- Oct 05, 2026
- 16 min read
Compliance Digest – September 2026
Learn about all the latest compliance updates from the past month.
Every month, Sumsub's Compliance Team prepares a digest of the latest updates in AML and beyond, covering industries from payments to crypto and iGaming.
If you'd like to get the latest news in one place every month, subscribe to our newsletter.
AML
EU🇪🇺 AMLA Finalizes Three Core AML/CFT Standards for the Private Sector (CDD, Business Relationships, Group-Wide Controls)
What happened?
On October 1, 2026, the EU Anti-Money Laundering Authority (AMLA) finalized three sets of regulatory technical standards (RTS) outlining key measures companies and professionals must apply to reduce money laundering and terrorist financing risks. They cover three areas:
- Business relationships and occasional transactions (AMLR Art. 19(9)): How to tell the two apart and how to identify linked transactions, so that customer due diligence thresholds are applied consistently
- Customer due diligence (AMLR Art. 28(1)): The information to collect and verify, including proportionate measures for lower-risk situations, non-face-to-face verification, electronic identification, and screening of PEPs, their family members, and close associates
- Group-wide arrangements (AMLR Art. 16(4) and 17(3)): Minimum requirements for group-wide AML/CFT frameworks, covering governance, risk management, internal controls, and secure information sharing
National supervisors developed the standards and shaped them through feedback from written consultations and hearings. The final drafts have been submitted to the European Commission.
Who's affected?
The standards apply to obliged entities under the AMLR – that is, companies and professionals subject to AML/CFT requirements – as well as the supervisors overseeing them. This includes groups with subsidiaries and branches in third countries. The release singles out football agents and professional football clubs for a separate application date.
Deadline:
The standards are not yet in force. Once the Commission adopts them and they are published in the Official Journal of the EU, they are proposed to apply six months after entry into force. For football agents and professional football clubs, they will apply from July 10, 2029.
Read more:
- AMLA Press Release
- Final Report: Draft RTS on CDD, Art. 28(1)
- Final Report: Draft RTS on Business Relationships and Transactions, Art. 19(9)
- Final Report: Draft RTS on Group-Wide Requirements, Art. 16(4) and 17(3)
Suggested read: AML Odyssey: How Growing Businesses Find Their Way to Ithaca
Payments
Türkiye🇹🇷 Tightens Remote Customer Identification Rules for Payment and E-Money Institutions (September 2026 Amendments)
What happened?
The Central Bank of the Republic of Türkiye published two amending instruments on the same day:
- A regulation amending the Regulation on Payment Services and Electronic Money Issuance and Payment Service Providers (Official Gazette of December 1, 2021, No. 31676). In the second sentence of Article 41(4), the words "by biometric methods or with identity documents capable of electronic identity verification" were inserted after "by remote communication means to the customer." This specifies how remote identity verification must be carried out.
- A communiqué amending the Communiqué on Information Systems of Payment and Electronic Money Institutions and Data Sharing Services of Payment Service Providers in the Field of Payment Services (Official Gazette of December 1, 2021, No. 31676).
Together, the changes address identity documents, biometric data use, and remote identity verification.
Who's affected?
Payment institutions, electronic money institutions, and other payment service providers operating in Türkiye, particularly those that onboard or identify customers remotely. Their information systems and data-sharing services are also affected.
Deadline:
Both the regulation and the communiqué took effect upon publication on September 3, 2026. There is no transition period, so remote onboarding and verification processes should already be compliant.
Read more:
Suggested read: FATF Puts Türkiye Under Enhanced Follow-Up After AML Review
Crypto
EU🇪🇺 MiCA Review: EBA Calls for a Dedicated Regime for Multi-Issuer Stablecoins and a Fresh Look at Deposit-Based Reserve Requirements
What happened?
