# BCBS ICT Risk Management Report (June 2026): Information and communication technology risk management: range of practices

Source: https://www.bankingnewsai.com/ai-regulation/documents/bcbs-ict-risk-management-range-of-practices-2026
Last updated: Aug 26, 2026

The Basel Committee published its 23-page range-of-practices report on ICT risk management on 2 June 2026, produced under the 2025–26 work programme and focused on non-malicious ICT incidents affecting critical bank operations, complementing its 2018 cyber-resilience report. It identifies skills and control challenges in cyber security, cloud, AI/ML, and legacy systems, records that banks are embedding AI/ML tools in ICT risk management for predictive failure detection and change testing, and stresses that human oversight remains critical. The accompanying press release commits the Committee to keep monitoring AI model developments and their implications for bank cyber security.

## At a glance

| Field | Value |
| --- | --- |
| Authority | [Basel Committee](https://www.bankingnewsai.com/ai-regulation/basel-committee) |
| Type | Report |
| Status | Final |
| Published | Jun 2, 2026 |
| Applies to | Banks and supervisors in Basel member jurisdictions; range-of-practices report, no new standards |
| Official text | https://www.bis.org/bcbs/publ/d611.htm |

## Key points

- Scope: observed ICT risk-management practices across jurisdictions for non-malicious incidents (outages, change failures, capacity problems), as a companion to the 2018 cyber-resilience range-of-practices report (d454).
- Finds skills shortages 'particularly in cyber security, cloud, artificial intelligence / machine learning (AI/ML), and legacy systems', worsened by competition with the technology industry.
- Reports banks implementing automation 'including through new technologies and AI/ML, while maintaining an appropriate level of human oversight and control'.
- Industry outreach: AI/ML is used to scan for issues, predict failures, improve response times, and detect blind spots in change testing; panellists said humans must interpret and prioritise AI signals.
- Positions robust ICT risk management as a critical component of operational risk management under the Committee's operational-resilience framework.
- Agreed at the 19–20 May 2026 meeting, where the Committee also noted frontier AI models' potential to change the speed and scale of cyber incidents.

## What changed for banks

The report is the Committee's first document to describe AI/ML as a tool inside bank ICT risk management rather than only as a risk source, and it sets a Basel-level expectation that AI-driven monitoring keeps a human in the loop. It also formalises the Committee's watch on frontier AI and cyber, which is the most likely trigger for future Basel action on AI.

## Use cases it governs

- [Cybersecurity](https://www.bankingnewsai.com/ai-regulation/by-use-case#cybersecurity)
- [AI governance (general)](https://www.bankingnewsai.com/ai-regulation/by-use-case#governance-general)
- [Generative & agentic AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#generative-agentic-ai)

## FAQ

### Does the Basel ICT risk-management report set new requirements?

No. It is a range-of-practices report describing what supervisors observed, intended as a reference for banks and supervisors under existing operational-risk and resilience principles.

### What does the Basel Committee say about AI and cyber security in 2026?

In May 2026 it noted that frontier AI models could help banks and supervisors find vulnerabilities but that malicious use may materially change the speed and scale of cyber incidents, and it will continue monitoring AI model developments.

## Related documents

- [BCBS 239 Implementation Newsletter (Jan 2026)](https://www.bankingnewsai.com/ai-regulation/documents/bcbs-newsletter-bcbs239-implementation-2026) — Implementation of the Principles for effective risk data aggregation and risk reporting (BCBS 239 Principles) (Jan 6, 2026)
- [BCBS Third-Party Risk Principles (Dec 2025)](https://www.bankingnewsai.com/ai-regulation/documents/bcbs-third-party-risk-principles-2025) — Principles for the sound management of third-party risk (Dec 10, 2025)
- [BCBS Work Programme 2025–26](https://www.bankingnewsai.com/ai-regulation/documents/bcbs-work-programme-2025-26) — Basel Committee work programme and strategic priorities for 2025/26 (Feb 4, 2025)
- [BCBS Digitalisation of finance report (May 2024)](https://www.bankingnewsai.com/ai-regulation/documents/bcbs-digitalisation-of-finance-2024) — Digitalisation of finance (May 16, 2024)
- [BCBS AI/ML Newsletter (March 2022)](https://www.bankingnewsai.com/ai-regulation/documents/bcbs-newsletter-ai-ml-2022) — Newsletter on artificial intelligence and machine learning (Mar 16, 2022)
- [BCBS Principles for Operational Resilience (2021)](https://www.bankingnewsai.com/ai-regulation/documents/bcbs-principles-operational-resilience-2021) — Principles for Operational Resilience (Mar 31, 2021)
- [BCBS 239](https://www.bankingnewsai.com/ai-regulation/documents/bcbs-239) — Principles for effective risk data aggregation and risk reporting (Jan 9, 2013)
- [Bailey: Frontier AI and the Question of Governance (Sep 2026)](https://www.bankingnewsai.com/ai-regulation/documents/boe-bailey-frontier-ai-governance-2026) — Frontier AI and the Question of Governance — Governor Andrew Bailey (Sep 30, 2026)

Last reviewed Aug 26, 2026. Cite the official text (https://www.bis.org/bcbs/publ/d611.htm) for the rule and this page for the summary and dates.

---

Canonical page: https://www.bankingnewsai.com/ai-regulation/documents/bcbs-ict-risk-management-range-of-practices-2026
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (41 authorities, 237 documents) and AI-strategy profiles of the 120 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
