top of page

Search Results

Search this site

74 results found with an empty search

  • What’s Changing in the EU Suitability Assessment Rules - Joint EBA & ESMA Guidelines (Consultation Paper)

    On 25 February 2026, ESMA and the EBA published a consultation on revised joint guidelines for assessing the suitability of members of the management body and key function holders in banks and investment firms. The suitability guidelines themselves already exist: what’s new here is a set of targeted updates designed to reflect recent EU legal developments, expand and clarify supervisory expectations, and improve consistency across Member States. Below is a practical breakdown of the key changes. Alignment with updated EU prudential requirements (CRD) A major driver of the revision is alignment with the updated Capital Requirements Directive (CRD). The revised framework clarifies how institutions and supervisors should apply suitability requirements under the latest prudential rules, especially where the updated CRD introduces new expectations around governance and appointments. What this means in practice: more explicit links between legal requirements and the suitability process, clearer expectations on how assessments should be performed and evidenced. Wider focus on key roles beyond board membership The revised approach strengthens the focus on key function holders, including roles that may not sit on the board but have a critical impact on governance and control. In particular, the revisions emphasise suitability assessment expectations for senior control and financial roles (for example, internal control functions and senior finance leadership), reinforcing that governance risk isn’t limited to board appointments alone. Clearer approach for third-country branches The consultation also addresses how the suitability framework should apply in the context of third-country branches operating in the EU. This is important for groups with non-EU headquarters and EU branch structures, as it clarifies supervisory expectations around governance and key individuals in those branch setups. Stronger link to financial crime and AML/CFT considerations Another notable development is the clearer connection between suitability assessments and AML/CFT risk considerations. This doesn’t replace existing fit-and-proper principles, but it strengthens how institutions and supervisors should factor in integrity, reputation, and relevant risk signals when assessing individuals in senior positions. More harmonised documentation expectations Alongside the revised guidelines, the consultation package supports greater standardisation of what information is expected for suitability reviews (such as the structure/content of questionnaires, CV information, and supporting documentation). The practical outcome is likely to be: more consistent submissions to regulators, fewer jurisdiction-by-jurisdiction differences in what is considered “enough” evidence, clearer internal file standards for firms. Clarifications aimed at consistency and reduced friction The revised guidelines also include clarifications intended to improve: supervisory convergence (more consistent outcomes across the EU), operational clarity (who assesses what, when, and how), and overall efficiency, reducing avoidable administrative complexity where possible. Conclusion This consultation is a signal that EU supervisors want more consistent, better-documented, and more risk-aware suitability assessments, not only for boards, but also for senior roles that drive control, finance, and governance outcomes.

  • CySEC Circular C754: What CIFs Need to Know About the 2025 Cross-Border Reporting Requirement

    The Cyprus Securities and Exchange Commission (CySEC)  issued today its Circular C754 , introducing a targeted electronic cross-border reporting obligation for Cyprus Investment Firms (CIFs). The circular focuses on CIFs that provided cross-border investment services to retail clients  in other EEA Member States during 2025 . This development aligns with broader EU supervisory efforts to strengthen oversight of cross-border activities and enhance data consistency across Member States. Who Is in Scope? The requirement applies to CIFs that, between 1 January and 31 December 2025 , provided investment services on a freedom to provide services (FPS) basis to more than 50 active retail clients in at least one EEA Member State. Important clarification: “Retail clients” also include clients treated as professionals on request under MiFID II (opt-up clients). This means some firms may fall within scope even if their client base is not traditionally retail-focused. What Is Required? In-scope CIFs must participate in an electronic questionnaire  hosted on a dedicated EU reporting platform. The questionnaire will collect structured information on cross-border activities, enabling competent authorities to better assess scale, impact, and potential risks arising from such services. Immediate Action Required & Deadlines By Wednesday, 18 February 2026 , all CIFs must take one of the following actions : If in scope: Email riskstatistics.cifs@cysec.gov.cy  with a generic company email address  (e.g., compliance@ , info@ ). CySEC will then send the link to the electronic questionnaire. If not in scope: Formally notify CySEC at the same email address that the firm does not meet the threshold  (i.e., fewer than 50 active retail clients in any EEA Member State). Failure to respond whether in scope or not may be treated as non-compliance.

