Risk Intelligence Archives -

Baretzky & Partners LLP has published its European Risk Mitigation Report 2026: Frozen Sovereign Assets — EU Legal Weaponisation & Corporate Exposure — a high-priority risk intelligence assessment prepared for US corporate clients operating in or exposed to the European Union. Assigned an overall risk grade of HIGH — R-4, this report addresses one of the most consequential legal and financial confrontations to emerge in the EU since 1945.

Why This Report Matters Right Now

On 1 June 2026, the Central Bank of Russia formally filed a lawsuit before the General Court of the European Union challenging the legality of the EU’s 90 billion euro loan-to-Ukraine mechanism — a mechanism financed by interest proceeds stripped from approximately 300 billion dollars in frozen Russian sovereign assets held principally at Euroclear in Belgium. This filing crystallises a legal confrontation years in the making and represents the most consequential challenge to EU property-rights architecture since the bloc’s inception.

For US corporations with European operations, contractual counterparties, asset holdings, or transactional exposure, the ramifications are material, immediate, and inadequately understood. Euroclear — which holds the bulk of frozen Russian assets — is also a principal infrastructure node for the settlement of US corporate bonds, equities, and structured products in European markets. Any disruption to Euroclear’s legal standing, capital adequacy, or operational continuity creates direct settlement risk for US-issued securities.

What the Report Covers

  • Legal Architecture & Procedural Status (Part II) — A detailed analysis of the CBR lawsuit before the EU General Court, the December 2025 indefinite freeze extension challenge, the 230 billion dollar Moscow arbitration award against Euroclear, and the network of bilateral treaty claims spanning multiple jurisdictions.
  • Macro-Financial & Regulatory Environment (Part III) — Assessment of the macro-financial consequences for the EU and the euro, including regulatory contagion, counterparty instability, and clearing and settlement disruption risks.
  • Sector-by-Sector Exposure Analysis for US Corporations (Part IV) — Targeted analysis of sector-specific corporate exposures, identifying where US firms face direct and indirect risk from the evolving legal environment.
  • Litigation Risk & Legal Liability Pathways (Part V) — Evaluation of litigation exposure, sanctions divergence risk between US (OFAC) and EU regimes, and legal liability pathways for firms with European nexus.
  • Mitigation Framework & Recommended Actions (Part VI) — A structured six-workstream mitigation programme including settlement infrastructure audit, sanctions divergence mapping, contractual review, legal monitoring protocol, board-level governance, and insurance programme review.
  • Scenario Analysis & Stress-Testing (Part VII) — Forward-looking scenario modelling across a 24-month horizon, including escalation triggers and probability-weighted outcome ranges.
  • Conclusions & Risk Grade Rationale (Part VIII) — Final risk grade rationale and the conditions under which the grade would be elevated to R-5 (Critical).

Key Risk Domains Assessed

The report identifies four principal risk domains: Legal and Litigation Risk (R-4 HIGH), driven by the CBR lawsuit and Euroclear sovereign immunity doctrine; Settlement and Clearing Risk (R-3 ELEVATED), driven by Euroclear operational stress and T2S disruption scenarios; Sanctions Divergence Risk (R-4 HIGH), driven by the widening US-EU regime gap and secondary sanctions exposure; and Regulatory Contagion Risk, driven by the accelerating fragmentation of the international legal order underpinning cross-border commerce.

Who Should Read This Report

This report is essential reading for general counsel, chief risk officers, treasurers, and board audit committees of any US corporation that maintains a meaningful nexus with the European Union — including financial institutions, multinational corporates with European subsidiaries or counterparties, asset managers with EU-settled securities, and professional services firms advising on cross-border transactions. Boards and senior management teams that treat this report as background reading do so at material risk to shareholder value, regulatory standing, and operational continuity.

Access the Report

The European Risk Mitigation Report 2026 is available free of charge through our Risk Intelligence Reports page. Select the report, complete the short access form, and download your copy immediately.

Subscribe on the reports page to receive future country and sector reports as they are published by Baretzky & Partners LLP.


Baretzky & Partners LLP is a multinational risk mitigation and cyber intelligence advisory firm, headquartered in Washington DC. This report was authored by Dr. Ricardo Baretzky, PhD (Law), Senior Partner and specialist in Risk Mitigation, Strategic Risk, Legal Affairs, and Crisis Mitigation & Investigations.

AML supervision has become one of the most intensely scrutinised areas in banking and financial services compliance. Regulators across the EU, UK, and US have dramatically increased enforcement actions against firms with inadequate anti-money laundering controls — and the pace of regulatory change in 2026 shows no sign of slowing. For compliance teams and risk officers, understanding where the principal failure points lie is essential to building programmes that withstand supervisory scrutiny.

Why AML Supervision Risk Is Escalating

The global AML and financial crime landscape has shifted fundamentally over the past three years. The FATF Recommendations continue to drive national-level legislative reform, while the EU’s Anti-Money Laundering Authority (AMLA) is now operational and imposing direct supervisory mandates on high-risk obligated entities. In the US, FinCEN’s beneficial ownership registry under the Corporate Transparency Act (CTA) has added new layers of compliance obligation, particularly for correspondent banking and cross-border transactional business.

Against this backdrop, firms that have not modernised their AML compliance infrastructure face compounding risk: not just regulatory penalty, but reputational harm and the operational disruption of remediation programmes imposed under supervisory direction.

Key Risk Areas in AML Supervision

1. Transaction Monitoring Gaps

Transaction monitoring remains the most commonly cited deficiency in AML supervisory findings. Regulators consistently identify tuning failures — systems that generate too many false positives without catching genuine risk, or that have not been recalibrated to reflect changes in product mix, customer base, or typology guidance. FATF’s updated guidance on risk-based transaction monitoring places the onus firmly on firms to document and evidence their calibration methodology, including threshold decisions and scenario logic.

Key risk indicators in this area include: failure to monitor cash transactions below reporting thresholds, insufficient coverage of digital asset and crypto-adjacent activity, and alert backlogs that result in investigations being completed outside of required timeframes.

2. Customer Risk Stratification and KYC Inadequacies

Customer risk rating models that were designed years ago may no longer reflect the risk profile of the current customer base. Regulators pay particular attention to whether firms have applied enhanced due diligence (EDD) consistently to high-risk customers, including Politically Exposed Persons (PEPs), high-net-worth individuals, and customers operating in high-risk jurisdictions as identified by FATF’s grey and black lists.

A common supervisory concern is the failure to refresh customer due diligence on a risk-rated cycle — firms that onboard clients correctly but fail to update KYC records when material changes occur are routinely cited in enforcement actions. Baretzky & Partners’ KYC framework advisory specifically addresses this gap through ongoing monitoring design and trigger-based refresh protocols.

3. Sanctions Screening Infrastructure

Sanctions compliance sits at the intersection of AML and financial crime risk, and screening failures have resulted in some of the largest financial penalties in recent enforcement history. The convergence of EU, UN, US OFAC, and UK OFSI sanctions regimes — particularly following escalation of Russia-related designations — has significantly increased the complexity of maintaining effective screening infrastructure.

Key risks include: screening system lag time (screens that are updated too infrequently), failure to screen against all relevant lists, inadequate fuzzy matching logic for name variants and transliterated names, and insufficient documentation of screening decisions. Firms operating in multiple jurisdictions must also manage conflicting obligations between regimes.

4. Governance and Accountability Frameworks

Supervisors are increasingly focused on governance — specifically, whether the MLRO has adequate authority and resource, whether the Board and Senior Management are receiving meaningful AML MI, and whether there is a documented three-lines-of-defence model with clear accountability. The Senior Managers and Certification Regime (SMCR) in the UK, and equivalent accountability frameworks in the EU and US, have made personal liability for AML failures a real and pressing concern for individual executives.

