Executive Summary
- What’s new: The French Prudential Supervision and Resolution Authority published its 2025 annual report, confirming the resilience of the French banking and insurance sectors while announcing increased supervision on multiple fronts, including under the Basel III framework, DORA Regulation, the MiCA Regulation, the AI Act and adjacent regulation, and the new EU Anti-Money Laundering Authority (AMLA).
- Why it matters: The 2026 supervisory program (which includes 213 planned missions, versus the 185 in 2025) will require companies in the banking and insurance sectors to prepare for more intrusive and crosscutting oversight.
- What to do next: Institutions will need to comply immediately with new requirements, document remediation plans and ensure contract compliance with IT service providers. Companies can also comment on AMLA’s draft texts to raise sector-specific issues.
__________
The Autorité de contrôle prudentiel et de résolution (ACPR) has published its 2025 annual report. This reference document both confirms the resilience of the French banking and insurance sectors despite a strained international environment and outlines increased supervision on multiple fronts, including final transposition of the Basel III regulatory framework, entry into force of the EU’s Digital Operational Resilience Act (DORA) Regulation, scaling of the EU’s Markets in Crypto-Assets (MiCA) Regulation, preparation for the EU’s Artificial Intelligence (AI) Act and establishment of the EU Anti-Money Laundering Authority.
This alert summarizes the report’s key messages. The 2026 supervisory program (with 213 planned missions, compared to 185 in 2025) will require banking operators to prepare for more intrusive and crosscutting oversight.
1. A Robust Financial Sector, With Emerging Vulnerabilities to Monitor
The report affirms the soundness of the French banking and insurance sectors in an environment marked by international trade tensions, the Russia-Ukraine conflict and a particularly tense macroeconomic climate.
The French banking sector, underpinned by its diversified universal banking model, recorded net banking income growth of 5.6% (€167.5 billion for the six main groups) and a strengthened Common Equity Tier 1 (CET1) ratio of 15.7%, validated by the European stress test. The French insurance sector presents a Solvency Capital Requirement (SCR) coverage ratio of approximately 250% (the regulatory minimum is 100%), record net inflows of €44 billion in life insurance and a recovery in nonlife insurance technical profitability.
However, the report identifies several areas of concern. Interconnections with nonbank financial intermediation (NBFI) are growing dynamically, which the ACPR chair characterizes as an issue “still poorly understood, particularly in periods of stress.” A pilot “systemwide” stress test exercise involving 25 institutions, conducted jointly by the ACPR, the Autorité des Marchés Financiers (AMF) and the Banque de France, will deliver its results in autumn 2026. Furthermore, the increase in the natural catastrophe surcharge (from 12% to 20%, effective 1 January 2025) illustrates the progressive materialization of climate risk in insurance pricing.
2. Prudential Supervision: Basel III, Simplification and Solvency II
2025 constituted the first year of application of the European prudential framework transposing the Basel III framework, via the EU’s Capital Requirements Regulation (CRR3)1 and the Capital Requirements Directive (CRD6).2 For institutions, this implementation generates a considerable operational burden, including new solvency ratio calculation methods, transitional provisions to be managed in parallel (until 2033), adaptation of information systems and internal-model governance. The ACPR implemented the national options and discretions, as updated by the European Central Bank (ECB) in July 2025, for Less Significant Institutions (LSIs).
Simultaneously, the ACPR is aiming to “simplify … without deregulating while reinforcing a risk-based approach.” Three reports published in late 2025 — from the ECB, the Single Supervisory Mechanism (SSM) and the European Banking Authority (EBA) — recommend the completion of the Banking Union and the Savings and Investment Union to streamline cross-border activities. In the insurance sector, the European Insurance and Occupational Pensions Authority (EIOPA) has undertaken a 25% reduction in its guidelines, and the Solvency II review (Delegated Regulation adopted on 29 October 2025, applicable starting 30 January 2027) strengthens proportionality by adapting requirements to the profile and size of undertakings.
This dynamic creates a paradox: Institutions must comply immediately with new requirements (CRR3, DORA Regulation, the AI Act) while anticipating a future easing of certain obligations. Furthermore, increasing inspections (French enforcers conducted 92 on-site missions in 2025 in the prudential domain and have planned 102 for 2026) and the close monitoring of requests for corrective measures (enforcers issued 453 requests in 2025) require rigorous documentation and tracking of remediation plans.
