
Welcome to the FIG Top 5 at 5
The Top 5 at 5 is a weekly update in which members of the Financial Institutions Group (FIG) identify five of the key legal and regulatory developments relevant to the financial services industry from the preceding week.
Priority is given, in the first instance, to Irish based developments but the update will also include important developments in European law and regulation.
The topics chosen are dictated by the developments during the relevant period but priority is given to cross sectoral developments. The FIG Top 5 at 5 is not intended to represent all developments of note for the relevant period but rather a snap shot of some of the issues which we feel are of particular importance.
Should you have any queries in respect of the contents of the update, please do not hesitate to contact your usual Matheson LLP contact or any member of our team detailed below.
The Top 5 at 5
1. Central Bank publishes results of thematic review of liquidity risk management in MiFID sector
On 6 October 2026, the Central Bank of Ireland (“Central Bank“) published the results (“Results“) of a thematic review (“Thematic Review“) of liquidity risk management conducted on a sample of MiFID investment firms during 2025. The Thematic Review assessed whether the sample of firms were managing their liquidity risk exposures in line with the Joint European Banking Authority and European Securities and Markets Authority Guidelines for the supervisory review and evaluation process under the Investment Firm Directive (“Joint Guidelines“) and the Central Bank’s expectations.
Liquidity risk requirements for investment firms are governed by article 43 of the Investment Firm Regulation (“IFR“). The firms reviewed were requested to complete a liquidity risk questionnaire and to provide supporting documentation, including their internal capital adequacy and risk assessment (“ICARA“), policies and procedures, and internal management information.
Two focus areas
The Thematic Review focused on two specific aspects of how firms manage the liquidity risks to which they are exposed: (i) firms’ evaluation of their exposures to liquidity risk; and (ii) the adequacy of firms’ liquidity risk management frameworks. Overall, the sample of firms were found to be managing liquidity risk exposures broadly in line with the Joint Guidelines and the Central Bank’s expectations, although the Central Bank noted varying degrees of maturity across firms’ liquidity risk management frameworks.
Focus area 1: evaluation of liquidity risk
This aspect of the Thematic Review examined how firms self-assessed the material liquidity risks arising from their business activities, their ability to meet liquidity needs over different time horizons, their ongoing compliance with the minimum liquidity requirement under article 43 of the IFR, and the stability of their funding sources. Some of the good practices and findings highlighted by the Results are as follows:
- the majority of firms performed an adequate assessment of their business model and the resulting liquidity risks, with clear analysis of liquidity risk exposures presented within firms’ ICARAs;
- no issues of concern were noted regarding firms’ ability to meet liquidity needs over different time horizons, with all firms demonstrating consideration of intraday liquidity risk and its relevance to their individual businesses;
- all firms clearly demonstrated the ability to ensure ongoing compliance with the minimum liquidity requirement under the IFR, both on a business-as-usual basis and under stress, with a number of firms operating to a self-determined minimum level of liquidity that is higher than the IFR minimum; and
- all firms demonstrated consideration of the stability of their funding, typically as part of their stress testing framework.
Some of the weaknesses identified included that some firms’ ICARAs contained limited detail on liquidity risk exposures and their impact on the firm, and that some firms did not provide analysis of how liquidity risks impact the firm from both a normative and an economic perspective.
Focus area 2: liquidity risk management
This aspect of the Thematic Review focused on the adequacy of the liquidity risk management arrangements in place, including the appropriateness of firms’ risk management and limit frameworks, monitoring arrangements, stress testing frameworks, and contingent funding sources. Some of the good practices highlighted by the Results are as follows:
- all firms reviewed had enacted a three lines of defence structure for the management of liquidity risk, including independent review and validation by the second and third lines, and a committee structure for reporting and escalating issues of concern;
- all firms had implemented specific liquidity risk limits, with some firms setting limits clearly reflective of the firm’s business model and / or funding model and aligned to the output of internal stress testing;
- monitoring arrangements implemented by firms reviewed appeared adequate having regard to each firm’s liquidity risk exposure, with the majority of firms conducting daily monitoring of their liquidity positions; and
- the majority of firms had developed stress testing frameworks clearly aligned to their self-assessed material liquidity risks, conducted from both the normative and economic perspectives, with some firms also producing reverse stress test scenarios to complement their ICARA stress tests.
