Operational Resilience and Third Party Risk
Created: 2026-05-17 Updated: 2026-09-17 Source count: 20
Updated 2026-09-14 based on S-2026-09-01-anthropic-enterprise-frontier-safeguards (daily AI-governance vendor-intelligence scan) — adds a frontier-model-provider instance of this page’s third-party data-custody thread: Anthropic’s Enterprise Frontier Safeguards (announced 1 Sep 2026; phased rollout from autumn) lets a customer keep the activity logs used for the provider’s misuse detection in the customer’s own S3/Azure Blob/GCS account under customer-managed keys, access policies and audit logging, with automated flags routed to the customer’s own reviewers and no provider human review — designed with the ARC systemic-risk centre (CISOs of the largest US banks) and quoted by Wells Fargo’s CISO, FIS and Stripe; trade press frames it as a reversal of a 30-day retention policy after regulated-customer pushback. Read-across for this page: who holds the logs and keys for a frontier-model provider becomes a register-of-information and exit-planning item (the data stays in the firm’s cloud if the relationship ends) and the firm inherits alert-triage and retention duties; the “sovereign access” concentration concern raised by BIS FSI OP28 is partly addressed at the data layer but not at the model layer [inference]. No EU/UK reference, standard or retention period stated ⚠️. Added as a Key Point and a Source; per-vendor detail on Anthropic and the tooling read on AI Governance Platforms [S-2026-09-01-anthropic-enterprise-frontier-safeguards].
Updated 2026-09-11 based on S-2026-09-11-weekly-vendor-synthesis (weekly vendor-synthesis agent) — adds three DG/DM vendor-market instances of this page’s ICT third-party thread from one week, none of them a product feature: (1) Alation confirmed a cyberattack on 20 Aug 2026 (“unauthorized activity in one of its systems”; nature, root cause, customer impact and exfiltration undisclosed) — the first security incident recorded against a tracked governance vendor, and unmentioned in Alation’s 4 Sep IDC Leader release; a catalogue holds concentrated metadata about a bank’s most sensitive data estates, so this is a live ICT third-party incident-notification and exit-strategy test for any FI customer [inference]; (2) Collibra’s Console log End of Life and Dataplex-ingestion freeze (releases 2026.08/2026.09) — the audit-log retrieval path an FI uses for DORA / operational-resilience evidence is itself being retired, with the successor Log API undated; (3) Ataccama’s Benelux distributor appointment (Systemation, 3 Sep) — distributor-led delivery adds a subcontracting layer that a DORA register of information must name. Per-vendor facts are integrated on Alation, Collibra and Ataccama; this banner records the cross-vendor read that vendor-side events of three different kinds all land as register-of-information items [S-2026-09-11-weekly-vendor-synthesis]. Updated 2026-09-10 based on S-2026-09-09-bis-fsi-op28-frontier-ai-cyber (daily regulatory-intelligence scan) — the BIS Financial Stability Institute published FSI Occasional Paper No 28, When machines attack: frontier AI cyber threats and policy responses in the financial sector (9 September 2026; Crisanto, Currat, Yong). It synthesises the exact frontier-AI-cyber overlay this page already tracks and reaches the same headline posture as the UK (15 May) and EU (7 & 31 July) statements: authorities are reinforcing existing cyber-risk-management and operational-resilience frameworks rather than building new AI-specific cyber regimes, and frontier AI “does not fundamentally change the foundations of cyber resilience, but … significantly increases the speed and intensity with which established practices need to be executed.” Three practitioner-relevant additions: (i) compressed remediation windows — frontier models collapse the discovery-to-exploitation window and automate exploit chaining, raising breach likelihood, with unpatched software the leading initial-access vector; (ii) a sharpened third-party thread — reliance on common cloud/software/frontier-AI providers creates concentration and “sovereign access” risk, where one provider’s disruption or policy decision can cascade across firms and jurisdictions; (iii) policy emphasis on governance for timely decision-making, accelerated patching and stronger response/recovery. Reinforcing (not contradicting) the existing thread; medium authority (FSI Occasional Paper — authors’ views, not an official BCBS/BIS standard). Added as a Key Point and a Detail subsection. The 28-page PDF was not extracted this run — jurisdiction-level policy mapping and any quantification are not captured ⚠️. [S-2026-09-09-bis-fsi-op28-frontier-ai-cyber]
Updated 2026-09-09 based on S-2026-09-08-cpmi-iosco-fmi-third-party-cyber (daily regulatory-intelligence scan) — CPMI-IOSCO published, for consultation, two linked documents on 8 September 2026: a discussion paper FMIs’ reliance on third-party service providers: challenges and risks (22pp, with cover note) and a consultative report Cyber resilience toolkit: practical considerations for FMIs (comments due 1 December 2026). The discussion paper identifies how financial market infrastructures’ increased reliance on third-party providers for critical services amplifies risk, and — given FMIs’ “unique and highly interconnected role in the financial system” — stresses the importance of FMIs managing it, posing consultation questions to industry; the companion toolkit addresses cyber resilience explicitly “in the context of risks that may arise through their use of third-party service providers”. This adds a global standard-setter (CPMI-IOSCO) voice to this page’s third-party-concentration and cyber-resilience threads, previously carried mainly by DORA/CTPP, BCBS d605 and the UK CTP regime. Reinforcing (not contradicting): consultative, and scoped to FMIs — the read-across to DORA CTPP oversight and the UK Critical Third Parties regime for banks/insurers is this vault’s inference, not stated by the source [inference]. Added as a Key Point, a Detail subsection and an Open Question. The two document PDFs and cover note were not extracted this run — the enumerated risks, questions and toolkit “practical considerations” are not captured ⚠️. [S-2026-09-08-cpmi-iosco-fmi-third-party-cyber]
Updated 2026-08-28 based on S-2026-08-26-eba-oprisk-rts-cp (daily regulatory-intelligence scan) — the EBA launched a consultation on draft RTS specifying the operational risk management framework under Article 323(2) CRR3 (26 August 2026, to 31 December 2026). This adds the operational-risk management-framework layer beneath this page’s operational-resilience and DORA threads: harmonised, proportionality-tiered requirements for three components — governance arrangements, the operational risk management process, and the operational risk assessment system — clarifying the roles of the management body, senior management and an independent operational risk management function, and setting requirements for operational risk data and taxonomy, the business indicator component, reporting, validation and audit. Crucially for this page’s integrate-don’t-duplicate boundary, the EBA states ICT risk is addressed through DORA (not this RTS), and the RTS build on the BCBS Principles for the Sound Management of Operational Risk and are consistent with the EBA Guidelines on internal governance — the same technology-neutral posture the EBA takes on AI. Proportionality: firms with a business indicator below EUR 750m get lower review/reporting frequency and less granular data/taxonomy. Reinforcing (not contradicting): draft, under consultation, not in force. Added as a Key Point and a Detail note. The RTS detail (Art 323(1)(a)–(h), data/taxonomy specifics) sits in the 709KB consultation PDF, not extracted this run ⚠️. [S-2026-08-26-eba-oprisk-rts-cp]
Updated 2026-08-21 based on S-2026-08-21-weekly-vendor-synthesis (weekly vendor-synthesis agent) — adds the first explicit vendor-market instance to this page’s AI Supply-Chain Concentration thread: Databricks’ expanded Microsoft partnership (23 Jul 2026, captured into the wiki 18 Aug) deepens a firm’s practical dependency on a single cloud/platform pairing (Databricks core operations moving to Azure Databricks / Azure Cobalt infrastructure) at the same time Databricks closed a $5B funding round ($190B valuation, 13 Aug) partly earmarked for its Unity AI Gateway governance layer. Read together, this is a concrete, named instance of the concentration risk this page’s “Maintain a Foundation-Model Exit Plan” practical application already anticipates in the abstract — the underlying facts were previously recorded only on the Databricks entity page as an open question; this synthesis is the first place the connection to the DORA Critical Third-Party thread is made explicit [inference — S-2026-08-21-weekly-vendor-synthesis].
