The Basel Committee published its 23-page range-of-practices report on ICT risk management on 2 June 2026, produced under the 2025–26 work programme and focused on non-malicious ICT incidents affecting critical bank operations, complementing its 2018 cyber-resilience report. It identifies skills and control challenges in cyber security, cloud, AI/ML, and legacy systems, records that banks are embedding AI/ML tools in ICT risk management for predictive failure detection and change testing, and stresses that human oversight remains critical. The accompanying press release commits the Committee to keep monitoring AI model developments and their implications for bank cyber security.
| Document | BCBS ICT Risk Management Report (June 2026) — Information and communication technology risk management: range of practices |
| Issued by | Basel Committee on Banking Supervision (BCBS) |
| Type | Report |
| Status | Final |
| Published | Jun 2, 2026 |
| Applies to | Banks and supervisors in Basel member jurisdictions; range-of-practices report, no new standards |
| Official source | bis.org ↗ |
| Use cases | Cybersecurity · AI governance (general) · Generative & agentic AI |
What are the key points of BCBS ICT Risk Management Report (June 2026)?
- Scope: observed ICT risk-management practices across jurisdictions for non-malicious incidents (outages, change failures, capacity problems), as a companion to the 2018 cyber-resilience range-of-practices report (d454).
- Finds skills shortages 'particularly in cyber security, cloud, artificial intelligence / machine learning (AI/ML), and legacy systems', worsened by competition with the technology industry.
- Reports banks implementing automation 'including through new technologies and AI/ML, while maintaining an appropriate level of human oversight and control'.
- Industry outreach: AI/ML is used to scan for issues, predict failures, improve response times, and detect blind spots in change testing; panellists said humans must interpret and prioritise AI signals.
- Positions robust ICT risk management as a critical component of operational risk management under the Committee's operational-resilience framework.
- Agreed at the 19–20 May 2026 meeting, where the Committee also noted frontier AI models' potential to change the speed and scale of cyber incidents.
What did BCBS ICT Risk Management Report (June 2026) change for banks?
The report is the Committee's first document to describe AI/ML as a tool inside bank ICT risk management rather than only as a risk source, and it sets a Basel-level expectation that AI-driven monitoring keeps a human in the loop. It also formalises the Committee's watch on frontier AI and cyber, which is the most likely trigger for future Basel action on AI.
Does the Basel ICT risk-management report set new requirements?
No. It is a range-of-practices report describing what supervisors observed, intended as a reference for banks and supervisors under existing operational-risk and resilience principles.
What does the Basel Committee say about AI and cyber security in 2026?
In May 2026 it noted that frontier AI models could help banks and supervisors find vulnerabilities but that malicious use may materially change the speed and scale of cyber incidents, and it will continue monitoring AI model developments.
| Date | Document | Status |
|---|---|---|
| Jan 6, 2026 | BCBS 239 Implementation Newsletter (Jan 2026) — Implementation of the Principles for effective risk data aggregation and risk reporting (BCBS 239 Principles) | Final |
| Dec 10, 2025 | BCBS Third-Party Risk Principles (Dec 2025) — Principles for the sound management of third-party risk | In force |
| Feb 4, 2025 | BCBS Work Programme 2025–26 — Basel Committee work programme and strategic priorities for 2025/26 | In force |
| May 16, 2024 | BCBS Digitalisation of finance report (May 2024) — Digitalisation of finance | Final |
| Mar 16, 2022 | BCBS AI/ML Newsletter (March 2022) — Newsletter on artificial intelligence and machine learning | Final |
| Mar 31, 2021 | BCBS Principles for Operational Resilience (2021) — Principles for Operational Resilience | In force |
Follow every document these regulators publish
6 curated AI stories for banking executives · Every morning · Free
Subscribe to BankingNewsAI →