Some of the weaknesses identified included that the rationale for the calibration of liquidity risk limits was not always clear, with some firms providing inadequate justification for limit thresholds, using the same thresholds for their liquidity metric as for their own funds metric with no supporting rationale, or setting binary thresholds with no buffers or early warning indicators.
Some firms also provided insufficient detail regarding the impact of stress scenarios on the firm’s liquidity position. In addition, the Central Bank noted a high level of reliance on funding from affiliate entities to meet any stressed liquidity requirements. In some firms, it was observed that the contingent funding was uncommitted in nature, giving rise to the risk that such funding may not be made available in a stressed scenario.
Central Bank’s expectations / action to be taken by firms
The Central Bank expects all investment firms, and their boards and senior management, to revisit the Joint Guidelines to consider their adherence to same in light of the findings of the Thematic Review. Where gaps or weaknesses have been identified, firms should develop and implement actions to address these in a timely and proactive manner.
The Central Bank emphasised the responsibilities of the board and senior management in considering liquidity risk as part of an investment firm’s overall risk management framework, and noted that boards and senior management should ensure that risk management frameworks are well designed, operating effectively, and sufficiently robust.
The Central Bank requires the Results to be discussed at firms’ next board meeting, with the discussion to be recorded in the minutes of that meeting. Finally, the Results state that the Central Bank may engage directly with firms on the matters set out in the Results during the course of its supervisory activities.
2. Commission adopts amending delegated regulation on organisational requirements of trading venues and circuit breakers under MiFID II
On 1 October 2026, the European Commission (“Commission”) adopted a delegated regulation (“Amending Delegated Regulation”) amending the regulatory technical standards (“RTS”) in delegated regulation (EU) 2017/584 as regards certain organisational requirements of trading venues and circuit breakers.
The European Securities and Markets Authority (“ESMA”) published a final report containing the RTS in April 2025 – for more information, see FIG Top 5 at 5 dated 17 April 2025.
The RTS:
- amend the scope, so that delegation regulation (EU) 2017/584 applies to trading venues where order submission and order matching is facilitated by electronic means;
- take account of amendments to the MiFID II directive made by DORA and MiFID III; and
- detail common principles applicable to circuit breakers and the information to be disclosed by trading venues about circuit breakers.
Next steps
The Amending Delegation Regulation will now be scrutinised by the European Parliament and the European Council – if neither institution objects, it will be published in the official journal of the European Union and will enter into force on the third day following publication.
On 1 October 2026, the Governor of the Central Bank of Ireland (“Central Bank“), Gabriel Makhlouf, delivered a speech (“Speech“) at the Irish Funds Annual Global Funds Conference, entitled “Opportunity and trust: Europe’s capital market and the Irish funds sector”. While the Speech was addressed to the funds industry, some of the Governor’s remarks addressed themes relevant to the financial sector generally. This update focuses on those cross-sectoral matters.
Capital, opportunity and trust
The Governor discussed the reasons why deeper capital markets matter for growth, resilience and households, noting that, the innovative firms that Europe needs, are often better financed by risk capital than by bank lending alone. He highlighted that diversity of funding sources enhances economic resilience, and that broader retail participation in markets, with the right investor protections, can support households’ long-term financial resilience.
He reiterated his view that capital follows real economic activity and that Europe does not lack savings, but that capital seeks the best risk-adjusted returns and too often finds them elsewhere. To change this situation, he identified the need to complete the single market and to ensure that regulatory frameworks do not create unnecessary fragmentation.
The Governor emphasised the importance of trust as a “crucial underpinning” of the economy and financial system as a whole, observing that while capital follows opportunity, it also flows to, and stays where there is, trust.
Technology and tokenisation
The Governor identified technology, particularly distributed ledger technology (“DLT“) and tokenisation, as a major opportunity, having the potential to transform the monetary and financial system, delivering efficiencies in settlement and broader access to investment products. However, he cautioned that tokenising only one part of the system is insufficient, stating that the wider ecosystem must be involved, including tokenising both assets and money.
In this regard, he stressed the importance of the role of central banks, noting that the Eurosystem has recently enabled transactions on DLT platforms to settle in central bank money. The Governor also referenced the Central Bank’s recent discussion paper on DLT and tokenisation – for more information, see FIG Top 5 at 5 dated 12 March 2026. Indeed, he stated that the Central Bank’s authorisation regulation and supervision work increasingly relates to DLT and tokenisation, across a number of sectors.
