ECB IT Risk Questionnaire: How the ITRQ Feeds Your SREP Score
The ECB IT Risk Questionnaire (ITRQ) is where a significant institution puts a number on its own ICT risk before its Joint Supervisory Team does. Every bank under direct ECB supervision completes the workbook once a year, scoring its inherent ICT risk and the maturity of the controls that mitigate it. The 2026 questionnaire covers the reference period 1 January 2025 to 31 December 2025 and was due, at the latest, by 27 February 2026. The ITRQ responses feed into the ECB’s SREP assessment, but the institution’s self-assigned ITRL and ITRC grades are not themselves the supervisory SREP score. The ECB’s published operational and ICT risk methodology uses responses to the regular ITRQ as additional supervisory data. JSTs assess ICT risk level and ICT risk control using a wider set of quantitative and qualitative information and then apply constrained supervisory judgement.
The ECB has published the 2026 ITRQ for transparency and accountability, including the questionnaire content and its guidance in the published document. That makes it a rare chance to see, field by field, what supervisors expect institutions to be able to evidence about their IT estate. It also removes any excuse for running the questionnaire as a form-filling exercise divorced from the SREP score it feeds.
The ECB requires the supervised entity to complete the questionnaire and reconcile its scope, but the published ITRQ does not prescribe which internal function must own the submission. Get the self-assessment wrong and you either understate a risk your supervisor already knows about, or you flag a control weakness you cannot defend in the follow-up dialogue.
Related reading: ECB SREP 2026 priorities
The ITRQ calendar at a glance
The questionnaire is a deadline-driven, annual collection with a fixed reference year. The 2026 questionnaire covered the reference period 1 January 2025 to 31 December 2025 and was due, at the latest, by 27 February 2026. Two further dates frame the legal environment: EBA/GL/2017/05 will be repealed and replaced from 1 January 2027, and the revised SREP Guidelines that consolidate the standalone ICT-risk guidelines were published by the EBA on 26 June 2026.
The published 2025 and 2026 questionnaires used calendar-year reference periods and late-February deadlines, but the 2026 publication does not set the deadline for the next cycle. Banks can prepare the underlying evidence during 2026, but the next submission date remains unconfirmed until the ECB or JST issues the next collection.
What the ITRQ collects, tab by tab
The published 2026 ITRQ contains 33 numbered questionnaire pages organised by tab, including sections to be completed and scoring-guidance sections. The Overview tab tracks completion rates for each section a bank has to fill in, which tells you the ECB reads the workbook as a controlled data submission with defined completion fields.
The core input tabs cover six areas. The General Data tab provides an ICT overview of the entity, including total headcount, permanent and fixed-term ICT FTEs, temporary ICT personnel, and separate first-, second- and third-line ICT personnel fields. The Entities in scope tab reconciles the questionnaire perimeter against the prudential scope of consolidation. From there, the two self-assessment tabs carry the analytical weight: ICT Risk Level (ITRL) asks the firm to score its overall inherent risk across four ICT risk areas, while ICT Risk Control (ITRC) asks it to score the maturity of the controls that address those risks. Two further tabs are operational: Gross costs and losses collects aggregated annual costs, losses and recoveries from major ICT-related incidents, and Information-sharing arrangements records the entity’s memberships of cyber threat information-exchange arrangements.
Two additional tabs, the ITRL and ITRC guidance, exist purely to anchor the scoring so that the same question means the same thing across every bank in the sample. A glossary defines the terms that supervisors know get read inconsistently. The design intent is comparability: the ECB and the national competent authorities built the ITRQ so that the results can be run through thematic reviews and horizontal analyses across the whole population of directly supervised banks, so no single file is read in isolation.
Two scores, two different questions: ITRL versus ITRC
The heart of the questionnaire is a pair of self-assessments that answer different questions, and confusing them is the fastest way to produce an internally inconsistent return.
