BaFin - Navigation & Service

Stand:updated on 07.07.2020 | Topic Risk management Operational risk measurement approaches

Institutions can select from three approaches to calculate their capital requirement for operational risks. The requirements the institutions must meet are set forth in the Capital Requirements Regulation (CRR) and the Capital Requirements Directive (CRD IV). The CRR (for operational risk primarily Part Three Title III) and the Banking Act (KreditwesengesetzKWG) are directly applicable legislation in Germany.

Since 1 January 2007, institutions have been able to choose between the two more simple approaches, namely the Basic Indicator Approach and the Standardised Approach, when calculating their capital requirements. Since 1 January 2008, institutions have also been allowed to use advanced measurement approaches for their calculations. Until 31 December 2013, the German Solvency Regulation (SolvabilitätsverordnungSolvV) was applicable, which was – to a great extent – replaced by the CRR on 1 January 2014, which in turn is directly applicable to the institutions. The remaining parts of the new SolvV are now transposing the provisions of the CRD IV into national law.

Simple approaches

The two more simple calculation approaches are based on income statement items which form the relevant indicator. Under the Basic Indicator Approach, 15% of the three-year average of the relevant indicator equals the capital requirement, provided that the annual figures for the relevant indicator were positive for the last three years. Otherwise, only the positive annual figures for the relevant indicator are averaged with the number of positive years.

The Standardised Approach, on the other hand, is based on a more sophisticated methodology. Here, the relevant indicator must be mapped to eight regulatory business lines and multiplied by a percentage rate set for each business line (12%, 15%, 18%). These calculated partial capital charges for one year are then added together, whereby the negative values for business lines may be offset against the positive values for business lines within the year. The annual figures calculated in this manner represent the capital requirement by adding up the positive annual figures for the last three years and dividing them by three.
When using the Alternative Standardised Approach, the normalised income indicator may be determined using the relevant indicator to calculate the partial capital charges for certain business lines. This normalised income indicator is calculated by multiplying the total nominal amount of credits and loans and advances of the institution with a factor of 0.035.

Notification procedure when opting to use the Standardised Approach

The use of the Standardised Approach (TSA) is only subject to the notification requirement. The normalised income indicator, on the other hand, may only be used in the Alternative Standardised Approach as a special feature of the TSA upon application and subject to prior permission from the supervisors. Additionally, the use of the TSA always requires that certain qualitative requirements be met. The use of the Basic Indicator Approach is permissible without notifying the supervisors beforehand.

Advanced Measurement Approach

An Advanced Measurement Approach (AMA) may also be used to calculate the capital requirement for operational risk. The AMA stands for all methods of identifying, measuring, monitoring, reporting and treating operational risk. The institutions' AMA must pass an approval examination by the supervisors before it may be used.

Additional information

Did you find this article helpful?

We appreciate your feedback

Your feedback helps us to continuously improve the website and to keep it up to date. If you have any questions and would like us to contact you, please use our contact form. Please send any disclosures about actual or suspected violations of supervisory provisions to our contact point for whistleblowers.

We appreciate your feedback

* Mandatory field

Publications on this topic

Prepar­ing for DO­RA: “We’ve stepped it up a notch”

Companies in the financial sector have had to apply DORA since 17 January 2025. Jens Obermöller, Director-General of IT Supervision at BaFin, talks about how companies and supervisors have been preparing for the new rules – and what will happen next.

„A pal­pa­ble con­tri­bu­tion to­wards re­duc­ing bu­reau­cra­cy“

Small institutions can now benefit from additional simplified requirements in the area of risk management. That is thanks to a new supervisory statement published by BaFin. Chief Executive Director Raimund Röseler provides background information as well as some surprising insights.

Sim­u­lat­ing at­tacks to en­hance se­cu­ri­ty

Cyberattacks continue to pose a great risk to the financial industry. Special tests can simulate the tactics, techniques and methods of potential attackers. Which companies are required to undergo the tests?
By Hanno Burgau and Lucas Pausewang, BaFin IT Supervision

Trans­paren­cy en­sured by re­port­ing re­quire­ments

(BaFinJournal) Starting in January 2025, major ICT incidents will have to be reported to BaFin. What exactly is at stake here? What will happen with the reports? And what role will BaFin play? By Benedikt Queng and Michael Göddecke, BaFin IT Supervision

”Start get­ting ready for DO­RA now”

(BaFinJournal) Throughout Europe, companies in the financial sector are being called on to protect themselves more effectively against IT risk. Jan Kiefer from BaFin’s IT Supervision explains what this means for risk management.

All documents