Bank regulators want proof that your apps hold up.

Supervisors from Frankfurt to Riyadh, Singapore and New York now expect banks to test their mobile apps and APIs often, behind login, and to prove each fix. Here is what each regulator asks, in plain words and with the official sources, and how Ostorlab supports the testing part.

  • EU: DORA testing rules, and the ECB action plan due 31 October 2026
  • Middle East: UAE, Saudi Arabia, Qatar, Kuwait and Jordan
  • Asia: Pakistan, Bangladesh, Japan, Singapore and Indonesia
  • Americas: United States and Brazil, plus Ukraine in Europe
Scan your own appBook a demo

Free scan of your app from the App Store or Google Play. No login required.

These pages sum up public texts to help you plan testing. They are not legal advice. Ostorlab supports your testing obligations; it does not make you compliant on its own, so check how it fits with your compliance team.

By country

Bank regulations where Ostorlab works

One page per regulator, each built from the official texts: what they ask of your mobile app and its APIs, how Ostorlab helps with the testing, and what stays with you.

Asia-Pacific

Americas

Side by side

Three regimes, compared

Who each one applies to, what it asks you to test, and where Ostorlab supports the testing part.

ECB letter on AI-enabled cyber threatsDORACBUAE rules and Notice 2176
Issued byECB Banking SupervisionEuropean Parliament and Council, with Commission technical standardsCentral Bank of the UAE
Legal natureSupervisory letter built on DORA, not a new regulationEU regulation, directly applicable in every Member StateFederal law, regulations, standards and guidelines, plus Notice 2176, which is not public
Who it applies toSignificant institutions, the banks the ECB supervises directlyEU financial entities, including banks, payment and e-money institutionsLicensed financial institutions in the UAE, with some rules for specific licences
Key date or cadenceAction plan to the Joint Supervisory Team by 31 October 2026Applies since 17 January 2025: weekly scans, yearly tests, TLPT every 3 years if identifiedDecree-Law in force since 16 September 2025; quarterly reporting of vulnerabilities
Testing it asks forPrioritised vulnerability scanning at scale, AI-based tools under human oversight, security by designVulnerability scans, static and dynamic code testing, penetration and end-to-end testing, TLPTVulnerability assessments, code review, business-logic testing, yearly independent API testing
What it means for mobile appsMobile apps and their APIs are internet-facing assets and internally developed softwareApps supporting critical or important functions need weekly automated scans and security testing before releaseAuthentication, step-up checks, sessions and device protections are fraud controls to test
Where Ostorlab helpsBaseline, remediation and retest evidence for the application part of the planStatic, dynamic and AI-agent testing, dependency tracking, remediation tracking, groundwork for TLPTShielding bypass tests, logged-in testing, API testing and evidence for each release
Common thread

What the three have in common

Different regulators, the same four expectations for the apps your customers use.

  1. Test more often

    Weekly automated scans under DORA, scanning at scale in the ECB letter, regular assessments in the UAE: a yearly pentest alone no longer covers it.

  2. Test what customers really use

    The store build, behind login, with the APIs and SDKs it depends on, not a debug build with protections turned off.

  3. Prove the fix

    Findings are prioritised, remedied and validated, and the record shows it, for auditors and supervisors.

  4. Stay in control of data and AI

    AI tools under human oversight, vendors you can audit, and data kept where your policies require.

Ostorlab supports your testing obligations. Decisions on compliance stay with your teams. This is not legal advice.

FAQ

Frequently asked questions

Straight answers on coverage, setup, and how results reach your team.

Can't find your answer? Book a demo or contact us.

Test your banking app before your supervisor asks

Start with a free scan of your app from the store, or book a demo to plan testing across your releases.