Author: RegReportingDesk

  • CSSF AI Communique: Mapping Frontier Cyber Risk to DORA

    On 7 July 2026 the Commission de Surveillance du Secteur Financier (CSSF) published a communique, “Evolving opportunities and risks in artificial intelligence and its adoption”, addressed to the entities it supervises. The CSSF AI communique responds to a specific concern: frontier AI models have the potential to shrink drastically the gap between vulnerability disclosure and…

  • Payments Vision Delivery Committee Update: The 11 September Deadline

    On 2 July 2026 the Payments Vision Delivery Committee published an update on roles and responsibilities in the future retail payments ecosystem. The FCA and PSR published same-day statements directing stakeholders to it, while HM Treasury published the update on GOV.UK. It reads like a background note. It is closer to a pricing document. The…

  • EBA Reporting Framework 4.3: TCB and AMLA Reporting From 2027

    On 9 July 2026 the European Banking Authority published the final technical package for version 4.3 of its supervisory reporting framework, and with it two build deadlines that reporting teams can no longer treat as roadmap items. The EBA reporting framework 4.3 package carries the standard specifications for two separate obligations: supervisory reporting by third-country…

  • DORA ICT-Risk Reporting: Reading KNF’s 2026 Cyber-Threat Report

    On 9 July 2026, CSIRT KNF, the cyber-incident response team inside Poland’s Financial Supervision Authority, refreshed its report on the cyber threats facing the Polish financial sector for 2026. The document reads like a briefing pack rather than a rulebook: the priority attack scenarios, the techniques criminals are stacking into single campaigns, and the risks…

  • UK Critical Third Parties Regime: 13 July 2026 Go-Live

    On 13 July 2026 the Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority begin overseeing the first firms brought inside the UK Critical Third Parties regime. HM Treasury announced the designations three days earlier, on 10 July 2026, but the designations themselves take legal effect only from 13 July 2026, the…

  • APRA Minor Updates to the Prudential Framework: What ADIs Must Check

    On 10 July 2026, APRA opened its consultation on the 2026 APRA minor updates to the prudential and reporting framework. APRA describes the package as primarily technical clarifications without a material change in policy settings, but several proposals affect prudential calculations or reporting instructions. For ADIs, APS 120 would increase the credit conversion factor for…

  • SS2/21 Outsourcing: The PRA Register and Notification Guide

    SS2/21 is the PRA’s supervisory statement on outsourcing and third-party risk management. Its main scope covers UK banks, building societies and PRA-designated investment firms; insurance and reinsurance firms and groups in scope of Solvency II, including Lloyd’s and managing agents; and UK branches of overseas banks and insurers. It has been the working reference for…

  • FSB Cross-Sectoral Resolution Planning: The ReSolve Signal for Banks

    On 9 July 2026, the Financial Stability Board put bank, financial-market-infrastructure and insurance resolution experts in the same room and told them to stop planning in parallel. The occasion was the FSB’s ReSolve event for its Cross-Border Crisis Management working groups, and the framing came from FSB Secretary General John Schindler: the financial system is…

  • APRA ECAI Recognition Guidelines: What ADIs Must Check in APS 112

    APRA ECAI recognition matters where APS 112 uses an external rating to determine a credit rating grade and risk weight. Many other standardised-approach exposures are risk-weighted under prescribed exposure-class, loan-to-value, default-status or other rules that do not depend on an ECAI rating. On 9 July 2026, APRA republished the guidelines that govern that recognition, after…