top of page

Regulatory Updates Newsletter: September 2026

11 minutes ago
7 min read

Welcome to the September Ed. of our Regulatory Newsletter. 


This month brings a mix of regulatory changes and financial innovation, from the Fed’s proposed stablecoin framework and Basel III updates to the UK’s proposed adjustments to market risk internal models and its first live tokenised deposit transactions.


Dive in for a quick look at the key developments.

Federal Reserve Proposes Stablecoin Issuer Framework Under GENIUS Act


The U.S. Federal Reserve Board (under the new GENIUS Act) published two rulemaking proposals to regulate payment stablecoin issuers and solicited public comment. 


One proposal would require stablecoin issuers (typically banks) to fully back all redemption requests with high-quality liquid assets and to meet standardized capital, liquidity and operational resilience requirements. A parallel proposal sets out a special regulatory application process for banks to obtain Fed approval to issue stablecoins, including required business plans and hearings procedures. 


In effect, any bank issuing a payment stablecoin would need to hold all customer funds in safe (e.g. Treasury) reserves and meet prudential standards.

The public comment period (ending mid-October) invites feedback on these requirements, covering risk management, reserve management, custody of assets, and consumer disclosures. The proposals aim to bring uniform oversight to the growing stablecoin sector while preserving financial stability.


The Fed notes that these rules target “payment stablecoins” (designed for mainstream transactions) and do not cover volatility-prone cryptoassets like Bitcoin.


Implications

  • Banks considering stablecoin issuance must plan for potentially significant reserve and capital requirements.

  • The proposed framework suggests strong supervisory expectations: firms should bolster compliance, auditing, and cybersecurity around stablecoin operations.

  • If finalized, the rules will channel stablecoin issuance through the regulated banking system, likely curbing purely unregulated issuers and promoting bank-backed digital currencies.

Source:  FED 


The UK Prudential Regulation Authority (PRA) closed its consultation on CP9/26 – Basel 3.1: Adjustments to the Internal Model Approach (IMA) for Market Risk on 18 September 2026. The consultation proposes targeted changes to make the Basel 3.1 market risk framework more proportionate and operationally effective for firms using, or considering adopting, internal models.


Key proposals include extending the Profit and Loss Attribution Test (PLAT) monitoring period from one year to three years, during which failing the test would not automatically make a trading desk ineligible for the IMA. The PRA also proposes reducing the number of verifiable prices required under the Risk Factor Eligibility Test (RFET) from 24 to 16 for risk factors with liquidity horizons above 20 days.


The proposals would also introduce a new Type 1 category of Non-Modellable Risk Factors (NMRFs) for risk factors that meet qualitative data standards but do not meet quantitative verifiable-price requirements. These would be included in the Expected Shortfall model but subject to an NMRF capital add-on based on an assumption of zero correlation. The PRA also proposes changes to reduce barriers for firms using a combination of the Advanced Standardised Approach (ASA) and IMA, including recognising diversification between the two approaches.


Importantly, the PRA confirmed that the implementation date for the IMA, including any changes resulting from CP9/26, remains 1 January 2028. This is separate from the broader Basel 3.1 implementation date of 1 January 2027 for most of the remaining rules.


Implications

  • Banks using or considering the IMA should assess how the proposed changes could affect their market risk models, capital requirements and approval plans.

  • The extended PLAT monitoring period and revised NMRF treatment could give firms more flexibility while the PRA gathers further evidence on model performance and calibration.

  • Firms preparing for Basel 3.1 should maintain separate implementation planning for the broader framework in 2027 and the IMA requirements in 2028.

  • Market risk and model governance teams should monitor the PRA’s final policy response following the consultation, particularly the treatment of NMRFs, PLAT and mixed ASA-IMA portfolios.

Source - PRA


The Basel Committee on Banking Supervision published its latest monitoring report (data as of end-2025).


It found that the average risk-based capital and leverage ratios of large internationally active banks remained stable compared to mid-2025. On average, implementing the fully phased-in Basel III reforms would raise Tier 1 capital needs by about +2.2% for these banks. Liquidity positions also remain strong: the average Liquidity Coverage Ratio (LCR) rose slightly to 136.6%, while the Net Stable Funding Ratio (NSFR) was a healthy 123.3% (both well above the 100% minimum).


These results indicate that most banks have maintained robust capital buffers and liquidity under the tightened Basel III rules. The report noted that the final Basel III standards (including output floors, leverage, and liquidity requirements) started full implementation on 1 Jan 2023, and the monitored banks are on track with gradual compliance. The Basel Committee highlighted that only a small aggregate capital shortfall (~€1.2bn) remains for G-SIBs under fully phased-in rules.


Implications

  • International banks appear well-positioned under Basel III; regulators will likely stick to scheduled implementation (fully phased-in by 2028).

  • Banks may need only modest additional capital as standards finalize, reducing fears of a sharp credit impact.

  • Policymakers and markets can take reassurance from the resilience of global bank balance sheets amid new regulatory requirements.

Source: Basel Committee Media Release, BIS


UK banks collaborated under the Great British Tokenised Deposit (GBTD) initiative to complete the first live customer transactions using tokenised sterling deposits. 


