THE RISK

Everything here is already the law. The only forecast is the direction.

Sections 01–07 are published rules and recorded enforcement outcomes, each with its primary source attached, not our opinion. Section 07 then closes with our own reading of those figures, and says so plainly. The authorities throughout are doing precisely what their mandates require of them.

Which leaves one question, and it is not rhetorical. A bank, a counterparty or an authority asks a company to account for how a raise was run. What could the company actually show, and who would have to go and find it?

THE DOOR

Getting the perimeter wrong is criminal law, not paperwork.

Whether an activity needed a licence, whether an offer was public, whether a statement was misleading: these are answered by criminal statutes, not by internal policy. And the answer does not wait for anyone to lose money.

Sources and the detail (§)
  • In Germany, offering financial services without a licence is a crime, punishable by up to five years' imprisonment (§ 54 KWG). The same provision covers unlicensed crowdfunding services under the EU regime.
  • Misleading statements in investment marketing are criminal even if no investor loses a cent, and carry up to three years (§ 264a StGB).
  • A public share offering without the required prospectus exposes a company to fines of up to €5 million or 3% of turnover, which are statutory maxima (§ 24 WpPG). And BaFin names suspects publicly while investigating: in December 2025 it publicly named a company on suspicion alone.

The defensible position is not the belief that the company stayed inside the perimeter. It is a contemporaneous record of how it stayed inside it: who was invited, what they were sent, what they opened, and on what date. Exedra Gate produces that record while the work is happening (whether that work is a raise or the compliance file behind it), because a contemporaneous record cannot be created after the fact.

Where does the evidence of a company's last offer live today, and could it show who received it without asking a single person to remember?

See how a raise runs on one rail
THE MAP

This is not a German rule, or a European one.

The public offering of securities is regulated through a named competent authority in 63 countries. Counted as authorities rather than as countries there are more than 120 of them, and the difference is North America: the United States adds a securities administrator in each of the fifty states alongside the federal regulator, and Canada is commonly described as having no federal securities regulator at all, only thirteen provincial and territorial ones.

The perimeter, counted twice

Counted as countries, 63 have a named competent authority for a public offer of securities. Thirty of them are the states of the European Economic Area, which apply one prospectus regulation between them: Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain and Sweden. The United Kingdom and Switzerland sit beside them, the United States and Canada are two more, and the count runs on through the Gulf, Asia and other markets. Counted as authorities the number is larger, and the difference is North America. The United States is one country in that count, and inside it sit the federal Securities and Exchange Commission and a securities administrator in each of the fifty states. Canada is one country, and is commonly described as having no federal securities regulator at all, only thirteen provincial and territorial ones. Counted that way there are more than 120 authorities. The two counts measure different things and are never added together.

