The EU Benchmarks Regulation Tightens Again: What ESMA's 2026 Internal Control Guidelines Mean for Benchmark Administrators

The EU Benchmarks Regulation has just acquired another layer. On 5 May 2026, the European Securities and Markets Authority (ESMA) published new Guidelines on Internal Controls for Benchmark Administrators, Credit Rating Agencies and Market Transparency Infrastructures that apply from 1 October 2026. That’s the most recent step in a regulatory story that runs straight back to the LIBOR scandal. In the EU, producing a benchmark has moved from a quiet, trust-based activity into a supervised, license-dependent one; a shift that reaches both the firms that calculate benchmarks and those that rely on them.
Key points
- Regulation (EU) 2016/1011 was the EU's direct answer to the LIBOR and EURIBOR manipulation cases. It made producing a benchmark a regulated activity for the first time.
- Benchmark administrators and credit rating agencies generally need authorization, registration or recognition before their indices and ratings may be used in EU financial instruments and contracts.
- The regime sorts benchmarks into three tiers: critical, significant and non-significant.
- ESMA supervises the most systemically relevant administrators directly and has steadily added detail, most recently through the 2026 Internal Control Guidelines.
From an unregulated rate to a regulated market: the LIBOR scandal
LIBOR was formally established in 1986 by the British Bankers' Association and became a reference rate for a very large volume of financial instruments and contracts. For roughly three decades it carried that weight without any formal supervision. Until about 2008, central bankers, corporate treasurers and households treated LIBOR almost as an objective fact rather than as a number a panel of banks submitted each morning.
The 2012 manipulation scandal ended that assumption. Regulators concluded the banks had manipulated their submissions to suit their own trading positions, and the UK's Serious Fraud Office prosecuted it as fraud. That characterization was contested in the courts until very recently: in July 2025 the UK Supreme Court overturned the landmark convictions for jury misdirection, with no retrial sought, leaving the alleged unlawfulness ultimately unconfirmed. The legal outcome aside, the financial reality was unchanged: Self-regulation alone had not safeguarded the benchmark's integrity.
What the EU Benchmarks Regulation requires of administrators
Out of that vacuum came Regulation (EU) 2016/1011. The core idea is straightforward: An administrator must obtain authorization or registration before its benchmarks may be used in EU financial instruments, financial contracts, or to measure the performance of investment funds. Recognition and endorsement routes exist for indices produced outside the EU.
The obligations attach to governance and process rather than to the level of the benchmark itself. The provisions for critical benchmarks took effect on the regulation’s entry into force in 2016, ahead of the general application in 2018. In practical terms, the EU Benchmarks Regulation turned a discretionary calculation into an audited, governed production process with a paper trail that regulators can inspect.
Critical, significant and non-significant benchmarks: why the tiers matter
Not every index carries the same systemic weight, and the regulation reflects that. It divides benchmarks into three categories:
- A critical benchmark is one whose failure or manipulation would seriously affect financial stability, market integrity or the financing of households and businesses; EURIBOR is the obvious example. These face the strictest regime, including powers for authorities to compel contributions and to manage an orderly wind-down.
- Significant benchmarks sit in the middle, with substantial but somewhat lighter requirements.
- Regulation (EU) 2025/914 removes non-significant benchmarks from scope, broadly those used as a reference for instruments, contracts or funds worth less than EUR 50 billion and not designated as critical. These made up the large majority of benchmarks (around 90% of administrators).
For practitioners, if they administer a benchmark, their in-scope status may have changed at the turn of the year. Firms on the ESMA register at end-2025 keep their standing through a transitional windowthat runs to 30 September 2026, but whether they remain in scope, opt back in, or fall out is a live decision for 2026.
The tier determines how much governance, oversight and documentation a benchmark demands, whether contributors can be compelled, and how closely ESMA or a national authority will look.
How ESMA supervises benchmark administrators
Supervision under the regime is split. National competent authorities handle most administrators, while ESMA took on direct supervision of the most systemically relevant ones, including administrators of critical benchmarks and certain recognized third-country entities. That direct remit is why ESMA, rather than a national regulator, now sets expectations through guidelines that reach the supervised benchmark administrators.
ESMA supervision is not a single point-in-time check. It is continuous: the authority monitors how administrators run their methodologies. It can request information, conduct reviews, and escalate where controls fall short. The 2026 Internal Control Guidelines make the expectation explicit — administrators are assessed on whether their internal control framework is genuinely present and working, not merely documented.
