EBA, EIOPA and ESMA call for enhanced governance and consistent supervision to mitigate ICT risks from frontier AI models in the EU financial sector 31 July 2026 Digital Finance and Innovation Joint Committee The European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) today published a statement calling for a cross-sectoral, risk-based and consistent supervisory approach to mitigate the ICT risks stemming from frontier AI models. The statement takes into account existing regulatory ...
All Firms
No description available.
Bank
New Q&As available 10 July 2026 Digital Finance and Innovation Sustainable finance Trading The European Securities and Markets Authority (ESMA), the EU's securities markets regulator, has published the following question and answer: EU ESG Ratings Regulation (ESGRR) Consulting activities to investors or undertakings (2889) Application of two working day notification period (2719) Scope of two working day notification period (2890) Access to dataset for factual error review (2891) Notification...
What Changed
- - ESMA added a Q&A clarifying consulting activities to investors or undertakings under the EU ESG Ratings Regulation (ESGRR), which is relevant where a ratings provider’s advisory services may...
- ESMA added Q&As on the application and scope of the two working day notification period under ESGRR, indicating that firms must apply the notification clock consistently and in line with ESMA’s...
- ESMA clarified access to the dataset for factual error review under ESGRR, which affects how rated entities or issuers can review underlying data used in ESG ratings processes.
- ESMA added a Q&A on notifications without a designated contact under ESGRR, which is relevant for governance and outreach workflows when a notification lacks an identified recipient.
- ESMA clarified the obligation to consider issuer feedback under ESGRR, reinforcing that issuer comments cannot be ignored and must be handled through a documented review process.
Suggested Considerations
- Review ESG ratings policies to ensure consulting, notification, issuer feedback, and factual error review procedures align with ESMA’s latest ESGRR Q&As.
- Update internal case-handling workflows so notifications are screened for the designated contact issue and the two-working-day notification period is calculated consistently.
- Document how your firm distinguishes internal-use ESG ratings or in-house financial services from externally provided ESG ratings activity.
- Reassess whether any second-party opinion business can rely on the ESGRR exemption and record the legal basis for that conclusion.
- Re-map MiCA permissions for custody, administration, transfer, and lending services to confirm the firm is not performing activities outside its authorisation scope.
Key Dates
- ESMA publishes the new Q&As on ESGRR, MiCA, and MiFIR secondary market topics
Compliance Impact
Non-compliance risk is high because these Q&As affect how firms interpret regulatory scope, notification timing, and operational controls across sustainability, crypto, and market structure regimes. Firms that ignore the guidance may face supervisory challenge, remediation costs, and potential findings that their current procedures, permissions, or disclosures are misaligned with ESMA’s expectations.
AI-generated analysis. May contain errors or omissions — verify with the
original ESMA source
before acting. Full disclaimer.
All FirmsAsset ManagerBroker Dealer ESMA launches Common Supervisory Action on CASPs’ digital operational resilience for custody 08 July 2026 Digital Finance and Innovation The European Securities and Markets Authority (ESMA), the EU regulator and supervisor, is launching a Common Supervisory Action (CSA) focusing on the digital operational resilience of Crypto-Asset Service Providers (CASPs), with a specific emphasis on custody services. The CSA will assess the maturity of CASPs’ digital operational resilience frameworks in re...
Crypto ExchangeFintech
The ESAs support ESRB warning on systemic cyber risks from frontier AI models 07 July 2026 Digital Finance and Innovation Joint Committee Press Releases The European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) welcome and support today’s warning from European Systemic Risk Board (ESRB) on the systemic cyber risks posed by frontier AI models. Recent advances have significantly enhanced the ability of frontier AI models to identify and exploit high-severity vulnerabilities in IT sy...
All Firms
No description available.
Bank
No description available.
Bank
No description available.
Bank
No description available.
