Key Highlights
- Results of due diligence visits to the Baltics and Romania.
- AI governance included in Risk Methodologies: New independent scoring component introduced under Operational Risk, to be rolled out across all assessed entities.
- Global Custodian Assessment methodology overhauled: Methodology refreshed with new assessed elements, rebalanced weightings and more streamlined structured scoring.
Market Outlook and Capital Markets update
The Committee noted several prevailing trends in the global capital markets that may impact the risk profile of global and sub-custodians:
- AI Integration and Systemic Risk: As financial institutions accelerate the deployment of (particularly Agentic) AI across their businesses, the Committee is monitoring the transition from “pilot” to “production” phases to ensure operational resilience and the mitigation of algorithmic errors.
- Monetary Policy Uncertainty: Central banks were moving toward a more normalised interest rate environment in June with the ceasefire between US-Iran diminishing geopolitical threats and renewing confidence in the global economic outlook. However, the more recent breakout of hostilities has seen more hawkish interest-rate projections with a ‘higher-for-longer’ regime more probable.
- EU Harmonisation: Continued progress toward the T+1 settlement cycle across European markets is increasing the pressure on custodians to automate reporting and corporate action processing. Harmonisation for Savings and Investment Union (SIU) is also driving change, a trend reflected in our recent Baltic and Romanian reviews.
Baltic Markets Review
The Committee reviewed the risk assessments for all custodian banks and market infrastructures across the Baltic region. Upgrades were approved for Asset Servicing across agent banks in Estonia, Latvia, and Lithuania, following confirmation that market claims are processed automatically by the CSD. Combined with a strengthened operational risk profile specifically relating to Disaster Recovery Plan (DRP) tests, this resulted in an overall Custody rating upgrade for some of the local providers.
Romanian Market Review
The Committee noted a positive trend in the Romanian market, highlighted by an increase in the main index and rising foreign investment. Key structural improvements were noted, including the imminent operationalisation of a CCP (CCP.RO) The CCP.RO was provided with it’s operating authorisation by the Financial Supervisory Authority (ASF) on 1st July to clear equities, equity index futures (Phase 1), and cash-settled electricity futures and forward contracts (Phase 2). It is currently finalising its technical infrastructure and risk management protocols and onboarding clearing members, but no live date has yet been announced.
Regarding custodian banks in the market, most risk grades remained unchanged except for one provider whose improved ability to offer bespoke, customized reminders for corporate action instructions resulted in an upgrade to their Asset Servicing risk grade. Another provider’s Overall Risk outlook has been returned to ‘Stable’ from ‘On Watch,’ as previous reports regarding the potential sale of the Romanian business did not materialise.
Global Custodian Assessment (GCA) Methodology
The Committee conducted a comprehensive review of the GCA scoring methodology to better reflect current operational risks and asset safety developments.
On Asset Safety Risk refinements were made to the scoring guidelines for network structure, proportion of segregated versus omnibus accounting across bank networks, contractual liability, network insolvency legal opinions, insurance verification, and regulatory standing to better differentiate between various risk profiles.
On Operational Risk, AI governance and its operational application will now be incorporated into the Operational Risk category, with new criteria covering AI adoption, strategy, risk management, and audit introduced. The same criteria will be rolled out across all TM methodologies.
Due diligence and field activity
The network management team continues to maintain active oversight of the global network. Due diligence visits were conducted in the following jurisdictions: Argentina, Indonesia, Philippines, Turkey, Tunisia and Uruguay.


Risk Committee Updates
Stay informed with Thomas Murray for the latest on market dynamics and regulatory trends – subscribe to Risk Committee Updates on LinkedIn.
We safeguard clients and their communities

Petroleum Development Oman Pension Fund
“Thomas Murray has been a very valuable partner in the selection process of our new custodian for Petroleum Development Oman Pension Fund.”

ATHEX
"Thomas Murray now plays a key role in helping us to detect and remediate issues in our security posture, and to quantify ATHEX's security performance to our directors and customers."

Northern Trust
“Thomas Murray provides Northern Trust with a range of RFP products, services and technology, delivering an efficient and cost-effective solution that frees our network managers up to focus on higher Value activities.”
Insights

Why Cyber Risk Belongs in Operational Due Diligence
Cyber risk is still treated as an IT checkbox in operational due diligence. Here's why it needs to be a continuous monitoring signal.

Thomas Murray Publishes "Beneath the Asset: Cyber Risk and the Infrastructure Institutions Depend On"
Cyber risk has become the primary mechanism through which infrastructure failures reach institutional assets

Private Equity Cyber Risk Checklist
The PE Cyber Risk Checklist is a ten-step diagnostic for PE fund leadership, covering every stage from pre-deal surveillance to exit readiness.

Why Private Equity Has Underinvested in Asset Safety, and Why the Window Is Closing
Half of PE portfolio companies carry elevated cybersecurity risk. Here's why asset safety has been underinvested, and why that's changing fast.
