Skip to content
RiskTemplates · The Daily Brief Monday, August 3, 2026
Wire The Exodus OFAC Settlement: What a $3.1M Crypto Wallet Enforcement Action Teaches About Sanctions Compliance Programs JUL 30

Feature Business Continuity

The ECB Just Ran 110 Banks Through a Geopolitical Reverse Stress Test. Here's What US Banks' BCPs Are Missing.

On July 31, 2026, the ECB published results of its thematic geopolitical risk reverse stress test covering 110 directly supervised euro area banks—and urged the sector to improve. The OCC's Spring 2026 Semiannual Risk Perspective added geopolitical risk as a prominent new concern for the first time. Most US bank business continuity programs are built for IT failures and natural disasters. They are not built for this class of scenario.

Table of Contents

TL;DR

  • On July 31, 2026, the ECB published results of a geopolitical risk reverse stress test covering 110 directly supervised euro area banks and urged the sector to improve its geopolitical risk assessment capabilities
  • The OCC’s Spring 2026 Semiannual Risk Perspective added geopolitical risk as a prominent new topic—flagging sanctions compliance, state-sponsored cyberattacks, and interconnected multi-channel shocks
  • Most US bank BCPs are built around IT failures, natural disasters, and pandemic scenarios; they do not include geopolitical scenario types—sanctions cascade, state-sponsored cyber, critical technology vendor with geopolitical exposure, or energy shock
  • The ECB findings are a publicly available stress test benchmark; US regulators are watching what European supervisors found, and the gaps ECB flagged in 110 institutions likely exist in US peer institutions too

A Benchmark Nobody Was Ready For

The ECB didn’t publish a warning. It published results.

On July 31, 2026, the European Central Bank published the findings of its thematic geopolitical risk reverse stress test covering 110 euro area banks under direct ECB supervision. The exercise was part of a supervisory priority the ECB has been building since declaring geopolitical risk a priority theme for 2026-28. Banks developed geopolitical narratives, built out scenario mechanics, and identified the conditions that could threaten their viability.

The ECB’s verdict: banks need to improve.

That’s a careful way of saying that a significant portion of 110 large European financial institutions—institutions with dedicated risk management infrastructure, board-level oversight frameworks, and DORA operational resilience obligations—hadn’t thought hard enough about geopolitical scenarios in their business continuity programs.

If that’s true of those banks, it’s almost certainly true of yours.


Why Geopolitical Risk Is Not Your Existing BCP’s Problem

The standard bank BCP was built for a specific failure mode: a single-system or single-location disruption with a defined recovery timeline. Datacenter fire. Hurricane. Pandemic. Core banking outage. These scenarios have clear anatomy: an event, an affected system or team, a recovery objective, and a tested playbook.

Geopolitical risk doesn’t work that way.

A geopolitical stress event is not a single failure. It’s a combination of simultaneous, interacting disruptions that hit revenue, costs, liquidity, supplier continuity, compliance exposure, and reputational standing at the same time through channels that weren’t all part of the same threat model. An escalating conflict in the Middle East could simultaneously: spike energy prices affecting data center operating costs, trigger OFAC action against counterparties in your commercial loan portfolio, increase foreign state-sponsored cyberattack frequency against US financial infrastructure, and create credit stress in energy-sector concentrations on your balance sheet.

None of those four things is the kind of “scenario” your tabletop exercise was designed to handle. Your datacenter-outage scenario exercises IT recovery. Your pandemic scenario exercises personnel continuity. Nothing in a standard FFIEC BCM program connects those four threads simultaneously and asks: what do we do when all of this is happening at once?

That’s what the ECB was testing. And the answer it found was: most banks don’t have a ready answer.


The OCC’s Spring 2026 Signal Was Already There

The ECB’s July 31 publication is the most recent data point, but the signal had already appeared in US supervision.

The OCC’s Spring 2026 Semiannual Risk Perspective added geopolitical risk as a prominent concern—an addition that prior editions of the report hadn’t included. The OCC identified two specific channels:

Sanctions and BSA/AML compliance risk. Geopolitical tensions increase the risk that customers, counterparties, or payment flows become subject to OFAC designations or BSA/AML violations. The OCC noted that compliance systems may be strained by rapid, unexpected OFAC action affecting customer segments that previously appeared low-risk. The pace of geopolitical-driven sanctions changes (Russia, Iran, now Middle East and potential Taiwan scenarios) has exceeded the update cycle of many banks’ AML screening programs.

