GDPR applies in the Isle of Man — but through the Island’s own Applied GDPR and Data Protection Act 2018, not the EU or UK regime. Here’s what…
A Customer Risk Assessment is a Code §6 duty for every customer, undertaken before you onboard them — and kept alive. Here is what a defensible CRA looks…
There is no AI-specific FSA rulebook in the Isle of Man — AI sits inside the obligations you already have. Here is what the board is accountable for,…
The Technology Risk Assessment is a statutory AML/CFT requirement under Code §7 — and it is not the same as a cyber-security review. Here is what a TRA…
Not every Isle of Man firm must appoint a Data Protection Officer — but where it’s required, the Applied GDPR sets strict rules on independence and conflict. Here’s…
The April 2026 AML/CFT Handbook is the FSA’s current guidance — and the Code still has primacy. Here are the areas to pressure-test your AML/CFT/CPF framework against now.
