- Aug 31, 2026
- 17 min read
Compliance Digest—August 2026
Learn about all the latest compliance updates from the past month.
Every month, Sumsub’s Compliance Team prepares a digest with all the latest updates in the world of AML and beyond. We cover multiple industries, from AML to crypto.
If you want to get the latest news every month in one place, subscribe to our newsletter.
AML
EBA🇪🇺 Publishes Draft Framework for AMLA's 2027 Direct-Supervision Eligibility Assessment
What happened?
On August 4, 2026, the European Banking Authority (EBA) published a public working draft of the data model and taxonomy for the 2027 data collection used to determine eligibility for direct supervision by AMLA. The draft forms part of EBA Reporting Framework Release 4.4.
Who’s affected?
The framework is relevant to obliged entities identified as provisionally eligible in the 2026 selection exercise, as well as national competent authorities involved in collecting and reporting the relevant data.
Business effect
Provisionally eligible firms should prepare for a further data collection in early 2027. This exercise will verify whether they continue to meet AMLA's eligibility criteria as of December 31, 2026, and will inform the process for determining which institutions fall under AMLA's direct supervision. The draft should be considered alongside AMLA's existing 2026 eligibility templates and instructions.
Deadline
The deadline to provide feedback on the draft was August 24, 2026. The underlying eligibility data will be collected in early 2027, using December 31, 2026 as the reference date.
Read more
EBA publishes draft reporting framework for the 2027 eligibility data collection
Payments
AMLA🇪🇺 Launches Survey on Central Contact Points to Inform Future AML/CFT Standards
What happened?
On August 6, 2026, the Anti-Money Laundering Authority launched a survey seeking practical feedback on the existing Central Contact Point (CCP) framework under Article 45(9) AMLD and Delegated Regulation (EU) 2018/1108. The exercise will inform AMLA’s preparation of an upcoming Regulatory Technical Standard (RTS) under Article 41(2) AMLD.
Who’s affected?
The survey is aimed at Electronic Money Institutions (EMIs) and Payment Service Providers (PSPs) with experience of the existing CCP framework. AMLA is conducting separate surveys of national competent authorities. Crypto-asset service providers (CASPs) are excluded from this exercise because the previous CCP framework did not apply to them.
Business effect
EMIs and PSPs have an opportunity to influence the development of AMLA’s future CCP requirements by providing evidence on how current arrangements operate, their effectiveness and any operational challenges. The findings may shape future regulatory expectations and compliance arrangements for firms operating cross-border through agents or distributors in the EU. AMLA plans to publish a report summarizing the main findings after the survey.
Deadline
The survey is open until September 15, 2026.
Read more
AMLA launches survey on Central Contact Points
Germany’s🇩🇪 BaFin Clarifies Supervisory Expectations for Virtual IBANs
What happened?
On July 27, 2026, Germany’s financial regulator BaFin published Supervisory Communication 06/2026 addressing money laundering and terrorist financing risks associated with virtual IBANs (vIBANs), particularly their potential use in underground banking. BaFin does not prohibit vIBANs or introduce new legal obligations. Instead, it clarifies how existing AML/CFT requirements should be applied to these structures.
Who’s affected?
The guidance is particularly relevant to banks, payment institutions/payment service providers (PSPs), electronic-money institutions (EMIs), Banking-as-a-Service providers and other firms involved in vIBAN, master-account or cross-border payment structures.
Business effect
Affected firms should review their vIBAN arrangements to maintain sufficient transparency around end customers, beneficial owners, and the origin and destination of funds. BaFin expects firms to understand the complete payment structure and apply appropriate customer due diligence, risk assessment, transaction monitoring and information-sharing controls. Complex or cross-border arrangements in which the institution can’t adequately identify the parties to transactions are particularly exposed to supervisory scrutiny.
Deadline
The supervisory communication applies immediately and will remain in force until July 10, 2027, when the EU Anti-Money Laundering Regulation (AMLR) is due to apply. Firms should not wait for the new EU regime to take effect before addressing identified weaknesses.
Read more
Suggested read: BaFin Compliance Guide: AML & KYC Requirements in Germany 2026
iGaming
Isle of Man🇮🇲 GSC Clarifies How Gambling Operators Should Use Country Risk Lists
What happened?
