The competence boards are missing has no box on the "fit & proper" form...
I won’t bore you with regulation but CRD6 isn’t really helping Europe modernise…
Hi all 👋
As the years go by, regulations pile up, habits and customs settle in, tensions grow around risk and putting the impact on the business into perspective is visibly pushed to one side…. Well, I’m speaking from my own feeling and my own practice here…
There is a systemic gap between the official doctrine displayed by supervisors and the operational reality on the ground. The CSSF’s 2024 annual report, published in 2025, illustrates this well : technology and artificial intelligence appear there as supervisory priorities but always attached to the risk and governance chapter (which, to be fair, is the CSSF’s role), unfortunately never to the strategy or business model one. And yet, the financial sustainability of supervised organisations is also part of the equation. Isn’t it?
In practice, this distinction plays out through two major dynamics.
Tech’ as a mere sub-category of risk
For Banks and funds, technology is almost never treated as a strategic subject at board level. Which is rather sad. It is systematically reframed through the lens of risk management (cyber risk, operational resilience under DORA, third-party risk,…). The Tech’ profile sought in a board member is that of a manager able to make sure the IT system doesn’t cut off client access or trigger a fine, rarely that of a visionary who deeply understands, say, the impact of AI on the organisation.
The obsession of financial institutions remains the preservation of their licence to operate and the smoothness of their relationship with the supervisory authority. Appointing an atypical tech’ profile to the board is often seen as a political risk during the “fit & proper” approval process. Banks prefer to over-represent profiles of former regulators, lawyers or traditional risk directors. These profiles master the supervisor’s codes and guarantee smooth communication with the CSSF or the ECB, which turns out to be valued internally more than mastery of artificial intelligence or the cloud.
I’ve experienced this from the inside over the past few months, through three selection processes where I was a candidate as an iNED. The conversation with the headhunter or the Board Chairman kept coming back to the same place: my ease with the regulator, my ability to anticipate its expectations, the fluidity people imagined between me and the regulator. My background in tech’ and my network, though praised in interviews as a rare point of differentiation, stayed in the background.
In the final rounds of several of these processes, I eventually understood where the final decision had actually been made: on a regulatory address book judged insufficient on my part, weighing more in the arbitration than the competence that no one else around the table carried.
What the reform has just sealed
The reform that has just gone through confirms it, almost word for word. The transposition of CRD6 has just tightened the “fit & proper” assessment of board members and executive directors. Reputation, knowledge, competence, experience, availability, the number of mandates held: the file has grown even thicker. The text even specifies that members of the supervisory body must collectively possess the knowledge required in banking and financial markets, legal and regulatory requirements, the governance system, internal control, strategic planning and risk management.
Nowhere is it required that this collective competence cover technology, AI or cyber. The regulator has just made heavier, more formalised, more documented, the very exercise that ended up ruling me out, without ever touching what is actually missing around the table.
In other words, this market habit has just become a regulatory requirement, one that protects this gap instead of filling it.
This week’s episode
This week’s episode comes from further afield, on ground adjacent to mine.
I hosted Clotilde Bouchet, an independent board member in the financial sector. A career that starts at Sciences Po, ten years at Crédit Agricole up to group CFO functions at Amundi, then ABN Amro at the time of a spin-off, then Axa IM in the middle of the 2008 crisis. It was that crisis which pushed her towards fintech. She then sat on the board of Silvr, since sold to Karmen.
In the conversation, she points to an imbalance she observes in large groups: Boards spend most of their time on compliance, risk matrices and prudential ratios and you have to fight to bring a real business discussion back onto the agenda.
Without talking about Tech’ or AI at all, she describes, in her own terms, exactly the same reflex as the one that ruled me out: a board that reassures itself with the right totem rather than checking whether it collectively holds the competence it actually needs.
What I take from this
The common thread between these three moments : my own experience, the CRD6 reform, Clotilde’s observation, comes down to one simple sentence: European financial governance has learned to assess a number of topics closely tied to past risks, without ever learning to assess competence in the face of risks it cannot yet name.
This gap gets filled by changing what a nomination committee is actually looking for in a shortlist, before looking at who knows how to talk to the ACPR, FCA, CSSF or the ECB.
Next time a nomination file lands in front of you, look first at what it says about the candidate in the face of the risk no one else around the table can assess. The rest, reputation, availability, the regulator’s address book, comes after.


