Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
FinCEN reissued the Southwest Border Geographic Targeting Order (GTO), requiring money services businesses (MSBs) in designated ZIP codes to file Currency Transaction Reports on cash transactions between $1,000 and $10,000 — below the standard $10,000 CTR threshold. The reissued order runs September 3, 2026 through March 1, 2027 (180 days) and covers Bernalillo, Doña Ana, and San Juan Counties in New Mexico and Cameron, El Paso, Hidalgo, Maverick, and Webb Counties in Texas. Newly-covered MSBs (relative to the March 2026 order) have a compliance date of October 3, 2026. Treasury Secretary Bessent framed the order as targeting Mexico-based drug-cartel money laundering through the border MSB channel.
China's Ministry of Commerce issued Announcement No. 26 of 2026 on June 24, 2026, establishing a formal reporting and handling system for violations of export controls on strategic minerals and dual-use items, effective July 1, 2026. The mechanism opens two reporting channels — a dedicated hotline (010-12369) and an online portal (aqygzj.mofcom.gov.cn) — through which any organisation or individual may report suspected violations including unauthorised exports, circumvention via third-country re-routing, illegal technology transfers, and provision of services to sanctioned exporters. Anonymous reports are accepted; real-name reporters may qualify for monetary rewards; voluntary self-disclosure is treated as a mitigating factor in penalty determination. Service providers including freight forwarders and financial institutions face mandatory reporting obligations when they discover suspected violations in the course of business.
FinCEN issued an amendment to its June 30, 2025 special-measure order (90 FR 27770) that had prohibited US covered financial institutions from transmitting funds to or from CIBanco S.A., a Mexican multiple-banking institution previously designated as of primary money-laundering concern in connection with illicit-opioid trafficking. Effective April 16, 2026, the amendment authorizes transmittals of funds ordinarily incident and necessary for the Government of Mexico to liquidate CIBanco. The carve-out is narrow: the broader §2313a prohibition on US-side correspondent activity with CIBanco remains in force outside the liquidation channel.
Premier Li Qiang signed State Council Order No. 835 on 13 April 2026 promulgating the "Regulations of the People's Republic of China on Countering Foreign States' Unlawful Extraterritorial Jurisdiction" (20 articles), effective on the date of publication. The Regulations are the first State Council–level administrative regulation to operationalise the PRC's framework for identifying and countering foreign extraterritorial measures on a horizontal basis, complementing the 2021 Anti-Foreign Sanctions Law and the March 2025 AFSL implementation regulations. Article 5 establishes a State Council–led inter-agency coordination mechanism; Article 6 vests the State Council legal affairs department (the Ministry of Justice in practice) with authority to identify "improper" foreign extraterritorial measures and to grant exemptions; Article 8 authorises a new Malicious Entity List targeting foreign organisations and individuals that "promote or participate in implementing" such measures, with nine countermeasure categories spanning visa denial, asset freezing, trade restrictions and fines; Article 11 codifies an exemption-application channel under which Chinese persons facing conflicting legal demands may request approval to comply with foreign measures within a defined scope; Article 14 authorises a private right of action for harmed Chinese citizens and organisations to sue parties enforcing such measures; and Article 18 elevates enforcement beyond administrative penalties by referencing potential criminal liability.
FinCEN issued an expanded Geographic Targeting Order (GTO) requiring money services businesses (MSBs) located in designated counties and ZIP codes across Arizona, California, New Mexico, and Texas to file Currency Transaction Reports (CTRs) on cash transactions between $1,000 and $10,000 — well below the standard $10,000 CTR threshold. The order took effect March 7, 2026 and runs through September 2, 2026; the FR notice (FR Doc. 2026-04641) was published March 10, 2026. The expansion adds Bernalillo, Doña Ana, and San Juan Counties in New Mexico and Maricopa and Pima Counties in Arizona to the geography covered by the prior September 10, 2025 GTO. Compliance date for newly-covered MSBs is April 6, 2026; reports must be filed within 30 days (extended from the standard 15-day CTR deadline). The instrument is part of the post-2024 US enforcement architecture targeting fentanyl-related illicit-finance flows through the US-Mexico border MSB channel.
Directive (EU) 2026/470 of 24 February 2026, published in the EU Official Journal on 26 February 2026 and entered into force on 18 March 2026, amends the Corporate Sustainability Reporting Directive (CSRD, Directive (EU) 2022/2464) and the Corporate Sustainability Due Diligence Directive (CSDDD, Directive (EU) 2024/1760). It raises CSRD scope thresholds to undertakings with more than 1,000 employees and more than EUR 450 million net turnover, raises CSDDD scope thresholds to entities with more than 5,000 employees and EUR 1.5 billion turnover (and non-EU entities with EUR 1.5 billion EU turnover), drops the requirement to adopt or put into effect a climate transition plan under CSDDD, and replaces reasonable-assurance with limited-assurance for CSRD reports. CSRD-related provisions must be transposed by 19 March 2027; CSDDD-related provisions by 26 July 2028.
