Home › Academy › Library › Draft Regulatory Technical Standards on…
Synthesis note · Standard

Draft Regulatory Technical Standards on operational risk losses mandates

European Banking Authority (EBA) · 2025 · Standard · 82 pages · Intermediate

This document presents regulatory technical standards on managing operational risk losses. It proposes a risk taxonomy compliant with international standards and a methodology for classifying loss events. Additionally, it specifies the conditions under which the calculation of annual losses may be deemed 'unduly burdensome'.

General Information

The document is a final report published in August 2025 by the European Banking Authority (EBA). It presents draft regulatory technical standards (RTS) concerning the management of losses related to operational risk in European financial institutions. These standards rely on Regulation (EU) 575/2013 (CRR), notably articles 316(3), 317(9) and 321(2). The scope covers the definition of an operational risk taxonomy compliant with international standards, the methodology for classifying loss events, the specification of conditions under which the annual operational loss calculation may be considered “unduly burdensome,” and the modalities for adjusting loss data sets during mergers and acquisitions. The framework applies to financial institutions whose Business Indicator (BI) exceeds 750 million euros, with a ten-year loss reference period. The document comprises 82 pages, about half of which were provided for this synthesis.

Executive Summary

The report addresses the implementation of CRR 3 requirements related to operational risk, which replaces previous approaches with a calculation based on the Business Indicator Component (BIC). Institutions with a BI above 750 million euros must build an operational loss data set covering losses above a threshold (20,000 or 100,000 euros) over a ten-year window. Three main mandates are addressed: 1) establishing an operational risk taxonomy compliant with international standards, with classification into seven event types (level 1) and 26 detailed categories (level 2), as well as complementary attributes (flags) to enrich information, notably on ESG risks and greenwashing; 2) defining conditions where the annual operational loss calculation is “unduly burdensome,” notably in case of merger-acquisition leading to a BI between 750 million and 1 billion euros, or during a temporary BI increase, with exemptions up to three years; 3) modalities for adjusting data sets when including losses of merged or acquired entities, with currency conversion according to annual rates and temporary calculation methods when data are not immediately integrable. These RTS underwent a public consultation (June-September 2024) and a workshop with sector stakeholders, leading to amendments. The report specifies that these standards aim to harmonize operational loss data collection and classification, facilitate supervision, and integrate emerging risks such as ESG and greenwashing. The European Commission must now validate these standards before their official publication.

Context and Objectives

The document responds to the requirements of the European banking package which transposes the Basel III framework into the EU, modifying capital calculation for operational risk. CRR 3 imposes a single framework based on the BIC, replacing previous approaches. Institutions with a BI ≥ 750 million euros must record and calculate their annual operational losses, building a harmonized data set. The EBA is mandated to establish a common operational risk taxonomy, define the notion of “unduly burdensome” for annual loss calculation, and specify adjustments to data sets during mergers or acquisitions. These measures aim to ensure data consistency, comparability, and quality, while considering operational constraints of institutions, notably in case of rapid growth via mergers-acquisitions or temporary BI fluctuations. The document specifies that the RTS cover only losses above regulatory thresholds and apply over a ten-year period. Public consultation and stakeholder exchanges helped refine the proposals.

Summary of Key Points by Theme

- Operational risk taxonomy: The taxonomy is based on seven event types at level 1, aligned with the BCBS taxonomy, and 26 detailed categories at level 2, designed to be mutually exclusive and collectively exhaustive (MECE). This structure facilitates precise loss classification. Level 2 categories were adjusted based on historical data and industry practices to ensure relevance and exhaustiveness (p. 6-9).

- Complementary attributes: Attributes (flags) are added to enrich loss descriptions, notably for legal risks (conduct and others), model risks, ICT risks (cyber and non-cyber), third-party risks, ESG risks (environmental, social, governance) and greenwashing, as well as business continuity and business lines (retail, trading, commercial, others). These attributes are neither exclusive nor exhaustive, allowing analytical flexibility (p. 8-15).

- ESG risks and greenwashing: Two specific attributes are introduced to identify losses related to ESG factors and greenwashing. ESG risk covers losses related to environmental, social, and governance impacts on counterparties or invested assets, while greenwashing concerns losses related to misleading sustainability communication practices, often linked to sanctions or litigation. This distinction addresses the need to monitor these emerging risks within the operational framework (p. 9-12).

- Alignment with DORA: The taxonomy integrates DORA regulation requirements on digital operational resilience, notably classification of ICT incidents and cyberattacks, with specific attributes to ensure consistency of reporting between incidents and losses (p. 12-14).

