Operational Resilience / Outsourcing in European Union
Operational Resilience / Outsourcing regulatory updates from European Union.
We track 94 Operational Resilience / Outsourcing updates from European Union regulators, published by ECB, ESMA and EBA. The archive covers 71 news items, 9 consultations and 7 enforcement actions. Most recent update: September 2026. Coverage runs from 2025 to 2026.
ESAs call for vigilance over external dependencies, cyber threats and private credit risks 23 September 2026 Joint Committee Risk monitoring The European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) have identified external dependencies, emerging technologies and private credit as key vulnerabilities for…
Why this matters
This is an autumn 2026 joint risk and vulnerabilities report from the ESAs presented to the EU's Financial Stability Table. It identifies material systemic risks (non-EEA ICT dependencies, AI-enabled cyber threats, private credit growth) and explicitly calls on supervisors and market participants to strengthen crisis...
The European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) have identified external dependencies, emerging technologies and private credit as key vulnerabilities for the EU financial system in their Autumn 2026 risk update.
Why this matters
This is an Autumn 2026 risk update and press release from the three ESAs (EBA, EIOPA, ESMA) presenting findings on systemic vulnerabilities. The content is informational and advisory in nature—calling for vigilance and preparedness rather than imposing new rules or enforcement actions.
This is a substantive policy speech by a senior ECB official addressing digital innovation's impact on bank business models and financial stability. It signals supervisory priorities (data aggregation remediation, AI governance, cyber resilience, quantum-resistant cryptography, outsourcing dependencies) and describes...
As part of the European Banking Authority’s (EBA) ongoing efforts to simplify its regulatory framework, the Guidelines focus on third-party arrangements supporting critical or important functions (CIFs) namely the disruption of which would materially impair the performance of a financial entity. By concentrating on…
Why this matters
This is a final EBA guideline publication establishing mandatory requirements for third-party risk management across ICT and non-ICT services. It applies to critical or important functions and covers the full lifecycle of third-party arrangements.
Ongoing geopolitical and economic vulnerabilities masked by strong investor optimism 10 September 2026 Press Releases Risk monitoring The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, published today its second risk monitoring report of 2026 , setting out the…
Why this matters
This is ESMA's H1 2026 financial stability report identifying key market vulnerabilities and structural developments. It contains noteworthy regulatory signals on valuation risks, infrastructure resilience, cyber/AI operational risks, and crypto-financial system linkages affecting multiple firm types across capital...
This is a contribution/speech by Claudia Buch at a Bruegel panel discussing the ECB's supervisory reform priorities. While not a binding rule or consultation, it provides substantive regulatory signals on capital requirements methodology, supervisory simplification initiatives (halving data points in stress tests, 20%...
The European Banking Authority (EBA) today launched a public consultation on draft Regulatory Technical Standards (RTS) specifying the operational risk management framework that institutions must have in place as per Article 323 of the Capital Requirements Regulation (CRR3). The draft RTS set out harmonised…
AI Analysis
The EBA launched a consultation on draft Regulatory Technical Standards under Article 323(2) of Regulation (EU) No 575/2013, as amended by CRR3 Regulation (EU) 2024/1623, defining institutions’ operational risk management framework. The draft would harmonise governance, operational risk processes, assessment systems, data, taxonomy, reporting, validation and audit requirements, with reduced granularity and review/reporting frequency for institutions with a business indicator below EUR 750 million.
Key dates
2026-08-26
EBA consultation launched and consultation period opened.
2026-09-25 Deadline
Deadline to register for the EBA virtual public hearing, at 16:00 CEST.
2026-09-29
EBA virtual public hearing from 10:00 to 12:00 CEST (Paris time).
2026-12-31 Deadline
Deadline for submitting consultation responses to the EBA, at 23:59 CEST.
Suggested considerations
Compliance and operational-risk teams should obtain and map the consultation draft against Article 323(1), points (a) to (h), of the CRR and identify requirements that would require changes to policies, committee mandates, controls or management information.
Institutions should determine their business indicator and assess whether it is below the proposed EUR 750 million proportionality threshold, while treating that threshold as proposed rather than final.
Firms should inventory operational-risk data sources, loss-event thresholds, taxonomies, reporting processes, validation controls and audit coverage, and assess whether data granularity is sufficient for the proposed framework.
Management-body and senior-management responsibilities should be compared with existing governance arrangements, including the independence, authority and resourcing of the operational risk management function.
Firms should assess alignment between the proposed RTS, CRR3 operational-risk capital and reporting implementation, the EBA Guidelines on internal governance and DORA, avoiding duplication or gaps for ICT-related risk.
Affected stakeholders should consider submitting comments to the EBA by 31 December 2026; compliance teams may wish to coordinate responses with risk, finance, internal audit and industry associations.
Stakeholders wishing to participate in the EBA public hearing should register by 25 September 2026 at 16:00 CEST and prepare questions on proportionality, data granularity, thresholds, reporting frequency and implementation timing.
Institutions should monitor the EBA’s final draft, the European Commission’s endorsement process and the eventual application date before treating the consultation text as a binding requirement.
What changed
The proposed RTS would give detailed effect to Article 323(1), points (a) to (h), of the CRR by requiring three framework components: governance arrangements, an operational risk management process and an operational risk assessment system. They clarify responsibilities of the management body, senior management and the independent operational risk management function, and address operational risk data and taxonomy, the business indicator component, reporting, validation and audit. ICT risk requirements are intended to remain governed primarily by Regulation (EU) 2022/2554 (DORA).
Compliance impact
The proposal is not yet legally binding, but it signals material future supervisory expectations for operational-risk governance, data quality, taxonomy, monitoring, validation and audit across CRR3 institutions. Impact is likely to be highest for institutions whose existing frameworks were designed around legacy operational-risk approaches or whose loss data and management information cannot support the proposed harmonised requirements; institutions below EUR 750 million business indicator should receive proportional relief, subject to the final text.
EBA, EIOPA and ESMA call for enhanced governance and consistent supervision to mitigate ICT risks from frontier AI models in the EU financial sector 31 July 2026 Digital Finance and Innovation Joint Committee The European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) today published a statement calling for…
Why this matters
This is a regulatory guidance statement from ESAs addressing AI-related cybersecurity risks across the EU financial sector. It provides supervisory expectations and governance recommendations for managing frontier AI model risks, applicable to all financial entities.
The European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) today published a statement calling for a cross-sectoral, risk-based and consistent supervisory approach to mitigate the ICT risks stemming from frontier AI models.
AI Analysis
On 2026-07-31, the European Supervisory Authorities (EBA, EIOPA and ESMA) issued a joint statement calling for a cross-sectoral, risk-based and consistent supervisory approach to address ICT and cyber risks arising from frontier AI models in the EU financial sector. The statement does not introduce new binding rules but signals how supervisors expect existing frameworks, particularly under DORA and related ICT risk regulations, to be applied to frontier AI use cases.
Key dates
2026-07-31
Joint ESA statement on ICT risks from frontier AI models in the EU financial sector published
Suggested considerations
Compliance teams may wish to map existing and planned uses of frontier AI models (including large language models and other advanced generative or predictive systems) to current ICT risk and cyber resilience frameworks under Regulation (EU) 2022/2554 (DORA) to demonstrate that these models are covered by documented risk assessments, controls and monitoring.
Firms should consider reviewing governance arrangements for frontier AI, including board and senior management oversight, clear accountability, and integration of AI-related ICT risks into the firm’s risk appetite, risk taxonomy and operational risk frameworks, with specific escalation and reporting lines.
Risk and technology functions may wish to update ICT and cyber risk management policies to explicitly address frontier AI threats (e.g. prompt injection, model poisoning, data leakage, adversarial attacks) and to align detection, logging and incident response capabilities with the ESAs’ emphasis on prevention, detection and management of AI-related cyber risks.
Operational resilience teams should consider conducting scenario analysis and testing around frontier AI incidents (such as compromised AI-enabled customer interaction tools or automated decision engines) to evidence the ability to maintain critical services in line with DORA requirements on ICT-related incident management and business continuity.
Compliance and procurement teams may wish to review contracts and due diligence for critical ICT third‑party providers that supply or host frontier AI models, assessing how provider controls, service levels and incident processes meet DORA expectations and the ESAs’ focus on frontier AI risks.
Supervisory engagement teams should consider preparing to discuss the firm’s frontier AI strategy, risk management and governance with competent authorities, using the ESA statement as a reference point for how existing supervisory expectations on ICT risk and cyber resilience are applied to AI use cases.
Internal audit and second‑line control functions may wish to plan thematic reviews of frontier AI deployments to assess coverage of AI-specific ICT risks within existing control frameworks, including documentation quality, model oversight, and alignment with DORA and sectoral guidance.
Firms should consider monitoring forthcoming ESA and national competent authority publications on frontier AI and DORA oversight activities, as the statement signals that supervisory practices and expectations in this area are evolving and may be further operationalised.
What changed
The publication introduces a consolidated supervisory expectation that frontier AI models be treated explicitly as a source of ICT and cyber risk within existing EU operational resilience and ICT risk management frameworks, rather than as a separate technology domain. It emphasises the need for robust governance, risk management, and controls around the prevention, detection and management of cyber risks stemming from frontier AI, including model governance, validation, monitoring and incident handling.
Compliance impact
The impact is primarily supervisory and interpretative rather than creating new binding obligations, but it raises expectations that frontier AI deployments will be demonstrably integrated into existing ICT risk, cyber security and DORA compliance frameworks. Firms that cannot evidence robust governance and risk management for frontier AI may face heightened supervisory scrutiny and potential findings in ICT risk or operational resilience reviews.
ECB publishes results of thematic reverse stress test on geopolitical risks covering 110 euro area banks. Content focuses on supervisory expectations for stress-testing frameworks, capital adequacy (CET1 ratio), liquidity management, and operational resilience including cyber risk.
ESMA publishes latest edition of its newsletter 31 July 2026 ESMA newsletter The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, has published today the latest edition of its Spotlight on Markets newsletter, covering key activities and publications from June and…
Why this matters
ESMA newsletter covering multiple regulatory updates including MiCA transitional period wind-down for crypto providers, T+1 settlement preparations, transaction reporting simplification, DORA ICT incident reporting, and consolidated tape provider authorizations.
Interview with ECB Supervisory Board member discussing banking supervision priorities including geopolitical risks, stress testing, AI governance, cyber resilience, and banking union completion.
ESMA calls on firms to finalise preparations ahead of T+1 settlement deadlines 20 July 2026 Post Trading The European Securities and Markets Authority (ESMA), the EU regulator and supervisor, has published a statement highlighting key deadlines and action points to be ready for the transition to a T+1 settlement cycle…
Why this matters
ESMA regulatory deadline for T+1 settlement preparations with critical milestones in 2026 and implementation in October 2027. Affects trading and settlement infrastructure across capital markets participants requiring significant operational readiness and ecosystem coordination.
ESMA launches Common Supervisory Action on CASPs’ digital operational resilience for custody 08 July 2026 Digital Finance and Innovation The European Securities and Markets Authority (ESMA), the EU regulator and supervisor, is launching a Common Supervisory Action (CSA) focusing on the digital operational resilience…
Why this matters
ESMA's Common Supervisory Action targets CASPs' digital operational resilience frameworks for custody activities, focusing on DLT-specific risks. This is informational guidance on a supervisory exercise running 2026-2027, not an urgent regulatory change.
The ESAs support ESRB warning on systemic cyber risks from frontier AI models 07 July 2026 Digital Finance and Innovation Joint Committee Press Releases The European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) welcome and support today’s warning from European Systemic Risk Board (ESRB) on the systemic…
Why this matters
ESAs issue joint warning on systemic cyber risks from frontier AI models threatening financial sector operational resilience. Applies across all financial entities under DORA framework.
ESMA publishes preliminary findings on the Active Account Requirement and the first Annual Report of the Joint Monitoring Mechanism 06 July 2026 CCP The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, has today published the Interim Report of the Effectiveness of…
AI Analysis
ESMA’s interim report on the EMIR 3 Active Account Requirement (AAR) and the first Annual Report of the Joint Monitoring Mechanism (JMM) confirm that the AAR is operational, materially impacting EU clearing behaviour and beginning to shift activity from Tier 2 (third‑country) CCPs to EU CCPs. For compliance teams, this marks a move from regime design to supervisory assessment: firms subject to AAR must now assume their notifications, clearing patterns, and reporting will be benchmarked against ESMA’s evolving effectiveness methodology and cross‑sectoral monitoring of EU clearing risks.
Key dates
24 December 2024
– EMIR 3 enters into force, establishing the legal basis for the Active Account Requirement and related RTS framework
2025 (full year)
– First year of operation of the Joint Monitoring Mechanism, covering monitoring of AAR implementation and broader EU clearing landscape developments, as described in the JMM’s first Annual Report
25 June 2025 Deadline
– Active Account Requirement becomes applicable, starting the reference period for AAR compliance and reporting and triggering obligations to maintain an active account at an EU CCP for specified derivatives
February 2026 (as of)
– Approximately 500 entities have notified ESMA and national competent authorities that they are subject to the AAR, marking a key supervisory data‑collection milestone
26 February 2026 Deadline
– Regulatory Technical Standards specifying detailed AAR conditions, including operational obligations, stress‑testing, activity and reporting requirements, enter into force, operationalising how the AAR must be met in practice
Suggested considerations
Confirm whether your entity (and any funds or branches) is subject to the Active Account Requirement by assessing EMIR clearing obligation status and relevant notional clearing volumes against EMIR 3 thresholds for AAR‑scope derivatives.
Implement and document annual stress‑testing of the active account arrangements, including at least one test per year, to evidence that positions and new trades can be shifted from Tier 2 CCPs to EU CCPs under stress scenarios.
Map and quantify exposures to Tier 2 CCPs across AAR‑relevant derivatives, and establish an internal monitoring framework to track shifts in clearing volumes between Tier 2 CCPs and EU CCPs in line with AAR objectives.
Align trade booking, clearing workflows, and client documentation so that the required minimum number of trades per relevant subcategory and contract class can be cleared through the EU active account on an annual average basis, taking into account representativeness requirements where applicable.
Prepare to submit the first AAR report by 31 July 2026, ensuring that systems and controls can capture and report activity from 25 June 2025 to 30 June 2026 in accordance with ESMA’s reporting templates and instructions.
What changed
- ESMA has published an Interim Report on the effectiveness of the Active Account Requirement, covering implementation and market impact during 2025 and early 2026, and explicitly framing this as the...
ESMA confirms that roughly 500 entities have formally notified ESMA and national competent authorities that they are subject to the AAR, indicating that competent authorities now have a defined...
Notified entities represent more than 90% of notional outstanding held by EU entities in relevant AAR‑scope derivatives, signalling supervisory focus on a concentrated set of high‑exposure...
ESMA identifies early signs of increased clearing activity at EU CCPs, particularly among smaller entities, including some full relocation of positions from Tier 2 CCPs to EU CCPs for AAR‑relevant...
ESMA notes a gradual but limited shift in market shares from systemically important Tier 2 CCPs to EU CCPs in certain AAR‑related products, indicating that supervisors will monitor market‑share...
Compliance impact
Non‑compliance with the AAR and associated reporting and operational requirements raises significant supervisory and financial stability concerns, with a high risk of regulatory intervention, enforcement, and potential restrictions on clearing arrangements, especially for firms with large exposures to Tier 2 CCPs. Given ESMA’s explicit focus on effectiveness and systemic risk channels, persistent weaknesses in AAR implementation may also affect prudential assessments, stress‑testing outcomes, and broader supervisory views of CCP and clearing‑member risk management.
Moody’s Germany fined EUR 2,145,000 for misreporting to ESMA 02 July 2026 Press Releases Securities Financing Transactions Supervision Trade Repositories The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, has fined Moody’s Deutschland GmbH (Moody’s Germany) a…
AI Analysis
ESMA has fined Moody’s Deutschland GmbH EUR 2,145,000 for four negligent breaches of the EU Credit Rating Agencies Regulation (CRA Regulation), all relating to incomplete, inaccurate and outdated regulatory data reported to ESMA and published on ESMA’s central platforms. This enforcement action underscores that ESMA now treats **data quality in regulatory reporting by credit rating agencies (CRAs)** as a core supervisory priority, with failures in reporting frameworks, policies, procedures and internal controls attracting significant financial penalties and public censure.
