The European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) have identified external dependencies, emerging technologies and private credit as key vulnerabilities for the EU financial system in their Autumn 2026 risk update.
Why this matters
This is an Autumn 2026 risk update and press release from the three ESAs (EBA, EIOPA, ESMA) presenting findings on systemic vulnerabilities. The content is informational and advisory in nature—calling for vigilance and preparedness rather than imposing new rules or enforcement actions.
As part of the European Banking Authority’s (EBA) ongoing efforts to simplify its regulatory framework, the Guidelines focus on third-party arrangements supporting critical or important functions (CIFs) namely the disruption of which would materially impair the performance of a financial entity. By concentrating on…
Why this matters
This is a final EBA guideline publication establishing mandatory requirements for third-party risk management across ICT and non-ICT services. It applies to critical or important functions and covers the full lifecycle of third-party arrangements.
Following a plenary vote in the European Parliament, Thomas Gstädtner has been confirmed as the new Executive Director of the European Banking Authority (EBA). Thomas Gstädtner, who will serve a five-year renewable term, was selected by the EBA Board of Supervisors from a shortlist of candidates following an open…
Why this matters
The update announces the European Parliament's confirmation of Thomas Gstädtner as Executive Director of the EBA following an open selection procedure. It is purely informational and administrative in nature, containing biographical details and congratulatory statements but no regulatory substance, binding...
The European Banking Authority (EBA) issued today an updated list of validation rules defined in its reporting frameworks, as part of its regular quarterly review process. The revised package identifies rules that (i) have been deactivated due to inaccuracies or IT-related issues, or (ii) have been reactivated.
Why this matters
The EBA's quarterly validation rules update is a standard administrative exercise. While it affects EU banks' supervisory reporting compliance, the content is primarily technical maintenance (deactivation/reactivation of rules, taxonomy and DPM script updates) rather than a new policy or enforcement action.
The EBA acknowledges the European Commission’s non-adoption of the targeted amendments of the Commission Delegated Regulation (EU) No 241/2014 aimed at shortening the application period for reducing own funds and eligible liabilities instruments.
Why this matters
This is an informational news item reporting the European Commission's decision not to endorse EBA draft Regulatory Technical Standards on prior permission applications for reducing own funds and eligible liabilities instruments.
The European Banking Authority (EBA) today published an Opinion in response to the observations made by European Parliament in its 2024 Discharge Report covering all agencies, including the EBA. The EBA welcomes the overall positive feedback from the European Parliament. Only nine observations of the Parliament’s…
Why this matters
This is a routine administrative communication from the EBA responding to parliamentary oversight. The content confirms that only nine observations mentioned the EBA and none warrant specific follow-up actions.
The European Banking Authority (EBA) today launched a public consultation on draft Regulatory Technical Standards (RTS) specifying the operational risk management framework that institutions must have in place as per Article 323 of the Capital Requirements Regulation (CRR3). The draft RTS set out harmonised…
AI Analysis
The EBA launched a consultation on draft Regulatory Technical Standards under Article 323(2) of Regulation (EU) No 575/2013, as amended by CRR3 Regulation (EU) 2024/1623, defining institutions’ operational risk management framework. The draft would harmonise governance, operational risk processes, assessment systems, data, taxonomy, reporting, validation and audit requirements, with reduced granularity and review/reporting frequency for institutions with a business indicator below EUR 750 million.
Key dates
2026-08-26
EBA consultation launched and consultation period opened.
2026-09-25 Deadline
Deadline to register for the EBA virtual public hearing, at 16:00 CEST.
2026-09-29
EBA virtual public hearing from 10:00 to 12:00 CEST (Paris time).
2026-12-31 Deadline
Deadline for submitting consultation responses to the EBA, at 23:59 CEST.
Suggested considerations
Compliance and operational-risk teams should obtain and map the consultation draft against Article 323(1), points (a) to (h), of the CRR and identify requirements that would require changes to policies, committee mandates, controls or management information.
Institutions should determine their business indicator and assess whether it is below the proposed EUR 750 million proportionality threshold, while treating that threshold as proposed rather than final.
Firms should inventory operational-risk data sources, loss-event thresholds, taxonomies, reporting processes, validation controls and audit coverage, and assess whether data granularity is sufficient for the proposed framework.
Management-body and senior-management responsibilities should be compared with existing governance arrangements, including the independence, authority and resourcing of the operational risk management function.
Firms should assess alignment between the proposed RTS, CRR3 operational-risk capital and reporting implementation, the EBA Guidelines on internal governance and DORA, avoiding duplication or gaps for ICT-related risk.
Affected stakeholders should consider submitting comments to the EBA by 31 December 2026; compliance teams may wish to coordinate responses with risk, finance, internal audit and industry associations.
Stakeholders wishing to participate in the EBA public hearing should register by 25 September 2026 at 16:00 CEST and prepare questions on proportionality, data granularity, thresholds, reporting frequency and implementation timing.