Regulators expect to see documented Board-level risk appetite statements for financial crime, supported by regular management information reports that track programme performance against defined metrics — not simply activity metrics, but outcome measures.

5. Regulatory Response and Remediation Readiness

When supervisors initiate an AML review — whether via a themed examination, Dear CEO letter, or enforcement action — the firm’s response capability is itself a supervisory risk. Firms that lack documented policies, cannot produce evidence of control operation, or whose compliance teams are unable to articulate the design rationale for key controls, consistently receive more adverse findings.

Remediation programmes imposed by regulators under supervisory direction are enormously disruptive and costly. Proactive investment in programme quality assurance — including independent testing, look-back reviews, and model validation — significantly reduces the risk of mandated remediation.

How Baretzky & Partners Supports AML Supervision Risk Management

Baretzky & Partners operates an AML and financial crime advisory practice that covers the full compliance lifecycle. Our FATF-aligned methodology and deep knowledge of EU, UK, US, and international sanctions regimes means we are well-positioned to support firms across all the key risk areas identified above.

Our AML supervision support services include: AML programme gap analysis and maturity assessment; transaction monitoring model validation and recalibration; KYC framework design and EDD protocol development; sanctions screening infrastructure review; governance and MLRO effectiveness assessment; and regulatory response and remediation programme management.

Whether your organisation is preparing for a regulatory examination, responding to supervisory findings, or proactively strengthening its financial crime framework ahead of AMLA’s expanded supervisory scope, our specialists can deliver findings and recommendations within defined timeframes.

AML Supervision in 2026: The Strategic Imperative

The direction of travel in AML supervision is unambiguous: regulators are more resourced, more coordinated, and more willing to use enforcement tools than at any previous point. The establishment of AMLA, combined with FinCEN’s continued rulemaking activity and the FCA’s publication of its three-year strategy placing financial crime at the top of its supervisory agenda, means that the window for addressing programme gaps is narrowing.

For banks, payment institutions, and other obligated entities, the strategic imperative is clear: invest now in programme quality assurance, governance infrastructure, and the specialist advisory capability needed to navigate an increasingly demanding supervisory environment.

For enquiries about AML supervision risk management, programme assessment, or regulatory response support, contact Baretzky & Partners via our enquiry form or reach our specialists directly at info@baretzky.com.

IP Assets Are Your Most Valuable — And Most Vulnerable — Business Assets

For many organisations, intellectual property is their primary source of competitive advantage. Brands, patents, trade secrets, copyrights, and proprietary technology represent years of investment and differentiation — and they are increasingly at risk. Counterfeiting, trademark infringement, domain name abuse, and IP theft in the digital environment have all escalated dramatically, while the legal landscape for IP protection has become both more complex and more valuable to navigate effectively.

At Baretzky & Partners LLP, we approach intellectual property as a strategic asset management challenge — not just a legal compliance exercise. As an authorised EUIPO service provider (Reg. No. 107758), our IP specialists have a proven track record in European trademark registration, brand protection, and IP risk management for organisations operating globally. Our practice covers the full lifecycle of intellectual property: from registration and portfolio management through to infringement investigation and M&A IP due diligence.

European Trademark Registration: The EUIPO Advantage

European Union trademark registration through EUIPO (the European Union Intellectual Property Office) provides protection across all 27 EU member states with a single application — one of the most cost-effective and comprehensive forms of IP protection available to organisations with European operations or markets.

As an authorised EUIPO service provider, Baretzky & Partners manages the full EU trademark registration process: initial trademark search and clearance to identify conflicts and assess registrability, filing and prosecution of the application through the EUIPO examination process, opposition proceedings where third parties challenge the application, and ongoing trademark portfolio management and renewal.

The Madrid Protocol provides a pathway for extending trademark protection internationally through a single application — making it the preferred mechanism for organisations seeking protection in multiple jurisdictions simultaneously. Our team manages Madrid Protocol applications and coordinates with local counsel in non-EU jurisdictions to build comprehensive global trademark portfolios.

Our track record includes successful trademark registrations for clients across Europe, Asia, and the Americas — including organisations in financial services, technology, professional services, and consumer goods sectors.

Brand Protection and Enforcement: Protecting What You Have Registered

Registration is only the beginning of effective trademark protection. In the digital economy, brand abuse — counterfeit goods, online infringement, domain name disputes, and social media impersonation — represents a growing and rapidly evolving threat that requires active monitoring and enforcement.

Our brand protection practice provides brand monitoring and watch services that identify infringement as it emerges, enabling early intervention before significant damage is done. When infringement is identified, our approach combines legal action — cease and desist strategy, opposition proceedings, and litigation preparation — with cyber intelligence support to investigate the scope and source of infringement and gather evidence that supports enforcement.

Counterfeit investigation is a specialist discipline that requires both legal authority and investigative capability. Our team has experience investigating counterfeit operations across multiple jurisdictions — coordinating with customs authorities, law enforcement agencies, and e-commerce platforms to disrupt infringement at scale.

Domain name disputes under the UDRP (Uniform Domain-Name Dispute-Resolution Policy) provide a faster and less expensive alternative to litigation for recovering domains that infringe registered trademarks. We manage UDRP proceedings from complaint preparation through to decision, with a strong success rate in recovering domain names for legitimate brand owners.

IP Risk Management: Building a Strategic Framework

Risk management in IP infringement is a critical component for businesses that rely heavily on intellectual property assets. Many organisations manage their IP reactively — responding to infringement when it is discovered rather than systematically assessing and managing IP exposure as a strategic risk.

Our IP risk management advisory helps organisations build comprehensive IP risk management frameworks — identifying where IP exposure exists, quantifying the risk, and building protective strategies that align with business objectives. This includes IP risk assessment, IP asset strategy development, patent protection strategy, trade secret protection frameworks, copyright advisory, and IP policy and procedure development.

Trade secret protection deserves particular emphasis in 2026. The EU Trade Secrets Directive has significantly strengthened the legal protection available for confidential business information across EU member states — but only for organisations that have implemented adequate measures to keep information confidential. Without documented trade secret protection programmes, the legal protections may not apply.

IP Assessment in M&A Due Diligence: Don’t Acquire Hidden Liability

In any merger, acquisition, or significant investment, intellectual property is a critical due diligence consideration. IP assets can represent a substantial portion of the transaction value — and IP liabilities can significantly affect the risk profile of the deal.

Comprehensive IP due diligence covers ownership and chain of title review (ensuring the target actually owns the IP it claims), freedom to operate analysis (assessing whether the target’s products or processes infringe third-party rights), IP portfolio due diligence (evaluating the strength and coverage of registered IP), IP valuation advisory, licensing agreement review, and IP liability assessment.

Successor liability for IP infringement is a real risk in acquisitions — if the target has been infringing third-party IP, the acquirer may inherit that liability. Early IP due diligence allows acquirers to identify and price this risk before transaction close, or to require remediation as a condition of completion.

The EUIPO Authorised Service Provider Advantage

Baretzky & Partners’ status as an authorised EUIPO service provider (Reg. No. 107758) reflects both our expertise in European trademark practice and our commitment to the quality standards required for official authorisation. This status provides clients with confidence that their EUIPO filings are handled by practitioners who meet the professional standards required by the EU’s official IP office.

Our track record includes the successful grant of full European Trademark Rights for clients across multiple sectors — demonstrating the practical results that expert trademark management delivers.