Counts exactly as stated above. The European Economic Area authorities are the ones designated in ESMA's register of competent authorities under Article 31(1); the North American split follows NASAA's description of its own membership, quoted in full in the sources below. The thirty are named because they are states and because that register names them; the rest are drawn and not labelled, because the research behind them is not uniformly confident and four of the counted regimes sit inside a country the count has already reached. Neither count says anything about how any of these authorities enforces.
Sources and the detail (§)
  • Thirty of the 63 are the states of the European Economic Area, where the authority competent for a public offer is designated and published: Germany's Bundesanstalt für Finanzdienstleistungsaufsicht, France's Autorité des marchés financiers, Italy's Commissione Nazionale per le Società e la Borsa, Spain's Comisión Nacional del Mercado de Valores and twenty-six more (ESMA, register of competent authorities under Article 31(1)). The United Kingdom's Financial Conduct Authority and Switzerland's Eidgenössische Finanzmarktaufsicht sit beside them, and the count runs on through the Gulf, Asia, North America and beyond.
  • North America is where a count of countries and a count of authorities separate. The North American Securities Administrators Association describes its own membership as "67 state, provincial, and territorial securities administrators in the 50 states, the District of Columbia, Puerto Rico, the U.S. Virgin Islands, Canada, and Mexico" (NASAA). NASAA is a voluntary association rather than a regulator and its members sit in three countries, so 67 is a count of administrators and not of jurisdictions. The two counts are therefore not added together, and the total is given as more than 120 rather than as a sum.
  • A published name does not wait for a finding of wrongdoing, and that is the stated rule rather than an inference. The mechanic was examined in thirteen of these authorities and is not asserted for the rest. Where an authority states its own test, the test is suspicion: BaFin may inform the public, naming the company, of the suspicion itself, where facts justify the assumption of unauthorised business (§ 37(4) KWG), a provision that in the same breath requires the company to be heard first and requires BaFin to correct the record publicly if what it published proves wrong.
  • FINMA lists companies precisely because its own findings "were inconclusive", the information it required having been refused or supplied falsely, and says plainly that being on the list "does not automatically mean that its activities are unlawful" (FINMA warning list). The FCA publishes warnings naming entities that "appear to us" to be carrying on a regulated activity without authorisation, and told Parliament this lets it act "in circumstances where our prospects for taking successful enforcement action may be limited" (FCA letter to the Minister for Pensions, 5 October 2020). The SEC states that inclusion on its public alert lists "does not mean that the SEC has concluded that a violation of the US securities laws has occurred" (SEC public alerts).
  • Spanish law goes furthest of the thirteen: the CNMV may publish the opening of a sanctions procedure once the parties have been notified, with personal data removed except as regards the names of the alleged infringers, on a reasoned weighing of the public interest against the harm publication causes them (Ley 6/2023, art. 336).
  • The thirteen, in full: the Bundesanstalt für Finanzdienstleistungsaufsicht (Germany), the Eidgenössische Finanzmarktaufsicht (Switzerland), the Financial Conduct Authority (United Kingdom), the Autorité des marchés financiers (France), the Commissione Nazionale per le Società e la Borsa (Italy), the Autoriteit Financiële Markten (Netherlands), the Comisión Nacional del Mercado de Valores (Spain), the Monetary Authority of Singapore, the Securities and Futures Commission (Hong Kong), the Capital Market Authority (United Arab Emirates, which replaced the Securities and Commodities Authority on 1 January 2026), the Dubai Financial Services Authority (Dubai International Financial Centre), the Financial Services Regulatory Authority (Abu Dhabi Global Market), and the United States Securities and Exchange Commission.

Two counts, measuring two different things. Sixty-three is the number of countries. More than 120 is the number of authorities, and the gap between them is North America. Neither number says anything about how any of those authorities enforces, and a figure published by one of them is not comparable with a figure published by another.

A named party is not a guilty party, and is sometimes not even the suspect.
Some of these lists carry a category in which the named party is the victim. One of the three categories on the SEC's public alert list is impersonators of genuine firms, where the name that appears belongs to a legitimate firm whose identity was misappropriated; alerts published by the Dubai Financial Services Authority and parts of the Hong Kong Alert List work the same way. Appearing on a regulator's alert list is therefore not, by itself, an adverse signal about the party named, and nothing on this page should be read as saying otherwise. The regimes examined also carry protections: a right to be heard before publication in Germany, consultation before a warning notice is published in the United Kingdom, proportionality and anonymisation tests throughout, and in the Netherlands an injunction request that suspends publication until a judge has ruled.

None of this is Exedra Gate's to move. Nothing in a private system changes which authority is competent, what it publishes, or when. What sits inside a company's control is narrower: whether the record of what it actually did exists in one governed place, or in five tools and an inbox spread across the countries it raised in.

If a raise reached investors in four countries, who decided which four sets of rules applied, and where is that decision written down today?

See what the record contains
THE REGISTER

The punishment that never leaves the internet.

Publication is not a side effect of enforcement. In these markets it is a substantial part of the sanction itself, and it is mandated, not discretionary.