Key dates
Since July 2011
– ESMA has been responsible for the supervision and registration of credit rating agencies in the EU under the CRA Regulation, including enforcement actions for breaches
TBD (post‑02 July 2026)
– Potential appeal window for Moody’s Germany to bring the case before the Board of Appeal of the European Supervisory Authorities; any appeal does not have automatic suspensive effect, though suspension can be granted by the Board of Appeal on request
02 July 2026
– ESMA Board of Supervisors adopts supervisory measures and imposes fines on Moody’s Deutschland GmbH for four negligent breaches of the CRA Regulation, and publishes a public notice and press release
Suggested considerations
Conduct a comprehensive review of all ESMA‑related reporting processes to ensure that data submitted to ESMA (including rating information, historical performance data, rating changes, and other CRA regulatory reports) is complete, accurate, and kept up‑to‑date at all times.
Map and document all responsibilities for ESMA reporting within the CRA group, ensuring that where one entity reports on behalf of others, the allocation of roles, ownership of data, and validation steps is explicitly defined, approved, and regularly reviewed.
Perform a gap analysis of existing regulatory reporting policies, procedures, and internal control mechanisms against CRA Regulation requirements and ESMA supervisory expectations, and update documentation to remove ambiguities and outdated provisions.
Implement or strengthen data validation and reconciliation controls over submissions to the European Rating Platform and ESMA’s central repositories, including automated checks for missing ratings, non‑withdrawn ratings, incorrect rating actions, and inconsistencies in historical performance data.
Establish a formal governance process for changes to regulatory reporting frameworks, ensuring regular review, independent challenge by compliance or risk functions, and clear escalation routes for identified data quality issues or control failures.
What changed
- ESMA has clarified, through enforcement, that CRAs must ensure complete, accurate and up‑to‑date data is reported to ESMA across all relevant CRA reporting channels (including the European Rating...
ESMA has reinforced that errors limited to regulatory reporting data (and not directly affecting published ratings) can still constitute material breaches of the CRA Regulation, demonstrating that...
ESMA has indicated that group reporting arrangements (where one CRA entity reports on behalf of others in the group) must have clear documentation of responsibilities, validation processes, and...
ESMA has emphasized that regulatory reporting frameworks must include robust policies, procedures and internal control mechanisms, and that deficiencies in these frameworks constitute distinct...
ESMA has signalled that negligence, rather than intentional misconduct, is sufficient to trigger significant fines under the CRA Regulation, and that both aggravating and mitigating factors will be...
Compliance impact
The compliance impact is high: ESMA has imposed a multi‑million euro fine on Moody’s Germany for negligent data reporting failures that did not affect the underlying ratings, indicating that poor regulatory reporting alone can trigger significant financial and reputational consequences, and that persistent or systemic weaknesses in CRA reporting frameworks could ultimately risk sanctions up to withdrawal of registration.
This is an informational speech by ECB Supervisory Board Chair to European Parliament outlining regulatory reform agenda. Key focus areas include capital framework simplification, cyber/AI resilience requirements, banking union completion, and supervisory methodology updates.
ESMA recognises the Clearing Corporation of India Limited as a Tier 1 third-country CCP 01 July 2026 CCP The European Securities and Markets Authority (ESMA), the EU’s securities markets regulator, has recognised The Clearing Corporation of India Limited (CCIL) as a Tier 1 third-country central counterparty (CCP)…
AI Analysis
ESMA has recognised The Clearing Corporation of India Limited (CCIL) as a **Tier 1 third‑country CCP** under EMIR, with the recognition effective from **30 June 2026**, allowing CCIL to provide clearing services to EU clearing members and trading venues. This restores and regularises EU firms’ ability to clear eligible Indian markets through CCIL under EMIR Article 25, subject to equivalence, cooperation, and oversight conditions tied to the Reserve Bank of India (RBI) and the Indian CCP regime.
Key dates
30 April 2023
- ESMA’s withdrawal of recognition decisions for six Indian CCPs, including CCIL, took effect under EMIR, prohibiting EU clearing members and trading venues from using those CCPs for EU‑regulated clearing activity
Earlier 2026
- ESMA and the Reserve Bank of India sign a Memorandum of Understanding establishing supervisory cooperation arrangements for Indian CCPs, including CCIL
30 June 2026
- ESMA’s decision recognising CCIL as a Tier 1 third‑country CCP under EMIR takes effect, and CCIL is added to ESMA’s updated list of recognised TC‑CCPs
Suggested considerations
Confirm and document that CCIL now appears on ESMA’s official list of recognised third‑country CCPs and that its status is Tier 1 under EMIR, updating internal CCP eligibility lists and counterparty approval registers accordingly.
Review and update internal clearing policies, procedures and governance documents to reflect that EU entities may again clear eligible products through CCIL, subject to EMIR and firm‑specific risk appetite.
Reassess and formally approve CCIL within the firm’s CCP due‑diligence framework, including credit risk, operational risk, legal risk and jurisdictional risk assessments, taking account of the RMU with RBI and the Tier 1 classification.
Update EMIR compliance mappings to ensure that trades cleared via CCIL are correctly treated for clearing obligation, risk‑management, reporting and collateral requirements, and that no activity is undertaken through non‑recognised CCPs in India.
Coordinate with front‑office, clearing operations and collateral management teams to re‑open or adjust clearing access to CCIL (e.g. membership arrangements, client clearing channels, account structures, margin and collateral workflows).
What changed
- CCIL is formally recognised as a Tier 1 third‑country central counterparty (TC‑CCP) under Regulation (EU) No 648/2012 (EMIR), allowing it to offer clearing services to EU clearing members and EU...
The recognition is contingent on an equivalence decision adopted by the European Commission for the Indian regulatory framework applicable to CCPs under EMIR Article 25.
ESMA has assessed and confirmed effective supervision and enforcement by the Reserve Bank of India (RBI) over CCIL as a prerequisite for recognition.
ESMA and RBI have put in place cooperation arrangements, formalised through a Memorandum of Understanding, to support ongoing supervisory coordination over CCIL’s activities that affect EU...
CCIL is now included in ESMA’s updated list of recognised third‑country CCPs, clarifying that EU firms may use CCIL’s clearing services while complying with EMIR’s clearing and risk‑management...
Compliance impact
Non‑compliance with EMIR’s requirement to use only recognised third‑country CCPs for clearing in scope activities could expose firms to supervisory action, including potential enforcement, fines and restrictions on clearing activities. The recognition of CCIL materially reduces legal and regulatory risk for EU firms clearing Indian markets, but firms must still ensure their governance, risk and operational controls are aligned with EMIR and the Tier 1 TC‑CCP framework.
Speech by ECB Supervisory Board member addressing regulatory complexity and fragmentation in banking supervision. Discusses proportionality in prudential framework, SREP reforms, capital requirements, and supervisory simplification initiatives.
Interview with ECB Supervisory Board member discussing banking supervision priorities including geopolitical risk stress testing, digital transformation, AI strategies, SREP reforms, capital requirements (P2R), operational resilience including cyber threats and third-party outsourcing, and Basel III implementation.
This is a fireside chat speech by ECB Executive Board member Frank Elderson discussing regulatory simplification, capital requirements, banking competitiveness, cyber resilience with frontier AI models, and the digital euro project.
ESMA contributes to global CCP fire drill exercise 19 June 2026 CCP In November 2025, 38 central counterparties (‘CCPs’) from across the world, together with clearing members, conducted a coordinated fire drill exercise simulating the failure of a hypothetical common participant. Known as the CCP Global International…
AI Analysis
ESMA has announced its participation as a lead authority in the 2025 CCP Global International Default Simulation (CIDS), a coordinated multi-jurisdictional default-management “fire drill” involving 38 CCPs and their clearing members, simulating the failure of a common participant in November 2025. This is not a new binding rule but it signals heightened supervisory expectations on default management, cross-CCP coordination, porting, and operational resilience, which EU CCPs and clearing members should treat as de facto supervisory standards.
