Current thematic dossiers

Select a theme to view its dossier.

Cyber & operational resilience

This deep dive takes stock of recent developments in cyber and operational resilience, including current supervisory risk watch points, the direction of policy and guidance as well as evolving supervisory practices.

What's new

Overview

This deep dive takes stock of recent developments in cyber and operational resilience, including current supervisory risk watch points, the direction of policy and guidance as well as evolving supervisory practices.

What's new

  1. EuropeEuropeEuropean Banking Authority

    European Supervisory Authorities identify external dependencies, cyber threats and private credit as key EU financial vulnerabilities

    The European Supervisory Authorities identified non-EU dependencies, cyber and emerging technology threats, and private credit as key vulnerabilities, while assessing the EU financial system as resilient overall. They called for stronger crisis preparedness, monitoring and stress testing of external and private credit exposures, and early action on risks from artificial intelligence and quantum computing.

  2. EuropeDenmarkDanish Finanstilsynet

    Danish Financial Supervisory Authority sets 2030 technology agenda for AI, quantum risks, tokenization and innovation

    The Danish Financial Supervisory Authority has set a technology agenda through 2030 covering AI, quantum technology, tokenization and financial innovation. It will assess emerging risks, clarify existing requirements and consider expanding its FT Lab regulatory sandbox, with the aim of supporting innovation without adding unnecessary rules or weakening financial stability and customer protections.

  3. PacificAustraliaReserve Bank of Australia

    Reserve Bank of Australia finds continuing ASX shortfalls in four risk areas, upgrades two operational risk ratings

    The Reserve Bank of Australia found that ASX’s clearing and settlement facilities still partly observed standards covering governance, comprehensive risk management, credit risk and operational risk. It upgraded ASX Clear and ASX Settlement from not observed to partly observed for operational risk after specific CHESS improvements, but said this did not indicate broader progress in ASX’s operational risk management.

  4. EuropeUnited KingdomFinancial Conduct Authority

    UK's Financial Conduct Authority finalizes working capital guidance, consults on sustainability reporting and outlines cyber disclosure expectations

    The UK's Financial Conduct Authority finalized guidance allowing certain uncommitted facilities in working capital calculations where directors judge them available throughout the working capital period, with appropriate disclosure. It is also consulting on comply or explain expectations for listed companies under UK sustainability reporting rules applying from accounting periods beginning January 1, 2027. Issuers should assess cyber incidents case by case under the UK Market Abuse Regulation, promptly disclose inside information unless delay conditions are met, and monitor confidentiality and impacts continuously.

  5. EuropeEuropeEuropean Central Bank - Banking Supervision

    European Central Bank Banking Supervision calls for board oversight of bank digital strategies and stronger risk safeguards

    European Central Bank Supervisory Board Chair Claudia Buch called for board oversight, multiyear investment and strong risk controls as banks expand their use of artificial intelligence, cloud services and tokenisation. Supervision will focus on common cyber, outsourcing and data vulnerabilities while holding banks accountable for automated decisions. Buch also backed integrated European markets and interoperable public infrastructure without weakening prudential standards.

  6. EuropeEuropeEuropean Banking Authority

    European Banking Authority finalizes DORA-aligned non-ICT third-party risk Guidelines with two-year transition

    The European Banking Authority has finalized DORA-aligned Guidelines for managing third-party risk involving non-ICT services, replacing its narrower 2019 outsourcing framework. Stricter governance, contracting, monitoring and exit requirements focus on arrangements supporting critical or important functions. Financial entities have a two-year transitional period to review and document those existing arrangements.

  7. CaribbeanBahamasCentral Bank of the Bahamas

    Central Bank of the Bahamas advances analysis of gaming links to banks and cyber preparedness plans

    The Central Bank of the Bahamas reported progress on financial stability analysis of links between gaming flows and banks. The Financial Stability Council also agreed to develop sectorwide cyber preparedness plans focused on incident reporting, management and harmonized regulatory guidance. Its 2025 assessment found resilience across banks, securities and insurance, while identifying geopolitical tensions and oil prices as external risks.

  8. EuropeFinlandFinanssivalvonta

    Finnish Financial Supervisory Authority reports strong sector solvency and highlights operational and cyber risks

    The Finnish Financial Supervisory Authority found that financial sector solvency remained strong in the first half of 2026, despite operational, cyber, geopolitical and trade policy risks. Banks maintained ample capital and stable liquidity, while pension and insurance sectors recorded high solvency ratios. Strong investment markets lifted pension assets, fund capital and the results of management companies and investment firms.

