A strategic shift in the EU supervisory data ecosystem

The DPM Refit project, which resulted in the DPM 2.0 standard, established a critical semantic foundation for European supervisory reporting. However, this is only the first step in a much larger data architecture story. European supervisors are steadily moving from simple document collection to active, data-centric oversight. The initial framework established a common metamodel for structuring regulatory reporting requirements across different modelling approaches. Subsequent developments, however, indicate a broader plan to build an integrated ecosystem where data is defined once, stored logically, and reused across multiple frameworks.

For financial institutions, this evolution redefines the entire reporting lifecycle. Compliance is transitioning from a cyclical, template-driven task to a continuous data governance discipline, where a governed, logically integrated data foundation must feed the entire supervisory pipeline.

At a Glance

  • The European Banking Authority (EBA) is transitioning from template-based collections to a machine-readable data architecture designed to harmonize and integrate cross-border supervision.
  • The DPM Alliance (EBA, ECB, and EIOPA) announced a consultation on improvements to the data dictionary metamodel to better support statistical and supervisory reporting. 
  • Technical enhancements in DPM metamodel 2.1 include standardized JSON schemas, chronological version control, and decoupled semantic layers that establish the metadata foundation required for cross-domain data reuse.
  • A structured, machine-readable data dictionary serves as the essential fuel for deploying explainable AI, automated impact analysis, and semantic data mapping.
  • Institutions should consider shifting resources from downstream report adjustments to upstream, robust, centralized data modeling and governance.

Understanding the DPM metamodel 2.1

Making this integration vision possible is the DPM 2.1 metamodel release, representing the next evolution of the supervisory foundation. To anchor this evolution, the DPM Alliance has launched a public consultation on the draft DPM 2.1 standard, with a deadline for feedback of 30 September, 2026. The final version is scheduled for publication in the fourth quarter of 2026. The evolved model is not a disruptive migration but an extension and refinement of the established metamodel, driven by practical experience and the need to support broader, cross-domain use cases, such as the ECB’s Integrated Reporting Framework (IReF). DPM 2.1 introduces eight key enhancements that have been identified as important enablers for the continued convergence of the EBA and ECB reporting systems. A major driver of these enhancements was the decision to base IReF on DPM 2.0, which revealed additional metamodel requirements now being incorporated into DPM 2.1. Analysis of the specifications highlights:

  • Explicit JSON taxonomies: Standardizing on native JSON schemas establishes a modernized, lightweight format for machine-to-machine metadata exchange, reducing processing overhead for complex data transfers.
  • Structured versioning and historization of metadata: DPM 2.1 introduces refined versioning mechanics. Instead of managing regulatory changes as isolated, ad-hoc updates, the new model tracks changes chronologically within a unified database structure, preserving historical reporting relationships over time
  • Semantic hierarchies: The metamodel explicitly separates physical reporting templates from underlying logical concepts, allowing the same data, such as a specific exposure value, to be defined once and reused across completely different reporting modules without duplication.
  • Further planned enhancements: The draft DPM 2.1 specifications indicate several further refinements, including an explicit identification of frameworks for both physical and logical modelling; improved version control for item names and descriptions; an explicit definition of data domains and their hierarchical structures; and a more detailed representation of compound properties, and include standardized Regex ("regular expression") for property values.

The broader institutional framework

This technical structure gains its authority from a unified, cross-border governance system that solidifies the framework’s role as a shared European standard. 

  • DPM Alliance: Established in 2024 by the EBA, ECB, and EIOPA, the Alliance provides a joint governance framework to ensure consistent application of reporting standards across banking, insurance, and monetary statistics. With the Single Resolution Board (SRB) also involved, the collaboration is pivotal in dismantling structural silos between prudential, statistical, and insurance reporting. The stated objectives of the Alliance include maintaining and upgrading the DPM standard, facilitating the exchange of regulatory metadata, and reducing duplicated modelling efforts across authorities.
  • Common Data Dictionary: This initiative represents the semantic core of the integrated vision. The goal is to create a single, authoritative source for the definition of regulatory concepts, reducing ambiguity and the need for manual reconciliation between risk, finance, and compliance functions.

