1st October 2026 

Key takeaways 

Digitalisation changes how banking risks interact, how quickly they materialise, and ultimately how they need to be supervised. A supervisory paradox emerges: faster-moving and increasingly interconnected risks require more timely information, while the infrastructure needed to provide it entails costs and greater technological dependence. Technological dependence and asymmetric access to privately developed technologies also have a geopolitical dimension. Against this backdrop, supervision needs to move beyond traditional financial metrics towards multifaceted, institution-specific risk factors. It also requires balancing information requirements with proportionality and simplification. Reverse stress testing can help identify bank-specific vulnerabilities. For banks, these changes increase risk-management and governance responsibilities.

Introduction

Digitalisation is transforming banking. The most visible manifestations are familiar: mobile banking, remote digital account opening and customer identification, instant payments, personalised financial products and the growing use of artificial intelligence. Less visible, but potentially more important from a financial-stability perspective, is the transformation taking place underneath these services. Banks increasingly depend on cloud computing, application programming interfaces (APIs), external technology providers and complex digital infrastructures across their front, middle and back offices. New digital banks and fintech intermediaries can also reach customers across geographical boundaries without the physical infrastructure traditionally associated with banking.

These developments may generate substantial benefits at both bank and system level. Digitalisation can improve banks’ operational efficiency and enhance credit scoring, collateral monitoring and payment services. By making banking services more easily accessible across geographical boundaries, digitalisation can also broaden financial inclusion and contribute to greater financial integration. But digitalisation also changes how traditional vulnerabilities materialise and interact, while creating new operational and informational dependencies. The supervisory question is therefore whether frameworks developed primarily around financial resilience are sufficiently equipped to identify vulnerabilities arising from banks’ increasingly digital operating environment.

This note argues that this transformation requires an evolution in prudential supervision. Capital and liquidity remain indispensable, but resilience now also depends on the continuity of critical technological services, the availability of timely and reliable information, and the ability of banks and authorities to identify institution-specific vulnerabilities before they materialise. Faster reaction times, wider cross-border reach and greater technological dependence illustrate this changing environment. The evolution of the ECB's supervisory priorities towards geopolitical risk, operational resilience and ICT capabilities can therefore be interpreted as part of a broader shift in the object and practice of supervision (ECB, 2025a).

How digitalisation affects supervision

Recent evidence illustrates how digitalisation can amplify rather than independently create liquidity vulnerabilities. Silicon Valley Bank (SVB) provided a striking example: approximately USD 42 billion, or 25% of deposits, left on 9 March 2023, while roughly another USD 100 billion was scheduled to leave the following day before the bank was closed (Rose, 2023). Yet historical evidence cautions against attributing this exceptional speed to technology alone: large corporate depositors had electronic transfer capabilities decades earlier, while the 2022-23 episodes combined uninsured funding with concentrated and interconnected depositor bases. Consistent with this, Cookson et al. (2026) show that social-media exposure amplified classical run vulnerabilities, while Fascione et al. (2025) find that online banking is associated with more pronounced extreme outflows in Europe, but primarily when underlying vulnerabilities are already present. Koont et al. (2025) similarly find greater sensitivity of deposits and deposit rates to policy-rate increases at more digital US banks. 

A first supervisory implication is that the effects of digitalisation depend on bank-specific characteristics, including depositor concentration, insurance coverage, customer interconnectedness and funding structure. Supervisors should therefore not treat digital deposits as inherently unstable or mechanically apply the same assumptions across institutions. Standard liquidity metrics need to be complemented by assessments of bank-specific funding vulnerabilities and of the operational capacity to mobilise liquidity under compressed timelines. Therefore, the relevant question is not only whether financial resources are formally available, but whether they can actually be deployed at the speed required under stress.

Digitalisation also creates new supervisory challenges by expanding the geographical scope of banking activity. Digital banks can attract customers and funding across borders without developing an equivalent physical presence, and EU passporting can reinforce this reach. For European supervision, this has a twofold implication. Digital distribution can support financial integration and the Savings and Investments Union (SIU) by facilitating cross-border access to financial services and private risk-sharing. At the same time, more integrated business models require supervisory information and institutional arrangements capable of following risks across national boundaries, as well as a sufficiently common institutional, regulatory and supervisory framework (Beck et al., 2024).