The ITRL measures inherent risk. In the 2026 ITRQ, a bank scores four ITRL categories on a scale from 1 (lowest exposure) to 4 (highest exposure): ICT security risk, ICT availability and continuity risk, ICT change risk and ICT data integrity risk. The guidance says the assessment should reflect inherent risks, relevant key risk indicators, potential losses, and results from on-site inspections, internal audits and other relevant reviews. EBA/GL/2017/05 also defines ICT outsourcing risk, but the 2026 workbook does not present it as a separate ITRL scoring category; ICT third-party risk is addressed elsewhere in the questionnaire.
The ITRC measures control maturity, and it runs on its own 1 to 4 scale where 1 means the best controls are in place and 4 means controls are not in place or risks are not effectively mitigated. The guidance frames maturity against criteria such as whether controls are documented with a named owner and whether they are formally tested by management on a regular basis. Many of the ITRC questions map directly onto DORA obligations, for example whether the management body keeps its ICT knowledge current, whether the entity maintains an inventory of ICT-supported business functions and information assets, and whether it tracks its dependencies on ICT third-party providers.
Reading the two scales as a single axis where a high number is always bad leads to internally inconsistent submissions. A bank can legitimately carry high inherent risk and strong controls at the same time: an ITRL of 3 on security risk paired with an ITRC of 1 says the exposure is real but well managed. What supervisors pursue is the mismatch that does not add up, such as a low inherent-risk score sitting next to a control set the bank admits is immature, or a strong control score that its own audit reports contradict.
How the ECB IT Risk Questionnaire feeds the SREP operational and ICT risk assessment
The reason the ITRQ carries weight is the SREP plumbing behind it. EBA/GL/2017/05 was drawn up under Article 107(3) of the Capital Requirements Directive to converge how competent authorities assess ICT risk within the SREP referred to in Article 97 of that directive. The methodology runs in a fixed order: competent authorities first identify the material inherent ICT risks the institution faces, then assess how effectively the institution’s ICT risk management framework, procedures and controls mitigate them. That inherent-risk-then-controls structure is the same shape as the ITRL and ITRC self-assessments, which is why the questionnaire slots so cleanly into the supervisory process.
For significant institutions, the ECB’s current SREP methodology assesses operational risk and ICT risk as a combined element. The ICT risk assessment produces a summary of findings that feeds into the operational risk score; where ICT risk is deemed material, supervisors may assign it an individual score as a sub-category of operational risk. The combined operational risk score (informed by ICT risk findings) is expressed on a 1-to-4 scale with qualifiers, and the ITRQ is one of the additional supervisory data sources used in that assessment.
Self-assessed scores function as one input to the JST’s supervisory assessment. The Joint Supervisory Team uses the ITRQ alongside on-site inspection findings, internal and external audit results, incident and loss data and the management information the bank feeds its own board, and it forms its own supervisory judgement. A bank that scores itself generously and cannot back the number with evidence has not improved its SREP outcome; it has handed the supervisor a documented inconsistency to open on. The questionnaire that helps a bank is the one whose scores it can defend line by line.
For the operational-risk context around this, our COREP reporting guide covers how the quantitative operational risk own funds requirements are reported, which sits alongside the qualitative SREP assessment the ITRQ informs.
Where DORA now sits inside the questionnaire
The ECB states that the 2026 questionnaire is designed in accordance with both EBA/GL/2017/05 and Regulation (EU) 2022/2554 (DORA). The workbook links the Gross costs and losses tab to DORA Article 11(10) and the Joint Guidelines, and the Information-sharing arrangements tab to DORA Article 45. The ECB notice does not describe DORA as a separate legal basis for the questionnaire.
The Gross costs and losses tab collects aggregated annual costs, losses and financial recoveries from major ICT-related incidents in line with DORA Article 11(10) and the EBA Joint Guidelines on the estimation of aggregated annual costs and losses caused by major ICT-related incidents (JC/GL/2024/34). The workbook asks for per-incident lines, each with the incident reference number, the date the final incident report was submitted, and the gross costs or losses and recoveries expressed in thousands of units, plus a total for the reference year. That basis matters: a figure keyed in the wrong units, or a total that does not reconcile to the incident-by-incident lines, is a data-quality flag before any risk judgement is even reached.
