The Future of Supervisory Data: How Real-Time Reporting Is Reshaping Financial Regulation

The Future of Supervisory Data: How Real-Time Reporting Is Reshaping Financial Regulation

The Future of Supervisory Data: How Real-Time Reporting Is Reshaping Financial Regulation

For most of the past century, regulatory oversight of financial institutions has operated on a simple premise: banks submit reports, regulators review them, and supervisors respond. The cycle measured itself in quarters, not minutes. That premise is now breaking down — and the change is happening faster than many institutions realize.

In February 2026, the Bank of England published DP1/26: Future Banking Data, a landmark discussion paper that laid out a fundamental rethinking of how supervisory data should be collected, governed, and exchanged. The paper did not propose minor adjustments to existing templates. It described a structural reset — one in which banks continuously maintain standardized, validated datasets and regulators access them directly when needed, rather than waiting for periodic disclosures.

This is not a UK-specific development. The European Central Bank's Supervisory Priorities for 2026–2028, published in November 2025, put data quality and risk data aggregation at the center of its oversight agenda. Regulators globally are arriving at the same conclusion: the old model of snapshot reporting is insufficient for supervising institutions that operate at digital speed and across interconnected markets.

From Periodic Reports to Continuous Data Streams

The traditional regulatory reporting model has deep roots. Banks file detailed returns — capital adequacy ratios, liquidity coverage, non-performing loan classifications — at fixed intervals. Supervisors analyze the aggregated picture. The problem is that by the time a quarterly report lands on a regulator's desk, the underlying conditions may have already shifted materially.

The 2023 collapse of several mid-sized US banks demonstrated precisely this vulnerability. Supervisors observed stress through public signals — deposit outflows, equity market movements — rather than through direct access to real-time data. The institution's own internal data told a different story than what had been disclosed in the most recent supervisory return.

The move toward real-time or near-real-time supervision is a direct response to this structural blind spot. Under the model envisioned in the Bank of England's DP1/26, banks would maintain structured, machine-readable datasets as a matter of ongoing operational practice. Supervisors would pull from these datasets on demand — during periods of stress, for peer analysis, or for macroprudential monitoring — rather than waiting for the next reporting cycle.

This reframes regulatory reporting from an output to be produced on a schedule into a capability that a financial institution maintains continuously.

What the Bank of England's Vision Signals for the Industry

The Bank of England's discussion paper is particularly significant because of its practical specificity. It outlines how the Prudential Regulation Authority (PRA) currently uses data — for risk assessment, compliance confirmation, peer group comparison, and policy research — and then interrogates whether the current collection mechanisms are fit for those purposes.

The paper's implicit answer is that they are not.

The future model described in DP1/26 emphasizes three principles: standardization (common taxonomies and consistent data definitions across institutions), granularity (moving from aggregated returns toward more disaggregated, atomic data), and accessibility (regulators accessing structured data rather than relying on institutions to format and submit it).

For banks, this has significant infrastructure implications. It requires what the industry has come to call a "golden source" architecture — a single, authoritative repository of clean, validated, lineage-tracked data that serves as the source of truth for both internal management reporting and external regulatory disclosure. Institutions that have historically managed supervisory reporting as a downstream process — assembling numbers at period-end from multiple siloed systems — will need to fundamentally rethink that approach.

ECB Priorities: Data Quality as a Supervisory Imperative

The European Central Bank's supervisory priorities for 2026–2028 reinforce this direction from a different angle. The ECB has explicitly flagged shortcomings in risk data aggregation and risk reporting (RDARR) as a material supervisory concern. Banks under SSM (Single Supervisory Mechanism) oversight have been put on notice: remediation plans must be executed, and escalation tools may be applied where deficiencies persist.

Forvis Mazars analysis of the ECB's published priorities notes that this reflects a broader shift in supervisory philosophy. Digital resilience and data quality are now considered as foundational to a bank's safety and soundness as capital adequacy. A bank that cannot produce reliable, timely, and granular data is, by that measure, not well-governed — regardless of its headline ratios.

This connects directly to the Digital Operational Resilience Act (DORA), which entered into force at the start of 2025. DORA requirements around ICT risk management, third-party dependencies, and incident reporting all assume a level of real-time data capability that many institutions are still building toward.

What This Means for Financial Institutions

The practical implications of this regulatory direction cut across technology, operations, and governance.

Building the Golden Source Architecture

The golden source concept is easier to describe than to implement. Most financial institutions of any scale operate legacy systems that were not designed for real-time data sharing. Core banking platforms, risk engines, treasury management systems, and ledger infrastructure often maintain their own data representations, with reconciliation happening manually or through batch processes.

Moving toward a unified data layer requires significant investment in data architecture: API-based integration between source systems, automated validation pipelines, clear data ownership and lineage documentation, and governance structures that ensure the golden source stays authoritative over time.

The good news is that the technology to do this now exists and is increasingly accessible. Cloud-native data platforms, real-time streaming pipelines, and purpose-built regulatory data management solutions have matured considerably. The gap for most institutions is not technical capability but organizational prioritization.

Standardization as Strategic Advantage

Institutions that embrace standardization proactively — adopting common taxonomies such as the ECB's BIRD (Banks' Integrated Reporting Dictionary), aligning to ISO 20022 for financial messaging, or implementing the XBRL reporting standard — will be better positioned to absorb future regulatory changes without emergency retrofitting.

