Guidelines for common procedures and methodologies for the supervisory review and evaluation process (SREP) and supervisory stress testing
EBA/GL/2026/06 26 June 2026
Final Report
Guidelines (revised) on common procedures and methodologies for the supervisory review and evaluation process (SREP) and supervisory stress testing under Directive 2013/36/EU
Executive Summary
The EBA, pursuant to Article 107(3) of Directive 2013/36/EU (CRD), has been mandated to develop guidelines promoting common procedures and methodologies for the supervisory review and evaluation process (SREP). The SREP is the core supervisory process that consolidates findings from all supervisory activities into a comprehensive assessment of an institution. The guidelines, addressed to competent authorities, also aim to harmonise supervisory stress testing across the EU in accordance with Article 100 of Directive 2013/36/EU.
Since the issuance of the previous SREP Guidelines, the regulatory framework has evolved considerably. The ‘banking package’ (Directive (EU) 2024/1619 and Regulation (EU) 2024/1623), together with other legislation such as the Digital Operational Resilience Act – DORA (Regulation (EU) 2022/2554) and the IRRBB/CSRBB package, have substantially upgraded the regulatory and supervisory landscape. At the same time, nearly ten years of the SREP implementations, dedicated peer reviews and lessons from past financial market turmoil have highlighted areas where the SREP framework can be further streamlined and improved.
Against this backdrop, the update of the SREP Guidelines became necessary to integrate regulatory changes, reflect nearly a decade of supervisory experience, and ensure simplification while preserving their core objectives and structure.
Therefore, the revised guidelines consolidate all relevant SREP provisions into a single, comprehensive framework, retaining the core elements while integrating new aspects such as ESG factors, operational resilience, third-country branches and clarifications on the interaction between the revised Pillar 1 and Pillar 2 capital requirements, including the output floor. They also repeal the separate ICT SREP Guidelines (EBA/GL/2017/05) as the ICT risk assessment has been integrated into the revised guidelines to ensure consistency and foster simplification. In addition, this revision enhances the proportionality, sequencing, and effectiveness of the supervisory process, taking into account institutions’ track record in addressing deficiencies. Overall, the revised guidelines aim to strengthen supervisory convergence across the EU, improve clarity, and ensure the SREP remains fit for purpose in light of both regulatory developments and supervisory experience.
These guidelines also fulfil the mandates under Article 48n(6) of Directive (EU) 2024/1619 to issue guidelines on the SREP for third-country branches, and under Article 104a(7) of the same Directive to issue guidelines to operationalise the requirements where an institution becomes bound by the output floor.
Next steps
The revised guidelines will be translated into the official EU languages and published on the EBA website. The deadline for competent authorities to report whether they comply with the guidelines will be two months after the publication of the translations. Upon application of the revised guidelines, the existing SREP Guidelines (EBA/GL/2022/03) and the Guidelines on ICT risk assessment under the SREP (EBA/GL/2017/05) will be repealed and replaced. The revised Guidelines will apply from 1 January 2027.
Background and rationale
1. The EBA is mandated to foster sound and effective supervision and to drive supervisory convergence across the EU arising from the requirements under the CRD and more generally from its obligations under its founding regulation. The SREP is the core supervisory process through which competent authorities form a comprehensive view on the risk profile of the institutions, as well as on their overall viability and sustainability, and it may impose adequate supervisory measures to ensure material risks are properly addressed.
2. Article 107 of the CRD mandates the EBA to draft guidelines for competent authorities, specifying the common procedures and methodologies for the SREP and for the assessment of the organisation and treatment of risks referred to in Articles 76 to 87a of the CRD, in a manner that is appropriate to the size, structure and internal organisation of institutions, and to the nature, scope, and complexity of their activities. Additionally, Article 100(2) of the CRD empowers the EBA to issue guidelines to ensure that common methodologies are used by competent authorities when conducting annual supervisory stress tests for SREP purposes.
3. Based on those mandates, the EBA’s primary objective for these guidelines is establishing consistent, efficient and effective supervisory practices and application of European Union law throughout the EU so that institutions with similar risk profiles, business models and geographic exposures are subject to broadly equivalent supervisory expectations, actions and measures, where applicable, including institution-specific prudential requirements. To achieve this objective, in addition to specifying the SREP procedures and methodologies, these guidelines also provide guidance for setting subsequent supervisory measures that competent authorities should consider.
4. The first version of the guidelines was published in 2014 (entering into force on 1 January 2016). A subsequent upgrade was published in 2018 as part of the EBA Pillar 2 Roadmap to incorporate P2G and supervisory stress test elements (and has been applied since 1 January 2019). The last update was carried out in 2021 to account for the changes brought by Directive (EU) 2019/2034 (CRD V), provisions with regards to, inter alia, the introduction of the assessment of the risk of excessive leverage (P2R-LR and P2G-LR), the revision of the methodology for the P2G determination and the cooperation with AML/CFT supervisors (and has been applicable from 1 January 2023).
5. This third review aims to align the guidelines with regulatory developments that have taken place since their latest revision. In particular, these revised guidelines take into account changes stemming from Directive (EU) 2024/1619 (CRD VI) amending Directive 2013/36/EU, Regulation (EU) 2024/1623 (CRR III) amending Regulation (EU) No 575/2013 and Regulation (EU) 2022/2554 (DORA), as well as the issuance by the EBA of other relevant guidelines and technical standards. At the same time, this review takes stock of nearly ten years of the SREP implementation, dedicated peer reviews and lessons from past financial market turmoil which have highlighted areas where the SREP framework can be further streamlined and improved. It is clarified that these guidelines are addressed to the competent authorities of credit institutions and of investment firms , in relation to the investment firms referred to in Article 1(2) and (5) of Regulation (EU) 2019/2033, which are supervised for compliance with prudential requirements under Directive 2013/36/EU and Regulation (EU) No 575/2013.
6. In particular, a key objective of this review is to enhance the readability and use of the guidelines, while at the same time supporting a risk-focused supervisory approach. This approach is considered more suitable for the current, more mature stage of the SREP, which requires more targeted and focused guidance compared to the one originally developed in 2014. The simplification effort was carried out mainly through the following steps: a. Streamlining the text with focus on core assessment. The emphasis remains on the key areas to be assessed, while references to outdated provisions or assessments already set out in other legal acts have been removed (these are now listed in a separate document aiming to enhance transparency, support proportionality, and ensure that SREP assessments remain anchored in existing requirements rather than creating new obligations). b. Establishing a single, comprehensive set of SREP Guidelines. The previous SREP Guidelines were complemented by a separate set ICT risk assessment (ICT SREP Guidelines – EBA/GL/2017/05). In addition, the CRD VI requires the EBA to issue SREP Guidelines for thirdcountry branches, as well as guidelines specifying how to operationalise cases in which an institution becomes bound by the output floor. All of these elements are now integrated into this revised set: the ICT SREP Guidelines will be repealed and the ICT risk assessment provisions are integrated in Title 6 under the operational risk assessment; new guidance for third-country branches has been added as a Title 12; and the considerations on the output floor – drawing on the relevant EBA Opinion – have been integrated into Title 7. c. Incorporating new aspects into existing SREP elements. As further explained in the subsequent paragraphs, new cross-cutting dimensions – such operational resilience and environmental, social and governance (ESG) risk factors – have been integrated across the existing SREP elements, rather than being introduced as a separate element or independent risk categories.
7. The cyclical nature of the SREP assessment requires that the overall framework is applied at the start of a SREP cycle. Since the SREP cycle often corresponds to a calendar year, these guidelines will apply from 1 January 2027, following the consultation period and the publication of the final version. However, competent authorities are encouraged to take revised guidance into account, and where possible, to introduce its elements at an earlier stage. The general SREP framework is built around the following major components (as presented in figure 1):
8. As illustrated in figure 1, the well-established SREP framework – in place since 2016 – has not been materially altered by this review. Experience has shown that its core elements are well embedded in the ongoing supervisory practices and provide a solid basis for supervisory dialogue. The SREP is based on information gathered through the full range of supervisory activities (e.g. on-site inspections and off-site supervisory activities). When performing their assessments, competent authorities should use available information sources as outlined in paragraph 124. In this spirit, the introduction of few new elements (through this revision) keeps the overall framework valid and up to date. Subsection ‘3.1 The general SREP framework’ provides an overview of the different elements of the framework as well as a summary of the new aspects introduced through this review. The dedicated subsection ‘3.2 Cross-cutting and more general elements’ addresses in greater detail the cross-cutting and overarching elements – such as the scoring framework, supervisory effectiveness, operational resilience, ESG risks, SREP for third-country branches, and the link with other relevant processes – and explains their underlying rationale.
3.1 The general SREP framework
Categorisation of institutions and application of the principle of proportionality
9. The application of the principle of proportionality in the SREP is anchored in the categorisation of institutions, which defines the minimum level of supervisory engagement, modulating the frequency of assessments and shaping the supervisory dialogue both for individual SREP elements and for the overall SREP outcome. As proportionality lies at the core of supervisory engagement, the revised guidelines – drawing on supervisory experience in SREP implementation and on the peer review on proportionality under the SREP – aim to foster riskfocused supervision and a more efficient use of supervisory resources. 10.To this aim, enhanced flexibility in identifying the appropriate supervisory engagement coexists with the retention of the existing four categories of institutions defined by size, systemic importance, scale, nature, and complexity of activities. Categories 1 and 4 continue to follow the CRR definitions of ‘large institutions’ and ‘small and non-complex institutions’. Retaining the categories is essential to ensure a common understanding of materiality, consistent treatment across the EU, and effective supervisory dialogue, particularly in cross-border cases. These categories also serve as a benchmark for assessing supervisory convergence ex-post. 11.Competent authorities will continue to categorise all institutions under their remit for SREP purposes, while applying the following principles: a. Categorisation may be applied at group or individual entity level as appropriate (e.g. assigning different categories to subsidiaries and/or to the consolidated entity, where justified). b. The supervisory approach should be tailored to the risk profile of each institution and to emerging risks. This is consistent with a multi-year SREP approach where in-depth assessments of selected risks or risk factors are planned over a longer (multi-year) period. c. Despite of the assigned category, lighter reviews of SREP elements or risk areas that are deemed immaterial or not relevant in the context of the current risk profile of the institution may be undertaken where risks have been assessed as unchanged vis-a-vis the previous SREP cycles. d. Institutions may be reassigned to a lower or higher category to better reflect their risk profile and business model or supervisory needs. This refinement fosters risk-focused supervision and a more efficient use of supervisory resources. 12.As an additional element of proportionality, large institutions (under the CRR) that are not G- SIIs may be allocated to Categories 1, 2 or 3 depending on their business model and risk profile. The revised guidelines provide for an extension of the minimum frequency for the assessment of all SREP elements from three to five years for a subset of Category 4 institutions, provided they maintain a stable low-risk profile, sound financial metrics and healthy margins, and quarterly monitoring does not raise material concerns. Competent authorities retain discretion to increase the frequency of engagement whenever warranted. Monitoring of key indicators 13.Regular monitoring of key quantitative and qualitative indicators supports the SREP by flagging changes in the institution’s financial conditions and risk profile. Such monitoring should prompt updates to the assessment of the SREP elements as new material information arises. This revision has not introduced major changes to this Title apart from integrating DORA-related indicators in the competent authorities’ monitoring systems and ensuring appropriate review and update of monitoring indicators and tools by the competent authorities. Business model analysis (BMA) 14.Without undermining the responsibility of the institution’s management body for organising and running its business, the supervisory business model analysis should assess both the viability of the current business model and the sustainability of the strategic plans. This analysis should also help identify key vulnerabilities that may not be captured by other elements of the SREP, including those arising from ML/TF, ICT and ESG risks. 15.One of the main changes introduced by this review is that this Title now explicitly focuses on the most material areas of assessment for an institution’s business model. It also explicitly enables the use of prior supervisory assessments as a baseline where no material changes have occurred since the previous SREP cycle, provided materiality is duly assessed. The BMA now also includes reference to climate-related and other environmental risks, as well as the institution’s capacity to ensure medium- to long-term resilience to ESG risks, operational resilience, and the ability to withstand geopolitical risks. Although addressed only at high level in the guidelines, these elements are nonetheless expected to form part of an institution’s overall BMA, serving to complement the more traditional drivers and to enrich the supervisory assessment in this area. Additionally, these elements are expected to also inform the assessment of other SREP elements, such as risks to capital and risks to liquidity and funding, always with a view to ensuring complementarity and avoiding duplication. Assessment of internal governance and institution-wide controls 16.As part of the overall governance assessment, competent authorities should determine whether the internal governance framework of an institution is adequate given its risk profile, size, nature and complexity, and whether the institution sufficiently adheres to the requirements and standards of good internal governance and risk controls arrangements, including aspects such as diversity, non-discrimination and sound code of conduct. 17.As part of the risk management framework, competent authorities should review the institution’s internal capital adequacy assessment process (ICAAP) and internal liquidity adequacy assessment process (ILAAP). The assessment should focus on the soundness, effectiveness and comprehensiveness of these processes, and on the reliability of the institution’s internal estimates to support the supervisory determination of capital and liquidity adequacy. Furthermore, competent authorities should also assess the adequacy of institutions’ stress testing programmes, including scenarios and assumptions, and their outcomes. 18.The main changes introduced in this Title relate to the integration of the DORA framework and the third-party risk management framework within the institutions’ overall risk management framework, for which supervisors should evaluate compliance with DORA for the ICT services received from ICT third-party providers and with the EBA Guidelines issued pursuant to Article 74(3) of Directive 2013/36/EU for the non-ICT services received from third-party providers. These changes also relate to the importance of institutions’ risk data aggregation and risk reporting capabilities through ICT systems, also reflecting BCBS principles where applicable. Business continuity management aspects have been grouped under Title 6.4 to better reflect the latest BCBS principles and the DORA framework. Moreover, related CRD VI changes have been reflected regarding the institutions’ statements of responsibilities and mapping of duties as well as the management body’s knowledge and skills on ESG and ICT risks. Lastly, the institution’s ability to effectively and timely remedy the deficiencies identified and/or supervisory concerns is evaluated by competent authorities, as part of the overall assessment of internal governance and institution-wide controls, in an effort to promote supervisory effectiveness. Assessment of risks to capital 19.The SREP Guidelines provide guidance for the assessment of the most common risks to capital, encompassing credit and counterparty risk, market risk, operational risk and interest rate and credit spread risk from non-trading activities (IRRBB and CSRBB), further split into risk subcategories. Competent authorities should focus their assessment on the material risks the institution is or might be exposed to, including any additional institution-specific risks that are not described in detail in the guidelines. The assessment should be performed in terms of the risk exposure, as well as the quality of management and controls employed to mitigate the impact of the risk. 20.The market risk section now includes an approach to ensure the capital adequacy of subsidiaries of third-country groups subject to transfer pricing arrangements envisaging the redistribution of market risk losses from other third-country group entities. Competent authorities should assess the materiality of the impact of these arrangements and set additional own fund requirements under Pillar 2 to address this risk. To support competent authorities in this assessment, the approach includes a quantitative formula to measure the risk. 21.The methodologies and internal processes for identification, measurement, monitoring and control of IRRBB are subject to the SREP as part of the risks to capital. In addition to covering IRRBB, the scope of Title 6.5 has been extended to also provide guidance for the assessment of CSRBB. The addition was made in view of the increased relevance of this risk type, in line with the EU legislative framework and the BCBS Standards. The additional provisions on CSRBB are proportionate and adapted to reflect the less mature stage of this risk compared to IRRBB while still providing meaningful guidance to competent authorities. Competent authorities should reflect the outcome of the CSRBB assessment in a combined IRRBB/CSRBB score. 22.This review provides a non-exhaustive breakdown of risks to capital into sub-categories, included in the Annex, to support a risk-based and proportionate supervisory approach. This intends to further promote consistent risk identification across jurisdictions, while remaining non-exhaustive and flexible, hence not limiting the scope of supervisory assessment. Moreover, the assessment of ESG elements has been integrated into the existing risks to capital and similarly, operational resilience has been incorporated into the internal governance and operational risk sections. SREP capital assessment 23.Since an institution may face risks that are not covered or not fully covered by the own funds requirements in accordance with the CRR or the capital buffers specified in the CRD, the SREP Guidelines include guidance on the determination of the quantity and composition of additional own funds requirements (P2R) determined to cover such risks, emphasising their institutionspecific nature. As a separate stack of own funds requirements, the SREP Guidelines also include guidance on the assessment of the risk of excessive leverage and on the determination of the quantity and composition of additional own funds required to cover that risk (P2R-LR). 24.Where the outcomes of the relevant stress tests suggest that an institution may not be able to meet the applicable own funds requirements under stress conditions, or is excessively sensitive to the assumed scenarios, competent authorities should take appropriate supervisory measures to ensure the institution is adequately capitalised, including the imposition of guidance on additional own funds, separately, to address the risk of excessive leverage and other risks (P2G- LR and P2G). 25.To increase convergence and level the playing field between institutions, the SREP Guidelines specify the quality of capital competent authorities should require institutions to hold to meet their guidance on additional own funds, CET1 capital for P2G coverage, and Tier 1 for P2G-LR coverage, respectively. 26.In light of the overhaul of the Level 1 provisions under the banking package on the Pillar 1 framework to implement the revised Basel standards , the guidelines have been updated to reflect the interaction between Pillar 1 own funds requirements (P1R) and P2R, as well as the introduction of the output floor . 27.In general, as an operationalisation of the CRD requirement under Article 104a(1), the guidelines foresee that – when a relevant change in the regulatory framework for determining P1R has, or is expected to have, material impact on an institution’s capital profile – competent authorities are expected to assess this impact in terms of its interplay with the relevant P2R. The objective of this assessment is to ensure that the complementary nature of P1R and P2R components is preserved (i.e. that P2R addresses only those risks, or elements of risk, that are not covered or not sufficiently covered by P1R). Based on its outcome, this assessment may lead to a redetermination of the level or composition of the P2R, either within the annual SREP cycle or at an adjusted frequency. This assessment is intended to ensure that the P2R remains appropriately calibrated to the institution’s risk profile in the event of changes in TREA dynamics (both upward and downward) arising from relevant changes to the P1R regulatory framework, including potential recurring material impact of the output floor. 28.More specifically when an institution becomes bound by the output floor, the guidelines set out how its interaction with P2R should be operationalised, thereby fulfilling the mandate in Article 104a(7) of the CRDVI. The provisions reflect those set out in the previously referenced EBA/Op/2025/01. Assessment of liquidity and funding risks and SREP liquidity and funding assessment 29.The SREP Guidelines provide guidance for the assessment of the risks to liquidity and funding the institution is or might be exposed to over various time horizons, as well for the related risk management controls. Competent authorities should focus their assessment on risks identified as material for the institution. 30.Competent authorities should determine whether the liquidity resources held by the institution ensure an appropriate coverage of risks to liquidity and funding, where applicable, taking adequate supervisory measures. Among such measures, competent authorities may consider imposing specific liquidity requirements to address concerns related to the institution’s liquidity and funding resources. 31.The guidance on the assessment of risks to liquidity and funding and on the liquidity adequacy assessment were merged into one Title (Title 8) in view of their strong interlinkage. The incorporation also resulted in the merger of the scores combining the liquidity and funding risk assessment scores and liquidity adequacy score into one overall liquidity and funding adequacy score. This provides for a more streamlined approach. In particular, under the proposed approach the assessment of liquidity risk already encompasses the consideration of the amount and quality of liquidity available to mitigate the risk, and there is a combined assessment of the risk management and control framework addressing both liquidity risk and funding risk. The resulting liquidity and funding adequacy score should reflect the supervisory view of the capacity of the institution’s liquidity resources to mitigate/cover the risks to liquidity and funding. Overall SREP assessment and communication 32.Having conducted the assessment of the above SREP elements, competent authorities should form a comprehensive overview of the risk profile and viability of the institution concluding with the overall SREP assessment. As part of the effort to enhance supervisory effectiveness (see next section) the revised guidelines introduce a dedicated section devoted to the communication of the SREP assessment, comprising of all the relevant information that competent authorities are expected to share, in accordance with the SREP engagement model, with institutions as a basis for an enhanced supervisory dialogue. 33.Although conceptually related to the overall SREP assessment, the consideration on any necessary supervisory measures to address concerns emerged by the SREP has been moved from this Title to the specific assessment areas (e.g. BMA, governance and institution-wide controls, risks to capital and risks to liquidity and funding) to directly link them with the relevant assessment areas. This aims to enhance the relevance of supervisory measures and hence supervisory effectiveness.
3.2 Cross-cutting and more general elements
Scoring framework
34.To help facilitating communication with the competent authorities and colleges of supervisors, foster comparability and a level playing field across institutions as well as to adequately prioritise supervisory resources and measures in the assessment of SREP elements, competent authorities should score from a range of ‘1’ (low risk) to ‘4’ (high risk), to reflect the supervisory view for each element-specific title of the guidelines. Scores should be assigned based on supervisory judgement, taking into account the considerations outlined in the tables at the end of each relevant section and title of these guidelines.
35.In this regard, the revised guidelines explicitly clarify that, while these considerations serve as a common baseline for assigning scores, they should not be interpreted as a mechanical checklist to be completed for each element, nor should they be seen as establishing a hierarchy of importance among the elements. Instead, they are intended to guide competent authorities in assigning scores by considering the interplay and relevance of the different elements within the specific dimension of the institution being assessed. More granular scores (such as qualifiers) can be also assigned by competent authorities for their internal purposes, provided that these are consistent with the overarching scoring framework set out in these guidelines. Competent authorities are also encouraged to use the full range of available scores to differentiate institutions and avoid undue clustering.
Supervisory effectiveness
36.Past supervisory experience and recent financial market turmoil events have further underscored the need for supervisors not only to anticipate and detect, at an early stage, potential deficiencies that could threaten institutions’ financial soundness, but also to intervene promptly and decisively to ensure their timely remediation. As a way of drawing on these experiences and lessons learned, and with a view to strengthening supervisory effectiveness and establish a high-level common framework across the EU, the revised guidelines introduce targeted provisions in the following areas: a. a high-level and flexible escalation framework for supervisory measures; b. a non-exhaustive list of supervisory measures based on the specific SREP elements and subelements, building on the supervisory powers set out in the CRD; c. the ability and willingness of institutions to remedy identified deficiencies or supervisory concerns in an effective and timely manner; d. communication concerning the outcome of the SREP.
37.The escalation framework, illustrated in figure 2, is designed to assist competent authorities in selecting the most appropriate supervisory measures in light of identified deficiencies. Within this framework, competent authorities are expected to focus on the root causes of deficiencies, reflect them in the scores assigned under these guidelines, and use such root causes as the basis for subsequent supervisory decisions and measures. While particularly relevant to the SREP, the escalation framework is conceived as an overarching structure applicable to all supervisory activities and capable of extension beyond the SREP. The framework is characterised by the following features: a. high-level: it does not prescribe binding or automatic measures to be applied to specific deficiencies. The type, scope, depth and level of detail of the measures remain at full discretion of the competent authorities, depending on the nature of the findings and on what constitute the most effective means of remediation. b. flexible: supervisory measures are not strictly sequential. Competent authorities may escalate or de-escalate measures, as appropriate, in light of the specific circumstances.
38.Supervisory effectiveness also depends on the capacity/ability and willingness of institutions to respond adequately to supervisory measures; hence these should form part of the competent authorities’ assessment of internal governance and institution-wide controls.
39.The guidelines also reinforce transparency and communication regarding SREP outcomes. All relevant expectations for competent authorities regarding the communication related to the SREP have been now rationalised and grouped into a single Title. These expectations include, beyond the indication of material risk drivers supporting any additional own funds requirement (P2R and P2R-LR) that should be duly justified to institutions, a description of the overall outcome of the SREP, including a summary of the assessment and the overall SREP score. Furthermore, in line with the principle of risk-based supervision, where appropriate and depending on the specific remedial action required, competent authorities may disclose to institutions the SREP scores for relevant elements or sub-elements.
ESG
40.In line with the increased prominence of ESG risks in the financial sector – and, in particular, with the requirement under Article 98(9) of the CRD to include in the SREP an assessment of institutions’ governance and risk management processes for addressing ESG risks, as well as their exposures to such risks – the guidelines specify how competent authorities should take ESG risks into account in the SREP.
41.Since ESG risks materialise through the traditional categories of financial risks and should be managed as part of institutions’ core business strategy, governance arrangements and risk management framework, they are integrated across the existing SREP elements rather than treated as separate or stand-alone category of risk in a separate module.
42.This approach enables competent authorities to assess the prudential impact of ESG risks within the established SREP framework, including in the assessment of the business model, the assessment of internal governance and institution’s wide controls and risks to capital, liquidity and funding. At the same time, the guidelines acknowledge that competent authorities may adopt a gradual approach to the assessment of ESG risks, initially prioritising environmental factors and progressing to other sustainability factors while recognising the greater capacity to quantify climate-related risks compared to other types of environmental risks. Competent authorities should seek to progressively enhance supervisory practices as data availability, methodologies and analytical tools evolve, including with a view to advancing supervisory assessment of all types of environmental risks and gradually broadening the scope to social and governance risks.
43.Acknowledging the specific characteristics of climate-related and other environmental risks, the supervisory treatment of these risks should take into account both the high likelihood that environmental risks will increasingly materialise going forward, through different possible combinations of transition and physical risks, and the uncertainties in the timing, severity and distribution of future risks, particularly when considering long-term horizons. From this perspective, the guidelines now also refer to the integration of environmental risks into supervisory stress testing, in accordance with the Joint ESAs Guidelines on this topic , recognising that stress testing and scenario analysis are important tools to understand and assess institutions’ resilience to environmental risks, given their forward-looking nature and high level of uncertainty. Competent authorities may apply supervisory measures to strengthen institution’s management of ESG risks, including adjustments to prudential plans, where this could have a material impact on the institution’s stability or solvency.
Operational resilience
44.The concept of operational resilience has become prominent at the EU and international level due to the increase in cyber threats, supply chain disruptions and financial system interdependencies that can expose institutions to systemic risks. Operational resilience is an integral objective of the sound governance arrangements and effective internal control mechanisms required pursuant to Article 74 of Directive 2013/36/EU (CRD). The emphasis ensuring the continuity of critical or important functions, and in parallel maintaining financial stability, is also reflected in the DORA framework, as well as in the latest BCBS principles on operational resilience, the sound management of operational risk and third-party risk management. The ability to ensure such continuity could enable an institution, either directly or indirectly including through the use of third-party services to identify and protect itself from threats and potential failures, to respond and adapt to, as well as recover and learn from disruptive events in order to minimise their impact on the delivery of critical or important function through disruption. It is therefore necessary to introduce the concept of operational resilience within the SREP framework as its key components are already evaluated through the existing EU regulatory framework and embedded in the existing SREP framework. It is further clarified that within the EU regulatory framework, ICT risk is part of operational risk, and DORA strengthens its prudential treatment through digital operational resilience requirements; together, these contribute to the broader objective of operational resilience.
45.To this end, consistently with the treatment of other cross-cutting elements, such as ESG risks, and in line with the overarching objectives of simplification and rationalisation pursued in the revised guidelines, operational resilience is integrated within the SREP framework rather than developed as a stand-alone module. This does not aim to introduce a new framework, nor to introduce duplicative reporting or testing beyond those already established under the applicable EU regulatory framework. Rather, these Guidelines seek to ensure that operational resilience integrates and builds upon areas already covered and assessed in EU banking supervision, including internal governance and controls, operational risk management, ICT risk management, third-party risk management and business continuity management.
SREP for third-country branches
46.In view of the significant and increasing presence of third-country branches in the EU, the CRD VI establishes a prudential framework setting out common requirements for third-country branches (TCBs) and facilitating the effective and comprehensive supervision of the activities of third-country groups in the EU. Under the new framework, competent authorities shall evaluate whether the governance arrangements implemented by TCBs and the capital endowment and liquidity held by them ensure a sound management and coverage of their material risks. In addition, the EBA is mandated with the development of Guidelines setting out common procedures and methodologies for this SREP for TCBs. The SREP Guidelines for TCBs are incorporated as a separate title in the SREP Guidelines (Title 12) allowing cross-references to other relevant parts of the Guidelines, while ensuring that the assessment is sufficiently tailored and proportionate to the specific nature of TCBs.
47.In particular, the SREP should be conducted with a level of frequency and intensity that is proportionate to the classification of TCBs as class 1 or class 2 under CRDVI Article 48a reflecting the nature, scale and complexity of the activities. Competent authorities should assess the business model, internal governance arrangements and controls, booking arrangements and the capital endowment and liquidity of the TCB (the SREP elements for TCBs). Recognising the status of the branch and its reliance on the third-country parent, competent authorities should also assess whether the TCB has sufficient independence in its governance and risk management to act in the best interests of the branch, safeguarding its safety, soundness and viability. The outcome of the assessment feeds into the overall viability score of the TCB. Unlike the overall SREP score for institutions, the scoring table for TCBs does not provide a score ‘F’ for TCBs considered as ‘failing or likely to fail’ as, while TCBs are in scope of Directive 2014/59/EU (BRRD) with some specific conditions, they cannot be subject to ‘failing or likely to fail’ under BRRD Article 32(4).
Link between SREP and other supervisory processes
48.Competent authorities should reflect in the SREP assessment the available information and outcomes from other supervisory activities, including on-site inspections, approvals of internal models, authorisation approvals, outcomes of supervisory stress testing, assessment of recovery and resolution plans, market conduct and consumer protection activities, AML/CFT activities, etc. Likewise, the findings from the SREP assessment should inform other supervisory processes.
49.The revised guidelines further stress the importance for competent authorities to consider the SREP as the process integrating all outcomes of their activities during the supervisory cycle. This aims to streamline the supervisory process, allow the reallocation of resources to the most relevant risk areas and ensure that consistent feedback is given to institutions throughout the different supervisory tasks. In particular, in light of the significant efforts undertaken – and the progress achieved – in recent years in the area of recovery planning, both by institutions and competent authorities, the linkage between recovery planning outcomes and the SREP framework has been made more explicit, with the aim of fostering a stronger risk management continuum between ongoing supervision and crisis preparedness.
50.In the revised guidelines, the outcome of the recovery planning assessment – in addition to its role in the assessment of governance and institution-wide controls – also informs the assessment of capital and liquidity adequacy through the overall recovery capacity (ORC). The ORC provides an indication of an institution’s overall ability to restore its financial position following a material deterioration in its financial condition in severe stressed scenarios.
