Japan FSA IT Resilience Report 2026: Four Supervisory Fronts for Banks
Japan’s Financial Services Agency published its Analytical Report on IT Resilience in the Financial Sector on 30 July 2026, and the framing in the executive summary is blunt: the management of financial institutions needs to recognise IT risk and cyber risk as top management priorities. The Japan FSA IT resilience report carries no template and no filing deadline. Its purpose is to tell boards, in writing, how the supervisor now reads the failures they already report to it.
The document sits on top of an obligation Japanese institutions have lived with for years. When a system failure occurs, deposit-taking institutions report it to the FSA under the supervisor’s guidelines for the management of system risk, and those reports are one of the raw inputs the FSA analyses. Since 2019 the agency has published an annual read of those cases. In June 2025 it widened the exercise and renamed it the Analytical Report on IT Resilience in the Financial Sector. The July 2026 edition is the second under that title, and it arrives with geopolitical, cyber and third-party risk named in the opening lines.
For a Japanese-regulated bank, and for a cross-border group with a Tokyo branch or a Japanese subsidiary, the practical question is what a supervisory report changes when it changes no rule. The answer is where supervisory attention lands next, and what a board is expected to be able to evidence when a Japan Financial Services Agency monitoring team asks.
Related reading: the ESAs’ annual report on DORA ICT incidents, the European counterpart to this kind of supervisor-level analysis.
What the FSA IT resilience report now covers
The 2026 report is organised into four parts, plus two appendices and a forward-looking column. Part I analyses system failures. Part II assesses IT governance maturity. Part III covers cybersecurity, and breaks into four threads: key issues identified through inspections and monitoring with illustrative practices, the evolving cyber threats posed by AI, an outsourced study on strengthening third-party cybersecurity risk management, and unauthorised access to and fraudulent transactions involving customer accounts. Part IV covers the conduct of cloud resilience exercises.
Appendix 1 collects system-failure cases. Appendix 2 summarises the Basel Committee on Banking Supervision’s Principles for the Sound Management of Third-Party Risk, compares them with relevant Japanese supervisory materials, records findings from the FSA’s dialogue with selected institutions and describes intended next steps. A standalone column addresses migration to post-quantum cryptography.
A common misreading is to file this alongside a prudential return and move on. It is neither a capital calculation nor a data submission with a remittance date. It carries no template, no validation rules and no deadline. Its weight is supervisory: it sets out what the FSA looked at, what it found wanting, and where individual firms and the industry are expected to strengthen. When a supervisor publishes its own diagnosis, the follow-up usually arrives through inspections and monitoring, well before any rulebook amendment.
The key dates worth pinning
- 2019: the FSA begins publishing annual analytical reports on system failures at financial institutions.
- June 2025: the exercise is reorganised and first published as the Analytical Report on IT Resilience in the Financial Sector.
- 30 July 2026: the FSA publishes the 2026 edition, the report discussed here.
- 10 December 2025: the BCBS finalises its Principles for the Sound Management of Third-Party Risk, summarised at Appendix 2.
- 17 January 2025: the EU Digital Operational Resilience Act began to apply, the reference point for a cross-border group’s European entities.
System failures and the reporting trail behind Part I
Part I draws on system-failure information received under the laws and supervisory materials applicable to each regulated sector. For major banks, the current supervisory guideline requires immediate notification when the institution recognises a reportable system failure or cybersecurity incident, followed by the applicable written report. The FSA may require additional reporting under Article 24 of the Banking Act where necessary.
Submission of the initial report does not complete the reporting sequence. The current major-bank guideline also requires further reporting on recovery and cause identification and, where recovery or cause analysis remains unresolved, a report on the current position within one month. Part I then analyses reported cases and presents sector-wide trends and selected examples.
For cross-border groups the notification map is more crowded than a single obligation suggests. A group running the same core platform across a Tokyo branch and a European entity can face a Japanese system failure notification and, in parallel, a major ICT-related incident report under the EU framework. The triggers, timelines and recipients differ by regime. Firms that treat incident reporting as one global process, when it is really a set of jurisdiction-specific obligations that happen to describe the same outage, tend to discover the gap mid-incident. Our DORA ICT incident reporting guide sets out the European trigger and timing that would run alongside a Japanese filing.
