Summary of findings, scoring and supervisory measures
Following the above assessment, competent authorities should form a view on the institution’s operational risk. This view should be reflected in a summary of findings, accompanied by a risk score based on the considerations specified in table 10. Where, based on the materiality of certain risk sub-categories, the competent authority decides to assess and score them individually, the guidance provided in this table should be applied, as far as possible, by analogy.
Risk score | Considerations in relation to Supervisory Considerations in relation to adequate management and view inherent risk controls |
1 | • Operational risk exposures are • There is consistency between limited to a few high-the institution’s operational risk frequency/low-severity impact policy and strategy and its categories. overall strategy and risk • The significance of the appetite. exposure to operational risk is • The organisational framework not material/very low, as There is a low for operational risk is robust shown by scenario analysis and with clear responsibilities and a risk of compared with the losses of clear separation of tasks significant peers. between risk-takers and prudential • The level of gross losses (before management and control impact on the recoveries and including losses functions. institution on credit portfolio caused by • Operational risk framework considering the operational risk) experienced includes all relevant risks. level of by the institution in recent • Operational risk measurement, inherent risk years has been not monitoring and reporting material/very low or has and the systems are appropriate. decreased from a higher level. management • The control framework for • No significant ICT risk and controls. operational risk is sound. exposures, • ICT risk management and simple/resilient/agile ICT controls are adequate with architecture and no respect to the requirements set material/very low ICT risks. out in DORA. • The level of concentration risk • Third-party risk management towards third-party service framework is sound and providers is low, with simple effective, along with subcontracting chains. |
Risk score | Considerations in relation to Supervisory Considerations in relation to adequate management and view inherent risk controls |
• The threat intensity that could appropriate contractual result into major operational arrangements. disruption (including ICT- • Effective and sound business related incidents) of critical or continuity management, important functions is low. including tested business | |
2 | • Operational risk exposures are continuity, response and mainly in high-frequency/low- recovery plans. severity impact categories. • The significance of the exposure to operational risk is low to medium, as shown by scenario analysis and compared There is a with the losses of peers. medium-low • The level of gross losses risk of experienced by the institution in recent years has been low to significant medium, or is expected to prudential increase from a lower historic impact on the level or decrease from a higher institution historic level. considering the • Low ICT risk exposures, level of moderately complex/partially inherent risk constrained ICT architecture and the and low/medium ICT risks. management • The level of concentration risk and controls. towards third-party service providers is medium, with moderate subcontracting chains. • The threat intensity that could result into major operational disruption (including ICT-related incidents) of critical or important functions is medium. |
3 | • Operational risk exposures There is a • The consistency between the extend to some low-medium-high institution’s operational risk frequency/high-severity impact policy and strategy and its risk of categories. overall strategy and risk significant • The significance of the appetite is not sufficiently prudential exposure to operational risk is developed or even inadequate. impact on the medium to high, as shown by • The organisational framework institution scenario analysis and compared for operational risk is not considering the with the losses of peers. sufficiently robust. level of • The level of gross losses • Operational risk framework inherent risk experienced by the institution does not include all relevant in recent years has been and the risks. medium to high, or is expected management • Operational risk measurement, to increase from a lower and controls. monitoring and reporting historic level or decrease from a systems are inappropriate. higher historic level. |
Risk score | Considerations in relation to Supervisory Considerations in relation to adequate management and view inherent risk controls |
• Indications of possible • The control framework for significant ICT risk exposures, operational risk is tenuous. complex/rigid/fragmented ICT • ICT risk management and architecture and medium/high controls are not compliant with ICT risks. respect to the requirements set • The level of concentration risk out in DORA. towards third-party service • Third-party risk management providers is high, with framework is incomplete/weak, moderate to long/complex along with inadequate subcontracting chains. contractual arrangements. • The threat intensity that could • Inadequate business continuity result into major operational management, including disruption (including ICT- unreliable/ineffective/incomple related incidents) of critical or te business continuity, response important functions is high. and recovery plans. | |
4 | • Operational risk exposures extend to all main categories. • The significance of the exposure to operational risk is high and increasing, as shown by scenario analysis and compared with the losses of There is a high peers. risk of • The level of gross losses significant experienced by the institution prudential over the last few years has impact on the been high, or risk has institution significantly increased. considering the • Multiple indications of level of significant ICT risk exposures, inherent risk highly complex/fragile ICT and the architecture and high ICT risks. management • The level of concentration risk and controls. towards third-party service providers is very high/severe, with long/complex subcontracting chains. • The threat intensity that could result into major operational disruption (including ICT-related incidents) of critical or important functions is very high/severe. |
The table below presents a non-exhaustive list of supervisory measures that competent authorities may take in case of identified deficiencies in the institution’s operational risk management framework and operational resilience (taking into account the close interconnection of operational resilience and operational risk management). Competent authorities should decide on the type of the measure based on its effectiveness to the specific identified deficiency. Competent authorities may apply additional supervisory measures (including quantitative measures in accordance with Article 104(1)(a) of the Directive 2013/36/EU) or a combination of these with the ones listed in the table below, if these are deemed more appropriate to address the identified deficiencies. For breaches of DORA, the competent authorities should consider the applicable corrective and remedial measures provided in Article 50 of DORA.
Table 11. Potential and non-exhaustive list of supervisory measures stemming from the assessment of operational risk and operational resilience Potential supervisory measures for competent authorities in accordance with Article 104(1), points (b), (d), (e), (f), (j), (l), (m), and (n) of Directive 2013/36/EU and Article 50 of Regulation (EU) 2022/2554 – Competent authorities may require the institution to: A. involve the management body or its committees more actively in operational risk management decisions; B. improve operational risk measurement systems; C. strengthen controls on operational processes, including identification, monitoring, response and recovery; D. improve the operational governance framework; E. enhance operational risk reporting to the management body and senior management; F. develop and implement corrective action plans to address deficiencies; G. limit certain third-party arrangements, in particular for critical or important functions; H. enhance stress testing and scenario analysis of operational risk; I. implement stronger operational measures; J. enhance business continuity, response and recovery plans; K. enhance operational risk management related to ESG risks, in particular environmental risks, potentially based on one or several actions listed above.