Compliant in Every Market, exposed at the Intersections

Compliant in Every Market, exposed at the Intersections

Why leading asset managers have stopped treating regulatory risk as a cost centre and started managing it like market risk.

More global AUM than ever is distributed across three or more jurisdictions, and the compliance surface area has never been larger or more consequential. The firms ahead of this are not playing catch-up. They have changed how they think about the problem entirely.

The firms that have made the leap have stopped treating regulatory risk as a cost centre. They now manage it as a strategic variable, applying the same rigour used for market and credit risk, and turning disciplined oversight into a source of competitive advantage.

The compliance surface area problem

When asset managers first ventured into multi-jurisdiction distribution, the dominant model was additive: hire a local compliance officer, engage a regional legal firm, bolt on a country-specific fund wrapper, and proceed. That worked while regulatory frameworks were broadly aligned. That alignment no longer holds.

The result is a compliance surface area that does not merely grow with every new market — it multiplies in complexity. The arithmetic is unforgiving. Each new jurisdiction adds one rulebook, but it adds a pairwise interaction with every rulebook already in place. Three markets generate three intersections. Eight markets generate 28. The headcount line in the compliance budget grows linearly; the risk does not.

Interactions between regimes create risks that no single-jurisdiction lens can detect. A fund can be lawfully marketed in London and still fall foul of national private placement rules in Frankfurt. A client relationship that qualifies as an Accredited Investor in Singapore may not meet the DFSA’s Professional Client threshold in the DIFC. These intersection risks are the new frontier of regulatory exposure.

Client classification is the cleanest illustration, because it is the gate through which every distribution decision passes. The same individual, same wealth, same experience, same documents, is tested against four different measurement bases and three different treatments of the primary residence, depending on where the relationship is booked.

TABLE 1: Same client, six different tests

Jurisdiction / RegulatorCategoryIndividual TestIn Motion
UK — FCAElective professional client (COBS 3.5)Qualitative assessment, plus two of three: portfolio above €500,000; ~10 significant transactions a quarter over four quarters; one year in a professional financial-sector roleCP25/36 would delete the quantitative test and add a £10m investable-assets route; consultation closed 2 February 2026, policy statement pending
EU — MiFID IIElective professional clientSame two-of-three structure as the current UK testRetail Investment Strategy proposals would cut the portfolio limb to €250,000 averaged over three years and widen the experience limb
DIFC — DFSA‘Assessed’ Professional Client (COB 2.3.7 / 2.4.2)Net assets of at least US$1m, excluding primary residence, plus an assessment of experience and understandingThreshold rose from US$500,000 on 1 April 2016; earlier classifications grandfathered
UAE mainland — SCAProfessional / Qualified InvestorNet assets of at least AED 4m excluding main residence, or annual income of at least AED 1m, plus a knowledge and experience declarationThis threshold dates from SCA-era rules, carried over to the CMA as its legal successor from 1 January 2026 under Federal Decree-Laws 32 and 33 of 2025; new CMA implementing regulations that could revise it are still awaited
Singapore — MASAccredited Investor (SFA s.4A), opt-inNet personal assets above S$2m with the primary residence capped at S$1m; or net financial assets above S$1m; or income of at least S$300,000 over 12 monthsOpt-in since the 2018 review; digital tokens take a 50% haircut and count only up to S$200,000
Hong Kong — SFCIndividual Professional InvestorPortfolio of at least HK$8m (roughly US$1m)‘Sophisticated’ treatment under the 2023 HKMA–SFC joint circular requires a HK$40m portfolio or HK$80m net assets

Note: net assets, net financial assets, portfolio value and income are four distinct bases. The DIFC excludes the primary residence outright, Singapore caps its contribution, Hong Kong measures a portfolio and ignores the question. A single global onboarding standard cannot be built on top of this; only a mapping can.

Three strategies the leading firms are using

1. Unified regulatory risk registers

Leading firms maintain a dynamic register that maps every product, investor category, and distribution channel against the requirements of each jurisdiction simultaneously. The key word is dynamic. A static register, updated quarterly, is already obsolete when the DFSA can issue a supervisory notice and MAS can update its licensing guidance in the same week. These registers detect cross-regime conflicts: where two individually compliant positions create a joint exposure.

2. Multi-entity structural planning

Sophisticated firms now treat entity structure as a risk management tool. One mid-sized alternatives manager restructured its EU-facing product through a Luxembourg ManCo in 2024 not for tax efficiency, but because post-Brexit divergence had created enforcement overlap risk on a single shared entity. Separating the regulatory perimeters isolated UK compliance risk from EU compliance risk, containing the cascading-failure scenario in which an enforcement action in one jurisdiction triggers a licensing review in another.

Perimeter separation contains contagion; it does not remove it. Regulators increasingly look through group structures, and common ownership, shared systems and shared senior management functions all remain visible. The gain is that a supervisory event no longer arrives at the second regulator as a fact about the same authorised person.

