Skip to main content

New rules on supervision, anti-money laundering and sanctions

BaFin, the EBA and the ECB keep publishing new circulars and guidelines, and the EU Official Journal new sanctions regulations. COBACK reads these publications, checks them against your institution and turns a relevant change into tasks for the department in charge.

Looking up a gold-tinted glass office tower into a cloudy sky

Topics and rules

What is changing, who in the company works with it and which legal acts are behind it.

  • Prudential supervision and risk management

    CRR III and CRD VI implement the final Basel III reforms in the EU, including new approaches to credit and operational risk and the output floor. In Germany, BaFin sets out risk management requirements in the MaRisk. The revision of 30 June 2026 is more principles-based and brings further relief for small and very small institutions. Risk control, regulatory reporting, treasury and the management board are affected.

    Examples

    • Regulation (EU) 2024/1623 (CRR III)
    • Directive (EU) 2024/1619 (CRD VI)
    • German Banking Act (KWG)
    • MaRisk, BaFin Circular 06/2026 (BA)
  • Digital operational resilience

    DORA has applied since 17 January 2025. It requires ICT risk management, reporting of major ICT-related incidents, digital operational resilience testing and a register of information on all contractual arrangements with ICT third-party service providers. BaFin repeals the BAIT in full at the end of 31 December 2026. IT, information security, outsourcing management and procurement are affected.

    Examples

    • Regulation (EU) 2022/2554 (DORA)
    • List of critical ICT third-party providers, European Supervisory Authorities, 18 November 2025
  • Anti-money laundering

    The EU Anti-Money Laundering Regulation (AMLR) applies directly from 10 July 2027 and makes customer due diligence rules uniform across the EU. Until then, due diligence follows the German Money Laundering Act. The new EU authority AMLA in Frankfurt am Main selects forty obliged entities active in several member states in 2027 and is to supervise them directly from 2028. Money laundering reporting officers, client onboarding and transaction monitoring are affected.

    Examples

    • Regulation (EU) 2024/1624 (AMLR)
    • Regulation (EU) 2024/1620 (AMLA Regulation)
    • German Money Laundering Act (GwG)
    • Transfer of Funds Regulation (EU) 2023/1113
  • Sanctions and embargoes

    The EU extends its Russia sanctions package by package. Since the 18th package of July 2025, the listed Russian banks have been subject to a full transaction ban, and the same package put two Chinese banks under a transaction ban for helping to circumvent the sanctions. Since February 2026, more sanctions breaches are criminal offences in Germany and the maximum fine for companies acting intentionally has risen from EUR 10 million to EUR 40 million. Sanctions compliance, payments and trade finance are affected. International business adds the US and UK sanctions lists.

    Examples

    • Council Regulation (EU) No 833/2014
    • Council Regulation (EU) No 269/2014
    • German Foreign Trade and Payments Act (AWG)
    • OFAC Specially Designated Nationals List (US)
  • Payments and consumer credit

    Since 9 October 2025, payment service providers in the euro area must be able to send instant credit transfers and must offer payers a check of the payee's name against the IBAN before a transfer is authorised. The new Consumer Credit Directive applies from 20 November 2026. For the first time it covers interest-free and short-term credit and loans under EUR 200, which brings many buy now, pay later models into scope. Payments, lending and product management are affected.

    Examples

    • Regulation (EU) 2024/886 (Instant Payments Regulation)
    • Consumer Credit Directive (EU) 2023/2225
    • Payment Services Directive (EU) 2015/2366 (PSD2)
  • Securities and crypto-assets

    MiFID II and the Market Abuse Regulation govern investment advice, product governance, the handling of inside information and the reporting of suspicious orders and transactions. Crypto-asset services have been subject to MiCAR since December 2024. The retail investment strategy, on which the Council and Parliament reached political agreement in December 2025, is set to amend MiFID II and the PRIIPs Regulation again. Distribution and securities compliance are affected.

    Examples

    • Directive 2014/65/EU (MiFID II)
    • Market Abuse Regulation (EU) No 596/2014
    • Regulation (EU) 2023/1114 (MiCAR)
  • AI in lending

    The AI Act classifies AI systems used to evaluate the creditworthiness of natural persons or establish their credit score as high-risk. Systems used to detect financial fraud are excluded. Under amending Regulation (EU) 2026/1744, the obligations for these systems apply from 2 December 2027. Credit risk, model validation, IT and data protection are affected.

    Examples

    • AI Act (EU) 2024/1689, Annex III point 5(b)
    • Regulation (EU) 2026/1744

The path of a change

Example: a new sanctions package

  1. 01Law database

    The EU Official Journal publishes an amendment to Regulation (EU) No 833/2014 that puts further banks under a transaction ban, including banks in third countries. COBACK picks it up in its daily run.

  2. 02Relevance

    COBACK checks it against the digital twin: your institution handles foreign payments and letters of credit. The score is 91 out of 100, with the reasoning, the articles cited and the company facts used.

  3. 03Open questions

    Whether there are correspondent relationships with any of the newly listed banks is not in the twin, so COBACK asks instead of guessing. The head of sanctions compliance answers and marks the change as relevant.

  4. 04Task

    Tasks with owners and deadlines follow: sanctions compliance reviews the screening filters by 1 October 2026. Trade finance goes through the open letters of credit and guarantees within 5 days and the organisation department updates the payments work instruction within 2 weeks.

Working with COBACK

  • Supervision, AML and sanctions in one place

    COBACK reads new publications from BaFin, the EBA and the ECB every day, along with the EU Official Journal, the sanctions lists of the EU and the United Nations and the US Treasury's OFAC sanctions notices in the Federal Register.

  • A score with its reasoning

    Every publication gets a score from 0 to 100 with the reasoning, the sources it relied on and the facts about your institution it used.

  • Questions instead of assumptions

    Where a fact is missing, such as a business line or a subsidiary, COBACK asks. A person at your institution decides whether a change is relevant.

  • Tasks for the right department

    A relevant change becomes tasks with steps, owners and deadlines, for example for regulatory reporting, the money laundering reporting officer or payments.

Frequently asked questions

Does COBACK replace our sanctions screening?

No. COBACK does not screen customers or payments against lists. It reads new sanctions acts and list changes and shows which of them affect your business lines, entities and locations, and what needs to be done.

How does COBACK know our institution?

From its digital twin, which is filled from connected systems such as SharePoint, Confluence or Google Drive, public registers such as GLEIF, your website and a questionnaire. Nobody has to upload files by hand.

Does COBACK decide whether a rule applies to us?

No. COBACK scores, gives its reasoning and names its sources. A person at your institution makes the decision, and COBACK does not give legal advice.

Does COBACK cover rules outside the EU?

Yes. Besides the EU and Germany, COBACK reads publications from other European countries such as the United Kingdom, from the Americas, from Asia and from international bodies. Changes that affect your business there go through the same checks.