What's new
Overview
This deep dive takes stock of recent developments in cyber and operational resilience, including current supervisory risk watch points, the direction of policy and guidance as well as evolving supervisory practices.
What's new
Canadian Securities Administrators launches consultation on harmonized IT system integrity framework
The Canadian Securities Administrators has proposed a harmonized national framework for the IT systems of key market infrastructure entities. It would consolidate existing requirements and covers marketplaces, clearing agencies, trade repositories, information processors and matching service utilities, while seeking input on international alignment and emerging technologies.
European Central Bank President Lagarde urges systemwide action on AI risks to trading, cyber resilience and model access
European Central Bank President and ESRB Chair Christine Lagarde urged systemwide monitoring of AI risks to trading, cyber resilience and access to frontier models. She called for updated cyber defences, coordinated response plans and stronger European AI capabilities to reduce dependence on externally controlled technology.
Swedish Financial Supervisory Authority to update Fidac DORA incident reporting and add overdue report reminders
The Swedish Financial Supervisory Authority will update DORA incident reporting in Fidac on Oct. 19, including a redesigned form and automated reminders for overdue interim or final reports. The update also separates affected entity data into a dedicated table, adds reference code filtering and introduces a revised JSON schema.
Bank for International Settlements’ Basel Committee approves machine-readable Pillar 3 standard and G-SIB window-dressing revisions
The Bank for International Settlements’ Basel Committee approved a final machine-readable Pillar 3 standard, G-SIB assessment results and revisions to curb year-end window dressing. It will consult on stronger Pillar 2 guidance for interest rate risk and the treatment of European banking union exposures in the G-SIB framework. Updates on the cryptoasset standard review, liquidity principles and final Pillar 3 requirements are expected by the end of 2026.
Australia's Council of Financial Regulators flags rising bond yields and AI-related cyber threats
Australia's Council of Financial Regulators said rising longer-term bond yields warrant close monitoring, although markets remain orderly and the domestic financial system is well placed to manage shocks. It urged financial institutions to strengthen resilience and flagged increasingly complex cyber threats from frontier artificial intelligence. The Council may meet more frequently if needed.
Reserve Bank of Australia finds financial system resilient but warns global and operational vulnerabilities are mounting
The Reserve Bank of Australia assessed the financial system as resilient, with most borrowers able to withstand weaker conditions and banks capable of continuing to lend during a severe downturn. The main risks stem from global market vulnerabilities, geopolitical tensions and operational threats linked to AI, cyberattacks and concentrated service providers. Financial institutions should strengthen operational recovery, crisis testing and liquidity risk management while maintaining prudent lending standards.
Argentina's National Securities Commission outlines cyberfraud prevention priorities and coordination efforts
Argentina's National Securities Commission Vice President Sonia Salvatierra outlined the regulator’s cyberfraud prevention priorities, including stronger supervision, transparency, investor protection and financial education. She emphasized coordination with the Financial Intelligence Unit, the Central Bank of Argentina and the private sector.
Executives’ Meeting of East Asia-Pacific Central Banks assesses AI shocks, financial stability risks and central bank adoption
The Executives’ Meeting of East Asia-Pacific Central Banks assessed how AI could generate interacting economic and financial shocks, including labor disruption, asset price corrections, rising leverage and concentration among technology providers. About half of member central banks used AI for general tasks as of 2025, with some expanding into specialized functions. The note emphasizes human oversight, strong governance, systemwide supervision and regional cooperation.
European Banking Authority sets 2027 agenda for banking reforms, supervisory convergence and digital oversight
The European Banking Authority’s 2027 programme prioritizes completing banking reforms, strengthening supervisory convergence and embedding its DORA, MiCA and EMIR responsibilities. It will run a streamlined EU-wide stress test with 55% fewer data points and a climate risk module, while advancing integrated reporting and data sharing. Preparatory work will also begin for the first EU-wide crisis simulation exercise in 2028.
Financial Stability Board Americas group examines stablecoin risks, emerging technology and crisis preparedness
The Financial Stability Board’s Americas regional group assessed financial stability risks from geopolitical uncertainty, extreme weather, capital flows and exchange rates. Members also discussed global stablecoin arrangements, AI and quantum computing risks, and preparedness for cyber incidents and third-party outages.
US Federal Reserve Board Vice Chair Bowman urges community banks to strengthen cyber defenses as AI expands threats
Federal Reserve Board Vice Chair for Supervision Michelle W. Bowman urged community banks to reinforce cyber hygiene as AI makes attacks faster and more sophisticated. She emphasized core controls, employee training, incident response testing and active oversight by boards and senior management. AI can also strengthen defenses, but banks should deploy it with sound risk management.
Dutch Authority for the Financial Markets identifies four priorities to strengthen asset managers’ ICT recovery
The Dutch Authority for the Financial Markets found that large institutional asset managers have the foundations for ICT recovery in place but need better alignment across critical functions, recovery objectives, providers and testing. It identified four priorities covering consistent classification, function-level recovery objectives, provider agreements and testing against extreme disruption scenarios.