The Information-sharing arrangements tab records the entity’s participation in cyber threat information-exchange arrangements under DORA Article 45, capturing the name of each arrangement, the scope of information exchanged, and the dates membership was validated and, where relevant, ceased. The ITRC questions, in turn, are drafted around DORA’s ICT risk management framework, including the framework requirement in Article 6(1) and the detail in the ICT risk management RTS (Commission Delegated Regulation (EU) 2024/1774). If your DORA programme and your ITRQ answers are owned by different teams, this is where they have to reconcile.
These tabs are close cousins of your other DORA obligations without duplicating them. The ITRQ aggregates annual cost and loss data, while incident-by-incident supervisory reporting runs on its own track. The ITRQ Gross costs and losses data should reconcile to the relevant major-incident population and related cost/loss data. The DORA register of information is a separate dataset on contractual arrangements for ICT services; it should be reconciled with ITRQ fields only where the underlying third-party information genuinely overlaps.
Scope: what “the supervised entity” actually means here
The perimeter of the questionnaire is wider than the single legal entity that receives it. A supervised entity must complete the ITRQ covering all entities it owns, including owned subsidiaries, or that it supervises. The ITRQ covers all entities owned or supervised by the legal entity receiving the questionnaire. Where several legal entities provide ICT services, the ECB expects a comprehensive description of controls at the highest level of consolidation; the Entities in scope tab reconciles the questionnaire perimeter against the prudential scope of consolidation.
This is also where the population boundary sits. The ITRQ is a standardised collection from significant institutions under the direct supervision of the ECB. Less significant institutions supervised by national competent authorities are outside this particular ECB collection. DORA applies independently according to its own scope and proportionality rules, and national competent authorities may use their own ICT supervisory tools. Reading the ITRQ as a pan-European reporting return for every bank overstates its reach; it is an ECB direct-supervision instrument first.
Preparing answers you can defend
Because the score is only as good as the evidence behind it, the real preparation work is assembling that evidence before the scores are keyed. The questionnaire guidance itself points to the sources: on-site inspection results, internal audit findings and other reviews for the ITRL, and control documentation, ownership and formal testing for the ITRC. The ECB methodology identifies internal management data, ICAAP reports and internal audit reports as examples of additional information that JSTs may consider, alongside ITRQ responses and other supervisory data.
Two mechanical points reward attention. First, the workbook asks whether the definition of an item has changed materially since last year’s reporting, and it asks for explanations where a self-assessment score deviates from the prior year. A score that moves without a documented reason is a question waiting to be asked, so the delta commentary is not optional colour. Second, the data integrity questions turn on whether golden sources are defined for critical or important functions and whether manual inputs and transfers are under control. A bank that reports its supervisory data through spreadsheets it cannot fully control is describing a data integrity weakness in the same file it uses to attest to data quality.
The governance thread runs through all of it. The ITRC asks whether the management body actively keeps up to date sufficient ICT knowledge and skills, reflecting DORA Article 5(4). The ECB methodology supports use of ITRQ information within the ICT risk-control assessment; the primary sources reviewed do not establish a direct mapping of this answer into the separate SREP internal-governance score. The ECB methodology identifies ICAAP reports as one possible source of additional information for the operational and ICT risk assessment. The primary sources reviewed do not establish a prescribed ITRQ-to-ILAAP mapping.
What changes when the ICT SREP Guidelines are repealed in 2027
The supervisory framework around the ITRQ is changing. The EBA published revised SREP Guidelines on 26 June 2026; they will apply from 1 January 2027 and will repeal and replace EBA/GL/2017/05. The EBA’s 23 February 2026 follow-up peer review assessed progress against the recommendations made in its 2022 report in light of DORA and the forthcoming integration. The EBA described that integration as a key recommendation of the 2022 report, and the 2026 follow-up concluded that no further recommendations were necessary.
