Stay in the know
Receive timely insights and briefings from HSF Kramer, tailored to keep you informed and ahead
We are pleased to bring you the latest edition of the Herbert Smith Freehills Kramer (HSF Kramer) white collar crime and government investigations global round-up.
This six-monthly publication calls on lawyers from around the world to provide updates from their jurisdictions on significant new developments and enforcement trends relevant to financial crime. Where available, the updates link to underlying posts with more detail. As ever, please do not hesitate to contact the authors, or your local HSF Kramer contacts, if you wish to discuss any of the issues raised.
Spring 2026 brings an array of legal reforms (and associated increased scope for corporate criminal liability), as well as a focus on the heightened risks arising from the current geopolitical environment and the rapid pace of technological change.
The UK's new Crime and Policing Act 2026 (the CPA) represents the next stage in the expansion of corporate criminal liability in the UK, building on the changes introduced by the Economic Crime and Corporate Transparency Act 2023 (ECCTA) and discussed in our November 2023 update. Among other changes, ECCTA expanded the so-called "identification doctrine" by introducing a new basis for attributing criminal liability to companies for the actions of their "senior managers". A company can therefore be held criminally liable if one of its senior managers commits an "economic crime offence" while acting within the actual or apparent scope of their authority. That provision came into force in October 2023.
The CPA extends the relevant ECCTA provisions to cover all offences (i.e. no longer limiting the "senior manager" rule to specified economic crimes). This will make it easier to bring corporate prosecutions in cases where this may not previously have been possible.
Potential areas of additional exposure include:
The expansion of senior manager attribution will come into force in June 2026. For further detail, please see our blog posts here and here.
EU restrictive measures have taken on a central role in the response to geopolitical crises, yet the absence of uniform rules has long hampered enforcement. Directive (EU) 2024/1226 (the Directive), adopted in April 2024, introduced common minimum rules on offences and penalties for violations of such measures. Member States had until 20 May 2025 to transpose the Directive into national law.
However, implementation has been delayed in several Member States. The position in Italy, France, Germany and Spain is as follows:
Italy
France
Germany
Spain
The recent escalation of conflict in the Middle East has materially reshaped the regional risk landscape for sanctions compliance and financial crime, creating a volatile environment for businesses, financial institutions and consumers alike. Geopolitical instability is translating directly into heightened enforcement scrutiny, increasing exposure across both traditional financial channels and emerging risk areas, including through the following:
These risks underscore how quickly geopolitical conflict can translate into sanctions and financial crime exposure across multiple sectors. Organisations operating in or connected to the region should expect sustained regulatory scrutiny and ensure that sanctions, financial crime and fraud risks are closely monitored.
South Africa recently released the Protected Disclosures Bill, 2026 (the Bill), for public comment, which proposes a wholesale replacement of the Protected Disclosures Act, 2000 (the Act).
The need for reform is evident — a report submitted by the National Anti-Corruption Council in August 2025 revealed that only 45% of respondents indicated they would report corrupt behaviour. This is primarily due to fear and weak law enforcement. Unfortunately, under the Act, it is often easier to participate in corruption than to expose it.
Against this backdrop, the Bill seeks to address these issues by aligning South Africa’s whistleblowing framework more closely with international best practice. For example, similar to the EU Whistleblowing Directive, the Bill extends protection beyond traditional employees to include contractors, consultants, volunteers and trainees, as well as related persons and those assisting the discloser.
The changes proposed in the Bill are of paramount importance given the severe risks faced by whistleblowers in South Africa, which range from job loss to, in extreme cases, death. Notably, the Act provided no financial incentive to encourage reporting, unlike the United States and, to a lesser extent, Canada. The Bill addresses this by introducing a discretionary reward system which allows courts to grant whistleblowers up to 25% of any monetary sanction resulting from their disclosure, where their evidence materially contributed to a conviction.
Other key changes reflected in the Bill are summarised as follows:
The Bill can be accessed here.
