ESAs Autumn 2026 Risk Update: The Reporting Data Behind the Warning

The ESAs Autumn 2026 risk update, published on 23 September 2026 by the EBA, EIOPA and ESMA through their Joint Committee (reference JC 2026 29), puts a number on bank exposure to private credit and then qualifies it in a footnote. EU/EEA banks’ exposures to private credit funds and related asset managers reached nearly EUR 150 billion in June 2025, equal to 0.6% of total assets, measured from EBA large exposures reporting data. For around half of those exposures, banks did not report the counterparty’s country of domicile.

The update names three vulnerabilities: reliance on non-EU providers and infrastructures, cyber risk that increasingly capable AI models could amplify, and private credit. Its key findings went to the Financial Stability Table of the EU’s Economic and Financial Committee on 10 September 2026. For a reporting team, the useful reading runs backwards from each chart to the return that fed it: large exposures reporting under the CRR, DORA major incident reports, and a DORA oversight regime whose provider designations run on registers of information.

Related reading: DORA ICT Incident Reporting: What the ESAs First Annual Report Reveals

What the ESAs Autumn 2026 risk update asks of firms

The deck closes with six recommendations addressed to authorities and financial institutions. Three concern readiness for geopolitical challenges, with resilience testing, recovery plan dry runs and adequate simplification as the examples given. Three concern external dependencies, private credit and AI: monitoring and risk-managing exposures to non-EEA entities with a private credit focus, continued monitoring of dependencies on non-EU/EEA technology service providers, and preparation for AI and quantum computing risks.

The deck summarises the risk assessment the ESAs prepare for the Financial Stability Table, and none of the six recommendations carries a date, a threshold or a reporting format. One line under regulatory effectiveness is still worth a reporting team’s attention: the ESAs call for more effective use of available data. Several of the deck’s charts are built from data firms already submit, including EBA supervisory reporting, DORA incident reports and EMIR data.

Private credit: what the EUR 150 billion measures

The ESAs attach two caveats to the bank figure, and they pull in opposite directions. It captures exposures to investment funds and asset managers engaged more broadly in private credit activities, so its scope runs wider than private credit itself. It also excludes exposures below the large exposure reporting threshold. G-SIIs hold the largest share. By counterparty domicile, the EBA’s breakdown shows 37.9% US, 5.5% Luxembourg, 2.1% Switzerland and 49.5% unidentified.

The threshold has a precise meaning. Article 394(1) CRR requires institutions to report every large exposure, which Article 392 defines as one equal to or above 10% of Tier 1 capital, and, on a consolidated basis, exposures of EUR 300 million or more that sit below that 10% line. Article 394(3) CRR sets a minimum reporting frequency of at least semi-annually, but Article 14 of Implementing Regulation (EU) 2024/3117 requires the Section 5 large-exposure supervisory reporting to be submitted quarterly.

The missing country is a reporting field

The large exposures counterparty template, LE1 (C 27.00), carries a residence column reported as the ISO 3166-1 alpha-2 code of the counterparty’s country of incorporation. In the LE instructions as published in Implementing Regulation (EU) 2021/451, the predecessor of the current reporting ITS, Implementing Regulation (EU) 2024/3117, a group of connected clients carries no residence at all; only individual counterparties do. The ESAs do not explain the gap, and the instructions alone do not settle it. I read the finding as a prompt to check how fund and manager counterparties are set up in the large exposures engine: as individual counterparties with a country of incorporation, or only as group lines.

A classification question sits beside it. Under Commission Delegated Regulation (EU) 2023/2779, an alternative investment fund is identified as a shadow banking entity where it is authorised as a money market fund, employs leverage on a substantial basis, or is not prohibited by its rules or instruments of incorporation from originating loans in the ordinary course of its business or purchasing third-party lending exposures for its own account, subject to the exclusions in Article 1(2). Article 394(2) CRR requires the ten largest such exposures to be reported on a consolidated basis, and CRR3 added reporting of aggregate exposure to shadow banking entities. The EBA’s consultation module on other CRR3-driven reporting changes, which took responses until 10 July 2026, proposes a new template for that aggregate figure.

On the fund side the numbers are smaller: funds with EU managers following a private credit strategy held EUR 97.1 billion, 95.2% of it invested in Europe (a definition that includes the UK and Switzerland), and the ESAs flag their liquidity mismatches as a possible spillover channel to banks. Our guide to the AIFMD II Annex IV reporting changes covers the manager-side reporting under Directive (EU) 2024/927.

