ECB supervision is moving beyond identifying weaknesses.
The focus is increasingly on whether banks can demonstrate resilience, execute remediation and deliver sustainable change before vulnerabilities become material business risks.
For banks under ECB supervision, regulatory expectations are no longer something to address when an inspection arrives or a SREP outcome identifies a weakness.
The direction is clear. ECB Banking Supervision’s 2026 to 2028 priorities place significant emphasis on resilience, operational capability and the ability of banks to manage increasingly complex risks. This includes geopolitical uncertainty, macrofinancial risks, operational resilience, ICT capabilities, risk data and reporting, third party risk and the governance of new technologies such as artificial intelligence.
For Chief Risk Officers, Heads of Regulatory Affairs and Programme Directors, this creates a very different challenge.
It is no longer enough to know where the gaps are.
Banks need to demonstrate that they can close them.
The ECB is looking for evidence, not intentions
Regulatory findings can be straightforward to identify. Delivering the remediation is where the real difficulty begins.
A bank may understand exactly what the ECB expects but still struggle to translate those expectations into a coordinated programme with clear ownership, realistic milestones and measurable outcomes.
This is where regulatory programmes frequently lose momentum.
Remediation becomes fragmented across Risk, Finance, Technology, Data, Compliance and Operations. Different teams interpret requirements differently. Dependencies remain unresolved. Decisions take too long. Executive visibility becomes limited.
The result is predictable.
A programme that was intended to reduce regulatory risk starts creating additional delivery risk.
The ECB’s supervisory approach continues to include targeted activities, thematic reviews and follow up work on previous shortcomings. Banks therefore need to be prepared not only to respond to new findings but to demonstrate that previously identified weaknesses have been sustainably addressed.
DORA, AI and ICT resilience are changing the delivery challenge
Operational resilience has become a central component of the ECB’s supervisory agenda.
With DORA now in force, banks are expected to strengthen their operational resilience and ICT capabilities, including areas such as ICT third party risk and incident response. Supervisory attention also continues to cover deficiencies identified through previous reviews of cybersecurity, third party risk and risk data aggregation and reporting.
At the same time, the ECB is increasing its focus on how banks use emerging technologies, particularly AI, including the associated governance and risk management requirements.
These areas cannot be delivered successfully through isolated compliance workstreams.
A DORA programme can affect technology architecture, supplier management, incident processes, data and operational controls.
An AI programme can affect model governance, risk management, technology, data, workforce capability and decision making.
The regulatory requirement may sit within one function. The transformation required to satisfy it does not.
Failing programmes become regulatory problems
The greatest risk is not always the original regulatory finding.
It is failing to deliver the response.
When remediation programmes begin to slip, costs increase. Executive attention is diverted. Business priorities compete with regulatory commitments. Dependencies become harder to manage.
Most importantly, confidence begins to deteriorate.
A programme that repeatedly misses milestones or produces inconsistent evidence can create a much larger problem than the weakness it was originally established to resolve.
This is why programme recovery needs to be treated as a specialist capability.
The objective is not simply to update a plan or increase reporting. It is to establish what is preventing delivery, remove the blockers and create a credible route to completion.
ECB remediation requires transformation leadership
Brickendon approaches regulatory transformation from a delivery perspective.
We work with financial institutions facing complex regulatory programmes where failure is not an option. Our specialists combine regulatory understanding with programme delivery, governance, risk, data and technology expertise to address the practical challenges that prevent organisations from moving forward.
That can mean assessing a programme before regulatory scrutiny intensifies:
- It can mean recovering a programme that has lost momentum.
- It can mean strengthening governance after a SREP outcome.
- It can mean coordinating technology, risk and business teams around DORA delivery.
- It can mean establishing the operating model required to govern AI safely at enterprise scale.
The common requirement is the same.
Turn regulatory expectations into measurable delivery.
Do not wait for the next finding
The ECB’s current supervisory priorities make one thing clear. Banks are expected to remain resilient, address vulnerabilities and strengthen their ability to manage an increasingly complex risk environment. Supervisory activities will continue to assess, monitor and follow up on those vulnerabilities.
For banks, waiting for the next supervisory finding before acting is becoming an increasingly expensive strategy.
The strongest institutions are identifying weaknesses early, establishing accountable remediation programmes and building capabilities that remain effective after the immediate regulatory requirement has been satisfied.
The ECB is not waiting for banks to catch up.
Neither should your programme, we help banks restore control, accelerate remediation and deliver the outcomes regulators expect.