Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
FinCEN issued an amendment to its June 30, 2025 special-measure order (90 FR 27770) that had prohibited US covered financial institutions from transmitting funds to or from CIBanco S.A., a Mexican multiple-banking institution previously designated as of primary money-laundering concern in connection with illicit-opioid trafficking. Effective April 16, 2026, the amendment authorizes transmittals of funds ordinarily incident and necessary for the Government of Mexico to liquidate CIBanco. The carve-out is narrow: the broader §2313a prohibition on US-side correspondent activity with CIBanco remains in force outside the liquidation channel.
FinCEN issued a Geographic Targeting Order (GTO) under 31 U.S.C. § 5326 requiring banks and money transmitters located in Hennepin and Ramsey Counties, Minnesota (i.e., Minneapolis–St. Paul metro) to file reports with FinCEN on transactions of $3,000 or more where the beneficiary is located outside the United States. The order is effective February 12, 2026 through August 10, 2026 and is paired with a parallel Treasury/IRS audit and enforcement push targeting alleged government-benefits fraud (notably the federal child-nutrition program rings under prosecution in Minnesota since 2022). It is the second high-profile FinCEN GTO of the Trump 2.0 administration after the Southwest-border MSB GTO.
On 18 November 2025, the European Supervisory Authorities (EBA, ESMA, and EIOPA) jointly designated 19 Critical ICT Third-Party Providers (CTPPs) under DORA Article 31, with immediate effect — the first-ever exercise of direct EU financial-regulator supervision over hyperscale cloud and infrastructure providers. The designated entities include Amazon Web Services, Microsoft Azure, Google Cloud, Deutsche Telekom, Oracle, SAP, IBM, Bloomberg LP, London Stock Exchange Group (LSEG), Tata Consultancy Services, and Orange, among others. Designation triggers direct oversight by a lead ESA (EBA for banking-critical, ESMA for capital-markets-critical, EIOPA for insurance-critical) via Joint Examination Teams (JETs), with powers to conduct investigations, carry out on-site inspections, and impose fines of up to 1% of average daily worldwide turnover per day for non-compliance.
FinCEN issued a final rule under Section 311 of the USA PATRIOT Act (31 U.S.C. § 5318A) prohibiting US covered financial institutions from opening or maintaining a correspondent account for, or on behalf of, Cambodia-based Huione Group, a foreign financial institution found to be of primary money-laundering concern. Treasury determined that Huione Group and its subsidiaries — including Haowang Guarantee, Huione Pay PLC, and Huione Crypto — laundered at least $4 billion of illicit proceeds between August 2021 and January 2025, including funds tied to North Korean cyber-heist actors and Southeast Asian "pig-butchering" investment-scam compounds. The rule also imposes a special-due-diligence requirement on US covered institutions to guard against indirect access via foreign correspondent accounts. Effective November 17, 2025.
Presidential Decree No. 693 of 30 September 2025 ("On certain particularities of the sale of property held in federal ownership"), signed by Vladimir Putin and entered into force on the day of its official publication, creates an accelerated pathway for disposing of federally-owned property in cases determined by a separate decision of the President, where the goal is to ensure the Russian Federation's defence capability and security. Market valuation and the appraisal report must be completed within 10 business days of signing the appraisal contract; PSB Bank JSC (formerly Promsvyazbank, the state-controlled defence-procurement bank) is designated as the sale-organising agent and seller-on-behalf-of-the-state. The Decree also authorises the President to set special features of how Russian legislation on privatisation, joint-stock companies, limited-liability companies, the securities market, banks and competition protection applies to such sales. Expressly framed as a counter-measure to "unfriendly" actions by the United States and its allies; structurally the disposal-mechanism complement to the foreign-asset external- administration and seizure decrees (95/322/520/442) — the fast-track liquidation channel that converts seized or nationalised assets into state-budget cash for defence purposes.
FinCEN published an order amending the three June 25, 2025 special-measure orders (as previously amended by the July 11, 2025 order, FR doc 2025-12973) prohibiting US covered financial institutions from transmitting funds to or from CIBanco S.A., Intercam Banco S.A., and Vector Casa de Bolsa, S.A. de C.V. — three Mexican institutions designated of primary money-laundering concern in connection with illicit-opioid trafficking under Section 2313a of the Fiscal Year 2024 NDAA. The amendment extends the effective date of all three prohibitions from September 4, 2025 to October 20, 2025, granting US covered institutions an additional ~46 days to wind down correspondent exposures. The underlying primary-money-laundering-concern findings remain intact — only the implementation deadline shifts.