Protecting Your Brand in the Digital Economy

The digital economy has created new vectors for brand abuse that traditional trademark protection was not designed to address. Social media impersonation, app store fraud, keyword advertising infringement, and the use of confusingly similar marks in online marketplaces all require proactive monitoring and enforcement strategies that go beyond conventional trademark management.

Our online brand protection advisory covers the full range of digital brand risks — from monitoring and early identification through to platform takedowns, UDRP proceedings, and coordination with law enforcement for criminal counterfeit operations. We combine legal expertise with cyber intelligence capability to provide enforcement support that is effective in the digital environment.

Contact Baretzky & Partners for IP Advisory

Whether you are seeking to register a European trademark, investigate infringement, conduct M&A IP due diligence, or build a comprehensive IP risk management framework, our authorised EUIPO service provider team is available for immediate consultation.

Contact Baretzky & Partners LLP to start a trademark application or discuss your IP advisory needs. All enquiries are handled in strict confidence.

Baretzky & Partners LLP is an authorised EUIPO service provider (Reg. No. 107758). We provide strategic risk mitigation, legal affairs and crisis mitigation, and international information policy and compliance specialist counsel. We do not provide litigation services. All investigative services are provided by our European offices only.

Information Policy in 2026: Why It Has Never Been More Important

Information — how it is created, stored, shared, protected, and governed — sits at the heart of virtually every significant regulatory challenge facing organisations today. GDPR compliance, data breach response, AI governance, national security frameworks, internet governance, and the legal obligations of internet service providers all converge on a single discipline: information policy.

Baretzky & Partners LLP is led by Dr. Ricardo Baretzky, a PhD in Law specialising in Information Policy and National Cyber Security — bringing a depth of expertise to this field that very few advisory practices can match. Our Information Policy & Security practice provides comprehensive advisory on information governance, security policies, and data protection frameworks for organisations operating across multiple jurisdictions.

From GDPR compliance and data governance frameworks to internet governance and information policy in the government sector, our practice covers the full spectrum of information-related legal and regulatory challenges facing organisations today.

GDPR in 2026: The Enforcement Landscape Has Changed

The General Data Protection Regulation has been in force since 2018, but the enforcement landscape has changed dramatically. Data protection authorities across the EU have significantly increased the frequency and scale of enforcement actions — with multi-million euro penalties becoming routine for organisations that fail to implement adequate technical and organisational measures, conduct proper Data Protection Impact Assessments, or manage data breaches effectively.

Under UK GDPR (which applies post-Brexit with substantial equivalence to EU GDPR), the Information Commissioner’s Office has similarly intensified its enforcement posture. Organisations with operations in both the EU and UK face the additional complexity of managing two regulatory regimes that are closely aligned but not identical.

Key areas of enforcement focus in 2026 include cross-border data transfers (particularly in light of the ongoing evolution of Standard Contractual Clauses and adequacy decisions), AI-generated personal data processing, and the security of personal data held by third-party processors.

The Four Core Information Policy Services

1. Data Protection and GDPR Compliance

Comprehensive GDPR and data protection advisory must be structured around the specific risk profile of each organisation — not a generic compliance checklist. Our approach begins with a GDPR gap analysis: a systematic assessment of where current policies, procedures, and technical measures fall short of applicable requirements.

From this foundation, we provide privacy policy development, Data Protection Impact Assessments for high-risk processing activities, DPO (Data Protection Officer) advisory services, and cross-border data transfer compliance. Subject Access Request management — one of the most operationally challenging aspects of GDPR compliance — is an area where specialist advisory can significantly reduce both compliance burden and legal risk.

For organisations processing significant volumes of EU personal data, ensuring that processor and sub-processor agreements are compliant, that Article 30 records of processing activities are current, and that breach notification procedures are tested and functional is a continuous compliance obligation, not a one-time exercise.

2. Information Security Policy and Governance

Information security governance is the framework within which technical security controls operate. Without robust policy frameworks — covering information classification, access control, incident response, and security governance structures — even the most sophisticated technical controls will be undermined by process failures and human factors.

Our information security policy advisory covers the full range of governance requirements: information security policy design, ISO 27001 alignment, security governance frameworks, incident response policy, access control frameworks, and PCI DSS advisory for organisations in scope for payment card industry standards.

ISO 27001 certification is increasingly required by enterprise clients as a condition of doing business, and provides a credible framework for demonstrating the adequacy of information security management to regulators, clients, and insurers alike.

3. Information Policy in Legal and Government Contexts

The intersection of information policy and the government sector presents distinctive challenges. Public sector organisations and those working with government clients must navigate a complex landscape of obligations: freedom of information requirements, national security information frameworks, the specific data protection obligations applicable to law enforcement and national security processing, and internet governance frameworks that are evolving rapidly under both EU and international pressure.

Our practice, led by a PhD specialist in National Cyber Security, provides advisory on these complex intersections — helping organisations understand where their information policy obligations arise and how to build frameworks that satisfy them without compromising operational effectiveness.

4. WISP and ISP Information Policy Advisory

Wireless internet service providers and ISPs face a distinctive set of information policy obligations. Lawful intercept compliance, data retention policy, content regulation advisory, and the full range of ISP regulatory compliance requirements create a complex operational environment that demands specialist expertise.

Data retention obligations in particular vary significantly across jurisdictions — with some requiring extensive retention of communications data for law enforcement purposes and others restricting it. Navigating these requirements while maintaining operational efficiency and protecting user privacy is a specialist discipline where generic legal advice is rarely adequate.

Cross-Border Data Transfers: Navigating Post-Schrems II Complexity

One of the most technically complex areas of GDPR compliance remains cross-border data transfers — the movement of EU personal data to countries outside the European Economic Area that do not benefit from an adequacy decision. Since the Schrems II judgment invalidated the EU-US Privacy Shield in 2020, organisations have relied primarily on Standard Contractual Clauses supplemented by transfer impact assessments to legitimise such transfers.

The practical implementation of this framework is demanding. Transfer impact assessments must assess the law and practice of the destination country, evaluate whether that country’s legal regime provides essentially equivalent protection to EU law, and determine what supplementary measures (if any) can address identified deficiencies. For organisations with complex global data flows involving multiple destination countries, this is a significant ongoing compliance obligation.

The EU-US Data Privacy Framework, adopted in 2023, provides a mechanism for transfers to certified US organisations — but its durability remains subject to legal challenge, and organisations should maintain alternative transfer mechanisms as a precaution.

AI and Personal Data: The Emerging Frontier

The intersection of artificial intelligence and personal data protection has emerged as one of the most significant new information policy challenges of 2026. AI systems that process personal data — for profiling, automated decision-making, or training purposes — are subject to GDPR obligations that were not designed with AI in mind, creating interpretive challenges that regulators are still working through.

Key issues include the lawful basis for AI training data, transparency requirements for automated decision-making under Article 22, the categorisation of AI-generated inferences as personal data, and the application of data minimisation principles to machine learning systems that depend on large data sets.

The EU AI Act, which entered into force in 2024, adds a further layer of obligation for high-risk AI applications — requiring conformity assessments, technical documentation, and ongoing monitoring. Organisations developing or deploying AI systems must now navigate the intersection of GDPR and the AI Act, which do not always align neatly.

Information Governance Gaps: The Risk They Create

Information governance gaps — where an organisation’s policies, procedures, and controls fail to adequately govern its information assets — create exposure on multiple dimensions. Regulatory penalties for GDPR non-compliance can reach €20 million or 4% of global annual turnover, whichever is higher. Data breaches resulting from inadequate security measures create both regulatory and litigation exposure. And increasingly, cyber insurers are requiring evidence of robust information governance as a condition of coverage.

