On 7 April 2025, the Hong Kong Monetary Authority (HKMA) and the Securities and Futures Commission (SFC) issued guidance for authorized institutions (and subsidiaries of locally incorporated authorized institutions) and SFC-licensed virtual asset trading platforms respectively, who are interested in providing Staking Services. The guidance outlines the regulatory framework and expected standards for providing Staking Services.
On the same day, the SFC revised its “Circular on SFC-authorized funds with exposure to virtual assets” issued on 22 December 2023 to facilitate SFC-authorized virtual asset funds (SFC-authorized VA Funds) which wish to engage in staking and other virtual asset-related activities.
Over the past week there have been two significant announcements by US Financial Crimes Enforcement Network and the US Department of the Treasury with respect to the filing of beneficial ownership information (BOI) reports under the Corporate Transparency Act (CTA). Based on these announcements, foreign reporting companies should technically continue complying with the BOI requirements, though there will be no consequences for failing to do so until new regulations are issued. As to domestic reporting companies, there should not be any enforcement of the CTA against such companies or consequences if such companies fail to file BOI reports.
On 19 February 2025, the Securities and Futures Commission (SFC) issued a regulatory roadmap for Hong Kong’s virtual asset market. Entitled “‘A-S-P-I-Re’ Roadmap for a Resilient Virtual Asset Ecosystem”, it sets out a five-pillar framework (Access, Safeguards, Products, Infrastructure, and Relationships) that is intended to serve as a strategic action plan for addressing emerging new priorities in the virtual asset space (e.g., managing liquidity fragmentation and ensuring investor protection across decentralized and centralized platforms) and, in the SFC’s words, “future-proof[ing] Hong Kong’s VA ecosystem”.
ASIC has released a draft regulatory guide alongside a consultation paper intended to help providers of Buy Now Pay Later services understand the modified responsible lending obligations and requirements.
On 10 March 2025, the Health Sciences Authority launched its public consultation for the draft on the Best Practices Guide for Medical Device Cybersecurity. The document provides medical device manufacturers and healthcare providers with best practice recommendations and considerations on general cybersecurity principles to protect the security of medical devices for their entire product life cycle.
On 7 March 2025, the Ministry of Health announced a host of changes to the healthcare system to address the shifting needs of the Singapore population. These changes included a review of advertising regulations for certain healthcare professionals, the recognition of family medicine as a medical specialty and the introduction of registration requirements for psychologists.
On 18 February 2025, ASIC commenced consultation on proposals to:
1. provide additional relief for Australian financial services and credit licensees from reporting certain breaches of the misleading and deceptive conduct (MDC) provisions and certain contraventions of civil penalty provisions (CPPs); and
2. consolidate this additional relief and the relief in ASIC Corporations and Credit (Breach Reporting — Reportable Situations) Instrument 2024/620 (ASIC Instrument 2024/620) into a single instrument.
The proposals, as further described in CS 16, aim to reduce the reporting burden on Australian financial services and credit licensees. ASIC’s rationale for the changes is, under the current reportable situations regime, some reports of MDC and CPP breaches have been of minimal intelligence value to ASIC.
The European Supervisory Authorities are preparing to designate critical third-party service providers under the Digital Operational Resilience Act (DORA). DORA, which came into force on 17 January 2025, enables the ESAs to designate key ICT providers to the EU financial services sector as critical, subjecting them to direct supervisory and oversight obligations. The ESAs have recently published a roadmap indicating their expected timeline for designations – with the final designations expected to be in place by the end of this year.
On 18 July 2024, the UK Financial Conduct Authority (FCA) published the findings of its multi-firm review on firms’ treatment of politically exposed persons (PEPs). This review is likely to be of interest to family offices and their advisers for the following reasons:
• UBOs of family offices are often treated as being within the scope of the PEP categorization.
• An overly restrictive approach to KYC and AML controls on the part of financial institutions can create friction and delays for family offices and their UBOs, and the FCA’s findings may provide some basis to push back on or query the approach on this point (see below).
• Given the FCA’s strong public stance on the PEP issue, we may see other global regulators following the UK’s lead in the future.
Regulation (EU) 2022/2554, commonly known as the Digital Operational Resilience Act (DORA), represents a significant step forward in enhancing the digital resilience of the financial sector within the European Union. Adopted by the European Parliament and the Council on 14 December 2022, DORA aims to establish a comprehensive framework to ensure that financial entities can withstand, respond to, and recover from all types of ICT-related disruptions and threats. The regulation entered into force on 17 January 2025, and applies directly across all EU member states.