😱 A U.S. VC fund with only $120M under management was just fined $216M for violating sanctions — potentially wiping out the investments of all its LPs. This is GVA Capital, and we need to talk about why this is such a big deal for both GPs and LPs. What happened: From 2018 to 2021, GVA Capital — based in San Francisco and domiciled in the Cayman Islands — knowingly handled tens of millions for sanctioned Russian oligarch Suleiman Kerimov. Even after Kerimov was blacklisted, they allegedly routed investments through his nephew as a proxy. The U.S. Treasury called this a “blatant violation of sanctions law” and hit the firm with a $216M penalty... nearly DOUBLE its AUM. This means almost certain ⚰️ for the firm. Once tied to sanctions violations, raising future funds becomes nearly impossible. What this means for LPs invested in GVA Capital: 💸 Massive Capital Erosion – A $216M fine against a $120M fund means there’s not enough money in the pot. LPs could see their capital essentially wiped. 🚫 Liquidity & Operations Risk – Paying the fine could choke off cash flow for follow-ons, operations, and distributions. 📉 Regulatory Compliance Exposure – Being an LP in a fund tied to sanctioned individuals can create your own compliance headaches — especially for institutional investors. Why this matters for GPs: 🔸 Compliance infrastructure is a non-negotiable. Basic AML/sanctions screening isn’t optional; it’s the foundation that prevents fund-destroying penalties. 🔸 Fund ops, AML, and sanctions screening should be institutional-grade from day one, regardless of fund size. 🔸 Weak operational discipline can undo years of portfolio work in a single enforcement action. Why this matters for LPs: 🔸 Limited liability doesn’t protect investment value. While your personal assets are safe, your committed capital can still be completely wiped out by GP misconduct. 🔸 Always diligence how a fund operates, not just what it invests in. 🔸 Know the back-office provider. Audit AML, sanctions screening, and regulatory compliance processes. Great deal flow means nothing if your compliance foundation is weak. One preventable mistake in the back office can end your career before Fund I is even fully deployed. Institutional-grade compliance isn’t a “nice to have.” It’s the cost of admission if you want to survive in this industry. — ✍️ Myrto Lalacos Follow for more on launching, running, and investing in VC firms.
Regulatory Compliance in Finance
Explore top LinkedIn content from expert professionals.
-
-
One of the first mistakes I made when launching my first regulated business was delegating compliance. I started with TransferTo, a mobile micro value transfer service, which wasn’t regulated. Eventually, TransferTo split into two branches (now DT One and Thunes), with the new branch handling actual money transfers that required regulatory compliance. At that time, I thought, "I'll hire a Chief Compliance Officer and let them set up the function," just as I did with marketing or tech. That was a mistake. I faced significant challenges in opening a bank account because I hadn't fully mastered my processes. I also had a hard time communicating with my compliance officer. I didn't have the words or the right codes. Regulatory compliance is ultimately the responsibility of the company and its leadership—it cannot be outsourced. As a CEO, I believe it's essential to make the effort to understand it because the risks for the company are too significant. The least severe risk is a fine. The moderate risk is a suspension of the license. The most severe risk is revocation, or even imprisonment. To effectively manage these risks, I believe it's the CEO's duty to establish the compliance framework. Get your hands dirty. Understand the mechanics. Then, the Chief Compliance Officer can execute your plan. And this is exactly what regulators expect. The CEO's ability to manage compliance is one of the key aspects they evaluate when you apply for a licence. They don't require you to know how to code, but they do expect you to fully understand your company's compliance. If I have one piece of advice for a fintech entrepreneur: invest in compliance. The stakes are too high. As a startup, it could destroy your business. As a scale-up, it could strongly hinder your growth.
