EBA — European Banking Authority
Type: regulator Sector: EU banking and payments (prudential) First seen: 2026-03-18 Last updated: 2026-08-28
Updated 2026-09-17 based on S-2026-09-16-eba-dora-incident-reporting-operational-instructions — daily regulatory-intelligence scan: the EBA published (for the ESAs — EBA, EIOPA, ESMA) “DORA Incident Reporting – Operational Instructions” (16 September 2026), a best-efforts, regularly-updated ESAs-staff document — explicitly not legal interpretation nor the official ESA stance, and agreed with competent authorities — to improve data quality and cross-jurisdiction consistency in reporting major ICT-related incidents under ITS 2025/302 and RTS 2025/301 / 2024/1772. It sets 14 field-level conventions for the CA→ESA notification leg (English templates; monetary fields in thousands; blank non-applicable free-text; a one-month final-report deadline with monthly intermediate updates; immutable unique incident IDs; always flagging “critical services affected” in Field 2.5; excluding the home country from geographical spread; a standardised LEI/EUID third-party-provider origin format in Field 2.8; conditional resolution-authority and economic-impact fields). Reinforces the EBA’s DORA-oversight and reporting-data-quality posture and follows the ESAs’ first annual DORA incident report (S-2026-06-03-esas-dora-incident-report). Tracked-change entry and Source added; PDF fetched and extracted in full. Medium authority (staff best-efforts guidance). See DORA — Digital Operational Resilience Act and Operational Resilience and Third Party Risk. (Selected as the EBA net-new item for 16 Sep: same-day listing entries are board declarations of interest, an org chart and an SNCIs public-hearing deck — administrative/internal.) Updated 2026-08-28 based on S-2026-08-26-eba-oprisk-rts-cp — daily regulatory-intelligence scan: the EBA launched a consultation on draft RTS specifying the operational risk management framework under Article 323(2) CRR3 (26 August 2026, to 31 December 2026; public hearing 29 September 2026). The RTS specify three components — governance arrangements, the operational risk management process, and the operational risk assessment system — clarify the roles of the management body, senior management and an independent operational risk management function, and set requirements for operational risk data and taxonomy, the business indicator component, reporting, validation and audit; ICT risk is addressed through DORA. They support the EU Banking Package’s single standardised approach for operational risk (business-indicator-based, replacing the AMA), build on the BCBS Principles for the Sound Management of Operational Risk and are consistent with the EBA Guidelines on internal governance — reinforcing the EBA’s technology-neutral, integrate-into-existing-frameworks posture. Proportionality: firms with a business indicator below EUR 750m get lighter review/reporting and less granular data/taxonomy. Position bullet and tracked-change entry added. (Press release fetched in full; the 709KB consultation PDF not extracted ⚠️.) See Operational Resilience and Third Party Risk. Updated 2026-08-20 based on S-2026-08-10-eba-integrated-reporting-vision — daily regulatory-intelligence scan: the EBA published a “Vision for the Integrated Reporting System” (10 August 2026), a long-term strategy for integrating prudential, resolution and statistical reporting around a common data dictionary, harmonised definitions and semantic integration, built on DPM 2.0 / DPM Studio and an enhanced glossary, converging over time with ECB statistical reporting (IReF) and supported by a 2026 Digital Europe Programme project; delivered through the JBRC. The target-state above the reporting-simplification / Reporting Framework 4.3 / DPM 2.1 milestones; reinforces the integrate-don’t-duplicate, data-modernisation posture. Position bullet and tracked-change entry added. (Listing fetched via WebFetch; vision PDF did not extract — substance via WebSearch of EBA integrated-reporting pages ⚠️.) See EBA Simplification and Efficiency Programme. Updated 2026-08-10 based on S-2026-08-05-eba-isda-simm-validation-reporting — daily regulatory-intelligence scan: the EBA launched a consultation on a reporting framework for the validation and monitoring of the ISDA Standard Initial Margin Model (SIMM) (5 August 2026, to 2 November 2026). It operationalises the EBA’s EMIR central-validator role for pro forma initial margin models (live since 1 March 2026 under Decision EBA/DC/610): a standardised, deliberately proportionate set of regular reporting requirements so counterparties’ initial-margin models can be validated and their performance monitored on an ongoing basis (firms with less significant OTC activity report annually only), feeding EBA technical package v4.4 Phase 2 (first reference date December 2027; Decision expected end-2026). A model-validation / ongoing-monitoring supervisory-reporting item — not AI; relevance is the model-risk-evidence and machine-readable-reporting substrate. Position bullet and tracked-change entry added. (Selected as the EBA net-new item because the more recent 6 Aug ESG Risk Dashboard S-2026-08-06-eba-esg-risk-dashboard was already ingested.) Updated 2026-08-07 based on S-2026-08-06-eba-esg-risk-dashboard — daily regulatory-intelligence scan: the EBA published its latest ESG Risk Dashboard (6 August 2026), reporting broadly stable EU/EEA bank climate-risk exposures for H2 2025 (high-climate-impact-sector exposure unchanged at 62%) alongside continued improvement in the availability and quality of climate-related data — notably a marginal fall in mortgage exposures lacking energy-performance (EP) information and in estimated EP scores. A routine, recurring supervisory-monitoring product built on ESG disclosure data (not a new rule), it extends the