The 2026 Compliance Landscape (Part 2 of 3)
2026 is the year fraud prevention transitioned from operational priority to liability exposure.
For context on the regulatory shifts driving this change, see Part 1.
1. The Global Recalibration of Fraud Liability
2026 marks a fundamental shift in accountability when fraud succeeds.
The UK established the precedent with mandatory APP fraud reimbursement rules, now operational for over a year. Results have been significant: 86% of stolen funds returned to victims, compared to 68% previously. Liability now splits equally between sending and receiving payment service providers — a structural change that distributes fraud prevention responsibility across the payment chain.
Europe is advancing similar measures. PSD3, anticipated for finalisation this year, extends liability beyond traditional financial institutions to include telecommunications providers and online platforms under a shared liability framework. Platforms that fail to remove fraudulent content may bear financial responsibility for resulting losses.
In the United States, the Protecting Consumers from Payment Scams Act proposes amendments to the Electronic Fund Transfer Act, introducing bank liability for transfers induced through fraud.
Operational Implications:
• Fraud Prevention as Financial Risk Management: Detection and intervention capabilities directly affect reimbursement exposure. Investment in these systems is no longer discretionary.
• Cross-Sector Coordination: PSD3’s shared liability model necessitates information-sharing mechanisms between banks, telecoms, and platforms. Early movers will influence emerging standards.
• Aligned Incentives: The UK’s 86% reimbursement rate demonstrates that consumer protection and institutional risk management can reinforce each other.
Risk Considerations:
• Receiving Institution Exposure: Equal liability distribution means mule account detection capabilities now carry direct financial consequences.
• The Corruption Intersection: Fraud infrastructure frequently overlaps with corruption channels. Shell companies used to layer bribe payments also receive scam proceeds. Weak KYC processes that enable corrupt PEPs to move funds simultaneously facilitate fraud cash-out operations. Strengthening fraud prevention infrastructure closes pathways that corruption exploits.
2. Stablecoin Regulation Advances
While central bank digital currencies remain developmental across most jurisdictions, stablecoins have become the immediate regulatory priority.
The United States enacted the GENIUS Act, establishing the first federal framework for digital asset regulation. This formalises stablecoins as recognised financial instruments while introducing corresponding compliance obligations.
The Corruption Dimension:
Stablecoins have emerged as preferred instruments for cross-border illicit fund movement, including bribe payments and corruption proceeds. Venezuela’s sanctioned oil company accepting USDT to circumvent traditional banking channels illustrates the pattern. The characteristics that make stablecoins attractive for legitimate purposes — speed, low cost, borderless transfers — equally serve those seeking to evade controls.
Operational Implications:
• Early Infrastructure Development: Organisations building compliant stablecoin capabilities now position themselves advantageously as regulatory frameworks mature.
• Financial Inclusion Applications: Stablecoins offer genuine potential for cost-effective remittances and cross-border payments when compliance infrastructure is proportionate to risk. This aligns with FATF’s proportionality mandate: applying high-friction controls to low-risk transactions now constitutes a technical compliance failure.
Risk Considerations:
• Transaction Monitoring Limitations: Legacy monitoring systems were not designed for on-chain activity. Detecting corruption-related flows requires new capabilities — wallet clustering, chain analytics, and understanding of mixing services and privacy-enhancing technologies.
• Jurisdictional Fragmentation: The GENIUS Act governs U.S. operations. MiCA applies in Europe. Asia remains inconsistent. Organisations operating across regions must navigate evolving requirements around reserves, disclosures, and AML obligations.
• Stability Risk: Not all stablecoins carry equivalent risk profiles. Consumer protection requires understanding distinctions between fully-reserved, algorithmic, and partially-backed instruments. The TerraUSD collapse remains instructive.
3. ESG Regulatory Divergence
Environmental, social, and governance requirements have entered a period of significant fragmentation.
The United States has reduced federal ESG mandates while California and the European Union expand requirements. This creates compliance complexity for organisations operating across jurisdictions.
Governance — the “G” in ESG — is where corruption resides. Regulatory divergence creates tangible risk: organisations may deprioritise anti-corruption governance in jurisdictions with softened ESG mandates, only to face reputational and legal consequences when gaps surface.
Operational Implications:
• Governance as Differentiation: While competitors default to regulatory minimums, organisations maintaining robust anti-corruption governance strengthen their position for cross-border operations, investor confidence, and regulatory resilience.
• Integrated Reporting Frameworks: Organisations building unified ESG and financial crime reporting systems now avoid duplicative efforts as requirements eventually converge.
Risk Considerations:
• Regulatory Arbitrage Temptation: Absence of global alignment creates incentives to meet only minimum requirements per jurisdiction. However, ethical standards — not the lowest regulatory threshold — should establish the baseline. Reputational risk does not respect jurisdictional boundaries.
• Supply Chain Opacity: ESG due diligence increasingly extends to third parties and supply chains. The same opacity enabling environmental and labour violations often enables corruption. Visibility into extended networks is essential.
• ESG Misrepresentation as Financial Crime: False ESG claims constitute more than marketing failures — they can constitute fraud. Where fraud exists, corruption frequently follows. The intersection of ESG misrepresentation and financial crime represents an emerging enforcement focus.
Strategic Assessment
The common element across fraud liability, stablecoin regulation, and ESG divergence: liability is expanding, accountability is shifting, and inaction costs are increasing.
Part 1 examined enforcement fragmentation — U.S. FCPA priorities narrowing while Malaysia’s MACC seized RM8.4 billion and the UK expanded corporate liability through “failure to prevent fraud” provisions.
Part 2 demonstrates where fragmented enforcement meets operational reality: in fraud reimbursements, stablecoin processing, and governance gaps.
The liability evolution extends beyond victim reimbursement. It concerns building systems sufficiently robust to resist the full spectrum of financial crime.
The trajectory is evident. Organisations waiting for enforcement to materialise will find themselves exposed. Those building robust, integrated frameworks now will be positioned accordingly.
The relevant question is not whether an organisation complies with a single jurisdiction. It is whether the framework demonstrates resilience across all of them.