operational resilience

  • CSSF AI Communique: Mapping Frontier Cyber Risk to DORA

    On 7 July 2026 the Commission de Surveillance du Secteur Financier (CSSF) published a communique, “Evolving opportunities and risks in artificial intelligence and its adoption”, addressed to the entities it supervises. The CSSF AI communique responds to a specific concern: frontier AI models have the potential to shrink drastically the gap between vulnerability disclosure and…

  • UK Critical Third Parties Regime: 13 July 2026 Go-Live

    On 13 July 2026 the Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority begin overseeing the first firms brought inside the UK Critical Third Parties regime. HM Treasury announced the designations three days earlier, on 10 July 2026, but the designations themselves take legal effect only from 13 July 2026, the…

  • SS2/21 Outsourcing: The PRA Register and Notification Guide

    SS2/21 is the PRA’s supervisory statement on outsourcing and third-party risk management. Its main scope covers UK banks, building societies and PRA-designated investment firms; insurance and reinsurance firms and groups in scope of Solvency II, including Lloyd’s and managing agents; and UK branches of overseas banks and insurers. It has been the working reference for…

  • DORA Compliance Checklist for Luxembourg Fund Administrators

    Last updated: April 2026 DORA (Regulation (EU) 2022/2554) has been live since 17 January 2025. For Luxembourg fund administrators, UCITS management companies, and AIFMs, the question is no longer whether it applies to you. It does. The question is whether your implementation actually covers what the CSSF expects, or whether you have gaps disguised as…