State-sponsored cyber threats. The OCC flagged sophisticated foreign state-sponsored actors as an elevated threat to financial services specifically—targeting not just individual institutions but the payment infrastructure and critical third-party providers those institutions share. The concern is not just a breach at one bank but a coordinated attack on shared infrastructure that creates correlated operational failures across multiple institutions simultaneously.

The OCC then layered on the interconnectedness point: that multiple manageable individual risks—credit stress, cyber threats, technology failures, fraud—could interact with geopolitical shocks in ways that amplify impact beyond what single-risk analysis would predict.

This is the OCC telling examiners what to look for. And what they’re looking for is whether your risk program has thought about these scenarios.


Five Geopolitical BCP Scenarios Most US Banks Don’t Have

Based on the ECB’s testing approach and the OCC’s framing, here are the five geopolitical scenario types that should exist in a US bank’s BCP program but typically don’t:

1. Sanctions Cascade

What happens: OFAC issues a rapid, broad designation affecting a customer segment, payment rail, or correspondent bank that your institution relies on. You have 24-48 hours to identify affected relationships and halt transactions before becoming complicit in sanctions violations.

Why standard BCP misses it: Sanctions cascades don’t show up in IT recovery or personnel continuity exercises. They require simultaneous action from legal, compliance, operations, credit, and customer service—and the decision authority matrix for “we’re blocking all wire transactions with X country effective immediately” almost certainly hasn’t been tested.

What the scenario exercise should test: Who declares the sanctions emergency? Who can authorize temporary account freezes at scale? How long does it take to screen the entire affected customer base? What’s the customer communication protocol?

2. State-Sponsored Cyberattack on Shared Infrastructure

What happens: A nation-state actor executes a coordinated cyberattack targeting payment infrastructure—SWIFT, ACH networks, or a critical cloud provider—used by multiple financial institutions simultaneously. Your individual institution’s defenses are intact, but the shared infrastructure you depend on is unavailable.

Why standard BCP misses it: Standard BCP tabletops model your own datacenter going offline. They don’t model the scenario where your infrastructure is fine but SWIFT is degraded, ACH is down, and Fedwire has restricted processing capacity for 48 hours due to a coordinated attack affecting multiple participants.

What the scenario exercise should test: What’s your payment fallback when three rails are unavailable simultaneously? How do you communicate with customers who can’t receive ACH payroll or wire transfers? What’s your liquidity position if interbank settlement is disrupted for 72 hours?

3. Critical Technology Vendor with Geopolitical Exposure

What happens: A core software vendor, cloud provider, or critical data provider is suddenly subject to export controls or sanctions due to its country of incorporation or ownership—or its own supply chain has geopolitical exposure that creates a sudden service disruption.

Why standard BCP misses it: BCP testing exercises at community and regional banks typically focus on whether the vendor can restore service after a technical failure, not on whether the vendor relationship itself becomes legally untenable overnight due to geopolitical action. As the software supply chain has globalized, many core banking system components have dependencies in jurisdictions that wouldn’t have been flagged as geopolitical exposures five years ago.

What the scenario exercise should test: Can you identify which of your technology vendors have significant operations, ownership, or supply chain dependencies in jurisdictions that are active or plausible sanctions targets? What’s the 30-day fallback if the relationship has to terminate?

4. Trade Disruption Stress in Commercial Loan Portfolio

What happens: Tariff escalation or export controls create severe credit stress in a commercial lending concentration—manufacturing, agriculture, semiconductor, or energy sectors—over a 6-12 month window, combining credit losses with operational stress as borrowers draw on credit lines for liquidity.

Why standard BCP misses it: This is as much a credit stress scenario as a business continuity scenario. But the operational dimension is real: simultaneous drawdowns on revolving credit facilities and a surge in commercial workout cases require operational capacity planning—staffing, workout procedures, regulatory reporting—that a standard BCP doesn’t address.

What the scenario exercise should test: Which commercial portfolios have significant trade-exposure concentration? What does your workout infrastructure look like if 15-20% of those credits go into distress simultaneously? What regulatory notification triggers apply?

5. Energy Shock Affecting Operational Infrastructure

What happens: A geopolitical event disrupts energy supply to regions where your data centers, branch network, or critical vendors operate—creating rolling blackouts, backup power reliance, and cooling capacity constraints at facilities not designed for extended outage.

