Fostering robust ICT capabilities is one of the ECB’s supervisory priorities for 2026-2028. In a world of growing technological complexity and rising expectations for resilience, effective ICT change management is an increasingly vital risk governance capability.
As part of its work programme, the ECB has therefore begun a targeted review covering more than 30 banks. This off-site exercise requires participants to complete a structured questionnaire, provide supporting documentation and evidence, and respond to follow-up requests from JSTs. Banks will then receive a formal feedback letter. Supervisors will also use anonymised benchmarking to compare banks and identify systemic weaknesses.
The review marks a further step towards evidence-based, implementation-focused supervision of operational resilience in a post-DORA world. It not only tests the existence of ICT change management frameworks, but their effectiveness in practice.
Experience shows that introducing new hardware, software and processes into the live environment is frequently the root cause of unplanned downtime in banks. Common structural weaknesses include:
- Poor alignment between defined processes and practical execution
- Opaque roles, responsibilities and decision-making
- Insufficient documentation and audit trails
- Weak classification and integration of risks
To address this, the current review takes a full-spectrum, end-to-end view of change management. Areas of particular focus for supervisors are likely to include the following: