatory framework can preserve strong consumer protection and support innovation and competition in the payments sector.

Who's affected?

  • Payment service providers (PSPs)
  • Electronic money institutions (EMIs)
  • Fintech firms
  • Banks and payment infrastructure providers
  • Open Banking participants
  • Businesses developing tokenized or AI-enabled payment solutions
  • Consumer groups and other payments ecosystem stakeholders 

Impact:

The consultation could lead to significant reforms of the UK's payment services framework, including updates to the Payment Services Regulations and the Electronic Money Regulations. The proposed changes are intended to create a more innovation-friendly regulatory environment for emerging payment technologies while preserving robust consumer protections. Stakeholder feedback will inform future legislation and regulatory reforms, helping shape the UK's long-term payments strategy.

Deadline:

October 6, 2026 for submitting consultation responses to HM Treasury. 

Read more:

Modernising Payment Services Regulation

Bank of Thailand🇹🇭 Consults on Enhanced Security Requirements for Digital Financial Services

What happened?

The Bank of Thailand (BOT) launched a public consultation on the "Principles for Maintaining the Security of Financial Services Provided through Digital Channels." The proposal introduces enhanced security requirements for financial services delivered through mobile applications and internet banking, with the aim of strengthening fraud prevention, customer authentication, and mobile application security.

Who's affected?

  • Financial institutions
  • Specialized financial institutions
  • E-money providers
  • Credit card and loan providers offering account transfers or cardless cash withdrawal services
  • Customers using digital banking and payment services

Impact:

The proposed requirements would strengthen security across digital financial services by introducing enhanced identity verification during service registration and device changes, including out-of-band notifications and risk-mitigation measures such as cooling-off periods and transaction limits. They would also make independent two-factor authentication mandatory for fund transfers, cardless cash withdrawals, and transaction-limit increases. To reduce fraud, SMS one-time passwords (OTPs) would be phased out for transaction authentication in favor of more secure methods, including device binding, hardware or software tokens, and biometric authentication with anti-spoofing capabilities. In addition, providers would be prohibited from sending SMS messages or emails containing links to help combat phishing and would be required to implement processes for detecting and addressing fraudulent applications and websites impersonating their services. Mobile banking applications would also need stronger protections against tampering and remote control, with facial recognition and biometric anti-spoofing required for high-value transfers exceeding THB 50,000 per transaction or THB 200,000 per day.

Deadline:

August 24, 2026, for submitting comments to the Bank of Thailand.

Read more:

Singapore's🇸🇬 MAS Issues AML/CFT Supervisory Expectations for Digital Payment Token Service Providers

What happened?

On July 13, 2026, the Monetary Authority of Singapore (MAS) published an Information Paper on AML/CFT Supervisory Expectations for Digital Payment Token Service Providers (DPTSPs). The paper outlines supervisory expectations for the use of compliance technology, Travel Rule solutions, blockchain analytics, screening tools and outsourced AML/CFT service providers. A central message is that outsourcing compliance functions or using third-party vendors does not transfer regulatory responsibility—DPTSPs remain accountable for understanding, assessing and overseeing all AML/CFT controls.

Who's affected?

  • DPTSPs
  • Crypto exchanges and virtual asset service providers operating in Singapore
  • AML/CFT technology vendors
  • Travel Rule solution providers
  • Blockchain analytics and sanctions screening providers
  • Outsourced AML/CFT service providers

Impact:

The guidance sets out MAS's supervisory expectations for Digital Payment Token Service Providers (DPTSPs) across key areas of AML/CFT compliance. Firms are expected to conduct robust due diligence and ongoing oversight of outsourced AML/CFT providers, including governance reviews, performance monitoring, audit assessments, and periodic reassessments. 

The guidance also establishes six evaluation criteria for selecting Travel Rule solutions, covering network coverage, interoperability, counterparty due diligence, virtual asset service provider (VASP) identification, data transmission capabilities, and information security. It also requires firms to implement compensating controls where such solutions do not provide full coverage. Transfers involving unhosted wallets and wallets hosted by unregulated VASPs should be treated as inherently higher risk and, where appropriate, be subject to enhanced verification measures, such as proof of wallet ownership. In addition, blockchain analytics and screening tools are expected to support—rather than replace—firms' risk assessments. 

Suggested read: Custodial vs Non-Custodial Wallets: Key Differences, Security, and Control Compared

DPTSPs should calibrate vendor solutions to their own risk appetite, integrate crypto and fiat transaction monitoring, understand the underlying screening data sources, and avoid relying solely on vendor-generated outputs for compliance decisions. Overall, the guidance signals increased regulatory scrutiny of vendor governance and is likely to drive more detailed due diligence, stronger contractual requirements, and higher assurance expectations for AML/CFT technology providers.