Updated 2026-08-06 based on S-2026-07-31-esas-frontier-ai-statement (daily regulatory-intelligence scan) — the ESAs (EBA, EIOPA, ESMA) published a joint Statement on frontier AI models (JC 2026 25, 31 July 2026) calling for a cross-sectoral, risk-based and consistent supervisory approach to the ICT risks stemming from frontier AI models. It outlines measures to strengthen operational resilience against frontier-AI cyber risk (emphasis on prevention, detection and management), states that financial entities should have robust governance and risk-management frameworks to manage those cyber risks, updates on ongoing and planned DORA oversight of Critical ICT Third-Party Providers (CTPPs), and invites firms and competent authorities to use it as a basis for supervisory dialogue against existing expectations. This advances the frontier-AI cyber overlay on this page from the ESAs’ 7 July warning S-2026-07-07-esas-esrb-frontier-ai-cyber to a supervisory-approach and governance-expectation statement, and is the EU counterpart to the UK FCA/BoE/HMT 15 May 2026 statement S-2026-05-15-fca-boe-treasury-frontier-ai-cyber. Reinforcing (not contradicting): framed within DORA/AI Act as reinforcement, not a new rule; the “measures” and specific CTPP activities were not enumerated in the press release (full JC 2026 25 PDF not retrieved ⚠️). Added as a Key Point and a Detail note. [S-2026-07-31-esas-frontier-ai-statement]
Updated 2026-07-28 based on S-2026-07-07-esas-esrb-frontier-ai-cyber (daily regulatory-intelligence scan) — the ESAs (EBA, EIOPA, ESMA) issued a joint statement (7 July 2026) supporting an ESRB warning on the systemic cyber risks posed by frontier AI models. The ESAs judge that DORA and the AI Act “provide a solid foundation” but warn the “speed and scale” of frontier models’ ability to find and exploit high-severity vulnerabilities “could undermine the operational resilience of financial entities”; they urge financial entities to adapt cybersecurity capabilities and invite competent authorities to reflect this in supervision, frame their response within DORA, and confirm they are engaging Critical ICT Third-Party Providers (in their CTPP Overseer capacity) on mitigation. This is the EU cross-sectoral counterpart to the 15 May 2026 UK FCA/BoE/HMT frontier-AI cyber statement already on this page — reinforcing (not contradicting) the frontier-AI cyber overlay and the CTPP/third-party-oversight thread. Framed as reinforcement of existing DORA/AI-Act requirements, not a new rule; the amplification is hedged (“could”). Added as a Key Point and a Detail note;
domain/ai-regulationcontext noted. [S-2026-07-07-esas-esrb-frontier-ai-cyber]
Updated 2026-07-10 based on S-2026-07-08-outseer-iso42001 (daily AI-governance vendor-intelligence scan) — a supply-side signal for this page’s AI-vendor-due-diligence thread: Outseer, an AI-driven fraud/scam-prevention vendor serving banks and payment providers, announced (8 Jul 2026) it has achieved ISO/IEC 42001 (AIMS) certification from Intertek, explicitly marketing the certificate as third-party assurance for its FS customers’ oversight of the AI protecting their accounts. Reinforces (does not contradict) the existing picture that AI vendors fall inside BCBS d605 / DORA third-party frameworks — this is the first vault-recorded instance of an FS-sector third party supplying a management-system certificate to meet that demand. Certification scope unstated and not verified against Intertek’s register; customer-scale claims are vendor marketing. Added as a Key Point, a Detail note, a Practical Application caution and an Open Question.
Updated 2026-06-26 based on S-2026-06-18-eba-rar-spring-2026 — the EBA’s Spring 2026 Risk Assessment Report (18 June 2026) adds the EU prudential supervisor’s current sector risk view: operational and cyber risk are “key concerns”, and “the rapid development of increasingly capable (frontier) AI models may further amplify operational and cyber risks, including through new attack vectors and the potential misuse of AI-enabled tools”, reinforcing the need for “strong operational resilience, cybersecurity controls and contingency planning”. Added as a Key Point; reinforcing (not contradicting) the frontier-AI cyber overlay already on this page from the FCA/BoE/HMT joint statement, BCBS d611 and the ESAs DORA incident report — note the EBA’s “may” hedge is preserved. The RAR PDF/dashboard/RAQ detail was not retrieved (open question). Updated 2026-06-25 based on S-2026-06-24-fca-rathi-ai-speech — FCA CEO Nikhil Rathi (techUK, 24 June 2026) escalated the third-party / AI-stack concentration thread to CEO level: financial services are “increasingly reliant on cloud providers, model providers, data providers … many parts of the AI stack”, so dependencies “must be properly mapped and governed, and the Critical Third Parties regime becomes more important than ever”, with boards expected to understand the risks — anchored by the figure that 98% of operational incidents reported to the FCA last year were technology/cyber-related. Added as a Key Point; reinforces (does not contradict) the d605 / DORA / PS26/2 third-party-accountability picture and the frontier-AI cyber overlay already on the page. Updated 2026-06-23 based on S-2026-05-28-sifflet-insurance-continuous-evidence (daily vendor-intelligence scan) — adds the vendor-market reflection of this page’s “continuous evidence” thread: data-observability vendor Sifflet (28 May 2026) positions continuous, auditable data-quality/lineage/incident evidence as the answer to converging Solvency II Art 82 / EIOPA / ACPR, DORA Art 9(2) and Solvency UK expectations, and cites a named French insurer (Malakoff Humanis) reference. Captured as vendor positioning + FS reference (low authority), not as a new regulatory fact. Updated 2026-06-09 based on S-2026-06-03-esas-dora-incident-report — the ESAs (EBA/EIOPA/ESMA) published the first annual DORA major-ICT-incident report (3 June 2026); adds the first hard supervisory dataset on EU ICT incidents (3,383 major incidents, ~one third cross-border, system failures/external events the main drivers, ~10% cyber), reinforcing the third-party-oversight thread and the AI-cyber watch-item already on this page. Updated 2026-06-04 based on S-2026-06-02-bcbs-ict-range-of-practices — the BCBS ICT range-of-practices report (d611) was published on 2 June 2026, confirming the publication foreshadowed by the 19–20 May 2026 meeting press release; the prior “scheduled for June 2026” Key Point is updated to reflect actual publication, and the report’s complementarity with the 2018 cyber-resilience report (d454) and its non-malicious-incident focus are integrated. Updated 2026-06-03 based on S-2026-05-19-eba-ict-security-guidelines — EBA consolidated amending Guidelines on ICT and security risk management (EBA/GL/2025/02, 19 May 2026) integrated; reinforces the DORA-as-binding-backbone picture, with the residual EBA Guidelines narrowed to remove overlap with DORA. Updated 2026-05-29 based on S-2026-05-15-fca-boe-treasury-frontier-ai-cyber — FCA / BoE / HMT joint statement on frontier AI models and cyber resilience integrated. Updated 2026-05-28 based on S-2026-05-20-bcbs-ict-press-release — BCBS ICT range-of-practices report approval added.