BankPayment Provider
ESMA 2025 Annual Report: focus on stronger supervision, regulatory simplification, and innovation 17 June 2026 About ESMA Board of Supervisors Management Board Press Releases The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, has today published its Annual Report for 2025 , highlighting a year of progress in strengthening EU’s financial markets through enhanced supervision, regulatory simplification and innovation. Set against a backdrop...
Asset ManagerBroker DealerCrypto Exchange
No description available.
Bank
No description available.
Bank
No description available.
BankInsuranceAll Firms
ESAs publish the first report on DORA major ICT-related incidents 03 June 2026 Digital Finance and Innovation Joint Committee The European Supervisory Authorities (EBA, EIOPA and ESMA) today published their first annual overview of major ICT-related incidents in the EU financial sector based on a reporting mechanism established by the Digital Operational Resilience Act (DORA). It shows that ICT risks are increasingly borderless and interconnected. The authorities also note that the recent evo...
The ESAs (EBA, EIOPA and ESMA) have published their first annual report under Article 22(2) DORA, aggregating 3,383 **major ICT‑related incidents** reported by EU financial entities and highlighting that roughly one third had a cross‑border impact. This is an early supervisory “heat map” of DORA incident reporting and sends a clear signal that competent authorities will focus on cross‑border ICT risk, third‑party/outsourcing failures and the adequacy of firms’ incident classification and reporting frameworks.
What Changed
- - The ESAs have operationalised Article 22(2) DORA by issuing the first annual overview of major ICT‑related incidents, confirming that yearly ESA‑level aggregation and analysis of incident data is...
- Incident reporting under DORA is now demonstrably harmonised and centralised, with major ICT‑related incidents being notified to all competent authorities involved and then aggregated by the ESAs for...
- The report confirms that cross‑border incidents are prevalent (around one third of major incidents), reinforcing that the “borderless and interconnected” nature of ICT risk is a key supervisory...
- System failures and external events, rather than pure cyber‑attacks, are identified as the main drivers of major incidents, placing regulatory emphasis on ICT change management, resilience of core...
- The ESAs highlight third‑party and outsourcing risk as a core theme, stressing the need for robust oversight of ICT service providers and close coordination with them during incident response and...
Suggested Considerations
- Review and, where necessary, recalibrate internal incident classification criteria against the DORA definition of “ICT‑related incident” and “major ICT‑related incident”, ensuring consistency with applicable RTS on classification and materiality thresholds.
- Validate that your firm’s incident management and escalation processes can identify, assess and classify incidents “without undue delay” and trigger major‑incident reporting within the prescribed timelines (initial, intermediate and final reports).
- Conduct a gap analysis of cross‑border incident handling, ensuring that governance, communication and coordination arrangements adequately address incidents affecting multiple Member States or shared cross‑border infrastructures.
- Strengthen third‑party and outsourcing risk management by mapping critical and important functions to their supporting ICT service providers, and ensuring contracts, SLAs and incident‑response clauses support DORA reporting and cooperation obligations.
- Test and, if needed, enhance incident response runbooks to ensure close coordination with ICT service providers during incident containment, remediation and recovery, including clear roles for data provision required for regulatory reporting.
Key Dates
– DORA (Regulation (EU) 2022/2554) applies, and financial entities become obliged to report major ICT‑related incidents to their competent authority once classification thresholds are met
– Under Article 22(2) DORA, the ESAs must issue a yearly report covering number, nature, impact, remedial actions and costs of major ICT‑related incidents; the publication in early June 2026 is the first such report and sets the expectation for future annual cycles
Compliance Impact
Non‑compliance with DORA incident management and reporting obligations can lead to supervisory findings, administrative sanctions, and heightened intrusive supervision, especially where cross‑border incidents or third‑party failures are not properly reported or managed. Given the ESAs are now publicly benchmarking the sector, firms whose reporting patterns appear inconsistent with peers face increased risk of challenge on classification practices and operational resilience adequacy.
AI-generated analysis. May contain errors or omissions — verify with the
original ESMA source
before acting. Full disclaimer.
BankAsset ManagerInsurance No description available.