A further, and perhaps more structural, supervisory challenge concerns technological dependence. Banks rely on external providers for cloud computing, payments, core-banking systems, data services and other critical functions. Such arrangements can generate major efficiency gains, but concentration can also create common exposures and potential single points of failure. A disruption affecting a major provider may hit several institutions simultaneously, turning an individual outsourcing decision into a potential financial-stability issue. Chang et al. (2025), analysing cyber vulnerabilities at large US financial institutions and their third-party providers, estimate that catastrophic incidents targeting providers could generate losses around 60 times larger than routine incidents in their scenarios, with business interruption accounting for much of the damage.

This concern is now embedded in European supervision. The ECB's supervisory priorities for 2026-28 include targeted work on cybersecurity and third-party risk, a deep dive into banks' preparedness for disruption at a major cloud provider, and the oversight framework for critical ICT third-party providers under the Digital Operational Resilience Act (DORA) (ECB, 2025a). DORA establishes an EU framework for digital operational resilience and direct oversight of designated critical ICT third-party service providers. Operational resilience can therefore no longer be treated mainly as an internal IT-management matter: business continuity, cyber resilience, third-party dependence and recoverability of critical functions have become part of prudential resilience.

These developments also change supervisors’ information need and the speed at which they need it. If deposits can move in hours, supervisory information cannot operate on a fundamentally different timescale.. Effective supervision therefore requires the capacity to access critical indicators on deposits, liquidity and operational disruptions in real or near-real time when stress emerges.

At the same time, additional costs as well as a potential paradox emerge. Reliable near-real-time information requires investment by banks in data architecture, integration, automation and data-quality controls, while supervisors need the infrastructure and skills to process it. These demands must be reconciled with the parallel European agenda of simplification and proportionality (Brancaccio et al., 2026). Moreover, the supervisory response to technological dependence may itself deepen its reliance on technology: the systems needed to generate faster information can become additional sources of operational vulnerability. 

In term of information requirements, the objective should therefore be not more frequent reporting per se, but a limited set of real time, accurate and decision-relevant information, supported by an information architecture that is itself resilient. The ECB's reliance on existing supervisory data and templates in its 2026 geopolitical reverse stress test illustrates how additional information needs can be addressed while limiting unnecessary reporting burdens (ECB, 2025b).

From technological dependence to geopolitical vulnerability

Technological concentration provides a natural bridge to another important component of the supervisory agenda: geopolitical risk. When critical banking functions depend on a small number of private technology providers, concentration has a geographical, ownership and jurisdictional dimension as well as an operational one. It matters not only how many providers exist, but where they are located, under which jurisdiction they operate, who controls strategically important capabilities, and whether access can be relied upon in stress. Concentration of control in a single provider, a small group of decision-makers or ultimately one jurisdiction can therefore create vulnerabilities concerning continuity, control and accessibility. Technology-transfer restrictions, sanctions, export controls or deteriorating relations between jurisdictions can turn those vulnerabilities into operational constraints.

Technological and geopolitical risks are therefore increasingly intertwined. The ECB's priorities for 2026-28 place resilience to geopolitical and macro-financial uncertainty alongside operational resilience and ICT capabilities (ECB, 2025a). This also fits the longer evolution of supervision: from repairing bank-specific weaknesses after the global financial and sovereign-debt crises, through the pandemic and the war-energy-inflation shock, towards an agenda increasingly concerned with vulnerabilities generated by an unstable external environment.

The 2026 debate around Anthropic's Claude Mythos provides an illustrative example. Anthropic developed Mythos as an advanced model capable of identifying software vulnerabilities and initially restricted access to selected organisations through Project Glasswing. The issue acquired direct supervisory relevance in Europe when the ECB convened an ad hoc meeting with major banks to discuss the cybersecurity implications of Mythos and similar advanced AI models. European banks initially lacked the access available to some US institutions, while the ECB stressed that advances in AI could accelerate cyber threats and compress the time available to address vulnerabilities (Financial Times, 2026). The episode illustrates how asymmetric access to a privately developed strategic technology can acquire prudential relevance.