TL;DR
Operational resilience and third-party risk are converging across regimes. BCBS d605 (10 December 2025) finalises a technology-agnostic third-party risk baseline; DORA is the binding EU framework for ICT risk and third-party oversight; and the UK joint PS26/2 Policy Statement (in force 18 March 2027) brings operational incident and third-party reporting into a continuous-compliance posture. For AI, the practical consequence is that GPAI providers, AI vendors, and cloud / model hosts fall within third-party risk frameworks — accountability for AI outputs cannot be outsourced even when the underlying capability is.
Key Points
- BCBS d605 establishes 12 principles (9 banks, 3 supervisors) as a technology-agnostic third-party risk baseline; supersedes the 2005 Joint Forum Outsourcing paper; aligns with DORA and the FCA Critical Third Parties regime [S-2025-12-10-bcbs-d605].
- Banks must retain clear accountability for all activities performed by third parties even where fully outsourced, with robust governance frameworks, comprehensive risk assessments, and ongoing monitoring throughout the relationship lifecycle [S-2025-12-10-bcbs-d605].
- The EBA published a consolidated version of its amending Guidelines on ICT and security risk management (EBA/GL/2025/02 amending EBA/GL/2019/04, dated 19 May 2026), narrowing their scope because DORA’s harmonised ICT risk-management requirements have applied since 17 January 2025; the aim is to simplify the framework and provide legal clarity, while still requiring ICT and security risk management to be embedded in institutions’ governance frameworks with board oversight [S-2026-05-19-eba-ict-security-guidelines].
- UK joint Policy Statement PS26/2 on operational incident and third-party reporting (FCA / PRA / Bank of England) comes into force 18 March 2027 [S-2026-03-fca-ps26-2].
- PS26/2 represents a shift from one-time compliance exercises to demonstrating continuous adherence to impact tolerances [S-2026-03-fca-ps26-2].
- The FCA published “Operational resilience: insights and observations one year on” — a review of self-assessments after the 31 March 2025 transition deadline [S-2026-03-fca-ps26-2].
- Deployers of third-party GPAI models in regulated workflows must evidence upstream-provider compliance (copyright policy, training-data summary) within their own AI governance and third-party risk frameworks [S-2026-04-29-eu-ai-office-gpai].
- BCBS published its range-of-practices report on ICT risk management on 2 June 2026 (BCBS d611), delivering the report approved at the 19–20 May 2026 meeting; it documents observed bank and supervisory ICT risk-management practices across jurisdictions for non-malicious ICT incidents, complements the 2018 cyber-resilience report (d454), and is descriptive (reference points to adapt) rather than a new binding standard — sitting within the broader operational-resilience agenda alongside DORA and PS26/2 [S-2026-06-02-bcbs-ict-range-of-practices][S-2026-05-20-bcbs-ict-press-release].
- The BCBS notes it will keep monitoring AI-model developments and their implications for banks’ cyber security from a prudential perspective — signalling AI’s ICT/operational-resilience surface remains an active supervisory watch-item even though d611 itself is framed around non-malicious incidents [S-2026-06-02-bcbs-ict-range-of-practices].
- FCA / BoE / HMT joint statement on frontier AI models and cyber resilience (15 May 2026) reinforces operational-resilience expectations specifically for frontier-AI cyber risk, with firm-level expectations across governance and strategy, vulnerability management, third-party / supply-chain (including open-source) cyber risk, protection, and response and recovery [S-2026-05-15-fca-boe-treasury-frontier-ai-cyber].
- The joint statement names CMORG as the engagement channel and points firms to NCSC guidance; the statement is explicitly framed as reinforcement of existing operational-resilience rules, not new requirements [S-2026-05-15-fca-boe-treasury-frontier-ai-cyber].
- The ESAs (EBA, EIOPA, ESMA) published the first annual DORA major-ICT-incident report on 3 June 2026 — the first hard dataset from DORA’s harmonised incident-reporting mechanism: 3,383 major incidents (0.18 per entity), ~one third with cross-border impact, but generally limited direct client/transaction impact [S-2026-06-03-esas-dora-incident-report].
- System failures and external events were the main drivers of major incidents (only ~10% cybersecurity-related), which the ESAs say underscores the need for robust third-party risk management, oversight of outsourced services, and close coordination with service providers during incident response and remediation [S-2026-06-03-esas-dora-incident-report].
- The ESAs warn that the evolution of highly capable AI-driven tools should push firms to strengthen cybersecurity to maintain resilience — echoing the BCBS d611 AI/cyber watch-item from the prudential side [S-2026-06-03-esas-dora-incident-report][S-2026-06-02-bcbs-ict-range-of-practices].
- The ESAs followed the incident dataset with “DORA Incident Reporting – Operational Instructions” (16 September 2026) — best-efforts, regularly-updated staff guidance (not legal interpretation or official ESA stance, agreed with competent authorities) to raise data quality and cross-jurisdiction consistency in major-ICT-incident reporting under ITS 2025/302 / RTS 2025/301 / RTS 2024/1772. Fourteen field-level conventions include always flagging “critical services affected”, a one-month final-report deadline with monthly intermediate updates, immutable unique incident IDs, and a standardised LEI/EUID third-party-provider origin field (2.8) — the last making TPP-originated incidents more analysable and feeding the third-party-concentration thread on this page. Directly relevant to firms’ incident-reporting controls and evidence packs, though its formal addressees are competent authorities [S-2026-09-16-eba-dora-incident-reporting-operational-instructions].
