Back to all articles
COMPLIANCE

EBA integrates MiCA into its system of risk indicators: From footnote to core of supervisory analytics

·
10 min
EBA integrates MiCA into its system of risk indicators: From footnote to core of supervisory analytics

How the EBA update of January 28, 2026, changes the risk management of banks, FinTechs and CASPs

1. Core signal: MiCA becomes part of the regular Risk Dashboard

On January 28, 2026, the European Banking Authority (EBA) published an updated list of Risk Assessment Indicators and a revised version of the Methodological Guide. These form the methodological basis for central analysis instruments such as the EBA Risk Dashboard, the Risk Assessment Report and the Transparency Exercise, which are used by national supervisors, decision-makers and investors to assess the stability of the EU financial sector.

Core of the update: For the first time, the general list of EBA risk indicators includes metrics relating to MiCA-relevant activities (crypto-assets, tokens) and investment firms. In the future, crypto risks will thus be analysed according to the same methodological principles as classic banking risks – embedded in a uniform set of key figures, macroprudential evaluations and stress testing approaches.

Practical consequence: Institutions that have previously taken a separate view of "classic" risks and MiCA metrics are increasingly faced with the expectation of providing a consistent, integrated risk overview. For groups with hybrid business models – such as banks with crypto services, FinTechs with a CASP licence or issuers of ART/EMT – this means gradually aligning internal KRIs and Risk Dashboards with the updated EBA standards.

2. Classification: The development of the EBA risk indicators

The EBA's system of Key Risk Indicators (KRIs) has been gradually developed since 2011. The starting point was a reporting approach that was partly based on voluntary data and only limited harmonised definitions – with correspondingly limited comparability between countries and institutions.

With the introduction of the uniform supervisory reporting (ITS on supervisory reporting, COREP/FINREP, XBRL taxonomies), the indicators were standardised and directly linked to defined reporting fields. The set was continuously expanded, including:

  • Indicators for Resolution and MREL,
  • Key figures on credit risk under the Standardised Approach,
  • ESG indicators for monitoring climate risks,
  • Metrics within the Banking Package (CRR3/CRD6),
  • Key figures on operational risks and profitability under IFRS 9.
The Methodological Guide has thus become a dynamic reference document that is regularly adapted to new regulations and reporting requirements. The update of January 2026 follows this logic, but extends the framework to include two previously missing building blocks: MiCA indicators and indicators for Investment Firms. In doing so, the EBA underlines that crypto-assets and securities firms are no longer regarded as a marginal issue, but as an integral part of the overall prudential picture.

3. Architecture of the updated risk indicator set

3.1. Central risk blocks

The updated Methodological Guide classifies the indicators according to risk types and analysis fields. The most important clusters are:

Risk categoryTypical key figures
Liquidity Risk (LIQ)LCR, NSFR, Core Funding Ratio, ratio of liquid assets to short-term liabilities
Funding Risk (FND)Asset Encumbrance, refinancing structure (deposits/market), Loan-to-Deposit, currency/country concentration
Asset Quality (AQT)NPE/NPL ratio, Texas Ratio, reserve coverage, IFRS 9 staging, movements between stages
Profitability (PFT)RoE, RoA, Net Interest Margin, Cost-to-Income, stability of the result
Solvency (SVC)CET1, Tier 1 and total capital ratios, fulfilment of regulatory capital requirements
Concentration (CON)Large exposures, sector and country concentrations
Operational Risk (OPR)Operational loss events, incident frequency, restart capability
Market Risk (MKR)Interest rate risk, FX exposure, commodity risks
ESG RiskClimate and environmental risk indicators, governance metrics
Sovereign Risk (SVR)Exposures to states, home country concentration
Standardised Approach (CRS)Credit risk key figures under the standardised approach, CCR exposure
Resolution / MRELMREL fulfilment, bail-in capability, resolvability

The following have been added in particular:

  • Indicators for Investment Firms: Metrics for assessing market and operational risks of companies that provide investment services.
  • MiCA indicators (Part I.18): Key figures for monitoring MiCA-relevant crypto activities, for example for issuers of ART/EMT and CASPs.