- Classification methodology: The document clarifies loss event classification, including quickly recovered losses, multiple events, and losses related to legal proceedings, to ensure full harmonization and avoid calculation errors (p. 16).

- “Unduly burdensome” condition: The RTS specifies that the annual loss calculation may be considered unduly burdensome for institutions with BI between 750 million and 1 billion euros in certain cases: recent merger-acquisition (up to 3 years exemption), temporary BI threshold crossing (up to 4 consecutive reporting dates or 8 non-consecutive over 20), or for bridge institutions created in resolution. This approach aims to avoid disproportionate burdens related to data integration (p. 16-18).

- Data set adjustments in case of mergers-acquisitions: Losses of merged or acquired entities must be integrated in the currency of the acquiring institution, with annual conversion according to financial rates. If data are not immediately available or do not comply with the taxonomy, a temporary calculation method using a coverage ratio based on BI is provided, with an obligation for full integration within one year. In absence of precise classification, loss allocation must follow that of the acquiring institution (p. 18-19, 36-37).

- Detailed taxonomy structure: Each event type (level 1) is broken down into categories (level 2) with precise definitions, for example: internal fraud (corruption, fraud against the institution, fraud against third parties), external fraud (by clients, non-clients, data theft, physical theft), employment practices, clients/products, physical asset damage, business disruption, process management. This granularity aims to ensure precise and homogeneous classification (p. 23-30).

- Attributes associated with categories: The document lists correspondences between attributes and categories, for example the “legal risk – conduct” attribute applies to certain internal and client categories, while “model risk” relates to model errors and their implementation. ICT risks are distinguished between cyber and non-cyber, with particular attention to third-party providers and business continuity (p. 31-39).

- Application and timeline: Institutions must apply level 1 classification over ten years before the effective date, and may voluntarily apply levels 2 and attributes at least one year before the effective date. Exemptions related to excessive burdens are temporary and conditional (p. 34-36).

Main Results and Lessons Learned

- Established facts: The CRR 3 framework imposes a single capital calculation for operational risk based on the BIC, with obligation to build a loss data set for institutions above 750 million euros BI. The proposed taxonomy includes 7 event types and 26 categories, with complementary attributes, meeting international standards and supervisory needs. Exemptions for excessive burdens are clearly defined and time-limited. Rules for data set adjustments in case of merger-acquisition are specified, including currency conversion and temporary calculation methods. (p. 3-4, 6-19, 23-39)

- Assumptions: The taxonomy is built in continuity with CRR 2 and industry practices, assuming institutions have sufficient historical data to apply classifications. Use of attributes assumes flexibility in capturing emerging risks such as ESG and greenwashing. Exemptions are based on BI thresholds and time periods deemed reasonable for data integration. (p. 6-7, 9-12, 16-18)

- Interpretations: The EBA considers the proposed taxonomy will facilitate comparability and consistency of operational loss data, while integrating new risks related to ESG factors and digital risks. Exemptions are interpreted as a means to avoid disproportionate constraints, notably during mergers-acquisitions. Alignment with DORA highlights the growing importance of ICT risks in operational risk. (p. 9-15, 12-14, 16-18)

- Uncertainties: Effective implementation will depend on institutions’ capacity to adapt IT systems and collect quality data. Impact of new ESG and greenwashing attributes on risk management remains to be observed. Transition period and exemptions may pose challenges for harmonized supervision. Public consultation allowed proposal adjustments, but further feedback during implementation is possible. (p. 5, 40)

Conclusions and Author’s Recommendations

The EBA recommends adoption of the three draft regulatory technical standards to ensure European harmonization in classification and calculation of operational losses. The proposed taxonomy, with its levels 1 and 2 and attributes, must be implemented by all concerned institutions, with retroactive application over ten years for level 1 and voluntary application for levels 2 and attributes one year before the effective date. Exemptions for excessive burdens must be granted according to defined criteria, notably in case of merger-acquisition or temporary BI threshold exceedance, with durations limited to two or three years. Institutions must integrate losses of merged or acquired entities respecting currency conversion and the common taxonomy, using temporary calculation methods if necessary, with obligation for full integration within one year. These measures aim to strengthen data quality, supervision, and operational risk management, while considering operational constraints of institutions. The report specifies that the RTS will be submitted to the European Commission for approval, then to the European Parliament and Council for review before official publication.

Key takeaways

References

Year
2025
Type
Standard
Level
Intermediate
Licence
Attribution required
Original document
https://www.eba.europa.eu/sites/default/files/2025-08/1f9809f8-13bf-4…
Read the original document ← Back to the library

Synthesis note written from the full document by DataSAI Academy. This note comes from the scientific library of the DataSAI Academy, open to all.