BCBS publishes range-of-practices report on ICT risk management (d611)
Tag: S-2026-06-02-bcbs-ict-range-of-practices Type: report (press release announcing publication) Author(s): Basel Committee on Banking Supervision Date of source: 2026-06-02 (press release / publication date) Date ingested: 2026-06-04 Authority weight: high — primary international banking supervisory standard-setter. Raw file: S-2026-06-02-bcbs-ict-range-of-practices.md. External URLs: https://www.bis.org/press/p260602.htm (press release); https://www.bis.org/bcbs/publ/d611.htm (report).
What it claims
On 2 June 2026 the Basel Committee on Banking Supervision published a range-of-practices report on information and communication technology (ICT) risk management. The report describes and compares observed bank ICT risk-management practices and regulatory/supervisory approaches across jurisdictions, focused specifically on non-malicious ICT incidents that affect the delivery of critical operations and services. ICT is framed as a key component of operational risk management and a vital contributor to the broader goal of operational resilience, with banks’ resilience to ICT incidents described as increasingly important in an evolving, digitalised technology landscape. The report explicitly complements the Committee’s 2018 cyber-resilience report (d454) by concentrating on non-malicious incidents rather than malicious cyber events. The documented practices are positioned as reference points that banks and supervisors can adapt to their own circumstances, not as new binding standards. The Committee states it will continue to monitor developments in the digitalisation of finance and financial technology from a prudential perspective, including developments in artificial intelligence models and the implications for banks’ cyber security.
Notable quotes
“ICT is a key component of operational risk management, playing a vital role in supporting the broader goal of achieving operational resilience.” — BIS press release p260602 (2 June 2026)
“The Committee will continue to monitor developments … related to the digitalisation of finance and financial technology from a prudential perspective, including developments in artificial intelligence models and the implications for banks’ cyber security.” — BIS press release p260602 (2 June 2026)
What’s speculative vs. asserted
- Asserted: publication of the report on 2 June 2026; its focus on non-malicious ICT incidents; the range-of-practices (descriptive, non-prescriptive) nature; the complementarity with the 2018 cyber-resilience report (d454); the operational-resilience framing; the Committee’s ongoing monitoring of AI-model cyber-security implications.
- Speculative / forward-looking: whether the documented practices will harden into formal supervisory expectations or principles in future; the precise content of the d611 report body (not retrieved this run); whether and how the report addresses AI-enabled ICT components directly.
Topics this feeds
Open questions raised
- What specific benchmark, if any, the documented practices set for ICT incident-management maturity.
- Whether the d611 report body references AI-enabled ICT components (e.g. model-serving infrastructure) explicitly, beyond the press release’s forward-looking AI/cyber monitoring statement.
- How the descriptive range-of-practices posture will interact with the binding DORA ICT regime and UK PS26/2 in cross-border firms.
Ingestion note
Press release fetched directly from bis.org (p260602.htm, dated 2 June 2026); confirmed it is the publication of the report foreshadowed at the 19–20 May 2026 BCBS meeting and previously captured in S-2026-05-20-bcbs-ict-press-release (which anticipated a June 2026 publication). The underlying report PDF/page (d611) was referenced in the press release but its full text was not retrieved this run — confirm report-body specifics before relying on this page for client deliverables. Report number recorded as d611 per the press release link; verify against the BIS publication index.