Feature Operational Risk
The Basel III Endgame Re-Proposal Slashed Op Risk Capital. Here's What Your Operational Risk Program Still Has to Do.
On March 19, 2026, the Fed, OCC, and FDIC formally rescinded the 2023 Basel III proposal and issued a dramatically different re-proposal that delivers net capital relief after industry feedback identified operational risk as the single largest driver of inflated RWA. Here's what changed, what didn't, and what your op risk program needs to do before 2027 implementation.
Table of Contents
In July 2023, when the Fed, OCC, and FDIC released the original Basel III Endgame proposal, the operational risk component drew immediate fire. The American Bankers Association ran the numbers and concluded that operational risk capital alone accounted for roughly 78% of total RWA inflation for the largest US banks under the proposed framework. The reaction from industry was swift and sustained — testimony, comment letters, and one now-famous chart showing how the US proposal diverged sharply from international peers.
On March 19, 2026, the agencies formally rescinded the 2023 proposal and issued a fundamentally different re-proposal. The headline: aggregate bank capital is expected to modestly decrease under the new framework, compared to a roughly 16-19% CET1 increase under the original. Net capital relief of approximately $87.7 billion. Industry won the capital fight.
What they didn’t win — and what gets lost in the celebration — is this: your operational risk program still has to work. The calculation is simpler. The examiner isn’t.
TL;DR
- The March 19, 2026 Basel III re-proposal delivers net capital relief of ~$87.7B and formally rescinds the 2023 proposal’s operational risk treatment
- The Advanced Measurement Approach (AMA) is out; a standardized “business indicator” approach replaces internal models for Category I and II banks
- ABA had identified operational risk as ~78% of RWA inflation under the 2023 proposal — that pressure is resolved, but qualitative program expectations are unchanged
- Comment period ended June 18, 2026; finalization expected late 2026 with 2027 implementation — your data infrastructure needs work now
What the 2023 Proposal Got Wrong — and the March 2026 Fix
The 2023 Basel III Endgame proposal created a structural problem for large US banks: it required the largest institutions to use the Advanced Measurement Approach for operational risk, which calculated capital using internal loss data and risk models. The intended effect was precision — banks with mature risk programs and clean loss histories could theoretically demonstrate lower risk and therefore lower capital. The actual effect was massive upward pressure, because the proposed calibration produced capital requirements far above what AMA-derived internal models had previously generated.
The March 2026 re-proposal abandons that logic entirely. The new framework — applicable to Category I and Category II banking organizations under the Enhanced Risk-Based Approach (ERBA) — replaces internal models with a standardized methodology called the business indicator (BI) approach.
The BI approach calculates operational risk capital using a financial statement proxy that measures the volume of a bank’s activities across three component buckets:
- Interest, lease, and dividend income/expenses — capturing banking book activity
- Services income/expenses — capturing fee-based and operational activity
- Financial income/expenses — capturing trading and market-making volume
Banks cannot use internal models to argue below the standardized output. The formula is the formula.
Who This Actually Affects
The ERBA framework — and thus the new operational risk capital requirement — applies only to Category I and Category II banking organizations. Those are the eight US global systemically important banks (GSIBs) and the next tier of large international active banks above $700 billion in total assets or $75 billion in cross-jurisdictional activity.
Category III and IV banks face a different, simplified framework that is materially less burdensome than either the 2023 proposal or the March 2026 re-proposal. Community banks are largely unaffected by the operational risk capital changes.
If you work at a mid-size or regional bank, the capital mechanics may feel distant. But the supervisory expectations for your operational risk program — RCSA, loss data, scenario analysis, governance — are set by the same agencies issuing this re-proposal, and those expectations don’t have a Category I/II qualifier on them.
The Business Indicator Approach: What It Measures and What It Doesn’t
The business indicator is a better fit for a standardized framework than internal models, but it has a fundamental limitation: it measures volume, not risk quality. A bank with a higher BI component — more revenue, more activity — gets a higher capital charge regardless of how well-managed its operational risk program is.
That trade-off is intentional. The international Basel framework made the same move, prioritizing comparability and simplicity over model precision. US regulators are aligning with the international standard while calibrating the multipliers to avoid the overcharge that sank the 2023 proposal.
What this means in practice: the capital charge is now driven by the size of your balance sheet activity, not by the quality of your risk controls. Which means the quality of your risk controls becomes the exam question, not the capital formula input.
Examiners at the OCC and Fed who previously spent significant time stress-testing internal AMA models will shift scrutiny to qualitative program elements: Is your RCSA meaningful or checkbox? Do your KRIs actually indicate risk? Is loss data capture complete? Are scenarios being tested and refreshed?
What Examiners Still Expect
Regardless of where the final rule lands on capital, the baseline operational risk program requirements haven’t changed. Under the OCC’s Heightened Standards for large banks and the Fed’s supervisory expectations, Category I and II banks — and frankly any bank taking compliance seriously — are expected to maintain:
Risk and Control Self-Assessment (RCSA) The RCSA is still the core tool. It should cover your material operational risk exposures, map controls to risks, and document residual risk assessments that get revisited when the business changes. The move to a standardized capital formula doesn’t reduce examiner interest in whether your RCSA is operational or a once-a-year document exercise. If your RCSA process needs structure, our RCSA template is built for exactly this environment.
Loss Event Capture Loss events are still a supervisory priority. For Category I and II banks, loss data matters not just for the capital formula (historical losses factor into the BI coefficient for the largest banks) but for demonstrating program functionality. An examiner who asks to see your operational loss database and finds it incomplete — or finds that losses under a certain threshold are systematically not captured — has a clear program deficiency.
Scenario Analysis Regulators expect large banks to use scenario analysis to stress-test operational risk exposures beyond what historical data captures. Cyber incidents, fraud events, third-party concentration failures, and technology outages are all scenarios that should be documented, quantified, and reviewed at least annually. We’ve written about the operational risk implications of cloud concentration and about NACHA’s $10 million ACH limit increase — both of which create scenario-worthy exposure.
Governance and Board Reporting Who owns operational risk reporting to the board? What metrics go to the board vs. the risk committee vs. line management? Examiner questions on operational risk governance are among the most common MRA triggers at large banks. A clear RCIF (Operational Risk Governance Framework) that documents ownership, escalation, and reporting cadence is not a nice-to-have.
The Timeline: What Needs to Happen Before 2027
The comment period on the March 2026 re-proposal closed June 18, 2026. Comments were submitted. Final rulemaking is expected before year-end. Implementation — including transition provisions — is projected to begin in 2027.
For Category I and II banks, that window is short.
| Priority | Action | Timing |
|---|---|---|
| Loss data | Audit completeness; close capture gaps below threshold | Now |
| RCSA | Run a gap assessment against the regulatory operational risk taxonomy | Q4 2026 |
| Scenario analysis | Calibrate top 5-10 scenarios; update for cyber and third-party concentration | Q4 2026 / Q1 2027 |
| BI component mapping | Work with finance to map revenue streams to the BI methodology | Now |
| Governance | Document and test board/risk committee reporting structure | Q4 2026 |
| Model inventory review | Understand which operational risk models will be deprecated vs. retained | Now |
For firms tracking how model risk management guidance applies alongside operational risk frameworks, the SR 26-2 model risk management update is relevant context — especially if your AMA models or op risk scenario tools run through your model inventory.
The Irony of Winning the Capital Fight
Here’s the counterintuitive situation: banks spent three years lobbying against the 2023 Basel III Endgame’s operational risk treatment. They won. The capital charge is lower. The business indicator methodology is simpler. And now examiners will have more time to focus on the program behind the number.
Banks that used the AMA model as a demonstration of program sophistication — and de-emphasized the qualitative framework because the model carried the weight — are exposed. A lower capital charge calculated by a standardized formula is not a sign that the program can atrophy. It’s an invitation for examiners to look behind the math.
The institutions that do well in examinations post-implementation will be the ones that used the 2024-2026 period to strengthen loss data infrastructure, refresh RCSA programs, and document governance clearly — not just the ones that celebrated the re-proposal and waited for the final rule.
So What?
If you work at a Category I or II bank: The March 2026 re-proposal is good news on capital, but your workload in op risk is unchanged. Use the finalization window — late 2026 — to complete your BI component mapping with finance, audit loss event capture completeness, and calibrate your scenario analysis to the top emerging risk themes (cyber, AI-related failures, payment fraud at higher ACH limits, cloud concentration). Do not let the capital relief reduce examiner readiness.
If you work at a Category III or IV bank: The ERBA framework doesn’t apply to you, but examiners at the OCC and Fed are reviewing op risk program quality across all size tiers. The same program elements — RCSA, loss data, scenario analysis, governance — appear in exam findings at mid-size banks constantly. Use this period to assess whether your program would hold up to the same scrutiny being applied at larger institutions.
If you’re newly responsible for op risk and inherited a program: Read the March 2026 re-proposal’s operational risk section and the Freshfields 8-key-takeaways summary. Map your existing program against the categories in the proposal. Then find the gaps before an examiner does.
The capital number will be set by a formula. Whether your bank is ready for 2027 implementation — and ready for the examiner who follows — is a program question.
Sources: Sullivan & Cromwell, Banking Agencies Release Basel III GSIB Surcharge Revised Standardized Approach Proposals (March 2026) | Freshfields, Basel III Endgame Take Two: 8 Key Takeaways (2026) | Holland & Knight, US Banking Agencies Propose New Rules to Reduce Regulatory Capital Requirements (June 2026) | PwC, Capital Reform 2026: Basel III Endgame and More
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
RCSA (Risk & Control Self-Assessment)
141 pre-populated fintech risks with control assessments, questionnaire framework, and testing calendar.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What did the March 2026 Basel III Endgame re-proposal change for operational risk capital?
What is the business indicator approach and how does it differ from the Advanced Measurement Approach (AMA)?
Which banks are subject to the new operational risk capital requirements?
When will the Basel III Endgame final rule be issued and when does implementation begin?
Does a lower operational risk capital charge mean my op risk program can do less?
What should operational risk teams be doing right now while the final rule is being finalized?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
RCSA (Risk & Control Self-Assessment)
141 pre-populated fintech risks with control assessments, questionnaire framework, and testing calendar.
◆ Keep reading
Related posts.
Operational Risk
New Silicon Valley Bank Review: The Seven Supervisory Failures Risk Teams Should Fix
The new Silicon Valley Bank review says supervisors saw risks but failed to act. Here is how banks can repair escalation and decision rights.
Sep 19, 2026
Operational Risk
NACHA Just Approved a $10 Million Same Day ACH Limit. Your Fraud Controls Were Built for $1 Million.
NACHA approved a $10 million per-transaction limit for Same Day ACH in April 2026, effective September 2027. That's a 10x increase from the current $1 million cap. Most financial institution fraud controls, velocity limits, and risk-based monitoring thresholds weren't built for that exposure. Here's what needs to change before the September 2027 effective date.
Sep 13, 2026
Operational Risk
FinCEN Hit UBS With a Record $125 Million 'Willful' BSA Fine — and FINRA Added $20 Million More. What the Double-Barrel Enforcement Action Means for Your AML Program.
FinCEN's $125 million penalty against UBS Financial Services — the largest BSA fine ever imposed on a broker-dealer — combined with FINRA's simultaneous $20 million fine creates a $145 million enforcement landmark. Both actions trace back to the same root cause: UBS knew its transaction monitoring had gaps, promised to fix them after a 2018 settlement, and didn't. Here's what 'reasonably designed' AML monitoring actually requires.
Sep 8, 2026