Institutions should monitor the EBA’s final draft, the European Commission’s endorsement process and the eventual application date before treating the consultation text as a binding requirement.
What changed
The proposed RTS would give detailed effect to Article 323(1), points (a) to (h), of the CRR by requiring three framework components: governance arrangements, an operational risk management process and an operational risk assessment system. They clarify responsibilities of the management body, senior management and the independent operational risk management function, and address operational risk data and taxonomy, the business indicator component, reporting, validation and audit. ICT risk requirements are intended to remain governed primarily by Regulation (EU) 2022/2554 (DORA).
Compliance impact
The proposal is not yet legally binding, but it signals material future supervisory expectations for operational-risk governance, data quality, taxonomy, monitoring, validation and audit across CRR3 institutions. Impact is likely to be highest for institutions whose existing frameworks were designed around legacy operational-risk approaches or whose loss data and management information cannot support the proposed harmonised requirements; institutions below EUR 750 million business indicator should receive proportional relief, subject to the final text.
The European Banking Authority (EBA) today launched a consultation on three draft Regulatory Technical Standards (RTS) on the reclassification of investment firms as credit institutions, when they exceed the EUR 30 billion total assets threshold. The proposals clarify how total assets should be calculated against this…
AI Analysis
The EBA launched a consultation on 25 August 2026 covering three draft RTS that would determine how investment firms monitor the EUR 30 billion asset threshold, report threshold information, and seek a waiver from credit institution authorisation. The consultation is particularly relevant to large EU investment firms and groups because exceeding the threshold can trigger an application for authorisation as a credit institution, with significantly broader prudential, supervisory and governance consequences.
Key dates
2026-08-25
EBA launched the consultation on three draft RTS.
2026-09-25 Deadline
Deadline at 16:00 CEST to register for the EBA virtual public hearing.
2026-09-30
EBA virtual public hearing scheduled from 10:00 CEST.
2026-11-25 Deadline
Deadline for submitting comments on the consultation.
Suggested considerations
Firms should assess whether their solo and group-level asset populations capture all entities and activities covered by the CRD amendments, including the potential effect of EU branches and consolidated group assets.
Compliance and finance teams may wish to reconcile the proposed threshold methodology against regulatory reporting, audited financial statements and internal management information, using a rolling 12-month monitoring process where relevant.
Investment firms above EUR 5 billion should review the draft reporting templates and instructions and identify data, governance, validation and submission gaps before the RTS become applicable.
Firms near the EUR 30 billion threshold should model the consequences of credit institution authorisation, including CRD and CRR application, supervisory engagement, capital and liquidity requirements, governance expectations and implementation timelines.
Groups potentially affected by the group test should consider submitting comments on the geographic scope of assets, treatment of branches, consolidation methodology and any disproportionate effects on cross-border business models.
Potentially eligible firms may wish to prepare evidence against the proposed waiver factors and engage early with their competent authority, while recognising that a waiver is discretionary and not guaranteed.
Stakeholders wishing to participate in the EBA public hearing should register by the stated registration deadline and firms wishing to influence the final RTS should submit consultation responses by 25 November 2026.
What changed
The EBA is revising its draft RTS following the 2024 amendments to the Capital Requirements Directive, including clarifications on which entities and assets must be included in the threshold calculation at solo and group level. The package addresses the methodology for calculating total assets against the EUR 30 billion threshold, reporting requirements for investment firms whose total assets exceed EUR 5 billion under Article 55(5) of the Investment Firms Regulation, and the factors competent authorities must consider when deciding whether to grant a waiver under Article 8a(7) of the CRD.
Compliance impact
The immediate impact is preparatory because these are draft RTS, but the potential consequence of crossing the EUR 30 billion threshold is high: an investment firm may be required to apply for authorisation as a credit institution rather than continue under a MiFID investment firm authorisation. Firms should treat the consultation as an important supervisory and implementation signal, particularly where asset growth, group consolidation or branch structures could bring them within scope.
The European Banking Authority (EBA) today published its latest Environmental, Social and Governance (ESG) risk dashboard, showing continued stability in banks’ transition and physical climate risk indicators across the EU/EEA in second half of 2025. The results also indicate gradual improvements in the availability…
Why this matters
This is an informational news release announcing the EBA's ESG risk dashboard results for H2 2025. It reports on climate risk exposures and data quality improvements across EU/EEA banks but does not impose new binding obligations or announce enforcement actions.
The European Banking Authority (EBA) is consulting on a new reporting framework to support the validation and ongoing monitoring of initial margin models based on the ‘Standard Initial Margin Model’ (SIMM) developed by the International Swaps and Derivatives Association (ISDA). The proposed reporting requirements…
AI Analysis
The EBA has launched a consultation on a new reporting framework to support its role as central validator of pro forma initial margin models based on the ISDA Standard Initial Margin Model (SIMM) under EMIR, following its assumption of this function on 1 March 2026. The framework will define regular reporting, fee-calculation data and proportional requirements for counterparties using ISDA SIMM, with first reporting expected on a December 2027 reference date.
