The EBA seeks feedback on the 4.4 draft technical package of its reporting and disclosure framework

Source: European Banking Authority

The European Banking Authority (EBA) today published a draft technical package for version 4.4 of its reporting and disclosure framework, covering IFRS 18 reporting, Pillar 3 ESG disclosures and other technical amendments.

This early release is intended to support reporting entities in preparing for upcoming changes ahead of the final publication, scheduled for September 2026. The EBA invites stakeholders to provide feedback on both the draft technical package and the accompanying glossary.

The draft technical package for release 4.4, includes validation rules, the Data Point Model (DPM) and XBRL taxonomies, and introduces the following new reporting requirements:

  • Amendments to the ITS on Pillar 3 disclosures on ESG risks, equity and shadow banking exposures published here. The first reference date is 31/12/2026 (31/12/2027 for SNCIs);
  • New IFRS 18-aligned templates in Supervisory Financial Reporting (FINREP) framework. These templates should be read in conjunction with the EBA Opinion and related Annexes published here. The first reference date is 31/03/2027;
  • The integration of FRTB-related disclosures templates into the DPM. The first reference date is 31/03/2027;
  • Technical amendments to DPM and taxonomy related to Resolution Planning, MREL decisions and Pillar 3 disclosure templates. The first reference date is 31/12/2026;
  • DPM and taxonomy to Anti Money Laundering Authority (AMLA)- Eligibility templates. The first reference date is 31/12/2026.

Background, consultation process and next steps

The final technical package for reporting framework 4.4 will be published in September 2026 and will reflect necessary amendments following stakeholder review. This draft publication aims to provide additional implementation time for institutions and to enable the EBA to gather early feedback ahead of finalisation. This version relates to phase 1 of the 4.4 release, as indicated on the EBA Reporting frameworks webpage. The second phase of 4.4 (4.4.1) will include the rest of the topics included in the consultation paper on major simplification of supervisory reporting, published on 10 April.

This release includes the technical amendments and corrections to DPM for resolution planning and Pillar 3 disclosure templates, as identified in the list of DPM known issues published by the EBA on 9 April.

Finally, this draft framework reflects the impact of the third FRTB Delegated Act on disclosures. Further details will be communicated by the EBA soon. Stakeholders are invited to submit comments and suggestions on the draft technical package 4.4 and the new glossary by 24 August 2026, using the EBA feedback form.

In June 2024, the EBA published its plan for the implementation of DPM 2.0. The draft technical package for version 4.4 published today, continues the transition to DPM 2.0 and to the new glossary. This draft technical package includes a new version of the conversion file between DPM 1.0 and DPM 2.0 glossary.

Disclaimer: This draft technical package is provided for information purposes only. The final package will include additional elements not yet covered, notably the validation rules on anti-money laundering (AML)-eligibility and the revised version of the AMLA risk assessment 2027 data collection exercise templates.

​The EBA consults on rules to further improve depositor protection under the revised Deposit Guarantee Schemes Directive

Source: European Banking Authority

The European Banking Authority (EBA) today launched four public consultations on proposed rules to further strengthen depositor protection, preserve financial stability, and further harmonise depositor protection standards across the EU under the revised Deposit Guarantee Schemes Directive (DGSD3). The EBA seeks stakeholders’ feedback on Implementing Technical Standards (ITS) on depositor information, ITS on information exchange between credit institutions, Deposit Guarantee Schemes (DGSs) and other relevant authorities, Regulatory Technical Standards (RTS) on the treatment of client funds protection standards across the EU, and Guidelines (GL) on how DGSs should invest funds collected from the industry. The four consultations run until 23 October 2026. 

The draft ITS on depositor information set out harmonised content and formats for depositor information sheets provided at account opening, and on a regular basis. They also establish requirements for communications to depositors in specific situations, such as bank mergers of banks, or failures. The proposals aim to improve depositors’ awareness of coverage while allowing flexibility in how institutions communicate, without increasing administrative burden.

The draft ITS on information exchange introduce standardised procedures, templates and minimum requirements for information exchange in bank failure scenarios. They also:

  • enhance reporting from DGSs to the EBA on covered deposits and available financial means;
  • define information to be reported by authorities on bank failures;
  • improve transparency on the use of DGS funds.