Czech Republic's first standalone federal statute on the resilience of critical-infrastructure entities — Act No. 266/2025 Sb., "Zákon o odolnosti subjektů kritické infrastruktury a o změně souvisejících zákonů" (Critical Infrastructure Act). Transposes EU Directive 2022/2557 (CER Directive on the resilience of critical entities) into Czech law and removes critical-infrastructure regulation from the earlier crisis-management law (Zákon č. 240/2000 Sb.) into a dedicated statute. Covers the 11 CER-Directive sectors (energy, transport, banking, financial-market infrastructure, health, drinking water, wastewater, digital infrastructure, public administration, space, food production-processing-distribution) and obligates designated operators of essential services to conduct risk analyses, implement technical/organisational resilience measures, report incidents to sector-competent authorities, and submit to inspection. Published in the Sbírka zákonů on 4 August 2025; in force 19 August 2025; operator information-obligation deadline 1 March 2026.
The Joint Committee of the European Supervisory Authorities (EBA, EIOPA, ESMA) published the Guide on DORA Oversight Activities (JC 2025 29) on 15 July 2025, the definitive operational description of how the ESAs will supervise Critical ICT Third-Party Providers (CTPPs) designated under DORA Art. 31. The guide establishes the governance of Joint Examination Teams (JETs), the oversight examination lifecycle (planning, risk assessment, binding recommendations, follow-up), penalty processes of up to 1% of average daily worldwide turnover per day of breach (DORA Art. 35(6)), and lead-overseer assignments (EBA for banking, ESMA for capital markets, EIOPA for insurance). It is authoritative ESA interpretive guidance, not legally binding per se, but constitutes the supervisory playbook CTPPs and their dependent financial entities must plan against.
FinCEN published an order amending the three June 25, 2025 special-measure orders (FR docs 2025-11991, 2025-11993, 2025-11990; 90 FR 27770 et seq.) prohibiting US covered financial institutions from transmitting funds to or from CIBanco S.A., Intercam Banco S.A., and Vector Casa de Bolsa, S.A. de C.V. — three Mexican institutions designated of primary money-laundering concern in connection with illicit-opioid trafficking under Section 2313a of the Fiscal Year 2024 NDAA. This first extension shifts the effective date of all three prohibitions from July 21, 2025 to September 4, 2025 (a 45-day delay), giving US covered institutions additional time to wind down correspondent exposures. The underlying primary-money-laundering- concern findings remain unchanged — only the implementation deadline shifts.
On 26 June 2025, the Governing Board of Mexico's National Banking and Securities Commission (CNBV), invoking Article 129 of the Ley de Instituciones de Crédito, decreed the temporary managerial intervention of CI Banco, S.A. and Intercam Banco, S.A., replacing their administrative bodies and legal representatives. The measure came one day after the US Treasury's FinCEN designated both institutions (along with Vector Casa de Bolsa) as foreign financial institutions of primary money-laundering concern tied to opioid-trafficking networks, and prohibited certain US fund transmittals to them. CNBV/SHCP framed the intervention as a depositor- and creditor-protection measure to safeguard the two banks' operations against the fallout of the US action; Vector Casa de Bolsa was not included in the CNBV intervention.
Bangladesh Bank's Foreign Exchange Policy Department issued Circular No. 14 of 20 April 2025, amending paragraph 26, Chapter 7 of the Guidelines for Foreign Exchange Transactions, 2018 (GFET-2018) to liberalise import-LC discrepancy-handling procedures. Authorised Dealers (AD banks) may now settle discrepant import bills against importer-issued indemnity-and-waiver letters without prior Bangladesh Bank approval, provided discrepancies do not contravene UCP-600 or constitute material changes as defined in GFET-2018 para 31(c). The same treatment is extended to back-to-back import LCs under the export-oriented bonded-warehouse and EPZ regime, directly benefiting Bangladesh's garment-manufacturing sector in settling raw-material import payments against export-LC proceeds.
On 11 April 2025 President Javier Milei signed Decreto de Necesidad y Urgencia 269/2025, published in the Boletín Oficial on 14 April 2025 (edición Nº 35.647). The decree repealed Decreto 28/2023, formally lifting the cepo cambiario — the foreign-exchange restrictions that had been in continuous operation in some form since November 2011. Operative provisions include elimination of the 80/20 export-proceeds-channelling mandate, removal of individual USD purchase and wire-transfer caps, permission for companies to repatriate post-1-January-2025 dividend profits, and replacement of the daily crawling-peg with a band float within a $1,000–$1,400 ARS/USD corridor with BCRA floor/ceiling intervention rules. The measure was coordinated with the IMF Extended Fund Facility (USD 20bn total; USD 15bn 2025 free-availability tranche) approved 11 April 2025, and operationalises the currency-stability guarantee embedded in the RIGI large- investment regime (Law 27.742, July 2024).
Commission Delegated Regulation (EU) 2025/532, adopted 24 March 2025 and published in the Official Journal on 2 July 2025, supplements DORA (Regulation (EU) 2022/2554) with binding Regulatory Technical Standards governing ICT subcontracting of critical or important functions. It requires all EU-regulated financial entities to establish a subcontracting policy, conduct due-diligence and concentration-risk assessments at each tier of the ICT supply chain (including nth-party providers), impose equivalent resilience standards on sub-ICT-providers, and maintain enforceable termination and information-access rights. The RTS entered into force on 22 July 2025, completing the second-batch DORA implementing acts on outsourcing chains.
