Sebastien Rousseau

CATEGORY

Policy & resilience

DORA, EU AI Act, NIST standards, third-party risk — the supervisory pressure shaping technology decisions.

4 tags

Tags in this category

  • DORA — 61 articles

    Digital Operational Resilience Act — register of information, ICT third-party risk, threat-led penetration testing, and the operational resilience programme banks must run.

  • EU AI Act — 8 articles

    Implementation guidance, supervisory expectations, high-risk system classification, and the conformity-assessment burden the Act puts on banks.

  • NIST — 5 articles

    NIST standards relevant to banking — FIPS 203/204, AI RMF, SP 800/1800 series — and the supervisory adoption patterns around them.

  • Third-party risk — 4 articles

    ICT third-party risk under DORA, EBA outsourcing guidelines, and the supervisory expectation around critical-vendor concentration.

INFRASTRUCTURE & CRYPTOGRAPHY

Red Team als beaufsichtigte Lieferkette: Was DORA-TLPT verlangt

Die meisten Banken haben den Test kalkuliert. Weniger haben die Lieferkette kalkuliert, von der er nun abhängt: einen akkreditierten Markt für Testdienstleister an einer synchronisierten Dreijahresuhr und Bedrohungsaufklärung, die jedes Mal von außen kommen muss.

INFRASTRUCTURE & CRYPTOGRAPHY

Nicht erfassbar, nicht migrierbar: Das fehlende CBOM der Banken

Jede Post-Quanten-Roadmap setzt ein Inventar voraus, das es nicht gibt. Das Asset-Register kennt den Server, den Eigentümer und die Kritikalität; es kennt nicht den Algorithmus, die Schlüssellänge, die Bibliothek oder das Ablaufdatum.

APPLIED AI

Von der Fragmentierung zur Bruchlinie: Der fehlende API-Standard des Firmenkundengeschäfts im agentischen Zeitalter

Das Privatkundengeschäft erhielt seinen API-Standard vor einem Jahrzehnt. Das Firmenkundengeschäft nie — und da KI-Agenten und das Model Context Protocol die Integration zu einer Laufzeitentscheidung gemacht haben, ist die Lücke keine Lästigkeit mehr, sondern eine Bruchlinie. Ein konkretes Fehlerbild, die strategische Entscheidung, die es erzwingt, und was ein Firmenkunden-API-Standard vorschreiben muss.

INFRASTRUCTURE & CRYPTOGRAPHY

The Agentic AI Index for Banks in 2026: Measuring Autonomy

Agentic AI is operational infrastructure in 2026. This index measures it the way banks measure capital and credit: a six-dimension readiness score across autonomy tiers, the control plane, regulatory evidence, unit economics, organisational readiness, and global regulatory alignment.

APPLIED AI

Der Agentic-AI-Index für Banken 2026: Autonomie messen

Agentic AI is operational infrastructure in 2026. This index measures it the way banks measure capital and credit: a six-dimension readiness score across autonomy tiers, the control plane, regulatory evidence, unit economics, organisational readiness, and global regulatory alignment.

PAYMENTS & MONEY

Open Source, FINOS und der Cloud-native CIB-Stack

Morgan Stanley, JPMorgan und Citi setzen verstärkt auf FINOS und die Linux Foundation. Ein Rust-Stack mit null Abhängigkeiten — noyalib, http-handle, hsh, KyberLib — zeigt, wie der Cloud-native CIB-Stack 2026 unter PSD3, FiDA und DORA aussieht.