EBA integrates MiCA into its system of risk indicators: From footnote to core of supervisory analytics

How the EBA update of January 28, 2026, changes the risk management of banks, FinTechs and CASPs
1. Core signal: MiCA becomes part of the regular Risk Dashboard
On January 28, 2026, the European Banking Authority (EBA) published an updated list of Risk Assessment Indicators and a revised version of the Methodological Guide. These form the methodological basis for central analysis instruments such as the EBA Risk Dashboard, the Risk Assessment Report and the Transparency Exercise, which are used by national supervisors, decision-makers and investors to assess the stability of the EU financial sector.
Core of the update: For the first time, the general list of EBA risk indicators includes metrics relating to MiCA-relevant activities (crypto-assets, tokens) and investment firms. In the future, crypto risks will thus be analysed according to the same methodological principles as classic banking risks – embedded in a uniform set of key figures, macroprudential evaluations and stress testing approaches.
Practical consequence: Institutions that have previously taken a separate view of "classic" risks and MiCA metrics are increasingly faced with the expectation of providing a consistent, integrated risk overview. For groups with hybrid business models – such as banks with crypto services, FinTechs with a CASP licence or issuers of ART/EMT – this means gradually aligning internal KRIs and Risk Dashboards with the updated EBA standards.
2. Classification: The development of the EBA risk indicators
The EBA's system of Key Risk Indicators (KRIs) has been gradually developed since 2011. The starting point was a reporting approach that was partly based on voluntary data and only limited harmonised definitions – with correspondingly limited comparability between countries and institutions.
With the introduction of the uniform supervisory reporting (ITS on supervisory reporting, COREP/FINREP, XBRL taxonomies), the indicators were standardised and directly linked to defined reporting fields. The set was continuously expanded, including:
- Indicators for Resolution and MREL,
- Key figures on credit risk under the Standardised Approach,
- ESG indicators for monitoring climate risks,
- Metrics within the Banking Package (CRR3/CRD6),
- Key figures on operational risks and profitability under IFRS 9.
3. Architecture of the updated risk indicator set
3.1. Central risk blocks
The updated Methodological Guide classifies the indicators according to risk types and analysis fields. The most important clusters are:
| Risk category | Typical key figures |
|---|---|
| Liquidity Risk (LIQ) | LCR, NSFR, Core Funding Ratio, ratio of liquid assets to short-term liabilities |
| Funding Risk (FND) | Asset Encumbrance, refinancing structure (deposits/market), Loan-to-Deposit, currency/country concentration |
| Asset Quality (AQT) | NPE/NPL ratio, Texas Ratio, reserve coverage, IFRS 9 staging, movements between stages |
| Profitability (PFT) | RoE, RoA, Net Interest Margin, Cost-to-Income, stability of the result |
| Solvency (SVC) | CET1, Tier 1 and total capital ratios, fulfilment of regulatory capital requirements |
| Concentration (CON) | Large exposures, sector and country concentrations |
| Operational Risk (OPR) | Operational loss events, incident frequency, restart capability |
| Market Risk (MKR) | Interest rate risk, FX exposure, commodity risks |
| ESG Risk | Climate and environmental risk indicators, governance metrics |
| Sovereign Risk (SVR) | Exposures to states, home country concentration |
| Standardised Approach (CRS) | Credit risk key figures under the standardised approach, CCR exposure |
| Resolution / MREL | MREL fulfilment, bail-in capability, resolvability |
The following have been added in particular:
- Indicators for Investment Firms: Metrics for assessing market and operational risks of companies that provide investment services.
- MiCA indicators (Part I.18): Key figures for monitoring MiCA-relevant crypto activities, for example for issuers of ART/EMT and CASPs.
3.2. Methodological principles
Part III of the Methodological Guide describes the methodological cornerstones for the compilation and evaluation of the indicators:
- Scope and consolidation level: Definition of the consolidation level at which key figures are calculated (individual institution, subgroup, total group).
- Data basis: Assignment of the indicators to concrete COREP/FINREP templates and further reporting requirements.
- Handling of negative values: Rules for the treatment of negative numerators/denominators (e.g. in the event of losses or negative equity).
- Use of statistical measures: Use of averages, medians and percentiles for peer comparisons as well as explanations on the "follow-the-money" approach.
4. MiCA in the EBA Risk Assessment: From technical standards to an integrated world of key figures
4.1. MiCA criteria as a starting point
In its roles and technical recommendations under MiCA – in particular on the classification of significant ART/EMT – the EBA has already previously described indicators for assessing the significance of crypto-assets. These include:
- Issue volume and circulation size,
- Number of users and transaction volumes,
- Interconnectivity with the financial sector,
- Composition and quality of the reserves,
- Concentration of holders (in particular financial institutions),
- Cross-border significance and international distribution.
