Chapter 1 · International Regulatory Environment

20 of 100 exam questions · models of regulation · extraterritorial reach · international bodies · IOSCO Principles
← Back to quiz
Why this chapter matters. 20 of 100 exam questions (20%). Foundational chapter — every other GFC chapter references the international bodies, regulatory models, and cross-border mechanics introduced here. Trap zones: rules-based vs principles-based (not black-and-white — most regimes are hybrid), MTF vs SI vs OTF (the venue-type trap), who does what (BCBS = banking, IOSCO = securities, IAIS = insurance, FSB = coordinator), IOSCO MMoU is for enforcement info-sharing, NOT rule-making, home vs host state responsibilities. Post-2019 to be aware of but not exam-critical yet: Russia sanctions overhaul, EU AMLA, UK OFSI strict liability.

1.1 Why regulate? — the objectives

The three canonical objectives syllabus 1.1

Financial regulators around the world share three broad objectives:

  1. Market confidence + integrity — investors and firms need to trust that markets are fair, orderly, and free from abuse
  2. Consumer / investor protection — especially retail clients who lack the sophistication or bargaining power of institutional counterparts
  3. Financial stability — the "systemic" objective added post-2008: prevent failures that could cascade through the whole system

The FSB, BCBS, IOSCO and IAIS all trace their mandates back to some combination of these three.

Common trap: "which is NOT an objective of financial regulation?" — distractors usually include "maximise firm profits" or "eliminate all risk". Regulation aims to manage risk, not eliminate it.

Why regulation exists (economic rationale) syllabus 1.1

Textbook market failures that regulation addresses:

  • Information asymmetry — sellers know more than buyers (mis-selling risk)
  • Externalities — one firm's failure hits others (systemic risk)
  • Moral hazard — firms take risks knowing someone else absorbs the downside
  • Principal-agent conflicts — advisers put their own interests ahead of clients'

Regulation is not always the best fix, but where markets self-correct too slowly or the harm is too severe, state intervention is justified.

1.2 Law vs regulation (and why it matters)

The distinction is bigger than you think syllabus 1.2

LAW = passed by the legislature (Parliament, Congress, etc.), enforceable through the courts, changes slowly (usually years).

REGULATION = made by regulatory bodies (FCA, SEC, MAS…) under authority DELEGATED by law. Enforceable through regulatory sanctions AND (sometimes) criminal courts. Changes much faster than primary law.

Example: UK Financial Services and Markets Act 2000 (LAW) gives the FCA (REGULATOR) power to write and enforce the FCA Handbook (REGULATION).

Trap: exam questions may describe a rule as "law" when it's actually a regulator's rule made under delegated authority. Read carefully.

1.3 Rules-based vs principles-based

Two philosophies of regulation syllabus 1.3

RULES-BASED — detailed, prescriptive requirements. Firms follow the specific rule. Example: "you must file X form within 30 days." Advantages: certainty, easy to check compliance. Disadvantages: rigid, encourages "letter not spirit" behaviour, can't cover every scenario.

PRINCIPLES-BASED — high-level principles that firms must apply using judgement. Example: "treat customers fairly." Advantages: flexible, harder to game, applies to novel situations. Disadvantages: subjective, harder to challenge in court, requires strong firm culture.

MOST REAL REGIMES ARE HYBRID. UK FCA uses 12 high-level Principles + a detailed Handbook of rules underneath. Post-financial-crisis (2008), the trend has moved toward MORE principles + toward stronger enforcement of "spirit of the rule".

Common trap: "the UK is purely principles-based" — FALSE. It combines both. Same for most major jurisdictions.

1.4 Self-regulation + Islamic finance

Self-regulation and SROs syllabus 1.4

Self-regulation = industry regulates itself (usually via a self-regulatory organisation, SRO). Common historically; largely superseded by statutory regulation after the industry couldn't police its own conflicts.

