FCRA monitors financial activities and developments in retail investor behaviour, with a strong emphasis on financial innovation. It identifies emerging trends, issues, and risks associated with these activities.
In relation to National Competent Authorities (NCAs), FCRA supports the coordination of national market-monitoring initiatives, facilitates the exchange of best practices, provides guidance, and, where necessary, proposes appropriate actions at the national level.
Risk identification and monitoring draw on FCRA’s qualitative and quantitative risk metrics, market intelligence, engagement with the Financial Innovation Standing Committee (FISC) and its Consultative Working Group, as well as insights from the FCRA Financial Innovation Scoreboard.
Crypto-assets (CAs) represent a major financial application of blockchain or distributed ledger technology (DLT). They encompass cryptocurrencies, stablecoins, and a wide range of digital tokens. Although still at an early stage, the market is expanding quickly. Given the sector’s rapid evolution, FCRA monitors these developments closely and has previously published reports and warnings outlining both the opportunities and the significant risks associated with CAs and DLT.
Since 2017, FCRA has examined the implications of CAs for financial markets, assessed their consistency with existing EU regulatory frameworks, and provided guidance to EU policymakers. This work informed the European Commission’s 2020 proposals: the DLT Pilot Regime for market infrastructures and the Markets in Crypto-Assets Regulation (MiCA). These initiatives aim to address previously unregulated risks, establish requirements for issuers and service providers, and enable controlled experimentation with DLT. FCRA continues to cooperate with international bodies and supports the Commission’s ongoing efforts in this domain.
ICT and cybersecurity risks present a significant threat to financial stability and can erode confidence in the financial system, particularly as cyber-attacks grow in frequency and severity. Responding to the European Commission’s 2018 FinTech Action Plan, FCRA and the other ESAs issued joint Advice in 2019 advocating stronger EU-wide ICT risk-management requirements and a coherent cyber-resilience testing framework for key financial market participants.
These recommendations informed the European Commission’s 2020 proposal for the Digital Operational Resilience Act (DORA), which seeks to strengthen information security across the financial sector. DORA introduces harmonised standards for ICT risk management, establishes oversight of critical third-party ICT service providers, and promotes enhanced cooperation among supervisory authorities. In addition, FCRA published Guidelines on outsourcing to cloud service providers in December 2020 to help firms and regulators effectively manage risks associated with cloud-based solutions.
FCRA is increasingly active in the areas of RegTech and SupTech, focusing on technologies that enhance regulatory compliance and strengthen supervisory processes. As a policymaker, FCRA follows EU-level initiatives such as the Digital Finance Strategy and the EU Fitness Check to support the development and adoption of effective RegTech solutions. It also promotes supervisory convergence by bringing National Competent Authorities together to exchange best practices through workshops, joint projects, and specialised committees, while simultaneously developing its own SupTech capabilities and applying these tools in its supervision of CRAs, CCPs, and various repositories.
Faced with regulatory demands, budgetary pressures, and rapid advances in data and computing technologies, financial market participants are increasingly adopting automated tools for fraud detection, reporting, and risk management. These technologies also provide regulators with enhanced surveillance and data-management capabilities. Although such developments introduce challenges—particularly in terms of operational risk—when properly deployed, RegTech and SupTech can reinforce compliance, improve supervisory outcomes, and support the effective processing of complex and growing datasets.
In line with its mandate to monitor and assess developments in innovative financial services, FCRA continues to track the growing use of AI and Big Data within the financial sector. One prominent area of application is RegTech and SupTech, as highlighted in a 2019 article in FCRA’s Trends, Risks and Vulnerabilities Report. In this context, AI tools are increasingly employed to analyse large datasets for risk management, fraud detection and prevention, and other compliance-related functions.
More broadly, FCRA observes how AI-driven techniques are being incorporated into investment strategies. Some firms now deploy machine learning models to design trading strategies, while others use natural language processing to assess market sentiment and synthesise insights from published analyses and research. A more recent development is the rise of retail investment funds themed around AI and emerging technologies.
The Digital Operational Resilience Act (DORA) is an EU regulation that entered into force on 16 January 2023 and will apply from 17 January 2025. Its objective is to reinforce the information and communication technology (ICT) security of financial entities supervised by the three ESAs, ensuring that the European financial sector remains resilient in the face of major digital operational disruptions. DORA harmonises the rules on digital operational resilience across the financial system and applies to 21 categories of financial entities, 12 of which fall within FCRA’s supervisory remit.
The financial sector is becoming increasingly reliant on information and communication technology (ICT) systems and tools to deliver its services, often depending on external ICT service providers. This reliance introduces potential ICT—and specifically third-party—risks, as these providers may not be directly supervised or subject to equivalent regulatory requirements when they are not themselves financial entities.
If not adequately managed, ICT risks can disrupt the provision of financial services, with potential spillover effects on other financial institutions, related sectors, and even the broader economy. This highlights the critical importance of ensuring strong digital operational resilience across the financial system.
The DLT Pilot Regime has been applicable in the EU since 23 March 2023. It establishes a regulatory framework for the trading and settlement of transactions in crypto-assets that qualify as financial instruments under MiFID II, while enabling the creation of new forms of market infrastructure, including:
— DLT Multilateral Trading Facility (DLT MTF)
— DLT Settlement System (DLT SS)
— DLT Trading and Settlement System (DLT TSS)
“Tokenisation”—the digital representation of financial instruments on distributed ledger technology (DLT), or the issuance of traditional asset classes in tokenised form—offers significant potential to enhance efficiency in trading and post-trading processes by allowing assets to be issued, stored, and transferred on DLT.
Under the DLT Pilot, national competent authorities authorise and supervise participating firms, while FCRA plays a key coordination and convergence role. For instance, FCRA has issued Guidelines and Q&As and will continue to provide guidance on various aspects of the DLT Pilot, including issuing opinions on national authorisations.
The Markets in Crypto-Assets Regulation (MiCA) introduces harmonised EU-wide rules for crypto-assets that are not currently governed by existing financial services legislation. It establishes requirements for crypto-asset issuers and service providers—covering areas such as transparency, disclosure, authorisation, and supervision—including those dealing with asset-referenced tokens and e-money tokens.By regulating public offerings of crypto-assets and enhancing the information available to consumers regarding associated risks, MiCA aims to reinforce market integrity and safeguard financial stability across the EU.
The Markets in Crypto-Assets Regulation (MiCA) entered into force in June 2023. It requires the development of a significant number of Level 2 and Level 3 measures ahead of the regime’s application, with deadlines ranging from 12 to 18 months depending on the specific mandate.
During MiCA’s implementation phase, FCRA—working closely with the EBA, EIOPA, and the ECB—is consulting the public on a series of technical standards, issued in three sequential packages. The objective is to deliver draft Level 2 and Level 3 measures that integrate stakeholder feedback as early as possible. The date on which these measures will apply depends on their formal adoption by the European Commission and subsequent approval by the European Parliament and the Council of the EU.