51.More specifically, the ORC has been included as one of several informative elements to be considered by competent authorities when assigning SREP scores for capital and liquidity adequacy under Title 7 and Title 8. Its inclusion is intended to provide an additional forwardlooking perspective in the supervisory assessment of institutions’ capital and liquidity profiles, particularly regarding their resilience and potential recoverability through the implementation of recovery options under stress conditions. This inclusion is intended to be applied flexibly and
does not imply a mechanistic or automatic correlation between the ORC scores and SREP scores for capital or liquidity adequacy. Rather, it forms part of a broader set of factors that can inform the capital and liquidity adequacy scoring process, without constraining the outcome of the supervisory assessment in this area.
52.These guidelines also identify the relevant building blocks required for an effective supervisory stress testing programme. They focus on different forms of supervisory stress testing and objectives, the respective use for SREP purposes, aspects related to the organisation, resources and communication, and possible methodologies. In particular, the supervisory stress testing section complements the assessment on capital adequacy by further clarifying and operationalising procedures for setting P2G and P2G-LR.
Link between SREP and assessment of the risk of money laundering and terrorism financing
53.The revised guidelines keep unchanged the provisions on how anti-money laundering (AML) and countering the financing of terrorism (CFT)-related aspects should be factored into the SREP, while ensuring alignment with the AMLD6 package, including by reflecting risks related to the non-implementation and evasion of targeted financial sanctions (as defined in Article 2(1)(49) of Regulation (EU) 2024/1624) in relevant SREP elements. Such common guidance is important because failures by institutions to address ML/TF and targeted financial sanctions-related risks can have detrimental effects on the financial soundness of those institutions, as well as on the integrity of the internal market and financial stability. Therefore, prudential supervisors should consider, to the extent known to them, such risks from a prudential perspective throughout their work, including in the SREP, and cooperate with the authorities and bodies responsible for ensuring compliance with AML/CFT requirements.
Link between the SREP and early intervention measures and resolution
54.The SREP assessment may also be used in setting triggers for early intervention measures, as provided for in Article 27 of Directive 2014/59/EU (BRRD). It also allows for the determination of an institution as ‘failing or likely to fail’, which activates the formal interaction procedure with resolution authorities pursuant to Article 32 of that Directive. To this end, these guidelines should be read together with the EBA Guidelines on triggers for use of early intervention measures and guidelines on the interpretation of the different circumstances when an institution shall be considered as failing or likely to fail . No changes have been proposed to this part in the revised guidelines.
Guidelines (revised) on common procedures and methodologies for the supervisory review and evaluation process (SREP) and supervisory stress testing under Directive 2013/36/EU Compliance and reporting obligations
Status of these guidelines
1. This document contains guidelines issued pursuant to Article 16 of Regulation (EU) No 1093/2010 . In accordance with Article 16(3) of Regulation (EU) No 1093/2010, competent authorities and financial institutions must make every effort to comply with the guidelines.
2. Guidelines set out the EBA’s view of appropriate supervisory practices within the European System of Financial Supervision, and of how Union law should be applied in a particular area. Competent authorities as defined in Article 4(2) of Regulation (EU) No 1093/2010 to whom guidelines apply should comply by incorporating them into their practices as appropriate (e.g. by amending their legal framework or their supervisory processes), including where guidelines are directed primarily at institutions.
Reporting requirements
3. According to Article 16(3) of Regulation (EU) No 1093/2010, competent authorities must notify the EBA by [dd.mm.yyyy] whether they comply or intend to comply with these guidelines, or if not, provide reasons for non-compliance. In the absence of any notification by this deadline, the EBA will consider competent authorities to be non-compliant. Notifications should be sent by submitting the form available on the EBA website with the reference ‘EBA/GL/2026/xx’. Notifications should be submitted by persons with appropriate authority to report compliance on behalf of their competent authorities. Any change in the status of compliance must also be reported to the EBA.
1. Title 1. Subject matter, scope and definitions, and implementation
Subject matter
1. These guidelines specify the common procedures and methodologies for the functioning of the supervisory review and evaluation process (SREP) referred to in Articles 48n, 97 and 107(1)(a) of Directive 2013/36/EU , including those for the assessment of the organisation and treatment of risks, including money laundering and terrorist financing, referred to in Articles 76 to 87 of that Directive, and the processes and actions taken with reference to Articles 48o, 98, 100, 101, 102, 104, 104a, 104b, 104c, 105, 107(1)(b) and 117 of that Directive. These guidelines aim to provide common methodologies to be used by competent authorities when conducting supervisory stress tests in the context of their SREP referred to in Article 100(2) of Directive 2013/36/EU. In addition, these guidelines also specify in accordance with Article 104a(7) of Directive (EU) 2024/1619 on how to operationalise the requirements where an institution has become bound by the output floor.
2. These guidelines do not set methodologies for the stress tests conducted by the EBA in cooperation with other competent authorities in accordance with Article 22 of Regulation (EU) No 1093/2010; however, they do describe the range of stress tests to help set the appropriate context for the consideration of future EBA stress tests as one part of the supervisory stress tests.
Scope of application
3. Competent authorities should apply these guidelines in accordance with the level of application determined in Article 110 of Directive 2013/36/EU following the requirements and waivers used pursuant to Articles 108 and 109 of Directive 2013/36/EU.
4. For parent undertakings and subsidiaries included in the consolidation, competent authorities should adjust the depth and the level of granularity of their assessments to correspond to the level of application established in the requirements of Regulation (EU) No 575/2013 specified in Part One, Title II of that Regulation, in particular recognising waivers applied pursuant to Articles 7, 10 and 15 of Regulation (EU) No 575/2013 and Article 21 of Directive 2013/36/EU.
5. Where an institution has a subsidiary in the same Member State, but no waivers specified in Part One of Regulation (EU) No 575/2013 have been granted, a proportionate approach for the assessment of capital and liquidity adequacy may be applied by focusing on the assessment of allocation of capital and liquidity across the entities and potential impediments to the transferability of capital or liquidity within the group.
6. For cross-border groups, procedural requirements should be applied in a coordinated manner within the framework of colleges of supervisors established pursuant to Article 116 or 51 of Directive 2013/36/EU. Title 10 explains the details of how these guidelines apply to cross-border groups and their entities.
7. When an institution has established a liquidity subgroup pursuant to Article 8 of Regulation (EU) No 575/2013, competent authorities should conduct their assessment of risks to liquidity and funding, and apply supervisory measures, for the entities covered by such a subgroup at the level of the liquidity subgroup.
Addressees Definitions
9. Unless otherwise specified, terms used and defined in Regulation (EU) No 575/2013 , Directive 13 14 2013/36/EU, Directive 2014/59/EU or the EBA Guidelines on institutions’ stress testing , have the same meaning in the guidelines. In addition, for the purposes of these guidelines, the following definitions apply: ‘AML/CFT supervisor’ means a supervisory authority, as defined under Article 2(1), point (45), of Regulation (EU) 2024/1624, responsible for the supervision of institutions’ compliance with provisions of that Regulation. ‘Capital buffer requirements’ means the own funds requirements specified in Chapter 4 of Title VII of Directive 2013/36/EU. ‘Consolidating institution’ means an institution that is required to abide by the prudential requirements on the basis of the consolidated situation in accordance with Part 1, Title 2, Chapter 2 of Regulation (EU) No 575/2013. ‘Counterbalancing capacity’ means the institution’s ability to hold, or have access to, excess liquidity over short-term, medium-term and long-term time horizons in response to stress scenarios. ‘Funding risk’ means the risk that the institution will not have stable sources of funding in the medium and long term, resulting in the current or prospective risk that it will not be able to meet its financial obligations such as payments and collateral needs as they fall due in the medium-tolong term, either at all or without unacceptable funding cost increases. ‘FX lending’ means lending to borrowers, regardless of the legal form of the credit facility (e.g. including deferred payments or similar financial accommodations), in currencies other than the legal tender of the country in which the borrower is domiciled. ‘FX lending risk’ means the current or prospective risk to the institution’s earnings and own funds arising from FX lending to unhedged borrowers. ‘Internal capital adequacy assessment process (ICAAP)’ means the process for the identification, measurement, management and monitoring of internal capital implemented by the institution pursuant to Article 73 of Directive 2013/36/EU. ‘Internal liquidity adequacy assessment process (ILAAP)’ means the process for the identification, measurement, management and monitoring of liquidity implemented by the institution pursuant to Article 86 of Directive 2013/36/EU. ‘Institution’s category’ means the indicator of the institution’s systemic importance assigned based on the institution’s size and complexity, and the scope of its activities. ‘Intraday liquidity’ means the funds that can be accessed during the business day to enable the institution to make payments in real time. ‘Intraday liquidity risk’ means the current or prospective risk that the institution will fail to manage its intraday liquidity needs effectively. ‘Macro-prudential requirement’ or ‘measure’ means a requirement or measure imposed by a competent or designated authority to address macroprudential or systemic risk. ‘Material currency’ means a currency in which the institution has material balance-sheet or offbalance-sheet positions. ‘Money laundering and terrorist financing (ML/TF) risk’ means the risk as defined in the EBA Risk- Based Supervision Guidelines . ‘Operational resilience’ means the ability of an institution to deliver critical or important functions through disruption. ‘Overall capital requirement (OCR)’ means the sum of the total SREP capital requirement (TSCR), capital buffer requirements and macroprudential requirements, when expressed as own funds requirements. ‘Overall leverage ratio requirement (OLRR)’ means the sum of the total SREP leverage ratio requirement (TSLRR) and the G-SII leverage ratio buffer requirement in accordance with Article 92(1a) of Regulation (EU) No 575/2013. ‘Overall SREP assessment’ means the up-to-date assessment of the overall viability of an institution based on assessment of the SREP elements. ‘Overall SREP score’ means the numerical indicator of the overall risk to the viability of the institution based on the overall SREP assessment. ‘Pillar 1 own funds requirements’ or ‘P1R’ means the own funds requirements the institution is required to hold in accordance with Parts Three, Four and Seven of Regulation (EU) No 575/2013 and Chapter 2 of Regulation (EU) 2017/2402. ‘Pillar 2 guidance’ or ‘P2G’ means the level and quality of own funds the institution is expected to hold in excess of its OCR, determined in accordance with the criteria specified in these guidelines. ‘Pillar 2 guidance for the risk of excessive leverage’ or ‘P2G-LR’ means the level and quality of own funds the institution is expected to hold in excess of its OLRR, determined in accordance with the criteria specified in these guidelines. ‘Pillar 2 requirement’ or ‘P2R’ means the additional own funds requirements imposed in accordance with Article 104(1)(a) of Directive 2013/36/EU to address risks other than the risk of excessive leverage. ‘Pillar 2 requirement for the risk of excessive leverage’ or ‘P2R-LR’ means the additional own funds requirements imposed in accordance with Article 104(1)(a) of Directive 2013/36/EU to address the risk of excessive leverage. ‘Reputational risk’ means the current or prospective risk to the institution’s earnings, own funds or liquidity arising from damage to the institution’s reputation. ‘Risk appetite’ means the aggregate level and types of risk the institution is willing to assume within its risk capacity, in line with its business model, to achieve its strategic objectives. ‘Risk score’ means the numerical expression summarising the supervisory assessment of an individual risk to capital, liquidity and funding representing the likelihood that a risk will have a significant prudential impact on the institution (e.g. potential loss) after considering risk management and controls and before consideration of the institution’s ability to mitigate the risk through available capital or liquidity resources. ‘Risks to capital’ means distinct risks that, should they materialise, will have a significant prudential impact on the institution’s own funds over the next 12 months. These include but are not limited to risks covered by Articles 79 to 87 of Directive 2013/36/EU. ‘Risks to liquidity and funding’ means distinct risks that, should they materialise, will have a significant prudential impact on the institution’s liquidity over different time horizons. ‘SREP element’ means one of the following: business model analysis, assessment of internal governance and institution-wide risk controls, assessment of risks to capital, SREP capital assessment, or SREP liquidity and funding assessment. ‘Supervisory benchmarks’ means risk-specific quantitative tools or methodologies developed by the competent authority to provide an estimation of the own funds required to cover risks or elements of risks not covered by Regulation (EU) No 575/2013. ‘Survival period’ means the period during which the institution can continue operating under stressed conditions and still meet its payments obligations. ‘Total risk exposure amount (TREA)’ means total risk exposure amount as defined in Article 92 of Regulation (EU) No 575/2013. ‘Total SREP capital requirement (TSCR)’ means the sum of own funds requirements as specified in Article 92(1), points (a) to (c), of Regulation (EU) No 575/2013 and additional own funds requirements determined in accordance with the criteria specified in these guidelines to address risks other than the risk of excessive leverage. ‘Total SREP leverage ratio requirement (TSLRR)’ means the sum of own funds requirements as specified in Article 92(1), point (d), of Regulation (EU) No 575/2013 and additional own funds requirements determined in accordance with the criteria specified in these guidelines to address the risk of excessive leverage. ‘Unhedged borrowers’ means retail and SME borrowers without a natural or financial hedge that are exposed to a currency mismatch between the loan currency and the hedge currency; natural hedges include, in particular, cases where borrowers receive income in a foreign currency (e.g. remittances/export receipts), while financial hedges normally presume that there is a contract with a financial institution. ‘Viability score’ means the numerical expression summarising the supervisory assessment of a SREP element and representing an indication of the risk to the institution’s viability stemming from the SREP element assessed.
Date of application
10.These guidelines apply from 1 January 2027.
Paragraphs 102, 103, 239, 462, 463 and 470(f) apply from 01 January 2027, except for taking into account the risks of non‑implementation and evasion of targeted financial sanctions, which applies from 10 July 2027.
Title 12 applies from 11 January 2027.
Repeal
11.The EBA Guidelines on common procedures and methodologies for the supervisory review and evaluation process (SREP) and supervisory stress testing of 18 March 2022 (EBA/GL/2022/03) and the EBA Guidelines on ICT risk assessment under the SREP (EBA/GL/2017/05) are repealed with effect from 1 January 2027. The references to the Guidelines repealed shall be construed as reference to these guidelines.
2. Title 2. SREP framework
2.1. Overview of the SREP framework
12.Competent authorities should have a comprehensive SREP framework covering the following components, which should be assessed on a regular basis, having regard to the list of legal acts published separately on the EBA website against which compliance of institution should be evaluated. The SREP engagement model in section 2.4 sets out how this framework can be calibrated across diverse institutions in application of the proportionality principle. These components are: a. categorisation of the institution as specified in section 2.1.1; b. monitoring of key indicators as specified in Title 3; c. business model analysis (BMA) as specified in Title 4; d. assessment of internal governance and institution-wide controls as specified in Title 5; e. assessment of risks to capital as specified in Title 6; f. assessment of the adequacy of the institution’s own funds as specified in Title 7; g. assessment of risks to liquidity and funding and SREP liquidity and funding assessment as specified in Title 8; h. overall SREP assessment (including the application of supervisory measures - and early intervention measures, where necessary) and communication as specified in Title 9 and section 2.1.2 respectively.
13.Competent authorities should consider the SREP an ongoing process that integrates the outcome of all the supervisory activities and all available sources of information into a comprehensive supervisory overview of an institution. The SREP should include consideration of the following: a. the outcome of previous SREP assessments, business model analysis and ongoing off-site supervision; b. institution’s financial reporting, strategic plan(s), regulatory reporting (common reporting – COREP, financial reporting – FINREP, and credit register, where available) and internal reporting (e.g. management information, capital and liquidity reporting, internal risk reports); c. institution’s ICAAP/ILAAP and recovery planning arrangements; d. on-site inspections; e. internal model assessments; f. targeted deep-dive analysis; g. horizontal thematic reviews;
h. stress testing analysis; i. third-party reports (e.g. audit reports, reports by equity/credit analysts); j. other relevant sectoral or macroeconomic studies/surveys.
2.1.1. Categorisation of institutions
14.Competent authorities should categorise all institutions under their supervisory remit into four different categories based on the size, systemic importance, nature, scale and complexity of the activities of the institutions concerned and considering Article 97(4) of Directive 2013/36/EU. The categorisation should reflect the assessment of systemic risk posed by institutions to the financial system.
15.Within a group of entities, if competent authorities determine that the relevance of different entities within the group, based on the elements listed in paragraph 17, varies, they may apply categorisation at the individual level to reflect these differences (e.g. assigning different categories to various group subsidiaries and/or consolidated entity).
16.Competent authorities should review the categorisation of their institutions periodically, and following events that may affect the business models’ riskiness, or major corporate operations such as a large divestment, a merger or acquisition, an important strategic action.
17.To ensure a minimum level of comparability, competent authorities should refer to the categories below as a starting point: ► Category 1 – All institutions defined as ‘large institutions’ in Article 4(1), point 146 of Regulation (EU) 575/2013. Competent authorities may classify ‘large institutions’ as Category 2 or Category 3 institutions for proportionality reasons provided they are not G- SIIs. The reclassification of ‘large institutions’ that are not G-SIIs should be performed in accordance with the qualitative criteria of Category 2 and Category 3 below, considering the institution’s size, systemic importance, nature, scale and complexity of the activities. ► Category 2 – (i) Medium to large institutions other than those included in Category 1 which are not ‘small and non-complex institutions’ as defined in Article 4(1), point 145, of Regulation (EU) 575/2013 and operate in several business lines, including non-banking activities, or have sizeable cross-border activities, and offer credit and financial products to retail and corporate customers; (ii) non-systemically important specialised institutions with significant market shares in their lines of business or payment systems, or trading platforms/markets for financial instruments; (iii) institutions considered important, due to their size, activities, or business model (e.g. central institutions of an IPS, CCPs, CSDs, central cooperative banks or central savings banks), for the economy (e.g. in terms of total assets over gross domestic product – TA/GDP) or for the banking sector in a particular Member State. ► Category 3 – (i) Small to medium institutions other than those included in Categories 1 and 2, which are not ‘small and non-complex institutions’ as defined in Article 4(1), point 145, of Regulation (EU) 575/2013 and operate in a limited number of business lines, or have
non-significant cross-border activities, offering predominantly credit products to retail, corporate and institutional customers with a limited offering of financial products; (ii) specialised institutions with less-significant market shares in their lines of business or payment systems, or financial exchanges. ► Category 4 – All institutions defined as ‘small and non-complex institutions’ in Article 4(1), point 145 of Regulation (EU) 575/2013 and all other small non-complex institutions that do not fall into Categories 1 to 3 (e.g. with a limited scope of activities and non-significant market shares in their lines of business).
2.1.2. Continuous assessment of risks, escalation framework and supervisory measures
18.Competent authorities should continuously assess the risks to which the institution is or might be exposed through their supervisory activities in accordance with the SREP engagement model set out in section 2.4.
19.Competent authorities should ensure that the findings of their assessments are clearly documented, with a focus on the root causes of the identified deficiencies. These findings should be reflected in the SREP scores assigned in accordance with these guidelines and should inform subsequent supervisory measures that competent authorities may apply as specified in Articles 102, 104 and 105 of Directive 2013/36/EU and national law, and, when applicable, early intervention measures as specified in Article 27 of Directive 2014/59/EU, or any combination of the above.
20. As part of their ongoing supervisory activities, competent authorities should undertake appropriate and timely follow-up activities to ensure that an institution has effectively addressed the identified deficiencies. In this regard, competent authorities should establish a high-level escalation framework for supervisory measures, supporting the selection of the most appropriate measures (both quantitative and qualitative) to address the identified deficiencies. This is without prejudice to the supervisory powers provided under the applicable legal framework and the competent authorities’ discretion to determine the most appropriate measures based on the specific circumstances and deficiencies. 21.The framework referred to in the previous paragraph should consider the following actions, which are not to be intended to be strictly sequential and may be escalated or de-escalated as appropriate: a. engaging in an enhanced supervisory dialogue with the institution, such as holding a meeting with the management body or requiring a self-assessment from the institution; b. communicating corrective actions expected from the institution (non-binding measures), such as supervisory expectations or recommendations; c. requiring specific corrective action(s) from the institution (binding measures), such as setting qualitative measures the institution needs to comply with and/or setting/increasing Pillar 2 requirement or liquidity requirements; d. enforcing supervisory measures to remedy the deficiencies identified, such as administrative penalties, remedial measures or fines. 22.When selecting supervisory measures, competent authorities should identify the full escalation path, taking into account the information available, the nature, size and complexity of the institution and the need to ensure timely remediation of identified deficiencies. The selection should be guided by the following considerations, as applicable: a. the intended outcome that the measures aim to achieve and, where feasible, the expected timelines for the institution to address the deficiencies; b. the severity of the deficiencies and the potential prudential impact of not addressing the issue (i.e. whether it is necessary to address the issue with a specific measure) and whether the deficiencies have already been addressed/covered by other measures; c. the demonstrated ability or intention of the institution to remediate to the deficiencies; d. whether other measures would achieve the same objective with less of an administrative and financial impact on the institution; e. the possibility that risks and vulnerabilities identified may be correlated or self-reinforcing, or both, meriting an increase in the rigorousness of supervisory measures; f. any other factors deemed relevant by the competent authorities. 23.Without prejudice to the discretion of the competent authorities in selecting the most appropriate measures, all available quantitative and qualitative measures should be used in a way that allows to best address the risk level and/or deficiencies. This should take into account the nature of the risk (quantitative and/or qualitative), the escalation process, and the fact that quantitative measures should be applied to address deficiencies in internal governance, including internal control arrangements, and other issues, where other supervisory measures have not been effective or are considered insufficient to address the identified deficiencies within an appropriate timeframe . 24.The provisions of this title are without prejudice to the possibility of competent authorities taking supervisory measures directly linked to the outcomes of any supervisory activities (e.g. on-site examinations or assessments of the suitability of members of the management body and key functions) where the outcomes of such activities necessitate immediate application of supervisory measures to address material deficiencies.
2.1.3. Dialogue with institutions
25.Competent authorities should engage in dialogue with institutions as they perform their supervisory activities.
26.Competent authorities should communicate the outcomes of the SREP assessment to the institution in accordance with Title 9 and inform the institution of any action required to comply with supervisory measures applied on the basis of those findings.
2.2. Scoring in the SREP
27.Competent authorities should apply a consistent scoring system to help facilitate communication between competent authorities and colleges of supervisors, foster comparability and a level playing field across institutions, and prioritise supervisory resources and measures in the assessment of the SREP elements. They should summarise the outcomes of their assessments by assigning risk scores, SREP element scores and an overall SREP score.
28.When assigning risk scores, SREP elements scores and the overall SREP score, competent authorities should refer to the considerations outlined in the tables at the end of each relevant section and title of these guidelines, alongside the application of supervisory judgment. While these considerations serve as a baseline for assigning scores, they should not be interpreted as a mechanical checklist to be completed for each element, nor should they be seen as establishing a hierarchy of importance among the elements. Instead, they are intended to guide competent authorities in assigning scores by considering the interplay and relevance of the different elements within the specific dimension of the institution being assessed.
29.The risk scores aim to capture the likelihood that the risks to capital, liquidity and funding will have a significant impact on the institution. The SREP element scores and the overall SREP score indicate the magnitude of risks to the institution’s viability; in particular the overall SREP score should reflect the supervisory view of the overall viability of the institution as specified in Title 9.
30.The scores are: 1 (low risk), 2 (medium-low risk), 3 (medium-high risk), and 4 (high risk – this represents the worst possible assessment). An additional score of ‘F’ is available only for the
overall SREP score, as explained in paragraph 38. Competent authorities may introduce more granular scoring for their internal purposes, such as planning of resources, provided the overall scoring framework set out in these guidelines is respected.
31.Competent authorities should review the scores upon completion of the SREP assessments with the minimum frequency set out in the SREP engagement model in section 2.4. The scores should also be reviewed without undue delay on the basis of material new findings or developments.
2.2.1. Risk scores
32.Risk scores are assigned to summarise risks to capital (as specified in Title 6). These scores represent the likelihood that a risk will have a significant prudential impact on the institution (e.g. potential loss), after considering the quality of risk controls to mitigate this impact (i.e. residual risk), but before consideration of the institution’s ability to mitigate the risk through available capital or liquidity resources.
33.Competent authorities should determine the risk score through an assessment of an institution’s inherent risk level, while duly considering the adequacy of the institution’s risk management and controls framework. In particular, an adequate risk management and controls framework may mitigate the prudential impact of a specific risk, while a weak framework may amplify the prudential impact. The assessment of inherent risk and the adequacy of management and controls should be made with reference to the considerations specified in table 6 for credit and counterparty risk, in table 8 for market risk, in table 10 for operational risk, in table 12 for interest rate and credit spread risk in the banking book (IRRBB and CSRBB), in table 17 for liquidity and funding.
34.When assessing risks to capital, competent authorities should also consider relevant subcategories (e.g. concentration risk or country risk as part of the credit and counterparty risk assessment, as set out in Title 6). Depending on the materiality of any of these subcategories to a particular institution, competent authorities may decide to assess and score them individually.
35.Competent authorities may use different methods to apply the risk scores, they could score ‘risk’ and ‘risk management and controls’ separately (resulting in an intermediate and final score) or score them together. Competent authorities may also aggregate all the risks to capital into an aggregate score.
2.2.2. SREP element scores and overall SREP score
36.At the end of the overall SREP assessment, competent authorities should form a comprehensive overview of the risk profile and viability of the institution based on the four SREP elements: a. business model and strategy as specified in Title 4; b. internal governance and institution-wide controls as specified in Title 5; c. capital adequacy, as specified in Title 7; d. liquidity and funding adequacy, as specified in Title 8.
37.Capital adequacy and liquidity and funding adequacy represent the supervisory view of the capacity of the institution’s capital and liquidity resources to mitigate/cover risks to capital and liquidity and funding, as set out in Titles 6 and 8, and/or other elements for which additional own funds have been determined as set out in Title 7.
38.The final score is an overall SREP score. This incorporates the four SREP element scores above and supervisory judgement. Competent authorities should ensure that the overall SREP score provides an indication of the institution’s overall viability, including whether the institution is ‘failing or likely to fail’ within the meaning of Article 32 of Directive 2014/59/EU, and having regard to the EBA Guidelines on ‘failing or likely to fail’ . When the outcome of the overall SREP assessment suggests that an institution can be considered to be ‘failing or likely to fail’, competent authorities should apply a score of ‘F’ and follow the process of engaging with resolution authorities as specified in Article 32 of Directive 2014/59/EU.
39.Competent authorities should ensure that the SREP element scores and the overall SREP score: a. reflect the likelihood that supervisory measures are needed to address concerns; b. are considered among the triggers for the decision on whether to apply early intervention measures in accordance with the EBA Guidelines on triggers for use of early intervention measures ; c. inform the prioritisation and planning of supervisory resources and the setting of priorities in the supervisory examination programme (SEP).
2.3. Organisational arrangements
40.Competent authorities should ensure that their organisational arrangements for conducting SREP include at least the following: a. a description of the roles and responsibilities of their supervisory staff with respect to performing the SREP, as well as the relevant reporting lines, in both normal and emergency situations; b. procedures for documenting and recording findings and supervisory judgements; c. arrangements for the approval of the findings and scores, as well as escalation procedures where there are dissenting views within the competent authority, in both normal and emergency situations; d. arrangements for organising dialogue with the institution following the model of minimum engagement as stipulated in section 2.4 to assess individual SREP elements; e. arrangements for engaging in consultations with an institution and for communicating the outcomes of the SREP to the institution, reflecting the interaction within colleges of
supervisors for cross-border groups and their entities, in accordance with Commission Implementing Regulation (EU) No 710/2014 ; f. internal checks and balances to support effective decision-making, consistency of outcomes and accountability.
41.When defining arrangements for dialogue with institutions, competent authorities should consider the potential implications of providing the scores to the institutions in terms of their disclosure obligations pursuant to the requirements of Regulation (EU) No 596/2014 and 21 22 Directives 2014/57/EU and 2004/109/EC .
2.4. Proportionality and supervisory engagement
42.Competent authorities should adjust the scope, frequency, granularity and intensity of supervisory engagement with an institution in accordance with its category and taking into account the principle of proportionality. When planning SREP activities, competent authorities should refer to the minimum SREP engagement model outlined in table 1. The model maps the intensity of the supervisory engagement to the institution’s category. The model should not be interpreted as an obstacle to allocate resources on identified supervisory priorities. Competent authorities may therefore, regardless of the categorisation of the institution, set the focus and granularity of their assessment to reflect the risk profile of the institution, the materiality of the different risks, trends and emerging risks identified through the monitoring of key indicators as outlined in Title 3, stress testing as outlined in Title 11 or the outcome of previous SREP assessments.
43.Under this model, competent authorities should form a view on all the SREP elements (business model analysis, governance/internal controls, risks to capital, and risks to liquidity and funding) in accordance with the minimum frequency set out in table 1, while remaining able to make a yearly meaningful and comprehensive assessment of an institution’s viability (summary of the overall SREP assessment).
44.This view should be based on information gathered through the full range of supervisory activities listed in paragraph 13. In particular, information from previous years may also serve as
a baseline for the assessment and summary of the overall SREP assessment, provided that the competent authority has determined - while also taking into account the quarterly monitoring of the indicators - that the institution’s risk profile has not materially changed.
45.Competent authorities should engage with the institutions’ management body and senior management based on the minimum frequency indicated in table 1. Regardless of the category of the institution, competent authorities should intensify their engagement to follow up on findings from previous SREP assessments, or to monitor institutions with higher/rapidly changing risk profiles or with a poor overall SREP score reflecting severe supervisory concerns.
46.Where institutions are part of cross-border groups, competent authorities should discuss how they plan to perform their SREP assessment within the framework of colleges of supervisors to identify concerns at an early stage and adjust and coordinate the approach among the authorities as specified in Title 10.
47.Where competent authorities determine that institutions have similar risk profiles or may be exposed to similar emerging risks, they may conduct thematic SREP assessments on multiple institutions as a single assessment (e.g. a BMA may be conducted on all small mortgage lenders, given that it is likely to identify the same business viability issues for all these institutions). Competent authorities may also use tailored methodologies for the application of the SREP for institutions with similar risk profiles, such as similar business models or geographical location of exposures in accordance with Article 97(4a) of Directive 2013/36/EU.
48.For institutions covered by the supervisory examination programme required by Article 99 of Directive 2013/36/EU, competent authorities should ensure that the level of engagement and application of the SREP is determined by that programme.
49.When planning supervisory activities, competent authorities should coordinate activities internally to ensure a coherent assessment and with other parties directly or indirectly involved in the assessment, in particular when input is required from them.
3. Title 3. Monitoring of key indicators
50.Competent authorities should regularly monitor key financial and non-financial indicators to observe changes in the financial and operational conditions, and risk profiles of institutions. Where monitoring reveals a material change in the risk profile of an institution, or any anomalies in the indicators, competent authorities should investigate the causes and, where relevant, review the assessment of the relevant SREP element, including the risk score as relevant, to capture the new information. Competent authorities should regularly review and, where necessary, update their monitoring indicators and tools to ensure these remain relevant and effective.