More generally, geopolitical risk can act as a cross-cutting amplifier of existing financial and non-financial vulnerabilities, transmitting through credit, market, liquidity, business-model, governance and operational channels. Its effects are also inherently heterogeneous: the same geopolitical or technological event can have very different consequences across banks depending on business model, geographical and sectoral exposures, funding structure, customer base and technological dependencies. This helps explain the ECB's use of reverse stress testing in its 2026 exercise. Rather than imposing a single common geopolitical scenario, participating banks identify events capable of producing a predefined severe outcome - at least a 300 basis point depletion in their CET1 ratio - and assess the implications for solvency, liquidity and funding (ECB, 2025b). The focus therefore shifts from predicting a common shock to identifying the events that could trigger severe outcomes in light of each bank’s specific vulnerabilities.

The conceptual shift underlying reverse stress testing is important. Supervisors cannot reasonably predict the next geopolitical confrontation, cyber incident or restriction on a critical technology, nor can regulation keep pace simply by adding new items to an expanding catalogue of risks. A more robust approach is to identify critical functions, concentrations, dependencies and transmission channels, and assess whether institutions could continue to operate if these were impaired.

Reverse stress testing is particularly useful in this respect because it starts from a severe outcome and works backwards to identify the bank-specific events that could produce it. This shift in supervisory approach also places greater responsibility on banks. Identifying institution-specific vulnerabilities is a core risk-management and governance task for boards and senior management, informing risk appetite, contingency planning, provider strategies and the protection of critical functions. Supervisors, in turn, can challenge these assessments and identify common dependencies and concentrations across the banking system that may not be visible to individual institutions.

A broader conception of prudential preparedness

An important policy implication is that, while capital and liquidity remain the foundations of banking resilience, digitalisation changes the environment in which those buffers must work. Adequate liquidity is of limited help if collateral cannot be mobilised quickly enough; adequate capital does not ensure continuity if a critical provider fails; and neither capital nor liquidity can be deployed effectively if management and authorities cannot obtain reliable information during a crisis.

Preparedness has therefore three interconnected dimensions: financial, operational and informational. Financial preparedness concerns the capacity to absorb losses and meet liquidity needs. Operational preparedness concerns the capacity to maintain or rapidly restore critical services and manage external dependencies. Informational preparedness concerns the capacity of banks and authorities to obtain reliable, sufficiently granular and timely information when decisions have to be made quickly. These dimensions reinforce one another and should increasingly be tested together.
Crisis simulations could, for example, combine a rapid liquidity shock with the temporary unavailability of a cloud provider or a cyber incident affecting access to deposit or collateral data. Such exercises would test not only whether resources exist on paper but whether they can be identified and mobilised when normal systems are impaired.

The institutional perimeter of preparedness must also broaden. A technologically driven financial crisis may require coordination among banking and cybersecurity authorities and, where necessary, critical private technology providers. DORA and its oversight of critical ICT third-party providers are important responses, but public oversight complements rather than substitutes banks’ own third-party risk management. Where banks rely on sophisticated external technologies, the policy objective is therefore not to eliminate dependence per se, but to ensure that the resulting vulnerabilities are well understood and effectively managed.

Conclusion

Digitalisation is changing not only the risks confronting banks but also the information, expertise and analytical approach required of supervisors. The central supervisory challenge is to understand how financial vulnerabilities interact with banks' technological infrastructure, external dependencies and exposure to a more unstable external environment. Faster reaction times, cross-border business models and concentrated technological dependencies matter because they affect both the nature of institution-specific vulnerabilities and the conditions under which these may translate into stress. 

The regulatory and supervisory response needs to adapt accordingly. Standard financial metrics remain essential, but need to be complemented by institution-specific assessments of funding structures, operational capacity, technological dependencies and information preparedness. This requires supervisors to combine traditional prudential expertise with stronger technological and data capabilities, while preserving proportionality and avoiding information requirements that impose costs without meaningful decision value.

Technological dependence also has a jurisdictional dimension, helping to explain why geopolitical risk has become intertwined with the supervisory agenda. Concentration of critical technologies in particular providers or jurisdictions can create channels through which geopolitical fragmentation translates into operational and ultimately financial vulnerabilities. Rather than attempting to predict every technological or geopolitical shock, supervision should focus on identifying institution-specific vulnerabilities and the potential trigger events that, given each bank's characteristics, could lead to severe outcomes.

