Financial Regulations – FFFS, EBA, EIOPA & ESMA
Financial institutions in Sweden and across the EU operate under stringent IT and information security regulations.
Financial institutions in Sweden and across the EU operate under stringent IT and information security regulations. In Sweden, Finansinspektionen (FI) issues its regulations in a collected code (FFFS). FFFS is therefore not a single regulation, and which parts apply varies with the type of financial firm. Among the requirements is that banks and investment firms work in a “structured and methodical manner” with information security. These regulations cover governance of IT operations and mandate robust protection for critical systems (e.g. bank deposit systems).
At the European level, the supervisory authorities, the European Banking Authority (EBA) for banks, European Insurance and Occupational Pensions Authority (EIOPA) for insurers, and European Securities and Markets Authority (ESMA) for investment firms have established common guidelines to harmonize Information and Communication Technology (ICT) risk management and security practices across member states. Since DORA began to apply on 17 January 2025, the regulation is the primary harmonised framework for ICT risk for the financial entities within its scope. The EBA consequently amended its Guidelines on ICT and security risk management to avoid duplication, narrowing their entity scope to DORA-covered entities, with the amendment applying from 20 May 2025. The EBA, EIOPA and ESMA guidelines remain relevant in specific areas, but how they interact with DORA has to be assessed per entity type and subject matter. DORA expands the scope of these requirements to virtually all financial entities (banks, insurers, investment firms, payment providers, etc.), emphasizing comprehensive operational resilience strategies and unified standards for ICT security.
In short, whether you are a bank, insurance company or asset manager, you face broad obligations to secure your information systems and to align with both Swedish FFFS rules and EU-level supervisory expectations. Achieving compliance is not only a legal mandate – it’s critical for protecting customers and maintaining trust in the financial system.
In brief
- Who
- Banks, investment firms, insurers and asset managers under the supervision of Finansinspektionen and the guidelines of the European supervisory authorities
- What
- Risk management and continuity planning, outsourcing and third-party governance, incident management and reporting, documentation and governance aligned with FFFS and the EBA, EIOPA and ESMA guidelines
- How
- Support for policies and documentation, ISMS implementation and governance framework, implementation and ongoing support so that compliance becomes part of daily operations
Key Obligations for Financial Firms
Financial regulators outline a range of key obligations that firms must fulfill to ensure information security and operational resilience. The requirements can be grouped into several core areas.
- ICT Governance & Strategy
Firms are expected to establish strong governance around IT and security. This means defining clear roles and responsibilities (often up to the board level) and aligning the ICT strategy with the overall business strategy. Organizations must maintain comprehensive information security policies approved by management, and implement security measures covering access controls, physical and logical security, monitoring, testing, and staff training and awareness. The goal is to embed security into the corporate governance framework from the top down. - Risk Management & Continuity Planning
Financial institutions must manage ICT and cyber risks through structured, documented processes. Key requirements include maintaining an up-to-date inventory of IT assets, conducting regular risk assessments, and having formal procedures for incident management and change management. Firms are also obliged to develop and test robust business continuity plans and disaster recovery capabilities to ensure they can withstand and quickly recover from disruptions. Regulators often require an Information Security Management System (ISMS) – a systematic framework to “establish, introduce, operate, monitor, review, maintain and develop” the security of the firm. Independent control functions (e.g. internal audit or risk control) should oversee ICT risk management effectiveness, ensuring any deficiencies are identified and addressed promptly. - Outsourcing & Third-Party Oversight
Using third-party IT service providers or cloud services does not reduce a firm’s accountability for risk. Supervisors demand that outsourcing arrangements are tightly controlled and deliver equivalent security as in-house operations. Financial firms must perform thorough due diligence on external providers, impose contractual requirements (for example, on data security, breach notification, and audit rights), and continuously monitor third-party performance. In practice, this means having detailed supplier risk assessments, ensuring contracts include all required security and continuity clauses, and retaining the right to inspect or audit vendors. Firms should also have exit strategies in place so that critical services can be transitioned if a provider fails to meet obligations. Regulators have made it clear that outsourcing does not transfer risk – ultimate responsibility stays with the financial institution. - Incident Management & Reporting
A cornerstone of operational resilience is the ability to rapidly handle and report incidents. Firms need effective processes to detect, contain, and resolve cybersecurity or IT disruptions. Additionally, they are required to notify regulators of major incidents within strict timelines. Under DORA’s unified incident reporting regime, financial entities must classify an incident as “major” and send an initial notification within four hours of classifying the incident as major, and no later than 24 hours after becoming aware of it. This is followed by an intermediate report within 72 hours of classification and a final report within one month that analyze root causes and remedial actions. These reporting obligations mean companies must have clear criteria for what constitutes a serious incident and readiness to communicate necessary information quickly. Beyond reporting, lessons learned from incidents should feed back into improving the security controls and continuity plans.
Common Challenges
Reaching compliance and holding it is rarely straightforward. Financial firms commonly meet these challenges.
