In brief
- The money a bank holds for operational risk is calculated from a fixed formula, and this regulation says what goes into it. The capital required for operational risk is 12% of the business indicator as long as that stays below one billion euro, 15% for the part between one and thirty billion and 18% above. At a business indicator of EUR 750 million, the capital tied up for operational risk alone comes to EUR 90 million.
- Losses from fraud, errors and system failures are counted from 23 September 2026 on a common grid: 7 event types, 26 finer categories and 15 additional labels. Among the labels are „Model risk”, „ICT risk related to cyber security”, „Third-party risk” and „Greenwashing risk”. The obligation to keep a loss record falls only on banks with a business indicator of at least EUR 750 million.
- For the customer of a bank in Romania nothing changes directly: no interest rate, no fee, no contract. The stake lies elsewhere. The figures banks report to the National Bank of Romania and publish become comparable with one another, and the way a bank counts its own losses comes under a written rule instead of being left to it.
Published: Official Journal of the European Union, L series, 2026/1167 of 3 September 2026
In force from: 23 September 2026, the twentieth day after publication, as Article 40 of the regulation provides
From 23 September 2026, credit institutions in the European Union, that is banks, have a written rule for two things each of them used to do in its own way: how much capital it ties up for operational risk and how it counts the losses caused by fraud, by processing errors, by system failures or by court cases lost. This is not about the money banks are required to keep with the National Bank of Romania as minimum reserve requirements, which is liquidity deposited with the central bank. What is at stake here is own funds, that is the bank’s own capital, set aside as a buffer and used for nothing else.
The act is Commission Delegated Regulation (EU) 2026/1167, adopted by the European Commission in Brussels on 28 May 2026 and published on 3 September 2026, 98 days after adoption. Being a regulation, it applies directly in all Member States, with no Romanian act needed to bring the law into line.
The text is a regulatory technical standard, and the formula is worth unpacking, because it recurs often in banking legislation. The European Banking Authority, the European agency that writes the technical rules for banks, prepares the draft; the Commission adopts it as a delegated regulation; the substantive rules stay in the basic act, that is in Regulation (EU) No 575/2013 on prudential requirements for credit institutions. A technical standard fills in the detail of obligations that already exist in the basic act. The preamble invokes five bases of delegation, all of them in the basic regulation: the third subparagraph of Article 314(9), the third subparagraph of Article 315(3), the third subparagraph of Article 316(3), the third subparagraph of Article 317(9) and the third subparagraph of Article 321(2). The basic regulation had required the European Banking Authority to submit the drafts by 10 January 2026; the Commission adopted them on 28 May 2026, three days before two years had passed since Regulation (EU) 2024/1623, the act that rewrote the operational risk chapter.
Operational risk has a legal definition, in Article 4(1)(52) of the basic regulation: the risk of loss resulting either from inadequate or failed internal processes, people or systems, or from external events, including legal risk, model risk and ICT risk, but excluding strategic risk and reputational risk. In short, everything that can go wrong in a bank and has to do neither with unpaid loans nor with market movements.
The capital requirement is calculated from a single figure, called the business indicator. It is built from the profit and loss account and from the balance sheet, with no link to past losses: it adds up, over the average of the last three financial years, the interest, leases and dividend component, the services component, that is fees and commissions, and the financial component, that is the trading result. The thinking behind it is simple: the more business a bank does, the more chances it has to get something wrong. Out of the business indicator comes the business indicator component, and that component is, under Article 312 of the basic regulation, the own funds requirement for operational risk itself.
Most of the 28 pages of the new act deal with exactly that: what goes into the business indicator and what does not. Part I has 22 articles and goes down to the level of the accounting sub-item. Interest income is calculated as the sum of eleven sub-items, from interest on assets held for trading to gains on the modification of lease contracts. Fee and commission income has eighteen items, from custody to fiduciary transactions. Part II, with 17 articles, builds the grid for classifying losses. Part III has a single article, the one on entry into force. The annex, a single page, links three of the risk labels to the categories the events fall into.
The second act adopted on the same day, Commission Implementing Regulation (EU) 2026/1166, published also on 3 September 2026 and in force also from 23 September 2026, does the translation into reporting cells: it maps the items of the business indicator onto the FINREP entries in Implementing Regulation (EU) 2024/3117. The two are read together. Article 1 of the implementing regulation refers expressly to the lists „as listed in Delegated Regulation (EU) 2026/1167”, so without the present act the mapping table has nothing to map.