The ECB has not confirmed the 2027 ITRQ cycle in the primary sources reviewed. Its 2026 notice states that the ITRQ is a standardised regular data collection and may be updated to reflect changes in regulation and best practice. That supports possible continuity with amendment, but it does not establish that the instrument will persist after EBA/GL/2017/05 is repealed.
The supervisory direction reinforces the point. Operational resilience and banks’ ICT capabilities form one of the ECB’s two supervisory priorities for 2026 to 2028, with expectations centred on full DORA implementation, ICT third-party risk and long-standing weaknesses in cybersecurity, outsourcing management and risk data. Institutions that keep the ITRQ aligned with that evolving agenda will find the follow-up dialogue easier. Our guide to ECB on-site inspections and timely remediation covers how the supervisor tests those same weaknesses on the ground.
Frequently Asked Questions
Do less significant institutions have to complete the ITRQ?
No. The ITRQ is a standardised collection from significant institutions under the direct supervision of the ECB. Less significant institutions are supervised by their national competent authority, which may run its own ICT supervisory tools. DORA applies to those firms according to its own scope and proportionality rules, but the ECB ITRQ is not addressed to less significant institutions as a class.
What do we enter in the gross costs and losses tab if we had no major ICT-related incidents in the reference year?
The tab is built around DORA Article 11(10) and JC/GL/2024/34. The published 2026 workbook contains a total field, while the Joint Guidelines specify the incidents that must be included and the per-incident breakdown; neither source reviewed states the data-entry convention to use when there are no qualifying incidents. Follow the ECB/JST submission instruction for nil treatment rather than assuming that a zero entry is required.
How is the ITRQ different from our DORA incident reports and register of information?
They are separate instruments with different data structures. DORA major-incident reporting is incident-specific and time-bound, while the register of information records contractual arrangements for ICT services. The 2026 ITRQ collects annual major-incident cost/loss data, information-sharing memberships and broader ICT self-assessment information. The ITRQ cost/loss lines should reconcile to the relevant incident population; register-of-information data should be reconciled only where fields or underlying third-party inventories overlap.
Can our ITRL and ITRC scores differ from last year, and do we have to explain why?
Yes. The workbook explicitly asks for explanations where a self-assessment score deviates from the prior year, and whether the definition of an item has changed materially. An unexplained movement in either direction invites a supervisory question, so the delta commentary should carry the reasoning and the evidence.
Does a poor control maturity score push up our capital requirement?
An ITRC maturity score is one input to the JST’s supervisory judgement; it does not convert into a capital add-on through a formula in the questionnaire. For significant institutions, JSTs use the ITRQ as one input to the ICT risk assessment. Under the ECB’s SREP and P2R framework, individual risk outcomes (including operational risk, within which ICT risk is assessed) inform the determination of Pillar 2 requirements through supervisory judgement. Any capital effect therefore comes through supervisory judgement in the wider SREP/P2R process, not through a formula in the questionnaire.
Will the ITRQ disappear when EBA/GL/2017/05 is repealed on 1 January 2027?
EBA/GL/2017/05 will be repealed and replaced from 1 January 2027 by the revised SREP Guidelines. The ITRQ is an ECB data-collection instrument separate from the EBA guideline, and the ECB states that it may be updated as regulation evolves. The primary sources reviewed do not yet confirm the 2027 ITRQ cycle, so continuity should be read as an expectation rather than a confirmed requirement.
Who should own the answers internally?
The workbook spans ICT risk, information security, internal audit input, incident and loss data and the entity-scope reconciliation, so no single team holds all of it. The practical answer is a named owner who can reconcile the ITRQ against the ICAAP self-assessment, the DORA data and the audit record before scores are finalised, because the supervisor reads all of those together.
Related Articles
- ECB SREP 2026 Priorities: How the ECB’s supervisory priorities shape what banks are assessed on across the cycle.