The framework builds on existing best practices to ensure that information is accurate, timely and proportionate.

The draft RTS on client funds establish rules to ensure DGSs receive the data needed to identify and reimburse clients whose funds are held in intermediary accounts. They clarify:

  • when reimbursement should be made directly to clients or via the account holder; and
  • how to prevent duplicate payouts.

These measures aim to ensure consistent protection, operational efficiency and legal certainty across the EU.

The draft Guidelines on investment of available financial means set out how DGSs should invest their funds to ensure diversification, low risk and sufficient liquidity.

The proposals support DGSs’ ability to rapidly mobilise funds not only for depositor reimbursement, but also for resolution and other interventions within their mandate, as strengthened under DGSD3.

Consultation process 

Comments on the four consultations can be sent to the EBA by clicking on the “send your comments” button on the four respective web pages. Please note that the deadline for the submission of comments to any of these consultation papers is 23 October 2026. All contributions received will be published after the consultation closes, unless requested by the respondent otherwise.  

A public hearing on all four regulatory products will take place on 24 September from 10:00 to 13:00 CEST. The deadline for registration is the 21 September 2026, 12:00 CEST. 

Background and legal basis

The revised Deposit Guarantee Schemes Directive (DGSD3), adopted in 2026, strengthens the EU framework for managing bank crises by enhancing depositor protection and further harmonising rules across Member States. It incorporates over 100 operational improvements, many based on EBA recommendations issued between 2019 and 2021.The draft regulatory products published today support consistent and effective implementation of the revised framework across the Union.

Under DGSD3, the EBA is mandated to develop 12 Technical Standards and Guidelines, the first four of which have been published today for consultation.

​Joint Board of Appeal dismisses appeal against the EBA

Source: European Banking Authority

​The Joint Board of Appeal of the European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) has issued a decision stating that an appeal brought by an individual against the European Banking Authority (EBA) is inadmissible.

​The appeal concerned a response by the EBA to a complaint regarding the closure of a bank account by a credit institution and the handling of the matter by the Finnish National Competent Authority (FIN-FSA). The appellant had requested that the EBA investigate a possible breach of Union law by FIN-FSA.

​Following its assessment, the EBA decided against initiating an investigation. The appellant subsequently challenged that decision before the Board of Appeal.

​The Board of Appeal concluded that, under established EU case law, any decision to initiate an investigation is at the EBA’s discretion. The Board added that a decision not to open such an investigation is not subject to review by the Board of Appeal.

​Furthermore, the Board examined whether the circumstances of the case differed from previous decisions and relevant EU case law in a way that could justify a different conclusion. It found no such distinguishing circumstances.

​​Background

The Board of Appeal is a joint body of the European Supervisory Authorities composed of independent members. It reviews appeals against certain decisions taken by the European Banking Authority (EBA), the European Securities and Markets Authority (ESMA) and the European Insurance and Occupational Pensions Authority (EIOPA), in accordance with the relevant ESA Regulations. 

The ESAs support ESRB warning on systemic cyber risks from frontier AI models

Source: European Banking Authority

The European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) welcome and support today’s warning from European Systemic Risk Board (ESRB) on the systemic cyber risks posed by frontier AI models.

Recent advances have significantly enhanced the ability of frontier AI models to identify and exploit high-severity vulnerabilities in IT systems within very short timeframes. While the EU’s regulatory framework – including DORA and the AI Act – provides a solid foundation for managing cyber and AI-related risks, the speed and scale of these tools raise concerns that AI-enabled cyber-attacks could undermine the operational resilience of financial entities.

Since the release of the first frontier AI models, the ESAs have raised awareness about the ICT risks posed by the widespread adoption of these models and engaged with EU competent authorities to ensure that financial entities take appropriate mitigation measures. In their first annual report on major ICT-related incidents under DORA, the ESAs encouraged financial entities to strengthen cybersecurity measures to maintain their resilience amid the rapid evolution of highly capable AI-driven tools.