  • Regulatory Alert: CySEC Circular C751 – DORA Reporting, Governance Portal and Related Obligations

    CySEC has issued Circular C751 , providing targeted operational guidance on specific obligations arising under Regulation (EU) 2022/2554 (DORA) . The Circular focuses on four practical areas: ICT-related incident reporting, the Register of Information submission format, governance of the ICT risk management framework, and mandatory entries in the CySEC Portal. ICT-related incident reporting CySEC states that it has identified deficiencies in how regulated entities classify and report ICT-related incidents. In particular: incidents that should have been classified and reported as “major” were not reported; incidents were reported but incorrectly classified as major. Regulated entities are required to apply the classification criteria and materiality thresholds in Commission Delegated Regulation (EU) 2024/1772 and to ensure timely reporting upon detection of a major ICT-related incident. Register of Information – XBRL-CSV only CySEC reiterates that the “Build in Excel” file is no longer accepted. The Register of Information must be submitted exclusively in XBRL-CSV format, which is the only format accepted by the EBA. Key operational points: use XBRL-compatible software supporting mapping and validation against EBA rules; generate fully compliant XBRL files; zip the files and submit them via the CySEC XBRL Portal; submit annually by 28 February , with reference date 31 December of the preceding year. ICT risk management framework – governance, review and audit CySEC reminds regulated entities of their obligations under Article 6 DORA to establish, implement and maintain a documented ICT risk management framework. In particular: for non-microenterprises, ICT risk management and oversight must be assigned to a control function with appropriate independence and segregation from internal audit; the framework must be reviewed at least annually and following major ICT incidents, supervisory instructions or resilience testing and audit findings; a report on the review must be submitted to CySEC upon request and should be based on Chapter V of Commission Delegated Regulation (EU) 2024/1774 ; for non-microenterprises, the framework must be subject to regular internal audit, with a formal follow-up process for critical ICT audit findings; small and non-interconnected (Class 3) investment firms remain subject to a simplified ICT framework. CySEC Portal – mandatory designations Circular C751 introduces two specific operational obligations in the CySEC Portal: designation of the ICT auditor (for non-microenterprises) under the Auditors section, selecting “Is ICT”; designation of the person responsible for the ICT risk control function under the Personnel section. How ENAH Services Can Support ENAH Services supports regulated entities across the banking, payments, investment and fintech sectors with: DORA implementation and gap assessments ICT risk governance frameworks Incident reporting workflows and simulations ICT third-party risk management and contract reviews Board-level DORA readiness reporting Regulatory engagement and remediation programmes For further information or tailored DORA support, please contact us at consulting@enaservicesltd.com .

  • EU Pay Transparency Directive: What It Means for Employers and Employees in 2026

