General considerations
When assessing the operational risk management framework, competent authorities should evaluate inter alia the compliance of the institution with the legal acts published separately on the EBA website as referred to in paragraph 12.
Competent authorities should assess operational risk throughout all the business lines and operations of the institution, taking into account findings from the assessment of internal governance arrangements and institution-wide controls as specified in Title 5. In conducting this assessment, competent authorities should determine how operational risk may materialise, also considering the loss data set of the institution and potential impacts from other related risks (e.g. boundary credit-related and market-related operational risk).
Competent authorities should assess the materiality of operational risk arising from third-party service providers, including concentration (at entity and where relevant at group level) on one or more services provided by a single third-party service provider (directly or indirectly through subcontracting chains) or a limited number of third-party providers supporting institution’s critical or important functions, and whether these could affect the institution’s operational resilience, performance and risk management. When carrying out this assessment, competent authorities should take into account the extent to which the same third-party service providers are relied upon by other institutions, where such information is available to them.
When assessing operational risk, competent authorities should assess ICT risk, pursuant to DORA, and its potential impact on the institution’s critical or important functions, including any potential financial, reputational, regulatory and strategic impact to the institution.
Competent authorities should assess whether the institution has an adequate operational resilience approach to be able to withstand, adapt to and recover from disruptions when they materialise and whether this has been adequately and consistently aligned with the existing risk management framework, business continuity plans and third-party management.
When assessing operational risk, competent authorities should assess, if applicable, whether the institution’s policies and procedures identify, evaluate and manage appropriately the operational risks arising from crypto-assets activities and their supporting technology.
Competent authorities should assess reputational risk jointly with operational risk as it is inherently linked to operational risk events. However, the outcome of reputational risk assessment should not be reflected in the scoring of operational risk but, where relevant, should be considered as part of the BMA and/or the liquidity risk assessment, as its main effects can deteriorate investors’, depositors’ or interbank-market participants’ confidence to the institution.
Competent authorities should assess the impact of ESG risks on the inherent operational and reputational risks as well as the adequacy of the operational risk and reputational risk controls related to ESG risks, giving priority to environmental physical and transition risks. In particular, competent authorities should consider environmental risks and greenwashing risks when carrying out the assessment of legal risk and reputational risk.