On August 28, 2026, the Isle of Man Gambling Supervision Commission (GSC) published guidance explaining how gambling operators should use jurisdictional risk lists in their AML/CFT and proliferation-financing risk assessments. The GSC stresses that, except where an automatic response is required for DHA List A, country lists should inform rather than replace a firm's wider risk assessment. FATF grey-listing, for example, is a risk indicator and does not automatically make every customer or transaction linked to that country high risk.
Who’s affected?
The guidance is relevant to Isle of Man-regulated gambling operators, with particular significance for online gambling businesses due to their exposure to cross-border customers, international corporate structures, third-party providers, payment intermediaries and digital onboarding.
Business effect
Operators should make sure their country-risk methodology is risk-based, documented and capable of explaining why a particular risk rating or control was applied. Assessments should look beyond customer residence and consider ownership and control, group-company locations, payment and service flows, network partners and software suppliers. During inspections, the GSC expects firms to demonstrate a clear audit trail from the country-risk information considered to the ultimate decision, including enhanced due diligence, escalation, monitoring and review where appropriate.
Deadline
No specific implementation deadline is stated. The publication is supervisory guidance on how existing country lists and AML/CFT risk assessments should be applied. Operators should consider the expectations as part of their current and ongoing compliance framework, particularly when risk circumstances or country-list classifications change.
Read more
Isle of Man GSC – Country Lists: A Quick Guide
Curaçao🇨🇼 Introduces Mandatory Standards for Remote Customer Identification and Verification
What happened?
Curaçao’s supervisory authorities (the Curaçao Gaming Authority (CGA), Central Bank of Curaçao and Sint Maarten (CBCS), and Financial Intelligence Unit) issued new Provisions governing identification and verification of customers without physical contact. The rules implement Article 3(1) of the National Ordinance on Identification when rendering Services (NOIS) and establish a uniform framework for remote onboarding, integrating it with existing AML/CFT/CFP requirements.
The provisions expressly allow technology-based verification, including biometrics, facial recognition, liveness detection, document authentication software, QR code checks, and video identification, subject to appropriate safeguards.
Who’s affected?
The requirements apply to all service providers within the scope of the NOIS, including relevant Curaçao-regulated gaming operators. They also cover the remote identification of individuals acting as controllers, directors, representatives, proxy holders, or ultimate beneficial owners of legal entities. Money transfer companies are excluded because they cannot serve non-face-to-face clients under the applicable framework.
Business effect
Businesses using remote onboarding will need to review their KYC technology, policies, risk assessments and controls. Before implementing or materially changing a solution, firms must assess ML/TF, fraud, IT, operational, legal and reputational risks and conduct end-to-end testing. Existing solutions require ongoing monitoring and documented remediation when weaknesses emerge.
The rules also impose detailed technology and security expectations, including audit trails, encryption, security and penetration testing, biometric accuracy controls, vulnerability scanning and appropriate oversight of outsourced/cloud verification providers. Non-compliance can lead to administrative or criminal sanctions, including fines, penalties and license revocation.
Deadline
The Provisions took effect on August 21, 2026. Firms introducing a new remote onboarding solution must comply with applicable requirements before using it. Firms that already use remote onboarding have a transition period and must achieve full compliance by May 1, 2027. Existing solutions may continue during that period provided the firm has begun the necessary compliance work and can demonstrate this to its supervisor.
Read more
- Curaçao – Provisions for Identification and Verification Without Physical Contact
- Curaçao Imposes New Digital Identity Rules as Gambling Oversight Tightens
Philippine🇵🇭 Supreme Court Approves Civil Forfeiture Rules for Assets Linked to Illegal POGOs
What happened?
The Philippine Supreme Court approved new procedural rules allowing the government to pursue civil forfeiture of assets connected to illegal Philippine Offshore Gaming Operators (POGOs). The rules implement Section 15 of the Anti-POGO Act of 2025 (Republic Act No. 12312) and strengthen enforcement of the Philippines’ offshore gaming ban. Importantly, forfeiture proceedings can proceed without a prior criminal charge or conviction.
Who’s affected?
The rules affect illegal POGO operators, POGO service providers, property owners and other parties whose assets are directly or indirectly connected with prohibited offshore gaming activities. Covered assets can include buildings, facilities, gaming equipment, materials, tools and proceeds from illegal operations. Innocent owners, bona fide purchasers, and secured creditors have protections if they can demonstrate a lack of knowledge of or participation in the prohibited activity.
