Operational risk sub-categories
The table below presents a non-exhaustive list of sub-categories for operational risk that competent authorities should consider when relevant.
Operational risk sub-categories (level 1) | Operational risk sub-Legal references/Definitions Legal references/Definitions categories (level 2) |
Legal risk | Article 4(1), point (52a) of the CRR |
Model risk | Article 4(1), point (52b) of the CRR |
The risk that performance and availability of ICT systems, data or services are adversely impacted, including the inability to timely ICT availability and recover the institution’s services, due to a failure of ICT hardware continuity risk or software components; weaknesses in ICT system management; or any other event | |
ICT risk | The risk that unauthorised access or malicious or intentional acts ICT security risk compromise ICT systems, data or services irrespective of whether (including cyber) they originate from within or outside the institution (e.g. cyber-Article 4(1), point (52c) of the CRR attacks) |
The risk arising from the inability of the institution to manage ICT change risk changes to ICT systems or ICT services in a timely and controlled manner | |
The risk that data stored and processed by ICT systems are incomplete, inaccurate or inconsistent across different ICT ICT data integrity risk systems impairing the soundness or continuity of the institution’s services and activities and potentially resulting in operational, financial, legal, or reputational impact |
188
Operational risk sub-categories (level 1) | Operational risk sub-Legal references/Definitions Legal references/Definitions categories (level 2) |
the risk that may arise for an institution in relation to its use of ICT services provided by ICT third-party service providers or by subcontractors of the latter, including through outsourcing ICT third-party risk arrangements (Article 3 (18) of DORA), including ICT concentration risk (Article 3 (29) of DORA) on both critical and non-critical ICT third-party services providers | |
Third-party risk (non-ICT) | The risk that may arise for a financial entity in relation to the use of function provided by third-party service providers or by subcontractors of the latter, including the provision of a function or the support to a function, including through outsourcing arrangements (upcoming EBA Guidelines on sound management of third-party risk) |
Credit risk (operational risk events related to credit risk not accounted for in the risk-weighted exposure for credit risk) | Article 317 (5) of the CRR |
Market risk (operational risk events related to market risk) | Article 317 (6) of the CRR |
189