Key dates
2026-03-01
EBA central validation function for pro forma initial margin models under EMIR became operational
2026-08-05
Publication date of the EBA consultation on the reporting framework for validation and monitoring of ISDA SIMM
2026-11-02 Deadline
Deadline for submission of comments to the EBA consultation on ISDA SIMM reporting
2026-12-31
Indicative target for EBA adoption of a Decision establishing the collection of relevant information for ISDA SIMM validation reporting by end of 2026
2027-03-31
Expected release of the final EBA technical package version 4.4, Phase 2, incorporating the new reporting requirements
2027-12-31
Expected first reporting reference date for ISDA SIMM-related information under the new framework
2028-03-31
Expected first quarter of 2028 window for collection of initial ISDA SIMM validation and monitoring data based on the December 2027 reference date
Suggested considerations
Compliance teams may wish to review the consultation paper, IMMV reporting instructions and templates to understand the proposed data fields, frequency and proportional thresholds for ISDA SIMM-related reporting under EMIR.
Firms using or planning to use ISDA SIMM for non-centrally cleared OTC derivative initial margin calculations should consider whether they will fall under the more intensive or lighter reporting category based on the significance of their OTC trading activity and assess system readiness for the expected December 2027 reference date reporting in Q1 2028.
Risk and collateral management functions may wish to map the proposed reporting requirements to existing SIMM backtesting, model performance, risk factor sensitivity and margin monitoring processes to identify gaps and necessary enhancements.
Regulatory reporting and IT teams should consider planning for integration of the new IMMV reporting templates into their infrastructure, taking into account the incorporation of these requirements into the EBA technical package version 4.4, Phase 2 and the planned final technical release in March 2027.
Legal and regulatory affairs teams may wish to assess the implications of Article 11(12a) EMIR and EMIR 3 for their use of pro forma initial margin models, including governance around EBA’s central validation function and associated fee obligations, and prepare internal feedback on the consultation by the 2 November 2026 deadline.
Firms intending to rely on ISDA SIMM should consider engaging with the consultation process to comment on the proportionality of the proposed reporting frequency and content, especially where OTC trading activity is limited but compliance costs could be significant.
Supervisory liaison teams at affected groups may wish to coordinate with competent authorities to understand how the EBA’s data collection will be used in authorisation and ongoing supervision of ISDA SIMM-based initial margin models.
What changed
The consultation sets out a proposed standardised reporting framework for counterparties seeking validation to use ISDA SIMM as a pro forma initial margin model under Regulation (EU) No 648/2012 (EMIR) as amended by Regulation (EU) 2024/2987 (EMIR 3). From 1 March 2026, the EBA acts as the central validator of the elements and general aspects of pro forma initial margin models pursuant to Article 11(12a) EMIR, and this proposal defines the information that must be submitted on a regular basis to enable validation and ongoing performance monitoring.
Compliance impact
The proposal signals a material expansion of structured reporting and supervisory scrutiny around ISDA SIMM initial margin models, with ongoing data submissions and fee-linked information becoming part of firms’ EMIR compliance obligations. While the EBA emphasises proportionality and lighter requirements for less significant OTC trading activities, larger derivatives users should expect non-trivial operational, data and governance implications.
The European Banking Authority (EBA) today published a no-action letter on the boundary between the banking book and the trading book and shared technical clarifications on issues linked to the European Commission’s Delegated Act modifying the calculation of own funds requirements for market risk based on the…
AI Analysis
On 2026-08-03, the EBA issued a no-action letter under Article 9c of Regulation (EU) No 1093/2010 and published technical considerations to support EU implementation of the Fundamental Review of the Trading Book (FRTB) market risk framework. The package addresses the boundary between the banking book and trading book, internal risk transfers, and related reporting and benchmarking under the forthcoming 3rd FRTB Delegated Act amending CRR market risk capital requirements.
Key dates
2026-06-04
European Commission adoption of the 3rd FRTB Delegated Act under Article 461a CRR modifying own funds requirements for market risk for a three-year period
2026-08-03
EBA publication of no-action letter on the trading/banking book boundary and internal risk transfers, and technical considerations on FRTB application
2027-01-01
Start of modified calculation of own funds requirements for market risk under the 3rd FRTB Delegated Act for a three-year period
Suggested considerations
Compliance teams at EU banks should consider reviewing the EBA no-action letter to understand which aspects of the FRTB boundary between banking book and trading book, internal risk transfers, and related reporting are currently deprioritised for supervisory or enforcement action, and how this interacts with national competent authority expectations.
Risk and regulatory capital teams may wish to map their existing and planned FRTB implementation (standardised and internal models approaches) against the technical considerations published by the EBA, focusing on how the 3rd FRTB Delegated Act’s institution-specific multiplier and related boundary rules affect market risk capital calculations from 2027-01-01.