Deadline:

This is an Information Paper setting out supervisory expectations and does not include a consultation or response deadline.

Read more:

AML/CFT Supervisory Expectations for Digital Payment Token Service Providers

Crypto 

FATF🌏 Publishes Targeted Report on Regulatory Challenges in Decentralized Finance (DeFi)

What happened?

In July 2026, the Financial Action Task Force (FATF) published a ‘Targeted Report on Regulatory Challenges from Decentralised Finance (DeFi)’, updating its 2021 DeFi guidance to reflect the sector's rapid growth and evolving risks. The report clarifies how the FATF Standards apply to DeFi arrangements, identifies implementation gaps across jurisdictions, and provides recommendations for regulators, DeFi participants, and VASPs to strengthen AML/CFT oversight.

Who's affected?

  • National AML/CFT regulators and supervisory authorities
  • VASPs
  • DeFi protocol developers, operators and governance participants
  • Financial institutions interacting with DeFi
  • Stablecoin issuers
  • Law enforcement and Financial Intelligence Units (FIUs)

Impact:

The report clarifies that DeFi arrangements fall within the scope of the FATF Standards where a natural or legal person exercises "control or sufficient influence," while truly decentralized protocols remain outside their scope. It also highlights significant implementation gaps, noting that relatively few jurisdictions have assessed DeFi-related risks or established dedicated supervisory frameworks despite the sector's continued growth. To support more effective oversight, FATF provides practical indicators for identifying hidden control over DeFi protocols, including governance structures, administrative privileges, and off-chain operational activities. The report further recommends strengthening AML/CFT controls for centralized DeFi arrangements, enhancing international cooperation and risk assessments, and adopting more effective measures to combat illicit finance involving DeFi, including the use of stablecoin issuer controls and regulated VASP off-ramps to facilitate asset recovery.

Deadline:

N/A

Read more:

Targeted Report on Regulatory Challenges from Decentralised Finance

Gambling

Mozambique🇲🇿 Approves Draft Regulation for Online Games of Chance

What happened?

In July, the Mozambican Council of Ministers approved a new ‘Regulation on the Operation and Practice of Games of Chance via Electronic or Computerised Media’. The regulation establishes Mozambique's first dedicated legal framework for online gambling, recognizing it as a distinct activity from traditional land-based casinos and introducing a specific licensing regime for operators offering games of chance through digital platforms.

Who's affected?

  • Online gambling operators
  • Existing casino license holders
  • Prospective online gaming licence applicants
  • Gambling regulators and supervisory authorities
  • Technology and platform providers supporting online gaming services

Impact:

The draft regulation establishes a dedicated legal framework for the operation of online games of chance conducted through electronic platforms and other remote digital channels. It introduces a separate licensing regime for online gambling operators, distinguishing online licenses from those issued to land-based casinos. The reform is designed to support the regulation and supervision of Mozambique's growing online gambling market while modernizing the country's broader gambling framework. It also aims to strengthen oversight of digital gambling activities and help address declining tax revenues from the traditional casino sector.

Deadline:

The regulation has been approved by the Council of Ministers. Further implementation measures, including licensing procedures and entry into force, will follow under the new regulatory framework.

Read more:

Government Seeks to Strengthen Responsible Gaming With New Online Betting Regulations

Gibraltar🇬🇮 Introduces World's First Regulatory Framework for Prediction Markets

What happened?

On July 13, 2026, Gibraltar published the ‘Prediction Market Regulations 2026’, establishing what is considered the world's first dedicated regulatory regime for prediction markets. The regulations create a legal framework governing platforms that facilitate the creation, trading and settlement of prediction market contracts, while expressly distinguishing prediction market activity from traditional betting, gaming and lottery activities.

Suggested read: What Are Prediction Markets and How Do They Work in 2026?

Who's affected?

  • Prediction market operators
  • Fintech and digital asset platforms offering prediction markets
  • Technology providers supporting prediction market infrastructure
  • Investors and participants in prediction markets
  • Firms seeking to establish prediction market businesses in Gibraltar

Impact:

The new framework introduces a dedicated licensing regime for prediction market operators, providing greater legal certainty for this emerging sector. It defines prediction market contracts as instruments whose value depends on the occurrence or non-occurrence of an event or on changes in an associated index, measure, statistic, or outcome. The framework also establishes prediction markets as a distinct regulatory category by clarifying that their activities are not to be treated as betting, gaming, or lotteries solely because of their characteristics. 

To operate in Gibraltar, providers will be required to obtain authorization from the Minister for Justice, Trade and Industry and maintain a sufficient substantive presence within the jurisdiction.

Deadline:

None. The Prediction Market Regulations 2026 have been published and establish the regulatory framework for authorization of prediction market operators.

Read more:

Prediction Market Regulation