Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

Basel Committee Takes on AI Risk in Push to Modernize Bank Supervision

Basel Committee Takes on AI Risk in Push to Modernize Bank Supervision

By
Key Takeaways
  • AI Moves Deeper Into Basel’s Work: The Committee will review operational risk loss categories with a particular focus on AI and cyber risk as it monitors the technology’s growing role in banking.
  • Systemic Bank Rules Are Being Tightened: Basel approved revisions to the G-SIB assessment framework aimed at reducing year-end window-dressing, with publication expected later in October.
  • Pillar 3 Disclosures Are Going Machine-Readable: A final standard intended to make bank risk disclosures easier to aggregate, process and compare is expected around the end of 2026.
  • Cryptoasset and Interest Rate Work Continues: Basel expects an update on its targeted cryptoasset standard review by year-end and will consult in November on additional Pillar 2 guidance for interest rate risk in the banking book.
  • Supervision Itself Is Under Examination: Regulators are looking at modernization, proportionality and judgment-led supervision while also reviewing liquidity, AML/CFT practices and links between banks and non-bank financial institutions.
Deep Dive

The Basel Committee spent two days in Indonesia earlier this week looking at a banking system that is changing faster in some places than the rules written to govern it. Artificial intelligence was high on the agenda, but it was hardly alone. Cryptoassets, interest rate risk, liquidity, systemic banks, cyber risk and the quality of supervision itself all made the list.

The meeting on Sept. 28–29 produced several decisions that will begin showing up in the Basel framework over the coming months. The Committee approved a final standard for machine-readable Pillar 3 disclosures. It signed off on revisions intended to curb window-dressing by global systemically important banks. It agreed to consult on additional guidance for interest rate risk in the banking book. And it continued a targeted review of the rules governing banks’ cryptoasset exposures.

Then there was AI. The Committee said the financial footprint of the AI ecosystem is expanding rapidly, accompanied by greater use of leverage and increasingly interconnected financing arrangements. Inside banks, the concerns run closer to the machinery. Frontier AI could improve efficiency and innovation in financial services, but Basel warned that it could also amplify operational vulnerabilities, including those arising from cyberattacks and correlated dependencies across the financial system.

The deeper AI moves into critical financial functions, the more attention Basel expects banks and supervisors to pay. The Committee said its integration will require careful governance, robust risk management and ongoing supervisory attention. Basel is not proposing a separate AI regulatory regime. What it has decided to do, for now, is examine whether parts of the existing framework remain adequate as the technology develops.

The Committee will review the sufficiency and adequacy of the “event type” loss categories contained in its operational risk framework, specifically with cyber risk and AI developments in mind. It also plans to continue monitoring AI and discussing the implications for supervisors.

That discussion carried into the 24th International Conference of Banking Supervisors, held in Bali on Sept. 30 and Oct. 1. Almost 300 central bankers and banking supervisors representing more than 60 jurisdictions attended the conference, hosted by Bank Indonesia and the Indonesian Financial Services Authority.

There, the conversation widened. Participants compared how supervisors are using AI and how supervisory expectations are changing as the technology improves. They discussed the risks and potential efficiencies AI presents to banks, alongside cryptoassets and operational resilience. They also considered banks’ reliance on a small number of critical third-party service providers and the growing risks posed by cyberattacks and broader information and communication technology failures.

These were not presented as separate curiosities. They were part of a broader discussion about what digitalization asks of bank supervision when technologies, dependencies and business models move faster than supervisory practice traditionally has.

The End of the PDF Problem

One of the Committee’s more concrete decisions concerned a much older piece of technology i.e., PDFs. Internationally active banks publish Pillar 3 disclosures containing important information about their risk profiles. Those disclosures are supposed to promote market discipline by giving outside stakeholders access to key risk metrics. Yet most banks still publish them only in PDF format, which makes aggregating, processing and comparing information across institutions considerably harder than it needs to be.

Following an earlier consultation, the Committee approved a final standard for machine-readable Pillar 3 disclosures. The aim is to provide what Basel described as an innovative and efficient channel for bank disclosures. The final standard is expected around the end of 2026.

That decision also fits with a larger discussion underway among supervisors about modernization. At the Bali conference, participants considered whether parts of banking regulation and supervision have become unnecessarily complex and where simplification might be possible without weakening the resilience of the financial system.

The examples were practical rather than revolutionary. Focus more closely on material risks. Apply proportionality where appropriate. Improve transparency and comparability. Harness technological innovation responsibly. Subject requirements to rigorous cost-benefit analysis.

Basel Committee Chair Erik Thedéen, who is also Governor of Sveriges Riksbank, said the Committee is considering how to keep its governance and delivery mechanisms “results-oriented, relevant and responsive” to the changing needs of the global banking system.

