DORA

  • CSSF Circular 26/915: DORA Circulars Re-Mapped for Third-Country Branches

    On 27 August 2026 the CSSF published Circular 26/915, and it applies with immediate effect. Circular CSSF 26/915 updates the Luxembourg ICT and outsourcing circular framework following the European Commission position on DORA’s applicability to third-country branches. It removes the TCB categories within the CSSF’s remit from the relevant pre-DORA circular provisions and maps them…

  • DORA for Third-Country Branches in Luxembourg: Circular CSSF 26/915

    On 27 August 2026 the CSSF issued Circular CSSF 26/915, applicable with immediate effect, to bring specified third-country branches into the CSSF circular framework for DORA. For Luxembourg purposes, the governing scope is the branch perimeter set out in Circular CSSF 26/915 and in each amended circular; the change is not a blanket head-office-only test…

  • EBA Operational Risk RTS: The 31 December 2026 Consultation Deadline

    On 26 August 2026 the European Banking Authority opened a four-month consultation on draft Regulatory Technical Standards that will spell out, article by article, the operational risk management framework every institution subject to the Capital Requirements Regulation has to run. The mandate sits in Article 323(2) of Regulation (EU) No 575/2013 (the CRR), as amended…

  • FSB AI Sound Practices: Consultation Closes, Final Report Next

    On 6 August 2026 the Financial Stability Board published the public responses to its consultation on Sound Practices for Responsible Adoption of Artificial Intelligence (AI). The FSB AI sound practices were put out for comment on 10 June 2026, the comment window closed on 22 July 2026, and the FSB now says it expects to…

  • Japan FSA IT Resilience Report 2026: Four Supervisory Fronts for Banks

    Japan’s Financial Services Agency published its Analytical Report on IT Resilience in the Financial Sector on 30 July 2026, and the framing in the executive summary is blunt: the management of financial institutions needs to recognise IT risk and cyber risk as top management priorities. The Japan FSA IT resilience report carries no template and…

  • Japan FSA Crypto Cybersecurity Report: What CASPs Must Map Now

    The Deloitte Tohmatsu LLC research report is dated 30 June 2026, and the FSA added it to its public research page on 23 July 2026 under the title “Cybersecurity Issues and Countermeasures in Crypto-Asset-Related Businesses.” It sits under the FSA’s Blockchain Governance Initiative Network (BGIN) research track and follows the JFSA’s April 2026 Policy for…

  • STAR-FS and DORA TLPT: Threat-Led Testing for Firms in Both Regimes

    A UK banking group with an EU financial entity identified by its competent authority for DORA threat-led penetration testing may be subject to STAR-FS in the UK and DORA TLPT in the EU at the same time. The Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority maintain STAR-FS, the Simulated Targeted…

  • ESRB Frontier AI Warning: DORA Cyber Risk Reporting Under Scrutiny

    On 7 July 2026 the European Systemic Risk Board published a formal warning that frontier artificial intelligence models are now a source of systemic cyber risk with direct implications for DORA cyber risk reporting across the EU financial system, and the three European Supervisory Authorities backed it the same day. On the same date, ECB…

  • CSSF AI Communique: Mapping Frontier Cyber Risk to DORA

    On 7 July 2026 the Commission de Surveillance du Secteur Financier (CSSF) published a communique, “Evolving opportunities and risks in artificial intelligence and its adoption”, addressed to the entities it supervises. The CSSF AI communique responds to a specific concern: frontier AI models have the potential to shrink drastically the gap between vulnerability disclosure and…

  • DORA ICT-Risk Reporting: Reading KNF’s 2026 Cyber-Threat Report

    On 9 July 2026, CSIRT KNF, the cyber-incident response team inside Poland’s Financial Supervision Authority, refreshed its report on the cyber threats facing the Polish financial sector for 2026. The document reads like a briefing pack rather than a rulebook: the priority attack scenarios, the techniques criminals are stacking into single campaigns, and the risks…