Track 8 key financial services regulations for 2026 and see how Vixio helps compliance teams stay ahead of regulatory change with automation and expert insight.
Financial services is one of the most heavily regulated industries, and staying compliant is difficult because of more than just the sheer volume of rules. Regulations are constantly evolving, deadlines overlap, and the cost of falling behind is steep, with non-compliance potentially leading to fines, reputational damage, or even revoked licenses.
To keep pace, compliance teams need a clear view of what's changing and when. This guide looks at why regulatory change is becoming harder to manage and how automated regulatory compliance tools can help. But first, let’s look at some of the latest regulatory developments financial services firms need to keep an eye on.
Vixio is a unified regulatory change management platform purpose-built for financial services. You can use Vixio to monitor regulatory developments, identify relevant changes, and manage the actions needed to stay compliant. Book a call to see how it works.
Regulatory change touches nearly every corner of financial services, from operational resilience to financial crime prevention. No single list can capture every rule shaping the industry in 2026, but here are eight developments to have on your radar, drawn from what we've covered in the Vixio platform.
The EU's Digital Operational Resilience Act (DORA) introduced requirements designed to help financial entities withstand, respond to, and recover from Information and Communication Technology (ICT) disruptions and threats, ranging from cyber attacks and sensitive data breaches to system outages and third-party failures. The rules cover areas including ICT risk management, incident reporting, resilience testing, and oversight of critical third-party technology providers.
While DORA entered into application in January 2025, firms should continue watching how national regulators interpret and enforce the rules. For example, Norway’s financial regulator recently updated its DORA incident reporting guidance in May 2026.

Enforcement is another area to watch. Austria’s first DORA fines show that regulators can take action over procedural and administrative shortcomings, not just major incidents or financial losses.

The third Payment Services Directive (PSD3) and the Payment Services Regulation (PSR) are slated to replace the current PSD2/EMD2 architecture. While both are still moving through the EU legislative process, final publication is expected soon in Q2/Q3 2026.
PSD3/PSR aim to bring the EU's payment services framework in line with how the retail payments market looks today, particularly by improving the reliability of digital payments and levelling the playing field between traditional banks and non-bank payment service providers (PSPs) like fintech companies and EMIs.
What’s important to watch now is how the new framework moves from EU legislation into national implementation. PSR will apply directly across member states, but PSD3 will need to be transposed into national law. That will likely create differences in timing and implementation between countries, with potential implications for licensing, reauthorisation, and passporting.
Learn more about PSD3: PSD3 Compliance: What You Need To Know
The EU overhauled its anti-money laundering and terrorist financing framework in June 2024, replacing the previous directive-led approach with a single, consistent rulebook across member nations.
Published in June 2024, the Anti-Money Laundering Regulation (AMLR) will apply from July 10th, 2027, alongside the 6th Anti-Money Laundering Directive and other reforms. Among its key aims is harmonising customer due diligence requirements across member states.
Firms should keep a close eye on the Anti-Money Laundering Authority (AMLA), the EU’s new AML authority based in Frankfurt, as it develops the guidelines, technical standards, and reporting frameworks that will shape how the new rules work in practice.
For example, in July 2026, AMLA launched a public consultation on establishing a common format for suspicious activity and transaction reporting.

The Markets in Crypto-Assets Regulation (MiCA) creates a harmonised regulatory framework for crypto-assets and crypto-asset service providers (CASPs) across the EU, covering authorisation and licensing, issuance requirements, conduct of business rules, and market abuse prohibitions.
MiCA also introduced dedicated rules for stablecoins – referred to under MiCA as asset-referenced tokens and e-money tokens – including reserve, redemption, and disclosure requirements for issuers.
MiCA entered into force in December 2023, with a transitional period for existing firms. The EU-wide backstop deadline for that period was July 1st, 2026, meaning firms covered by MiCA now need to meet its requirements in full.
For firms, the focus is now on ongoing compliance and supervisory expectations. It’s also worth watching how MiCA interacts with the EU’s wider AML reforms. Under the AMLR, CASPs will be subject to full AML/CTF (Counter Terrorist Financing) obligations from July 10th, 2027.
The Financial Conduct Authority’s (FCA) Consumer Duty came into force in 2023, raising the standard for consumer protection across UK financial services.
The FCA is increasingly focused on showing what good and poor compliance looks like through supervision and enforcement. In July 2026, the FCA reported 11 open investigations into potential Consumer Duty breaches.

