September roundup of regulatory and compliance news

Andrew Bailey

A monthly roundup of the most important regulatory, legal and supervisory developments shaping QA, software testing, AI governance and digital resilience across banking and financial services.

Regulators have returned from the summer with a remarkably consistent message for financial institutions: awareness of AI and cyber risk is no longer enough.

Across Europe, Asia and Australia, authorities are increasingly asking firms to demonstrate that their controls work under real conditions. Governance policies must be supported by tested recovery plans, validated security tools, reliable incident reporting and evidence that systems can withstand faster and more sophisticated attacks.

The growing capabilities of frontier AI models have become a particular concern. Regulators fear these systems could help attackers discover and exploit vulnerabilities far more quickly, while shared cloud platforms, software suppliers and technology dependencies could allow disruption to spread across multiple institutions.

At the same time, new EU transparency and vulnerability-reporting requirements are turning aspects of AI and software assurance into explicit compliance obligations.

FSB puts frontier AI at top of cyber agenda

The Financial Stability Board has identified the effect of frontier AI on cyber risk as the most immediate AI-related concern facing the financial system.

In a letter to G20 finance ministers and central bank governors, FSB chair Andrew Bailey warned that advanced models are developing increasingly sophisticated autonomous, problem-solving and threat capabilities.

FSB HQ in Basel

The global financial system’s interconnectedness means a cyber incident may not remain confined to one institution. Disruption could spread across borders through common technology providers, shared vulnerabilities and dependencies on a relatively small group of major suppliers.

The warning strengthens the case for tests that go beyond isolated system failures. Scenario design may need to cover simultaneous outages, disruption at a widely used supplier, attacks that move across connected systems and recovery when normal digital infrastructure is unavailable.

The FSB’s intervention also elevates AI testing from an internal technology concern to a potential financial-stability issue.

EBA proposes operational risk standards for banks

The European Banking Authority has launched a consultation on draft regulatory technical standards specifying the operational risk management framework banks must maintain under the revised Capital Requirements Regulation.

The proposed framework has three main elements: governance arrangements, the operational risk management process and an operational risk assessment system.

It would require institutions to identify, assess, monitor and report operational risks through documented and traceable processes. ICT risk management under the Digital Operational Resilience Act would form part of that wider framework, allowing institutions to rely on certain DORA arrangements where the two regimes overlap.

The consultation is significant for technology teams because software failures, cyber incidents, data problems and unsuccessful system changes can all result in operational losses.

Testing evidence may consequently need to serve several purposes. It must demonstrate the technical effectiveness of controls while also supporting operational risk assessments, incident classification, management reporting and audit.

The EBA consultation runs until December 31, with a public hearing scheduled for September 29.

EU supervisors demand testing for frontier AI threats

The EBA, European Insurance and Occupational Pensions Authority and European Securities and Markets Authority have called for a coordinated supervisory response to ICT risks arising from frontier AI.

Their joint statement says governance structures, risk management frameworks and testing methodologies must adapt to AI-assisted cyber threats and the possibility of failures affecting multiple systems.

The authorities specifically highlight operational resilience testing, disaster recovery, backup capabilities and stronger cyber maturity. They also want management bodies to ensure accountability develops at the same pace as the underlying risks.

This provides one of the clearest regulatory links yet between frontier AI and software testing.

Traditional penetration tests conducted at fixed intervals may be insufficient when AI can accelerate vulnerability discovery and reduce the time available to deploy a tested patch.

Firms may need more continuous security validation, faster remediation processes and recovery exercises built around compressed incident timelines.

The statement also connects frontier AI risk with DORA oversight of critical ICT third-party providers, reinforcing supervisory concern about concentration across the financial system.

ENISA prepares software suppliers for new reporting regime

The EU Cyber Resilience Act will begin imposing mandatory vulnerability and incident-reporting obligations on manufacturers of products with digital elements from September 11.

The European Union Agency for Cybersecurity is preparing a Single Reporting Platform through which manufacturers and qualifying open-source software stewards can report actively exploited vulnerabilities and severe security incidents.