IT governance maturity becomes the lens in Part II
Part II assesses IT governance maturity, and this is where the report speaks most directly to boards. The executive summary lists five things management is expected to review and strengthen on a continuing basis: governance, risk management frameworks, investment, human resource development, and third-party risk management. Read together, they describe IT and cyber risk as a standing board agenda item, owned above the technology function.
Human-resource development is one of the areas that the executive summary says management should review and strengthen continuously. Part II uses questionnaire data and interviews, including material relating to IT strategy, IT investment, IT personnel and shared-system arrangements, to examine IT-governance conditions at financial institutions.
The report presents survey findings, issues and selected practices, but it does not establish a scored maturity scale or a formal pass-or-fail checklist. Firms should distinguish the report’s analytical observations from any binding test contained in the applicable supervisory guideline.
Part III: cyber offence, AI-enabled threats, and account fraud
Part III is the longest strand and the one most exposed to the outside world. Three of its threads are worth separating because firms tend to run them as one programme.
The first is the evolving cyber threat posed by AI. The report treats AI as a force multiplier for attackers and asks what that means for the sector, which places it alongside supervisory work elsewhere that has warned about generative tools lowering the cost of credible social engineering and malware. The second is the outsourced study on strengthening third-party cybersecurity risk management, which connects Part III back to the third-party theme running through the whole document. The third is unauthorised access to and fraudulent transactions involving customer accounts, which is the point where a cyber weakness turns into a customer loss and a conduct question.
The report treats AI-related cyber threats, third-party cybersecurity risk and unauthorised access or fraudulent customer-account transactions as separate analytical threads. Firms should therefore map each thread to the controls and legal obligations that govern the relevant entity. The FSA report itself does not prescribe DORA threat-led penetration testing as the control for these issues or establish reimbursement requirements for account fraud.
Part IV: cloud resilience exercises and the assume-disruption posture
Part IV covers the conduct of cloud resilience exercises, and it carries the report’s sharpest instruction to firms. The executive summary states that financial institutions should assume disruptions and cyber incidents may still occur despite preventive measures, and, on that assumption, strengthen their IT resilience to ensure continuity of critical operations, timely recovery of services, and mitigation of customer impact.
That sentence places continuity and recovery alongside prevention. Part IV reports lessons from an FSA-led tabletop exercise involving financial institutions and public-cloud providers. The exercise focused on how outage information is obtained, shared and used during initial response, business continuity, recovery and root-cause analysis, including whether an institution can gather sufficient information for decisions such as switching to a backup site. The report does not present the exercise as a live failover test or as proof that a service met a recovery-time tolerance.
The report includes concentration risk in the exercise design. It recommends identifying systems that could be affected by a cloud outage, assessing relevant third-party and nth-party concentration, and determining whether the institution can obtain sufficient information for decisions such as switching to a backup site. The exercise scenario and response options should reflect the institution’s own risk profile rather than an assumed ability to move providers during an incident.
The BCBS third-party principles the FSA chose to append
Appendix 2 summarises the Basel Committee’s Principles for the Sound Management of Third-Party Risk and adds the FSA’s own dialogue findings and intended next steps. The BCBS published the final principles on 10 December 2025, and they supersede the 2005 Joint Forum paper for the banking sector. Principles 1 to 9 guide banks and Principles 10 to 12 guide supervisors. The BCBS states that the principles are directed to large internationally active banks and their prudential supervisors in BCBS member jurisdictions and are intended to be applied proportionately.
Appendix 2 shows that the FSA is using the BCBS principles as a reference point in its dialogue with selected internationally active institutions. The FSA identifies areas where Japanese practices could be strengthened and states that it will consider, where necessary, clarifying its supervisory approach. The report does not state that all BCBS principles have already been incorporated into binding Japanese requirements.
One caution on status. The BCBS principles are an international standard; they are not directly binding law in Japan by virtue of appearing in an FSA report. Their presence indicates where the FSA’s supervisory expectations are heading and gives firms a reference framework. It does not convert them into a Japanese statutory obligation with a compliance date.