Remaining SROs include:

  • FINRA — US broker-dealer SRO (technically self-regulatory, actually delegated by SEC)
  • Exchanges — some retain SRO functions over their own listings and members
  • Professional bodies — CISI, CFA Institute, ICAEW etc. regulate their own members' conduct (parallel to state regulation)

Islamic finance syllabus 1.4

Financial products structured to comply with SHARIA law. Key prohibitions:

  • Riba — no interest / usury
  • Gharar — no excessive uncertainty (limits speculation, some derivatives)
  • Haram — no financing of prohibited activities (alcohol, gambling, pork, adult entertainment, conventional interest-based finance)

Compliance is verified by a firm's Sharia Supervisory Board. Standards issued by AAOIFI (accounting), IFSB (prudential). Growing market especially in the GCC (UAE, Saudi Arabia, Malaysia).

UAE candidates: Islamic finance is heavily tested in local regulator exams. Even in the international GFC, expect at least one question on the Sharia principles.

1.5 Extraterritorial reach — GDPR / FATCA / CRS / Basel

When one country's rules reach you in another syllabus 1.5

Extraterritorial reach = a rule from one jurisdiction applies to conduct in another. The four most commonly-tested examples:

RuleOriginReach
GDPREUAny firm processing EU residents' data, wherever the firm is based
FATCAUSAny foreign financial institution holding accounts for US persons; 30% withholding tax if non-compliant
CRSOECD (global)110+ jurisdictions report account holders' tax residency data to each other automatically
Basel IIIBIS / BCBSNot directly extraterritorial, but adopted by ~30 major jurisdictions → de-facto global bank capital standard
Trap: FATCA and CRS overlap but are DIFFERENT. FATCA = US-specific, withholding tax teeth. CRS = OECD, multilateral, no withholding. US does NOT participate in CRS.

US OFAC sanctions reach syllabus 1.5

The most powerful example of extraterritorial reach: US OFAC sanctions apply to any transaction that touches:

  • A US person (citizen, resident, US entity)
  • The US dollar (cleared through US correspondent banks)
  • US-origin goods or technology
  • US financial infrastructure

This is why global banks obsess about US sanctions even when they have no direct US presence — BNP Paribas paid $8.9bn in 2014 for sanctions breaches without a single transaction "in" the United States.

1.6 Venues — RM / MTF / SI / OTF

The four MiFID II venue types syllabus 1.6

MiFID II (2018) sets four categories of trading venue in Europe. Same broad structure adopted elsewhere. Learn the differences — the exam LOVES this one.

VenueWhatDiscretion?
RM (Regulated Market)Traditional exchange — e.g. LSE, NasdaqNo — rule-based matching
MTF (Multilateral Trading Facility)Exchange-like alternative venueNo — rule-based matching
SI (Systematic Internaliser)Investment firm trading against its OWN book, systematicallyYes — quotes prices but is the counterparty
OTF (Organised Trading Facility)Non-equity venue (bonds, derivatives, structured products)Yes — operator has discretion

KEY DIFFERENCES:

  • RM and MTF are multilateral (multiple buyers meet multiple sellers) and non-discretionary (rule-based).
  • SI is bilateral (the firm is always the counterparty) — a market-maker on its own account.
  • OTF is multilateral but discretionary — operator can choose how orders match. NOT for equities.
Memory hook: RM = old-school exchange · MTF = new-school exchange · SI = one firm's shop window · OTF = discretionary bonds/derivatives club.

1.7 International bodies — BIS · BCBS · IOSCO · FSB · IAIS

Who does what — the memorise-this table syllabus 2.2

BodyFull nameFocus
BISBank for International Settlements (Basel)"Central bank of central banks" — hosts BCBS, provides research and settlement services
BCBSBasel Committee on Banking SupervisionGlobal standards for BANK regulation — Basel I / II / III / III-finalisation
IOSCOInternational Organization of Securities CommissionsGlobal standards for SECURITIES regulation — IOSCO Principles, MMoU for enforcement
FSBFinancial Stability BoardPost-2008 body coordinating global regulatory response, monitoring systemic risk
IAISInternational Association of Insurance SupervisorsGlobal standards for INSURANCE regulation — Insurance Core Principles (ICPs)
Common trap: which body sets banking standards? BCBS (NOT the BIS itself, though the BIS hosts BCBS). Which sets insurance standards? IAIS (NOT IOSCO — IOSCO is securities only).

