Basel Committee Agrees to Publish ICT Risk Management Report and Advances Cryptoasset Standards Review
The headquarters building of the Bank for International Settlements in Basel, which hosts the Secretariat of the Basel Committee on Banking Supervision, Wikimedia Commons (Licensed under CC BY-SA 3.0).

The Basel Committee on Banking Supervision agreed to publish a report on observed information and communication technology risk management practices and to advance an expedited review of parts of its cryptoasset prudential standard, following its meeting in Basel on 19–20 May 2026. Its decisions were set out in a communiqué published on the Bank for International Settlements website.

The Committee said it approved a report on ICT risk management practices across jurisdictions addressing non-malicious ICT incidents, and that the report is scheduled to be published the following month. The document draws on comparative analysis of how supervised banks manage operational, technology and continuity risks arising from unintentional disruptions rather than deliberate attacks.

ICT INCIDENTS IN FOCUS

The publication of the report follows sustained attention from global standard-setters to the operational resilience of banks in the face of ICT incidents, spanning outages, software errors and dependencies on third-party service providers. The Committee's focus on non-malicious incidents complements the extensive work already under way internationally on cyber security and malicious threats and reflects hard-earned lessons from high-profile technology failures at large financial institutions.

The report is expected to identify common features of leading practice and to highlight areas where supervisors have observed gaps, without prescribing new binding standards at this stage. Its publication will provide a reference point for both banks and their supervisors as they refine internal frameworks and expectations around change management, testing, incident response and third-party oversight.

The Committee also discussed feedback received on its proposals for machine-readable Pillar 3 disclosures, and said it would provide a further update on that workstream later in 2026. The initiative aims to make regulatory disclosures more usable for investors and analysts by structuring them for machine consumption, reducing manual processing and enabling more consistent cross-firm comparisons.

CRYPTOASSETS AND LIQUIDITY PRINCIPLES ADVANCE

On the digital assets file, the Committee progressed an expedited review of targeted elements of the prudential standard for banks' cryptoasset exposures. The review is intended to keep the standard fit for purpose as market structures, product designs and risk profiles in crypto continue to evolve, with the Committee flagging the need for a timely response rather than a wait-and-see stance.

The Committee also agreed to consider targeted updates to its Principles for Sound Liquidity Risk Management and Supervision, a foundational document in the global framework. Any updates would build on lessons learned from recent episodes of banking stress rather than represent a wholesale overhaul of the existing principles, in keeping with the Committee's usual incremental approach to core standards.

Committee members concluded the two-day meeting by reaffirming their commitment to the full, timely and consistent implementation of Basel III across member jurisdictions. That message is a staple of the Committee's communications and reflects continuing sensitivity around divergences in implementation timing and scope across major banking centres.

Additional detail on the workstreams referenced in the communiqué will follow in the coming months, in line with the Committee's usual practice of publishing consultation papers and final standards as work matures. Banks, industry associations and other stakeholders will have opportunities to engage during any consultation phases that emerge from the streams flagged in the Basel meeting.