The EBA publishes its 2025 Annual Report outlining key achievements

Source: European Banking Authority

The European Banking Authority (EBA) today published its 2025 Annual Report, outlining its main achievements and activities in delivering on its mandates under its Work Programme. In 2025, the EBA focused on streamlining and improving the efficiency of the EU regulatory framework while expanding its supervisory role, particularly under the Digital Operational Resilience Act (DORA) and Markets in Crypto-Assets Regulation (MiCA). 

Notable achievements and activities featured in the Report include:

Strengthening a simpler and more efficient Single Rulebook

The EBA made substantial progress in enhancing both the simplicity and efficiency of the EU Single Rulebook. This included delivering key elements of the Basel III reforms, while refining and clarifying requirements across core risk areas such as credit risk, market risk and operational risk.

The Authority also contributed to making the broader regulatory framework more effective and proportionate. This included targeted adjustments to environmental, social and governance (ESG) disclosure timelines and continued support to major legislative initiatives, notably the revised Payment Services Directive and Payment Services Regulation (PSD3/PSR), the Central Securities Depositories Regulation (CSDR) and the Securitisation Package.

Finally, the EBA made 21 recommendations in October 2025 for simplifying and improving the efficiency of the EU supervisory and regulatory framework, including a number of initiatives which do not require legislative change, and which will be delivered in the course of 2026.

Banking system resilience confirmed

Its 2025 EU-wide stress test published on 1 August 2025 confirmed the resilience of banks across the European Union and the European Economic Area (EU/EEA), demonstrating their capacity to maintain capital ratios above minimum regulatory requirements even under severe adverse scenarios.

Driving data integration and ESG analytics

Significant progress was achieved in data modernisation. The EBA launched a Pillar 3 Data Hub, thus creating a centralised platform for prudential disclosures across hundreds of banks, and further expanded the European Data Access Portal (EDAP).

The Authority also strengthened its analytical capabilities on sustainability risks, publishing its first ESG Risk Dashboard and advancing preparations for a regular climate stress testing framework.

Expanded supervisory role in digital finance

Under DORA and MiCA, the EBA assumed new supervisory responsibilities and established the necessary governance structures, methodologies and joint examination frameworks.

Nineteen third-party providers of critical information and communication technology (ICT) to the EU financial system were designated under DORA, with the EBA being their lead overseer. Under MiCA, the EBA finalised supervisory procedures for issuers of significant asset-referenced tokens and e-money tokens, marking a key step in the oversight of crypto-asset markets.

Enhancing consumer protection and supervisory convergence

Against a background of buoyant financial innovation, consumer protection remained a priority in 2025. The EBA supported the implementation of the Instant Payments Regulation, published its Consumer Trends Report and launched awareness campaigns on risks related to crypto-assets and digital finance fraud.

The Authority also strengthened supervisory convergence across the EU through peer reviews, training initiatives and enhanced cooperation with EU institutions and international partners.

Note to the editors

A consolidated version of the 2025 Annual report will be published by the end of June 2026 with the addition to the current report of a comprehensive overview of all the EBA’s activities in delivering on its mandates under the Work Programme.

The Annual report published today presents the main annual achievements, while the forthcoming chapters will provide detailed information on the implementation of the EBA’s Work Programme, as well as on the EBA’s budget, staff policy plan, management and internal control systems. 

ESAs publish the first report on DORA major ICT-related incidents

Source: European Banking Authority

The European Supervisory Authorities (EBA, EIOPA and ESMA) today published their first annual overview of major ICT-related incidents in the EU financial sector based on a reporting mechanism established by the Digital Operational Resilience Act (DORA). It shows that ICT risks are increasingly borderless and interconnected. The authorities also note that the recent evolution of highly capable AI-driven tools should encourage financial entities to strengthen cybersecurity measures to maintain their resilience going forward.

With the objective to harmonise and streamline the reporting regime of major ICT-related incidents, DORA introduces consistent requirements for financial entities on management, classification and reporting of ICT-related incidents. By ensuring major ICT-related incidents are properly notified to all Competent Authorities involved, this mechanism allows a faster and more coordinated response in case of borderless and interconnected major ICT-related incidents, ultimately contributing to the resilience of the European financial system.

The report indicates that around one third of the 3,383 major incidents reported by financial entities in the EU (i.e. 0.18 per entity subject to DORA) had a cross-border impact, underscoring the growing interconnectedness through shared infrastructures and services. On the other hand, the direct impact on clients and transactions was generally limited. System failures and external events were the main drivers, highlighting the need for robust third-party risk management, effective oversight of outsourced services and close coordination with service providers during incident response and remediation. While only 10% of the reported incidents were related to cybersecurity, it is key that financial entities uphold to the highest cybersecurity standards to be able to keep pace with the potential use of highly capable AI-driven tools.

