(27)
CRD6
in Article 85, paragraph 1 is replaced by the following: ‘1. Competent authorities shall ensure that institutions implement policies and processes to evaluate and manage exposures to operational risk, including risks arising from outsourcing arrangements and direct and indirect crypto-asset exposures and exposures to crypto-asset service providers, and to cover low-frequency high-severity events. Institutions shall articulate what constitutes operational risk for the purposes of those policies and procedures.’ ;
← (26) · All articles · (28) →
Source: EUR-Lex CELLAR · retrieved 2026-09-04 · Text as adopted (Official Journal); later amendments are not incorporated in this text.