What it changes in practice
The first effect is visible in the capital figure. The formula in Article 313 of the basic regulation has three tiers, calculated on the business indicator expressed in billions of euro: 12% of the indicator, as long as it does not exceed one billion; 0.12 billion plus 15% of whatever goes above one billion, up to thirty billion; 4.47 billion plus 18% of whatever goes above thirty billion. The thresholds fit together: 0.12 plus 0.15 multiplied by 29 gives exactly 4.47, the constant in the third tier.
Translated into sums, at a business indicator of EUR 750 million the requirement is EUR 90 million of own funds, for operational risk alone. At one billion, the requirement rises to EUR 120 million. At five billion, to EUR 720 million. Since the basic regulation requires, in Article 92(6)(b), these requirements to be multiplied by 12.5 in order to obtain the risk exposure amount, the EUR 90 million translate into a risk exposure amount of EUR 1.125 billion, which goes into the denominator of every capital adequacy ratio the bank publishes.
The second effect concerns the loss record and does not touch every bank. The obligation to build a loss data set and to calculate the annual operational risk loss falls, under Article 316(1) of the basic regulation, only on institutions with a business indicator of at least EUR 750 million. Below that threshold, a bank does the capital calculation only. The threshold is measured on the highest value reported over the last eight reporting reference dates, so a passing breach keeps the bank above the line for two years.
For the banks that fall under this obligation, the present act sets out the grid. Each loss event falls into a single level 1 event type, out of the seven in Article 24: internal fraud; external fraud; employment practices and workplace safety; clients, products and business practices; damage to physical assets; business disruption and system failures; execution, delivery and process management. Under each type sit level 2 categories, 26 in all, distributed as follows: three for internal fraud, four for external fraud, two for employment practices, eight for clients and products, two for damage to physical assets, two for business disruption and five for execution and processes. An event goes into a single category; where it would fit into several, the most relevant one is chosen.
On top of the classification come the labels, which the act calls attributes. There are 15 of them, and one event may receive several at once. Eleven describe the nature of the risk: the two kinds of legal risk, model risk, ICT risk related and not related to cyber security, credit risk not already captured in the risk weighting of loans, market risk, third-party risk, environmental, social and governance risks, greenwashing risk and business continuity. The other four show the business line hit: retail, trading and sales, commercial banking and the rest. Article 32(2) requires each event to receive at least one of those four, so every loss gets at least one label.
A few practical rules genuinely change what gets recorded. Losses recovered in full within five working days do not enter the data set at all; where the recovery is partial, only the unrecovered part goes in. Litigation goes in whole, and Article 23(4) specifies that out-of-court settlements count in the same way as cases won or lost in court. An IT service provider that goes down and causes losses receives, according to the reasoning of the act, two labels at once, „ICT risk” and „third-party risk”.
The third effect is procedural and is borne directly by the relationship between the bank and the National Bank of Romania, as competent authority. A bank that wants to move to the alternative way of calculating the financial component, called in the act the prudential boundary approach, notifies the authority at least 90 days in advance and sends eleven categories of documents, from the approval of the management body to an independent review report. The 90-day period starts running only once the file is complete. Returning to the accounting approach again requires 90 days’ notice. A request to take a divested business out of the indicator is also lodged 90 days in advance, and the authority replies in writing within 90 days; where the divested business brings in less than 5% of the bank’s net operating income, silence from the authority for 90 days counts as approval.
The fourth effect is visible in what reaches the public. Article 446 of the basic regulation requires every bank to disclose the capital requirement for operational risk, the business indicator and the values of each component for the three years taken into account. Banks above EUR 750 million also disclose the annual operational risk losses for each of the last ten financial years, plus the number of exceptional events taken out of the calculation and the reasons for taking them out. The grid in the present act is what makes those figures comparable from one bank to another.
What has changed compared with the previous situation
The substantive change came earlier, through Regulation (EU) 2024/1623 of 31 May 2024, which replaced the old methods of calculating operational risk capital with a single one. The mark of that replacement is still visible in the basic regulation: Article 314(4) still speaks of „the alternative standardised approach, as provided for in the version of this Regulation applicable on 8 July 2024”, which an EU parent institution may go on using until 31 December 2027 at the latest. The present act leaves the method untouched and makes it workable: without its lists, a bank could not know with precision which income goes into which component.
