List your product on Stack Search

Get in front of thousands of GRC decision-makers

Basel Committee Finds Familiar Weaknesses Behind Bank Technology Failures

Basel Committee Finds Familiar Weaknesses Behind Bank Technology Failures

By
Key Takeaways
  • Basel Sharpens Its Focus on Non-Malicious ICT Failures: The Committee’s report examines technology incidents caused by operational failures rather than cyberattacks, including problems with software changes, testing, capacity and external dependencies.
  • Change Management Remains a Persistent Weakness: Change-control gaps were the most frequently cited root cause of ICT incidents, despite banks generally demonstrating mature change-management practices.
  • Third-Party Dependencies Complicate Resilience: Banks can be disrupted by failures beyond their direct control, while limited visibility into technology supply chains makes it difficult to understand where critical dependencies lie.
  • ICT Risk Is Now Firmly a Governance Issue: Banks across most surveyed jurisdictions have incorporated ICT risk into broader risk-management frameworks, with oversight extending to senior management and boards.
  • Basel Will Continue Watching AI and Digitalization: The Committee plans to continue monitoring financial technology and digitalization from a prudential perspective, including AI developments and their implications for bank cybersecurity.
Deep Dive

The Basel Committee on Banking Supervision is turning its attention to the technology failures that can disrupt banks without a cyberattack ever taking place, highlighting weaknesses in change management, system testing and third-party dependencies as persistent sources of operational risk.

In a report published June 2, the Committee examined how banks and supervisors across jurisdictions are managing non-malicious information and communication technology incidents that affect critical operations and services. The findings place ICT risk firmly within the broader question of operational resilience as banks become more dependent on increasingly complex and interconnected technology.

The Committee surveyed 16 jurisdictions and found no consistent trend in the number of non-malicious ICT incidents between 2022 and 2024. The causes, however, were more revealing. Change-control gaps were the most frequently cited root cause, followed by problems with system design, development and testing. System capacity and performance failures and external dependencies were also recurring sources of disruption.

Some of those failures carried consequences far beyond the technology department. In one case examined by the Committee, a system migration disrupted multiple banking channels and affected roughly 10% of the population in the jurisdiction. Another incident left critical banking operations unavailable for several days.

The report does not establish a new Basel standard or prescribe a single approach for banks. Instead, it brings together practices observed across jurisdictions, giving banks and supervisors reference points as they confront a problem that has become harder to separate from banking itself: the more financial institutions depend on technology to deliver their critical services, the less meaningful the distinction between an IT failure and an operational one.

There is something almost mundane about that list. These are not exotic vulnerabilities discovered at the frontier of banking technology. They are the old difficulties of changing complicated systems without breaking them, understanding what depends on what, and knowing whether a system will behave under pressure the way it behaved in testing. Digitalization has not made those problems disappear. It has given them more places to hide.

Change management is perhaps the clearest example. The Committee found that banks in most surveyed jurisdictions generally demonstrated mature approaches to managing ICT changes. Yet failures in change controls remained the most commonly reported cause of incidents.

The contradiction is less puzzling than it first appears. Banks are changing more technology, more often, across systems whose relationships are increasingly difficult to map. One internationally active bank told the Committee it implemented more than 5 million changes in 2025 while significantly reducing its failure rate. Some large banks have automated as much as 85% of standard, pre-approved and low-risk changes.

That sort of automation is becoming necessary simply to cope with the volume. Critical changes remain another matter. Banks described layers of governance around higher-risk work, including segregation of duties, dependency mapping, extensive testing in production-like environments, post-change validation and contingency planning. Previous incidents are also being fed back into change and problem-management processes so that a failure becomes, at minimum, something the institution should be less likely to repeat.

The difficulty is that a bank can control its own change process without controlling everything on which the bank depends.

One of the cases described by the Committee began not inside a bank but in a data center. Unsupervised modifications to cooling infrastructure contributed to rising temperatures, forcing an emergency shutdown. Several major banks hosted at the facility experienced disruptions.

It is a useful illustration of how ICT risk now travels. A bank may have sound internal controls and still inherit the operational weaknesses of a provider whose systems sit underneath its own. And the chain does not necessarily stop with the provider the bank knows. Suppliers have suppliers. Cloud environments, software providers, data centers and other technology services can create dependencies several layers removed from the institution that ultimately bears the disruption.

Banks have become better at cataloging what they own. The Committee found that they generally maintain hardware and software inventories and are increasingly using automated discovery and configuration-management tools. Knowing what exists, however, is not the same thing as understanding how everything fits together.

Banks continue to struggle with mapping critical business services all the way down to the technology assets that support them. Third parties make that work harder, particularly where institutions have limited visibility into the controls operated by their providers or into dependencies further down the supply chain.

That gap matters because operational resilience ultimately depends on relationships. A payment service does not exist as a box on an organizational chart. It exists through applications, infrastructure, data, employees, vendors and connections between them. A weakness buried several layers down can remain invisible until the moment it interrupts something customers and markets assumed would simply work.

The Basel Committee’s findings suggest that supervisors have largely accepted ICT risk on those terms. All 16 jurisdictions surveyed had banking-sector regulations or guidance covering ICT risk management, and most supervisory authorities use risk-based approaches combining measures such as on-site examinations, thematic reviews and off-site assessments.

Inside banks, ICT risk has also moved beyond the technology department. Most institutions covered by the survey had documented risk-management frameworks reviewed at least annually, with ICT oversight typically incorporated into broader risk arrangements and reporting reaching senior management and boards or board-level committees. Fourteen of the 16 jurisdictions reported that banks had established an ICT risk appetite or tolerances connected to wider enterprise frameworks and standards.

The governance architecture, in other words, is increasingly there. Banks told the Committee that shortages of people with the right expertise remain a problem, particularly in cybersecurity, cloud computing, artificial intelligence and machine learning, as well as the increasingly specialized work of maintaining legacy systems. They are competing for that talent with technology companies, including some of the same companies on which the banking sector has become more dependent.

Artificial intelligence complicates the picture further. Banks are beginning to use AI-enabled and real-time monitoring to detect anomalies before they become disruptions, while automation and machine learning may help institutions manage technology environments that have become too complex to oversee manually at every point. Industry participants also emphasized the need for human oversight, particularly where critical decisions are concerned.

The Committee plans to keep watching that development. It said it will continue exchanging supervisory insights on the digitalization of finance and financial technology from a prudential perspective, including developments in AI models and their implications for banks’ cybersecurity. But the most immediate lesson in the report is less futuristic.

Operational resilience can fail through an accumulation of very ordinary things: a change that was insufficiently controlled, software that behaved differently outside the test environment, infrastructure that reached its limit, or a provider whose own safeguards turned out not to be as dependable as the bank believed.

None of these failures requires malicious intent. That may be precisely why they deserve attention. Cybersecurity has taught banks to think carefully about the people trying to make their systems fail. ICT resilience asks them to confront the more uncomfortable possibility that, given enough complexity, the systems can manage that on their own.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

🔒
Cancel anytime
Full archive access
Custom alerts

Oops! Something went wrong