BCBS press release p260520 — agreement to publish ICT risk management range-of-practices report

Tag: S-2026-05-20-bcbs-ict-press-release Type: press release Author(s): Basel Committee on Banking Supervision Date of source: 2026-05-20 (press release date; meeting held 19–20 May 2026) Date ingested: 2026-05-28 Authority weight: high — primary international banking supervisory body. Raw file: S-2026-05-20-bcbs-ict-press-release.md. External URL: https://www.bis.org/press/p260520.htm

What it claims

The Basel Committee on Banking Supervision met in Basel on 19–20 May 2026 and approved a range-of-practices report describing observed information and communication technology (ICT) risk management practices across jurisdictions, focused on the treatment of non-malicious ICT incidents. ICT is framed as a key component of operational risk management and a contributor to the broader goal of operational resilience. The report is scheduled for publication “next month” (June 2026). The meeting also covered ongoing market developments, the cryptoasset standard targeted review, and machine-readable Pillar 3 disclosures.

Additional elements confirmed from the full press release (fetched directly 2026-06-05): members took note of recent developments in AI models and the implications for banks’ cyber security — frontier AI models could help banks and supervisors identify cyber vulnerabilities and strengthen defences, but their potential malicious use “may materially change the speed and scale of cyber incidents”; the Committee will continue to monitor and exchange supervisory insights. The Committee also agreed to consider targeted updates to its 2008 Principles for Sound Liquidity Risk Management and Supervision, approved a workplan on the financial impacts of extreme weather events, and agreed to consult later in 2026 on embedding the treatment of cross-border exposures within the European banking union in the G-SIB framework.

Notable quotes

“The Committee approved a report describing a range of observed information and communication technology (ICT) risk management practices across jurisdictions to addressing non-malicious ICT incidents.” — BIS press release p260520 (verbatim; confirmed by direct fetch 2026-06-05)

“While frontier AI models could help banks and supervisors in identifying cyber vulnerabilities and strengthening defences, their potential malicious use may materially change the speed and scale of cyber incidents.” — BIS press release p260520, Financial stability outlook section (verbatim; added 2026-06-05)

What’s speculative vs. asserted

  • Asserted: the Committee’s agreement to publish a range-of-practices report on ICT risk management; the focus on non-malicious ICT incidents; the June 2026 publication target; the broader operational-resilience framing.
  • Speculative / forward-looking: the specific content of the report and whether it will set new supervisory expectations vs. summarise existing practice; whether subsequent BCBS work will harden into formal principles.

Topics this feeds

Open questions raised

  • What benchmark the published report will set for ICT incident management practices.
  • Whether the range-of-practices report will reference AI-enabled ICT components (e.g. model-serving infrastructure) explicitly.

Ingestion note

Search-derived from BIS press release excerpts; direct fetch of the press release page was not completed in this scan. Confirm wording from the published press release before relying on this page for client deliverables.

2026-06-05 re-scan: full press release fetched directly (WebFetch of https://www.bis.org/press/p260520.htm). Original excerpts confirmed verbatim; AI/cyber, liquidity-principles, extreme-weather and G-SIB elements added above. The earlier confirm-wording caveat is now resolved for this page.