These findings illustrate the growing systemic dimension of ICT risk as well as the importance of resilience and supervision in strengthening the financial sector’s ability to prevent, absorb and recover from future incidents.

Legal basis and background

Article 22(2) of the Digital Operational Resilience Act (DORA) mandates the European Supervisory Authorities (ESAs) to report yearly on major ICT-related incidents, setting out at least: (i) the number of major ICT-related incidents, (ii) their nature, (iii) their impact on the operations of financial entities or clients, (iv) remedial actions taken, and (v) the costs incurred.

Under the Digital Operational Resilience Act (DORA), an ICT-related incident is defined as a single event or a series of linked events unplanned by the financial entity that compromises the security of the network and information systems, and have an adverse impact on the availability, authenticity, integrity or confidentiality of data, or on the services provided by the financial entity’. A major ICT-related incident is an ICT-incident that has a high adverse impact on the network and information systems that support critical or important functions of a financial entity. 

​The EBA and the New York State Department of Financial Services sign a Memorandum of Understanding to foster cooperation in the supervision of international stablecoin activities

Source: European Banking Authority

​The European Banking Authority (EBA) has signed a Memorandum of Understanding (MoU) with the New York State Department of Financial Services (NYDFS) under the Markets in Crypto-Assets Regulation (MiCA). The agreement aims to strengthen cooperation in the supervision of entities engaged in cross-border stablecoin activities.

​The MoU establishes principles and procedures to facilitate information exchange and the coordination of supervisory activities related to stablecoins issued in both the New York State and the European Union, including by entities directly supervised by the EBA under MiCA. It also provides a framework for mutual assistance in ongoing supervision, as well as timely coordination in crisis or emergency situations.

​This cooperation framework reflects the growing international dimension of stablecoin markets and supports effective and consistent supervision across jurisdictions.

​EBA Chair, François-Louis Michaud said: “This agreement marks an important milestone in strengthening transatlantic cooperation on stablecoin supervision and ensuring that cross-border activities are conducted to the highest standards. It reflects our commitment to building a strong, effective, and globally coordinated supervisory framework for crypto-assets.”

​“Effective financial regulation has always depended on strong relationships between regulators, and that principle holds firm in the digital asset space,” said Acting Superintendent Kaitlin Asrow. “This MoU reflects the Department’s deep commitment to cross-border supervision and collaboration in order to protect consumers, regulated entities, and markets.”  ​

Legal basis and background

Under MiCA, the EBA is entrusted with direct supervisory responsibility over issuers of ‘significant’ asset-referenced tokens (ARTs) and electronic money tokens (EMTs). In this context, Article 126 of MiCA allows the EBA to conclude administrative agreements on the exchange of information with third-country supervisory authorities.  

The disclosure of confidential information to non-EU authorities relating to supervised entities within the scope of the MoU, is subject to a positive assessment confirming that the confidentiality and professional secrecy framework of the third-country authority is equivalent to that provided for under MiCA. In this respect, the EBA has assessed the regime applicable to the NYDFS as equivalent. 

The EBA consults on amendments to the RTS on the assignment of risk weights to specialised lending exposures under the Supervisory Slotting Criteria Approach

Source: European Banking Authority

The European Banking Authority (EBA) today launched a public consultation on proposed amendments to its Regulatory Technical Standards (RTS), set out in a Delegated Regulation, on the assignment of risk weights to specialised lending exposures under the Supervisory Slotting Criteria Approach (SSCA). The purpose of the amendments is to update the RTS in light of the changes introduced by the revised Capital Requirements Regulation (CRR 3) and to enhance the risk sensitivity, clarity and usability of the framework. Overall, the RTS aim to ensure a consistent and robust prudential treatment of specialised lending exposures under the SSCA across the EU, supporting sound risk management and financial stability. The consultation runs until 7 August 2026.

With the proposed amendments, the RTS are aligned with the definitions and terminology introduced by CRR3. In addition, certain constraints in the current RTS methodology are removed to allow for a better reflection of risk, and several clarifications to the assessment criteria are introduced with a view to simplifying their application.

Consultation Process

Responses to this consultation can be sent to the EBA by clicking on the “send your comments” button on the consultation page. Please note that the deadline for the submission of comments is 7 August 2026.

A public hearing will take place via conference call on 27 May 2026 from 10:00 to 11:00 CEST. Please register here by 22 May 2026, 10:00 CEST.

Legal basis and background

The EBA has developed these draft amending RTS under Article 153(9) of Regulation (EU) No 575/2013, which mandates the Authority to specify how institutions are to take into account the factors referred to in Article 153(5), when assigning risk weights to specialised lending exposures under the Supervisory Slotting Criteria Approach. The mandate already existed under CRR2 and was renewed by CRR3. 

