Updated 07/09/2026
Coming into force on 23/09/2026

Initial Legal Act
Amendments
Search within this legal act

Article 32 - Delegated Regulation 2026/1167

Article 32

Attributes

1.   Institutions shall assign to each loss event all the applicable of the following attributes:

Attributes

Description

Legal risk – Misconduct

As defined in Article 4, point (52a), (d), of Regulation (EU) No 575/2013.

Legal risk – Other than Misconduct

As defined in Article 4, points (52a)(a), (b), (c),(e), (f) and (g) of Regulation (EU) No 575/2013.

Model risk

As defined in Article 4, point (52b) of Regulation (EU) No 575/2013.

ICT risk – not related to Cyber

As defined in Article 4, point (52c) of Regulation (EU) No 575/2013, excluding losses from cyber-attacks.

ICT risk – related to Cyber

Losses induced by cyber-attacks as defined in Article 3, point (14), of Regulation (EU) 2022/2554.

Credit risk (where not included in credit risk weighted assets)

Operational risk losses related to credit assets, including credit frauds (committed by the client on its own account or by a third party through identity theft), unenforceable credit contracts or collateral failures, that have been unpaid and are not accounted for in the risk-weighted exposure amount for credit risk.

Market risk

The following events, and the related losses, shall be classified as operational risk related to financial transactions and market risk:

(a)

events due to operational and data entry errors, including the following:

(i)

failures and errors during the introduction or execution of orders;

(ii)

loss of data or misunderstanding of the data flow from the front to the middle and back offices of the institution;

(iii)

errors in classification;

(iv)

incorrect specification of deals in the term-sheet, including errors related to the transaction amount, maturities and financial features;

(b)

events due to failures in internal controls, including the following:

(i)

failures in properly executing an order to unwind a market position in case of adverse price movements;

(ii)

unauthorised positions taken in excess of allocated limits, irrespective of the type of risk they relate to;

(c)

events due to inadequate data quality and unavailability of IT environment, including technical unavailability of access to the market resulting in an inability to close contracts.

Third-party risk

Losses that may arise for an institution in relation to its use of services provided by third-party service providers or by subcontractors of the that provider, including through outsourcing arrangements.

Those losses include losses due to failures in managing third-party relationships and risks appropriately, including developing and maintaining an adequate third-party control framework (including due diligence including selection of third-party service providers, ongoing monitoring) or defining and implementing adequate contractual arrangements / service level agreements.

Environmental, social and governance risks

Losses that may arise from environmental, physical, and transition risks, as defined in Article 4, points (52e), (52f), and (52g) of Regulation (EU) No 575/2013. Losses that may arise from social and governance risks, as defined in Article 4, points (52h) and (52i), of Regulation (EU) No 575/2013.

Greenwashing risk

The scope of application includes greenwashing risk, with reference to the losses arising from practices whereby sustainability related statements, declarations, actions, or communications do not clearly and fairly reflect the underlying sustainability profile of an entity, a financial product, or financial services. Those practices may be misleading to consumers, investors or other market participants.

Business continuity

Failure to provide and maintain appropriate business continuity management and event management framework (including ICT business continuity and ICT recovery and response aspects as referred to in Articles 11 and 12 of Regulation (EU) 2022/2554), and in Articles 24, 25 and 26 of Commission Delegated Regulation (EU) 2024/1774 (5), including inadequate business continuity plans.

Retail (including banking and retail brokerage)

Operational events and losses linked to retail clients, including:

(a)

natural persons;

(b)

SMEs (small and medium-sized enterprises) as defined in Article 5, point(9), of Regulation (EU) No 575/2013.

The list of activities for this attribute includes:

(a)

retail and private banking: lending and deposits, transactional and saving accounts, ATMs services, banking services, financial leasing, guarantees and commitments, trusts and estates, investment advice, card services (debit and credit cards, merchant/commercial/corporate cards, private labels);

(b)

retail brokerage: reception, transmission and execution of client orders, placing of financial instruments without a firm commitment basis.

Trading and sales

Operational events and losses linked to activities including flow business and sales, brokerage, market making, treasury, position taking, and proprietary positions managed by trading desks, as defined in Article 4, point (144), of Regulation (EU) No 575/2013.

The list of products for this attribute includes:

(a)

equities: equity portfolios and indices;

(b)

fixed income and credit trading;

(c)

foreign exchange;

(d)

commodities and energy products;

(e)

money market, funding, repos and securities lending;

(f)

derivatives.

Commercial banking

Operational events and losses linked to activities including lending and deposits, guarantees, leasing and factoring, trade finance, project finance, real estate.

Other business lines (including corporate finance, payment and settlement, asset management, agency services, corporate items)

This attribute includes the remaining operational events and losses linked to activities, other than those referred to in in the Retail, trading and sales, and Commercial banking attributes, including the following:

(a)

corporate finance: mergers and acquisitions, underwriting, privatisations, securitisation, initial public offering and private placements, advisory services, municipal and government finance, merchant banking;

(b)

payments and settlements for external clients: payments and collections, funds transfer, cash and securities clearing and settlement; payment and settlement losses related to a institution´s own activities shall be incorporated in the affected business line;

(c)

agency services for the account of clients: custody services (escrow, depository receipts, corporate actions, etc.), corporate trust and agency (issuer and paying agents);

(d)

asset management: discretionary and non-discretionary fund management, including portfolio management (pooled, segregated, retail, institutional, closed, open, private equity);

(e)

corporate items: for purely corporate level items, including those affecting the Board of Directors, misreporting financial statements, or other events that can only be categorised at corporate centre.

(5)  Commission Delegated Regulation (EU) 2024/1774 of 13 March 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying ICT risk management tools, methods, processes, and policies and the simplified ICT risk management framework (OJ L, 2024/1774, 25.6.2024, ELI: http://data.europa.eu/eli/reg_del/2024/1774/oj).

2.   By way of derogation from paragraph 1, institutions shall assign to each loss event at least one attribute among ‘Retail (including banking and retail brokerage)’, ‘Trading and sales’, ‘Commercial banking’ and ‘Other business lines (including corporate finance, payment and settlement, asset management, agency services, corporate items)’.

3.   By way of derogation from paragraph 1, institutions shall assign the attributes ‘Legal risk – Misconduct’, ‘Legal risk – Other than misconduct’ and ‘Model risk’ to Level 1 event types and Level 2 categories in accordance with the Annex.