The European Banking Authority (EBA) has launched a public consultation on draft Regulatory Technical Standards (RTS) specifying the operational risk management framework that institutions must have in place under Article 323 of the CRR3.
The draft RTS focus on three core components:
🔹 Governance arrangements – clarifying the roles and responsibilities of the management body, senior management and the independent operational risk management function.
🔹 Operational risk management process – covering the identification, assessment, monitoring and management of operational risk.
🔹 Operational risk assessment system – including requirements for operational risk data and taxonomy, reporting, validation, audit and related systems.
One of the most important features is proportionality. Institutions with a business indicator below EUR 750 millionwould benefit from less frequent reviews and reporting, less granular operational risk data requirements, and simplified thresholds and taxonomy requirements.
The RTS also clarify the interaction with DORA, with ICT risk requirements addressed through the Digital Operational Resilience Act.
Under the EBA framework, operational risk is the risk of losses resulting from inadequate or failed internal processes, people and systems, or from external events. It includes legal risk, but excludes reputational risk.
This makes operational risk a broad risk category covering areas such as process failures, human error, fraud, legal and conduct risks, business disruption, outsourcing and ICT-related risks. The EBA also highlights ICT and cyber risk, fraud, and legal risk among the key drivers of operational risk.
At the same time, the draft RTS recognise that ICT risk should not be managed through a parallel set of CRR3 requirements. Instead, ICT risk requirements are addressed through DORA, which establishes the dedicated EU framework for digital operational resilience, including ICT risk management, ICT-related incident reporting, resilience testing and ICT third-party risk management.
In practice, this creates an important distinction:
CRR3 / Operational Risk RTS → broader operational risk framework
DORA → specific ICT risk and digital operational resilience requirements
The two frameworks therefore need to work together, rather than institutions maintaining two disconnected ICT risk management frameworks.
📅 Consultation deadline: 31 December 2026