Bank
ESMA’s annual data report shows increased quality, wider use and digital progress 29 May 2026 Market data The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, published today its annual report on the quality and use of regulatory data . It shows that improvements in data quality and data use reinforce each other in a virtuous cycle, supporting more effective supervision and market monitoring across the EU. This year’s edition reflects an e...
ESMA’s latest annual report on the **quality and use of regulatory data** confirms a material step‑up in supervisory reliance on EMIR, SFTR, MiFIR, AIFMD and MMFR datasets, alongside new inclusion of Prospectus and DORA ICT‑incident reporting. For compliance teams this is a clear signal that data quality is now an enforcement‑relevant topic across a broader perimeter, and that ESMA is actively moving toward **streamlined, “report once” cross‑regime reporting** and an integrated funds reporting framework, which will reshape reporting architecture and controls over the next 1–3 years.
What Changed
- - ESMA confirms measurable data quality improvements across EMIR, SFTR, MiFIR, AIFMD and MMFR regulatory datasets, indicating that regulators now consider these data sufficiently reliable for...
- ESMA highlights extensive and growing supervisory use of regulatory data by ESMA and NCAs for investor protection, financial stability, orderly markets and market integrity, increasing the...
- The scope of the annual data quality and use report is expanded to include Prospectus reporting obligations, bringing prospectus‑related data formally into ESMA’s cross‑regime data quality scrutiny.
- The report scope is also expanded to include ICT‑related incident reporting under the Digital Operational Resilience Act (DORA), signaling that operational resilience incident data will be monitored...
- ESMA has launched a 2025 Call for Evidence on streamlining reporting across EMIR, MiFIR and SFTR, including options to remove duplications and apply a “report once” approach, which will likely lead...
Suggested Considerations
- Map all existing regulatory reporting obligations across EMIR, SFTR, MiFIR, AIFMD, MMFR, Prospectus and DORA ICT‑incident reporting, and document the underlying data sources, systems and ownership for each regime.
- Review and enhance data quality controls for EMIR, SFTR and MiFIR reporting, including validation rules, completeness checks, reconciliations, pairing and matching processes, and governance around Unique Transaction Identifiers and counterparty data.
- Perform a gap analysis of Prospectus reporting and DORA ICT‑incident reporting processes against ESMA’s emerging cross‑regime data quality expectations and ensure they are covered in the firm’s enterprise data governance framework.
- Establish or update a centralised regulatory data governance framework that explicitly covers cross‑regime consistency (for example, trade and position data alignment between EMIR, SFTR and MiFIR) and defines clear accountability at senior management level.
- Engage with internal IT and reporting teams to identify where a future “report once” model could be supported technically, including harmonised reference data, common identifiers and golden‑source transaction and position records.
Key Dates
– ESMA’s Call for Evidence on streamlining reporting across EMIR, MiFIR and SFTR is scheduled, with stakeholders expected to provide input on duplication removal and “report once” options
– ESMA will host a webinar to present the main findings of the annual report on the quality and use of regulatory data
Compliance Impact
Regulatory data reported under EMIR, SFTR, MiFIR, AIFMD, MMFR, Prospectus rules and DORA is increasingly used for day‑to‑day supervision, thematic reviews and enforcement, making poor data quality a direct source of regulatory, reputational and potentially financial sanctions risk. As ESMA and NCAs deploy more automated, risk‑based data quality tools, firms with weak controls or inconsistent cross‑regime reporting will be more visible and more likely to face targeted supervisory action.
AI-generated analysis. May contain errors or omissions — verify with the
original ESMA source
before acting. Full disclaimer.
BankBroker DealerAsset Manager No description available.
All Firms
ESMA issues guidance on effective use of resolution tools in CCP crisis planning 13 May 2026 CCP The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, has today published a resolution briefing for Central Counterparties (CCPs). The briefing provides practical guidance to National Resolution Authorities (NRAs) on how to operationalise the write-down and conversion of instruments tool (WDCI). Marking an important step in ESMA’s wider efforts ...