Agency for Regulation and Development of the Financial Market of the Republic of Kazakhstan plans cyber exercise covering banks with about 90% of sector assets
Kazakhstan’s financial regulator plans a full-scale supervisory cyber exercise in 2027 involving major banks with about 90% of sector assets. It will assess their ability to withstand cyberattacks and restore information systems after incidents, building on an earlier pilot.
Taiwan Financial Supervisory Commission identifies common control deficiencies across 10 financial sectors
The Taiwan Financial Supervisory Commission identified common deficiencies across 10 financial sectors in fraud and money-laundering controls, customer protection, related-party governance and cyber security. Institutions should strengthen customer checks and transaction monitoring, product sales controls, related-party documentation, privileged-access management and application security testing.
Swedish Financial Supervisory Authority launches review of financial firms’ defenses against AI enabled cyberthreats
The Swedish Financial Supervisory Authority has launched an on-site review of how financial firms address cyberthreats from advanced AI models. It will assess whether firms identify emerging risks and adapt their measures to prevent, detect and manage increasingly automated attacks.
Bank of Ghana emphasizes operational resilience and safeguards as banks pursue digital innovation
Bank of Ghana Second Deputy Governor Matilda Asante-Asiedu urged banks to pair digital innovation with operational resilience, cybersecurity and effective controls. She said systemically important Absa Bank Ghana must maintain adequate capital, strong liquidity, regulatory compliance and responsible conduct.
Hong Kong Securities and Futures Commission urges brokers to strengthen cyber resilience and anti-scam controls
The Hong Kong Securities and Futures Commission urged brokers to strengthen cyber resilience and controls protecting clients’ assets from technology-enabled scams. More than 600 participants joined regulators, police and industry representatives to discuss emerging threats and prevention measures, against a backdrop of HKD 3.58 billion in online investment scam losses last year.
European Securities and Markets Authority sets 2027 delivery agenda for expanded supervision, simplification and T+1 settlement
The European Securities and Markets Authority’s 2027 work program moves major initiatives into delivery, including expanded direct supervision, regulatory simplification and the EU’s Oct. 11, 2027 transition to T+1 settlement. ESMA will advance integrated reporting, investor protection and risk-based supervision while overseeing new entities and strengthening crypto-asset, operational resilience and clearing work. It will also expand its use of data and artificial intelligence in supervision.
Bank for International Settlements paper assesses trusted execution environments for central banks
The Bank for International Settlements has published a paper assessing how trusted execution environments could help central banks process sensitive data without widening access to plaintext records. It identifies applications in collaborative analytics, compliance, digital asset wallets and cyber resilience, but stresses that benefits depend on attestation, strict output controls, auditable governance and layered safeguards. The paper recommends staged adoption and procurement measures addressing software supply chains, revocation, portability and vendor concentration.
France's Financial Markets Authority finds third parties caused 87% of portfolio managers' major DORA incidents in 2025
France's Financial Markets Authority found that third party providers caused 87% of the 31 major DORA incidents confirmed for portfolio management companies in 2025, while cyberattacks accounted for 71%. The incidents disrupted critical investment management, trading, data and compliance functions across firms of all sizes. Reporting arrangements also remain incomplete, with 23% of portfolio managers lacking a DORA-compliant major incident reporting system in a November 2025 self-assessment.
National Bank of the Kyrgyz Republic strengthens interagency cybersecurity coordination for financial infrastructure
The National Bank of the Kyrgyz Republic participated in the first meeting of an interagency commission on information security and cybersecurity. The initiative covers threat assessment, rapid information sharing and stronger coordination to protect financial infrastructure and information systems.
European Securities and Markets Authority announces 2027 digital innovation supervisory priority focused on AI and tokenisation
The European Securities and Markets Authority will begin a digital innovation supervisory priority in 2027, initially focusing on supervised entities’ use of AI and tokenisation. Authorities will map client facing uses, build common supervisory approaches and conduct initial checks on selected firms. The initiative will operate alongside the continuing cyber and operational resilience priority as the ESG disclosures priority closes.
Central Bank of Iceland keeps countercyclical capital buffer at 2.5% as economic slowdown and cyber threats test resilience
The Central Bank of Iceland kept the countercyclical capital buffer at 2.5%, finding that strong banks and low private-sector indebtedness support financial stability. A cooling economy and housing market could increase pressure on construction companies, while AI-enabled cyberattacks require stronger defenses and coordinated incident preparedness. Offline payment card functionality has now been implemented to strengthen payment resilience.
Central Bank of Iceland keeps countercyclical capital buffer at 2.5% as construction and AI cyber risks rise
The Central Bank of Iceland kept the countercyclical capital buffer at 2.5%, with banks remaining highly resilient and profitable. Rising construction exposures and nonperforming loans are increasing systemic risk, though distress is not widespread. Geopolitical uncertainty and AI-enabled cyber threats also require stronger financial infrastructure and fallback arrangements.
Danish Financial Supervisory Authority identifies DORA weaknesses at insurers and pension companies
The Danish Financial Supervisory Authority found that insurers and pension companies are advancing their DORA implementation but still have weaknesses in governance, risk management documentation, skills, operational testing and incident learning. Companies with deficiencies must submit remediation plans, while targeted inspections and inadequate progress may result in supervisory action.