Japan's Financial Watchdog Says Technology Failures Have Become a Management Problem

Japan's Financial Watchdog Says Technology Failures Have Become a Management Problem

By
Key Takeaways
  • Technology Risk Is Now a Board-Level Issue: The FSA says IT risk and cyber risk should be treated as top management priorities, requiring ongoing oversight from boards and senior executives rather than remaining solely the responsibility of IT departments.
  • Operational Resilience Has Become the Focus: The report shifts attention from analyzing why systems fail to ensuring financial institutions can maintain critical operations, recover services quickly and minimize customer impact when disruptions occur.
  • Third-Party Dependencies Are Increasing Risk: Growing reliance on cloud services, outsourced providers and interconnected digital infrastructure is creating new operational and cybersecurity risks that require stronger governance and oversight.
  • Cyber Threats Continue to Evolve: The report highlights AI-driven cyber threats, unauthorized account access, fraudulent transactions and the need for more robust third-party cybersecurity risk management, while also examining the transition to post-quantum cryptography.
Deep Dive

A banking outage used to be the sort of event that invited an engineering postmortem. Something broke, someone fixed it, and a report followed. Japan's Financial Services Agency no longer believes that sequence tells the whole story.

Its latest Analytical Report on IT Resilience in the Financial Sector reads as though the regulator has quietly shifted the question. The concern is no longer simply why systems fail, but what those failures reveal about the way financial institutions are governed, how dependent they have become on technology they do not fully control, and whether their leadership understands that operational resilience has become inseparable from financial resilience.

Since 2019, the FSA has published annual analyses of system failures at financial institutions, using breakdowns as opportunities to identify recurring weaknesses. Last year, it reorganized the exercise under a broader title focused on IT resilience. The 2026 edition pushes that evolution further, reflecting a world in which the boundaries between technology risk, cyber risk, geopolitical instability and third-party dependency have become increasingly difficult to separate.

Banks now conduct more of their business through digital infrastructure than ever before. Customer services, payment systems, cloud platforms and outsourced providers have become woven together so tightly that a weakness in one corner can ripple far beyond its point of origin. The report argues that this growing complexity is producing risks capable of reaching beyond individual firms and affecting the stability of the financial system itself.

That is why the document spends as much time discussing governance as technology. The report examines system failures, assesses the maturity of IT governance, reviews cybersecurity findings from inspections and supervisory monitoring, and explores cloud resilience through dedicated exercises.

It also looks beyond immediate operational concerns to emerging issues, including the cybersecurity implications of artificial intelligence, stronger oversight of third-party cyber risk, unauthorized access to customer accounts, fraudulent transactions and the financial sector's eventual migration toward post-quantum cryptography.

Running through each of those subjects is the same quiet insistence that technology decisions have escaped the confines of the IT department. The FSA says boards and senior executives should regard IT risk and cyber risk as management priorities, requiring sustained attention to governance, risk management, investment, workforce development and oversight of third-party providers. It is a notable shift in tone from regulators that once treated operational resilience largely as a matter of technical controls.

The report is equally clear about something else. Preventing every disruption is no longer considered a realistic objective. Financial institutions, the agency says, should assume that outages and cyber incidents will occur despite preventive measures. The measure of resilience is therefore not whether an organization avoids disruption altogether, but whether it can continue critical operations, restore services quickly and limit the consequences for customers when those moments inevitably arrive.

That assumption changes the conversation. An outage stops being evidence that prevention failed and becomes a test of whether the institution prepared for the possibility that prevention would fail.

The FSA leaves little doubt about the role it intends to play. Alongside inspections and supervisory monitoring, it says it will continue supporting resilience through information sharing, guidance and industry-wide exercises intended to strengthen preparedness across Japan's financial sector. The report ultimately asks financial institutions to think less about building systems that never break than about building organizations capable of absorbing the moment when they do. For a regulator that once catalogued failures after the fact, that is a distinctly different ambition.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

Oops! Something went wrong