This matters commercially as well as from a compliance perspective. Institutions with clean, interoperable data are faster to onboard new supervisory requirements, generate fewer reconciliation errors, and spend less on manual remediation. Data quality, in this environment, becomes a source of operational efficiency.

SupTech as the Enabler

On the regulatory side, the push for better supervisory data is creating demand for more sophisticated tools to collect, validate, and analyze that data. This is the domain of SupTech — supervisory technology — a field that has grown substantially over the past five years as central banks and regulators invest in their own analytical capabilities.

The evidence that SupTech investment pays off is accumulating. Research published by the Centre for Economic Policy Research (CEPR) found that after Brazilian financial supervisors deployed AI-enabled SupTech tools, banks in their jurisdiction increased loan-loss provisions by nearly 20% and reduced risky lending by 5%. The tools did not just change how supervision was conducted — they changed how banks behaved under supervision.

For regulators considering SupTech investments, the lesson is that better data collection infrastructure and better analytical tools are not independent investments. They compound. Richer data enables more sophisticated analysis; more sophisticated analysis creates demand for richer data.

Platforms purpose-built for this environment — capable of ingesting structured supervisory datasets, running automated validation rules, generating dashboards for supervisory review, and maintaining audit trails — are increasingly central to how regulators operate. FINA's Integrated Regulatory Platform (IRP) is one example of infrastructure designed specifically for this regulatory data workflow, currently deployed across nearly 15 central banks.

Key Challenges on the Road to Real-Time Supervision

The trajectory toward real-time supervisory data is clear, but the path is not without obstacles.

Legacy system debt is the most immediate barrier for many institutions. Replacing or integrating core systems is expensive, time-consuming, and operationally risky. Most banks will need to pursue incremental modernization strategies rather than wholesale replacement.

Jurisdictional fragmentation complicates the standardization agenda. Banks operating across multiple supervisory regimes — different reporting taxonomies, different data format requirements, different submission timelines — cannot simply adopt one golden source architecture. They need frameworks that can translate between jurisdictions while maintaining consistent internal data governance.

Data privacy and access governance present legal and political challenges as supervisors seek more granular, real-time access. Establishing clear protocols for what data regulators can access, under what conditions, and with what safeguards will require careful negotiation between institutions, regulators, and in some cases legislators.

None of these challenges are insurmountable. But they do mean that the transition will take time, and institutions that start building the underlying capability now will have a meaningful advantage over those that wait for mandates to arrive.

Conclusion

The shift from periodic reporting to continuous supervisory data is not a distant regulatory aspiration. It is underway, shaped by concrete policy signals from the Bank of England, the ECB, and regulators in markets around the world. For financial institutions, the window to build the data infrastructure this model requires is open now — before specific requirements are mandated and the pressure to move quickly becomes intense.

The institutions that will navigate this transition most successfully are those that treat data quality and governance not as compliance obligations but as operational capabilities. Real-time supervisory readiness, in this sense, is not fundamentally different from real-time business intelligence. The same investment in clean, accessible, well-governed data serves both purposes.

Understanding how to architect that capability — and which platforms can support it — is one of the most consequential technology decisions financial institutions face today. For regulators and institutions exploring SupTech-enabled regulatory infrastructure, FINA's team works with central banks and financial supervisors across more than 15 countries on exactly this challenge.

References

  1. Bank of England. (2026, February 4). DP1/26 – Future Banking Data. Prudential Regulation Authority. https://www.bankofengland.co.uk/prudential-regulation/publication/2026/february/future-banking-data-discussion-paper

    1. European Central Bank. (2025, November). Supervisory Priorities 2026–2028. Banking Supervision. https://www.bankingsupervision.europa.eu/framework/priorities/html/ssm.supervisory_priorities202511.en.html

      1. Chartis Research. (2026). The Future of Supervisory Data: Implications of the Bank of England's Discussion Paper. https://www.chartis-research.com/regulations/7947471/the-future-of-supervisory-data-implications-of-the-bank-of-englands-discussion-paper

        1. Forvis Mazars. (2026). ECB Supervisory Priorities 2026–2028: Banks Face Heightened Scrutiny on Geopolitical Risks, Digital Resilience and ICT Capabilities. https://www.forvismazars.com/group/en/insights/latest-insights/ecb-supervisory-priorities-2026-2028

          1. Banking.Vision. (2026). Data as the Foundation: Why Compliance and Reporting Will Determine Survival in 2026. https://banking.vision/en/data-as-the-foundation-compliance-and-reporting-2026/

            1. Grant Thornton. (2025). Resilience Redefined: ECB's Supervisory Priorities for 2026–2028. https://www.grantthornton.es/en/insights/financial-advisory/resilience-redefined-ecbs-supervisory-priorities-for-2026-2028/

              1. European Central Bank. Banks' Integrated Reporting Dictionary (BIRD). https://www.ecb.europa.eu/stats/ecb_statistics/escb/html/index.en.html

                1. XBRL International. XBRL: The Global Standard for Exchanging Business Information. https://www.xbrl.org/

                  1. Centre for Economic Policy Research (CEPR). AI-Enabled SupTech Tools and Their Impact on Bank Behavior. https://cepr.org/

                    1. KPMG. (2025). SSM Supervisory Priorities 2026–2028. https://kpmg.com/xx/en/our-insights/ecb-office/ssm-supervisory-priorities-2026-2028.html

პროდუქტები

სერვისები

ღონისძიებები

Georgian