Key dates
13 November 2023
– Week-long 2023 Global CCP fire drill coordinated by ESMA and other authorities, simulating the default of a hypothetical major clearing member across more than 30 CCPs
5 December 2024
– Kick-off meeting for the second industry-led multi-CCP default simulation (CIDS 2025) organised by CCP Global in Singapore, setting parameters and expectations for the 2025 exercise
3 November 2025
– Start of the 2025 CCP Global International Default Simulation (CIDS) multi-CCP fire drill window (up to 7 November 2025 for some CCPs), simulating the failure of a hypothetical common participant
4 December 2025
– Debrief meeting in Singapore for CIDS 2025 participants to discuss operational outcomes, bottlenecks, and potential improvements
19 June 2026
– ESMA and the lead authorities publish the 2025 CIDS key findings and recommendations, outlining expectations for further progress in standardisation, porting, portal-based solutions, and potential market stress overlay modules
Suggested considerations
CCPs should review and update their default management procedures to align with emerging cross-CCP standards, including harmonised communication conventions, standardised information templates, and coordinated auction timelines.
Clearing members should conduct a cross-CCP gap analysis of their default-management playbooks to ensure they can support simultaneous auctions and calls from multiple CCPs without creating operational bottlenecks.
CCPs and clearing members should implement or upgrade portal-based communication and workflow tools for default events, replacing fragmented email- or spreadsheet-based processes where feasible.
Clearing brokers and client-clearing firms should test and, where necessary, redesign their porting arrangements (including client consent, documentation, booking models, and operational capacity) to ensure they can port positions and collateral under stressed but realistic timelines.
Risk and operations teams at CCPs and clearing members should incorporate findings from the 2023 and 2025 CIDS exercises into their internal default-management training, drills, and board reporting on operational resilience.
What changed
- Supervisory expectations are raised for standardisation and reduction of fragmentation in CCP default-management procedures and communication conventions, with a strong push toward harmonised...
Lead authorities explicitly promote greater use of portal-based solutions (rather than ad hoc email or bespoke channels) for communication, information sharing, and auction-related workflows between...
Authorities call for more realistic testing of porting arrangements, including end-to-end operational tests that reflect real-life constraints (documentation, client consent, timing of transfers, and...
The lead authorities propose considering a voluntary “market stress overlay” module in future CIDS exercises, creating a coherent cross-CCP macro stress scenario to test whether operational capacity...
ESMA confirms that global CCP fire drills are now a core component of system-wide resilience expectations, effectively embedding regular multi-CCP default simulations into ongoing supervisory...
Compliance impact
The immediate legal impact is indirect, as the publication itself does not amend EMIR or introduce binding RTS/ITS, but it clearly elevates supervisory expectations on default management, porting, and operational resilience for CCPs and clearing members. Failure to adapt to these expectations may expose firms to supervisory criticism, remediation demands, and heightened scrutiny of their default management, operational resilience, and governance frameworks.
This is a keynote speech by ECB Supervisory Board member Sharon Donnery addressing banking supervision modernization. It discusses capital requirements (Pillar 1/2), operational resilience including cyber threats and third-party dependencies, and the need for risk-based supervisory frameworks.
ESAs publish the first report on DORA major ICT-related incidents 03 June 2026 Digital Finance and Innovation Joint Committee The European Supervisory Authorities (EBA, EIOPA and ESMA) today published their first annual overview of major ICT-related incidents in the EU financial sector based on a reporting mechanism…
AI Analysis
The ESAs (EBA, EIOPA and ESMA) have published their first annual report under Article 22(2) DORA, aggregating 3,383 **major ICT‑related incidents** reported by EU financial entities and highlighting that roughly one third had a cross‑border impact. This is an early supervisory “heat map” of DORA incident reporting and sends a clear signal that competent authorities will focus on cross‑border ICT risk, third‑party/outsourcing failures and the adequacy of firms’ incident classification and reporting frameworks.
Key dates
17 January 2025
– DORA (Regulation (EU) 2022/2554) applies, and financial entities become obliged to report major ICT‑related incidents to their competent authority once classification thresholds are met
Annual (from 2026 onwards) Deadline
– Under Article 22(2) DORA, the ESAs must issue a yearly report covering number, nature, impact, remedial actions and costs of major ICT‑related incidents; the publication in early June 2026 is the first such report and sets the expectation for future annual cycles
Suggested considerations
Review and, where necessary, recalibrate internal incident classification criteria against the DORA definition of “ICT‑related incident” and “major ICT‑related incident”, ensuring consistency with applicable RTS on classification and materiality thresholds.
Validate that your firm’s incident management and escalation processes can identify, assess and classify incidents “without undue delay” and trigger major‑incident reporting within the prescribed timelines (initial, intermediate and final reports).
Conduct a gap analysis of cross‑border incident handling, ensuring that governance, communication and coordination arrangements adequately address incidents affecting multiple Member States or shared cross‑border infrastructures.
Strengthen third‑party and outsourcing risk management by mapping critical and important functions to their supporting ICT service providers, and ensuring contracts, SLAs and incident‑response clauses support DORA reporting and cooperation obligations.
Test and, if needed, enhance incident response runbooks to ensure close coordination with ICT service providers during incident containment, remediation and recovery, including clear roles for data provision required for regulatory reporting.
What changed
- The ESAs have operationalised Article 22(2) DORA by issuing the first annual overview of major ICT‑related incidents, confirming that yearly ESA‑level aggregation and analysis of incident data is...
Incident reporting under DORA is now demonstrably harmonised and centralised, with major ICT‑related incidents being notified to all competent authorities involved and then aggregated by the ESAs for...
The report confirms that cross‑border incidents are prevalent (around one third of major incidents), reinforcing that the “borderless and interconnected” nature of ICT risk is a key supervisory...
System failures and external events, rather than pure cyber‑attacks, are identified as the main drivers of major incidents, placing regulatory emphasis on ICT change management, resilience of core...
The ESAs highlight third‑party and outsourcing risk as a core theme, stressing the need for robust oversight of ICT service providers and close coordination with them during incident response and...
Compliance impact
Non‑compliance with DORA incident management and reporting obligations can lead to supervisory findings, administrative sanctions, and heightened intrusive supervision, especially where cross‑border incidents or third‑party failures are not properly reported or managed. Given the ESAs are now publicly benchmarking the sector, firms whose reporting patterns appear inconsistent with peers face increased risk of challenge on classification practices and operational resilience adequacy.
This is an informational keynote speech by ECB Executive Board member Frank Elderson addressing operational resilience and AI-driven cyber threats in banking. While it contains supervisory guidance and expectations (including mention of forthcoming 'dear CEO letter'), it is primarily a speech outlining strategic...
ESMA publishes latest edition of its newsletter 01 June 2026 ESMA newsletter The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, has published today the latest edition of its Spotlight on Markets newsletter , covering ESMA’s key activities and publications from…
AI Analysis
ESMA’s latest *Spotlight on Markets* newsletter (covering April–May 2026 activity) signals a coordinated push on reporting simplification, CCP resilience, EMIR 3 implementation and enhanced enforcement of corporate and digital reporting standards. For compliance teams, the newsletter is a consolidated forward‑looking risk map: it highlights where ESMA and NCAs will focus supervision and enforcement in the next cycle, especially around fund/transaction reporting, CCP crisis planning, ESEF taxonomy use and internal control functions in the funds sector.
Key dates
2025 (completed) Deadline
– ESMA and NCAs conduct the 2025 Common Supervisory Action on compliance and internal audit functions of fund managers, establishing benchmarks for good and poor practices in the funds sector
2025 (completed)
– First year of enforcement of European Sustainability Reporting Standards (ESRS) and application of ESMA Guidelines on Enforcement of Sustainability Information for in‑scope issuers’ 2025 reporting
2025 (throughout year)
– ESMA and NCAs carry out corporate reporting enforcement across the EEA, including financial, sustainability and digital (ESEF) reporting, feeding into ESMA’s 2025 corporate reporting enforcement report
Q2 2026
– ESMA launches the sixth CCP stress test exercise, with follow‑up supervisory actions by ESMA and NCAs expected after results are analysed
Q2 2026
– ESMA publishes reporting templates and instructions for the EMIR 3 Active Account Requirement, enabling firms and CCPs to begin design and implementation work ahead of EMIR 3 go‑live
Suggested considerations
Map your firm’s current EMIR, MiFIR and fund reporting obligations against ESMA’s stated objective of simplifying EU reporting frameworks and begin scenario‑planning for changes to templates, data models and validation rules.
