BDO Worldwatch 2026: White-Collar Crime Trends Accounting Firms and CFOs Must Act On
BDO has published its midyear Worldwatch: Investigations and White-Collar Crime report, drawing on perspectives from leading investigations and compliance professionals across the US, Mexico, Singapore, Japan, the UK, Switzerland, and South Africa. The headline message is direct: white-collar crime no longer respects borders, business functions, or traditional methods, and for firms operating with digital asset exposure, the enforcement environment has rarely been more demanding. This report is not a distant macro survey. For accounting firms and CFOs using crypto accounting software to manage client or company digital asset portfolios, the trends it identifies translate into concrete compliance gaps that need to be closed now.
The Converging Risk Landscape in 2026
The report's opening framing is deliberate. BDO's panelists describe a risk environment shaped by the simultaneous pressure of geopolitical conflict, trade disruption, inflationary stress, expanding sanctions regimes, and rapid technological change. None of these forces is new in isolation. What makes 2026 different, according to the professionals consulted, is that they are converging, and that convergence is creating compliance blind spots that traditional frameworks were not designed to catch.
Technology as both threat and tool
AI-enabled fraud sits near the top of the risk register across all seven jurisdictions covered. The specific concern is not hypothetical: deepfake technology is being deployed to impersonate executives, manipulate internal approval chains, and fabricate documentation in ways that bypass conventional controls. Cyber-enabled misconduct more broadly, including intrusions that facilitate false invoicing or internal theft, is accelerating in sophistication. For firms advising clients on digital assets, this intersects directly with the operational risk layer of any crypto bookkeeping software deployment, because the integrity of transaction records depends on the integrity of the systems feeding them.
Cryptocurrency as a vector, not just an asset class
BDO's panelists treat cryptocurrency not as a separate compliance domain but as one of several overlapping misconduct vectors alongside export-control violations, money laundering, antitrust breaches, and internal fraud. That framing matters for how accounting firms structure their advisory offering. A client operating a treasury that holds digital assets is not just exposed to market volatility or fair-value accounting complexity. They are exposed to the same converging enforcement pressures that BDO's global practitioners describe: tighter AML expectations, enhanced scrutiny of beneficial ownership, and regulators who are increasingly willing to pursue cross-border cooperation to reach conduct that originates outside their jurisdiction.
What Regulators Are Demanding Across Jurisdictions
The report does not focus on a single regulator or jurisdiction. Its value for a global compliance team is precisely that it synthesises what practitioners in seven markets are seeing on the ground. Several themes emerge consistently.
Beneficial ownership transparency
Across the US, UK, and several other jurisdictions covered, regulators are intensifying requirements around beneficial ownership disclosure. For firms holding or transacting in digital assets, this is not abstract. Wallet addresses do not self-identify their beneficial owners, and the gap between what a firm's digital asset accounting software records and what a regulator expects to see in a beneficial ownership register can itself become an enforcement issue. Firms that have not mapped their digital asset counterparty relationships to underlying beneficial owners are carrying a risk that the BDO report flags as growing, not shrinking.
AML controls and the end of paper compliance
The sharpest practical message in the BDO roundup is the explicit rejection of what the panelists call "paper compliance": policies that exist on paper but are not operationally effective. Regulators in multiple jurisdictions are moving from checking whether a policy document exists to testing whether it actually detects and escalates risk in practice. For digital asset operations, that means transaction monitoring that is calibrated to crypto-specific typologies, not just adapted from fiat banking playbooks. It means periodic testing of alert thresholds, documented escalation trails, and evidence that the compliance function has genuine independence from the revenue line.
Self-disclosure and corporate accountability
BDO's practitioners note a consistent regulatory push toward self-disclosure incentives alongside heavier penalties for firms that fail to come forward early when misconduct is identified. This has a direct bearing on how accounting firms advise clients who discover irregularities in their digital asset records, whether that is unexplained wallet activity, discrepancies between on-chain data and internal ledgers, or third-party arrangements that raise beneficial ownership questions. The window between discovery and disclosure matters, and a firm that waits risks losing the credit that regulators in the US and UK are increasingly offering for timely, voluntary cooperation.
Cross-Border Enforcement: Why Jurisdictional Arbitrage Is Closing
One of the most practically significant sections of the BDO report addresses the growth of coordinated cross-border investigations. Firms that historically relied on the friction of multi-jurisdiction enforcement as an informal buffer against prosecution are finding that buffer eroded. Mutual legal assistance frameworks, financial intelligence unit cooperation, and increasingly standardised AML reporting requirements are making it easier for regulators to share evidence and coordinate action.
Implications for firms with multi-jurisdiction digital asset exposure
For an accounting firm advising a client with crypto operations spread across the US, UK, and Asia, this has direct structural implications. Conduct that appears locally compliant may still trigger exposure in another jurisdiction where the same counterparty or transaction chain is under scrutiny. That is not a hypothetical risk. It is the pattern that BDO's practitioners are reporting from active mandates. The practical response is to map the full jurisdictional footprint of any digital asset operation and to ensure that the compliance framework, including the data captured by whatever crypto accounting software is in use, is adequate to respond to multi-jurisdiction enquiries, not just the home-country standard.
