European Banking Authority (EBA)
The European Banking Authority (EBA) is the EU agency responsible for building a single rulebook for banking across the Union. It does not supervise most banks directly. Its influence comes from writing the detailed technical standards that, once adopted by the European Commission, apply as binding law in every member state.
That is the thing to understand about the EBA: it is a rule-writing body whose output reaches firms through other instruments.
| Established | 2011, following the financial crisis |
| Headquarters | Paris |
| Principal function | Drafting technical standards and guidelines for the single rulebook |
| Direct supervision | Limited — national authorities supervise, the ECB supervises large eurozone banks |
| Best known for | The SCA technical standards under PSD2, and EU-wide stress tests |
| Changed in 2026 | AML mandate transferred to AMLA |
What the EBA actually does
Technical standards. EU legislation frequently sets an objective and delegates the specifics. The EBA drafts regulatory and implementing technical standards that fill that gap; the Commission adopts them, and they then apply directly. The requirement that a payment authentication code be dynamically linked to the amount and payee, for example, is not in PSD2 itself — it is in the technical standards the EBA wrote.
Guidelines and recommendations. These are not binding in the same way, but operate on a comply-or-explain basis: a national authority that does not intend to follow them must say so publicly, which makes departure costly.
Stress testing. The EBA runs EU-wide exercises assessing bank resilience under adverse scenarios, and publishes bank-level results.
Supervisory convergence. Working to ensure national authorities interpret the same rules the same way — the persistent problem in a union that legislates by directive.
The 2026 change worth knowing
For years the EBA also held the EU’s anti-money laundering mandate, having acquired it in 2020. That mandate transferred to the Anti-Money Laundering Authority (AMLA) at the start of 2026.
AMLA, headquartered in Frankfurt, is a purpose-built AML supervisor rather than a rule-writing body with AML added. Its own timeline runs further out: the AML Regulation it enforces applies from July 2027, and direct supervision of up to 40 selected cross-border groups begins in 2028, with the selection confirmed during 2027.
The practical effect is that AML questions no longer route to the EBA. Its remaining perimeter is prudential regulation, payments, consumer protection and the single rulebook — still the body behind the authentication rules, no longer the body behind the money laundering ones. A great deal of published material has not caught up with this.
Why it matters for identity verification
The EBA is the reason strong customer authentication has a precise technical meaning rather than a general one. Its standards define what counts as an independent element, what dynamic linking requires, and the conditions under which the transaction risk analysis exemption can be used — the detail that determines whether a given implementation complies or merely resembles compliance.
It also issued the guidance that made remote customer onboarding workable in Europe, setting out what a digital identification process must demonstrate for it to be relied on. That work is what allows a European institution to onboard a customer without a branch visit, and it is the reason document-and-biometric verification became the default rather than an exception.
The standing point for any firm reading the rules: a technical standard tells you what the check must accomplish, never which vendor or method satisfies it. Demonstrating that a process meets the standard remains the firm’s responsibility, and it is demonstrated with evidence the process produces rather than with a supplier’s assertion.
Who supervises what in the EU
| Body | Role | Supervises firms directly |
|---|---|---|
| EBA | Writes technical standards and guidelines; runs stress tests | Rarely |
| ECB (SSM) | Prudential supervision of significant eurozone banks | Yes |
| AMLA | AML rulemaking and, from 2028, direct supervision of selected groups | From 2028 |
| National authorities | Supervision of most firms in their market | Yes |
| ESMA / EIOPA | The equivalent authorities for securities and for insurance | Rarely |
What the EBA does not do
It does not supervise most banks. A firm’s supervisor is its national authority, or the ECB if it is a significant eurozone institution. The EBA shapes the rules those supervisors apply.
It does not handle AML any more. That moved to AMLA in January 2026.
It does not make law on its own. Technical standards become binding when the Commission adopts them; guidelines rely on comply-or-explain rather than direct force.
It does not approve vendors. There is no EBA-certified list for identity verification or anything else. A claim that a product is EBA-approved is describing something that does not exist.
Frequently asked questions
What is the difference between the EBA and the ECB?
The EBA writes rules that apply across the EU and does not, in general, supervise individual banks. The ECB, through the Single Supervisory Mechanism, directly supervises significant banks in the eurozone. One sets standards union-wide; the other examines firms in a narrower geography.
Does the EBA still handle anti-money laundering?
No. The EBA’s AML mandate transferred to the Anti-Money Laundering Authority at the beginning of 2026. AMLA’s rules apply from July 2027 and it begins directly supervising selected cross-border groups in 2028.
Are EBA guidelines legally binding?
Technical standards are, once the Commission adopts them. Guidelines operate on comply-or-explain: a national authority must publicly state if it does not intend to comply, which in practice produces widespread adoption without formal binding force.
How does the EBA affect identity verification?
Through the technical standards defining strong customer authentication under PSD2, and through its guidance on remote customer onboarding, which set out what a digital identification process must demonstrate. Together these made document and biometric verification the standard European approach to onboarding without a branch visit.
Related reading
- Payment Services Directive 2 — the law whose authentication standards the EBA wrote
- AML regulators by country — where the AML mandate sits now
- Financial Conduct Authority — the UK equivalent after EU withdrawal
- Anti-money laundering — the framework that moved to AMLA