ESAs Autumn 2026 Risk Update: The Reporting Data Behind the Warning
The ESAs Autumn 2026 risk update, published on 23 September 2026 by the EBA, EIOPA and ESMA through their Joint Committee (reference JC 2026 29), puts a number on bank exposure to private credit and then qualifies it in a footnote. EU/EEA banks’ exposures to private credit funds and related asset managers reached nearly EUR 150 billion in June 2025, equal to 0.6% of total assets, measured from EBA large exposures reporting data. For around half of those exposures, banks did not report the counterparty’s country of domicile.
The update names three vulnerabilities: reliance on non-EU providers and infrastructures, cyber risk that increasingly capable AI models could amplify, and private credit. Its key findings went to the Financial Stability Table of the EU’s Economic and Financial Committee on 10 September 2026. For a reporting team, the useful reading runs backwards from each chart to the return that fed it: large exposures reporting under the CRR, DORA major incident reports, and a DORA oversight regime whose provider designations run on registers of information.
Related reading: DORA ICT Incident Reporting: What the ESAs First Annual Report Reveals
What the ESAs Autumn 2026 risk update asks of firms
The deck closes with six recommendations addressed to authorities and financial institutions. Three concern readiness for geopolitical challenges, with resilience testing, recovery plan dry runs and adequate simplification as the examples given. Three concern external dependencies, private credit and AI: monitoring and risk-managing exposures to non-EEA entities with a private credit focus, continued monitoring of dependencies on non-EU/EEA technology service providers, and preparation for AI and quantum computing risks.
The deck summarises the risk assessment the ESAs prepare for the Financial Stability Table, and none of the six recommendations carries a date, a threshold or a reporting format. One line under regulatory effectiveness is still worth a reporting team’s attention: the ESAs call for more effective use of available data. Several of the deck’s charts are built from data firms already submit, including EBA supervisory reporting, DORA incident reports and EMIR data.
Private credit: what the EUR 150 billion measures
The ESAs attach two caveats to the bank figure, and they pull in opposite directions. It captures exposures to investment funds and asset managers engaged more broadly in private credit activities, so its scope runs wider than private credit itself. It also excludes exposures below the large exposure reporting threshold. G-SIIs hold the largest share. By counterparty domicile, the EBA’s breakdown shows 37.9% US, 5.5% Luxembourg, 2.1% Switzerland and 49.5% unidentified.
The threshold has a precise meaning. Article 394(1) CRR requires institutions to report every large exposure, which Article 392 defines as one equal to or above 10% of Tier 1 capital, and, on a consolidated basis, exposures of EUR 300 million or more that sit below that 10% line. Article 394(3) CRR sets a minimum reporting frequency of at least semi-annually, but Article 14 of Implementing Regulation (EU) 2024/3117 requires the Section 5 large-exposure supervisory reporting to be submitted quarterly.
The missing country is a reporting field
The large exposures counterparty template, LE1 (C 27.00), carries a residence column reported as the ISO 3166-1 alpha-2 code of the counterparty’s country of incorporation. In the LE instructions as published in Implementing Regulation (EU) 2021/451, the predecessor of the current reporting ITS, Implementing Regulation (EU) 2024/3117, a group of connected clients carries no residence at all; only individual counterparties do. The ESAs do not explain the gap, and the instructions alone do not settle it. I read the finding as a prompt to check how fund and manager counterparties are set up in the large exposures engine: as individual counterparties with a country of incorporation, or only as group lines.
A classification question sits beside it. Under Commission Delegated Regulation (EU) 2023/2779, an alternative investment fund is identified as a shadow banking entity where it is authorised as a money market fund, employs leverage on a substantial basis, or is not prohibited by its rules or instruments of incorporation from originating loans in the ordinary course of its business or purchasing third-party lending exposures for its own account, subject to the exclusions in Article 1(2). Article 394(2) CRR requires the ten largest such exposures to be reported on a consolidated basis, and CRR3 added reporting of aggregate exposure to shadow banking entities. The EBA’s consultation module on other CRR3-driven reporting changes, which took responses until 10 July 2026, proposes a new template for that aggregate figure.
On the fund side the numbers are smaller: funds with EU managers following a private credit strategy held EUR 97.1 billion, 95.2% of it invested in Europe (a definition that includes the UK and Switzerland), and the ESAs flag their liquidity mismatches as a possible spillover channel to banks. Our guide to the AIFMD II Annex IV reporting changes covers the manager-side reporting under Directive (EU) 2024/927.
Non-EU ICT providers and the register field that records them
The EBA’s risk assessment questionnaire, cited in the deck, puts ICT service provider dependencies first among banks’ non-EU/EEA dependency concerns (c. 80%) and payment solutions second (c. 60%). The matching recommendation asks for monitoring of dependencies on critical and other technology service providers in the context of the DORA joint oversight teams, including services concentrated on a few providers, payment services among them.
That oversight regime already runs on reported data. The ESAs announced the first designations of critical ICT third-party providers on 18 November 2025, using data collected from registers of information, and Implementing Regulation (EU) 2024/2956 describes register information as essential for the annual designation process.
Two parts of register template B_05.01 carry the non-EEA dimension. Field B_05.01.0080 records the ISO country code of the provider’s global operating headquarters, usually its country of tax residence, and fields B_05.01.0110 and B_05.01.0120 identify its ultimate parent undertaking. For a contract signed with an EU-incorporated subsidiary of a non-EU group, the parent fields are where the group dimension is recorded explicitly. My working assumption is that a register with thin parent data understates the very dependency the ESAs want monitored. Our DORA register of information guide covers the full template set.
