What Irish banks should expect from CBI supervision in 2026

A man and woman looking at a document
  • Insight
  • 10 minute read
  • April 21, 2026

The CBI’s 2026 Regulatory and Supervisory Outlook and Dear CEO letter point to a year of deeper scrutiny for Irish banks. Early action on governance, resilience, consumer protection and risk management will be critical.

30–75%

AI-powered efficiency gains across risk and compliance processes.

75%

increase in monitoring efficiency by testing all transactions.

30%

reduction in issue turnaround times through real‑time monitoring.

70–90%

reduction in manual document review effort using AI automation.

The Central Bank of Ireland’s (CBI) 2026 Regulatory and Supervisory Outlook and Dear CEO letter signal a more intensive supervisory agenda for banks. While the core themes remain financial resilience, business model and strategy, operational resilience and financial crime, the emphasis has sharpened. Customer treatment and cyber resilience now stand out more clearly, reflecting digitalisation, new entrants and rising fraud risks. Banks that prepare early will be better placed to meet expectations and strengthen resilience.

What the CBI’s 2026 supervisory agenda means for Irish banks

Banks should anticipate an intensive supervisory approach. The scale and depth of engagement will be tailored to each institution’s significant institution (SI) or less significant institution (LSI) designation, business model, operational complexity and status of prior remediation work.

Supervisory engagement will include frequent direct engagement, expanded data-driven monitoring, targeted deep dives and on-site inspections. The ECB-SSM will drive several thematic reviews, alongside a reverse stress-testing exercise. These will be complemented by a range of CBI thematic reviews, particularly in fraud, conduct and AML/CFT. Banks should expect intensive supervisory activity across five areas:

  1. Business model and strategy
    Supervisors will continue to test the credibility and resilience of banks’ strategies, with a focus on:
    • Reviews of corporate strategy, including alignment with risk appetite, governance and the credibility of strategic assumptions.
    • Assessments of strategic positioning in response to evolving payments trends, including access to cash, P2P payment solutions, the digital euro, stablecoins and tokenisation initiatives.
    • Evaluation of the impact of CRD6 Article 21c on balance sheets, with institution-specific engagement depending on the nature and magnitude of the impact.
    • Scrutiny of new bank licence applications.
    • Assessments of growth strategies and new business lines, with a focus on consumer and investor protection, governance effectiveness, and operational and financial resourcing.
  2. Treatment of consumers
    Consumer outcomes remain a clear regulatory priority, with supervisory attention likely to focus on:
    • Reviews of root-cause analysis processes and how effectively lessons learned are embedded.
    • A thematic review of digital product sales via banking apps, assessing how risks to consumers are identified and mitigated.
    • Examination of customer service standards.
    • Cross-sector thematic work on customer communication effectiveness and the treatment of vulnerable customers.
    • Reviews of how banks safeguard customer interests in current account operations.
    • Review of buy now, pay later (BNPL) arrangements.
    • Examination of mortgage lending practices, including credit risk, underwriting quality and borrower risk.
  3. Operational and cyber resilience
    Operational and cyber resilience will remain a core supervisory priority, with different areas of focus for significant institutions (SIs) and less significant institutions (LSIs):
    1. Significant institutions
      • Targeted follow-up on institutions with material ICT, cyber security or outsourcing weaknesses.
      • On-site inspections of cyber security and third-party risk management, aligned with DORA expectations.
      • Threat-led penetration testing.
      • Targeted reviews of ICT change management.
      • Deep dives into cloud dependency and resilience planning for service disruption.
    2. Less significant institutions
      • Institution-specific follow-up to the 2025 operational resilience thematic review.
      • Ongoing monitoring of the remediation of outsourcing deficiencies.
      • Continued supervisory engagement following outages, including oversight of customer communications and support for vulnerable customers.
  4. Financial resilience
    Financial resilience will remain under close supervisory review, particularly in relation to:
    • SREP assessments incorporating CRR3/CRD6 changes, including, for SIs, the implementation of the revised Pillar 2 Requirement methodology.
      • Assessments of Pillar 1 capital requirements under CRR3 for both standardised credit risk and market risk.
      • Holistic assessments of financial resilience, including capital adequacy.
      • A review of progress on integrating climate and environmental risks into risk management frameworks and addressing identified deficiencies.
      • Ongoing remediation of RRARR shortcomings.
      • A sector-wide assessment of banks’ use of AI.
  5. Financial crime and market integrity
    Financial crime and market integrity will remain areas of sustained supervisory focus, including:
    • Review of banks’ enhanced AML/CFT risk evaluation questionnaires.
    • Targeted supervisory engagement and follow-up work.
    • Assessment of fraud controls and fairness in customer treatment.
    • Review of conflict-of-interest frameworks, particularly in wholesale banking.
    • Examination of market abuse controls and surveillance systems.
    • Reviews of unauthorised trading risks and the effectiveness of trading controls.