EBA’s data-modernisation / ESG-disclosure-data theme (Pillar 3 Data Hub; first ESG Risk Dashboard noted in the 2025 Annual Report). Position bullet and tracked-change entry added. Primarily a climate/ESG data-quality signal — tangential to the wiki’s AI core; relevance is the data-governance substrate (completeness, estimation transparency) that credible risk monitoring rests on. See EBA Pillar 3 Data Hub. (The 5 Aug EBA consultation on validation/monitoring reporting for the ISDA SIMM is a model-risk-relevant runner-up, noted in the raw stub, not separately ingested.) Updated 2026-08-06 based on S-2026-07-31-esas-frontier-ai-statement — daily regulatory-intelligence scan: the ESAs (EBA with EIOPA and ESMA) published a joint Statement on frontier AI models (JC 2026 25, 31 July 2026) calling for a cross-sectoral, risk-based and consistent supervisory approach to the ICT risks from frontier AI models. It states that financial entities should have robust governance and risk-management frameworks to prevent, detect and manage frontier-AI cyber risks, is framed within DORA, and updates on ongoing and planned DORA oversight of Critical ICT Third-Party Providers (CTPPs) — the EBA acting as a CTPP lead overseer. This advances the ESAs’ 7 July ESRB-warning support to a concrete supervisory-approach + governance-expectation statement. A joint-ESA output (not EBA-only). Position bullet and tracked-change entry added; reinforces the EBA’s DORA-oversight and AI-as-cyber-risk-surface posture. Full JC 2026 25 PDF not retrieved (press-release summary only ⚠️). See Operational Resilience and Third Party Risk. Updated 2026-07-28 based on S-2026-07-07-esas-esrb-frontier-ai-cyber — daily regulatory-intelligence scan: the ESAs (EBA with EIOPA and ESMA) issued a joint statement supporting an ESRB warning on the systemic cyber risks posed by frontier AI models (7 July 2026), judging DORA and the AI Act a “solid foundation” but warning frontier models’ speed and scale of vulnerability exploitation “could undermine the operational resilience of financial entities”; the ESAs urge firms to adapt cybersecurity capabilities, invite competent authorities to reflect this in supervision, and — as Overseers of Critical ICT Third-Party Providers — are engaging those providers on mitigation. A joint-ESA output (not EBA-only). Position bullet and tracked-change entry added; reinforces the EBA’s DORA-oversight and AI-as-cyber-risk-surface posture. See Operational Resilience and Third Party Risk. Updated 2026-07-03 based on S-2026-06-30-eba-pog-esg-greenwashing — daily regulatory-intelligence scan: the EBA published revised Guidelines on product oversight and governance (POG) for retail banking products (30 June 2026, apply 11 January 2027), amending EBA/GL/2015/18 to make ESG / greenwashing considerations explicit across the product lifecycle (manufacturers’ internal control functions, target-market identification, distribution channels, information to distributors), plus non-substantive alignment with the revised CRD Internal Governance Guidelines and the sound management of third-party risk (SMTPR), self-badged under the EBA’s “simplify and build a more efficient framework” work. Position bullet and tracked-change entry added. Primarily a conduct/consumer-protection/ESG measure — peripheral to the wiki’s AI core, but relevant to internal-governance and third-party-risk framework design. See EBA Simplification and Efficiency Programme. Updated 2026-07-02 based on S-2026-06-29-eba-supervisory-convergence — daily regulatory-intelligence scan: the EBA published its 2025 Report on Supervisory Convergence (29 June 2026), badged under “Simplifying to strengthen” and delivering on TFE Recommendation 17. Frames consistent supervision as the enabler of simplification; sets 2026 convergence priorities — Basel III implementation, resolution-testing frameworks, strengthening DORA oversight, enhancing MiCA supervision — and reports a digital-finance focus on “data quality issues, ICT dependencies and emerging technological risks”. Position bullet and tracked-change entry added; reinforces the integrate-don’t-duplicate, DORA/MiCA-heavy supervisory posture. See EBA Simplification and Efficiency Programme. Updated 2026-06-26 based on S-2026-06-18-eba-rar-spring-2026 — the Spring 2026 Risk Assessment Report (with the Q1 2026 Risk Dashboard and Spring 2026 RAQ), published 18 June 2026, added. EU/EEA banks remain strong on capital, liquidity, asset quality and profitability, but the EBA flags rising operational and cyber risk (a key sector concern) and notes that “increasingly capable (frontier) AI models may further amplify operational and cyber risks”, alongside NBFI/private-credit interconnectedness and a geopolitical overlay. Position bullet and tracked-change entry added; reinforces the EBA’s operational-resilience and AI-as-cyber-risk-surface posture. See Operational Resilience and Third Party Risk. Updated 2026-06-25 based on S-2026-06-22-eba-pillar3-esg-disclosure-its — final draft ITS amending Pillar 3 disclosures on ESG risks, equity and shadow-banking exposures (22 June 2026), the fourth “Simplifying to strengthen” milestone. Extends ESG disclosure to all institutions (CRR3 Art 449a) via a “core plus supplement” model; datapoint cuts (large −37% with taxonomy disclosures stopped, medium −17%, SNCIs −84% vs large); the EBA will centrally pre-fill SNCIs’ ESG disclosures via the Pillar 3 Data Hub and publish an updated Pillar 3 ↔ supervisory-reporting mapping tool in 2026; ESRS-aligned; JBRC semantic integration embedded; expected reference date 31 Dec 2026 (31 Dec 2027 for SNCIs). Position bullet and tracked-change entry added; reinforces the data-centralisation, integrate-don’t-duplicate posture. See EBA Simplification and Efficiency Programme and EBA Pillar 3 Data Hub. Updated 2026-06-19 based on