He stressed that innovation must be accompanied by appropriate safeguards and risk management that scales with firm size, given the new vulnerabilities that can arise as regards cybersecurity, operational complexity, custody, legal certainty and governance.
Resilience: shocks, operations and third-party concentration
The Governor stated that maintaining trust requires a financial system that is well-run, with “resilient fundamentals” that function in both good times and bad, and identified three aspects of resilience – resilience to shocks, resilient operations and resilient governance.
When it comes to operational resilience, which he described as being “at the forefront of supervisory attention globally”, the Governor stated that business continuity plans are a minimum requirement and that regulators need confidence that firms have embedded operational resilience into day-to-day decision-making and governance, rather than treating it as a matter of minimum compliance. He noted that the Central Bank’s cross-industry reviews have been encouraging but have shown an uneven picture, with some firms taking a genuinely strategic approach and others remaining too narrowly focused on compliance with minimum requirements.
The Governor drew attention to concentration risk arising from reliance on a small number of critical technology and infrastructure providers, warning that a significant outage at a single cloud provider or data management platform could have profound ripple effects across the industry and, as retail participation grows, across households too. He stated that firms are expected to have exit strategies, to test them, and to ensure boards and senior management understand the dependencies underpinning their operations.
On governance, the Governor stated that governance is fundamental to delivering both resilience and trust across the financial sector generally.
Conclusion
The Governor concluded that capital goes where the opportunity is, and stays where it is trusted. He describes creating opportunity as being Europe’s task, through completing the single market and deepening capital markets.
He highlighted that maintaining trust is a task shared by the financial sector and regulators, with the financial services industry needing to have the highest standards of investor protection, of governance, and of risk management. For the Central Bank, the Governor stated that maintaining trust means being forward-looking, connected, proportionate, predictable, transparent and agile, evolving its frameworks, investing in supervisory capacity, and continuing to take enforcement action where necessary.
1. EBA publishes work programme for 2027
On 30 September 2026, the European Banking Authority (“EBA”) published its work programme (“Programme”) for 2027.
Cross-cutting drivers
The Programme is centred around three cross-cutting drivers, which underpin the EBA’s work across all core activities and provide the framework for the 2027 priorities, as follows:
- fostering resilience – reflecting the EBA’s role as regards contributing to the stability and effectiveness of the European financial system, including resilience to geopolitical, macroeconomic, cyber, technological and environmental risks, as well as risks affecting consumers;
- improving efficiency – reflecting the need to streamline supervisory and regulatory rules and processes while safeguarding financial stability, including through simplification, more integrated reporting, better coordination and internal processes; and
- supporting transformation – reflecting the technological changes affecting the financial sector and public authorities, the emergence of new supervisory tasks and methods, and the need to support innovation while addressing the risks arising from new technologies and business models.
These drivers support the EU’s broader priorities including competitiveness and deeper single market integration, green and digital transition, innovation and consumer protection.
Focus areas 2027 and activities
The Programme sets out seven main activities (with 251 deliverables of which 131 are of an ongoing nature and 120 have deadlines or delivery targets). The areas of focus for 2027 are grouped under the corresponding main area of activity. Detailed descriptions of the specific activities that the EBA intends to undertake in 2027, including the timings for the main outputs of those activities, are set out in chapter 2 of the Programme.
Activity 1: policy development, with the areas of focus being as follows:
- contributing to regulatory framework changes to strengthen the banking sector;
- finalising implementation of the 2024 banking package;
- implementing new payment services framework;
- implementing crisis management and deposit insurance reform; and
- supporting the Savings and Investments Union and securitisation framework.
Activity 2: supervisory convergence and enforcement, the focus areas are:
- implementing a new supervisory convergence framework;
- monitoring consistent implementation of the supervisory review and evaluation process and pillar 2 (including interest rate risk in the banking book and liquidity);
- strengthening supervisory technological capacity (AI Act, crypto, distributed ledger technology (“DLT”) and value chain); and
- protecting consumers (over-indebtedness, de-risking and education, innovation).
