8 Key Financial Services Compliance Regulations to Track in 2026

Date
October 1, 2026
Written by
Vixio
Industry
Payments

Track 8 key financial services regulations for 2026 and see how Vixio helps compliance teams stay ahead of regulatory change with automation and expert insight.

Financial services is one of the most heavily regulated industries, and staying compliant is difficult because of more than just the sheer volume of rules. Regulations are constantly evolving, deadlines overlap, and the cost of falling behind is steep, with non-compliance potentially leading to fines, reputational damage, or even revoked licenses.

To keep pace, compliance teams need a clear view of what's changing and when. This guide looks at why regulatory change is becoming harder to manage and how automated regulatory compliance tools can help. But first, let’s look at some of the latest regulatory developments financial services firms need to keep an eye on.

Vixio is a unified regulatory change management platform purpose-built for financial services. You can use Vixio to monitor regulatory developments, identify relevant changes, and manage the actions needed to stay compliant. Book a call to see how it works.

8 financial services regulations and regulatory developments to watch in 2026 

Regulatory change touches nearly every corner of financial services, from operational resilience to financial crime prevention. No single list can capture every rule shaping the industry in 2026, but here are eight developments to have on your radar, drawn from what we've covered in the Vixio platform.

1. Digital Operational Resilience Act (DORA)

The EU's Digital Operational Resilience Act (DORA) introduced requirements designed to help financial entities withstand, respond to, and recover from Information and Communication Technology (ICT) disruptions and threats, ranging from cyber attacks and sensitive data breaches to system outages and third-party failures. The rules cover areas including ICT risk management, incident reporting, resilience testing, and oversight of critical third-party technology providers.

While DORA entered into application in January 2025, firms should continue watching how national regulators interpret and enforce the rules. For example, Norway’s financial regulator recently updated its DORA incident reporting guidance in May 2026. 

Enforcement is another area to watch. Austria’s first DORA fines show that regulators can take action over procedural and administrative shortcomings, not just major incidents or financial losses.

2. PSD3 and the Payment Services Regulation (PSR)

The third Payment Services Directive (PSD3) and the Payment Services Regulation (PSR) are slated to replace the current PSD2/EMD2 architecture. While both are still moving through the EU legislative process, final publication is expected soon in Q2/Q3 2026.

PSD3/PSR aim to bring the EU's payment services framework in line with how the retail payments market looks today, particularly by improving the reliability of digital payments and levelling the playing field between traditional banks and non-bank payment service providers (PSPs) like fintech companies and EMIs.

What’s important to watch now is how the new framework moves from EU legislation into national implementation. PSR will apply directly across member states, but PSD3 will need to be transposed into national law. That will likely create differences in timing and implementation between countries, with potential implications for licensing, reauthorisation, and passporting.

Learn more about PSD3: PSD3 Compliance: What You Need To Know

3. Anti-Money Laundering Regulation (AMLR)

The EU overhauled its anti-money laundering and terrorist financing framework in June 2024, replacing the previous directive-led approach with a single, consistent rulebook across member nations.

Published in June 2024, the Anti-Money Laundering Regulation (AMLR) will apply from July 10th, 2027, alongside the 6th Anti-Money Laundering Directive and other reforms. Among its key aims is harmonising customer due diligence requirements across member states.

Firms should keep a close eye on the Anti-Money Laundering Authority (AMLA), the EU’s new AML authority based in Frankfurt, as it develops the guidelines, technical standards, and reporting frameworks that will shape how the new rules work in practice. 

For example, in July 2026, AMLA launched a public consultation on establishing a common format for suspicious activity and transaction reporting.

4. Markets in Crypto-Assets Regulation (MiCA)

The Markets in Crypto-Assets Regulation (MiCA) creates a harmonised regulatory framework for crypto-assets and crypto-asset service providers (CASPs) across the EU, covering authorisation and licensing, issuance requirements, conduct of business rules, and market abuse prohibitions.

MiCA also introduced dedicated rules for stablecoins – referred to under MiCA as asset-referenced tokens and e-money tokens – including reserve, redemption, and disclosure requirements for issuers.

MiCA entered into force in December 2023, with a transitional period for existing firms. The EU-wide backstop deadline for that period was July 1st, 2026, meaning firms covered by MiCA now need to meet its requirements in full.

For firms, the focus is now on ongoing compliance and supervisory expectations. It’s also worth watching how MiCA interacts with the EU’s wider AML reforms. Under the AMLR, CASPs will be subject to full AML/CTF (Counter Terrorist Financing) obligations from July 10th, 2027.

