Articles

  • ESRB Frontier AI Warning: DORA Cyber Risk Reporting Under Scrutiny

    On 7 July 2026 the European Systemic Risk Board published a formal warning that frontier artificial intelligence models are now a source of systemic cyber risk with direct implications for DORA cyber risk reporting across the EU financial system, and the three European Supervisory Authorities backed it the same day. On the same date, ECB…

  • ESAP First Phase: Where Regulated Disclosures Must Now Be Filed

    On 10 July 2026, ESMA started pulling regulated disclosures into the European Single Access Point (ESAP). The public ESAP portal is not yet accessible; Regulation (EU) 2023/2859 requires ESMA to establish and operate it by 10 July 2027. What went live on 10 July was the plumbing underneath it: from that date, Officially Appointed Mechanisms…

  • IFRS 18 FINREP Reporting: The Interim Templates Banks Can File Early

    For annual reporting periods beginning on or after 1 January 2027, IFRS reporters must apply IFRS 18 unless they adopt it earlier. On the supervisory-reporting side, the affected population is the institutions inside FINREP’s IFRS scope under Article 430(3) or (4) of the Capital Requirements Regulation (CRR), not every bank that happens to use IFRS…

  • CSSF AI Communique: Mapping Frontier Cyber Risk to DORA

    On 7 July 2026 the Commission de Surveillance du Secteur Financier (CSSF) published a communique, “Evolving opportunities and risks in artificial intelligence and its adoption”, addressed to the entities it supervises. The CSSF AI communique responds to a specific concern: frontier AI models have the potential to shrink drastically the gap between vulnerability disclosure and…

  • Payments Vision Delivery Committee Update: The 11 September Deadline

    On 2 July 2026 the Payments Vision Delivery Committee published an update on roles and responsibilities in the future retail payments ecosystem. The FCA and PSR published same-day statements directing stakeholders to it, while HM Treasury published the update on GOV.UK. It reads like a background note. It is closer to a pricing document. The…

  • EBA Reporting Framework 4.3: TCB and AMLA Reporting From 2027

    On 9 July 2026 the European Banking Authority published the final technical package for version 4.3 of its supervisory reporting framework, and with it two build deadlines that reporting teams can no longer treat as roadmap items. The EBA reporting framework 4.3 package carries the standard specifications for two separate obligations: supervisory reporting by third-country…

  • DORA ICT-Risk Reporting: Reading KNF’s 2026 Cyber-Threat Report

    On 9 July 2026, CSIRT KNF, the cyber-incident response team inside Poland’s Financial Supervision Authority, refreshed its report on the cyber threats facing the Polish financial sector for 2026. The document reads like a briefing pack rather than a rulebook: the priority attack scenarios, the techniques criminals are stacking into single campaigns, and the risks…

  • UK Critical Third Parties Regime: 13 July 2026 Go-Live

    On 13 July 2026 the Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority begin overseeing the first firms brought inside the UK Critical Third Parties regime. HM Treasury announced the designations three days earlier, on 10 July 2026, but the designations themselves take legal effect only from 13 July 2026, the…

  • APRA Minor Updates to the Prudential Framework: What ADIs Must Check

    On 10 July 2026, APRA opened its consultation on the 2026 APRA minor updates to the prudential and reporting framework. APRA describes the package as primarily technical clarifications without a material change in policy settings, but several proposals affect prudential calculations or reporting instructions. For ADIs, APS 120 would increase the credit conversion factor for…