An early warning must generally be submitted within 24 hours of an organisation becoming aware of a reportable vulnerability or incident, followed by a more detailed notification within 72 hours. Final reporting deadlines will depend on whether the event involves a vulnerability or a severe incident.

These timelines create a direct challenge for software quality and security teams.

Organisations need processes capable of establishing quickly whether a vulnerability is being actively exploited, which products and versions are affected, how severe the impact may be and whether available mitigations have been tested sufficiently.

Incident detection, evidence collection, product inventories and escalation workflows must therefore work together. Poor integration between engineering, security, legal and compliance teams could make it difficult to meet the reporting deadline without submitting incomplete or unreliable information.

ENISA says the reporting platform itself will undergo user and security testing before launch and will be periodically reassessed.

MAS builds sector-wide response to AI threats

The Monetary Authority of Singapore and Association of Banks in Singapore have established an AI-Driven Cyber and Technology Risk Taskforce to strengthen resilience against AI-enabled threats.

The initiative brings together MAS, DBS, OCBC, UOB, Singapore Exchange, NETS, Banking Computer Services and the Association of Banks in Singapore.

Its work will include sharing financial-sector AI cybersecurity use cases, improving cyber-defence capabilities and developing guidance on controls that can detect, prevent and respond to more sophisticated attacks.

Crucially for testing teams, the taskforce plans to conduct proof-of-concept trials to explore and validate advanced AI-enabled defensive tools.

The programme recognises that financial institutions cannot simply purchase an AI security product and assume it will work. Defensive systems must be evaluated against realistic attack scenarios, operational data and the infrastructure in which they will ultimately be deployed.

It also reflects the sector-wide nature of the risk. Collaboration may be essential where financial institutions share suppliers, infrastructure and potential points of failure.

EU starts enforcing AI transparency requirements

The European Commission’s AI Office and national authorities have begun a new phase of AI Act enforcement, alongside transparency requirements that became applicable on August 2.

Providers of certain AI systems must ensure people are informed when they are interacting directly with AI, unless that fact is already obvious. Providers of systems that generate or manipulate content must also support the identification of AI-generated material through machine-readable marking.

Additional requirements cover the labelling of deepfakes and certain AI-generated or manipulated text published to inform the public on matters of public interest.

For banks and insurers, compliance will depend on more than adding a statement to a chatbot screen.

Testing may need to confirm that disclosures appear consistently across websites, mobile applications, virtual assistants and different customer journeys. Firms must also check that machine-readable information remains intact when content passes through APIs, document conversions, archiving systems and third-party platforms.

Regression testing will be particularly important. A disclosure or provenance control that works when first released may disappear after a user-interface change, model update or alteration to an external integration.

FCA expands controlled AI testing

The UK’s Financial Conduct Authority has selected 21 organisations for the second cohort of its Supercharged Sandbox, following 199 applications.

The programme gives participants access to synthetic and curated datasets, computing resources, AI tools and specialist support. The cohort began in July and will continue until the end of December.

Participants are using the controlled environment to develop, test and refine AI-enabled financial propositions before wider deployment.

The sandbox provides an opportunity to examine what meaningful pre-production AI evidence should contain. Depending on the use case, firms may need to test accuracy, bias, explainability, security, robustness and the ability of human operators to recognise and correct an unsuitable output.

Synthetic data can make experimentation safer, but it also creates an assurance question of its own. Firms must establish whether test data represents the complexity, edge cases and customer groups the system will encounter in production.

Participation in the sandbox does not remove a firm’s regulatory responsibilities, but the resulting evidence may help shape wider FCA thinking on AI testing and assurance.

Australian regulators demand tested response plans

Australia’s two principal financial regulators have told firms to move beyond awareness of frontier AI risks and take decisive action.

Simone Constant

The Australian Securities and Investments Commission and Australian Prudential Regulation Authority issued the warning after nine industry roundtables attended by more than 600 people.

