For years, U.S. Section 232 supply chain risk was largely viewed through the lens of trade compliance. That assumption is becoming harder to defend. As global supply chains become more layered and sourcing models become increasingly difficult to trace, what began as a national security measure on imported steel and aluminium is now creating wider operational pressure across procurement, supplier governance, and third party risk. For many organisations, the challenge is no longer simply tariff classification. It is whether they can confidently evidence what sits inside the products they buy, where those materials originated, and whether supplier declarations can withstand regulatory scrutiny when trade policies tighten. That is where Section 232 becomes far more relevant to supplier oversight. What Is Section 232? Section 232 is a trade provision under the Trade Expansion Act of 1962, which gives the U.S. President authority to restrict imports if they are considered a threat to national security. In March 2018, the United States introduced: 25 percent tariffs on imported steel 10 percent tariffs on imported aluminium The original objective was clear. Protect domestic industrial capacity and reduce strategic dependence on foreign materials. Since then, Section 232 has evolved through country specific quota arrangements, exemptions,...
Read moreDetailsThe new EU beneficial ownership regulation marks one of the most significant shifts in European anti money laundering oversight in more than a decade. After years of inconsistent national enforcement, fragmented registry standards, and varying interpretations of ownership control, the European Union is moving toward a single enforceable framework that will reshape how organisations verify beneficial ownership across member states. For banks, payment institutions, regulated corporates, procurement teams, and third party risk leaders, this is more than another compliance update. It signals a structural change in how ownership transparency, cross border due diligence, and third party accountability will be assessed under the European Union’s new AML framework. At the centre of this reform sits the EU AML Package, made up of three interconnected components: The Anti Money Laundering Regulation, or AMLR The Sixth Anti Money Laundering Directive, or 6AMLD The creation of the new Anti Money Laundering Authority, known as AMLA Together, these reforms aim to replace fragmented national supervision with a more harmonised model across all EU member states. That sounds straightforward. Operationally, it is anything but. Many organisations still rely on jurisdiction-by-jurisdiction onboarding processes, local company registries, and ownership definitions that vary significantly between countries. What may satisfy...
Read moreDetailsWhen the United States passed the Corporate Transparency Act in 2021, it was positioned as one of the most significant anti-money laundering reforms in decades. The objective was clear. For years, shell companies and opaque ownership structures had created blind spots across financial crime investigations, sanctions enforcement, procurement due diligence, and cross-border onboarding. The new law aimed to change that by requiring millions of private companies to disclose their beneficial ownership information, or BOI, to the U.S. Treasury’s Financial Crimes Enforcement Network, better known as FinCEN. For banks, fintechs, payment providers, and third party risk teams, the legislation promised something operationally valuable. A central ownership reporting framework could reduce reliance on fragmented registries, inconsistent customer declarations, and manual investigative work. That promise has now become far less certain. In March 2025, FinCEN issued an interim final rule that significantly narrowed the original scope of the Corporate Transparency Act. Under the new rule, U.S. domestic companies and U.S. persons are no longer required to submit beneficial ownership reports. Only certain foreign entities registered to do business in the United States remain within scope. For many compliance leaders, the immediate question is not what changed. It is why one of the most...
Read moreDetailsWhen Canada’s financial intelligence regulator, FINTRAC, announced a C$693,742.50 administrative monetary penalty against 13010431 Canada Inc., operating as Necosmart, it would have been easy to file it under another anti-money laundering enforcement story. Necosmart, an Edmonton-based money services business registered to deal in virtual currency and peer-to-peer transactions, was cited for five separate compliance violations following a FINTRAC examination. According to the regulator, the firm failed to submit suspicious transaction reports where reasonable grounds existed, did not adequately apply enhanced measures for higher risk business relationships, maintained incomplete compliance procedures, and failed to keep sufficient records relating to its virtual currency activity. On the surface, it looks like a familiar AML failure. Look more closely, and the case reveals something more relevant for modern third-party risk programmes. FINTRAC noted that Necosmart had already identified indicators that should have triggered deeper analysis. The issue was not necessarily the absence of warning signs. The issue was what happened after those signals appeared. Risk indicators were present, but the organisation failed to connect them, escalate them, and act on them in a way regulators now expect. This is where AML third party risk begins to move beyond compliance documentation and into operational accountability....
Read moreDetailsHong Kong AML third-party risk expectations are exposing ownership blind spots across supplier onboarding and cross-border due diligence. For years, many organisations operating in Asia have treated Hong Kong registry checks as sufficient evidence of supplier legitimacy. A registered entity. An active company status. Named directors. For operational teams, that often feels enough. But regulatory expectations are beginning to move beyond legal existence. They are moving towards control, influence, and ownership accountability. That creates a structural challenge for organisations relying on distributors, intermediaries, holding entities, and service providers across Greater China and wider Asia. Registry data may confirm that a company exists. It does not always explain who ultimately controls it, whether influence sits behind nominee structures, or whether ownership has shifted since onboarding. This is where many third-party programmes begin to struggle. What appears low-risk from a registration perspective may still carry ownership exposure that sits outside traditional vendor workflows. The operational tension is visibility. Procurement wants commercial continuity. Business teams want regional expansion. Compliance teams are increasingly expected to explain not only who was onboarded, but who actually controlled the relationship over time. That gap becomes harder to defend when ownership structures evolve quietly through intermediaries or offshore...
Read moreDetails© 2026 TPRM INSIGHTS
To provide the best experiences, we and our partners use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us and our partners to process personal data such as browsing behavior or unique IDs on this site and show (non-) personalized ads. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Click below to consent to the above or make granular choices. Your choices will be applied to this site only. You can change your settings at any time, including withdrawing your consent, by using the toggles on the Cookie Policy, or by clicking on the manage consent button at the bottom of the screen.
© 2026 TPRM INSIGHTS