Against this backdrop, the ESAs concur with the ESRB warning and urge financial entities to make appropriate arrangements to adapt their cybersecurity capabilities. They also invite competent authorities to reflect these developments in their supervisory activities. Finally, the ESAs note the ESRB’s call on the European Union to scale up its capacity, expertise and strategic autonomy in this critical area, which requires that all parties are involved, including AI providers, software providers, security firms, open-source maintainers, financial institutions, and authorities at both national and Union level.

The ESAs are working closely with the EU supervisory community to ensure that financial entities across the EU proactively identify and mitigate these risks in line with the requirements of the Digital Operational Resilience Act (DORA), which establishes a harmonised framework for mitigating ICT risks in the financial sector.

In their capacity as Overseers of Critical ICT Third-Party Providers, the ESAs are also engaging with these providers on the measures they are taking to adapt to the situation, in order to manage risks and ensure the continuity of services provided to the EU financial sector.

Background and next steps

The warning by the ESRB highlights how frontier AI models are transforming the cybersecurity landscape by enabling threat actors to increase the speed, scale, and sophistication of cyber-attacks in the short to medium term. The ESRB urged all EU stakeholders, including financial institutions, to enhance their cybersecurity capacities and encouraged relevant authorities to reflect these risks in their supervisory and oversight work.

The ESAs will continue to closely monitor the use and development of highly cyber-capable frontier AI models and assess their potential impact on the financial sector. To promote a consistent, risk-based and forward-looking supervisory approach in this area, the ESAs are also working with national supervisors to clarify supervisory expectations, and will communicate them consistently to financial entities to ensure compliance with the existing regulatory framework.

​The EBA publishes 2025 loss data for immovable property markets under Article 430a of the Capital Requirements Regulation

Source: European Banking Authority

​The European Banking Authority (EBA) today published its annual dataset on losses and exposures for residential and commercial immovable property across the European Union and European Economic Area for 2025, in line with Article 430a(3) of the Capital Requirements Regulation (CRR). The publication provides a centralised and harmonised source of data on losses and exposures relating to residential and commercial immovable property across the EU/EEA. The data are drawn from supervisory reporting submitted by institutions and are presented by national immovable property market.

​ ​These data are relevant for the application of the CRR “hard test” mechanism, under which certain preferential treatments for exposures secured by immovable property may be applied where the relevant loss-rate thresholds are met. In particular, the published data support the application of the following CRR provisions:

  • ​​Article 125(2), which allows institutions, where the relevant conditions are met, to apply the loan-splitting approach to income-producing residential real estate exposures;

  • ​Article 126(2), which provides for an equivalent treatment for income-producing commercial real estate exposures;

  • Articles 199(3) and 199(4), which allow institutions using the Internal Ratings-Based approach to recognise residential or commercial immovable property as eligible collateral, including where repayment materially depends on the cash flows generated by the property, provided that the applicable legal conditions are met.

​​The publication is intended to improve transparency, promote simplification and facilitate the consistent application of the above mentioned CRR provisions. It does not amend the legal conditions set out in the CRR, nor does it constitute a separate supervisory decision on the eligibility of individual exposures. Institutions remain responsible for assessing whether the relevant CRR conditions are met when applying the corresponding treatments. 

​Legal basis and background

​​Article 430a of the CRR requires the collection and publication of aggregated data on exposures and losses related to lending secured by residential and commercial immovable property. These data are used for the application of the loss-rate thresholds embedded in the CRR framework for immovable property exposures.

 ​Articles 125 and 126 of the CRR set out the Standardised Approach treatment for exposures secured by residential and commercial immovable property, including the conditions under which income-producing real estate exposures may benefit from the loan-splitting treatment. Article 199 of the CRR sets out the conditions under which immovable property collateral may be recognised as eligible collateral under the IRB Approach, in particular under the Foundation IRB Approach for the recognition of real estate collateral securing IPRE exposures, where the relevant derogations in Article 199(3) and (4) of the CRR apply.

​ ​The data published today cover the reference year 2025 and are presented at the level of national immovable property markets.