3.2. Methodological principles

Part III of the Methodological Guide describes the methodological cornerstones for the compilation and evaluation of the indicators:

  • Scope and consolidation level: Definition of the consolidation level at which key figures are calculated (individual institution, subgroup, total group).
  • Data basis: Assignment of the indicators to concrete COREP/FINREP templates and further reporting requirements.
  • Handling of negative values: Rules for the treatment of negative numerators/denominators (e.g. in the event of losses or negative equity).
  • Use of statistical measures: Use of averages, medians and percentiles for peer comparisons as well as explanations on the "follow-the-money" approach.
For institutions, the Guide thus functions as a referential reference work that transparently shows how the EBA converts raw data from supervisory reporting into aggregated risk indicators and dashboards.

4. MiCA in the EBA Risk Assessment: From technical standards to an integrated world of key figures

4.1. MiCA criteria as a starting point

In its roles and technical recommendations under MiCA – in particular on the classification of significant ART/EMT – the EBA has already previously described indicators for assessing the significance of crypto-assets. These include:

  • Issue volume and circulation size,
  • Number of users and transaction volumes,
  • Interconnectivity with the financial sector,
  • Composition and quality of the reserves,
  • Concentration of holders (in particular financial institutions),
  • Cross-border significance and international distribution.
These criteria were initially used primarily in the context of Delegated Acts and technical standards for MiCA – i.e. with a relatively narrow focus on significance classification and supervisory intensity.

4.2. What the 2026 update adds

By including a separate MiCA chapter block (I.18) in the Methodological Guide and supplementing the list of indicators, the EBA makes it clear that MiCA key figures are being integrated into the general risk indicator framework.

In terms of content, this means:

  • MiCA-related variables are placed in the same methodological framework as liquidity, capital or ESG indicators (peer group analyses, statistical aggregation, outlier treatment).
  • Crypto activities can be mapped more systematically in the future within the framework of the EBA instruments (Risk Dashboard, Risk Assessment Report, thematic analyses).
  • The reporting architecture (including XBRL taxonomies) is being gradually expanded so that MiCA data can be recorded and evaluated in a structured manner.

4.3. Concrete implications for the crypto perimeter

The following points in particular arise for CASPs, issuers of ART/EMT and banks with relevant crypto exposures:

  • Greater visibility in supervisory analytics:
MiCA key figures become part of the regular data budget that the EBA uses for sector-wide risk analyses and published dashboards.
  • Stress Testing Perspective:
It is plausible that MiCA indicators will be taken into account in EU-wide stress tests and scenario analyses in the future, e.g. to assess the impact of market stress on users of crypto-assets.
  • Reference for national authorities:
National supervisors receive a European reference framework on how to integrate MiCA data into their own risk frameworks – an important factor for cross-border groups that want to minimise fragmentation risks.

5. From strategy to implementation: What changes for banks, FinTechs and CASPs

5.1. Banks and classic institutions

The EBA makes it clear that the update itself does not create any additional Supervisory Reporting obligations. Nevertheless, the effects are substantial:

  • Uniform "language" of risk indicators:
Institutions that closely align their internal KRIs – for example for liquidity, asset quality or capital – with the formulas in the Methodological Guide can better reflect their own profile with the EBA evaluations and peer data.
  • Better controllability of supervisory dialogues:
If management reports are based on the same key figures as EBA dashboards, deviations and anomalies become visible at an early stage – before they escalate into supervisory issues.
  • Focus on consumer protection:
In its 2026 work programme, the EBA signals that updated risk indicators will also be used to identify priorities in consumer protection. Banks with a strong retail and crypto focus should take this into account in their risk and product governance.

