operational resilience

  • BCBS Third-Party Risk Principles: DORA and Outsourcing Rules

    On 10 December 2025 the Basel Committee on Banking Supervision published its Principles for the sound management of third-party risk, a 22-page Guidelines publication setting out 12 principles for how banks and their supervisors handle the providers now sitting inside almost every banking process. For the banking sector it supersedes the 2005 Joint Forum paper…

  • Basel Committee ICT Risk Management: The Four Root Causes of Incidents

    On 2 June 2026 the Basel Committee on Banking Supervision published a range-of-practices report on information and communication technology (ICT) risk management. It draws on a survey of 16 jurisdictions and centres on how global and domestic systemically important banks handle the technology failures that take critical services offline. The Basel Committee ICT risk management…

  • ECB IT Risk Questionnaire: How the ITRQ Feeds Your SREP Score

    The ECB IT Risk Questionnaire (ITRQ) is where a significant institution puts a number on its own ICT risk before its Joint Supervisory Team does. Every bank under direct ECB supervision completes the workbook once a year, scoring its inherent ICT risk and the maturity of the controls that mitigate it. The 2026 questionnaire covers…

  • APRA’s BEAR Case Against Bendigo: An $8m Cyber Accountability Test

    Bendigo and Adelaide Bank has admitted it breached its accountability obligations under the Banking Executive Accountability Regime (BEAR), and on 10 August 2026 the Australian Prudential Regulation Authority (APRA) filed civil penalty proceedings against it in the Federal Court. The parties have jointly proposed that the bank pay an $8 million pecuniary penalty, subject to…

  • Japan FSA IT Resilience Report 2026: Four Supervisory Fronts for Banks

    Japan’s Financial Services Agency published its Analytical Report on IT Resilience in the Financial Sector on 30 July 2026, and the framing in the executive summary is blunt: the management of financial institutions needs to recognise IT risk and cyber risk as top management priorities. The Japan FSA IT resilience report carries no template and…

  • PRA LIAF02/26: The Low-Impact Corrections That Bite on 1 January 2027

    On 29 July 2026 the Prudential Regulation Authority published PRA LIAF02/26, finalising its April 2026 Low Impact Amendments Consultation (LIAC01/26) plus minor corrections made without further consultation. The “low impact” label is supervisory housekeeping and easy to leave unread. The trap is that several of these corrections touch the exact PRA Rulebook Parts that UK…

  • STAR-FS and DORA TLPT: Threat-Led Testing for Firms in Both Regimes

    A UK banking group with an EU financial entity identified by its competent authority for DORA threat-led penetration testing may be subject to STAR-FS in the UK and DORA TLPT in the EU at the same time. The Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority maintain STAR-FS, the Simulated Targeted…

  • CSSF AI Communique: Mapping Frontier Cyber Risk to DORA

    On 7 July 2026 the Commission de Surveillance du Secteur Financier (CSSF) published a communique, “Evolving opportunities and risks in artificial intelligence and its adoption”, addressed to the entities it supervises. The CSSF AI communique responds to a specific concern: frontier AI models have the potential to shrink drastically the gap between vulnerability disclosure and…

  • UK Critical Third Parties Regime: 13 July 2026 Go-Live

    On 13 July 2026 the Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority begin overseeing the first firms brought inside the UK Critical Third Parties regime. HM Treasury announced the designations three days earlier, on 10 July 2026, but the designations themselves take legal effect only from 13 July 2026, the…

  • SS2/21 Outsourcing: The PRA Register and Notification Guide

    SS2/21 is the PRA’s supervisory statement on outsourcing and third-party risk management. Its main scope covers UK banks, building societies and PRA-designated investment firms; insurance and reinsurance firms and groups in scope of Solvency II, including Lloyd’s and managing agents; and UK branches of overseas banks and insurers. It has been the working reference for…