Non-EU ICT providers and the register field that records them

The EBA’s risk assessment questionnaire, cited in the deck, puts ICT service provider dependencies first among banks’ non-EU/EEA dependency concerns (c. 80%) and payment solutions second (c. 60%). The matching recommendation asks for monitoring of dependencies on critical and other technology service providers in the context of the DORA joint oversight teams, including services concentrated on a few providers, payment services among them.

That oversight regime already runs on reported data. The ESAs announced the first designations of critical ICT third-party providers on 18 November 2025, using data collected from registers of information, and Implementing Regulation (EU) 2024/2956 describes register information as essential for the annual designation process.

Two parts of register template B_05.01 carry the non-EEA dimension. Field B_05.01.0080 records the ISO country code of the provider’s global operating headquarters, usually its country of tax residence, and fields B_05.01.0110 and B_05.01.0120 identify its ultimate parent undertaking. For a contract signed with an EU-incorporated subsidiary of a non-EU group, the parent fields are where the group dimension is recorded explicitly. My working assumption is that a register with thin parent data understates the very dependency the ESAs want monitored. Our DORA register of information guide covers the full template set.

DORA’s pre-contract rules ask the same question. Where an arrangement for ICT services supporting critical or important functions is concluded with a provider established in a third country, Article 29(2) requires financial entities to consider compliance with Union data protection rules and the effective enforcement of the law in that country, alongside insolvency law and data-recovery constraints. The incident template closes the loop: field 2.8 in Implementing Regulation (EU) 2025/302 records whether an incident originates from a third-party provider or another financial entity, with that party’s name and identification code. The ESAs’ report on 2025 major ICT-related incidents found 29% caused by a failure attributable to a third-party provider.

USD, GBP and CHF: a precision the press release loses

The press release says banks face funding gaps in some non-EU currencies, mostly in USD, GBP and CHF. The deck is more exact: at a systemic level, EU/EEA banks show CHF and GBP funding gaps, with more assets than liabilities in those currencies, and a USD funding overhang, with USD liabilities above the corresponding assets. Household and non-financial corporation deposits drive most of that foreign-currency funding.

Cyber, frontier AI and quantum: read the incident chart with its footnote

The cyber section rests on DORA incident data for 2026 up to May. The ESAs conclude that system failures account for most ICT incidents, that cyber risk and data security remain the leading drivers of operational risk followed by fraud, and that cyberattack numbers remain high while the data indicate a levelling. The frontier AI concern looks forward, to tools that could find and exploit IT weaknesses, including zero-day vulnerabilities, at unprecedented speed. Our note on the ESRB’s frontier AI warning covers the same concern from the systemic-risk side.

Field 3.23 of Implementing Regulation (EU) 2025/302 classifies the type of major ICT-related incident and permits multiple selections. The ESAs’ 2025 incident report already named the weak spot: the high count at credit institutions, together with competent authorities’ own assessment, may point to underreporting of payment-related incidents, possibly because entities do not select all applicable options. The ESAs’ DORA major incident reporting instructions set out the field-level conventions.

On quantum computing, the ESAs call for preparedness for risks arising from rapid technological development. Separately, the NIS Cooperation Group’s coordinated roadmap states that all Member States should start transitioning to post-quantum cryptography by the end of 2026. The binding text is more operational. For entities outside DORA’s simplified framework, Article 6(4) of Commission Delegated Regulation (EU) 2024/1774 requires the encryption policy to provide for updating or changing, where necessary, cryptographic technology on the basis of developments in cryptanalysis, and Article 6(5) requires a reasoned record of any mitigation adopted instead. The end-2026 date is addressed to Member States.

Frequently Asked Questions

A provider we rely on is on the critical ICT third-party provider list and is headquartered outside the EU. Can we keep using it?

Article 31(12) DORA allows financial entities to use a critical provider established in a third country only if it has established a subsidiary in the Union within the 12 months following its designation. The first list of designated providers was published on 18 November 2025.

We are an insurer. Which parts of the update touch us?

Around 28% of ceded risks are transferred to non-EEA counterparties, concentrated in the UK, Bermuda and Switzerland. AI-enabled cyberattacks could raise claims and accumulation risk in cyber underwriting, though exclusion clauses could limit the impact. On private credit, the ESAs note that limited look-through data makes insurers’ asset mix harder to assess, and they point to Solvency II and the prudent person principle as the supervisory tools.

