The CUBE Read: 3 Compliance and Risk developments where the detail is now doing the work
In brief: Regulators spent this fortnight adjusting the detail of existing rules: windows, fees, reporting and decision processes. This edition covers how that moves compliance and risk work from knowing a rule exists to managing its parameters. It also covers why provenance now matters more than speed as AI changes how teams find answers, and why hard deadlines are a prompt to map the second layer of dependencies. This edition covers September 22 - October 2, 2026.
The detail is moving. Parameter-level intelligence keeps compliance and risk teams ahead.
Much of this fortnight's activity changed the settings inside existing rules rather than creating new ones. ASIC extended MDA relief and lengthened the non-compliance notification window to 30 days. ASIC also extended other legislative instruments, and the Bank of England consulted on payment system fees as HM Treasury weighs a cap increase.
The EBA consulted on a streamlined joint decision process for bank-specific prudential requirements. It is also pursuing reporting cuts and simpler prudential requirements through its 2027 work program. The Hong Kong SFC plans a 2027 consultation on streamlined prospectus disclosure, alongside wider access initiatives, in its strategic action plan.
Each of these changes a number, a window, a method or a process. The obligations themselves stay in place, which makes parameter-level monitoring the way to see each change as it lands. In CUBE's Cost of Compliance Report 2025, 82% of surveyed firms track between 26 and 100 regulatory developments a month, and 79% say more than a quarter of those require action.
On the other side, carriers and managing general agents are moving to automate state cancellation and non-renewal notices, at volumes from several hundred to close to a thousand a month, with API integration the next step. Across financial services more broadly, firms are looking to move from spreadsheet- and email-based monitoring toward structured, connected workflows.
What it means for compliance and risk professionals: When the change is a parameter, your teams gain most from seeing which parameter moved, in which jurisdiction, and what it touches in your workflows. Automation helps most when it is tied to tracked, expert-reviewed requirements and leaves room for your own review. Removing the need for manual tracking frees your teams to spend their time applying the change.
Speed gets teams to an answer. Provenance gives it authority.
Supervisory attention to AI is becoming more specific. ESMA set a 2027 supervisory priority on client-facing AI and tokenisation alongside continued DORA oversight. ASIC found disclosure quality improved markedly in the first statutory sustainability reports and identified forward-looking disclosures as the next area to strengthen, which shows that statements about the future benefit from a documented basis.
Compliance and risk teams are responding to this. Some are building internal agents. Others are asking sharper questions of vendor AI: how it uses their inputs, how to view the underlying sources, and how to frame model outputs as indicators that support validation.
What it means for compliance and risk professionals: The question is moving from “can AI answer this?” to “can we show where the answer came from, who validated it, and what happened to our data?” Intelligence that links to its sources, carries expert review and supports documented validation matches the direction supervisors are taking. CUBE's Cost of Compliance Report 2025 points the same way: respondents' ideal operating model features clear lineage and traceability between regulations and downstream controls, with the audit trail named as a critical factor. Teams can use AI to accelerate the process; what’s important is that they can trace the data it uses back to a source they trust as accurate.
Hard dates are a prompt to map the second layer
Two dates anchored the fortnight. The UK FCA opened its crypto application window and set a February 28, 2027 deadline. The CFTC is preparing customer-fund repo changes ahead of the June 2027 Treasury repo clearing deadline.
Behind the dates, supervisors are asking firms to look past the first layer. The FCA is asking firms to trace money-mule networks beyond first receiving accounts. It also plans to consult on safeguarding rules for tokenised assets in the first half of 2027 as tokenisation moves beyond pilots. The ESAs are calling for proactive monitoring and stronger preparedness on external dependencies, private credit and AI. PwC's 2027 Global Digital Trust Insights survey found that 39% of surveyed leaders have a fully formalised and integrated operational continuity plan for cyber threats, which shows how much room there is to build.
The same question applies to the tools compliance and risk teams rely on. Many teams are planning ahead for read-only and end-of-support dates on legacy regulatory tools, running old and new platforms in parallel to protect timeliness, and getting hundreds of users up to speed within weeks. Including regulatory intelligence in that same testing gives your teams confidence that the intelligence they act on keeps flowing through any change,.
What it means for compliance and risk professionals: Dependency testing should include the tools your own function runs on, with dated cut-over plans, parallel running where timeliness is at stake, and clear ownership. Teams that map the second layer early reach each deadline with time and choices.
The through line
Across all three themes, the work has moved down a level. Regulators are adjusting parameters rather than principles, so the detail beneath a rule now matters as much as the rule. AI has made answers fast, so the evidence behind an answer is what gives it authority with supervisors and colleagues. Supervisors are looking past the first account, the first provider and the first date, so mapping the second layer early puts your teams in command of it.
It is what CUBE is built for: applying AI to regulatory workflows, built on 15 years of regulatory data, inside the platforms compliance and risk teams already use.
FAQs
What does tracing money-mule networks “beyond first receiving accounts” mean?
Money mules receive criminal proceeds and move them on, often quickly and through several accounts. Tracing beyond the first receiving account means following funds through that chain, which gives firms a fuller picture of the network. The FCA's review found proceeds commonly pass through two to five mule accounts before cash-out.
What is a tokenised asset, and why does safeguarding matter?
A tokenised asset is a digital representation of an asset on a distributed ledger. Safeguarding rules set how client assets are held and protected, so they determine how a firm segregates and records what it holds for clients.
What counts as an external dependency in a resilience review?
Any third party a function relies on to operate, including technology providers, data suppliers and service partners. Testing looks at how a firm keeps operating when one of them changes or is unavailable.
How often is The CUBE Read published?
Fortnightly. Each edition covers the regulatory developments most relevant to compliance and risk teams in financial services.