What firms often get wrong before an inspection.
Inspection readiness depends on whether policies, monitoring, governance and remediation can be evidenced in practice—not simply whether the documents exist.
SVP Insights
Practical perspectives on compliance, AML/CFT, internal audit and governance.
Featured Insights
Inspection readiness depends on whether policies, monitoring, governance and remediation can be evidenced in practice—not simply whether the documents exist.
Trading-platform settings, client activity, dealing arrangements, conflicts and operational processes must be understood and controlled as part of the compliance framework.
Marketing practices, client communications and complaint trends can reveal weaknesses in governance, product oversight, conduct controls and regulatory culture.
SVP News
Selected circulars, directives and regulatory amendments published during the last three months, with a concise explanation of their practical significance.
CySEC highlights the first operational milestone on 7 December 2026 and the EU transition to T+1 on 11 October 2027. In-scope firms should review allocation and confirmation processes, settlement data, counterparties, technology dependencies and end-to-end testing.
View CySEC circular →AMLA has finalised draft technical standards on supervisory cooperation for the institutions it will directly supervise from 2028. Regulated entities should follow the eligibility exercise, reporting package and related implementation guidance.
View CySEC circular →CySEC will participate in ESMA’s 2026 Common Supervisory Action and conduct targeted reviews in late 2026 or early 2027. UCITS management companies and AIFMs should assess the independence, expertise, governance, monitoring and reporting of their risk-management function.
View CySEC circular →ESMA and national authorities will assess authorised CASPs providing custody services. Focus areas include governance, storage and key management, transaction controls, incident response, smart-contract risk and third-party dependencies.
View CySEC circular →Fund managers are expected to perform and evidence a gap analysis against the revised liquidity-management framework, including the selection, calibration and activation of liquidity-management tools and effective Board oversight.
View CySEC circular →In-scope counterparties must assess whether an active EU CCP account is required and establish the necessary governance, legal, operational, IT, notification and recurring reporting arrangements.
View CySEC circular →The consultations address the format for reporting suspicions and transaction records, and the methodology for assessing inherent and residual risk in non-financial obliged entities. Affected firms should assess the proposals and consider providing evidence-based feedback.
View CySEC circular →Following the end of the transitional period on 1 July 2026, firms should address risks arising from VASP exits and customer migrations through documented wind-down controls, updated CDD, transaction monitoring and proportionate customer risk assessments.
View CySEC circular →Financial entities using advanced AI should incorporate model-related cyber risks into their DORA governance, ICT-risk framework, third-party controls, incident management, resilience testing and senior-management oversight.
View CySEC circular →CySEC reminds CIFs marketing to Spanish retail clients that the CNMV treats Spot Quoted Futures as CFDs. Firms should ensure that CFDs, SQFs, perpetual futures and analogous products comply with Spain’s product-intervention requirements.
View CySEC circular →CySEC issued updated templates for reporting major ICT-related incidents and significant cyber threats. Firms should align escalation, classification, recordkeeping and regulatory-reporting procedures with the current forms.
View CySEC circular →The reporting package supports identification of entities potentially eligible for AMLA direct supervision from 2028. Although the original submission deadline has passed, the data architecture and interpretative guidance remain relevant to future supervisory selection and data-readiness work.
View CySEC circular →The draft guidelines concern the variables and methodology supervisors should use when classifying obliged entities by risk. Firms should understand how their inherent risk, controls, residual risk and supervisory profile may be assessed under the future EU framework.
View CySEC circular →The consolidated Directive incorporates the 2026 amendments governing registration and changes, authorised users, access, subscriptions and fees, exemptions and discrepancy reporting. Trustees, equivalent persons and obliged entities should review their register procedures and data-quality controls.
View consolidated Directive →These summaries are provided for general information only and do not constitute legal or regulatory advice. The official CySEC document should always be consulted.