    In May 2023, the European Union adopted Directive (EU) 2023/970, a landmark piece of labour law aimed at tackling persistent gender-based pay disparities. Often referred to as the EU Pay Transparency Directive, its primary objective is to transform the principle of “equal pay for equal work or work of equal value” into enforceable practice through transparency, reporting, and accountability. Why This Directive Matters Despite decades of law promoting equal pay, wage inequalities across the EU persist. According to recent Eurostat figures, the average gender pay gap remains around 12 – 13 %, with notable differences across Member States. The Directive is designed to: Make pay practices transparent Equip workers with the right to information Expose unjustified pay gaps Encourage early correction and remedies In this way, transparency becomes a tool not just for disclosure, but for action. Key Deadlines Every Employer Should Know EU Member States must transpose the Directive into national law by 7 June 2026 . Only after this transposition will the specific obligations become enforceable at the national level. Once national laws are in place, employers need to prepare for phased pay gap reporting: 250+ employees: first reports due by 7 June 2027 (then annually) 150 – 249 employees: first report by 7 June 2027 (then every 3 years) 100 – 149 employees: reporting begins by 2031 (every 3 years) Member States may impose even stricter requirements or include smaller companies in reporting obligations. What Employers Will Be Required to Do Once implemented nationally, the Directive introduces several important duties: 1. Reporting on Gender Pay Gaps Employers with 100+ employees will need to publish detailed pay gap reports, covering: Average gender pay gap Gap in variable or supplementary pay Median and mean pay comparisons Distribution of men and women across pay quartiles   If a pay gap of 5 % or more  is identified and cannot be justified on objective, gender-neutral grounds, companies must take action to correct it within six months of reporting. 2. Salary Transparency in Recruitment Employers will be required to include salary ranges  in job postings and disclose the criteria used to determine pay. Potential and current employees should have the right to request information on pay comparisons for roles of equal value. This is intended to prevent discriminatory negotiation practices and reduce information asymmetry in hiring. 3. Objective Pay Setting The Directive strengthens the legal principle that equal work or work of equal value must be remunerated equally. Employers must rely on objective, gender-neutral criteria  when determining remuneration. How Employers Can Prepare Now With the June 2026 deadline approaching fast, preparation should begin immediately: Audit Current Pay Structures: Start collecting and analysing internal pay data by gender across all job categories. Establish Transparent Pay Policies : Create documented, objective criteria for salary decisions and ranges for roles. Engage HR, Legal & Compliance: Integrate reporting and compliance tasks into your HR and governance frameworks. Educate Leaders and Employees: Build internal understanding of the Directive’s requirements and expectations. Conclusion The EU Pay Transparency Directive marks a significant shift from “equal pay as a principle” toward equal pay as proof. It places employers and policymakers on a shared journey toward measurable gender pay equity, backed by enforceable transparency measures and accountability. For employers operating across the EU and HR professionals supporting them early action is not only wise, it’s essential. Compliance will require strategic planning, cultural change, and robust data management, but it also presents a unique opportunity to lead on fairness and equity in the workplace.

  • The PSD3 / PSR Political Agreement: What Was Decided, What Comes Next

    The Political Decision: Why This Agreement Matters Following prolonged negotiations, the European Parliament and the Council of the European Union reached a political agreement on the new Payment Services Regulation (PSR) and the Third Payment Services Directive (PSD3)  package on the basis of the proposal advanced by the European Commission. This agreement is politically significant for three reasons: It represents a strategic shift from minimum harmonisation to direct applicability, via the PSR. It responds to systemic weaknesses in fraud prevention, especially Authorised Push Payment (APP) fraud. It completes the post-PSD2 recalibration of EU payments law, aligning it with the Digital Finance Strategy, DORA, and broader consumer-protection objectives. What Was Agreed: Core Elements of the PSD3 / PSR Package A New Legal Architecture The framework is split deliberately: PSR (Regulation) : directly applicable rules on conduct of business, transparency, fraud liability, and operational requirements. PSD3 (Directive) : institutional and prudential matters (licensing, supervision, passporting, governance). This division aims to reduce national divergence that undermined PSD2’s effectiveness. Stronger Fraud Protection & Liability Rules A key political concession was enhanced consumer protection against fraud: Mandatory reimbursement for certain APP fraud cases, subject to limited exceptions. Reinforced obligations for PSPs on transaction monitoring and customer warnings. Greater emphasis on shared liability across the payment chain. This is one of the most contentious areas and will be heavily scrutinised in implementation. Transparency and Fee Disclosure The agreed text strengthens rules on: Hidden charges and opaque FX mark-ups. Pre-transaction and post-transaction disclosure obligations. Comparability of fees across providers. Open Banking / Open Finance Continuity While not revolutionary, the package: Consolidates access-to-account rules. Seeks to stabilise business models for third-party providers (TPPs). Addresses data-access friction without fully moving into “Open Finance” (reserved for future initiatives). What Happens Next: The Formal and Practical Timeline The political agreement must still pass through: Legal-linguistic finalisation Formal adoption by Parliament and Council Publication in the Official Journal Only then do the clocks start running. Indicatively: PSR : applies directly after a transition period (18–24 months). PSD3 : Member States will have a transposition deadline (typically ~18 months). For firms, the message is clear: Compliance will no longer be defensive. It will be operational, technological, and strategic. Early preparation, legal, compliance, IT, and governance-wise will be the decisive differentiator. The agreed measures must be formally adopted by the European Parliament and the Council of the European Union before they can come into force. The Council and the Parliament will continue working on the technical elements of the package before final adoption by the co-legislators. We anticipate that the final texts will be published in the Official Journal of the European Union in H1 2026.

