New rules on supervision, anti-money laundering and sanctions
BaFin, the EBA and the ECB keep publishing new circulars and guidelines, and the EU Official Journal new sanctions regulations. COBACK reads these publications, checks them against your institution and turns a relevant change into tasks for the department in charge.

Topics and rules
What is changing, who in the company works with it and which legal acts are behind it.
Prudential supervision and risk management
CRR III and CRD VI implement the final Basel III reforms in the EU, including new approaches to credit and operational risk and the output floor. In Germany, BaFin sets out risk management requirements in the MaRisk. The revision of 30 June 2026 is more principles-based and brings further relief for small and very small institutions. Risk control, regulatory reporting, treasury and the management board are affected.
Examples
- Regulation (EU) 2024/1623 (CRR III)
- Directive (EU) 2024/1619 (CRD VI)
- German Banking Act (KWG)
- MaRisk, BaFin Circular 06/2026 (BA)
Digital operational resilience
DORA has applied since 17 January 2025. It requires ICT risk management, reporting of major ICT-related incidents, digital operational resilience testing and a register of information on all contractual arrangements with ICT third-party service providers. BaFin repeals the BAIT in full at the end of 31 December 2026. IT, information security, outsourcing management and procurement are affected.
Examples
- Regulation (EU) 2022/2554 (DORA)
- List of critical ICT third-party providers, European Supervisory Authorities, 18 November 2025
Anti-money laundering
The EU Anti-Money Laundering Regulation (AMLR) applies directly from 10 July 2027 and makes customer due diligence rules uniform across the EU. Until then, due diligence follows the German Money Laundering Act. The new EU authority AMLA in Frankfurt am Main selects forty obliged entities active in several member states in 2027 and is to supervise them directly from 2028. Money laundering reporting officers, client onboarding and transaction monitoring are affected.
Examples
- Regulation (EU) 2024/1624 (AMLR)
- Regulation (EU) 2024/1620 (AMLA Regulation)
- German Money Laundering Act (GwG)
- Transfer of Funds Regulation (EU) 2023/1113
Sanctions and embargoes
The EU extends its Russia sanctions package by package. Since the 18th package of July 2025, the listed Russian banks have been subject to a full transaction ban, and the same package put two Chinese banks under a transaction ban for helping to circumvent the sanctions. Since February 2026, more sanctions breaches are criminal offences in Germany and the maximum fine for companies acting intentionally has risen from EUR 10 million to EUR 40 million. Sanctions compliance, payments and trade finance are affected. International business adds the US and UK sanctions lists.
Examples
- Council Regulation (EU) No 833/2014
- Council Regulation (EU) No 269/2014
- German Foreign Trade and Payments Act (AWG)
- OFAC Specially Designated Nationals List (US)
Payments and consumer credit
Since 9 October 2025, payment service providers in the euro area must be able to send instant credit transfers and must offer payers a check of the payee's name against the IBAN before a transfer is authorised. The new Consumer Credit Directive applies from 20 November 2026. For the first time it covers interest-free and short-term credit and loans under EUR 200, which brings many buy now, pay later models into scope. Payments, lending and product management are affected.
Examples
- Regulation (EU) 2024/886 (Instant Payments Regulation)
- Consumer Credit Directive (EU) 2023/2225
- Payment Services Directive (EU) 2015/2366 (PSD2)
Securities and crypto-assets
MiFID II and the Market Abuse Regulation govern investment advice, product governance, the handling of inside information and the reporting of suspicious orders and transactions. Crypto-asset services have been subject to MiCAR since December 2024. The retail investment strategy, on which the Council and Parliament reached political agreement in December 2025, is set to amend MiFID II and the PRIIPs Regulation again. Distribution and securities compliance are affected.
Examples
- Directive 2014/65/EU (MiFID II)
- Market Abuse Regulation (EU) No 596/2014
- Regulation (EU) 2023/1114 (MiCAR)
AI in lending
The AI Act classifies AI systems used to evaluate the creditworthiness of natural persons or establish their credit score as high-risk. Systems used to detect financial fraud are excluded. Under amending Regulation (EU) 2026/1744, the obligations for these systems apply from 2 December 2027. Credit risk, model validation, IT and data protection are affected.
Examples
- AI Act (EU) 2024/1689, Annex III point 5(b)
- Regulation (EU) 2026/1744
The path of a change
Example: a new sanctions package
01Law database
The EU Official Journal publishes an amendment to Regulation (EU) No 833/2014 that puts further banks under a transaction ban, including banks in third countries. COBACK picks it up in its daily run.
02Relevance
COBACK checks it against the digital twin: your institution handles foreign payments and letters of credit. The score is 91 out of 100, with the reasoning, the articles cited and the company facts used.
03Open questions
Whether there are correspondent relationships with any of the newly listed banks is not in the twin, so COBACK asks instead of guessing. The head of sanctions compliance answers and marks the change as relevant.
04Task
Tasks with owners and deadlines follow: sanctions compliance reviews the screening filters by 1 October 2026. Trade finance goes through the open letters of credit and guarantees within 5 days and the organisation department updates the payments work instruction within 2 weeks.
Working with COBACK
Supervision, AML and sanctions in one place
COBACK reads new publications from BaFin, the EBA and the ECB every day, along with the EU Official Journal, the sanctions lists of the EU and the United Nations and the US Treasury's OFAC sanctions notices in the Federal Register.
A score with its reasoning
Every publication gets a score from 0 to 100 with the reasoning, the sources it relied on and the facts about your institution it used.
Questions instead of assumptions
Where a fact is missing, such as a business line or a subsidiary, COBACK asks. A person at your institution decides whether a change is relevant.
Tasks for the right department
A relevant change becomes tasks with steps, owners and deadlines, for example for regulatory reporting, the money laundering reporting officer or payments.
Frequently asked questions
Does COBACK replace our sanctions screening?
No. COBACK does not screen customers or payments against lists. It reads new sanctions acts and list changes and shows which of them affect your business lines, entities and locations, and what needs to be done.
How does COBACK know our institution?
From its digital twin, which is filled from connected systems such as SharePoint, Confluence or Google Drive, public registers such as GLEIF, your website and a questionnaire. Nobody has to upload files by hand.
Does COBACK decide whether a rule applies to us?
No. COBACK scores, gives its reasoning and names its sources. A person at your institution makes the decision, and COBACK does not give legal advice.
Does COBACK cover rules outside the EU?
Yes. Besides the EU and Germany, COBACK reads publications from other European countries such as the United Kingdom, from the Americas, from Asia and from international bodies. Changes that affect your business there go through the same checks.










