Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Should Regulators Be Forced to Investigate Every Complaint?Regulatory Obligations Management
4 min readFor Third-Party Risk Managers

Should Regulators Be Forced to Investigate Every Complaint?

The Joint Board of Appeal recently dismissed an appeal against the European Banking Authority (EBA), ruling that the EBA's decision not to investigate a complaint about a Finnish authority's handling of a bank account closure was within its discretionary power and couldn't be challenged. The Board cited established EU case law: supervisory authorities decide which investigations to pursue, and those decisions aren't reviewable.

For third-party risk managers, this raises a critical question: when discretionary power sits with the regulator, who ensures the regulator acts?

The Question at Hand

Should European Supervisory Authorities be required to investigate every complaint alleging a breach of Union law by a national competent authority, or should they retain discretion over which matters warrant formal investigation?

This isn't just theoretical. When you're assessing a financial services vendor's regulatory standing, you're trusting that supervisory authorities will enforce the rules. If those authorities can decline to investigate without meaningful recourse, you need to account for that gap in your vendor risk profile.

The Case for Regulatory Discretion

Supervisory authorities operate with limited resources. The EBA, EIOPA, and ESMA oversee thousands of institutions across 27 member states. If they had to investigate every complaint, they'd spend their time chasing minor infractions while systemic risks went unaddressed.

Discretion enables prioritization. A regulator can focus on material breaches that affect market integrity or consumer protection, rather than individual account disputes. You see this in other regulatory contexts: the SEC doesn't investigate every Form D filing irregularity, and the FCA doesn't open enforcement actions over every customer complaint.

The Board of Appeal's decision reflects established EU case law for good reason. Courts have consistently held that investigative decisions involve complex assessments of regulatory priorities, resource allocation, and enforcement strategy. Forcing regulators to justify every non-investigation would create a second litigation track that consumes the resources meant for actual supervision.

There's also a practical argument: discretion prevents abuse of the complaint mechanism. Without it, you'd see strategic complaints filed to tie up regulatory resources or harass competitors. The ability to screen complaints protects the system from being weaponized.

The Case Against Unchecked Discretion

Discretion without accountability creates blind spots in your vendor risk assessment process.

When you conduct third-party due diligence on a European financial institution, you check for regulatory actions, enforcement history, and supervisory findings. You're looking for red flags. But if a national competent authority mishandles a compliance matter and the EBA declines to investigate, that incident never appears in the public record. The vendor's regulatory profile looks clean, but you're missing information that could indicate control failures.

The Board of Appeal ruled that its own review power doesn't extend to decisions not to investigate. That's a complete accountability gap. If the EBA can decline an investigation without stating its reasoning, and if that decision can't be appealed, then the complainant has no recourse and no transparency into why their concern was dismissed.

This matters more when the complaint alleges a breach by a national authority rather than by an institution directly. Cross-border supervision depends on national competent authorities enforcing EU law consistently. If the EBA won't investigate when a national authority allegedly fails to enforce those rules, who checks the checkers?

You can't build a reliable vendor risk program on the assumption that regulators always act. You need mechanisms that surface compliance failures even when supervisory authorities don't pursue them. The current framework doesn't provide that.

Where Practitioners Actually Land

Most third-party risk managers don't wait for regulatory enforcement to identify vendor issues. You're already building redundancy into your monitoring programs because you know supervisory action lags behind actual risk.

You're using ongoing vendor monitoring to track regulatory filings, media reports, and industry intelligence. You're not relying solely on whether the EBA opened an investigation. You're looking at the underlying facts: Did the vendor close accounts without proper notice? Did the national authority respond adequately to complaints? Those questions matter regardless of whether the EBA exercised its discretion to investigate.

You're also factoring regulatory discretion into your risk ratings. A vendor operating under a national competent authority with a weak enforcement record gets a different risk score than one supervised by a more active regulator. You can't control whether the EBA investigates, but you can control how much weight you place on the absence of enforcement actions.

The practical middle ground involves treating regulatory oversight as one input among many, not as the definitive measure of vendor compliance. If you're waiting for the EBA to investigate before you identify a vendor risk, you've already failed.

Our Take

The Board of Appeal's decision is legally defensible but operationally troubling. Regulators need discretion to function, but discretion without transparency creates information asymmetries that make vendor risk management harder.

The better approach would preserve discretion while requiring minimal procedural accountability. The EBA should be required to acknowledge receipt of complaints and provide a brief statement of its decision not to investigate. That doesn't mean justifying every prioritization call in detail, but it does mean creating a record that stakeholders can reference.

For your vendor risk program, this decision reinforces what you already know: regulatory oversight is a lagging indicator. You can't outsource due diligence to supervisory authorities. Build your monitoring program to surface compliance issues independently, and treat the absence of regulatory action as a data point, not as proof of compliance.

The discretionary power of supervisory authorities is here to stay. Your job is to manage vendor risk in a world where that power exists, not to wait for a system where every complaint gets investigated. Adjust your control expectations accordingly.

European Banking Authority European Securities and Markets Authority

Promotional banner for the Penetration Report Template Kit

You Might Also Like