What Happens When the Snapshot Lies

The Committee also turned to global systemically important banks, where an old supervisory problem remains stubbornly useful. Banks know when the photograph is being taken.

Basel approved the results of its end-2025 assessment of global systemically important banks, or G-SIBs. Those results will now be submitted to the Financial Stability Board before it publishes the 2026 list. But the Committee also approved revisions to the G-SIB assessment framework designed to reduce window-dressing. The concern is that year-end adjustments can affect the measurements used in the assessment framework without necessarily reflecting a bank’s position across the year.

Basel was direct about why that matters. Window-dressing by banks undermines the intended objectives of its standards and risks disrupting the operation of financial markets. The revisions are due to be published later in October.

A separate consultation will consider whether the G-SIB methodology should incorporate the treatment of cross-border exposures within the European banking union. That consultation is also expected later this month.

The two pieces of work concern different questions, but both go to the quality of the measurement itself. A framework for identifying systemic importance depends on the information it captures about the banks being measured.

Cryptoassets Remain Unfinished Business

Basel’s prudential treatment of cryptoassets is back under review, although the Committee is being careful about the scope of that work. It is examining targeted elements of its standard for banks’ exposures to cryptoassets and said it advanced that review during the Indonesia meeting. An update is expected by the end of the year. The Committee did not announce changes to the standard at this meeting.

Cryptoassets also surfaced at the Bali conference, where supervisors discussed the practical challenges of overseeing the risks they create. Participants exchanged views on supervisory approaches to cryptoassets as digitalization continues to alter banking activities.

Interest rate risk is further along. The Committee has been examining whether its 2016 standard on interest rate risk in the banking book, or IRRBB, is achieving what it was designed to do. Its empirical assessment identified specific shortcomings in banks’ management of that risk.

Basel will now consult on additional Pillar 2 guidance intended to strengthen implementation of the IRRBB framework by banks and supervisors. The consultation is expected in November.

Liquidity principles dating from the financial crisis are getting another look as well. The Committee is assessing targeted updates to its Principles for Sound Liquidity Risk Management and Supervision, published in September 2008. It is considering which aspects would benefit from updates to reflect regulatory, supervisory and structural developments since their publication and plans to provide an update later this year.

Supervision Gets Its Own Examination

A noticeable part of the discussion in Indonesia concerned what supervisors actually do with them. The Committee has developed additional voluntary supervisory tools covering credit risk and governance. They are intended to help authorities exchange information about supervisory practices and, where supervisors choose to use them, oversee risks at individual banks and tailor supervisory requirements to each institution’s size, complexity and risk profile.

That emphasis continued at the international conference, where participants discussed judgment-led and risk-based supervision. Recent revisions to Basel’s Core Principles for Effective Banking Supervision place greater emphasis on how supervisors exercise judgment to achieve effective supervisory outcomes.

There is an uncomfortable but useful point buried in that shift. More detailed rules do not necessarily produce better supervision. At some point, somebody still has to understand the bank.

Basel is also gathering evidence on how that judgment works in anti-money laundering and counter-terrorist financing supervision. The Committee recently surveyed 19 jurisdictions on AML/CFT risk assessment data and methodologies and held a related workshop. That work identified a range of approaches that Basel said enhance risk-based supervision and effective supervisory judgment. A summary of the results is due later in October.

Implementation of the existing Basel framework remains part of the work as well. Under the Regulatory Consistency Assessment Programme, the Committee approved reports examining implementation of the leverage ratio in Australia, Canada, Japan, Korea, Switzerland and the United Kingdom. Those reports are expected later this month.

The Bali conference added another problem that does not respect the traditional boundary of the banking sector. Supervisors discussed the links between banks and non-bank financial institutions, including recent trends involving synthetic risk transfers, approaches to overseeing and mitigating risks from those interconnections, and remaining data needs and gaps.

None of this amounts to a new Basel architecture. The Committee is doing something less tidy. It is working through individual places where existing standards and supervisory practices may need attention. A disclosure regime still dominated by PDFs. A systemic-bank methodology vulnerable to year-end window-dressing. Liquidity principles written in 2008. An operational risk framework now being reviewed with AI and cyber risk specifically in mind. Supervisors confronting technologies and financial relationships that continue to change beneath them.

Some of that work will produce guidance. Some could eventually produce changes to standards. Some is about improving the practice of supervision rather than writing another rule. For now, Basel has a crowded work program. Several of its next decisions are due before the year is out.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

🔒
Cancel anytime
Full archive access
Custom alerts

Oops! Something went wrong