Risk & Resilience

Cyber Risk Emerges as Outlier in EIOPA's Latest Risk Assessment

The European insurance sector remains on stable footing despite growing geopolitical uncertainty and an increasingly challenging cyber threat landscape, according to the latest risk assessment from the European Insurance and Occupational Pensions Authority (EIOPA).

Japan's Financial Watchdog Says Technology Failures Have Become a Management Problem

A banking outage used to be the sort of event that invited an engineering postmortem. Something broke, someone fixed it, and a report followed. Japan's Financial Services Agency no longer believes that sequence tells the whole story.

Book Review: From Heatmaps to Histograms

I have argued for years that risk is no longer a color. Red, amber, and green may make a report easier to scan, but they do not necessarily make risk easier to understand. The heatmap can tell an executive that something has been placed in a red box. It generally cannot explain how frequently the event might occur, what range of financial consequences the organization faces, whether a proposed control is worth its cost, or how one uncertain choice compares with another.

ECB Expands Climate Risk Framework to Corporate Credit Claims

The European Central Bank has spent the past year teaching its collateral framework a new habit. First it learned to look at corporate bonds through the lens of climate-related transition risk. Now it will do the same for a broader class of assets that sit behind the Eurosystem's lending operations.

Norway Warns Financial Institutions Face More Complex Risks Despite Stable Operations

Norway's financial sector entered 2026 from a position most regulators would envy. Payment services remained stable throughout the previous year, operational disruptions stayed broadly in line with recent experience, and none of the ICT incidents reported in 2025 threatened financial stability. That stability, however, is not what concerns the Norwegian Financial Supervisory Authority.

Is Risk Management a 2nd Line Function in the Updated Three Lines Model?

The Institute of Internal Auditors' updated Three Lines Model has reignited a longstanding debate over where risk management belongs within an organization's governance structure. In this commentary, governance and risk expert Norman Marks examines whether the revised definition of the second line finally reflects the reality of modern risk management, or simply broadens the concept so far that it loses much of its practical value. He argues that while the new language is an improvement over earlier versions, it raises fundamental questions about the purpose of the model and whether it still meaningfully distinguishes assurance providers from decision-support functions.

AMF Says Market Resilience Has Not Dispelled Geopolitical, Cyber & Private-Market Risks

In its 2026 Markets and Risk Outlook, the Autorité des marchés financiers said geopolitical and cyber risks remain central concerns. Financial markets, it said, have stayed broadly orderly and resilient despite a correction and heightened volatility following the outbreak of the conflict with Iran. That resilience is not presented as a clean bill of health. It is the backdrop against which the regulator now sees familiar vulnerabilities becoming more exposed.