-
When it comes to #openbanking, the #US has been known for their market-led approach - contrary, for example, to Europe or the UK. Now with the Personal Financial Data Rights rule a U-turn is being made. Let’s take a look. Like most other things in the US, Open Banking has been left to the market to sort out. That means that the access to data and the connections between the various parties (mainly financial institutions and front-end providers like #fintech players) were not subject to centrally designed and imposed rules. As a result, market players jumped in to cover the gap: Plaid has managed to build within the past years APIs to almost every financial institution in the country (about 18,000), acting, in essence, as the main intermediary or gateway to thousands of apps, the likes of Venmo, PayPal, Coinbase or Robinhood. On the other end, we have geographies where Open Banking has been triggered by regulation, with financial institutions forced to open up and provide access to their data to authorized third parties (i.e. in Europe via PSD2 and in the UK via OBIE). However as open banking initiatives around the world are increasingly setting the bar higher, voices were becoming louder in the US since quite some time in favour of a regulatory approach that would expedite and facilitate the path to open banking. This is what just happened a few days ago with the Consumer Financial Protection Bureau (CFPB) proposing a rule (still in draft) that practically facilitates this. Here is what changes: — Consumers own their #data for free and banks and other FIs are obliged to provide access to personal financial data via dedicated digital interfaces — Consumers can share their data with third parties, which is the basis for providers to build new innovative services on top — Competition will be boosted by allowing consumers to easily switch providers These changes will be enforced via a number of measures: — Measures to prevent unchecked surveillance and misuse of data — Measures to give consumers control (i.e. revoking data access) — Standards will be still set by the market but rules by the CFPB in order to ensure that they are fair, open, and inclusive Implementation will be done in phases with larger providers subject to the rules much sooner than smaller ones and community banks and credit unions without digital interfaces to their customers would be exempted. If there is one thing that stands out, it is the following: the entire transformation evolves around data. Or better the access to data. Exactly as Europe has recently done with its draft Financial Data Access (FIDA) framework announced in the summer. This is not by accident or coincidence. Data is the main driver behind the rise of open banking and its further transition to open #finance. The new rule has the potential to completely change the US finance landscape. What do you think? Opinions: my own
-
Scoop: Piermont Bank is exiting its relationship with Banking-as-a-Service platform Unit, but is seeking to keep some fintech clients the two shared, sources with direct knowledge tell me: Piermont will be the 3rd bank partner Unit has lost, following Blue Ridge Bank and Choice Bank, though Unit had minimal activity through Choice. The news comes as US bank regulators make increasingly clear that they expect banks engaged in BaaS business models to have DIRECT visibility, oversight, and responsibility of their third-party fintech partners. The recent consent order Lineage Bank reached with the FDIC reinforces that bank executive management *and* their boards need to monitor what's happening with their BaaS and fintech partners at a fairly granular level, with the order specifically mentioning activity in "FBO" accounts and ACH transactions. It has quickly become conventional wisdom that "intermediated models," where a non-bank third party sits between banks and customer-facing fintechs and takes some level of responsibility for program management and compliance, are just not workable in the current climate. Some players in the middleware space are already moving to adapt to this reality. For example, alongside its recent significant layoffs, Treasury Prime announced a strategic re-alignment from selling BaaS services to FINTECHS and matching them with a partner bank in its network to a focus on selling software to BANKS that enables them to work directly with fintechs. Unit hasn't made any similar public announcement as of yet, but is undoubtedly aware of and working with its bank and fintech partners to respond to the shifting regulatory environment. #breakingnews #banking #fintechnews
-
