DORA

  • CSSF Tokenisation FAQ: Control Agents, Fund Registrars and DORA

    On 2 October 2026 the CSSF published version 1 of its FAQ on tokenisation, a nine-page document with six questions about Luxembourg investment funds that issue units or shares on a distributed ledger and about the control agents created by Blockchain Law IV. The CSSF tokenisation FAQ splits its answers evenly: three for fund managers…

  • CSSF Incident Handling Guidance: NIS2 Rulebooks and the DORA Clock

    On 28 September 2026 the CSSF published press release 26/19 announcing operational guidance for incident handling: nine rulebooks written jointly by cybersecurity experts from the High Commission for National Protection (HCPN, acting as ANSSI and as GOVCERT.LU), CIRCL, the CSSF and the ILR. The practical question for Luxembourg DORA entities is whether the CSSF incident…

  • ESAs Autumn 2026 Risk Update: The Reporting Data Behind the Warning

    The ESAs Autumn 2026 risk update, published on 23 September 2026 by the EBA, EIOPA and ESMA through their Joint Committee (reference JC 2026 29), puts a number on bank exposure to private credit and then qualifies it in a footnote. EU/EEA banks’ exposures to private credit funds and related asset managers reached nearly EUR…

  • DORA Major Incident Reporting: The ESAs’ Filing Instructions

    On 16 September 2026 the three European Supervisory Authorities, the EBA, EIOPA and ESMA, published joint operational instructions for DORA major incident reporting. Short and technical, the document addresses something narrow and, for reporting teams, immediate: how selected fields of the major-incident template are expected or recommended to be populated, so that the data reaching…

  • EBA Third-Party Risk Guidelines: Non-ICT Scope and the Two-Year Clock

    On 18 September 2026 the European Banking Authority published EBA/GL/2026/09, its final guidelines on the sound management of third-party risk relating to non-ICT services. The EBA third-party risk guidelines widen the governed perimeter beyond outsourcing, which remains a subset, to non-ICT third-party arrangements within the Guidelines’ defined scope, with particular focus on arrangements supporting critical…

  • CPMI-IOSCO Third-Party Risk at FMIs: The 1 December Deadline

    On 8 September 2026 the Committee on Payments and Market Infrastructures and the International Organization of Securities Commissions published for public comment a discussion paper, “FMIs’ reliance on third-party service providers: challenges and risks,” and set a comment deadline of 1 December 2026. It is the clearest signal yet of where CPMI-IOSCO third-party risk work…

  • CPMI-IOSCO Cyber Resilience Toolkit: What FMIs Should Review

    On 8 September 2026, the Committee on Payments and Market Infrastructures (CPMI) and the International Organization of Securities Commissions (IOSCO) published the CPMI-IOSCO cyber resilience toolkit for public comment. It sets out four voluntary tools and asks central counterparties, central securities depositories, securities settlement systems, payment systems and trade repositories to look hard at how…

  • BCBS Third-Party Risk Principles: DORA and Outsourcing Rules

    On 10 December 2025 the Basel Committee on Banking Supervision published its Principles for the sound management of third-party risk, a 22-page Guidelines publication setting out 12 principles for how banks and their supervisors handle the providers now sitting inside almost every banking process. For the banking sector it supersedes the 2005 Joint Forum paper…

  • Basel Committee ICT Risk Management: The Four Root Causes of Incidents

    On 2 June 2026 the Basel Committee on Banking Supervision published a range-of-practices report on information and communication technology (ICT) risk management. It draws on a survey of 16 jurisdictions and centres on how global and domestic systemically important banks handle the technology failures that take critical services offline. The Basel Committee ICT risk management…

  • ECB IT Risk Questionnaire: How the ITRQ Feeds Your SREP Score

    The ECB IT Risk Questionnaire (ITRQ) is where a significant institution puts a number on its own ICT risk before its Joint Supervisory Team does. Every bank under direct ECB supervision completes the workbook once a year, scoring its inherent ICT risk and the maturity of the controls that mitigate it. The 2026 questionnaire covers…