Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
FinCEN issued a final rule delaying by two years the effective date of the August 28, 2024 Investment Adviser AML Rule (89 FR 72156) — which would have required SEC-registered investment advisers (RIAs) and Exempt Reporting Advisers (ERAs) to implement AML/CFT programs and file SARs under the Bank Secrecy Act. The compliance deadline moves from January 1, 2026 to January 1, 2028. Treasury cited the need for additional time to review and re-tailor the rule to the diverse business models and risk profiles of the investment adviser sector, and to coordinate with related rulemakings. The final rule follows the September 22, 2025 NPRM and the August 5, 2025 exemptive relief order that had already paused enforcement.
On 18 November 2025, the European Supervisory Authorities (EBA, ESMA, and EIOPA) jointly designated 19 Critical ICT Third-Party Providers (CTPPs) under DORA Article 31, with immediate effect — the first-ever exercise of direct EU financial-regulator supervision over hyperscale cloud and infrastructure providers. The designated entities include Amazon Web Services, Microsoft Azure, Google Cloud, Deutsche Telekom, Oracle, SAP, IBM, Bloomberg LP, London Stock Exchange Group (LSEG), Tata Consultancy Services, and Orange, among others. Designation triggers direct oversight by a lead ESA (EBA for banking-critical, ESMA for capital-markets-critical, EIOPA for insurance-critical) via Joint Examination Teams (JETs), with powers to conduct investigations, carry out on-site inspections, and impose fines of up to 1% of average daily worldwide turnover per day for non-compliance.
On 4 November 2025, La Banque Postale — a bank wholly owned by the French state via La Poste Group and Caisse des Dépôts — together with its asset-management subsidiary LBP AM and Japan's Mitsubishi UFJ Financial Group (MUFG), refinanced EUR 170 million of debt for NEoT Green Mobility (NGM), a European green-mobility asset-financing platform. The long-term, non-recourse, multi-currency facility is structured as a portfolio combining project and asset financings backing NGM's electric buses, coaches, trucks, cars, charging stations and boats operated across several European countries. Global Trade Alert logs the transaction as a "certainly harmful" state-loan intervention given the state ownership of the lead bank.
Banque des Territoires, acting on behalf of the French State under the France 2030 programme, launched a EUR 500 million fund-of-funds called "Global Tech Coté" on 7 August 2025. The vehicle takes minority stakes (EUR 15 million minimum, capped at 10% of a target fund's subscribed capital) in privately-managed investment funds that in turn back publicly-listed French technology companies with strong growth potential, aiming to build up domestic asset-management capacity alongside the state's stated goal of channelling capital into equities. The selection window for management companies runs until 31 December 2026 or until the EUR 500 million envelope is exhausted, whichever comes first.
The Joint Committee of the European Supervisory Authorities (EBA, EIOPA, ESMA) published the Guide on DORA Oversight Activities (JC 2025 29) on 15 July 2025, the definitive operational description of how the ESAs will supervise Critical ICT Third-Party Providers (CTPPs) designated under DORA Art. 31. The guide establishes the governance of Joint Examination Teams (JETs), the oversight examination lifecycle (planning, risk assessment, binding recommendations, follow-up), penalty processes of up to 1% of average daily worldwide turnover per day of breach (DORA Art. 35(6)), and lead-overseer assignments (EBA for banking, ESMA for capital markets, EIOPA for insurance). It is authoritative ESA interpretive guidance, not legally binding per se, but constitutes the supervisory playbook CTPPs and their dependent financial entities must plan against.
FinCEN issued a final rule (published September 4, 2024 at 89 FR 72156; FR Doc 2024-19260) including most SEC-registered investment advisers (RIAs) and Exempt Reporting Advisers (ERAs) within the Bank Secrecy Act definition of "financial institution." Covered firms must implement a risk-based AML/CFT compliance program, appoint a compliance officer, train staff, obtain independent testing, file Suspicious Activity Reports (SARs) and Currency Transaction Reports (CTRs), and participate in §314(a)/(b) information sharing. The original compliance date was January 1, 2026; FinCEN subsequently delayed the effective date to January 1, 2028 by final rule published 2026-01-02 (FR Doc 2025-24184).
Three Commission Delegated Regulations (CDR 2024/1772, 1773, 1774) adopted 13 March 2024 and published in the EU Official Journal on 25 June 2024 constitute the first batch of binding Level 2 implementing rules under DORA (Regulation (EU) 2022/2554). CDR 2024/1772 sets ICT incident classification criteria and materiality thresholds for mandatory reporting; CDR 2024/1773 specifies the required content of contractual policies for ICT third-party services supporting critical or important functions; CDR 2024/1774 defines the ICT risk management tools, methods, processes, and policies — including a simplified framework for smaller in-scope entities. All three apply from 17 January 2025 alongside the parent DORA regulation, covering approximately 22,000 EU regulated financial entities.
Regulation (EU) 2022/2554 (Digital Operational Resilience Act, DORA) is the EU's first horizontal cyber- and ICT-resilience instrument for the financial sector. Adopted 14 December 2022 and published in the Official Journal on 27 December 2022, it entered into force on 16 January 2023 and applies from 17 January 2025. DORA covers approximately 22,000 EU regulated financial entities across ~20 entity types (credit institutions, insurers, investment firms, CCPs, trading venues, crypto-asset service providers, etc.) under five pillars: ICT risk management, ICT-incident reporting, digital operational resilience testing (including threat-led penetration testing for significant entities), ICT third-party risk management, and information sharing. Structurally novel, DORA establishes the Critical ICT Third-Party Provider (CTPP) oversight regime under which the European Supervisory Authorities (EBA, ESMA, EIOPA) acquire direct supervisory powers over hyperscale cloud providers (AWS, Azure, GCP, Oracle) servicing EU financial entities — the first EU mechanism for ESA direct oversight of non-financial cloud providers.