3. Digital Operational Resilience and Technological Innovation
DORA: A Revealing First Operational Year
Since the entry into force of the DORA Regulation on 17 January 2025,3 institutions have notified nearly 200 major incidents to the ACPR, 15% of which were of malicious origin and 60% of which involved an IT service provider. This latter figure confirms that third-party providers currently constitute the primary source of operational vulnerability for the financial sector. Entities participated in the first collection of registers of information, enabling regulators to identify critical providers at the European level. However, a questionnaire sent to 175 entities reveals that several of them do not yet consider themselves fully compliant, with some having failed to develop action plans to establish specific organizational structures and procedures to enhance their digital resilience.
The monitoring of threat-led penetration testing (TLPT), required for the largest entities, commenced in summer 2025 and will be phased over three years. The 2026 program provides for intensified DORA follow-up, with a focus on incident management, compliance of contracts with IT service providers and the adequacy of the governance framework. Noncompliant entities face an increased risk of administrative enforcement measures.
Artificial Intelligence and Technological Innovations
The EU’s AI Act4 applies to the financial sector, in particular to “high-risk” AI systems (e.g., credit scoring, life- and health-insurance pricing). The ACPR has been designated as the French supervisory authority responsible for enforcing the AI Act for high-risk systems in the French banking and insurance sectors. It is already working with institutions to develop an assessment methodology for AI systems. A survey of nine banking institutions and 35 insurance undertakings has helped the ACPR update its view on effective adoption of AI in an accelerated context.
Furthermore, the ACPR has launched exploratory studies on quantum computing risks (including threats to current cryptographic systems) and the tokenisation of financial services, which will include a strategic review of the MiCA Regulation in 2026. The authority has also established a new Directorate for Innovation, Data, and Technological Risks (DIDRIT), reflecting the growing prominence of these subjects within the supervisory architecture.
4. Anti-Money Laundering and the Establishment of AMLA
The ACPR ensures compliance with anti-money laundering and countering the financing of terrorism (AML/CFT) obligations by the entities it supervises, including digital asset service providers (DASPs) and cryptoasset service providers (CASPs), under shared competences with the AMF. In 2025, regulators assessed the risk profiles of 972 entities and conducted 28 inspections and seven on-site visits, resulting in 30 follow-up letters, five formal notices, two activity restrictions and two disciplinary sanctions. The authorities paid particular attention to DASPs (due to their transition to the MiCA framework), online providers, private banking, correspondent banking and the “banking as a service” model (with the latter subject to heightened vigilance due to the risks of dilution of AML/CFT responsibility and loss of visibility over the end customer).
Among notable developments, the ACPR published a July 2025 report on “bounce accounts” (comptes-rebonds), a money-laundering mechanism that has risen sharply, facilitated by virtual International Bank Account Numbers (IBANs) and the digitalization of payments, to set out best practices for institutions. This phenomenon occurs in a context of tightening international sanctions (e.g., the 20th EU sanctions package against Russia, including a general prohibition on transactions with CASPs established in Russia, effective 24 May 2026).5 The joint update to the guidelines by the Directorate General of the French Ministry of the Economy and Finance (DGT) and ACPR addresses asset freezing, incorporating instant credit transfers and cryptoasset transfers to respond to the growing sophistication of circumvention mechanisms.
Finally, the establishment of AMLA constitutes a paradigm shift for European AML/CFT efforts, comparable to what the SSM represented for prudential supervision in 2014. AMLA will exercise direct supervision over approximately 40 institutions, and more than 60 implementing texts are expected within a short time frame. Institutions likely to fall under this direct supervision must anticipate a level of requirements comparable to that applied to “Significant Institutions.” At this stage, AMLA has set up working groups to prepare the technical standards and guidance for the AML legislative package, with the aim of promoting convergence of practices at the European level. The ACPR encourages all industry participants to comment on draft texts in order to raise sector-specific issues.
5. Consumer Protection: Strengthening the Supervision of Commercial Practices
The ACPR conducted 70 on-site inspections and 12 investigations in the area of commercial practices, reviewed 1,818 advertisements, issued six formal notices and opened five disciplinary proceedings in 2025. The 2026 program provides for 84 missions in this area, signaling bolstered and lasting oversight. The ACPR also reinforced its partnership with the Autorité de régulation professionnelle de la publicité (ARPP) and intensified its efforts against abusive calling practices, particularly from call centres located outside the European Economic Area.