In the classification of losses the granularity changes while the structure stays the same. The reasoning of the regulation says plainly that the seven level 1 event types „are unchanged compared with the existing framework”, because they come from the international standards of the Basel Committee on Banking Supervision. What is new sits on the second floor: the 26 level 2 categories and the 15 attributes did not exist as a binding rule. Until now, a bank could keep its internal records however it liked, as long as it could put the data into the seven big boxes at the supervisor’s request.
The second change, less visible, concerns what can no longer be taken out of the calculation. Article 16 of the new act lists items banks may not exclude from the business indicator, even though they would seem excluded on the letter of the basic regulation: income and expenses from the distribution of insurance or reinsurance products, fees paid for the outsourcing of financial services, rental expenses and administrative expenses arising from operational risk events. The distinction is a fine one and it costs money: the expense of outsourcing a financial service goes into the indicator, the expense of outsourcing a non-financial service, whether IT, logistics or human resources, stays outside it.
The third change concerns mergers and acquisitions. Until now, the basic regulation said only that the items of the acquired entity are included in the indicator from the moment of the transaction, covering the last three financial years. The new act adds what happens where the historical data are missing or are not accurate: the bank uses its own indicator multiplied by a merger and acquisition factor, which is the ratio between the bank’s net operating income added to that of the acquired entity and the bank’s net operating income on its own. Where even that is not possible, financial projections are used. For divestments, Articles 19 and 20 build an approval procedure that the basic regulation had announced twice.
The fourth change is the retroactive timetable, and it says the most about how quickly the grid becomes useful. Article 33 requires classification into the seven level 1 types from 1 January 2016 and allows, without requiring, classification into the 26 level 2 categories and the assignment of the labels from 1 January 2025. Since losses are tracked over a window of ten financial years, this means that, on first application, nine years out of ten stay at the old granularity, with seven boxes, while a single year carries the new grid.
Advantages and disadvantages
What it improves
- The figures become comparable. The same loss from a processing error ends up, in two different banks, in the same category 7.1 and receives the same labels, which until now was not guaranteed.
- The grid is built to leave nothing out: the reasoning requires the level 1 types and the level 2 categories to be mutually exclusive and to cover everything, with no residual category of the „other” kind.
- The labels bring into bank records risks that until now had no heading of their own: model risk, the risk associated with third-party suppliers, ICT risk split into cyber attacks and the rest, environmental, social and governance risks, and greenwashing.
- The regulation applies directly, so a Romanian bank and a German one get the same rule on the same day, with no differences in transposition.
- Small banks are spared: below a business indicator of EUR 750 million there is no obligation to build the loss data set, and between EUR 750 million and one billion the act provides for three situations in which the calculation is treated as an undue burden.
- All the provisions sit in a single regulation, chosen deliberately for that, instead of being split across five acts matching the five bases of delegation.
What remains a problem
- The new grid covers a single year out of the ten required by the loss tracking window. Full comparability of the ten-year series will be reached only around the middle of the 2030s.
- The three formulas in the act, the merger and acquisition factor and the two in Article 39, are set as images. In the text layer of the official PDF edition a note appears in their place saying that the item is an illustration, so they cannot be searched, copied or read automatically.
- Where the deadlines run in the bank’s favour the act is precise; where they ought to run in its favour, the act is silent. Article 12(5) requires the authority to verify the conditions for the prudential boundary approach, but gives it no deadline.
- The label „Legal risks, Misconduct” is applied automatically to all 11 categories of internal fraud and of clients and products, even where the event never reached any judicial proceedings, which is precisely the condition in the legal definition of legal risk.
- Exceptional losses that the supervisor approves to be taken out of the calculation of the annual loss stay, through Article 6(2)(c), inside the business indicator, that is inside the very figure that determines the capital.
- The name „business indicator” says nothing to a reader outside the banking system, and the act uses it hundreds of times without explaining it, because the explanation sits in another regulation.
Practical advice
- If you work in a bank and have one single thing to check, check where the expenses caused by operational risk events end up. Article 2 takes them out of interest expenses and sends them to Article 6(1)(d)(i), that is to other operating expenses. If they stay where they were, the business indicator comes out wrong.
- Do not confuse financial outsourcing with non-financial outsourcing. Fees paid for the outsourcing of a financial service go into the indicator, those paid for IT, logistics or human resources services do not. Article 8 and Article 16(2)(a) draw the distinction.