51.Consistent with the SREP engagement model in section 2.4, competent authorities should monitor key financial and non-financial indicators at least quarterly for all institutions and establish more frequent monitoring to reflect the specific features of an institution or emerging risks and trends, subject to data availability (e.g. market data).
52.Competent authorities should set up monitoring systems to identify patterns, material changes and anomalies in the behaviour of the indicators (or combinations of indicators), for instance by setting out alerts based on materiality thresholds. Competent authorities should set escalation procedures to deal with anomalies. Identification of material changes or anomalies in indicators, especially in cases where changes are outliers to the peer-group performance, should be considered by competent authorities as a prompt for further investigation.
53.Competent authorities should tailor the monitoring systems, and the escalation procedures in case of anomalies, to reflect the institution’s size, complexity, business model and risk profile, focussing on the geographies, sectors and markets where the institution operates.
54.The monitoring systems should as a minimum be based on information and data reported to the competent authorities and may include the EBA dashboards or indicators. Monitoring systems should include at least the following institution-specific indicators: a. indicators related to the institution’s business model analysis (see Title 4), internal governance and controls (see Title 5), risks to capital (see Title 6) and risks to liquidity and funding (see Title 8); indicators for risk of excessive leverage (see Title 7) and indicators deduced from the application of Regulation (EU) 2022/2554; b. all the ratios derived from the application of Regulation (EU) 575/2013 and from the national law implementing Directive 2013/36/EU for calculating the minimum prudential requirements (e.g. Core Tier 1 - CET1, liquidity coverage ratio - LCR, net stable funding ratio - NSFR, Leverage ratio); c. the minimum requirements for own funds and eligible liabilities (MREL) as specified by Directive 2014/59/EU;
d. relevant market-based indicators (e.g. equity price, credit default swap - CDS spreads, bond spreads); e. where applicable , and particularly in case of idiosyncratic or systemic events, recovery indicators used in the institution’s own recovery plans; f. where available, indicators based on quantitative or qualitative information from reporting provided to competent authorities that may point to ML/TF risk.
55.Competent authorities should accompany institution-specific indicators with relevant macroeconomic indicators, where available, in the geographies, sectors and markets where the institution operates. They should also consider relevant independent market research and analysis, including threat landscape reports, where these are available, as an informative source of alternative points of view.
4. Title 4. Business model analysis (BMA)
4.1. General considerations
56.This title specifies criteria for the assessment of the business model and strategy of the institution. The purpose of this assessment by competent authorities is to achieve a comprehensive understanding – both in current and forward-looking perspectives – of the institution’s operations, identify significant existing or potential vulnerabilities which are most likely to have a material impact on the institution, and assess the overall soundness of its business model and strategy. Following this assessment, competent authorities should determine: a. the viability of the institution’s current business model, measured by its ability to generate acceptable returns over the next 12 months; b. the sustainability of the institution’s strategy, based on its ability to generate acceptable returns over a forward-looking period of at least three years, as derived from its strategic plans and financial projections.
57.Competent authorities should use the outcome of the BMA to support the assessment of all other elements of the SREP. Competent authorities may assess specific aspects of the BMA, in particular the quantitative assessment of the business model, as part of the assessment of other SREP elements (e.g. understanding the funding structure can be part of the risks to liquidity assessment).
58.Competent authorities should take into account environmental, social and governance (ESG) risks, giving priority to environmental transition and physical risks, when performing the BMA, with a view to assessing the strategic and prudential implications of these risks for the business model of the institution in the short, medium and long term.
59.Competent authorities should also use the business model analysis to assess prudential implications of ML/TF risks, linked to the business model of the institution. In this respect, competent authorities should use the input received from AML/CFT supervisors to complement their findings from ongoing supervision and evaluate whether they give rise to prudential concerns related to ML/TF risk. Where the assessment indicates the business model of the institution gives rise to prudential concerns related to ML/TF risk, competent authorities should share the outcome of the prudential assessment of the business model with the AML/CFT supervisor .
60.To conduct the BMA, competent authorities should use at least the following sources of quantitative and qualitative information: a. institution’s strategic plan(s) with current-year and forward-looking forecasts, and underlying economic assumptions; b. financial reporting (e.g. profit and loss - P&L, balance-sheet disclosures); c. regulatory reporting (COREP, FINREP and credit register, where available); d. internal reporting (management information, including – where available – contribution to the profitability by business lines, capital planning, liquidity reporting, operational resilience, internal risk reports); e. recovery plans; f. resolution plans, including the work and outcome of resolvability assessment provided by the resolution authority in accordance with Article 14 of Directive 2014/59/EU; g. institution’s plan to address ESG risks, to be prepared in accordance with Article 76(2) of Directive 2013/36/EU; h. third-party reports (e.g. audit reports, reports by equity/credit analysts); i. other relevant macroprudential or financial stabilities studies/surveys (e.g. from the International Monetary Fund - IMF, macroprudential authorities and institutions, European institutions).
4.2. Identifying the areas of focus for the BMA
Assessment areas
61.In accordance with the engagement model set out in Title 2, competent authorities should focus their analysis on the most material assessment areas for the business model of the institution. The scope and depth of the BMA may be differentiated depending on the number and nature of supervisory reviews already performed on that institution. This assessment should in any case allow competent authorities to form a view on the overall institution’s business model viability and sustainability.
62.Competent authorities should form a view on the materiality of the changes to the institution’s business model compared to prior supervisory review, in order to decide the scope and depth of their assessment and the extent to which the prior supervisory assessment can be used as a baseline for the new one. In forming such a view, competent authorities should, in particular, consider whether there have been relevant changes in the following areas of the institution: a. the previously communicated and assessed strategic plan; b. the structure and composition of the balance sheet, including changes in sources of profit and their concentration, asset growth, changes in the liabilities structure, or shift in the relevant financial and risk indicators, and consider the results of the indicator monitoring outlined in Title 3;
c. governance and operations, including acquisitions, mergers or divestments of other entities, the opening or exit of business lines or geographic markets as well changes to IT infrastructure.
Identification of most important business lines
63.Competent authorities should carry out a materiality assessment of the institution’s business lines to determine the key areas for the BMA to focus on. When performing this assessment, competent authorities should take into account: a. the relevance of the business lines in terms of generating profits/losses, including the geographies, subsidiaries/branches and product lines that are most material based on their contribution to the overall revenues/costs in the P&L, risk (e.g. based on TREA or other measures of risk) and/or organisational/statutory priorities (e.g. specific obligations for public sector banks to offer specific products); b. previous supervisory findings, including those arising from onsite inspections – where these findings can provide indicators on business lines requiring further investigation –, as well as findings and observations from internal or external audit reports – whether the internal audit function has identified specific issues regarding the sustainability or viability of certain business lines; c. outcomes of thematic supervisory reviews – whether a sector-wide analysis has revealed common underlying issues that prompt additional institution-specific analysis; d. importance to strategic plans – whether there are business lines that the institution wishes to grow substantially or decrease; e. peer comparisons – whether a business line has performed atypically (been an outlier) compared to peers, where such information is available to competent authorities. To identify relevant peers for the BMA, competent authorities should consider the rival product/business lines targeting the same source of profits/customers, the regulatory regimes and geopolitical risks of location of operations as well as other factors appropriate to the sector in which the institution operate.
4.3. Assessment of BMA robustness and identification of vulnerabilities
64.Competent authorities should perform an analysis of quantitative features of the institution’s current business model to assess its ability to generate acceptable profits in the short, medium and long term, given the institution’s risk appetite and its funding and capital structures. Areas for analysis by competent authorities should include: a. drivers of profitability, including trends, by assessing the underlying elements of the institution’s earning capacity, after exception items and one-offs, breakdown of income streams, breakdown of costs and costs allocation, impairment provisions and key ratios (e.g. net interest margin, cost/income, loan impairment, and cost of risk). This assessment may be complemented by the analysis of the relevant risk-adjusted profitability metrics (e.g. Return
On Allocated Capital – ROAC, or the Risk-Adjusted Return on Capital Return - RAROC), where these are available and deemed reliable; b. the balance sheet, including trends, by assessing the asset and liability mix, funding structure, change in the TREA and own funds, and key ratios (e.g. return on equity/assets, Core Tier 1, funding gap), as well as concentrations in the P&L and balance sheet related to customers, sectors and geographies; c. risk appetite and tolerance levels, by assessing the formal limits put in place by the institution by risk type and its adherence to them to understand the risks that the institution is willing to take to drive its financial performance and to ensure operational resilience. This should also cover the impact tolerance for ICT disruptions.
65.Competent authorities should perform an analysis of qualitative features of the institution’s current business model to understand its success drivers and key dependencies. Areas for analysis by competent authorities should include: a. the business environment, by assessing the forward-looking environment in which the institution operates based on its main or material geographic and business exposures. As part of this assessment, competent authorities should develop an understanding of the key macroeconomic variables, market trends, the competitive landscape and other relevant developments (such as regulatory and legal changes); b. key internal and external dependencies, by assessing main exogenous and endogenous factors that may influence the success of the business model, considering associated governance and internal control arrangements; c. franchise and areas of competitive advantage, by assessing the reputation of the institution and the strength of relationships with customers, suppliers and partners, as well as whether there are areas in which the institution has a competitive advantage over its peers; d. ICT support, by assessing the level and adequacy of alignment between the ICT and the business in terms of strategy, objectives, activities, resources and functions, and by considering whether any ICT-related concerns could impact the institution’s business strategy and objectives.
66.Competent authorities should complement the analysis by carrying out a forward-looking analysis (both quantitative and qualitative) of the institution’s financial projections and strategic plan to understand the underlying assumptions and dependencies, plausibility and riskiness of its business strategy. Areas for analysis by competent authorities should include: a. overall strategy and success drivers, by assessing the main quantitative and qualitative management objectives and the gap between the envisaged business model – post execution – and the current model; b. projected financial performance, by assessing the plausibility and consistency of the assumptions made by the institution that drive its strategy and forecasts; c. execution capabilities, by assessing management’s track record on delivering previous strategies and forecasts, as well as the overall ability of the institution to make use of
competitive advantages and success drivers in carrying out its business and to generate returns in an effective way. As part of this assessment, competent authorities should consider: i. the adequacy of the cost allocation framework - in terms of adequacy to reflect the profitability of business lines/units; ii. the fund transfer pricing framework – in terms of adequate determination of the net income component for each business line/unit, product and customer; iii. the loan pricing framework – in terms of adequate governance of the loan pricing process, pricing methodology, appropriate consideration of all the loan pricing components, and ex post profitability monitoring and reporting of product pricing decisions; iv. the revenue sharing framework between institutions established in the Union that are part of third-country groups and other entities of that group established outside the Union and not consolidated by the EU parent undertaking – in terms of fair sharing of P&L between entities or business lines taking part in the life cycle of transactions, and of the adequate governance.
67.In the analysis, competent authorities should consider any indications that the business model and activities give rise to increased ML/TF risks, including crypto-asset activities or deposittaking or establishment or use of legal entities in high-risk third countries, as identified in accordance with Article 9 of Directive (EU) 2015/849. Where present, these indications should be complemented by quantitative analysis, as appropriate, focusing in particular on the materiality of the revenues and the income from operations run in such high-risk third countries, the concentrations of exposures to customers for which the institution apply enhanced customer due diligence as set out in Chapter II, Section 3 of Directive 2015/849. Competent authorities should exchange information with the AML/CFT supervisor on these indications as laid out in paragraph 5963.
4.4. Business model viability and sustainability
68.Competent authorities should assess the resilience of the institution’s business model to external shocks and its adaptability to structural changes in terms of its capacity to absorb them and adapt to exogenous factors that could threaten business and strategic objectives. Areas for analysis by competent authorities should include: a. climate-related and other environmental risks, by assessing their impact on the institution’s current and future business environment and business strategy, the institution’s exposure to material transition and physical risks, as well as the development and implementation of a plan to monitor and address the financial risks stemming from ESG factors - including those arising from the process of transition towards regulatory objectives, in particular climaterelated objectives applicable in the jurisdiction(s) where the institution operates; b. digitalisation, by assessing the use and adoption level of new technologies and impact on the institution’s business strategy and business plan, execution capabilities and cost control, as well as revenue generation;
c. operational resilience, by reviewing the institution’s operational resilience approach and its consideration to the business strategy by the management body; d. geopolitical risks, by assessing the source of geopolitical uncertainties and its inclusion in the business strategy, as well as their financial impact on the institution’s current and future profitability, while also taking into account the institution’s capacity to withstand such uncertainties, for instance by means of its geographical and business profile diversification; e. crypto-asset activities, if applicable, by assessing the institution’s provision of crypto-asset services and any other activities related to crypto-assets.
69.Based on the performed analysis, competent authorities should form, or update, their view on the following elements: a. key vulnerabilities to which the institution’s business model and strategy expose it or may expose it, such as excessive concentrations or risk-taking, poor strategic steering of profitability and execution capabilities; b. viability of the institution’s current business model, as defined in paragraph 56, given its quantitative performance, risk appetite, funding structure, key success drivers and dependencies and business environment; c. sustainability of the institution’s strategy, as defined in paragraph 56, based on the plausibility of its strategic plan and financial forecasts, and given the supervisory assessment of the projected financial performance, overall strategy, level of operational resilience and the execution capabilities. Competent authorities should also consider the institution’s capacity to ensure its medium- to long-term resilience to environmental risks by taking into account long-term horizons of at least ten years, including by reviewing the environmental business model resilience analyses conducted by the institution in compliance with the EBA Guidelines on environmental scenario analysis ;
4.5. Summary of findings, scoring and supervisory measures
70.Based on the assessment of the viability and sustainability, and of any potential risks and vulnerabilities to the institution, competent authorities should form a view on the institution’s business model. This view should be reflected in a summary of findings, accompanied by a viability score based on the considerations specified in table 2.
71.The table below presents a non-exhaustive list of supervisory measures that competent authorities may take in case of identified deficiencies in the institution’s business model. Competent authorities should decide on the type of the supervisory measure based on its effectiveness to the specific identified deficiency.
72.Competent authorities may apply additional supervisory measures (including quantitative measures in accordance with Article 104(1)(a) of the Directive 2013/36/EU) or a combination of them if these are deemed more appropriate to address the identified deficiencies.
5. Title 5. Assessing internal governance and institution-wide controls
5.1. General considerations
73.When assessing the internal governance and institution-wide controls, competent authorities should evaluate inter alia the compliance of the institution with the legal acts published separately on the EBA website as referred to in paragraph 12.
74.Competent authorities should assess the adequacy of the institution’s internal governance arrangements, taking into account the nature, scale and complexity of the risks inherent in the business model and the institution’s activities. Competent authorities should identify the extent to which the institution complies with the applicable legal and regulatory requirements regarding sound internal governance arrangements, including those listed in the previous paragraph, and identify any deficiencies. Competent authorities should assess whether material risks are posed due to poor internal governance arrangements and their potential effect on the risk profile, operational resilience and sustainability of the institution. For these purposes, the following areas should be assessed, in accordance with the proportionality principle and supervisory engagement outlined in Title 2: a. organisational structure, management body and its committees; b. risk culture and business conduct; c. remuneration policies and practices; d. internal control functions; e. risk management framework; f. ICT systems, risk data aggregation and risk reporting; g. ML/TF risks and prudential concerns; h. recovery planning governance.
75.Competent authorities should take into account ESG risks, giving priority to environmental transition and physical risks, when assessing the areas covered by points (a) to (f) of the previous paragraph.
76.The assessment of internal governance should inform the specific assessment of risk management and controls as specified in Titles 6 and 8, as well as the assessment of ICAAP and ILAAP in the SREP capital assessment (Title 7) and the SREP liquidity and funding assessment (Title 8). Likewise, a risk-by-risk analysis of ICAAP calculations/capital estimates reviewed under Title 7, and any deficiencies identified through that analysis, should inform the assessment of the overall ICAAP framework assessed under this Title.
77.As part of the overall assessment of internal governance and institution-wide controls, competent authorities should evaluate the institution’s ability to effectively and timely remedy the deficiencies identified and/or supervisory concerns expressed by competent authorities. In conducting this evaluation, competent authorities should consider whether the institution’s track record demonstrates its ability and intention to address supervisory concerns and/or identified deficiencies in an effective and timely manner, and whether this has been already taken into account in the assessment of other SREP areas. For this purpose, competent authorities should leverage the assessment of the following elements: a. the role of management body in (i) assessing the effectiveness of the institution’s governance arrangements, in particular relating to the remediation actions, and (ii) taking appropriate measures to address supervisory concerns and/or deficiencies (effective reaction to supervisory concerns); b. the risk culture within the institution; c. the adequacy and timeliness of information provided and exchanged with the competent authority; d. the quality of internal reporting on remediation actions to the management body, senior management and internal control functions; e. the role of internal control functions in reviewing the adequacy and effectiveness of the remediation actions undertaken.
78.When conducting the assessment of internal governance and institution-wide controls at subsidiary level, in addition to the elements listed in this title, competent authorities should assess whether group-wide policies and procedures are implemented consistently at subsidiary level, and whether group entities have taken appropriate measures to ensure that their activities are compliant with all applicable laws and regulations.
5.2. Organisational structure, management body and its committees
79.In assessing the institution’s organisational structure, management body and committees, competent authorities should assess institution’s compliance with Articles 74, 88, and 91 of Directive 2013/36/EU, the EBA Guidelines on internal governance and the Joint ESMA and EBA Guidelines on the assessment of the suitability of members of the management body and key function holders . In the context of assessing the institution’s organisational and operational structure of the institution, and where applicable that of the group, competent authorities should consider inter alia whether: a. it is appropriately and clearly established, with well-defined, transparent and consistent lines of responsibility, including for the management body and its committees; b. it is suitable for the size and the complexity of the business and operations;
c. it is transparent to stakeholders, including staff and shareholders.
80. In the context of assessing the institution’s management body, competent authorities should consider inter alia whether: a. the management body knows and understands the institution’s legal, organisational and operational structure (‘know your structure’) and its risks, including appropriate oversight; b. where applicable, the management body of the consolidating institution understands both the organisation of the group and the roles of its different entities, and the links and relationships among them; c. the management body collectively has an appropriate understanding of the institution’s business model and activities, and remains up to date on sufficient knowledge and skills regarding relevant risks, including ICT risks, ESG risks and other emerging risks, through regular training; d. the institution has a policy to promote diversity and inclusion within the management body and regularly assesses these, including gender balance, and whether the composition, functioning and succession planning of the management board support effective decisionmaking and reflect the institution’s diversity and inclusion objectives; e. the members of the management body interact effectively, including between its management and supervisory functions; f. each member of the management body acts with independence of mind, maintaining a sufficient time commitment and is appropriately informed of the institution’s risk situation; g. the management body in its supervisory function has established, where applicable, risk, audit, nomination and remuneration committees, and whether these committees fulfil their tasks as prescribed by the applicable legal and regulatory framework. 81.When reviewing the composition and functioning of the institution’s management body and its committees, competent authorities should also consider any relevant findings from the suitability assessments on the institution’s members of the management body and key function holders, performed by the institution, or where relevant by the competent authorities. Competent authorities should review the outcome of the institution’s process of identifying key function holders and evaluate the level of individual accountability by taking into account the individual statements regarding the roles and duties of all members of the management body in its management function, senior management, and key function holders, along with the mapping of duties, including details of the reporting lines, lines of responsibility, and the persons who are part of the governance arrangements of the institution, and their duties.
5.3. Risk culture and business conduct
82.In assessing the institution’s risk culture and business conduct, competent authorities should assess institution’s compliance with the EBA Guidelines on internal governance. In this context, competent authorities should consider inter alia whether:
a. the institution has consistent corporate values and a sound risk culture, which (i) are supported by effective and robust policies and procedures, communication and training to all staff, including a code of conduct and an appropriate framework for managing conflicts of interests and reporting mechanisms to foster responsible, ethical behaviour and to monitor and manage related party exposures, and (ii) promote an environment of open communication and effective challenge; b. the management body, senior management and key function holders are committed to promoting a strong risk and corporate culture and responsible business conduct; c. a strong level of risk awareness is demonstrated across the institution; d. the institution integrates risk awareness into its decision-making processes, including appropriate risk ownership.
83.Competent authorities should assess whether the institution has an appropriate framework in place to identify, document and manage related party transactions, including an approval process, exposure limits, arm’s length terms, monitoring and reporting mechanisms. Competent authorities should also evaluate the level of oversight by the management body.
5.4. Remuneration policies and practices
84.In assessing the institution’s remuneration policies and practices, competent authorities should assess institution’s compliance with Articles 74, 92, 94 of Directive 2013/36/EU, Delegated Regulation (EU) 2021/923 and the EBA Guidelines on sound remuneration policies . In this context, competent authorities should consider inter alia whether: a. the institution has implemented appropriate and gender-neutral remuneration policies and practices for all staff, approved, regularly reviewed and overseen by the management body, and whether these policies adhere to the applicable legal and regulatory requirements; b. the internal control functions are involved in the design of the remuneration policies and verify their proper review, monitoring and update; c. the remuneration policies and practices promote sound and effective risk management, including by taking into consideration the institution’s risk appetite in terms of ESG risks, and are consistent with the institution’s business and risk strategies, risk culture and corporate values, the long-term interests of the institution and conflicts of interest measures, and do not provide incentives for excessive risk-taking; d. the institution has correctly identified all its staff whose activities have a material impact on its risk profile in accordance with the applicable legal and regulatory requirements; e. the ratio of variable and fixed remuneration is appropriate, and the variable remuneration component does not exceed 100% of the fixed remuneration component (or 200% with shareholders’ approval) for the identified staff; f. the institution has made a proper allocation of the fixed and variable components, with no use of vehicles or practices to circumvent remuneration requirements;
g. variable remuneration is based on performance (considering both financial and non-financial criteria) and whether the institution adheres to related legal and regulatory requirements on deferral and retention periods, pay-out in instruments, and clawback and malus clauses.
5.5. Internal control functions
85.In assessing the institution’s internal control functions, competent authorities should assess institution’s compliance with the EBA Guidelines on Internal Governance and the relevant provisions of the Regulation (EU) 2022/2554 (DORA) . In this context, competent authorities should consider inter alia whether: a. the institution has an appropriate internal control framework covering all areas, consistent with the ‘three lines of defence’ model, including well-functioning, effective and independent risk management, compliance and internal audit functions; b. the heads of internal control functions (i) are established at an adequate hierarchical level that provides them with the appropriate authority and stature needed to fulfil their responsibilities, (ii) have direct access and can report directly to the management body in its supervisory function, and (iii) have all the resources necessary to perform their tasks; c. the institution has adequate written internal control policies effectively implemented and a clear allocation of responsibilities for the implementation of the framework, segregation of duties, sound administrative and accounting procedures and robust reporting arrangements.
86.Competent authorities should assess whether the risk management function covers the whole institution, having a holistic view of all risks, is actively involved at an early stage in elaborating the institution’s risk strategy and monitors its effective implementation. Competent authorities should also determine whether the risk management function provides the management body with complete, updated and relevant risk-related information to enable setting the institution’s risk appetite level and related risk limits. Competent authorities should also consider the risk management function’s assessment of the robustness and sustainability of the risk strategy and appetite as well as its involvement in the evaluation of the impact of material changes or exceptional transactions on the institution’s and group’s (where applicable) overall risk.
87.Competent authorities should assess whether the compliance function effectively assesses and mitigates compliance risks arising from non-compliance with applicable legal and regulatory requirements, contractual obligations or internal rules and codes of conduct, including rules on ethics, and ensures that all material risk management decisions adequately take into account these risks.
88.Competent authorities should assess whether the internal audit function independently reviews and provides objective assurance, in accordance with the audit plan and detailed work
programme, on the appropriateness and effectiveness of the institution’s policies, procedures and internal controls and on the compliance of all the institution’s activities, including activities provided by third-party service providers, with legal and regulatory requirements. Where applicable, competent authorities should assess whether the group-wide internal audit function is independent, has a group-wide risk-based audit plan, has appropriate resources and stature and has a direct reporting line to the management body of the consolidating institution.
5.6. Risk management framework
89.In assessing the institution’s risk management framework, competent authorities should assess institution’s compliance with the EBA Guidelines on Internal Governance, the DORA and other EBA Guidelines issued pursuant to Article 74(3) of Directive 2013/36/EU on internal governance arrangements, processes and mechanisms. In this context, competent authorities should consider inter alia whether: a. the institution has established an appropriate risk management framework and risk management processes, encompassing an appropriate and implemented risk strategy, risk appetite, including a third-party risk management policy, ICAAP and ILAAP frameworks and stress testing capabilities and results; b. where applicable, the group-wide risk management framework covers all material risks regardless of whether the risk arises from entities not subject to consolidation and establishes a comprehensive view on all risks the institution is or might be exposed to; c. the management body has the ultimate responsibility for the risk strategy, risk appetite and risk management framework and provides appropriate direction and oversight; d. the institution, and where applicable the consolidating institution, has documented and implemented an appropriate risk strategy and risk appetite, which cover all the institution’s material risks, contain risk limits and tolerances, and reflect the institution’s financial resources; e. the risk management framework establishes adequate procedures for risk identification, measurement, mitigation and monitoring and the extent to which it is embedded in, and how it influences, the overall strategy of the institution; f. the decision-making processes are clear, transparent and adequately documented, and take into account the appropriate risk considerations, and whether policies and amendments to policies are communicated in a proper and timely manner; g. there are appropriate and consistent links between the business strategy, risk strategy, digital operational resilience strategy, risk appetite and risk management framework, and the capital and liquidity management frameworks, as well as the institution’s plan to address ESG risks in accordance with Article 76(2) of Directive 2013/36/EU.
90.Competent authorities should assess whether the institution has in place a well-documented new product approval policy, approved by the management body, that addresses the development of new markets, products and services, and significant changes to existing ones, including exceptional transactions. Competent authorities should also consider whether the risk
management and compliance functions are appropriately involved in the assessment and approval of new products or significant changes to existing ones, with approvals linked to the adequacy of the respective controls.
ICAAP and ILAAP frameworks
91.In assessing the institution’s ICAAP and ILAAP frameworks, competent authorities should assess institution’s compliance with the EBA Guidelines on ICAAP and ILAAP information . The assessment of the institution’s ICAAP and ILAAP frameworks should encompass periodic review of the ICAAP and ILAAP and determine their soundness, effectiveness and comprehensiveness. In this regard, competent authorities should: a. assess how ICAAP and ILAAP are integrated into the institution’s overall risk management and strategic management practices, including capital and liquidity planning, as well as the extent of their forward-looking nature; b. consider the appropriateness of the ICAAP and ILAAP to assess and maintain an adequate level of internal capital and liquidity to cover the institution’s risks and to take sound business decisions (e.g. in relation to allocating capital under the business plan), including under stressed conditions; c. assess whether the ICAAP and ILAAP are embedded into the decision-making and management processes at all levels in the institution (e.g. limit setting, performance measurement); d. verify whether the ICAAP and ILAAP frameworks are subject to regular oversight by the management body, including the approval of these frameworks and their outcomes; e. assess whether the ICAAP and ILAAP are consistently and proportionately implemented in all the institution’s business lines and legal entities and cover all material risks to which the institution is or might be exposed to; f. assess compliance with related legal and regulatory requirements and also consider whether institution’s ICAAP identifies emerging risks and/or low-probability, high-impact risks, including ICT risks, environmental risks and geopolitical uncertainties; g. assess whether any deviations from the institution’s standard ICAAP or ILAAP for one or more of its legal entities or business lines are justified.
92.These assessments should contribute to the determination of P2R and to the assessment of capital adequacy as outlined in Title 7, as well as to the evaluation of liquidity and funding adequacy as outlined in Title 8.
Assessment of institution’s stress testing
93.In assessing the institution’s stress testing, competent authorities should assess institution’s compliance with the EBA Guidelines on stress testing and the EBA Guidelines on environmental
scenario analysis for the integration of environmental risks. This assessment encompasses the review of the institution’s stress testing programme, taking into account the size and internal organisation, and the nature, scale and complexity of the activities of the institution.
94.Competent authorities should perform a qualitative assessment of the institution’s stress testing programme, as well as a quantitative assessment of the results of stress tests. Competent authorities should consider the outcomes of qualitative and quantitative assessments together with the results of supervisory stress tests (see Title 11) for the purposes of assessing capital and liquidity adequacy and determining the appropriate supervisory response to the deficiencies identified. If the stress testing review identifies deficiencies in the institution’s governance and institution-wide controls, these should be considered by competent authorities in the assessment of these areas. Furthermore, the results of an institution’s stress tests can be used for the assessment of the institution’s capital planning, and in the quantification of liquidity requirements for the assessment of liquidity adequacy.
95.Competent authorities should assess the extent to which stress testing is embedded in the institution’s risk management framework, including how stress testing is considered in the processes of setting up the institution’s risk appetite and limits. Furthermore, competent authorities should assess the involvement of institution’s senior management and management body in the stress testing programme, including the related internal reporting, and the degree of integration of stress testing and its outcomes into the decision-making processes.
96.When assessing the stress testing programme, the results of stress tests and proposed management actions, competent authorities should consider both idiosyncratic and systemwide perspectives. Competent authorities should consider the feasibility of management actions in stress situations, including whether the timelines for the implementation of the actions are realistic and consider the idiosyncrasies of the institution. For the review of stress testing programmes of cross-border groups, competent authorities should take into account potential barriers to the transferability of capital and liquidity within groups and the functioning of any intra-group financial support arrangements, which may arise in stressed conditions.
97.Competent authorities should assess the results of stress tests and whether the institution is able to maintain the applicable TSCR, at all times, in an adverse scenario and if it has identified a set of management actions to address any potential breaches of the TSCR. Competent authorities should also consider the impact of stress tests on the institution’s leverage ratio, as well as its eligible liabilities held for the purposes of minimum requirements for eligible liabilities (MREL) as referred to in Directive 2014/59/EU.
98.In the assessment of stress test results, competent authorities should also consider all known future regulatory changes affecting the institution within the scope and the time horizon of the stress test exercise.
5.7. ICT systems, risk data aggregation and risk reporting
99. Competent authorities should assess whether the institution’s ICT systems are reliable, resilient and adequate to measure, assess and report on the size, composition and quality of exposures across all the institution’s risk types, products and counterparties and fully support risk data aggregation capabilities at normal times and times of stress.
100. Competent authorities should verify whether the institution develops and maintains appropriate risk data aggregation and risk reporting capabilities commensurate with its risk profile and systemic importance. When reviewing the institution’s risk data aggregation and risk reporting capabilities, competent authorities should take into account the BCBS 239 principles for effective risk data aggregation and risk reporting for supervised institutions that fall under the scope of those principles. In particular, competent authorities should assess whether the institution is able to generate accurate, consistent, complete and reliable risk data and reporting for the entire institution, capturing all material risks, and appropriately reflecting the institution’s risk profile and capital and liquidity needs, and whether these can be aggregated and made available in a timely and flexible manner to the management body and senior management. Where applicable, competent authorities should assess whether the institution has established an effective group-wide management information and reporting system applicable to all business units and legal entities, and this information is available to the management body of the institution’s parent undertaking on a timely basis.