- The ESAs (EBA, EIOPA, ESMA) published a joint Statement on frontier AI models (JC 2026 25, 31 July 2026) calling for a cross-sectoral, risk-based and consistent supervisory approach to the ICT risks from frontier AI models; it states that financial entities should have robust governance and risk-management frameworks to prevent, detect and manage the cyber risks associated with frontier AI, framed within DORA, and updates on ongoing and planned DORA oversight of Critical ICT Third-Party Providers (CTPPs) — moving the ESAs’ frontier-AI position from the 7 July warning to an outline of measures and a supervisory-dialogue basis [S-2026-07-31-esas-frontier-ai-statement].
- FCA CEO Nikhil Rathi (techUK speech, 24 June 2026) framed AI-stack concentration as a front-line resilience issue: as reliance on cloud, model and data providers grows, “dependencies … must be properly mapped and governed, and the Critical Third Parties regime becomes more important than ever”, with boards expected to understand the risks; he cited that 98% of operational incidents reported to the FCA last year related to technology and cyber issues and that frontier AI could magnify cyber risk for both defenders and attackers — a CEO-level reinforcement of the third-party-accountability and frontier-AI-cyber threads already on this page [S-2026-06-24-fca-rathi-ai-speech].
- EBA Spring 2026 Risk Assessment Report (18 June 2026) records the EU prudential supervisor’s view that operational and cyber risk are rising and are “key concerns for the banking sector”, driven by digitalisation, wider AI adoption and an evolving cyber threat landscape; it adds that “increasingly capable (frontier) AI models may further amplify operational and cyber risks, including through new attack vectors and the potential misuse of AI-enabled tools”, underlining “strong operational resilience, cybersecurity controls and contingency planning” — a regulator-side reinforcement of the frontier-AI cyber thread on this page, with the amplification expressly hedged (“may”) and not quantified in the press-release text retrieved [S-2026-06-18-eba-rar-spring-2026].
- ESAs (EBA, EIOPA, ESMA) support ESRB warning on systemic cyber risks from frontier AI models (joint statement, 7 July 2026) — the EU cross-sectoral supervisory reinforcement of the frontier-AI cyber overlay. The ESAs judge that DORA and the AI Act “provide a solid foundation for managing cyber and AI-related risks” but warn that the “speed and scale” of frontier models’ ability to “identify and exploit high-severity vulnerabilities in IT systems within very short timeframes” mean “AI-enabled cyber-attacks could undermine the operational resilience of financial entities”; they urge financial entities to make appropriate arrangements to adapt their cybersecurity capabilities and invite competent authorities to reflect these developments in their supervisory activities, anchoring the response in DORA and confirming that — as Overseers of Critical ICT Third-Party Providers — they are engaging those providers on mitigation. The ESRB’s stakeholder call expressly spans “AI providers, software providers, security firms, open-source maintainers, financial institutions, and authorities”. Reinforces the frontier-AI cyber and CTPP/third-party threads already on this page (the EU counterpart to the 15 May 2026 UK FCA/BoE/HMT statement); framed as reinforcement of existing requirements, not a new rule, with the amplification hedged (“could”) [S-2026-07-07-esas-esrb-frontier-ai-cyber].
- Vendor-market signal — supply side of AI vendor due diligence: fraud/scam-prevention vendor Outseer (London; RSA heritage; serves banks and payment providers using “predictive, generative, and agentic AI”) announced on 8 July 2026 that it achieved ISO/IEC 42001 AI-management-system certification from Intertek, marketing the certificate as “additional assurance” for banks and payment providers that the AI systems protecting their customers “operate under rigorous controls”, and citing “growing demand from regulators, financial institutions, and consumers” for transparency in AI-powered decision-making. The certification and certifying body are specifically asserted; the certificate’s scope is unstated, and the demand claim and customer-scale figures are vendor assertions [S-2026-07-08-outseer-iso42001].
- Vendor-market signal (low authority): data-observability vendor Sifflet argues (28 May 2026) that supervisors now expect continuous, auditable proof of data quality rather than annual/quarterly reconstruction, mapping its “control plane for Data and AI” onto Solvency II Art 82, EIOPA TP-valuation Guidelines, a tightened ACPR posture, DORA Art 9(2) data-integrity duties, and Solvency UK — and naming Malakoff Humanis (a large French ACPR-supervised insurer) as a reference running continuous Solvency II data-quality controls; regulatory references are Sifflet’s characterisation and the reference-customer/capability claims are self-interested and unverified [S-2026-05-28-sifflet-insurance-continuous-evidence].
- EBA consults on the operational-risk management framework (RTS, Art 323(2) CRR3, 26 Aug 2026): harmonised, proportionality-tiered requirements for governance arrangements, the operational risk management process, and the operational risk assessment system, clarifying the roles of the management body, senior management and an independent operational risk management function, plus requirements for operational risk data and taxonomy, the business indicator component, reporting, validation and audit. ICT risk is addressed through DORA (carved out of this RTS); the RTS build on the BCBS Principles for the Sound Management of Operational Risk and are consistent with the EBA Guidelines on internal governance; firms with a business indicator below EUR 750m get proportionate relief. Draft, consultation to 31 December 2026 (public hearing 29 Sept 2026) — not yet in force [S-2026-08-26-eba-oprisk-rts-cp].
- CPMI-IOSCO consult on FMI third-party reliance + cyber resilience (8 Sep 2026): two linked consultative documents — a discussion paper FMIs’ reliance on third-party service providers: challenges and risks and a Cyber resilience toolkit: practical considerations for FMIs — identify how FMIs’ growing reliance on third-party providers for critical services amplifies risk given FMIs’ interconnected systemic role, tie cyber resilience explicitly to third-party use, and pose consultation questions (comments due 1 December 2026). A global standard-setter reinforcement of this page’s third-party-concentration and cyber-resilience threads; consultative and FMI-scoped, with read-across to DORA CTPP oversight and the UK Critical Third Parties regime marked as this vault’s inference [inference — S-2026-09-08-cpmi-iosco-fmi-third-party-cyber].
- BIS FSI Occasional Paper No 28 — frontier AI cyber threats (9 Sep 2026): the FSI (Crisanto, Currat, Yong) concludes that financial authorities are reinforcing existing cyber-risk-management and operational-resilience frameworks rather than introducing new AI-specific cyber regimes, and that frontier AI “does not fundamentally change the foundations of cyber resilience, but … significantly increases the speed and intensity with which established practices need to be executed.” Frontier models can autonomously find vulnerabilities, build exploits and chain multi-step operations, collapsing the discovery-to-exploitation window and raising breach likelihood (unpatched software the leading initial-access vector); reliance on common cloud/software/frontier-AI providers adds concentration and “sovereign access” risk; policy emphasis falls on governance for timely decision-making, accelerated patching and response/recovery. Reinforces the frontier-AI-cyber and third-party-concentration threads on this page (the global-analysis counterpart to the UK 15 May and EU 7/31 July statements); medium authority (FSI Occasional Paper — authors’ views, not an official BCBS/BIS standard); 28-page PDF not extracted ⚠️ [S-2026-09-09-bis-fsi-op28-frontier-ai-cyber].
