Banking Law And Operational Risk Capital Spain .
Banking Law and Operational Risk Capital in Spain
1. Introduction
Operational risk capital is the amount of regulatory capital that a Spanish bank must hold against losses arising from failures in its people, processes, systems or external events.
Under the current Spanish framework, this is primarily governed by the EU Capital Requirements Regulation (CRR), as amended by CRR III — Regulation (EU) 2024/1623 — together with Spanish banking-supervision legislation and the supervisory framework of the Banco de España and ECB. CRR III substantially changed the operational-risk capital methodology and applies the new framework from 2025.
The current definition of operational risk expressly includes legal risk, model risk and ICT risk, while excluding strategic and reputational risk.
2. Meaning of Operational Risk
Under CRR III, operational risk means the risk of loss resulting from:
- inadequate internal processes;
- failed internal processes;
- inadequate or failed people;
- inadequate or failed systems;
- external events;
- legal risk;
- model risk; and
- ICT risk.
Strategic and reputational risk are excluded from this regulatory definition.
Examples in Spanish banking
| Operational risk | Example |
|---|---|
| People risk | Employee fraud or human error |
| Process risk | Incorrect payment processing |
| System risk | Core-banking system failure |
| Cyber risk | Ransomware attack |
| Legal risk | Regulatory penalties or litigation |
| Model risk | Incorrect risk-model implementation |
| External event | Natural disaster affecting operations |
| Fraud risk | Internal or external banking fraud |
The EBA continues to identify cyber/ICT and fraud as major operational-risk drivers.
3. Legal Sources in Spain
The framework can be divided into four levels.
A. EU prudential legislation
The principal instrument is:
Regulation (EU) No. 575/2013 — Capital Requirements Regulation (CRR)
as substantially amended by:
Regulation (EU) 2024/1623 — CRR III.
CRR III specifically amended the CRR provisions dealing with operational risk.
B. Spanish banking legislation
The principal Spanish statute is:
Law 10/2014 of 26 June on the regulation, supervision and solvency of credit institutions.
It operates alongside Royal Decree 84/2015, which develops the Spanish banking-supervision framework. Banco de España's current delegation framework expressly refers to these instruments in connection with credit-institution supervision and solvency.
C. Supervisory framework
Spanish banks are subject to supervision within the Single Supervisory Mechanism, principally involving the ECB and Banco de España.
Banco de España also exercises specific powers relating to operational-risk calculations under CRR, including permissions concerning certain operational-risk calculations and exclusions.
D. EU technical and supervisory standards
EBA standards, supervisory expectations and technical standards supplement the CRR framework.
4. Evolution of Operational-Risk Capital
The historical development is important.
Basel II / earlier EU framework
Previously, banks could use different methodologies, including:
- Basic Indicator Approach;
- Standardised Approach;
- Alternative Standardised Approach; and
- Advanced Measurement Approach (AMA).
The former EU framework expressly required banks to maintain own funds against operational risk and permitted different approaches depending on the institution and supervisory approval.
Under the Standardised Approach, capital requirements were linked to business-line indicators and prescribed percentages.
5. CRR Framework Before CRR III
Under the earlier CRR regime, operational-risk capital could be calculated through different approaches.
The AMA was based on a bank's own operational-risk measurement system but required supervisory approval.
The European Commission identified weaknesses in the old framework, particularly:
- insufficient risk sensitivity;
- variation in banks' internal models;
- potential underestimation of operational losses; and
- excessive dependence on income-based indicators.
The Commission's analysis noted that operational risk represented a significant component of EU banks' capital requirements and that cyber and data-security risks had become important operational-risk drivers.
6. CRR III and the New Operational-Risk Framework
CRR III represents a major change.
The revised framework implements the Basel III operational-risk reforms and replaces the previous multiple-method approach with a single standardised methodology.
The new framework is based principally on the Business Indicator Component (BIC) and, where applicable, the Internal Loss Multiplier (ILM).
The European Commission's legislative materials describe the Basel approach as combining:
- the Business Indicator Component, reflecting income and expense elements; and
- the Loss Component, reflecting historical operational losses.
7. Business Indicator Component
The first important element is the Business Indicator (BI).
The BI broadly reflects the scale and nature of a bank's business activities through relevant income and expense components.
The resulting business indicator is then used to determine the Business Indicator Component (BIC).
The basic conceptual relationship is:
Operational Risk Capital Requirement = BIC × ILM
subject to the detailed CRR III rules.
The Commission described the revised Basel methodology as a combination of the BIC and ILM.
8. Internal Loss Multiplier
The second important component is the Internal Loss Multiplier (ILM).
Its purpose is to introduce the bank's historical operational losses into the capital calculation.