“We are ISO 27001 certified, are we DORA compliant?” Not so fast. ISO 27001 and DORA both focus on cybersecurity and risk management, but they serve very different purposes. If you're a financial institution or an ICT provider working with financial institutions in the EU, DORA compliance is mandatory, and ISO 27001 alone won’t get you there. Let’s break it down: 1. Regulatory vs. Voluntary Framework ↳ ISO 27001 – A voluntary international standard for information security management. ↳ DORA – A mandatory EU regulation for financial entities and their ICT providers, with strict oversight and penalties for non-compliance. 2. Scope and Focus ↳ ISO 27001 – Offers a customizable scope tailored to organizational needs, focusing on information security (confidentiality, integrity, availability) based on specific risk assessments and chosen controls. ↳ DORA – Enforces a standardized scope across financial entities, extending beyond security to operational resilience. It ensures institutions can withstand, respond to, and recover from ICT disruptions while maintaining service continuity. 3. Key Compliance Gaps 🔸 Incident Reporting ↳ ISO 27001 – Requires incident management but doesn’t impose strict deadlines or mandate reporting to regulators, as it is a flexible standard. ↳ DORA – 4 hours to report a major incident, 72 hours for an update, 1 month for a root cause analysis. 🔸 Security Testing ↳ ISO 27001 – Requires vulnerability management but leaves testing methods and frequency to organizational risk. ↳ DORA – Annual resilience testing, threat-led penetration testing every 3 years, continuous vulnerability scanning. 🔸 Third-Party Risk Management: ↳ ISO 27001 – Covers supplier risk but with general security controls. ↳ DORA – Enforces contractual obligations, exit strategies, and regulatory audits for ICT providers working with financial institutions. 4. How financial institutions and ICT providers can address the delta? ✅ Perform a DORA Gap Analysis – Identify missing controls beyond ISO 27001. (Hopefully, you're not still at this stage now that DORA has been mandatory since January 17, 2025.) ✅ Upgrade Incident Response – Implement real-time monitoring and reporting mechanisms to meet DORA’s deadlines. ✅ Enhance Security Testing – Introduce formalized resilience testing and threat-led penetration testing. ✅ Strengthen Third-Party Risk Management – Update contracts, prepare for regulatory audits, and ensure exit strategies comply with DORA. ✅ Improve Business Continuity Planning – Move from cybersecurity alone to full digital operational resilience. 💡 ISO 27001 is just the tip of the iceberg - beneath the surface lie significant gaps that only DORA addresses. 👇 What’s the biggest challenge in aligning with DORA? Let’s discuss. ♻️ Repost to help someone. 🔔 Follow Amine El Gzouli for more.
-
The Financial Action Task Force (FATF) has released its Updated Recommendations (February 2025), reinforcing international standards on AML, CFT, and Combating the Financing of Proliferation (CFP). Key Highlights: ✅ Risk-Based Approach (RBA) Strengthened • Countries and financial institutions must continuously assess ML/TF risks. • Proliferation financing risks (linked to WMDs) must now be explicitly assessed and mitigated. • Greater emphasis on data-driven decision-making in risk management. ✅ Stronger Financial Crime Enforcement & Asset Recovery • Enhanced measures to identify, freeze, and confiscate illicit assets, even without conviction-based legal proceedings. • Countries must cooperate more effectively on cross-border investigations related to ML, terrorism, and sanctions evasion. • Expanded legal mandates for regulators to seize cryptocurrency-related assets used for illicit activities. ✅ Enhanced Corporate Transparency & Beneficial Ownership Regulations • Stricter disclosure requirements for companies and trusts to prevent anonymous ownership structures facilitating financial crime. • Introduction of centralized registries for beneficial ownership information, accessible by regulators and FIUs. • Bearer shares and nominee shareholder arrangements are further restricted due to their role in obfuscating ownership. ✅ New Standards for Virtual Assets & Emerging Technologies • FATF mandates stronger oversight on VASPs, aligning AML rules for crypto-assets with traditional financial institutions. • New tech-based compliance controls (including AI-driven monitoring) recommended to enhance financial crime detection. • Stricter regulations for cross-border virtual asset transactions to combat illicit financing and crypto-enabled ML. ✅ Expanded Measures Against Terrorist Financing & Sanctions Evasion • Countries must implement targeted financial sanctions to prevent terrorism and WMD proliferation financing. • NPOS are now required to assess their terrorist financing risks while ensuring legitimate operations are not disrupted. • Greater scrutiny on correspondent banking relationships to prevent facilitation of illicit transactions. ✅ Increased International Cooperation & Mutual Legal Assistance • FATF calls for faster cross-border financial intelligence sharing to prevent criminals from exploiting jurisdictional gaps. • Countries must align with UNSCRs on CTF and sanctions enforcement. Recommandations: 🔹 Implement advanced transaction monitoring using AI to detect suspicious financial activities more effectively. 🔹 Reinforce beneficial ownership compliance 🔹 Strengthen cross-border AML/CFT coordination by fostering partnerships between FIs, regulators, and law enforcement agencies. 🔹 Ensure robust oversight on virtual assets by applying FATF’s Travel Rule to cryptocurrency transactions and monitoring DeFi risks. #AML #FATF #FinancialCrime #Compliance #CryptoRegulation
