← Back to Regulatory Radar

The Operational-Risk RTS: What the SMA Formula Left for Supervisors to Inspect

On 26 August 2026 the EBA opened consultation EBA/CP/2026/18: draft RTS under Article 323(2) CRR specifying the operational-risk management framework obligations of Article 323(1), points (a) to (h). CRR3 collapsed op-risk capital into a single business-indicator formula — no models, no argument. What the formula does not do is tell a supervisor whether the institution manages operational risk. This RTS is where that assessment gets its inspectable requirements: governance roles for the management body and senior management, an independent op-risk function, loss-data collection and classification, review, reporting, validation and audit. The consultation runs to 31 December 2026.

26 Aug 2026
Consultation paper published — EBA/CP/2026/18
31 Dec 2026
Consultation closes — final RTS to the Commission follows
€750m
Business-indicator threshold below which simplified requirements apply

Eight legal obligations become one inspectable framework

Article 323(1) CRR lists what an operational-risk management framework must contain; the draft RTS specifies how each element is expected to operate. Three components carry the weight — and the boundary with DORA matters: ICT risk management sits in the DORA framework, not here, but the revised SREP Guidelines score both inside the same operational-risk assessment.

1

Governance made explicit

Defined roles for the management body and senior management, and an independent operational-risk management function. “The op-risk framework is owned by the capital-calculation team” stops being an acceptable answer.

2

Process and assessment systems specified

Operational-risk data collection and classification, taxonomy, business-indicator components, review and reporting mechanisms, validation and audit requirements — specified as obligations, not expectations.

3

Proportionality drawn at €750m

Institutions with a business indicator below €750m get reduced review frequency, less detailed reporting, reduced data granularity, applicable loss thresholds and a simplified taxonomy. Above the line, the full framework applies.

ComponentWhat the draft RTS doesWho feels it first
GovernanceRoles of the management body and senior management defined; independent operational-risk management function requiredBanks where op risk reports into finance or the capital-calc team
Risk management processCollection and classification of operational-risk data, review and reporting mechanisms specifiedBanks with fragmented loss-event capture across business lines
Assessment systemsTaxonomy, business-indicator components, validation and audit requirements set outBanks whose op-risk taxonomy predates CRR3 and DORA
ICT boundaryICT risk management remains under DORA — but the revised SREP Guidelines (EBA/GL/2026/06) score ICT inside operational risk from 2027Banks running DORA compliance and op-risk management as separate programmes
ProportionalitySimplified requirements below a €750m business indicator: review frequency, reporting detail, data granularity, loss thresholds, taxonomyMid-size institutions just above the threshold — full framework, mid-size resources

Four months of consultation, then the Commission’s pen

The consultation window is long by EBA standards — 26 August to 31 December 2026 — and it is the only stage at which the proportionality boundary and taxonomy definitions are genuinely negotiable. After close, the EBA finalises the RTS and submits them to the European Commission for adoption under Article 10 of Regulation (EU) No 1093/2010.

26 Aug 2026 Consultation opens EBA/CP/2026/18 31 Dec 2026 Consultation closes Responses published unless confidential Final RTS → Commission 2027 Finalisation and adoption Art. 10, Regulation (EU) No 1093/2010

Source: EBA Consultation Paper EBA/CP/2026/18 and consultation page, 26 August 2026 — dates as stated by the EBA.

The SMA ended the capital argument. This starts the management one.

Under CRR3 the operational-risk own-funds requirement is arithmetic on the business indicator — there is no model to defend and no capital to negotiate. That moved the entire supervisory conversation into the management framework: how losses are captured, classified, reported, validated and governed. From 2027 the revised SREP Guidelines (EBA/GL/2026/06) score ICT risk inside the operational-risk element, on DORA-era expectations — so the framework this RTS specifies is not a compliance artefact off to the side. It is an input to the operational-risk score that flows into P2R formation.

The forwardable line

The SMA ended the argument about op-risk capital; EBA/CP/2026/18 starts the argument about op-risk management — and that one is scored in SREP.

Capital is formulaic; supervision is not

The business indicator sets the requirement, but the JST’s operational-risk score is built on the framework: governance, data quality, reporting, validation. A weak framework no longer costs you a model approval — it costs you a SREP score.