Activity 3: risk and financial stability analysis, some of the focus areas include:
- enhancing EU-wide stress testing capacity;
- analysing ICT incidents, cyber threats, and risks from quantum computing, DLT; and
- tracking risks to consumers.
Activity 4: oversight and supervision, with some of the focus areas being as follows:
- embedding DORA oversight of critical ICT providers;
- implementing effective MiCA supervision; and
- implementing EMIR initial margin model validation.
Activity 5: data – including a focus on delivering a more integrated reporting framework and expanding data sharing, data-driven supervision and data services.
Activity 6: governance – including a focus on, implementing new internal governance and strategic steer / monitoring equivalence of regulatory, supervisory and confidentiality frameworks beyond the EU / deepening international cooperation and dialogue.
Activity 7: operations – including a focus on, enhancing IT resilience, security and digital sovereignty.
2. EIOPA publishes its single programming document 2027 – 2029 including its annual work programme 2027
On 29 September 2026, the European Insurance and Occupational Pensions Authority (“EIOPA”) published a draft of its single programming document for 2027 – 2029 (“SPD”), this includes EIOPA’s annual work programme for 2027 (“AWP”).
The SPD sets out the activities that EIOPA will undertake in the period 2027 – 2029, while the AWP, which is contained in section III of the SPD sets out EIOPA’s main priorities as part of its annual activities in 2027, taking account of the renewed EIOPA strategy towards 2030 (“Strategy”).
EIOPA’s priorities for 2027 relate to strengthening single market integration, enhancing market and societal resilience against risks, and better regulation and supervision. These priorities reflect EIOPA’s latest strategy, which was published in January 2026 – for more information, see FIG Top 5 at 5 dated 22 January 2026.
The SPD highlights that that 2027-2029 will be marked by intense legislative, regulatory
and implementation activity, driven by the application of the revised Solvency II framework and the
Insurance Recovery and Resolution Directive (“IRRD“) from 30 January 2027, continued implementation
of DORA and the AI Act, and anticipated work on files still under negotiation, including the Retail
Investment Strategy (“RIS“), Institution for Occupational Retirement Provision Directive (“IORP II”), Pan-European Personal Pension Product Regulation (“PEPP”) and the Sustainable Finance Disclosure Regulation (“SFDR”).
AWP
The AWP sets out details of the deliverables and timing for each of EIOPA’s 2027 priorities. This work covers a wide range of matters, some of which are as follows:
- developing a framework, guidance and possibly a supervisory handbook chapter on claims handling;
- developing technical advice, regulatory technical standards, guidelines and new IT tools under the RIS;
- developing supervisory convergence tools under DORA and contributing to the Commission’s review;
- further clarification on the regulatory framework on the use of AI by the insurance sector; and
- developing measures to simplify regulation and reduce burdens under the Insurance Distribution Directive, in preparation for a future review;
- finalising and implementing a new risk-based methodology for prioritising supervisory
convergence tools, and targeted amendments to the EIOPA supervisory handbooks to reflect
the revised Solvency II framework; - timely execution of the first phase of RIS policy mandates, subject to final
adoption by the co-legislators; - contributing technical input to the level 1 review of SFDR and continued cooperation with the
European Systemic Risk Board on climate-related and cross-sectoral risks; - producing reports on investment and capital management following the Solvency II review, and
a report on composite insurers; - technical support to the European Commission on the IORP II review and follow-up on the PEPP
Regulation review, including preparatory supervisory support for NCAs; and - sequenced implementation of the IRRD, including operation of the Resolution Committee and
participation in resolution colleges, and continued work on a European network of national
insurance guarantee schemes.
3. EIOPA publishes strategic supervisory priorities for 2027
On 30 September 2026, the European Insurance and Occupational Pensions Authority (“EIOPA”) published a document (“Document”) detailing its union-wide strategic supervisory priorities (“USSPs”) for 2027-2029 and focus areas for 2027.
The USSPs are set at a strategic level every three years. Within each annual cycle, EIOPA publishes insurance-specific focus areas for the upcoming year, supporting national competent authorities (“NCAs”) in applying the strategic priorities in light of relevant developments and trends.
The Document highlights that EIOPA’s forward-looking risk assessment for 2027 to 2029 suggests that the European Economic Area insurance sector will be operating in a structurally more complex, interconnected and volatile environment. Additionally, it is stated that the nature of risks may change from cyclical financial pressures to more structural, systemic and technology-driven vulnerabilities.