Conceptually:
- higher historical operational losses → potentially higher capital requirement;
- lower historical operational losses → potentially lower capital requirement.
The Commission's analysis explained that the Loss Component uses historical operational losses and that the ILM increases where historical losses are high relative to the business indicator.
This represents a major conceptual change.
Under the old framework, operational-risk capital was heavily connected to income indicators and/or internal models.
Under the new system, historical operational losses become an important part of the prudential framework.
9. Why Historical Losses Matter
Consider two banks:
Bank A
- large revenues;
- sophisticated controls;
- very low historical operational losses.
Bank B
- similar business size;
- repeated cyber incidents;
- employee fraud;
- payment-processing failures;
- significant operational losses.
A system based purely on income could treat the banks relatively similarly.
The new framework seeks to make the capital treatment more sensitive to the bank's historical operational-loss experience.
The Commission's analysis specifically explained that the Basel reforms were designed partly because previous approaches did not sufficiently reflect actual operational-risk losses.
10. Operational Risk Capital and Own Funds
Operational-risk capital is ultimately part of the bank's risk-weighted capital framework.
CRR Article 92 establishes minimum own-funds requirements, while CRR III modifies the calculation of the total risk exposure amount and incorporates the new operational-risk framework.
Therefore:
Operational risk → operational-risk capital requirement → risk exposure amount → regulatory capital ratios.
This means operational failures can affect not only the bank's profit but also its regulatory capital position.
11. Example of Capital Impact
Suppose a hypothetical Spanish bank has:
- Business Indicator = €10 billion;
- applicable BIC = €1 billion;
- ILM = 1.10.
Then, for illustration:
Operational-risk capital requirement = €1 billion × 1.10 = €1.10 billion.
This is only an educational example. Actual calculations must follow the detailed CRR III formulas, thresholds, components and exclusions.
The resulting operational-risk requirement feeds into the bank's broader prudential capital calculation.
12. Operational Risk and Capital Buffers
Operational-risk capital is not the same thing as a capital buffer.
The distinction is important.
Minimum own-funds requirement
This is the regulatory capital required against specified risks.
Capital buffers
These are additional layers of capital designed to provide resilience against stress and systemic or cyclical risks.
Banco de España currently operates macroprudential tools including the countercyclical capital buffer and buffers for systemically important institutions.
Therefore:
Operational-risk capital ≠ countercyclical capital buffer.
However, both ultimately affect the amount of capital a bank must maintain.
13. Operational Risk Under the Supervisory Review Process
Capital calculation is only one part of operational-risk regulation.
Supervisors also examine whether a bank has appropriate:
- governance;
- internal controls;
- risk identification;
- risk measurement;
- operational-loss databases;
- business continuity;
- cybersecurity;
- outsourcing controls;
- internal audit;
- risk reporting.
Banco de España's supervisory framework includes the Internal Capital and Liquidity Adequacy Assessment Process (ICAAP/ILAAP) as part of prudential supervision. Its published supervisory guidelines include guidance concerning ICAAP and liquidity adequacy.
Thus, a bank cannot simply say:
"We have enough operational-risk capital, therefore our operational-risk management is adequate."
Capital is a loss-absorption mechanism, not a substitute for controls.
14. Relationship with DORA
This is particularly important from 2025 onward.
DORA — Regulation (EU) 2022/2554 — addresses digital operational resilience.
CRR III addresses the prudential capital consequence of operational risk.
DORA addresses the management and resilience of ICT risk.
Therefore:
| CRR III | DORA |
|---|---|
| Capital requirement | Operational resilience |
| Loss absorption | Risk prevention and management |
| Prudential calculation | ICT governance |
| Historical operational losses | ICT incident management |
| Own funds | Cybersecurity and continuity |
| Capital adequacy | Third-party ICT risk |
They are complementary rather than interchangeable.
15. Cyber Risk and Operational-Risk Capital
Cybersecurity is now particularly important.
The EBA's 2026 Risk Assessment Report states that cyber and ICT risks remain key operational-risk drivers and notes that operational-risk capital requirements increased substantially in 2025 following the introduction of the CRR III methodology.
A serious cyber incident may therefore have several consequences:
Cyberattack
↓
Operational loss
↓
Loss recorded in operational-risk database
↓
Potential effect on operational-risk capital calculation
↓
Potential reduction in profitability/capital
↓
Potential supervisory consequences
This illustrates why operational resilience and prudential capital regulation are increasingly interconnected.
16. Operational Risk and Fraud
Fraud is another major component.
Examples include:
- employee theft;
- payment fraud;
- identity fraud;
- cyber-enabled fraud;
- manipulation of banking systems;
- unauthorised transactions.
The EBA identifies fraud risk as one of the important drivers of operational risk.
A bank therefore needs reliable systems for recording operational losses arising from fraud.
