Skip to main content
Authority

ECB Banking Supervision (SSM)

ECB Banking Supervision or Single Supervisory Mechanism (SSM) directly supervises the euro area's largest banks, 110 significant institutions as at 1 May 2026, and oversees national supervisors for the smaller ones. If your bank is below the significance thresholds, your direct supervisor is DNB, BaFin or the FMA, working inside a framework the ECB sets.

Checked by Remmert
5 min read

What is ECB Banking Supervision?

ECB Banking Supervision is the supervisory arm of the European Central Bank, established by the SSM Regulation (Council Regulation (EU) No 1024/2013) and operational since November 2014. It is separate from the ECB's monetary policy function and is governed by a Supervisory Board chaired by Claudia Buch, with Frank Elderson as vice-chair, whose term was extended to 14 December 2028 (confirmed 17 February 2026). It is funded by supervisory fees charged to the banks it supervises: €690.0 million for 2025, split €659.1 million from significant institutions and €30.9 million from less significant ones.

Last updated: 17 August 2026. First version of this page.

Key facts

Which banks does the ECB supervise directly?

110 significant institutions, on the list of supervised entities with a cut-off date of 1 May 2026, published 26 June 2026. Everything else, roughly two thousand less significant institutions, is supervised by national authorities under ECB oversight.

A bank is significant if it meets any one of these criteria:

  • total assets above €30 billion; or
  • total assets above €5 billion and above 20% of national GDP; or
  • it is one of the three largest banks in its member state; or
  • it has received or requested assistance from the ESM or EFSF.

Dutch significant institutions include ABN AMRO, Rabobank, ING, BNG Bank, Nederlandse Waterschapsbank, GarantiBank International, RBS Holdings, NatWest Markets and Promontoria 19. In Germany, BaFin's Annual Report 2025 counts 1,089 less significant institutions supervised nationally as at 31 December 2025, a ratio to the significant population that tells you most of what you need to know about where mid-sized German banks are actually supervised.

Which regulations does the ECB apply?

RegulationThe ECB's role

What does the ECB publish, and how often?

ECB Banking Supervision publishes an annual set of supervisory priorities covering the next three years, annual aggregate SREP results, stress test results, a quarterly Supervision Newsletter, supervisory banking statistics, guides and public consultations, and individual sanction decisions. Data is available through the ECB Data Portal. The rhythm is predictable: priorities in December, SREP aggregates in December, the sanctioning report in spring, stress test results in summer.

The 2025 SREP produced an aggregate CET1 requirement of 11.2%, a Pillar 2 requirement of 1.2% and Pillar 2 guidance of 1.1%.

What has the ECB published recently?

Five items rather than ten: this table covers only the ECB's own headline supervisory publications since January 2026, not the full newsletter and speech stream, and it is regenerated by our monitoring pipeline rather than hand-maintained.

DatePublication

Which deadlines does the ECB own?

The ECB owns the supervisory cycle, but the reporting deadlines a bank actually diarises are set nationally, in EBA reporting frameworks or by its own national supervisor.

2026

  1. 20 March 2026Passed

    DORA register of information due, Netherlands

  2. 13 March 2026Passed

    DORA register of information due, Austria

No fixed date

  1. Annual, Q4Recurring

    SREP decisions communicated to significant institutions

  2. Annual, DecemberRecurring

    Supervisory priorities for the next three years

  3. Phased to 2028 and beyondExpected

    CRR3 / CRD6 transitional arrangements

What does the ECB's enforcement look like?

2025 was a five-year high. The ECB's 2025 sanctioning report, published 11 May 2026, records 370 proceedings and €57.15 million in fines. Individual sanctions in the last twelve months include J.P. Morgan (€12.18 million), Belfius (€6.94 million), BofA Securities Europe (€6.2 million), Banque Internationale à Luxembourg (€3.255 million) and Nordea Finance Finland (€2.26 million). On-site activity in 2025 comprised 163 on-site inspections and 77 internal model investigations.

For a mid-sized bank, the useful signal is not the fine amounts but the inspection count: 163 inspections across 110 significant institutions is roughly 1.5 per bank per year, and that intensity is the reference point against which national supervision of less significant institutions is calibrated.

What changes at the significance threshold?

Crossing €30 billion in total assets moves your direct supervisor from your national authority to the ECB, brings you into the EU-wide stress test population, and puts your SREP decision in Frankfurt. Below it, you are supervised by DNB, BaFin or the FMA, but under ECB oversight, with the ECB setting the framework, issuing guides and retaining the power to take over direct supervision. CRR3 also carries proportionality for small and non-complex institutions, a defined category under the CRR rather than a supervisory courtesy.

The practical consequence for a growing institution: the threshold is a planning horizon, not a surprise. It is measurable years ahead from your own balance sheet.

What we do with this

We track the ECB's supervised-entities list, priorities, sanctions and stress-test cycle, and date each change. The list itself is the interesting artefact: it is the authoritative answer to "who supervises this bank", it changes several times a year, and a group's own entities can sit on different sides of it. Our model resolves that per legal entity.

If you want to know which side of the significance threshold your institution sits on and what changes when it moves, that is a working session, not a guess.

Regulations

  • Digital Operational Resilience Act (DORA)

    DORA is Regulation (EU) 2022/2554. It has applied since 17 January 2025 to 20 categories of licensed financial entity, from banks to crypto-asset service providers. It requires an ICT risk management framework, major incident reporting within 4 hours of classification, an annual register of ICT contracts, and threat-led penetration testing every three years.

    NextNext register of information cycle, reference date expected 31 December 2026

    Checked

  • Anti-Money Laundering Regulation (AMLR)

    The AMLR is Regulation (EU) 2024/1624. It applies from 10 July 2027 and is directly applicable, so from that date customer due diligence, beneficial ownership, reporting and internal controls come from EU law rather than national statute. Cash payments for goods and services are capped at €10,000. Football clubs and agents follow on 10 July 2029.

    NextAMLR applies (Art. 90) and the AMLD6 transposition deadline. References to Directive (EU) 2015/849 are construed as references to the AMLR and AMLD6, per the correlation table in Annex VI (Art. 89); the repeal itself sits in AMLD6

    Checked