3 min read

The 2026 Compliance Landscape (Part 1 of 3)

Published on
January 21, 2026
Share

In 2025, the U.S. Department of Justice closed approximately half of its active FCPA investigations. This does not signal easier enforcement. It signals fragmentation.

For compliance professionals, 2026 presents a uniquely challenging environment — not due to stricter rules, but diverging ones. Multiple jurisdictions are moving in different directions simultaneously.

FATF’s Fifth Round: Redefining Risk-Based Compliance

The February 2025 FATF Standards revision introduced a critical shift: replacing “commensurate” with “proportionate” as the governing standard for AML controls.

This distinction carries operational weight.

Under the previous framework, institutions often defaulted to maximum-friction controls across all client segments to avoid regulatory criticism. The revised standard explicitly rejects this approach. Controls must now reflect the character of the risk, not simply its scale.

Excessive due diligence on demonstrably low-risk clients no longer constitutes prudent compliance. Under the new methodology, it represents misallocation of finite compliance resources away from genuine threats.

Operational Implications:

• Simplified Due Diligence pathways become viable for qualifying low-risk segments, improving onboarding efficiency

• Experienced analysts can be redeployed from routine monitoring to complex case investigations

• The explicit protection against de-risking enables institutions to serve previously excluded populations through calibrated controls

Risk Considerations:

• Jurisdictions with identified gaps face a compressed three-year remediation window before potential public escalation

• DNFBPs, including legal, accounting, and real estate professionals now undergo independent effectiveness assessments, elevating third-party risk management requirements

• Beneficial ownership verification standards have tightened. Systems must actively identify discrepancies, not merely archive submitted data

Anti-Corruption Enforcement: Divergent Trajectories

U.S. enforcement priorities have narrowed considerably. Following a February 2025 executive order pausing FCPA enforcement, the DOJ resumed activity in June with revised guidelines. Investigations now prioritise conduct affecting “U.S. national interests” — cartels, transnational criminal organisations, and threats to critical infrastructure. Approximately half of pre-existing investigations were discontinued.

The UK has moved in the opposite direction. The “failure to prevent fraud” offence, effective September 2025, expands corporate liability for economic crimes, placing greater accountability on organisations for inadequate preventive controls.

APAC Focus: Malaysia’s Enforcement Acceleration

While U.S. enforcement contracts, Malaysia’s Anti-Corruption Commission (MACC) has demonstrated what aggressive regional enforcement looks like.

2025 enforcement outcomes:

• RM8.4 billion in assets seized, frozen, and forfeited (as of November 2025)

• 1,128 arrests; 445 charges filed; 189 convictions secured

• Targeted operations across banking (Ops Tiger: 49 officers charged), immigration (Ops Rentas: 27 arrests, including 18 enforcement personnel), and military procurement

• Investigation of former Prime Minister Ismail Sabri Yaakob; RM169 million in cash and 16kg of gold bars subsequently forfeited to the government

MACC’s 2026 priorities include expanded use of AI and data analytics for pattern detection and financial flow analysis.

For organisations with Malaysian operations, these developments represent immediate operational considerations.

Strategic Assessment

Regulatory frameworks have not weakened. They have dispersed.

Enforcement gaps between jurisdictions create space for corrupt practices to persist. The relevant question is no longer whether an organisation meets a single jurisdiction’s requirements, it is whether the compliance framework demonstrates resilience across multiple, often conflicting, regulatory environments.

The Fifth Round methodology explicitly penalises checkbox compliance. It rewards demonstrated effectiveness.

Proportionality-based frameworks enable organisations to shift from defensive postures to dynamic risk management, reducing friction where evidence supports lower risk, concentrating resources where threats are substantiated.

This represents both a regulatory mandate and a competitive opportunity.

Julia Chin, 2026

 

Table of Contents

More Insights

6 min read
29 min read