Financial Services and Fintech
Financial services firms answer to more regulators than almost any other sector, and several of those regulators now test the change process itself. In the UK, the expectation to spot and act on regulatory change is assembled from the FCA Handbook, starting with SYSC 6.1.1R on compliance policies and procedures. In the EU, DORA, Regulation (EU) 2022/2554, has applied since 17 January 2025, and the MiCA transitional period for crypto-asset service providers closed on 1 July 2026. In the US, bank examiners score change management as a named factor in the FFIEC consumer compliance rating system.
The guides here are written from the compliance seat: what UK firms must demonstrate on horizon scanning, a MiCA checklist for the post-transition market, a worked DORA impact assessment, a DORA obligations register and an FFIEC-aligned change management policy.
Start here
- Horizon Scanning and FCA Expectations: What UK Firms Must DemonstrateWe found no FCA Handbook rule that names horizon scanning; the expectation is assembled from SYSC, the Principles and the Senior Manager Conduct Rules. This piece maps each anchor to the evidence a supervisor can ask for, with a 17-row checklist and the enforcement record for firms that missed changes.
- MiCA Compliance Checklist for Crypto Firms After the TransitionThe Article 143(3) grandfathering window closed on 1 July 2026, which makes most MiCA checklists obsolete. This one lists obligations by entity type with article-level citations, the evidence supervisors ask for, and the TFR, DORA and AMLR dates that land on the same firms.
- Regulatory Change Impact Assessment Template (With a Worked DORA Example)A six-section regulatory change impact assessment template, published in full with no sign-up wall, then filled in end to end for the DORA subcontracting RTS. It includes the fields most templates omit: instrument lifecycle status, documented out-of-scope reasoning, and evidence and validation for each obligation.
- Regulatory Obligations Register Template: How to Build One That Survives an AuditA free, ungated obligations register template with 28 annotated fields, six populated rows from DORA, and the change-management columns that decide whether the register survives an audit. It is built for a time when regulators collect registers in prescribed formats.
- Regulatory Change Management Policy Template (FFIEC-Aligned)A 13-section regulatory change management policy template published in full with no email gate, plus a crosswalk that maps each section to the FFIEC rating-system language and OCC examination procedure it answers, and a change log entry with a worked example.
- EU AMLR Readiness Checklist: What to Do Before 10 July 2027 (With AMLA's Standards Tracked)The AMLR applies from 10 July 2027, and AMLA finalized its CDD, linked-transaction and group-wide standards on 1 October 2026. This checklist maps 14 workstreams to AMLR articles, owners and the evidence examiners sample, with a standards tracker, a 90-day plan and a group view.
- GENIUS Act Implementation Tracker: Every Rule, Agency and Deadline Before 18 January 2027The GENIUS Act takes effect on 18 January 2027, and by 2 October 2026 the OCC, FDIC, Federal Reserve and NCUA had not finalized a single rule. This tracker lists all 14 rulemakings by agency and stage, what applies on day one without them, and a 15-week checklist for banks, payment firms and crypto platforms.
Terms
- DORA (Digital Operational Resilience Act)
- MiCA (Markets in Crypto-Assets Regulation)
- AMLA (Anti-Money Laundering Authority)
- PSD3 and the Payment Services Regulation (PSR)
- Basel III endgame
- FCA Consumer Duty
- Operational resilience
- Third-party risk management
- Regulatory and implementing technical standards (RTS and ITS)
- SEC rulemaking
- FINRA Regulatory Notices

Bring your regulators. We’ll show you what applies.
A session run on the regulators and markets you name.