Firms should consider identifying whether they fall within the scope of "multiplier banks" under the Delegated Act and assess operational implications, including whether their systems and data architecture can support a single, harmonised boundary framework rather than multiple versions during the three-year transitional period.
Supervisory reporting and Pillar 3 disclosure teams may wish to analyse the EBA’s clarifications on reporting requirements linked to the trading/non-trading book boundary and internal risk transfers to determine whether current templates, data points, and governance need adjustment ahead of the Delegated Act’s entry into force.
Institutions participating in the EBA supervisory benchmarking exercise should consider reviewing the clarified treatment of institutions in that exercise under the revised FRTB framework, and ensure their benchmarking submissions and internal controls are aligned with the EBA’s technical considerations.
Legal and regulatory policy teams may wish to monitor the scrutiny process of the 3rd FRTB Delegated Act by the European Parliament and Council, as the practical relevance of the no-action letter and technical considerations is contingent on the Delegated Act entering into force as adopted on 2026-06-04.
What changed
The EBA has formally issued a no-action letter recommending that competent authorities do not prioritise supervisory or enforcement action regarding provisions of the FRTB framework that govern: (i) the boundary between the banking book and the trading book; (ii) internal risk transfers between these books; and (iii) certain related reporting requirements, during the transition to the revised market risk regime.
Compliance impact
The update is primarily interpretative and transitional, reducing immediate enforcement risk on specific FRTB boundary and reporting provisions while signalling how the EBA expects the revised market risk framework and institution-specific multiplier to be applied from 2027. Consequences for firms are mainly in implementation planning, systems changes, and ensuring consistent treatment for supervisory benchmarking rather than in new binding obligations.
The European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) today published a final report on draft Regulatory Technical Standards (RTS), proposing to simplify the bilateral margin requirements of the European Commission’s Delegated Regulation (EU) 2016/2251.
AI Analysis
On 2026-08-03, the European Supervisory Authorities (EBA, EIOPA and ESMA) published a final report containing draft Regulatory Technical Standards (RTS) to amend Delegated Regulation (EU) 2016/2251 on bilateral margin requirements under EMIR. The amendments would remove the obligation to exchange initial margin on both new and existing uncleared OTC derivatives for counterparties below the €8 billion initial margin threshold, simplifying the framework and aligning with other jurisdictions.
Key dates
2026-08-03
ESAs publish final report and draft RTS proposing amendments to Delegated Regulation (EU) 2016/2251 bilateral margin requirements
Suggested considerations
Compliance teams may wish to review current EMIR margin frameworks and inventories of uncleared OTC derivatives to identify portfolios and counterparties that are below the €8 billion initial margin threshold and could be affected by the proposed phase-out of initial margin exchange.
Risk and collateral management functions should consider assessing the operational processes, documentation and systems currently used to calculate, call and exchange initial margin on legacy uncleared OTC derivative contracts, to understand the potential impact of a removal of these obligations on collateral flows and counterparty risk management.
Legal and documentation teams may wish to map existing credit support annexes (CSAs) and collateral agreements to EMIR margin requirements, evaluating whether standard terms referencing Delegated Regulation (EU) 2016/2251 would need amendment if the RTS are endorsed and the obligation to exchange initial margin for below-threshold portfolios is removed.
Regulatory affairs and policy teams should consider monitoring the European Commission’s endorsement process and subsequent scrutiny by the European Parliament and Council, tracking any changes to the draft RTS text that could affect scope, thresholds or transitional arrangements.
Firms subject to EMIR in multiple jurisdictions may wish to compare the proposed EU treatment of below-threshold initial margin portfolios with requirements in other key jurisdictions (e.g. US, UK) to ensure consistent cross-border collateral and margin policies and avoid regulatory arbitrage or misalignment.
Compliance teams may wish to prepare briefing materials for senior management and boards outlining the anticipated simplification and burden reduction, alongside any residual risks or supervisory expectations that could accompany the phase-out of initial margin for below-threshold counterparties.
What changed
Under the current EU bilateral margin framework in Delegated Regulation (EU) 2016/2251, counterparties with an aggregate average notional amount of non-centrally cleared derivatives below the €8 billion initial margin threshold specified in Regulation (EU) No 648/2012 (EMIR) are exempt from exchanging initial margin on new uncleared OTC derivative contracts, but must continue to exchange initial margin on existing contracts.
Compliance impact
The proposed RTS would materially reduce operational and collateral management obligations for EMIR in-scope counterparties below the €8 billion initial margin threshold, by removing the need to exchange initial margin on both new and existing uncleared OTC derivatives. The ESAs frame the impact as simplification and burden reduction rather than a tightening of requirements, but firms may still face transitional work to adjust collateral frameworks and documentation once the RTS are adopted.
