Current thematic dossiers

Select a theme to view its dossier.

Cyber & operational resilience

This deep dive takes stock of recent developments in cyber and operational resilience, including current supervisory risk watch points, the direction of policy and guidance as well as evolving supervisory practices.

What's new

Overview

This deep dive takes stock of recent developments in cyber and operational resilience, including current supervisory risk watch points, the direction of policy and guidance as well as evolving supervisory practices.

What's new

  1. AsiaSouth KoreaSouth Korea Financial Services Commission

    South Korea Financial Services Commission expands AI security testing eligibility to 75 firms

    The South Korea Financial Services Commission expanded eligibility for its second frontier AI security test from 49 to 75 firms and will select up to 15 participants for one-year relief from network-separation rules. Selected firms must adopt alternative security controls and report their findings, while an interim review of the first round found that AI could scan large codebases rapidly and consistently for vulnerabilities.

  2. PacificAustraliaCouncil of Financial Regulators

    Australia’s Council of Financial Regulators finds system resilient, backs unchanged macroprudential settings amid elevated risks

    The Council of Financial Regulators maintained that Australia’s financial system remains resilient despite elevated geopolitical, market and cyber risks, and backed unchanged macroprudential settings. Borrower stress remains limited, but authorities emphasized sound lending standards and stronger operational resilience. A payments cyber crisis coordination framework will be published shortly, alongside ongoing work on critical third-party and AI-enabled cyber risks.

  3. North AmericaUnited StatesU.S. Securities & Exchange Commission

    U.S. Securities and Exchange Commission proposes transfer agent rule overhaul, including one-day processing and new compliance safeguards

    The U.S. Securities and Exchange Commission proposed a comprehensive modernization of registered transfer agent rules, including one-day processing and posting standards, six-year record retention and expanded reporting. The package would add compliance, safeguarding, cybersecurity and business continuity requirements while removing several existing exemptions. It would also regulate restrictive legend removal and require notifications to securityholders after 18 months of inactivity.

  4. PacificAustraliaAustralian Prudential Regulation Authority

    Australian Prudential Regulation Authority and Australian Securities and Investments Commission release superannuation CEO roundtable notes on AI and resilience

    The Australian Prudential Regulation Authority and Australian Securities and Investments Commission have released notes from superannuation CEO roundtables on frontier AI, cyber and operational resilience, and crisis preparedness. Participants emphasized tested governance, individual accountability and stronger oversight of concentrated service-provider dependencies, reinforcing the regulators’ recent focus on converting cyber-risk awareness into operational readiness.

  5. AfricaMozambiqueBank of Mozambique

    Bank of Mozambique sets data localization and cloud outsourcing requirements for financial institutions

    The Bank of Mozambique requires credit institutions and financial companies to keep primary data centers and core systems in Mozambique and obtain approval for specified offshore and cloud arrangements. Banks, microbanks and electronic money institutions may use only private clouds, while outsourcing contracts must provide security, audit, regulatory access and exit protections. Existing institutions have 12 months after the rules take effect to comply fully.

  6. GlobalGlobalFinancial Stability Board

    Financial Stability Board chair warns of cyber risks from frontier AI models

    Financial Stability Board Chair Andrew Bailey warned that frontier AI models could intensify cyber risk and called for safe model deployment, robust financial-sector recovery capabilities and resilient critical technology providers. He also cautioned that rising leverage, stretched valuations, market concentration and AI-related optimism could amplify a market correction.

  7. PacificAustraliaReserve Bank of Australia

    Reserve Bank of Australia sets 2026/27 priorities for monetary policy, payments resilience and digital money

    The Reserve Bank of Australia’s 2026/27 corporate plan prioritizes modernizing monetary policy implementation, strengthening payment infrastructure and advancing work on digital money. The RBA plans to complete its payments regulation review, test new crisis management powers and assess the case for a retail central bank digital currency. It will also progress cyber upgrades and maintain demanding availability targets for critical settlement services.

  8. EuropeEuropeEuropean Banking Authority

    European Banking Authority launches consultation on proportionate operational risk framework, with lighter requirements below EUR 750 million

    The European Banking Authority has consulted on harmonized standards for institutions’ governance, assessment and management of operational risk. The proposals cover management accountability, independent oversight, data, reporting, validation and audit, with lighter requirements for institutions whose business indicator is below EUR 750 million. The final standards will be submitted to the European Commission for adoption.

  9. PacificAustraliaAustralian Securities & Investments Commission

    Australian Securities and Investments Commission sets 2026–27 priorities on consumer harm, AI oversight and regulatory burden

    The Australian Securities and Investments Commission has set its 2026–27 priorities, combining stronger action on consumer harm and artificial intelligence risks with measures to reduce unnecessary regulatory burden. Its work will cover scams, debt collection, insurance intermediaries, buy now pay later, superannuation fee deductions and AI-related threats to consumers and markets.