Business effect
The rules significantly increase asset-seizure and property risk surrounding prohibited POGO operations. Government agencies can seek forfeiture through the courts, and a court must determine within 24 hours whether probable cause exists. Where established, the court can preserve or control assets to prevent their transfer, concealment or disposal.
For businesses, landlords, lenders, and other counterparties with potential exposure to former POGO operations, this increases the importance of due diligence regarding property use, customers and counterparties, contractual protections, and evidence of legitimate ownership or financing arrangements.
Deadline
The Rule on the Civil Forfeiture of POGO-Related Assets took effect on August 24, 2026. Once proceedings begin, respondents generally have 20 calendar days to submit a verified comment or opposition. The rules also impose accelerated timelines on courts, including deadlines for pre-trial, presentation of evidence and judgment.
Read more
- SiGMA – Philippines sets rules to seize illegal POGO assets
- Philippine Supreme Court – Civil Forfeiture of POGO-Related Assets
Australia🇦🇺 Passes Major Gambling Reforms Covering Advertising, BetStop, Payments and Online Gambling Products
What happened?
On August 19, 2026, the Australian Parliament passed the Interactive Gambling Amendment (Gambling Reform) Bill 2026, the Interactive Gambling (Cost Recovery Levy) Bill 2026, and the National Self-exclusion Register (Cost Recovery Levy) Amendment Bill 2026. The reforms introduce tighter controls on wagering advertising, expand the BetStop self-exclusion framework, prohibit online keno and foreign matched lotteries, and introduce measures to restrict payments and access to designated interactive gambling services.
Who’s affected?
The reforms primarily affect licensed interactive wagering service providers, gambling operators, online platforms and services carrying wagering advertising, and financial institutions/payment providers. They also affect businesses subject to the expanded BetStop requirements.
Suggested read: Gambling and Betting in Australia—A Complete Guide
Business effect
Affected gambling businesses will need to review their advertising, customer targeting, product offerings and BetStop controls. In particular, operators and online services must make sure restricted users do not receive prohibited advertising and comply with new restrictions around wagering advertising during live sports coverage.
Financial institutions and relevant online services will also face obligations designed to prevent payments to, and access to, designated interactive gambling services. Licensed wagering providers will additionally be subject to a cost-recovery levy to fund the operation of BetStop.
Deadline
The amendment Acts will take effect on January 1, 2027, following Royal Assent. Affected businesses should use the remaining implementation period to update their systems, policies, and compliance controls.
Read more
- Interactive Gambling Act 2001
- Australian Communications and Media Authority Act 2005
- National Self-exclusion Register (Cost Recovery Levy) Act 2019
Armenia🇦🇲 Proposes Website Blocking and Payment Restrictions for Unlicensed Gambling, With Two-Working-Day Deadlines
What happened?
Armenia’s State Revenue Committee (SRC) has drafted a Government Decision establishing procedures for identifying and blocking websites that allow users in Armenia to participate in gambling offered by unlicensed operators. The proposal implements restrictions already provided for under Article 8 of Armenia’s Law on Regulation of Gambling Activities.
The SRC would maintain a central electronic database of blocked websites, covering domain names, mirror domains, operator information, and types of gambling activity. The regulator would identify potentially illegal sites through internet/open-source monitoring, information from government bodies and international cooperation.
Who’s affected?
The proposal directly affects unlicensed online gambling operators targeting or remaining accessible to users in Armenia. It also imposes implementation obligations on internet service/network operators, Armenian commercial banks and payment and settlement organizations.
A website can qualify for blocking where, among other things, its operator lacks an Armenian license, and the site enables users to register, fund an account, place bets or otherwise participate in gambling, betting or lottery activities. Mirror and replacement domains are expressly covered.
Business effect
Once an unlicensed gambling site is confirmed and entered into the database, internet operators must restrict access to it, while banks and payment organizations must restrict receipt and transfer of funds connected with the unlicensed gambling activity. Payment restrictions may rely on confirmed website/brand information as well as gambling-related MCC codes.