For CCPs and clearing members, review participation in the sixth ESMA CCP stress test, ensure timely and accurate data delivery, and assess internal implications of potential stress test findings for risk management frameworks.
CCPs should compare existing recovery and resolution plans and playbooks against ESMA’s new guidance on effective use of resolution tools, updating governance, triggers, communications and coordination arrangements with resolution authorities.
Counterparties and CCPs in scope of EMIR 3 should identify products and business lines affected by the Active Account Requirement and begin implementing systems, processes and controls to populate ESMA’s reporting templates and instructions.
Investment firms active in equity markets should respond to ESMA’s call for evidence on European equity market structure where appropriate, and internally assess potential impacts on best execution, order routing, internalisation and transparency obligations.
What changed
- ESMA is advancing the simplification of EU reporting frameworks for funds and transaction reporting, indicating upcoming changes to reporting templates, data fields and/or reporting channels under...
ESMA has launched its sixth EU‑wide stress test exercise for Central Counterparties (CCPs), expanding supervisory scrutiny of CCP risk management, default management processes and resilience to...
ESMA has published guidance on the effective use of resolution tools in CCP crisis planning, clarifying expectations for CCP resolution planning, coordination with resolution authorities and use of...
ESMA has issued reporting templates and instructions for the Active Account Requirement under EMIR 3, operationalising new obligations for counterparties and CCPs to maintain and report active...
ESMA has published a call for evidence on the structure of European equity markets, opening a policy workstream that may lead to changes in market structure, transparency, and best execution...
Compliance impact
The overall impact is medium to high: while the newsletter itself does not create new binding obligations, it consolidates ESMA priorities that will drive supervisory focus and future technical standards, particularly in EMIR 3, CCP oversight, ESEF and sustainability reporting. Failure to anticipate and align with these priorities can lead to enforcement actions, remediation mandates, higher supervisory scrutiny and reputational risk once the related rules and guidance are fully applied.
ESMA’s annual data report shows increased quality, wider use and digital progress 29 May 2026 Market data The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, published today its annual report on the quality and use of regulatory data . It shows that improvements…
AI Analysis
ESMA’s latest annual report on the **quality and use of regulatory data** confirms a material step‑up in supervisory reliance on EMIR, SFTR, MiFIR, AIFMD and MMFR datasets, alongside new inclusion of Prospectus and DORA ICT‑incident reporting. For compliance teams this is a clear signal that data quality is now an enforcement‑relevant topic across a broader perimeter, and that ESMA is actively moving toward **streamlined, “report once” cross‑regime reporting** and an integrated funds reporting framework, which will reshape reporting architecture and controls over the next 1–3 years.
Key dates
2025 (exact dates TBD)
– ESMA’s Call for Evidence on streamlining reporting across EMIR, MiFIR and SFTR is scheduled, with stakeholders expected to provide input on duplication removal and “report once” options
18 June 2026
– ESMA will host a webinar to present the main findings of the annual report on the quality and use of regulatory data
Suggested considerations
Map all existing regulatory reporting obligations across EMIR, SFTR, MiFIR, AIFMD, MMFR, Prospectus and DORA ICT‑incident reporting, and document the underlying data sources, systems and ownership for each regime.
Review and enhance data quality controls for EMIR, SFTR and MiFIR reporting, including validation rules, completeness checks, reconciliations, pairing and matching processes, and governance around Unique Transaction Identifiers and counterparty data.
Perform a gap analysis of Prospectus reporting and DORA ICT‑incident reporting processes against ESMA’s emerging cross‑regime data quality expectations and ensure they are covered in the firm’s enterprise data governance framework.
Establish or update a centralised regulatory data governance framework that explicitly covers cross‑regime consistency (for example, trade and position data alignment between EMIR, SFTR and MiFIR) and defines clear accountability at senior management level.
Engage with internal IT and reporting teams to identify where a future “report once” model could be supported technically, including harmonised reference data, common identifiers and golden‑source transaction and position records.
What changed
- ESMA confirms measurable data quality improvements across EMIR, SFTR, MiFIR, AIFMD and MMFR regulatory datasets, indicating that regulators now consider these data sufficiently reliable for...
ESMA highlights extensive and growing supervisory use of regulatory data by ESMA and NCAs for investor protection, financial stability, orderly markets and market integrity, increasing the...
The scope of the annual data quality and use report is expanded to include Prospectus reporting obligations, bringing prospectus‑related data formally into ESMA’s cross‑regime data quality scrutiny.
The report scope is also expanded to include ICT‑related incident reporting under the Digital Operational Resilience Act (DORA), signaling that operational resilience incident data will be monitored...
ESMA has launched a 2025 Call for Evidence on streamlining reporting across EMIR, MiFIR and SFTR, including options to remove duplications and apply a “report once” approach, which will likely lead...
Compliance impact
Regulatory data reported under EMIR, SFTR, MiFIR, AIFMD, MMFR, Prospectus rules and DORA is increasingly used for day‑to‑day supervision, thematic reviews and enforcement, making poor data quality a direct source of regulatory, reputational and potentially financial sanctions risk. As ESMA and NCAs deploy more automated, risk‑based data quality tools, firms with weak controls or inconsistent cross‑regime reporting will be more visible and more likely to face targeted supervisory action.
ESMA consults on revised guidelines to support smoother allocations and confirmations under T+1 26 May 2026 Post Trading The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, has launched a consultation on the updated guidelines on standardised procedures and…
AI Analysis
ESMA has launched a consultation on **revised ESMA Guidelines on standardised procedures and messaging protocols for allocations and confirmations**, aligning them with the forthcoming CSDR Settlement Discipline RTS amendments and the EU’s move to **T+1 settlement by 11 October 2027**. The draft guidelines harden expectations around **mandatory electronic, standardised, machine‑readable communication** for post‑trade processes and remove reliance on manual or non‑machine‑readable methods, significantly tightening operational requirements for EU trading, post‑trade and operations functions.
Key dates
07 July 2026 Deadline
– Deadline stated by ESMA for stakeholders to submit consultation feedback on the revised guidelines
October 2026
– ESMA expects to publish its final report, including updated and finalised guidelines on standardised procedures and messaging protocols
07 December 2026
– Expected application date of the revised ESMA Guidelines on allocations and confirmations, aligned with the anticipated application of the amended CSDR RTS on Settlement Discipline requirements for allocations and confirmations
11 October 2027 Deadline
– EU transition date to a T+1 settlement cycle, when trades in in‑scope instruments must settle one business day after the trade date and firms must fully operate under the new T+1‑aligned post‑trade framework
Suggested considerations
Map all current allocation and confirmation workflows and identify any use of non‑electronic, non‑standardised or non‑machine‑readable communication (including email attachments, faxes, PDFs, and oral instructions).
Develop and execute a remediation plan to replace manual or oral allocation and confirmation processes with fully electronic, machine‑readable workflows using recognised international messaging standards.
Review and update front‑to‑back trade processing systems (OMS, EMS, middle‑office, back‑office, matching engines) to ensure they can generate, receive and process standardised electronic allocation and confirmation messages within same‑day T+1‑compatible timelines.
Engage with CSDs, custodians, brokers, counterparties and third‑party vendors to confirm their roadmap and readiness for the mandated electronic standards and to align implementation timelines to the 7 December 2026 application date.
Update contractual documentation with clients and counterparties (including terms of business and service level agreements) to incorporate obligations for electronic, standardised, machine‑readable allocations and confirmations and to remove reliance on manual methods except as contingency.
What changed
- ESMA proposes revised Guidelines on standardised procedures and messaging protocols for allocations and confirmations under CSDR Settlement Discipline, specifically to support the transition to a...
The guidelines will mandate the use of electronic, standardised communication channels for post‑trade allocations and confirmations, moving away from mixed paper / manual practice to fully electronic...
Firms will be required to use international messaging standards (e.g. ISO‑based protocols) for post‑trade communication, to ensure interoperability and faster straight‑through processing across EU...
The guidelines remove references to non‑electronic and non‑machine‑readable methods, including oral allocations and confirmations, except where there is a temporary technical disruption that prevents...
The revisions are explicitly aligned with ESMA’s Final Report on Amendments to the CSDR RTS on Settlement Discipline, which introduce same‑day timing for allocations and machine‑readable formats for...
