What might the Central Bank of Ireland’s thematic inspection priorities look like in 2026?
The Central Bank’s (the CBI) Regulatory & Supervisory Outlook (RSO) 2025 lays out cross-cutting risks (liquidity/valuation, cyber/fraud, AI/data, business-model sustainability) and confirms an integrated supervisory approach from 2025. Thematic work will therefore cut across prudential, conduct and resilience dimensions, mirroring the CBI’s PRISM’s (the CBI’s risk-based framework for supervision) risk-based DNA.
European coordination will shape scope and timing: European Securities and Markets Authority’s (ESMA) Common Supervisory Action (CSA) looking at the effectiveness of the second and third lines, Liquidity Management Tools (LMT)/ Money Market Funds deliverables, European Banking Authority’s (EBA) Digital Operational Resilience Act (DORA) build-out, and the European Central Bank’s (ECB) 2025–27 priorities provide the templates and the momentum for Irish thematic inspections.
Looking forward, five thematic inspection priorities for 2026 present themselves, anchored in the Bank’s holistic risk lens, the shift to an integrated supervisory model, and alignment with ESMA, EBA, ECB and European Insurance and Occupational Pensions Authority (EIOPA) programmes.
1) Digital operational resilience & third-party risk
Why it’s hot: From January 2025, the CBI reorganised supervision to be more integrated and outcomes-focused, with resilience a cross-sector priority. EU supervisors will apply DORA in a risk-based, coordinated way (see EIOPA’s Union-wide Strategic Supervisory Priorities and the ECB’s European Supervisory Examination Programme), and the EBA is building the oversight machinery for critical Information and Communication Technology (ICT) providers. Expect testing of ICT risk management, major incident handling, threat-led penetration testing (TLPT), and third-party/outsourcing controls.
What an inspection could look like: population questionnaires on ICT frameworks and dependency mapping; on-site file reviews of incident logs, playbooks, TLPT scoping, and board MI; sample testing of critical vendor oversight and exit/contingency plans.
2) Liquidity, leverage & valuation in market-based finance (funds)
Why it’s hot: The CBI’s 2025 Outlook flags concerns about opacity and reliability of valuations for illiquid assets and the potential for liquidity events under stress. ESMA’s 2025 programme prioritises Regulatory Technical Standards/ guidelines for LMTs and updates to MMF stress testing—setting the tone for National Component Authority work.
What an inspection could look like: cross-firm reviews of valuation governance, model adjustments, and price challenge; testing design/use of LMTs, swing pricing calibration, and liquidity bucketing; assessment of leverage monitoring and stress scenarios.
3) Governance, control effectiveness & integrated assurance (second and third line effectiveness)
Why it’s hot: The RSO reiterates an integrated, risk-based supervisory approach. ESMA’s 2025 CSA on Compliance & Internal Audit will drive coordinated checks on whether firms’ second and third lines are effective, resourced, and independent—an obvious springboard for CBI thematic work (especially in funds and markets).
What an inspection could look like: evaluation of compliance monitoring plans, audit charters/independence, reliance rules between lines, assurance maps, and a single issues/actions register; evidence of board-level combined assurance reporting and timely remediation.
4) Conduct & investor/consumer protection (product governance, distribution, conflicts)
Why it’s hot: The Outlook frames consumer/investor protection as a core outcome, noting data-driven conduct risks and the need for robust product oversight. ESMA’s 2025 work also emphasises retail investor safeguards and outputs under the Markets in Financial Instruments Directive II (MiFID II) and the Markets in Financial Instruments Regulation (MiFIR) and the Alternative Investment Fund Managers Directive (AIFMD) and Undertakings for Collective Investment in Transferable Securities (UCITS). EIOPA has declared a value-for-money focus. Expect convergence on product governance and disclosures.
What an inspection could look like: review of product approval and target-market articulation, value-for-money assessments, conflicts management (including inducements), suitability/appropriateness testing, distribution oversight (including intragroup), and complaint/breach trends.
5) Cyber, data & AI risk (model governance, privacy, fairness)
Why it’s hot: The 2025 RSO dedicates a spotlight to AI—highlighting governance, explainability, bias, data protection and broader resilience linkages—as well as the growing threat of fraud. ECB priorities for 2025–27 also call out digital-transformation risk management, reinforcing cross-border expectations for Irish banks within the Single Supervisory Mechanism (SSM).
What an inspection could look like: inventories of AI/advanced analytics use-cases; model risk governance (policies, validation, monitoring, drift); data quality/lineage controls; privacy impact assessments; cyber controls around privileged access and identity; fraud detection and response MI.
Board Takeaways
- Prioritise readiness reviews for evidence packs across the five themes.
- Ensure Board MI integrates control effectiveness, assurance gaps, and remediation status.
- Expect cross-functional CBI on-sites: business, risk, compliance, internal audit, and IT leadership will all be engaged.
- The CBI expects boards to demonstrate challenge, not just approve frameworks.
Let’s Talk
If you would like to discuss how we can help you with your readiness reviews please do get in touch at contact@VPP.ie