EBA Operational Risk RTS: The 31 December 2026 Consultation Deadline
On 26 August 2026 the European Banking Authority opened a four-month consultation on draft Regulatory Technical Standards that will spell out, article by article, the operational risk management framework every institution subject to the Capital Requirements Regulation has to run. The mandate sits in Article 323(2) of Regulation (EU) No 575/2013 (the CRR), as amended by Regulation (EU) 2024/1623 (CRR3). Comments are due by 31 December 2026, and the EBA has to hand the finished draft to the European Commission by 10 January 2027. The EBA operational risk RTS is therefore short on runway: the text that governs your governance arrangements, loss data and validation routines is being written now, and the window to influence it closes at the end of the year.
The draft (reference EBA/CP/2026/18) specifies the management machinery behind the capital number: who in the organisation owns operational risk, what data has to be captured, how the framework is validated and audited, and how much of all this scales down for smaller institutions. The single most consequential design choice is a business-indicator threshold of EUR 750 million that splits almost every requirement into a fuller version and a lighter version.
The EUR 750 million threshold is the operational hinge of the whole instrument, and it is the first thing a reporting or risk team should locate itself against before reading another paragraph.
Related reading: our guide to the CRR3 operational risk own funds RTS, the parallel standard that specifies the business indicator components feeding the capital number.
The dates that actually bind
The consultation runs on a tight calendar.
- 26 August 2026: the EBA launches the consultation on draft RTS on the operational risk management framework (EBA/CP/2026/18).
- 25 September 2026, 16:00 CEST: registration deadline for the public hearing.
- 29 September 2026, 10:00 to 12:00 CEST: virtual public hearing on the draft RTS.
- 31 December 2026: deadline for submitting written comments through the EBA consultation page.
- 10 January 2027: the statutory deadline in Article 323(2) CRR for the EBA to submit the finished draft RTS to the European Commission.
After 10 January 2027 the file leaves the EBA. The Commission adopts the RTS as a Delegated Regulation under Articles 10 to 14 of Regulation (EU) No 1093/2010, with the usual scrutiny period for the Parliament and Council before it enters into force. There is no application date in the draft yet, which is exactly why the consultation phase is where the requirements are still moveable.
Where the mandate comes from, and why a simpler capital number changed nothing here
Article 323(1) of the CRR already requires institutions to have specific arrangements in place: a well-documented operational risk assessment and management system, an independent operational risk management function, regular reporting on exposures and losses, corrective-action procedures, routines for ensuring compliance, internal validation processes, regular audit reviews, and transparent and accessible data flows. Those obligations, points (a) to (h), have applied since 1 January 2025; the Article 323(2) mandate for the EBA to develop the RTS applied from 9 July 2024. Article 323(2) then instructs the EBA to develop draft RTS specifying those obligations while taking the size and complexity of the institution into account. The draft under consultation is the delivery of that mandate.
It helps to remember what changed around this article. CRR3 (Regulation (EU) 2024/1623), which entered into force on 9 July 2024 and applied from 1 January 2025, replaced the old menu of operational risk capital methods, including the advanced measurement approaches, with a single standardised approach built on the business indicator. A common reading of that simplification is that operational risk became a lighter subject, a formula rather than a discipline. The draft RTS pushes back on that reading in its own recitals: the revised prudential framework improves comparability and simplicity in the own funds calculation, and that revision does not lessen the need for sound internal arrangements to identify, assess, monitor, control, mitigate and report operational risk.
The draft also names its reference points. It builds on the Basel Committee’s Principles for the Sound Management of Operational Risk and stays consistent with the EBA Guidelines on internal governance, the EBA Guidelines on the management of ESG risks (EBA/GL/2025/01) and the digital operational resilience framework under DORA. If your existing framework already tracks those, much of the drafting will feel familiar; the value of the RTS is that it turns supervisory expectation into a single Level 2 baseline applied the same way across the Union.
Three components the operational risk RTS pins down
The RTS organises the framework into three interlocking parts, and the article structure follows them.