5.2. FinTechs and Investment Firms

For FinTechs and securities firms, the risk profile is increasingly coming into prudential focus:

  • Operational Risk becomes more measurable:
Standardised KRIs on loss events, incidents and restart capabilities complement qualitative assessments and create comparability with banks.
  • Market risk and leverage more clearly in view:
Investment Firms are increasingly faced with structured requirements for monitoring market positions and leverage – especially in trading and portfolio management.
  • Integrated view of hybrid models:
For providers that combine payment services, investment services and crypto services, a silo-like risk view is becoming less and less sustainable. Supervisors will pay more attention to the consolidated risk profile and the interactions between the types of risk.

5.3. Crypto players under MiCA

For CASPs and issuers of ART/EMT, the EBA's signal can be summarised as follows:

  • MiCA key figures will not be a separate "add-on", but part of the regular indicator set that is used for sector-wide analyses.
  • The quality and granularity of MiCA reporting is therefore becoming increasingly important – not only for the direct supervision of individual institutions, but also in the context of macroprudential assessments.

6. How NEXORA supports the adaptation

NEXORA Unternehmensberatung GmbH supports banks, FinTechs and CASPs in adapting their risk management and reporting structures to the updated EBA methodology and the MiCA framework conditions.

6.1. Gap analysis of the risk indicators

  • Comparison of the existing KRIs with the descriptions and formulas in the Methodological Guide.
  • Mapping of COREP/FINREP fields to the EBA risk indicators and identification of data and process gaps.
  • Peer comparison based on published EBA data (Risk Dashboard, Transparency Exercise).
6.2. Integration of MiCA metrics into the Risk Dashboard
  • Establishment of a MiCA reporting pipeline (including XBRL taxonomies), coordinated with the EBA and MiCA requirements.
  • Design of an integrated Risk Dashboard in which crypto metrics are managed on an equal footing with classic risk types.
  • Establishment of a regular benchmark against sector medians and percentiles.
6.3. Automation of Regulatory Reporting
  • Selection and implementation of suitable RegTech solutions for COREP/FINREP and MiCA reports.
  • Establishment of data quality controls (plausibility and consistency checks) before reporting to supervisors.
  • Ongoing support with changes to templates, guidelines and technical standards.
6.4. Integration into ICAAP/ILAAP and Governance
  • Integration of MiCA and crypto key figures into risk appetite, capital planning and liquidity management.
  • Development of scenarios and stress tests that take crypto exposures into account.
  • Adaptation of governance so that the Management Board/Supervisory Board addresses crypto risks as a fixed component of risk reporting.

7. Compact To-Do List for CRO and Head of Risk

  • Compare the formulas and definitions of the most important KRIs with the Methodological Guide and adapt internal calculations where appropriate.
  • Compare the structure and content of the management dashboards with the EBA risk clusters – including MiCA and Investment Firm blocks.
  • Analyse MiCA data management and reporting readiness, define implementation plan (data, systems, processes).
  • Gradually integrate MiCA metrics into ICAAP/ILAAP, risk appetite and stress tests.
  • Anchor a structured monitoring of EBA publications (guides, reporting standards, guidelines) in the compliance and risk plan.
  • Establish peer group benchmarking in order to identify deviations from the sector profile at an early stage.

About NEXORA Unternehmensberatung GmbH:

NEXORA Unternehmensberatung GmbH, based in Vienna, supports banks, FinTechs and crypto service providers (CASPs) in the DACH region in the implementation of European regulatory requirements – with a focus on MiCA, DORA, AML/CFT, CSRD and digital reporting. The offering combines specialist regulatory expertise with practical implementation in organisation, processes and IT systems.

Our focus in the context of the EBA update and MiCA are in particular:

  • Development and optimisation of integrated Risk Dashboards (including MiCA metrics),
  • Design and implementation of MiCA reporting pipelines (XBRL-capable),
  • ICAAP/ILAAP integration of crypto exposures,
  • Selection and introduction of RegTech solutions for supervisory reporting and data quality.
NEXORA works closely with management, risk and compliance teams to ensure that regulatory requirements are not only met "on paper", but are translated into robust control and decision-making processes.

Need a consultation?

Book a free initial consultation with the NEXORA team.

Free Consultation
EBA integrates MiCA into its system of risk indicators: From footnote to core of supervisory analytics | NEXORA