Beyond the direct financial exposure, information governance failures damage the trust that organisations depend on — with clients, employees, regulators, and the public. Rebuilding that trust after a significant data breach or regulatory investigation is a lengthy and costly process.

Baretzky & Partners: PhD-Led Information Policy Advisory

Our Information Policy & Security practice is built on a foundation of genuine expertise in a field that demands both legal depth and technical understanding. Led by Dr. Ricardo Baretzky — PhD in Law with specialisation in Information Policy and National Cyber Security — our practice covers the full spectrum of information governance challenges facing organisations in 2026.

We work with organisations across sectors and jurisdictions, providing advisory that bridges legal frameworks with practical operational implementation — ensuring that compliance programmes are not only technically sound but actually work in the organisations they are designed to serve.

Contact Baretzky & Partners LLP to request an information policy review or discuss your GDPR compliance needs. Initial consultations are strictly confidential.

Baretzky & Partners LLP provides strategic risk mitigation, legal affairs and crisis mitigation, and international information policy and compliance specialist counsel. We do not provide litigation services. All investigative services are provided by our European offices only.

The Rising Cost of Corruption: Why ABAC Compliance Is Non-Negotiable in 2026

Anti-bribery and corruption enforcement has reached a new intensity in 2026. Global enforcement agencies — led by the US Department of Justice, the UK Serious Fraud Office, and their counterparts across Europe and Asia — are imposing record penalties, pursuing individual executives, and extending their reach into supply chains and third-party relationships that were previously considered outside the enforcement perimeter.

For organisations operating internationally, the risk is not abstract. FCPA enforcement alone has resulted in billions of dollars in penalties over the past decade, and the trend is consistently upward. UK Bribery Act prosecutions are increasing. And emerging economies — which represent the fastest-growing markets for many multinationals — frequently rank among the highest-risk jurisdictions for corruption exposure.

At Baretzky & Partners LLP, we advise organisations on the legal and ethical aspects of compliance and privacy in risk management — building ABAC programmes that function under real-world operational pressure, not just on paper. Our approach covers the full spectrum of anti-bribery and corruption risk: from initial programme design and risk assessment through to investigations, remediation, and compliance training.

Understanding the Legal Framework: FCPA, UK Bribery Act, and Beyond

Effective ABAC compliance requires a clear understanding of the legal frameworks that apply to your organisation — and in most cases, multiple frameworks apply simultaneously.

The Foreign Corrupt Practices Act (FCPA)

The FCPA applies to US persons and companies, foreign companies listed on US exchanges, and any entity that takes action in furtherance of a corrupt payment within US territory — a jurisdictional reach that extends to a vast number of non-US organisations. It prohibits payments to foreign government officials for the purpose of obtaining or retaining business, and imposes detailed books-and-records and internal controls requirements on issuers.

FCPA enforcement is characterised by its extraterritorial reach, the use of deferred prosecution agreements, and the DOJ’s willingness to pursue individuals alongside corporate entities. Voluntary disclosure remains a significant factor in determining enforcement outcomes, making the quality of an organisation’s internal investigation capability critical.

The UK Bribery Act 2010

The UK Bribery Act is widely regarded as the world’s most comprehensive anti-corruption legislation. Unlike the FCPA, it covers private sector bribery as well as public official corruption, applies to facilitation payments without exception, and creates a corporate offence of failing to prevent bribery that does not require proof of management knowledge or involvement.

The sole defence to the corporate failure-to-prevent offence is having “adequate procedures” in place — which in practice means a proportionate, risk-based ABAC programme that has been genuinely implemented and is actively monitored. What constitutes adequate procedures is determined by reference to six principles: proportionate procedures, top-level commitment, risk assessment, due diligence, communication and training, and monitoring and review.

The OECD Anti-Bribery Convention and National Implementing Legislation

Beyond the FCPA and UK Bribery Act, organisations operating in OECD member states are subject to the implementing legislation of each jurisdiction — which varies significantly in scope, enforcement approach, and penalty regime. The OECD Working Group on Bribery conducts regular monitoring of member states’ implementation, and the trend across jurisdictions is toward more aggressive enforcement, broader jurisdictional reach, and increased cooperation between national enforcement agencies.

The Four Pillars of an Effective ABAC Programme

1. ABAC Programme Design and Architecture

An ABAC programme that satisfies regulatory expectations must be risk-based, proportionate, and genuinely implemented. It begins with a comprehensive risk assessment — identifying the geographic, sectoral, transactional, and relationship-based corruption risks that are specific to the organisation.

From this foundation, the programme architecture is built: ABAC policy and procedure development, compliance programme architecture, gifts and hospitality frameworks, facilitation payments policy, and whistleblower channel design. Third-party risk management — covering agents, distributors, joint venture partners, and suppliers in high-risk jurisdictions — is typically the most complex and resource-intensive component.

2. Corruption Risk Assessment

Geographic risk assessment must go beyond published corruption indices to assess the specific risk profile of the organisation’s operations in each jurisdiction. Government interaction risk analysis is particularly important — organisations that engage with government officials in procurement, licensing, or regulatory contexts face heightened exposure that demands specific controls.

M&A anti-corruption due diligence is a distinct discipline. Acquiring a company in a high-risk jurisdiction without adequate ABAC due diligence exposes the acquirer to successor liability under the FCPA and UK Bribery Act — making pre-acquisition assessment a critical risk management step.

3. Corruption Investigations and Remediation

When corruption allegations arise — whether through whistleblower reports, regulatory inquiries, or internal audit findings — the internal review must be conducted with independence, rigour, and full awareness of the regulatory implications. Our specialists combine compliance expertise with cyber intelligence methodology to deliver findings that stand up to external scrutiny.

Document review and analysis, witness interview methodology, and regulatory disclosure advisory are all components of an effective investigation response. Remediation programme design and monitorship support complete the post-investigation phase — addressing root causes and rebuilding regulatory credibility.

4. Compliance Training and Culture

The most technically sophisticated ABAC programme will fail if the organisation does not have a genuine culture of integrity. Board-level ABAC training sets the tone from the top — communicating that anti-corruption compliance is a genuine organisational priority, not a compliance function exercise. Employee compliance training and third-party training programmes extend this commitment throughout the organisation and its supply chain.

Effective training is not a one-time event. It must be regular, tailored to role and risk level, and reinforced through the organisation’s incentive structures and day-to-day decision-making.

High-Risk Jurisdictions: Where ABAC Risk Is Greatest

For multinational organisations, corruption risk is not uniformly distributed. Certain geographies, sectors, and transaction types consistently present elevated exposure. Transparency International’s Corruption Perceptions Index identifies consistently high-risk regions including parts of sub-Saharan Africa, Southeast Asia, Central Asia, and Latin America — but country-level indices mask significant variation at the city, sector, and transaction level.

Industries with intensive government interaction — infrastructure, energy, defence, healthcare, and financial services — face heightened exposure regardless of jurisdiction. Organisations entering new markets, pursuing government contracts, or operating through local agents or partners in high-risk jurisdictions should treat ABAC risk assessment as a prerequisite, not an afterthought.

Voluntary Disclosure: Weighing the Benefits and Risks

One of the most consequential decisions an organisation can face following the discovery of potential FCPA or UK Bribery Act violations is whether to make voluntary disclosure to enforcement authorities. The calculus is complex and fact-specific: voluntary disclosure can significantly reduce penalties and enable resolution through deferred prosecution agreements rather than criminal prosecution, but it also initiates a regulatory process with uncertain scope and duration.