  10. GlobalGlobalINTERPOL

    INTERPOL operation against West African organized crime leads to 58 arrests and identification of 263 suspects

    INTERPOL reported 58 arrests and the identification of 263 suspects following a 22-country operation against West African organized crime groups. Authorities disrupted major romance, investment and money laundering schemes, including by blocking 257 South African bank accounts and identifying a 196-person Crime-as-a-Service network in Argentina. The operation also found increased sextortion targeting minors and greater outsourcing of criminal activities through the dark web.

  11. AsiaIndiaSecurities & Exchange Board of India

    Securities and Exchange Board of India signs partnership to strengthen cybersecurity, market intelligence and technical innovation

    The Securities and Exchange Board of India signed a long-term partnership with Rashtriya Raksha University and the National Institute of Securities Markets. The collaboration covers cybersecurity and emerging-technology training, research and open-source intelligence, and includes a planned Technical Innovation Unit for joint operations and innovation in the securities market.

  12. AsiaIndiaSecurities & Exchange Board of India

    Securities and Exchange Board of India mandates IT resilience index for market infrastructure institutions by February 2027

    The Securities and Exchange Board of India will require market infrastructure institutions to calculate a system-driven IT Resilience Index every six months. Institutions must implement the index, early warnings and real-time service monitoring by February 28, 2027. The first submission will cover the half-year ending March 31, 2027.

  13. EuropeDenmarkDanish Finanstilsynet

    Danish Financial Supervisory Authority urges financial firms to strengthen defenses against AI-enabled cyberattacks

    The Danish Financial Supervisory Authority has urged all financial firms to assess AI-enabled cyber threats and strengthen their cybersecurity and operational resilience proportionately. Firms should establish clear management accountability, improve vulnerability monitoring and patching, and test response and recovery plans against AI-driven attacks. The authority will analyze the sector’s AI use and related risks in the second half of 2026.

  14. PacificAustraliaAustralian Prudential Regulation Authority

    Australian Prudential Regulation Authority sets 2026-27 agenda for cyber resilience, system risk and burden-neutral reform

    The Australian Prudential Regulation Authority’s 2026-27 Corporate Plan prioritizes cyber and AI threats, technology-provider concentration, geopolitical risk and financial-sector interconnections. Planned measures include bank lending reviews, a new system-risk stress test and reforms covering superannuation capital, governance, bank capital and liquidity. APRA aims to offset new requirements through regulatory simplification.

  15. PacificAustraliaAustralian Prudential Regulation Authority

    Australian Prudential Regulation Authority outlines trustee priorities as retirement-age accounts are projected to grow by 3.9 million

    The Australian Prudential Regulation Authority outlined stronger operational resilience, investment governance and liquidity expectations for superannuation trustees as retirement-age accounts are projected to grow by 3.9 million over the next decade. It also highlighted continued scrutiny of Retirement Income Covenant compliance, revised capital treatment for longevity products and increased reporting transparency.

  16. Middle EastKuwaitCentral Bank of KuwaitProjects and initiatives

    Central Bank of Kuwait launches sixth cohort of Cybersecurity Leaders Program

    The Central Bank of Kuwait has launched the sixth cohort of its three-month Cybersecurity Leaders Program for Kuwaiti nationals. Delivered with the SANS Institute, the program includes a final workshop involving the Bank for International Settlements, with applications open through Sept. 24, 2026.

  17. AsiaKazakhstanAgency for Regulation and Development of the Financial Market of the Republic of KazakhstanSupervision

    Agency for Regulation and Development of the Financial Market of the Republic of Kazakhstan details mandatory cybersecurity requirements for all financial market participants

    Kazakhstan’s financial regulator detailed mandatory minimum information security requirements applying to all financial market participants since July 12, 2026, with stricter controls for banks. Compliance is monitored through reporting and supervisory reviews, while consumers are urged to verify suspicious requests through official channels.

  18. AsiaPhilippinesCentral Bank of the Philippines

    Central Bank of the Philippines sets guidelines for rural bank cloud core banking support, including 36-month subscriptions

    The Central Bank of the Philippines has set rules for supporting qualified rural banks’ migration to cloud-based core banking systems. Assistance covers implementation for up to six months and a 36-month subscription, subject to capital, readiness, outsourcing and supervisory assessments. Applications open one month after issuance, with the deadline to be announced separately.

  19. PacificAustraliaAustralian Prudential Regulation AuthorityEnforcement

    Australian Prudential Regulation Authority brings civil penalty case against Bendigo Bank over admitted cyber control breaches, parties propose AUD 8 million penalty

    The Australian Prudential Regulation Authority has brought civil penalty proceedings against Bendigo Bank over admitted accountability, cyber control and testing failures linked to a 2023 attack on its Alliance Bank business. The parties propose an AUD 8 million penalty, subject to court approval. The historical weaknesses have been remediated, and APRA has no current concerns about the bank’s information security controls.