
What the EU published
The European Union published Commission Delegated Regulation (EU) 2026/1167 in the Official Journal on 3 September 2026. The measure sets regulatory technical standards concerning operational-risk requirements for banks and is scheduled to enter into force on 23 September. [1] [2]
For regulated institutions and their technology providers, the publication converts a policy topic into a dated implementation requirement. The official text, rather than summaries alone, should be the primary basis for legal and control interpretation. [1]
The operating consequence
Operational-risk rules affect more than compliance reporting. They shape how loss events are classified, evidence is retained, controls are tested and responsibilities are assigned across banks and material service providers. [2]
Fintech vendors serving EU banks should map the final requirements to incident, change, resilience and audit processes. A supplier's general security certification is not a substitute for institution-specific operational-risk evidence.
What teams should verify
Before the effective date, teams should verify scope, accountable owners, data availability and any gap between formal controls and the evidence generated in daily operations. Any implementation decision should be reviewed against the official regulation and appropriate professional advice. [1] [2]