Newsroom ·

FI implements second banking package: new regulations, licensing requirements and updated disclosures

regulatorycapital-requirements

What happened

On 16 June 2026, Finansinspektionen’s board decided on a set of new and amended regulations (FFFS 2026:9–22) to implement the EU’s second banking package – the amended Capital Requirements Directive (CRD6) and the Capital Requirements Regulation (CRR3). The regulations were published on 17 June. Most entered into force on 1 July 2026, with a few provisions delayed until 11 January 2027.

The package introduces rules for third-country branches, requirements for certain financial holding companies, and information provisions for the special management-approval procedure. It also amends rules on governance, risk management and control, and adds requirements for ESG-related specific plans and stress tests. FI also made adjustments beyond those required by the banking package, including changes prompted by the revised investment-firms directive.

The amended FFFS touch many areas: payment institutions (FFFS 2010:3), liquidity-risk disclosures (2010:7), remuneration (2011:1), governance (2014:1), supervisory requirements and capital buffers (2014:12), credit risk (2018:16), branch reporting (2020:27), ownership and management assessments (2023:13), and clearing and settlement (2024:5). Three new regulations cover third-country branch licensing and requirements.

FI also published two additional documents. On 18 June it updated its annual CRD supervisory disclosures under Article 143 CRD. The material contains the texts of Swedish laws implementing the CRD, information on exercised options and discretions, the SREP criteria and methods, and aggregated statistical data on CRD/CRR implementation in Sweden.

On 1 July, FI issued a comprehensive overview of the new licensing and notification obligations under the amended Swedish laws – the Särskild tillsynslag (2014:968) and the Bank- och finansieringsrörelselag (2004:297). The overview lists prior-approval requirements for certain acquisitions and transactions, a new prior-notification procedure for management appointments in large institutions, and a license requirement for third-country firms providing core banking services through a Swedish branch. It also clarifies that from 1 July 2026 the previous license requirement for certain large property acquisitions under LBF chapter 7, section 12 ceases to apply, though some transactions may still be subject to the new rules.

Relevance for Swedish reporting entities

For Sigill’s primary customer segment – Swedish payment institutions, e-money institutions and registered payment service providers – the most directly relevant change is the amendment to FFFS 2010:3 (regulations on payment institutions and registered payment service providers). While FFFS 2010:3 does not impose COREP reporting, it may affect licensing conditions, governance standards or other operational obligations these firms must meet. Sigill’s customers using its service for FI’s national returns (betesa, aml, psd2mi) should check whether any internal policies need updating, especially since FI has made changes beyond the strict banking-package requirements, including adaptations prompted by the revised investment-firms directive.

For credit institutions and large investment firms – the next segment that Sigill is targeting – the changes are far more extensive. The amended FFFS directly modify the supervisory framework that underpins COREP reporting. Requirements for third-country branches, updated governance and risk-control rules, ESG-related plans, and new stress-test obligations will all feed into the data firms submit in COREP and, for some institutions, FINREP. The updated SREP criteria and the published supervisory disclosures signal how FI will assess capital adequacy, which may influence Pillar 2 add-ons and the internal capital adequacy assessment process (ICAAP).

What needs to happen next

Credit institutions and large investment firms subject to COREP must review the new and amended regulations immediately, as compliance is now mandatory. Pay particular attention to changes in governance (FFFS 2014:1), credit risk (2018:16), liquidity risk (2010:7) and remuneration (2011:1). The new licensing and notification procedures are active; any planned management appointments or acquisitions must follow the new routes described on FI’s website.

For payment institutions, the impact on Sigill’s reporting service is limited, as the core national returns are not directly affected. However, the amendment to FFFS 2010:3 may require a review of internal policies, and firms should verify whether any new governance or notification obligations apply to them.

Sigill will continue to monitor whether the new requirements lead to changes in the EBA’s Data Point Model or COREP templates and will incorporate any necessary updates at the earliest opportunity.

Sources: FI: New and amended regulations following changes to the Capital Requirements Directive · FI updates disclosures under the Capital Requirements Directive (CRD) · FI: The banking package: New licences and notifications under the Capital Requirements Directive