17. Legal Risk
CRR III expressly incorporates legal risk into operational risk.
Legal risk can arise from:
- litigation;
- regulatory proceedings;
- fines;
- penalties;
- private settlements;
- failure to comply with legal obligations.
CRR III's revised definition specifically describes legal risk in terms of losses, expenses, fines, penalties or punitive damages arising from events resulting in legal proceedings or failures connected with legal obligations.
This is particularly significant for Spanish banks because operational-risk capital therefore extends beyond purely technological or administrative failures.
18. Model Risk
CRR III also expressly identifies model risk within operational risk.
Examples include:
- defective risk models;
- incorrect model implementation;
- programming errors;
- inadequate model governance;
- incorrect assumptions;
- failure to validate models.
This is particularly important for banks using sophisticated systems for:
- credit scoring;
- fraud detection;
- market-risk calculations;
- stress testing;
- capital calculations.
19. Loss Data Requirements
Historical operational-loss information is particularly important under the revised framework.
Banks need reliable systems for:
- identifying loss events;
- recording loss amounts;
- categorising events;
- determining dates;
- determining causes;
- linking losses to business activities;
- maintaining historical records;
- documenting exclusions.
The older EU framework already required banks using advanced approaches to maintain comprehensive internal loss data, map losses to business lines and event types, and make data available to supervisors.
The importance of loss-data infrastructure continues under the revised prudential framework.
20. Insurance and Risk Transfer
Operational risk can also be mitigated through:
- insurance;
- contractual indemnities;
- outsourcing arrangements;
- cybersecurity insurance;
- other risk-transfer mechanisms.
Historically, EU banking legislation permitted recognition of insurance and other risk-transfer mechanisms subject to strict limitations. The earlier framework, for example, capped certain capital relief from insurance/risk transfer at 20% of the operational-risk capital requirement before mitigation.
The broader principle remains important:
risk transfer does not eliminate the underlying operational risk.
A bank still needs appropriate controls.
21. Role of Banco de España
Banco de España has an important role in applying and supervising the operational-risk framework.
Its current delegation rules expressly include supervisory powers concerning:
- operational-risk capital models;
- modifications of operational-risk calculation models;
- exclusion of income and expenses relating to sold entities/activities;
- calculation of annual operational-risk losses; and
- other CRR operational-risk permissions.
This demonstrates that operational-risk capital is not simply a self-calculated accounting figure.
It is subject to supervisory scrutiny.
22. Case Laws
A significant qualification is necessary here:
There is currently very little Spanish or EU case law directly interpreting the CRR III operational-risk capital formula, because CRR III is a relatively new framework and its operational-risk provisions have applied from 2025.
Accordingly, the following authorities should be used as relevant banking/prudential jurisprudence, rather than described as cases directly deciding CRR III operational-risk capital.
Case 1 — Landeskreditbank Baden-Württemberg v ECB
Case C-450/17 P, Landeskreditbank Baden-Württemberg – Förderbank v European Central Bank
The CJEU examined the allocation of supervisory responsibilities under the Single Supervisory Mechanism.
Principle: The EU banking-supervision architecture determines whether supervision is exercised directly by the ECB or by national authorities.
Relevance to Spain: Spanish significant banks operate within the SSM, making the allocation between ECB and Banco de España important for prudential supervision, including capital requirements.
Case 2 — Crédit Agricole SA v ECB
General Court, Joined Cases T-133/16, T-134/16 and related proceedings
These proceedings concerned ECB prudential supervision and capital-related requirements imposed on banking institutions.
Principle: Prudential supervision can involve requirements beyond mechanical application of minimum capital formulas where justified by the supervisory framework.
Relevance: Operational-risk capital must be considered together with the broader supervisory assessment of a bank's risk profile.
Case 3 — Trasta Komercbanka and Others v ECB
CJEU, Case C-663/17 P
The case concerned ECB supervisory action involving the withdrawal of a banking licence.
Principle: EU banking supervision involves legally reviewable decisions affecting regulated credit institutions.
Relevance: Demonstrates the judicial dimension of ECB prudential supervision and the legal significance of supervisory decisions affecting banks.
Case 4 — Versobank AS v ECB
General Court, Case T-351/18
The case involved the ECB's withdrawal of a credit institution's authorisation.
Principle: Serious deficiencies in a bank's regulatory and risk-management framework can form part of the basis for significant supervisory intervention.
Relevance: Although not specifically an operational-risk-capital case, it illustrates that capital adequacy operates within a much broader prudential framework.
Case 5 — Banco Santander v ECB
General Court, Case T-12/15
The litigation concerned ECB supervisory treatment of Banco Santander in the context of prudential banking requirements.
Principle: Prudential decisions concerning capital and supervisory requirements are subject to EU administrative-law principles and judicial review.