The European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) today published a statement calling for a cross-sectoral, risk-based and consistent supervisory approach to mitigate the ICT risks stemming from frontier AI models.
AI Analysis
On 2026-07-31, the European Supervisory Authorities (EBA, EIOPA and ESMA) issued a joint statement calling for a cross-sectoral, risk-based and consistent supervisory approach to address ICT and cyber risks arising from frontier AI models in the EU financial sector. The statement does not introduce new binding rules but signals how supervisors expect existing frameworks, particularly under DORA and related ICT risk regulations, to be applied to frontier AI use cases.
Key dates
2026-07-31
Joint ESA statement on ICT risks from frontier AI models in the EU financial sector published
Suggested considerations
Compliance teams may wish to map existing and planned uses of frontier AI models (including large language models and other advanced generative or predictive systems) to current ICT risk and cyber resilience frameworks under Regulation (EU) 2022/2554 (DORA) to demonstrate that these models are covered by documented risk assessments, controls and monitoring.
Firms should consider reviewing governance arrangements for frontier AI, including board and senior management oversight, clear accountability, and integration of AI-related ICT risks into the firm’s risk appetite, risk taxonomy and operational risk frameworks, with specific escalation and reporting lines.
Risk and technology functions may wish to update ICT and cyber risk management policies to explicitly address frontier AI threats (e.g. prompt injection, model poisoning, data leakage, adversarial attacks) and to align detection, logging and incident response capabilities with the ESAs’ emphasis on prevention, detection and management of AI-related cyber risks.
Operational resilience teams should consider conducting scenario analysis and testing around frontier AI incidents (such as compromised AI-enabled customer interaction tools or automated decision engines) to evidence the ability to maintain critical services in line with DORA requirements on ICT-related incident management and business continuity.
Compliance and procurement teams may wish to review contracts and due diligence for critical ICT third‑party providers that supply or host frontier AI models, assessing how provider controls, service levels and incident processes meet DORA expectations and the ESAs’ focus on frontier AI risks.
Supervisory engagement teams should consider preparing to discuss the firm’s frontier AI strategy, risk management and governance with competent authorities, using the ESA statement as a reference point for how existing supervisory expectations on ICT risk and cyber resilience are applied to AI use cases.
Internal audit and second‑line control functions may wish to plan thematic reviews of frontier AI deployments to assess coverage of AI-specific ICT risks within existing control frameworks, including documentation quality, model oversight, and alignment with DORA and sectoral guidance.
Firms should consider monitoring forthcoming ESA and national competent authority publications on frontier AI and DORA oversight activities, as the statement signals that supervisory practices and expectations in this area are evolving and may be further operationalised.
What changed
The publication introduces a consolidated supervisory expectation that frontier AI models be treated explicitly as a source of ICT and cyber risk within existing EU operational resilience and ICT risk management frameworks, rather than as a separate technology domain. It emphasises the need for robust governance, risk management, and controls around the prevention, detection and management of cyber risks stemming from frontier AI, including model governance, validation, monitoring and incident handling.
Compliance impact
The impact is primarily supervisory and interpretative rather than creating new binding obligations, but it raises expectations that frontier AI deployments will be demonstrably integrated into existing ICT risk, cyber security and DORA compliance frameworks. Firms that cannot evidence robust governance and risk management for frontier AI may face heightened supervisory scrutiny and potential findings in ICT risk or operational resilience reviews.
The Data Point Model Alliance, a joint initiative of the EBA, ECB and EIOPA, is committed to making financial sector statistical and supervisory reporting across the EU simpler, smarter and more proportionate. To facilitate the integration of reporting, they launched today a public consultation on enhancements to…
AI Analysis
The EBA-ECB-EIOPA Data Point Model (DPM) Alliance has launched a two‑month public consultation on DPM 2.1, a new version of the common metadata model and associated naming conventions intended to support integrated statistical and supervisory reporting in the EU. This is a standard-setting initiative that will shape how prudential, resolution and statistical data are modelled, named and reported across banking, insurance and pensions sectors.
Key dates
2026-07-31
Launch of the public consultation on DPM 2.1 and publication of naming conventions for metadata used in reporting
2026-09-30 Deadline
Deadline for submitting comments to the DPM 2.1 public consultation
2023-06-01
Publication month of DPM Standard 2.0 by EBA and EIOPA, establishing the current baseline data dictionary standard
2024-03-01
Establishment of the DPM Alliance joint governance framework by EBA, EIOPA and ECB to extend DPM to ECB statistical reporting
Suggested considerations
Compliance teams may wish to review the DPM 2.1 factsheet and the published naming conventions to understand proposed changes in metadata versioning, logical data model support and naming structures, and how these could impact existing COREP, FINREP, resolution and insurance reporting implementations.
Regulatory reporting and technology teams should consider mapping current data dictionaries and reporting taxonomies (including those used for CRR/CRD prudential reports, BRRD/SRB resolution reports and EIOPA insurance and pensions reports) against the DPM 2.1 metamodel to assess the scale of future migration effort and potential system changes.
