Skip to content
EBA · EU-wide

Incident reporting clocks — four regimes, one incident

Fintech Passport
August 21, 2026 · 4-min read
Incident reporting clocks — four regimes, one incident

A single operational incident can start four reporting clocks simultaneously, running to different authorities on different deadlines with different tests. The classification decisions that determine each of them have to be made in the first hours — by people who are also trying to restore service. Which is why the only thing that reliably works is deciding the framework in advance and rehearsing it, because nobody reads a regulation at 2am.

1. The four clocks

RegimeTriggerShape of the obligation
DORAA major ICT-related incident, on the classification criteriaStaged: an initial notification, an intermediate report, and a final report
Data protectionA personal data breachNotification to the supervisory authority within 72 hours of becoming aware, where the threshold is met
AMLSuspicion arising from the incidentEvent-driven, promptly, to the financial intelligence unit
Prudential and conductMateriality under national notification dutiesAd hoc notification to the supervisor

2. DORA is staged, which changes the work

Major ICT incident reporting for payment firms moved from PSD2 Article 96 to DORA Article 19, and the staged structure — initial, intermediate, final — is what makes it operationally different from a single-shot notification.

Two consequences follow. First, the initial notification is due while you still know very little, so the process has to be able to file with incomplete information rather than waiting for certainty. Second, the final report arrives long after the incident is closed and the team has moved on, which means root-cause and remediation detail has to be captured contemporaneously or it will be reconstructed from memory.

The classification test itself is the gate, and it should be a decision tree someone can apply under pressure — not a paragraph of regulation to be interpreted during an outage.

3. What to do in hour one

The pattern that works is a single triage step that answers four questions before any report is drafted:

  • Is it a major ICT incident on the classification criteria? If unclear, treat as yes and downgrade later — the cost of an unnecessary initial notification is far lower than a late one.
  • Is personal data involved? If yes, the 72-hour clock has already started, from awareness.
  • Does it raise a suspicion? A compromise involving customer funds frequently does, and that is a separate obligation to a separate authority.
  • Is it materially notifiable to the prudential or conduct supervisor under national duties?

Assigning that triage to a named role — not a committee — is the single highest-value design decision. Committees convene; clocks do not wait.

4. The confidentiality tension

One interaction deserves specific attention because it can go badly wrong. Where an incident engages both incident reporting and AML suspicion reporting, the tipping-off prohibition applies to the latter — and it prohibits disclosing that activity is being assessed, not merely that a report has been made.

Incident communications, customer notifications and status pages are all disclosure channels. A firm managing an incident that also involves a suspicion needs its incident communications reviewed against that prohibition before they go out, which is a step nobody has time for unless it is already in the runbook.

5. A worked case

Facts: a payment platform detects unauthorised access to an internal system. Customer records were accessible; a number of unauthorised payments appear to have been initiated.

What the clocks do: the ICT classification test is applied immediately and, if met, the initial DORA notification is prepared. Personal data was accessible, so the 72-hour data-protection clock runs from awareness. The unauthorised payments raise a suspicion, engaging the AML reporting duty. And the operational impact may meet a national notification threshold.

What the practitioner does: runs the triage, opens all four workstreams in parallel with named owners, and — critically — routes all external communications through a single reviewer who holds both the incident facts and the tipping-off constraint. The four reports then say consistent things, which is the outcome that matters most: inconsistency between reports to different authorities about the same incident is a finding in its own right.

FAQ

Do the clocks run in sequence?

No. They run in parallel from their own triggers, and the data-protection clock runs from awareness rather than from containment.

What if the DORA classification is unclear?

Treat it as in scope and downgrade later if appropriate. An unnecessary initial notification costs far less than a late one.

What is the most common cross-regime mistake?

Incident communications that breach the tipping-off prohibition, because the prohibition covers disclosing that activity is being assessed — not only that a report was filed.


Related: Major ICT incident reporting · Tipping-off · Reporting suspicions

Related reads.