  • CySEC Signals Major Shift: EU Securities Market Moves to T+1 Settlement Cycle

    The Cyprus Securities and Exchange Commission (CySEC) has issued Circular C741 to regulated market participants, signalling an important evolution in the post-trade landscape of European securities markets. This development aligns Cyprus with broader EU policy aimed at boosting market efficiency, reducing risk, and harmonising settlement practices with global standards. What’s Changing? Under the updated EU framework, specifically Regulation (EU) 2025/2075   amending the Central Securities Depositories Regulation (CSDR), the standard settlement cycle for most securities transactions in the EU will be shortened from T+2 to T+1. That means trades in equities, bonds, and other transferable securities executed on trading venues must be settled no later than one business day after the trade date. This is a significant acceleration compared to the traditional two-day cycle. Transition Timeline Regulation Entry into Force: 3 November 2025 Effective Application Date:  11 October 2027 Why T+1 Matters The move to T+1 settlement is driven by three key objectives : Operational Efficiency:  Shorter settlement cycles reduce the time between trade execution and settlement, streamlining the post-trade process. Risk Reduction:  By cutting the exposure window, market participants face lower counterparty and settlement risk - a major benefit during periods of market stress. Global Alignment : Many leading markets outside the EU, including the United States, already operate on a T+1 basis, and this shift harmonises European practices with international norms. What Transactions Are Covered? The T+1 requirement applies broadly to transferable securities executed on trading venues. However, the regulation clarifies that certain trades remain outside its scope, such as: Privately negotiated trades executed on trading venues Bilateral trades reported to trading venues Initial book-entry transactions under specific conditions Certain securities financing transactions (SFTs) Margin lending (as these are not considered transactions in transferable securities) Practical Implications for Firms Regulated entities, including Cyprus Investment Firms (CIFs), UCITS, AIFs, trading venues, and central securities depositories, are now encouraged to begin their readiness preparations. According to the Circular: Entities are urged to review the potential impact of the transition on internal systems, operational workflows, liquidity and treasury frameworks, client onboarding practices, and cross-border arrangements. This early engagement is especially important, as technological and procedural adjustments will be necessary to comply with the tighter settlement timeline. Industry Collaboration: T+1 Readiness Survey In addition to the regulatory timeline, the EU T+1 Industry Committee has launched a readiness survey to gauge the preparedness of market participants. CySEC’s Circular strongly encourages regulated entities to participate in this exercise in order to help identify challenges and operational bottlenecks ahead of implementation. What’s Next? As the countdown to October 2027 begins, market participants must take proactive steps to adapt: Upgrade systems to support T+1 clearing and settlement processes. Assess liquidity management practices to accommodate faster cash and securities flows. Coordinate across departments to ensure seamless transition. The shift to T+1 is more than a technical tweak; it represents a structural enhancement to EU financial markets that promises greater resilience and efficiency. For Cyprus-based firms under CySEC supervision, early planning and active engagement with the T+1 readiness initiatives will be key to complying with this new chapter in European capital markets.