The 38 IOSCO Principles syllabus 2.3

IOSCO's core standards for securities regulation. 38 principles across 10 categories including regulator objectives, self-regulation, enforcement, issuers, auditors, CIS, market intermediaries, secondary markets, systemic risk, market abuse, and (added post-2008) OTC derivatives.

Countries are assessed on their implementation of these principles as part of the IMF-World Bank Financial Sector Assessment Program (FSAP). Weak implementation = reputational damage + market-access consequences.

1.8 Enforcement + cross-border (MMoU, colleges)

The IOSCO MMoU syllabus 2.5

Multilateral Memorandum of Understanding — signed by 130+ securities regulators globally. Enables:

  • Cross-border sharing of INVESTIGATION information (bank records, trading data, beneficial ownership)
  • Cooperation on enforcement actions
  • Compelled assistance regardless of local secrecy laws

NOT a rule-making body. NOT a treaty. Just an enforcement information-sharing framework — but a powerful one, particularly for cross-border market abuse and insider dealing cases.

Trap: MMoU is often confused with FATF (money laundering standards) or the Basel Concordat (banking supervision cooperation). MMoU = securities enforcement info-sharing specifically.

Home vs host + supervisory colleges syllabus 2.8

Home state = country where the firm is HEADQUARTERED / authorised (has the primary licence).

Host state = country where the firm operates a branch or subsidiary.

General rule for cross-border banking (Basel Concordat, refined post-BCCI collapse 1991):

  • Prudential supervision (capital, solvency) → primary home state responsibility
  • Conduct of business (customer treatment, local rules) → primary host state responsibility

For large cross-border banks, home + host regulators coordinate via a supervisory college — regular meetings to share information, plan resolution, and align supervisory approach. Global systemically-important banks (G-SIBs) all have colleges.

Regulated activities and firm requirements syllabus 2.6-2.7

Financial services activities generally require prior AUTHORISATION from the local regulator. Common regulated activity categories:

  • Deposit-taking (banking)
  • Dealing in investments (broker-dealer)
  • Advising on investments
  • Managing investments
  • Insurance underwriting / distribution
  • Home finance (mortgage lending / broking)

Firm requirements to obtain and maintain authorisation:

  1. Adequate CAPITAL (prudential threshold — Basel for banks, Solvency II for insurers)
  2. Adequate SYSTEMS + CONTROLS
  3. FIT AND PROPER senior management
  4. Conduct-of-business rules (client treatment, complaints, disclosure)
  5. Compliance function (see [[Ch 2 — The Compliance Function]])
  6. Ongoing REPORTING to the regulator

1.9 All the numbers (cheat sheet)

Ch 1 quick-reference — the exam-day list

ItemAnswer
3 objectives of regulationMarket confidence · Consumer protection · Financial stability
Sharia prohibitionsRiba (interest) · Gharar (uncertainty) · Haram (prohibited activities)
FATCA reachUS persons' accounts anywhere; 30% withholding on non-compliant FFIs
CRS jurisdictions110+ · US does NOT participate (uses FATCA instead)
OFAC reach triggersUS person · USD (correspondent clearing) · US-origin goods · US infrastructure
MiFID II venuesRM · MTF · SI · OTF
SI vs MTFSI = bilateral (own book) · MTF = multilateral (rule-based matching)
OTF asset scopeNon-equity ONLY (bonds, derivatives, structured products)
Basel bodyBCBS · hosted by BIS · sets Basel I/II/III
Insurance bodyIAIS · Insurance Core Principles
Securities bodyIOSCO · 38 Principles · MMoU for enforcement
FSB rolePost-2008 coordinator · systemic risk monitoring
IOSCO Principles count38
MMoU purposeCross-border enforcement info-sharing (NOT rule-making)
MMoU signatories130+ securities regulators
Home statePrudential (capital, solvency)
Host stateConduct of business (local customer treatment)
Supervisory collegeCoordinated home+host oversight of cross-border banks
Basel Concordat triggerBCCI collapse 1991
Firm authorisation pillarsCapital · Systems & controls · Fit & proper · Conduct rules · Compliance · Reporting
Print this table (or the full cram sheet) the day before the exam. Everything above is directly tested.