Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
On 18 November 2025, the European Supervisory Authorities (EBA, ESMA, and EIOPA) jointly designated 19 Critical ICT Third-Party Providers (CTPPs) under DORA Article 31, with immediate effect — the first-ever exercise of direct EU financial-regulator supervision over hyperscale cloud and infrastructure providers. The designated entities include Amazon Web Services, Microsoft Azure, Google Cloud, Deutsche Telekom, Oracle, SAP, IBM, Bloomberg LP, London Stock Exchange Group (LSEG), Tata Consultancy Services, and Orange, among others. Designation triggers direct oversight by a lead ESA (EBA for banking-critical, ESMA for capital-markets-critical, EIOPA for insurance-critical) via Joint Examination Teams (JETs), with powers to conduct investigations, carry out on-site inspections, and impose fines of up to 1% of average daily worldwide turnover per day for non-compliance.
FinCEN issued a final rule under Section 311 of the USA PATRIOT Act (31 U.S.C. § 5318A) prohibiting US covered financial institutions from opening or maintaining a correspondent account for, or on behalf of, Cambodia-based Huione Group, a foreign financial institution found to be of primary money-laundering concern. Treasury determined that Huione Group and its subsidiaries — including Haowang Guarantee, Huione Pay PLC, and Huione Crypto — laundered at least $4 billion of illicit proceeds between August 2021 and January 2025, including funds tied to North Korean cyber-heist actors and Southeast Asian "pig-butchering" investment-scam compounds. The rule also imposes a special-due-diligence requirement on US covered institutions to guard against indirect access via foreign correspondent accounts. Effective November 17, 2025.
Presidential Decree No. 693 of 30 September 2025 ("On certain particularities of the sale of property held in federal ownership"), signed by Vladimir Putin and entered into force on the day of its official publication, creates an accelerated pathway for disposing of federally-owned property in cases determined by a separate decision of the President, where the goal is to ensure the Russian Federation's defence capability and security. Market valuation and the appraisal report must be completed within 10 business days of signing the appraisal contract; PSB Bank JSC (formerly Promsvyazbank, the state-controlled defence-procurement bank) is designated as the sale-organising agent and seller-on-behalf-of-the-state. The Decree also authorises the President to set special features of how Russian legislation on privatisation, joint-stock companies, limited-liability companies, the securities market, banks and competition protection applies to such sales. Expressly framed as a counter-measure to "unfriendly" actions by the United States and its allies; structurally the disposal-mechanism complement to the foreign-asset external- administration and seizure decrees (95/322/520/442) — the fast-track liquidation channel that converts seized or nationalised assets into state-budget cash for defence purposes.
Czech Republic's first standalone federal statute on the resilience of critical-infrastructure entities — Act No. 266/2025 Sb., "Zákon o odolnosti subjektů kritické infrastruktury a o změně souvisejících zákonů" (Critical Infrastructure Act). Transposes EU Directive 2022/2557 (CER Directive on the resilience of critical entities) into Czech law and removes critical-infrastructure regulation from the earlier crisis-management law (Zákon č. 240/2000 Sb.) into a dedicated statute. Covers the 11 CER-Directive sectors (energy, transport, banking, financial-market infrastructure, health, drinking water, wastewater, digital infrastructure, public administration, space, food production-processing-distribution) and obligates designated operators of essential services to conduct risk analyses, implement technical/organisational resilience measures, report incidents to sector-competent authorities, and submit to inspection. Published in the Sbírka zákonů on 4 August 2025; in force 19 August 2025; operator information-obligation deadline 1 March 2026.
On 11 April 2025 President Javier Milei signed Decreto de Necesidad y Urgencia 269/2025, published in the Boletín Oficial on 14 April 2025 (edición Nº 35.647). The decree repealed Decreto 28/2023, formally lifting the cepo cambiario — the foreign-exchange restrictions that had been in continuous operation in some form since November 2011. Operative provisions include elimination of the 80/20 export-proceeds-channelling mandate, removal of individual USD purchase and wire-transfer caps, permission for companies to repatriate post-1-January-2025 dividend profits, and replacement of the daily crawling-peg with a band float within a $1,000–$1,400 ARS/USD corridor with BCRA floor/ceiling intervention rules. The measure was coordinated with the IMF Extended Fund Facility (USD 20bn total; USD 15bn 2025 free-availability tranche) approved 11 April 2025, and operationalises the currency-stability guarantee embedded in the RIGI large- investment regime (Law 27.742, July 2024).
