Financial Risk

ECCTA Information Sharing: How Firms Can Collaborate Without Losing Control of Data Risk

The Economic Crime and Corporate Transparency Act creates a stronger legal basis for information sharing between regulated firms in certain circumstances. ICA’s July 2026 coverage highlights the operational question: how can firms use the new powers without creating uncontrolled confidentiality, privacy

By Jonas Adam Mohamed Osman AbdelghafourPublished 27 August 2026Last reviewed 27 August 2026

The opportunity

The Economic Crime and Corporate Transparency Act creates a stronger legal basis for information sharing between regulated firms in certain circumstances. ICA’s July 2026 coverage highlights the operational question: how can firms use the new powers without creating uncontrolled confidentiality, privacy or tipping-off risk?

Purpose limitation

Information sharing should begin with a defined financial crime purpose. Firms should document why information is required, what legal basis applies, which entities are involved and whether the information requested is proportionate.

Governance

Requests should flow through controlled channels with clear approval authorities. Sensitive customer data should not be exchanged through informal messaging or personal email. Record keeping is critical because firms may later need to explain why information was shared.

Data minimisation

More information is not automatically better. Sharing unnecessary data increases privacy and operational risk. Firms should identify the minimum information required to address the financial crime concern.

Tipping-off and investigation sensitivity

Information-sharing processes need controls to prevent disclosures that could prejudice investigations or alert subjects improperly. Legal and compliance teams should agree escalation rules for complex cases.

Conclusion

ECCTA creates an opportunity to reduce the information asymmetry exploited by criminals. Its value will depend on disciplined implementation. Effective collaboration requires a framework that is legally grounded, proportionate, auditable and operationally secure.

Practical actions for compliance leaders

  • Assign clear ownership and document decision rights.
  • Test control effectiveness using actual case outcomes rather than policy completion alone.
  • Escalate ambiguous or high-consequence cases to appropriately skilled reviewers.
  • Track exceptions, overrides, quality assurance findings and recurring root causes.
  • Ensure board and senior management reporting focuses on risk and control effectiveness, not only volumes.
  • Maintain evidence showing how the firm reached material compliance decisions.

Related reading

See AML & Financial Crime, Regulatory Compliance and Governance, Risk and Compliance.

About the author

Jonas Adam Mohamed Osman Abdelghafour writes about governance, risk and compliance, anti-money laundering, financial crime prevention, sanctions, customer due diligence, AI governance, model risk and regulatory risk. His work focuses on practical control design, risk-based decision-making and the interaction between regulation, technology and financial services. See About and Qualifications.

Source and editorial context

This article is original analysis informed by a current compliance theme highlighted by the International Compliance Association. The ICA is cited as an editorial/current-issue source; no affiliation with or endorsement by the ICA is claimed or implied.

Frequently asked questions

What should risk leaders know about the opportunity?

The Economic Crime and Corporate Transparency Act creates a stronger legal basis for information sharing between regulated firms in certain circumstances. ICA’s July 2026 coverage highlights the operational question: how can firms use the new powers without creating uncontrolled confidentiality, privacy or tipping-off risk?

What should risk leaders know about purpose limitation?

Information sharing should begin with a defined financial crime purpose. Firms should document why information is required, what legal basis applies, which entities are involved and whether the information requested is proportionate.

What should risk leaders know about governance?

Requests should flow through controlled channels with clear approval authorities. Sensitive customer data should not be exchanged through informal messaging or personal email. Record keeping is critical because firms may later need to explain why information was shared.

What should risk leaders know about data minimisation?

More information is not automatically better. Sharing unnecessary data increases privacy and operational risk. Firms should identify the minimum information required to address the financial crime concern.

What should risk leaders know about tipping-off and investigation sensitivity?

Information-sharing processes need controls to prevent disclosures that could prejudice investigations or alert subjects improperly. Legal and compliance teams should agree escalation rules for complex cases.