S-2026-06-11-eba-2027-stress-test — the 11 June 2026 early consultation on the simplified 2027 EU-wide stress test (the second “Simplifying to strengthen” milestone) now has its own primary source: a 55% data-point reduction achieved mainly by drawing on regular supervisory reporting, plus the first-time integration of climate risk via a dedicated (non-result-affecting) module; 63 banks / 47 euro-area / 75% sector coverage, feeding the SREP. Tracked-change entry and source link added; reinforces the data-modernisation and simplification posture already on the page. See EBA Simplification and Efficiency Programme. Updated 2026-06-18 based on S-2026-06-16-eba-annual-report-2025 — 2025 Annual Report (Part 1) (16 June 2026) added. The EBA’s own framing of 2025 is “streamlining and improving the efficiency of the EU regulatory framework while expanding its supervisory role, particularly under DORA and MiCA”: delivery of key Basel III elements; 21 recommendations (October 2025) to simplify the supervisory/regulatory framework, a number deliverable in 2026 without legislative change (the origin of the EBA Simplification and Efficiency Programme); the 1 August 2025 stress test confirming EU/EEA resilience; data modernisation via the Pillar 3 Data Hub and EDAP plus a first ESG Risk Dashboard; and expanded direct supervision (19 critical ICT third-party providers designated under DORA with the EBA as lead overseer; MiCA ART/EMT supervisory procedures finalised). A consolidated Part 2 is due end-June 2026. Position bullet and tracked-change entry added; reinforces the integrate-don’t-duplicate, technology-neutral, data-and-resilience-heavy posture already on the page. (Distinct from the same-day stacking-orders Report S-2026-06-16-eba-stacking-orders-simplification.) Updated 2026-06-17 based on S-2026-06-16-eba-stacking-orders-simplification — Stacking orders simplification Report (16 June 2026), the third milestone of the EBA’s “Simplifying to strengthen” efficiency programme. Targeted simplifications across the micro-/macroprudential and resolution capital stacks (clarify P1/P2R/P2G roles, remove macroprudential considerations from the microprudential stack, convert the leverage-ratio P2R into a buffer, merge CCyB+SyRB into a single releasable buffer, align TLAC/MREL definitions); “not a fundamental redesign”, delivering on TFE Recommendation 9 and linked to the forthcoming SREP Guidelines final report. Position bullet and tracked-change entry added; new EBA Simplification and Efficiency Programme topic created promoting the now-multi-source simplification theme. Updated 2026-06-16 based on S-2026-04-16-eba-reporting-framework-43 — Reporting Framework 4.3 draft technical package (16 April 2026; final package scheduled June 2026) added: DPM/XBRL taxonomies, validation rules and glossary for new third-country-branch reporting (first reference date 31 March 2027) and AMLA obliged-entity identification (first reference date 31 December 2026). Position bullet and tracked-change entry added; reinforces the EBA’s integrated/machine-readable reporting (JBRC, DPM 2.0) posture. Updated 2026-06-11 based on S-2026-06-02-eba-nydfs-stablecoin-mou — EBA signed a Memorandum of Understanding with the New York State Department of Financial Services (NYDFS) under MiCA (2 June 2026) to coordinate supervision of cross-border stablecoin activities; an Article 126 MiCA administrative agreement on information exchange, mutual assistance and crisis coordination, conditional on the EBA’s positive assessment that the NYDFS confidentiality/professional-secrecy regime is equivalent to MiCA. Position bullet and tracked-change entry added; extends the EBA’s direct-supervision-under-MiCA and international supervisory-cooperation posture. Updated 2026-06-10 based on S-2026-06-08-eba-p3dh-sncis — EBA Discussion Paper EBA/DP/2026/02 on extending the Pillar 3 Data Hub (P3DH) to Small and Non-Complex Institutions (8 June 2026, comments due 20 July 2026) added; the EBA will centrally calculate and publish SNCIs’ Pillar 3 disclosures from their supervisory reporting data (first publication Q4 2026, EU KM1 only; full set by 2028). Position bullet, tracked-change entries and a new EBA Pillar 3 Data Hub topic added; reinforces the EBA’s data-centralisation and proportionality posture. Updated 2026-06-09 based on S-2026-06-03-esas-dora-incident-report — the ESAs (EBA with EIOPA and ESMA) published the first annual DORA major-ICT-incident report (3 June 2026); a joint-ESA output, not EBA-only. Position bullet and tracked-change entry added; reinforces the EBA’s DORA-oversight priority. Updated 2026-06-08 based on S-2026-04-29-eba-connected-clients — Decision + consolidated Guidelines on connected clients (29 April 2026) added; further evidence of the EBA migrating material from guidance into directly-applicable single-rulebook RTS (here, Delegated Regulation (EU) 2024/1728 on identifying groups of connected clients for large exposures). Updated 2026-06-05 based on S-2026-04-29-eba-supervisory-independence — final Guidelines on Supervisory Independence (29 April 2026) now sourced: press release fetched directly; the previously unsourced position bullet is expanded with the four substantive areas (declarations of interest, trading restrictions, appointment/tenure transparency, cooling-off periods). Updated 2026-06-03 based on S-2026-05-19-eba-ict-security-guidelines — EBA consolidated amending Guidelines on ICT and security risk management (EBA/GL/2025/02, 19 May 2026) added; reinforces the EBA’s technology-neutral, integrate-into-existing-frameworks posture and its deference to DORA as the binding ICT baseline. Updated 2026-06-02 based on S-2025-12-17-eba-oprisk-reporting-guidance — enhanced operational-risk reporting: first reference date postponed to end-June 2026 (COREP OF release 4.2); imminent reporting-readiness milestone added.