Among the ACPR’s 2025 priorities, the authority examined “everyday protection” insurance products, the indemnification conditions of which proved particularly restrictive, and certain remuneration mechanisms of which are conducive to conflicts of interest. An investigation of “accidents of life” guarantees revealed shortcomings in 75% of the 176 advertisements analyzed. The authority also put an end to the practices of six institutions that made access to a regulated savings account conditional upon holding a deposit account.
Among its supervisory priorities for 2026, the ACPR has included “value for money” (the quality-to-price ratio of insurance products). It expects the market to achieve significant improvement in this area and companies to modify sales practices for compliance. Ten years after the entry into force of the Eckert Act, the ACPR also conducted a review of dormant bank accounts and life insurance contracts, identifying best practices to be generalized.
6. Resolution: Consolidation of the Banking Framework and Emergence of the Insurance Regime
In the area of bank resolution, the EU’s Single Resolution Board (SRB) adopted 38 preventive resolution plans for smaller institutions and 13 plans for significant institutions, designed to organize the orderly management of a potential bank failure. On 25 June 2025, a political agreement was reached on the Crisis Management and Deposit Insurance (CMDI) legislative package, which amends the Single Resolution Mechanism Regulation (SRMR),6 the Bank Recovery and Resolution Directive (BRRD)7and the Deposit Guarantee Schemes Directive (DGSD).8 The CMDI package includes a framework for recourse to the Single Resolution Fund (SRF) and relaxes the use of deposit guarantee schemes (DGS) — aimed at addressing the “blind spot” of medium-sized institutions (“too small to resolve, too big to liquidate”). Final publication is expected in 2026, with application in 2028.
With regard to insurance, work on the Insurance Recovery and Resolution Directive (IRRD) accelerated in 2025. The ACPR is participating in the drafting of delegated acts and in the national transposition expected by January 2027. The convergence of timelines between IRRD (2027), revised Solvency II (2027) and CMDI (2028) creates a significant regulatory compression effect for French financial conglomerates, which will need to adapt their banking and insurance resolution plans simultaneously. For institutions subject to Minimum Requirement for Own Funds and Eligible Liabilities (MREL) obligations, the 2025–2028 period constitutes a critical preparation window.
7. Sustainable Finance: Between ESG Ambitions and the ‘Information Gap’
The EBA’s ESG guidelines, published in early 2025, impose new requirements to identify and manage environmental, social and governance (ESG) risks. However, the Digital Omnibus proposal, by raising the thresholds of the Corporate Sustainability Reporting Directive (CSRD), mechanically reduces the availability of data published by counterparties. The ACPR clarified that the ESG guidelines cannot require institutions to collect data from a counterparty that the counterparty would no longer be required to publish under the revised CSRD. In practice, institutions will need to document their data collection efforts and use data providers or estimates when primary data are no longer available in order to justify their approach to the supervising authority.
In the insurance market, the ACPR deepened its thematic review, conducted across 90% of the French market, of the integration of sustainability risks. For the first time, regulators dedicated an on-site inspection mission to the governance and management of climate and environmental risks within an insurance group, foreshadowing the entry into application in 2027 of the revised Solvency II provisions on sustainability risks.
8. Case Law Developments of the Sanctions Committee
The ACPR Sanctions Committee issued four decisions in 2025, imposing three reprimands and three pecuniary sanctions (ranging from €250,000 to €600,000, with a cumulative amount of €1.35 million, and nominative publication for five years). Decision 2024-029 (€600,000) identified major deficiencies in the management of money laundering and terrorist financing (ML/TF) risks and in alert processing. Decision 2024-0110 (€250,000) found a miscalibration of the automated surveillance system that generated a significant backlog of unprocessed alerts, and insufficient access by the compliance function to the monitoring tools of certain branches.
Notably, the case law exposed the following developments:
(i) The existence of remediation plans is not sufficient; enforcers will take into account only effective implementation as a mitigating circumstance.
(ii) The Sanctions Committee clarified the scope of the “right to remain silent” in the context of on-site inspections, recalling that, in accordance with Conseil d’État case law, the privilege against self-incrimination does not apply prior to the opening of disciplinary proceedings by the ACPR Board, and therefore does not apply during the inspection phase.
