Blog
Technical-commercial articles on the regulatory and technological challenges facing financial entities in the era of artificial intelligence.
TLPT under DORA: Spain's first testing cycle
September 2026 · 7 min read
Article 26 of DORA (Digital Operational Resilience Act) is Regulation (EU) 2022/2554 on digital operational resilience for the financial sector. It requires EU banks, insurers and investment firms to withstand ICT disruptions and threats, respond to them and recover. It has applied since 17 January 2025.Read more → DORA requires identified entities to run threat-led penetration testing at least every 3 years, on live production. Which thresholds Delegated Regulation (EU) 2025/1190 sets, which deadlines the cycle imposes and which architecture survives it.
DORA for fintech and insurtech: a practical guide and 90-day checklist
August 2026 · 10 min read
DORA (Digital Operational Resilience Act) is Regulation (EU) 2022/2554 on digital operational resilience for the financial sector. It requires EU banks, insurers and investment firms to withstand ICT disruptions and threats, respond to them and recover. It has applied since 17 January 2025.Read more → DORA's five pillars translated into concrete technical controls, where most growing entities fail, and a 90-day checklist to comply without freezing the business.DORA Register of Information: why almost no one passes first time
August 2026 · 6 min read
In the ESAs dry run, only 6.5% of the registers analysed passed all the quality checks. The ICT third-party Register of Information (DORA (Digital Operational Resilience Act) is Regulation (EU) 2022/2554 on digital operational resilience for the financial sector. It requires EU banks, insurers and investment firms to withstand ICT disruptions and threats, respond to them and recover. It has applied since 17 January 2025.Read more → DORA Art. 28) is an annual obligation, and a data-quality problem, not paperwork.
Anatomy of agentic AI AML triage: what the machine decides
June 2026 · 7 min read
A case study: an AI agent triages Anti-money laundering (AML) is the prevention of money laundering and terrorist financing. In Spain, Law 10/2010 requires credit and financial institutions to apply customer due diligence and to report suspicious transactions to SEPBLAC; Regulation (EU) 2024/1624 harmonizes it from July 2027.Read more → AML alerts overnight. What it resolves alone, where the four-eyes principle stops it before the report to SEPBLAC (Servicio Ejecutivo de la Comisión de Prevención del Blanqueo de Capitales e Infracciones Monetarias) is Spain's Financial Intelligence Unit and its supervisor for the prevention of money laundering and terrorist financing. Obliged entities file suspicious transaction reports with it (Law 10/2010).Read more → SEPBLAC, and what the audit trail records.
Agentic AI and regulation: who answers when the agent acts alone
June 2026 · 7 min read
An autonomous agent decides on credit, insurance or funds without human approval at every step. How to govern it under the The AI Act is Regulation (EU) 2024/1689, the European risk-based framework for AI: it bans unacceptable uses, regulates high-risk systems and requires transparency from general-purpose models. Its high-risk regime covers credit scoring and life and health insurance pricing from 2 December 2027 (Reg. 2026/1744).Read more → AI Act, DORA (Digital Operational Resilience Act) is Regulation (EU) 2022/2554 on digital operational resilience for the financial sector. It requires EU banks, insurers and investment firms to withstand ICT disruptions and threats, respond to them and recover. It has applied since 17 January 2025.Read more → DORA and Law 10/2010, and what changes with the Digital Omnibus delay.
Anatomy of a DORA incident: from first signal to notification
June 2026 · 7 min read
A case study: how a fintech walks a major incident under DORA (Digital Operational Resilience Act) is Regulation (EU) 2022/2554 on digital operational resilience for the financial sector. It requires EU banks, insurers and investment firms to withstand ICT disruptions and threats, respond to them and recover. It has applied since 17 January 2025.Read more → DORA, from detection to the notification to its regulator, and where the manual process loses the hours the rule does not forgive.
SEPBLAC software: automate AML reporting without losing traceability
June 2026 · 6 min read
Every fintech operating in Spain is an obliged entity before SEPBLAC (Servicio Ejecutivo de la Comisión de Prevención del Blanqueo de Capitales e Infracciones Monetarias) is Spain's Financial Intelligence Unit and its supervisor for the prevention of money laundering and terrorist financing. Obliged entities file suspicious transaction reports with it (Law 10/2010).Read more → SEPBLAC. How to automate the special examination and filing while preserving the audit trail and the four-eyes principle.
Agentic AI and Zero Trust: Why identity must precede connectivity
May 2026 · 8 min read
Agentic AI multiplies attack velocity. The "connect first" model is broken. Cryptographic identity must be the starting point.
DORA 2026: A practical guide for financial entities
May 2026 · 8 min read
What DORA (Digital Operational Resilience Act) is Regulation (EU) 2022/2554 on digital operational resilience for the financial sector. It requires EU banks, insurers and investment firms to withstand ICT disruptions and threats, respond to them and recover. It has applied since 17 January 2025.Read more → DORA requires, how it affects your entity, and what you need to implement before the next audit. Includes compliance checklist by department.
AML Automation with AI: From manual screening to intelligent triage
May 2026 · 7 min read
How artificial intelligence is transforming Anti-money laundering (AML) is the prevention of money laundering and terrorist financing. In Spain, Law 10/2010 requires credit and financial institutions to apply customer due diligence and to report suspicious transactions to SEPBLAC; Regulation (EU) 2024/1624 harmonizes it from July 2027.Read more → AML compliance — from sanctions screening to automated special examination.
Zero Trust in banking: Why VPNs are no longer enough
May 2026 · 6 min read
The perimeter security model is exhausted. Zero Trust is the security model NIST formalizes in SP 800-207: network location grants no implicit trust, and every access is authenticated and authorized separately. In banking and insurance it limits lateral movement after a credential is stolen; BlueUP applies it with per-service cryptographic identity.Read more → Zero Trust redefines how financial entities protect their critical applications.
Want to go deeper?
Download our technical whitepapers on DORA compliance and agentic AI.