Snapshot
The European Banking Authority — EU prudential supervisor for banking and payments. Pivotal to the wiki because the EBA’s AI Act mapping exercise crystallises the EU-banking position that CRR / CRD are technology-neutral and can host AI controls within existing frameworks — meaning firms should not build parallel AI governance structures.
Positions / Claims they advance
- CRR / CRD provide a comprehensive, technology-neutral governance and risk-management framework that supervisors will leverage to oversee AI use in banks [S-2025-11-eba-ai-act-mapping].
- 2026 Work Programme prioritises AI Act mapping and DORA oversight, with a 2026–2027 supervisory convergence programme rather than immediate new guidelines [S-2025-11-eba-ai-act-mapping].
- Only about half of EU banks have introduced dedicated policies or committees to oversee AI; 2LoD / 3LoD AI oversight is inadequate at most firms [S-2025-11-eba-ai-act-mapping].
- Revised Internal Governance Guidelines under CRD reflect DORA changes, tightening expectations on board oversight, ICT / third-party risk and internal governance [S-2025-11-eba-ai-act-mapping].
- Published a consolidated version of its amending Guidelines on ICT and security risk management (EBA/GL/2025/02 amending EBA/GL/2019/04, dated 19 May 2026), narrowing their scope because DORA’s harmonised ICT requirements have applied since 17 January 2025; framed as simplification and legal clarity, with ICT and security risk management still required to be embedded in governance frameworks under board oversight [S-2026-05-19-eba-ict-security-guidelines].
- Joint consultation EBA/CP/2026/03 on revised Guidelines on suitability extends to heads of control functions and CFOs; consultation closed 25 May 2026 with a public hearing held 15 April 2026 [S-2026-05-25-eba-esma-suitability-cp].
- With EIOPA and ESMA, co-authored a joint ESA Statement on frontier AI models (JC 2026 25, 31 July 2026) calling for a cross-sectoral, risk-based and consistent supervisory approach to frontier-AI ICT risk; it sets a governance/risk-management-framework expectation on financial entities, is framed within DORA, and updates on DORA oversight of Critical ICT Third-Party Providers — consistent with the EBA’s technology-neutral, integrate-into-existing-frameworks and DORA-oversight posture [S-2026-07-31-esas-frontier-ai-statement].
- Final Report on Guidelines on Supervisory Independence issued 29 April 2026 under CRD Art. 4a(9): minimum harmonised standards for competent authorities on declarations of interest (pre-employment, annual, ad-hoc), procedural requirements for disposing of conflict-prone financial instruments, transparency around appointment and tenure of governance body members, and criteria for cooling-off periods beyond the CRD minimum; builds on the Joint ESAs Supervisory Independence criteria (JC 2023 17) [S-2026-04-29-eba-supervisory-independence].
- EBA staff paper Systematic backtesting of probability of default models with regulatory data (29 April 2026) sets out a supervisory-data-driven approach to PD model backtesting [S-2026-04-29-eba-pd-backtesting].
- Final Guidelines on the Management of ESG Risks effective for Significant Institutions from 11 January 2026, with ECB applying strictly from 1 April 2026.
- Consultation on revised Guidelines on limits on exposures to shadow banking entities under CRR — shifts limit basis from eligible capital to Tier 1 capital; responses due 9 July 2026.
- Connected clients — published a Decision and a consolidated version of its Guidelines on connected clients (EBA/GL/2017/15) on 29 April 2026, partially deleting provisions now redundant because directly-applicable RTS in Commission Delegated Regulation (EU) 2024/1728 set out when institutions must identify groups of connected clients (control relationships, economic dependency); a single-rulebook simplification on the large-exposures data-identification substrate [S-2026-04-29-eba-connected-clients].
- Cross-border stablecoin supervision (MiCA) — signed a Memorandum of Understanding with the New York State Department of Financial Services (NYDFS) on 2 June 2026 under MiCA, establishing principles and procedures for information exchange, supervisory coordination, mutual assistance and crisis/emergency coordination over entities engaged in cross-border stablecoin activities, including issuers of significant ARTs/EMTs the EBA directly supervises; concluded under MiCA Article 126 (administrative agreements with third-country authorities) and conditional on the EBA’s positive assessment that the NYDFS confidentiality and professional-secrecy regime is equivalent to MiCA [S-2026-06-02-eba-nydfs-stablecoin-mou].
- DORA major-incident reporting — jointly with EIOPA and ESMA, published the first annual report on DORA major ICT-related incidents on 3 June 2026 (the Article 22(2) DORA mandate): 3,383 major incidents reported across EU financial entities (0.18 per entity), ~one third with cross-border impact, with system failures and external events the main drivers and only ~10% cybersecurity-related; the ESAs warn that highly capable AI-driven tools should push firms to strengthen cybersecurity [S-2026-06-03-esas-dora-incident-report].
- Frontier-AI systemic cyber risk (ESAs/ESRB, 7 July 2026) — jointly with EIOPA and ESMA, the EBA issued a statement supporting an ESRB warning on the systemic cyber risks posed by frontier AI models. The ESAs judge that DORA and the AI Act “provide a solid foundation for managing cyber and AI-related risks” but warn that frontier models’ enhanced ability to “identify and exploit high-severity vulnerabilities in IT systems within very short timeframes” means “AI-enabled cyber-attacks could undermine the operational resilience of financial entities”; they urge financial entities to adapt cybersecurity capabilities, invite competent authorities to reflect this in supervision, and confirm that in their capacity as Overseers of Critical ICT Third-Party Providers they are engaging those providers on mitigation. Framed as reinforcement of existing DORA/AI-Act requirements, not a new rule; the amplification is hedged (“could”) [S-2026-07-07-esas-esrb-frontier-ai-cyber]. See Operational Resilience and Third Party Risk.
