The European Banking Authority has launched a consultation on draft Regulatory Technical Standards establishing a harmonized minimum operational risk management framework under the Capital Requirements Regulation. The proposal supports the EU Banking Package’s move from multiple operational risk capital approaches to a single standardized approach based on the business indicator, while continuing the EBA’s emphasis on proportionate, risk-based regulation. It covers governance, the operational risk management process and the operational risk assessment system for all institutions subject to the regulation. The standards clarify responsibilities across the management body, senior management and the independent operational risk management function, and set requirements for risk appetite, data and taxonomy, reporting, validation, audit and data governance. Institutions with a business indicator below EUR 750 million would receive simplified treatment, including effectiveness reviews at least every two years rather than annually, management-body reporting at least annually rather than quarterly, and less granular data and taxonomy requirements. Larger institutions would have to maintain an extended data set, calculate annual operational risk losses and use a taxonomy consistent with the EBA’s operational risk taxonomy. Institutions may rely on policies, procedures and controls established under the Digital Operational Resilience Act where these also satisfy the proposed standards, limiting duplication for ICT risk. After considering consultation feedback, the EBA will finalize the draft standards and submit them to the European Commission for adoption.