3. RegTech for real-time monitoring

The volume and velocity of regulatory change across global markets exceeds what any compliance team can track manually. Some firms deploy horizon-scanning tools that ingest regulatory feeds and flag what is relevant to their product footprint. Others go further, using AI-assisted research to interrogate the underlying material directly and identify the second-order implications that keyword-based alerting misses entirely.

Where Sherlocq changes the calculus

This is precisely the environment where Sherlocq becomes operationally decisive. Its document intelligence capabilities allow compliance teams to benchmark fund documentation and regulatory texts against the applicable rulebook, surfacing the clauses and obligations that matter without the manual review burden that slows multi-market distribution.

For teams managing regulatory submissions across global jurisdictions, querying a document with precision in seconds is not a productivity gain. It is a reduction in structural risk.

Future outlook

Three structural shifts will reshape the landscape before 2030. First, machine-readable regulation will become a competitive battleground. The Bank of England and FCA’s Digital Regulatory Reporting work, and the machine-readable reporting taxonomies being built out by ESMA and the EBA, point toward structured rule sets that can be queried programmatically. Firms that build the infrastructure now will have a material speed advantage at launch.

Second, Dubai and Singapore are consolidating as dominant hubs for alternative managers seeking regulated access to Asian and Middle Eastern capital. Both jurisdictions are moving from fast-moving, growth-oriented regimes toward sophisticated, principle-based frameworks with real enforcement teeth. Managers who treated these markets as light-touch will need to recalibrate. Those who built rigorous infrastructure early are already positioned to benefit from the barriers this creates.

Third, the intersection of AI governance regulation and investment management will become a major compliance theme, though the timetable has just moved, which is itself instructive. The EU’s Digital Omnibus on AI deferred the Act’s high-risk obligations by 16 months while leaving the transparency duties exactly where they were. Firms that read the headline as a blanket delay will find obligations already in force. Alongside it, the PRA’s model risk principles are setting a supervisory template that reaches well beyond the firms formally in scope.

TABLE 2: What is in motion, and what it changes

InstrumentStatus (19 Aug 2026)What it changes
FCA CP25/36: client categorisationConsultation closed 2 February 2026; policy statement pendingRemoves the COBS 3.5 quantitative opt-up test in favour of an enhanced qualitative assessment; adds a £10m investable-assets route. Firms would have one year from commencement to review every existing elective professional client, and many will need fresh consent.
EU Digital Omnibus on AI: Regulation (EU) 2026/1744Published 24 July 2026; in force 27 July 2026Defers Annex III high-risk obligations from 2 August 2026 to 2 December 2027, and Annex I to 2 August 2028. Article 50 transparency duties applied on schedule on 2 August 2026; marking obligations for systems already on the market fall due 2 December 2026.
UAE Capital Market AuthoritySucceeded the SCA on 1 January 2026Federal Decree-Laws 32 and 33 of 2025 extend jurisdiction to cross-border activity affecting UAE markets and raise enforcement ceilings. Implementing regulations defining private placement procedure and investor eligibility are still awaited.
EU Retail Investment StrategyFinal approval pendingPolitical agreement reached December 2025; Council endorsed the final text in June 2026, with Parliament confirmation and Official Journal publication expected in the second half of 2026. Would lower the elective professional portfolio test to €250,000 averaged over three years and broaden the experience criterion, moving in the opposite direction to the FCA’s wealth-only proposal.
PRA SS1/23: model risk managementIn force since 17 May 2024Five principles covering model identification, governance, validation and mitigants, with explicit treatment of AI and machine learning. Formally scoped to UK firms with internal model approval, not asset managers, but widely used as the reference standard.

Thresholds and dates stated as at 19 August 2026 and drawn from the relevant regulators’ published materials. Verify against the current rulebook before relying on any figure; several of the items above are expected to move within the next two quarters.

The firms that will lead in this environment have made one conceptual leap: from compliance as a cost to be minimised, to regulatory risk management as a core operational competency that informs strategy, shapes product design, and determines which firms can operate at scale in the markets that matter.

What this means in practice

1. Audit the refresh cycle, not the register. The question is not whether a regulatory risk register exists but how many days old its oldest entry is. Anything on a quarterly cycle is a lagging indicator.

2. Map client classification across every booking jurisdiction. Table 1 is the test. If the firm cannot show, for a named client, which category applies in each jurisdiction and on what evidence, the gate is not controlled.

3. Stress-test the group structure for enforcement contagion. Ask the counterfactual directly: if a supervisory action landed on one entity tomorrow, which other authorisations would come under review, and through what mechanism?

See Sherlocq in Action

Discover how asset management compliance teams use Sherlocq to interrogate fund documentation and regulatory texts across jurisdictions in seconds. Book a demo at sherlocq.com

Ready to bring intelligence
to your compliance work?

Join compliance professionals, lawyers, risk managers, and regulators already using Sherlocq.

Try Sherlocq Talk to our team