On 9 February 2026 the UK Office of Financial Sanctions Implementation (OFSI) published a comprehensively revised enforcement and monetary-penalties guidance following its July–October 2025 public consultation. The update introduces a Settlement Scheme (20% penalty discount for subjects who agree not to contest OFSI's findings within 30 business days), an Early Account Scheme (up to 20% discount for legal persons providing a timely senior-attested factual account), a revised voluntary-disclosure framework (maximum discount cut from 50% to 30% and renamed to cover both prompt self-reporting and full cooperation), a four-level case-assessment seriousness matrix (severity × conduct), and fixed monetary penalties of £5,000 and £10,000 for information, reporting, and licensing offences. A planned legislative amendment (requiring primary legislation) will subsequently double the statutory civil monetary-penalty cap from £1m / 50%-of-breach to £2m / 100%-of-breach; in the interim the Policing and Crime Act 2017 caps remain in force. The revised guidance is the foundational enforcement architecture for all UK financial-sanctions programs (Russia, Iran, DPRK, Syria, Belarus, Myanmar, and 10+ additional regimes).
FinCEN issued a final rule delaying by two years the effective date of the August 28, 2024 Investment Adviser AML Rule (89 FR 72156) — which would have required SEC-registered investment advisers (RIAs) and Exempt Reporting Advisers (ERAs) to implement AML/CFT programs and file SARs under the Bank Secrecy Act. The compliance deadline moves from January 1, 2026 to January 1, 2028. Treasury cited the need for additional time to review and re-tailor the rule to the diverse business models and risk profiles of the investment adviser sector, and to coordinate with related rulemakings. The final rule follows the September 22, 2025 NPRM and the August 5, 2025 exemptive relief order that had already paused enforcement.
Taiwan's Legislative Yuan passed the Artificial Intelligence Basic Act (人工智慧基本法) on third reading on 23 December 2025, and President Lai Ching-te promulgated the 20-article statute on 14 January 2026, bringing it into force immediately. The Act designates the National Science and Technology Council (NSTC) as the central AI-policy competent authority and codifies seven governance principles — sustainability and well-being, human autonomy, privacy protection and data governance, cybersecurity and safety, transparency and explainability, fairness and non-discrimination, and accountability — that apply to all public-sector AI procurement and high-risk sectoral applications. The statute establishes a statutory foundation for the Taiwan AI Action Plan 2.0, mandates an Executive Yuan National AI Strategy Committee, and provides authority for sector-specific implementing regulations by FSC, NCC, MOHW, and MOTC across finance, telecoms, medical, and autonomous-vehicle AI within a two-year window. As the first national AI governance statute in the Greater China region and the third globally after the EU AI Act and South Korea's AI Basic Act, it frames regulatory expectations for the companies at the heart of the global AI hardware supply chain — TSMC, NVIDIA ODM partners, and advanced-packaging incumbents — that are headquartered or operate substantially in Taiwan.
Morocco's Loi de Finances n° 50-25 for fiscal year 2026, promulgated by Dahir n° 1-25-67 of 10 December 2025 and published in Bulletin Officiel n° 7465 bis of 16 December 2025, sets the FY2026 customs-tariff schedule (continuing the EU Common External Tariff alignment process at 2.5%/17.5%/40% tiers with sector-specific input reductions), amends the fiscal regimes for Zones d'Accélération Industrielle and Casablanca Finance City, and delivers the 2026 tranche of the multi-year IS (corporate-tax) rate-convergence schedule under Framework Law n° 69-19. The law also extends green-investment fiscal accelerators aligned with the EU's Carbon Border Adjustment Mechanism and the EU-Morocco Strategic Partnership on Sustainable Raw Materials Value Chains, and contains phosphate-sector fiscal provisions affecting OCP Group's DAP/MAP/TSP export treatment. Entry into force: 1 January 2026.
FinCEN issued a final rule under Section 311 of the USA PATRIOT Act (31 U.S.C. § 5318A) prohibiting US covered financial institutions from opening or maintaining a correspondent account for, or on behalf of, Cambodia-based Huione Group, a foreign financial institution found to be of primary money-laundering concern. Treasury determined that Huione Group and its subsidiaries — including Haowang Guarantee, Huione Pay PLC, and Huione Crypto — laundered at least $4 billion of illicit proceeds between August 2021 and January 2025, including funds tied to North Korean cyber-heist actors and Southeast Asian "pig-butchering" investment-scam compounds. The rule also imposes a special-due-diligence requirement on US covered institutions to guard against indirect access via foreign correspondent accounts. Effective November 17, 2025.