Compliance impact
The change is high impact for operational and conduct compliance: failure to implement mandatory electronic, standardised post‑trade communication and to meet compressed T+1 timelines will directly increase settlement fails, trigger CSDR Settlement Discipline measures and may expose firms to supervisory findings, sanctions and client detriment. Given the hard deadlines and dependency on technology and counterparties, non‑compliance risks crystallising as both regulatory breaches and material operational risk.
ESMA issues guidance on effective use of resolution tools in CCP crisis planning 13 May 2026 CCP The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, has today published a resolution briefing for Central Counterparties (CCPs). The briefing provides practical…
ESMA identifies areas for further supervisory convergence on compliance and internal audit in the funds sector 11 May 2026 Audit Fund Management The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, has published the results of its 2025 Common Supervisory Action…
Joint Committee annual report highlights digitalisation, cyber resilience and sustainable finance as key priorities of 2025 24 April 2026 Joint Committee The Joint Committee of the European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) today published its Annual Report for 2025 , setting out the main…
This regulatory update from the ECB Governing Council focuses on proposals to boost the competitiveness of the EU banking sector, including measures to simplify banking rules, enhance cross-border integration, and strengthen bank resilience.
This regulatory update from the ECB is focused on streamlining the supervision of banks' internal models for credit risk, which is a key prudential requirement. It impacts banks, asset managers, and wealth managers that use internal models.
ESAs spring risk update highlights geopolitical pressures and rising private finance risks 27 March 2026 Joint Committee Risk monitoring The European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) today published their spring 2026 Joint Committee update on risks and vulnerabilities in the EU financial…
Why this matters
The regulatory update highlights significant geopolitical risks and emerging risks in private finance that could impact the financial sector, particularly banks, asset managers, and insurers. Supervisors and firms are called to maintain vigilance and proactively assess and manage these risks.
This regulatory update from the ECB covers topics relevant to the banking and investment management sectors, including prudential requirements, operational resilience, and technology/cyber risks. It has a medium level of urgency as it discusses current challenges and future priorities for European banking supervision.
This speech discusses the growing role of synthetic risk transfers in the European banking sector, which are a tool for banks to manage their balance sheets and capital requirements.
This regulatory update from the ECB discusses simplifying banking supervision processes while maintaining prudential standards and resilience. It is relevant for banks, asset managers, and wealth managers in the banking and investment management sectors, covering topics around prudential requirements, operational...
This regulatory update discusses harmonization and diversity in banking regulation and supervision within the EU, covering topics such as the Single Rulebook, proportionality, and the ECB's supervisory approach. It is relevant for banks, wealth managers, and the broader financial sector.
This regulatory update discusses the interconnections between banks and non-bank financial institutions (NBFIs) in the context of a fragmented credit market. It highlights the challenges for banking supervision in identifying and monitoring concentration risks, as well as the need for enhanced data sharing and...
This regulatory update from the ECB focuses on upgrading banks' capacity to deal with digital risks, including IT change management, third-party dependencies, and cybersecurity testing. It is relevant for banks and fintechs and covers key operational resilience and technology/cyber topics.
This regulatory update from the ECB discusses the resilience of European banks, including their preparedness for geopolitical risks, interest rate changes, and non-performing loans.
This regulatory update from the ECB covers key topics for the banking and investment management sectors, including prudential requirements, operational resilience, and technology/cyber risks. It is of medium urgency as it provides an overview of the ECB's supervisory priorities and activities.
This regulatory update from the ECB covers key supervisory priorities and activities related to the resilience of the euro area banking sector, including managing geopolitical risks, credit risk, operational resilience, climate/environmental risks, and data aggregation/reporting.
This regulatory update from the ECB provides detailed supervisory banking statistics on significant institutions, covering key metrics such as capital ratios, asset quality, profitability, and liquidity.
EU financial markets enter 2026 amid high-risk environment 11 March 2026 Press Releases Risk monitoring The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, published today its first risk monitoring report of 2026 , outlining the key risks and vulnerabilities in EU…
Why this matters
The regulatory update discusses significant market volatility, cyber and hybrid threats, and operational risks in the EU financial markets, particularly impacting securities, crypto-assets, and financial infrastructures.
This regulatory update from the ECB covers topics relevant to banks, asset managers, and wealth managers, including prudential requirements, operational resilience, and the use of technology and AI models.
This regulatory update discusses the role of banks in promoting competitiveness and growth, with a focus on the importance of strong regulation and supervision in contributing to bank resilience and competitiveness.
ESMA consults on post-trade risk reduction services under EMIR 3 26 February 2026 Post Trading The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, has launched a consultation on the requirements for how post-trade risk reduction (PTRR) services can benefit from…
AI Analysis
ESMA has launched a consultation on draft Regulatory Technical Standards (RTS) that establish requirements for **post-trade risk reduction (PTRR) services** to qualify for a conditioned exemption from the mandatory clearing obligation under EMIR 3. This framework is critical because it balances market efficiency gains from risk reduction tools against systemic risk concerns, requiring compliance professionals to understand new operational, transparency, and monitoring requirements before the standards take effect.
Key dates
26 February 2026
- ESMA launches consultation
Q2 2026
- ESMA considers feedback received and prepares final report
20 April 2026 Deadline
- Deadline for stakeholder feedback submissions
Q4 2026
- Draft RTS submitted to the European Commission
Suggested considerations
*For PTRR Service Providers:
*Assess current operations against proposed RTS requirements, particularly regarding market risk neutrality and risk reduction thresholds
*Review algorithm safeguards and execution protocols to ensure compliance with transparency and non-discrimination standards
*Establish record-keeping systems capable of documenting PTRR exercises and demonstrating exemption qualification
*Prepare monitoring capabilities to support NCA oversight and supervisory reporting
What changed
The draft RTS introduce a structured framework governing how PTRR services operate under the clearing obligation exemption:
Eligible Service Types
The standards focus on three primary PTRR service...
Market risk neutrality in PTRR exercises—transactions must not alter the overall market risk profile of portfolios
Required risk reduction in submitted portfolios—genuine risk mitigation rather than speculative activity
Compliance with pre-agreed rules and reasonable, transparent, non-discriminatory conduct
Operational & Governance Framework
The RTS establish requirements across multiple dimensions:
Transparency towards participants in PTRR exercises
ESMA issues a supervisory briefing on algorithmic trading 26 February 2026 Trading The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, today published a supervisory briefing to support consistent supervision of algorithmic trading across the EU. The briefing…
Why this matters
This regulatory update from ESMA provides guidance and supervisory expectations for firms engaged in algorithmic trading, with a focus on areas such as pre-trade controls, governance, testing, and the use of emerging technologies like AI.
This regulatory update from the ECB covers key supervisory priorities for 2026-2028, including initiatives related to credit underwriting and geopolitical risk stress testing. These initiatives impact banks, asset managers, and wealth managers, and touch on prudential, operational, and sustainability-related topics.
This regulatory update from the ECB discusses the adoption of artificial intelligence (AI) in the banking sector, covering key areas such as governance, risk management, and the impact of generative AI.
ESMA consults on guarantees as CCP collateral and on certain aspects of CCP investment policy 23 February 2026 CCP The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, has launched a public consultation following the review of the European Market Infrastructure…
AI Analysis
ESMA has launched a public consultation under EMIR 3 to gather stakeholder input on conditions for CCPs accepting public guarantees, public bank guarantees, and commercial bank guarantees as collateral, eligibility of debt instruments for CCP investment policies, and secured arrangements for emission allowances as margins or default fund contributions. This matters because it permanently broadens eligible collateral types and extends access to NFC clients, enhancing EU CCP efficiency, competitiveness, and accessibility amid liquidity pressures in energy and other markets.
Key dates
End of 2026
- ESMA to submit final draft technical standards to the European Commission following final report preparation
30 April 2026 Deadline
- Consultation response deadline; submit online via ESMA portal, addressing specific questions with rationale
Suggested considerations
Review and Respond to Consultation: CCPs, clearing members, NFCs, and clients should analyze the paper, prepare responses to Annex 1 questions by 30 April 2026, and submit online; indicate confidentiality if needed.
Assess Internal Policies: CCPs must evaluate current collateral, investment, and emission allowance frameworks against proposed conditions; clearing members/NFCs should model impacts on liquidity and margin posting.