101. Competent authorities should determine whether the management body of the institution approves the institution’s risk data aggregation and risk reporting framework and oversees its effective implementation, including deployment of adequate resources to support these efforts. Competent authorities should also assess whether the institution’s risk data aggregation capabilities and risk reporting practices are independently validated in accordance with the institution’s internal control framework.
5.8. ML/TF risks and prudential concerns
102. When analysing the internal governance framework and institution-wide controls, competent authorities should also take into account the assessments received from AML/CFT supervisors and evaluate whether these give rise to prudential concerns. Conversely, where the competent authority’s assessment indicates the shortcomings in an institution’s internal controls and governance framework and institution-wide controls give rise to prudential concerns related to ML/TF risk and risks of non-implementation and evasion of targeted financial sanctions, competent authorities should share the outcome of that assessment with AML/CFT supervisors.
103. Competent authorities should assess whether the institution’s overall internal governance and risk management framework includes also the management of the ML/TF risks and the risks of non-implementation and evasion of targeted financial sanctions.
104. Competent authorities should assess from a prudential perspective whether the roles and responsibilities of the management body with regard to the AML/CFT framework are being complied with. Competent authorities should take into account any supplementary information received from the AML/CFT supervisors following their assessment in line with the EBA Guidelines on policies and procedures in relation to compliance management and the role and responsibilities of the AML/CFT Compliance Officer .
5.9. Recovery planning governance
105. To assess internal governance and institution-wide controls, competent authorities should consider findings and deficiencies identified in the assessment of the recovery planning governance framework conducted in accordance with Articles 6 and 8 of Directive 2014/59/EU.
106. Similarly, findings identified from the assessment of the SREP elements, including internal governance and institution-wide control arrangements, should inform the assessment of institution’s recovery plans.
5.10. Summary of findings, scoring and supervisory measures
107. Following the above assessment, competent authorities should form a view on the adequacy of the institution’s internal governance arrangements and institution-wide controls. This view should be reflected in a summary of findings, accompanied by a viability score based on the considerations specified in table 4.
108. The table below presents a non-exhaustive list of supervisory measures that competent authorities may take in case of identified deficiencies in institution’s internal governance and institution-wide controls. Competent authorities should decide on the type of supervisory measure based on its effectiveness towards the specific identified deficiency. Competent authorities may apply additional supervisory measures or a combination of these with the ones listed in the table below, if these are deemed more appropriate to address the identified deficiencies. For breaches of DORA, competent authorities should consider the applicable corrective and remedial measures provided in Article 50 of DORA.
6. Title 6. Assessing risks to capital
6.1. General considerations
109. Competent authorities should assess and score the risks to capital that have been identified as material for the institution.
110. The purpose of this title is to provide common methodologies to be considered for assessing individual risks and risk management and controls. It is not intended to be exhaustive and gives leeway to competent authorities to take into account other additional criteria that may be deemed relevant based on their experience and the specific features of the institution.
111. This title provides competent authorities with guidance for the assessment and scoring of the following risks to capital: a. credit and counterparty risk; b. market risk; c. operational risk; d. interest rate risk from non-trading activities (IRRBB).
112. The title also identifies a set of subcategories within each risk category above, which need to be taken into account when risks to capital are assessed. Depending on the materiality of any these subcategories to a particular institution, they can be assessed and scored individually. Annexes I-IV present non-exhaustive lists of sub-categories for credit risk, market risk, operational risk and IRRBB that competent authorities should consider, when relevant.
113. The decision on materiality depends on the supervisory judgement. However, for FX lending risk, in light of the ESRB Recommendation on lending in foreign currencies , materiality should be determined taking into account the following threshold: loans denominated in foreign currency to unhedged borrowers constitute at least 10% of an institution’s total loan book (total loans to non-financial corporations and households), where such a total loan book constitutes at least 25% of the institution’s total assets.
114. Competent authorities should also assess other risks that are identified as material to a specific institution but are not listed above (e.g. pension risk, strategic and business risk, step-in risk, intra- and inter-risk concentration). The following may assist with the identification process: a. drivers of TREA; b. risks identified in the institution’s ICAAP; c. risks arising from the institution’s business model (including those identified by other institutions operating a similar business model); d. information stemming from the monitoring of key indicators; e. findings and observations from internal or external audit reports; f. recommendations and guidelines issued by the EBA, as well as warnings and recommendations issued by macroprudential authorities or the ESRB.
115. The above elements should also be taken into account by competent authorities when they are planning the intensity of their supervisory activity in relation to the assessment of a specific risk.
116. For credit, market and operational risk, competent authorities should evaluate inter alia the compliance of the institution with the legal acts published separately on the EBA website as referred to in paragraph 12. However, these guidelines extend the scope of the assessment beyond those minimum requirements to allow competent authorities to form a comprehensive view on risks to capital.
117. When evaluating risks to capital, competent authorities should also consider the potential impact of funding cost risk following the methodology included in Title 8 and may decide on the necessity of measures to mitigate this risk.
118. In their implementation of the methodologies specified in this title, competent authorities should identify relevant quantitative indicators and other metrics, which could also be used to monitor key indicators, as specified in Title 3, and should also consider, when appropriate, institutions’ internal risk measures.
119. For each material risk, competent authorities should assess and reflect in the risk score: a. inherent risk (risk exposures); b. the quality and effectiveness of risk management and controls.
120. This assessment flow is represented in figure 2 below.
121. When performing their assessments, competent authorities should use available information sources, including regulatory reporting, the institution’s internal metrics and reports (e.g. internal audit report, risk management reports, information from the ICAAP), on-site inspection reports and external reports (e.g. the institution’s communications to investors, rating agencies). Competent authorities should resort to ad-hoc reporting where it is strictly necessary and proportionate to carry out their supervisory tasks, and where the information is not duplicative or otherwise available, in accordance with the second subparagraph of Article 104(2) of the CRD. While the assessment is intended to be institution-specific, comparison with peers should be considered to identify potential exposure to risks to capital. For such purposes, peers should be defined on a risk-by-risk basis and might differ from those identified for BMA or other analyses.
122. In the assessment of risks to capital, competent authorities should also evaluate the accuracy and prudency of the calculation of minimum own fund requirements to identify situations where minimum own funds calculations may underestimate the actual level of risk. This assessment would inform the determination of the P2R as provided in section 7.2.3.
123. The outcome of the assessment of each material risk should be reflected in a summary of findings that provides an explanation of the main risk drivers, and a risk score, as specified in the following sections.
6.2. Assessment of credit and counterparty risk
6.2.1. General considerations
124. When assessing the credit risk management framework, competent authorities should evaluate the compliance of the institution with the legal acts published separately on the EBA website as referred to in paragraph 12.
125. Competent authorities should assess credit risk arising from all non-trading book exposures (including off balance sheet items). They should also assess the counterparty credit risk and the settlement risk that could fall under both non-trading and trading books. In order to perform such assessment, competent authorities should consider all the components that determine potential credit losses, and in particular: a. the probability of a credit event (i.e. default), or correlated credit events, that mainly concerns the borrowers and their ability to repay relevant obligations; b. the size of exposures subject to credit risk; c. the recovery rate of the credit exposures in the event of borrowers defaulting.
126. Competent authorities should take into account the possibility that these components may deteriorate over time and worsen compared to expected outcomes.
127. Competent authorities should assess the impact of ESG risks on the inherent credit risk as well as the adequacy of the credit risk controls related to ESG risks, giving priority to environmental risks. In particular, competent authorities should consider environmental transition and physical risks when carrying out the assessment of credit concentration risk and real estate risk, as well as when assessing credit risk in specific portfolios or exposure classes considered as materially exposed to environmental risks.
128. In addition, competent authorities should also pay attention to consideration given to ML/TF risks within the context of the credit-granting process, including whether the institution has systems and controls in place to ensure funds used to repay loans are from legitimate sources.
6.2.2. Assessment of inherent credit risk Identification of material sources of credit risk
129. Competent authorities should assess credit risk from both a current and forward-looking perspective, integrating the analysis of the current portfolio’s credit risk with the assessment of the institution’s credit risk strategy, risk appetite and risk limits (potentially as part of the wider assessment of strategy carried out as part of the BMA). Competent authorities should also consider how the expected, as well as the stressed, macro-economic developments could affect those elements.
130. To assess the inherent credit risk of an institution, competent authorities should first identify its credit risk exposure. To achieve this and ensure consistent identification of the sources of credit risk the institution is or might be exposed to, they should consider the following sources of information: a. regulatory reporting templates, such as COREP and FINREP, taking into account the relevant regulatory exposure classes based on the institution’s approach to own funds requirements (i.e., standardised or IRB); b. insights gained from the assessment of other SREP elements (such as the BMA) and from prior supervisory activities; c. comparisons of the institution’s position with its peers, where available. In particular, for institutions using the internal ratings-based approach, competent authorities should consider the result of the supervisory benchmarking exercise carried in accordance with Article 78 of Directive 2013/36/EU.
131. Competent authorities should focus their assessment primarily on the most significant identified sources of credit risk, evaluating their materiality for the institution from a prudential perspective. To conduct this assessment, they should consider the following elements: a. the credit risk strategy and appetite and relevant limits; b. the amount of exposure value for the considered portfolio, compared to the total exposure value of credit exposures, including its growth over time; c. the amount of own funds requirement for credit risk for the considered portfolio compared to the total own funds requirement, including its growth over time; d. where relevant, the internal capital allocated for credit risk for the considered portfolio by the institution compared to the total internal capital; e. the composition and quality of the institution’s on- and off-balance sheet credit-related items in the performing (including forborne exposure) and non-performing portfolio, including the level and change over time of impairments and write-offs and of the default rates of the credit portfolio.
132. Competent authorities should assess the materiality of the risk in relation to the current portfolio, as well as with an historical and forward-looking perspective (previous change in these figures and forecasts, where available).
133. As additional source of information for the materiality assessment, competent authorities should – where available and appropriate – consider the internal credit risk parameters used by the institution. This includes assessing their adequacy in accurately quantifying credit risk exposures across different portfolios, with particular attention to evidence from the yearly report produced by the validation function of the institution, and more specifically on backtesting outcomes – that is, comparing estimated parameters with observed outcomes as conducted by the institution. Competent authorities should place emphasis on portfolios where the estimated parameters have underestimated the observed outcomes.
134. Competent authorities should also consider the results of stress tests performed by the institution to identify any previously unidentified sources of credit risk, such as those emerging from changes in credit quality, credit concentrations, collateral value and credit exposure during a stressed period.
135. Based on the materiality assessment performed in the previous paragraphs, as well as the size and complexity of the institution’s credit risk and credit portfolio, competent authorities should choose the relevant level of details for the assessment.
Nature, size and composition of the institution’s credit portfolio (on- and off-balance sheet credit-related items)
136. Competent authorities should assess the nature of the credit exposures (i.e. the types of borrowers and exposures) and analyse the composition of the institution’s credit portfolio. In performing this assessment, competent authorities should also consider how the nature of credit risk exposure can affect the size of exposure (e.g. credit lines/undrawn commitments drawn down by borrowers, foreign currency denomination), taking into consideration the institution’s legal capacity to unilaterally cancel undrawn amounts of committed credit facilities.
137. To assess the nature of credit risk, competent authorities should consider at least the following subcategories of credit risk by carrying out a more detailed assessment of those subcategories which are considered most relevant for the institution : a. credit concentration risk; b. counterparty credit risk and settlement and delivery risk; c. country risk; d. credit risk from securitisations; e. FX lending risk; f. real estate risk; g. equity risk in the banking book; h. dilution risk; i. model risk for regulatory approved models.
138. Where specialised lending exposures are deemed material, competent authorities should assess such exposures separately from other lending activities, given that the risk of such exposures lies in the profitability of the asset or project financed (e.g. commercial real estate, energy plant, shipping, commodities) rather than the borrower (which is generally a special purpose vehicle). In conducting this assessment, competent authorities should consider: a. the profitability of the projects and the conservativeness of the assumptions underlying the business plans (including the credit risk of the main customers); b. the impact of changes in regulation, especially for subsidised sectors, on future cash flows; c. the impact of changing market demand, where relevant, and the existence of a market for the potential future sale of the object financed; d. the existence of a syndicate or of other lenders sharing the credit risk; e. any form of guarantee pledged by the sponsors; f. the potential increase in concentration risk that these activities may entail.
Portfolio credit quality
139. When assessing portfolio credit quality, competent authorities should pay particular attention to the adequacy of the classification of credit exposures and assess the impact of potential misclassification, with the subsequent delay in the provisioning and recognition of losses by the institution.
140. Competent authorities should carry out an analysis to distinguish between performing, nonperforming and forborne exposure categories, considering both the number of obligors and the relevant amounts/volumes. Competent authorities should assess the overall credit quality at portfolio level and the different quality grades within each of the above categories to determine the institution’s overall credit risk. As part of this assessment, competent authorities should analyse default and migration risk by exposure classes, taking into account trends in the credit quality over time, and they should consider whether the actual portfolio credit quality is consistent with the stated risk appetite and establish reasons for any deviations.
141. This should result in an overall assessment on the end-to-end credit cycle of the institution, from origination through the monitoring and management of each exposure categories. In conducting these analysis, competent authorities should employ peer comparison and use benchmark portfolios (i.e. portfolios of borrowers common to groups of institutions) where appropriate and possible. This analysis should be carried out taking into account: a. asset quality indicators, historical trends and grow rates by types of borrowers, sectors and product, borrowers’ credit grade distribution, historical migration rates across credit grades, delinquency and default rates for different time horizons; b. the non-performing rates and coverage per portfolio, sector, geography and changes over time, also taking into account the relevant inflows/outflows from each relevant portfolio, the distribution of the exposures across classes of non-performing exposures (i.e. past-due, doubtful), the level and change over time of impairments and write-offs for each relevant driver, historical recovery rates and the duration of the recovery process, foreclosed assets and changes over time, as well as the time since exposures were classified as nonperforming.
142. Competent authorities should assess whether the level of loan loss provisions and credit valuation adjustments are appropriate for the quality of the exposures and, where relevant, for the level of collateral, assessing in particular whether the level of loan loss provisions is consistent with the level of risk in different portfolios, over time and compared with the institution’s relevant peers as well as relevant macro-economic developments and whether the credit valuation adjustments to derivatives’ market values reflect the creditworthiness of relevant counterparties. Where deemed necessary, competent authorities should use on-site inspections or other appropriate supervisory actions to assess whether or not the level of loan loss provisioning and risk coverage is adequate, by assessing a sample of loans, for example. When conducting such assessment, competent authorities should also consider any findings raised by internal and external auditors, where available.
143. When evaluating the inherent credit risk of an institution, competent authorities should also take into account the results of stress tests performed by the institution to identify any previously unidentified sources of credit risk, such as those emerging from changes in credit quality, credit concentrations, collateral value and credit exposure during a stressed period.
Level and quality of the credit risk mitigation framework
144. Competent authorities should consider the level and quality of guarantees (including credit derivatives) and of available collateral that would mitigate credit losses where credit events occur, including those not accepted as eligible credit risk mitigation techniques for own funds calculations. In performing such assessment, competent authorities should consider: a. the coverage provided by collateral and guarantees by portfolio, borrower type, rating, sector, and other relevant aspects; b. collateral values, for performing and non-performing exposures; c. historical recovery ratios by type and amount of collateral and guarantees.
145. Competent authorities should also assess the materiality of the residual risk (as referred to in Article 80 of Directive 2013/36/EU) and in particular the adequacy and enforceability of collateral agreements and of guarantees, the timing and the ability to realise collateral and execute guarantees under the national legal framework, the liquidity and volatility in asset values for collateral and the recoverable value of collateral under any credit enforcement actions. Competent authorities should also assess the concentration of guarantors and collateral, as well as the correlation with borrowers’ creditworthiness (i.e. wrong-way risk) and the potential impact in terms of the effectiveness of protection.
ESG factors
146. When assessing the impact of ESG risks and environmental risks in particular on the inherent credit risk, competent authorities should aim at taking into account the specific characteristics of these risks such as their forward-looking nature and distinct impacts over various time horizons, recognising the uncertainties associated with long-term projections while developing their capacity to factor in these characteristics into their assessment.
6.2.3. Assessment of credit risk management and control framework
147. To achieve a comprehensive understanding of the institution’s credit risk profile, competent authorities should review the institution’s credit risk management and control framework and its adequacy with respect to the inherent credit risk exposures. For this assessment, competent authorities should also rely on the outcome coming from the assessment of other SREP elements (such as the BMA and governance areas). For institutions subject to the application of the NPE (reduction) strategies and the associated governance and operational guidance, competent authorities should also assess whether institutions meet specific requirements set out in the relevant EBA guidelines for such strategies and their operationalisation, including with respect to meeting the consumer protection obligations.
Credit risk strategy and appetite
148. Competent authorities should assess whether the institution has a sound, clearly formulated and documented credit risk appetite, strategy and limits approved by the management body. For this assessment, among other factors, competent authorities should take into account the role of the management body in setting, approving and reviewing the credit risk strategy and appetite, the proper implementation of this strategy by the senior management as well as its appropriateness for the institution given its business model, overall risk appetite, current and prospective market environment and financial condition.
Organisational and internal control framework
149. Competent authorities should assess whether the institution has an appropriate organisational framework and governance arrangements to enable effective credit risk taking, management, measurement and control, with sufficient (both qualitative and quantitative) human and technical resources to carry out the required tasks. They should in particular assess whether the institution’s management body and senior management understand the assumptions underlying the credit measurement system. For this assessment, competent authorities should take into account the adequacy of the lines of responsibility, as well as staffs’ skills and experience to perform their tasks, for taking on, measuring, monitoring and reporting credit risk, including management of NPEs, and in particular NPE workout, and finally the existence of a clear separation between risk-takers and risk managers.
150. Competent authorities should assess whether the institution has appropriate policies and procedures for the credit granting, identification, measurement, reporting and control of credit risk and whether these are consistent with the institution’s credit risk strategy and cover all the main businesses and processes. This includes the assessment of whether these policies are clearly formalised, communicated and applied consistently across the institution and the banking group it belongs to. For this assessment, competent authorities should take into account whether the management body approves these policies and discusses and reviews them regularly, in line with risk strategies as well as whether senior management is responsible for drawing up and implementing the policies and procedures, as defined by the management body.
151. Competent authorities should assess whether the institution has an appropriate framework for identifying, understanding, measuring, monitoring and reporting credit risk, in line with the institution’s size and complexity. In this regard, competent authorities should consider whether the institution has adequate data infrastructure and whether analytical techniques are appropriate to enable the institution to adequately manage their credit risk, and to fulfil supervisory reporting requirements, and to detect, measure and regularly monitor the credit risk inherent in all on- and off-balance-sheet activities (where relevant at group level).
152. Competent authorities should assess whether the institution’s management body and senior management understand the assumptions underlying the credit measurement system and whether they are aware of the degree of relevant model risk. They should assess whether the institution has undertaken stress testing to understand the impact of adverse events on its credit risk exposures and on the adequacy of its credit risk provisioning, by considering the stress test frequency, relevant risk factors identified, assumptions underlying the stress scenario; and the internal use of stress testing outcomes for capital planning and credit risk strategies.
153. Competent authorities should assess whether the institution has defined and implemented continuous and effective monitoring of credit risk exposures (including credit concentration) throughout the institution, amongst others, by means of specific indicators and relevant triggers to provide effective early warning alerts. Competent authorities should assess whether the institution has implemented regular reporting of credit risk exposures, including the outcome of stress testing, to the management body, senior management and the relevant credit risk managers.
154. Competent authorities should assess whether the institution has a strong and comprehensive internal control framework and sound safeguards to mitigate its credit risk in line with its credit risk strategy and appetite. For this assessment, competent authorities should in particular pay attention to the adequate scope covered by the institution’s control functions (including all consolidated entities, geographical locations and credit activities), to the existence of operating limits and other practices aimed at keeping credit risk exposures within levels acceptable to the institution in accordance with its risk appetite and limits. For this purpose, competent authorities should pay particular attention to whether institution has appropriate internal controls and practices to ensure that breaches of (or exceptions to) policies, procedures and limits are reported in a timely manner to the appropriate level of management for action, including checks to identify, assess and manage ML/TF risks to which the institution is exposed as a result of the credit granting activities.
155. In conducting this assessment, competent authorities should consider whether the limit system is adequate for the institution’s complexity and its capacity to measure and manage credit risk. This includes assessing whether the limits established are absolute or whether breaches thereof may occur. In the latter case, the institution’s policies should clearly describe the period of time during which and the specific circumstances under which such breaches of limits are possible. Furthermore, competent authorities should assess the adequacy of the procedures in place to keep credit managers informed about their limits, as well as whether such limits are subject to regular review and updates (e.g. to remain aligned with changes in strategy).
156. Competent authorities should also assess the functionality of the internal audit function in terms of adequacy, scope and frequency of internal audits on the credit risk management framework. These audits should capture the review of the main elements of credit risk management, measurement and controls framework across the institution and the adherence to relevant external regulations of the internal policies and procedures and any deviations from either.
157. For institutions adopting an internal rating-based approach to determining minimum own funds requirements for credit risk, competent authorities should also assess whether the internal validation process is sound and effective in challenging model assumptions and identifying any potential shortcomings with respect to the credit risk management system. This assessment should be based – where available – on the information stemming from already performed supervisory activities on internal models (such as onsite inspections) and taking into account the supervisory practices detailed in the EBA Supervisory handbook for the validation of internal ratings-based systems .
6.2.4. Summary of findings, scoring and supervisory measures
158. Following the above assessment, competent authorities should form a view on the institution’s credit and counterparty risk. This view should be reflected in a summary of findings, accompanied by a risk score based on the considerations specified in table 6. Where, based on the materiality of certain risk sub-categories, the competent authority decides to assess and score them individually, the guidance provided in this table should be applied, as far as possible, by analogy.
159. The table below presents a non-exhaustive list of supervisory measures that competent authorities may take in case of identified deficiencies in the institution’s credit and counterpart risk management framework. Competent authorities should decide on the type of the measure based on its effectiveness to the specific identified deficiency. Competent authorities may apply additional supervisory measures (including quantitative measures in accordance with Article 104(1)(a) of the Directive 2013/36/EU) or a combination of them if these are deemed more appropriate to address the identified deficiencies.
6.3. Assessment of market risk
6.3.1. General considerations
160. When assessing the market risk management framework, competent authorities should evaluate inter alia the compliance of the institution with the legal acts published separately on the EBA website as referred to in paragraph 12.
161. In these guidelines, references to ‘market risk’ will encompass all the following risks, which should be assessed by competent authorities: a. the market risk arising from all on- and off-balance-sheet positions which are subject to losses arising from movements in market prices, i.e. risks in trading book positions as well as the foreign-exchange and commodity risk in the non-trading book; b. the risk of losses arising from changing CVA amounts in response to changes in counterparty credit spreads and/or market prices, impacting the fair value of derivative transactions and, if applicable, of security financing transactions (SFTs); c. the risk linked to the valuation of fair-valued instruments in the sense of Article 105 of Regulation (EU) 575/2013.
162. Competent authorities may perform a less granular analysis for institutions which meet the conditions of the small trading book as set out in Article 94 of Regulation (EU) 575/2013. For institutions with immaterial exposures, the assessment should focus on the adequacy of the risk management and governance structure and the quality and effectiveness of systems and controls.
163. Competent authorities should take into account the impact of ESG risks on the inherent market risk as well as the adequacy of the market risk management framework and controls related to ESG risks, giving priority to environmental risks.
6.3.2. Assessment of inherent market risk
164. Through the assessment of inherent market risk competent authorities should determine the main drivers of the institution’s risk exposures and evaluate the risk of significant prudential impact on the institution. To develop such an understanding, competent authorities should first identify the market risks to which the institution is or may be exposed and focus their attention on the subcategories and drivers deemed the most material for the institution.
165. To support this analysis, competent authorities should consider, as a minimum, the products, activities and business lines of the institution. They should compare the own funds requirements for market and CVA risk and the additional valuation adjustment deducted from the institution own funds, against the total own funds requirements. Where relevant they should compare the internal capital allocated to those risks by the institution against the total internal capital. They may also consider the relative weight of market risk positions in terms of total assets, the relative weight of net gains on market risk positions to total operating income and the historical changes in these figures and forecasts. Also, the strategy of the institution as regards market activities and the related risk appetite should be taken into account. When considering market activities, competent authorities should refer to the risks mentioned in paragraph 161 which may encompass the trading and non-trading book.
Nature and composition of the institution’s risk activities
166. The first step in assessing the nature of the inherent market risk of an institution is to identify its market risk exposures consistently and comprehensively. Competent authorities should use available regulatory reporting templates, such as COREP and FINREP, internal reporting, insights gained from the assessment of other SREP elements (such as the BMA) or prior supervisory activities, and comparisons with the institution’s peers, where available.
167. Competent authorities should base their assessment primarily on the most significant identified sources of risk, evaluating their materiality for the institution from a prudential perspective. To assess the nature of market risk, competent authorities should consider at least the following subcategories : a. interest rate risk (trading book); b. credit spread for non-securitisation, credit spread for securitisation (trading book); c. equity risk (trading book); d. migration risk (for business subject to a default risk charge) ; e. default risk (for business subject to a default risk charge); f. foreign exchange risk, including translation risk (both in the trading and banking book); g. commodities risk (trading and banking book); h. CVA risk (trading and banking book); i. valuation risk (fair-valued instruments in the trading and non-trading books).
168. Competent authorities should also consider: a. the complexity of financial products (e.g. products valued using mark–to-model techniques, products bearing non-delta risks and basis risks). Competent authority may assess this by using as an indicator the add-on resulting from residual risks as per Article 325u of Regulation 575/2013/EU; b. the liquidity of the institution’s exposure. The competent authority can do so by assessing whether the institution is exposed to subcategories with high liquidity horizons in accordance with table 2 of Article 325bd of Regulation 575/2013/EU; c. the concentration of market risk towards specific names, sectors, economies, risk-classes; d. the employment of specific market operations the risk of which may not be fully represented by the market risk own funds requirements (e.g. high-frequency trading).
169. When appropriate, competent authorities should also consider the internal risk measures of institutions. These could include the internal VaR or expected shortfall not used in the calculations of own funds requirements or sensitivities of the market risk to different risk factors and potential losses.
170. Competent authorities should also assess the institution’s ability to form a comprehensive view on the degree of market concentration risk to which it is exposed, either from exposures to a single risk factor or from exposures to multiple risk factors that are correlated, thereby paying specific attention to concentrations in complex and illiquid products. They should review the firm’s own assessment of concentrations and illiquid positions. Competent authorities should require institutions to reduce exposure towards a given CCP in case of excessive concentration risk, or to realign exposures across their clearing accounts in accordance with Article 7(a) of Regulation 648/2012.
171. When determining whether P2R should be imposed for the market risk to which the institution is exposed, in line with paragraph 300, competent authorities should consider whether the Pillar 1 methodology adequately captures the risk, taking into account that: a. institutions employing the alternative standardised approach are required under Pillar 1 to calculate an add-on (residual risk add-on) for the risks inherent in complex financial products that are not sufficiently captured in the sensitivity-based method and the default risk charge; b. institutions employing the internal model approach or the alternative internal model approach are required to capture all material risks in those internal models; c. the risk-weights provided in the alternative standardised approach, the expected shortfall measures referred to in Article 325bb of Regulation 575/2013/EU and the stress scenario risk measures referred to in Article 325bk of Regulation 575/2013/EU in the alternative internal model approach are designed to cater for the positions’ liquidity in line with liquidity horizon referred to in table 2 of Article 325bd of Regulation 575/2013/EU.
172. Competent authorities should identify and analyse in relation to market risk positions and the corresponding governance arrangements, any transfer pricing arrangements between institutions established in the Union that are part of a third-country group and other entities of that group established outside of the Union and not consolidated by the EU parent undertaking. The analysis should include: a. a quantitative component to identify the materiality of the transfer pricing arrangements relative to the trading book total P&L and the own funds of the institution; b. a qualitative component to assess if the effect of these arrangements is transparent to the institution’s management board and appropriately reflected in the risk management governance; c. a qualitative component to assess how the transfer pricing arrangement affects the business decisions of the institution, including how the dynamics of the transfer pricing arrangement potentially affect the decisions of front-office desks, and the potential conflicts of interest that the arrangement may create.
173. Competent authorities should identify the materiality of the transfer pricing in the context of trading book items by focusing on the transfer pricing arrangements that meet the following conditions: a. they involve at least one entity of the group that is established outside of the Union and for which the highest level of consolidation is outside the Union; b. they are based on a transaction profit method (TPM) – or any similar practice that would be economically equivalent – in accordance with which the profits and losses relating to positions owned by several entities are re-distributed across those entities on the basis of the marginal contribution ‘m’ of each entity towards key-metrics set out in the pricing arrangement.
174. For institutions under paragraph 1733, point (a), where the profits and losses, re-allocated as a result of transfer pricing arrangements based on transaction profit methods, are material (e.g. account for more than 5% of the P&L generated by the institution) and this risk is not covered or fully covered by P1R, competent authorities should: a. consider this risk for the determination of P2R; b. consider the results of the components listed in paragraph 1722, such as the materiality of the transfer pricing arrangements, in relation to the market risk capital requirements of the portfolio whose profits and losses are used to determine the amount to be transferred to the institution as well as potential weaknesses in the related governance arrangements; c. determine P2R that sufficiently cover the market risks not captured under P1R which are generated under the transfer pricing arrangement. To that end, competent authorities may use the calculation method as laid down in Annex V or an alternative methodology that provides accurate measurement of the risk not covered in P1R and identifies the consequent P2R, considering as a reference the methodology in Annex V.
Profitability analysis and stress testing
175. Competent authorities should analyse the historic profitability, including volatility of profits, of market activities to gain a better understanding of the institution’s risk profile for market risk. This analysis could be performed at portfolio level as well as being broken down by business line, asset class or desk depending on the materiality and complexity of the institution’s exposures (as emerging from the BMA or other supervisory insight).
176. Competent authorities should distinguish between trading and non-trading revenues (such as commissions, clients’ fees, etc.) on one hand and realised and unrealised profits/losses on the other hand.
177. For those asset classes and/or exposures generating significant profits or losses, competent authorities should assess profitability in comparison to the level of risk assumed by the institution (e.g. VaR/net gains on financial assets and liabilities held for trading) to identify and analyse possible inconsistencies. Where possible, competent authorities should compare the institution’s figures to its historical performance and its peers.