On September 24, 2026, the European Banking Authority (EBA) published its response to the European Commission's targeted consultation on the review of MiCA (Regulation (EU) 2023/1114), which the Commission launched on May 20, 2026. The EBA answers the questions within its remit across four areas: scope and definitions; requirements for asset-referenced tokens (ARTs), e-money tokens (EMTs), and their issuers; the crypto-asset service provider (CASP) framework; and policy areas outside MiCA's current scope. Its key points are:
- Third-country multi-issuance schemes: The EBA wants a dedicated regulatory and supervisory regime for these schemes, if they are to be permitted at all. Proposed measures include a new "significance" criterion for participation in such a scheme, an equivalence regime as a baseline for market access, aligned redemption terms, and stronger backstop powers for EU authorities.
- Reserve requirements: Issuers that are e-money institutions must currently hold 30% of reserves as bank deposits, or 60% for significant EMTs. The EBA asks the Commission to carry out a cost-benefit analysis of whether these minimums could be lowered, while cautioning that any reduction would depend on the non-deposit reserve assets being high-quality and liquid.
- Group supervision and cooperation: The EBA calls for stronger oversight of non-bank groups that combine crypto-asset and other financial services. Suggested tools include group-level reporting, supervisory colleges, consolidated supervision, and possibly EU intermediate parent undertakings.
- Interplay with PSD3/PSR: The EBA welcomes the clarifications made during the PSD3/PSR negotiations but flags two concerns: possible regulatory asymmetries between payment institutions and CASPs, and gaps in the safekeeping and safeguarding of client funds.
Other points:
- Harmonized EU definitions of "financial instrument" and "deposit"
- A clear maximum redemption timeframe
- Continued prohibition of interest on ARTs and EMTs
- A definition of "EU holder"
- A comprehensive reporting mandate covering issuers and CASPs
- A cost-benefit analysis on regulating crypto lending and borrowing, including access to DeFi
Who's affected?
- Issuers of EMTs and ARTs, both e-money institutions and credit institutions, especially those participating in third-country multi-issuer stablecoin schemes
- CASPs and payment institutions dealing in EMTs
- Mixed-activity financial groups
- Banks holding stablecoin reserve deposits or exploring tokenized deposits
- National competent authorities
Deadline:
None for firms. This is a consultation response, not a binding measure, and it creates no new obligations. Any changes would depend on a future Commission legislative proposal to amend MiCA.
Read more:
EBA Response to the EC Targeted Consultation on the MiCA Review (PDF)
Suggested challenge: Cryptocurrency Crossword: 15 Terms to Start, No Hints to Finish
Thailand's🇹🇭 SEC Issues Travel Rule for Digital Asset Operators, Effective February 27, 2027
What happened?
On September 2, 2026, Thailand's Securities and Exchange Commission (SEC) announced its Travel Rule requirements for digital assets. They are set out in Notification No. SorThor. 9/2569 of August 25, 2026, on managing risks related to the transfer and receipt of digital assets. The SEC developed the rules together with the Anti-Money Laundering Office (AMLO), which is preparing its own rules under AML law. The SEC consulted on the principles in March–April 2026 and on the draft notification in June–July 2026. Under the new rules, digital asset operators must:
- Put in place policies and procedures for managing the risks of sending and receiving digital assets
- Collect information on customers and their counterparties for each transfer, and screen counterparties
- Perform due diligence on counterparty VASPs and on any intermediary digital asset operators in the transfer chain
- Verify ownership or control of self-hosted wallets when transferring to or receiving from them
- As the ordering operator, send originator and beneficiary information with the transfer instruction to the beneficiary operator
- Retain transfer information for every transaction for at least five years, in a form that regulators can access or inspect immediately
According to the SEC, the rules bring Thailand in line with FATF standards and aim to prevent digital asset businesses from being used for money laundering, terrorist financing, and technology-related crime.
Who's affected?
Digital asset operators licensed by the Thai SEC, such as exchanges, brokers, dealers, and custodial wallet providers. Foreign VASPs that transact with Thai operators will also be affected indirectly, since they will need to exchange Travel Rule data with them.
Deadline:
February 27, 2027. The lead time is intended to give operators time to build systems to send and receive data and check transactions.
