Assessment of inherent operational risk
Competent authorities should develop a thorough understanding of the institution’s inherent operational risk exposures and evaluate the significance of the prudential impact of this risk for the institution as well as the impact on its ability to deliver critical or important functions through disruption.
To support this assessment, competent authorities should consider the own funds requirement for operational risk compared to the total own funds requirement, and where relevant the internal capital allocated for operational risk by the institution compared to the total internal capital. Moreover, competent authorities should leverage the knowledge gained from the assessment of other SREP elements (in particular from Title 4 and Title 5), from the comparison with peers, from any other supervisory activities including the input from the AML/CFT supervisors and market surveillance authorities and from other relevant information sources.
Competent authorities should consider at minimum key operational risk factors, potential disruptive scenarios, and where relevant, analyse them by business line, legal entity, geography, and event type category (subject to data availability) and benchmark the institution’s position against its peers. These factors should at least cover the institution’s main strategy for operational risk and operational risk appetite, business environment (including geographical presence, ICT operations, and distribution channels), recent significant corporate events (such as mergers, acquisitions, disposals and restructuring), ICT systems and other ICT-related aspects as per section 6.4.2.3, process changes, third-party arrangements, regulatory compliance issues, business ambitions and incentive schemes and other key operational risk drivers.
Nature and significance of operational risk exposures
Competent authorities should determine the nature of operational risk exposures by analysing exposures to the main sources and drivers of operational risk to form a forward-looking view on prospective operational risk. For this analysis, competent authorities:
may consider the operating model, business lines, products, processes and geographies relevant to the institution, assessment of dependencies and operational risk exposures to primary risk drivers (e.g. processes, people, systems and external factors) and interactions of risk drivers, leveraging the institution’s self-risk assessment, peer analysis, data and public and/or consortium databases, if available and relevant;
should consider both the frequency and the severity of the events to which the institution is exposed and distinguish those causing high-severity losses and those occurring with high frequencies. Based on this distinction, competent authorities should assess the trends of operational risk losses and their concentration; and
should leverage scenario analyses and consider planned business operations and prospective operational risk analyses performed by the institution, where available, taking into account any corrective measures and mitigation actions already implemented and effective.
Following the identification and analysis of the major sources and drivers of operational risk, competent authorities should focus on those with the most material potential impact to the institution.
A primary source of information competent authorities should consider it is the institution’s loss and event data set as it can provide valuable insights on the evolution of the institution’s operational risk profile. Competent authorities should periodically assess the comprehensiveness, accuracy and quality of the loss data. Another source of information should be the institution’s records of all ICT-related incidents and significant cyber threats (as per Article 17(2) of DORA) and the identified sources of ICT risk (as per Article 8(2) of DORA).
Assessment of operational risk sub-categories
Competent authorities should focus the assessment of operational risk sub-categories to those which are considered material to the institution. Competent authorities should also apply their expert judgement to identify significant sub-categories, based on all available internal and external information sources. In conducting the assessment, competent authorities should always pay attention to the following aspects of operational risk(41):
6.4.2.1Legal risk
Competent authorities should consider the following when assessing the relevance and significance of the institution’s exposures to legal risk:
mis-selling of products or services;
conflicts of interest in conducting business;
manipulation of benchmark interest rates, foreign exchange rates or any other financial instruments or indices;
barriers to switching financial products during their lifetime and/or to switching financial service providers;
automatic renewals of products or exit penalties; and/or
customer complaints processing;
violation of national and international rules and regulations (tax rules, internal fraud or internal theft, anti-money laundering rules, anti-terrorism rules and economic sanctions);
ESG-related, in particular environment-related and greenwashing-related, litigation exposures.
Competent authorities should consider whether the institution may occur any expenses, fines, penalties or punitive damages from legal proceedings and the number and content of complaints. The outcomes of the Title 4 assessment should be also leveraged, along with scrutinising the incentive policies, to obtain high-level insights into sources of potential misconduct. In this context, competent authorities should also consider whether the institution has in place adequate and effective systems and processes to implement and comply with restrictive measures (e.g. sanctions), including assessing institution’s compliance with the EBA Guidelines on internal policies, procedures and controls(42).
However, the competent authority should apply a forward-looking approach, also considering the possible impact of regulatory developments and the activity of relevant authorities in respect of consumer protection and the supply of financial services in general.
6.4.2.2Model risk
Under the operational risk, competent authorities should assess model risk, with specific regard to internal non-regulatory models (e.g. AI models, product pricing, setting and monitoring risk limits, ICAAP/ILAAP models, recovery options).