- Pillar 3 Data Hub (P3DH) — the EBA’s CRR3-mandated (CRR Art. 434) centralised single access point for banks’ Pillar 3 prudential disclosures went live for large and other institutions on 26 January 2026 (data from June 2025 reference date). Discussion Paper EBA/DP/2026/02 (8 June 2026, comments due 20 July 2026) sets out the extension to SNCIs, under which the EBA will itself calculate and publish their disclosures from Article 430 supervisory reporting data (first publication Q4 2026, template EU KM1 only; full set envisaged 2028); the firm’s supervisory-reporting sign-off serves as disclosure sign-off, with data ownership remaining with the institution [S-2026-06-08-eba-p3dh-sncis]. See EBA Pillar 3 Data Hub.
- Integrated Reporting System vision (10 August 2026) — the EBA published a long-term “Vision for the Integrated Reporting System” setting out how prudential, resolution and statistical reporting can be integrated to raise efficiency and cut reporting cost for institutions and authorities. Its first objective is a common data dictionary with harmonised definitions and semantic integration across the three reporting areas; the technical route is the DPM 2.0 standard, DPM Studio and an enhanced concept glossary, with future integration to ECB statistical reporting (IReF) and a 2026 Digital Europe Programme project for a common European banking/insurance data dictionary, coordinated via the JBRC. The EBA notes integrated reporting may increase granularity even as it simplifies design and enables automation. A direction/target-state document (not an instrument) — the strategic layer above the concrete reporting milestones; relevance is the harmonised, machine-readable data-governance substrate credible reporting and model/AI data rest on [S-2026-08-10-eba-integrated-reporting-vision]. See EBA Simplification and Efficiency Programme.
- Reporting Framework 4.3 / integrated reporting — published a draft technical package for release 4.3 on 16 April 2026 (final package scheduled June 2026), delivering the Data Point Model (DPM) and XBRL taxonomies, validation rules and glossary for two new streams: ITS on supervisory reporting of third-country branches (CRD Art. 48l(1); first reference date 31 March 2027) and the DPM/taxonomy to identify obliged entities for direct AMLA supervision (first reference date 31 December 2026). It is the machine-readable data-dictionary layer firms map reporting data lineage to, and sits within the wider supervisory-reporting simplification package (consultation open to 10 July 2026; benchmarking public hearing 24 June 2026; ~50% data-point reduction; applies from September 2027) under the Joint Bank Reporting Committee (JBRC) DPM 2.0 initiative [S-2026-04-16-eba-reporting-framework-43]. Note: AML/TCB subject matter is tangential to the wiki’s AI core; relevance is the data-governance / regulatory-reporting taxonomy.
- Simplification and efficiency programme (“Simplifying to strengthen”) — on 16 June 2026 the EBA published its Report on simplifying the stacking orders of the EU prudential and resolution framework, the third milestone of the programme (after the April reporting simplification and the simpler 2027 stress test). It recommends targeted simplifications across the microprudential stack (clarify Pillar 1 / P2R / P2G roles; remove macroprudential considerations; convert the leverage-ratio Pillar 2 requirement into a buffer and remove LR guidance), the macroprudential stack (merge CCyB and SyRB into a single releasable buffer; update O-SII scoring/calibration) and the resolution stack (streamline MREL, aligning TLAC/MREL eligible-resource definitions). The EBA stresses it is “not a fundamental redesign”, assessed against four principles (resilience and capital neutrality, international standards, proportionality, Single-Market efficiency); it delivers on Task Force on Efficiency Recommendation 9 and is linked to the forthcoming SREP Guidelines final report (consulted 24 October 2025) [S-2026-06-16-eba-stacking-orders-simplification]. See EBA Simplification and Efficiency Programme.
- 2025 Annual Report (Part 1) — published 16 June 2026, the EBA characterises its 2025 delivery as “streamlining and improving the efficiency of the EU regulatory framework while expanding its supervisory role, particularly under DORA and MiCA”. Reported milestones: delivery of key Basel III elements with refinements across credit/market/operational risk; 21 recommendations (October 2025) for simplifying the supervisory/regulatory framework, a number of which require no legislative change and will be delivered during 2026 (the stated origin of the EBA Simplification and Efficiency Programme); the 1 August 2025 EU-wide stress test confirming EU/EEA banks hold capital above minima under severe scenarios; data modernisation via the Pillar 3 Data Hub and an expanded EDAP, plus a first ESG Risk Dashboard and preparation of a regular climate-stress-testing framework; and an expanded direct-supervision footprint — 19 critical ICT third-party providers designated under DORA (EBA as lead overseer) and finalised MiCA supervisory procedures for significant ART/EMT issuers. A consolidated Part 2 (Work Programme delivery, budget, staffing, management and internal control systems) is due by end-June 2026 [S-2026-06-16-eba-annual-report-2025].
- Pillar 3 disclosure simplification (ESG / equity / shadow banking) — on 22 June 2026 the EBA published its final draft ITS amending the Pillar 3 disclosure framework for ESG risks and introducing disclosures on equity exposures (CRR3 Art 438(e)) and aggregate shadow-banking exposures (Art 449b), finalising CRR3 disclosure implementation. ESG disclosure is extended to all institutions for the first time (Art 449a) via a “core plus supplement” proportionality model that cuts datapoints (large institutions −37%, taxonomy disclosures stopped; medium −17%; SNCIs −84% vs large); the EBA will centrally pre-fill and disclose SNCIs’ ESG information via the Pillar 3 Data Hub from supervisory reporting, embed JBRC semantic-integration recommendations, align with ESRS, and publish a DPM/XBRL taxonomy plus an updated Pillar 3 ↔ supervisory-reporting mapping tool in 2026; expected application reference date 31 Dec 2026 (31 Dec 2027 for SNCIs). Delivers TFE Recommendations 4 and 5; the fourth milestone of the “Simplifying to strengthen” programme [S-2026-06-22-eba-pillar3-esg-disclosure-its]. See EBA Simplification and Efficiency Programme and EBA Pillar 3 Data Hub.