The Ethiopian Capital Market Authority (ECMA) issued Directive No. 1009/2024 on 16 July 2024, establishing the comprehensive licensing, operational, and supervisory framework for securities exchanges, derivatives exchanges, and the over-the-counter (OTC) market under the authority of Article 108 of the Capital Market Proclamation No. 1248/2021. The directive consolidates Ethiopia's previously fragmented securities-trading architecture into a single, licensed, and regulated market structure and provided the statutory pathway for the Ethiopian Securities Exchange (ESX) to receive the country's first securities-exchange licence. This is the first capital-markets architecture filing for Ethiopia on the IPTM register, forming the operating- licence layer alongside the banking-sector liberalisation enacted under Proclamation 1360/2025.
FinCEN issued a final rule under Section 311 of the USA PATRIOT Act (31 U.S.C. § 5318A) prohibiting US covered financial institutions from opening or maintaining a correspondent account for, or on behalf of, Iraq-based Al-Huda Bank, a foreign financial institution found to be of primary money-laundering concern. Treasury determined that Al-Huda Bank exploited its access to US dollars to support designated Foreign Terrorist Organizations including Iran's Islamic Revolutionary Guard Corps (IRGC) and IRGC-Quds Force, as well as Iran-aligned Iraqi militias Kata'ib Hizballah and Asa'ib Ahl al-Haq. The rule also imposes a special-due-diligence requirement on US covered institutions to guard against indirect access via foreign correspondent accounts. Published in the Federal Register on July 3, 2024; effective August 2, 2024.
Three Commission Delegated Regulations (CDR 2024/1772, 1773, 1774) adopted 13 March 2024 and published in the EU Official Journal on 25 June 2024 constitute the first batch of binding Level 2 implementing rules under DORA (Regulation (EU) 2022/2554). CDR 2024/1772 sets ICT incident classification criteria and materiality thresholds for mandatory reporting; CDR 2024/1773 specifies the required content of contractual policies for ICT third-party services supporting critical or important functions; CDR 2024/1774 defines the ICT risk management tools, methods, processes, and policies — including a simplified framework for smaller in-scope entities. All three apply from 17 January 2025 alongside the parent DORA regulation, covering approximately 22,000 EU regulated financial entities.
Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities, published OJ L 333, 27 December 2022, entered into force 16 January 2023, with Member State transposition deadline 17 October 2024 (rules applicable from 18 October 2024). The CER Directive repeals Council Directive 2008/114/EC on European Critical Infrastructures, extending the scope from two sectors (energy, transport) to eleven essential-service sectors: energy, transport, banking, financial market infrastructures, health, drinking water, wastewater, digital infrastructure, public administration, space, and food. Member States must adopt national resilience strategies, conduct risk assessments at least every four years, identify "critical entities" providing essential services whose disruption would have significant cross-border impacts, and ensure those entities implement technical, security, and organisational resilience measures, business-continuity plans, incident-reporting obligations, and personnel-security background checks. The CER Directive is the physical and hybrid resilience twin to the NIS2 Directive (2022/2555) — the two instruments form the binding EU critical-infrastructure-protection architecture replacing the 2008/114/EC regime.
Regulation (EU) 2022/2554 (Digital Operational Resilience Act, DORA) is the EU's first horizontal cyber- and ICT-resilience instrument for the financial sector. Adopted 14 December 2022 and published in the Official Journal on 27 December 2022, it entered into force on 16 January 2023 and applies from 17 January 2025. DORA covers approximately 22,000 EU regulated financial entities across ~20 entity types (credit institutions, insurers, investment firms, CCPs, trading venues, crypto-asset service providers, etc.) under five pillars: ICT risk management, ICT-incident reporting, digital operational resilience testing (including threat-led penetration testing for significant entities), ICT third-party risk management, and information sharing. Structurally novel, DORA establishes the Critical ICT Third-Party Provider (CTPP) oversight regime under which the European Supervisory Authorities (EBA, ESMA, EIOPA) acquire direct supervisory powers over hyperscale cloud providers (AWS, Azure, GCP, Oracle) servicing EU financial entities — the first EU mechanism for ESA direct oversight of non-financial cloud providers.
Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive), published OJ L 333, 27 December 2022, entered into force 16 January 2023. NIS2 repeals and substantially expands the 2016 NIS1 Directive (2016/1148), extending the scope from ~7 sectors to 18 enumerated essential and important sectors, imposing binding cybersecurity risk- management and incident-reporting obligations on covered entities, introducing board-level management accountability, and mandating Member State transposition by 17 October 2024. NIS2 is the structural EU statutory anchor for national cybersecurity frameworks across the bloc, operating alongside DORA (Reg 2022/2554) for financial-sector digital resilience and CRA (Reg 2024/2847) for product cybersecurity.