Effective April 2027, under the Act on the Prevention of Transfer of Criminal Proceeds (APTCP), Japan will require financial institutions to confirm customers’ identities via chips embedded in ‘My Number’ identity cards or driver’s licences for all remote account openings. This replaces the current practice of accepting images or photocopies of identity documents. Customers without 'My Number' cards or driver's licences may still submit original residency certificates or tax documents by mail.
The change will apply to natural persons acting in both their personal capacity and their corporate representative capacity in "Specified Transactions" (as defined under the APTCP) but will not apply to corporations as it relates specifically to personal ID documents.
The change is designed to prevent fraudulent accounts opened under stolen identities, bank transfer scams and telephone banking fraud. It occurs against a backdrop of similar shifts by regulators around the world, such as the European Union’s eIDAS Regulation and EU Digital Identity Wallet, and Singapore’s Singpass system. However, Japan’s mandatory, nationwide shift to chip-based verification for remote financial services sets a particularly high standard for AML/KYC compliance in the banking sector.
In addition, an earlier revision to the APTCP, effective June 2023, imposes notification requirements on Cryptoasset Exchange Service Providers and Electronic Payment Instruments Service Providers (collectively VASPs). Commonly known as the “travel rule”, the APTCP now requires originator VASPs to notify beneficiary VASPs of originator and beneficiary information at the time of the transfer of cryptoassets (virtual assets or VAs) or electronic payment instruments (stablecoins or SCs). The travel rule enables regulators to track the transaction routes of VAs/SCs, which helps to combat the use of VAs/SCs for money laundering purposes.
Since late 2025, regulatory scrutiny of speaker/expert fees in China’s pharmaceutical sector has intensified, with the focus shifting from procedural compliance checks to substantive review. Regulators have drawn clearer compliance boundaries, supported by authoritative guidance and targeted penalties. The overall enforcement message is clear: academic activities must not be used to disguise improper transfers of value, and both pharmaceutical companies and healthcare providers (HCPs) may face accountability.
The latest compliance framework is anchored in guidance issued in January 2026 by the Central Commission for Discipline Inspection and the National Supervisory Commission, entitled “How to Identify Illegal Receipt of Speaker Fees”. The guidance identifies four core red lines for speaker fee compliance:
Enforcement actions from late 2025 illustrate how regulators were already applying principles that would later be explicitly consolidated in the January 2026 guidance. For example, in October 2025, a Shanghai regulator penalised a company for fabricating 587 academic meetings, forging participant lists and recharacterising routine internal meetings as academic events between 2022 and 2024. The company paid RMB 609,800 in improper speaker fees to HCPs and was fined RMB 400,000.
Regulatory actions confirm that “substance over form” is the governing standard for speaker fee compliance. Companies can no longer rely on formal documentation alone and should verify the authenticity and substance of each activity. They should also align fee levels with official standards, obtain prior institutional approval for HCP participation and avoid any link between speaker payments and sales performance.
In recent months, the Department of Justice (DoJ) and Securities and Exchange Commission (SEC) have continued to refine their corporate enforcement practices.
In February 2026, the SEC announced the first updates to its enforcement manual since 2017, revising policies on the Wells Notice process, settlements and cooperation credit.
On 10 March 2026, DoJ announced a new Department-wide Corporate Enforcement and Voluntary Self-Disclosure Policy, providing a uniform framework across all DoJ components except the Antitrust Division and superseding all preexisting policies. DoJ largely adopted Department-wide the framework of the Criminal Division’s comparable policy, which was revised in May 2025, and establishes a three-tiered structure: (i) declination cases; (ii) “near-miss” cases; and (iii) cases without voluntary disclosure or full cooperation.