  • Regulatory Alert: EMIR Data-Collection for Initial Margin Model Validation

    On December 12, 2025, the Cyprus Securities and Exchange Commission (CySEC) published a Circular C740 , addressing the upcoming regulatory requirements under the European Market Infrastructure Regulation (EMIR). This circular sets out precise data-collection expectations for regulated entities in Cyprus that are subject to EMIR’s initial margin model authorisation and validation procedures. Background: EMIR and Initial Margin Models Under Article 11(3) of EMIR (Regulation (EU) No 648/2012), firms that exchange initial margin and use internal margin models—such as the ISDA Standard Initial Margin Model (SIMM)—must seek prior authorisation from their competent authority before implementing or continuing to use such models. Moreover, validation of these models by the European Banking Authority (EBA) is required before they can be adopted across the EU. What is Required The core purpose of Circular C740 is to ensure that regulated entities report the necessary information to CySEC by 16 January 2026 to facilitate: Identification of which entities need to apply for authorization and subsequent EBA validation. Onboarding of these entities to the EBA’s ISDA SIMM Validation System (under development). To this end, the circular instructs entities to send: The standard data set specified in the EBA’s opinion on initial margin model applications. A completed template (titled “EMIR IMM application for authorisation_LEI of Regulated Entity” and referenced as “EMIR IMM validation_LEI of Regulated Entity.xlsx”) — submitted to CySEC via email to emir@cysec.gov.cy . This information will then be transmitted by CySEC to the EBA for validation purposes. 📌 Key Takeaways for Compliance Teams For compliance officers in Cyprus-regulated entities (investment firms, UCITS, AIFs, non-financial counterparties), Circular C740 imposes urgent data submission requirements that must be prioritised to avoid regulatory gaps. Identify whether your entity exceeds EMIR initial margin thresholds. Prepare the required datasets and complete the CySEC/EBA templates. Submit all data to CySEC no later than 16 January 2026. Ensure readiness for the next phase: EBA validation of internal margin models. Deadline Regulated entities must submit their data to CySEC by 16 January 2026 , creating an immediate compliance priority for affected firms. Entities that fail to submit the required data will not be onboarded to the EBA validation system, effectively preventing them from applying for the EBA validation and thereby risking non-compliance with EMIR.

  • Loan-Originating AIFs vs Banks: Same Activity, Different Architecture in the Years Ahead