Why standard BCP misses it: Most BCP datacenter scenarios assume 72-hour backup power. They don’t model a regional grid event lasting 2-3 weeks as geopolitical disruptions to fuel supply cascade into power generation. The BCP testing frameworks used in standard exercises don’t typically stress-test energy dependency duration.

What the scenario exercise should test: What’s the generator fuel supply capacity at your primary and backup sites? What’s the cascading impact on HVAC and cooling at extended duration? Which critical functions have to be migrated to unaffected locations and on what timeline?


How to Build Geopolitical Scenarios Into Your Existing BCP Framework

You don’t need to rebuild your BCP from scratch. Geopolitical scenarios plug into existing FFIEC BCM framework elements:

Business Impact Analysis update. Add a threat identification category for “geopolitical events”—subcategorized by sanctions cascade, state-sponsored cyber, trade disruption, and energy shock. For each critical function, assess which of these threat types could interrupt it and what the maximum tolerable outage is.

Scenario library expansion. Add at minimum two geopolitical scenarios to your annual tabletop calendar—one sanctions-driven, one cyber-physical. The software supply chain BCP scenarios developed after the CrowdStrike 2024 event provide a useful template for structuring multi-party simultaneous failure scenarios.

Cross-functional scenario participants. Geopolitical scenarios require compliance, legal, credit, treasury, and operations at the same table—which most IT-led BCP exercises don’t include. The decision authority matrix for “we’re halting all transactions with X counterparty” is a legal-compliance decision, not an IT recovery decision.

Vendor geopolitical exposure mapping. For each critical vendor, document: country of incorporation, significant operational locations, key supply chain dependencies, and whether sanctions exposure is a realistic near-term scenario. This integrates with your third-party risk management program and closes the gap the ECB was examining.

Board-level scenario reporting. The ECB exercise found boards across 110 institutions engaging with geopolitical scenarios—some for the first time. US bank boards should be briefed on the institution’s geopolitical risk exposure and the scenario library used to test it. If you have a board risk committee receiving quarterly operational risk reports, geopolitical scenario results belong in that deck.


What Examiners Will Find If You Haven’t Done This

The OCC Spring 2026 Risk Perspective is an examiner briefing as much as it is a public document. When the OCC identifies geopolitical risk as a prominent concern in its semiannual publication, it’s telling its examination workforce what to look for in the next examination cycle.

An institution whose BCP threat identification section lists “IT failure,” “natural disaster,” and “pandemic” but doesn’t include geopolitical scenarios has a documentable gap against the threat landscape the OCC has publicly identified. That doesn’t automatically become a finding—examiners exercise judgment about proportionality. But it’s the kind of gap that tends to come up in “other findings” during an operations examination, or in a BSA/AML exam that asks about sanctions readiness.

More importantly: a BCP that doesn’t model geopolitical scenarios isn’t just a regulatory gap. It’s a planning gap. The ECB’s findings across 110 large institutions suggest that the scenario is real, the risk is material, and the sector hasn’t caught up with it.


So What?

The ECB’s July 31 publication gives every US bank compliance and risk team a specific mandate: use 110 banks’ experience to close your own geopolitical scenario gap before your examiner does it for you.

This month: Review your BCP threat identification section and confirm whether geopolitical scenarios are documented. If they’re not, add them.

Next quarter: Add at least one geopolitical scenario to your tabletop calendar—a sanctions cascade is the easiest starting point because it’s operationally specific and ties directly to your OFAC compliance program.

Before your next exam: Update your business impact analysis to include geopolitical threats as a category, map your critical vendors’ geopolitical exposure, and ensure board-level reporting includes geopolitical scenario planning results.

The Business Continuity & Disaster Recovery Kit includes BIA templates, tabletop scenario facilitation frameworks, and vendor dependency mapping tools structured for FFIEC BCM examination expectations—including updated scenario library templates that incorporate geopolitical threat types.