Firms should consider engaging in the consultation process, either directly or via industry bodies, to provide feedback on the practicality of the proposed metamodel and naming conventions, particularly where they affect multi-framework reporting or large-scale data integration projects.
Compliance and regulatory change functions may wish to flag DPM 2.1 internally as a strategic development in EU reporting architecture and ensure it is reflected in medium-term reporting transformation programmes, including planning for alignment with the ESCB Integrated Reporting Framework (IReF).
Reporting vendors and in-house IT teams should consider evaluating whether their current regulatory reporting tools and data models can support DPM 2.1’s enhanced versioning and logical data model capabilities, and identify potential design changes needed to remain aligned with future EBA, EIOPA and ECB requirements.
Supervisory liaison and public policy teams may wish to monitor subsequent EBA, EIOPA, ECB and SRB communications following the close of the consultation for indications of timelines when DPM 2.1 and the naming conventions will become expected or mandatory for specific reporting frameworks.
What changed
The DPM Alliance is consulting on DPM 2.1, an updated version of the DPM metadata model that introduces enhanced metadata versioning and extends the metamodel to host logical data models, with the explicit objective of supporting integrated European reporting across all regulatory frameworks in the financial sphere. The consultation also covers newly published naming conventions that set out a common approach for naming metadata used in reporting, designed to ensure consistent use of the common data dictionary across regulatory reporting frameworks.
Compliance impact
The immediate compliance impact is moderate because this is a consultation rather than a binding rule, but it foreshadows significant medium-term changes to how EU prudential, resolution and statistical reports are modelled and integrated. The alliance emphasises reduced complexity, improved data quality and lower reporting costs, indicating that supervisors expect firms to adapt systems and data governance to a more unified, DPM-based reporting architecture.
The European Banking Authority (EBA) today published a draft technical package for version 4.4 of its reporting and disclosure framework, covering IFRS 18 reporting, Pillar 3 ESG disclosures and other technical amendments.
AI Analysis
On 2026-07-24, the EBA opened consultation on the draft technical package for reporting framework version 4.4, covering IFRS 18 FINREP templates, Pillar 3 ESG disclosures, FRTB-related disclosure templates, and technical amendments to resolution planning, MREL, and AMLA eligibility data. The package matters because it sets the first reporting reference dates for several new or amended templates and gives firms an early view of the DPM 2.0 transition ahead of final publication expected in September 2026.
Key dates
2026-07-24
EBA published the draft technical package for reporting framework 4.4 and opened the consultation
2026-08-24 Deadline
Deadline for stakeholders to submit comments and suggestions on the draft technical package 4.4 and new glossary
2026-09-30
EBA expects to publish the final technical package for reporting framework 4.4
2026-12-31
First reference date for amended Pillar 3 ESG, equity and shadow banking disclosures; technical amendments for resolution planning, MREL decisions, Pillar 3 disclosure templates; and AMLA eligibility templates
2027-03-31
First reference date for new IFRS 18-aligned FINREP templates and FRTB-related disclosure templates
2027-12-31
First reference date for Pillar 3 ESG, equity and shadow banking disclosures for SNCIs
Suggested considerations
Compliance teams may wish to assess the draft 4.4 package against current reporting architecture, especially where FINREP, Pillar 3, FRTB, resolution planning, MREL, or AMLA templates rely on local mapping or vendor implementation.
Firms may wish to review the new IFRS 18-aligned FINREP templates and identify any chart-of-accounts, data lineage, or consolidation changes needed ahead of the 2027-03-31 first reference date.
Reporting teams may wish to map the updated Pillar 3 ESG, equity exposure, and shadow banking disclosures to the 2026-12-31 reporting cycle, and to 2027-12-31 for SNCIs.
Institutions may wish to compare their DPM 1.0 to DPM 2.0 conversion controls against the new glossary conversion file and plan for taxonomy or validation rule changes in downstream reporting tools.
Affected firms may wish to submit comments on the draft technical package and glossary by 2026-08-24 if they have implementation concerns, data gaps, or interpretation issues.
Compliance functions may wish to monitor the expected September 2026 final publication for changes to validation rules, AML eligibility elements, and the AMLA risk assessment 2027 templates.
What changed
The draft technical package for release 4.4 includes validation rules, the Data Point Model, XBRL taxonomies, and a new conversion file between DPM 1.0 and the DPM 2.0 glossary. It introduces amendments to the ITS on Pillar 3 disclosures on ESG risks, equity exposures and shadow banking exposures, with first reference dates of 2026-12-31 and 2027-12-31 for SNCIs. It also adds new IFRS 18-aligned FINREP templates, with a first reference date of 2027-03-31, and integrates FRTB-related disclosure templates into the DPM, also with a first reference date of 2027-03-31.