On September 10, 2025 FinCEN issued a Geographic Targeting Order (GTO) under 31 USC 5326 requiring money services businesses (MSBs) in designated southwest-border counties and ZIP codes across California, Texas, and (newly added) Arizona to file Currency Transaction Reports (CTRs) on cash transactions between $1,000 and $10,000 — well below the BSA's standard $10,000 CTR threshold. The order ran through March 6, 2026 (180 days, the GTO statutory maximum) and was subsequently extended via the March 10, 2026 expanded GTO (FR Doc. 2026-04641) which retained the $1,000 floor and added inland transit hubs (Bernalillo, Doña Ana, San Juan in NM; Maricopa, Pima in AZ). The September 2025 order modified an earlier March 14, 2025 GTO that had used a $200 threshold and covered a narrower TX/CA strip; the September 2025 modification raised the threshold to $1,000 in response to MSB-industry feedback on operational burden, while extending the geography to include Arizona. Filing deadline is extended from the standard 15 days to 30 days.
FinCEN published an order amending the three June 25, 2025 special-measure orders (as previously amended by the July 11, 2025 order, FR doc 2025-12973) prohibiting US covered financial institutions from transmitting funds to or from CIBanco S.A., Intercam Banco S.A., and Vector Casa de Bolsa, S.A. de C.V. — three Mexican institutions designated of primary money-laundering concern in connection with illicit-opioid trafficking under Section 2313a of the Fiscal Year 2024 NDAA. The amendment extends the effective date of all three prohibitions from September 4, 2025 to October 20, 2025, granting US covered institutions an additional ~46 days to wind down correspondent exposures. The underlying primary-money-laundering-concern findings remain intact — only the implementation deadline shifts.
The Mauritius Finance Act 2025 (Act No. 18 of 2025), assented to by Acting President Dharambeer Gokhool G.C.S.K. and gazetted in August 2025, is an omnibus financial-sector statute amending the Companies Act, Financial Services Act 2007, Income Tax Act, Bank of Mauritius Act, and FIAMLA. Its headline provisions are: (i) introduction of a Qualified Domestic Minimum Top-Up Tax (QDMTT) aligned with the OECD GloBE Pillar Two rules, imposing a 15% effective minimum tax on Mauritius profits of MNE groups with consolidated revenue ≥ EUR 750 million; (ii) new fiscal incentives for investments in AI infrastructure and Virtual Asset Service Provider (VASP) licensees; (iii) enhanced beneficial-ownership (UBO) identification and record-keeping requirements under the Companies Act, aligned with FATF Recommendation 24; (iv) tightened substance and economic-presence requirements for Global Business Companies (GBCs); and (v) an expanded AML/CFT administrative- penalty framework under FIAMLA.
FinCEN published an order amending the three June 25, 2025 special-measure orders (FR docs 2025-11991, 2025-11993, 2025-11990; 90 FR 27770 et seq.) prohibiting US covered financial institutions from transmitting funds to or from CIBanco S.A., Intercam Banco S.A., and Vector Casa de Bolsa, S.A. de C.V. — three Mexican institutions designated of primary money-laundering concern in connection with illicit-opioid trafficking under Section 2313a of the Fiscal Year 2024 NDAA. This first extension shifts the effective date of all three prohibitions from July 21, 2025 to September 4, 2025 (a 45-day delay), giving US covered institutions additional time to wind down correspondent exposures. The underlying primary-money-laundering- concern findings remain unchanged — only the implementation deadline shifts.
On 26 June 2025, the Governing Board of Mexico's National Banking and Securities Commission (CNBV), invoking Article 129 of the Ley de Instituciones de Crédito, decreed the temporary managerial intervention of CI Banco, S.A. and Intercam Banco, S.A., replacing their administrative bodies and legal representatives. The measure came one day after the US Treasury's FinCEN designated both institutions (along with Vector Casa de Bolsa) as foreign financial institutions of primary money-laundering concern tied to opioid-trafficking networks, and prohibited certain US fund transmittals to them. CNBV/SHCP framed the intervention as a depositor- and creditor-protection measure to safeguard the two banks' operations against the fallout of the US action; Vector Casa de Bolsa was not included in the CNBV intervention.
On 26 June 2025 President Bola Ahmed Tinubu signed four acts constituting Nigeria's most comprehensive fiscal overhaul in decades: the Nigeria Tax Act 2025 (NTA), Nigeria Tax Administration Act 2025 (NTAA), Nigeria Revenue Service (Establishment) Act 2025, and Joint Revenue Board (Establishment) Act 2025. The NTA consolidates and repeals six core statutes — CITA, PITA, PPTA, VAT Act, CGT Act, and Stamp Duties Act — into a single unified code effective 1 January 2026, while the NTAA standardises assessment, filing, and enforcement procedures across all federal taxes. The two establishment acts restructure the Federal Inland Revenue Service (FIRS) into the Nigeria Revenue Service (NRS) with a broadened mandate and create an empowered Joint Revenue Board to coordinate federal-state fiscal relations.