4.2. What the 2026 update adds
By including a separate MiCA chapter block (I.18) in the Methodological Guide and supplementing the list of indicators, the EBA makes it clear that MiCA key figures are being integrated into the general risk indicator framework.
In terms of content, this means:
- MiCA-related variables are placed in the same methodological framework as liquidity, capital or ESG indicators (peer group analyses, statistical aggregation, outlier treatment).
- Crypto activities can be mapped more systematically in the future within the framework of the EBA instruments (Risk Dashboard, Risk Assessment Report, thematic analyses).
- The reporting architecture (including XBRL taxonomies) is being gradually expanded so that MiCA data can be recorded and evaluated in a structured manner.
4.3. Concrete implications for the crypto perimeter
The following points in particular arise for CASPs, issuers of ART/EMT and banks with relevant crypto exposures:
- Greater visibility in supervisory analytics:
- Stress Testing Perspective:
- Reference for national authorities:
5. From strategy to implementation: What changes for banks, FinTechs and CASPs
5.1. Banks and classic institutions
The EBA makes it clear that the update itself does not create any additional Supervisory Reporting obligations. Nevertheless, the effects are substantial:
- Uniform "language" of risk indicators:
- Better controllability of supervisory dialogues:
- Focus on consumer protection:
5.2. FinTechs and Investment Firms
For FinTechs and securities firms, the risk profile is increasingly coming into prudential focus:
- Operational Risk becomes more measurable:
- Market risk and leverage more clearly in view:
- Integrated view of hybrid models:
5.3. Crypto players under MiCA
For CASPs and issuers of ART/EMT, the EBA's signal can be summarised as follows:
- MiCA key figures will not be a separate "add-on", but part of the regular indicator set that is used for sector-wide analyses.
- The quality and granularity of MiCA reporting is therefore becoming increasingly important – not only for the direct supervision of individual institutions, but also in the context of macroprudential assessments.
6. How NEXORA supports the adaptation
NEXORA Unternehmensberatung GmbH supports banks, FinTechs and CASPs in adapting their risk management and reporting structures to the updated EBA methodology and the MiCA framework conditions.
6.1. Gap analysis of the risk indicators
- Comparison of the existing KRIs with the descriptions and formulas in the Methodological Guide.
- Mapping of COREP/FINREP fields to the EBA risk indicators and identification of data and process gaps.
- Peer comparison based on published EBA data (Risk Dashboard, Transparency Exercise).
- Establishment of a MiCA reporting pipeline (including XBRL taxonomies), coordinated with the EBA and MiCA requirements.
- Design of an integrated Risk Dashboard in which crypto metrics are managed on an equal footing with classic risk types.
- Establishment of a regular benchmark against sector medians and percentiles.
- Selection and implementation of suitable RegTech solutions for COREP/FINREP and MiCA reports.
- Establishment of data quality controls (plausibility and consistency checks) before reporting to supervisors.
- Ongoing support with changes to templates, guidelines and technical standards.
- Integration of MiCA and crypto key figures into risk appetite, capital planning and liquidity management.
- Development of scenarios and stress tests that take crypto exposures into account.
- Adaptation of governance so that the Management Board/Supervisory Board addresses crypto risks as a fixed component of risk reporting.
7. Compact To-Do List for CRO and Head of Risk
- Compare the formulas and definitions of the most important KRIs with the Methodological Guide and adapt internal calculations where appropriate.
- Compare the structure and content of the management dashboards with the EBA risk clusters – including MiCA and Investment Firm blocks.
- Analyse MiCA data management and reporting readiness, define implementation plan (data, systems, processes).
- Gradually integrate MiCA metrics into ICAAP/ILAAP, risk appetite and stress tests.
- Anchor a structured monitoring of EBA publications (guides, reporting standards, guidelines) in the compliance and risk plan.
- Establish peer group benchmarking in order to identify deviations from the sector profile at an early stage.
About NEXORA Unternehmensberatung GmbH:
NEXORA Unternehmensberatung GmbH, based in Vienna, supports banks, FinTechs and crypto service providers (CASPs) in the DACH region in the implementation of European regulatory requirements – with a focus on MiCA, DORA, AML/CFT, CSRD and digital reporting. The offering combines specialist regulatory expertise with practical implementation in organisation, processes and IT systems.
Our focus in the context of the EBA update and MiCA are in particular:
- Development and optimisation of integrated Risk Dashboards (including MiCA metrics),
- Design and implementation of MiCA reporting pipelines (XBRL-capable),
- ICAAP/ILAAP integration of crypto exposures,
- Selection and introduction of RegTech solutions for supervisory reporting and data quality.
Need a consultation?
Book a free initial consultation with the NEXORA team.