    In the coming years, loan-originating Alternative Investment Funds (LO-AIFs) will continue to expand their presence across the European credit landscape. Although banks and LO-AIFs will both engage in lending, they will do so under fundamentally different business models, funding structures and regulatory regimes. Understanding these distinctions will become increasingly important for policymakers, investors and market participants as private credit grows into a mainstream financing channel. 1. Business Purpose and Economic Function Banks will remain financial intermediaries serving the wider public. They will continue accepting deposits, safeguarding money, facilitating payments and extending credit that supports the real economy. Their role will remain systemic and central to financial stability. LO-AIFs, meanwhile, will operate as investment funds designed to generate returns for professional investors. They will raise committed capital and deploy it into private lending opportunities without performing any public-intermediation or monetary-system function. Key distinction: Banks will continue serving depositors and the payment system. LO-AIFs will continue serving investors seeking yield. 2. Funding, Liquidity and Redemption Dynamics Banks will keep relying on deposits, wholesale markets, central-bank liquidity and bond funding. Their liabilities will remain short term and payable on demand, meaning that liquidity and funding management will continue to be essential to their resilience. LO-AIFs will operate with committed capital and controlled redemption mechanisms. Investors will continue accepting illiquidity as part of the private-debt strategy. Because LO-AIFs will not take deposits or guarantee instant withdrawals, their liquidity risk will evolve differently from that of banks. Banks will face: deposit withdrawals payment-system liquidity obligations systemic liquidity shocks LO-AIFs will face: liquidity constraints linked to loan portfolios redemption pressures only where the fund is open-ended no systemic run risk 3. Regulatory Frameworks: Prudential vs Investment-Fund Supervision Banks will remain subject to CRR/CRD, Basel III requirements, leverage ratios, supervisory stress testing and resolution planning. These rules will continue to exist because banks will remain “public crisis points,” requiring strong prudential oversight. Under AIFMD II, LO-AIFs will operate under a regulatory framework focused on investor protection and sound fund governance, not systemic risk. Although LO-AIFs will incorporate bank-style credit processes, their oversight will continue reflecting their nature as investment products. The LO-AIF regime will include: leverage limits risk-retention rules lending prohibitions to connected persons enhanced underwriting standards liquidity and redemption governance stress testing for open-ended funds Banks and LO-AIFs will both lend, but the regulatory logic behind each model will remain fundamentally different. 4. Lending Behaviour and Market Focus Banks will continue prioritising standardised, collateralised and low-risk lending, driven by capital requirements and risk-weighted asset considerations. They will maintain strength in relationship banking, retail lending and senior secured credit. LO-AIFs will increasingly focus on specialised, higher-yielding private credit, such as: SME growth finance real-estate mezzanine and development loans infrastructure and project finance distressed and opportunistic credit sponsor-backed private-debt transactions This flexibility will allow LO-AIFs to serve segments where banks will remain constrained by prudential rules or slower credit processes. 5. Risk Profiles and Risk Transmission Banks will continue carrying composite risks — credit, liquidity, systemic and interest-rate mismatch risks. Bank distress will remain capable of transmitting shocks across the financial system due to their public-facing and deposit-taking role. LO-AIF risks will remain contained within a closed group of professional investors. Losses will continue being absorbed by the fund’s capital without affecting depositors or requiring public intervention. While open-ended LO-AIFs will still face liquidity-management challenges, these will be controlled through redemption gates, notice periods and liquidity-management tools. Crucially, LO-AIF failures will not generate systemic contagion in the way bank failures could. 6. Complementarity: A Dual Credit Ecosystem In future years, banks and LO-AIFs will increasingly operate in a complementary  manner rather than competing directly. Banks will: originate senior or low-risk loans that LO-AIFs could acquire or participate in partner with LO-AIFs in syndicated lending use LO-AIFs as an outlet for NPL disposals or balance-sheet optimisation refer borrowers requiring complex or flexible financing LO-AIFs will: provide credit where banks will remain limited by capital rules support SMEs, real estate, infrastructure and transitional finance offer speed and structural flexibility co-lend with banks in multi-layered financing packages The strongest credit markets will be those where both channels operate in parallel. Conclusion: Divergent Structures, Converging Roles Although banks and LO-AIFs will both lend, their functions, incentives and regulatory foundations will remain distinct. Banks will continue to anchor financial stability and public trust. LO-AIFs will increasingly channel institutional capital into specialised private-credit opportunities, without taking on systemic responsibilities. As AIFMD II is implemented, and as private credit continues to evolve, Europe’s financing landscape will likely transition toward a dual-track credit system: one supported by prudentially regulated banks, and one driven by flexible, investor-funded LO-AIFs. The goal will not be to force convergence but to ensure that each model operates within a framework that reflects its risks, responsibilities and contribution to the economy.

  • Regulatory Alert: AML Awareness: EU Adds Russia to “High-Risk Third Countries” List

    Source: European Commission Press Release IP/25/2910 Date: 03 December 2025 On 3 December 2025, the European Commission (the “Commission”) officially added Russia to its list of “high-risk third countries with strategic deficiencies” in their anti-money laundering and counter-terrorist financing (AML/CFT) frameworks. The addition follows a technical assessment mandated by Delegated Regulation (EU) 2025/1393, under the scope of the Fourth Anti‑Money Laundering Directive (4AMLD). The evaluation considered public sources, inputs from Member States’ authorities, and information from the European External Action Service (EEAS). As a result, all entities and financial institutions within the EU that fall under the AML framework are now required to apply “enhanced vigilance / enhanced due diligence (EDD)” when dealing with transactions involving Russia (or counterparties connected to Russia). Find the European Commission - Press release here : https://ec.europa.eu/commission/presscorner/api/files/document/print/en/ip_25_2910/IP_25_2910_EN.pdf   Next steps: The delegated regulation will enter into force after scrutiny and non-objection of the European Parliament and the Council within a period of one month. This can be prolonged for another month. The Commission will monitor the progress of all listed countries and will continue to follow relevant developments. For more information Directive on anti-money laundering and terrorist funding (AMLD IV) Anti-Money Laundering Authority (AMLA) The Financial Action Taskforce (FATF)

  • Commission launches whistleblower tool for EU Artificial Intelligence Act (AI Act)

