EBA Consultation Paper on draft RTS on the Operational Risk Management Framework (26 August 2026)
Tag: S-2026-08-26-eba-oprisk-rts-cp Type: report (consultation paper on draft Regulatory Technical Standards) Author(s): European Banking Authority (EBA) Date of source: 2026-08-26 Date ingested: 2026-08-28 Authority weight: high — the EBA’s own consultation paper / press release, retrieved in full by WebFetch of the EBA press release; primary supervisory product under a direct CRR3 mandate. Raw file: S-2026-08-26-eba-oprisk-rts-cp.md. Listing URL: eba.europa.eu/publications-and-media/publications (item “Consultation paper on draft RTS on Operational Risk management framework”, 26 August 2026). Press release: eba.europa.eu/publications-and-media/press-releases/eba-consults-draft-technical-standards-institutions-operational-risk-management.
What it claims
On 26 August 2026 the EBA launched a public consultation on draft Regulatory Technical Standards (RTS) specifying the operational risk management framework that institutions must have in place under Article 323 of the Capital Requirements Regulation (CRR3). The draft RTS set out “harmonised, proportionate requirements for the governance, management process and systems institutions should use to identify, assess, monitor and manage operational risk.” The consultation runs until 31 December 2026, with a virtual public hearing on 29 September 2026.
The draft RTS specify three main components of the framework: (i) governance arrangements; (ii) the operational risk management process; and (iii) the operational risk assessment system. They clarify the roles and responsibilities of the management body, senior management and the independent operational risk management function, and set requirements for operational risk data and taxonomy, the business indicator component, reporting, validation and audit. The EBA states that requirements relating to ICT risk are addressed through DORA (i.e. not duplicated in this RTS).
A key feature is proportionality: institutions with a business indicator below EUR 750 million benefit from a lower frequency of reviews and reporting, a lesser level of granularity for their operational risk data, loss thresholds, and operational risk taxonomy.
On legal basis and background, the RTS are developed under Article 323(2) CRR (Regulation (EU) No 575/2013 as amended by Regulation (EU) 2024/1623 — CRR3), which mandates the EBA to specify the obligations under Article 323(1)(a)–(h), taking into account the size and complexity of the institution. The RTS support the EU Banking Package’s revised prudential framework for operational risk, which replaces the previous approaches (including the advanced measurement approaches) with a single standardised approach based on the business indicator. The EBA states the draft RTS build on the Basel Committee’s Principles for the Sound Management of Operational Risk and are consistent with the EBA Guidelines on internal governance and the DORA digital-operational-resilience framework. Following consultation, the EBA will finalise the draft RTS and submit them to the European Commission for adoption under Article 10 of Regulation (EU) No 1093/2010.
Notable quotes
- “The draft RTS set out harmonised, proportionate requirements for the governance, management process and systems institutions should use to identify, assess, monitor and manage operational risk.” (press release / meta description)
- “They clarify the roles and responsibilities of the management body, senior management and the independent operational risk management function.” (press release)
- “Requirements relating to ICT risk are addressed through the Digital Operational Resilience Act (DORA).” (press release)
What’s speculative vs. asserted
- Asserted (EBA / legal fact): the 26 August 2026 launch of the consultation; the Article 323(2) CRR3 legal basis; the three-component structure (governance arrangements, management process, assessment system); the clarification of management-body / senior-management / independent operational-risk-function roles; the requirements for operational-risk data and taxonomy, business indicator component, reporting, validation and audit; ICT risk routed to DORA; the EUR 750m business-indicator proportionality threshold; the 31 December 2026 deadline and 29 September 2026 hearing; the build-on-Basel-Principles and consistency-with-internal-governance-Guidelines framing.
- Draft / not yet in force: these are draft RTS under public consultation — not binding requirements. Firm-level obligations crystallise only after finalisation, Commission adoption and entry into force; content may change following consultation feedback.
- Ingesting-agent inference (not the source’s own claim): the article-level detail of Article 323(1)(a)–(h) and the specific granularity/threshold mechanics beyond the EUR 750m business-indicator tier sit in the 709KB consultation PDF, which was not extracted this run — the summary above is from the EBA press release only. The service-line mapping (GFD / RRE / IGA) and the read-across to the wiki’s AI-governance and 3LoD themes are the wiki’s assessment, not the EBA’s.
Topics this feeds
- Operational Resilience and Third Party Risk — the RTS codifies the operational-risk management-framework layer (governance, process, assessment system) that sits beneath the operational-resilience and DORA third-party threads this page tracks; the explicit “ICT risk via DORA” carve-out reinforces the integrate-don’t-duplicate boundary already documented there.
- EBA — European Banking Authority — a further CRR3-mandated RTS from the EBA, continuing its technology-neutral, integrate-into-existing-frameworks posture (build on Basel Principles + internal-governance Guidelines; ICT to DORA).
- Three Lines of Defence for AI — the draft RTS is an EU-prudential codification of a three-lines structure for operational risk: the management body and senior management (governance/oversight), an independent operational risk management function (2LoD), and validation/audit (3LoD) — a directly transferable template for how an AI/model-risk operating model would be evidenced under a technology-neutral regime [inference].
Open questions raised
- What do the draft RTS require specifically on operational risk data and taxonomy — and how closely does that align with BCBS 239 risk-data-aggregation and the EBA’s own integrated-reporting / common-data-dictionary work? (Detail in the unextracted consultation PDF.)
- How will the independent operational risk management function requirements interact with existing 2LoD/3LoD structures, and do they raise the bar on functional independence in a way that maps onto AI/model-risk oversight?
- Where exactly does the RTS boundary with DORA fall in practice, given ICT risk is carved out but AI/model operational-risk events (e.g. failures of AI-enabled processes) could straddle both?
- Will the proportionality tiering (EUR 750m business-indicator threshold) shape how smaller institutions evidence AI-related operational-risk controls?