By Patrick Green, Chief Compliance Officer, Banking Circle
Compliance in payments has shifted from a defensive, end-of-process control function to a strategic capability that shapes decisions from the outset. A wave of converging regulation – PSD3, AMLD6, the EU AML Regulation, DORA, MiCA, the US GENIUS Act, and Australia’s AML reforms, means regulators now expect institutions to demonstrate genuine understanding of their risks, not just the existence of controls. At the same time, a more complex geopolitical and sanctions landscape and fast-moving technology are raising the bar further. The institutions pulling ahead are those that embed compliance in product, market-entry, and client decisions early, engage regulators as peers, and are transparent with clients about how risk appetite is set and when it shifts. Treated as a cost, compliance becomes increasingly expensive; treated as a strategic capability, it becomes a source of commercial confidence.
The compliance function has had many labels over the years, from ‘business blocker’ to the ‘department of no’.
For most of the past decade, the questions compliance leaders were asked to answer followed a typical theme: are we covered? BAU meant controls, policies, and making decisions at the end of a process they were rarely fully involved in. It meant a defensible position when a regulator came knocking. That question hasn’t gone away.
But it is no longer the right starting point.
The right question today is: are we positioned? Positioned to move confidently, dynamically and safely in a landscape where regulatory expectations, geopolitical pressures, and client demands are shifting simultaneously and often in competing directions.
The organisations that understand this distinction are pulling ahead. Those that don’t are spending more on compliance as a tick box and getting less from it.
Why converging global regulation now demands understanding, not just controls
The Regulatory Environment Is Structurally More Demanding
The days of regulatory checklists and building processes to match these line by line are still visible in the rear view mirror. However, the tone of the regulators globally is changing. PSD3, AMLD6 and the EU AML Regulation are reshaping supervisory architecture across European payments. DORA sets a new standard for operational resilience. MiCA brings digital assets into the regulatory perimeter with real substance behind it. Across the Atlantic, the US GENIUS Act is establishing a stablecoin framework that will matter far beyond US borders. Australia is at the start line of the biggest AML reforms in two decades.
Taken individually, each represents a significant piece of work. Taken together, they signal something more important: regulators across jurisdictions are converging on a higher standard of risk awareness, resiliency and consistency. Not just compliance with regulations.
The expectation is no longer that you can demonstrate you have controls in the form of policies, procedures and experienced teams. It’s that you can demonstrate you understand your risks – their nature, their scale, and their interaction with your business model and that you have built a framework that not only addresses those risks but has the capability to scale dynamically as the business grows.
At the same time, the geopolitical environment is adding a layer of complexity that no regulatory framework fully anticipated. With approximately 130* active armed conflicts worldwide, sanctions regimes are multiplying and diverging jurisdictionally. For institutions operating cross-border payments infrastructure, the intersection of sanctions, local regulation, and commercial imperatives has become one of the most technically demanding spaces in financial services.
Meanwhile, technology is reshaping the terrain as fast as regulation is. New AI capabilities are introducing both tools and risk categories that didn’t exist a year ago – operational, resilience-related, and reputational -regardless of an institution’s size or shape. Staying ahead of them is becoming part of the compliance remit itself.
*source: Humanitarian Outlook 2026: A World Succumbing to War | ICRC
Compliance adds the most value when it shapes decisions, not reviews them
The compliance function that adds the most value is not the one that reviews and approves. It’s the one that shapes.
This distinction matters in practice. A compliance team brought in late can stop a bad decision or potentially prolong a good one. A compliance team involved early can help design a better one – one that’s commercially viable, jurisdictionally sound, and risk-based from the outset. The difference in outcome, and in the cost of reaching it, is significant.
At Banking Circle, our plan is to have the team embedded at the front end of product development, market entry decisions, and new client category assessments. We are not a checkpoint at the end of the process. We are part of the process – which means we understand the commercial ambition, the applicable regulatory frameworks across every relevant jurisdiction, and the risk profile before commitments are made. That changes the dynamic and enables safe, educated growth
The best compliance functions in payments today operate this way. Regulatory expertise combined with commercial awareness, geopolitical literacy, and the ability to provide clear-headed analysis under conditions of genuine uncertainty. The ability to overlay that with a balance of technology, subject matter expertise and a data-led approach will unlock a dynamic compliance culture going forward. That is a different professional profile from what this role demanded five years ago, and institutions that have not updated their expectations of the function may well fall behind in the bid to tackle bad behaviors proactively.