The Hong Kong Legislative Council passed the Stablecoins Ordinance (Cap. 656) on 21 May 2025 (third reading), brought into operation by the Secretary for Financial Services and the Treasury on 1 August 2025. The Ordinance introduces a mandatory licensing regime administered by the Hong Kong Monetary Authority (HKMA) for any person who issues a fiat-referenced stablecoin (FRS) in Hong Kong, issues an HKD-pegged stablecoin anywhere in the world, or actively markets such issuance to the Hong Kong public. Key requirements include minimum HK$25 million paid-up capital, segregated pools of high-quality liquid reserve assets fully backing circulating supply, mandatory redemption-at-par rights for holders, AML/CFT controls, and broad HKMA enforcement powers including licence suspension, revocation, and financial penalties. A six-month transitional period for existing operators expires 31 January 2026.
Switzerland's State Secretariat for Economic Affairs (SECO) and the US Treasury Office of Foreign Assets Control (OFAC) signed a Memorandum of Understanding on 9 May 2025 (jointly published 16 May 2025) establishing a framework for information-sharing, coordinated investigations, designated points of contact, regular bilateral meetings, joint training, and exchange of technical expertise on sanctions enforcement. The MoU is not legally binding and neither side is obliged to share information, but it formalises an enforcement-cooperation channel that previously operated only ad-hoc. It is the first sanctions-enforcement MoU Switzerland has concluded with a third country (the US has a comparable arrangement with the UK's OFSI), and SECO has indicated more such MoUs will follow.
The Office of Foreign Assets Control (OFAC) issued a final rule on 21 March 2025 adopting without change its 13 September 2024 interim final rule that doubled the recordkeeping retention requirement for transactions subject to OFAC regulations from five years to ten years. The extension aligns 31 CFR 501.601, paragraph IV.B of appendix A to part 501, and 31 CFR 515.572 with the 10-year statute of limitations for IEEPA and TWEA violations enacted by the 21st Century Peace through Strength Act of 24 April 2024. The interim final rule's 10-year retention obligation became effective 12 March 2025; the final rule confirmed the IFR text without modification.
FinCEN issued an interim final rule (FR Doc 2025-05199, 90 FR 13688, published March 26, 2025) revising the definition of "reporting company" under the Corporate Transparency Act to mean only entities formed under the law of a foreign country that have registered to do business in a U.S. State or tribal jurisdiction. All entities created in the United States — previously known as "domestic reporting companies" — and U.S. persons are exempted from BOI reporting. Foreign reporting companies registered before March 26, 2025 must file by April 25, 2025; those registered on or after that date have 30 days from registration. Foreign reporting companies are not required to report any U.S. persons as beneficial owners. The IFR is effective immediately; FinCEN is accepting comments and intends to finalize the rule.
The Nigeria Data Protection Commission issued the General Application and Implementation Directive (GAID) 2025 on 20 March 2025, the principal implementing directive of the Nigeria Data Protection Act 2023 (NDPA). The GAID came fully into force on 19 September 2025, replacing the Nigeria Data Protection Regulation (NDPR) 2019 as the operative enforcement instrument. It applies extraterritorially to any data controller or processor established outside Nigeria that processes personal data of Nigerian data subjects, imposes a tripartite cross-border transfer framework (adequacy decisions, Transfer Instruments, and statutory exceptions), mandates Data Protection Impact Assessments for AI and high-risk technologies, and carries a civil-penalty ceiling of 2% of annual gross revenue or NGN 10 million for designated data controllers and processors of major importance (DCPMIs), whichever is greater.
On March 11, 2025 FinCEN issued a Geographic Targeting Order (GTO) under 31 USC 5326 — published in the Federal Register on March 14, 2025 (FR Doc. 2025-04099) and effective April 14, 2025 — requiring every money services business (MSB) located in 30 designated ZIP codes across seven counties in California (Imperial, San Diego) and Texas (Cameron, El Paso, Hidalgo, Maverick, Webb) to file a Currency Transaction Report (CTR) on cash transactions of more than $200 but not more than $10,000, far below the Bank Secrecy Act's standard $10,000 CTR floor. The order also imposed customer-identification recordkeeping and, per the FinCEN order text, gave covered MSBs thirty (30) days to file CTRs (vs. the standard fifteen). It was framed by Treasury as part of the post-January-2025 cartel-targeting policy stack (Trump Executive Order 14157 designating Mexican drug cartels as Foreign Terrorist Organizations / SDGTs) and was intended to surface low-value cash flows used by Mexico-based cartels and related criminal actors. The GTO was a 180-day order set to expire September 9, 2025; it was subsequently superseded on September 10, 2025 by a modified GTO that raised the threshold to $1,000 in response to MSB-industry feedback on burden, expanded geography to Arizona, and was itself replaced/expanded again on March 10, 2026.
El Salvador's Legislative Assembly adopted Decreto Legislativo No. 199 on 29 January 2025 with 55 of 60 votes, reforming six articles and repealing three articles of the original Ley Bitcoin (Decreto 57, June 2021). The reform downgrades Bitcoin from compulsory legal tender to voluntary acceptance only — private parties are no longer obliged to accept BTC payments, and Bitcoin can no longer be used to pay taxes or settle public-sector debts. The State also withdraws from operational involvement in the Chivo Wallet platform. The reform is an explicit prior action under the IMF's US$1.4 billion Extended Fund Facility (EFF) programme (IMF Country Report 25/58), published in the Diario Oficial on 30 January 2025 and entering into force 90 days later on 30 April 2025.