“The 2026 supervisory programme marks a shift from frameworks to proof. Banks will be expected to show how strategy, resilience and customer outcomes are delivered in practice.”

Sinead Ovenden,Financial Services Risk & Regulation Partner at PwC Ireland

Key actions firms can take today

With the Central Bank’s 2026 RSO signalling increased scrutiny and more intrusive supervision, Irish banks should move quickly to strengthen readiness. Banks that act early and proactively will be best positioned to demonstrate resilience, support smoother supervisory engagement and seize strategic advantage.

Banks should take a structured, forward-looking approach to the 2026 supervisory agenda by reviewing key RSO risk areas, assessing readiness, and ensuring risk management and governance documentation is current and readily accessible for supervisory engagement. Clear evidence of preparedness will reduce friction during inspections. Given the scale of planned supervisory activity through 2026 and into early 2027, banks must also ensure they have sufficient capacity and expertise across regulatory, risk, compliance, ICT and operational resilience teams to meet heightened supervisory expectations.

Actions should then be aligned to the main areas of supervisory focus:

  1. Strengthen strategic and business model preparedness
    Supervisors will assess the credibility and resilience of banks’ strategies. Banks should:
    • Reassess strategic plans and ensure alignment with risk appetite, capital plans and operational capacity.
    • Prepare for heightened scrutiny of payments innovation, digital money and business model transformation.
    • Analyse and document the potential impact of CRD6 Article 21c to support informed supervisory dialogue.
  2. Demonstrate excellence in consumer outcomes
    Consumer protection remains a core regulatory priority. Banks should:
    • Improve conduct frameworks, root-cause analysis and controls across digital sales channels.
    • Strengthen approaches to identifying and supporting vulnerable customers.
    • Refresh mortgage, BNPL and credit risk frameworks in advance of planned supervisory reviews.
  3. Accelerate operational and cyber resilience
    DORA and ICT resilience remain high on the supervisory agenda. Banks should:
    • Address legacy issues in cyber security, outsourcing and change management.
    • Advance DORA implementation, including testing, incident response and third-party risk management.
    • Strengthen cloud dependency planning and prepare for enhanced penetration testing and on-site inspections.
  4. Reinforce financial resilience
    Supervisors expect tangible progress in prudential risk and capital management. Banks should:
    • Update capital models and methodologies to reflect CRR3/CRD6 changes.
    • Enhance climate and environmental risk integration, including supporting data, scenarios and reporting.
    • Close gaps in recovery and resolution planning and strengthen AI governance and oversight.
  5. Enhance AML/CFT and market integrity frameworks
    Financial crime will remain an area of intensified supervisory focus. Banks should:
    • Refresh AML/CFT risk assessments, monitoring frameworks and supporting data quality.
    • Strengthen fraud prevention, detection and customer remediation capabilities.
    • Reinforce market abuse surveillance, conflicts of interest controls and unauthorised trading safeguards.

We’re here to help

As supervisory expectations intensify, banks will need clear governance, strong accountability and credible remediation to respond effectively. We support institutions as they prepare for the 2026 supervisory cycle, from inspection readiness and CRR3/CRD6 impact assessment to DORA implementation, consumer protection, AML/CFT, climate risk and AI governance.

Our teams work with banks to assess gaps, prioritise action and strengthen readiness across prudential, operational and conduct obligations. A proactive, evidence-based approach can help institutions respond with confidence, support more effective supervisory engagement and build resilience in a more demanding regulatory environment. Contact our team to discuss your priorities for the year ahead.

Risk and Regulation

Create a panoramic view of your unique risk landscape.

Follow PwC Ireland