Six months ago, much of the compliance conversation was still focused on getting onboarding right. Halfway through 2026, a harder question has come into focus: is the ownership information you relied on at onboarding still current, and can you evidence where it came from?
That shift has not come from a single piece of legislation. In fact, regulatory regimes are not all moving in the same direction.
Australia has expanded the reach of its AML/CTF regime. Europe is preparing for a more harmonised AML framework. The United States, by contrast, has substantially narrowed federal beneficial ownership reporting requirements.
Different approaches, but a common operational challenge
Whether the requirement comes directly from legislation, regulatory supervision, a bank, a counterparty or an organisation’s own risk framework, businesses increasingly need to be able to answer three basic questions:
Who ultimately owns or controls this entity? What evidence supports that conclusion? And would we know if something material changed?
Australia’s Tranche 2 reforms brought professions including lawyers, accountants, real estate professionals and trust and company service providers within the AML/CTF regime from 1 July 2026.
In Europe, responsibility for a number of AML/CFT functions transferred from the European Banking Authority to the new Anti-Money Laundering Authority, AMLA, at the beginning of 2026. Work is now underway on the technical standards that will support the EU’s new AML framework ahead of the substantive requirements applying from 2027.
The United States illustrates why this cannot simply be described as regulation getting tougher everywhere. Federal beneficial ownership reporting requirements have moved in the opposite direction, with US-created entities and US persons now largely outside the Corporate Transparency Act reporting regime.
That divergence matters.
A lower statutory reporting requirement does not necessarily mean a lower due diligence requirement for everyone dealing with that entity. Banks, regulated businesses, counterparties and internal risk teams may still require considerably more information than the legal minimum.
For compliance teams operating internationally, that distinction between what the law requires an entity to report and what you need to know about that entity is becoming increasingly important.
The APAC lens
For businesses with China exposure, another issue is becoming harder to ignore: how information has been sourced, collected and transferred.
China’s Decrees 834 and 835 are not beneficial ownership rules. But they add another dimension to cross-border due diligence because they can affect the legality and defensibility of information gathering and data sharing in particular circumstances.
The practical implication is not that legitimate corporate verification has suddenly become prohibited. It is that organisations relying on China-linked data should understand where that information came from, how it was obtained and whether its use and transfer are appropriate within the applicable legal framework.
Data provenance therefore becomes more than a data-quality question, but a compliance and risk question.
In Singapore, the regulatory framework is well established, but the practical focus is increasingly on the quality and defensibility of the underlying due diligence, including how beneficial ownership is identified, evidenced and kept current.
Hong Kong presents a similar operational challenge. The Significant Controllers Register is not new, but firms still need to be able to establish and evidence who ultimately owns or controls an entity, particularly where structures are complex or span multiple jurisdictions.
The regimes are different. The underlying discipline is remarkably consistent: do not simply hold the information — be able to substantiate it.
Why this is harder than simply “checking more often”
The natural response is to run periodic checks more frequently. That helps, but it does not solve the entire problem.
Traditional due diligence was largely designed to establish a point-in-time position: this company exists, these are its shareholders, this is the beneficial owner, this is the assessed risk.
But ownership is not static.
Shareholdings change. Corporate structures are reorganised. Directors and controlling individuals change. New entities are inserted into ownership chains. Changes may be entirely legitimate while still materially altering the risk profile of a business relationship.
And a KYB report that was accurate at onboarding does not necessarily reflect the organisation you are dealing with today.
Three questions worth asking
Across many regulatory environments, three practical questions keep recurring:
- Is the ownership information we hold still accurate?
- Can we evidence how we reached that conclusion?
- If something material changes, how quickly would we know?
Most established compliance programmes are designed to answer the first question at onboarding.
The second requires good source data, clear provenance and an audit trail.
The third requires a different mindset: treating verification not simply as an event, but as something that needs to remain valid throughout the business relationship.
That does not mean every organisation needs to monitor every entity in exactly the same way. The approach should remain proportionate to risk.
But it does mean being deliberate about what changes matter, how those changes will be identified and what happens when they occur.
What I would watch for next
Three areas stand out for the remainder of 2026 and beyond.
First are implementation and enforcement. Much of the regulatory architecture already exists. The important question increasingly becomes how regulators and regulated institutions apply it in practice.
Second is the growing distinction between regulatory minimums and counterparty expectations. The United States is a good example: federal reporting obligations may have reduced significantly, but that does not remove the need for banks and international counterparties to establish ownership for their own regulatory and risk purposes.
Third is data provenance. Compliance teams have traditionally concentrated on whether the information in front of them is accurate. Increasingly, particularly in complex cross-border environments, another question needs to sit alongside it:
Where did this information come from, and can we defend our reliance on it?
None of this requires compliance teams to start from scratch.
The fundamentals of cross-border due diligence remain the same: verify the entity, understand who ultimately owns or controls it, assess the risk and retain the evidence supporting that conclusion.
What is changing is the importance of what happens next.
Book a 20-min demo and see how AsiaVerify accelerates onboarding, reduces false positives, and keeps you audit-ready.