Updated 07/09/2026
Coming into force on 23/09/2026

Initial Legal Act
Amendments
Search within this legal act

Article 28 - Delegated Regulation 2026/1167

Article 28

Level 2 classification for Level 1 event type Clients, products and business practices

Institutions shall classify each loss event classified as Clients, products and business practices in accordance with Article 24 into one of the following Level 2 categories:

Clients, products and business practices Level 2 classification

Description

Reference number

Client mistreatment / Failure to fulfil duties to customer

Inappropriate behaviour towards customers and failure to respect and comply with duties to customers, either actual or potential.

4.1

Data privacy breach / Confidentiality mismanagement

Improper disclosure or misuse of confidential information.

4.2

Improper market practices, Anti-Trust / Anti-Competition

Conducting business activities in breach of trading rules and standards, including all types of market abuse and manipulation.

Violations of antitrust or competition laws where the institution fails to act in accordance with clients’ best interest.

4.3

Improper distribution and marketing, including sale Service Failure

Improper/inadequate means of distribution of products and services and improper/inaccurate direct marketing practices.

Sale service failure includes both pre-sales service failure and post-sales service failure. Pre-sales failure is inadequate/improper services to clients ahead of sales, including mis-selling and failure to provide adequate advice. Post-sales failure refers to inadequate/improper services to clients after sales, including the failure to respond to client complaints regarding poor sales services within the timelines defined by the regulator

4.4

Financial crime

The risk of money laundering, know-your-customer (KYC) failure and sanctions violations. This category includes:

(a)

failure to comply with the restrictions imposed by sanctions, including operational risk events due to mistaken transactions involving sanctioned countries;

(b)

engagement in money laundering and terrorism financing, including failures in KYC process.

4.5

Breaches of statute and regulations, other than those specifically assigned to other event types or categories

Breach of any legal or regulatory obligations, other than those specifically assigned to other event types or categories, including the institution’s legal obligations and the obligations imposed by regulatory and tax authorities.

This category includes:

(a)

operating without the necessary authorisation, licence, certification or registration;

(b)

tax evasion.

Where tax evasion is committed to consciously breach the tax regulation, institutions shall assign the loss event to event 1.3.

4.6

Improper product and service design

Flaws in design of products or services targeted at clients such that the design of a product/service does not meet a client’s needs.

4.7

Model methodology

Losses due to errors in the model itself, including the model design, incorrect formulae, methodology and underlying assumptions. Where Artificial Intelligence (AI) systems are components of the model, an error due to that technology could fall under the scope of model risk.

4.8