The 2026 Internal Control Guidelines: ESMA's next refinement
The new Guidelines, published on 5 May 2026 and applicable from 1 October 2026, sit on top of an already-regulated population. They do not replace the EU Benchmarks Regulation; they set out, in considerable detail, what ESMA expects a sound internal control system to look like across benchmark administrators, credit rating agencies and market transparency infrastructures. The substance lives in Section 5 of the Guidelines, which separates two things that firms often blur: the control framework a firm operates within, and the control functions that run inside it.
Before that, Section 1 settles the question of who is bound. The Guidelines define six categories of "supervised entities":
- Benchmark administrators (BMAs) authorized, registered or recognized with ESMA under the EU Benchmarks Regulation.
- Credit rating agencies (CRAs) established in the Union and registered with ESMA under the CRA Regulation.
- Data reporting services providers (DRSPs) established in the Union and authorized by ESMA under MiFIR — with consolidated tape providers (CTPs) expressly excluded.
- Securitization repositories (SRs) established in the Union and registered with ESMA under the Securitization Regulation.
- Trade repositories (TRs) established in the Union and registered with ESMA under EMIR.
- Trade repositories registered with ESMA under the SFTR.
The first two carry out the load-bearing assessments; the latter four are the market transparency infrastructures that record and report what the market actually did.
A governance point frames everything that follows. The management body is accountable for overseeing and approving every component of the framework, while executive senior management is responsible for building, implementing and keeping it current. ESMA also wants a decision-making process that is clear, transparent and documented, with roles and responsibilities allocated unambiguously.
The internal control framework: five components supervised entities must demonstrate
The Guidelines establish a framework for the supervised entities that rests on five components.
- Control environment. The management body and senior management jointly set the tone at the top. Expect to show a working ethics-and-compliance culture, conduct rules covering integrity, due skill and care, and staff awareness that misconduct carries disciplinary, legal and regulatory consequences.
- Risk management. A dynamic, continuously evolving process to identify, assess and measure every risk that could impair your ability to meet your obligations or to keep operating including risks from new technology and a shifting external environment. It needs a defined methodology, a stated risk appetite with tolerance levels, and coverage of all business lines and control functions.
- Control activities. Controls should be preventative, detective, corrective or deterrent. In practice that means segregation of duties, documented policies and key controls, clear designation of who performs each control, authorization and approval mechanisms on a need-to-know and least-privilege basis, and verifications, validations and reconciliations. Firms outside the scope of DORA, that is, administrators of significant (non-critical) benchmarks must additionally run general ICT controls for data quality and information security.
- Information and communication. Information has to move in every direction: downward to staff and external stakeholders, upward through escalation channels including a route for material disagreement between control functions and operating units, and outward to the market, clients and regulators.
- Monitoring activities. Evaluations at different levels of the firm, run on a regular or thematic basis and built into business processes. Deficiencies and the remediation that follows must reach the management body and senior management, who are then expected to track timely implementation. Where you outsource, monitoring of the outsourced process has to be assigned to a named member of staff.
The control functions supervised entities must run
Alongside the framework, the Guidelines describe dedicated internal control functions. ESMA's baseline expectation is that these functions have enough resources, expertise and seniority to do their job, report regularly to the management body, and stay organizationally independent of the activities they monitor. They should not perform operational tasks in those areas, nor report to the people running them. Outsourcing a function to group level or a third party is permitted, but full responsibility remains with the firm.
For a benchmark administrator, the distinctive piece is the Oversight Function, which benchmark administrators are required to maintain. It oversees the main aspects of benchmark provision: reviewing the benchmark's definition and methodology, managing the third parties involved, assessing internal and external audits of the control framework, and reporting any relevant misconduct to competent authorities. ESMA expects it to be genuinely independent and free of conflicts of interest, to run regular self-assessments of its own effectiveness and the suitability of its members, to be able to access and challenge management information, and to keep a defined channel open to authorities. This includes a channel for reporting misconduct by administrators or contributors.
The remaining functions apply more broadly. The Compliance Function monitors and reports on regulatory compliance, tracks legal change and advises the management body through a structured monitoring programme. The Risk Management Function owns the risk framework and recommends improvements. The Internal Audit Function provides independent, risk-based assurance under an audit charter, reporting to the independent members of the management body or an audit committee, with formal follow-up on its recommendations. Firms outside DORA also need an Information Security Management Function. The Review Function, by contrast, is specific to credit rating agencies and does not apply to benchmark administrators.