Monitor Developments: Track ESMA's final report and RTS submission; prepare for potential supervisory expectations on guarantee acceptance and debt instrument eligibility post-2026.
Engage with Industry: Join associations like EACH for coordinated feedback on risk-based approaches and proportionality.
What changed
- Permanent expansion of eligible CCP collateral to include public guarantees, public bank guarantees, and commercial bank guarantees, with specified conditions for acceptance.
Criteria for deeming debt instruments as eligible financial instruments under CCP investment policies.
Requirements for highly secured arrangements to deposit emission allowances as margins or default fund contributions.
These build on EMIR 3's measures to broaden collateral scope and entity coverage,...
Compliance impact
Urgency: High - Firms face a tight 2-month window (from 23 February 2026) to influence final RTS, with implementation likely in 2027+ affecting core clearing operations; delays risk non-compliance with broadened collateral rules amid ongoing liquidity strains, especially for NFCs in volatile markets like energy.
ESMA publishes a supervisory briefing on the AAR representativeness obligation 20 February 2026 CCP The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, has published a supervisory briefing on the representativeness obligation linked to the active account…
AI Analysis
ESMA has published supervisory guidance clarifying how counterparties must comply with the **representativeness obligation** under the Active Account Requirement (AAR), a key component of EMIR 3 that mandates EU counterparties maintain active accounts at EU central counterparties (CCPs) and clear representative volumes of derivatives trades. This briefing is critical because market participants and regulators have held conflicting interpretations of the representativeness requirement, creating compliance uncertainty that this guidance now resolves.
Key dates
26 February 2026
- AAR RTS enter into force (20 days after Official Journal publication on 6 February 2026)
31 July 2026 Deadline
- First EMIR 3 representativeness reporting deadline
31 January 2027 Deadline
- First AAR compliance report due
Suggested considerations
*Immediate (by 26 February 2026):
Review the ESMA supervisory briefing and Commission Delegated Regulation (EU) 2026/305 in detail
Assess whether your firm meets the €6 billion notional clearing volume outstanding threshold triggering AAR obligations
Identify internal teams responsible for AAR compliance (trading, operations, compliance, reporting)
*Short-term (by 31 July 2026):
What changed
The supervisory briefing addresses three core compliance areas:
Identifying Most Relevant Subcategories: Counterparties must continuously identify the five most relevant subcategories for each class of derivatives over each reference period, based on their trading activity. The guidance clarifies that the number of subcategories to select equals the maximum number available for that derivative class.
Representativeness Compliance Standard: Counterparties must clear, on an annual average basis, at least five trades in each of the most relevant subcategories per class of derivative contracts...
ESMA sanctions Regis-TR for serious breaches of organisational obligations 19 February 2026 Press Releases Securities Financing Transactions Supervision Trade Repositories The European Securities and Markets Authority (ESMA), the European Union’s (EU) financial markets regulator and supervisor, has fined the trade…
AI Analysis
ESMA has fined REGIS-TR, S.A. €1,374,000 for seven negligent breaches of organisational obligations under EMIR and SFTR, marking the first SFTR enforcement action and ESMA's highest fine against a trade repository. The breaches involved deficiencies in policies, procedures, organisational structure, operational risk management, and data confidentiality, compromising SFTR reporting and market data integrity. This underscores ESMA's intensified enforcement on trade repositories (TRs) to ensure high-quality data for market surveillance and financial stability.
Key dates
14 November 2013
- REGIS-TR initial registration with ESMA under EMIR
7 May 2020
- REGIS-TR registration extended to SFTR reporting
14 June 2024
- ESMA Supervisory Report identifying serious indications of breaches
17 June 2024
- Public notice references investigations leading to findings (dated in decision docs)
17 February 2026
- ESMA Board of Supervisors meeting discussing the case
Suggested considerations
For REGIS-TR specifically: Cease three ongoing breaches (policies/procedures under EMIR/SFTR; SFTR organisational structure for business continuity) per ESMA supervisory measures (EMIR Art. 73).
For all TRs:
- Review and strengthen policies/procedures for clarity on governance roles/responsibilities.
Audit organisational structure for SFTR business continuity and orderly functioning.
Conduct operational risk assessments, implementing controls/systems to minimise risks under EMIR/SFTR.
Enhance data confidentiality/integrity protections and misuse prevention measures.
What changed
This is an enforcement decision, not new legislation, but it reinforces existing EMIR and SFTR requirements on TRs, particularly:
Policies and procedures: Must be adequate to ensure compliance, with clear roles and responsibilities for governing bodies (breaches under EMIR Art. 78(3) and SFTR Art.
Organisational structure: Must ensure business continuity and orderly functioning, especially for SFTR services (breach under SFTR).
Operational risk management: Identify and minimise risks via systems, controls, and procedures (breaches under EMIR and SFTR, Point (a) Section II Annex I EMIR).
Data confidentiality and integrity: Protect information received under EMIR and prevent misuse (breaches under EMIR).
Fines were calculated per EMIR Art.
Compliance impact
Urgency: High – As the first SFTR enforcement and record TR fine (€1.374M), it demonstrates ESMA's commitment to punitive action on negligence causing systemic data risks, directly threatening market integrity and surveillance. TRs face immediate remediation pressure (three breaches ongoing), with fines amplified by duration/systemic factors; non-TRs using TRs risk indirect exposure via poor data quality. Firms should prioritise audits now to avoid similar "negligent" findings.
ESMA publishes list of supplementary deferrals for sovereign bonds 19 February 2026 Post Trading The European Securities and Markets Authority (ESMA), together with National Competent Authorities (NCAs), has agreed supplementary deferrals that may be applied on top of the standard Markets in Financial Instruments…
AI Analysis
ESMA has authorized **supplementary deferrals for sovereign bond post-trade transparency**, allowing market participants to omit transaction volumes from immediate publication for medium-sized trades on liquid bonds, with full disclosure required by end-of-day. This measure balances market transparency with liquidity protection in EU sovereign bond markets, effective May 4, 2026, with a compressed implementation timeline requiring immediate compliance planning.
Key dates
February 17, 2026
- ESMA Board of Supervisors adopts decision
February 19, 2026
- ESMA publishes supplementary deferrals list
March 2, 2026
- Original implementation date (subsequently extended)
May 4, 2026
- **Effective date for supplementary deferrals application**
Suggested considerations
*Immediate Compliance Preparation (by May 4, 2026)
*System Configuration: Trading venues and investment firms must update post-trade reporting systems to implement volume omission deferrals for Group 1, Category 1 sovereign bonds, with automated end-of-day publication triggers.
*Instrument Classification: Establish processes to correctly identify which sovereign bonds qualify as Group 1, Category 1 under Commission Delegated Regulation (EU) 2017/583 (RTS 2), referencing Table 2.6 of Annex III.
*APA Coordination: Approved Publication Arrangements must configure deferral management services to apply volume omission rules consistently across all reporting firms, with fallback procedures for system failures.
*Policy Documentation: Update post-trade transparency policies, procedures, and client disclosures to reflect the new deferral regime and explain the timing of volume publication.
What changed
Scope of Supplementary Deferrals
The decision permits volume omission deferrals for sovereign bonds classified as Group 1, Category 1 instruments (medium-size, liquid instruments) under MiFIR's post-trade transparency framework. Market operators and investment firms may defer publication of transaction volumes until end-of-trading-day, rather than the standard 15-minute deferral period.
Regulatory Rationale
ESMA determined that these deferrals are necessary to account for specific characteristics of sovereign bond markets, particularly protecting market liquidity and ensuring orderly price...
This regulatory update discusses the establishment of the European Anti-Money Laundering Authority (AMLA) and its impact on banking supervision, particularly in relation to money laundering and terrorist financing risks.
This regulatory update from the ECB covers the recovery of the Cypriot banking sector from the 2013 financial crisis, including improvements in asset quality, non-performing loans, and the role of bank supervision. It also discusses cross-border banking activity and cooperation within the European banking union.
This regulatory update discusses competitiveness and capital requirements in the European banking sector, which is relevant for banks, asset managers, and wealth managers. It covers prudential and operational resilience topics, as well as reporting and disclosure requirements.