For licensed Armenian operators, the proposal is intended to strengthen enforcement against offshore/unlicensed competitors and create more equal competitive conditions. For internet service providers, banks and payment firms, it creates operational requirements to integrate the SRC's blocking information into their website access and transaction control processes.
Deadline
This is currently a draft Government Decision, rather than a final rule. Under the draft, once information on a blocked site becomes available through the database, internet operators would have no more than 2 working days to restrict access. Banks and payment organizations would likewise have no more than 2 working days to restrict relevant payment transactions.
Once adopted, the Government Decision itself is proposed to enter into force on the day following its official publication.
Read more
Armenia e-Draft – Blocking of unlicensed gambling websites
Crypto
US🇺🇸 SEC Proposes Tailored Securities Framework for Crypto Asset Offerings
What happened?
On August 18, 2026, the US Securities and Exchange Commission (SEC) proposed “Regulation Crypto Assets,” a new regulatory framework for certain investment contracts involving crypto assets. The proposal builds on the SEC’s March 2026 interpretation of how federal securities laws apply to crypto assets and is intended to provide clearer pathways for crypto businesses to raise capital in the US.
The proposal introduces two exemptions from Securities Act registration: a one-time exemption for offerings of up to $5 million over four years, and another allowing offerings of up to $75 million in each 12-month period.
Who’s affected?
The proposal is primarily relevant to crypto asset issuers, developers and entrepreneurs raising capital in the US, as well as investors and other crypto market participants dealing with assets that may constitute or be associated with investment contracts under US securities law.
Business effect
If adopted, the framework could significantly simplify US capital raising for qualifying crypto projects. Both exemptions would require issuers to provide principles-based disclosures to investors. Issuers relying on the larger $75 million exemption would also need to provide financial statements and comply with ongoing reporting requirements.
The proposal also creates a conditional safe harbor under which a crypto asset could cease to be treated as subject to an “investment contract” once specified conditions are satisfied. It would additionally pre-empt certain state securities registration and qualification requirements, potentially creating a more uniform nationwide framework.
Deadline
This is currently a proposal, not a final rule. The public comment period will remain open for 60 days following publication of the proposing release in the Federal Register.
Read more
SEC – Regulation Crypto Assets proposal
Vietnam🇻🇳 Introduces Penalties for Violations Involving Crypto Assets
What happened?
Vietnam issued Decree No. 284/2026/ND-CP, dated July 16, 2026, establishing administrative penalties for violations involving crypto assets and the crypto-asset market. The practical significance became particularly relevant in late August because the Decree is scheduled to take effect on September 1, 2026.
This supplements the broader legal recognition of digital assets under the Law on the Digital Technology Industry and Vietnam’s existing five-year pilot crypto-asset market framework set out in Resolution No. 05/2025/NQ-CP.
Who’s affected?
The rules are relevant to crypto-asset issuers, crypto-asset service providers, trading platforms, and other organizations and individuals participating in Vietnam’s crypto-asset market. They are especially important for businesses seeking to provide crypto-asset services under Vietnam's emerging licensing regime.
Business effect
The Decree gives Vietnam an enforcement mechanism alongside its developing licensing framework. In particular, providing crypto-asset-related services without the required license can result in administrative penalties. The maximum monetary penalty under the Decree is VND 200 million (USD 7,670) for organizations and VND 100 million (USD 3,835) for individuals. Domestic investors trading crypto without a Ministry of Finance-licensed provider face fines of VND 30-50 million (USD 1,150-1,920), rising to VND 70-100 million (USD 2,680-3,835) for assets issued to foreign users.
This matters because Vietnam is moving from simply recognizing digital/crypto assets toward an operational regulated market. The Ministry of Finance has already established administrative procedures for the issuance, amendment and revocation of licenses for providers organizing crypto-asset trading markets, with the State Securities Commission handling applications.
Separately, an August 6 Ministry of Finance research publication reiterated that licensed domestic exchanges are being prepared under the five-year pilot framework, including significant capital and ownership requirements. This is more of a policy/implementation update than a new binding rule.
Deadline
The key date is September 1, 2026, when Decree No. 284/2026/ND-CP takes effect. Penalties applying to unlicensed service provision by organizations become applicable from that date. The obligation on domestic investors to trade through licensed providers is subject to a separate transition under Resolution No. 05/2025/NQ-CP and only takes effect six months after the Ministry of Finance issues its first license, which had not happened as of end-August 2026.
