MiFID II Resilience: 2026 Standards & Compliance

by priyanka.patel tech editor

CBI Urges Irish Investment Firms to Bolster Operational Resilience Amid Rising Digital Threats

The Central Bank of Ireland (CBI) has called on MiFID investment firms to reassess their operational resilience frameworks, citing deficiencies in critical areas like service mapping and scenario testing. The findings, published on January 12, 2026, stem from a thematic assessment of the sector’s implementation of the CBI’s guidance on operational resilience, initially released in December 2021 and updated in July 2025 to align with the Digital Operational Resilience Act (DORA).

The CBI defines operational resilience as “the ability of a firm, and the financial services sector as a whole, to identify and prepare for, respond and adapt to, recover and learn from an operational disruption that affects the delivery of critical or important buisness services.” This assessment is a key component of the CBI’s supervisory work and reflects its priorities as outlined in its Regulatory and Supervisory Outlook 2025.

Positive Trends and Existing Frameworks

The CBI’s review revealed that many MiFID firms already have operational resilience frameworks in place that generally align with existing guidance and supervisory expectations. Boards were typically found to hold ultimate obligation for operational resilience, delegating tasks to appropriate committees and assigning functional responsibility to senior management. Regular reporting and challenge at both board and senior management levels were also noted as positive practices.

areas Requiring Betterment

Despite thes positives, the CBI identified several areas where firms need to enhance their preparedness. Deficiencies were found in:

  • The identification of critical or critically important business services.
  • The detailed mapping of how these services are delivered.
  • The depth and breadth of scenario testing.
  • The integration of operational resilience with existing risk management frameworks.

Specifically, the CBI noted that some mapping exercises lacked sufficient detail, hindering firms’ ability to pinpoint vulnerabilities and develop effective remediation plans. “Operational resilience is an evolution of operational risk and business continuity management and, in this very way, should be aligned with existing or developing frameworks in these areas,” a senior official stated.

CBI Guidelines and Next Steps

The CBI expects all MiFID firms to revisit their compliance with the existing guidance, including the recent DORA-related updates. The assessment highlighted three key guidelines for immediate attention:

  • Guideline 4: Firms must clearly identify their critical or critically important business services.
  • guideline 7: A thorough understanding and mapping of service delivery processes is essential.
  • Guideline 8: Mapping must account for dependencies on third-party providers.

Focus on Cyber and Digital Resilience

While the assessment didn’t specifically focus on DORA, cyber resilience, or digital operational resilience, the CBI emphasized that these areas remain paramount. The regulator plans further supervisory work in these domains between 2026 and 2027.

The CBI recognizes the increasingly complex and dynamic surroundings in which firms operate,citing the rapid evolution of technology,increasingly elegant threats,and the concentration risk associated with reliance on a limited number of third-party ICT providers. “Firms should take note of the above and review their operational resilience frameworks now,in readiness for further supervisory engagement in the coming year,” the CBI stated.

The regulator expects firms to strengthen their frameworks to ensure they can recover critical services from disruptions, minimize negative impacts, and protect customers. Firms should proactively review their operational resilience frameworks in anticipation of increased scrutiny.

.

For firms seeking assistance in reassessing and updating their operational resilience frameworks, specialized advisory services are available.

You may also like

Leave a Comment