The quality of the internal investigation completed before any disclosure decision is critical. A thorough, privileged investigation conducted under legal supervision allows the organisation to understand the full scope of the issue, assess the strength of the evidence, and make an informed decision about disclosure strategy.

Baretzky & Partners ABAC Advisory

Our ABAC practice covers the full lifecycle of anti-bribery and corruption compliance — from initial programme design through to investigation management and regulatory engagement. We work with organisations entering high-risk markets, multinationals responding to regulatory inquiries, and companies seeking to strengthen existing programmes ahead of regulatory review.

All ABAC advisory is conducted in strict confidence. Our specialists are available for immediate consultation on corruption allegations, regulatory inquiries, or programme development needs.

Contact Baretzky & Partners LLP to discuss your ABAC programme needs or request a corruption risk assessment. A specialist will respond within one business day.

Baretzky & Partners LLP provides strategic risk mitigation, legal affairs and crisis mitigation, and international information policy and compliance specialist counsel. We do not provide litigation services. All investigative services are provided by our European offices only.

Why Risk Management Frameworks Are Failing — And How to Fix Them

Most organisations have risk management frameworks. Very few have risk management frameworks that actually work under operational pressure. The gap between the two is where regulatory penalties, reputational damage, and business disruption live.

In 2026, enterprise risk management is facing a perfect storm: increasingly complex multi-jurisdictional regulatory requirements, faster-moving threat landscapes, and boards demanding more granular visibility into risk exposure than ever before. Against this backdrop, compliance programmes built on legacy structures — outdated policies, siloed risk functions, and reactive mindsets — are simply no longer adequate.

At Baretzky & Partners LLP, we deliver comprehensive risk management programmes designed to identify, assess, and mitigate enterprise-wide exposures — from operational and regulatory risk through to reputational and cyber risk — across 116 countries. Our certified practitioners design bespoke compliance frameworks aligned with ISO 31000, COSO ERM, and sector-specific regulatory requirements, combining deep jurisdictional knowledge with practical implementation experience.

The Four Pillars of Effective Enterprise Risk Management

Effective enterprise risk management is not a single programme — it is an integrated system of interconnected capabilities. Organisations that treat risk management as a box-ticking exercise will find their frameworks failing precisely when they are most needed. Those that build genuine capability across four core areas are positioned to manage risk proactively, demonstrate compliance effectively, and recover rapidly when disruptions occur.

1. Enterprise Risk Framework Design

The foundation of effective risk management is a properly designed risk architecture. This means more than a risk register — it encompasses governance structures, risk appetite statements, escalation protocols, and board-level reporting frameworks that give senior leadership genuine visibility into risk exposure.

Critical components include risk appetite and tolerance frameworks that translate abstract board-level risk tolerance into operational parameters; three lines of defence models that clearly delineate the responsibilities of business functions, risk and compliance, and internal audit; and governance structure design that ensures risk ownership is clearly assigned and accountability mechanisms are functioning.

Without this architectural foundation, even the most sophisticated risk identification processes will generate insights that cannot be effectively acted upon.

2. Compliance Programme Development

Compliance programmes must be built for the regulatory environment organisations actually face — not the one that existed when the programme was last updated. In 2026, this means addressing a dramatically expanded regulatory landscape covering GDPR, DORA (Digital Operational Resilience Act), the EU AI Act, ESG disclosure requirements, and continued expansion of AML and sanctions obligations.

Effective compliance programme development starts with regulatory gap analysis — a systematic assessment of where the organisation’s current policies and procedures fall short of applicable requirements. From this foundation, policy and procedure drafting, cross-jurisdictional mapping, and compliance training programmes can be built on a solid evidential basis rather than assumption.

PCI security compliance, GDPR and data protection obligations, and sector-specific requirements all demand specific attention. Multi-jurisdictional organisations face the additional challenge of reconciling conflicting regulatory requirements — an area where specialist advisory is particularly valuable.

3. Operational and Third-Party Risk Assessment

Some of the most significant risk exposures facing organisations in 2026 are not internal — they sit in the supply chain, in third-party relationships, and in the complex ecosystem of vendors, partners, and counterparties that modern businesses depend on.

Comprehensive operational risk assessment covers internal process vulnerabilities, technology dependencies, and human factors. Third-party due diligence extends this assessment to the organisation’s external relationships — identifying where concentration risk, compliance gaps, or integrity issues in the supply chain could create exposure.

Business continuity planning completes this picture, ensuring that when disruptions occur — whether from operational failures, cyber incidents, regulatory actions, or external shocks — the organisation has tested, credible plans to maintain critical functions and recover effectively.

4. Regulatory Response and Remediation

No compliance programme is perfect, and regulatory inquiries, enforcement actions, and compliance gaps are an inevitable feature of operating in complex regulated environments. When they occur, the quality of the response is as important as the underlying compliance posture.

Effective regulatory response requires rapid assessment of the scope of the issue, transparent and well-structured communication with regulators, and a credible remediation programme that addresses root causes rather than symptoms. Our team supports organisations through regulatory inquiries and enforcement actions — providing regulator liaison expertise, remediation programme management, and the specialist advisory needed to minimise exposure and restore compliance standing as efficiently as possible.

ISO 31000 and COSO ERM: The International Standards Framework

Two frameworks dominate enterprise risk management practice internationally: ISO 31000 and the COSO Enterprise Risk Management Framework. Understanding both — and knowing when to apply which — is fundamental to building programmes that satisfy regulatory expectations while delivering genuine operational value.

ISO 31000:2018 provides principles and guidelines for risk management applicable to any organisation, regardless of sector or size. Its strength is its universality and its focus on integrating risk management into organisational processes and decision-making at every level. For organisations seeking a risk management standard that is recognised globally and applicable across jurisdictions, ISO 31000 is the benchmark.

The COSO ERM Framework (2017 update) integrates enterprise risk management with strategy and performance, emphasising the connection between risk appetite and strategic objectives. Its five components — governance and culture, strategy and objective-setting, performance, review and revision, and information, communication and reporting — provide a structured approach particularly suited to larger organisations with complex governance structures.

Our practitioners are experienced in both frameworks and advise on their application based on organisational context, regulatory requirements, and existing risk infrastructure.

The DORA Challenge: Digital Operational Resilience in Financial Services

For organisations in the financial services sector, the Digital Operational Resilience Act (DORA) represents the most significant new compliance obligation of the current regulatory cycle. In force since January 2025, DORA requires financial entities — including banks, investment firms, insurance companies, and crypto-asset service providers — to implement comprehensive digital operational resilience frameworks covering ICT risk management, incident reporting, operational resilience testing, and third-party ICT risk management.

DORA’s requirements are prescriptive and demanding. ICT risk management frameworks must be documented, tested, and subject to independent review. Significant ICT-related incidents must be reported to competent authorities within defined timeframes. Digital operational resilience testing — including advanced threat-led penetration testing for significant institutions — must be conducted on a regular basis.

Third-party ICT risk management under DORA is particularly significant, as it extends compliance obligations beyond the regulated firm to its critical third-party service providers — creating a new dimension of supply chain risk management that many organisations are still working to address.

Building a Risk Culture That Sustains Compliance

Technical compliance frameworks are necessary but insufficient. Organisations that sustain genuine compliance over time are those that have built a risk culture — where risk awareness is embedded in decision-making at every level, where escalation of concerns is encouraged rather than discouraged, and where the tone from the top communicates genuine commitment to compliance rather than performative adherence.