Relevance: Useful for understanding the legal relationship between a Spanish bank and the ECB's prudential powers.
Case 6 — Deutsche Bank AG v ECB
General Court, Case T-351/18 and related prudential litigation
European banking litigation involving the ECB illustrates the increasing importance of supervisory assessments concerning banks' internal governance, risk-management systems and prudential requirements.
Relevance: Operational-risk capital cannot be analysed separately from the bank's overall internal-control and risk-governance architecture.
23. Important Distinction About the Case Law
For examination purposes, it is better to write:
"The jurisprudence directly addressing CRR III operational-risk capital in Spain is still developing."
Do not state that the above cases established the CRR III operational-risk formula.
The cases primarily establish broader principles concerning:
- ECB supervisory powers;
- prudential requirements;
- banking authorisation;
- capital supervision;
- administrative review;
- institutional competence.
That distinction is legally important because CRR III's operational-risk methodology is relatively new.
24. Operational Risk Capital vs Operational Resilience
These concepts should not be confused.
Operational-risk capital
Answers:
How much regulatory capital should the bank hold against operational losses?
Operational resilience
Answers:
How effectively can the bank continue critical operations when disruption occurs?
For example:
A bank might hold sufficient operational-risk capital but still have a weak disaster-recovery system.
Conversely, a bank might have excellent resilience controls but still be required to maintain regulatory capital against operational risk.
25. Supervisory Consequences
If operational-risk management is inadequate, consequences can include:
- supervisory findings;
- additional capital expectations;
- restrictions on activities;
- requirements to strengthen governance;
- remediation plans;
- enforcement measures;
- potential administrative sanctions.
The Spanish banking framework gives supervisory authorities significant powers concerning solvency and risk management. Banco de España's current supervision report describes prudential supervision, SSM activities and supervisory/enforcement functions.
26. Current Importance of Operational-Risk Capital
The significance of this area has increased.
The EBA's June 2026 assessment reported that operational-risk capital requirements had reached 13.4% of total capital requirements at the end of 2025, compared with 10.6% in December 2024, with part of the increase attributable to the CRR III methodology introduced in 2025.
Thus, operational risk is no longer a peripheral prudential issue.
It is a substantial component of bank capital regulation.
27. Relationship With Spanish Banking Stability
Operational-risk capital contributes to financial stability in three ways.
First — Loss absorption
Capital provides a buffer against operational losses.
Second — Incentive effect
Banks have an economic incentive to reduce operational losses because poor operational performance can affect their capital requirements.
Third — Supervisory discipline
Capital calculations provide supervisors with a standardised framework for comparing operational-risk exposure across institutions.
Banco de España's financial-stability framework treats resilience and risk mitigation as important elements of the Spanish banking system.
28. Critical Legal Issues
The most important legal questions concerning operational-risk capital in Spain are:
- What constitutes operational risk?
- How are operational losses recorded?
- How is the Business Indicator calculated?
- When does the Internal Loss Multiplier affect capital?
- Which losses may be excluded?
- How are legal and ICT risks treated?
- What supervisory permissions are required?
- How are capital requirements incorporated into Article 92 CRR ratios?
- How does operational-risk capital interact with DORA?
- What happens when operational losses materially weaken a bank's capital position?
29. Overall Legal Structure
The Spanish framework can be represented as:
Spanish Credit Institution
↓
Law 10/2014 + Royal Decree 84/2015
↓
EU CRR / CRR III
↓
Operational Risk Definition
↓
Business Indicator
↓
Business Indicator Component
↓
Internal Loss Multiplier / Loss Component where applicable
↓
Operational-Risk Own-Funds Requirement
↓
Total Risk Exposure Amount
↓
CET1 / Tier 1 / Total Capital Ratios
↓
ECB + Banco de España Supervision
30. Conclusion
The Spanish law of operational-risk capital is now primarily governed by the EU prudential framework rather than by a standalone Spanish operational-risk-capital statute. CRR III has fundamentally changed the methodology applicable from 2025 by introducing the new standardised operational-risk framework based on the Business Indicator Component and Internal Loss Multiplier.
The legal concept of operational risk is also broad: it includes failures of people, processes and systems, external events, legal risk, model risk and ICT risk.
For Spain, the framework operates through CRR III + Law 10/2014 + Royal Decree 84/2015 + ECB/SSM supervision + Banco de España supervision, with DORA providing a complementary framework for digital operational resilience.
The key legal principle is therefore:
Operational-risk capital is the prudential capital response to operational risk; it does not replace the bank's obligation to prevent, manage and remediate that risk.
This distinction is especially important after CRR III and DORA became applicable, because capital adequacy and operational resilience now form two closely connected but legally distinct pillars of Spanish banking regulation.

comments