From a conduct perspective, the Document states that disruption and change are not only affecting providers, products, and consumers but are also transforming business models and the risks stemming from the broader operating environment. The main challenge for the next three years, the Document goes on to emphasise, is not perceived as a single dominant risk, but rather the interaction of multiple risks which can potentially materialise simultaneously.
The Document explains that:
- the environment calls for strong capital and liquidity resilience, forward-looking underwriting and climate risk management;
- robust digital operational resilience and close monitoring of AI-driven conduct risks are also important; and
- supervisors need to understand how business models change and adapt to current and emerging risks.
Two strategic priorities
With the forgoing in mind, the Document sets out two strategic priorities, that EIOPA has identified, that NCAs should consider when drawing up their work programmes for 2027 to 2029. These are:
- enhancing resilience in a structurally evolving and volatile risk environment; and
- supporting societal resilience by mitigating conduct risks in business models and distribution.
2027 Focus Areas
The supervisory focus areas for EIOPA and NCAs in 2027 are:
- continuity and contingency planning, including planning for digital operational resilience – this includes the integration of continuity planning with risk management and governance frameworks. It also covers compliance with DORA and EIOPA’s opinion on AI governance and risk management, and assessing whether own risk and solvency assessments reflect all relevant risks; and
- supporting societal resilience by mitigating conduct risks in business models and distribution – this includes managing conflicts of interest that may lead to poor product design and assessing affordability trends and related risks. It also covers the monitoring and assessment of digital distribution mechanisms.
Next steps
The Document highlights that the specific supervisory focus for 2028 and 2029 will be identified and published as part of the yearly revision of developments and trends.
1. AMLA publishes three sets of RTS under AML regulation
On 1 October 2026, the Anti-Money Laundering Authority (“AMLA”) published three final reports containing draft regulatory technical standards (“RTS”) under Regulation (EU) 2024/1624 (“AMLR”).
The draft RTS, which define key measures that companies and professionals are required to apply to reduce money laundering and terrorist financing risks, are as follows:
Draft RTS on customer due diligence under article 28(1) AMLR:
The draft RTS specify the information to be collected for standard, simplified and enhanced customer due diligence (“CDD”) purposes, the risk factors relevant to exempting certain electronic money instruments from CDD measures, reliable and independent sources for identity verification, and the attributes required of electronic identification means and qualified trust services.
The AMLA consulted on this set of draft RTS in February 2026 – for more information, see FIG Top 5 at 5 dated 12 February 2026. A summary of responses is set out in section 4.2 of the final report. Respondents welcomed more consistent CDD standards but were concerned about the prescriptive nature of some of the RTS. AMLA has made revisions to the draft RTS, including clarifying that they should be applied in a proportionate and risk-based manner.
AMLA has also published a related factsheet, accompanying the final report.
This set of draft RTS sets out how companies and professionals should distinguish between business relationships and occasional transactions, and how to identify linked transactions, so that customer due diligence thresholds are applied consistently.
The AMLA also consulted on this set of draft RTS in February 2026, see above for more information. A summary of responses is set out in section 4.2 of the final report. Respondents requested extra detail in the RTS. AMLA has made some revisions to the draft RTS to improve clarity.
AMLA has published an accompanying factsheet as regards the RTS.
This set of draft RTS contain requirements that further specify the framework and content of group-wide requirements. As well as minimum general requirement, the draft RTS define provisions related to information sharing among entities of a group. Additionally, they contain criteria for identifying the parent undertaking in the Union in cases of two or more obliged entities in the Union belonging to a head office in a third country where they are not in a parent / subsidiary relationship. The RTS also set out conditions to apply group-wide requirements to structures other than groups and criteria to identify the head of the structure in these cases.
AMLA consulted on the draft RTS in April 2026 – for more information, see FIG Top 5 at 5 dated 23 April 2026. A summary of responses is set out in section 4.2 of the final report. Respondents raised concerns about implementing some of the provisions. AMLA has amended the draft RTS to address some of the concerns.
Two accompanying factsheets have also been published, available here and here.
Next steps
In a related press release, AMLA has stated that the three sets of RTS have been submitted to the European Commission for adoption. Once they have been adopted and published in the official journal of the European Union, it is proposed that they will apply six months after their entry into force.