How proportionality changes what is actually required
ESMA applies proportionality throughout, calibrating its expectations to a firm's nature, scale and complexity — and this is where the Guidelines become workable rather than punitive for smaller administrators. Three levers matter. Where strict segregation of duties is not practical and Union law does not demand it, alternative controls are acceptable, provided the firm documents the rationale, identifies the risks and puts compensating controls in place. Staffing can be scaled to the volume of control activity rather than fixed at full-time roles in every function. And the maturity of controls — from manual to hybrid to automated, in some cases incorporating AI tools — is expected to match the firm's risk profile, with larger and more complex administrators moving toward more automation and tighter integration between their control systems.
A small administrator of a significant and an administrator of a critical benchmark will therefore not be held to identical operational thresholds.
Third-country benchmarks and the scope rethink
The regulation's reach has been its most contested feature. Because qualifying a benchmark for EU use is costly, many third-country administrators were unable or unwilling to do it, and a large number of non-EU benchmarks risked becoming unusable inside the bloc. That is a genuine commercial problem for any EU firm whose products reference a foreign index.
The Commission later found in its own review that no comparable jurisdiction had chosen a scope as broad as the Benchmark Regulation, and that the rules placed a heavier burden on smaller EU administrators than regimes focused on a handful of systemic benchmarks. Regulation (EU) 2025/914, amending the Benchmark Regulation, is applicable since 1 January 2026 and removes non-significant benchmarks from scope entirely. It also establishes a revised third-country framework allowing recognition without requiring equivalence.
The framework was introduced after a crisis and has already been narrowed once; its scope and the third-country regime remain under review. The practical implication is ongoing supervision combined with a still-evolving perimeter.
Frequently asked questions
What is the EU Benchmarks Regulation?
It is Regulation (EU) 2016/1011, the EU law governing the indices used as benchmarks in financial instruments and contracts and to measure fund performance. It requires the firms that produce critical and significant benchmarks to be authorized and supervised, and it sets standards for methodology, input data and conflict-of-interest control.
Do benchmark administrators need authorization in the EU?
In-scope administrators must hold authorization or registration. Since 1 January 2026, however, the scope is narrower: it covers critical and significant benchmarks, EU climate benchmarks and certain commodity benchmarks, so administrators that only provide non-significant benchmarks are largely outside the regime, subject to transitional arrangements and a possible voluntary opt-in.
What is the difference between critical, significant and non-significant benchmarks?
The three tiers reflect systemic weight. Critical benchmarks, such as EURIBOR, face the strictest regime; significant benchmarks carry substantial but somewhat lighter obligations. Non-significant benchmarks are the long tail, now removed from the regulation's scope by Regulation (EU) 2025/914.
Why was the EU Benchmarks Regulation introduced?
It was the direct response to the LIBOR scandal and related manipulation of EURIBOR and other benchmarks. Those cases showed that discretion and weak governance left benchmarks open to manipulation, and that voluntary codes of conduct were not enough.
How does ESMA supervise benchmark administrators?
ESMA directly supervises the most systemically relevant administrators, while national authorities handle the rest. Supervision is ongoing and substance-based: ESMA reviews methodologies, governance, conflicts management and internal controls, and from October 2026 it assesses firms against its new Internal Control Guidelines.
What do the ESMA internal control guidelines require of benchmark administrators?
They require a documented, functioning internal control framework — covering control environment, risk management, control activities, information flows and monitoring — plus independent control functions, including the Oversight Function specific to administrators. ESMA applies these proportionally to a firm's nature, scale and complexity.
Related articles
Continue exploring with related insights from our experts.

The EBA Climate Stress Test: The New 2027 Climate Risk Module and What Banks Should Do
The draft 2027 EBA stress test introduces a dedicated climate risk module, layering transition and flood shocks onto the adverse macro-financial scenario. It leaves capital ratios untouched for now, but it produces exactly the kind of supervisory dataset that shapes future cycles, so the draft is best treated as a dry run.

PD Model Backtesting in the Spotlight: What the EBA's 2026 Paper Means for European Banks
For two decades, the performance of banks' PD models stayed inside confidential supervisory channels. The EBA's April 2026 Staff Paper changes that — applying systematic PD model backtesting across EU IRB banks, sharpening the binomial test for both asset and serial correlation, and putting a Tier 1 capital number on the result.

Credit Risk Modeling Trends 2026: Five Shifts Risk Managers Should Prepare For
The credit risk function of 2026 looks materially different from the one most banks still operate. Here are the five shifts, from generative AI to ESG integration, that risk managers should plan for now.