Loss data becomes a governed asset

Collection and classification standards, applicable thresholds, validation and audit requirements — the draft treats loss data the way credit-risk data has been treated since BCBS 239. A loss-event database maintained for capital purposes only will not pass an inspection sampled against this text.

The DORA boundary cuts both ways

ICT risk management is excluded here because DORA owns it — but SREP scores both in one assessment. Two rulebooks, one score: the op-risk framework and the DORA artefacts need to tell the same story, in the same taxonomy.

The consultation is the negotiation window

Where the €750m proportionality line sits, how loss thresholds are calibrated, how prescriptive the taxonomy becomes — these are open questions until 31 December 2026 and settled ones after. Banks that respond shape the text; banks that do not inherit it.

Who it bites

A

Mid-size banks just above €750m

The proportionality boundary is a cliff, not a slope: cross it and the full framework applies — review frequency, reporting depth, data granularity, taxonomy. Institutions whose business indicator sits just above the line carry G-SIB-shaped obligations on mid-size infrastructure, and should say so in their consultation response while the boundary is still open.

B

Banks whose op-risk function is a capital-calc team

An independent operational-risk management function with defined governance roles is a structural requirement, not a reporting-line nicety. Where op risk sits inside finance because the SMA made it a calculation, the draft RTS makes the organisational chart itself a finding.

C

Banks with fragmented loss data and a legacy taxonomy

Classification standards, thresholds, validation and audit requirements assume one taxonomy applied consistently across business lines. Banks still mapping losses to a pre-CRR3 event taxonomy — or holding ICT incidents in a separate DORA silo with different definitions — will fail the consistency test before the framework test.

Four moves for op-risk owners before 31 December

1

Gap-assess against the draft, not the final

The requirements that survive to the final RTS will look substantially like these. Walking governance, data, reporting, validation and audit against the draft now prices the remediation while there is still budget calendar left in 2027 — and produces the evidence for move 4.

2

Unify the taxonomy across CRR3, SREP and DORA

One operational-risk taxonomy, applied in the loss database, the ICAAP, the DORA register and the SREP narrative. The revised SREP Guidelines score ICT inside operational risk from 2027 — two vocabularies for one risk is now a supervisory finding waiting to be written.

3

Put loss-data governance on a named owner

Thresholds, completeness checks, validation cadence and the audit trail need an accountable owner before an inspection team asks who that is. The draft’s validation and audit requirements are precisely the kind of provision OSI workplans sample first.

4

Respond to the consultation — by 31 December 2026

Proportionality calibration, threshold levels and taxonomy prescriptiveness are the parameters the EBA can still move. A two-page response grounded in your gap assessment is worth more than a trade-association annex — and signals process fluency to the same authority that will supervise the result.

Is your op-risk framework ready to be sampled against this text?

We run framework gap assessments, taxonomy unification and consultation responses — against the draft the final RTS will grow from, before the JST reads it first. Senior-only, partner-led.

See the regulatory programmes practice →
Sources & references

Primary documents cited in this analysis

  1. [1]
    EBAEBA — Consultation Paper on draft Regulatory Technical Standards on the operational risk management framework under Article 323(2) CRR (EBA/CP/2026/18), 26 August 2026. Consultation closes 31 December 2026 → source
  2. [2]
    EBAEBA press release — “The EBA consults on draft technical standards on institutions’ operational risk management”, 26 August 2026 → source
  3. [3]
    EBAEBA — Final Report, revised SREP Guidelines (EBA/GL/2026/06), 26 June 2026 — the framework under which ICT risk is scored inside operational risk from the 2027 cycle → source

Dates, reference numbers and quoted language verified against the EBA consultation paper at publication (1 September 2026). Corrections: research@ezelman.com.

From analysis to mandate

This analysis underpins our regulatory-programme mandates.

Partner-led, senior-only, no audit conflict. If the question in this piece is live at your institution, the first conversation is with a partner — not a BD team.

Talk to a partner →
Follow Ezelman on LinkedIn — Regulatory insights read by 2,000+ risk professionals across Europe & the GCC Follow →