    The European Commission has launched today a new whistleblower tool designed to support enforcement of the AI Act. In brief: What is the new whistleblower tool The tool offers a secure and confidential channel  for individuals to report suspected breaches of the AI Act. Reports go directly to the European AI Office. Reports can be submitted in any official EU language , in any format , which aims to maximize accessibility for whistleblowers across the EU. The system uses certified encryption mechanisms  to guarantee confidentiality and data protection. Reporters remain anonymous, yet they can receive secure follow-up communications : updates on the progress of their report and the possibility to answer additional questions from the EI AI Office - all without compromising anonymity. Why this matters The AI Act aims to foster innovation and adoption of artificial intelligence across the EU, while at the same time safeguarding health, safety, fundamental rights, public trust, and the rule of law . Effective enforcement of the AI Act is key to ensuring compliance. The whistleblower tool empowers insiders , employees, collaborators, shareholders, or other stakeholders with knowledge about AI systems to report non-compliance early . This helps the EU AI Office detect and address risks before they escalate. With this tool, the Commission leverages transparency and accountability  as core mechanisms for AI governance, which is especially important in a regulatory environment where full oversight of complex AI systems is technically and practically challenging. Practical points & Current Limitations |Currently, the tool ensures confidentiality and anonymity , but statutory protection against retaliation  (e.g., from employers) under the general EU whistleblower rules -namely the Whistleblower Directive - will only apply to AI Act-related reports from 2 August 2026  onwards. Until then, protections remain based on Commission assurances. Despite those caveats, the tool represents a significant step forward . As noted by independent observers, early detection of AI-related risks (e.g. breaches of safety, privacy, non-discrimination) can meaningfully contribute to “safe, transparent and trustworthy” AI deployment across the EU.

  • The EU’s “Digital Omnibus on AI” - What it means for companies’ AI compliance roadmaps

    The European Commission has proposed the Digital Omnibus on AI , a legislative package designed to adjust and simplify the implementation of the EU AI Act . The goal is to give organisations more flexibility, align compliance deadlines with the availability of technical standards, and ease the burden on companies deploying AI in the EU. Key Changes at a Glance Flexible compliance deadlines: Instead of fixed dates, the obligations for high-risk AI systems would take effect only when the relevant EU standards or guidelines are published. If these are delayed, fallback deadlines will apply from late 2027 to mid-2028. Companies would also get short grace periods to complete compliance work. Transitional support for existing systems: Generative AI models and high-risk AI systems already on the market would benefit from additional time to adjust. “Legacy” high-risk systems can continue to be used or sold if their design remains unchanged. Reduced administrative load: Lower-risk AI systems would no longer need to be listed in the EU AI database. Providers must still conduct risk assessments, but only need to submit them on request. The proposal also broadens the ability to process sensitive data for bias-mitigation, subject to safeguards. More flexibility for GPAI and content-marking: The mandatory element for codes of practice on general-purpose AI and content provenance would be removed. These frameworks would stay as soft-law tools, not binding legal requirements. Support for SMEs and smaller mid-caps: The simplified regime available under the AI Act would be expanded, reducing documentation demands and lowering fines for qualifying companies. What This Means for Organisations Businesses should treat this proposal as an opportunity to recalibrate their AI compliance plans, not as an excuse to delay preparation. The Diogital Omnibus Directivemay offer extra time, but deadlines can still arrive early if EU standards are finalised sooner. Organisations should continue building strong AI governance, documentation and monitoring processes, especially if operating in regulated sectors like financial services. What’s Next? The Digital Omnibus Directive is still under negotiation and may change before adoption. If it is not finalised before August 2026, the original AI Act deadlines will remain in force. Organisations should therefore continue preparing proactively while monitoring legislative developments.