Governance: Board and Executive Accountability
BDO's panelists place significant weight on the role of board-level oversight in driving compliance effectiveness. The direction of travel in US and UK enforcement is toward holding senior individuals accountable, not just the corporate entity. For CFOs specifically, that raises the stakes of any compliance gap in the digital asset function. A CFO who cannot demonstrate active oversight of the firm's crypto-related AML controls, transaction monitoring, and beneficial ownership processes is exposed in a way that was not true five years ago.
The internal reporting and whistleblower dimension
The report highlights the growing importance of internal reporting channels and robust whistleblower protections as early-warning mechanisms. Regulators are expanding whistleblower frameworks in both the US and UK, and the BDO practitioners note that firms with weak internal reporting cultures are systematically slower to detect issues, and therefore slower to self-disclose, which compounds the enforcement risk. For digital asset operations, where the technical complexity of on-chain activity can obscure misconduct from non-specialist reviewers, the human layer of internal reporting is not a redundancy. It is often the first detection mechanism that works.
Third-Party and Supply-Chain Diligence
A recurring theme across the BDO panelists is the inadequacy of third-party due diligence programs at most organisations. The issue is not that firms do no diligence. It is that the diligence is often a one-time onboarding check rather than an ongoing monitoring function. In digital asset contexts, third-party risk takes specific forms: the custody provider whose internal controls have not been independently validated, the OTC desk whose beneficial ownership structure has not been re-verified since the original engagement, the DeFi protocol counterparty for which no traditional due diligence pathway exists at all.
The BDO report's call for data-driven monitoring and coordinated investigations applies directly here. Firms that rely on periodic manual reviews of third-party relationships are behind the curve. The expectation, reflected in what BDO's practitioners are seeing from regulators, is for continuous or at least systematic periodic monitoring, with documented escalation when red flags appear. That capability needs to be built into the compliance architecture, not bolted on after an issue surfaces.
Accounting and Practical Implications for Firms and CFOs
Pulling the BDO report's themes into concrete accounting and compliance actions, several priorities stand out for firms with digital asset exposure.
AML and transaction monitoring calibration
If the firm's current transaction monitoring is built on fiat-era rules applied to crypto transactions, that is a gap. Crypto-specific typologies, including chain-hopping, mixing service usage, rapid layering through multiple wallets, and peer-to-peer exchange activity, need to be reflected in alert logic. The monitoring output also needs to be documented in a way that demonstrates genuine detection capability to a regulator, not just policy compliance.
Beneficial ownership mapping
Every significant digital asset counterparty relationship should have a documented beneficial ownership trail. Where that trail is incomplete or where it has not been refreshed within the last review cycle, that is a priority remediation item given the regulatory trajectory the BDO report describes.
Governance documentation
Board and executive oversight of digital asset compliance needs to be evidenced, not assumed. Minutes, risk committee reporting, and documented escalation decisions all matter if a regulator subsequently questions whether leadership was exercising genuine oversight. CFOs should ensure the compliance reporting chain for digital assets reaches board level and is recorded.
Self-disclosure readiness
Given the BDO practitioners' clear message about the value regulators are placing on early voluntary disclosure, firms should have a pre-agreed internal protocol for how a discovered irregularity in digital asset records is escalated, assessed for disclosure obligation, and actioned. Waiting until legal counsel is engaged to begin that conversation is often too late to capture the full benefit of early cooperation.
For deeper context on how AML obligations intersect with digital asset operations, see our earlier coverage on AML and sanctions compliance best practices for digital asset firms. The enforcement dimension is illustrated starkly in our piece on the former FBI agent indicted for crypto theft, which underscores why internal controls and oversight cannot be delegated entirely to external validators.
Source: BDO Insights
Frequently Asked Questions
What does BDO's Worldwatch report mean for firms with crypto exposure?
The report signals that regulators across the US, UK, and multiple other jurisdictions are raising the bar on AML controls, beneficial ownership transparency, and self-disclosure. Firms with digital asset operations need to ensure their compliance programs reflect those higher expectations, not just the minimum requirements in place when their frameworks were last updated.
What is "paper compliance" and why does it matter for crypto AML?
Paper compliance refers to policies that exist in documentation but are not operationally effective at detecting and escalating actual risk. BDO's practitioners flag this as a key enforcement concern: regulators are testing whether programs work in practice, not just whether a policy document can be produced. For crypto AML, that means calibrated transaction monitoring, documented escalation trails, and demonstrated independence of the compliance function.
How does cross-border enforcement affect firms operating in multiple crypto markets?
Growing cooperation between financial intelligence units and regulators means conduct that appears locally compliant can still generate enforcement exposure in another jurisdiction where the same transaction chain or counterparty is under investigation. Firms need to map their full jurisdictional footprint and ensure their compliance data is adequate to respond to multi-jurisdiction enquiries.
What specific third-party risks does the BDO report highlight for digital asset operations?
The key risks include custody providers whose internal controls have not been independently validated, OTC counterparties whose beneficial ownership has not been re-verified recently, and DeFi protocol interactions where traditional due diligence pathways do not exist. The expected standard is ongoing monitoring, not a single onboarding check.
What should a CFO do now in response to the BDO findings?
Three immediate priorities stand out: review whether AML transaction monitoring covers crypto-specific typologies; verify that beneficial ownership records for all significant digital asset counterparties are current; and confirm that board-level oversight of digital asset compliance is documented in governance records. A pre-agreed internal protocol for self-disclosure should also be in place before an issue is discovered, not after.