- Sector risk view (Spring 2026 RAR) — on 18 June 2026 the EBA published its Spring 2026 Risk Assessment Report with the Q1 2026 Risk Dashboard and Spring 2026 RAQ. EU/EEA banks “continue to operate from a position of strength” (solid capital, liquidity, asset quality, sustained profitability), but the EBA flags rising operational and cyber risk as key concerns — driven by digitalisation, wider AI adoption and the cyber threat landscape — and warns that “increasingly capable (frontier) AI models may further amplify operational and cyber risks, including through new attack vectors and the potential misuse of AI-enabled tools” (hedged, not quantified). It also highlights growing NBFI / private-credit interconnectedness (bank exposures to NBFIs up notably; private-credit exposures concentrated in larger institutions) and a geopolitical overlay [S-2026-06-18-eba-rar-spring-2026]. See Operational Resilience and Third Party Risk.
- Product oversight and governance (revised POG Guidelines, 30 June 2026) — the EBA published revised Guidelines on product oversight and governance (POG) for retail banking products, amending its 2016 Guidelines (EBA/GL/2015/18). Targeted amendments make ESG and greenwashing considerations explicit throughout the product lifecycle — inserted into manufacturers’ internal control functions, target-market identification, distribution channels, and information provided to distributors — to ensure robust design/distribution of ESG-featured retail products and reduce consumer mis-selling; the EBA anchors “greenwashing” in the ESAs’ common definition (EBA/REP/2024/09). The revision also carries non-substantive updates aligning the POG GLs with the revised CRD Internal Governance Guidelines and the sound management of third-party risk (SMTPR), framed as removing outdated provisions “in line with the EBA’s work to simplify and build a more efficient regulatory and supervisory framework”. Addressed to manufacturers/distributors of products in the EBA’s remit (mortgages, personal loans, deposits, payment accounts, payment services, e-money); issued under Article 16 of Regulation (EU) No 1093/2010; to be published in all 24 languages in 2026 and applying from 11 January 2027 [S-2026-06-30-eba-pog-esg-greenwashing]. (Primarily a conduct/consumer-protection/ESG measure; tangential to the wiki’s AI core — relevance is the internal-governance / third-party-risk framework alignment and the simplification linkage.) See EBA Simplification and Efficiency Programme.
- Supervisory convergence (2025 Report, 29 June 2026) — the EBA published its annual Report on Supervisory Convergence, presenting consistent, risk-based supervision as the mechanism that makes rulebook simplification safe (“strong and consistent supervision can support the simplification of the regulatory framework, reduce unnecessary complexity, and help secure a level playing field”). It reports 2025 convergence across prudential supervision, resolution, consumer protection and digital finance (MiCA/DORA rollout, plus “strengthening supervisory capacity to address data quality issues, ICT dependencies and emerging technological risks”), delivered via peer reviews, Q&As, breach-of-Union-law investigations and training (25 courses / 2,900+ participants). 2026 priorities: Basel III implementation, resolution-testing frameworks, strengthening DORA oversight, and enhancing MiCA supervision. Delivers on Task Force on Efficiency Recommendation 17 (transparency of convergence work) and reports annually under Article 107 CRD [S-2026-06-29-eba-supervisory-convergence]. See EBA Simplification and Efficiency Programme.
- Operational risk reporting — following Regulation (EU) 2025/2475, the first reference date for the enhanced operational-risk reporting ITS was postponed from March 2026 to the end of June 2026; institutions must move to COREP OF module release 4.2, with templates C 16.02/16.03/16.04 first mandatory at the June 2026 reference date and revised reporting/disclosure instructions applying from that date [S-2025-12-17-eba-oprisk-reporting-guidance].
- ESG Risk Dashboard (H2 2025 update, 6 August 2026) — on 6 August 2026 the EBA published its latest ESG Risk Dashboard, reporting stable EU/EEA bank climate-risk exposures for H2 2025 (high-climate-impact-sector exposure unchanged at 62%; physical-risk exposures broadly unchanged but widely dispersed across jurisdictions, ~<10% to >55%) and continued improvement in the availability and quality of climate-related data — the share of mortgage exposures without energy-performance (EP) information and the share of estimated EP scores both declined marginally, while highly energy-efficient mortgage exposures (≤100 kWh/m²) rose slightly. A recurring monitoring product built on ESG disclosure data; the “data quality improving” reading is the EBA’s directional interpretation, not an independent audit. Reinforces the EBA’s data-modernisation / disclosure-data posture (Pillar 3 Data Hub) [S-2026-08-06-eba-esg-risk-dashboard]. (Primarily a climate/ESG data-quality signal; tangential to the wiki’s AI core — relevance is the data-governance substrate.) See EBA Pillar 3 Data Hub.