DPM 2.1 features and benefits

  1. Enhanced standardization through the use of patterns (regular expressions) for property validation.
  2. Greater flexibility in maintaining and versioning item names and descriptions.
  3. Improved modeling and management of compound properties.
  4. Enhanced organizational modelling through structured hierarchical organization data.
  5. Support for conceptual modelling through the explicit distinction between logical and physical frameworks.
  6. Clear identification of the role and origin of modules within the data lifecycle (reported, calculated, or disseminated).
  7. Improved consistency and harmonization of naming and labelling conventions.
  8. Better support for the convergence of supervisory

DPM 2.1: Building the foundation for integrated statistical and supervisory reporting

Impact of DPM 2.1 on regulatory reporting

By unifying institutional governance and standardizing definitions under a common dictionary, the new EBA DPM 2.1 architecture has several direct, practical implications for how financial institutions manage data:

  • Consistent definitions across regulatory frameworks:  Common glossaries and clearer links between legal sources and reporting definitions will reduce inconsistent use of concepts across frameworks. Where differences are necessary, the system identifies and describes them more transparently.
  • Enhanced comparability between banks’ reports: Greater alignment of regulatory concepts can reduce interpretation differences and improve the consistency and comparability of reported data.
  • Improved traceability: Requirements can be traced more systematically from their legal provision to the final reporting template, data point, or XBRL artifact, making the entire process easier to validate and audit.
  • Efficient change management: A connected metadata model supports a structured impact chain, improving the speed and completeness of regulatory impact analysis.
  • Greater reuse across domains: A common foundation increases data reuse across prudential, statistical, resolution, and insurance reporting, avoiding duplicate modeling work where common elements exist.

Connecting legal requirements with reporting implementation

The most significant strategic leap in the DPM 2.1 architecture is the ability to make the relationships between legal texts and data requirements explicit and machine-readable. Historically, the connection existed only in the minds of regulatory experts. The new DPM structure formalizes this relationship, creating an unbroken dependency chain.

The future structure of the DPM metamodel is being designed to explicitly support this, with planned blocks for legal references, master data definitions, and reporting-obligation rules. This enables a clear, versioned, and traceable path:

Figure: The integrated regulatory traceability chain

Today, these relationships are scattered across legislation, spreadsheets, and implementation documents. A richer, integrated metadata environment makes these connections explicit, giving expert judgment a more structured and transparent foundation.

Limits and Governance

It is important to note that a richer DPM metamodel will not enable a fully automated translation of legal texts into reporting requirements. Regulatory interpretation remains dependent on legal context, supervisory objectives, and expert judgment. Similarly, AI-generated mappings or impact assessments will continue to require accountable review by human experts.

The value of this emerging architecture lies in making the relationships between legal requirements, regulatory concepts, and technical artifacts more explicit and machine-interpretable, thereby providing a stronger foundation for experts to work from.

Historically, the connection between legal texts and data requirements existed only in the minds of regulatory experts. The new DPM 2.1 structure formalizes this relationship, creating an unbroken dependency chain. 

Erik Becker Director Product Management
Regnology

DPM 2.1 creates a foundation for AI-supported regulatory reporting use cases

A formally structured and connected metadata environment provides a substantially stronger foundation for the use of Artificial Intelligence across the entire reporting lifecycle. AI systems struggle when relationships between legal sources, regulatory concepts, and data requirements are implicit. A governed, machine-readable metadata model provides relationships explicitly, unlocking several high-value AI use cases.

  • ~

    Regulatory change management

    AI agents can compare new or amended legal texts with the legal references and concepts stored in the metadata environment to help identify newly introduced requirements, amended definitions, and affected reporting areas.

  • ~

    Automated impact analysis

    Once legal provisions and data variables are formally connected, an AI agent can navigate relationships to identify potential downstream impacts. An impact analysis can move beyond a document-level comparison to examine the effects across the entire reporting chain

  • ~

    Semantic mapping

    Semantic AI engines can suggest mappings between terminology used in legal texts and existing glossary concepts, or between new reporting requirements and a firm's internal data structures.

  • ~

    Explainable regulatory assistance

    AI-enabled compliance assistants can navigate the structured DPM lineage to provide more traceable, explainable answers to complex internal queries, linking each data point back to its relevant legal source.