5. FCA Consumer Duty

The Financial Conduct Authority’s (FCA) Consumer Duty came into force in 2023, raising the standard for consumer protection across UK financial services. 

The FCA is increasingly focused on showing what good and poor compliance looks like through supervision and enforcement. In July 2026, the FCA reported 11 open investigations into potential Consumer Duty breaches.

Separately, a May 2026 government policy statement on Consumer Credit Act reform proposed moving existing CCA requirements into FCA rules, potentially expanding the FCA’s conduct requirements for consumer credit firms.

6. FCA safeguarding rules for payments and e-money firms

The FCA’s new Supplementary Regime came into force on May 7th, 2026, strengthening how payment and e-money firms safeguard customer funds. The rules introduce requirements around daily reconciliations, monthly regulatory returns, annual safeguarding audits, third-party due diligence, resolution packs to help return customer funds quickly if a firm fails, and more.

The new regime is intended as a stepping stone toward a longer-term “Post-Repeal Regime”, which could replace the current safeguarding framework with a CASS-style statutory trust. 

Back in August 2025, FCA Director Matthew Long said the regulator would be “watching closely” and that firms’ behaviour would help determine whether further rule changes are needed. For now, firms should watch how the FCA assesses compliance with the new rules. 

7. UK operational incident and third-party reporting

With PS26/2 (published in March 2026), the FCA, Prudential Regulation Authority (PRA), and Bank of England introduced a unified regime for operational incident and third-party reporting, with final rules to take effect on March 18th, 2027. The policy statement set out the new requirements, which included standardised reporting for operational incidents and notifications for new third-party arrangements.

For operational incidents, firms will need to report when an incident meets or could meet thresholds relating to consumer harm, market integrity, or safety and soundness, using a phased process covering an initial notification, updates, and a final report. Firms will also need to maintain a register of material third-party arrangements and submit it annually to the FCA.

With the rules not taking effect until 2027, 2026 is largely about preparation. Firms should watch for further guidance and assess how their existing incident and third-party reporting processes will need to change.

8. Basel 3.1

Basel 3.1 is the final package of international banking reforms designed to make banks’ risk calculations more consistent and ensure they hold sufficient capital against those risks. The reforms cover credit, operational, and financial market risk, as well as introduce output floors that limit the capital benefits banks can gain from internal models.

The UK’s implementation is being led by the PRA, with the new Basel 3.1 standards set to take effect on January 1st, 2027. Banks should use 2026 to prepare for the changes, particularly where they affect capital requirements, risk models, and reporting.

Why keeping up with financial regulations manually is not sustainable

The developments above from the Vixio platform are only a snapshot of what financial services firms need to track. Regulatory requirements keep evolving, creating a moving target for compliance teams. 

Teams who don’t use a dedicated regulatory compliance tool typically face the following challenges: 

  • Multiple regulators and jurisdictions make it difficult to maintain an up-to-date understanding of your obligations. Staying on top of new regulations means monitoring developments from multiple regulators across different markets, each with its own rules, guidance, timelines, and approaches to implementation.
  • The sheer volume of regulatory change makes manual monitoring hard to scale. The different types of updates – new rules, amendments, consultations, guidance, enforcement actions – can generate regulatory noise that only gets worse as you grow your footprint.
  • Generic AI tools aren't built for the nuances of regulatory compliance. Some teams turn to generic AI tools to close the gap, but these tools can hallucinate details, miss critical updates, misinterpret requirements, and surface outdated information, often creating more work to verify than they save.
  • Determining what actually applies to your business can be just as difficult as identifying a change itself. Regulatory requirements rarely apply uniformly across an organisation, and a change’s relevance can depend on factors such as your products, activities, entities, and jurisdictions.
  • Understanding how a regulatory change affects your business requires complex coordination across functions. A new requirement may affect multiple products, processes, policies, and controls, making it difficult for compliance teams to assess the full operational impact on their own. Without a clear record of how regulations connect to the business, you may need to repeatedly coordinate across functions to determine what’s affected, how urgent the change is, and what action is needed.
  • Taking action and proving compliance requires ongoing coordination. Without clear ownership and an audit trail, changes can fall through the cracks or leave teams unable to demonstrate how they responded. That can create unnecessary compliance risk and make it harder to defend decisions during regulatory reviews or audits.

In short, as the regulatory landscape grows more complex, managing change through spreadsheets, email, and manual research becomes harder to sustain. That's why automation is critical. It can help speed up parts of the regulatory change management process, freeing up your team to focus on implementing needed changes and supporting growth initiatives.