Sources and References

  • Joint Committee of the ESAs, Update on Risks and Vulnerabilities in the EU Financial System, Autumn 2026 (JC 2026 29, 23 September 2026): PDF
  • EBA press release, ESAs call for vigilance over external dependencies, cyber threats and private credit risks (23 September 2026): EBA
  • Regulation (EU) No 575/2013 (CRR), Articles 392 and 394: EUR-Lex
  • Implementing Regulation (EU) 2024/3117 (reporting ITS), Article 14: EUR-Lex
  • Implementing Regulation (EU) 2021/451 (predecessor ITS, LE1 instructions): EUR-Lex
  • Delegated Regulation (EU) 2023/2779 (shadow banking entities), Article 1: EUR-Lex
  • EBA consultation on revisions to the reporting ITS, module on other changes: EBA
  • Regulation (EU) 2022/2554 (DORA), Articles 28, 29 and 31: EUR-Lex
  • Implementing Regulation (EU) 2024/2956 (register of information): EUR-Lex
  • Implementing Regulation (EU) 2025/302 (major incident reporting templates): EUR-Lex
  • Delegated Regulation (EU) 2024/1774 (ICT risk management RTS), Article 6: EUR-Lex
  • European Commission, Post-Quantum Cryptography, Coordinated Implementation Roadmap: Digital Strategy Europe
  • ESAs, 2025 report on major ICT-related incidents: PDF
  • ESAs designation of critical ICT third-party providers (18 November 2025): EBA
  • Directive (EU) 2024/927 (AIFMD II): EUR-Lex

Two reconciliations the ESAs’ data gaps point to

The update sets no new deadline. Large-exposure supervisory reporting under Article 14 of Implementing Regulation (EU) 2024/3117 is quarterly. For the DORA register, the annual ESA collection uses registers transmitted through competent authorities, while financial entities must maintain the register and make it available to their competent authority as required. The artifact worth producing before either goes out is a two-part reconciliation of private credit fund and manager counterparties with and without a country of incorporation, and of register providers with and without ultimate parent identifiers.

Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.

Similar Posts

  • MiFID II Sustainability Preferences: What the ESMA Common Supervisory Action Results Mean for Investment Firms

    Updated July 2026In this guideWhat the ESMA CSA actually wasThe legal basis you are measured againstCollecting MiFID II sustainability preferences: where the questionnaires fall shortCategorising products and the suitability matchAdapting preferences and the record you keepProduct governance and the negative target marketWhy ESMA chose dialogue over enforcementFrequently Asked QuestionsRelated ArticlesKey TakeawaysSources and ReferencesWhat to fix…

  • ECB Digital Euro Pilot: BCL and Two Luxembourg PSPs Join

    On 14 July 2026 the Banque centrale du Luxembourg (BCL) confirmed it will take part in the European Central Bank’s digital euro pilot, joining the ECB and 18 other Eurosystem national central banks in a controlled test of a beta version of the digital euro. The same day the ECB named the 36 payment service…

  • AMLA Direct Supervision: How Luxembourg Entities Are Identified for the 2027 Selection

    Updated July 2026In this guideWhat the CSSF announced, and what it did notThe eligibility gate: a cross-border footprint, not sizeHow risk classification turns eligibility into selectionEligible, selected, and under AMLA direct supervisionThe timeline that drives the data workFrequently Asked QuestionsRelated ArticlesKey TakeawaysSources and ReferencesWhere the next decision really sitsIf a Luxembourg credit institution or financial…

  • MONEYVAL Bulgaria AML Follow-Up: The Correspondent Banking Read

    On 17 June 2026, MONEYVAL published its third enhanced follow-up report on Bulgaria, and the headline is clear: Bulgaria is now rated compliant or largely compliant on all 40 FATF Recommendations, and no further reporting is required under MONEYVAL’s fifth-round evaluation. For anyone who runs country-risk models or approves correspondent relationships, the MONEYVAL Bulgaria AML…

  • ESMA Prospectus Disclosure Guidelines: The 9 November 2026 Deadline

    ESMA published a full package of prospectus materials on 9 September 2026, and only one part of it is still open for comment. The European Securities and Markets Authority put out a Consultation Paper on updated Guidelines on disclosure requirements under the Prospectus Regulation (Regulation (EU) 2017/1129), revised its Q&As, finalised Guidelines on supplements that…

  • COREP Reporting Explained: A Practical Guide to Prudential Reporting

    Updated September 2026In this guideWhat Is COREP and Why It MattersThe Legal Basis for COREP ReportingWho Has to Report?What Gets Reported: Key Templates and DataWhen and How Often: Reporting Frequency and DeadlinesCOREP in Practice: Workflows, Tools, and Team StructureCommon Errors and PitfallsRecent Changes and Future OutlookComing Soon: Template-by-Template Deep DivesFrequently Asked QuestionsRelated ArticlesKey TakeawaysSources and…