- Interpreting complex requirements
The rules and guidelines are detailed and at times abstract, which makes them hard to translate into practical action. What counts as “appropriate” protection, or how “critical” services should be delimited, can be unclear. Continual updates — new guidelines or technical standards under DORA — add to the complexity. Compliance usually means several layers of requirement at once: fitting something new into existing processes, handling the technical detail, and making sure the whole organisation is covered. - Implementation and resource constraints
Putting the necessary controls in place can be demanding, particularly in an organisation with limited resources. Smaller firms may have no dedicated team, and even larger ones find the requirements extensive — risk analyses, supplier audits, testing. The cost of technical improvement, competence, training and resilience exercises adds up. Supplier compliance is a practical challenge in its own right: negotiating contracts and following up a long list of suppliers is heavy work. - Integrating it into business as usual
The largest challenge is making compliance a natural part of the daily work. It is common to run compliance as a project to get through a review, but supervisors expect continuous compliance. That means risk management becoming a routine in decision-making and IT governance rather than a checklist.
Changing processes and behaviour takes time: from staff following policies day to day, to management following up ICT risks regularly. Many lose momentum — the documentation gets written but is not kept current or operational, incident plans go untested, inventories are not updated when something changes. Holding a compliance-minded culture under other business pressure is hard. Without that integration, measures risk existing on paper and not in practice.
Helping You Comply
Kristensson i Skåne AB specialises in helping financial customers navigate these regulatory requirements and build compliance that lasts. Our model combines senior advice with hands-on support.
- Regulatory readiness assessments
We start by assessing your current state against the relevant FFFS requirements, the EBA, EIOPA and ESMA guidelines, and DORA. The review includes a detailed gap analysis to identify shortfalls in governance, risk processes and documentation. Comparing your practice against a regulatory baseline lets us point out exactly what needs to improve. You get a clear roadmap of measures prioritised by risk, from governance gaps such as a missing forum or committee to shortfalls in technical control. We translate complex requirements into concrete and prioritised recommendations. - Policy and documentation support
Documentation is at the centre of compliance, and usually the largest burden. We help you produce and improve the documents you need: the information security policy, the guidelines, incident plans, continuity plans, the outsourcing policy, so they meet supervisory expectations. We write the documentation to be fitted to your organisation and possible to implement, not only right on paper. With experience from standards such as ISO 27001 we see that the policies cover the right scope — access rules, data protection, responsibilities and reporting. - ISMS implementation and governance
We help you establish an ISMS and a governance framework that makes compliance operational and ongoing. In practice we set up the structures: a security forum, a risk register, a routine for following up controls, and reporting to management and the board. We help define the governance processes — how risks are identified, escalated and handled across the three lines of defence. We can also support the choice of tooling for risk, incidents and supplier governance. The result is a living framework where risk reviews, audits and policy revisions are built into the ordinary year. We work to keep management and the board engaged and accountable, in line with what supervisors expect. - Implementation and ongoing support
We do not stop at recommendations; we help you carry the changes out. That can cover technical improvements — network protection, monitoring, IAM — and process improvements such as incident exercises and third-party assessments. We also support training and security awareness, so that everyone understands the new ways of working and why they matter. Our view is that real compliance takes a security culture, and we work actively to build the engagement and the attitudes that reach the whole organisation.
We also offer continuing support: recurring compliance checks, updates when the regulation changes, or taking part as an external adviser in a governance forum. That lets you handle new requirements over time and stay aligned as things are updated.
In short, Kristensson i Skåne AB offers end-to-end support: from current-state analysis and action plan, through policy work and technical implementation, to continuous improvement and culture. We help you meet the Swedish and EU requirements and strengthen your operational resilience at the same time.
Regulatory requirements on information security and ICT risk will keep growing — but you do not have to make that journey on your own. Kristensson i Skåne AB has the competence and the practical experience to guide you through compliance and to turn it into an opportunity to strengthen your resilience. Whether you need a one-off gap analysis or a long-term partner, we are here.
Contact us to see how we can help you meet the FFFS, EBA, EIOPA and ESMA requirements and build a secure, well-governed operation at the same time. Read more about how we work and about supplier and third-party review.
Frequently asked questions
What do FFFS, EBA, EIOPA and ESMA mean in practice?
These regulations and guidelines affect how financial organisations manage risk, internal control, outsourcing, ICT security and compliance. In practice, the work is about translating requirements into clear processes and controls.
How do we know which requirements apply to our organisation?
The requirement landscape depends on business type, licences, products, outsourcing, geography and supervisory authority. A structured regulatory mapping is needed to identify the relevant rules and guidelines.
How should regulatory requirements be linked to internal controls?
Each relevant requirement should be linked to a policy, process, control, responsible role and evidence. This makes it easier to demonstrate compliance during internal follow-up, audit and supervision.
How should we handle overlap between DORA and other financial regulations?
Overlap should be managed through a common control framework. The same control can often support several requirements, but the organisation needs traceability between each control and each regulatory obligation.
How do we keep the requirement landscape updated over time?
Establish a process for regulatory monitoring, change analysis and ownership. New requirements should be assessed, documented, prioritised and translated into governance, controls and training.
Want to know how you meet the FFFS and EU requirements on ICT risk?
Contact us