The EBA amends Guidelines on the definition of default

Source: European Banking Authority

The European Banking Authority (EBA) published today its final Report amending the Guidelines on the application of the definition of default. The Report introduces targeted amendments to better reflect specific aspects of non‑recourse factoring. It also confirms that the 1% threshold applied to reductions in net present value loss (NPV threshold) in debt restructuring remains appropriate for prudential default recognition.

The EBA has introduced targeted amendments to address specific technical aspects of the past-due treatment of non-recourse factoring. In particular, the specific technical past-due treatment at the individual invoice level has been extended from 30 to 90 days. This change better reflects the operational features of invoice-based receivables and reduces the risk of incorrect default classifications. The Guidelines have also been updated to align with the amendments introduced by the Capital Requirements Regulation (CRR 3).

At the same time, the current NPV threshold framework is sufficiently flexible, risk-sensitive and consistent with the accounting framework. It does not lead to default misclassifications, as it applies only to borrowers experiencing financial difficulties, and to restructurings resulting in losses. In addition, it is aligned with other thresholds used for default identification, ensuring a simple and efficient framework.

By contrast, amending the framework – such as by increasing the NPV threshold – could undermine post-financial-crisis efforts to reduce non-performing loans by weakening the reliability of capital and provisioning assessments. Such changes would also entail significant operational costs, including redevelopment and revalidation of models. Ultimately, they could reduce the resilience of the banking sector and discourage credit institutions from undertaking proactive, preventive, and meaningful debt restructuring to support borrowers.

Legal references and background

Article 178 of Regulation (EU) No 575/2013 provides criteria for the regulatory definition of a default. Among these criteria, in paragraph 3, point (d) mentions ‘forbearance measure […] likely to result in a diminished financial obligation due to the material forgiveness, or postponement, of principal, interest or, where relevant, fees’. In September 2016, the EBA published guidelines to further clarify the definition of default, as part of its IRB repair program.

Article 178(7) of the CRR, as amended by Regulation (EU) 2024/1623, mandates the EBA to review and update the Guidelines on the definition of default, and in particular to consider the need to grant sufficient flexibility to institutions when specifying what constitutes a ‘diminished financial obligation’. In this review, the EBA dully considered the necessity to encourage proactive, preventive and meaningful debt restructuring to support obligors.

This review work forms part of the EBA roadmap on the implementation of the Basel III framework through the EU banking package.

The EBA publishes its final Guidelines on supervisory independence

Source: European Banking Authority

The European Banking Authority (EBA) today published its final Guidelines on Supervisory Independence under the Capital Requirements Directive (CRD). The Guidelines further clarify the arrangements that competent authorities should have in place to prevent and manage conflicts of interest involving both their staff and the members of their governance bodies. These arrangements include declarations of interest, limitations on trading of financial instruments and cooling-oof restrictions.

Risks to supervisory independence pose challenges to the soundness of supervision and good governance. New requirements introduced in the CRD therefore aim to strengthen the framework for managing such risks. To safeguard the trust in the governance of competent authorities and ensure transparency of procedures, the Guidelines clarify additional aspects related to the appointment of members of governance bodies and the duration of their tenure.

To support the prevention and management of conflicts of interest, the Guidelines set out minimum harmonised standards for the submission and assessment of declarations of interest on a pre-employment, annual and ad-hoc basis.

The Guidelines also include harmonised procedural requirements for the sale or disposal of financial instruments that may give rise to conflicts of interest and further specify the prohibition on trading in financial instruments laid down in the CRD.

Finally, where national laws allow for cooling-off periods beyond the minimum period set out in the CRD, the Guidelines aim to ensure a proportionate and consistent approach across the EU. To this end, they establish procedures and assessment criteria for competent authorities to consider when determining the appropriate length of such periods.

Legal basis and background

The Guidelines on supervisory independence of competent authorities have been developed pursuant to Article 4a(9) of Directive 2013/36/EU, which mandates the EBA to issue guidelines on the prevention of conflicts of interest and the independence of competent authorities, to ensure a proportionate application of that Article, taking into account international best practices.

The Guidelines build on existing EU and international standards and principles related to supervisory independence and the management of conflicts of interest, including the Joint European Supervisory Independence criteria.pdf of 25 October 2023 (JC 2023 17).

The EBA streamlines its Guidelines on connected clients to align with new EU legislation

Source: European Banking Authority

The European Banking Authority (EBA) has decided to partially delete sections of its Guidelines on connected clients, following the entry into force of new, directly applicable EU legislation. The changes ensure continued clarity, consistency and alignment in the framework used by credit institutions to identify groups of connected clients.

The decision reflects the application of Commission Delegated Regulation (EU) 2024/1728, which introduces binding regulatory technical standards, developed by the EBA, setting out the circumstances in which institutions must identify groups of connected clients. As these rules now apply directly across the EU, certain provisions of the EBA Guidelines are no longer necessary to ensure a common and consistent application of Union law and have therefore been removed.

