Overview
Recent supervisory insights point to six recurring operational resilience and ICT concerns:
- Operational and ICT risk controls that are not consistently executed, evidenced or independently challenged
- Insufficient independent assurance over critical ICT providers and intra-group services
- Critical-service mapping and impact tolerances that do not consistently drive severe end-to-end testing
- Change and migration controls that are not preventing avoidable service disruption
- Uneven fundamental cyber controls and visibility over the technology estate
- Incident classification, reporting and remediation that do not consistently support effective learning
Many of these watch points now reflect the first wave of DORA-specific supervisory assessment activity. From a supervisory perspective, the focus is whether firms can demonstrate that DORA implementation has moved beyond formal project plans, policies and gap analysis into reliable operating practice: complete and well-documented ICT risk-management frameworks, accurate registers of information, effective contract, subcontracting and oversight arrangements for ICT third-party providers, business-impact analysis for critical or important functions, and reliable classification and reporting of major ICT incidents among other things.
Taken together, the DORA assessment findings and broader operational-resilience, ICT risk and cyber hygiene observations point to the same practical concern: firms may have frameworks in place, but they do not always execute them consistently, evidence them clearly, challenge them independently, remediate weaknesses promptly or translate incidents and tests into learning points that drive concrete oversight and control changes.
What's new
European Central Bank President and ESRB Chair Christine Lagarde urged systemwide monitoring of AI risks to trading, cyber resilience and access to frontier models. She called for updated cyber defences, coordinated response plans and stronger European AI capabilities to reduce dependence on externally controlled technology.
Australia's Council of Financial Regulators said rising longer-term bond yields warrant close monitoring, although markets remain orderly and the domestic financial system is well placed to manage shocks. It urged financial institutions to strengthen resilience and flagged increasingly complex cyber threats from frontier artificial intelligence. The Council may meet more frequently if needed.
The Reserve Bank of Australia assessed the financial system as resilient, with most borrowers able to withstand weaker conditions and banks capable of continuing to lend during a severe downturn. The main risks stem from global market vulnerabilities, geopolitical tensions and operational threats linked to AI, cyberattacks and concentrated service providers. Financial institutions should strengthen operational recovery, crisis testing and liquidity risk management while maintaining prudent lending standards.
Deep dive
Frontier AI is shortening vulnerability, patching and response windows
Supervisors increasingly treat frontier AI as a strategic operational resilience issue stressing that advanced models can increase the speed, scale, accessibility and sophistication of vulnerability discovery, exploitation and attack execution. The concern is that weaknesses in firms, market infrastructures and shared digital infrastructure may be exploited before defenders can respond, potentially turning isolated vulnerabilities into wider operational disruption.
Anthropic’s April 7 release of Claude Mythos Preview was followed by a concentrated series of financial-sector warnings in the second quarter of 2026. The model was reported to have autonomously identified thousands of previously unknown vulnerabilities in widely used operating systems and web browsers, while a UK AI Security Institute assessment found that it was the first model to autonomously sequence a complete 32-step corporate-network attack, completing all steps in three of 10 attempts. Authorities broadly warned that such capabilities could make sophisticated attacks faster, cheaper and accessible to less skilled actors, narrowing the interval between vulnerability discovery, exploitation and remediation and increasing the risk of simultaneous failures across common software, cloud, payments and data infrastructure.
In Australia, the Australian Prudential Regulation Authority said information security practices were struggling to keep pace and flagged prompt injection, data leakage, insecure integrations, exploit injection, autonomous agent misuse, incomplete security testing and patching timelines that did not match the accelerated threat. The Australian Securities and Investments Commission warned that isolated weaknesses could have a systemwide domino effect. The Securities and Exchange Board of India cited the potential for cascading effects across the interconnected securities market and established the cyber-suraksha.ai task force, while the Financial Conduct Authority, Bank of England and HM Treasury said current frontier models already exceed what a skilled practitioner could achieve at greater speed, larger scale and lower cost. Japan’s Financial Services Agency and the Bank of Japan called for short-term preparations for the rapid discovery of large numbers of vulnerabilities and the resulting volume of patches, while South Korea’s Financial Services Commission announced arrangements to support AI-driven cyber defense. Across these actions, authorities reinforced expectations that boards and senior management treat frontier AI as a management and operational-resilience issue, accelerate vulnerability triage and patching, strengthen access, network and data controls, monitor third-party and open-source dependencies and maintain tested containment, incident response, recovery and business continuity arrangements.
Firms lack sufficient independent assurance over critical ICT providers and intra-group services
Supervisors are concerned that firms remain heavily dependent on external or group service providers without maintaining an adequate independent basis for assessing the resulting risks. Notably, oversight of critical external and intra-group ICT services does not always provide an independent and sufficiently detailed view of provider performance, access, subcontracting, control effectiveness and continuity.
European Central Bank (ECB) Banking Supervision has identified that some banks remain behind in renegotiating third-party contracts and establishing adequate business continuity arrangements, and has made closure of these gaps a focus of an ICT third-party-risk on-site campaign. Across ICT inspections of banks and insurers, the Financial Supervisory Authority of Norway (Finanstilsynet) found that firms sometimes relied too heavily on assurance supplied by providers, groups or industry alliances. The authority expected firms’ control functions to maintain their own documented basis for assessing provider risk, service-level performance, access rights and compliance, and to conduct targeted checks where the criticality or complexity of a service required them. The concern is reinforced by the European Supervisory Authorities (ESAs)’ analysis of major ICT incidents occurring in 2025: around one-third of the 3,383 major incidents reported by EU financial entities had a cross-border impact, underscoring how shared infrastructure, services and dependencies can transmit disruption across firms and jurisdictions.