All Firms
No description available.
All Firms
No description available.
Bank
European Commission launches call for candidates for the ESAs’ Board of Appeal 12 May 2026 Board of Appeal The European Commission has launched a call for expression of interest for the appointment of members to the Board of Appeal of the three European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs). This call aims to establish a reserve list of qualified candidates to fill vacancies that may arise within the Board of Appeal. The reserve list will remain valid for a period of five y...
All Firms
No description available.
All Firms
ESMA identifies areas for further supervisory convergence on compliance and internal audit in the funds sector 11 May 2026 Audit Fund Management The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, has published the results of its 2025 Common Supervisory Action (CSA) on the compliance and internal audit functions of fund managers , carried out in with the participation of all EU and EEA national supervisors. The EU-wide review found that m...
Asset Manager
No description available.
All Firms
No description available.
All Firms
ESMA outlines enforcement activities for corporate reporting across the EEA in 2025 07 May 2026 Corporate Finance Electronic reporting Financial reporting Sustainable finance The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, has today published its Report on 2025 Corporate reporting enforcement and regulatory activities . The report provides an overview of how national enforcers and ESMA supervised corporate reporting across the Europea...
All Firms
ESMA consults on a new simplified approach to updating MMF stress test parameters 05 May 2026 Fund Management Simplification and Burden Reduction The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, has today launched a consultation on a new approach to updating the parameters for stress test scenarios under the Money Market Funds framework. ESMA proposes replacing the current annual amendments to Section 5 of the Guidelines with an annual...
All Firms
ESMA promotes proportionate supervision of MiFID II sustainability requirements 06 May 2026 Investor protection The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, has issued a statement presenting the results of its Common Supervisory Action (CSA) on how sustainability is integrated into firms’ suitability assessment as well as into processes and procedures for product governance. The statement highlights key themes emerging from the sup...
All Firms
No description available.
Bank
ESMA advances the simplification of EU reporting frameworks for funds and transactions 04 May 2026 Fund Management Market data Press Releases Securities Financing Transactions Simplification and Burden Reduction The European Securities and Markets Authority (ESMA), the EU financial markets regulator and supervisor, has launched a harmonised approach to funds reporting and has set a clear path towards streamlined, more efficient transaction reporting across European markets. The two reports pu...
All Firms
No description available.
All Firms
ESMA launches its sixth stress test exercise for Central Counterparties 30 April 2026 CCP Press Releases The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, today launched its sixth stress test exercise for Central Counterparties (CCPs) . The CCP stress test framework drafted by ESMA for the purpose of this exercise is supported by an adverse market scenario provided by the European Systemic Risk Board (ESRB). Mandated under the European ...
All Firms
ESMA launches a call for evidence on the structure of European equity markets 30 April 2026 Trading The European Securities and Markets Authority (ESMA) has published a call for evidence (CfE) presenting a data driven analysis of the evolution of trading in European equity markets between 2022 and 2025, based on MiFIR transaction reporting data. The CfE invites stakeholder feedback on observed trends and their potential regulatory implications. The analysis shows that European equity markets ...
Broker Dealer
ESMA consults on guidelines on endorsement under the ESG Ratings Regulation 29 April 2026 Credit Rating Agencies The European Securities and Markets Authority (ESMA) has launched a public consultation on draft guidelines on endorsement under the ESG Ratings Regulation 1 . The consultation paper sets out ESMA’s proposed approach to the endorsement of non-EU ESG ratings under the regulatory framework and seeks feedback from ESG rating providers and other stakeholders on the draft guidelines. Th...
All Firms
No description available.
Bank
Joint Committee annual report highlights digitalisation, cyber resilience and sustainable finance as key priorities of 2025 24 April 2026 Joint Committee The Joint Committee of the European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) today published its Annual Report for 2025 , setting out the main priorities and achievements of its cross-sectoral work over the past year. In 2025, the Joint Committee focused on protecting consumers in increasingly digital financial markets, stren...