​In relation to the following Member States, the relevant reference for the application of the above-mentioned derogations remains the publication of loss data made by the respective competent authorities on their websites:

Targeted EBA peer review finds high compliance on Pillar 3 disclosures but calls for greater consistency

Source: European Banking Authority

The European Banking Authority (EBA) today published a Discussion Paper on certain key performance indicators (KPIs) and other aspects of the Disclosures Delegated Act, under Article 8 of the Taxonomy Regulation. The aim is to consult the public on potential measures to simplify and enhance the usability of information disclosed by credit institutions and investment firms. The consultation is open until 12 August 2026.

In March 2026, the EBA together with other European Supervisory Authorities (ESAs), received a targeted Call for Technical Advice[1] from the European Commission on Taxonomy disclosures. The ESAs’ input will support the European Commission’s forthcoming review of the Taxonomy Disclosures Delegated Act and contribute to the broader simplification efforts initiated under the Omnibus Delegated Act.

The Discussion Paper represents the first step in the EBA’s response to the European Commission’s Call for Advice, and outlines preliminary assessment and proposals on:

  1. simplifying the Fees and Commission’s KPI, Trading Book KPI and Off-balance sheet exposures KPI for credit institutions;
  2. simplifying the ‘other services’ KPI for investment firms;
  3. aligning grandfathering provisions for financial instruments under Taxonomy disclosures with those set out in the EU Green Bond Regulation;
  4. clarifying and improving group-level disclosures, including disclosures by parent undertakings and other undertakings within the group; and
  5. the treatment of operational expenditure KPI disclosed by non-financial undertakings in the calculation of financial undertakings’ KPI.

In this Discussion Paper the EBA addressed the specific issues within its remit and coordinated with the European Insurance and Occupational Pensions Authority (EIOPA) and the European Securities and Markets Authority (ESMA) on issues of cross-cutting nature affecting a wider group of undertakings, as specified in the European Commission’s request.

The EIOPA and ESMA consultations conducted in parallel on the same subject, within their respective areas of competence. The EIOPA consultation is accessible here, while the ESMA’s consultation can be found here.

The ESAs will continue to cooperate closely in developing their advice and submit their responses to the European Commission in October 2026.

Consultation process

Comments to this Discussion Paper can be sent to the EBA by clicking on the “send your comments” button on the discussion page. Please note that the deadline for the submission of comments is 12 August 2026. All contributions received will be published following the end of the consultation, unless requested otherwise.

A public hearing will take place virtually in the form of a webinar on Thursday 16 July from 13:30 to 15:00 CEST. Please register here  by 13 July 16:00 CEST.

All comments received will be published following the end of the public consultation, unless requested otherwise.


[1] Reference to the CfA (Ref. Ares(2026)2366154) on the EBA website (link).

The EBA launches consultation on key performance indicators of Taxonomy disclosures

Source: European Banking Authority

The European Banking Authority (EBA) today published a Discussion Paper on certain key performance indicators (KPIs) and other aspects of the Disclosures Delegated Act, under Article 8 of the Taxonomy Regulation. The aim is to consult the public on potential measures to simplify and enhance the usability of information disclosed by credit institutions and investment firms. The consultation is open until 12 August 2026.

In March 2026, the EBA together with other European Supervisory Authorities (ESAs), received a targeted Call for Technical Advice[1] from the European Commission on Taxonomy disclosures. The ESAs’ input will support the European Commission’s forthcoming review of the Taxonomy Disclosures Delegated Act and contribute to the broader simplification efforts initiated under the Omnibus Delegated Act.

The Discussion Paper represents the first step in the EBA’s response to the European Commission’s Call for Advice, and outlines preliminary assessment and proposals on:

(i)   simplifying the Fees and Commission’s KPI, Trading Book KPI and Off-balance sheet exposures KPI for credit institutions;

(ii)  simplifying the ‘other services’ KPI for investment firms;

(iii) aligning grandfathering provisions for financial instruments under Taxonomy disclosures with those set out in the EU Green Bond Regulation;

(iv) clarifying and improving group-level disclosures, including disclosures by parent undertakings and other undertakings within the group; and

(v)  the treatment of operational expenditure KPI disclosed by non-financial undertakings in the calculation of financial undertakings’ KPI.

In this Discussion Paper the EBA addressed the specific issues within its remit and coordinated with the European Insurance and Occupational Pensions Authority (EIOPA) and the European Securities and Markets Authority (ESMA) on issues of cross-cutting nature affecting a wider group of undertakings, as specified in the European Commission’s request.