Governance arrangements
The responsibilities of the management body, senior management and the internal control functions, including the operational risk management function. This is where the roles get allocated across the three lines of defence.
The operational risk management process
The policies, processes and procedures used to identify, assess, monitor, control, mitigate and report operational risk, embedded in day-to-day decision-making so it informs ordinary management processes.
The operational risk assessment system
The methods, data, taxonomy, indicators and analyses that support a view of the institution’s operational risk profile, including the calculation of the business indicator component and, above the threshold, the annual operational risk loss.
The draft treats these as mutually reinforcing, and that shapes how a bank scopes its gap analysis: a data gap in the assessment system usually shows up as a reporting gap at the management body, and a governance gap shows up as unowned data.
Who owns what: management body, senior management, and the risk function
Article 4 of the draft is precise about the split between the two functions of the management body. The management body in its supervisory function approves the operational risk management framework, defines and approves the institution’s operational risk appetite at least annually, and monitors on a continuous basis that the operational risk profile stays within that appetite. The management body in its management function is responsible for implementing the approved framework. Senior management then translates the operational risk appetite into quantitative limits, for example limits based on loss metrics, monitors exposures against those limits, and runs escalation procedures when they are breached.
Article 10 sets out the independent operational risk management function as part of the second line of defence. Its tasks include designing and overseeing the management process and assessment system, challenging the operational risk of new products, markets, processes and systems, overseeing activities that could breach the risk appetite, and promoting an operational risk culture. The head of the function needs appropriate knowledge and stature, direct communication with the management body, and independence from the units being overseen.
The independence requirement has a precise scope in the draft text. Independence here means the function is not responsible for the day-to-day management, operation or performance of the activities, processes or systems it oversees, is free from conflicts of interest, and can challenge without undue influence; proportionate structural arrangements are permitted, with no obligatory separate department at every institution. The draft is explicit that the operational risk management function must not be responsible for the audit function, because audit sits in the third line and challenges the framework itself, and that where the operational risk and compliance functions are separate they should cooperate and document their reporting lines, particularly on legal risk. Smaller institutions can house the function proportionately, provided the independent, institution-wide view of operational risk is real and can be evidenced.
The EUR 750 million line and what changes on each side
The proportionality design is not a vague “apply proportionately” clause. The draft RTS draws a hard line at a business indicator of EUR 750 million, calculated in accordance with Article 314 of the CRR, and sets different expectations on each side of it. The table below is the EBA’s own summary of that split.
- Review of the effectiveness of the framework: at least annually above the threshold; at least every two years below it.
- Operational risk appetite: translated into quantitative limits with exposures monitored against them above the threshold; below it, the business indicator or its relevant components may be used as the only proxy for appetite.
- Operational risk data: an extended set above the threshold, including relevant loss data below EUR 20,000, near misses, scenario analysis and stress-testing results, and key risk and control indicators; a reduced set below it, including material loss data below EUR 20,000.
- Operational risk taxonomy: required to be consistent with the RTS on operational risk taxonomy above the threshold; recommended below it.
- Reporting of the operational risk profile to the management body: at least quarterly above the threshold; at least annually below it.
Below the threshold there is a further relief in Article 4: an institution may use the business indicator, or its relevant components, as the only proxy for its operational risk appetite. That relief is not unconditional. The competent authority may require additional quantitative measures where the business model or risk profile would be misrepresented by the business indicator alone. So a small institution with an unusually concentrated operational risk profile should not assume the proxy is the end of the conversation.
The CRR itself sets EUR 750 million as the starting point for the annual operational risk loss calculation in Article 316(1), but with an important qualification: the competent authority may waive that requirement for an institution whose business indicator does not exceed EUR 1 billion where the institution demonstrates that applying it would be unduly burdensome. Article 317’s loss-data-set obligations apply to institutions that calculate an annual operational risk loss under Article 316(1). Below EUR 750 million, the Article 316 annual-loss calculation is not required.
Loss data, near misses, and the EUR 20,000 question
The draft expands the operational-risk information used for management purposes beyond the statutory CRR loss-data calculation and applies a lighter approach below the EUR 750 million business-indicator threshold. The detailed Article 9 data fields should be mapped only against the consultation text or final RTS.