- Vendor-market signal — named concentration instance: Databricks closed a $5B funding round at a $190B valuation (13 Aug 2026) partly earmarked for its Unity AI Gateway governance layer, at the same time it deepened its Microsoft partnership “into the 2030s” (core operations moving to Azure Databricks / Azure Cobalt infrastructure). For EU/UK regulated firms already dependent on both platforms, this is a concrete, named instance of the AI-stack/cloud-platform concentration this page’s Practical Applications already flag in the abstract via the AI Supply-Chain Concentration Heatmap — the read that this materially raises DORA Critical Third-Party concentration risk is this vault’s inference, not stated by either company [inference — S-2026-08-21-weekly-vendor-synthesis].
- Vendor-market signal — governance-vendor incident and lifecycle events as register items (Aug–Sep 2026): in the week to 11 Sep three DG/DM vendor events landed that are ICT third-party items rather than capability news — Alation’s confirmed 20 Aug cyberattack (scope undisclosed; not referenced in its 4 Sep analyst-placement release), Collibra’s retirement of Console-based log access and Dataplex ingestion (successor Log API undated), and Ataccama’s appointment of a Benelux distributor (a subcontracting layer between vendor and FI). The synthesis’s practitioner read: for each, the client question is concrete — the incident-notification terms actually exercised and what catalogue-metadata exposure would mean (Alation); Log API availability before Console EoL and Edge-equivalence for GCP estates (Collibra); which party the FI contracts with for implementation and support (Ataccama) [S-2026-09-11-weekly-vendor-synthesis]. A catalogue vendor compromise is a concentrated-metadata event — the catalogue describes where sensitive data lives, who owns it and how it flows — which is why it belongs on this page rather than only on the vendor’s [inference — S-2026-09-11-weekly-vendor-synthesis].
- Vendor-market signal — a frontier-model provider offering customer-held usage evidence (Sep 2026): Anthropic’s Enterprise Frontier Safeguards (1 Sep 2026) stores misuse-detection activity data in the customer’s own cloud account under customer-managed keys and audit logging, routes automated misuse flags to the customer’s own reviewers with no provider human review, and is opt-in and unpriced; co-designed with US G-SIB CISOs via ARC and quoted by Wells Fargo, FIS and Stripe; trade press reads it as a retention-policy reversal under regulated-customer pressure. For DORA registers and exit plans this moves log custody to the firm but leaves the model, the detection logic and the monitoring-window length with the provider; no EU/UK reference, standard or retention period is stated [inference] [S-2026-09-01-anthropic-enterprise-frontier-safeguards].
Detail
Three regimes, one operational posture
The three regimes converge on continuous, evidenced operational resilience:
- DORA (binding from January 2025) provides the EU’s ICT risk management and third-party oversight backbone, including the Critical ICT Third-Party Provider designation regime. As of the EBA’s 19 May 2026 consolidated amending Guidelines, the EBA’s own ICT and security risk-management Guidelines (EBA/GL/2019/04) have been narrowed to remove overlap with DORA — confirming DORA, not the legacy EBA Guidelines, as the primary binding ICT baseline, with the residual Guidelines covering areas not fully absorbed by DORA [S-2026-05-19-eba-ict-security-guidelines].
- BCBS d605 sets the international supervisory baseline. Its 12 principles broaden “outsourcing” into a wider third-party risk concept and explicitly align with DORA [S-2025-12-10-bcbs-d605].
- UK PS26/2 brings operational incident reporting and third-party reporting into a joint FCA / PRA / Bank of England regime, in force 18 March 2027 [S-2026-03-fca-ps26-2].
The common operating posture is continuous adherence to impact tolerances and retention of accountability even where activities are outsourced.
Implications for AI governance
GPAI providers, foundation-model hosts, and AI-vendor stacks are third parties in this framework. The EU AI Act’s deployer obligations align: deployers of third-party GPAI must evidence upstream-provider compliance with copyright policy and training-data summary requirements [S-2026-04-29-eu-ai-office-gpai]. Paul’s AI Assurance Pathway calls out the AI Contract Clause Library (DORA Art 30 + AI Act Arts 25, 53) and the AI Supply-Chain Concentration Heatmap as core practitioner artefacts [S-2026-05-06-paul-ai-data-pathway].
Authority retention principle
The single most consequential principle from BCBS d605 is that banks cannot outsource accountability. This shapes contract design, ongoing monitoring, audit rights, and exit planning — all of which need to be evidenced for AI third parties as much as traditional outsourcing.
Frontier AI cyber resilience — operational-resilience overlay
The FCA / BoE / HMT joint statement of 15 May 2026 operationalises the operational-resilience rule set for frontier-AI cyber risk specifically. Firms are expected to: (i) provide board-level understanding of frontier-AI risks; (ii) accelerate vulnerability triage and remediation at scale; (iii) manage frontier-AI cyber risks from third parties and supply chains including open-source software; (iv) reduce the attack surface via access management, network security and data protection and consider AI-enabled defences; and (v) align response and recovery to the October 2025 Bank/PRA/FCA effective-practices guidance [S-2026-05-15-fca-boe-treasury-frontier-ai-cyber]. The third-party / supply-chain pillar explicitly extends third-party risk to open-source AI components — a meaningful broadening of the BCBS d605 perimeter for practitioner purposes, even though the statement disclaims new expectations.
The EU side reached the same posture on 7 July 2026, when the ESAs (EBA, EIOPA, ESMA) issued a joint statement supporting an ESRB warning on the systemic cyber risks of frontier AI models [S-2026-07-07-esas-esrb-frontier-ai-cyber]. Three points matter for practitioners. First, the ESAs locate the risk in the existing framework rather than a new one: DORA and the AI Act “provide a solid foundation”, so the response is adaptation of cybersecurity capabilities and supervisory attention, not fresh rules — the same “reinforcement, not new expectations” framing as the UK statement. Second, they route it through DORA and the CTPP oversight regime: as Overseers of Critical ICT Third-Party Providers the ESAs are directly engaging cloud/model/security providers on mitigation, which ties the frontier-AI threat to the concentration and third-party-continuity thread this page already tracks. Third, the ESRB’s explicit inclusion of AI providers, software providers, security firms and open-source maintainers in the stakeholder set mirrors the UK statement’s extension of third-party risk to open-source AI components. Practitioner inference (not in source): the convergence of the UK (15 May) and EU (7 July) supervisory communities on the same frontier-AI cyber posture means a firm’s board-readiness and vulnerability-management evidence built for one regime should transfer to the other — the two are best treated as a single cross-border expectation, not two separate exercises [inference].
