The European Supervisory Authorities' Autumn 2026 risk update has exposed vulnerabilities that many GRC leaders thought they'd already addressed. The findings reveal a gap between what financial institutions believe about their external dependencies and what those dependencies actually mean for operational resilience. These misconceptions persist partly because regulatory frameworks have evolved faster than organizational understanding, and partly because the risks themselves have shifted with geopolitical tensions and emerging technologies.
Let's examine what you might be getting wrong.
Myth 1: Geographic diversification of investments equals reduced dependency risk
Reality: Your fund exposures tell only part of the story. The ESAs found that while bond funds show geographic diversification, equity UCITS and alternative investment funds maintain substantial exposures to the US. More critically, the infrastructure supporting those investments concentrates risk in ways your asset allocation doesn't capture.
Clearing, repo, and credit ratings markets remain largely intermediated by non-EU entities. You're not just exposed to foreign assets; you're dependent on foreign operational infrastructure to value, settle, and assess those assets. When geopolitical tensions rise, this infrastructure dependency creates vulnerabilities that diversified holdings can't mitigate.
The insurance sector demonstrates this principle clearly. While global interconnectedness appears contained overall, it's primarily asset- and reinsurance-driven. Those links bring diversification benefits, but they simultaneously increase market, counterparty, and concentration risks. Your geographic spread doesn't eliminate the systemic dependencies embedded in how you access those markets.
Myth 2: ICT service provider contracts are primarily a procurement issue
Reality: Your reliance on non-EEA ICT service providers represents a strategic vulnerability, not a vendor management checkbox. The ESAs specifically warn that this dependence could amplify the impact of geopolitical shocks and operational disruptions.
Banks face funding gaps in non-EU currencies, mainly in USD, GBP, and CHF, because of household and non-financial corporation deposits. Your payment systems likely run through non-EU infrastructure. Your clearing mechanisms depend on entities outside EU regulatory reach. This isn't about contract terms or service-level agreements. It's about whether your critical operations can continue when geopolitical events disrupt access to providers or infrastructure you can't replace quickly.
The concentration of dependence on non-EEA ICT providers heightens cyber risks in ways traditional vendor assessments don't address. You're not evaluating individual supplier security postures. You're managing systemic dependency on a small number of providers that many of your peers also use, creating concentration risk across the sector.
Myth 3: AI-enabled cyber threats are a future concern you can address incrementally
Reality: The rapid development of advanced AI systems is making cyberattacks more powerful and harder to contain right now. Malicious actors can identify and exploit vulnerabilities at unprecedented speed. Your current incident response timelines assume human-speed reconnaissance and exploitation. That assumption no longer holds.
For insurers, this creates immediate challenges in cyber-insurance underwriting. In a context of severe geopolitical instability, added frequency and severity of orchestrated AI-enabled cyberattacks could increase claims and accumulation risks. Exclusion clauses might limit impacts, but they also signal that traditional risk transfer mechanisms aren't keeping pace with threat evolution.
Quantum computing presents an even more compressed timeline. It could undermine cryptography systems widely used to secure communications, transactions, databases, and blockchains. The ESAs note that risks could materialize faster than any commercially viable application. You can't wait for quantum computing to become mainstream before addressing quantum-resistant cryptography. The threat arrives before the benefit.
Myth 4: Private credit exposure is minimal because EU markets remain small
Reality: The EU private credit market's relatively small size obscures growing vulnerabilities. The sector continues to expand rapidly as a source of financing globally, and your exposure extends beyond direct EU market participation.
Banks and insurers show limited aggregate exposures in EU private credit, but risks arise from exposures to the larger US private credit market. You face credit risks through shared borrowers and financing commitments to private credit vehicles. Liquidity mismatches in private credit funds could amplify redemption pressures and generate spillovers to banks through funding and common exposures.
The vulnerabilities stem from increasing complexity, limited transparency, and interlinkages across the financial system. Infrequent and potentially inaccurate loan valuations create uncertainty. High credit risk combines with uncertainty about leverage across the value chain. Data gaps affect both market participants and regulators, meaning you can't rely on supervisory oversight to identify concentration before it becomes critical.
Myth 5: Strong fundamentals in banking, insurance, and investment funds mean the system is resilient
Reality: The ESAs confirm that EU investment funds remained resilient throughout recent volatility, insurance and pension sector fundamentals stayed strong, and European banks operate from positions of strength with high capital ratios and strong profitability. But resilience under current conditions doesn't equal resilience under stress scenarios that haven't yet materialized.
Banks maintain low levels of Non-Performing Loans, but expectations of asset quality deterioration exist in certain portfolios, particularly Commercial Real Estate and Small and Medium-sized Enterprises. Banks reflect these concerns in their impairment overlays. More frequent natural catastrophes could widen protection gaps in insurance, reinforcing the need for stronger action on adaptation that hasn't yet occurred.
Your current capital position addresses known risks. The ESAs' warnings focus on dependencies and emerging threats that your capital models don't fully capture because the stress scenarios are unprecedented or inadequately understood.
What to do instead
Stop treating external dependencies as vendor management and start treating them as strategic resilience questions. Map your dependencies on non-EEA ICT providers, payment systems, and clearing mechanisms. Identify where concentration creates single points of failure. Assess whether you could continue critical operations if geopolitical events disrupted access to specific providers or infrastructure.
For AI and quantum computing risks, accelerate your timeline. Implement AI-aware threat detection that assumes adversaries move faster than your current incident response can handle. Begin quantum-resistant cryptography planning now, before the threat fully materializes.
On private credit, improve your visibility into indirect exposures through shared borrowers and fund commitments. Press for better transparency from private credit vehicles where you have exposure. Build stress scenarios that account for liquidity mismatches in private credit funds spilling over to your institution.
The ESAs call on supervisors and market participants to strengthen resilience through crisis preparedness, resolution coordination, and more effective and adaptable regulation. That means your GRC program needs to move from compliance verification to active resilience testing against scenarios your current frameworks don't fully address.