9. 2026 Work Program and Practical Implications for Institutions
The ACPR Supervisory Board will structure its 2026 work program around five pillars:
(i) Identifying vulnerabilities and risk monitoring using a proportionate approach (including market risks, sovereign risks, systemwide stress tests and FATF Recommendation 16 on cryptoassets).
(ii) Strengthening governance and key functions, including the sustainability of business models and oversight of outsourced functions.
(iii) Implementing DORA and increasing cybersecurity monitoring.
(iv) Preparing for AI supervision and considering tokenisation (including MiCA strategic review and designation under the AI Act).
(v) Simplifying collection of and strengthening data quality.
Conclusion
ACPR’s 2025 annual report outlines regulatory developments on simultaneous fronts. The convergence of regulatory timelines (for CRR3/CRD6, DORA, the AI Act, MiCA, IRRD, revised Solvency II, the AML/AMLA package and CMDI) creates an unprecedented compliance burden for companies. In parallel, the authority’s simplification agenda creates a temporal paradox: Institutions must invest heavily in compliance today while anticipating that certain requirements may be eased tomorrow.
_______________
1 Regulation (EU) 2024/1623 of the European Parliament and of the Council of 31 May 2024 amending Regulation (EU) No 575/2013 as Regards Requirements for Credit Risk, Credit Valuation Adjustment Risk, Operational Risk, Market Risk and the Output Floor.
2 Directive (EU) 2024/1619 of the European Parliament and of the Council of 31 May 2024 amending Directive 2013/36/EU as Regards Supervisory Powers, Sanctions, Third-Country Branches, and Environmental, Social and Governance Risks.
3 DORA is a European regulation (2022/2554) adopted to strengthen the digital operational resilience of the financial sector, structured around four main pillars: (i) establishing an IT risk management framework; (ii) adopting a specific process for notifying major incidents to authorities; (iii) developing resilience testing programs; and (iv) establishing a third-party risk management framework and a specific oversight framework for critical IT service providers at the European level.
4 European Regulation 2024/1689 of 13 June 2024 on AI establishes a common risk-based framework for regulating the development and use of AI systems in the EU, with stricter obligations for high-risk uses and prohibitions on certain uses deemed unacceptable, such as social scoring. The regulation aims to protect fundamental rights, safety and health while promoting responsible innovation and transparent deployment of AI. (A report by the Haut Comité Juridique de la Place Financière de Paris dated 20 June 2025 examines the legal and regulatory impacts of AI in banking, financial and insurance matters.)
5 This prohibition (article 5bb of EU Regulation 833) represents a shift from the entity-by-entity listing approach to a blanket prohibition targeting all Russia-based cryptoasset service providers. The transaction ban also extends to entities providing cryptoasset services or payment services that operate as a mirror or successor entity of a previously listed entity, addressing the problem of sanctioned platforms reconstituting under new names.
6 Regulation (EU) No 806/2014 of the European Parliament and of the Council of 15 July 2014 Establishing Uniform Rules and a Uniform Procedure for the Resolution of Credit Institutions and Certain Investment Firms in the Framework of a Single Resolution Mechanism and a Single Resolution Fund, and Amending Regulation (EU) No 1093/2010.
7 Directive 2014/59/EU of the European Parliament and of the Council of 15 May 2014 Establishing a Framework for the Recovery and Resolution of Credit Institutions and Investment Firms and Amending Council Directive 82/891/EEC, and Directives 2001/24/EC, 2002/47/EC, 2004/25/EC, 2005/56/EC, 2007/36/EC, 2011/35/EU, 2012/30/EU and 2013/36/EU, and Regulations (EU) No 1093/2010 and (EU) No 648/2012, of the European Parliament and of the Council.
8 Directive 2014/49/EU of the European Parliament and of the Council of 16 April 2014 on Deposit Guarantee Schemes.
9 Sanctions Committee Decision No. 2024-02 of 19 June 2025.
10 Sanctions Committee Decision No. 2024-01 of 7 November 2025.
This memorandum is provided by Skadden, Arps, Slate, Meagher & Flom LLP and its affiliates for educational and informational purposes only and is not intended and should not be construed as legal advice. This memorandum is considered advertising under applicable state laws.