Fostering robust ICT capabilities is one of the ECB’s supervisory priorities for 2026-2028. In a world of growing technological complexity and rising expectations for resilience, effective ICT change management is an increasingly vital risk governance capability.

      As part of its work programme, the ECB has therefore begun a targeted review covering more than 30 banks. This off-site exercise requires participants to complete a structured questionnaire, provide supporting documentation and evidence, and respond to follow-up requests from JSTs. Banks will then receive a formal feedback letter. Supervisors will also use anonymised benchmarking to compare banks and identify systemic weaknesses.

      The review marks a further step towards evidence-based, implementation-focused supervision of operational resilience in a post-DORA world. It not only tests the existence of ICT change management frameworks, but their effectiveness in practice.

      Experience shows that introducing new hardware, software and processes into the live environment is frequently the root cause of unplanned downtime in banks. Common structural weaknesses include:

      • Poor alignment between defined processes and practical execution
      • Opaque roles, responsibilities and decision-making
      • Insufficient documentation and audit trails
      • Weak classification and integration of risks

      To address this, the current review takes a full-spectrum, end-to-end view of change management. Areas of particular focus for supervisors are likely to include the following:


      • Regulatory application
        • How well are regulatory requirements embedded in policies and procedures?
        • How well do those frameworks translate into operational reality?
      • Accountability and decision-making
        • How clearly are roles and responsibilities defined?
        • How well are duties segregated?
        • Is there clear ownership of decision-making?
      • Governance frameworks
        • How are structures like Change Advisory Boards established?
        • How practically effective is governance and oversight?
        • How well defined and documented are decisions and approvals?
      • Risk assessment
        • Are ICT changes defined and classified appropriately?
        • How independent are risk assessments?
        • Can initiating functions override concerns from other lines of defence?
      • Planning and execution
        • How well are changes planned, scheduled and implemented?
        • Are timelines realistic and flexible?
        • Are deviations from plan justified and documented?
      • Exceptions and emergencies
        • How well controlled are urgent or fast-track changes?
        • Do frequent exceptions reflect structural weaknesses in planning or design?
        • How robust are post-implementation reviews?
      • Rollout and rollback
        • Is there evidence of comprehensive pre-deployment testing?
        • Are rollback plans clearly defined and operational?
        • How is end-to-end traceability documented?
      • Metrics and reporting
        • Is there reliable, decision-relevant reporting on change management?
        • Are there clearly defined KPIs that enable effective oversight?
        • Does reporting allow leaders to monitor risks and take informed decisions?

      Banks seeking to learn from the current thematic review and anticipate future supervisory scrutiny of ICT change management should consider taking action in the following areas:


      • Validate implementation in practice

        Apply controls consistently, testing every change and identifying deviations from plan.

      • Strengthen governance and accountability

        Clarify decision-making responsibilities, reinforcing segregation of duties and formalising governance mandates.

      • Enhance control over high-risk changes

        Monitor emergency changes closely, checking risk classifications and ensuring strong oversight.

      • Close the evidence gap

        Establish audit-ready plans, ensuring that plans for testing, approval and rollback are fully documented.

      • Upgrade management reporting

        Define robust, consistent KPIs that enable informed decisions, enabling meaningful reporting for leaders.


      The current targeted review will challenge participants to demonstrate strong control of ICT change management processes. However, it also provides an opportunity for banks to strengthen controls, improve transparency, and build confidence in their operational resilience.


      KPMG European Central Bank Office

      KPMG ECB Office offers you solutions for dealing with the ECB supervisory approach under the Single Supervisory Mechanism (SSM).


      Our people

      Elvira Niedermeier

      Senior Manager, KPMG ECB Office

      KPMG in Germany

      Dina Friedrichs

      Senior Manager

      KPMG in Germany

      Alejandra Carrillo

      Associate partner - IT Risk and Compliance

      KPMG in Spain