Building this culture requires more than training programmes, although training is an important component. It requires governance structures that give risk and compliance genuine authority, incentive frameworks that do not reward short-term performance at the expense of risk management, and leadership that models the behaviours it expects from the organisation.

Our risk management advisory includes assessment of organisational risk culture — identifying where cultural barriers to effective risk management exist and advising on the interventions needed to address them.

When to Engage a Risk Management Specialist

Organisations typically engage specialist risk management advisory in several circumstances: when facing a new regulatory requirement that existing capabilities cannot address; when a regulatory inquiry or enforcement action has identified compliance gaps; when entering new markets or jurisdictions that require unfamiliar compliance frameworks; or when an internal review has identified that the existing risk programme is not functioning as intended.

In all of these situations, early engagement is advantageous. The earlier specialist advisory is engaged, the more options are available — whether that means building a compliance programme before a regulatory deadline, engaging proactively with a regulator before an inquiry becomes adversarial, or addressing a compliance gap before it escalates into an enforcement issue.

Baretzky & Partners: Risk Management Across 116 Countries

Our risk management practice combines global reach with local expertise. With coverage across 116 countries and 25+ years of experience in enterprise risk management, our certified practitioners deliver programmes that are not only technically sound but practically implementable in the jurisdictions and sectors where our clients operate.

We work with organisations across financial services, professional services, technology, energy, and government sectors — designing and implementing risk frameworks that meet regulatory requirements while delivering genuine operational value.

Contact Baretzky & Partners LLP to request a risk assessment or discuss your compliance programme needs. Initial consultations are strictly confidential, and our team can deliver a remediation roadmap within days of engagement.

Baretzky & Partners LLP provides strategic risk mitigation, legal affairs and crisis mitigation, and international information policy and compliance specialist counsel. We do not provide litigation services. All investigative services are provided by our European offices only.

Introduction: Why CyberCrime Advisory Has Never Been More Critical

In 2026, cybercrime is no longer a peripheral risk for businesses and governments — it is a central, operational threat with direct legal, financial, and reputational consequences. The global cost of cybercrime is projected to exceed $10 trillion annually, and organisations across every sector are confronting a landscape where digital attacks are increasingly sophisticated, jurisdictionally complex, and legally nuanced.

For legal practitioners, compliance officers, and executive leadership, the question is no longer whether a cyber incident will occur — it is whether your organisation has the legal frameworks, expert advisory support, and cross-border investigation capabilities to respond effectively when it does.

At Baretzky & Partners LLP, our CyberCrime & Investigations practice is built on a singular premise: bridging the gap between technical cybercrime realities and the legal frameworks that govern them. Led by Dr. Ricardo Baretzky — a PhD in Law specialising in Information Policy and National Cyber Security — our certified specialists deliver expert opinions, cyber intelligence advisory, and cross-border investigation management for the most complex cybercrime matters globally.

What Is Cybercrime Legal Advisory — And Why Does It Require Specialist Expertise?

Cybercrime spans a vast spectrum of criminal conduct — from ransomware attacks and business email compromise to state-sponsored intrusions, cryptocurrency fraud, and dark web intelligence operations. What makes cybercrime uniquely challenging from a legal perspective is the intersection of technical forensics, multi-jurisdictional law enforcement coordination, and rapidly evolving regulatory frameworks.

Generic legal counsel is rarely equipped to manage this intersection effectively. Organisations need advisors who understand both the technical dimensions of a cyber incident and the legal mechanisms available to investigate, prosecute, and remediate — across borders, across jurisdictions, and across regulatory regimes.

Effective cybercrime legal advisory encompasses four core capability areas:

1. Expert Opinion and Advisory Consulting

Courts, regulators, and law enforcement agencies increasingly require expert opinions from certified cybercrime specialists when prosecuting complex cases or assessing regulatory compliance. Baretzky & Partners provides expert witness reports, cybercrime legal opinions, and national security advisory support — grounded in both technical understanding and legal rigour.

Our certified practitioners have extensive experience preparing expert witness materials for judicial proceedings and regulatory investigations, ensuring that complex technical evidence is presented in a legally coherent and persuasive manner.

2. Cross-Border Cybercrime Investigations

Cybercrime rarely respects national borders. A ransomware operator may be based in one jurisdiction, route payments through cryptocurrency exchanges in another, and target victims across a dozen more. Managing a cross-border investigation requires not only technical capability — digital evidence collection, cryptocurrency tracing, dark web intelligence — but also the legal relationships and procedural knowledge to coordinate effectively with international law enforcement and partner law firms.

Baretzky & Partners manages complex cross-border cybercrime investigations from intake to resolution, coordinating international asset tracing, digital evidence collection, and law enforcement liaison across more than 116 countries. Our investigation management capability is particularly valuable in cases where speed, discretion, and jurisdictional precision are essential.

3. Cyber Risk Management and Legal Frameworks

Prevention is always preferable to response. Organisations that build robust legal and operational frameworks for cyber risk management are significantly better positioned to contain the damage when incidents occur — and to demonstrate regulatory compliance in the aftermath.

Our cyber risk management advisory covers incident response planning, legal framework development, cybersecurity governance advisory, and breach notification compliance. We work with organisations to align their cyber risk posture with applicable legal requirements — including NIS2, GDPR, and sector-specific regulatory obligations — before an incident forces the issue.

4. EU Cybercrime Law and Judicial Reform

For organisations operating across European Union member states, the regulatory landscape governing cybercrime is becoming increasingly complex. The NIS2 Directive, the Budapest Convention on Cybercrime, and national implementing legislation create a multi-layered compliance environment that demands both jurisdictional expertise and operational agility.

Baretzky & Partners advises on EU cybercrime legal compliance and the judicial reform implications arising from evolving European legislation — helping organisations navigate multi-jurisdictional coordination requirements and stay ahead of regulatory change.

The NIS2 Directive: What Organisations Must Know in 2026

The NIS2 Directive (EU 2022/2555) significantly expanded the scope and obligations of cybersecurity regulation across the European Union. In force since October 2024, NIS2 applies to a much broader range of sectors than its predecessor — including energy, transport, banking, financial market infrastructure, health, digital infrastructure, and public administration.

Key obligations under NIS2 include mandatory incident reporting (within 24 hours of becoming aware of a significant incident), implementation of appropriate cybersecurity risk management measures, and personal liability for senior management in cases of non-compliance. The penalties for failure to comply are substantial — with administrative fines of up to €10 million or 2% of total worldwide annual turnover for essential entities.

For organisations with EU operations, understanding NIS2 obligations and building compliant frameworks is no longer optional. Our team provides comprehensive NIS2 compliance advisory — from initial gap analysis through to implementation support and ongoing compliance monitoring.

Cryptocurrency Fraud and Dark Web Intelligence: The Frontiers of Cybercrime Investigation

Two of the most rapidly evolving areas in cybercrime investigation are cryptocurrency fraud and dark web intelligence. Both require specialist capability that goes well beyond conventional legal advisory.

Cryptocurrency investigations involve blockchain analysis, exchange cooperation, and often multi-jurisdictional asset recovery proceedings. The pseudonymous nature of cryptocurrency transactions creates both challenges and opportunities for investigators — skilled analysts can often trace funds across complex transaction chains, but doing so requires both technical expertise and legal authority to compel exchange disclosures.

Dark web intelligence operations require certified specialists who can operate safely and legally in environments that most advisors simply cannot access. Our team has experience gathering intelligence from dark web forums, marketplaces, and communication channels — providing clients with actionable threat intelligence that informs both defensive posture and active investigation strategies.

When Should You Engage a CyberCrime Legal Specialist?

Many organisations wait too long to engage specialist cybercrime legal counsel — often activating their incident response only after significant damage has already been done. Early engagement is almost always advantageous, for several reasons:

Preservation of legal privilege: Engaging legal counsel early ensures that investigation activities and communications may be protected by legal professional privilege — a critical consideration if regulatory investigations or litigation follow.

Evidence integrity: Digital evidence is fragile. Early engagement of certified investigators ensures that evidence is collected in a forensically sound manner that will withstand judicial scrutiny.

Law enforcement coordination: Effective coordination with law enforcement — particularly across jurisdictions — requires established relationships and procedural knowledge. Early engagement allows our team to mobilise these relationships before the critical window for action closes.

Regulatory notification: Under NIS2, GDPR, and many sector-specific regimes, organisations face mandatory breach notification obligations with tight deadlines. Early legal counsel engagement ensures that notifications are made correctly, on time, and in a manner that minimises regulatory exposure.

Baretzky & Partners: Coverage Across 116 Countries

Cybercrime knows no borders — and neither does our advisory capability. With coverage across 116 countries and established relationships with law enforcement agencies, partner law firms, and technical specialists globally, Baretzky & Partners is positioned to mobilise wherever an investigation takes us.

Our European offices — based in Plovdiv, Bulgaria, with partner coverage through the Milan Law Office in Italy — provide the jurisdictional grounding for EU-focused mandates. Our Washington, D.C. presence ensures coordination capability for US-nexus matters and transatlantic investigations.

All investigative services are provided exclusively through our European offices, in accordance with applicable law and investigative standards.

Conclusion: The Cost of Inadequate CyberCrime Legal Preparedness

Organisations that underinvest in cybercrime legal preparedness consistently face higher costs when incidents occur — not just from the incident itself, but from regulatory penalties, litigation exposure, reputational damage, and the operational disruption of uncoordinated response.

Investing in specialist cybercrime legal advisory — expert opinion capability, cross-border investigation management, robust cyber risk frameworks, and NIS2 compliance — is not a discretionary expenditure. In 2026, it is a fundamental component of organisational risk management.

Baretzky & Partners LLP offers immediate consultation for organisations facing cybercrime incidents or seeking to build resilient legal frameworks for cyber risk. Our certified specialists are available to mobilise rapidly — from expert witness support to full investigation management.

Contact Baretzky & Partners LLP to speak with a cybercrime specialist in confidence. All enquiries are handled with strict discretion, and a specialist will respond within one business day.

Baretzky & Partners LLP provides strategic risk mitigation, legal affairs and crisis mitigation, and international information policy and compliance specialist counsel. We do not provide litigation services. All investigative services are provided by our European offices only.

Anti-money laundering (AML) enforcement has accelerated dramatically over the past decade. Regulators across the US, UK, EU, and Asia-Pacific are issuing record-breaking fines, expanding personal liability to executives, and publishing deferred prosecution agreements that name institutions and individuals in detail. For compliance officers, risk managers, and banking counsel, understanding the current penalty landscape is no longer optional — it is a core operational requirement.

This article provides a practical overview of how AML penalties and sanctions work in 2026, what triggers enforcement, and how organisations can reduce their exposure.


The Scale of Modern AML Penalties

Global AML fines have reached unprecedented levels. Between 2020 and 2025, regulators issued over $25 billion in AML-related penalties to financial institutions worldwide. The United States remains the most aggressive enforcer, with the Department of Justice (DOJ), Financial Crimes Enforcement Network (FinCEN), and Office of Foreign Assets Control (OFAC) all maintaining active enforcement programmes. The UK’s Financial Conduct Authority (FCA) and the European Banking Authority (EBA) have similarly intensified oversight, particularly post-FATF mutual evaluations.

Common penalty categories include civil monetary penalties, criminal fines, deferred prosecution agreements (DPAs), and non-prosecution agreements (NPAs). In the most serious cases — particularly those involving sanctions violations or terrorist financing — institutions face asset freezes, licence revocations, and the appointment of independent compliance monitors at their own expense.


What Triggers AML Enforcement

Regulatory action is typically triggered by one or more of the following:

  • Failure to file Suspicious Activity Reports (SARs) — Financial institutions are required to report suspicious transactions. Systematic failures to file, or deliberate delays, attract severe penalties.
  • Inadequate Know Your Customer (KYC) procedures — Insufficient customer due diligence, particularly at onboarding, remains the leading cause of enforcement action.
  • Sanctions screening failures — Processing transactions involving OFAC-listed parties, or failing to maintain current screening lists, is treated as a strict liability offence in the US.
  • Correspondent banking negligence — Banks providing services to foreign financial institutions without adequate oversight of those institutions’ AML controls are increasingly liable for downstream violations.
  • Beneficial ownership gaps — Failure to identify and verify ultimate beneficial owners, particularly in corporate and trust structures, is a growing area of enforcement focus.

Personal Liability: The Shift Toward Individual Accountability

A significant enforcement trend is the expansion of personal liability. Regulators in the UK, US, and EU are increasingly pursuing individual executives, compliance officers, and board members alongside institutions. The UK’s Senior Managers and Certification Regime (SMCR) places direct accountability on named individuals for AML failures within their area of responsibility. In the US, the DOJ’s revised corporate criminal enforcement policy explicitly encourages individual prosecutions.

This shift means that compliance professionals must maintain contemporaneous documentation of their decisions, escalations, and recommendations — both to demonstrate good faith and to establish that responsibility was appropriately discharged.


OFAC Sanctions: A Strict Liability Framework

OFAC sanctions violations are particularly consequential because they operate on a strict liability basis — intent is not required for a civil violation. Any transaction involving a Specially Designated National (SDN) or a blocked country, regardless of whether the institution was aware, may result in a penalty. Mitigating factors — such as voluntary self-disclosure, a robust compliance programme, and lack of prior violations — can reduce penalties significantly, but the base exposure remains high.

Organisations operating internationally must maintain real-time sanctions screening, understand the jurisdictional reach of US secondary sanctions, and have documented escalation procedures for potential matches.


The Role of Compliance Programmes in Penalty Mitigation

Regulators consistently apply mitigating treatment to institutions that can demonstrate a robust, risk-based compliance programme. Key elements include:

  • A documented AML/CFT policy reviewed and approved at board level
  • Regular risk assessments calibrated to the institution’s specific client base, geographies, and product mix
  • Independent testing and audit of the AML programme
  • Ongoing training for all relevant staff
  • A clear escalation and reporting structure for suspicious activity

Voluntary self-disclosure to regulators, while not without risk, is generally treated as a significant mitigating factor. Institutions that discover violations and proactively report them — rather than waiting for examination findings — typically receive more favourable resolutions.


Practical Steps for Compliance Teams in 2026

Given the current enforcement environment, compliance teams should prioritise the following:

  1. Update beneficial ownership registers — Ensure all corporate clients have current UBO data, with verification appropriate to risk level.
  2. Review correspondent banking relationships — Conduct enhanced due diligence on correspondent accounts, particularly those in higher-risk jurisdictions.
  3. Test SAR filing processes — Ensure triage, escalation, and filing workflows are functioning and that staff understand thresholds.
  4. Validate sanctions screening coverage — Confirm that all products and payment channels are included in screening and that list updates are applied in real time or near real time.
  5. Document compliance officer decisions — Maintain records of how and why specific decisions were made, particularly in high-risk situations.

Conclusion

AML enforcement in 2026 is more rigorous, more personal, and more cross-border than at any previous point. Financial institutions and their advisors must treat compliance not as a cost centre but as a strategic function — one that protects the organisation’s licence to operate and the careers of those responsible for it. Organisations that invest in robust frameworks, clear documentation, and proactive engagement with regulators are best positioned to manage their exposure in an increasingly unforgiving regulatory environment.