Separately, a May 2026 government policy statement on Consumer Credit Act reform proposed moving existing CCA requirements into FCA rules, potentially expanding the FCA’s conduct requirements for consumer credit firms.

The FCA’s new Supplementary Regime came into force on May 7th, 2026, strengthening how payment and e-money firms safeguard customer funds. The rules introduce requirements around daily reconciliations, monthly regulatory returns, annual safeguarding audits, third-party due diligence, resolution packs to help return customer funds quickly if a firm fails, and more.
The new regime is intended as a stepping stone toward a longer-term “Post-Repeal Regime”, which could replace the current safeguarding framework with a CASS-style statutory trust.
Back in August 2025, FCA Director Matthew Long said the regulator would be “watching closely” and that firms’ behaviour would help determine whether further rule changes are needed. For now, firms should watch how the FCA assesses compliance with the new rules.

With PS26/2 (published in March 2026), the FCA, Prudential Regulation Authority (PRA), and Bank of England introduced a unified regime for operational incident and third-party reporting, with final rules to take effect on March 18th, 2027. The policy statement set out the new requirements, which included standardised reporting for operational incidents and notifications for new third-party arrangements.

For operational incidents, firms will need to report when an incident meets or could meet thresholds relating to consumer harm, market integrity, or safety and soundness, using a phased process covering an initial notification, updates, and a final report. Firms will also need to maintain a register of material third-party arrangements and submit it annually to the FCA.
With the rules not taking effect until 2027, 2026 is largely about preparation. Firms should watch for further guidance and assess how their existing incident and third-party reporting processes will need to change.
Basel 3.1 is the final package of international banking reforms designed to make banks’ risk calculations more consistent and ensure they hold sufficient capital against those risks. The reforms cover credit, operational, and financial market risk, as well as introduce output floors that limit the capital benefits banks can gain from internal models.
The UK’s implementation is being led by the PRA, with the new Basel 3.1 standards set to take effect on January 1st, 2027. Banks should use 2026 to prepare for the changes, particularly where they affect capital requirements, risk models, and reporting.
The developments above from the Vixio platform are only a snapshot of what financial services firms need to track. Regulatory requirements keep evolving, creating a moving target for compliance teams.
Teams who don’t use a dedicated regulatory compliance tool typically face the following challenges:
In short, as the regulatory landscape grows more complex, managing change through spreadsheets, email, and manual research becomes harder to sustain. That's why automation is critical. It can help speed up parts of the regulatory change management process, freeing up your team to focus on implementing needed changes and supporting growth initiatives.
Used strategically, automation can take on much of the repetitive work involved in managing regulatory change and maintaining compliance. The tools that make a difference are built specifically for regulatory compliance, pull from a closed set of vetted regulatory sources, and keep a human in the loop to validate output. Here are a few ways they can help:
Still, while these capabilities can meaningfully lighten the load, automation alone isn't the full answer.
AI and automation are powerful for identifying, organising, and analysing regulatory information, but they're not a substitute for business context and human judgment. Understanding the significance of a change and deciding how to respond still calls for regulatory expertise, internal risk assessments, and a clear understanding of the business.
Ultimately, the most effective approach combines the strengths of both. A regulatory change management platform can help here by automating the repetitive work of monitoring and organising regulatory change, while still leaving room for human experts to apply judgment where it matters most. Here’s why both elements matter:
Vixio brings both sides of that table together. Our platform combines automation and AI with decades of in-house regulatory expertise, so you get relevant regulatory changes faster than manual research alone, without losing the human judgment needed to act on them. Find out more by requesting a demo.
At Vixio, we’ve spent more than 20 years delivering regulatory and editorial intelligence to highly regulated industries. Today, that expertise powers a unified regulatory change management platform purpose-built for financial services and gambling companies.
Here’s what you can do with our platform:
Manually monitoring sources, sorting through updates, and researching what matters leaves less time for analysing changes and putting them into practice. Vixio automates much of this work with continuous monitoring, paired with deep regulatory expertise and expert-authored analysis, so you don’t have to connect the dots alone.
Our Horizon Scanning tool monitors regulatory sources across 200+ jurisdictions, surfacing new rules, amendments, consultations, and deadlines in a consistent format. At the same time, filters, urgency signals, and relevance scoring help you cut through the noise and focus on changes that matter to your organisation.
You also get a central triage queue for reviewing incoming updates, where you can assess relevance, dismiss irrelevant changes, or create actions directly.