What the report means for cross-border groups
Japanese-headquartered banks and foreign groups with FSA-supervised Japanese entities should map the report to the perimeter and supervisory materials applicable to each Japanese entity. The analytical report is sector-wide, but incident-reporting provisions, forms and reportability thresholds differ by regulated entity type.
Regulation (EU) 2022/2554 has applied since 17 January 2025 to the financial entities within its Article 2 scope, subject to its exclusions and national options. It imposes binding ICT risk-management, major ICT-related incident reporting and ICT third-party-risk requirements on those entities. The FSA report does not claim equivalence with DORA. A DORA operating model may provide reusable governance and control components, but it does not determine the Japanese entity’s reporting threshold, form, follow-up reports or supervisory treatment; those matters require a separate Japanese mapping.
The post-quantum cryptography column states that migration may need to align with five-to-ten-year system-renewal cycles and that financial institutions should begin PQC migration immediately. It records an in-principle 2035 migration target for Japanese government agencies but does not set that date as a deadline for financial institutions. The FSA is also supporting several financial institutions in building cryptographic inventories and intends to publish the resulting methods, practices and responses to implementation challenges.
Where firms tend to misread a supervisory report like this
The report records the FSA’s findings and states that the agency will continue to promote stronger IT resilience through inspections, monitoring, dialogue, information sharing, guidance and exercises. Institutions should assess those findings against their own arrangements without treating the analytical report itself as binding law.
The report says that the FSA will encourage individual and collaborative efforts and provide support through those supervisory and industry-engagement channels. It does not state that every institution must participate in a cloud exercise or that an invitation to an exercise creates a standalone statutory obligation.
The report is not limited to large banks. Part I analyses system-failure reports received from several categories of financial institution under the laws and supervisory materials applicable to each sector, including deposit-taking institutions, insurers, financial instruments business operators, money lenders, payment-service providers and crypto-asset exchange service providers. The applicable notification provision, prescribed form and reportability threshold must therefore be confirmed for the entity’s own regulated sector.
Frequently Asked Questions
Does the FSA IT resilience report create a new reporting obligation for Japanese institutions?
No. The analytical report does not itself create a new return. Existing sector-specific supervisory materials govern system-failure reporting. For major banks, the current guideline requires immediate notification of a reportable system failure or cybersecurity incident, submission of the applicable report, and follow-up reporting on recovery and cause identification. The FSA may require additional reporting under Article 24 of the Banking Act where necessary. The analytical report uses information received under laws and supervisory materials but does not add a separate notification.
Which institutions are in scope of the report’s expectations?
The report addresses the financial sector broadly, and Part I draws on system-failure reports from several regulated sectors. The governing notification provision, prescribed form and reportability threshold are nevertheless sector-specific. A non-bank entity must use the supervisory guideline or other legal instrument applicable to its own authorisation rather than the banking reporting provision or banking form.
How does a Japanese system-failure notification differ from a DORA major-incident report for a group that has both?
They are separate obligations with different triggers, timelines and recipients, even when they describe the same outage. A group with a Japanese entity and a European entity may owe a notification to the FSA and a major ICT-related incident report under Regulation (EU) 2022/2554 in parallel. Neither discharges the other. The practical task is a mapping that starts from the incident and produces each jurisdiction’s filing.
Are the BCBS third-party principles mandatory in Japan because the FSA appended them?
Not by that appendix alone. The BCBS Principles for the Sound Management of Third-Party Risk are an international standard finalised on 10 December 2025. Including them in Appendix 2 signals the direction of the FSA’s supervisory expectations and gives firms a reference framework. Legal obligations in Japan flow from Japanese law and the FSA’s own guidelines, and the Basel text as such does not create them.
Is participation in the FSA’s cloud resilience exercises compulsory?
Participation in FSA cloud resilience exercises carries no standalone statutory obligation. The report describes an FSA-led tabletop exercise involving financial institutions and public-cloud providers and recommends that institutions expanding, or considering, public-cloud use for important systems use the chapter as a reference when deciding, on a risk basis, whether and how to conduct exercises with relevant parties.
Does the report change any capital or prudential reporting requirement?
