EBA launches consultation on Operational Risk Management Standards
a man and woman sitting at a table with a laptop

EBA launches consultation on Operational Risk Management Standards

​The European Banking Authority (EBA) has launched a public consultation on draft Regulatory Technical Standards (RTS) specifying the operational risk management framework that institutions must have in place under Article 323 of the CRR3.

The draft RTS focus on three core components:

🔹 Governance arrangements – clarifying the roles and responsibilities of the management body, senior management and the independent operational risk management function.

🔹 Operational risk management process – covering the identification, assessment, monitoring and management of operational risk.

🔹 Operational risk assessment system – including requirements for operational risk data and taxonomy, reporting, validation, audit and related systems.

One of the most important features is proportionality. Institutions with a business indicator below EUR 750 millionwould benefit from less frequent reviews and reporting, less granular operational risk data requirements, and simplified thresholds and taxonomy requirements.

The RTS also clarify the interaction with DORA, with ICT risk requirements addressed through the Digital Operational Resilience Act.

Under the EBA framework, operational risk is the risk of losses resulting from inadequate or failed internal processes, people and systems, or from external events. It includes legal risk, but excludes reputational risk.

This makes operational risk a broad risk category covering areas such as process failures, human error, fraud, legal and conduct risks, business disruption, outsourcing and ICT-related risks. The EBA also highlights ICT and cyber risk, fraud, and legal risk among the key drivers of operational risk.

At the same time, the draft RTS recognise that ICT risk should not be managed through a parallel set of CRR3 requirements. Instead, ICT risk requirements are addressed through DORA, which establishes the dedicated EU framework for digital operational resilience, including ICT risk management, ICT-related incident reporting, resilience testing and ICT third-party risk management.

In practice, this creates an important distinction:

CRR3 / Operational Risk RTS → broader operational risk framework

DORA → specific ICT risk and digital operational resilience requirements

The two frameworks therefore need to work together, rather than institutions maintaining two disconnected ICT risk management frameworks.

📅 Consultation deadline: 31 December 2026

Save up to 20%

Learn More, Save More

Enroll in multiple courses and unlock exclusive bundle discounts

Related news:

Group Discount
Learn Together, Save Together

Team orders? Get 10% off automatically — bigger groups, contact us.

We value your privacy

We use cookies to personalize content, and analyze our traffic. We also share information about your use of our site with our analytics partners. You can change your preferences at any time. For more information, please see our Privacy Policy