- DORA ICT Incident Reporting: The incident-by-incident reporting track that feeds the same underlying data as the ITRQ cost tab.
- DORA Register of Information: How ICT third-party arrangements are catalogued for supervisors.
- ECB On-Site Inspections and Timely Remediation: How the supervisor tests ICT weaknesses on the ground and expects remediation.
- DORA Threat-Led Penetration Testing: The advanced testing regime for designated financial entities.
- ICAAP and ILAAP: Where the ICT risk and control self-assessment surfaces in the internal adequacy assessments.
Key Takeaways
- The ITRQ is a mandatory annual self-assessment for significant institutions under direct ECB supervision; the 2026 workbook covered reference year 2025 and was due by 27 February 2026.
- The 2026 ITRL scores four categories from 1 (lowest exposure) to 4 (highest): ICT security, ICT availability and continuity, ICT change and ICT data integrity. The ITRC scores control maturity from 1 (best controls in place) to 4 (controls not in place and/or risks not effectively mitigated).
- Self-assessed scores are supervisory inputs, not the SREP score itself; the Joint Supervisory Team validates them against audit, on-site inspection and incident evidence, and inconsistency is the risk.
- For significant institutions, the ECB’s current SREP methodology assesses ICT risk within the operational risk framework; ICT risk findings feed the operational risk score, and supervisors may score ICT risk as a sub-category of operational risk if deemed material. ITRQ responses are one supervisory data source used in that assessment.
- The Gross costs and losses tab follows DORA Article 11(10) and JC/GL/2024/34, reported per incident in thousands of units; the Information-sharing tab follows DORA Article 45.
- The ITRQ covers all entities owned or supervised by the legal entity receiving the questionnaire. Where several legal entities provide ICT services, the ECB expects a comprehensive description of controls at the highest level of consolidation; the Entities in scope tab reconciles the questionnaire perimeter against the prudential scope of consolidation.
- EBA/GL/2017/05 will be repealed and replaced from 1 January 2027 by the revised SREP Guidelines published on 26 June 2026. The ECB’s 2026 ITRQ notice says the questionnaire may be updated as regulation evolves; it does not yet confirm the 2027 ITRQ cycle.
- Operational resilience and ICT capabilities are one of the ECB’s two supervisory priorities for 2026 to 2028.
Sources and References
- European Central Bank, IT Risk Questionnaire (ITRQ) Publication – 2026: ssm.srep_ITRQ2026.en.pdf
- European Central Bank, SREP Supervisory Methodology 2025: ECB SREP methodology
- European Banking Authority, Guidelines on ICT Risk Assessment under the SREP (EBA/GL/2017/05): EBA guidelines page
- European Banking Authority, Final Report on revised SREP and supervisory stress testing Guidelines (26 June 2026): Final Report (PDF)
- European Banking Authority, follow-up Peer Review Report on ICT risk assessment under the SREP (press release, 23 February 2026): EBA press release
- European Banking Authority, List of legal acts facilitating SREP assessments (June 2026): List of legal acts (PDF)
- Regulation (EU) 2022/2554 (Digital Operational Resilience Act, DORA): EUR-Lex
- Commission Delegated Regulation (EU) 2024/1774 (RTS on ICT risk management tools, methods, processes and policies): EUR-Lex
- European Central Bank, Supervisory priorities 2026-2028: ECB Banking Supervision priorities
- European Central Bank, Annual report on the outcome of the SREP IT Risk Questionnaire (feedback to the industry): ECB feedback report
Filing the next ITRQ cycle
The instrument is public now, so preparation for a possible next cycle can start before the next workbook is issued. Map each ITRL and ITRC question to supporting evidence, reconcile gross cost and loss figures to the relevant DORA incident data, confirm the entity perimeter against the prudential scope, and retain explanations for year-on-year score changes. Use 2026 data as it accrues, but an end-February 2027 deadline is not confirmed; keep it on the horizon and wait for the ECB or JST to issue the next collection before treating it as fixed.
Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.