Malaysia's Personal Data Protection (Amendment) Act 2024 (Act A1727), gazetted 17 October 2024, enters its third and final commencement phase on 1 June 2025 per commencement order P.U.(B) 522/2024. Phase 3 activates sections 6 and 9 of the amending Act, which impose mandatory Data Protection Officer (DPO) appointment thresholds, a 72-hour breach-notification duty to the Commissioner, and a statutory data-portability right, bringing Malaysia's PDPA broadly into alignment with GDPR and the ASEAN Model AI Governance Framework.
The Office of Foreign Assets Control (OFAC) issued a final rule on 19 December 2024 amending 32 parts of 31 CFR chapter V to modernize the general licenses authorizing payments for legal services from funds originating outside the United States. The rule replaces the annual reporting requirement that had applied to such payments with a 10-year recordkeeping requirement, aligning the legal-services general licenses with the new 10-year statute of limitations for IEEPA/TWEA violations and OFAC's parallel 5→10-year recordkeeping extension (31 CFR 501). The rule also standardises legal-services general-license language across programs — removing legacy letter-of-engagement prerequisites in certain parts (e.g., 31 CFR 594, 597), updating 31 CFR 549 (Lebanon) and 31 CFR 576 (Iraq Stabilization and Insurgency) to remove the requirement that payments for authorised legal services be separately specifically licensed, and harmonising the 31 CFR 591 (Venezuela-related) authorisation language. The rule was effective 19 December 2024 with an applicability date of 12 March 2025.
UAE Cabinet Decision No. 142 of 2024, announced 9 December 2024 and formally gazetted 11 February 2025, introduces a Domestic Minimum Top-Up Tax (DMTT) on UAE constituent entities of Multinational Enterprise (MNE) groups with consolidated annual revenues ≥ EUR 750 million in at least two of the four preceding fiscal years. The DMTT ensures a 15% minimum effective tax rate (ETR) on UAE-source profits, functioning as a Qualified Domestic Minimum Top-up Tax (QDMTT) under the OECD/G20 Pillar Two GloBE framework, thereby giving the UAE first-priority taxing right before any IIR top-up by a parent-jurisdiction authority. The measure applies to fiscal years beginning on or after 1 January 2025. The UAE deliberately excluded the Income Inclusion Rule (IIR) and Under-Taxed Profits Rule (UTPR) from this primary instrument, deferring those to subsequent Cabinet Decisions; the QDMTT-only architecture mirrors Singapore's MEMTA and Switzerland's MindStV as the first-mover design choice for established low-tax financial hubs.
The U.S. Treasury's Office of Foreign Assets Control (OFAC) published in the Federal Register (89 FR 84472–84474, FR Doc 2024-24524) three general licenses issued under the Western Balkans Stabilization Regulations (31 CFR Part 588): GL 3A, GL 4, and GL 5. All three were originally issued on 18 June 2024 concurrent with OFAC's expansion of Republika Srpska / Dodik-network designations; the 23 October 2024 Federal Register notice formalises them per the Administrative Procedure Act notice requirements. GL 3A (which superseded GL 3 of 16 November 2023) authorises transactions involving certain WBSR-blocked entities that are ordinarily incident and necessary to the exportation or re-exportation of agricultural commodities, medicine, medical devices, replacement parts and components, software updates, or activities involving medical prevention, diagnosis, treatment, or clinical trials. GL 4 authorises wind-down transactions with entities blocked on 18 June 2024 through a defined cutoff. GL 5 authorises transactions ordinarily incident and necessary to the manufacture, distribution, operation, installation, or maintenance/repair of drinking-water pumps manufactured or distributed by the WBSR-blocked Bosnian Serb entity Kaldera Company EL PGP d.o.o. (and 50%-or-more-owned subsidiaries), preserving municipal water supply continuity.
FinCEN published a final rule (FR Doc 2024-23920, 89 FR 83782, effective on publication October 18, 2024) clarifying the public-utility exemption to the Corporate Transparency Act's beneficial ownership information (BOI) reporting rule. The amendment to 31 CFR 1010.380(c)(2)(xv) corrects a drafting cross-reference so the exemption explicitly covers any regulated public utility under 26 U.S.C. 7701(a)(33)(A) *or* (D) that provides telecommunications services, electrical power, natural gas, or water and sewer services within the United States. The change codifies FinCEN's June 10, 2024 telecommunications-provider guidance and is effective immediately upon publication; it neither expands nor restricts the underlying universe of reporting companies beyond aligning the rule text with the CTA statute.
