Learning Objectives:

  • Explain the structure of the EU banking regulatory framework.

  • Identify key EU regulations and directives governing digital banking.

  • Understand the role of EU supervisory authorities.

2.1 The European Banking Union and the Single Rulebook

The EU has developed a comprehensive regulatory framework for banking, including the European Banking Union and the Single Rulebook . Key components include [citation:1,9]:

Single Supervisory Mechanism (SSM): The ECB directly supervises significant banks in the Eurozone . The SSM consists of the ECB and national competent authorities (NCAs) .

Single Resolution Mechanism (SRM): A framework for the orderly resolution of failing banks, including the Single Resolution Board (SRB) .

Single Rulebook: Harmonised prudential rules for all EU Member States, including the Capital Requirements Regulation (CRR) and the Capital Requirements Directive (CRD) .

2.2 Key EU Financial Services Regulations

The EU regulatory landscape includes several key regulations and directives affecting digital banking:

  • Payment Services Directive 2 (PSD2) and PSD3: Regulates payment services and promotes the development of open banking [citation:12,6]. PSD2 mandates strong customer authentication and secure communication standards .

  • Markets in Financial Instruments Directive II (MiFID II): Regulates investment services and markets, setting transparency and investor protection requirements [citation:2,6].

  • Digital Operational Resilience Act (DORA): Establishes uniform requirements for the digital operational resilience of the EU financial sector [citation:12,2,13]. DORA imposes obligations on financial entities and ICT service providers, particularly critical third-party providers .

  • Markets in Crypto-Assets Regulation (MiCA): Regulates the crypto-asset market, increasing investor protection and ensuring financial stability [citation:12,6].

  • General Data Protection Regulation (GDPR): Establishes comprehensive rules for data protection and privacy, with significant penalties for non-compliance [citation:2,4].

  • Insurance Distribution Directive (IDD): Requires insurance distributors to implement appropriate measures protecting customer information .

  • AI Act: Lays down harmonised rules on artificial intelligence, introducing obligations for high-risk AI system providers .

2.3 Supervisory Authorities

The European supervisory framework consists of three European Supervisory Authorities (ESAs):

  • European Banking Authority (EBA): Develops regulatory technical standards, promotes supervisory convergence, and conducts risk analysis and stress testing [citation:1,6]. The EBA’s Guidelines on ICT and security risk management have been revised to align with DORA .

  • European Securities and Markets Authority (ESMA): Oversees securities markets and provides guidance on regulations such as MiFID II and EMIR .

  • European Insurance and Occupational Pensions Authority (EIOPA): Oversees the insurance and pensions sector.


.