Why automation is critical for financial services compliance

Used strategically, automation can take on much of the repetitive work involved in managing regulatory change and maintaining compliance. The tools that make a difference are built specifically for regulatory compliance, pull from a closed set of vetted regulatory sources, and keep a human in the loop to validate output. Here are a few ways they can help:

  • Identify regulatory changes faster. Automated tools can monitor verified regulatory bodies and surface new or amended requirements as they emerge, without you having to check sources manually.
  • Filter out regulatory noise. Automation can be used to categorise and filter updates by jurisdiction, business line, product, or topic, so you can quickly identify the most relevant changes.
  • Speed up research. AI can extract and summarise key information from lengthy regulatory documents, giving you a faster starting point for understanding what’s changed.
  • Better manage implementation. You can leverage automated workflows to assign actions, track progress, and maintain a central record of how your organisation responded.
  • Scale more easily. As your firm expands into new markets or launches new products, automation can help you handle increasing volumes of regulatory change rather than having to increase headcount to keep pace.

Still, while these capabilities can meaningfully lighten the load, automation alone isn't the full answer.

Combining human expertise and automated tools 

AI and automation are powerful for identifying, organising, and analysing regulatory information, but they're not a substitute for business context and human judgment. Understanding the significance of a change and deciding how to respond still calls for regulatory expertise, internal risk assessments, and a clear understanding of the business. 

Ultimately, the most effective approach combines the strengths of both. A regulatory change management platform can help here by automating the repetitive work of monitoring and organising regulatory change, while still leaving room for human experts to apply judgment where it matters most. Here’s why both elements matter:

Benefits of human expertise Benefits of automated tools
  • Deeper understanding of business and regulatory context
  • More nuanced interpretation of complex or ambiguous requirements
  • Ability to apply judgment to unusual or high-risk situations
  • Industry knowledge and regulatory relationships
  • Better understanding of organisational risk appetite and practical constraints
  • Greater confidence when making complex compliance decisions
  • Human accountability for important decisions
  • Greater speed and efficiency
  • Broader regulatory coverage
  • More consistent monitoring and analysis
  • Easier scaling as regulatory volume grows
  • Better visibility and traceability across regulatory activity
  • Teams conduct less repetitive research
  • More time for teams to focus on higher-value work

Vixio brings both sides of that table together. Our platform combines automation and AI with decades of in-house regulatory expertise, so you get relevant regulatory changes faster than manual research alone, without losing the human judgment needed to act on them. Find out more by requesting a demo.

How Vixio helps automate financial services compliance

At Vixio, we’ve spent more than 20 years delivering regulatory and editorial intelligence to highly regulated industries. Today, that expertise powers a unified regulatory change management platform purpose-built for financial services and gambling companies.

Here’s what you can do with our platform:

Stay ahead of regulatory change with AI-powered, expert-led regulatory intelligence

Manually monitoring sources, sorting through updates, and researching what matters leaves less time for analysing changes and putting them into practice. Vixio automates much of this work with continuous monitoring, paired with deep regulatory expertise and expert-authored analysis, so you don’t have to connect the dots alone.

Our Horizon Scanning tool monitors regulatory sources across 200+ jurisdictions, surfacing new rules, amendments, consultations, and deadlines in a consistent format. At the same time, filters, urgency signals, and relevance scoring help you cut through the noise and focus on changes that matter to your organisation.

You also get a central triage queue for reviewing incoming updates, where you can assess relevance, dismiss irrelevant changes, or create actions directly. 

For deeper research, turn to Vixio’s Jurisdiction Reports, Reg Analysis, and Insights for expert-led analysis of regulatory requirements and emerging developments.

You can also use VIQ Assistant to ask questions and search Vixio’s repository of expert-led content and curated regulatory documents. With AI-powered answers grounded in Vixio’s vetted regulatory intelligence rather than generic web content, VIQ combines the speed of automation with the credibility of expert-led research. 

Assess impact and connect obligations to your business

Understanding what changes mean for your products, processes, policies, and internal controls often requires significant coordination across compliance and business teams.

With Requirements Extraction, you can pull relevant passages from regulatory documents and turn them into suggested obligations your business can act on.

With Regulatory Mapping, you can then link those obligations to business units, products, policies, and controls. This creates a more connected view of your regulatory requirements, making it easier to see what a particular change could affect and identify potential gaps.

Instead of starting from scratch every time a new regulation appears, you can refer to that Obligations Library to see how the change relates to the business. This reduces repetitive analysis and gives you a more consistent way to assess regulatory impact.

Manage compliance actions with automated workflows and reporting

Once you understand what a regulatory change means for your business, you still need to make sure the right people act on it. When tasks, deadlines, and decisions are spread across spreadsheets, emails, and project management tools, it’s easy for actions to get missed or duplicated.