The Regulator Relationship Has Matured
One of the more meaningful shifts in the current environment has been in how regulators expect to engage with compliance leadership. The static model – annual reviews, reactive reporting, formal correspondence – is giving way to something considerably more dynamic.
I presented recently to financial intelligence unit staff at an AML college in Luxembourg. What struck me most was not the sophistication of the questions, though that was evident. It was the nature of the curiosity: regulators genuinely interested in how institutions are adapting their frameworks to emerging risk categories – digital assets, new payment rails, evolving sanctions landscapes.
They are not looking for institutions that can demonstrate compliance. They are looking for institutions that are thinking carefully, and are willing to share that thinking in a substantive way.
This creates real opportunity for compliance leaders who are prepared to engage as peers rather than subjects. It requires investment – in the calibre of your people, the quality of your risk narrative, the education of your commercial teams and the willingness to have difficult conversations proactively rather than reactively. But the return on that investment, in regulatory credibility and in the latitude it creates commercially, is substantial.
Why B2B clients now expect transparency on risk appetite, before access changes
In B2B payments, the compliance conversation with clients has matured significantly over the past few years – in large part because trust has been damaged before.
The industry has been through periods of abrupt de-risking, where banks shifted their appetite with little transparency and less notice, leaving payment service providers and their underlying clients without access to critical infrastructure. That history has made sophisticated clients rightly demanding about how their banking partners communicate on risk.
What sophisticated clients press their banking partners on now is no longer just whether the controls are sound. They want to know how you set your risk appetite, how it evolves, and how you will communicate with them when it shifts – before access is affected, not after.
The institutions that build durable commercial relationships in this environment are the ones willing to be transparent about their risk appetite and honest about its limits. Not because it is comfortable, but because silence – when it eventually breaks – breaks trust with it. A difficult conversation delivered well is recoverable. A difficult reality delivered silently is not.
Looking Forward With Confidence, Not Apprehension
The regulatory environment will continue to evolve. New technologies will introduce new risk categories. Client expectations will keep rising. None of this should be met with apprehension by institutions that have built genuine compliance capability.
The organisations that treated compliance as a cost to be managed will find the next phase of this environment increasingly expensive. The organisations that treated it as a strategic capability – that embedded it in decision-making, invested in the quality of their people, and built honest and proactive relationships with both regulators and clients – are the ones best positioned to move with clarity and confidence.
The compliance function is more demanding than it has ever been. It is also more central to institutional success than it has ever been. For those of us who have believed in that potential for a long time, that is genuinely encouraging.

Patrick Green is Chief Compliance Officer at Banking Circle, a licensed European payments bank specialising in financial infrastructure for the payments industry.
FAQ
What is the biggest shift in payments compliance right now?
The move from “are we covered?” to “are we positioned?” – from a defensive, end-of-process control function to a strategic capability embedded in product development, market entry, and client decisions from the outset. Institutions that treat compliance as a strategic capability are pulling ahead; those that treat it as a tick-box exercise are spending more and getting less.
Which regulations are reshaping payments compliance in 2025–2026?
Several major frameworks are converging at once. PSD3, AMLD6 and the EU AML Regulation are restructuring supervisory architecture across European payments. DORA sets a new standard for operational resilience, MiCA brings digital assets into the regulatory perimeter, the US GENIUS Act establishes a stablecoin framework with reach beyond the US, and Australia is beginning its largest AML reforms in two decades.
What do regulators expect from compliance functions now, if not just controls?
Evidence that an institution genuinely understands its risks – their nature, their scale, and how they interact with the business model – and has built a framework that can scale dynamically as the business grows. Demonstrating that you have policies, procedures and experienced teams is no longer sufficient on its own.
How should compliance be involved in business decisions?
At the front end. A compliance team brought in late can only stop a bad decision or slow a good one, whereas a team involved early helps design a better one – commercially viable, jurisdictionally sound, and risk-based from the start. The difference in outcome, and in the cost of reaching it, is significant.
How has the relationship between regulators and compliance leaders changed?
It has moved from a static model of annual reviews and reactive reporting toward more dynamic engagement. Regulators are increasingly curious about how institutions are adapting their frameworks to emerging risks such as digital assets, new payment rails, and evolving sanctions – and they want compliance leaders willing to share that thinking substantively, as peers rather than subjects.
What do sophisticated B2B payments clients now expect on compliance?
Not just sound controls, but transparency about how risk appetite is set, how it evolves, and how a banking partner will communicate changes before access is affected rather than after. This expectation is a direct response to past periods of abrupt de-risking, where appetite shifted with little transparency or notice.