Sources and the detail (§)
  • BaFin is required by law to publish enforcement measures on its website, by name, for at least five years. Anonymity is the exception, not the rule (§ 60b KWG).
  • Switzerland's highest court upheld exactly this in September 2025: five years of named publication for the operators of an unauthorised issuing house, and it held that relying on a favourable legal opinion was no excuse (TF 2C_596/2024).
  • In the UK in February 2026, seven social-media influencers were criminally sentenced for promoting an unauthorised scheme. The fines were small: hundreds of pounds. The criminal record, and the named press release, are what remain.
  • The five years is not one rule. Germany's banking act sets a floor: publications remain up for at least five years (§ 60b(5) KWG, above), and that floor originates in Article 71(3) of MiFID II. German securities and fund law sets the opposite, a deletion duty: publications are to be deleted five years after they appear (§ 123(5) and § 124(4) WpHG, and § 341a KAGB for funds).
  • Warning lists run on a different track from the enforcement publication above, and their retention is mostly unstated. Of eleven authorities examined on the point, nine publish no removal process at all. FINMA is the exception that states one: an entry comes down "once FINMA has completed its investigations and taken any appropriate measures" (FINMA warning list). An unpublished removal process is a different finding from a stated policy of permanence, and only the first of the two is established.

Enforcement is rarely fast. It is eventual, and it is permanent. A name, once published, is findable by every future counterparty, bank, and search engine.

Nothing in a private system changes what an authority publishes, and Exedra Gate will not suggest otherwise. What sits inside a company's control is the quality of the account it can give to a bank, a board, an auditor or a counterparty, and whether that account exists as a record or only as a recollection.

If a counterparty searched a company tomorrow and asked to be walked through the raise behind it, how long would that answer take to assemble?

What happens when it cannot be shown
THE FREEZE

The money stops before the questions finish.

Precautionary measures are built to precede conclusions. That is their function. They land while everything is still open, and they land on the operating accounts a company runs on.

Sources and the detail (§)
  • Germany's Financial Intelligence Unit blocked roughly €752 million in immediate measures in 2025, up from €18.8 million the year before. The largest single freeze: €585 million (FIU annual report).
  • UK courts issued 2,182 account-freezing orders (£221.6 million) in the year to March 2025 (Home Office statistics).
  • BaFin's President, describing one 2026 operation: "several hundred accounts" examined and frozen in a single day (annual press conference, May 2026).

What follows a measure like that is documentary: show the counterparty, the authorisation, the disclosure, the consent, the date. Companies that hold those artifacts in one governed place answer from a record. Companies that hold them across five tools and an inbox answer from memory, and from whoever still happens to work there.

Who in a company could produce the complete file for a single investor this week? And what happens to that answer when that person is on leave?

See what the rail records
THE PERSON

It attaches to the person, not only to the company.

A corporate structure does not absorb all of this. A material part of the exposure is personal, it is held by named individuals, and it does not stay behind when they leave.

Sources and the detail (§)
  • BaFin can demand the removal of managing directors and prohibit them from the role (§ 36 KWG).
  • FINMA bans individuals from senior functions across the whole industry, for up to five years (Art. 33 FINMASA).
  • In the UK, a chief executive was personally fined £1.1 million and prohibited from senior functions (Final Notice, 2025).
  • Switzerland's data-protection offences target individuals (up to CHF 250,000) (revised FADP).
◲ Visual · coming soon What one person approved risk-person-approvals

Personal exposure is answered with personal evidence: the approvals an individual gave, the documents they authorised, the terms they signed, each carrying a date that can be checked without their help. That record decides nothing and excuses nothing. It simply means the account of what a person did exists outside that person's memory, and outside their employment.

When an officer leaves a company tomorrow, does the record of what that person personally approved leave with them?

How the record is made
THE CLOCK

The question can arrive a decade later.

Retention duties and limitation periods are measured in years. Corporate memory is measured in staff turnover. The distance between those two is where reconstruction happens: slowly, and in front of exactly the people a company would rather appear composed to.

Sources and the detail (§)
  • German AML law requires keeping the record (including the reasoning behind decisions NOT to report) for five years, and up to ten (§ 8 GwG).
  • For civil claims, the limitation clock starts when the investor learns of the problem, and the long-stop is ten years (§ 199 BGB). A raise can be questioned long after everyone who ran it has moved on.

This is the asymmetry the whole page turns on, and it is worth stating without decoration. Enforcement is eventual, and permanent. Memory is neither. A record is, provided it was made at the time and independently timestamped so that its age can be demonstrated rather than asserted.

A 2021 raise: who ran it, and are they still there to explain it?

See how a raise closes
THE DIRECTION

Every number here is rising. The next rulebook already has dates.