The regulators highlighted timely patching, strong identity and access controls, reduced attack surfaces, backup integrity, third-party risk management and tested response and recovery arrangements.

ASIC commissioner Simone Constant said boards and executives must ensure their organisations have “well-tested response plans” and understand where they remain vulnerable.

The roundtables also identified interest in using AI for threat intelligence, vulnerability detection, code review and incident response, although the maturity of those capabilities remains limited.

The Australian intervention is unusually direct: having a response plan is not enough. Firms must demonstrate that it has been exercised and that recovery priorities, escalation authority and communication arrangements have been decided before an incident compresses the time available for action.

ASIC puts customer-facing banking AI under scrutiny

ASIC has separately made AI a priority in its Corporate Plan for 2026–27.

The regulator will examine how banks use AI in customer-facing services, how the technology affects consumers and investors, and how deepfakes, manipulation and AI-generated misinformation could affect market integrity.

The move brings customer experience testing into the regulatory picture.

Banks will need to demonstrate that AI-enabled services do not produce misleading information, conceal accountability or result in poorer treatment of particular customer groups. Monitoring must also identify emerging harm after deployment rather than relying solely on a model’s performance during development.

ASIC will build its own AI, data and cyber capabilities to detect misconduct earlier, suggesting that firms may increasingly face regulators equipped to interrogate the underlying technology and evidence rather than relying on policy descriptions.

Critical infrastructure warned over continuous remediation

A Banque de France speech published by the Bank for International Settlements has warned central counterparties that frontier AI will shorten the interval between discovering a vulnerability and exploiting it.

First Deputy Governor Denis Beau said organisations will need to move away from traditional periodic patching towards continuous, exploitability-driven remediation.

Central counterparties are particularly exposed because of their systemic role and reliance on a limited number of cloud providers, cybersecurity companies and specialist software suppliers. Disruption at one critical provider could spread across interconnected financial market infrastructures.

Denis Beau

The shift to continuous remediation has substantial implications for quality engineering. Faster patching cannot come at the expense of validation, particularly in infrastructure supporting clearing, collateral and margin processes.

Testing pipelines must therefore become quicker and more automated while retaining controls over compatibility, performance, failover behaviour and unintended changes to critical services.

Beau also pointed to work by CPMI and IOSCO on response, resumption and recovery plans, including scenario design and testing. Together with DORA’s new oversight regime for critical third-party providers, the work signals growing supervisory attention to the infrastructure and suppliers supporting the financial system.

Taken together, September’s developments show regulators converging around a common principle: resilience and responsible AI adoption must be demonstrated through evidence.

Policies, inventories and governance committees remain necessary, but they will not establish that a bank can recover from disruption, detect an AI-enabled attack or prevent a customer-facing model from causing harm.

Testing, validation, monitoring and documented recovery exercises are rapidly becoming the practical language through which financial institutions prove that their technology remains under control.

FSB responses expose emerging AI governance debate

Finally, the FSB has published responses to its consultation on responsible AI adoption in financial services.

Its original report proposed 12 sound practices covering organisation-wide governance and different stages of the AI development and deployment lifecycle. The framework was designed to address conventional AI alongside generative and increasingly agentic systems.

Publication of the submissions gives regulators and financial institutions a body of industry evidence to consider before the framework is finalised.

For testing teams, the key question is how broad governance principles will translate into repeatable assurance requirements.

Firms need practical criteria for deciding when a model is ready for deployment, which behaviours require adversarial testing, how performance should be monitored and when a change is significant enough to trigger revalidation.

Responsibility for third-party models remains equally important. A bank may not have built an underlying model, but it will still need evidence that its use of the technology is controlled, monitored and suitable for the customer or operational context.


THIS MONTH

REGISTER TODAY – SIMPLY CLICK HERE


Why not become a QA Financial subscriber?

It’s entirely FREE

* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *

SIGN UP HERE TODAY


READ MORE


QA FINANCIAL PODCASTS

CLICK HERE TO LISTEN TO OUR EXCLUSIVE CONVERSATIONS