  9. PacificAustraliaAustralian Competition and Consumer Commission

    Australian Competition and Consumer Commission conditionally authorises superannuation cyber and financial crime information sharing for five years

    The Australian Competition and Consumer Commission has conditionally authorised collective negotiation and threat information sharing through superannuation industry cyber and financial crime platforms until Oct. 9, 2031. The association must give the ACCC ongoing platform access and permit it to share information, while commercially sensitive business information remains outside the authorisation. The approval takes effect on Oct. 9, 2026, if it is not referred for review.

  10. EuropePortugalPortuguese Securities Commission (CMVM)

    Portuguese Securities Commission launches consultation on DORA reporting procedures

    The Portuguese Securities Commission is consulting on procedures for DORA reporting by entities under its prudential supervision, covering severe technology incidents, significant cyberthreats and third party technology contracts. Contract registers would be due annually by Feb. 28, while planned contracts supporting critical or important functions would require 30 days’ notice, rising to 60 days for specified market infrastructures.

  11. EuropeNorwayNorwegian Finanstilsynet

    Financial Supervisory Authority of Norway publishes DORA and bank supervision findings, flags governance and property risks

    The Financial Supervisory Authority of Norway has published supervisory findings showing that banks remain profitable and well capitalized but face property, market and operational risks. Under DORA, firms have made substantial implementation progress, although ICT governance, operationalization of policies and third-party oversight remain weak. Inspections of smaller banks also found shortcomings in credit controls, documentation, distressed exposure monitoring and concentration risk management.

  12. North AmericaUnited StatesFederal Deposit Insurance Corporation

    Federal Deposit Insurance Corporation, Federal Reserve Board, National Credit Union Administration and Office of the Comptroller of the Currency propose tailored third-party risk guidance

    Four federal regulators have proposed replacing existing third-party risk guidance with a nonbinding framework that tailors oversight to the magnitude and likelihood of risks posed by each relationship. The proposal emphasizes proportionate due diligence, contracting, monitoring, residual risk acceptance and governance. Separate guidance sharpens scrutiny of core providers serving community banks, including their transparency, contract practices, technology and operational resilience.

  13. AsiaSingaporeMonetary Authority of Singapore

    Monetary Authority of Singapore urges stronger AI governance and cyber defenses as financial sector adoption scales

    The Monetary Authority of Singapore urged financial institutions to strengthen AI governance and cyber defenses as adoption expands beyond pilots. Pathfin.ai now has more than 300 participants, while cross-bank AI testing for scam detection is expected to produce findings by the end of 2026. MAS also warned of a sixfold rise in high-severity vulnerabilities and called for stronger multilayered defenses supported by AI.

  14. North AmericaUnited StatesNew York State Department of Financial Services

    New York State Department of Financial Services clarifies cybersecurity risk assessment expectations

    The New York State Department of Financial Services clarified existing cybersecurity risk assessment requirements for regulated entities without imposing new obligations. Assessments must be updated at least annually and after material business or technology changes, and should address third-party concentrations, emerging technologies and whether existing controls remain adequate.

  15. EuropeLatviaCentral Bank of Latvia

    Central Bank of Latvia implements offline card payments up to EUR 200 for essential goods during communications outages

    The Central Bank of Latvia has implemented offline card payments for essential goods during internet or mobile communications outages. Customers of four designated banks can spend up to EUR 200 per card at participating grocery, fuel and pharmacy chains by inserting a physical card and entering the PIN. The service does not support smart device payments and requires electricity at the merchant.

  16. EuropeEuropeEuropean Securities and Markets Authority

    European Securities and Markets Authority identifies rising correction and cyber risks despite resilient markets

    The European Securities and Markets Authority warned that elevated technology valuations and strong investor optimism are increasingly detached from weaker economic conditions and geopolitical risks, raising the prospect of an abrupt market correction. Operational risks are also rising as frontier artificial intelligence intensifies cyber threats, while growing U.S. equity concentration leaves EU investors more exposed to a repricing.

  17. GlobalGlobalBank for International Settlements

    Bank for International Settlements assesses frontier AI cyber threats and finds authorities reinforcing existing resilience frameworks

    A Bank for International Settlements paper finds that frontier AI is accelerating cyber attacks by automating vulnerability discovery, exploitation and complex operations. Financial authorities are mainly reinforcing existing operational resilience frameworks, with greater emphasis on faster patching, stronger governance, recovery capabilities and oversight of critical third-party dependencies.

  18. GlobalGlobalIOSCO

    Committee on Payments and Market Infrastructures and International Organization of Securities Commissions launch cyber resilience toolkit consultation and assess third party risks at financial market infrastructures

    The Committee on Payments and Market Infrastructures and the International Organization of Securities Commissions are consulting on a voluntary cyber resilience toolkit for financial market infrastructures and a discussion paper on third-party service risks. The toolkit covers governance, scenario design, recovery and testing, while the discussion paper highlights provider concentration, supply chain opacity, exit constraints and other operational resilience challenges.