Financial Regulatory Deadlines to Watch in September 2026

Date
September 1, 2026
Written by
Kat Pilkington
Industry
Payments

Stay ahead of 50 key payments regulatory deadlines in September, including consultations closing and new rules taking effect across global markets.

Each month, we leverage data from our Horizon Scanning Regulatory Deadlines Calendar to bring you a glimpse of the key response deadlines and legislation effective dates coming up, so you can plan and take action around some of the most important regulatory developments unfolding right now.

In September, there are 50 regulatory deadlines on the horizon — with 12 key consultation periods coming to an end and requiring a response, and 27 actionable deadlines to be aware of coming into effect.

What are the regulatory deadlines to watch in September?

Peru

On August 24, 2026, the Central Reserve Bank of Peru (BCRP) issued Circular N° 0017-2026-BCRP establishing comprehensive regulations for immediate payment services using alias identifiers. The regulation sets out operational guidelines for a 24/7, 365-day payment system enabling real-time or near-real-time fund transfers between users of different payment service providers (PSP) through alias-based identification or QR code scanning via mobile applications and other approved digital channels.

The service operates exclusively in Peruvian Soles (S/) with a maximum transaction limit of S/ 30,000 (approximately US$8,900) per operation, though regulated entities may establish lower limits. Alias identifiers may include mobile phone numbers, national identity document numbers, or other identifiers approved by the BCRP. The regulation establishes a directory repository storing alias identifiers linked to beneficiary fund account data, enabling interoperable transfers across the payment ecosystem. The regulation enters into force 60 calendar days from publication, effective September 13, 2026.

UAE

On 15 September 2025, the Central Bank of the UAE (CBUAE) released the Federal Decree-Law No. (6) of 2025, which is the UAE’s new overarching financial services law that significantly reforms and consolidates regulation of banking, payments, insurance, and financial infrastructure.

The law broadens the CBUAE’s regulatory perimeter to cover emerging financial technologies and digital finance models, including:

  • Open finance services
  • Payment services using virtual assets
  • Digital money and Digital Dirham infrastructure,
  • Technology providers facilitating financial services such as payment platforms, APIs, dApps, or financial infrastructure providers

A major feature of the law is the strengthening of supervisory, enforcement, and crisis-management powers available to the CBUAE. The framework introduces:

  • enhanced governance and fit-and-proper obligations,
  • stronger fraud prevention and customer protection requirements,
  • early intervention and resolution powers for distressed firms,
  • substantially higher financial penalties,
  • and criminal sanctions for carrying out regulated activities without a licence.

The law is effective from September 16, 2026.

Australia

On June 15, 2026, Australia's Department of Finance brought into force the Digital ID Amendment (Redress Framework) Rules 2026, establishing a formal redress mechanism for the Digital ID Act 2024 (DIA 2024). The rules amend the existing Digital ID Rules to strengthen the redress framework for individuals affected by digital ID fraud incidents and cybersecurity incidents within the Australian Government Digital ID System (AGDIS). The Digital ID Amendment (Redress Framework) Rules 2026 come into effect on September 30, 2026.

Ukraine

On December 24, 2025, the National Bank of Ukraine adopted the Resolution on the Approval of Amendments to the Regulation on Requirements for the Management System of Financial Payment Service Providers, applicable to payment institutions (PI) and electronic money institutions (EMI).

Key amendments include: 

  • The internal auditor, chief risk manager and chief compliance manager shall not be entitled to hold any other positions or perform any other duties at the PI, EMI or any other legal entities. 
  • The PI or EMI shall be obliged to ensure conditions for the continuous professional development of the chief internal auditor, internal auditors of the PI/EMI and their training. 
  • The PI or EMI shall have internal documents on internal audits which shall define: 
  1. The internal audit strategy. 
  2. The order and procedures for conducting internal audits. 
  3. The methodology of conducting internal audits. 

PIs and EMIs are required to bring their management systems into compliance with these amendments within the following timeframes: 

  • Conduct a self-assessment of the compliance of the internal audit department (if established) or the chief internal auditor by March 31, 2026. 
  • Develop or amend internal policies on internal audits and bring activities into compliance by May 31, 2026. 
  • Bring activities related to the organisation of the internal audit of the PI or EMI into line with the amendments by September 30, 2026.

Vixio’s Horizon Scanning tool shows you real-time updates on regulatory deadlines and trends across 140+ global jurisdictions, including all US states, at the click of a button. Its Regulatory Deadlines Calendar feature sets out effective dates for published legislation, closing dates for consultation periods on proposed regulatory developments, and deadlines for specific requests for information by regulatory authorities. 

Want to see them all?

Book a demo with a member of our team, who can show you how the Regulatory Deadlines Calendar works, and why it forms a critical part of your compliance risk process. 

Stacked layered cards in gradient teal and blue, representing Vixio's regulatory intelligence platform
Turn these insights into your competitive advantage
Navigate complex compliance with our world-class regulatory insights.

Master your next market

Take a closer look at how we track and simplify global regulatory shifts in real-time