Fundamental cyber controls and visibility over the technology estate remain uneven
Supervisors continue to identify weaknesses in asset and dependency inventories, privileged access management, secure configuration, vulnerability detection, security monitoring, logging, backup testing and restoration preparedness. The concern is the coverage and operating effectiveness of these controls, particularly across externally managed systems.
In a thematic review of regulated markets and other trading platforms, the Dutch Authority for the Financial Markets found that elements of the ICT risk-management framework required stronger coverage, particularly security monitoring, access management, logging, emergency change controls and continuity management. Its separate SREP work also identified weaknesses in vulnerability detection, backup testing and incident preparedness. Cross-sector examination findings published by the Taiwan Financial Supervisory Commission (FSC) showed comparable deficiencies across financial institutions, including incomplete controls and audit trails for the external transmission of personal data, inappropriate use or administration of privileged accounts, and inadequate host-security baselines and configuration standards. The common concern is that firms may possess overarching cyber frameworks while lacking complete visibility of the assets, access rights and configurations to which those frameworks must be applied.
Change and migration controls are not preventing avoidable service disruption
Deficiencies in change classification, risk assessment, testing, approval, rollback and post-implementation verification are allowing technology changes and migrations to cause material operational incidents. Supervisors are particularly attentive to major transformations, emergency changes and high-volume or pre-approved changes.
ECB Banking Supervision reported that IT change was identified as the root cause of 38% of major incidents reported by banks for 2025 and has designated change management processes and controls as a specific supervisory focus. Following a March 2026 disruption at a major Singapore retail bank, the Monetary Authority of Singapore (MAS) found that an erroneous step during a system change had interrupted digital banking services and stated that it would follow up on the bank’s change-management process.
Critical service mapping and impact tolerances do not consistently drive severe end-to-end testing
Firms cannot always demonstrate that critical or important services will remain within tolerable disruption levels. Mapping and business impact analysis are not consistently translated into recovery priorities, test scenarios, fallback arrangements and evidence of end-to-end recoverability.
In its review of operational resilience self-assessments, the UK Financial Conduct Authority found that some firms’ mapping remained overly focused on technology and did not adequately capture people, processes, facilities, information and third-party dependencies. It also found cases where firms had not distinguished between tolerances for consumer harm and market integrity effects, claimed that they could recover from any disruption without sufficiently severe testing, or had not tested alternatives where normal communication channels were unavailable. Across inspections of banks and insurers, Norway's Finanstilsynet similarly found that business-impact analyses could be too high-level or insufficiently connected to availability requirements, control priorities and testing. It called for firm-level tests covering complete business processes, prolonged outages, serious cyber incidents, provider failures and worst-case scenarios.
Operational and ICT risk controls are not consistently executed, evidenced or independently challenged
Firms do not always translate operational and ICT risk frameworks into routinely performed controls, clear ownership, effective independent challenge and timely remediation. Board oversight is also weakened where approval trails, management information and accountability for corrective actions are unclear.
As part of a SREP assessment covering investment institutions, investment firms and trading and settlement platforms, the Dutch Authority for the Financial Markets (AFM) found that internal controls were not always performed consistently or properly documented, processes were not reviewed regularly, and responsibilities for ownership, oversight and monitoring were insufficiently clear. Similar patterns also emerged in other jurisdictions: The Financial Conduct Authority (FCA) identified in its review of operational resilience self-assessments across banks, insurers, payment firms, investment firms and market infrastructures: some firms could not evidence clear board approval, named owners and completion dates for remediation, or meaningful input from the second and third lines of defence. A series of ICT inspection reports issued by Norway’s Financial Supervisory Authority (Finanstilsynet) in 2026 covering banks and an insurer highlighted limited operationalisation of board-approved governance or steering documents, insufficient ICT capacity or expertise in parts of the control environment, gaps in ICT-risk reporting and control documentation, and, in at least one bank inspection, limited follow-up of internal-audit recommendations.
Incident classification, reporting and remediation do not consistently support effective learning
Incident severity assessment, root-cause analysis, loss measurement, regulatory reporting and remediation tracking remain inconsistent. This reduces the reliability of supervisory information and increases the risk that recurring control failures are detected without being prevented.
In a SPOT inspection campaign covering five portfolio-management companies and the period from 2022 to 2024, France’s Autorité des marchés financiers (AMF) found that the severity of operational incidents and near misses was not always assessed systematically, remediation plans were only partially tracked, and the materiality criteria used to exclude incidents from management reporting were not consistently documented. The AMF also identified significant inaccuracies in operational-loss data reported to the authority by one firm and found that some firms maintained multiple, non-harmonised incident registers. At EU level, the ESAs’ first annual analysis of major incidents reported under the Digital Operational Resilience Act identified divergent reporting practices across sectors and jurisdictions. Although partly attributable to the framework’s first year of operation, those differences limit data quality, comparability and supervisory usability and reinforce the need for consistent classification, complete root-cause reporting and verifiable remediation closure.