The EBA consults on draft technical standards on institutions’ operational risk management
AI Analysis
The EBA launched a consultation on draft Regulatory Technical Standards under Article 323(2) of Regulation (EU) No 575/2013, as amended by CRR3 Regulation (EU) 2024/1623, defining institutions’ operational risk management framework. The draft would harmonise governance, operational risk processes, assessment systems, data, taxonomy, reporting, validation and audit requirements, with reduced granularity and review/reporting frequency for institutions with a business indicator below EUR 750 million.
Key dates
- 2026-08-26
- EBA consultation launched and consultation period opened.
- 2026-09-25 Deadline
- Deadline to register for the EBA virtual public hearing, at 16:00 CEST.
- 2026-09-29
- EBA virtual public hearing from 10:00 to 12:00 CEST (Paris time).
- 2026-12-31 Deadline
- Deadline for submitting consultation responses to the EBA, at 23:59 CEST.
Suggested considerations
- Compliance and operational-risk teams should obtain and map the consultation draft against Article 323(1), points (a) to (h), of the CRR and identify requirements that would require changes to policies, committee mandates, controls or management information.
- Institutions should determine their business indicator and assess whether it is below the proposed EUR 750 million proportionality threshold, while treating that threshold as proposed rather than final.
- Firms should inventory operational-risk data sources, loss-event thresholds, taxonomies, reporting processes, validation controls and audit coverage, and assess whether data granularity is sufficient for the proposed framework.
- Management-body and senior-management responsibilities should be compared with existing governance arrangements, including the independence, authority and resourcing of the operational risk management function.
- Firms should assess alignment between the proposed RTS, CRR3 operational-risk capital and reporting implementation, the EBA Guidelines on internal governance and DORA, avoiding duplication or gaps for ICT-related risk.
- Affected stakeholders should consider submitting comments to the EBA by 31 December 2026; compliance teams may wish to coordinate responses with risk, finance, internal audit and industry associations.
- Stakeholders wishing to participate in the EBA public hearing should register by 25 September 2026 at 16:00 CEST and prepare questions on proportionality, data granularity, thresholds, reporting frequency and implementation timing.
- Institutions should monitor the EBA’s final draft, the European Commission’s endorsement process and the eventual application date before treating the consultation text as a binding requirement.
What changed
The proposed RTS would give detailed effect to Article 323(1), points (a) to (h), of the CRR by requiring three framework components: governance arrangements, an operational risk management process and an operational risk assessment system. They clarify responsibilities of the management body, senior management and the independent operational risk management function, and address operational risk data and taxonomy, the business indicator component, reporting, validation and audit. ICT risk requirements are intended to remain governed primarily by Regulation (EU) 2022/2554 (DORA). The proposal is part of CRR3’s replacement of legacy operational risk approaches, including advanced measurement approaches, with a single standardised approach based on the business indicator. The EBA’s broader o
Compliance impact
The proposal is not yet legally binding, but it signals material future supervisory expectations for operational-risk governance, data quality, taxonomy, monitoring, validation and audit across CRR3 institutions. Impact is likely to be highest for institutions whose existing frameworks were designed around legacy operational-risk approaches or whose loss data and management information cannot supp
Who is affected
Related regulations
References
AI-generated analysis. May contain errors or omissions — verify with the original EBA source before acting. Full disclaimer.
What the EBA said
The European Banking Authority (EBA) today launched a public consultation on draft Regulatory Technical Standards (RTS) specifying the operational risk management framework that institutions must have in place as per Article 323 of the Capital Requirements Regulation (CRR3). The draft RTS set out harmonised…
Extract from EBA . Read the full notice at the source for the authoritative text.