This regulatory update from the ECB discusses geopolitical risks and their impact on the banking sector, including potential disruptions to financial markets, credit risk, and operational resilience. It is relevant for banks, asset managers, and wealth managers.
This speech covers the ECB's approach to digital transformation and innovation in the banking sector, with a focus on the opportunities and risks of technologies like AI and tokenization.
This letter from the ECB Supervisory Board Chair to an MEP likely contains information relevant to banking supervision, prudential requirements, and operational resilience, which are of medium importance to banks, asset managers, and wealth managers.
This regulatory update from the ECB discusses the approach to simplification in banking regulation and supervision, which is relevant for banks, asset managers, and wealth managers in terms of prudential requirements, operational resilience, and reporting.
The European Supervisory Authorities and UK financial regulators sign Memorandum of Understanding on oversight of critical ICT third-party service providers under DORA 14 January 2026 Digital Finance and Innovation International cooperation The European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) have…
Why this matters
This regulatory update is relevant for banks, asset managers, and wealth managers as it covers the oversight of critical ICT third-party service providers under the Digital Operational Resilience Act (DORA).
ESMA’s Digital and Data strategies support supervision of EU financial markets 13 January 2026 About ESMA Market data Press Releases The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, has adopted a new Digital Strategy and updated its Data Strategy . They reflect…
Why this matters
This regulatory update from ESMA focuses on the adoption of new digital and data strategies to support the supervision of EU financial markets. It covers topics related to technology, data reporting, and operational resilience, which are relevant across various financial sectors including capital markets, crypto...
Principles for risk-based supervision: a critical pillar for ESMA’s simplification and burden reduction efforts 09 January 2026 Supervision The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, published today its principles for risk-based supervision . These…
Why this matters
This speech from ESMA outlines principles for risk-based supervision, which is a critical component of regulatory oversight and compliance for financial firms across the capital markets and investment management sectors.
ESMA publishes latest Spotlight on Markets newsletter featuring updates on market integration and transparency 23 December 2025 ESMA newsletter The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, has today published the latest edition of its Spotlight on Markets…
AI Analysis
ESMA's latest *Spotlight on Markets* newsletter (November/December 2025 issue, published 23 December 2025) summarizes key regulatory updates on EU market integration, transparency enhancements, and supervisory actions, including welcoming the European Commission's market integration proposal and announcing an equity consolidated tape provider (CTP) selection. This matters for compliance professionals as it signals accelerating EU efforts to deepen capital markets integration, improve data transparency, and strengthen oversight under MiFID II and DORA, potentially requiring firms to adapt governance, reporting, and conflict management practices.
Key dates
4 December 2025
- European Commission publishes market integration legislative package; legislative process expected to take at least one year
23 December 2025
- Newsletter publication date
Suggested considerations
Review the final non-equity transparency RTS and assess impacts on trading and reporting systems for compliance by any upcoming application dates (not specified).
Evaluate MiFID II conflicts of interest policies in preparation for the CSA; conduct internal audits and enhance training/staff attestations on identification and mitigation.
Monitor equity CTP rollout for changes to post-trade data access and costs; update vendor contracts if applicable.
For DORA-impacted firms, map exposures to designated critical ICT providers and strengthen due diligence, contractual clauses, and exit strategies.
Asset managers: Audit fund names against guidelines and review UCITS distribution practices for cost transparency.
What changed
- ESMA welcomes the European Commission's 4 December 2025 legislative package on market integration, emphasizing robust governance and market infrastructure for deeper EU capital markets.
Announcement of selected applicant for the equity consolidated tape provider (CTP), advancing MiFIR transparency for equity markets by improving post-trade data consolidation and access.
Publication of ESMA's final report on Regulatory Technical Standards (RTS) for non-equity transparency, clarifying pre- and post-trade transparency rules for bonds, derivatives, and other non-equity...
Launch of a Common Supervisory Action (CSA) on MiFID II conflicts of interest requirements to promote supervisory convergence and governance across Member States.
European Supervisory Authorities (ESAs) designate critical ICT third-party providers under DORA, enhancing oversight of key outsourcing risks.
Compliance impact
Urgency: Medium - The newsletter highlights finalized standards (e.g., RTS, CTP) and imminent actions (e.g., CSA, DORA designations) that require proactive preparation, but lacks hard deadlines or immediate mandates. It matters because it previews intensified supervision on transparency, conflicts, and resilience, aligning with EU Capital Markets Union goals; firms delaying reviews risk findings in upcoming CSAs or audits, especially amid ESMA's push for convergence.
This regulatory update from the ECB provides guidance on the notification of significant risk transfer and implicit support for securitisations, which is relevant for banking, investment management, and capital markets firms.
This regulatory update from the ECB appears to be focused on supervisory banking statistics for significant institutions, which is relevant for banks, asset managers, and wealth managers in terms of prudential requirements, reporting, and operational resilience.
This regulatory update from the ECB indicates that they will be assessing banks' stress testing capabilities to capture geopolitical risk. This is relevant for banking, investment management, and wealth management firms, as they will need to ensure their risk management frameworks are robust enough to handle potential...
This regulatory update from the ECB proposes simplification of EU banking rules, which would impact banks, asset managers, and wealth managers in the banking and investment management sectors. The key topics covered are prudential/capital requirements, operational resilience, and reporting/disclosure.
This regulatory update from the ECB focuses on streamlining and enhancing the effectiveness of European banking supervision, which is relevant for banks, asset managers, and wealth managers.
This speech from the ECB discusses evidence-based supervision and addressing evolving risks to maintain resilience, which is relevant for banking, investment management, and wealth management firms from a prudential, operational, and technology perspective.
This regulatory update from the ECB relates to an asset quality review of Raiffeisen-Holding Niederösterreich-Wien, which is a bank. The topics covered include prudential and capital requirements, operational resilience, and reporting and disclosure, which are relevant for the banking sector.
This regulatory update from the ECB discusses supervision and governance in uncertain times, which is relevant for banking, investment management, and wealth management firms. The key topics covered include prudential requirements, operational resilience, and senior management responsibilities.
This appears to be an informational fireside chat with Pedro Machado from the ECB, covering topics relevant to banking, investment management, and wealth management firms, including prudential requirements, operational resilience, and governance.
This regulatory update is relevant for banks, fintechs, and crypto exchanges as it provides guidance on implementing the TIBER-EU framework for digital operational resilience, which is a key requirement under the DORA regulation.
This regulatory update from the ECB discusses the importance of resilient banks in building Europe's economic growth, highlighting topics related to prudential requirements, operational resilience, and ESG considerations.
This regulatory update from the ECB discusses improving banks' resilience to hybrid threats, which is relevant for banking, investment management, and wealth management firms.
This appears to be an introductory statement from Claudia Buch of the ECB, which is likely to cover high-level regulatory and supervisory topics relevant to banks, asset managers, and wealth managers, including prudential requirements, operational resilience, and governance.
This regulatory update from the ECB relates to capital requirements for banks, which is a key prudential topic. It also touches on operational resilience and reporting, which are important for a range of financial firms.
This regulatory update from the ECB likely covers supervisory priorities and expectations for the banking and investment management sectors, focusing on prudential requirements, operational resilience, and reporting/disclosure.
This regulatory update from the ECB discusses the importance of effective supervision for building resilient banks, which is a key pillar of Europe's competitiveness.
This regulatory update from the ECB appears to be focused on supervisory banking statistics for significant institutions, which would be relevant for banks, asset managers, and wealth managers in terms of prudential requirements, reporting, and operational resilience.
This letter from the ECB Supervisory Board Chair to an MEP likely contains information relevant to banking supervision, including prudential requirements, operational resilience, and governance. It is informational in nature.
This regulatory update from the ECB appears to be focused on supervisory banking statistics for significant institutions, which is relevant for banks, asset managers, and wealth managers in terms of prudential requirements, reporting, and operational resilience.
This regulatory update provides high-level individual results for banks not included in the EBA sample, which is relevant for banking, investment management, and wealth management firms. The topics covered include prudential/capital requirements, reporting and disclosure, and operational resilience.
This regulatory update from the ECB appears to focus on counterparty credit risk, which is a key prudential concern for banks, investment managers, and capital markets participants. The exploratory scenario exercise suggests the need for enhanced operational resilience and reporting in these areas.