Read more
- Vietnam Government – August 2026 overview of rules taking effect in September
- Ministry of Finance – Development and management of digital assets in Vietnam, 6 August 2026
South Africa🇿🇦 Proposes Cross-Border Crypto Controls and New “Authorised CASP” Regime
What happened?
On August 3, 2026, South Africa’s National Treasury and the South African Reserve Bank (SARB) published a draft Crypto Assets Manual for Cross-Border Activities to be read together with the draft Capital Flow Management Regulations, 2026.
The proposed framework treats crypto assets neither as legal tender nor foreign currency, but as capital. As a result, moving crypto across the regulatory perimeter would constitute an import or export of capital. The approach is activity-based and applies across crypto-asset types, with no separate stablecoin exemption.
A crypto transaction would generally become cross-border where assets move between a domestic "Authorised CASP" and an offshore CASP, or outbound from a domestic Authorised CASP to a non-custodial wallet. Transfers between South African Authorised CASPs and holdings in domestic custodial wallets would remain domestic.
Suggested read: Custodial vs Non-Custodial Wallets: Key Differences, Security, and Control Compared
Who’s affected?
The proposals are relevant to crypto-asset service providers, resident individuals and companies, non-residents, foreign contract workers, financial institutions and other businesses involved in cross-border crypto activity.
CASPs wishing to facilitate covered transactions would need a new Authorised CASP status in addition to their existing FSCA license and FIC registration. Three categories are proposed:
- Category One: crypto-based remittance services, subject to transaction and monthly caps
- Category Two: custodial wallets and cross-border crypto transactions
- Category Three: both Category One and Category Two activities.
Resident individuals would be permitted to externalize crypto, subject to existing exchange-control allowances. Resident legal entities, however, would be prohibited from importing or exporting capital in crypto, although domestic crypto activity would remain permitted.
Residents of other Common Monetary Area countries – Lesotho, Namibia and Eswatini – would be excluded from transacting with South African Authorised CASPs, including certain transactions that would otherwise have no cross-border element.
Business effect
The proposal would create a significant new exchange-control and authorization layer for South Africa’s crypto market.
Resident individuals could transfer crypto to an offshore CASP or their own non-custodial wallet only within applicable capital allowances. These include the R2 million single discretionary allowance and the R10 million foreign capital allowance, with the latter requiring tax-compliance verification and an approved international transfer through SARS.
For businesses, the impact is more restrictive: resident entities would not be permitted to conduct cross-border crypto transfers at all under the draft framework.
Non-custodial wallets would also receive asymmetric treatment. Outbound transfers from an Authorised CASP to self-custody would be permitted within applicable limits, but crypto could not be transferred directly back from a non-custodial wallet into a domestic Authorised CASP wallet. Repatriation would generally have to pass through an offshore CASP.
Authorised CASPs would also face extensive reporting, record-keeping and data-governance obligations. Cross-border transactions would have to be reported to the FinSurv Reporting System irrespective of value, with records, including transaction hashes, wallet identifiers, and KYC information, retained for five years.
The proposals also restrict outsourcing and offshore hosting. Data and infrastructure may be hosted offshore only with approval and subject to access and jurisdictional safeguards, while outsourcing or offshoring of core functions and business processes would not be permitted.
Deadline
The framework is currently in draft form. Comments on the draft Manual and related framework close on September 30, 2026.
There is no proposed commencement date or transitional period yet. Several operational elements, including detailed reporting categories, Business and Technical Specifications and an Operations Manual, are also expected only once the framework is formally adopted.
Read more
Relevant articles
- news
- 3 weeks ago
- 1 min read
Germany is continuing preparations for its European Digital Identity Wallet (EUDI Wallet), targeting a January 2, 2027 launch.

- news
- 5 days ago
- 1 min read
Operation Jackal IV led to 58 arrests across 22 countries, targeting West African fraud networks, romance scams, and Crime-as-a-Service laundering.

What is Sumsub anyway?
Not everyone loves compliance—but we do. Sumsub helps businesses verify users, prevent fraud, and meet regulatory requirements anywhere in the world, without compromises. From neobanks to mobility apps, we make sure honest users get in, and bad actors stay out.


