Assessment of operational risk management and control framework
Competent authorities should assess the framework and arrangements the institution has in place to manage and control operational risk taking into account the outcome of the analysis of the overall risk management and internal control framework addressed in Title 5, as this will influence the institution’s operational risk exposures. Regarding ML/TF risk, the competent authority should take into account the assessment provided by the AML/CFT supervisor.
Operational risk strategy and appetite
Competent authorities should assess whether the institution has a sound, clearly formulated and documented operational risk strategy and appetite level approved by the management body, which outlines the nature, types and levels of operational risk the institution is willing to assume. For this assessment, among other factors, competent authorities should take into account the role of the management body in setting, approving, implementing and reviewing the operational risk strategy and appetite (including ICT risk appetite and digital operational resilience strategy), the strategy’s sufficient coverage and appropriateness with respect to the nature and materiality of the institution’s operational risk profile.
Organisational and internal control framework
Competent authorities should assess the institution’s compliance with Article 323 of the Regulation (EU) No 575/2013. In this assessment, competent authorities should evaluate the soundness and effectiveness of the organisational framework and governance arrangements to enable effective operational risk management, measurement and control, with sufficient human and technical resources to carry out the required tasks. Competent authorities should take into account whether clear lines of responsibility are in place for the identification, evaluation, mitigation, monitoring and reporting of operational risk as well as adherence to the three lines of defence model.
Competent authorities should assess whether the institution has a strong control framework and sound safeguards to mitigate its operational risk, including appropriate policies and procedures, covering also residual risk, and whether these are consistent with the institution’s operational risk management appetite and strategy and cover all the key operations and processes. This includes, amongst others, the assessment of whether these policies and procedures are clearly formalised, communicated and applied consistently across the institution.
Competent authorities should also assess the functionality of the internal audit function in terms of adequacy, scope and frequency of internal audits on the operational risk management framework.
Business continuity, response and recovery
Competent authorities should assess the institution’s compliance with the (i) EBA Guidelines on Internal Governance in relation to the overall business continuity management and with the (ii) DORA in relation to the ICT business continuity policy and ICT response and recovery plans. In this regard, competent authorities should determine whether ICT business continuity policy and ICT response and recovery plans form an integral part of the institution’s overall business continuity policy and response and recovery plan.
Competent authorities should assess whether the institution has established effective business continuity management with tested business continuity, response and recovery plans covering at least its critical or important functions, including those contracted to third-party providers, and whether these consider a range of severe but plausible scenarios to which the institution may be vulnerable. Competent authorities should also assess whether the institution’s business continuity policy enables appropriate response and recovery measures to any type of incident.
Competent authorities should determine whether the institution’s business continuity management includes:
Business Impact Analysis (BIA);
appropriate recovery strategies incorporating key internal and external dependencies and clearly defined recovery priorities and resilience levels;
comprehensive and flexible plans to deal with plausible disruptive scenarios, which are established based on the BIA and in coordination with internal and external stakeholders;
plans that establish contingency strategies and response and recovery procedures;
effective testing of the design and operational effectiveness of the plans;
BCM awareness and training programmes;
communications plans for informing management and all relevant stakeholders, and crisis-management documentation, measures and a crisis management function where applicable (as per Article 11(7) of DORA).
Competent authorities should assess whether the institution’s business continuity, response and recovery plans:
establish roles and responsibilities, including clear guidance on potential succession, and set out the internal decision-making process along with definition of activation triggers;
are reviewed to ensure contingency strategies remain consistent with current operations, risks and threats, resilience levels, and recovery objectives and priorities;
prioritise business continuity actions using risk-based approach;
are tested regularly to ensure that recovery objectives and timeframes can be met; and
are inclusive of the testing of services provided by third-party service providers, where applicable;
Competent authorities should also assess whether testing results are documented and reported to the management body.