Fintech
No description available.
All Firms
No description available.
All Firms
ESMA support ESEF implementation with updated taxonomy 21 April 2026 Electronic reporting The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, has published the 2025 European Single Electronic Format (ESEF) XBRL taxonomy files , together with an updated ESEF Conformance Suite . These materials support issuers and software vendors in preparing 2026 IFRS consolidated financial statements using the most up‑to‑date ESEF format. The 2025 taxono...
All Firms
ESMA releases reporting templates and instructions for the Active Account Requirement 13 April 2026 CCP Market data The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, has published the reporting templates and instructions for the Active Account Requirement (AAR) reporting under European Market Infrastructure Regulation (EMIR 3). The new templates set out in detail how entities subject to the AAR should report the required information to ...
All Firms
No description available.
BankAsset ManagerBroker Dealer
No description available.
BankWealth ManagerAll Firms
No description available.
BankAsset ManagerWealth Manager
No description available.
BankWealth ManagerAll Firms
No description available.
BankFintech
No description available.
Bank
No description available.
BankAsset ManagerWealth Manager
EU financial markets enter 2026 amid high-risk environment 11 March 2026 Press Releases Risk monitoring The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, published today its first risk monitoring report of 2026 , outlining the key risks and vulnerabilities in EU financial markets. ESMA finds that risks of market and systemic stress remain high despite resilient market performance in the second half of 2025. Our risk assessment for the s...
BankBroker DealerCrypto Exchange No description available.
BankAsset ManagerWealth Manager
No description available.
BankAsset ManagerBroker Dealer
No description available.
BankAsset ManagerWealth Manager
ESMA issues a supervisory briefing on algorithmic trading 26 February 2026 Trading The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, today published a supervisory briefing to support consistent supervision of algorithmic trading across the EU. The briefing provides National Competent Authorities (NCAs) with practical tools and clarified expectations for supervising firms engaged in algorithmic trading under MiFID II. It focuses on key a...
Broker DealerFintechAll Firms
No description available.
BankAsset ManagerWealth Manager
ESMA publishes latest edition of its newsletter 13 February 2026 ESMA newsletter The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, has published today its latest edition of the Spotlight on Markets Newsletter. This edition opens with ESMA’s Digital and Data Strategies , outlining how enhanced data use and improved digital tools will strengthen effective and risk-based supervision. Top news highlights include the launch of the selection ...
Asset ManagerBroker DealerCrypto Exchange No description available.
BankAsset ManagerWealth Manager
Join us for ESMA’s Conference “A new era for EU capital markets” on 21 May 2026 05 February 2026 About ESMA The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, is organising a high‑level conference “A new era for EU capital markets” on 21 May 2026 in Paris, France. Marking ESMA’s 15-year anniversary, the conference will bring together senior policymakers, regulators, leaders of major market infrastructures and financial institutions, as w...
Asset ManagerBroker DealerBank
No description available.
BankFintechCrypto Exchange No description available.
BankWealth ManagerFintech
The European Supervisory Authorities and UK financial regulators sign Memorandum of Understanding on oversight of critical ICT third-party service providers under DORA 14 January 2026 Digital Finance and Innovation International cooperation The European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) have today signed a Memorandum of Understanding (MoU) with the Bank of England (BoE), the Prudential Regulation Authority (PRA), and the Financial Conduct Authority (FCA). This agreement...
BankAsset ManagerWealth Manager
ESMA’s Digital and Data strategies support supervision of EU financial markets 13 January 2026 About ESMA Market data Press Releases The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, has adopted a new Digital Strategy and updated its Data Strategy . They reflect ESMA’s commitment to smarter regulatory reporting and technology-driven supervision, promote synergies and innovation while reducing unnecessary complexity. The digital strategy...
All Firms
No description available.
BankAsset ManagerWealth Manager
No description available.
BankAsset ManagerWealth Manager
No description available.
BankFintechCrypto Exchange
No description available.
BankWealth ManagerAll Firms