On 26 August 2026 the EBA opened consultation EBA/CP/2026/18: draft RTS under Article 323(2) CRR specifying the operational-risk management framework obligations of Article 323(1), points (a) to (h). CRR3 collapsed op-risk capital into a single business-indicator formula — no models, no argument. What the formula does not do is tell a supervisor whether the institution manages operational risk. This RTS is where that assessment gets its inspectable requirements: governance roles for the management body and senior management, an independent op-risk function, loss-data collection and classification, review, reporting, validation and audit. The consultation runs to 31 December 2026.
Article 323(1) CRR lists what an operational-risk management framework must contain; the draft RTS specifies how each element is expected to operate. Three components carry the weight — and the boundary with DORA matters: ICT risk management sits in the DORA framework, not here, but the revised SREP Guidelines score both inside the same operational-risk assessment.
Defined roles for the management body and senior management, and an independent operational-risk management function. “The op-risk framework is owned by the capital-calculation team” stops being an acceptable answer.
Operational-risk data collection and classification, taxonomy, business-indicator components, review and reporting mechanisms, validation and audit requirements — specified as obligations, not expectations.
Institutions with a business indicator below €750m get reduced review frequency, less detailed reporting, reduced data granularity, applicable loss thresholds and a simplified taxonomy. Above the line, the full framework applies.
| Component | What the draft RTS does | Who feels it first |
|---|---|---|
| Governance | Roles of the management body and senior management defined; independent operational-risk management function required | Banks where op risk reports into finance or the capital-calc team |
| Risk management process | Collection and classification of operational-risk data, review and reporting mechanisms specified | Banks with fragmented loss-event capture across business lines |
| Assessment systems | Taxonomy, business-indicator components, validation and audit requirements set out | Banks whose op-risk taxonomy predates CRR3 and DORA |
| ICT boundary | ICT risk management remains under DORA — but the revised SREP Guidelines (EBA/GL/2026/06) score ICT inside operational risk from 2027 | Banks running DORA compliance and op-risk management as separate programmes |
| Proportionality | Simplified requirements below a €750m business indicator: review frequency, reporting detail, data granularity, loss thresholds, taxonomy | Mid-size institutions just above the threshold — full framework, mid-size resources |
The consultation window is long by EBA standards — 26 August to 31 December 2026 — and it is the only stage at which the proportionality boundary and taxonomy definitions are genuinely negotiable. After close, the EBA finalises the RTS and submits them to the European Commission for adoption under Article 10 of Regulation (EU) No 1093/2010.
Source: EBA Consultation Paper EBA/CP/2026/18 and consultation page, 26 August 2026 — dates as stated by the EBA.
Under CRR3 the operational-risk own-funds requirement is arithmetic on the business indicator — there is no model to defend and no capital to negotiate. That moved the entire supervisory conversation into the management framework: how losses are captured, classified, reported, validated and governed. From 2027 the revised SREP Guidelines (EBA/GL/2026/06) score ICT risk inside the operational-risk element, on DORA-era expectations — so the framework this RTS specifies is not a compliance artefact off to the side. It is an input to the operational-risk score that flows into P2R formation.
The SMA ended the argument about op-risk capital; EBA/CP/2026/18 starts the argument about op-risk management — and that one is scored in SREP.
The business indicator sets the requirement, but the JST’s operational-risk score is built on the framework: governance, data quality, reporting, validation. A weak framework no longer costs you a model approval — it costs you a SREP score.
Collection and classification standards, applicable thresholds, validation and audit requirements — the draft treats loss data the way credit-risk data has been treated since BCBS 239. A loss-event database maintained for capital purposes only will not pass an inspection sampled against this text.
ICT risk management is excluded here because DORA owns it — but SREP scores both in one assessment. Two rulebooks, one score: the op-risk framework and the DORA artefacts need to tell the same story, in the same taxonomy.
Where the €750m proportionality line sits, how loss thresholds are calibrated, how prescriptive the taxonomy becomes — these are open questions until 31 December 2026 and settled ones after. Banks that respond shape the text; banks that do not inherit it.
The proportionality boundary is a cliff, not a slope: cross it and the full framework applies — review frequency, reporting depth, data granularity, taxonomy. Institutions whose business indicator sits just above the line carry G-SIB-shaped obligations on mid-size infrastructure, and should say so in their consultation response while the boundary is still open.
An independent operational-risk management function with defined governance roles is a structural requirement, not a reporting-line nicety. Where op risk sits inside finance because the SMA made it a calculation, the draft RTS makes the organisational chart itself a finding.
Classification standards, thresholds, validation and audit requirements assume one taxonomy applied consistently across business lines. Banks still mapping losses to a pre-CRR3 event taxonomy — or holding ICT incidents in a separate DORA silo with different definitions — will fail the consistency test before the framework test.
The requirements that survive to the final RTS will look substantially like these. Walking governance, data, reporting, validation and audit against the draft now prices the remediation while there is still budget calendar left in 2027 — and produces the evidence for move 4.
One operational-risk taxonomy, applied in the loss database, the ICAAP, the DORA register and the SREP narrative. The revised SREP Guidelines score ICT inside operational risk from 2027 — two vocabularies for one risk is now a supervisory finding waiting to be written.
Thresholds, completeness checks, validation cadence and the audit trail need an accountable owner before an inspection team asks who that is. The draft’s validation and audit requirements are precisely the kind of provision OSI workplans sample first.
Proportionality calibration, threshold levels and taxonomy prescriptiveness are the parameters the EBA can still move. A two-page response grounded in your gap assessment is worth more than a trade-association annex — and signals process fluency to the same authority that will supervise the result.
Dates, reference numbers and quoted language verified against the EBA consultation paper at publication (1 September 2026). Corrections: research@ezelman.com.
Partner-led, senior-only, no audit conflict. If the question in this piece is live at your institution, the first conversation is with a partner — not a BD team.
Talk to a partner →