The EUR 20,000 figure is where a quick reading goes wrong. It is tempting to treat EUR 20,000 as a clean floor and ignore anything beneath it. The draft does the opposite. Above the threshold, institutions have to define, in their own procedures, the criteria that make a sub-EUR 20,000 loss “relevant” and then capture it. Below the threshold, institutions apply a relevance and materiality assessment to those small losses. The logic is that individually immaterial losses can, in aggregate, reveal a recurring control weakness or an emerging risk, so the selective capture of the relevant ones completes the picture. A firm that hard-codes a EUR 20,000 cut-off into its loss-capture tooling and stops there is not meeting the draft.
Boundary cases are the second common trap, and the EBA spells out its own interpretation in the consultation. Losses where operational risk is intertwined with a risk already carrying Pillar 1 capital, credit risk, counterparty credit risk and CVA risk, are classified under those other risk types (market-risk boundary losses are already inside operational risk scope by Article 317(6) CRR). Boundary cases with Pillar 2 risks such as strategic, business or liquidity risk should always be treated as operational risk, so those losses flow into the business indicator and, above the threshold, into the annual operational risk loss. Getting that categorisation wrong pulls losses into or out of the operational risk data set incorrectly, which is precisely the kind of error internal validation is meant to catch.
On taxonomy, Article 9 requires every institution to build and govern an operational risk taxonomy for classifying events as well as losses, and to aggregate the profile across business processes and organisational levels. Above the threshold, that taxonomy has to be consistent with the operational risk taxonomy established under Article 317(9) of the CRR; below it, alignment is only recommended. If you file COREP for operational risk, this is where the management framework and the reporting classification start to converge, a point worth checking against how the CRR3 operational risk numbers land in reporting.
How ICT and DORA fit, and where they stop
Article 2 handles the overlap with digital operational resilience directly. ICT risk management under Regulation (EU) 2022/2554 (DORA) has to form an integral part of the overall risk management framework, and ICT-related incidents that fall within operational risk are identified and treated as operational risk events. Where the operational risk RTS would require a policy, procedure, control or tool that DORA already specifies in detail, institutions may rely on the DORA arrangement to satisfy the RTS. The design goal stated in the draft is to avoid duplication.
The RTS draws on the information already produced under DORA’s incident management and reporting arrangements so that the operational risk profile has a complete, consistent view of ICT events; it does not restate DORA’s incident-classification thresholds, its testing regime, or introduce a parallel ICT reporting channel. Teams that have stood up a DORA programme should be connecting its incident feed into the operational risk data set instead of rebuilding it, and our explainer on DORA ICT incident reporting covers the source classifications that feed across.
Validation, audit, and the model-risk hook
Chapter IV of the draft separates three assurance layers that firms sometimes blur. Reporting (Article 11) requires a regular, timely reporting system that follows ordinary reporting lines, with the management function reporting operational risk information to the supervisory function at least quarterly, or at least annually below the EUR 750 million threshold, and ad hoc escalation when deficiencies appear. Internal validation and compliance routines (Article 12) sit separately, and audit reviews (Articles 13 and 14) sit above both as independent assurance.
Article 12 carries a detail worth flagging for anyone running models outside the regulatory perimeter. Internal validation has to periodically assess the operational risk assessment system and the process for calculating the business indicator component, and, above the threshold, the annual operational risk loss calculation. It also has to assess, where models are used for decision-making such as product pricing, artificial intelligence applications, valuation of financial instruments or client profiling, the soundness of those models to identify and mitigate model risk, other than regulatory models. That drags a category of non-regulatory models, including AI tools, into the operational risk validation scope. For firms building out AI governance, this is a concrete anchor point, and it connects to the wider question of AI and model risk in prudential reporting. Article 12 also asks for reconciliation between the accounting data on operational risk losses and the operational risk loss data set, which is the kind of control supervisors test first.