Read more:
Indonesia's🇮🇩 Law No. 4/2026 Formally Brings Crypto and Digital Asset Firms into the Financial Services Institution Framework
What happened?
Indonesia has amended its Financial Services Omnibus Law (P2SK Law, Law No. 4/2023) through Law No. 4/2026, which took effect on June 17, 2026. The amendment creates a new category, Digital Financial Asset Financial Institutions (LJK AKD), divided into two groups:
- Crypto Asset Financial Services Institutions (LJK Aset Kripto)
- Financial Services Institutions for Digital Financial Assets Other Than Crypto Assets (LJK AKD selain Aset Kripto)
Until now, digital asset players were not formally classified as financial services institutions (Lembaga Jasa Keuangan, or LJK). They were nonetheless subject to key sector requirements, including licensing, fit-and-proper assessments, AML controls, consumer protection, and anti-fraud measures.
Other key changes:
- Who counts as a crypto asset institution: Crypto asset traders, exchanges, clearing, guarantee, and settlement institutions, centralized custodians, and other parties designated by the OJK. Each must be licensed by the OJK.
- Expanded activity scope: The law expressly covers tokenization, initial offerings, stablecoins used for transactions, staking, crypto lending and pledging, and spot and derivative crypto activities. Crypto assets are still not recognized as payment instruments.
- Market structure: The law sets minimum requirements for establishing and owning crypto asset exchanges. Crypto transactions, including those involving crypto digital wallets, must be conducted through or reported to the relevant exchange.
- OJK powers: The OJK can conduct fit-and-proper assessments of key parties. It can also freeze or block non-compliant crypto transactions or trading in Indonesia by both domestic and foreign parties.
Who's affected?
- Crypto asset traders, exchanges, clearing and settlement institutions, and custodians licensed in Indonesia
- Other digital financial asset businesses, such as tokenization platforms
- Foreign platforms serving Indonesian users, which face blocking if they operate without an OJK license
Deadline:
The law has been in force since June 17, 2026. Implementing OJK regulations are expected to set out detailed requirements and any transition periods. The OJK has also announced a 2026–2031 roadmap for digital finance and crypto oversight.
Read more:
Anti-Fraud
Bank of Thailand🇹🇭 Issues Minimum Digital Fraud Management Guidelines for Banks and E-Payment Providers
What happened?
On September 14, 2026, the Bank of Thailand (BoT) issued Circular No. BOT.W.5713/2569, which sets out minimum guidelines on digital fraud management. It follows the BoT's recent framework on preventing illicit transactions in the financial sector. The aim is to establish a clear, uniform standard for how institutions prevent, detect, and respond to digital fraud. The guidelines cover practices institutions should already have in place as well as measures still to be implemented. Under the guidelines, institutions must:
- Assess fraud risk on an ongoing basis, including the risk that customers are used as mule accounts or become fraud victims
- Monitor transactions for unusual or suspicious activity, and strengthen detection in line with their risk profile, including through AI/ML where necessary and appropriate
- Classify transactions, accounts, and customers by risk
- Detect and classify mule accounts using transaction behavior, internal data, and reliable external information
- Apply risk-based measures, such as transaction limits, closer monitoring, transaction restrictions, and additional verification or EDD
- Take stronger action in higher-risk mule cases, including restricting transactions and, in certain cases, refusing to open new accounts until further checks are completed
- Regularly review the accuracy and effectiveness of fraud detection processes
- Maintain appropriate governance, including measurable fraud management indicators, audits, and management oversight
Who's affected?
- Commercial banks registered in Thailand
- Non-bank electronic payment service providers regulated by the BoT, including e-money and electronic transfer providers
Deadline:
The BoT summary gives no effective date. The circular states that some requirements reflect what institutions should already be doing, while others must be completed going forward. Institutions should check the attached guideline document for any phased implementation timelines.