Australia's first standalone cyber-security statute (Act No. 98 of 2024), passed by Parliament on 25 November 2024 and granted Royal Assent on 29 November 2024, with provisions commencing in tranches through 30 May 2025. The Act creates four binding regimes: (i) mandatory security-of-things standards for connected and IoT products supplied in Australia under regulations administered by the Department of Home Affairs; (ii) a mandatory ransomware / cyber-extortion payment disclosure regime requiring reporting business entities with annual turnover above AUD 3 million to notify the Australian Signals Directorate within 72 hours of any ransom payment made by or on behalf of the entity; (iii) a statutory Cyber Incident Review Board to conduct no-blame post-incident reviews of significant cyber incidents; and (iv) a "limited use" protection restricting how information voluntarily shared with the National Cyber Security Coordinator may be used by Commonwealth agencies. The Act implements core initiatives from the 2023-2030 Australian Cyber Security Strategy and affects every firm selling connected devices into Australia or operating above the turnover threshold in Australia.
The Office of Foreign Assets Control (OFAC) issued a final rule on 8 October 2024 amending the Reporting, Procedures and Penalties Regulations (RPPR) at 31 CFR Part 501. The rule finalises portions of OFAC's 10 May 2024 interim final rule and adds three exceptions to the requirement to file a report with OFAC concerning blocked property that is unblocked or transferred. It also implements other technical clarifications to OFAC's reporting framework. The rule takes effect on 7 November 2024.
FinCEN issued a final rule (89 FR 70258, FR Doc 2024-19198) requiring certain real-estate-closing and settlement professionals to file a new "Real Estate Report" and maintain records on non-financed (i.e., all-cash) transfers of U.S. residential real property to specified legal entities and trusts, on a nationwide basis. The rule uses a "reporting cascade" to designate one filer per transaction (settlement agent, title-insurance underwriter, escrow agent, or attorney, depending on which is present), replacing the long-running geographic-targeting-order (GTO) regime with a permanent nationwide framework. The original effective date of December 1, 2025 was subsequently postponed to March 1, 2026 via a FinCEN exemptive-relief order issued September 30, 2025.
FinCEN issued a final rule (published September 4, 2024 at 89 FR 72156; FR Doc 2024-19260) including most SEC-registered investment advisers (RIAs) and Exempt Reporting Advisers (ERAs) within the Bank Secrecy Act definition of "financial institution." Covered firms must implement a risk-based AML/CFT compliance program, appoint a compliance officer, train staff, obtain independent testing, file Suspicious Activity Reports (SARs) and Currency Transaction Reports (CTRs), and participate in §314(a)/(b) information sharing. The original compliance date was January 1, 2026; FinCEN subsequently delayed the effective date to January 1, 2028 by final rule published 2026-01-02 (FR Doc 2025-24184).
The Ethiopian Capital Market Authority (ECMA) issued Directive No. 1009/2024 on 16 July 2024, establishing the comprehensive licensing, operational, and supervisory framework for securities exchanges, derivatives exchanges, and the over-the-counter (OTC) market under the authority of Article 108 of the Capital Market Proclamation No. 1248/2021. The directive consolidates Ethiopia's previously fragmented securities-trading architecture into a single, licensed, and regulated market structure and provided the statutory pathway for the Ethiopian Securities Exchange (ESX) to receive the country's first securities-exchange licence. This is the first capital-markets architecture filing for Ethiopia on the IPTM register, forming the operating- licence layer alongside the banking-sector liberalisation enacted under Proclamation 1360/2025.
FinCEN issued a final rule under Section 311 of the USA PATRIOT Act (31 U.S.C. § 5318A) prohibiting US covered financial institutions from opening or maintaining a correspondent account for, or on behalf of, Iraq-based Al-Huda Bank, a foreign financial institution found to be of primary money-laundering concern. Treasury determined that Al-Huda Bank exploited its access to US dollars to support designated Foreign Terrorist Organizations including Iran's Islamic Revolutionary Guard Corps (IRGC) and IRGC-Quds Force, as well as Iran-aligned Iraqi militias Kata'ib Hizballah and Asa'ib Ahl al-Haq. The rule also imposes a special-due-diligence requirement on US covered institutions to guard against indirect access via foreign correspondent accounts. Published in the Federal Register on July 3, 2024; effective August 2, 2024.
The Office of Foreign Assets Control (OFAC) issued an interim final rule (IFR) on 10 May 2024 (FR Doc 2024-10033, 89 FR) amending the Reporting, Procedures and Penalties Regulations (RPPR) at 31 CFR Part 501. The IFR overhauls OFAC's reporting framework by requiring electronic submission of certain reports through the OFAC Reporting System (ORS), expanding the rejected-transaction reporting obligation to all U.S. persons (not only U.S. financial institutions), modifying blocked-property reporting procedures, updating procedures for petitions for administrative reconsideration and property-blocked-in-error requests, and revising FOIA-availability provisions. The IFR took effect on 8 August 2024 and was subsequently finalised — with three new exceptions to the blocked-property reporting requirement — by the 8 October 2024 final rule (FR Doc 2024-23217, effective 7 November 2024).