On 31 July 2026 the ESAs moved from warning to supervisory approach, publishing a joint Statement on frontier AI models (JC 2026 25) [S-2026-07-31-esas-frontier-ai-statement]. Where the 7 July statement supported the ESRB warning, this one outlines measures to help financial entities strengthen operational resilience against frontier-AI cyber risk — with explicit emphasis on prevention, detection and management — and sets the governance expectation directly: financial entities should have robust governance and risk-management frameworks to manage those cyber risks. It keeps the same institutional anchors this page tracks: it is framed within DORA, it updates on ongoing and planned DORA oversight of Critical ICT Third-Party Providers (CTPPs), and it takes account of the EC Action Plan on Cybersecurity and AI (7 July 2026), ESRB, ENISA and SSM work. Crucially the ESAs cast it as a basis for supervisory dialogue against existing expectations, not a new rule — so for practitioners it is best read as the EU supervisory community converting the frontier-AI cyber theme into an active engagement item that firms should expect to be examined on. Caveat: the enumerated “measures” and the specific CTPP oversight activities sit in the 408KB JC 2026 25 PDF, which was not retrieved this run — the read above is from the ESAs’ press-release summary only ⚠️.
The first DORA incident dataset — what the numbers say
The ESAs’ first annual DORA major-ICT-incident report (3 June 2026) is the first time the harmonised reporting mechanism has produced a sector-wide picture. Three findings matter for practitioners. First, scale and interconnectedness: 3,383 major incidents at 0.18 per entity, with roughly a third spilling across borders via shared infrastructures and services — evidence that concentration and shared-service dependency are now a measured, not theoretical, systemic feature [S-2026-06-03-esas-dora-incident-report]. Second, the driver mix is availability-led, not cyber-led: system failures and external events dominate and only ~10% of incidents are cybersecurity-related, which points supervisory and assurance attention toward continuity, change management, and especially third-party / outsourced-service oversight and provider-coordinated incident response [S-2026-06-03-esas-dora-incident-report]. Third, the AI overlay is forward-looking: the ESAs frame highly capable AI-driven tools as a reason to raise the cyber bar now, consistent with the prudential-side BCBS d611 AI/cyber monitoring statement [S-2026-06-03-esas-dora-incident-report][S-2026-06-02-bcbs-ict-range-of-practices]. Practitioner inference (not in source): the dominance of system-failure/external-event drivers over cyber suggests assurance scoping for AI-enabled important business services should weight availability and third-party continuity controls at least as heavily as cyber controls — the opposite of where attention often defaults. The report-body breakdown (incident nature, remedial actions, costs) was not retrieved this run and is held as an open question.
Vendor-market reflection — “continuous evidence by design”
The continuous-compliance posture this page tracks on the regulatory side (PS26/2’s shift away from one-time exercises; DORA’s data-integrity duties) is now being mirrored on the vendor side. Sifflet’s 28 May 2026 positioning piece is a useful data point on how data-quality/observability vendors are repackaging Solvency II Art 82, EIOPA, ACPR, DORA Art 9(2) and Solvency UK into a single “make the evidence continuous by design” pitch — continuous monitoring of data feeding regulated outputs, visible end-to-end lineage, end-to-end incident records (cause/impact/remediation/time-to-resolution), and the same controls extended over AI/ML model inputs [S-2026-05-28-sifflet-insurance-continuous-evidence]. Two practitioner cautions: (i) the regulatory references are the vendor’s characterisation, and the claim that supervisors expect continuous tooling-based evidence (vs. accept it as supporting evidence) is asserted, not sourced to a supervisor; (ii) the Malakoff Humanis reference is a named-but-self-interested adoption claim with no scope or dates. Practitioner inference (not in source): this is the same convergence already on this page seen from the buy-side — the assurance question is whether continuous observability output is structured as admissible, attributable evidence against specific articles, not merely as operational dashboards.
Certification enters the AI supply chain — ISO/IEC 42001 as a due-diligence artefact
The buy-side pressure this page tracks (BCBS d605 accountability retention, DORA third-party oversight, AI-vendor DDQs) is now producing a visible supply-side response: FS-sector AI vendors obtaining management-system certification to pre-answer customer due diligence. Outseer’s ISO/IEC 42001 certification (Intertek, 8 July 2026) is the first instance recorded in this vault of an FS third party marketing an AIMS certificate specifically as assurance for its regulated customers [S-2026-07-08-outseer-iso42001]. Practitioner inference (not in source): an ISO 42001 certificate is useful DDQ evidence of a functioning AI management system, but it certifies the management system within its stated scope — not the performance, fairness or resilience of the specific AI service consumed. A buy-side reviewer should (i) obtain the certificate scope statement, (ii) verify the certificate with the issuing body, and (iii) still require system-level evidence (validation, monitoring, incident records) for the service in question — the accountability-retention principle from d605 means certification cannot substitute for the firm’s own oversight [S-2026-07-08-outseer-iso42001][S-2025-12-10-bcbs-d605][inference].
The operational-risk management-framework layer (EBA RTS, Art 323(2) CRR3)
Where DORA, BCBS d605 and PS26/2 govern resilience and third-party risk, the EBA’s 26 August 2026 draft RTS codify the broader operational-risk management framework that sits beneath them, under the CRR3 single standardised approach (business-indicator-based) that replaces the former advanced measurement approaches [S-2026-08-26-eba-oprisk-rts-cp]. Three points matter for practitioners. First, it is a governance-architecture instrument: it specifies the three components (governance arrangements, management process, assessment system) and pins accountability across the management body, senior management and an independent operational risk management function — a prudential codification of a three-lines structure that is directly transferable to how an AI/model-risk operating model would be evidenced under a technology-neutral regime [inference]. Second, the ICT-risk carve-out to DORA confirms, once more, the EBA’s integrate-don’t-duplicate boundary already documented on this page — the operational-risk RTS and DORA are designed to interlock, not overlap. Third, it explicitly reaches the operational risk data and taxonomy layer, connecting to the same data-substrate and machine-readable-reporting discipline the EBA pursues in its integrated-reporting and BCBS 239 work [inference — S-2026-08-26-eba-oprisk-rts-cp]. Caveats: the RTS are draft (consultation to 31 December 2026), so no firm-level obligation crystallises yet, and the article-level detail sits in the 709KB consultation PDF not extracted this run ⚠️.
FMIs’ third-party reliance — the global-standard-setter view (CPMI-IOSCO, 8 Sep 2026)
The third-party-concentration thread this page tracks mainly through DORA/CTPP, BCBS d605 and the UK Critical Third Parties regime now has a matching signal from the payments-and-market-infrastructure standard setters. On 8 September 2026 CPMI-IOSCO published two linked consultative documents: a discussion paper on FMIs’ reliance on third-party service providers and a cyber-resilience toolkit for FMIs [S-2026-09-08-cpmi-iosco-fmi-third-party-cyber]. Two points matter for practitioners. First, the framing is the same accountability-and-concentration logic already on this page, applied to market infrastructures: reliance on third parties for critical services amplifies risk, and — because FMIs are “unique and highly interconnected” nodes — managing that reliance is treated as a systemic-stability question, not merely a firm-level one. Second, the documents deliberately couple third-party risk with cyber resilience: the toolkit is published alongside the discussion paper precisely because cyber risk at FMIs often arrives through third-party providers — the same third-party-originated-cyber overlay this page tracks for banks via the FCA/BoE/HMT and ESAs frontier-AI statements. Practitioner inference (not in source): although the documents are FMI-scoped and consultative, a bank or insurer whose important business services clear/settle through an FMI inherits that FMI’s third-party-concentration exposure, so this consultation is worth tracking as an upstream input to a firm’s own DORA CTPP mapping and exit-planning — but it sets no obligation on non-FMI firms, and the enumerated risks, questions and toolkit “practical considerations” sit in PDFs not extracted this run ⚠️ [inference — S-2026-09-08-cpmi-iosco-fmi-third-party-cyber].
