Regulatory Updates

Regulatory updates from the EBA, ECB, ESMA, FCA, PRA, and other competent authorities, with practical analysis of what changes for reporting teams. Coverage includes EBA framework releases (4.x DPM packages), CRR3 implementation milestones, MiCAR and AML rule developments, sanctions packages, supervisory reporting simplification proposals, CSRD sustainability reporting, and resolution framework changes (CMDI, MREL, SRB consultations). Each article translates the regulator’s announcement into what your firm needs to map, prepare, or change before the deadline. The focus is on banks, fund administrators, payment institutions, CRA-regulated firms, and supervised investment firms across the EU and UK. Use this section to track upcoming compliance deadlines and consultation responses.

Reporting guides

Browse all guides in this framework →
  • STAR-FS and DORA TLPT: Threat-Led Testing for Firms in Both Regimes

    A UK banking group with an EU financial entity identified by its competent authority for DORA threat-led penetration testing may be subject to STAR-FS in the UK and DORA TLPT in the EU at the same time. The Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority maintain STAR-FS, the Simulated Targeted…

  • EU T+1 Settlement: First Deadline Is 7 December 2026

    The European Union will move to a T+1 securities settlement cycle on 11 October 2027. ESMA identifies 7 December 2026 as the first regulatory deadline for allocations and confirmations. The European Commission adopted the amending Delegated Regulation on 6 July 2026 as C(2026) 4640 final; it is currently under scrutiny by the European Parliament and…

  • MiFID II Triangular Passporting: ESMA’s July 2026 Supervisory Briefing

    On 7 July 2026 ESMA published a supervisory briefing on triangular passporting under MiFID II (reference ESMA35-243228190-8065), and the CSSF relayed it to Luxembourg professionals in a communique dated 17 July 2026. Triangular passporting is the arrangement where an authorised investment firm serves clients in one Member State through a branch or tied agent it…

  • EU Banking Competitiveness Communication: The Q1 2027 Reform Roadmap

    On 17 July 2026 the European Commission published its Communication on the Competitiveness of the Banking Sector and the Single Market in Banking, filed as COM(2026) 615 final with an accompanying Staff Working Document, SWD(2026) 615 final. It changes no reporting obligation the day it lands. What it does is set out the shape of…

  • ESMA Risk Management Function CSA: The 2026-2027 Supervisory Review

    On 3 July 2026, ESMA told every UCITS management company and alternative investment fund manager in the European Union that their risk management function is next in line for coordinated scrutiny. The announcement launched a Common Supervisory Action, an exercise ESMA will run with national competent authorities throughout 2026 and 2027, with a final report…

  • SRB Resolution Planning: Simpler Procedures, Same MREL Bar

    On 15 July 2026 the SRB Chair told the European Parliament’s ECON Committee that the Single Resolution Board is simplifying resolution planning wherever its mandate allows, and drew a firm line around what simplification will and will not touch. For teams that run SRB resolution planning, the speech matters as a direction of travel: the…

  • FCA Asset Management Reform: The £128m Rulebook Package

    On 14 July 2026 the Financial Conduct Authority opened three linked consultations that together make up its asset management reform package, a set of proposals the regulator estimates would save UK asset managers around £128m a year. The three papers cover fund reporting, the alternative investment fund manager regime, and the remuneration rules that apply…

  • ESRB Frontier AI Warning: DORA Cyber Risk Reporting Under Scrutiny

    On 7 July 2026 the European Systemic Risk Board published a formal warning that frontier artificial intelligence models are now a source of systemic cyber risk with direct implications for DORA cyber risk reporting across the EU financial system, and the three European Supervisory Authorities backed it the same day. On the same date, ECB…

  • CSSF AI Communique: Mapping Frontier Cyber Risk to DORA

    On 7 July 2026 the Commission de Surveillance du Secteur Financier (CSSF) published a communique, “Evolving opportunities and risks in artificial intelligence and its adoption”, addressed to the entities it supervises. The CSSF AI communique responds to a specific concern: frontier AI models have the potential to shrink drastically the gap between vulnerability disclosure and…

  • DORA ICT-Risk Reporting: Reading KNF’s 2026 Cyber-Threat Report

    On 9 July 2026, CSIRT KNF, the cyber-incident response team inside Poland’s Financial Supervision Authority, refreshed its report on the cyber threats facing the Polish financial sector for 2026. The document reads like a briefing pack rather than a rulebook: the priority attack scenarios, the techniques criminals are stacking into single campaigns, and the risks…