No. It concerns operational and cyber resilience, and it does not amend a capital calculation or a supervisory reporting template. Its consequences show up in supervisory dialogue, inspection focus and exercise participation.
Is there a deadline attached to the post-quantum cryptography column?
The report sets no migration deadline for financial institutions, but its message is stronger than an early signal: it states that financial institutions should begin PQC migration immediately. It also records an in-principle 2035 target for Japanese government agencies and describes FSA-supported work with several financial institutions to build cryptographic inventories.
Related Articles
- ESAs DORA ICT Incident Annual Report 2025: how European supervisors aggregate and analyse ICT incidents, the closest counterpart to the FSA’s system-failure analysis.
- DORA ICT Incident Reporting: the European trigger, classification and timing a cross-border group would run alongside a Japanese system-failure notification.
- DORA Register of Information: how the EU requires firms to catalogue their ICT third-party arrangements, the register discipline the BCBS principles also expect.
- PRA SS2/21 Outsourcing Register and Notification Duties: the UK approach to third-party registers and notification, a reference point for aligning group vendor governance.
- STAR-FS and DORA Threat-Led Penetration Testing: how intelligence-led attack simulation is scoped and evidenced, relevant to Part III’s cyber themes.
Key Takeaways
- The FSA published its 2026 Analytical Report on IT Resilience in the Financial Sector on 30 July 2026. It is supervisory analysis and does not itself create a new reporting return.
- The executive summary states that management needs to recognise IT and cyber risks as top management risks and continuously review and strengthen governance, risk-management frameworks, investment, human-resource development and third-party risk management.
- Part I analyses system-failure reports received from several regulated sectors under sector-specific laws and supervisory materials. For major banks, the current guideline requires immediate notification, the applicable written report, later reporting on recovery and cause identification, and a current-status report within one month where the matter remains unresolved.
- Part IV reports a risk-based tabletop exercise focused on cloud-outage information flows, decision-making, concentration risk and updates to incident and contingency plans; it is not presented as a live recovery-time test.
- Appendix 2 summarises the BCBS third-party-risk principles and records the FSA’s dialogue findings and intended next steps. The appendix does not itself make the BCBS principles binding Japanese law.
- Where both regimes are triggered, Japanese system-failure reporting and DORA major ICT-related incident reporting must be mapped separately because their entity scope, classification criteria, forms, timing and recipients differ.
- The PQC column sets no migration deadline for financial institutions, but states that financial institutions should begin migration immediately and describes FSA-supported cryptographic-inventory work with several institutions.
Sources and References
- Financial Services Agency, “Publication of Analytical Report on IT Resilience in the Financial Sector” (30 July 2026): https://www.fsa.go.jp/en/news/2026/20260730/20260730.html
- Financial Services Agency, Analytical Report on IT Resilience in the Financial Sector, Executive Summary (July 2026, PDF): https://www.fsa.go.jp/en/news/2026/20260730/02_en.pdf
- Financial Services Agency, Comprehensive Guidelines for Supervision of Major Banks, etc. (Japanese, current July 2026 version), III-3-7-1-3: https://www.fsa.go.jp/common/law/guide/city/03c2.html
- e-Gov Law Search, Banking Act (Act No. 59 of 1981), Article 24 (Japanese): https://laws.e-gov.go.jp/law/356AC0000000059
- Basel Committee on Banking Supervision, “Principles for the sound management of third-party risk” (10 December 2025): https://www.bis.org/bcbs/publ/d605.htm
- Bank for International Settlements, press release on the final third-party risk principles (10 December 2025): https://www.bis.org/press/p251210.htm
- Regulation (EU) 2022/2554 (Digital Operational Resilience Act), EUR-Lex: https://eur-lex.europa.eu/eli/reg/2022/2554/oj
The board-level test the FSA is now setting
The report’s stated management message is to review and strengthen governance, risk-management frameworks, investment, human-resource development and third-party risk management continuously. Its more specific actions include considering risk-based tabletop exercises for cloud-outage information flows and beginning PQC migration immediately. These are supervisory messages in an analytical report, not a new reporting return or a statutory compliance deadline created by the report itself.
Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.