The Cyberspace Administration of China (CAC) issued the Provisions on Promoting and Regulating Cross-Border Data Flows (《促进和规范数据跨境流动规定》) on 22 March 2024, effective immediately. The rules substantially raise the thresholds at which CAC security assessment, Standard Contractual Clauses (SCC), or Personal Information Protection Certification are required for outbound data transfers, and create categorical exemptions for contract performance, HR management, intra-group transfers below a volume threshold, and transit data processed in China with no domestic personal information introduced. A Free Trade Zone pilot mechanism allows designated FTZs (Shanghai Lingang, Tianjin, Beijing) to publish their own negative lists defining which data categories still require prior approval, easing conditions for multinationals with operations in those zones.
OFAC amended and reissued the Global Magnitsky Sanctions Regulations (31 CFR Part 583) in their entirety on 12 March 2024, to implement the Global Magnitsky Human Rights Accountability Act and EO 13818 (20 December 2017) more fully. The reissuance adds expanded interpretive guidance, new definitions (agricultural commodities, medicines, medical devices), new statutory authority (Uyghur Human Rights Policy Act of 2020), and several new general licenses covering blocked-account management, legal services, personal-use medical/food transactions, and emergency services. No new SDN designations or country-level targeting; the action is a compliance-architecture update that clarifies permissible conduct and tightens procedural standards across the global human-rights-and-corruption sanctions program.
The U.S. Treasury's Office of Foreign Assets Control (OFAC) published in the Federal Register (89 FR 16400, FR Doc 2024-04856) two general licenses issued under the Western Balkans Stabilization Regulations (31 CFR Part 588): GL 2 and GL 3. Both were originally issued on 16 November 2023 concurrent with OFAC's initial round of Republika Srpska / Dodik-network designations; the 7 March 2024 Federal Register notice formalises them per the Administrative Procedure Act notice requirements. GL 2 authorises wind-down transactions with newly blocked WBSR entities through 15 March 2024. GL 3 authorises exports and re-exports of agricultural commodities, medicine, medical devices, replacement parts, and services for medical prevention and treatment to WBSR-blocked persons; GL 3 was subsequently superseded by GL 3A on 18 June 2024.
The U.S. Treasury's Office of Foreign Assets Control (OFAC) published a final rule in the Federal Register (89 FR 15769, FR Doc 2024-04500) renaming the Darfur Sanctions Regulations (31 CFR Part 546) to the Sudan Stabilization Sanctions Regulations and amending them to implement Executive Order 14098 of May 4, 2023. E.O. 14098 broadened US sanctions authority beyond the Darfur-specific frame to cover all persons destabilising Sudan and undermining democratic transition, responding to the SAF–RSF armed conflict that erupted in April 2023. The rule adds new general licenses covering legal-service payments (§ 546.508), African Union transactions (§ 546.511), and agricultural/medical exports (§ 546.513), and introduces an interpretative provision clarifying that entities are not automatically blocked solely because a blocked individual holds a leadership position.
FinCEN published a final rule on January 25, 2024 adjusting the maximum civil monetary penalties (CMPs) for Bank Secrecy Act (BSA) violations as mandated by the Federal Civil Penalties Inflation Adjustment Act of 1990, as amended by the 2015 Improvements Act. Adjustments are calculated using the CPI-U percent change between October 2022 and October 2023 and are codified in 31 CFR § 1010.821. The update covers 12 BSA statutory penalty provisions, ranging from per-day recordkeeping violations to wilful correspondent-account and special-measures infractions, with the largest single-penalty ceiling rising to $1,731,383.
OFAC published a final rule on January 12, 2024 adjusting the maximum civil monetary penalty (CMP) ceiling amounts across five statutory authorities as mandated by the Federal Civil Penalties Inflation Adjustment Act of 1990 (as amended by the 2015 Improvements Act). The 2024 adjustment multiplier is 1.03241 (reflecting the October 2022–October 2023 CPI-U change). Penalties under IEEPA rise from $356,579 to $368,136; TWEA penalties from $105,083 to $108,489; and the Narcotics Kingpin Act maximum from $1,771,754 to $1,829,177. The rule is issued as a final rule effective on publication without prior notice and comment under the non-discretionary "good cause" exemption.
FinCEN published the Beneficial Ownership Information Access and Safeguards Final Rule (FR Doc 2023-27973, 88 FR 88732, December 22, 2023; effective February 20, 2024), implementing the access and disclosure provisions of Section 6403(c) of the Corporate Transparency Act (CTA) enacted as part of the Anti-Money Laundering Act of 2020. The rule defines six categories of authorized recipients permitted to access the FinCEN BOI database — US federal agencies engaged in national security/intelligence/law enforcement, state/local/tribal law enforcement, foreign law enforcement and competent authorities (via intermediary federal agency), financial institutions using BOI for customer due diligence (CDD), federal functional regulators assessing financial-institution CDD compliance, and Treasury officers/employees. Access is to be phased in, beginning with a 2024 pilot for key federal agencies before extending to financial institutions and their supervisors. The rule establishes data-security standards, re-disclosure prohibitions, and oversight mechanisms governing each recipient category.