178. Competent authorities should assess whether an institution has implemented adequate stress tests that complement its risk measurement system. For this purpose, they should take into account the following elements: a. stress test frequency; b. whether relevant risk drivers are identified (e.g. illiquidity/gapping of prices, concentrated positions, one-way markets); c. assumptions underlying the stress scenario; d. internal use of stress testing outcomes for capital planning and market risk strategies.
6.3.3. Assessment of the market risk management and control framework
179. To achieve an adequate understanding of the management of market risk, commensurate to the institution’s risk profile, competent authorities should review the institution’s risk management and control framework and its adequacy with respect to inherent risk exposures. For this assessment, the competent authority should use the paragraphs set out in this section, while also leveraging on: a. the outcome of the assessment of other SREP elements (such as the BMA and governance areas); b. the outcome of the assessment referred to in Article 325c of Regulation 575/2013/EU for institutions using the alternative standardised approach, and the outcome of the assessment performed in accordance with Delegated Regulation (EU) 2024/1085, especially in relation to the requirements referred to in Articles 104b, 325bi, and 325bj of Regulation 575/2013/EU.
180. Competent authorities should also assess the policies and procedures of institutions to allocate the positions to the trading book and to the banking book, as described by Title 1 of Chapter 3 of Regulation 575/2013/EU.
Market risk strategy and risk appetite
181. Competent authorities should assess whether institutions have sound, clearly formulated and documented risk appetite, strategy and limits approved by their management body. For this assessment, among other factors, competent authorities should take into account the role of the management body in setting, approving and reviewing the risk strategy and appetite, the proper implementation of this strategy by the management body as well as its appropriateness for the institution given its business model, overall risk appetite, current and perspective market environment and financial condition.
Organisational and internal control framework
182. Competent authorities should assess whether the institution has an appropriate organisation framework for identifying, understanding, measuring, monitoring and controlling market risk, with sufficient (both qualitative and quantitative) human and technical resources to carry out the required tasks. For this assessment, competent authorities should take into account the adequacy of the lines of responsibility for taking, monitoring, reporting and controlling market risk, their coverage of the entire institution, the existence of a clear separation between the front office and back office and between the risk-taking and the control functions, and the skills and expertise of staff involved.
183. Competent authorities should assess whether the institution has clearly defined policies and procedures for the identification, management, measurement and control of market risk and whether these are sound and consistent with the institution’s risk strategy and cover all the main businesses and processes. This includes the assessment of whether these policies and procedures are clearly formalised, communicated and applied consistently across the institution.
184. In particular, the assessment should cover the positions to be included/excluded from the trading book for regulatory purposes, the policies on internal hedges and the procedures for new market activities and/or products.
185. Competent authorities should assess whether the institution has an appropriate framework for identifying, understanding and measuring market risk, in line with the institution’s size and complexity, and that this framework is compliant with relevant minimum requirements in accordance with the applicable legal and regulatory framework.
186. Competent authorities should assess whether institutions have in place an adequate monitoring and reporting framework for market risks that ensures there will be prompt action at the appropriate level of the institution’s senior management or management body in case of breaches. The monitoring system should include specific indicators and relevant triggers to provide effective early warning alerts and should inform the management body and senior management about current exposures and measures compared to policy limits.
187. Competent authorities should assess whether the institution has a strong and comprehensive limit systems and control framework with sound safeguards to mitigate its risks in line with its risk strategy and appetite. For this assessment, competent authorities should pay particular attention to the adequate scope covered by the institution’s control functions (including all consolidated entities, geographical locations and market activities), to the existence of operating limits (including individual limits at desk or business-unit level which should be daily monitored) and other practices aimed at keeping market risk exposures within levels acceptable to the institution in accordance with its risk appetite and limits.
188. Competent authorities should also assess whether the internal validation process is sound and effective in challenging model assumptions and identifying any potential shortcomings with respect to the market risk management system. For institutions adopting an internal approach to determining minimum own funds requirements for market risk, this assessment should be based – where available – on the information stemming from already performed supervisory activities on internal models (such as on-site inspections).
189. Competent authorities should also assess the functionality of the internal audit function in terms of adequacy, scope and frequency of internal audits on the market risk management framework. This should comprise the review of the main elements of risk management, measurement and controls framework across the institution and the adherence to relevant external regulations of the internal policies and procedures and any deviations from either.
6.3.4. Summary of findings, scoring and supervisory measures
190. Following the above assessment, competent authorities should form a view on the institution’s market risk. This view should be reflected in a summary of findings, accompanied by a risk score based on the considerations specified in table 8. Where, based on the materiality of certain risk sub-categories, the competent authority decides to assess and score them individually, the guidance provided in this table should be applied, as far as possible, by analogy.
191. The table below presents a non-exhaustive list of supervisory measures that competent authorities may take in case of identified deficiencies in the institution’s market risk management framework. Competent authorities should decide on the type of the measure based on its effectiveness to the specific identified deficiency. Competent authorities may apply other supervisory measures (including quantitative measures in accordance with Article 104(1)(a) of the Directive 2013/36/EU) or a combination of them if these are deemed more appropriate to address the identified deficiencies.
6.4. Assessment of operational risk
6.4.1. General considerations
192. When assessing the operational risk management framework, competent authorities should evaluate inter alia the compliance of the institution with the legal acts published separately on the EBA website as referred to in paragraph 12.
193. Competent authorities should assess operational risk throughout all the business lines and operations of the institution, taking into account findings from the assessment of internal governance arrangements and institution-wide controls as specified in Title 5. In conducting this assessment, competent authorities should determine how operational risk may materialise, also considering the loss data set of the institution and potential impacts from other related risks (e.g. boundary credit-related and market-related operational risk).
194. Competent authorities should assess the materiality of operational risk arising from third-party service providers, including concentration (at entity and where relevant at group level) on one or more services provided by a single third-party service provider (directly or indirectly through subcontracting chains) or a limited number of third-party providers supporting institution’s critical or important functions, and whether these could affect the institution’s operational resilience, performance and risk management. When carrying out this assessment, competent authorities should take into account the extent to which the same third-party service providers are relied upon by other institutions, where such information is available to them.
195. When assessing operational risk, competent authorities should assess ICT risk, pursuant to DORA, and its potential impact on the institution’s critical or important functions, including any potential financial, reputational, regulatory and strategic impact to the institution.
196. Competent authorities should assess whether the institution has an adequate operational resilience approach to be able to withstand, adapt to and recover from disruptions when they materialise and whether this has been adequately and consistently aligned with the existing risk management framework, business continuity plans and third-party management.
197. When assessing operational risk, competent authorities should assess, if applicable, whether the institution’s policies and procedures identify, evaluate and manage appropriately the operational risks arising from crypto-assets activities and their supporting technology.
198. Competent authorities should assess reputational risk jointly with operational risk as it is inherently linked to operational risk events. However, the outcome of reputational risk assessment should not be reflected in the scoring of operational risk but, where relevant, should be considered as part of the BMA and/or the liquidity risk assessment, as its main effects can deteriorate investors’, depositors’ or interbank-market participants’ confidence to the institution.
199. Competent authorities should assess the impact of ESG risks on the inherent operational and reputational risks as well as the adequacy of the operational risk and reputational risk controls related to ESG risks, giving priority to environmental physical and transition risks. In particular, competent authorities should consider environmental risks and greenwashing risks when carrying out the assessment of legal risk and reputational risk.
6.4.2. Assessment of inherent operational risk
200. Competent authorities should develop a thorough understanding of the institution’s inherent operational risk exposures and evaluate the significance of the prudential impact of this risk for the institution as well as the impact on its ability to deliver critical or important functions through disruption.
201. To support this assessment, competent authorities should consider the own funds requirement for operational risk compared to the total own funds requirement, and where relevant the internal capital allocated for operational risk by the institution compared to the total internal capital. Moreover, competent authorities should leverage the knowledge gained from the assessment of other SREP elements (in particular from Title 4 and Title 5), from the comparison with peers, from any other supervisory activities including the input from the AML/CFT supervisors and market surveillance authorities and from other relevant information sources.
202. Competent authorities should consider at minimum key operational risk factors, potential disruptive scenarios, and where relevant, analyse them by business line, legal entity, geography, and event type category (subject to data availability) and benchmark the institution’s position against its peers. These factors should at least cover the institution’s main strategy for operational risk and operational risk appetite, business environment (including geographical presence, ICT operations, and distribution channels), recent significant corporate events (such as mergers, acquisitions, disposals and restructuring), ICT systems and other ICTrelated aspects as per section 6.4.2.3, process changes, third-party arrangements, regulatory compliance issues, business ambitions and incentive schemes and other key operational risk drivers.
Nature and significance of operational risk exposures
203. Competent authorities should determine the nature of operational risk exposures by analysing exposures to the main sources and drivers of operational risk to form a forward-looking view on prospective operational risk. For this analysis, competent authorities: a. may consider the operating model, business lines, products, processes and geographies relevant to the institution, assessment of dependencies and operational risk exposures to primary risk drivers (e.g. processes, people, systems and external factors) and interactions of risk drivers, leveraging the institution’s self-risk assessment, peer analysis, data and public and/or consortium databases, if available and relevant; b. should consider both the frequency and the severity of the events to which the institution is exposed and distinguish those causing high-severity losses and those occurring with high frequencies. Based on this distinction, competent authorities should assess the trends of operational risk losses and their concentration; and c. should leverage scenario analyses and consider planned business operations and prospective operational risk analyses performed by the institution, where available, taking into account any corrective measures and mitigation actions already implemented and effective.
204. Following the identification and analysis of the major sources and drivers of operational risk, competent authorities should focus on those with the most material potential impact to the institution.
205. A primary source of information competent authorities should consider it is the institution’s loss and event data set as it can provide valuable insights on the evolution of the institution’s operational risk profile. Competent authorities should periodically assess the comprehensiveness, accuracy and quality of the loss data. Another source of information should be the institution’s records of all ICT-related incidents and significant cyber threats (as per Article 17(2) of DORA) and the identified sources of ICT risk (as per Article 8(2) of DORA).
Assessment of operational risk sub-categories
206. Competent authorities should focus the assessment of operational risk sub-categories to those which are considered material to the institution. Competent authorities should also apply their expert judgement to identify significant sub-categories, based on all available internal and external information sources. In conducting the assessment, competent authorities should always pay attention to the following aspects of operational risk : a. legal risk; b. model risk; c. ICT risk.
6.4.2.1. Legal risk
207. Competent authorities should consider the following when assessing the relevance and significance of the institution’s exposures to legal risk: a. mis-selling of products or services; b. conflicts of interest in conducting business; c. manipulation of benchmark interest rates, foreign exchange rates or any other financial instruments or indices; d. barriers to switching financial products during their lifetime and/or to switching financial service providers; e. automatic renewals of products or exit penalties; and/or f. customer complaints processing; g. violation of national and international rules and regulations (tax rules, internal fraud or internal theft, anti-money laundering rules, anti-terrorism rules and economic sanctions); h. ESG-related, in particular environment-related and greenwashing-related, litigation exposures.
208. Competent authorities should consider whether the institution may occur any expenses, fines, penalties or punitive damages from legal proceedings and the number and content of complaints. The outcomes of the Title 4 assessment should be also leveraged, along with scrutinising the incentive policies, to obtain high-level insights into sources of potential misconduct. In this context, competent authorities should also consider whether the institution has in place adequate and effective systems and processes to implement and comply with restrictive measures (e.g. sanctions), including assessing institution’s compliance with the EBA Guidelines on internal policies, procedures and controls .
209. However, the competent authority should apply a forward-looking approach, also considering the possible impact of regulatory developments and the activity of relevant authorities in respect of consumer protection and the supply of financial services in general.
6.4.2.2. Model risk
210. Under the operational risk, competent authorities should assess model risk, with specific regard to internal non-regulatory models (e.g. AI models, product pricing, setting and monitoring risk limits, ICAAP/ILAAP models, recovery options).
211. For the assessment of model risk, competent authorities should consider: a. to what extent and for which purposes the institution uses models to make decisions and the business significance of such decisions. Competent authorities should determine the business/activity for which the institution makes significant use of models and assess the potential impact of model risk through, amongst others, sensitivity and scenario analyses or stress testing; and b. the soundness of control mechanisms (in terms of methods, frequency, follow-up, etc.), including a model approval process, regular reviews performed and the institution’s level of awareness of model deficiencies or market and business developments.
212. When models are used for decision-making purposes (e.g. product pricing, AI models, evaluation of financial instruments, client profiling), competent authorities should assess whether there is a sound internal validation process and/or model-review process to identify and mitigate model risk (other than regulatory models).
213. When conducting the model risk assessment, competent authorities should consider the assessment of other risks to capital and risks to liquidity and funding, in particular with respect to the adequacy of methodologies used for measuring risk, pricing and evaluating assets and/or liabilities. The results of such an assessment should inform the findings on operational risk.
6.4.2.3. ICT risk - Assessment of inherent ICT risk Identification of material ICT risks
214. In line with DORA, competent authorities should review the institution’s identification, classification and documentation of all ICT supported business functions, roles and 43 44 responsibilities, the information assets and ICT assets supporting those functions, and their roles and dependencies in relation to ICT risk. This review should assist competent authorities to develop a thorough understanding of the institution’s inherent ICT risk exposures (ICT risk profile), identify its material inherent ICT risk and form an opinion on its prudential impact. For this purpose, competent authorities should consider at least the following, where relevant and applicable: a. report on the review of ICT risk management framework (as per Article 6(5) of DORA); b. sources of ICT risk, in particular the risk exposure to and from other financial entities, identified by the institution under Article 8(2) of DORA; c. major ICT-related incidents reported (as per Article 19(1) of DORA), including the trend of aggregated annual costs and losses caused by major ICT-related incidents (as per Article 11(10) of DORA); d. outcomes of the tests envisaged in the digital operational resilience testing programme (as per Article 24 of DORA)), including summary of the threat-led penetration testing (TLPT) findings and related remediation plans (as per Article 26(6) of DORA); e. register of information (as per Article 28(3) of DORA), including degree of concentration on ICT third-party service providers, including ICT intra-group providers, per type of ICT services and/or ICT systems; f. recommendations and opinions from the Lead Overseers (as per Article 40(3) and Article 42(7) of DORA) and related responses, reports and information from critical ICT third-party service providers (as per Article 35(1)(c), Article 42(1) and Article 48(2) of DORA); g. level of complexity of ICT systems and results of ICT risk assessment on legacy ICT systems (as per Article 8(7) of DORA); h. risk assessment on major changes (as per Article 8(3) of DORA); i. level of adoption and integration of innovative ICT solutions; j. locations, namely the regions or countries, of data centres and sensitive designated areas, including where contractual ICT services are provided by ICT third-party service providers, also covering data processing and storage location; k. any related material deficiencies or weaknesses identified under Title 5; l. ICT risk and controls self-assessments (if provided in the ICAAP information); m. ICT risk-related management information submitted to the institution’s management body; n. ICT-related internal and external audit findings; o. external threat environment, including threat and vulnerability intelligence.
Review of ICT systems and ICT services
215. Competent authorities should review the institution’s relevant documentation, methodology and processes, and form an opinion on whether the institution has appropriately identified the ICT systems and ICT services that support critical or important functions. For this purpose, competent authorities should consider: a. ICT systems supporting critical or important functions as well as the critical information assets and ICT assets identified by the institution (as per Article 8 of DORA); b. key processes dependent on ICT third-party service providers, including interconnections with ICT third-party service providers that support critical or important functions, identified by the institution (as per Article 8.5 of DORA).
Identification and mapping of material ICT risks to ICT systems and ICT services that support critical or importance functions
216.Following the review of the institution’s dependency on information assets and ICT assets, ICT risk profile, ICT systems and ICT services, competent authorities should form an opinion on the material ICT risks that can have a significant prudential impact on the institution’s ICT systems
and services that support critical or important functions and a significant impact on its ability to operate under disruption. For this purpose, competent authorities should consider: a. financial loss, including potential customer compensation, legal and remediation costs, contractual damages, costs and lost revenue; b. potential for business disruption, considering (but not limited to) the criticality of the services affected, including institution’s transactions and operations (including third-party dependencies), the number of clients and/or financial counterparts and/or branches and employees potentially affected; c. potential data losses; d. potential reputational impact; e. potential regulatory impact, including the potential for public censure, fines or even variation of permissions; f. potential strategic impact on the institution; g. potential geographical spread.
217. Competent authorities should then map the identified material ICT risk into the ICT risk categories set out in Annex III. Institutions are expected to maintain their own categorisation rather than using the one set out in the Annex.
6.4.3. Assessment of operational risk management and control framework
218. Competent authorities should assess the framework and arrangements the institution has in place to manage and control operational risk taking into account the outcome of the analysis of the overall risk management and internal control framework addressed in Title 5, as this will influence the institution’s operational risk exposures. Regarding ML/TF risk, the competent authority should take into account the assessment provided by the AML/CFT supervisor.
Operational risk strategy and appetite
219. Competent authorities should assess whether the institution has a sound, clearly formulated and documented operational risk strategy and appetite level approved by the management body, which outlines the nature, types and levels of operational risk the institution is willing to assume. For this assessment, among other factors, competent authorities should take into account the role of the management body in setting, approving, implementing and reviewing the operational risk strategy and appetite (including ICT risk appetite and digital operational resilience strategy), the strategy’s sufficient coverage and appropriateness with respect to the nature and materiality of the institution’s operational risk profile.
Organisational and internal control framework
220. Competent authorities should assess the institution’s compliance with Article 323 of the Regulation (EU) No 575/2013. In this assessment, competent authorities should evaluate the soundness and effectiveness of the organisational framework and governance arrangements to enable effective operational risk management, measurement and control, with sufficient human and technical resources to carry out the required tasks. Competent authorities should take into account whether clear lines of responsibility are in place for the identification, evaluation, mitigation, monitoring and reporting of operational risk as well as adherence to the three lines of defence model.
221. Competent authorities should assess whether the institution has a strong control framework and sound safeguards to mitigate its operational risk, including appropriate policies and procedures, covering also residual risk, and whether these are consistent with the institution’s operational risk management appetite and strategy and cover all the key operations and processes. This includes, amongst others, the assessment of whether these policies and procedures are clearly formalised, communicated and applied consistently across the institution.
222. Competent authorities should also assess the functionality of the internal audit function in terms of adequacy, scope and frequency of internal audits on the operational risk management framework.
Business continuity, response and recovery
223. Competent authorities should assess the institution’s compliance with the (i) EBA Guidelines on Internal Governance in relation to the overall business continuity management and with the (ii) DORA in relation to the ICT business continuity policy and ICT response and recovery plans. In this regard, competent authorities should determine whether ICT business continuity policy and ICT response and recovery plans form an integral part of the institution’s overall business continuity policy and response and recovery plan.
224. Competent authorities should assess whether the institution has established effective business continuity management with tested business continuity, response and recovery plans covering at least its critical or important functions, including those contracted to third-party providers, and whether these consider a range of severe but plausible scenarios to which the institution may be vulnerable. Competent authorities should also assess whether the institution’s business continuity policy enables appropriate response and recovery measures to any type of incident.
225. Competent authorities should determine whether the institution’s business continuity management includes: a. Business Impact Analysis (BIA); b. appropriate recovery strategies incorporating key internal and external dependencies and clearly defined recovery priorities and resilience levels; c. comprehensive and flexible plans to deal with plausible disruptive scenarios, which are established based on the BIA and in coordination with internal and external stakeholders; d. plans that establish contingency strategies and response and recovery procedures; e. effective testing of the design and operational effectiveness of the plans; f. BCM awareness and training programmes; g. communications plans for informing management and all relevant stakeholders, and crisismanagement documentation, measures and a crisis management function where applicable (as per Article 11(7) of DORA).
226. Competent authorities should assess whether the institution’s business continuity, response and recovery plans: a. establish roles and responsibilities, including clear guidance on potential succession, and set out the internal decision-making process along with definition of activation triggers; b. are reviewed to ensure contingency strategies remain consistent with current operations, risks and threats, resilience levels, and recovery objectives and priorities; c. prioritise business continuity actions using risk-based approach; d. are tested regularly to ensure that recovery objectives and timeframes can be met; and e. are inclusive of the testing of services provided by third-party service providers, where applicable;
227. Competent authorities should also assess whether testing results are documented and reported to the management body.
Assessment of ICT risk management framework
228. Competent authorities should assess the institution’s compliance with the DORA and the EBA Guidelines on Internal Governance in relation to the internal governance and organisation of the management of ICT risk. Competent authorities should form a view on whether the institution’s management body is held overall accountable for managing ICT risk and appropriately defines, approves and oversees the implementation of all ICT-related arrangements. Competent authorities should consider whether the members of the management body possess sufficient knowledge and skills to understand and assess ICT risk and its impact on the institution’s operations.
229. Competent authorities should assess how the roles and responsibilities for all ICT-related functions and the established governance arrangements are embedded and integrated in the institution’s internal control and governance framework to manage ICT risk. For this purpose, competent authorities should consider whether the institution has effectively assigned the responsibility for managing and overseeing ICT risk to an independent control function that has direct access and can report directly to the management body in its supervisory function, and assess whether the institution demonstrates: a. clear communication, allocation and integration of roles and responsibilities in all ICTrelated functions, including ICT supported business functions, and processes; b. sufficient and appropriate budget to fulfil digital operational resilience in terms of all types of resources, including relevant awareness programmes, training, and ICT skills for all staff (as per Article 5(2)(g) of DORA); c. adequate follow-up and response by the management body on critical ICT audit findings and findings reported under Article 13(5) of DORA.
230. Competent authorities should develop a thorough understanding of the institution’s ICT risk management framework and assess whether the institution has in place sufficient and appropriate strategies, policies, procedures, ICT protocols and tools, including tolerance levels, to address effectively, efficiently and comprehensively the material ICT risk in line with DORA. For this purpose, competent authorities should consider, where applicable: a. appropriateness and effectiveness of institution’s ICT risk management policies , processes and procedures, covering inter alia ICT third-party management, ICT-related incident detection and response, ICT assess management, encryption and cryptography, ICT operations security, network security, access control, and whether these have been approved by the management body and communicated to all relevant stakeholders (as per Article 14 of DORA); b. appropriateness of institution’s risk tolerance level of ICT risk and the impact tolerance for ICT disruptions (as per Article 6(8)(b) of DORA); c. appropriateness and implementation of the institution’s digital operational resilience strategy, including its alignment with the business strategy; d. consistency of the strategy on ICT third-party risk, including the ICT multi-vendor strategy, where available, with the overall business strategy and ICT risk management framework; e. residual risk from the institution’s identified risks in respect to contractual arrangements on the use of ICT services supporting critical or important functions; f. residual risk from the institution’s identified risks on ICT projects impacting critical or important functions reported to the management body, and also on ICT systems acquisitions, development and maintenance and ICT changes; g. soundness and comprehensiveness of digital operational resilience testing programme; h. trend and magnitude of major ICT-related incidents and findings reported to the management body as per Article 17(3)(e) and Article 13(5) of DORA; i. ICT risk controls specific for the identified material ICT risk; j. timely reporting of ICT risk management aspects to the management body and senior management; k. internal audit coverage and findings.
231. When assessing ICT risk management, competent authorities should pay particular attention to ICT third-party risk management, including the institution’s concentration level to ICT thirdparty service providers. For this purpose, competent authorities should ensure close cooperation with the Lead Overseers of critical ICT third-party providers (CTPPs), in accordance with the ESAs’ Joint Guidelines , in case the institution under assessment receives ICT services from a CTPP. Competent authorities should also review the effectiveness of the dedicated role established by the institution, or the designated member of senior management, on the monitoring of ICT third-party arrangements.
232. Competent authorities should consider whether the internal audit function is effective and possesses sufficient knowledge, skills and expertise to audit institution’s ICT risk management framework, by reviewing whether: a. the ICT risk management framework is audited with the required quality, focus and frequency, and is commensurate to the ICT risk profile of the institution; b. the audit plan includes audits on the material ICT risks identified by the institution, including independent reviews of ICT response and recovery plans; c. critical ICT audit findings are timely verified and remediated, including reporting to the management body; d. ICT audit findings, including agreed actions, are formally followed up and progress reports periodically reviewed by the senior management and/or the audit committee.
6.4.4. Assessment of reputational risk
233. Competent authorities should assess the reputational risk to which the institution is exposed by leveraging the understanding gained from Title 4 to Title 6.2. Such an assessment should also focus on the overall reputational risk framework, ensuring the ability of the institution to effectively manage any reputation events. For this assessment, competent authorities should avoid double counting aspects already considered under the assessment of legal risk (section 6.4.2.1).
234. When assessing the relevance of reputational risk, competent authorities should consider the size of the institution as well as the nature, scale and complexity of their services, activities and operations (for example, listed equities or debts or participation in interbank markets).
235. Competent authorities should consider both internal and external factors or events that might give rise to reputational concerns, excluding events that result in legal proceedings. For Category 1 and Category 2 institutions, competent authorities should consider all the following indicators in their assessment: a. negative media/social media coverage and consumer-association initiatives that could deteriorate the public perception and reputation of the institution; b. the number of and changes in customer complaints or sudden loss of customers or investors; c. negative events relating to the institution’s peers that the public could associate with the whole financial sector or a group of institutions; d. the reputation of individuals involved in the management of the institution or with qualifying shareholdings; e. involvement or operation in sectors or jurisdictions highly exposed to ML/TF or with individuals associated with high risk from an ML/TF perspective; f. involvement or operation in sectors or jurisdictions and/or with counterparties highly exposed to material issues or public controversies related to ESG factors, including but not necessarily limited to environmental factors; g. the reputational impact of ICT-related incidents as recorded by the institution in accordance to the Commission Delegated Regulation (EU) 2024/1772 ; h. other ‘market’ indicators, if available (e.g. rating downgrades or changes in the share price throughout the year).
236. Competent authorities should assess the significance of the institution’s reputational risk exposure and its interconnectedness with the other risks by leveraging the relevant risk assessments (including from other supervisory authorities) to identify any possible secondary effects in either direction.
237. In the context of the operational risk analysis, competent authorities should take into account the relevance and significance of the institution’s exposures to ML/TF risk from a prudential perspective under the scope of operational risk. In this respect, competent authorities should use the relevant input received from AML/CFT supervisors to supplement their findings from ongoing supervision and evaluate whether they give rise to prudential concerns related to ML/TF risk.
238. Competent authorities should bear in mind that any institution can be exposed to ML/TF risk regardless of the institution’s size or financial soundness. Therefore, sufficient attention should also be paid to institutions that are perceived to be financially sound and may have a good reputation given that these institutions might be specifically targeted for ML/TF purposes. Attention should also be paid to institutions that are very successful in attracting new customers/expanding market share – especially by using non-traditional distribution channels - since this could be related to weak customer due diligence controls at the onboarding phase.
239. Competent authorities should share relevant information on operational risk issues identified that can give rise to ML/TF risks, risks of non-implementation and evasion of targeted financial sanctions and concerns such as deficiencies in the institutions’ ICT system or internal control framework with AML/CFT supervisors.
240. Competent authorities should assess whether the institution has implemented adequate arrangements, strategies, processes and mechanisms to manage reputational risk. In particular, competent authorities should take into account whether: a. the institution has formalised policies and processes in place for the identification, management and monitoring of this risk, including a robust code of conduct, and whether these policies and processes are proportionate to its size and its relevance in the system; b. the institution addresses this risk in a precautionary manner, including putting in place appropriate metrics and monitoring tools, coverage of potential reputation issues in contingency plans, conducting relevant training and awareness sessions and leveraging lessons learned; c. the institution conducts stress testing or scenario analysis to assess any secondary effects of reputational risk (e.g. liquidity and funding costs, securitisation transactions, access to correspondent banking service); d. the institution acts to protect its brand through tools to monitor media/social media, protocols to address misinformation and adverse publicity as well as prompt communication campaigns; e. the institution considers the potential impact of its strategy and business plans, and more generally of its behaviour, on its reputation.
6.4.5. Operational resilience
241. Competent authorities should form a holistic view on the ability of the institution to deliver critical or important functions through disruption (level of operational resilience), an outcome that benefits from the effective management of operational risk, taking into account the institution’s size, business model and overall risk profile. For this purpose, competent authorities should leverage on their existing assessments on operational risk management, business continuity, change management capabilities, third-party services and the ICT upon which the institution relies to holistically evaluate whether these elements collectively support the institution’s operational resilience. Competent authorities should also consider whether the institution implements its risk management framework, business continuity plans, thirdparty management (already assessed in the context of DORA and EBA Guidelines issued pursuant to Article 74(3) of Directive 2013/36/EU on internal governance arrangements, processes and mechanisms) and recovery and resolution frameworks in a consistent and coordinated manner. Moreover, competent authorities should consider whether the institution has sufficiently mapped the internal and external interconnections and interdependencies that are needed to deliver its critical or important functions.
242. Competent authorities should consider the attention given by the management body and senior management on the institution’s ability to respond to and recover from disruptions under the assumption that failures will occur. For this purpose, competent authorities should consider whether: a. the management body takes an active role in establishing a broad understanding of the operational resilience approach across the institution and in monitoring the effectiveness of the institution’s operational resilience approach; b. timely reporting on the institution’s ongoing operational resilience is provided in support of the management body’s oversight, particularly when major identified deficiencies could affect the delivery of the institution’s critical or important functions.
6.4.6. Summary of findings, scoring and supervisory measures
243. Following the above assessment, competent authorities should form a view on the institution’s operational risk. This view should be reflected in a summary of findings, accompanied by a risk score based on the considerations specified in table 10. Where, based on the materiality of certain risk sub-categories, the competent authority decides to assess and score them individually, the guidance provided in this table should be applied, as far as possible, by analogy.
244. The table below presents a non-exhaustive list of supervisory measures that competent authorities may take in case of identified deficiencies in the institution’s operational risk management framework and operational resilience (taking into account the close interconnection of operational resilience and operational risk management). Competent authorities should decide on the type of the measure based on its effectiveness to the specific identified deficiency. Competent authorities may apply additional supervisory measures (including quantitative measures in accordance with Article 104(1)(a) of the Directive 2013/36/EU) or a combination of these with the ones listed in the table below, if these are deemed more appropriate to address the identified deficiencies. For breaches of DORA, the competent authorities should consider the applicable corrective and remedial measures provided in Article 50 of DORA. Table 11. Potential and non-exhaustive list of supervisory measures stemming from the assessment of operational risk
6.5. Assessment of interest rate risk and credit spread risk arising from non-trading book activities
6.5.1. General considerations
245. When assessing the inherent interest rate risk arising from interest rate-sensitive positions from non-trading on and off-balance sheet activities (commonly referred to as interest rate risk in the non-trading book, or IRRBB) and credit spread risk arising from positions in the nontrading book (commonly referred to as CSRBB) and the adequacy of the internal control framework, competent authorities should evaluate inter alia the compliance of the institution with the legal acts published separately on the EBA website as referred to in paragraph 12.