Sources: ECB geopolitical risk reverse stress test results, July 31, 2026 | OCC Spring 2026 Semiannual Risk Perspective | Forbes/OCC: Beyond Bank Runs | ECB geopolitical risk preview, Forvis Mazars

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did the ECB's 2026 geopolitical reverse stress test find?
On July 31, 2026, the ECB published results of a thematic geopolitical risk reverse stress test covering 110 euro area banks under direct ECB supervision. The exercise was part of the ECB's supervisory priorities for 2026-28 and required banks to develop geopolitical risk narratives and identify scenarios that could threaten their viability. Key findings: banks developed a wide range of geopolitical scenarios including military conflicts, trade disruptions, sanctions, and cyber incidents, but the ECB urged banks to improve their geopolitical risk assessment capabilities, indicating many institutions still treated this as a peripheral risk rather than a core scenario planning exercise. The ECB noted that geopolitical risk is now a standing supervisory priority, not a one-time exercise.
Why did the OCC add geopolitical risk to its Spring 2026 Semiannual Risk Perspective?
The OCC's Spring 2026 Semiannual Risk Perspective was notable for prominently featuring geopolitical risk—a topic largely absent from prior editions. The OCC cited two primary channels: (1) geopolitical tensions increase sanctions and BSA/AML compliance risk, including the risk of sanctions violations from customer relationships touching sanctioned jurisdictions; and (2) foreign state-sponsored actors targeting the financial sector with cyberattacks and critical infrastructure disruption. The OCC characterized the overall risk environment as 'elevated and interconnected'—specifically noting that multiple individually manageable risks could interact with geopolitical events in ways that amplify impact across credit, operational, and liquidity risk simultaneously.
What is a geopolitical reverse stress test and how is it different from a regular BCP exercise?
A reverse stress test starts from a bad outcome and works backward—rather than starting from a scenario and calculating outcomes, you start from near-failure (or actual failure) and ask 'what sequence of events could cause this?' In the geopolitical context, the ECB asked banks to identify geopolitical scenarios that could threaten their viability or significantly impair their operations. This is different from a traditional BCP tabletop, which typically starts from an assumed event (datacenter outage, pandemic) and works through response. A geopolitical reverse stress test forces the institution to confront combinations of simultaneous stresses—sanctions freeze plus supply chain disruption plus cyber attack—that wouldn't surface in single-scenario exercises.
What geopolitical risk scenarios should a US bank's BCP include?
Based on the ECB's 2026 exercise and the OCC's Spring 2026 framing, US bank BCPs should incorporate at least the following geopolitical scenario types: (1) Sanctions cascade—a sudden OFAC designation affecting a material customer segment, correspondent banking relationship, or payment rail the bank relies on; (2) State-sponsored cyberattack targeting critical infrastructure—specifically the payment systems, core banking platforms, or communications infrastructure the bank depends on; (3) Trade disruption affecting commercial loan portfolio—tariffs or export controls creating credit stress in a concentrated industry vertical; (4) Critical technology vendor with geopolitical exposure—a core software or cloud vendor operating in or dependent on a jurisdiction subject to sudden sanctions or export restrictions; (5) Energy shock—supply disruption affecting data center operations or backup power reliability.
How does geopolitical risk connect to FFIEC business continuity management requirements?
The FFIEC BCM guidance (updated 2019, reflected in the IT Examination Handbook) requires financial institutions to identify threats that could disrupt critical operations, develop business impact analyses, and test continuity plans. While the guidance is not geopolitical-scenario-specific, its risk assessment framework is broad enough to encompass geopolitical threats: threat identification includes nation-state cyberattack, critical infrastructure disruption, and sanctions-related operational disruption. Examiners applying FFIEC BCM guidance in 2026 are aware of the OCC's Spring 2026 framing of geopolitical risk—and an institution that hasn't thought about geopolitical scenarios in its BIA and scenario library will have a documentable gap if the examiner asks about its threat identification process.
Should US banks run a geopolitical reverse stress test even if not required to?
Yes, for two reasons. First, the ECB's 2026 exercise is now a public benchmark—peer institutions in Europe have run it, and the ECB published its conclusions about sector-wide preparedness. US regulators, particularly the OCC and Federal Reserve, monitor ECB supervisory outputs. Second, and more importantly, geopolitical scenarios expose BCP gaps that single-failure scenarios miss. A datacenter-outage tabletop exercises your IT recovery playbook. A sanctions-cascade scenario exercises your legal, compliance, treasury, and operations teams simultaneously—and usually surfaces dependencies, escalation chains, and decision authorities that haven't been tested since they were documented. The exercise has value independent of whether a regulator requires it.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Business Continuity & Disaster Recovery (BCP/DR) Kit

BCP and DR templates with BIA, recovery procedures, and a standalone tabletop exercise kit.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.