The EBA publishes follow‑up Report on ICT risk assessment under the Supervisory Review and Evaluation Process

Date : Tags : , , , ,

This report evaluates how competent authorities have implemented previous recommendations regarding ICT risk assessment within the Supervisory Review and Evaluation Process (SREP). The document highlights a significant shift in the regulatory landscape due to the application of DORA, which establishes a unified framework for financial sector resilience. According to the findings, supervisors have made notable progress by forming specialized ICT teams, enhancing technical expertise, and adopting automated monitoring tools. Furthermore, the report details the integration of ICT‑specific guidelines into broader operational risk assessments to ensure a more cohesive supervisory approach. While most authorities have successfully adopted benchmarking and horizontal analysis, the EBA emphasizes that maintaining supervisory convergence remains an ongoing priority as technology evolves. Overall, the report confirms that the EU is moving toward a more harmonized and robust regime for managing digital risks in banking.