Assessment of ICT risk management framework
Competent authorities should assess the institution’s compliance with the DORA and the EBA Guidelines on Internal Governance in relation to the internal governance and organisation of the management of ICT risk. Competent authorities should form a view on whether the institution’s management body is held overall accountable for managing ICT risk and appropriately defines, approves and oversees the implementation of all ICT-related arrangements. Competent authorities should consider whether the members of the management body possess sufficient knowledge and skills to understand and assess ICT risk and its impact on the institution’s operations.
Competent authorities should assess how the roles and responsibilities for all ICT-related functions and the established governance arrangements are embedded and integrated in the institution’s internal control and governance framework to manage ICT risk. For this purpose, competent authorities should consider whether the institution has effectively assigned the responsibility for managing and overseeing ICT risk to an independent control function that has direct access and can report directly to the management body in its supervisory function, and assess whether the institution demonstrates:
clear communication, allocation and integration of roles and responsibilities in all ICT-related functions, including ICT supported business functions, and processes;
sufficient and appropriate budget to fulfil digital operational resilience in terms of all types of resources, including relevant awareness programmes, training, and ICT skills for all staff (as per Article 5(2)(g) of DORA);
adequate follow-up and response by the management body on critical ICT audit findings and findings reported under Article 13(5) of DORA.
Competent authorities should develop a thorough understanding of the institution’s ICT risk management framework and assess whether the institution has in place sufficient and appropriate strategies, policies, procedures, ICT protocols and tools, including tolerance levels, to address effectively, efficiently and comprehensively the material ICT risk in line with DORA. For this purpose, competent authorities should consider, where applicable:
appropriateness and effectiveness of institution’s ICT risk management policies(45), processes and procedures, covering inter alia ICT third-party management, ICT-related incident detection and response, ICT assess management, encryption and cryptography, ICT operations security, network security, access control, and whether these have been approved by the management body and communicated to all relevant stakeholders (as per Article 14 of DORA);
appropriateness of institution’s risk tolerance level of ICT risk and the impact tolerance for ICT disruptions (as per Article 6(8)(b) of DORA);
appropriateness and implementation of the institution’s digital operational resilience strategy, including its alignment with the business strategy;
consistency of the strategy on ICT third-party risk, including the ICT multi-vendor strategy, where available, with the overall business strategy and ICT risk management framework;
residual risk from the institution’s identified risks in respect to contractual arrangements on the use of ICT services supporting critical or important functions;
residual risk from the institution’s identified risks on ICT projects impacting critical or important functions reported to the management body, and also on ICT systems acquisitions, development and maintenance and ICT changes;
soundness and comprehensiveness of digital operational resilience testing programme;
trend and magnitude of major ICT-related incidents and findings reported to the management body as per Article 17(3)(e) and Article 13(5) of DORA;
ICT risk controls specific for the identified material ICT risk;
timely reporting of ICT risk management aspects to the management body and senior management;
internal audit coverage and findings.
When assessing ICT risk management, competent authorities should pay particular attention to ICT third-party risk management, including the institution’s concentration level to ICT third-party service providers. For this purpose, competent authorities should ensure close cooperation with the Lead Overseers of critical ICT third-party providers (CTPPs), in accordance with the ESAs’ Joint Guidelines(46), in case the institution under assessment receives ICT services from a CTPP. Competent authorities should also review the effectiveness of the dedicated role established by the institution, or the designated member of senior management, on the monitoring of ICT third-party arrangements.
Competent authorities should consider whether the internal audit function is effective and possesses sufficient knowledge, skills and expertise to audit institution’s ICT risk management framework, by reviewing whether:
the ICT risk management framework is audited with the required quality, focus and frequency, and is commensurate to the ICT risk profile of the institution;
the audit plan includes audits on the material ICT risks identified by the institution, including independent reviews of ICT response and recovery plans;
critical ICT audit findings are timely verified and remediated, including reporting to the management body;
ICT audit findings, including agreed actions, are formally followed up and progress reports periodically reviewed by the senior management and/or the audit committee.