Articles

  • Harmonised ISO 20022 Data Requirements: The 2027 Alignment Window

    On 26 February 2026 the Committee on Payments and Market Infrastructures (CPMI) published an updated set of harmonised ISO 20022 data requirements for enhancing cross-border payments, replacing the report it delivered to the G20 in October 2023. The document and technical annex recommend that payment system operators and participants align their ISO 20022 usage guidelines…

  • Basel Committee ICT Risk Management: The Four Root Causes of Incidents

    On 2 June 2026 the Basel Committee on Banking Supervision published a range-of-practices report on information and communication technology (ICT) risk management. It draws on a survey of 16 jurisdictions and centres on how global and domestic systemically important banks handle the technology failures that take critical services offline. The Basel Committee ICT risk management…

  • November 2026 TARGET Services Release: ECB Reassesses the Timeline

    On 28 August 2026 the ECB confirmed that the Eurosystem is reassessing the timeline for the November 2026 TARGET Services release. TARGET Services comprise T2 for settling payments, T2S for settling securities, TIPS for settling instant payments and the ECMS for collateral management, so release-calendar changes can affect participants across several Eurosystem market infrastructures. The…

  • SEPA Structured Address Deadline: Why 15 November 2026 Still Stands

    On 28 August 2026 the European Payments Council (EPC) confirmed that its 15 November 2026 end-date for the fully unstructured address format in SEPA scheme messages still stands. The confirmation landed one day after Swift said, on 27 August 2026, that it would extend the migration period for structured addresses in cross-border ISO 20022 payment…

  • ECB IT Risk Questionnaire: How the ITRQ Feeds Your SREP Score

    The ECB IT Risk Questionnaire (ITRQ) is where a significant institution puts a number on its own ICT risk before its Joint Supervisory Team does. Every bank under direct ECB supervision completes the workbook once a year, scoring its inherent ICT risk and the maturity of the controls that mitigate it. The 2026 questionnaire covers…

  • CSSF Circular 26/915: DORA Circulars Re-Mapped for Third-Country Branches

    On 27 August 2026 the CSSF published Circular 26/915, and it applies with immediate effect. Circular CSSF 26/915 updates the Luxembourg ICT and outsourcing circular framework following the European Commission position on DORA’s applicability to third-country branches. It removes the TCB categories within the CSSF’s remit from the relevant pre-DORA circular provisions and maps them…

  • RBA Payments System Board August 2026: A2A, RITS and Cash Outcomes

    On 27 August 2026 the Reserve Bank of Australia’s Payments System Board met and reported developments across four areas: it endorsed the annual assessment of ASX’s clearing and settlement facilities against the Financial Stability Standards, discussed progress on the account-to-account (A2A) payments roadmap, endorsed the proposed approach to consulting on the future role of the…

  • DORA for Third-Country Branches in Luxembourg: Circular CSSF 26/915

    On 27 August 2026 the CSSF issued Circular CSSF 26/915, applicable with immediate effect, to bring specified third-country branches into the CSSF circular framework for DORA. For Luxembourg purposes, the governing scope is the branch perimeter set out in Circular CSSF 26/915 and in each amended circular; the change is not a blanket head-office-only test…

  • BoE Delays November 2026 RTGS Standards Release: CHAPS Roadmap Reset

    The Bank of England will not run its November 2026 RTGS standards release. On 27 August 2026 the Bank confirmed it is deferring that release in its entirety, including the messaging standards for CHAPS payments, after Swift announced its decision to delay the November 2026 Swift Standards Release. For any CHAPS direct participant that had…

  • EBA Operational Risk RTS: The 31 December 2026 Consultation Deadline

    On 26 August 2026 the European Banking Authority opened a four-month consultation on draft Regulatory Technical Standards that will spell out, article by article, the operational risk management framework every institution subject to the Capital Requirements Regulation has to run. The mandate sits in Article 323(2) of Regulation (EU) No 575/2013 (the CRR), as amended…