-
🌐 Financial Action Task Force (FATF) Standards Update – June 2025 Yesterday, the #FinancialActionTaskForce (#FATF) announced important updates to #Recommendation16, commonly referred to as the Travel Rule, with a focus on enhancing the transparency and security of #crossborderpayments and #virtualasset transfers. updates : ▪️ Standardised data requirements for peer-to-peer cross-border payments above USD/EUR 1,000 (name, address, date of birth) ▪️ Clearer allocation of responsibilities within the payment chain, starting with the financial institution receiving the customer’s instruction ▪️ Mandatory adoption of anti-fraud and error-prevention technologies, such as recipient account verification tools ▪️ Clarified scope for card transactions, which remain exempt from full R.16 requirements when used for goods and services, with updated definitions These changes support the G20 roadmap to make cross-border payments faster, cheaper, more transparent, and more inclusive They were shaped by two public consultations involving over 300 contributions from financial institutions, industry bodies, civil society, and public authorities. The revised standards will take effect by the end of 2030, with further guidance to be issued by the FATF to support implementation across the private sector. #aml #antimoneylaundering #followthemoeny #dirtymoney #compliance #complianceofficer #duediligence #transactionmonitoring
-
SBTi lanches a net-zero standard for financial institutions The Science Based Targets initiative (SBTi) has officially launched its Financial Institutions Net-Zero Standard Version 1.0 in July 2025 after extensive pilot testing with 33 institutions and two public consultations. This 81-page comprehensive framework is a critical moment for sustainable finance. Over 165 financial institutions already use SBTi's existing criteria. The 81-page standard provides detailed criteria across 5 key areas: net-zero commitments, base-year assessments, policies & target setting, progress tracking, and SBTi claims. It includes specific metrics, sector specifications, and implementation guidance. Who does the standard apply to • Banks • Asset managers • Insurers • Private equity firms generating 5%+ revenue from financial activities What does the standard cover? • Lending • Investing • Insurance underwriting • Capital markets globally What are the key requirements? "Engagement first" approach prioritising client transition over divestment Immediate cessation of new coal financing globally Oil & gas project finance phase-out by 2030 latest 95% climate-aligned portfolio by 2050 Annual progress reporting with full transparency by 2030 What are the critical dates? NOW: Institutions can submit targets for validation • Dec 2026: Transition period ends • 2030: Deforestation exposure assessment required, oil & gas general-purpose finance phase-out • 2050: Net-zero target achievement Why decarbonisation is critical for asset protection? Climate risks pose unprecedented threats to financial assets. Recent data shows natural disasters caused $320bn in global losses in 2024 alone, with weather catastrophes responsible for 93% of overall losses. The ECB finds that 40% of eurozone bank loan portfolios are exposed to energy-intensive sectors vulnerable to transition risks. Studies estimate $1.4 trillion in oil and gas assets globally are at risk of becoming stranded. The projected economic losses from failing to achieve 1.5°C warming are 5x greater than the climate finance needed by 2050 to prevent them. #sustainablefinance #netzero #climateaction #esg #sbti #banking #insurance #assetmanagement
-