2. AMLA publishes final report on draft RTS on home and host supervisory duties and cooperation
On 1 October 2026, the Anti-Money Laundering Authority (“AMLA”) published a final report containing draft regulatory technical standards (“RTS”) on the respective duties of the home and host supervisors, and practical arrangements regarding their cooperation under article 46(4) of directive 2024/1640 (“AMLD6”).
The draft RTS establish a harmonised, operational baseline for AML / CFT supervisory cooperation in respect of groups of obliged entities operating across borders, in the financial and non-financial sectors – contributing to the consistent application of AML / CFT requirements across the single market.
AMLA consulted on the draft RTS in May 2026 – for more information as to the contents of the RTS, see FIG Top 5 at 5 dated 14 May 2026.
AMLA held a public hearing on the draft RTS in May 2026. Section 4.2 of the final report summarises the key issues raised by participants and the resulting revisions to the draft RTS made by AMLA, dealing with matters such as, multi-jurisdictional operations and supervisory convergence / groups with offshore or non-financial entities / information exchange protocols / proportionality and avoidance of duplicative reporting.
Next steps
The draft RTS will be submitted to the European Commission for adoption. The draft delegated regulation containing the draft RTS states that it will come into force 20 days after being published in the official journal of the European Union and will apply from 10 July 2027.
1. EIOPA publishes supervisory statement on the authorisation and ongoing supervision of (re)insurance undertakings related to private equity
On 6 October 2026, the European Insurance and Occupational Pensions Authority (“EIOPA“) published a supervisory statement (“Statement“) on the authorisation and ongoing supervision of (re)insurance undertakings related to private equity (“PE“) firms.
The Statement follows EIOPA’s February 2026 consultation on the draft statement – for more information, see FIG Top 5 at 5 dated 5 February 2026.
Background
EIOPA notes that, over the last ten years, PE firms have shown growing interest in acquiring (wholly or partially) insurance and reinsurance undertakings, a trend more developed in the US but increasingly present in the EU.
As owners of (re)insurance undertakings, PE firms often take an active role in defining strategy and managing the undertaking, which the Statement refers to as their “modus operandi”. EIOPA acknowledges this can bring benefits, such as a more diverse investment strategy and easier access to capital, but notes that the ownership structures used, together with the PE firm’s modus operandi and governance, can pose challenges for supervisory authorities, particularly during the acquisition process which is subject to a 60 working day timeframe under article 58 of the Solvency II Directive.
NCAs
The Statement is addressed to competent authorities and is issued on the basis of article 29(2) of the EIOPA Regulation and the Solvency II Directive. Its aim is to ensure high-quality and convergent supervision of (re)insurance undertakings that are owned by PE firms, taking into account their specific nature and risks. The Statement sets out supervisory expectations for acquisitions of qualifying holdings, portfolio transfers and mergers, as well as for ongoing supervision.
Content
The Statement identifies a number of risk areas associated with PE-related (re)insurance undertakings and sets out corresponding supervisory expectations, including in relation to:
- changes to the business model of the (re)insurance undertaking, including the need for
supervisory authorities to understand planned post-authorisation changes, request a business
plan covering at least three years, and to assess alignment with the undertaking’s long-term
operational capability. When analysing the business model and planned changes, if areas of significant risk are identified, supervisory authorities should consider measures to mitigate the identified risks, which potentially includes setting up conditions in their declaration of no objection; - the timespan of PE investments, given that a limited investment horizon and exit strategy may be misaligned with the undertaking’s long-term commitments to policyholders, supervisors must ensure that capital is not extracted from the undertaking in the form of high distributions to shareholders or other short-term measures that would negatively affect the long-term viability of undertakings and ultimately put policyholders and beneficiaries at risk;
- the simplicity and transparency of acquisition structures, with supervisory authorities expected to scrutinise the entire financing structure, request justifications for each level of ownership and test business plans against adverse financial scenarios;
- maintaining a sound and effective system of governance, with supervisory authorities to have regard to matters such as, independence of the undertaking’s governing bodies / whether affirmative voting rights or special shareholder rights undermine independent decision-making / conflicts of interest / management remuneration or leveraged share schemes that could encourage excessive risk taking;
- prudential aspects, with the Statement addressing matters such, the shift in asset allocation towards private credit and illiquid assets / the use of reinsurance (particularly with third-country or related-party reinsurers) / the impact of balance sheet enhancement measures on solvency positions; and
- high leverage and capital enhancements, including the use of collateralised debt to finance acquisitions and the need to assess the undertaking’s ability to service such debt while maintaining solvency, liquidity and policyholder protection.
