pancucci.pro

IT is taking the driver’s seat. Regulation is climbing in next to it.

From cost centre to enabler to driver: why the infrastructure behind your business is becoming the supervised perimeter.

Contents
  1. The regulators noticed before the market did
  2. The supervisor’s scorecard says the market has not caught up
  3. The frontrunners are already reorganising
  4. When infrastructure becomes the advantage, it becomes the perimeter
  5. What I would put on the board agenda

I have spent twenty-five years watching the same conversation change shape. In the first decade, technology came to the executive table to defend a budget. IT was a cost centre: the question was always how much, rarely what for. Then came the enabler years. Digital transformation earned technology a seat at the strategy table, and the question became what IT could do for the business: faster closings, cleaner data, better customer journeys.

We are now entering a third stage, and most governance models have not caught up with it. When models price risk, when algorithms decide which claims settle automatically, when agents execute decisions that used to require a signature, IT no longer enables the business. It drives it.

Where does your IT sit? Cost centre, enabler, driver: the evolution of the role of technology in the business model, and the regulator that followed each stage.
Chart. Where does your IT sit? Cost centre, enabler, driver: the evolution of the role of technology in the business model, and the regulator that followed each stage.

And when IT drives, regulation climbs in next to it.

The regulators noticed before the market did

Consider the sequence, because it is longer than most boards realise.

2020. Ireland moved first. The Central Bank added the Chief Information Officer to its list of pre-approval controlled functions. PCF-49 applies where IT is “a key enabler or core element of the firm’s business model”. Read that definition again: the regulator wrote half of this article’s thesis six years ago. And note what does not exist: there is no CTO function on the list. Whatever the title on the business card, the most senior technology role falls within scope. The regulator looks through titles at the function itself.

2024. The accountability deepened. Ireland’s Individual Accountability Framework assigns prescribed responsibilities, including technology and operational resilience, to named senior executives.

2025. DORA, applicable since January, places ultimate responsibility for ICT risk on the management body itself, and that responsibility cannot be delegated. Article 5 goes further than most boards have noticed: members must actively maintain sufficient knowledge and skills to assess ICT risk, with specific training on a regular basis.

2026. The direction of travel continues. EBA and ESMA are currently revising their joint suitability guidelines so that board fitness explicitly includes understanding of ICT risk, digital operational resilience and the AI technologies used within the entity.

Two levels, national and European, six years, one direction. The fit and proper perimeter has been moving steadily toward the people who run the technology, and now toward the technological literacy of the board itself.

The supervisor’s scorecard says the market has not caught up

Has the market drawn the consequences? The supervisor has already answered.

In the ECB’s aggregated SREP results for 2025, ICT risk received the worst average score of any category in the entire assessment. The recurring weaknesses will sound familiar to anyone who has sat through a supervisory dialogue: cybersecurity strategies, incident management, third-party risk frameworks. And among the deficiencies named in the 2024 cycle and the targeted data review that followed, one comes first: management bodies’ involvement and expertise.

The incident data tells the same story from another angle. In the first ESAs report on major ICT incidents under DORA, financial entities reported 3,383 of them; roughly one third had cross-border impact, largely because so many firms depend on the same shared infrastructures and services. Concentration is not a forecast. It is already in the incident statistics.

So the gap is documented on both sides: the rules have moved to the boardroom, and the boardroom, on the supervisor’s own scorecard, is not yet equipped for them.

The frontrunners are already reorganising

While the average scorecard lags, the leaders have started to redraw their organisation charts. Munich Re appointed a Chief Technology Officer to its Board of Management in August 2025.

Allianz has had, since 2021, a Chief Operating Officer on its Board of Management who previously ran Allianz Technology; the group now registers over 900 AI use cases and holds the industry’s largest AI specialist workforce, according to the 2026 Evident AI Index. Swiss Re places data and technology under a Group Chief Digital and Technology Officer.