Frontier AI cyber — the global-analysis synthesis (BIS FSI OP 28, 9 Sep 2026)
The BIS Financial Stability Institute’s Occasional Paper No 28 is the first vault-held source to pull the scattered frontier-AI-cyber statements (UK FCA/BoE/HMT 15 May; ESAs 7 July and 31 July) into a single cross-jurisdictional analysis, and it lands on the same conclusion this page has been building: the supervisory response is reinforcement of existing frameworks, not new AI-specific cyber regimes, because frontier AI changes the tempo of cyber risk, not its foundations [S-2026-09-09-bis-fsi-op28-frontier-ai-cyber]. Three elements are worth carrying forward for practitioners. First, the attack-side mechanics are made concrete: frontier models autonomously identify vulnerabilities, build exploits and chain multi-step operations, collapsing the discovery-to-exploitation window and automating exploit chaining — with the paper flagging unpatched software as the leading initial-access vector, which points assurance and remediation attention squarely at patch cadence and vulnerability-management SLAs. Second, it sharpens the third-party thread with a new label — “sovereign access” risk: dependence on common cloud, software and frontier-AI providers means a single provider’s disruption or policy decision can cascade across firms and jurisdictions, an angle (provider policy/geopolitical decisions, not just outages) that extends the DORA-CTPP concentration concern this page already tracks. Third, the policy emphasis is governance-led: authorities are stressing governance that supports timely decision-making, accelerated patching and stronger response/recovery — i.e. the same operational-resilience muscles, executed faster. Practitioner inference (not in source): because the FSI reaches the same posture as the UK and EU statements, a firm’s frontier-AI-cyber evidence set (board understanding, patch-window metrics, third-party/open-source mapping, response-and-recovery drills) should serve all three, and the “sovereign access” framing argues for adding provider policy/geopolitical decision scenarios to CTPP exit-planning, not just outage scenarios [inference]. Caveats: this is an FSI Occasional Paper (authors’ views, medium authority), not a standard, and the 28-page PDF — with any jurisdiction-by-jurisdiction mapping, quantification and named mitigations — was not extracted this run ⚠️.
Practical Applications
- Build an AI Vendor DDQ aligned to BCBS d605 + DORA + AI Act deployer obligations [S-2026-05-06-paul-ai-data-pathway]. When a vendor offers an ISO/IEC 42001 certificate as evidence, request the scope statement, verify it with the certification body, and treat it as management-system evidence complementing — not replacing — system-level assurance [S-2026-07-08-outseer-iso42001][inference].
- Pressure-test “continuous evidence” vendor claims against the actual articles. When evaluating data-quality/observability tooling (e.g. Sifflet), require the vendor to map each control to the specific obligation it evidences (Solvency II Art 82, DORA Art 9(2), Solvency UK) and to show the output as attributable, time-stamped audit evidence — not just monitoring dashboards — before relying on it for regulatory readiness [S-2026-05-28-sifflet-insurance-continuous-evidence].
- Maintain a Foundation-Model Exit Plan. Single-vendor concentration is a material concentration risk; the AI Supply-Chain Concentration Heatmap and Foundation-Model Exit Plan are the operating artefacts [S-2026-05-06-paul-ai-data-pathway].
- Map AI-system incidents to PS26/2 reporting, even where currently not explicitly in scope — practitioner consensus is that AI incidents will be in supervisory focus as PS26/2 beds in [S-2026-03-fca-ps26-2].
- Refresh third-party / supply-chain inventories to cover AI-enabled and open-source components in line with the FCA / BoE / HMT joint frontier-AI statement [S-2026-05-15-fca-boe-treasury-frontier-ai-cyber].
- Brief boards on frontier-AI cyber risk — produce board-pack content that evidences sufficient understanding of frontier-AI cyber risks, investment and resourcing posture, and insurance considerations [S-2026-05-15-fca-boe-treasury-frontier-ai-cyber].
- Use the ESAs DORA incident statistics to benchmark and prioritise. The 3,383-incident / one-third-cross-border / system-failure-led picture is a citable evidence base for sizing a firm’s incident-management and third-party-continuity controls; weight assurance scoping toward availability and outsourced-service oversight, not cyber alone, in line with the reported driver mix [S-2026-06-03-esas-dora-incident-report].
Related Concepts
- relates-to → DORA — binding EU regulation in this domain.
- relates-to → BCBS AI Governance Framework — connects through BCBS d605.
- relates-to → EU AI Act — deployer obligations on GPAI providers.
- relates-to → FCA approach to AI — Critical Third Parties regime; PS26/2.
- relates-to → Three Lines of Defence for AI — third-party oversight is a 2LoD priority.
- relates-to → Alation — first security incident recorded against a tracked governance vendor (20 Aug 2026); concentrated-metadata ICT third-party event [S-2026-09-11-weekly-vendor-synthesis].
- relates-to → Collibra — retirement of Console-based audit-log retrieval and Dataplex ingestion (Aug–Sep 2026) as an evidence-path lifecycle event [S-2026-09-11-weekly-vendor-synthesis].
- relates-to → Vendor Lifecycle Events as Evidence-Continuity Risk — the assurance design pattern under which the Collibra instance is classed [S-2026-09-11-weekly-vendor-synthesis].
- relates-to → Databricks — named vendor-market instance of AI-stack/cloud-platform concentration (funding + deepened Microsoft/Azure coupling, Aug 2026) [S-2026-08-21-weekly-vendor-synthesis].
Open Questions
- Scope of DORA Article 30 contractual clauses required for AI vendor contracts.
- How PS26/2 incident-and-third-party reporting (18 March 2027) will interact with DORA’s parallel obligations for cross-border firms.
- Whether AI-system incidents will be explicitly in scope of PS26/2 reporting.
- What the ESAs DORA report-body breakdown (incident nature, remedial actions, costs) shows beyond the headline figures — not retrieved this run [S-2026-06-03-esas-dora-incident-report].
- How the one-third cross-border-impact finding will feed the designation and oversight of Critical ICT Third-Party Providers (CTPPs) under DORA [S-2026-06-03-esas-dora-incident-report].