This approach also places responsibility on banks. Understanding institution-specific vulnerabilities is a core risk-management and governance task for boards and senior management. This includes identifying critical technological dependencies and concentrations, maintaining credible contingency arrangements, ensuring that essential data remain accessible under stress, and incorporating technological, cyber and geopolitical scenarios into risk management. Supervisors, in turn, can challenge these assessments and identify common dependencies and concentrations across the banking system that may not be visible to individual institutions.

In an increasingly digital financial system, financial resilience, operational resilience and informational preparedness are becoming interconnected dimensions of the same supervisory and risk-management challenge.

References
Beck, T., Bruno, B. and Carletti, E. (2024), Can the Banking Union foster market integration, and what lessons does this hold for Capital Markets Union?, European Parliament, PE 760.259. https://www.europarl.europa.eu/thinktank/en/document/IPOL_IDA(2024)760259

Brancaccio, I., Bruno, B. and Carletti, E. (2026), The Future of European Banking between Competitiveness and Deregulation, Bocconi University IEP. https://iep.unibocconi.eu/future-european-banking-between-competitiveness-and-deregulation

Chang, J.-W. et al. (2025), Cyber Vulnerabilities at Large US Financial Institutions and Their Third-Party Service Providers, Federal Reserve Board, Finance and Economics Discussion Series, 2025-103.

Cookson, J.A., Fox, C., Gil-Bazo, J., Imbet, J.F. and Schiller, C. (2026), “Social Media as a Bank Run Catalyst”, Journal of Financial Economics, 176, 104218.

ECB (2025a), Supervisory priorities 2026–28, ECB Banking Supervision. https://www.bankingsupervision.europa.eu/framework/priorities/html/ssm.supervisory_priorities202511.en.html

ECB (2025b), ECB to assess banks’ stress testing capabilities to capture geopolitical risk, press release, 12 December 2025. https://www.bankingsupervision.europa.eu/press/pr/date/2025/html/ssm.pr251212~69f656d4bf.en.html

ECB (2026), Annual Report on Supervisory Activities 2025, ECB Banking Supervision. https://www.bankingsupervision.europa.eu/press/other-publications/annual-report/html/ssm.ar2025~6ee989dc7e.en.html

Fascione, L. et al. (2025), Mind the App: Do European Deposits React to Digitalisation?, ECB Working Paper No. 3092.

Financial Times (2026), “ECB summons banks to urge them to fix flaws exposed by latest AI models”, 25 May 2026.

Koont, N., Santos, T. and Zingales, L. (2024, revised August 2025), Destabilizing Digital ‘Bank Walks’, NBER Working Paper No. 32601.

Rose, J. (2023), “Understanding the Speed and Size of Bank Runs in Historical Comparison”, Economic Synopses, No. 12, Federal Reserve Bank of St. Louis.


Brunella Bruno is a researcher with tenure in Bocconi University’s Department of Finance and holds the Italian National Scientific Habilitation (ASN) as Full Professor in Financial Markets, Financial Institutions and Corporate Finance. She is a Research Fellow at the Baffi Centre and a Fellow at the Institute for European Policymaking (IEP) at Bocconi. Her primary research interests are in empirical banking, with a focus on the effects of regulation and supervision on bank behaviour. She is also a member of the European Parliament’s Expert Panel on banking supervision and, in this capacity, the author of several in-depth analyses on European banking and supervisory issues.

Brunella Bruno

Elena Carletti is Professor of Finance and Dean for Research at Bocconi University. She serves as Deputy Vice Chair of the Board of Directors of UniCredit Group, where she also chairs the Risk Committee. She is also Director of the Banking and Corporate Finance Programme at the Centre for Economic Policy Research (CEPR) and Chair of the Scientific Committee at Bruegel. She also serves as an external evaluator for several central banks, particularly in the areas of economics, financial stability, and research. 

Professor Carletti founded the Florence School of Banking and Finance at the European University Institute. She is a former member of the European Parliament’s Expert Group on Bank Supervision and a past President of the European Finance Association. From 2015 to 2023, she served on the Advisory Scientific Committee of the European Systemic Risk Board (ESRB), and from 2015 to 2021, she was a member of the Scientific Committee of the Bank of Italy’s "Paolo Baffi Lecture".  

Elena Carletti