  • ~

    Consistency and duplication analysis

    Checks for duplicated concepts, similar concepts with conflicting descriptions, or inconsistent use of classifications across different reporting frameworks.

  • ~

    Assisted creation of reporting artifacts

    Based on structured requirements and established conventions, AI can assist with initial drafts of glossary definitions, reporting instructions, and change documentation, which remain subject to expert review.

  • ~

    Natural-language access to regulatory requirements

    Users can interact with the metadata through natural-language questions (e.g., "Which reports are affected by this amendment?" or "Which validation rules apply to this variable?"), with the AI navigating the structured relationships to retrieve supporting evidence.

The metamodel explicitly separates physical reporting templates from underlying logical concepts, allowing the same data... to be defined once and reused across completely different reporting modules.

Erik Becker Director Product Management
Regnology

Roadmap for DPM compliance

Successfully deploying machine-readable and AI-enabled applications requires a fundamental shift in how financial institutions design internal reporting workflows - a move away from siloed templates to integrated data. 

The shift

Current

Proposed

Situation Fragmented Integrated data foundation
Focus Producing template-based reporting Maintaining a reusable data asset
Complexity Downstream (manual reconciliation) Upstream (data models and governance)
Data quality Reactive, spot-checked validations Proactive, embedded controls and automated traceability
Technology Siloed databases for separate disclosures Unified, machine-readable metadata

Outlook

Adapting to a data-centric supervisory model requires a systematic, long-term approach, and financial institutions should start to:

  • Assess where fragmentation and data duplication exist across risk, finance, and reporting systems. This is the critical first step to understanding the scale of the challenge and opportunity.
  • Manually map a single reporting requirement from its legal source to the final data point. This practical exercise will highlight the internal complexities that a connected architecture is designed to solve.
  • Shift the budget focus from short-term, tactical reporting fixes to building a robust, centralized data foundation capable of supporting AI-enabled tools and automated oversight.

The direction is towards a more connected, cross-authority, and legally traceable metadata environment that can improve consistency, reuse, and transparency throughout the entire reporting chain.

How Regnology supports the entire regulatory reporting process

Navigating the transition to DPM 2.1 requires a strategic partner with a future-ready data architecture. Regnology supports both regulators and regulated institutions in adapting to the new paradigm:

  • Regnology Reporting Hub (RRH) serves as the unified processing engine for regulated institutions. It consumes data, applies the necessary regulatory logic, and automatically generates compliant, fully traceable regulatory reports and disclosures.
  • Regnology Granular Data Model (RGD) establishes a single, governed data backbone across the enterprise, breaking down traditional silos to ensure data consistency and auditability.
  • Regnology Supervisory Hub (RSH) supports supervisory authorities in defining and managing regulatory reporting requirements. RSH Metadata Modeller enables users to ingest, design, and manage complex reporting logic in alignment with evolving machine-readable standards, serving as the central engine for structured DPM schema integration.

You might also be interested in

  • The rise of machine-readable and AI-enabled regulatory reporting

    Insight

    The rise of machine-readable and AI-enabled regulatory reporting

    European regulatory authorities are increasingly aligning towards a unified, interoperable, data-centric reporting infrastructure. Read our mid-year analysis to see how these initiatives are laying the groundwork for an AI-enabled regulatory ecosystem.

    Read more
  • From Risk to Regulatory Distribution: Building an Integrated Value Chain

    Insight

    From Risk to Regulatory Distribution: Building an Integrated Value Chain

    As regulatory pressures grow, risk, finance, and reporting must evolve from fragmented data silos to an intelligent, integrated value chain. Our new whitepaper with Chartis outlines the path to building a more efficient & resilient regulatory operating model.

    Read more
  • EU Supervisory Reporting: Why the EBA’s simplification agenda is really a data architecture story

    Insight

    EU Supervisory Reporting: Why the EBA’s simplification agenda is really a data architecture story

    The EBA’s simplification package is not a reduction exercise; it is a structural shift. Our new discussion paper analyzes the move from fragmented reports to an integrated data architecture.

    Read more

Contact us