The pilot - led by UK Finance and involving Barclays, HSBC UK, Lloyds, Monzo, Nationwide, NatWest and Santander – executed two remortgages and a consumer marketplace purchase using programmable deposits. For example, in the remortgage pilots, funds were “locked” and automatically released on completion, speeding up settlement and ensuring customers continued to earn interest during processing. The marketplace pilot similarly locked the buyer’s funds until the goods exchanged hands, reducing fraud risk and building trust.


The results show that tokenised deposits retain the safety and regulatory protections of bank money while adding speed and programmability. The pilots demonstrated benefits such as reduced manual checks, greater customer control of funds, and faster trust-building in digital transactions. UK regulators (Bank of England, Treasury, FCA, Payments Regulator) are already working on modernising retail payments, and these pilots complement that effort. Banks plan further pilots linking tokenised deposits with digital assets (delivery-vs-payment-versus-reserves) later this year.


Implications

  • Financial institutions should explore tokenised deposit schemes to streamline processes (e.g. remortgages, online commerce) while preserving regulatory safeguards.

  • Firms need robust governance around programmable money (e.g. access controls, custody of tokens) to support these innovations safely.

  • Regulators will likely monitor these pilots closely as they inform the future framework for digital money and payments.

Source: UK Finance


RBA published its annual assessment of Australia’s systemically important clearing and settlement (CS) facilities operated by the ASX. It found that most Standards (governance, risk management, etc.) were “observed” or “broadly observed,” but noted some “partly observed” gaps in governance and operational risk management. 


The report praised recent improvements: after ASX enhanced its CHESS securities settlement system and contingency arrangements, the RBA upgraded two facilities from “not observed” to “partly observed” on operational risk. 


The RBA made clear that ASX’s ongoing “Transformation Portfolio” (addressing long-running issues) must successfully deliver on those fixes to fully meet standards.


Implications

  • ASX must continue its organizational changes; failure to meet RBA’s expectations could lead to enforceable actions or stricter oversight.

  • Clearing participants and issuers should monitor ASX’s progress, as changes may affect processing timeliness or costs in the transition.

  • Other market operators may see similar scrutiny: regulators are signaling that robust governance and resilient infrastructure are non-negotiable.

Source: Reserve Bank of Australia


The OCC, Federal Reserve, FDIC, FinCEN and NCUA jointly clarified rules on Suspicious Activity Report (SAR) confidentiality. 


The statement reiterates that the Bank Secrecy Act strictly prohibits revealing a SAR or any information that might imply one was filed. However, it permits banks to discuss the underlying facts or transactions of a case with customers, as long as the conversation does not explicitly disclose the SAR filing. 


In other words, a bank may warn a customer of a suspicious transaction (e.g. a large transfer or fraud alert) provided it avoids any indication that the matter has been reported to regulators.


Implications

  • Banks can more freely communicate with clients about specific transactions or fraud risks (improving customer service) without violating SAR rules.

  • Training should emphasize “the facts vs. the filing”: employees must discuss transaction details but never mention SARs or suspicion of money laundering directly.

  • This clarification may improve trust: institutions can now say “we flagged an unusual transaction” in customer outreach, rather than saying nothing until reporting to regulators.

Source: FinCEN


U.S. banking regulators (OCC, Fed, FDIC) with FinCEN and NCUA issued FAQs on verifiable digital credentials (VDCs) such as state mobile driver’s licenses. The guidance confirms that banks can accept compliant digital IDs under the Customer Identification Program (CIP) rule for customer onboarding. It notes that a mobile driver’s license is considered a valid government ID, provided the institution still verifies identity per AML/CIP requirements. 


The FAQs emphasize that use of VDCs must maintain security (e.g. digital verification) but do not impose new obligations beyond existing law.


Implications

  • Banks should integrate technology to support digital ID verification in their onboarding processes.

  • Financial institutions may streamline new-account opening using mobile IDs, potentially reducing paperwork.

  • Institutions must ensure digital ID providers meet security standards; updated procedures and employee training will be needed.

Source: OCC 

Jurisdiction

Regulator

Update

Link

UK

FCA

Published its Final Report on the pure protection product market, identifying a significant protection gap and reminding firms to improve fair value assessments under the Consumer Duty.

EU

ECB

Launched Pontes, a system linking market distributed ledger technology (DLT) platforms to TARGET Services, enabling wholesale tokenized asset transactions to settle in central bank money.

US

SEC

Issued an "Innovation Exemption" to facilitate the trading of tokenized NMS stock and opened a request for public comment on the framework.

US

SEC

Proposed the rescission of the Shareholder Proposal Rule and introduced reforms to modernize the proxy solicitation process.

US

CFTC

Approved a Final Rule concerning whistleblower awards to improve the efficiency, transparency, and predictability of claims processing.

US

CFTC

Released a staff advisory on Mention Markets, outlining the limited circumstances in which such derivative contracts may be listed consistently with the Commodity Exchange Act.

Stay informed with our regulatory updates and join us next month for the latest developments in risk management and compliance!

For any feedback or requests for coverage in future issues (e.g., additional countries or topics), please contact us at info@riskinfo.ai. We hope you found this newsletter insightful.


Best regards,

Comments


bottom of page