Compliance impact
The immediate impact is medium-high because the draft signals concrete reporting and disclosure changes with phased first reference dates, rather than a purely conceptual policy update. Firms that miss the data model and taxonomy changes risk implementation issues in supervisory reporting, disclosure production, and validation processing once the new templates become effective.
The European Banking Authority (EBA) today launched four public consultations on proposed rules to further strengthen depositor protection, preserve financial stability, and further harmonise depositor protection standards across the EU under the revised Deposit Guarantee Schemes Directive (DGSD3). The EBA seeks…
AI Analysis
On 2026-07-23, the EBA launched four consultations on draft ITS, RTS and Guidelines to implement the revised Deposit Guarantee Schemes Directive (DGSD3), focusing on depositor information, information exchange, client funds payouts, and investment of DGS financial means. These proposals will shape how EU Deposit Guarantee Schemes and credit institutions operationalise strengthened depositor protection and crisis management under DGSD3.
Key dates
2026-07-23
EBA launches consultations on draft ITS on depositor information, ITS on information exchange, RTS on DGS payouts of client funds deposits, and Guidelines on investment of available financial means under DGSD3
2026-09-21 Deadline
Registration deadline (12:00 CEST) for public hearing on all four regulatory products
2026-09-24
Public hearing on the four DGSD3-related regulatory products (10:00–13:00 CEST)
2026-10-23 Deadline
Deadline for submission of comments to the four consultation papers
Suggested considerations
Compliance teams at EU credit institutions should consider reviewing existing depositor information sheets, account-opening documentation and ongoing communications to assess alignment with the emerging harmonised formats and content envisaged by the draft ITS on depositor information, particularly for merger and failure scenarios.
DGSs and banks may wish to map current data flows and reporting processes for covered deposits, available financial means and bank failure events against the proposed ITS on information exchange, to identify gaps in data granularity, timeliness, and standardisation that could require system and process changes.
Firms that hold client funds in pooled or intermediary deposit accounts (such as investment firms or payment institutions) should consider analysing how client identification and segregation data are captured and shared with DGSs, in light of the draft RTS on client funds that aim to ensure accurate and timely reimbursement of underlying clients and avoidance of duplicate payouts.
DGS operators and finance teams may wish to review investment policies, risk limits, eligible instruments and liquidity management frameworks for DGS financial means, to anticipate adjustments needed to comply with the forthcoming Guidelines on diversification, low risk and liquidity, including readiness to support resolution financing within the DGSD3 mandate.
All affected stakeholders should consider preparing internal positions and impact assessments and submit consultation responses to the EBA by the stated deadline, highlighting operational challenges, data availability issues, and any potential conflicts with existing national frameworks for depositor protection and crisis management.
Risk and treasury functions in banks may wish to engage with DGSs and supervisors to understand how enhanced reporting on covered deposits and DGS financial means under the ITS on information exchange could affect crisis-preparedness expectations, stress-testing assumptions and disclosure practices.
Legal and regulatory affairs teams should consider monitoring the progression of these four draft instruments alongside the remaining eight technical standards and guidelines mandated by DGSD3, to plan for a coordinated implementation programme once final texts and application dates are confirmed.
What changed
The publication launches consultations on four draft regulatory products mandated by DGSD3: (i) Implementing Technical Standards on depositor information, which define harmonised content and format for depositor information sheets at account opening and on a regular basis, and specify communication requirements in special situations such as bank mergers or failures; (ii) Implementing Technical Standards on information exchange between credit institutions, Deposit Guarantee Schemes (DGSs) and other relevant authorities, introducing standardised procedures, templates and minimum information...
Compliance impact
The consultations signal materially enhanced, more granular and harmonised operational requirements for depositor information, data reporting, client funds payout mechanics and DGS investment governance under DGSD3, with implications for systems, documentation and crisis-management playbooks. Once finalised and made binding, the EBA’s technical standards and guidelines are likely to require coordinated implementation efforts across banks, DGSs and competent authorities to ensure consistent depositor protection and effective use of DGS funds in resolution.
The European Banking Authority (EBA) today published its final draft Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITSs) on material acquisitions, transfers of assets or liabilities, mergers and divisions involving credit institutions or (mixed) financial holding companies under the…
AI Analysis
On 2026-07-17, the EBA published final draft RTS and ITS under the Capital Requirements Directive to standardise notifications, supervisory assessment, and cooperation for material acquisitions, material transfers of assets or liabilities, mergers, and divisions involving credit institutions and mixed financial holding companies. For compliance teams, the significance is that the draft package would reduce uncertainty and create more harmonised, procedural expectations across EU competent authorities once adopted by the Commission.
Key dates
2026-07-17
EBA published the final draft RTS and ITS on material acquisitions, material transfers, mergers and divisions under the CRD
Suggested considerations
Compliance teams may wish to map proposed acquisition, transfer, merger, and division workflows against the draft minimum-information template and identify which data points are already held by competent authorities.