Early dialogue encouraged
- The Statement encourages early dialogue between proposed PE-related acquirers and supervisory authorities ahead of formal notification, particularly where significant changes to the target undertaking’s business model are planned.
Next steps
The Statement has been adopted by EIOPA’s board of supervisors and will apply to competent authorities in accordance with the principles of risk-based and proportionate supervision.
2. EIOPA publishes report on the impacts of climate change on life and health and potential emerging risks for the insurance and IORP sectors
On 30 September 2026, the European Insurance and Occupational Pensions Authority (“EIOPA”) published a report (“Report”) examining how climate change could affect life and health insurers and occupational pension providers. It identifies extreme heat as the main climate-related liability risk for the sectors.
The Report focuses on mortality, longevity and health only and second order impacts or chain reactions arising from climate change on life insurers are not considered.
The Report notes that heatwaves, not floods or storms, are the dominant cause of climate-related mortality in Europe, and are therefore the most significant climate-sensitive risk for life, health and longevity outcomes.
Some of the main points addressed in the Report are as follows:
- heatwaves have been the deadliest climate-related hazard in Europe since 2000, causing around 300,000 deaths and roughly 97% of all fatalities linked to extreme weather and climate events;
- scientists expect heatwaves to increase in frequency, intensity and duration over the coming decades, with heat-related deaths in extreme scenarios potentially reaching COVID-19-like levels;
- climate change is creating a growing liability risk for life and health (re)insurers and occupational pension providers, not only an asset-side risk. The liability risks are increasing for life and health also;
- for pension providers, this is a financial risk, not merely an ESG topic – climate change challenges the traditional longevity assumptions pension systems rely on, with implications for pension adequacy, liabilities, funding dynamics and long-term sustainability;
- the lines of business projected to be most affected are medical expense, income protection and workers’ compensation insurance (non-life) and similar-to-life health insurance and other non-participating life insurance (life segment). Impacts will be highly product and portfolio-specific, and while mortality and health-related products may see own-funds pressure, longevity-exposed products (for example, annuities) may see partially offsetting effects;
- overall, EIOPA currently assesses the impact of climate change on life and health insurance and institutions for occupational retirement provisions (“IORPs”) as not material, However, it is highlighted that this could change as Europe is the fastest-warming continent. Reduced cold-season mortality is not expected to offset heat-related excess mortality;
- rising climate-related health risks could affect the affordability and insurability of certain life insurance products, with a risk of widening protection gaps and anti-selection as insurers adjust pricing, reserving and underwriting — reinforcing the need for prevention measures and public-private collaboration;
- this area is receiving growing supervisory attention, with authorities reviewing own risk and solvency assessments (“ORSAs”) to understand how sustainability risks are defined, what analyses support assessments, and what materiality is attributed to them. However, the report notes that only a few ORSA respondents explicitly address life and health climate risks, with others treating the impact as non-material;
- heatwaves are rarely treated as a standalone stress scenario and are usually captured only indirectly. Insurers rarely refer explicitly to climate change in life and health pricing or technical provisions, even though effects may be implicitly embedded via long-term mortality trend assumptions;
- although current financial impact is limited, EIOPA encourages insurers to incorporate these emerging heat-related risks into their climate risk assessments holistically — covering both direct and broader indirect macroeconomic impacts — given that materiality is expected to increase over time;
- insurers should combine climate, epidemiological, demographic and insurance data, explicitly accounting for uncertainty, and supplement historical analysis with scenario-based modelling to strengthen risk assessment and long-term risk management; and
- more granular, harmonised data — on insurance products, age cohorts, geographic distribution and vulnerability factors is needed to properly assess European exposure to heatwave risk as the Report flags that current general-population data may not represent insured portfolios well.

Thought Leadership
Matheson Talks Financial Regulation Podcast
The Matheson Financial Institutions Group are delighted to share with you some useful podcasts.


