The EIOPA and ESMA consultations conducted in parallel on the same subject, within their respective areas of competence. The EIOPA consultation is accessible here, while the ESMA’s consultation can be found here.

The ESAs will continue to cooperate closely in developing their advice and submit their responses to the European Commission in October 2026.

Consultation process

Comments to this Discussion Paper can be sent to the EBA by clicking on the “send your comments” button on the discussion page. Please note that the deadline for the submission of comments is 12 August 2026. All contributions received will be published following the end of the consultation, unless requested otherwise.

A public hearing will take place virtually in the form of a webinar on Thursday 16 July from 13:30 to 15:00 CEST. Please register here  by 13 July 16:00 CEST.

All comments received will be published following the end of the public consultation, unless requested otherwise.


[1] Reference to the CfA (Ref. Ares(2026)2366154) on the EBA website (link).

​The European Banking Authority consults on a draft methodology for setting fines under the Markets in Crypto-Assets Regulation (MiCA)

Source: European Banking Authority

​The European Banking Authority (EBA) published today a Consultation Paper with a draft methodology for setting fines in its role as supervisor under MiCA. The objective is to ensure that fines imposed on issuers of significant crypto-assets are consistent, proportionate and transparent, and effectively support compliance with the regulatory framework.

​​Under MiCA, where an asset-referenced token (ART), or an e-money token (EMT) issued by an electronic money institution, is classified as significant by the EBA, the EBA is responsible for supervising the issuer. 

​The Consultation sets out the EBA’s proposed approach to calculating fines where an issuer of significant tokens, or a member of its management body, has negligently or intentionally committed an infringement.

​This methodology aims at providing a clear and a consistent approach for enforcement, enhancing transparency and accountability in supervisory decisions and helping stakeholders understand how fines are determined in individual cases.  

​​Consultation process

Comments to the consultation paper can be sent by clicking on the “send your comments” button on the EBA’s consultation page. The deadline for the submission of comments is 28 September 2026.

The EBA will hold a virtual public hearing on 16 of July from 14.30 CEST. The EBA invites interested stakeholders to register using this link by 13 of July, 16.00 (CEST). The dial-in details will be communicated to those who have registered for the meeting.

All comments received will be published following the end of the public consultation, unless requested otherwise.

Legal basis

In accordance with Article 134(1) of MiCA where the EBA in carrying out its supervisory responsibilities of issuers of significant tokens, identifies clear and demonstrable grounds to suspect that an infringement has been, or may be, committed, it may adopt one or more of the supervisory measures listed in Article 130(1) and (2) of MiCA. These measures include the imposition of fines and periodic penalty payments.   

​The EBA updates validation rules for supervisory reporting ​

Source: European Banking Authority

The European Banking Authority (EBA) today published an updated list of validation rules defined in its reporting frameworks, as part of its regular quarterly review process. The revised package identifies rules that have (i) been deactivated due to inaccuracies or IT-related issues, (ii) been reactivated, or (iii) undergone a change in severity status. 

Competent Authorities across the EU are reminded that data submitted in accordance with the ITS and Guidelines should not be formally validated against rules that have been deactivated.

In addition, the EBA has released a small validation rules package, which includes: 

These components are required from release 4.0 onwards for each validation rules update exercise and ensure amendments are consistently reflected in both the taxonomy and the DPM. 

With the introduction of DPM 2.0 from release 4.0 onwards, validation rules are now embedded directly into both the taxonomy and DPM. This integration enhances consistency in implementation by reporting institutions, improves traceability of changes, and contributes to a more efficient and harmonised supervisory reporting process. 

EBA updates Pillar 3 disclosure requirements on ESG risks, equity and shadow banking exposures, as part of simplification effort

Source: European Banking Authority

The European Banking Authority (EBA) has published today its final draft Implementing Technical Standards (ITS) amending the Pillar 3 disclosure framework on environmental, social and governance (ESG) risks, and introducing disclosure requirements on equity and shadow banking exposures. The package finalises the implementation of the disclosure requirements introduced by the Capital Requirements Regulation (CRR 3). Developed in line with the EU’s simplification agenda and the Omnibus package, the ITS streamline existing requirements, and enhance usability and consistency. The ITS are aligned with the European Sustainability Reporting Standards (ESRS) and with the EBA draft ITS on ESG reporting requirements, which are currently under consultation. They should, therefore, be read in conjunction with this Consultation paper to ensure a comprehensive understanding of the overall ESG framework and to support informed feedback.