246. Competent authorities should assess IRRBB, including hedges for these positions, irrespective of their recognition and measurement, and irrespective of the recognition and measurement of losses and gains, for accounting purposes.
247. Competent authorities should consider the relevance and materiality of at least the following subcategories when assessing IRRBB: gap risk, basis risk and option risk.
248. Assessment of IRRBB should be differentiated from assessment of CSRBB that competent authorities should also conduct in accordance with section 6.5.3. In particular, competent authorities should take into account whether institutions’ internal systems adequately assess and monitor the risk from CSRBB from an economic value and net interest income (including market value changes) perspective and appropriately define CSRBB and determine its scope .
249. Based on the overall assessment of the inherent risk of IRRBB and the risk management and controls for IRRBB and CSRBB, competent authorities should form a view on the IRRBB and CSRBB resulting in a combined score using the criteria laid out in table 12. The outcome of the assessment of each individual risk should be reflected in a summary of findings and an explanation of the main risk drivers.
6.5.2. IRRBB 6.5.2.1. Assessment of inherent IRRBB
250. Through the assessment of the inherent level of IRRBB, competent authorities should determine the main drivers of the institution’s IRRBB exposure and evaluate the potential prudential impact of this risk on the institution.
Preliminary assessment
251. To determine the scope of the IRRBB assessment, competent authorities should first identify the sources of IRRBB to which the institution is or might be exposed and if there have been any significant changes. To do so, competent authorities should leverage the knowledge gained from ICAAP and ILAAP information collected for SREP purposes, from reporting established on IRRBB, from the assessment of other SREP elements, from the comparison of the institution’s position with those of its peers and from any other supervisory activities. As part of this, competent authorities should consider the institution’s governance of interest rate risk, including its main IRRBB strategy and its risk appetite in relation to IRRBB, and the level of internal capital the institution has allocated to IRRBB.
Nature and composition of the institution’s interest rate risk profile
252. Competent authorities should form a clear view on how changes in interest rates can have an adverse impact on an institution’s net interest income (and, where relevant, its earnings) and economic value (the present value of expected cash flows) to gain both a short-term and a longer-term view on the possible threat to capital adequacy.
253. For this purpose, competent authorities should analyse and form a clear view on the structure and features of the institution’s assets, liabilities, and off-balance-sheet exposures, including their sensitivities to changes in interest rates, maturities and repricing dates, and the proportion of products and positions with uncertain maturities (e.g. with embedded options or prepayment features) and any associated behavioural assumptions.
254. In addition, competent authorities should review the institution’s hedging strategy and the extent to which a natural hedge may apply (considering also the robustness of modelling of repricing maturities for items with an undefined maturity), the amount of derivatives used for hedging purposes and whether the derivatives may mitigate sensitivity in EVE, NII or other metrics used by the institution internally.
255. Competent authorities should also pay attention to any concentrations (e.g. in the loan or bond portfolios) in terms of repricing maturity or in products with automatic or behavioural optionality, non-performing exposures, and the nature of IRRBB embedded in fair value instruments, including less liquid instruments such as level 3 assets and liabilities.
256. When analysing the impact on the institution’s earnings, competent authorities should be aware of how much the institution’s returns depend on interest rate-sensitive positions, and they should determine how different changes in interest rates would affect the institution’s net interest income, as well as determining the effects of changes in the market value of instruments – depending on accounting treatment – either shown in the profit and loss (P&L) account or directly in equity (e.g. via other comprehensive income).
257. When analysing the impact on the institution’s economic value and earnings, competent authorities should first consider the results of the supervisory outlier tests stipulated in Article 98(5) of Directive 2013/36/EU and further specified in Delegated Regulation (EU) 2024/856, to get an initial benchmark against which to compare how interest rate changes would affect the institution. For this assessment, competent authorities should pay particular attention to the sensitivity of cash flows to repricing, in terms of both their timing and amount and to changes in the underlying key assumptions (particularly for customer accounts without specific repricing dates, customer accounts with embedded customer optionality and/or equity capital).
258. Where the institution is identified as an outlier by the supervisory outlier test on net interest income, competent authorities should consider analysing additional dimensions to complement the assessment, when deemed appropriate (e.g. given the institution’s the business model). Additional dimensions to consider may include market value changes of fair value instruments, the evaluation of the worst NII projections versus current realised NII and versus administrative expenses/overhead cost and net commissions/fees for capturing embedded losses/gains due to observed changes in the interest rates and in the market conditions.
259. Competent authorities should pay attention to the sensitivity of cash flows to changes in the valuation of fair value instruments in the non-trading book, including interest rate derivatives used for the hedging of non-trading book instruments (e.g. impact of mark-to- market changes in fair value instruments on P&L, hedge account effectiveness).
260. In addition to using the supervisory outlier test stipulated in Article 98(5) of Directive 2013/36/EU and further specified in Delegated Regulation (EU) 2024/856, competent authorities may require institutions to take into account other interest rate shock scenarios.
261. In their quantitative assessment, competent authorities should also consider the results of the institution’s internal or standardised methodologies for measuring IRRBB, among which competent authorities should also assess, for those institutions operating in different currencies, the impact for the economic value and earnings measures coming from different currencies and, where an internal methodology is applied, the approaches that the institutions use for the aggregation across these currencies. Through the analysis of these methodologies, competent authorities should gain a deeper understanding of the main risk factors underlying the institution’s IRRBB profile.
262. When analysing the results of both the impact of the supervisory outlier tests, and the institution’s internal or standardised methodologies, competent authorities should consider ‘point in time’ figures as well as historical trends. These rates should be compared to peers and considered in the context of the global market situation.
Shock Scenarios and stress testing
263. Competent authorities should assess and take into account the results of the interest rate shock scenarios for ongoing management as well as the IRRBB stress tests performed by the institution as part of its ongoing internal management process. In this context, competent authorities should be aware of the main sources of the institution’s IRRBB and in particular of the effect of changes in behavioural assumptions such as on NMD.
264. If, when the outcome of the institution’s shock scenarios and stress tests is reviewed, particular accumulations of repricing/maturity at different points on the curve are revealed or suspected, competent authorities may need to carry out additional analyses.
6.5.2.2 Assessment of IRRBB management and control framework
265. To achieve a comprehensive understanding of the institution’s interest rate risk profile in the non-trading book, competent authorities should review the governance and framework underlying its interest rate exposures.
IRRBB strategy and appetite
266. Competent authorities should assess whether the institution has a sound, clearly formulated and documented IRRBB strategy and appetite, approved by the management body. For this assessment, among other factors, competent authorities should take into account the role of the management body in setting, approving and reviewing the IRRBB strategy and appetite, the proper implementation of this strategy by senior management as well as its appropriateness for the institution given its business model, its market environment and role in the financial system, and capital adequacy.
Organisational and internal control framework
267. Competent authorities should assess whether the institution has an appropriate organisational framework and clearly assigned responsibilities for IRRBB management, measurement, monitoring and control functions with sufficient human and technical resources. For this assessment, competent authorities should take into account the adequacy of the lines of responsibility for the overall management of IRRBB, and for taking, monitoring, controlling and reporting IRRBB, including the independence of the IRRBB control area.
268. Competent authorities should assess whether the institution has clearly defined policies and procedures for the management of IRRBB that are consistent with its IRRBB strategy and appetite, approved and reviewed regularly by the management body. The policies should be clearly formalised and communicated and applied consistently across the institution, as well as across banking groups. Competent authorities should verify that policies define the procedures for new product development, major hedging or risk management initiatives, ensuring that these are subject to adequate procedures and controls before they are undertaken and the institution has undertaken an analysis of their possible impact in its overall risk profile.
269. Competent authorities should assess whether the institution has an appropriate framework for identifying, evaluating, managing and mitigating IRRBB, in line with the level, complexity and riskiness of non-trading book positions and the institution’s size and complexity. The assessment should encompass internal models, such as those related to customer behaviour (e.g. models of deposit stability and loan early repayment). In this assessment competent authorities should evaluate whether the risk managers and the institution’s senior management understand the assumptions underlying the measurement systems and they are aware of the degree of model risk that prevails in the institution’s risk measurement techniques.
270. In addition, they should consider whether the information systems and measurement techniques enable management to measure the inherent IRRBB in all its material on- and offbalance- sheet exposures (where relevant at group level), including internal hedges, in concentrations in maturities and counterparties, in the non-trading book portfolio. The IRRBB framework should be subject to regular reviews and evaluations of the effectiveness of the framework. Competent authorities should compare internal reviews and evaluations with information from COREP.
271. Competent authorities should assess the institution’s approach to modelling the behaviour of non-maturity deposits (NMDs), including whether this takes account of relevant risk factors impacting NMD repricing behaviour. Competent authorities should use appropriate analytical tools for this assessment, taking into account the institution’s business model. Approaches that may be relevant include evaluation of how the institution segments NMDs using risk factors related to the customer, institution or market profile and benchmarking with peers that have a similar risk profile. In addition, competent authorities should consider how the institution balances historical data with forward looking approaches and expert judgment, and review the impact on NII and EVE if behavioural assumptions were adjusted.
272. Competent authorities should consider whether the institution’s internal measurement systems (IMS) take into account all material forms of interest rate risk to which the institution is exposed (e.g. gap risk, basis risk and option risk). The IMS should be properly calibrated, independently validated, back-tested and reviewed at an appropriate frequency. Competent authorities should take into account whether the IMS is supported by documentation considering the nature, scale and complexity of the IRRBB inherent in the business model and the institution’s activities.
273. Competent authorities should assess whether the institution has an appropriate monitoring and internal reporting framework for IRRBB that ensures there is prompt action at the appropriate level of the institution’s senior management or management body, where necessary. The monitoring system should include specific indicators and relevant triggers to provide effective early warning alerts (e.g. for breaches of IRRBB limits). Competent authorities should take into account whether the management and control area reports the results of the monitoring regularly to the management body and senior management, with an appropriate frequency depending on the scale, complexity and level of IRRBB exposures.
274. Competent authorities should assess whether the institution has a strong and comprehensive control framework and sound safeguards to mitigate its exposures to IRRBB in line with its risk management strategy and risk appetite, including an appropriate limit system on both IRRBB measures. The internal control function should include all consolidated entities, all geographical locations and all financial activities. Competent authorities should assess the functionality of the internal audit function, including whether its reviews are conducted sufficiently frequently and cover the main elements of the IRRBB framework.
6.5.3. CSRBB 6.5.3.1. Assessment of inherent CSRBB
275. Through the assessment of the inherent level of CSRBB, competent authorities should understand the main drivers of the institution’s CSRBB exposure and evaluate the potential prudential impact of this risk on the institution.
276. To determine the scope of the CSRBB assessment, competent authorities should first identify the sources of CSRBB to which the institution is or might be exposed and if there have been any significant changes. As part of this, competent authorities should have regard to the institution’s governance of credit spread risk, including its CSRBB strategy and its risk appetite in relation to CSRBB, and the treatment of CSRBB within the ICAAP context.
277. Competent authorities should form a clear view on how changes in credit spreads can have an adverse impact on an institution’s net interest income (and, where relevant, its earnings) and economic value to gain both a short-term and a longer-term view on the possible threat to capital adequacy. For this purpose, competent authorities should consider the approach applied by the institution to form this clear view on the structure and features of the institution’s assets, liabilities, and off-balance-sheet exposures, and how these are driving the level and direction of CSRBB.
278. When analysing the impact on the institution’s earnings, competent authorities should consider the impact of credit spread-sensitive positions on the institution’s return, the impact of the changes in credit spreads on the institution’s net interest income, and the effects of changes in the market value of instruments – depending on account treatment – either shown in the profit and loss (P&L) account or directly in equity (e.g. via other comprehensive income).
279. Competent authorities should consider the results of the institution’s methodologies for measuring CSRBB, where appropriate. Through the analysis of these methodologies, competent authorities should gain a deeper understanding of the main risk factors underlying the institution’s CSRBB profile.
6.5.3.2. Assessment of CSRBB management and control framework
280. To achieve a comprehensive understanding of the institution’s credit spread risk profile in the non-trading book, competent authorities should review the governance and framework underlying its interest rate exposures.
281. The review of the institution’s governance of CSRBB should include the following elements: a. the institution’s CSRBB strategy and appetite; b. the institution’s organisational framework and allocation of responsibilities with respect to CSRBB management, measurement, monitoring and control functions; c. the institution’s policies and procedures for the management of CSRBB.
282. For the assessment of these areas, competent authorities should refer to section 6.5.2.2 on the assessment of the IRRBB management and control framework, with the principles contained also applicable to the assessment of CSRBB management.
283. When analysing the perimeter of assets and liabilities covered by the CSRBB assessment, also as considered within the institution’s methodologies, competent authorities should assess whether any potential exclusion of instruments from the relevant perimeter is only made in the absence of sensitivity to credit spread risk and is appropriately documented and justified, as required in paragraph 124 of the EBA Guidelines on IRRBB and CSRBB . Factors to take into account include: a. whether the institution includes all assets and liabilities accounted at fair value; b. whether the institution includes all assets and liabilities whose credit spread risk can be inferred from a direct/indirect or even modelled market price, whatever their accounting treatment; c. the potential relevance of credit spreads in the institution’s pricing practice for different assets/liabilities (for example through explicit references to observed market prices or more indirect relevance); d. differences, if any, that the institution applies between the perimeter for EVE and NII in the measurement of CSRBB (e.g. due to the NII time horizon or other reasons).
284. To analyse the institution’s measurement of CSRBB, competent authorities should consider, where appropriate, to review which shock scenarios the institution is considering, and, how and why the shocks may be different between balance sheet items.
285. Competent authorities should check the exclusion of idiosyncratic spread in the institution’s measurement of CSRBB or its inclusion only for proportionality reasons and regardless of the SREP categorisation of the institution, as long as it is ensured that the measures will yield more conservative results.
286. Competent authorities should assess whether the institution has an appropriate framework for identifying, evaluating, managing and mitigating CSRBB, in line with the level, complexity and riskiness of non-trading book positions and the institution’s size and complexity. They should consider whether the information systems and measurement techniques enable management to measure the inherent CSRBB in all its material on- and off-balance- sheet exposures (where relevant at group level) in the non-trading book portfolio. The CSRBB framework should be subject to regular reviews and evaluations of its effectiveness. In this context, competent authorities should assess whether significant measurement assumptions are reviewed at least annually and more frequently during rapidly changing market conditions.
287. Competent authorities should consider whether the institution’s internal measurement systems (IMS) take into account all sources of CSRBB which are relevant for the institution’s business model. The IMS should be properly calibrated, independently validated, back-tested and reviewed at an appropriate frequency. Competent authorities should take into account whether the IMS is supported by documentation considering the nature, scale and complexity of the CSRBB inherent in the business model and the institution’s activities.
288. Competent authorities should assess whether the institution has an appropriate monitoring and internal reporting framework for CSRBB that ensures there is prompt action at the appropriate level of the institution’s senior management or management body, where necessary. Competent authorities should take into account whether the management and control area reports the results of the monitoring regularly to the management body and senior management, with an appropriate frequency depending on the scale, complexity and level of CSRBB exposures.
289. Competent authorities should assess whether the institution has a strong and comprehensive control framework and sound safeguards to mitigate significant exposures to CSRBB in line with its risk management strategy and risk appetite. The internal control function should include all consolidated entities, all geographical locations and all financial activities. Competent authorities should assess the functionality of the internal audit function, including whether its reviews are conducted sufficiently frequently and cover the main elements of the CRSBB framework.
6.5.4. Summary of findings, scoring and supervisory measures
290. Following the above assessments, competent authorities should form a view on the institution’s IRRBB and CSRBB. This view should be reflected in a summary of findings, accompanied by a score based on the considerations specified in table 12. If, based on the materiality of certain risk subcategories, the competent authority decides to assess and score them individually, the guidance provided in this table should be applied, as far as possible, by analogy.
291. The table below presents a non-exhaustive list of supervisory measures that competent authorities may take in case of identified deficiencies in the institution’s IRRBB and CSRBB management framework. Competent authorities should decide on the type of the measure based on its effectiveness to the specific identified deficiency. Competent authorities may apply additional supervisory measures (including quantitative measures in accordance with Article 104(1)(a) of the Directive 2013/36/EU) or a combination of them if these are deemed more appropriate to address the identified deficiencies.
7. Title 7. SREP capital assessment
7.1. General considerations
292. Competent authorities should determine through the SREP capital assessment whether the own funds held by the institution provide sound coverage of risks to capital to which the institution is or might be exposed, if such risks are assessed as material to the institution.
293. Competent authorities should do this by determining and setting the quantity (amount) and quality (composition) of additional own funds the institution is required to hold to cover institution-specific risks and elements of risks that are not covered or not sufficiently covered by P1R, and, where necessary, own funds requirements to address deficiencies in models, controls, governance or other deficiencies, as well as risk arising from the institution’s business model (P2R for risks other than risk of excessive leverage and P2R-LR for risk of excessive leverage).
294. When a material impact on institution’s capital profile is or may be expected due to relevant changes to the regulatory framework for determining P1R (e.g. increase or decrease in TREA) or to its implementation for the specific institution (such as the output floor), competent authorities should assess such impact in terms of its interaction with the P2R. Such assessment may lead to a redetermination (either upward or downward) of the level or composition of the P2R to ensure that the institution’s overall own funds requirements are in line with Article 104a(1) of Directive 2013/36/EU, in particular that P2R cover risks or elements of risks that are not covered or not sufficiently covered by the P1R. To perform such an assessment, competent authorities may increase the frequency of the SREP assessment as set out in the SREP engagement model in section 2.4 or of specific elements thereof.
295. To address potential capital inadequacies, including in stressed conditions, competent authorities should take appropriate supervisory measures, including, where relevant, establishing and communicating P2G and P2G-LR which is the quantity (amount) and quality (composition) of own funds that the institution is expected to hold over and above its OCR or its OLRR.
296. When setting the P2R and, where relevant, P2G, competent authorities should: a. take into account any supervisory measures they have applied or are planning to apply to an institution; b. clearly justify all elements of additional own funds requirements for P2R and P2R-LR as well as for P2G and P2G-LR; c. apply P2R and P2R-LR as well as P2G and P2G-LR in a consistent manner to ensure broad consistency of prudential outcomes across institutions.
297. Competent authorities should assess the adequacy of the institution’s own funds and the impact of economic stress thereon, as well as risks posed by excessive leverage, as a key determinant of the institution’s viability. This determination should be summarised in a score taking into account the considerations specified at the end of this Title.
7.2. Determining Pillar 2 requirement for risks other than the risk of excessive leverage (P2R)
298. Competent authorities should determine P2R for risks other than the risk of excessive leverage, where they identify any of the situations listed in Article 104a(1) of Directive 2013/36/EU for an institution, including in particular: a. the risk of unexpected losses, and of expected losses insufficiently covered by provisions, over a 12-month period (except where Regulation (EU) No 575/2013 specifies own funds requirements over a different period), which individual institutions are facing due to their activities, including those reflecting the impact of certain economic and market developments; b. model deficiencies for internal approaches for the calculation of own funds requirements (‘regulatory model deficiencies’) as assessed in the context of Article 101 of Directive 2013/36/EU, excluding those already covered by the fact that an institution has become bound by the output floor in accordance with Article 92 of Regulation 575/2013; c. deficiencies in internal governance, including internal control arrangements and other deficiencies, as well as risk arising from the institution’s business model, identified following the risk assessment outlined in Titles 4 to 6, where other supervisory measures have not been effective or are considered insufficient to address the identified deficiencies.
7.2.1. Determining additional own funds to cover unexpected losses
299. When setting P2R for the risk of unexpected losses pursuant to point (a) of the following paragraph, competent authorities should consider each type of risk that may jeopardise the institution’s capital position. Competent authorities should set P2R to cover the risk of unexpected losses by determining the capital considered adequate to cover the type of risk and deducting the relevant part of P1R.
300. Competent authorities should determine on a risk-by-risk basis, the amounts of capital considered adequate, by identifying, assessing and quantifying the risks to which the institution is exposed, taking into account its full risk profile. The determination of the amounts of capital considered adequate should include: a. institution-specific risks or elements of risks that are not covered by the P1R; b. institution-specific risks or elements of such risks that are not sufficiently covered by the P1R.
301. Competent authorities should ensure that the amount of capital considered adequate to cover each risk identified in accordance with Articles 79 to 85 and 87a of Directive 2013/36/EU is not lower than the relevant part of the applicable P1R covering that risk. In exceptional cases where it is overly burdensome, especially for small institutions, to meaningfully disentangle the amount of capital considered adequate on a risk-by-risk basis, competent authorities should comply with the first sentence of this paragraph on a best-effort basis, using the ICAAP calculations, supervisory judgement and other sources of information.
302. When identifying, assessing and quantifying risks to which the institution is exposed, competent authorities should rely on the following sources of information: a. the ICAAP and the outcomes of its assessment by the competent authority, including the ICAAP calculations where deemed reliable or partially reliable in accordance with paragraphs 3066 to 308; b. supervisory reporting; c. the outcome of supervisory assessment, including any relevant previous supervisory activities, and benchmarking, as well as other relevant inputs, including those arising from interaction and dialogue with the institution.
303. The ICAAP and outcomes of its assessment should be taken into account by competent authorities as one of the key inputs for the identification and assessment of risks relevant for the institution. The determination of the amount of capital considered adequate and P2R on a risk-by-risk basis should take into account the ICAAP calculations if deemed reliable or partially reliable, as well as the outcomes of supervisory benchmarking and other relevant inputs as appropriate, including the supervisory judgement.
304. For the purposes of Article 98(1), point (f) of Directive 2013/36/EU and the determination of P2R, competent authorities should assess and consider diversification effects arising from geographical, sectoral or any other relevant drivers within each material risk category (intrarisk diversification). For each of the risks to capital covered by Regulation (EU) No 575/2013, such diversification effects should not reduce the minimum own funds requirements calculated in accordance with Article 92 of Regulation (EU) No 575/2013.
305. However, diversification between risks in different categories, including those covered by Regulation (EU) No 575/2013 (inter-risk diversification) should not be considered as part of the determination of P2R.
ICAAP calculations
306. Competent authorities should assess the reliability of the ICAAP calculations by assessing whether they are: a. granular: the calculations/methodologies should allow calculations to be broken down by risk type, rather than presenting a single (economic capital) calculation covering all risks; b. credible: the calculations/methodologies used should demonstrably cover the risk they are looking to address (e.g. the credit concentration risk calculation should use appropriate sector breakdowns that reflect actual correlations and portfolio compositions) and should be sufficiently robust, stable, risk sensitive and conservative to adequately quantify losses associated with the risks. Such calculations/methodologies should be consistent with the institutions’ strategic processes, including the institutions’ risk appetite; c. understandable: the underlying drivers and key assumptions of the calculations/methodologies should be clearly specified. A ‘black box’ calculation should not be acceptable. Competent authorities should ensure that the institution provides an explanation of the key assumptions used, including at least time horizon, confidence levels, correlation assumptions, key parameters, the most fallible areas of the models used, and how these are accounted for and corrected in the final ICAAP calculation; d. comparable: the calculations/methodologies should clearly mention the main assumptions in terms of the overall level of conservatism, the holding periods/risk horizons and confidence levels (or equivalent measurement) in order to allow the adjustment that may be requested or enacted by competent authorities in order to facilitate comparability with peers and supervisory benchmarking.
307. Competent authorities should further assess the reliability of the ICAAP calculations by comparing them against the outcome of the supervisory benchmarks for the same risks, and other relevant inputs.
308. An ICAAP calculation should be considered partially reliable where, despite not meeting all the criteria of paragraph 3066, the calculation still seems highly credible, though this should be on an exceptional basis and accompanied by steps to improve deficiencies identified in the ICAAP calculation.
Supervisory benchmarks and other relevant inputs
309. Competent authorities should develop and apply risk-specific supervisory benchmarks as a means to challenge ICAAP calculations for those material risks, or elements of such risks, that are not covered or not sufficiently covered by Regulation (EU) No 575/2013, or to further support the determination of risk-by-risk P2R, especially where ICAAP calculations for those material risks, or elements of such risks, are deemed unreliable or are unavailable.
310. The supervisory benchmarks should be developed to provide a prudent, consistent (i.e. as applicable, calibrated to equivalent holding periods/risk horizons and confidence levels as required by Regulation (EU) No 575/2013), transparent and comparable measure with which to calculate and compare across institutions the capital considered adequate for a given risk.
311. When applying supervisory benchmarks, competent authorities should consider the business model of institutions and, to the extent appropriate, complement these with the application of supervisory judgement to account for business-model-specific and institution-specific considerations.
312. Competent authorities should use other relevant inputs to support the determination of riskby-risk P2R. Other relevant inputs may include the outcomes of risk assessments (following the criteria specified in Title 6), peer-group comparisons, including report(s) and benchmarks issued by the EBA.
313. Other relevant inputs should prompt the competent authority to reassess the appropriateness/reliability of an ICAAP/supervisory benchmarks for a specific risk, and/or make adjustments to the outcome, where they prompt doubts about its accuracy.
314. To ensure consistency in determining P2R, competent authorities should use the same peer groups established to analyse risks to capital as specified in Title 6.
315. When competent authorities take supervisory benchmarks as well as other relevant inputs into consideration for the determination of P2R, as part of the dialogue with the institution, they should explain the rationale and general underlying principles behind the inputs used.
7.2.2. Determining own funds or other measures to cover regulatory model deficiencies not covered by the fact that an institution has become bound by the output floor
316. If, during the ongoing review of internal approaches for the calculation of own funds requirements, competent authorities identify model deficiencies that could lead to underestimation of the P1R, they should set P2R only where this is determined to be more appropriate than other supervisory measures. Competent authorities should only set P2R to cover these deficiencies: a. where it is not possible to address them under P1R through other supervisory measures, such as requiring institutions to adjust their models or apply an appropriate margin of conservatism to their estimates; b. by taking into account whether the institution has become bound by the output floor in accordance with Article 92 of Regulation (EU) No 575/2013 and, if this is the case, proceed as explained in the next paragraph. Such P2R should only be set as an interim measure while the deficiencies are addressed.
317. When an institution becomes bound by the output floor as set out in Article 92(3) of Regulation (EU) No 575/2013, competent authorities should: a. ensure the nominal amount of P2R does not automatically increase as a result of the institution becoming bound by the output floor (‘temporary cap’), in accordance with Article 104a(6) point (a) of Directive 2013/36/EU. To this end, the applicable percentage of the P2R previously communicated to the institution by the competent authority following the last SREP cycle will be applied to the institution’s unfloored TREA (U-TREA), as set out in Article 92(4) of Regulation (EU) No 575/2013. This approach will remain in place until the performance of the review described in point b; b. without delay, and no later than the end date of the next SREP, review the P2R imposed on the institution in accordance with Article 104(1), point (a) of Directive 2013/36/EU. As part of this review, competent authorities should: i. remove any part of the P2R that may be covering regulatory model deficiencies for the calculation of own funds requirements that is already covered by the output floor, in order to eliminate any potential double-counting effects; ii. consider whether there are arithmetic effects (i.e. where the P2R nominal amount increase is not due to an increase in risk but results from the P2R being expressed as a percentage of TREA) on the nominal amount of P2R arising from the automatic increase in the TREA due to the fact that the institution has become bound by the output floor, and remove them as appropriate; c. communicate to the institutions the applicable own funds requirements following the review in point (b), emphasising, in particular, any findings related to double counting elements. Competent authorities may also require institutions to disclose, as part of their Pillar 3 reporting, the impact of either the temporary cap or the review of double counting – whichever is applicable at the reference date – on the reported P2R.
318. For the purpose of the previous paragraph, competent authorities should encourage institutions to inform them at an early stage when they foresee (based on estimates) they may become bound by the output floor. This is to facilitate as far as possible, the review of double counting elements described in the previous paragraph.
319. Competent authorities should perform the review described in paragraph 317 at the time an institution first becomes bound by the output floor. Following the conclusion of this review, the temporary cap on P2R does not apply, and the P2R communicated by competent authorities applies to floored TREA. Competent authorities should have regard to the fact that as long as an institution is bound by the output floor, no additional own funds requirements shall be imposed that would double-count the risks that are already fully covered by the fact that the institution is bound by the output floor, in accordance with Article 104a(8) of Directive 2013/36/EU, and in line with paragraph 2944.
7.2.3. Determining own funds or other measures to cover other deficiencies
320. Competent authorities should set P2R to cover deficiencies – identified following the risk assessment outlined in Titles 4 to 6 – where other supervisory measures have not been effective or are considered insufficient to address the identified deficiencies. Competent authorities should only set such P2R as an interim measure while the deficiencies are addressed.
321. Competent authorities should only set P2R to cover funding risk – identified following the risk assessment outlined in Title 8 – where this is determined to be more appropriate than other supervisory measures.
322. Where an institution repeatedly fails to establish or maintain an adequate level of own funds to cover the P2G, competent authorities should set P2R to cover that additional risk not later than 2 years after the breach of guidance. Competent authorities may postpone that decision where they allow institutions to operate below the level of guidance due to economic or market conditions or institution-specific circumstances, in line with paragraphs 4522 and 453.
7.2.4. Determining the composition of Pillar 2 requirements
323. Where necessary, and having regard to the institution’s specific circumstances, competent authorities may decide to require the institution to cover P2R with a higher quality of capital than that referred to in Article 104a(4) of Directive 2013/36/EU . This decision should be clearly justified, highlighting the specific circumstances that led to it. In their justifications competent authorities should refer to elements such as: a. the specific nature of the institution, its shareholding structure and, where relevant, the group structure, potentially affecting the possibility to raise capital; b. the specific nature of risks faced by the institution, potentially leading to a particularly rapid depletion of CET1 capital.
7.3. Pillar 2 requirements for the risk of excessive leverage (P2R-LR)
324. Where, as a result of the risk of excessive leverage assessment, in accordance with Article 104a (3) and (4), of Directive 2013/36/EU, competent authorities determine P2R-LR to address this risk, they should add this requirement to the own funds requirement based on the leverage ratio as set out in Article 92(1), point (d), of Regulation (EU) No 575/2013 and not to the P1R based on the TREA as set out in Article 92(1), points (a) to (c). Competent authorities should consider the leverage ratio requirement and P2R-LR as a separate stack from the TREA-based requirements and P2R for all other types of risk (i.e. available own funds can simultaneously be used to meet requirements in the TREA-based stack and in the leverage ratio-based stack of own funds requirements).