With Vixio, you can bring this work into one unified place. Our Task Management tool lets you create, assign, collaborate on, and track regulatory change actions, with clear ownership and deadlines. Meanwhile, Project Tracking provides a higher-level view of progress and project health, helping you identify bottlenecks before they become compliance issues.

Our platform also makes it easier to demonstrate what happened and why. Every action is logged, creating a built-in audit trail that can be used to generate configurable reports for operations, management, or regulators.

How Flywire uses Vixio to stay ahead of regulatory change

Trusted by leading names like PayPal, PwC, and Google, Vixio is built for teams navigating regulatory complexity across multiple markets and products.

Take Flywire, a global payments enablement and software company. For Flywire, compliance is also a key source of first-mover advantage. Anticipating regulatory changes early lets the company plan and move faster than competitors when launching products in new markets. But doing that well meant finding a monitoring tool built specifically for their niche.

As Frans Wiwanto, Managing Director of APAC at Flywire, explains: "Before Vixio, we hadn’t identified a regulatory monitoring tool that was focused only on the payments field and FinTech … We wanted to have a tool that is hyper-focused on the environment that we are involved in, which is the payments industry. And we were happy to find Vixio."

With a clearer view of the regulatory landscape, Flywire's team now makes faster, more informed decisions when entering new markets and solving complex regulatory challenges.

Read the full Flywire customer story to see how they use Vixio to get ahead.

Take control of financial services compliance with Vixio

Financial services compliance regulations are constantly evolving, and keeping up manually becomes harder as your business, product portfolio, and geographic footprint grow.

As an AI-powered, expert-led regulatory change management platform, Vixio helps you monitor regulatory change, identify what matters, assess the impact on your business, and manage the actions needed to stay compliant.

Ready to spend less time managing regulatory change manually? Book a demo to see how Vixio can help.

FAQs on financial services compliance regulations

Which regulations do financial services need to track in 2026?

Key regulations to watch include the EU's Digital Operational Resilience Act (DORA), the Anti-Money Laundering Regulation (AMLR), the Markets in Crypto-Assets Regulation (MiCA), and the UK's FCA Consumer Duty. Firms should also monitor PSD3/PSR, evolving safeguarding rules for payment and e-money firms, and Basel 3.1, depending on their sector, jurisdiction, and business model.

How can financial institutions automate compliance processes?

Financial institutions can automate compliance by using tools that monitor regulatory sources, filter and prioritise relevant updates, extract obligations from regulatory documents, and map those obligations to internal business components. Automated workflows can also be used to assign tasks, track implementation progress, and maintain an audit trail for proving compliance.

Can AI help with financial services compliance?

Yes, AI can speed up regulatory research by surfacing and categorising regulatory changes, filtering out noise, and summarising lengthy documents. However, AI isn't a substitute for human judgment. Understanding a change's significance and deciding how to respond still requires regulatory expertise, risk assessment, and business context, so the most effective approach combines automation with human oversight.

What are the different types of automated financial services compliance tools?

There’s a wide range of automated tools that can help financial services firms achieve and maintain compliance, with most falling into four broad categories:

  1. Tools that help you meet compliance requirements: These support the day-to-day processes needed to comply with regulations and include solutions for KYC and identity verification, transaction monitoring, fraud detection, and data security. These tools often use automation to process large volumes of data consistently and in real time.
  2. Tools that help you stay on top of regulatory change: Solutions providing regulatory intelligence, automated horizon scanning, and regulatory updates help compliance teams keep track of new rules, amendments, guidance, and other developments that could affect the business.
  3. Tools that help you manage the response: Regulatory change management tools help turn regulatory developments into actions. Think of them as project management tools built specifically for compliance. Often, you can assign responsibilities, track implementation, and manage the work needed to respond to changes, with automation making it easy to route changes to the right people, track progress, and keep an up-to-date record of what needs to happen.
  4. Tools that help you prove compliance: These create a structured record of your obligations and how they connect to your policies, controls, processes, and products. This helps you demonstrate how requirements are being addressed and provide evidence during external and internal audits or regulatory reviews. Governance, Risk, and Compliance (GRC) platforms are a common example.

Some compliance tools focus on one of these areas, while others combine several. Vixio supports the latter three, helping financial services firms stay on top of relevant regulatory changes, manage the actions they require, and maintain a clear record of compliance activities.

Stacked layered cards in gradient teal and blue, representing Vixio's regulatory intelligence platform
Turn these insights into your competitive advantage
Navigate complex compliance with our world-class regulatory insights.

Master your next market

Take a closer look at how we track and simplify global regulatory shifts in real-time