Link between ESG supervisory reporting and Pillar 3 disclosure framework

The final draft ITS on Pillar 3 disclosures on ESG risks are closely linked to the ESG supervisory reporting framework set out in the related consultation paper.

To fully understand the proposed scope and requirements, stakeholders are encouraged to consider both documents together.

Interoperability with other sustainability reporting frameworks

The EBA has closely followed the simplification of the European Sustainability Reporting Standards (ESRS) under the Corporate Sustainability Reporting Directive (CSRD), and these ITS are aligned accordingly. Interoperability between the two frameworks enables institutions to use—and where appropriate cross-refer to—information disclosed under Pillar 3 in their ESRS public reporting, thereby reducing duplication.

The EBA stands ready to cooperate closely with the European Commission to further strengthen alignment with ESRS, as needed, while ensuring a smooth adoption process.

Proportionality and simplification of ESG disclosure requirements

The amending ITS enhance the existing disclosure requirements on ESG-related risks applicable to large institutions and, for the first time, extend ESG disclosure requirements to all institutions in a proportionate manner, as required by CRR 3.

For large institutions, the ITS build on and simplifies the requirements already in place. The ITS introduce a “core plus supplement” approach, calibrated to institutions’ size and complexity. As a result, large institutions will disclose 37% less datapoints than now and the taxonomy related disclosures are stopped. Other (medium) institutions will disclose 17% less, and Small and Non-Complex Institutions (SNCI) 84% less datapoints than large institutions, respectively. Furthermore, the EBA will centrally pre-fill and disclose ESG information in the Pillar 3 Data Hub on behalf of SNCIs based on supervisory reporting.

The ITS also incorporate the recommendations of the Joint Bank Reporting Committee (JBRC) on semantic integration, ensuring integrated reporting.

Next steps

The EBA will submit the final draft ITS to the European Commission for adoption. It will also develop a Data Point Model (DPM) and XBRL taxonomy required for the submission of the information to the Pillar 3 Data Hub. In addition, the EBA will publish an updated mapping tool in 2026, linking Pillar 3 disclosures with supervisory reporting.

The ITS are expected to apply with a reference date of 31 December 2026, and 31 December 2027 for SNCIs – this notwithstanding any further adjustment needed as a result of the finalisation of Commission’s work.

Legal basis and background

Today’s publication contributes to the EBA’s communication campaign “Simplifying to strengthen: building a more efficient EU prudential and supervisory framework”. This initiative is part of the EBA’s broader priority to simplify and enhance the efficiency of the regulatory and supervisory framework, in line with the work of its Task Force on Efficiency (TFE) and the EBA’s Report on the efficiency of the regulatory and supervisory framework, published on 1 October 2025. It delivers, in particular, on Recommendations 4 (Integrated reporting), and 5 (Review and reduce existing reporting requirements) aimed at reducing costs and improving proportionality.

Regulation (EU) 2024/1623 (CRR3) amending Regulation (EU) No 575/2013 implements the Basel III post-crisis reforms in the EU, taking into account the specific features of the EU banking sector. The deliverable forms part of the ‘EBA Roadmap on strengthening the prudential framework’, published in December 2023. Following the adoption of Commission Implementing Regulation (EU) 2024/3172 as step 1 of the roadmap, these ITS represent step 2, amending the Pillar 3 disclosure framework to reflect additional CRR3 changes, including:

  • disclosures on equity exposures (Article 438(e) CRR3);
  • disclosures on aggregate exposures to shadow banking entities (Article 449b CRR3); and
  • the extension of ESG risk disclosure requirements to all institutions (Article 449a CRR3).

The final report repeals the Guidelines on non-performing and forborne exposures, reflecting the incorporation of these disclosures into the CRR framework, notably through Articles 433b and 433c of CRR3.