- Operational risk management framework (draft RTS consultation, 26 August 2026) — the EBA launched a consultation on draft RTS specifying the operational risk management framework institutions must have under Article 323(2) CRR3 (Regulation (EU) No 575/2013 as amended by CRR3, Regulation (EU) 2024/1623). The RTS specify three components — governance arrangements, the operational risk management process, and the operational risk assessment system — clarify the roles and responsibilities of the management body, senior management and the independent operational risk management function, and set requirements for operational risk data and taxonomy, the business indicator component, reporting, validation and audit; ICT risk is addressed through DORA. They support the EU Banking Package’s revised prudential framework for operational risk, which replaces prior approaches (including the AMA) with a single standardised approach based on the business indicator; they build on the BCBS Principles for the Sound Management of Operational Risk and are consistent with the EBA Guidelines on internal governance and DORA. A key feature is proportionality — firms with a business indicator below EUR 750 million benefit from lower review/reporting frequency and less granular operational-risk data, loss thresholds and taxonomy. Consultation closes 31 December 2026 (virtual public hearing 29 September 2026); the EBA will then finalise and submit to the Commission under Article 10 of Regulation (EU) No 1093/2010. A model-/operational-risk management-framework instrument (not AI), but its technology-neutral, roles-and-responsibilities-plus-independent-function architecture is a directly transferable template for AI/model-risk operating models [S-2026-08-26-eba-oprisk-rts-cp]. See Operational Resilience and Third Party Risk.
- ISDA SIMM validation/monitoring reporting (consultation, 5 August 2026) — as central validator of pro forma initial margin models under EMIR (Article 11(12a), EMIR 3; function live since 1 March 2026 under Decision EBA/DC/610), the EBA consulted on a standardised set of regular reporting requirements for counterparties seeking validation to use the ISDA SIMM, to enable ongoing validation and performance monitoring of the model and to calculate annual validation fees. Strongly proportionate by design — firms with less significant OTC trading activities would report only once a year — and framed as part of the EBA’s efficiency agenda; requirements enter technical package v4.4 Phase 2, with a Decision expected end-2026, first reporting reference date December 2027 and final package March 2027. Consultation closes 2 November 2026. A model-validation / ongoing-monitoring supervisory-reporting instrument (not AI); relevance is the model-risk-evidence and machine-readable-reporting substrate [S-2026-08-05-eba-isda-simm-validation-reporting]. See EBA Simplification and Efficiency Programme.
People
- Chair (addressees of the AI Act mapping outcome letter to Mr Berrigan and Mr Viola — typically European Commission addressees).
Relationships
- partners-with → ECB — parallel and coordinated supervisor; ECB applies EBA guidelines for SIs.
- partners-with → ESMA — joint ESA work programme overlap.
- relates-to → EU AI Act — EBA’s mapping exercise sits in service of the AI Act perimeter.
- relates-to → DORA — active supervisory priority.
- relates-to → CRR / CRD — the technology-neutral baseline.
- relates-to → BCBS — aligned posture on integrating AI into existing frameworks.
- relates-to → EBA Simplification and Efficiency Programme — the EBA’s multi-milestone burden-reduction initiative (reporting, stress test, capital stacks) [S-2026-06-16-eba-stacking-orders-simplification].
Tracked changes
- 2025-11 — Chair letter to Berrigan and Viola publishing AI Act mapping exercise outcome.
- 2026-01-11 — ESG risk guidelines effective for SIs.
- 2026-04-01 — ECB applies ESG guidelines strictly.
- 2026-04-29 — PD-backtesting staff paper [S-2026-04-29-eba-pd-backtesting]; Guidelines on Supervisory Independence final report [S-2026-04-29-eba-supervisory-independence].
- 2026-04-30 — Consultation on revised Internal Governance Guidelines.
- 2026-04-26 — 2026 Work Programme republished.
- 2026-04-29 — Decision + consolidated Guidelines on connected clients (EBA/GL/2017/15) published, partially deleting provisions superseded by Delegated Regulation (EU) 2024/1728 [S-2026-04-29-eba-connected-clients].
- 2026-05-19 — Consolidated amending Guidelines on ICT and security risk management (EBA/GL/2025/02) published, narrowing scope post-DORA [S-2026-05-19-eba-ict-security-guidelines].
- 2026-05-25 — EBA/CP/2026/03 suitability consultation closes [S-2026-05-25-eba-esma-suitability-cp].
- 2026-06-02 — EBA–NYDFS MoU on cross-border stablecoin supervision signed under MiCA Article 126 [S-2026-06-02-eba-nydfs-stablecoin-mou].
- 2026-06-03 — ESAs (EBA/EIOPA/ESMA) publish the first annual report on DORA major ICT-related incidents [S-2026-06-03-esas-dora-incident-report].
- 2026-07-07 — ESAs (EBA/EIOPA/ESMA) issue a joint statement supporting the ESRB warning on systemic cyber risks from frontier AI models; urge firms to adapt cybersecurity and competent authorities to reflect it in supervision [S-2026-07-07-esas-esrb-frontier-ai-cyber].
- 2026-07-31 — ESAs (EBA/EIOPA/ESMA) publish a joint Statement on frontier AI models (JC 2026 25) calling for cross-sectoral, risk-based, consistent supervision; sets a governance/risk-management-framework expectation on financial entities, framed within DORA, and updates on DORA CTPP oversight [S-2026-07-31-esas-frontier-ai-statement].
- 2026-04-16 — Draft technical package for Reporting Framework 4.3 (AML + third-country branches) published; final package scheduled June 2026 [S-2026-04-16-eba-reporting-framework-43].
- 2026-06-04 — Workshop ‘Efficient reporting: simpler, smarter, proportionate’ (supervisory-reporting simplification package) [S-2026-04-16-eba-reporting-framework-43].
- 2026-06-08 — Discussion Paper EBA/DP/2026/02 on the Pillar 3 Data Hub process to SNCIs published (comments due 20 July 2026) [S-2026-06-08-eba-p3dh-sncis].