FinCEN issued a final rule under Section 311 of the USA PATRIOT Act (31 U.S.C. § 5318A) prohibiting US covered financial institutions from opening or maintaining a correspondent account for, or on behalf of, Iraq-based Al-Huda Bank, a foreign financial institution found to be of primary money-laundering concern. Treasury determined that Al-Huda Bank exploited its access to US dollars to support designated Foreign Terrorist Organizations including Iran's Islamic Revolutionary Guard Corps (IRGC) and IRGC-Quds Force, as well as Iran-aligned Iraqi militias Kata'ib Hizballah and Asa'ib Ahl al-Haq. The rule also imposes a special-due-diligence requirement on US covered institutions to guard against indirect access via foreign correspondent accounts. Published in the Federal Register on July 3, 2024; effective August 2, 2024.
Three Commission Delegated Regulations (CDR 2024/1772, 1773, 1774) adopted 13 March 2024 and published in the EU Official Journal on 25 June 2024 constitute the first batch of binding Level 2 implementing rules under DORA (Regulation (EU) 2022/2554). CDR 2024/1772 sets ICT incident classification criteria and materiality thresholds for mandatory reporting; CDR 2024/1773 specifies the required content of contractual policies for ICT third-party services supporting critical or important functions; CDR 2024/1774 defines the ICT risk management tools, methods, processes, and policies — including a simplified framework for smaller in-scope entities. All three apply from 17 January 2025 alongside the parent DORA regulation, covering approximately 22,000 EU regulated financial entities.
Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities, published OJ L 333, 27 December 2022, entered into force 16 January 2023, with Member State transposition deadline 17 October 2024 (rules applicable from 18 October 2024). The CER Directive repeals Council Directive 2008/114/EC on European Critical Infrastructures, extending the scope from two sectors (energy, transport) to eleven essential-service sectors: energy, transport, banking, financial market infrastructures, health, drinking water, wastewater, digital infrastructure, public administration, space, and food. Member States must adopt national resilience strategies, conduct risk assessments at least every four years, identify "critical entities" providing essential services whose disruption would have significant cross-border impacts, and ensure those entities implement technical, security, and organisational resilience measures, business-continuity plans, incident-reporting obligations, and personnel-security background checks. The CER Directive is the physical and hybrid resilience twin to the NIS2 Directive (2022/2555) — the two instruments form the binding EU critical-infrastructure-protection architecture replacing the 2008/114/EC regime.
Regulation (EU) 2022/2554 (Digital Operational Resilience Act, DORA) is the EU's first horizontal cyber- and ICT-resilience instrument for the financial sector. Adopted 14 December 2022 and published in the Official Journal on 27 December 2022, it entered into force on 16 January 2023 and applies from 17 January 2025. DORA covers approximately 22,000 EU regulated financial entities across ~20 entity types (credit institutions, insurers, investment firms, CCPs, trading venues, crypto-asset service providers, etc.) under five pillars: ICT risk management, ICT-incident reporting, digital operational resilience testing (including threat-led penetration testing for significant entities), ICT third-party risk management, and information sharing. Structurally novel, DORA establishes the Critical ICT Third-Party Provider (CTPP) oversight regime under which the European Supervisory Authorities (EBA, ESMA, EIOPA) acquire direct supervisory powers over hyperscale cloud providers (AWS, Azure, GCP, Oracle) servicing EU financial entities — the first EU mechanism for ESA direct oversight of non-financial cloud providers.
Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive), published OJ L 333, 27 December 2022, entered into force 16 January 2023. NIS2 repeals and substantially expands the 2016 NIS1 Directive (2016/1148), extending the scope from ~7 sectors to 18 enumerated essential and important sectors, imposing binding cybersecurity risk- management and incident-reporting obligations on covered entities, introducing board-level management accountability, and mandating Member State transposition by 17 October 2024. NIS2 is the structural EU statutory anchor for national cybersecurity frameworks across the bloc, operating alongside DORA (Reg 2022/2554) for financial-sector digital resilience and CRA (Reg 2024/2847) for product cybersecurity.