Firms may wish to review whether planned intra-group transactions could qualify for the simplified treatment described in the draft RTS, including any discretion not to assess certain transactions.
Groups planning mergers or divisions may wish to check which documentation can be reused from Company Law Directive processes and where CRD-specific supplements will still be needed.
Legal and regulatory teams may wish to assess how multiple-notification scenarios are handled today and whether internal controls need to align with the proposed harmonised terminology and coordination timelines.
Firms may wish to prepare for supervisory coordination across jurisdictions by identifying the authorities likely to be involved in cross-border transactions and the likely sequence of notifications.
What changed
The EBA’s final draft RTS would specify the minimum information to be provided for material acquisitions, material transfers of assets and liabilities, mergers, and divisions, together with a common assessment methodology for the prudential scrutiny of those transactions. The draft RTS also streamline notifications by excluding information already held by competent authorities and by allowing reliance on documentation prepared under Directive (EU) 2017/1132 (the Company Law Directive) for mergers and divisions.
Compliance impact
The publication signals an imminent move toward a more harmonised EU prudential process for structural transactions, which should reduce uncertainty but also make notification and assessment procedures more standardised and traceable. The immediate impact is moderate to high for banking groups contemplating acquisitions, transfers, mergers, or divisions, especially where multiple supervisors or intra-group transactions are involved.
The European Banking Authority (EBA) today launched a consultation on amendments to the Implementing Technical Standards (ITS) governing the benchmarking of internal models and the standardised approach for market risk for the 2027 exercise. The proposed amendments aim to ensure that the benchmarking framework…
AI Analysis
The EBA has launched a 17 July 2026 consultation on amendments to the Implementing Technical Standards (ITS) for the 2027 market risk benchmarking exercise under Article 78 CRD. The changes recalibrate data collection for internal models and standardised approaches, align the benchmarking framework with CRR3/FRTB implementation from 1 January 2027, and adjust timing and scope to include institutions using the CRR3 Alternative Standardised Approach (ASA).
Key dates
2026-07-17
EBA launches consultation on amendments to ITS for the 2027 market risk benchmarking exercise
2026-07-27 Deadline
Deadline (16:00 CEST) for registration to the public hearing on the consultation
2026-07-28
Public hearing on the consultation (14:00–15:30 CEST)
2026-09-03 Deadline
Deadline for submission of comments to the EBA consultation on the 2027 market risk benchmarking ITS amendments
2027-01-01
Application date of the European Commission’s FRTB Delegated Act referenced in the amended ITS
Suggested considerations
Compliance teams at EU credit institutions using market risk internal models or the CRR3 Alternative Standardised Approach may wish to review the consultation paper and annexes (booking instructions, relevant dates, instruments and portfolios, template instructions, and templates) to understand proposed changes to the 2027 benchmarking data collection and reporting requirements.
Firms applying or planning to apply CRR2 Internal Model Approach for market risk should consider the implications of the resumption of CRR2-IMA data collection and assess whether existing reporting processes and systems can be reactivated or need updating to meet the revised ITS templates.
Institutions intending to use the CRR3 Alternative Standardised Approach for market risk may wish to assess the impact of being newly in scope of the EBA market risk benchmarking exercise, including internal governance, data availability, and operational readiness for participation in the second half of 2027.
Firms that anticipate using the CRR3 Alternative Internal Model Approach may wish to monitor the postponement of AIMA data collection and evaluate how the uncertainty in the effective implementation date interacts with their internal model development timelines and supervisory expectations.
Regulatory and reporting functions may wish to map current market risk reporting templates to the proposed reorganised and rationalised templates, identifying data gaps and system changes required once the final ITS enter into force.
Compliance teams may wish to coordinate with risk and reporting teams to prepare a response to the EBA consultation by the 3 September 2026 deadline, particularly on practical aspects of template design, data availability, and timing of the 2027 benchmarking exercise.
Institutions newly included in scope by virtue of using CRR3 ASA should consider whether additional internal documentation, model validation, and supervisory engagement are needed ahead of the second-half 2027 benchmarking exercise, given the EBA’s intention to adopt the final ITS earlier to give such institutions more preparation time.
What changed
The consultation proposes amendments to the ITS on supervisory benchmarking of market risk models for the 2027 exercise, updating the data collection framework and reporting templates used by institutions and competent authorities under Article 78 of Directive 2013/36/EU (CRD). The scope of the market risk benchmarking exercise would be expanded to include institutions applying the CRR3 Alternative Standardised Approach (ASA) for market risk, irrespective of whether they also use an Internal Model Approach (IMA).
Compliance impact
The impact is moderate but targeted, primarily affecting banks in scope of market risk benchmarking by expanding ASA coverage, restarting CRR2-IMA reporting, and adjusting the timing of the 2027 exercise. Failure to prepare for revised templates and data collection could result in supervisory findings on model quality and variability of own funds requirements under CRD benchmarking assessments.