- 2026-06-24 — Public hearing on changes to the ITS on supervisory benchmarking (simplification package) [S-2026-04-16-eba-reporting-framework-43].
- 2026-07-10 — Coupled Consultation Paper on revisions to the ITS on supervisory reporting (Module 8 – Alignment of P3 for SNCIs) closes [S-2026-06-08-eba-p3dh-sncis].
- 2026-07-20 — P3DH-to-SNCIs Discussion Paper comment deadline [S-2026-06-08-eba-p3dh-sncis].
- 2026-06 (end-June reference date) — First mandatory reference date for the enhanced operational-risk reporting ITS (COREP OF release 4.2) [S-2025-12-17-eba-oprisk-reporting-guidance].
- 2026-06-11 — Early consultation on the simplified 2027 EU-wide stress test published (draft methodology, templates, template guidance): 55% data-point reduction via reuse of supervisory reporting and first-time climate-risk module; second milestone of the “Simplifying to strengthen” programme [S-2026-06-11-eba-2027-stress-test].
- 2026-06-16 — Report on simplifying the stacking orders of the EU prudential and resolution framework published (third milestone of the “Simplifying to strengthen” programme; delivers on TFE Recommendation 9) [S-2026-06-16-eba-stacking-orders-simplification].
- 2026-06-16 — 2025 Annual Report (Part 1) published; consolidated Part 2 due end-June 2026 [S-2026-06-16-eba-annual-report-2025].
- 2026-06-18 — Spring 2026 Risk Assessment Report, Q1 2026 Risk Dashboard and Spring 2026 RAQ published; flags rising operational/cyber risk and possible frontier-AI amplification, plus NBFI/private-credit interconnectedness [S-2026-06-18-eba-rar-spring-2026].
- 2026-06-22 — Final draft ITS amending Pillar 3 disclosures on ESG risks, equity and shadow-banking exposures published (fourth “Simplifying to strengthen” milestone; SNCI ESG central pre-fill via P3DH) [S-2026-06-22-eba-pillar3-esg-disclosure-its].
- 2026-06-29 — 2025 Report on Supervisory Convergence published (fifth “Simplifying to strengthen” milestone; 2026 priorities include DORA oversight; delivers TFE Recommendation 17) [S-2026-06-29-eba-supervisory-convergence].
- 2026-06-30 — Revised Guidelines on product oversight and governance (POG) published, embedding ESG/greenwashing considerations across the product lifecycle and aligning with the revised CRD Internal Governance Guidelines and SMTPR; apply from 11 January 2027 [S-2026-06-30-eba-pog-esg-greenwashing].
- 2026-07-09 — Shadow banking exposure consultation responses due.
- 2026-08-05 — Consultation launched on a reporting framework for the validation and monitoring of the ISDA SIMM (operationalising the EMIR central-validator role for pro forma initial margin models); proportionate design with annual-only reporting for firms with less significant OTC activity; enters technical package v4.4 Phase 2; consultation to 2 November 2026 [S-2026-08-05-eba-isda-simm-validation-reporting].
- 2026-08-06 — Latest ESG Risk Dashboard published (H2 2025 data): stable climate-risk exposures (62% high-climate-impact-sector share) and continued improvement in climate-data availability/quality (fewer missing/estimated mortgage EP scores) [S-2026-08-06-eba-esg-risk-dashboard].
- 2026-08-10 — “Vision for the Integrated Reporting System” published: long-term target-state integrating prudential/resolution/statistical reporting around a common data dictionary and semantic integration (DPM 2.0 / DPM Studio; future IReF convergence; JBRC) [S-2026-08-10-eba-integrated-reporting-vision].
- 2026-08-26 — Consultation launched on draft RTS on the operational risk management framework (Art 323(2) CRR3): governance arrangements, management process and assessment system; independent operational risk management function; operational-risk data/taxonomy, business-indicator component, reporting, validation and audit; ICT risk via DORA; EUR 750m business-indicator proportionality threshold; consultation to 31 December 2026 (public hearing 29 September 2026) [S-2026-08-26-eba-oprisk-rts-cp].
- 2027-01-11 — Revised POG Guidelines apply [S-2026-06-30-eba-pog-esg-greenwashing].
Sources
- S-2025-11-eba-ai-act-mapping
- S-2026-05-25-eba-esma-suitability-cp
- S-2026-04-29-eba-pd-backtesting
- S-2025-12-17-eba-oprisk-reporting-guidance
- S-2026-05-19-eba-ict-security-guidelines
- S-2026-04-29-eba-supervisory-independence
- S-2026-04-29-eba-connected-clients
- S-2026-06-03-esas-dora-incident-report
- S-2026-06-08-eba-p3dh-sncis
- S-2026-06-02-eba-nydfs-stablecoin-mou
- S-2026-04-16-eba-reporting-framework-43
- S-2026-06-11-eba-2027-stress-test
- S-2026-06-16-eba-stacking-orders-simplification
- S-2026-06-16-eba-annual-report-2025
- S-2026-06-22-eba-pillar3-esg-disclosure-its
- S-2026-06-18-eba-rar-spring-2026
- S-2026-06-29-eba-supervisory-convergence
- S-2026-06-30-eba-pog-esg-greenwashing
- S-2026-07-07-esas-esrb-frontier-ai-cyber
- S-2026-07-31-esas-frontier-ai-statement
- S-2026-08-06-eba-esg-risk-dashboard
- S-2026-08-05-eba-isda-simm-validation-reporting
- S-2026-08-10-eba-integrated-reporting-vision
- S-2026-08-26-eba-oprisk-rts-cp