For deeper research, turn to Vixio’s Jurisdiction Reports, Reg Analysis, and Insights for expert-led analysis of regulatory requirements and emerging developments.
You can also use VIQ Assistant to ask questions and search Vixio’s repository of expert-led content and curated regulatory documents. With AI-powered answers grounded in Vixio’s vetted regulatory intelligence rather than generic web content, VIQ combines the speed of automation with the credibility of expert-led research.
Understanding what changes mean for your products, processes, policies, and internal controls often requires significant coordination across compliance and business teams.
With Requirements Extraction, you can pull relevant passages from regulatory documents and turn them into suggested obligations your business can act on.

With Regulatory Mapping, you can then link those obligations to business units, products, policies, and controls. This creates a more connected view of your regulatory requirements, making it easier to see what a particular change could affect and identify potential gaps.
Instead of starting from scratch every time a new regulation appears, you can refer to that Obligations Library to see how the change relates to the business. This reduces repetitive analysis and gives you a more consistent way to assess regulatory impact.
Once you understand what a regulatory change means for your business, you still need to make sure the right people act on it. When tasks, deadlines, and decisions are spread across spreadsheets, emails, and project management tools, it’s easy for actions to get missed or duplicated.
With Vixio, you can bring this work into one unified place. Our Task Management tool lets you create, assign, collaborate on, and track regulatory change actions, with clear ownership and deadlines. Meanwhile, Project Tracking provides a higher-level view of progress and project health, helping you identify bottlenecks before they become compliance issues.

Our platform also makes it easier to demonstrate what happened and why. Every action is logged, creating a built-in audit trail that can be used to generate configurable reports for operations, management, or regulators.
Trusted by leading names like PayPal, PwC, and Google, Vixio is built for teams navigating regulatory complexity across multiple markets and products.
Take Flywire, a global payments enablement and software company. For Flywire, compliance is also a key source of first-mover advantage. Anticipating regulatory changes early lets the company plan and move faster than competitors when launching products in new markets. But doing that well meant finding a monitoring tool built specifically for their niche.
As Frans Wiwanto, Managing Director of APAC at Flywire, explains: "Before Vixio, we hadn’t identified a regulatory monitoring tool that was focused only on the payments field and FinTech … We wanted to have a tool that is hyper-focused on the environment that we are involved in, which is the payments industry. And we were happy to find Vixio."
With a clearer view of the regulatory landscape, Flywire's team now makes faster, more informed decisions when entering new markets and solving complex regulatory challenges.
Read the full Flywire customer story to see how they use Vixio to get ahead.
Financial services compliance regulations are constantly evolving, and keeping up manually becomes harder as your business, product portfolio, and geographic footprint grow.
As an AI-powered, expert-led regulatory change management platform, Vixio helps you monitor regulatory change, identify what matters, assess the impact on your business, and manage the actions needed to stay compliant.
Ready to spend less time managing regulatory change manually? Book a demo to see how Vixio can help.
Key regulations to watch include the EU's Digital Operational Resilience Act (DORA), the Anti-Money Laundering Regulation (AMLR), the Markets in Crypto-Assets Regulation (MiCA), and the UK's FCA Consumer Duty. Firms should also monitor PSD3/PSR, evolving safeguarding rules for payment and e-money firms, and Basel 3.1, depending on their sector, jurisdiction, and business model.
Financial institutions can automate compliance by using tools that monitor regulatory sources, filter and prioritise relevant updates, extract obligations from regulatory documents, and map those obligations to internal business components. Automated workflows can also be used to assign tasks, track implementation progress, and maintain an audit trail for proving compliance.
Yes, AI can speed up regulatory research by surfacing and categorising regulatory changes, filtering out noise, and summarising lengthy documents. However, AI isn't a substitute for human judgment. Understanding a change's significance and deciding how to respond still requires regulatory expertise, risk assessment, and business context, so the most effective approach combines automation with human oversight.
There’s a wide range of automated tools that can help financial services firms achieve and maintain compliance, with most falling into four broad categories:
Some compliance tools focus on one of these areas, while others combine several. Vixio supports the latter three, helping financial services firms stay on top of relevant regulatory changes, manage the actions they require, and maintain a clear record of compliance activities.