Audit under Article 13 has to confirm the process and assessment system are reliable and effective, verify the integrity of policies and the quality of the data used, including for the business indicator component, and maintain a review programme kept current for new or materially changed products, processes and systems. Where audit is outsourced to a third party, the management body stays accountable for the work being done to the approved audit plan.
Scenario analysis, stress testing and the link to ICAAP
The assessment system in Article 7 is explicitly forward-looking. It requires identification of operational risk through both bottom-up and top-down approaches, business process mapping, risk and control assessments, and scenario analysis and stress testing, with sophistication and frequency proportionate to the institution’s size and profile. The draft names three purposes for that scenario and stress-testing work: the internal capital adequacy assessment of the operational risk capital requirement, informing the operational risk appetite and limits, and testing exposures under severe but plausible conditions feeding the operational resilience approach.
The EBA is careful about what these tools are for. They support risk appetite, emerging-risk identification, remediation prioritisation and the internal capital adequacy assessment. In other words, the scenario and loss data you build for this framework feeds the ICAAP and your operational resilience work, not a bespoke capital model. The draft flags ESG factors, the growing use of artificial intelligence and geopolitical developments as emerging drivers to be picked up through this forward-looking lens.
What reporting and risk teams should map before 31 December 2026
For a draft whose text can still move, a structured read-across carries more value at this stage than an early rebuild: grounding any comment you plan to submit while keeping implementation scoped for later. A few concrete steps carry most of the value.
First, confirm which side of the EUR 750 million business indicator line the institution sits on, because that single fact resets the review frequency, the appetite mechanics, the data set, the taxonomy obligation and the reporting cadence. Second, map the current allocation of roles against Articles 4 and 10, specifically whether the appetite is approved at least annually by the supervisory function and whether the operational risk function is genuinely independent of the units it oversees. Third, list the data fields in Article 9 against what is actually captured today, paying attention to sub-EUR 20,000 relevant losses, near misses and boundary cases. Fourth, check whether the DORA incident feed is wired into the operational risk data set or still sitting in a parallel silo. Fifth, identify any non-regulatory decision-making models, including AI tools, that Article 12 would pull into validation scope.
The consultation itself runs on 16 numbered questions, several of which invite firms to share their own loss thresholds, risk-appetite metrics and views on the EUR 750 million cut-off. A response grounded in how the institution actually operates carries more weight than a general comment, and the public hearing on 29 September 2026 is the forum to test the harder proportionality points before writing them up.
Frequently Asked Questions
Does this RTS change my Pillar 1 operational risk capital number?
No. The own funds requirement for operational risk runs off the standardised approach and the business indicator introduced by CRR3. The draft RTS specifies the management framework behind that number, governance, data, validation and audit, and the EBA states its forward-looking tools are not intended to recreate an internal capital model.
Are investment firms in scope, or only banks?
The draft applies to institutions subject to Regulation (EU) No 575/2013, on an individual and, where applicable, consolidated and sub-consolidated basis under Part One, Title II. In practice that is credit institutions and the CRR investment firms still inside the CRR; most investment firms sit under the separate Investment Firms Regulation regime, outside the CRR operational risk framework.
If my business indicator is below EUR 750 million, can I ignore losses under EUR 20,000?
No. Below the threshold you still have to assess the relevance and materiality of operational risk losses below EUR 20,000 and record the ones that qualify, alongside losses above EUR 20,000. The lighter regime reduces the data set and the frequency of reviews and reporting; it does not remove the small-loss materiality assessment.
We already comply with the EBA internal governance guidelines and DORA. How much is new?
The draft is deliberately consistent with the internal governance guidelines, the Basel operational risk principles and DORA, and it lets you rely on DORA arrangements where they already meet a requirement. The new element is a single Level 2 baseline that fixes specific data fields, the EUR 750 million proportionality split, and validation scope for non-regulatory decision-making models, so most institutions face a gap-closing exercise rather than a build from zero.
Which taxonomy do we have to use?
Every institution builds and governs an operational risk taxonomy for classifying events. Institutions with a business indicator of EUR 750 million or more have to keep it consistent with the operational risk taxonomy established under Article 317(9) of the CRR; institutions below the threshold are recommended to align with that standard, without being obliged to.
