At the end of each month, the SAFE Regulatory Radar highlights a selection of important news and developments on financial regulation at the national and EU level.
ESMA Work Programme and simplification report published
On 28 September 2026, the European Securities and Market Authority (ESMA) published its work programme for 2027. Key themes include the continued advancement of the Simplification and Burden Reduction (SBR) agenda and readiness for additional responsibilities stemming from the Market Integration and Supervision Package (MISP), which is still under negotiation.
Broader supervisory responsibilities: 2027 will be ESMAs first full year supervising ESG rating providers. The Authority plans on assessing their business models and potential risks to investors and market integrity. ESMA also plans on adapting the supervisory approach to entities that have recently come under its direct supervision, including Consolidated Tape Providers (CTPs), external reviewers under the European Green Bond framework and EU benchmark administrators endorsing third-country benchmarks.
Retail investor protection: The retail investment strategy, which is scheduled for a parliamentary vote in November 2026, will trigger technical advice to the European Commission and technical standards across a range of investor protection topics, such as value for money, inducements, disclosures, suitability and appropriateness, and marketing communications.
Data and technology: The public rollout of phase 1 of the European Single Access Point (ESAP) covering the Transparency Directive, the Prospectus Regulation, and the Short-selling Regulation is scheduled to go-live in 2027. Further initiatives in the data and technology strategy include plans to deploy AI-based supervisory tools and further develop the ESMA Data Platform to foster cooperation amongst authorities. Cyber and digital operational resilience will remain a Union-wide Strategic Supervisory Priority (USSP) and ESMA plans to set up another USSP on technological innovation, such as AI and tokenization, in the retail investors space.
Simplification and burden reduction: As part of the package, ESMA published its simplification report where it described how it plans on contributing to the simplification and burden reduction agenda. The report outlines four flagship initiatives with the greatest assumed impact: integrated transaction reporting, integrated funds reporting, a simpler investor journey and effective risk-based supervision. ESMA estimates that the long-term convergence of reporting could reduce reporting costs by 22–24 percent. ESMA plans on reviewing requirements under MiFIR/MiFID II, EMIR, CSDR, MAR, the Prospectus Regulation, MiCAR, AIFMD/UCITS, PRIIPs, and sustainability reporting.
- Holistic review of transaction reporting: ESMA aims to address overlaps and inefficiencies across MiFIR, EMIR, SFTR, and related legislative frameworks with the long-term goal to only report once.
- Integrated funds reporting: The aim is to establish an ESMA data hub for centralized storage and validation of all data reported using a fully integrated and harmonized single reporting template, based on common semantics/dictionary. ESMA has started the development of technical standards on funds reporting under the AIFM and UCITS directives, with the aim of finalizing this work in Q2 2027.
- Investor Journey: “The investor journey” is seen as a key area for simplification and burden reduction. ESMA plans on developing Level 2 and Level 3 measures aimed at simplifying disclosures, reducing duplicative requirements across MiFID II, PRIIPs and UCITS, and promoting digital-by-default communications. ESMA also intends to update MiFID II guidance and adapt more proportionate approaches for lower-risk products.
- Risk-based supervision: ESMA intends to advance risk-based supervision (RBS) following the publication of the RBS principles earlier this year. It plans to address entities with more targeted supervisory engagement according to their risk profiles, with a focus on efficiency and reaching high-quality supervisory outcomes to reduce unnecessary burden.
EBA Guidelines on Third-Party Risk Management
The European Banking Authority (EBA) has published its final Guidelines on third-party risk management, which replace its 2019 Guidelines on outsourcing arrangements. The Guidelines apply to non-ICT services and bring their management into line with DORA, which already governs ICT third-party providers. The Guidelines also widen the concept by outsourcing one category within the broader notion of third-party arrangements. The definition of a critical or important function aligns with the one used under DORA. The Guidelines are not yet applicable and are awaiting translation into the EU official languages. Once applicable, institutions will have a two-year transitional period to bring existing third-party arrangements and their non-ICT third-party registers into line with the new framework.
The Guidelines cover the whole life cycle of an arrangement from the pre-contractual risk assessment and due diligence, the contract itself, subcontracting, ongoing monitoring, documentation, and exit. Institutions keep a register of all third-party arrangements at individual and consolidated level, aligned with the DORA register format, and must record additional data for arrangements that support critical or important functions. Before entering such an arrangement, institutions must carry out a risk assessment and due diligence. Institutions must monitor third-party providers on a risk-based basis and, for arrangements supporting critical or important functions, assess substitutability and maintain appropriate exit strategies. Supervisors must be notified in advance of planned arrangements for critical or important functions and of material changes.
The guidelines are applied proportionately. EBA will consider an institution’s size and internal organization as well as the nature, scope and complexity of activities. The strictest requirements are for arrangements that support critical or important functions.
Updates
- In her State of the Union address on 16 September, Commission President von der Leyen announced a new Banking Package focused on simplification and tackling fragmentation. She also called for completing the One Europe, One Market Roadmap by the end of 2027, including action on capital markets infrastructure.
- ESMA published a package of materials under the prospectus regulation, including a consultation paper, final report on guidelines for product supplements, updated Q&As, and a final report on technical standards on key financial information to be included. ESMA seeks feedback on the consultation document until 9 November 2026.
- The European Commission declined to adopt the EBA's draft amending RTS on prior permission, submitted in March 2026, which aimed to speed up approval procedures for reducing own funds and eligible liabilities instruments. The Commission prefers a broader review; the EBA responded that it will carry out this wider review with a view to delivering further simplification at a later stage.
- EBA identified its priorities for the review of MiCAR. It calls for tougher rules for third-country multi-issuer schemes, a review of reserve requirements for stablecoins issuers, a clearer crypto-asset classification, a possible framework for crypto lending, and better reporting.
- On 16 September, the European Parliament confirmed Thomas Gstädtner as Executive Director of the EBA for a five-year term.
- The ESAs' published their joint autumn risk update where they flag three main vulnerabilities: external dependencies, emerging technologies and private credit.
Public consultations
|
Claudia Schaffranka is Head of the SAFE Policy Center.