- What concrete supervisory expectations the ESAs and national competent authorities will “clarify and communicate consistently” for frontier-AI cyber risk following the 7 July 2026 ESAs/ESRB warning, and whether those expectations will materially differ from — or simply mirror — the UK FCA/BoE/HMT frontier-AI cyber statement, i.e. whether firms can rely on a single cross-border evidence set [S-2026-07-07-esas-esrb-frontier-ai-cyber].
- Whether supervisors (ACPR / PRA / EIOPA) actually treat continuous data-observability output as Solvency II Art 82 / DORA Art 9(2) evidence or only as supporting controls — Sifflet asserts supervisory expectation but cites no supervisory confirmation [S-2026-05-28-sifflet-insurance-continuous-evidence].
- Is ISO/IEC 42001 certification becoming a de facto FS procurement requirement for AI-driven third parties, or an early-mover differentiator — and how much weight do FS buy-side reviewers (and supervisors) actually give an AIMS certificate versus system-level evidence for the specific AI service consumed? Outseer’s certificate scope is unstated and unverified this run [S-2026-07-08-outseer-iso42001].
- What specific challenges, risk categories and consultation questions does the CPMI-IOSCO FMI third-party-reliance discussion paper set out, and how far do they mirror (or diverge from) the DORA CTPP concerns for banks/insurers — and does the FMI-scoped framing carry read-across weight for non-FMI third-party governance? Detail sits in the unextracted 22-page PDF and companion toolkit [S-2026-09-08-cpmi-iosco-fmi-third-party-cyber].
- Would a deepened Databricks-Azure coupling actually change a firm’s DORA Critical Third-Party designation or exit-plan risk rating in practice, or does it remain a theoretical concentration concern until a supervisor or firm assessment says otherwise? Not addressed by any source held [S-2026-08-21-weekly-vendor-synthesis].
Sources
- [S-2025-12-10-bcbs-d605] → S-2025-12-10-bcbs-d605
- [S-2026-03-fca-ps26-2] → S-2026-03-fca-ps26-2
- [S-2026-04-29-eu-ai-office-gpai] → S-2026-04-29-eu-ai-office-gpai
- [S-2026-05-06-paul-ai-data-pathway] → S-2026-05-06-paul-ai-data-pathway
- [S-2026-05-20-bcbs-ict-press-release] → S-2026-05-20-bcbs-ict-press-release
- [S-2026-06-02-bcbs-ict-range-of-practices] → S-2026-06-02-bcbs-ict-range-of-practices
- [S-2026-05-15-fca-boe-treasury-frontier-ai-cyber] → S-2026-05-15-fca-boe-treasury-frontier-ai-cyber
- [S-2026-05-19-eba-ict-security-guidelines] → S-2026-05-19-eba-ict-security-guidelines
- [S-2026-06-03-esas-dora-incident-report] → S-2026-06-03-esas-dora-incident-report
- [S-2026-05-28-sifflet-insurance-continuous-evidence] → S-2026-05-28-sifflet-insurance-continuous-evidence
- [S-2026-06-24-fca-rathi-ai-speech] → S-2026-06-24-fca-rathi-ai-speech
- [S-2026-06-18-eba-rar-spring-2026] → S-2026-06-18-eba-rar-spring-2026
- [S-2026-07-08-outseer-iso42001] → S-2026-07-08-outseer-iso42001
- [S-2026-07-07-esas-esrb-frontier-ai-cyber] → S-2026-07-07-esas-esrb-frontier-ai-cyber — ESAs joint statement (7 July 2026) supporting the ESRB warning on systemic cyber risks from frontier AI models; EU cross-sectoral reinforcement of the frontier-AI cyber overlay, anchored in DORA and CTPP oversight.
- [S-2026-07-31-esas-frontier-ai-statement] → S-2026-07-31-esas-frontier-ai-statement — ESAs joint Statement on frontier AI models (JC 2026 25, 31 July 2026); calls for cross-sectoral, risk-based, consistent supervision, sets a governance/risk-management-framework expectation on financial entities, and updates on DORA CTPP oversight — the ESAs’ move from warning to supervisory approach.
- [S-2026-09-11-weekly-vendor-synthesis] → S-2026-09-11-weekly-vendor-synthesis — Weekly Vendor Synthesis (11 September 2026); Alation incident, Collibra log-path retirement and Ataccama distributor layer as DG/DM register-of-information items (own synthesis; underlying facts vendor/trade-press asserted).
- [S-2026-08-21-weekly-vendor-synthesis] → S-2026-08-21-weekly-vendor-synthesis — Weekly Vendor Synthesis (21 August 2026); names Databricks’ funding round + deepened Microsoft/Azure partnership as a concrete AI-stack concentration instance for this page’s DORA Critical Third-Party thread.
- [S-2026-08-26-eba-oprisk-rts-cp] → S-2026-08-26-eba-oprisk-rts-cp — EBA consultation on draft RTS on the operational risk management framework (Art 323(2) CRR3, 26 August 2026); the operational-risk management-framework layer beneath DORA/d605/PS26/2, with ICT risk carved out to DORA and consistency with the EBA internal-governance Guidelines.
- [S-2026-09-08-cpmi-iosco-fmi-third-party-cyber] → S-2026-09-08-cpmi-iosco-fmi-third-party-cyber — CPMI-IOSCO consultation (8 September 2026): discussion paper on FMIs’ reliance on third-party service providers + cyber-resilience toolkit for FMIs; global standard-setter reinforcement of the third-party-concentration and third-party-originated-cyber threads, FMI-scoped and consultative (comments due 1 December 2026).
- [S-2026-09-09-bis-fsi-op28-frontier-ai-cyber] → S-2026-09-09-bis-fsi-op28-frontier-ai-cyber — BIS FSI Occasional Paper No 28, When machines attack: frontier AI cyber threats and policy responses in the financial sector (9 September 2026; Crisanto, Currat, Yong); cross-jurisdictional analysis concluding authorities are reinforcing existing operational-resilience/cyber frameworks rather than new AI-specific regimes, adding the compressed-remediation-window mechanics and the “sovereign access” third-party-concentration angle; medium authority (authors’ views, not an official BCBS/BIS standard)
- [S-2026-09-01-anthropic-enterprise-frontier-safeguards] → S-2026-09-01-anthropic-enterprise-frontier-safeguards — Anthropic announcement of Enterprise Frontier Safeguards (1 Sep 2026) and Help Net Security report (2 Sep 2026), fetched in full; customer-held monitoring data and keys, automated-only misuse review, US G-SIB design cohort; medium authority (vendor primary + trade press)..
- [S-2026-09-16-eba-dora-incident-reporting-operational-instructions] → S-2026-09-16-eba-dora-incident-reporting-operational-instructions — ESAs “DORA Incident Reporting – Operational Instructions” (16 September 2026); best-efforts, regularly-updated staff guidance on field-level major-ICT-incident reporting conventions (data quality + cross-jurisdiction consistency); PDF fetched in full; medium authority (staff guidance, explicitly not legal interpretation or official ESA stance).