The Decision together with a consolidated version of the Guidelines on connected clients, reflecting these partial deletions, is published on the EBA’s website.

Background and legal basis

The EBA Guidelines on connected clients (EBA/GL/2017/15) were adopted in 2017 to support the identification of groups of connected clients, including situations involving control relationships, economic dependency, and combined control and economic dependency.

The Decision is adopted pursuant to Articles 16(2a) and 29(1)(d) of Regulation (EU) No 1093/2010 (the EBA Regulation), Article 4(4) of Regulation (EU) No 575/2013 (the CRR), and Articles 1, 2 and 3 of Commission Delegated Regulation (EU) 2024/1728.

The EBA updates list of correlated currencies

Source: European Banking Authority

Communicating to all our audiences in the most effective way and using the most appropriate channels is crucial for us. Through our publications, announcements, and participation in external events, we are committed to reaching out to all our stakeholders to report about our policies, activities, and initiatives.

The ESA’s Joint Committee highlights digitalisation, cyber resilience and sustainable finance as key priorities of 2025

Source: European Banking Authority

The Joint Committee of the European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) today published its Annual Report for 2025, setting out the main priorities and achievements of its cross-sectoral work over the past year. In 2025, the Joint Committee focused on protecting consumers in increasingly digital financial markets, strengthening operational and cyber resilience through the implementation of the Digital Operational Resilience Act (DORA), improving the effectiveness of sustainable finance disclosures, and enhancing cross-sectoral risk monitoring.

Chaired by the European Insurance and Occupational Pensions Authority (EIOPA), in 2025, the Joint Committee continued to act as a key coordination platform, supporting close cooperation and information exchange between the ESAs, the European Commission and the European Systemic Risk Board (ESRB).

The Joint Committee also advanced a range of other cross-sectoral initiatives, including work to enhance the EU securitisation framework, progress on the European Single Access Point (ESAP), and support for financial innovation through the European Forum for Innovation Facilitators (EFIF).

In line with the European Commission’s priorities, the Joint Committee further contributed to efforts to simplify the EU financial regulatory framework and reduce unnecessary complexity, notably in the areas of sustainable finance and packaged retail and insurance-based investment products (PRIIPs).

Background

The Joint Committee is a forum established to strengthen cooperation between the European Banking Authority (EBA), the European Insurance and Occupational Pensions Authority (EIOPA) and the European Securities and Markets Authority (ESMA). It coordinates cross-sectoral supervisory work and promotes consistent supervisory practices across the EU.

In an environment marked by heightened geopolitical uncertainty, accelerating digitalisation and rapid financial innovation, the ESAs focused on ensuring that regulatory frameworks remain robust, proportionate and forward-looking.

The EBA responds to the Commission’s proposed changes to its draft technical standards on operational risk

Source: European Banking Authority

The European Banking Authority (EBA) has today published an Opinion on the European Commission’s proposed amendments to the final draft Regulatory Technical Standards (RTS) specifying operational risk requirements under the Capital Requirements Regulation (CRR). It considers that two amendments proposed by the Commission could affect the consistency, transparency and supervisory effectiveness of capital requirements for operational risk.

On 2 March 2026, the European Commission informed the EBA of its intention to endorse, with amendments, the draft RTS submitted by the EBA in June and August 2025.

The EBA reaffirms its commitment to a prudent, transparent and consistent implementation of the operational risk framework and invites the European Commission to reconsider two of these amendments.

First, the Commission proposes to allow the combined use of the accounting approach (AA) and the prudential boundary approach (PBA) for the calculation of the financial component of the business indicator. The EBA considers that requiring institutions to apply only one approach to the full balance sheet is necessary to preserve the coherence of the framework. The combined use of both approaches is not envisaged in the Basel standard and may increase complexity, create inconsistencies across risk frameworks and facilitate regulatory arbitrage, while benefiting only a limited number of institutions.

Second, the Commission proposes to limit notification obligations to competent authorities to material changes in the scope of the PBA when used in combination with the AA. The EBA considers that this could weaken supervisory effectiveness by introducing institution-specific materiality judgments making supervisory reviews more complex.

The EBA supports the other amendments proposed which improve readability and legal certainty.

Legal basis and background

This Opinion is issued under Article 10(1) of Regulation (EU) No 1093/2010, which requires the EBA to provide an opinion where the European Commission intends to endorse draft RTS with amendments.

The prudential treatment of operational risk is set out in Articles 311a to 323 of Regulation (EU) No 575/2013 (CRR). The RTS developed by the EBA specify the components of the business indicator, adjustments to profit and loss data and a harmonised risk taxonomy for operational risk.