Baretzky and Partners LLP provides AML/CFT advisory services, compliance programme reviews, and regulatory response support to financial institutions and multinationals operating across multiple jurisdictions. Contact our team to discuss your compliance requirements.

Anti-money laundering (AML) and counter-financing of terrorism (CFT) compliance has never been more complex — or more consequential. With regulatory frameworks evolving across jurisdictions and enforcement agencies intensifying their scrutiny of financial institutions and corporates alike, organisations need a clear, current understanding of what AML/CFT compliance demands and how to meet it.

This article provides a comprehensive overview of AML/CFT regulatory requirements and practical compliance obligations for financial institutions and corporate organisations operating in today’s global environment.

What Are AML/CFT Regulations?

AML (Anti-Money Laundering) and CFT (Counter-Financing of Terrorism) regulations are legal and regulatory frameworks designed to prevent criminals from disguising illegally obtained funds as legitimate income, and to block the flow of funds to terrorist organisations. Together, they form the cornerstone of the global financial crime compliance infrastructure.

The principal international standard-setter is the Financial Action Task Force (FATF), whose Recommendations form the basis for national AML/CFT legislation in over 200 jurisdictions. Key regional frameworks include the EU’s Anti-Money Laundering Directives (currently the 6th AMLD), the US Bank Secrecy Act and FinCEN regulations, and the UK’s Proceeds of Crime Act and Money Laundering Regulations.

Core Compliance Obligations

1. Customer Due Diligence (CDD)

All regulated entities must identify and verify the identity of their customers and, where applicable, the beneficial owners of legal entities. This includes applying Enhanced Due Diligence (EDD) to higher-risk customers such as Politically Exposed Persons (PEPs), customers from high-risk jurisdictions, and those involved in complex or unusual transactions.

2. Transaction Monitoring

Organisations must maintain systems capable of detecting and flagging unusual or suspicious transaction patterns. This requires both technology-driven monitoring tools and human review processes — and those systems must be regularly tested and validated against current risk typologies.

3. Suspicious Activity Reporting (SAR)

Where suspicious activity is identified, regulated entities are legally obligated to file Suspicious Activity Reports (SARs) — or Suspicious Transaction Reports (STRs) — with the relevant Financial Intelligence Unit (FIU). Failure to file is itself a criminal offence in most jurisdictions.

4. Record-Keeping

Regulated entities must maintain records of customer identification information and transaction data for a minimum period — typically five years — and make those records available to regulators on request.

5. AML Programme Infrastructure

Regulated organisations must have a written AML programme in place, including policies and procedures, a designated compliance officer, a risk assessment framework, staff training, and an independent audit or testing function.

Common Compliance Gaps and How to Address Them

Despite significant investment in AML programmes, regulators continue to identify recurring deficiencies across the industry. The most common include:

  • Inadequate customer risk rating — Risk segmentation that fails to reflect true exposure, particularly for high-risk geographies and PEP relationships.
  • Transaction monitoring gaps — Outdated models that generate excessive false positives while missing genuine red flags.
  • Insufficient EDD — Superficial enhanced due diligence that meets the letter but not the spirit of regulatory requirements.
  • Weak governance — Compliance functions that lack the authority, resources, or board-level engagement to operate effectively.
  • Inadequate training — Front-line staff who cannot recognise the red flags they are expected to escalate.

The Regulatory Enforcement Landscape

AML enforcement has intensified substantially over the past decade. Regulators in the US, UK, EU, and beyond have imposed record fines on financial institutions for AML programme failures — with penalties reaching billions of dollars in the most serious cases. Beyond financial penalties, institutions face deferred prosecution agreements, licence restrictions, reputational damage, and in some cases, criminal liability for senior individuals.

The regulatory message is clear: AML compliance is not a box-ticking exercise. It requires genuine programme effectiveness, evidence-based risk management, and a culture of compliance from the top of the organisation down.

How Baretzky & Partners Can Help

Baretzky & Partners LLP offers specialist AML advisory services across the full compliance lifecycle — from programme design and KYC framework development through to regulatory response and remediation. Our advisors bring direct regulatory and operational experience across the FATF, EU, US, and UK frameworks.

If your organisation is facing an AML programme review, regulatory inquiry, or simply wants to benchmark and strengthen its current controls, speak with our AML team or contact us directly.


Baretzky & Partners LLP is a multinational risk mitigation and cyber intelligence advisory firm with specialist AML and financial crime advisory practices operating across 116 countries.

Baretzky & Partners LLP has published its Bulgaria: Risk Report 2026 — a comprehensive analysis of the legal, regulatory, anti-money laundering, and compliance landscape in Bulgaria. As a full EU member state with a dynamic financial services sector and active regulatory enforcement posture, Bulgaria presents a distinct and nuanced risk profile for firms operating in or entering the market.

Why Bulgaria Is on the Compliance Radar

Bulgaria occupies an important position within the EU regulatory framework while maintaining its own distinct enforcement characteristics. Firms entering the Bulgarian market, or those with Bulgarian counterparties, must navigate overlapping EU Directives, national AML legislation, sector-specific regulator expectations, and the broader context of Bulgaria’s ongoing judicial and anti-corruption reform agenda.

The 2026 report reflects updated regulatory developments, recent enforcement trends, and practical guidance for firms seeking to build compliant, risk-aware operations in the Bulgarian market.

What the Report Covers

  • Legal & Regulatory Framework — An overview of Bulgaria’s legal system, the transposition of EU directives, and key regulatory bodies governing financial services, investment, and corporate operations.
  • AML & Financial Crime Risk — Assessment of Bulgaria’s AML/CFT regime, enforcement landscape, and practical compliance obligations for firms under FATF and EU 6AMLD frameworks.
  • Market Entry Risk Indicators — Key risk considerations for foreign firms entering the Bulgarian market, including counterparty due diligence, beneficial ownership disclosure, and sector-specific exposures.
  • EU Framework Compliance — How Bulgaria implements and enforces EU regulations across GDPR, sanctions, and financial crime prevention — and where gaps or enforcement asymmetries exist.
  • Strategic Guidance — Actionable recommendations for compliance teams, legal counsel, and executives building or maintaining Bulgarian market positions.

Bulgaria’s EU Context: Opportunity and Obligation

As an EU member state, Bulgaria offers significant strategic advantages for firms seeking a European base of operations — including access to EU passporting, harmonised regulatory frameworks, and established legal infrastructure. However, compliance teams should not assume that EU membership equates to uniform enforcement. Our report identifies the specific areas where Bulgarian practice diverges from or exceeds baseline EU requirements, and where due diligence must be heightened accordingly.

Who Should Read This Report

This report is essential reading for compliance officers, legal advisors, risk managers, and senior executives at firms with current or prospective operations in Bulgaria — including financial institutions, professional services firms, investment vehicles, and multinational corporates with Bulgarian subsidiaries or counterparties.

Access the Report

The Bulgaria: Risk Report 2026 is available free of charge through our Risk Intelligence Reports page. Select the report, complete the short access form, and download your copy immediately.

Subscribe on the reports page to receive future country and sector reports as they are published by Baretzky & Partners LLP.


Baretzky & Partners LLP is a multinational risk mitigation and cyber intelligence advisory firm. Our Bulgaria office — Baretzky and Partners LLC (OOD), Plovdiv — provides on-the-ground expertise and direct regulatory knowledge for clients operating in the Bulgarian and broader Balkan market.