Regulatory Updates

Regulatory updates from the EBA, ECB, ESMA, FCA, PRA, and other competent authorities, with practical analysis of what changes for reporting teams. Coverage includes EBA framework releases (4.x DPM packages), CRR3 implementation milestones, MiCAR and AML rule developments, sanctions packages, supervisory reporting simplification proposals, CSRD sustainability reporting, and resolution framework changes (CMDI, MREL, SRB consultations). Each article translates the regulator’s announcement into what your firm needs to map, prepare, or change before the deadline. The focus is on banks, fund administrators, payment institutions, CRA-regulated firms, and supervised investment firms across the EU and UK. Use this section to track upcoming compliance deadlines and consultation responses.

  • SRB Resolution Planning: Simpler Procedures, Same MREL Bar

    On 15 July 2026 the SRB Chair told the European Parliament’s ECON Committee that the Single Resolution Board is simplifying resolution planning wherever its mandate allows, and drew a firm line around what simplification will and will not touch. For teams that run SRB resolution planning, the speech matters as a direction of travel: the…

  • FCA Asset Management Reform: The £128m Rulebook Package

    On 14 July 2026 the Financial Conduct Authority opened three linked consultations that together make up its asset management reform package, a set of proposals the regulator estimates would save UK asset managers around £128m a year. The three papers cover fund reporting, the alternative investment fund manager regime, and the remuneration rules that apply…

  • ESRB Frontier AI Warning: DORA Cyber Risk Reporting Under Scrutiny

    On 7 July 2026 the European Systemic Risk Board published a formal warning that frontier artificial intelligence models are now a source of systemic cyber risk with direct implications for DORA cyber risk reporting across the EU financial system, and the three European Supervisory Authorities backed it the same day. On the same date, ECB…

  • CSSF AI Communique: Mapping Frontier Cyber Risk to DORA

    On 7 July 2026 the Commission de Surveillance du Secteur Financier (CSSF) published a communique, “Evolving opportunities and risks in artificial intelligence and its adoption”, addressed to the entities it supervises. The CSSF AI communique responds to a specific concern: frontier AI models have the potential to shrink drastically the gap between vulnerability disclosure and…

  • DORA ICT-Risk Reporting: Reading KNF’s 2026 Cyber-Threat Report

    On 9 July 2026, CSIRT KNF, the cyber-incident response team inside Poland’s Financial Supervision Authority, refreshed its report on the cyber threats facing the Polish financial sector for 2026. The document reads like a briefing pack rather than a rulebook: the priority attack scenarios, the techniques criminals are stacking into single campaigns, and the risks…

  • UK Critical Third Parties Regime: 13 July 2026 Go-Live

    On 13 July 2026 the Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority begin overseeing the first firms brought inside the UK Critical Third Parties regime. HM Treasury announced the designations three days earlier, on 10 July 2026, but the designations themselves take legal effect only from 13 July 2026, the…

  • FSB Cross-Sectoral Resolution Planning: The ReSolve Signal for Banks

    On 9 July 2026, the Financial Stability Board put bank, financial-market-infrastructure and insurance resolution experts in the same room and told them to stop planning in parallel. The occasion was the FSB’s ReSolve event for its Cross-Border Crisis Management working groups, and the framing came from FSB Secretary General John Schindler: the financial system is…

  • EMIR CCP Admission Criteria: The New RTS for Clearing Members

    On 8 July 2026 the European Securities and Markets Authority published its final report on the technical standards that flesh out how EU central counterparties must build their CCP admission criteria (ESMA91-1505572268-4692). The standards sit under Article 37(7) of EMIR, the participation-requirements article that Regulation (EU) 2024/2987, better known as EMIR 3, rewrote when it…

  • ECB AI Cybersecurity Letter: The 31 October 2026 JST Action Plan

    On 7 July 2026, the Chair of the ECB Supervisory Board, Claudia Buch, wrote to the CEO of every significant institution under a letter numbered SSM-2026-0301 and titled “Addressing AI-enabled cybersecurity threats”. The ECB AI cybersecurity letter does one operationally concrete thing behind its strategic language: it gives each directly supervised bank until 31 October…

  • EU Taxonomy Disclosure Simplification: The 12 August ESMA Deadline

    On 1 July 2026 the three European Supervisory Authorities each opened a consultation on rewriting the Key Performance Indicators that firms disclose under Article 8 of the EU Taxonomy Regulation. ESMA published a Consultation Paper, the European Banking Authority a Discussion Paper, and EIOPA a consultation on the insurance side. All three close on 12…