Is KYC risk assessment becoming more complex by the day? 🤔 With stricter global regulations and increasingly sophisticated financial crime tactics, it's a challenge we can't afford to overlook. I recently found a guide from iDenfy that offers practical insights and actionable strategies for compliance professionals. Even better, it's completely free, not even a gated content page, and you can directly get it from my post! It explores some of the biggest hurdles in our field, like: 📌 Managing regulatory requirements across multiple jurisdictions 📌Tackling high onboarding volumes without sacrificing accuracy 📌 Minimizing false positives and false negatives in risk assessments 🪡 What caught my attention is how it emphasizes modern, tailored solutions. For example, you can: ➡️ Adjust risk levels based on specific industries (think gambling, fintech, or healthcare) ➡️ Assign custom risk weights for better compliance alignment ➡️ Use no-code tools to create rules that meet your unique needs with ease 🛡️ Another highlight for me was its focus on countering emerging fraud risks, like synthetic identities, deepfakes, and hidden ownership structures. It explains how technologies like AI and biometric verification can help us stay ahead of these threats. 🌐 Beyond the tools and technologies, the guide stands out for its practical, risk-based approach to global compliance. Whether you're improving cross-border operations or automating workflows, the strategies feel grounded and relevant. If you’re looking for valuable insights to optimize your compliance processes, I think you’ll find this resource very useful. Sometimes, small changes in how we assess and manage risk can lead to big results! 💪 Are you passionate about an AML-related topic? 🤔 Would you like to write about it and reach over 23k compliance professionals? 🔥 If so, just send me a message to work out the details! 🙂 #compliance #financialcrime #moneylaundering #aml Viktor Domantas Darius Robert
-
MDR/IVDR Are Just the Tip of Your Regulatory Iceberg—Look Beyond Them A cornerstone of successful medical device development is identifying all regulatory requirements. The MDR (Regulation (EU) 2017/745) and IVDR (Regulation (EU) 2017/746) provide a vast catalog of device requirements and company procedures. Standards then offer additional details for compliance. However, many see this as the entire iceberg and assume it’s enough for full compliance. The reality is different. Medical devices and manufacturers often need to comply with multiple regulations. It’s crucial to identify all applicable regulations beyond the obvious ones. Here are 7 regulations and directives many miss but are often essential: EU AI Act (Proposal COM/2021/206) → Crucial for any medical device incorporating AI. → Adds a certification framework beyond MDR/IVDR. → Overlapping requirements mean a thorough gap analysis is essential. European Health Data Space Regulation (Proposal COM/2022/197) → Central to unlocking cross-border health data sharing in the EU. → A framework for primary and secondary use of electronic health data. → Compliance requires alignment with GDPR and national health laws. Radio Equipment Directive (2014/53/EU) → Applies to devices with wireless communication (e.g., Bluetooth). → EMC testing under MDR isn’t enough for compliance. → Requires additional IFU content, such as wireless frequency specifications. General Data Protection Regulation (Regulation (EU) 2016/679) → Applies to all devices interacting with personal data. → Covers even non-sensitive data, beyond health-related information. → Expected since its enforcement began in 2018. Battery Regulation (Proposal COM/2020/798) → Relevant for devices with rechargeable or disposable batteries. → Mandates user access to batteries for removal or replacement. → Requires compliance with labeling and recycling standards. RoHS (Directive 2011/65/EU) and REACH (Regulation (EC) No 1907/2006) → Limit hazardous substances in device materials. → Biocompatibility doesn’t guarantee compliance with these regulations. → Crucial during material selection for physical devices. WEEE (Directive 2012/19/EU) → Governs proper decommissioning and disposal of electrical devices. → Includes exemptions for implantable and potentially infectious devices. → Often Requires agreements with waste management organizations. By identifying them early, the iceberg may remain large, but at least you’ll have transparency and control. P.S. What other regulations or directives would you add to this list? ⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡⬡ MedTech regulatory challenges can be complex, but smart strategies, cutting-edge tools, and expert insights can make all the difference. I’m Tibor, passionate about leveraging AI to transform how regulatory processes are automated and managed. Let’s connect and collaborate to streamline regulatory work for everyone! #automation #regulatoryaffairs #medicaldevices
Explore categories
- Hospitality & Tourism
- Productivity
- Soft Skills & Emotional Intelligence
- Project Management
- Education
- Technology
- Leadership
- Ecommerce
- User Experience
- Recruitment & HR
- Customer Experience
- Real Estate
- Marketing
- Sales
- Retail & Merchandising
- Science
- Supply Chain Management
- Future Of Work
- Consulting
- Writing
- Economics
- Artificial Intelligence
- Employee Experience
- Healthcare
- Workplace Trends
- Fundraising
- Networking
- Corporate Social Responsibility
- Negotiation
- Communication
- Engineering
- Career
- Business Strategy
- Change Management
- Organizational Culture
- Design
- Innovation
- Event Planning
- Training & Development