DORA’s pre-contract rules ask the same question. Where an arrangement for ICT services supporting critical or important functions is concluded with a provider established in a third country, Article 29(2) requires financial entities to consider compliance with Union data protection rules and the effective enforcement of the law in that country, alongside insolvency law and data-recovery constraints. The incident template closes the loop: field 2.8 in Implementing Regulation (EU) 2025/302 records whether an incident originates from a third-party provider or another financial entity, with that party’s name and identification code. The ESAs’ report on 2025 major ICT-related incidents found 29% caused by a failure attributable to a third-party provider.
USD, GBP and CHF: a precision the press release loses
The press release says banks face funding gaps in some non-EU currencies, mostly in USD, GBP and CHF. The deck is more exact: at a systemic level, EU/EEA banks show CHF and GBP funding gaps, with more assets than liabilities in those currencies, and a USD funding overhang, with USD liabilities above the corresponding assets. Household and non-financial corporation deposits drive most of that foreign-currency funding.
Cyber, frontier AI and quantum: read the incident chart with its footnote
The cyber section rests on DORA incident data for 2026 up to May. The ESAs conclude that system failures account for most ICT incidents, that cyber risk and data security remain the leading drivers of operational risk followed by fraud, and that cyberattack numbers remain high while the data indicate a levelling. The frontier AI concern looks forward, to tools that could find and exploit IT weaknesses, including zero-day vulnerabilities, at unprecedented speed. Our note on the ESRB’s frontier AI warning covers the same concern from the systemic-risk side.
Field 3.23 of Implementing Regulation (EU) 2025/302 classifies the type of major ICT-related incident and permits multiple selections. The ESAs’ 2025 incident report already named the weak spot: the high count at credit institutions, together with competent authorities’ own assessment, may point to underreporting of payment-related incidents, possibly because entities do not select all applicable options. The ESAs’ DORA major incident reporting instructions set out the field-level conventions.
On quantum computing, the ESAs call for preparedness for risks arising from rapid technological development. Separately, the NIS Cooperation Group’s coordinated roadmap states that all Member States should start transitioning to post-quantum cryptography by the end of 2026. The binding text is more operational. For entities outside DORA’s simplified framework, Article 6(4) of Commission Delegated Regulation (EU) 2024/1774 requires the encryption policy to provide for updating or changing, where necessary, cryptographic technology on the basis of developments in cryptanalysis, and Article 6(5) requires a reasoned record of any mitigation adopted instead. The end-2026 date is addressed to Member States.
Frequently Asked Questions
A provider we rely on is on the critical ICT third-party provider list and is headquartered outside the EU. Can we keep using it?
Article 31(12) DORA allows financial entities to use a critical provider established in a third country only if it has established a subsidiary in the Union within the 12 months following its designation. The first list of designated providers was published on 18 November 2025.
We are an insurer. Which parts of the update touch us?
Around 28% of ceded risks are transferred to non-EEA counterparties, concentrated in the UK, Bermuda and Switzerland. AI-enabled cyberattacks could raise claims and accumulation risk in cyber underwriting, though exclusion clauses could limit the impact. On private credit, the ESAs note that limited look-through data makes insurers’ asset mix harder to assess, and they point to Solvency II and the prudent person principle as the supervisory tools.
Related Articles
- DORA ICT Incident Reporting: What the ESAs First Annual Report Reveals: the 2025 major incident data by sector, incident type and root cause.
- DORA Major Incident Reporting: The ESAs’ Filing Instructions: the September 2026 instructions on fields, monetary values and conditional filing.
- DORA Register of Information: A Practical Guide for Financial Entities: the register templates, service classifications and submission cycle.
- ESMA Private Credit Ratings Call for Evidence: What CRA-Regulated Firms Should Watch: ESMA’s April 2026 fact-finding on private credit ratings.
Sources and References
- Joint Committee of the ESAs, Update on Risks and Vulnerabilities in the EU Financial System, Autumn 2026 (JC 2026 29, 23 September 2026): PDF
- EBA press release, ESAs call for vigilance over external dependencies, cyber threats and private credit risks (23 September 2026): EBA
- Regulation (EU) No 575/2013 (CRR), Articles 392 and 394: EUR-Lex
- Implementing Regulation (EU) 2024/3117 (reporting ITS), Article 14: EUR-Lex
- Implementing Regulation (EU) 2021/451 (predecessor ITS, LE1 instructions): EUR-Lex
- Delegated Regulation (EU) 2023/2779 (shadow banking entities), Article 1: EUR-Lex
- EBA consultation on revisions to the reporting ITS, module on other changes: EBA
- Regulation (EU) 2022/2554 (DORA), Articles 28, 29 and 31: EUR-Lex
- Implementing Regulation (EU) 2024/2956 (register of information): EUR-Lex
- Implementing Regulation (EU) 2025/302 (major incident reporting templates): EUR-Lex
- Delegated Regulation (EU) 2024/1774 (ICT risk management RTS), Article 6: EUR-Lex
- European Commission, Post-Quantum Cryptography, Coordinated Implementation Roadmap: Digital Strategy Europe
- ESAs, 2025 report on major ICT-related incidents: PDF
- ESAs designation of critical ICT third-party providers (18 November 2025): EBA
- Directive (EU) 2024/927 (AIFMD II): EUR-Lex
Two reconciliations the ESAs’ data gaps point to
The update sets no new deadline. Large-exposure supervisory reporting under Article 14 of Implementing Regulation (EU) 2024/3117 is quarterly. For the DORA register, the annual ESA collection uses registers transmitted through competent authorities, while financial entities must maintain the register and make it available to their competent authority as required. The artifact worth producing before either goes out is a two-part reconciliation of private credit fund and manager counterparties with and without a country of incorporation, and of register providers with and without ultimate parent identifiers.
Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.
