DORA

  • FSB AI Sound Practices: Consultation Closes, Final Report Next

    On 6 August 2026 the Financial Stability Board published the public responses to its consultation on Sound Practices for Responsible Adoption of Artificial Intelligence (AI). The FSB AI sound practices were put out for comment on 10 June 2026, the comment window closed on 22 July 2026, and the FSB now says it expects to…

  • Japan FSA IT Resilience Report 2026: Four Supervisory Fronts for Banks

    Japan’s Financial Services Agency published its Analytical Report on IT Resilience in the Financial Sector on 30 July 2026, and the framing in the executive summary is blunt: the management of financial institutions needs to recognise IT risk and cyber risk as top management priorities. The Japan FSA IT resilience report carries no template and…

  • Japan FSA Crypto Cybersecurity Report: What CASPs Must Map Now

    The Deloitte Tohmatsu LLC research report is dated 30 June 2026, and the FSA added it to its public research page on 23 July 2026 under the title “Cybersecurity Issues and Countermeasures in Crypto-Asset-Related Businesses.” It sits under the FSA’s Blockchain Governance Initiative Network (BGIN) research track and follows the JFSA’s April 2026 Policy for…

  • STAR-FS and DORA TLPT: Threat-Led Testing for Firms in Both Regimes

    A UK banking group with an EU financial entity identified by its competent authority for DORA threat-led penetration testing may be subject to STAR-FS in the UK and DORA TLPT in the EU at the same time. The Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority maintain STAR-FS, the Simulated Targeted…

  • ESRB Frontier AI Warning: DORA Cyber Risk Reporting Under Scrutiny

    On 7 July 2026 the European Systemic Risk Board published a formal warning that frontier artificial intelligence models are now a source of systemic cyber risk with direct implications for DORA cyber risk reporting across the EU financial system, and the three European Supervisory Authorities backed it the same day. On the same date, ECB…

  • CSSF AI Communique: Mapping Frontier Cyber Risk to DORA

    On 7 July 2026 the Commission de Surveillance du Secteur Financier (CSSF) published a communique, “Evolving opportunities and risks in artificial intelligence and its adoption”, addressed to the entities it supervises. The CSSF AI communique responds to a specific concern: frontier AI models have the potential to shrink drastically the gap between vulnerability disclosure and…

  • DORA ICT-Risk Reporting: Reading KNF’s 2026 Cyber-Threat Report

    On 9 July 2026, CSIRT KNF, the cyber-incident response team inside Poland’s Financial Supervision Authority, refreshed its report on the cyber threats facing the Polish financial sector for 2026. The document reads like a briefing pack rather than a rulebook: the priority attack scenarios, the techniques criminals are stacking into single campaigns, and the risks…

  • UK Critical Third Parties Regime: 13 July 2026 Go-Live

    On 13 July 2026 the Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority begin overseeing the first firms brought inside the UK Critical Third Parties regime. HM Treasury announced the designations three days earlier, on 10 July 2026, but the designations themselves take legal effect only from 13 July 2026, the…

  • SS2/21 Outsourcing: The PRA Register and Notification Guide

    SS2/21 is the PRA’s supervisory statement on outsourcing and third-party risk management. Its main scope covers UK banks, building societies and PRA-designated investment firms; insurance and reinsurance firms and groups in scope of Solvency II, including Lloyd’s and managing agents; and UK branches of overseas banks and insurers. It has been the working reference for…

  • CASP Digital Operational Resilience: ESMA’s Custody CSA

    On 8 July 2026 the European Securities and Markets Authority launched a Common Supervisory Action on crypto-asset service providers, aimed squarely at one activity: custody. The exercise assesses the maturity of CASP digital operational resilience frameworks for custody services, and national competent authorities will run it on a risk-based sample of authorised CASPs from the…