7.3.1. Assessment of risk of excessive leverage
325. In line with the concept of the leverage ratio (and its stack of requirements) as a backstop to the TREA-based own funds requirements, in the assessment of the risk of excessive leverage, competent authorities should focus on potential material vulnerabilities not covered or not sufficiently covered by the own funds requirements as set out in Article 92(1), point (d), of Regulation (EU) 575/2013 that may require corrective measures to the business activities of the institution, that were not envisaged in its business plan.
326. In assessing the risk of excessive leverage, competent authorities should consider all of the following aspects and adapt the depth of the assessment of each aspect in accordance with its relevance to the institution: a. The elements of risk of excessive leverage that are considered not covered or not sufficiently covered by the leverage ratio own funds requirement set out in Article 92(1), point (d), of Regulation (EU) No 575/2013, as a result of, in particular: i. regulatory arbitrage/optimisation of the leverage ratio by exchanging exposures counted in the leverage ratio for economically similar exposures that may be less counted in the leverage ratio exposure calculation; ii. regulatory arbitrage/optimisation by minimising the leverage ratio exposure in the form of temporary reductions in transaction volumes in key financial markets (particularly in the money market, in certain activities such as SFTs, but also in the derivative market) around reference dates, resulting in the reporting and public disclosure of elevated leverage ratios (‘window-dressing activities’); iii. specific features of the business model, business activities or other bank idiosyncrasies that either increase or decrease the extent to which the institution is exposed to the risk of excessive leverage, but are not covered or not sufficiently covered in the calculation of the leverage ratio. Competent authorities should consider, where applicable, high exposures to written options on equity or short positions via credit derivatives that may have an elevated exposure to peak losses, as these positions are not fully captured in the leverage ratio exposure (in contrast to, for example, written credit derivatives), and concentrations in certain off-balance sheet items where the idiosyncrasies inherent to the business activities of the institution may lead to increased volatility in drawdowns; b. the elements of risk of excessive leverage that are explicitly excluded from or not explicitly addressed by the leverage ratio own funds requirement, including due to the exclusions listed in Article 429a of Regulation (EU) No 575/2013, particularly where there are concerns about the assessment of continued compliance with the conditions for these exclusions and where the reliance on a single exclusion is highly significant for the institution and the amount excluded is unduly volatile; c. the changes in the institution’s leverage ratio and its components, including the foreseeable impact of current and future expected losses on the leverage ratio, taking into account the business model of the institution.
7.3.2. Determination of P2R-LR
327. Competent authorities should determine the P2R-LR as the difference between the capital considered adequate to cover the risk of excessive leverage and the leverage ratio own funds requirements as set out in Article 92(1), point (d), of Regulation (EU) No 575/2013. This amount cannot be negative.
328. When setting P2R-LR, competent authorities should consider in particular: a) elements of risk of excessive leverage that are considered not covered or not sufficiently covered by the leverage ratio own funds requirement set out in Article 92(1), point (d), of Regulation (EU) No 575/2013, particularly where the assessment of the aspects described in paragraphs 3255 and 326 indicate a high vulnerability when compared to the leverage ratio exposure; b) elements of risk of excessive leverage that are explicitly excluded from or not explicitly addressed by the leverage ratio own funds requirement, including due to the exclusions listed in Article 429a(1), of Regulation (EU) No 575/2013, assessed in accordance with paragraph 3263, point b. Competent authorities should set P2R-LR only in those cases where particularly extensive use of a certain exclusion results in a level of leverage ratio that does not appropriately reflect the risk faced by the institution.
329. Competent authorities should identify, assess and quantify the risk of excessive leverage using the sources of information and methods set out in paragraphs 302 and 303, to the extent that they are relevant for this risk.
7.3.3. Composition of P2R-LR
330. Competent authorities should add the P2R-LR to the minimum leverage ratio Tier 1 requirement. In order to meet this additional requirement, institutions should also be able to use any Tier 1 capital.
331. Where necessary, and having regard to the institutions’ specific circumstances, competent authorities may decide to require institutions to cover P2R-LR with a higher quality of capital than that specified in the previous paragraph. This decision should be clearly justified, highlighting the specific circumstances that led to it, taking into account the individual risk situation of the institution and considering situations where materialisation of the risk of excessive leverage may require a higher quality of capital to cover potential losses.
7.4. Reconciliation with the capital buffers and any macroprudential requirements
332. In determining Pillar 2 requirements (or other capital measures), competent authorities should reconcile the Pillar 2 requirements with any existing capital buffer requirements by addressing the same risks or elements of risks. Competent authorities should not set Pillar 2 requirements or other capital measures (including P2G) where the same risk is already covered by specific capital buffer requirements. Any Pillar 2 requirements or other capital measures should be institution-specific and should not cover macroprudential or systemic risks.
7.5. Determining the TSCR, TSLRR, OCR and OLRR
333. Competent authorities should determine and express the TSCR in terms of CET1 Capital, Tier 1 Capital and Total Own Funds in accordance with table 14 below:
334. Competent authorities should determine the TSLRR (in terms of Tier 1 capital) as the sum of: a. the leverage ratio own funds requirement pursuant to Article 92(1), point (d), of Regulation (EU) No 575/2013; b. the additional own funds required to address the risk of excessive leverage (determined in accordance with the criteria specified in section 7.3).
335. Where competent authorities require institutions to cover P2R-LR with a higher quality of capital in line with paragraph 331, they should determine the TSLRR (in terms of CET1) as the part of the additional own funds referred to in point b of the previous paragraph, that is required by the competent authority to be held in the form of CET1 capital.
336. Where considering the possibility of requiring a higher quality of capital, competent authorities should aim to avoid overlaps with other existing requirements within the relevant TREA-based or leverage ratio-based stack of requirements and with MREL.
337. Competent authorities should determine the OCR as the sum of: a. TSCR; b. combined capital buffer requirements.
338. Competent authorities should determine the OLRR as the sum of: a. TSLRR; b. G-SII leverage ratio buffer requirement in accordance with Article 92(1a), of Regulation (EU) No 575/2013.
339. Competent authorities should not consider items and instruments other than those eligible for the determination of own funds (as defined in Part Two of Regulation (EU) No 575/2013) in the assessment/calculation of the TSCR, TSLRR, OCR or OLRR.
7.6. Meeting requirements in stressed conditions – Use of P2G and P2G-LR to address the quantitative outcomes of stress testing
340. Competent authorities should determine by means of stress testing the adequacy of the institution’s own funds (quantity and composition) in stressed conditions and whether supervisory measures, including P2G, P2G-LR, revised capital planning and other measures are necessary to address potential inadequacies. To assess capital adequacy in stressed conditions, competent authorities should consider: a. the use of the qualitative outcomes (e.g. deficiencies identified in risk management and control) of institutions’ stress tests and supervisory stress testing; b. the use of the quantitative outcomes of institutions’ stress tests, if the ICAAP is deemed reliable, and of supervisory stress tests, pursuant to Article 100 of Directive 2013/36/EU as specified in Title 11, and including, for example: i. prescribing specific ‘anchor’ scenarios/assumptions to be implemented by institutions; ii. conducting system-wide stress tests using consistent methodologies and scenarios run either by institutions or by supervisors.
341. Competent authorities should assess as appropriate the quantitative outcomes of stress tests with regard to the adequacy and quality of the institution’s own funds and determine whether the quantity and quality of own funds are sufficient to cover applicable capital requirements, and in particular: a. OCR including its combined buffer requirements under the baseline scenario over a forward-looking time horizon of at least two years; b. TSCR under the adverse scenarios over a forward-looking time horizon of at least two years.
342. Competent authorities should determine P2G and P2G-LR, and, where the determination leads to a positive value, they should set P2G or P2G-LR to address supervisory concerns about the sensitivity of the institution to the adverse scenarios used in the supervisory stress tests. P2G should not be used to cover risks or elements of risks already covered by the P2R in accordance with section 7.2. Similarly, P2G-LR should not be used to cover those aspects of risk of excessive leverage already covered by P2R-LR in accordance with section 7.3.
343. The level of P2G should protect against the potential breach of TSCR in an adverse scenario. Similarly, the level of P2G-LR should protect against the breach of TSLRR in an adverse scenario. Where the quantitative outcomes of the supervisory stress tests suggest that the institution is not expected to breach its TSCR under the adverse stress test scenario, competent authorities may decide not to set P2G. Similarly, competent authorities may decide not to set P2G-LR where TSLRR is not expected to be breached under the adverse stress test scenario.
344. Competent authorities should determine and set P2G and P2G-LR based on the outcomes of the adverse scenario of the relevant supervisory stress tests, including the EU-wide stress tests performed by the EBA or any other relevant supervisory stress tests performed on a systemwide basis over a forward-looking horizon of at least two years.
345. On the basis of establishing a proportionate approach for non-Category 1 institutions and subsidiaries of cross-border groups, for setting and updating P2G and P2G-LR competent authorities may consider the outcomes of simplified forms of supervisory stress tests (e.g. through the use of supervisory-prescribed ‘anchor’ scenarios, sensitivity analysis, top-down stress tests conducted by designated authorities, and portfolio level impacts from consolidated level stress tests), past supervisory stress tests or institutions’ stress tests in accordance with paragraph 340. The simplified forms of supervisory stress tests may be carried out on an individual basis rather than as part of the system-wide exercise.
346. Competent authorities should determine and set P2G and P2G-LR in accordance with the minimum engagement model specified in section 2.4. In particular, the minimum frequency with which P2G and P2G-LR are determined and set should be the frequency of the capital adequacy assessment under the SREP minimum-engagement model.
347. Notwithstanding the previous paragraph, competent authorities: a. should assess whether the existing P2G and P2G-LR is still appropriate whenever the results of new supervisory stress tests are available, and revise them if necessary; b. may determine P2G and P2G-LR only every second year instead of annually, including for SREP Category 1 institutions. However, in the year that follows the year of determining P2G, competent authorities should assess whether P2G and P2G-LR are still relevant or need to be updated, on the basis of all relevant information, including outcomes of past supervisory stress tests, together with additional sensitivity analysis (i.e. simplified forms of supervisory stress testing).
348. When calibrating the P2G, competent authorities should ensure that it is set at a level appropriate to cover at least the anticipated maximum stress impact, which should be calculated based on the changes in the CET1 ratio (i.e. considering both movements in CET1 capital and TREA) in the worst year of stress, and taking into account the level of applicable capital requirements. The maximum stress impact for the purpose of setting the P2G should be understood as the difference between the lowest CET1 ratio in the adverse scenario over the stress test horizon and the actual CET1 ratio at the starting point.
349. When calibrating the P2G-LR, the maximum stress impact should be calculated based on the changes in the Tier 1 capital in the worst year of stress, and taking into account the applicable leverage ratio capital requirements. The maximum stress impact for the purpose of setting the P2G-LR should be understood as the difference between the lowest leverage ratio in the adverse scenario over the stress test horizon and the actual leverage ratio at the starting point.
350. Competent authorities should obtain the P2G starting point specific for each institution by offsetting elements that already cover risks reflected in the maximum stress impact. In particular, competent authorities should offset the relevant measures, in particular capital conservation buffer, in accordance with paragraph 354. In addition, when setting the P2G and P2G-LR starting points, competent authorities may consider, where relevant, other adjustments to the maximum stress impact related to the static balance sheet assumption or the different time horizon between the stress test exercise and the time of the starting point.
351. Where setting the P2G and P2G-LR, competent authorities should ensure an adequate link between their respective starting points as well as their final values. For this purpose, they may decide to use a bucketing approach to classify institutions in accordance with P2G and P2G-LR starting points, based on the relevant supervisory stress tests set out in paragraph 344 or based on other approaches set out in paragraph 345. Consequently, competent authorities may assign a fixed range of P2G or P2G-LR levels to each bucket and set the final P2G and P2G- LR within the range of the assigned bucket or, exceptionally, outside the range of the relevant bucket, based on the institution-specific considerations. Competent authorities should aim to avoid cliff effects between buckets, for instance by allowing partial overlap between the P2G or P2G-LR levels for adjacent buckets, and they should ensure that the resulting final P2G and P2G-LR are institution-specific.
352. When determining the final P2G and P2G-LR, competent authorities should consider, where relevant and available, the following factors: a. the year when the maximum stress impact occurs in relation to the starting point and time horizon of the scenarios used in the stress tests; b. the outcome of a reliable institution stress test, taking into account the specific scenario definitions and assumptions, in particular where they are deemed more relevant for the business model and risk profile of the institution or where the internal scenarios are more severe than the supervisory scenarios; c. changes occurring after the cut-off date of the stress test exercise with a material impact on the institution’s risk profile or capital position (e.g. sale of non-performing loans). These changes may include interim changes of the risk profile including structural changes in the institution’s activity or balance sheet; d. relevant management mitigating actions of the institution that are deemed credible and highly certain following their supervisory assessment; e. information about supervisory views on the relevance of supervisory stress testing to the institution’s strategy, financial plans and business model; f. reduced certainty on the actual sensitivity of the institution to adverse scenarios; g. any potential overlaps with the P2R or P2R-LR; h. the institution’s overall recovery capacity as specified in the EBA Guidelines on overall recovery capacity in recovery planning ; i. the quality (composition) of the institution’s available own funds, including the worst year of stress; j. whether or not the institution is under restructuring or resolution.
353. For the purpose of determining P2G, competent authorities should also consider the extent to which stress scenarios cover all the material risks contributing to the P2R in TSCR. Competent authorities should, in particular, have regard to the fact that macroeconomic downturn scenarios may not entirely capture some risks – for example pension risk or some elements of credit concentration risk (e.g. single name concentration) – that may amplify potential losses under the tested adverse scenarios.
354. In addition, competent authorities should consider the extent to which the existing combined buffer requirements and other applicable measures already cover risks revealed by stress testing. In this regard, competent authorities: a. should offset P2G against the capital conservation buffer (CCB), as P2G and the CCB overlap in nature; b. should in exceptional cases offset P2G on a case-by-case basis against the countercyclical capital buffer (CCyB) – while no overlap is in principle expected between them – based on the consideration of underlying risks covered by the buffer and factored into the design of the scenarios used for the stress tests, after liaising with the macroprudential authority; c. should not offset P2G against the systemic risk buffers (G-SII/O-SII buffers and the systemic risk buffer), as those are intended to cover the risks an institution poses to the financial system; d. should not offset P2G-LR against the G-SII leverage ratio buffer requirement specified in Article 92(1a) of Regulation (EU) No 575/2013; e. may review the P2G communicated to that institution to ensure that its calibration remains appropriate where an institution becomes bound by the output floor, in accordance with Article 104b(4a) of Directive 2013/36/EU.
355. Where competent authorities determine P2G, they should add this guidance on top of the OCR. Where competent authorities determine P2G-LR, they should add this guidance on top of OLRR. Competent authorities should consider OCR and OLRR as two separate stacks of requirements. Consequently, the available own funds can simultaneously be used to meet P2G and P2G-LR.
7.7. Summary of findings, scoring and supervisory measures
356. Following the above assessment, competent authorities should form a view on whether existing own funds resources provide sound coverage of the risks to which the institution is or might be exposed. This view should be reflected in a summary of findings, accompanied by a viability score based on the considerations specified in table 15.
357. In setting the score for capital adequacy, where applicable, competent authorities should consider the score of the overall recovery capacity with regard to capital (weak, adequate with potential room for improvement, or satisfactory) as specified in paragraphs 41 to 43 of the EBA Guidelines on Overall Recovery Capacity in Recovery Planning . The consideration of the overall recovery capacity score in the context of capital adequacy is especially relevant in case of a ‘weak’ overall recovery capacity score for capital.
358. The table below provides a non-exhaustive list of supervisory measures that competent authorities may take in case of identified deficiencies in the institution’s capital adequacy, including in stress conditions. Competent authorities should decide on the type of supervisory measure based on its effectiveness to the specific identified deficiency. Competent authorities may apply additional supervisory measures or a combination of them if these are deemed more appropriate to address the identified deficiencies.
359. When competent authorities assess the credibility of the capital plan or the revised capital plan, in line with points B. and C. of table 16, they should consider the following criteria: a. it covers the entire assumed stress testing time horizon; b. it puts forward a set of credible mitigating and management actions, such as restricting dividend payments, etc.; c. the institution is willing and able to take such actions in order to address the breaches of the applicable capital requirements in the system-wide stress tests; d. whether the mitigating and management actions are subject to any legal or reputational constraints, for instance due to contrary or conflicting former public announcements (e.g. on dividend policies, business plans and risk appetite); e. the probability that mitigating and management action would enable the institution to fully meet its applicable capital requirements within an appropriate timeframe; f. the proposed actions are broadly in line with macroeconomic considerations and with known future regulatory changes affecting an institution within the scope and timeline of the assumed adverse scenarios; g. the range of recovery options and their analysis as set out in the institution’s recovery plan.
360. Competent authorities should expect institutions to implement the revised capital plan, including further changes made based on the results of the supervisory assessment of and dialogue with the institution.
8. Title 8. Assessing risks to liquidity and funding and SREP liquidity and funding assessment
8.1. General considerations
361. Competent authorities should assess the institution’s material liquidity and funding risks and whether the institution’s liquidity and funding provides appropriate coverage of the risks assessed. The purpose of this title is to provide methodologies to be considered when assessing individual risks, and risk management and controls. It is not intended to be exhaustive, and gives leeway to competent authorities to take into account other additional criteria that may be deemed relevant based on their experience and the specific features of the institution in their assessment of the institution’s liquidity and funding. 362. When assessing the inherent liquidity and funding risk, and the adequacy of the liquidity and funding risk internal control framework, competent authorities should evaluate inter alia the institution’s overall compliance with the legal acts published separately on the EBA website as referred to in paragraph 12. 363. The methodology comprises six main components: a. assessment of inherent liquidity risk (section 8.2); b. assessment of inherent funding risk (section 8.3); c. assessment of liquidity and funding risk management and control framework (section 8.4); d. summary of findings and scoring for liquidity and funding adequacy (section 8.5); e. determination of potential SREP liquidity and funding risk measures (section 8.6); f. benchmarking and setting of quantitative liquidity and funding requirements (section 8.7). 364. The assessment flow is documented graphically in figure 3.
365. In the assessment of risks to liquidity and funding, competent authorities should review, among others, the institution’s liquidity coverage ratio (LCR), as specified in the Commission Delegated Regulation (EU) 2015/61 and the net stable funding ratio (NSFR), as established in Title IV of Part Six of the Regulation (EU) No 575/2013, and the institution’s ILAAP. They should also consider the recommendations, guidelines and guidance included in LCR and NSFR implementation reports issued by the EBA, as well as warnings and recommendations issued by macroprudential authorities or the ESRB. However, these guidelines extend the scope of the assessment beyond those minimum requirements, aiming to allow competent authorities to form a comprehensive view of the risks.
366. Competent authorities should ensure the assessment pays attention to how the institution’s business model impacts its liquidity and funding risk profile, taking into account the outcome of the business model analysis conducted under Title 4. In doing so, they should pay attention to how the institution’s business model has changed over time and whether this has resulted in any increased risks. Competent authorities should monitor key quantitative indicators to capture trends and inform this analysis.
367. To assist with the quantitative assessment of the institution’s liquidity and funding risks and adequacy, competent authorities should refer to the additional guidance available in section 8.7 on benchmarking and setting quantitative liquidity and funding requirements.
368. Competent authorities shall also evaluate any information with a potential impact on liquidity and funding position (e.g. from AML/CFT competent authorities).
369. In reviewing the quality of the institution’s organisational and risk management arrangements for managing liquidity and funding risk, competent authorities should ensure that those covers all of its material legal entities, branches and subsidiaries.
370. Competent authorities should take into account the impact of ESG risks on the inherent liquidity and funding risks as well as the adequacy of the liquidity and funding risk management and control framework related to ESG risks, giving priority to environmental risks.
371. The outcome of the assessment of each individual risk should be reflected in a summary of findings and an explanation of the main risk drivers and a score, as explained in the following sections.
8.2. Assessment of inherent liquidity risk
372. Competent authorities should assess the institution’s short- and medium-term liquidity risk over an appropriate set of time horizons, including intraday periods, to ensure that the institution maintains adequate levels of liquidity buffers, under both normal and stressed conditions. This assessment includes the following elements: a. evaluation of liquidity needs in the short and medium term; b. evaluation of intraday liquidity risk; c. evaluation of liquidity buffer and counterbalancing capacity; d. supervisory liquidity stress testing.
373. For the assessment of liquidity needs, buffers and counterbalancing capacity under normal conditions, competent authorities should support the analysis with evidence from the reporting templates for additional monitoring metrics as specified in the ITS on supervisory reporting. When assessing liquidity needs in stressed conditions, competent authorities should also consider actions the institutions may take to preserve its reputation/franchise. This should consider reputational effects on large wholesale and retail counterparties including those potentially triggered via social or other channels. Competent authorities may perform less granular intraday liquidity risk evaluation and liquidity stress testing, where this is justified by lower materiality of these sources of risk, especially for Category 3 and Category 4 institutions, and taking into account the results of the ILAAP.
Evaluation of liquidity needs in the short and medium term
374. Competent authorities should assess the institution’s liquidity needs in the short and medium term under both normal and stressed conditions. They should take into account the effect on the institution’s stressed liquidity needs before 30 days, between for example 30 days and 3 months, and after for example three to twelve months of severe but plausible stresses covering idiosyncratic, market-wide and combined shocks. Competent authorities should also analyse the size, location and currency of the liquidity needs and the separate impacts of shocks in its different material currencies to reflect currency convertibility risk and the risk of possible disruptions in the access to foreign exchange markets (including idiosyncrasies such as, for example, the loss of access to a correspondent banking account denominated in a foreign currency).
375. Competent authorities should support the assessment of short-term liquidity risk by analysing the LCR, as specified in Commission Delegated Regulation (EU) 2015/61, including whether the LCR is correctly measured and reported and adequately identifies the institution’s coverage of liquidity needs. Competent authorities should also assess whether institutions are periodically testing their ability to report the LCR on a daily basis in order to make sure that institutions will be able to deliver reliable data in accordance with Article 414 of Regulation (EU) 575/2013 when needed.
376. In evaluating the impact of shocks on the institution’s liquidity needs, competent authorities should take into account all material sources of liquidity risk for the institution, in particular: a. the possibility that any applicable EU regulatory requirement would not adequately identify the institution’s liquidity needs in the event of the type of stress scenario used for the requirement, including where maturities are shorter than 30 days; b. risks arising in respect of wholesale counterparties regarding on-balance-sheet items and funding concentrations. Competent authorities should have regard to the volatility of funding provided by counterparties that all belong to the most material sectors serviced and potential contagion risks. In this respect, particular attention should be paid to funding gathered through new business lines and distribution channels, as well as from clients running activities bearing an increased level of risk (crypto-asset issuers and services providers); c. risks arising in respect of contingent cash flows/off-balance-sheet items (for example, credit lines, margin calls) and activities (for example, liquidity support for unconsolidated specialpurpose vehicles beyond contractual obligations; d. inflows and outflows on a gross basis, as well as a net basis; where there are very large inflows and outflows, competent authorities should pay specific attention to the risk to the institution when inflows are not received when expected, even when the net outflow risk is limited; e. risks arising in respect of retail counterparties including funding concentrations. For this purpose, competent authorities should make use of the methodology on the classification of retail deposits into different risk buckets, pursuant to Articles 24 and 25 of Commission Delegated Regulation (EU) 2015/61; f. the risk that excessive risks in the medium- to long-term funding profile will adversely affect the behaviour of counterparties relevant to the short-term liquidity position; g. risk arising in the context of fiduciary deposits .
377. Competent authorities should ensure that their assessment of the institution’s short-term liquidity needs considers the impact of digitalisation (including for example instant payments) and potential for the spread of information on social media to increase the speed of withdrawals in a stressed scenario.
Evaluation of intraday liquidity risk
378. Competent authorities should assess the institution’s exposure to intraday liquidity risk for a selected time horizon. This assessment should include, as a minimum, an evaluation of intraday liquidity available or accessible under normal conditions as well as under financial or operational stress (e.g. IT failures, legal constraints on the transfer of funds, suspension/termination of access to correspondent banking services and/or clearing services for currencies, commodities or instruments significant for the institution). This should particularly consider how in times of stress, an institution´s increased intraday collateral needs may limit its ability to use a liquidity buffer to cover stressed outflows when needed.
379. For those jurisdictions where reporting on intraday risk is not yet available, competent authorities may rely on the institution’s own analysis of intraday liquidity risk.
Evaluation of liquidity buffer and counterbalancing capacity
380. Competent authorities should assess the adequacy of the institution’s liquidity buffer and counterbalancing capacity regarding the characteristics of the assets considered under different stress scenarios within a month as well as over different time horizons, potentially up to one year, including overnight. The assessment should include consideration of the classification and quality of liquid assets (as specified in the Commission Delegated Regulation (EU) 2015/61), their compliance with general and operational requirements for high-quality liquid assets, and whether the liquidity buffer and counterbalancing capacity are in line with the institution’s risk appetite.
381. Competent authorities should consider factors that might reduce the institution’s ability to monetise its liquid assets in a timely manner during a stress period including such as high concentrations with individual counterparties or type of assets, assets in the buffer that are encumbered or borrowed, and the denomination of liquid assets in a different currency to the institution’s liquidity needs. Competent authorities should also consider the likely value of committed liquidity facilities that may be included in the counterbalancing capacity.
382. Competent authorities should review (where applicable) the appropriateness of the institution’s assumptions concerning its ability to access repo markets and central bank funding in a stressed period, including regarding the suitability and availability of assets to serve as collateral. They should take into account whether the institution tests its market access by selling or repo-ing on a periodic basis. Equally they should review the institutions’ assumptions regarding time to liquidity under stress.
Supervisory liquidity stress testing
383. Competent authorities should run their own liquidity stress tests to independently assess short- and medium-term liquidity risks. Stress scenarios should be anchored to the 30-day LCR stress assumptions, but competent authorities may extend the scope of their assessment by exploring risks within 30 days as well as beyond 30 days, and altering LCR assumptions to reflect risks not adequately covered in the LCR. This should include a supervisory stress test combining institution-specific and market-wide stress.
8.3. Assessment of inherent funding risk
384. Competent authorities should assess the institution’s funding risk and whether the mediumand long-term assets and off-balance-sheet items are adequately met with a range of stable funding instruments under both normal and stressed conditions. This assessment includes the following elements: a. evaluation of the institution’s funding profile; b. evaluation of risks to the stability of the funding profile; c. evaluation of actual market access; d. evaluation of expected change in funding risks based on the institution’s funding plan.
Evaluation of the institution’s funding profile
385. Competent authorities should assess the appropriateness of the institution’s funding profile, including both medium- and long-term contractual and behavioural mismatches, in relation to its business model, strategy and risk appetite. They should take into account whether the institution’s medium- and long-term assets and off-balance-sheet items are adequately met with a range of stable funding instruments, pursuant to Article 413 of Regulation (EU) No 575/2013. Competent authorities should support this assessment by analysing the NSFR as specified in Title IV of Part Six of Regulation (EU) No 575/2013 and assess whether this has been correctly reported.
386. Competent authorities should consider the impact on the institution’s funding profile of any (local) regulatory and contractual factors affecting the behavioural characteristics of funding providers (e.g. regulations regarding clearing, bail-in, deposit guarantee schemes, as they may influence the behaviour of funding providers).
387. Competent authorities should assess whether potential shortcomings arising from the institution’s funding profile, such as maturity mismatches breaching acceptable boundaries, excessive concentrations of funding sources, excessive levels of asset encumbrance, or inappropriate or unstable funding of long-term assets could lead to an unacceptable increase in the cost of funding and a loss of funding access for the institution. In particular, assumptions regarding the stickiness of funding attracted via channels that rely on fintech or are less traditional for example online deposit platforms – need to be closely assessed when planning or designing stress scenarios.
Evaluation of risks to the stability of the funding profile
388. Competent authorities should consider factors that may reduce the stability of the funding profile in relation to the type and characteristics of assets, off-balance-sheet items and liabilities. They should take into account the structural maturity mismatch between assets and liabilities (including the impact of any currency mismatches), appropriate structural funding metrics (e.g. loan/deposit ratio, customer funding gap and behaviourally adjusted maturity ladder), and funding characteristics that could indicate increased ML/TF risks and concerns from a prudential perspective. Competent authorities should also consider impact of losses on the stability of funding; knowing that funding providers may be sensitive to much lower losses than those that would endanger capital ratios.
389. Competent authorities should assess risks to the sustainability of the funding profile arising from concentrations in funding sources (particularly in the type of funding instruments used, specific funding markets, single or connected counterparties). For example, they should consider the characteristics of the most material sectors serviced by the institution and how this impacts the institution’s funding risk profile, paying particular attention to exposures to cyclical or volatile sectors.
390. Competent authorities should also assess the risk that asset encumbrance may have an adverse effect on the market’s appetite for the unsecured debt of the institution (in the context of the specific characteristics of the market(s) in which the institution operates and the institution’s business model).
Evaluation of actual market access
391. Competent authorities should be aware of the institution’s actual market access and current and future threats to this market access including disruptions in the access to foreign exchange markets (including idiosyncratic). For the assessment, they should take into account the degree to which the institution makes high demands on particular markets or counterparties (including central banks) relative to those markets’/counterparties’ capacity, any significant or unexpected changes in the issuance of debt, the risk that news about the institution may negatively influence the market (perception/confidence) and therefore market access, and signs that short-term liquidity risks may reduce the access the institution has to its major funding markets.
Evaluation of expected change in funding risks based on the institution’s funding plan
392. Competent authorities should assess the expected change in funding risks based on the institution’s funding plan and form a view on the feasibility of the plan (such as backtesting, considering alternative scenarios).
8.4. Assessment of liquidity and funding risk management and control framework
393. To achieve a comprehensive understanding of the institution’s liquidity and funding risk profile and their interconnectedness, competent authorities should also review the governance and risk management framework underlying its liquidity and funding risk. To this end, competent authorities should assess: a. the liquidity risk and funding strategy and liquidity and funding risk appetite; b. the organisational framework, policies and procedures; c. risk identification, measurement, management, monitoring and reporting; d. the institution’s liquidity/funding-specific stress testing; e. the internal control framework for liquidity risk and funding risk management; f. the institution’s liquidity contingency plans and recovery plans; g. the institution’s funding plans.
Liquidity and funding risk strategy and risk appetite
394. Competent authorities should assess whether the institution has a sound, clearly formulated, documented and communicated liquidity/funding risk strategy and appetite, approved by the management body. For this assessment, among other factors, competent authorities should take into account the role of the management body in setting, approving and reviewing the liquidity/funding risk strategy and appetite (including its major underlying assumptions), the proper implementation of this strategy by the management body as well as its appropriateness for the institution given its business model, overall risk tolerance, role in the financial system, financial condition and funding capacity.