Read more:
Bank of Thailand: Circular BOT.W.5713/2569 on Minimum Digital Fraud Management Guidelines (Thai)
Hong Kong's🇭🇰 HKMA Updates Remote Onboarding Expectations to Address Deepfakes and AI-Enabled Fraud
What happened?
On September 3, 2026, the Hong Kong Monetary Authority (HKMA) issued an updated circular on the remote onboarding of individual customers. It replaces two earlier circulars: "Remote On-boarding of Individual Customers" (February 1, 2019) and "Remote On-boarding and iAM Smart" (May 24, 2021). Two other circulars remain in effect and should be read alongside it: one on the remote onboarding of corporate customers (September 24, 2020) and one providing feedback from thematic reviews of AML/CFT controls for remote onboarding (June 3, 2020).
The two core principles remain unchanged:
- Identity authentication: Institutions must ensure that documents, data, or information obtained electronically are reliable, including by using technology to confirm that identity documents are genuine.
- Identity matching: Institutions must use appropriate technology to link the customer incontrovertibly to the verified identity.
The main change is a stronger focus on AI-driven automation, deepfakes, impersonation, online fraud, and mule-account networks. The HKMA now expects the following:
- Continuous updates: Remote onboarding solutions should be subject to an ongoing program of updates and recalibration so they remain effective against evolving fraud techniques. Institutions should draw on the scam intelligence shared by the HKMA and the Hong Kong Police Force for this purpose.
- Risk-based product design: Products and services should be designed in proportion to the customer's assessed risk. For example, a tiered approach can scale account features, functionality, and transaction limits based on actual usage and behavior, supported by senior management oversight.
- Comprehensive review: Institutions should review their remote onboarding solutions, systems, and oversight in light of the latest fraud and scam intelligence.
Suggested read: How to Stay Ahead of Deepfake Evolution in 2026
Who's affected?
Authorized Institutions (banks) and Stored Value Facility (SVF) licensees in Hong Kong that onboard individual customers remotely.
Deadline:
The circular applies from its issue date of September 3, 2026. It sets no specific deadline for the comprehensive review, but institutions should complete it promptly and keep their solutions under ongoing recalibration.
Read more:
HKMA Circular: Remote On-boarding of Individual Customers (September 3, 2026, PDF)
iGaming
Brazil🇧🇷 Bans Sports Betting and Online Casinos by Provisional Measure, with Licenses Revoked and Sites Offline as of October 6
What happened?
On September 25, 2026, President Lula da Silva signed Provisional Measure No. 1,394 in São Paulo. It bans the operation, offering, intermediation, and advertising of fixed-odds betting across Brazil, both in person and online. Here's how it works:
- Legal status: The measure took effect upon publication but still has to be reviewed by Congress. As a provisional measure, it applies immediately while it moves through the legislative process within the constitutional deadline. If Congress does not convert it into law within 120 days, it lapses. That clock pauses during the congressional recess.
- Scope: The ban covers sports betting and online games, including offshore operators. Traditional lotteries, including those run by Caixa, are excluded. It also extends to concessions, permissions, and authorizations issued by states and the Federal District.
- Wider context: The measure revokes much of the regulatory framework established by Law No. 14,790, which Lula signed at the end of 2023. It was signed just nine days before the first round of the presidential election, prompting some analysts to criticize it as electorally motivated.
Enforcement:
Banks and payment systems, including Pix, may not process transactions to operators, and app stores and operating system providers must block operators' apps. Social networks and other internet services that advertise betting can be fined up to 10% of their in-country revenue, capped at about $9.7 million per violation. The measure also establishes an inter-institutional committee, coordinated by the Presidency's Chief of Staff Office (Casa Civil), to oversee enforcement against illegal betting and advertising. In addition, a separate bill proposes criminal penalties: four to six years in prison for organizing betting, and two to four years for promoting it, processing its payments, or using personal data to advertise it.
Industry reaction:
The ANJL and IBJR associations have petitioned the Supreme Court (STF) to suspend the measure, citing irreversible losses. The industry says more than 30 million players are moving to the illegal market, and IBJR estimates the budget risk at about $11.2–14.1 billion.
