European bank specialists conduct an operational-resilience review in an institutional meeting room.
European bank specialists conduct an operational-resilience review in an institutional meeting room.
01

What the EU published

The European Union published Commission Delegated Regulation (EU) 2026/1167 in the Official Journal on 3 September 2026. The measure sets regulatory technical standards concerning operational-risk requirements for banks and is scheduled to enter into force on 23 September. [1] [2]

For regulated institutions and their technology providers, the publication converts a policy topic into a dated implementation requirement. The official text, rather than summaries alone, should be the primary basis for legal and control interpretation. [1]

02

The operating consequence

Operational-risk rules affect more than compliance reporting. They shape how loss events are classified, evidence is retained, controls are tested and responsibilities are assigned across banks and material service providers. [2]

Fintech vendors serving EU banks should map the final requirements to incident, change, resilience and audit processes. A supplier's general security certification is not a substitute for institution-specific operational-risk evidence.

03

What teams should verify

Before the effective date, teams should verify scope, accountable owners, data availability and any gap between formal controls and the evidence generated in daily operations. Any implementation decision should be reviewed against the official regulation and appropriate professional advice. [1] [2]