  • Regulatory Alert: CySEC Circular C736 – Key Observations on the Prudential Framework for CIFs

    On 24 October 2025, CySEC issued on 24.10.2025 a Circular  C736 – Key Observations on the Prudential Framework for CIFs , addressed to Cyprus Investment Firms (CIFs), highlighting a series of supervisory observations and recommendations regarding the implementation of the prudential framework under Law 165(I)/2021 (Investment Firms) and Regulation (EU) 2019/2033 (IFR). Why it matters The Circular underscores that CySEC has identified recurring issues in how CIFs apply key prudential rules. These findings reflect both reporting and governance weaknesses, and signal that supervisory scrutiny will increase. Failure to adjust may lead to remedial measures or sanctions. Main Observations In brief: Timely Submission of Prudential Reporting CySEC observed delays in the submission of required prudential reports via the XBRL portal, and the use of outdated templates. Firms are reminded to submit all required reports within deadlines and to check the CySEC and EBA websites for the latest templates. Ongoing Compliance with Prudential Requirements Some CIFs are found to be failing to meet prudential obligations under Articles 9, 11 and 43 of the IFR, and to notify CySEC when they identify deficiencies. CySEC emphasises a proactive approach: monitoring requirements continuously and implementing corrective measures without delay. c Data Consistency Across Reporting Sources Significant inconsistencies were identified between the data reported via XBRL and other sources such as audited financial statements, QST-CIF forms and management accounts. Issues relate to profit/loss figures, retained earnings, own funds, liquid assets and fixed overheads. For example, the figure for “Annual fixed overheads of the previous year after distribution of profits” in the templates must align with audited statements and remain unchanged until the next audit. Remuneration Policies (Class 2 CIFs) The circular finds that some Class 2 CIFs did not comply with requirements such as: at least 50% of variable remuneration being in instruments; at least 40% deferred over a three-to-five-year period; and alignment with Law 165(I)/2021 and the EBA’s guidance. Establishment of Risk & Remuneration Committees CySEC identified CIFs that did not establish required committees (per sections 22 and 27 of Law 165(I)/2021), had committees composed solely of executive directors, single-person committees or lacked gender balance in remuneration committees. Internal Governance and Conflicts of Interest The circular highlights cases where Class 2 CIFs failed to implement conflicts-of-interest policies in loans or other transactions with members of the management body or their related parties, contrary to Law 165(I)/2021 and EBA internal governance guidelines. Liquidity Requirements (Article 43 IFR) CIFs have misclassified certain items as “unencumbered short-term deposits at a credit institution” which do not  meet the definition of liquid assets under Article 43(1) IFR. Examples: funds held with Electronic Money Institutions (EMIs), Payment Service Providers (PSPs), client-fund buffers, or contributions to the Investors Compensation Fund. Prudential Consolidation Supervisory findings include failures in assessing group structures for the purposes of prudential consolidation under the IFR and the new Regulation (EU) 2024/1771. Key issues relate to wrongly identifying whether an entity is a financial institution, union parent investment firm, or correctly applying consolidation requirements after structural changes. Completion of Form 165-03 (Section C) CySEC found that some CIFs did not disclose modified audit opinions or include links to their Pillar III disclosures in Section C of Form 165-03. Next Steps & Supervisory Warning CySEC advises CIFs to undertake a comprehensive review  of their practices across reporting, governance and prudential frameworks to ensure full compliance with Law 165(I)/2021, the IFR, applicable delegated regulations and the EBA’s guidelines. CySEC also states that it will continue its monitoring and will apply appropriate measures , including administrative sanctions or other supervisory actions, in cases of non-compliance. Implications for CIFs For CIFs operating in Cyprus, Circular C736 signals that the regulatory focus is sharpening on prudential discipline and governance. Some practical implications to consider: Reviewing internal processes for timely and accurate XBRL/prudential reporting. Ensuring full alignment and documentation across audited accounts, management accounts and reporting templates. Verifying governance structures, committee operations and remuneration frameworks for compliance. Re-classifying assets/liabilities appropriately under IFR definitions (especially liquid assets). Assessing group structure and consolidation requirements whenever there are changes. Strengthening disclosure practices for audit opinions and Pillar III disclosures. CySEC’s Circular C736 sends a clear supervisory message: accuracy, governance alignment and prudential discipline are now under closer regulatory scrutiny. CIFs are expected to address identified weaknesses promptly and ensure full and ongoing compliance with IFR requirements.

bottom of page