EBA Proposes New Operational Risk Framework for Banks Under CRR3
Key Takeaways
- EBA Sets Out the Operational Risk Rulebook: The draft standards specify how institutions should govern, identify, assess, monitor and manage operational risk under CRR3.
- Three Elements Form the Core Framework: The proposal centers on governance arrangements, the operational risk management process and the operational risk assessment system.
- Smaller Institutions Get a Lighter Touch: Institutions with a business indicator below €750 million would face less frequent reviews and reporting and less granular requirements for operational risk data, loss thresholds and taxonomies.
- DORA Remains the Home for ICT Risk: Rather than duplicate existing requirements, the EBA leaves ICT risk to the EU’s separate digital operational resilience framework.
- The New Framework Supports CRR3’s Standardized Approach: The standards accompany the EU Banking Package’s shift away from previous operational risk approaches, including advanced measurement approaches, toward a single standardized approach based on the business indicator.
Deep Dive
The EBA opened a public consultation on draft Regulatory Technical Standards under CRR3 that would set common requirements for how institutions govern, identify, assess, monitor and manage operational risk. The consultation runs through Dec. 31.
The proposal gives shape to Article 323 of the Capital Requirements Regulation, dividing the framework into three parts: governance arrangements, the operational risk management process and the operational risk assessment system. Within those, the standards get considerably more specific. They clarify the responsibilities of management bodies, senior management and independent operational risk management functions, and establish requirements covering operational risk data and taxonomies, the business indicator component, reporting, validation and audit.
ICT risk is largely absent for a reason. The EBA leaves those requirements to the Digital Operational Resilience Act, or DORA, rather than layering another set of technology-risk rules onto institutions already subject to that regime.
The result is an attempt to put some common architecture around a category of risk whose defining characteristic has always been its variety. Operational losses can begin with a broken process, a mistake, a weak control or an external event. The regulation cannot anticipate every failure. It can be considerably more prescriptive about the machinery an institution is expected to have ready when one occurs.
Not every institution would be expected to build that machinery to the same specifications. The EBA has made proportionality a central feature of the draft. Institutions with a business indicator below €750 million would be allowed less frequent reviews and reporting, as well as less granular operational risk data, loss thresholds and taxonomies. That distinction follows the mandate in CRR3 itself, which directs the EBA to account for an institution’s size and complexity when developing the standards.
The threshold is also a recognition of an old regulatory problem. A framework detailed enough for a large, complex bank can become an exercise in paperwork when applied unchanged to a smaller institution. The EBA’s proposal does not exempt smaller firms from operational risk management. It adjusts how much machinery they are expected to maintain around it.
Behind the consultation sits a larger change in the way European banks account for operational risk. The EU Banking Package revised the prudential framework and replaced the previous approaches to operational risk, including advanced measurement approaches, with a single standardized approach based on the business indicator. The draft standards deal with the management framework surrounding that new regime rather than simply its capital calculation.
That makes questions about governance and data more than administrative detail. A standardized capital methodology still depends on institutions being able to organize operational risk information, assign responsibility for it and maintain systems capable of assessing and reporting what is happening inside the business. The draft RTS specify how the EBA expects that work to be done.
The standards draw on the Basel Committee on Banking Supervision’s Principles for the Sound Management of Operational Risk and are designed to remain consistent with the EBA’s existing Guidelines on internal governance. Their treatment of ICT risk also keeps them aligned with the separate digital resilience framework established under DORA.
Stakeholders have four months to respond. The EBA will hold a virtual public hearing on Sept. 29 from 10 a.m. to noon CEST, with registration open until 4 p.m. CEST on Sept. 25. Comments submitted during the consultation will be published after it closes unless respondents request otherwise. After reviewing the feedback, the EBA will finalize the draft standards and submit them to the European Commission for adoption.
For institutions, the significance is less in any single requirement than in how much of the operational risk function the proposal would put on common footing. CRR3 has already replaced a collection of capital approaches with one standardized method. The EBA is now defining who owns operational risk, how it is assessed, what information supports it and how institutions demonstrate that the system actually works.
The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

