The European Supervisory Authorities (EBA, EIOPA, and ESMA) issued a statement on 23 September 2026, identifying external dependencies, emerging technologies, and private credit as key vulnerabilities in the EU financial system. They require firms to review and enhance their operational resilience and risk management frameworks to address these vulnerabilities.
The statement does not cite a specific instrument but is part of the Autumn 2026 risk update by the European Supervisory Authorities.
The guidance applies to all regulated entities within the EU financial sector, including those involved in crypto-assets and payment services.
The announcement does not specify a deadline for compliance or any transitional period for the firms to follow.
The authorities emphasize the importance of vigilance regarding external dependencies and cyber threats, urging firms to prepare for emerging risks that could impact their operations.