When will the RTS actually apply?
There is no application date in the draft. The EBA finalises the RTS after the consultation and submits it to the European Commission by 10 January 2027, the deadline set in Article 323(2) CRR. The Commission then adopts it as a Delegated Regulation, subject to the Parliament and Council scrutiny period, before it enters into force. Article 323(1) CRR obligations themselves already apply.
How does the operational risk function relate to compliance and audit?
The operational risk management function sits in the second line of defence and cannot be responsible for the audit function, which is the independent third line. Where the operational risk and compliance functions are organisationally separate, the draft expects them to cooperate and exchange information, particularly on legal risk, with reporting lines and escalation documented.
Related Articles
- EBA and Commission on the CRR3 Operational Risk RTS: How the parallel standard specifies the business indicator components and loss inputs that drive the capital number.
- CRR3 Operational Risk Reporting: Where the standardised operational risk figures land in COREP and how institutions file them.
- DORA ICT Incident Reporting: The incident classifications and feed the operational risk framework relies on for ICT events.
- ICAAP and ILAAP Explained: How operational risk scenario analysis and stress testing feed the internal capital adequacy assessment.
- AI Model Risk in Prudential Reporting: Validation expectations for decision-making models, including AI tools, outside the regulatory model perimeter.
Key Takeaways
- The EBA operational risk RTS (EBA/CP/2026/18) is out for consultation until 31 December 2026; the EBA must submit the final draft to the Commission by 10 January 2027 under Article 323(2) CRR.
- The RTS specifies the management framework behind the operational risk number, not the CRR3 own funds calculation, which already runs off the business indicator.
- A business indicator of EUR 750 million is the proportionality line: above it, annual framework reviews, quantitative appetite limits, an extended data set, a mandatory Article 317(9)-consistent taxonomy and at least quarterly management-body reporting; below it, biennial reviews, a business-indicator proxy for appetite, a reduced data set, a recommended taxonomy and at least annual reporting.
- Sub-EUR 20,000 losses are not out of scope: above the threshold firms capture relevant small losses on defined criteria; below it they apply a relevance and materiality test.
- Boundary cases with credit, counterparty and CVA risk are classified under those Pillar 1 risks; boundary cases with strategic, business or liquidity risk are treated as operational risk.
- ICT risk stays governed by DORA; the RTS pulls DORA incident data into the operational risk profile and lets firms rely on existing DORA controls to avoid duplication.
- Article 12 brings non-regulatory decision-making models, including AI applications used for pricing, valuation or client profiling, into internal validation scope.
- The public hearing is on 29 September 2026 (10:00 to 12:00 CEST); registration closes 25 September 2026 at 16:00 CEST.
Sources and References
- EBA press release, “The EBA consults on draft technical standards on institutions’ operational risk management”, 26 August 2026: eba.europa.eu
- EBA Consultation Paper on draft RTS on operational risk management framework (EBA/CP/2026/18), 26 August 2026 (PDF): eba.europa.eu (PDF)
- Regulation (EU) No 575/2013 (Capital Requirements Regulation), Article 323, as amended by Regulation (EU) 2024/1623 (CRR3): EUR-Lex consolidated CRR
- Regulation (EU) 2024/1623 (CRR3): EUR-Lex
- Regulation (EU) 2022/2554 (Digital Operational Resilience Act, DORA): EUR-Lex
- Basel Committee on Banking Supervision, Revisions to the principles for the sound management of operational risk (March 2021): bis.org
The window to shape the framework
The operational risk RTS will not change what an institution holds in capital, but it will set the governance, data and assurance standard that supervisors read against for years. The moveable part of that standard, the EUR 750 million split, the small-loss capture criteria, the validation scope for AI and other decision-making models, is on the table only until 31 December 2026. Locate the institution against the threshold, run the Article 9 data read-across, and put a grounded comment in before the hearing on 29 September 2026, because after 10 January 2027 the draft is the Commission’s to adopt.
Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.