For the assessment of model risk, competent authorities should consider:
to what extent and for which purposes the institution uses models to make decisions and the business significance of such decisions. Competent authorities should determine the business/activity for which the institution makes significant use of models and assess the potential impact of model risk through, amongst others, sensitivity and scenario analyses or stress testing; and
the soundness of control mechanisms (in terms of methods, frequency, follow-up, etc.), including a model approval process, regular reviews performed and the institution’s level of awareness of model deficiencies or market and business developments.
When models are used for decision-making purposes (e.g. product pricing, AI models, evaluation of financial instruments, client profiling), competent authorities should assess whether there is a sound internal validation process and/or model-review process to identify and mitigate model risk (other than regulatory models).
When conducting the model risk assessment, competent authorities should consider the assessment of other risks to capital and risks to liquidity and funding, in particular with respect to the adequacy of methodologies used for measuring risk, pricing and evaluating assets and/or liabilities. The results of such an assessment should inform the findings on operational risk.
6.4.2.3ICT risk - Assessment of inherent ICT risk
Identification of material ICT risks
In line with DORA, competent authorities should review the institution’s identification, classification and documentation of all ICT supported business functions, roles and responsibilities, the information assets(43) and ICT assets(44) supporting those functions, and their roles and dependencies in relation to ICT risk. This review should assist competent authorities to develop a thorough understanding of the institution’s inherent ICT risk exposures (ICT risk profile), identify its material inherent ICT risk and form an opinion on its prudential impact. For this purpose, competent authorities should consider at least the following, where relevant and applicable:
report on the review of ICT risk management framework (as per Article 6(5) of DORA);
sources of ICT risk, in particular the risk exposure to and from other financial entities, identified by the institution under Article 8(2) of DORA;
major ICT-related incidents reported (as per Article 19(1) of DORA), including the trend of aggregated annual costs and losses caused by major ICT-related incidents (as per Article 11(10) of DORA);
outcomes of the tests envisaged in the digital operational resilience testing programme (as per Article 24 of DORA)), including summary of the threat-led penetration testing (TLPT) findings and related remediation plans (as per Article 26(6) of DORA);
register of information (as per Article 28(3) of DORA), including degree of concentration on ICT third-party service providers, including ICT intra-group providers, per type of ICT services and/or ICT systems;
recommendations and opinions from the Lead Overseers (as per Article 40(3) and Article 42(7) of DORA) and related responses, reports and information from critical ICT third-party service providers (as per Article 35(1)(c), Article 42(1) and Article 48(2) of DORA);
level of complexity of ICT systems and results of ICT risk assessment on legacy ICT systems (as per Article 8(7) of DORA);
risk assessment on major changes (as per Article 8(3) of DORA);
level of adoption and integration of innovative ICT solutions;
locations, namely the regions or countries, of data centres and sensitive designated areas, including where contractual ICT services are provided by ICT third-party service providers, also covering data processing and storage location;
ICT risk and controls self-assessments (if provided in the ICAAP information);
ICT risk-related management information submitted to the institution’s management body;
ICT-related internal and external audit findings;
external threat environment, including threat and vulnerability intelligence.
Review of ICT systems and ICT services
Competent authorities should review the institution’s relevant documentation, methodology and processes, and form an opinion on whether the institution has appropriately identified the ICT systems and ICT services that support critical or important functions. For this purpose, competent authorities should consider:
ICT systems supporting critical or important functions as well as the critical information assets and ICT assets identified by the institution (as per Article 8 of DORA);
key processes dependent on ICT third-party service providers, including interconnections with ICT third-party service providers that support critical or important functions, identified by the institution (as per Article 8.5 of DORA).
Identification and mapping of material ICT risks to ICT systems and ICT services that support critical or importance functions
Following the review of the institution’s dependency on information assets and ICT assets, ICT risk profile, ICT systems and ICT services, competent authorities should form an opinion on the material ICT risks that can have a significant prudential impact on the institution’s ICT systems and services that support critical or important functions and a significant impact on its ability to operate under disruption. For this purpose, competent authorities should consider:
financial loss, including potential customer compensation, legal and remediation costs, contractual damages, costs and lost revenue;
potential for business disruption, considering (but not limited to) the criticality of the services affected, including institution’s transactions and operations (including third-party dependencies), the number of clients and/or financial counterparts and/or branches and employees potentially affected;
potential data losses;
potential reputational impact;
potential regulatory impact, including the potential for public censure, fines or even variation of permissions;
potential strategic impact on the institution;
potential geographical spread.
Competent authorities should then map the identified material ICT risk into the ICT risk categories set out in Annex III. Institutions are expected to maintain their own categorisation rather than using the one set out in the Annex.