The Index adds honest nuance to these examples. Munich Re ranks eleventh overall yet second on the innovation pillar, exactly where a reinsurer building AI underwriting capability would want to concentrate. Swiss Re sits fifteenth, strongest on transparency. Generali, whose practitioners co-authored the AI insurance blueprint I turn to below, ranks fourteenth overall but second on leadership. None of the three is a top-five generalist; all three are building depth where their strategic bets sit, which is precisely how organisation charts begin to change.

And across the Index’s cohort, the thirty largest insurers of North America and Europe by premiums written and assets held, spanning life, P&C and composite groups, AI specialist roles grew 32 percent in a year, to almost one employee in fifty, while the overall workforce shrank by 2.2 percent. That is not an experiment. It is a reallocation.

The Index’s own weighting, with talent counting for 45 percent of the score, quietly confirms what I argued in my first piece on AI readiness: this is an operations problem before it is a technology problem.

The regional split deserves a note of its own. Europe holds the top of the 2026 table, with Allianz first, AXA second and Zurich fourth, while North American carriers fill most of the remaining top ten. But look at the bottom of the ranking and the picture sharpens: the last three places are also European. Europe supplies both the frontrunners and the laggards.

That detail matters, because it disposes of the comfortable excuse in both directions: regulation did not hold the leaders back, and it did not carry the laggards forward. The firms that grew up under GDPR and DORA and chose to turn the obligation into organisational muscle are setting the pace. The muscle, in other words, is a choice, not a birthright.

So the divide that matters is no longer between insurance and its future. It is between firms whose organisation chart already reflects the driver era, and firms whose organisation chart still describes a cost centre.

When infrastructure becomes the advantage, it becomes the perimeter

A recent cross-industry blueprint on AI insurance, led by an AI underwriting firm with contributors from Generali, QBE, Aon, RAND and Stanford, argues that insuring AI risk at scale is not a wording exercise but an infrastructure business: incident data, technical assessment, continuous monitoring, specialist claims capability. As the researcher Hiroko Washiyama observed in her reading of that paper, the next competitive advantage in AI insurance may sit less in the policy than in the infrastructure behind it.

I would take that thought one step further, because in regulated financial services there is a pattern that never fails.

Whatever becomes the competitive advantage becomes, in time, the supervised perimeter.

It happened to capital, to conduct, to data. It is happening now to infrastructure. The registers, the monitoring, the tested exit strategies, the incident pipelines: the same capabilities that the blueprint describes as tomorrow’s competitive moat are the ones DORA already obliges regulated firms to build and supervisors already score.

That convergence is the real strategic fact of this decade. Firms that treat their compliance plumbing as a cost to be minimised will build it twice: once badly for the supervisor, once properly for the market. Firms that treat it as a product foundation will find they built it once, and that both the supervisor and the market pay for the same quality.

What I would put on the board agenda

The sequence I recommend is deliberately unglamorous.

Treat the CIO as a risk owner, not an internal supplier. If the function is important enough for pre-approval, it is important enough to report to the board on risk terms: exposures, tolerances, tested capabilities, not project status.

Recruit for technological literacy in the boardroom. Not coders: directors who can interrogate a model inventory, challenge a concentration map, and ask what was actually tested behind an exit strategy. The suitability guidelines are heading there anyway; better to arrive before they do.

Consolidate assurance. DORA, AI governance and security controls overlap heavily; one integrated assurance plan costs less than three parallel ones and produces the coherent evidence trail supervisors increasingly ask to see.

Make board training an engineering discipline, not an attestation. Article 5 does not ask whether directors attended a session; it asks whether they can understand and assess the risk.

And locate your firm honestly on the arc. Cost centre, enabler, driver: where does technology actually sit in your business model today? The regulator has already formed its view. The only question is whether your governance agrees with it.

The wheel has changed hands.
The passenger seat is taken.
What remains open is how well prepared the driver will be.

This is the edition of record of the article first published on LinkedIn on 26 July 2026.