- Check the threshold of EUR 750 million against the highest value reported over the last eight reporting reference dates, not against the latest one. A breach in a single quarter keeps the institution above the threshold for two years.
- If the institution is close to the threshold and the breach is a passing one, read Article 35 before starting a data collection project. The exemption applies for at most four consecutive reporting reference dates or at most eight out of the last twenty.
- Plan the notifications 90 days ahead and put the complete file together from the start. The period does not begin to run until the documentation is complete, so a file sent half finished causes a delay twice over.
- In an acquisition, raise the question of loss data at the analysis stage, not after signing. Article 37 requires the losses of the acquired entity to be reclassified into your own taxonomy, and Article 38 requires them to be converted into your currency at the rate at the end of each year, for each of the ten years.
- Where a loss has been recovered, look at the calendar before recording it. Five working days is the line: full recovery inside them takes the event out of the data set, one day later leaves it in.
- If you follow a bank from the outside, as an investor, a journalist or a customer, look in the annual report for the disclosures required by Article 446: the capital requirement for operational risk, the business indicator broken down by component and, at large banks, the losses of the last ten years. From financial year 2026 they will be built on the same grid at every bank.
Frequently asked questions
Does anything change for me, as an account holder or a borrower?
What does „operational risk” mean, to someone outside a bank?
What is a „loss event”?
Why does a threshold of EUR 750 million matter?
How many loss categories are there, in fact?
What is the link with the other regulation published on the same day?
Does Romania have to do anything for the act to apply?
Does anything change for non-bank financial institutions or for payment firms?
Errors and inconsistencies in the published text
- Article 14(1) and Article 15(1), deadlines that rule each other out. Article 14(1) provides that institutions „shall revert to the accounting approach where any of the conditions laid down in Article 9(b) is no longer met”. Article 15(1) requires them to notify the reversion „at least 90 days before reverting to it”, and Article 15(2)(c) requires the notification to contain „information on the conditions referred to in Article 9(b) that are no longer met”, so it is drawn up after the condition has fallen away. No bank can give 90 days’ notice of a fact it learns of on the day it happens. Either it reverts at once, as Article 14 requires, and breaches the deadline in Article 15, or it keeps to the deadline and spends another 90 days calculating the financial component by a method whose conditions of use, listed in Article 9(b), are no longer met. On entry into the method, where the event is planned, the 90 days’ notice in Article 13(1) works without any difficulty; on exit, it does not.
- Article 36, compared with Articles 34 and 35 and with the basis for the exemption. Articles 34 and 35 both tie the exemption to a business indicator that is „equal to or greater than EUR 750 million but does not exceed EUR 1 billion”. Article 36 declares the loss calculation unduly burdensome „for bridge institutions as defined in Article 2(59) of Directive 2014/59/EU”, with no size condition at all. The only basis for the exemption, the second subparagraph of Article 316(1) of Regulation (EU) No 575/2013, allows competent authorities to grant it only to institutions „with a business indicator that does not exceed EUR 1 billion”. For a bridge institution above that threshold, the new text says the exemption applies while the basic regulation says it cannot be granted, even though the reasoning of the act announces an exemption without reservation for all bridge institutions.
Editorial analysis
The most instructive observation about this regulation comes out of laying three articles over one another that do not sit side by side. All the classification work required by Part II, the seven types, the 26 categories and the 15 labels, has no bearing whatsoever on the capital figure. Article 312 of the basic regulation says that the own funds requirement for operational risk is the business indicator component, and no more, and Article 446(1)(b) repeats the same thing in disclosure terms. The Union chose not to use the internal loss multiplier from the international standard, so the loss record serves supervision and transparency, not the calculation. Operational risk losses do nonetheless reach the capital, but through another door: Article 314(5) of the basic regulation puts them into „other operating expenses”, and Article 6 of the present act widens that heading to all the financial impacts of operational risk events, wherever they may be booked. The figure can be worked out. An operational loss of EUR 300 million raises the three-year average of that heading by EUR 100 million a year; if the expense heading is the one that counts in the formula for the services component, the business indicator grows by the same amount, and in the 12% tier the capital requirement grows by EUR 12 million a year for three years, that is EUR 36 million in total, and by EUR 150 million of risk exposure amount in each of those three years. The bank pays the loss twice: once in cash and a second time in capital.