Five cited lines, read together. Our reading of them follows the list, and is marked as ours.

Sources and the detail (§)
  • BaFin's intervention measures nearly doubled in one year (72 → 140), and suspicion-warnings rose 505 → 639 (BaFin annual report 2025).
  • FINMA concluded 55 enforcement proceedings in 2025, up from 38, alongside 463 investigations into suspected unlicensed activity (FINMA annual report).
  • The EU's new anti-money-laundering authority, AMLA, is established in Frankfurt. It selects the 40 entities it will supervise directly during 2027 and begins that direct supervision in 2028, while the harmonised AML rulebook applies to every member state from July 2027 (AMLA).
  • Switzerland's financial regulator is publicly asking for more individual-accountability powers than it has today (as reported, 2026).
  • The movement is not uniformly heavier. On 5 June 2026 the European Union's Listing Act raised the threshold below which a public offer needs no prospectus at all to EUR 12,000,000 over twelve months, with a member-state option to set it at EUR 5,000,000 (Regulation (EU) 2024/2809, Arts. 1(3) and 4(3)).

That is the published record. What follows is our reading of it, and it is ours: an interpretation, not a citation. Supervisory capacity is being added, not withdrawn. A new authority has been constituted, with a mandate and a calendar, and a harmonised rulebook takes effect across every member state on a fixed date. And the one regulator on this list that is publicly asking for anything is asking for broader individual-accountability powers (FINMA, as reported above). That is not the same as every requirement getting heavier, and the Listing Act above is the counter-example: the document required at the gate got lighter, while what has to be provable afterwards did not. We read that as supervision being reallocated rather than simply increased. Read together, we think that trajectory runs one way: a heavier burden of proof, more reporting, more checks, and more sensitive personal data held about more people, tightened a little further each year, on published timetables, by institutions behaving exactly as they were designed to behave. It is what a market does once it decides that private capital deserves the scrutiny public capital has always had. We do not expect it to reverse, and we would not build a company on the hope that it might.

On that reading, the problem reduces to a single variable. A company does not choose the rules, the timing, or the questions. It chooses only whether the answer already exists on the day someone asks for it. Preparing for a trajectory like that is not pessimism. It is the response we think the record supports, and it is precisely why Exedra Gate exists.

If the questions asked in 2028 are more searching than the ones asked in 2021, and a 2021 raise can still be questioned, how many companies would be comfortable opening theirs today?

See what being prepared actually looks like
THOSE WHO HAVE BEEN THROUGH IT

They know how this goes

The requests for documents nobody can find. The thread that lived in a departed colleague's inbox. The months of reconstruction, in front of the counterparties a company most wants composed. Nobody who has lived it needs this page to name the cost. They need the next engagement to run differently.

THOSE WHO HAVE NOT

Neither had they

The names on the enforcement registers are mostly not villains. They are ordinary companies that believed this happens to other people, and ran their work across five tools and an inbox until the day a question arrived that memory could not answer.

What preparedness means, and what it does not.
Exedra Gate does not shield anyone from any authority, does not make a single obligation go away, and does not decide whether anything a client does is compliant. We are not the judge of anyone's file, and we do not claim to understand a regulator's case better than the regulator does. What we provide is narrower and more useful: a private, governed place to do the work, and evidence of what was actually done inside it: who was invited, what was shared, what was accessed, what was signed, what was consented to, and when. Not what anyone said; what was done, and on what date. It closes in a record that can be checked independently, years later, with free standard tools. And it does not require a raise: a company can run its compliance work here and never open an offering at all.
THE ONLY VARIABLE

The rules above are not the company's to move. This part is.

The statutes, the timetables, the publication periods, the years a question can travel: all fixed, and none of them by the companies they reach. Whether the answer exists when someone asks for it is the one thing a company decides, and it can only be decided in advance.

◲ Visual · coming soon The answer, already assembled risk-evidence-pack

So: what would a company show, and how long would it take to find?

This page describes published rules and enforcement practice, with sources, as at the dates given. It is general information, not legal advice, and not a description of any specific obligation applying to any particular reader. Exedra Gate is not a law firm and never holds or moves investor funds.