FinCEN published a final rule (FR Doc 2023-26399, 88 FR 83499, November 30, 2023; effective January 1, 2024) extending the initial beneficial ownership information (BOI) reporting deadline under the Corporate Transparency Act (CTA) for reporting companies created or registered in calendar year 2024. Rather than the default 30-day window, these companies receive 90 calendar days from the date of receiving actual or public notice of creation or registration becoming effective to file their initial BOI reports with FinCEN. Companies created before January 1, 2024 retain their original deadline of January 1, 2025; companies created on or after January 1, 2025 revert to the standard 30-day window.
FinCEN published a final rule (FR Doc 2023-24559, 88 FR 76995, November 8, 2023; effective January 1, 2024) specifying when and how entities required to report beneficial ownership information (BOI) under the Corporate Transparency Act (CTA) may use another entity's FinCEN identifier in lieu of disclosing the underlying individual beneficial owners. A reporting company may substitute a related entity's FinCEN ID when: (1) that entity has obtained a FinCEN identifier and provided it to the reporting company, (2) the individual is a beneficial owner solely through an ownership interest in the other entity, and (3) the beneficial owners of both entities are the same. Any change to beneficial ownership of the other entity requires an updated BOI report, after which the entity FinCEN identifier may no longer be used until recertified.
Saudi Arabia's Personal Data Protection Law (PDPL), issued under Royal Decree M/19 (16 September 2021) and substantively amended by Royal Decree M/148 (27 March 2023), entered into force on 14 September 2023 with a one-year transition period that ended on 14 September 2024 — at which point the Saudi Data & Artificial Intelligence Authority (SDAIA) became the binding regulator with full enforcement powers. Alongside the Implementing Regulations and the Regulations on the Transfer of Personal Data Outside the Kingdom (both issued 7 September 2023), SDAIA published in 2024 a set of four pre-approved Standard Contractual Clauses templates (C2C, C2P, P2P, P2C) governing cross-border transfers. The regime establishes consent requirements, DPO appointment, a 72-hour breach notification duty, and prior-clearance / SCC-or-BCR-style conditions on personal-data exports out of Saudi Arabia.
FinCEN published a final rule on January 19, 2023 (88 FR 3312) adjusting the maximum civil monetary penalties for Bank Secrecy Act (BSA) violations under 31 CFR § 1010.821, as mandated by the Federal Civil Penalties Inflation Adjustment Act of 1990 (as amended by the 2015 Improvements Act). The 2023 multiplier is 1.07745, reflecting the October 2021 → October 2022 CPI-U change per OMB Memorandum M-23-05. A correction notice (88 FR 7357, Feb. 3, 2023) revised certain table entries; the corrected amounts are authoritative and are reflected in this filing. The table covers 10 BSA statutory penalty provisions, with the largest single-penalty ceiling rising to $1,677,030.
OFAC published a final rule on January 13, 2023 adjusting the maximum civil monetary penalty (CMP) ceiling amounts across multiple statutory sanctions authorities as mandated by the Federal Civil Penalties Inflation Adjustment Act of 1990 (as amended by the Federal Civil Penalties Inflation Adjustment Act Improvements Act of 2015). The adjustment covers IEEPA, TWEA, and the Narcotics Kingpin Act authorities, resetting the penalty ceilings that apply to violations adjudicated through 2023. A correction notice (C1-2023-00593, April 17, 2023) fixed a purely typographical error in Appendix A to 31 CFR Part 501 — paragraph numbering "v" corrected to "vi" — with no change to any penalty amount.
On 21 December 2022 OFAC published final rule FR Doc 2022-27564, amending 30 CFR parts (31 CFR Parts 510, 525, 536, 539, 541, 542, 544, 546, 547, 548, 549, 551, 552, 555, 558, 560, 561, 562, 569, 576, 579, 582, 583, 584, 585, 591, 594, 596, 597, 598) to add or update general licenses authorising (1) official business of the US government and (2) official business of designated international organisations and entities across the full OFAC program library. The rule also updates the 50 Percent Rule interpretive provision, clarifying that an entity's property is blocked when one or more blocked persons own an aggregate interest of 50 percent or more — directly or indirectly — and corrects CFR citations to meet current Federal Register formatting requirements. Published as companion to FR Doc 2022-27639 (NGO and humanitarian GLs), both rules effective 21 December 2022.
FinCEN issued a final rule (87 FR 59498, September 30, 2022) implementing the Corporate Transparency Act (CTA) by requiring most corporations, limited liability companies, and similar entities created in or registered to do business in the United States to file beneficial ownership information (BOI) reports with FinCEN. Reporting companies must identify two categories of individuals: beneficial owners (persons exercising substantial control or owning ≥25% of the entity) and company applicants (persons who filed the formation documents). Entities formed before January 1, 2024 had until January 1, 2025 to file; entities formed on or after that date had 30 days. Non-compliance carries civil penalties of up to $500/day and criminal penalties of up to $10,000 and two years imprisonment.