Factors determining categorisation include: (i) timely self-report of previously unknown conduct to the appropriate division when not facing an imminent threat of discovery; (ii) full cooperation; (iii) timely and appropriate remediation; and (iv) absence of aggravating circumstances. A corporation that fails to qualify for declination solely due to aggravating factors or its self-report not qualifying as voluntary self-disclosure under the policy will qualify as a “near miss” and will be offered a non-prosecution agreement with a term of less than three years, no compliance monitor, and a 50-75% reduction from the low end of the applicable US Sentencing Guidelines fine range. All other cases remain subject to prosecutorial discretion.
Curiously, just two weeks earlier, the United States Attorney’s Office for the Southern District of New York (SDNY), the premier federal prosecutor’s office for major financial crime and misconduct affecting market integrity, had released its own Voluntary Self-Disclosure and Cooperation Program for Financial Crimes. Under the SDNY’s policy, companies that (i) self-report qualifying illegal activity; (ii) cooperate fully; (iii) commit to ongoing reporting of criminal conduct for three years; and (iv) remediate harm (including paying restitution) will receive a conditional declination “shortly after" self-reporting. This marks the first time any DoJ component has offered a conditional declination so early in the investigative process, extending unprecedented leniency and certainty. While commentators speculated that the Department-wide policy superseded the SDNY’s programme, US Attorney for the SDNY, Jay Clayton confirmed publicly in April that SDNY’s policy remained viable after the announcement of DoJ’s “Department-wide” policy and, indeed, the SDNY’s voluntary self-disclosure program remains published and in force on DoJ’s website.
ASIC has entered 2026 signalling a sustained uplift in its enforcement agenda, building on its doubling of new investigations and court proceedings in 2025. ASIC's key 2026 enforcement priorities encompass three key focus areas, including corporate crime and financial fraud, namely:
Aspects of this agenda are already translating into tangible enforcement outcomes. Since late 2025, ASIC has:
We expect ASIC to maintain a focus on these enforcement outcomes in 2026 with a continued emphasis on individual accountability and corporate liability.
The rapid advancement of artificial intelligence has altered Australia’s financial crime risk profile. While AI offers efficiencies for financial institutions, it has simultaneously provided fraudsters with powerful tools to scale, automate and industrialise misconduct.
In early 2026, public reporting highlighted the widespread use of generative AI to facilitate large-scale mortgage and lending fraud across major Australian banks. Fraud networks were alleged to have deployed AI tools to generate highly sophisticated false income statements, invoices and other business records to bypass traditional verification processes and secure home loans. Suspected fraudulent lending linked to these practices has been reported in the hundreds of millions of dollars. In response, AUSTRAC commenced an industry-wide review, issuing data-sharing requests to Australia's major banks and scrutinising mortgage books to assess the nature and extent of the misconduct.
This regulatory response aligns with a broader global escalation in AI-enabled‑financial crime, particularly in relation to cyber threats driven by frontier AI models such as Anthropic’s Mythos. APRA recently warned Australian banks that advanced AI models like Mythos are likely to significantly increase the probability, speed and scale of cyberattacks. It has also made clear its expectation that boards and executives strengthen AI literacy, governance frameworks and security controls, and has signalled an increased willingness to intensify supervision and enforcement where AI-related risks are not adequately managed.
Taken together, these developments convey that technology-enabled financial crime will attract heightened supervisory and enforcement attention, particularly where governance, accountability and risk management frameworks fail to keep pace with rapid technological change.
Partner, Head of White Collar Crime and Government Investigations, Hong Kong
Partner, Head of Corporate Crime and Investigations, EMEA, Paris
Partner, London
Head of Litigation, US and Managing Partner, New York Office, New York
Partner, Brisbane
The contents of this publication are for reference purposes only and may not be current as at the date of accessing this publication. They do not constitute legal advice and should not be relied upon as such. Specific legal advice about your specific circumstances should always be sought separately before taking any action based on this publication.
© Herbert Smith Freehills Kramer 2026
Receive timely insights and briefings from HSF Kramer, tailored to keep you informed and ahead