This website uses cookies

Read our Privacy policy and Terms of use for more information.

EBA Puts Banks' Operational-Risk Rulebook Out for Consultation

The European Banking Authority opened a four-month consultation on 26 August on draft technical standards for the operational-risk management framework banks must maintain under CRR3 — governance, process, and assessment rules that close for comment on 31 December 2026.

Why It Matters

This is the standard that completes the EU Banking Package's single standardised approach to operational risk. The draft RTS harmonise what “having an operational-risk management framework” actually means — the roles of the management body, senior management, and an independent operational-risk function, plus rules for risk data, taxonomy, the business-indicator calculation, reporting, validation, and audit. ICT risk stays with DORA, so this is the non-ICT operational-risk backbone.

Proportionality is the pivot point for scoping. Institutions with a business indicator below EUR 750 million get lower review and reporting frequency and lighter data, loss-threshold, and taxonomy requirements — so where a firm sits relative to that threshold changes the compliance burden materially. With comments due 31 December 2026 and a public hearing on 29 September, operational-risk and compliance teams have a narrow window to shape the rules before they harden.

Action Items

  1. Run a gap analysis — map the draft governance, process, and assessment requirements against your existing operational-risk framework and flag gaps in risk data, taxonomy, and the business-indicator calculation.

  2. Confirm your proportionality tier — if your business indicator is near EUR 750 million, model the reporting and data-granularity impact of falling on either side of the threshold.

  3. Calendar the deadlines — register for the 29 September public hearing by 25 September, and file your consultation response by 31 December 2026.

Get the full analysis. Pro subscribers receive the complete deep dive, all 5 action items, source documents, and jurisdiction-specific compliance checklists.

logo

Subscribe to Default to read the rest.

Become a paying subscriber of Default to get access to this post and other subscriber-only content.

Upgrade

A subscription gets you: