Global Trustee and Fiduciary Services Bite-Sized Issue 7 2026
5 AI CRYPTOASSETS CYBER DORA IOSCO MONEY MARKET FUNDS SUSTAINABLE FINANCE/ESG ASIA PACIFIC AUSTRALIA EUROPE IRELAND LUXEMBOURG NORTH AMERICA UNITED KINGDOM Global Trustee and Fiduciary Services Bite-Sized | Issue 7 | 2026 Quick Links The AFM says that its research shows that the basis is usually in place, but that further steps are needed to fully and sustainably comply with DORA. The AFM says that: • DORA-gap analyses are not yet sufficiently elaborated . Trading venues (regulated markets, multilateral trading facilities and organised trading facilities) have generally carried out gap analyses, but these are often too global. As a result, relevant DORA requirements sometimes remain out of the picture and shortcomings only become visible later. A more detailed and periodic assessment helps to identify risks in a timely manner and to make targeted adjustments. • Certain parts of the ICT risk management framework require better coverage . A number of parts of the ICT management framework require attention in view of the requirements that DORA sets for this. Improvements can be made in the areas of security monitoring, access control, logging, emergency changes and continuity management. The AFM says that it is precisely these measures that are crucial for cyber resilience and the orderly functioning of the market. • Qualification of required documentation could be more consistent . Policies and procedures are not always clearly distinguished from each other. It is therefore not always clear whether certain requirements are included in policy if the regulations require it. The AFM says that this is important for the governance and formal approval of the policy. Clear governance and formal approval of policy are essential to demonstrably comply with the regulations. • DORA policy for intragroup ICT services . When using ICT services within the group, the AFM says that it sees that DORA requirements are not always unambiguously incorporated into the policy and documentation at group level. By establishing DORA-compliant policy frameworks at group level, institutions can ensure greater consistency and better management of ICT risks. • Monitoring digital operational resilience . Digital operational resilience is important. The AFM says that this is why it monitors compliance with the DORA requirements. The AFMmonitor the extent to which financial institutions comply with these rules. The AFM adds that, in its research, it also looks not only at policies and procedures on paper, but increasingly at the application in practice. In doing so, the AFM assess, among other things, whether measures work and contribute to the digital resilience of institutions. If institutions do not (fully) comply with the legal requirements, the AFM says that it will intervene. Link to DORA ICT Report here ESAs Publish the First Report on DORAMajor ICT-related Incidents On 3 June 2026, the European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) published their first annual overview of major ICT-related incidents in the EU financial sector based on a reporting mechanism established by the DORA. In its press release, ESMA says that it shows that ICT risks are increasingly borderless and interconnected. The ESAs also note that the recent evolution of highly capable AI-driven tools should encourage financial entities to strengthen cybersecurity measures to maintain their resilience going forward. With the objective to harmonise and streamline the reporting regime of major ICT-related incidents, ESMA says that DORA introduces consistent requirements for financial entities on management, classification and reporting of ICT-related incidents. By ensuring major ICT-related incidents are properly notified to all Competent Authorities involved, this mechanism allows a faster and more coordinated response in case of borderless and interconnected major ICT-related incidents, ultimately contributing to the resilience of the European financial system. ESMA says that the report indicates that around one third of the 3,383 major incidents reported by financial entities in the EU (i.e. 0.18 per entity subject to DORA) had a cross-border impact, underscoring the growing interconnectedness through shared infrastructures and services. On the other hand, the direct impact on clients and transactions was generally limited. System failures and external events were the main drivers, highlighting the need for robust third-party risk management, effective oversight of outsourced services and close coordination with service providers during incident response and remediation.
Made with FlippingBook
RkJQdWJsaXNoZXIy MTM5MzQ2Mw==