The second observation is the natural continuation of the first and shows where the safety valve was placed. The basic act allows, in Article 320(1), exceptional events to be taken out of the calculation of the annual loss, with the supervisor’s approval. Article 6(2)(c) of the present act, however, says expressly that those same exceptional losses are included in other operating expenses. In other words, the exception exists exactly where the figure does not determine the capital and is missing exactly where it does. A bank can obtain from the National Bank of Romania approval to take out of its loss statistics an event it can show will not happen again, and that event will nonetheless go on inflating its business indicator and its capital requirement for three years.
The third observation concerns a label that loses its meaning along the way. Article 32 defines the attribute „Legal risks, Misconduct” by reference to Article 4(1)(52a)(d) of the basic regulation, and there legal risk is defined as the risk of loss „resulting from events that lead to judicial proceedings”. The annex to the act, however, turns the test upside down: events in categories 1.1, 1.2, 1.3 and in all eight categories 4.x „always receive” this attribute, and the others never receive it. The arithmetic closes without a remainder: 11 categories on one side, 15 on the other, exactly the 26 in existence, each in a single camp. The consequence is that the label no longer measures what the definition says, but the code of the category. A methodology error in an internal model, category 4.8, ends up marked as misconduct even where nobody has sued anybody, while a failure to meet contractual obligations, category 7.3, cannot be marked that way even where it reaches court. Comparability between banks goes up, because the label is applied mechanically; its usefulness for anyone looking for conduct losses goes down, for the same reason. The cross-references in the annex are, by contrast, correct: point 7 refers to points 5 and 6, and there indeed are the three categories you would expect, 4.8 and 7.5 compulsory and 7.4 optional.
Finally, an observation about form, which in an act of this kind is also an observation about substance. The only three formulas in the regulation, the merger and acquisition factor in Article 17(2) and the two in Article 39(1), are set as images. The text layer of the official PDF edition puts in their place a note saying that the item is an illustration, and inside the images, in the Romanian edition, the commas under ș and ț are missing: it reads „al instituiei”, „al entităii” and „din riscul operaional”. A reader with eyes on the page loses nothing, but the formulas cannot be searched, cannot be copied and do not reach a screen reader. In a regulation whose whole purpose is to produce data that are comparable and machine-processable, the part that actually calls for calculation is the only one a machine cannot read.
What should be changed
- Exit from the prudential boundary approach should be tied to a fixed date, not to a notice period that cannot be given. If the text said that the reversion takes effect from the first reporting reference date after the notification, and that the notification is made without delay once the condition falls away, the bank would no longer be made to choose between two articles that rule each other out.
- The size condition in Articles 34 and 35 should be repeated in Article 36 as well. Without it, a large bridge institution reads an exemption the competent authority cannot grant it, and its first conversation with the supervisor is spent on a predictable misunderstanding.
- The formulas should be published as text, not as images, and with complete diacritics. Three formulas in a 28-page act do not justify the loss of searchability and accessibility, and the Publications Office already has formats that allow mathematics to be written as text.
- An approved exclusion of an exceptional event should take effect on the business indicator as well. Otherwise the supervisor can find that a loss is no longer relevant to the bank’s risk profile, and that finding changes nothing in the amount the bank keeps tied up because of it.
- The link between the legal risk attributes and the definition in the basic regulation should be stated openly. Either the annex is declared to be a rule of presumption, or the attribute is assigned according to the definition. As it is written now, two texts of the same framework give the same word different meanings.
- The European Banking Authority should publish, after the first year of data, the distribution of events across the 26 categories and the 15 labels. Level 2 data start on 1 January 2025 and become a complete ten-year series only after 2034; an aggregated annual statistic would make the grid useful a decade earlier.
- The National Bank of Romania should say publicly how many credit institutions in Romania exceed the threshold of EUR 750 million. That figure decides who keeps the detailed loss record and who does not, and without it the Romanian reader cannot know whether the rule touches two banks or twelve.
Original text of the legal act
The text below is reproduced in Romanian, the official form of publication.
The full text, as published in the Official Gazette of Romania
Official Journal of the European Union, L series, 2026/1167 of 3 September 2026 28 pages PDF, 880 KB
Open the official PDFDownload the PDF
The viewer is not shown on small screens. Use the buttons above to open or download the file.
This article is for informational purposes only and does not constitute legal advice. For specific situations, consult a licensed attorney or tax advisor.