Who's affected?
- Licensed and offshore operators of fixed-odds betting and online casinos. JPMorgan names Evolution, Allwyn, Entain, and Flutter as the most exposed listed companies
- Banks, payment institutions, and Pix participants, which must block payments and process player refunds
- App stores, operating system providers, social networks, and other internet services
- Media and sports: TV broadcasters and the 13 of 20 Série A clubs with an operator as their title sponsor
- Players with balances held on betting platforms
Deadline:
- September 25, 2026: Ban in force; deposits halted and new licenses no longer issued
- October 5, 2026, 11:59 pm: Players' last chance to withdraw their balances themselves
- October 6, 2026: Websites and apps must be inaccessible to users in Brazil.
- Around October 5, 2026: Advertising and sponsor logos, including those on club kits, must be removed (10 days after publication)
- October 7–8, 2026: Operators must send banks client lists by CPF with the amounts to be refunded
- October 9–14, 2026: Banks must return the funds. Unclaimed amounts go to an account at Caixa. Operators that miss their refund obligations face a fine of about $38,600 per day
- Around October 25, 2026: Licenses expire, with no refund of the roughly $5.8 million fee and no compensation (30 days after publication)
- Within 120 days, plus any recess: Congress must convert the measure into law, or it lapses
Read more:
- Metrópoles: Fim das Bets, Lula Assina MP e Caso Vai ao Congresso (Portuguese)
- Exame: O Que Muda com a Proibição das Bets no Brasil (Portuguese)
- Diário Carioca: ANJL and IBJR Challenge the MP at the STF (Portuguese)
New Zealand🇳🇿 Opens Auction for Up to 15 Online Casino Licenses, with Unlicensed Operators to Exit by December 1, 2026
What happened?
On Tuesday, September 29, 2026, New Zealand's Department of Internal Affairs (DIA) launched its auction for up to 15 online casino licenses under the Online Casino Gambling Act 2026. It is an ascending clock auction with an unpublished reserve price, and every winner pays the same clearing price. The process works as follows:
- Right to apply only: Winning the auction grants only the right to apply for a license. Winners must pay the clearing price and submit full applications starting in October. Reports indicate applicants must complete the requirements by October 23, 2026. Applicants must submit five documents, including a harm prevention plan and a compliance plan.
- Ownership cap: Each platform or brand needs its own license, and no operator may control more than three.
- Costs: Each expression of interest costs NZ$ 19,000 (US$ 11,000). Licensees will then pay:
- a 16% online gambling duty, with 4 percentage points earmarked for community funding
- a 3.5% regulatory levy
- the problem gambling levy
- GST
- Technical requirements: The DIA has published a discussion draft of its testing and monitoring requirements, which builds on the minimum standards in force since July 8. At launch, the DIA will accept game and RNG certification to UK Gambling Commission or Ontario standards. Licensees must obtain independent game and platform certification within six months of receiving a license, and at least annually thereafter. GLI Australia, Quality Assurance Laboratories, and BMM Australia are the approved testing labs.
Who's affected?
- Online casino operators currently serving New Zealand customers, including offshore operators
- Operators seeking to enter the regulated market; Entain and Tabcorp are among those reported to be interested
- Game and RNG suppliers, and testing labs
Deadline:
- September 29, 2026: Auction launched
- October 2026: Winners file full license applications. Reports point to an October 23 deadline
- December 1, 2026: Operators that have not applied must stop serving New Zealand customers. Applicants may continue operating, without advertising, until their application is decided or until June 1, 2027
- By June 1, 2027: The DIA expects to have decided on every license
Read more:
Relevant articles
What is Sumsub anyway?
Not everyone loves compliance—but we do. Sumsub helps businesses verify users, prevent fraud, and meet regulatory requirements anywhere in the world, without compromises. From neobanks to mobility apps, we make sure honest users get in, and bad actors stay out.