Organisational framework, policies and procedures
395. Competent authorities should assess whether the institution has an appropriate organisational framework and governance arrangements for liquidity and funding risk management, including a robust ILAAP framework in line with paragraph 911 of Title 5 of these Guidelines. Further, they should assess whether the institution has implemented appropriate measurement and control functions, with sufficient human and technical resources to develop and implement these functions and to carry out the required monitoring tasks. The liquidity risk control and monitoring of systems and processes should be controlled by an independent function.
396. Competent authorities should assess whether the institution has appropriate policies and procedures for the management of liquidity and funding risk and whether these are consistent with the institution’s liquidity risk appetite. This includes assessment of whether the policies and procedures are properly defined, formalised and effectively communicated throughout the institution. The management body should approve and regularly review the policies and procedures, and these should be implemented by senior management.
397. Competent authorities should assess the adequacy of the institution’s approach to maintaining market access in its significant funding markets, including any testing of market access that has been undertaken, the institution’s approach to maintaining an ongoing presence in the markets (for specific small institutions or specialised business models, testing of access to markets may not be relevant), the institution’s approach to developing strong relationships with funding providers, and any evidence that the institution would continue to have ongoing market access in times of stress.
Risk identification, measurement, management, monitoring and reporting
398. Competent authorities should assess whether the institution has an appropriate framework and IT systems for identifying and measuring liquidity and funding risk, in line with the institution’s size, complexity, risk appetite and risk-taking capacity. They should take the following factors into account: a. whether the institution has implemented appropriate methods for projecting its cash flows over an appropriate set of time horizons, assuming business-as-usual and stress situations, and comprehensively across material risk drivers; b. whether the institution uses appropriate key assumptions and methodologies, which are regularly reviewed, recognising interaction between different risks (credit, market, IRRBB etc.) arising from both on- and off-balance sheet items; c. whether the institution understands its ability to access financial instruments wherever they are held, having regard to any legal, regulatory and operating restrictions on their use, including, for example, the inaccessibility of assets due to encumbrance during different time horizons.
399. Competent authorities should assess whether institutions have an appropriate reporting framework for liquidity and funding risk that has been agreed by the senior management. They should take into account the quality of information systems and internal information flows used to generate reporting and whether the reporting is understandable for the target audience, accurate and usable (e.g. timely, not overly complex, within the correct scope). The reporting should be provided regularly to appropriate recipients (such as the management body, senior management or an asset-liability committee).
400. Competent authorities should assess the adequacy of the process of measuring intraday liquidity risk, especially for those institutions that participate in payment, settlement and clearing systems. They should take into account whether the institution adequately monitors and controls cash flows and liquid resources available to meet intraday requirements and forecasts when cash flows will occur during the day, and whether the institution carries out adequate specific stress testing for intraday operations, also considering business developments (e.g. possibility for instant payments).
401. Competent authorities should assess whether the institution has an adequate set of liquidity and funding indicators. They should take into account: a. whether the indicators adequately reflect the institution’s liquidity risk profile including the degree of diversification of assets in the liquidity buffer and the consistency between the currency denomination of their liquid assets and the distribution by currency of their liquidity outflows; b. whether the indicators adequately cover key liquidity risk aspects related to potential cliff risks such as the concentration of outflows maturities (considering also any potential early withdrawal of liabilities) and central bank support programmes; c. whether the indicators permit identification of the institution’s structural funding vulnerabilities, including any concentrations in particular markets, currencies, counterparties, and maturities; d. whether the indicators provide an insight into the ‘stickiness’ of the institutions’ funding (independent of what is assumed in the LCR or NSFR), including the breakdown into homogenous categories in accordance with their risk properties, and the proportion of deposits outside the scope of a guarantee/insurance scheme.
402. Institutions should be able to demonstrate that the indicators are adequately documented, periodically revised, used as inputs to define the risk appetite of the institution, part of management reporting and used for setting operating limits.
Institution’s liquidity- and funding-specific stress testing
403. Competent authorities should assess whether an institution has implemented adequate liquidity-specific stress testing, in accordance with the EBA Guidelines on institutions’ stress testing : a. to understand the impact of adverse events on its risk exposure and to be able to assess the adequacy of its liquid assets, counterbalancing capacity and funding structure; b. to cover risks that may crystallise during different types of stress scenarios and/or to address risks posed by control, governance or other deficiencies.
404. Competent authorities should take into account whether the framework permits the institution to: a. determine the institution’s survival horizon given its existing liquidity buffer and stable sources of funding, and taking into account the institution’s risk appetite, during a severe but plausible liquidity stress period; b. analyse the impact of stress scenarios on its consolidated group-wide liquidity position and on the liquidity position of individual entities and business lines; c. understand where risks could arise, regardless of its organisational structure and the degree of centralised liquidity risk management.
405. Competent authorities should ensure that the institution provides the modelled impact of different types of stress scenarios (as explained in the EBA Guidelines on institutions’ stress testing), as well as a number of sensitivity tests (on the basis of proportionality). The stress scenarios and shocks simulated in them should not only be based on the past, but also make use of hypothetical stress scenarios based on expert judgement. Competent authorities should analyse whether the following scenarios are considered as a minimum: a. short-term and prolonged; b. institution-specific and market-wide (occurring simultaneously in a variety of markets); c. a combination of (a) and (b).
406. An important aspect that competent authorities should consider when assessing the institution’s stress testing framework is the modelling of the impact of the hypothetical stress scenario(s) on the institution’s cash flows and on its counterbalancing capacity and survival horizon, and whether the modelling reflects the different impacts that economic stress may have on both an institution’s assets and its in- and outflows.
407. Competent authorities should also assess whether the institution takes a conservative approach to setting stress testing assumptions. Depending on the type and severity of the scenario, competent authorities should consider, as relevant, the appropriateness of a number of assumptions, in particular: a. the run-off of retail funding; b. the reduction of secured and unsecured wholesale funding; c. the correlation between funding markets and diversification across different markets; d. additional contingent off-balance sheet exposures; e. funding tenors (e.g. where the funding provider has call options); f. the impact of any deterioration of the institution’s credit rating; g. FX convertibility and access to foreign exchange markets and correspondent banking accounts; h. the ability to transfer liquidity across entities, sectors and countries; i. estimates of future balance-sheet growth; j. due to reputational risks, an implicit requirement for the institution to roll over assets and to extend or maintain other forms of liquidity support.
408. Competent authorities should assess whether the management framework of the institution’s liquidity-specific stress testing is appropriate and whether it is properly integrated into the overall risk management strategy. They should take into account: a. whether the extent and frequency of stress tests are appropriate to the nature and complexity of the institution, its liquidity risk exposures and its relative importance in the financial system; b. whether the outcomes of stress testing are integrated into the institution’s strategic planning process for liquidity and funding and used to increase the effectiveness of liquidity management in the event of a crisis, including in the institution’s liquidity contingency and recovery plan; c. whether the institution has an adequate process for identifying suitable risk factors for conducting stress tests, having regard to all material vulnerabilities that can undermine the liquidity position of the particular institution; d. whether assumptions and scenarios are reviewed and updated sufficiently frequently; e. where the liquidity management of a group is being assessed, whether the institution pays adequate attention to any potential obstacles to the transfer of liquidity within the group.
Liquidity and funding risk internal control framework
409. Competent authorities should assess whether the institution has a strong and comprehensive internal limit and control framework, and sound safeguards to mitigate its liquidity and funding risk in line with its risk appetite and to ensure the availability of a diversified funding structure. They should take into account whether the limit and control framework is adequate for the institution’s complexity, size and business model and reflects the different material drivers of liquidity risk and the outcomes of liquidity stress tests.
410. Competent authorities should consider whether the institution has limits to ensure consistency between the currency denomination of their liquid assets and the distribution by currency of their net liquidity outflows in accordance with Article 8(6) of Commission Delegated Regulation (EU) 2015/61.
411. Competent authorities should assess whether the limits are approved and regularly reviewed by the competent bodies of the institution and communicated to all relevant business lines. This process, along with how the institution monitors compliance with limits and the escalation process for breaches, should be clearly documented in its procedures.
412. Competent authorities should assess whether the institution has implemented an adequate transfer pricing system as part of the liquidity risk control framework, which incorporates all relevant liquidity costs, benefits and risks. Competent authorities should take into account whether the transfer pricing mechanism allows management to give appropriate incentives for managing liquidity risk, and whether the system and its calibration are reviewed and updated appropriately given the size and complexity of the institution. In addition, competent authorities should assess whether the institution’s policy on incorporating the funds transfer pricing (FTP) methodology into the internal pricing framework is used for assessing and deciding on transactions with customers (this includes both sides of the balance sheet, e.g. granting loans and taking deposits).
413. Competent authorities should assess whether the institution has adequate controls regarding the liquid-assets buffer, including concentration limits and appropriate ongoing monitoring of the adequacy of the buffer and for changes in market conditions that could affect the institution’s ability to liquidate its assets quickly.
Liquidity contingency plans
414. Competent authorities should assess whether the institution’s liquidity contingency plan (LCP) adequately specifies the policies, procedures and action plans for responding to severe potential disruptions to the institution’s ability to meet its liquidity needs and fund itself. They should take into account the content and scope of contingency funding measures included in the LCP, and in particular factors such as: a. whether the LCP adequately explains governance arrangements for its activation and maintenance; b. whether the LCP appropriately reflects the institution’s liquidity- and funding-specific and wider risk profile; c. whether the institution has a framework of liquidity early warning indicators, including among others those established as liquidity indicators in the EBA GL on recovery plan indicators that are likely to be effective in enabling the institution to identify deteriorating market circumstances in a timely manner and to quickly determine what actions need to be taken; d. whether the LCP describes clearly that the LCR liquidity buffer is designed to be used in case of stress, even if that leads to LCR values below 100%, including that it is part of the expected management of liquidity risk under stress that subsequent communications to senior management take place if established lower LCR values are reached. The LCP should clearly reflect and describe how liquidity risk should be managed under stress to steer towards targeted LCR levels as closely as possible; e. whether the LCP clearly articulates all material (potential) funding sources, including the estimated amounts available for the different sources of liquidity and the estimated time needed to obtain funds from them; f. whether the measures are in line with the institution’s overall risk strategy and liquidity risk appetite; g. the appropriateness of the assumptions regarding the role of central bank funding in the institution’s LCP. Examples of factors competent authorities may consider could include the institution’s views on: I. the current and future availability of potential alternative funding sources connected to central bank lending programmes; II. the types of lending facilities, the acceptable collateral and the operational procedures for accessing central bank funds; III. the circumstances under which central bank funding would be needed, the amount required and the period for which such a use of central bank funding would probably be required.
415. Competent authorities should assess whether the actions described in the LCP are feasible in relation to the stress scenarios in which they are meant to be taken. They should take into account factors such as: a. the level of consistency and interaction between the institution’s liquidity-related stress tests, its LCP, its liquidity early warning indicators and, where applicable, its liquidity related recovery plan; b. whether the actions defined in the LCP appear likely to enable the institution to react adequately to a range of possible scenarios of severe liquidity stress, including institutionspecific and market-wide stress, as well as the potential interaction between them; and whether the actions defined in the LCP are prudently quantified in terms of liquiditygenerating capacity under stressed conditions and the time required to execute them, taking into account operational requirements such as pledging collateral at a central bank.
416. Competent authorities should assess the appropriateness of the institution’s governance framework with respect to its LCP. They should take into account factors such as: a. the appropriateness of escalation and privatisation procedures detailing when and how each of the actions can and should be activated; b. whether the institution has adequate policies and procedures with respect to communication within the institution and with external parties; c. the degree of consistency between the LCP and the institution’s business continuity plans.
Funding plans
417. Competent authorities should assess whether the funding plan is feasible and appropriate in relation to the nature, scale and complexity of the institution, its current and projected activities and its liquidity and funding profile. They should take into account factors such as: a. whether the funding plan addresses alternative scenarios. Competent authorities should pay particular attention to the robustness of the plan for supporting the projected business activities under adverse scenarios; b. the expected change in the institution’s funding profile arising from the execution of the funding plan and whether this is suitable given the institution’s activities and business model; c. whether the funding plan supports any required or desired improvements in the institution’s funding profile; d. their own view on the (changes in) market activity planned by institutions in their jurisdiction on an aggregated level, and what that means for the feasibility of individual funding plans; and e. whether the funding plan is: I. integrated with the overall strategic plan of the institution; II. consistent with its business model; III. consistent with its liquidity risk appetite;
418. In addition, competent authorities may consider: a. whether the institution adequately analyses and is aware of the appropriateness and adequacy of the funding plan given the institution’s current liquidity and funding positions and their projected development. As part of this, competent authorities may consider whether the institution’s senior management can explain why the funding plan is feasible and where its weaknesses lie; b. the institution’s policy for determining what funding dimensions and what markets are significant to the institution (and whether it is adequate); c. the time horizon envisaged by the institution for migration to a different funding profile, if required or desired, bearing in mind that there may be risks involved if migration towards the end state is either too fast or too slow;a d. whether the funding plan contains different strategies and clear management procedures for timely implementation of strategy changes.
419. Competent authorities should assess whether the institution’s funding plan is appropriately implemented. As a minimum, they should take into account: a. whether the funding plan is properly documented and communicated to all the relevant staff; b. whether the funding plan is embedded in the day-to-day operations of the institution, especially in the funding decision-making process.
420. In addition, competent authorities may take into account whether the institution is able to reconcile the funding plan with the data provided to competent authorities in the funding plan template.
421. Competent authorities should consider the quality of the institution’s processes for monitoring the execution of the funding plan and its ability to react to deviations in a timely manner. For this assessment, competent authorities should take into account factors such as: a. the quality of the updates to (senior) management regarding the current status of the execution of the funding plan; b. whether the funding plan envisages alternative fall-back measures to be implemented if there are changes in the market conditions; and c. the policy and practice of the institution regarding the regular review, back-testing, and updating of the funding plan when the actual funding raised significantly differs from the funding plan.
8.5. Summary of findings, scoring and supervisory measures
422. Following the above assessment, competent authorities should form a view on the institution’s liquidity and funding risks and the capacity of the institutions’ liquidity resources to cover/mitigate these. This view should be reflected in a summary of findings, accompanied by a liquidity and funding adequacy score based on the considerations specified in table 17. The liquidity and funding adequacy score should reflect the view of competent authorities on whether the existing liquidity resources provide appropriate coverage of the liquidity and funding risks. Competent authorities may consider the use of intermediate scores for liquidity and funding risk where deemed relevant.
423. In setting the liquidity and funding adequacy score, competent authorities should, where applicable, consider the score of the liquidity overall recovery capacity in recovery planning (weak, adequate with potential room for improvement, satisfactory) as specified in paragraphs 41-43 of the EBA Guidelines on overall recovery capacity in recovery planning . The consideration of the overall recovery capacity score in the context of liquidity adequacy is especially relevant in case of a ‘weak’ overall recovery capacity score for liquidity.
424. Following the liquidity and funding adequacy scoring of section 8.5, competent authorities should determine whether it is necessary to set specific liquidity and funding requirements to cover risks to liquidity and funding to which an institution is or might be exposed.
425. The next table provides a non-exhaustive list of qualitative and quantitative supervisory measures that competent authorities may use in case a specific deficiency is identified. Competent authorities may apply additional supervisory measures (including quantitative measures in accordance with Article 104(1)(a) of Directive 2014/36/EU or a combination of them if these are deemed more appropriate to address the identified deficiencies.
426. Where competent authorities determine that quantitative measures may be necessary, they should refer to the additional guidance in the subsequent section on benchmarking and setting quantitative liquidity and funding measures.
427. It is relevant to note that part of the measures mentioned in table 18 are of a qualitative nature. Where fundamental weaknesses arise, particularly in terms of management of liquidity and funding, qualitative measures should be prioritised, where possible.
428. When setting structural, long-term supervisory requirements, competent authorities should consider the need for additional short/medium-term liquidity and/or own fund requirements as an interim solution to mitigate the risks that persist while the structural requirements produce the desired effects.
429. Where competent authorities conclude that there is a high risk that the institution’s cost of funding will increase notably, they should consider requesting changes to the funding structure to mitigate the funding cost risk, or even own funds measures (as covered in Title 7) to compensate for the P&L impact if the institution cannot pass the increased costs of funding to its customer.
8.6. Benchmarking and setting of quantitative liquidity and funding requirements
Determination of specific quantitative liquidity and funding requirements
430. To support their liquidity and funding adequacy scoring and calibrate specific quantitative requirements where deemed potentially necessary (e.g. any of the measure referred to in table 18 above that are quantitative), competent authorities should consider supervisory liquidity and funding benchmarks as quantitative tools. They should be used to provide a prudent, consistent, transparent and comparable benchmark with which to calculate and compare specific quantitative liquidity requirements for institutions with similar business models and risk profiles. In developing supervisory benchmarks, competent authorities should use supervisory assessment of risks to liquidity and funding, and the results of supervisory liquidity stress testing.
431. Competent authorities should use the most appropriate benchmark for the institution’s business model, applying judgement to the outcome of the benchmark to account for business-model-specific considerations where necessary. When competent authorities take supervisory benchmarks into consideration for the determination of specific liquidity requirements, they should explain to the institution the rationale and general underlying principles behind the benchmarks.
432. Competent authorities should assess the suitability of any benchmarks applied to institutions and continually review and update them in light of the experience of using them.
433. A key input to the competent authority’s benchmarks for the quantification of specific quantitative liquidity or funding requirements will be the data collected through the supervisory reporting in accordance with Article 415 of Regulation (EU) No 575/2013 covering liquidity and stable funding on an individual and consolidated basis, and additional liquidity monitoring metrics.
434. Below are some examples of the possible approaches: a. Example 1: Institution with an initial liquidity buffer of EUR 1,200 million cumulative inflows and cumulative outflows estimated under stressed conditions are projected through a time horizon of five months. During this time horizon, the institution makes use of the liquidity buffer each time inflows fall below outflows. The result is that, under the stressed conditions defined, the institution would be able to survive for four and a half months, which is longer than the minimum survival period set by supervisors (in this example, three months); b. Example 2: The supervisory minimum survival period is set at three months. An alternative measure to setting a minimum survival period, which can also address the supervisory concern that the gap between inflows and outflows is unacceptably high, is to set a cap on outflows. In the figure below, the mechanism for setting a cap on outflows is shown by the black horizontal bar. An institution is required to reduce its outflows to a level below the cap. The cap can be set for one or more-time buckets and for net outflows (following correction for inflows) or gross outflows. The alternative of adding a buffer requirement instead is shown in the third column.
435. Where competent authorities have not developed their own benchmark for the quantification of specific quantitative liquidity requirements, they can apply a benchmark using the following steps particularly in the case of liquidity risk: a. perform a comparative analysis, under stressed conditions, of net cash outflows and eligible liquid assets over a set of time horizons: up to one month (including overnight), from one month to three months, and from three months to one year; for this purpose, competent authorities should project net outflows (gross outflows and inflows); b. counterbalance capacity throughout different maturity buckets, considering stressed conditions (for example, prudent valuation under stress assumptions for liquid assets versus current valuation under normal conditions and after a haircut), building a stressed maturity ladder for the year ahead; c. estimate the survival period of the institution, based on the assessment of the stressed maturity ladder; d. determinate the desired/supervisory minimum survival period, taking into account the institution’s risk profile and market and macroeconomic conditions; e. if the desired/supervisory minimum survival period is longer than the institution’s current survival period, competent authorities may estimate additional amounts of liquid assets (additional liquidity buffers) to be held by the institution to extend its survival period to the minimum required.
Articulation of specific quantitative liquidity and funding requirements
436. To articulate the specific quantitative liquidity requirements, competent authorities should use one of the following approaches, unless another approach is considered more appropriate in specific circumstances: a. Approach 1 – Require an LCR higher than the regulatory minimum, of such a size that shortcomings identified are sufficiently mitigated. b. Approach 2 – Require a minimum survival period of such a length that identified shortcomings are sufficiently mitigated; the survival period can be set either directly, as a requirement, or indirectly, by setting a cap on the amount of outflows over the relevant time buckets considered; competent authorities may require different types of liquid assets (e.g. assets eligible for central banks), to cover risks not (adequately) covered by the LCR. c. Approach 3 – Require a minimum total amount of liquid assets or counterbalancing capacity, either as a minimum total amount or as a minimum amount in excess of the applicable regulatory minimum, of such a size that identified shortcomings are sufficiently mitigated; competent authorities may set requirements for the composition of liquid assets, including operational requirements (e.g. direct convertibility to cash, or deposit of the liquid assets at the central bank).
437. To articulate the specific quantitative stable funding requirements appropriately, competent authorities should use one of the following approaches, unless another approach is considered more appropriate in specific circumstances: a. Approach 4 – Require a NSFR higher than the regulatory minimum, of such a size that shortcomings identified are sufficiently mitigated. b. Approach 5 – Require a minimum total amount of available stable funding, either as a minimum total amount or as a minimum amount in excess of the applicable regulatory minimum, of such a size that identified shortcomings are sufficiently mitigated.
438. Competent authorities should structure quantitative liquidity or funding requirements in such a manner as to deliver broadly consistent prudential outcomes across institutions, bearing in mind that the types of requirements may differ between institutions because of their individual circumstances. In addition to the quantity, the structure should specify the expected composition and nature of the requirement. In all cases, it should specify the supervisory requirement and any applicable Directive 2013/36/EU requirements. Liquidity buffers and counterbalancing capacity held by the institution to meet supervisory requirements should be available for use by the institution during times of stress.
439. Competent authorities should ensure that the institution immediately notifies them if it does not meet the requirements or does not expect to meet the requirements in the short term. The notification should be accompanied by a plan drawn up by the institution for the timely restoration of compliance with the requirements. Competent authorities should assess the feasibility of the plan and take appropriate supervisory measures if the plan is not considered feasible. Where the plan is considered feasible, competent authorities should: determine any necessary interim supervisory measures based on the institution’s circumstances; monitor the implementation of the restoration plan; and closely monitor the institution’s liquidity position, asking the institution to increase its reporting frequency if necessary.
440. Notwithstanding the above, competent authorities may also set qualitative requirements in the form of restrictions/caps/limits on mismatches, concentrations, risk appetite, quantitative restrictions on the issuance of secured loans, etc., in accordance with the criteria specified in Title 9 of the Guidelines.
441. Below are some examples of the different approaches for the structure of specific quantitative liquidity requirements: Example of specific requirements articulation As of 1 January 2025, and until otherwise directed, Bank X is required to: a. Approach 1: ensure that its counterbalancing capacity is at all times equal to or higher than e.g. 125% of its liquidity net outflows as measured in the LCR. b. Approach 2: ensure that its counterbalancing capacity results at all times in a survival period that is greater than or equal to three months, measured by the internal liquidity stress test/the maturity ladder/specific metrics developed by the supervisor. c. Approach 3: − ensure that its counterbalancing capacity is at all times equal to or higher than EUR X billion; or − ensure that its counterbalancing capacity is at all times equal to or higher than EUR X billion in excess of the minimum requirement in accordance with the LCR. d. Approach 4: ensure that its available stable funding is at all times equal to or higher than e.g. 125% of its required stable funding as measured in the NSFR. e. Approach 5: − ensure that its available stable funding is at all times equal to or higher than EUR X billion; or − ensure that its available stable funding is at all times equal to or higher than EUR X billion in excess of the minimum requirement in accordance with the NSFR.
9. Title 9. Overall SREP assessment and communication
9.1. General considerations
442. This title covers how the findings from the assessments of each SREP elements are combined into the overall SREP assessment, as well as how the respective outcome is communicated – including the articulation and justification of own funds requirements and guidance. It also addresses how the non-exhaustive supervisory measures listed at the end of each relevant sections and titles of these guidelines interact with other relevant frameworks (i.e. early intervention measures, resolution authorities’ assessments, macroprudential measures and AML/CFT).
9.2. Overall SREP assessment
443. In determining the overall SREP assessment, competent authorities should consider the findings of the assessments of the SREP elements, specifically: a. the risks to which the institution is or may be exposed; b. the likelihood that the institution’s governance, control deficiencies and/or business model or strategy are likely to exacerbate or mitigate these risks, or expose the institution to new sources of risk; c. whether the institution’s own funds and liquidity resources provide sound coverage of these risks; d. the potential for positive and negative interaction between the elements (e.g. competent authorities may consider a strong capital position to be a potential mitigating factor for certain concerns identified in the area of liquidity and funding, or by contrast, that a weak capital position may exacerbate concerns in that area).
444. On the basis of these considerations, competent authorities should determine the institution’s viability, defined as its proximity to a point of non-viability on the basis of the adequacy of its own funds and liquidity resources, governance, controls and/or business model or strategy to cover the risks to which it is or may be exposed. As a result of this determination, competent authorities should: a. take any supervisory measures necessary to address concerns; b. determine future supervisory resourcing and planning for the institution, including whether any specific supervisory activities should be planned for the institution as part of the Supervisory Examination Programme; c. determine the need for early intervention measures as specified in Article 27 of Directive 2014/59/EU; d. determine whether the institution can be considered to be ‘failing or likely to fail’ within the meaning of Article 32 of Directive 2014/59/EU.
445. The overall SREP assessment should be reflected in a viability score based on the considerations specified in table 20 and clearly documented in an annual summary of the overall SREP assessment. This annual summary should also include the overall SREP score and scores for elements of the SREP, and any supervisory findings made over the course of the previous 12 months.
446. When determining that an institution is ‘failing or likely to fail’, as reflected by an overall SREP score of ‘F’, competent authorities should engage with the resolution authorities to consult on findings following the procedure specified in Article 32 of Directive 2014/59/EU.
9.3. Communication of the outcome of the SREP assessment
447. Competent authorities should communicate, in accordance with the SREP engagement model set out in section 2.4, the outcome of the SREP assessment to the institution in writing. The communication should be addressed to the management body of the institution.
448. The communication of the outcome of the SREP assessment to institutions, and, where relevant, to other competent or resolution authorities, should at least include the following elements: a. the relevant level of application, the date and the date of the application of the SREP assessment, as well as the reference dates of the information used in its preparation in accordance with Article 10 of the Commission Implementing Regulation (EU) No 710/2014; b. a description of the outcome of the SREP, including a summary of the assessment, material supervisory findings, and the overall SREP score. Where remedial action is required from the institution for specific SREP elements or sub-elements, competent authorities should consider including an appropriate timeframe for remediation and sharing the score for these elements and sub-elements, where appropriate; c. the required level and quality of the P2R, in accordance with the process and criteria specified in Title 7, including the institution-specific justification for setting the requirements, separately for the risk of excessive leverage and for other types of risks. The justification should provide a clear indication of the material risk drivers contributing to the P2R. In case of relevant changes to the regulatory framework for determining the P1R applicable to an institution, communication should include the outcome of the assessment performed as per paragraph 294 of Title 7. In justifying P2R, competent authorities should: i. refer, to the extent possible, to the risk categories and subcategories/elements as described in Title 6 and sections 7.2 and 7.3, taking into account the existing definitions of specific risk types in the applicable legislation, with the aim of ensuring overall comparability across institutions; ii. identify the main deficiencies to be covered by these requirements until they are addressed line with paragraph 320. d. in communicating the required level of capital and quality of the Pillar 2 requirements in accordance with the previous point, competent authorities should: i. communicate the institution’s TSCR as a proportion (ratio) of the TREA, broken down in terms of the composition of the requirement. The TSCR should be expressed using the following formula: 𝑇𝑆𝐶𝑅 𝑇𝑆𝐶𝑅 𝑟𝑎𝑡𝑖𝑜 = 𝑇𝑅𝐸𝐴 ii. communicate the institution’s TSLRR as a proportion (ratio) of the leverage ratio exposure (LRE), broken down in terms of the composition of the requirement. The TSLRR should be expressed using the following formula: 𝑇𝑆𝐿𝑅𝑅 𝑇𝑆𝐿𝑅𝑅 𝑟𝑎𝑡𝑖𝑜 = 𝐿𝑅𝐸 iii. communicate the institution’s OCR and its component parts – the Pillar 1 own funds requirements, P2R and the buffer requirements – as a proportion (ratio) of the TREA, broken down in terms of the composition of the requirement; iv. communicate the institution’s OLRR and its component parts – the leverage ratio own funds requirement, P2R-LR and G-SII leverage ratio buffer requirement – as a proportion (ratio) of the LRE, broken down in terms of the composition of the requirement. e. The expected level and quality of the P2G and P2G-LR in accordance with the process and criteria specified in section 7.6, where their determination results in a positive value, including: i. all applicable own funds ratios affected by P2G (CET1, T1 and total own funds) and leverage ratio requirement affected by P2G-LR and that own funds held for the purposes of P2G cannot be used to meet any of the elements of OCR and that P2G-LR cannot be used to meet any of the elements of OLRR; ii. the relevant time limits for its establishment; iii. the institution-specific justification for setting the guidance and the main elements of the methodology used; iv. the potential supervisory reaction to situations where P2G and P2G-LR are not met. f. a statement on the liquidity held and any specific liquidity requirements set by the competent authority other than those laid down in Article 4(2) Commission Delegated Regulation 2015/61 and 428b(2) of Regulation No 575/2013, including the institutionspecific reasons for these requirements; g. if applicable, a statement on other supervisory measures, whether qualitative or quantitative, including any early intervention measures that the competent authority intends to take.
9.4. Supervisory reaction to a situation where TSCR or OCR is not met
449. TSCR as determined in accordance with these guidelines and communicated in the SREP assessment is a legally binding requirement that institutions have to meet at all times, including in stressed conditions. If TSCR is no longer met, the competent authorities should consider additional intervention powers in accordance with Directives 2013/36/EU and 2014/59/EU, including withdrawal of authorisation in accordance with Article 18(d) of Directive 2013/36/EU, application of early intervention measures in accordance with Article 27 of Directive 2014/59/EU, determination that an institution is failing or likely to fail in accordance with Article 32(4)4a of Directive 2014/59/EU and relevant Guidelines and resolution actions in accordance with that Directive. When exercising those powers, competent authorities should consider whether measures are proportionate to the circumstances and their judgement on how the situation is likely to develop.
450. Competent authorities should also monitor whether the institutions meet the OCR. Where necessary, competent authorities should take measures to ensure that institutions comply with requirements set out in Articles 141 to 142 of Directive 2013/36/EU.
9.5. Supervisory reaction to a situation where P2G is not met
451. Competent authorities should monitor whether the amount of own funds expected in accordance with P2G is established and maintained by the institution over time. When the institution’s own funds drop, or are likely to drop, below the level determined by P2G, the competent authority should expect the institution to notify it and prepare a revised capital plan. In its notification, the institution should explain what adverse consequences are likely to force it to do so and what actions are envisaged for the eventual restoration of compliance with P2G as part of an enhanced supervisory dialogue.
452. There are generally three situations to be considered by a competent authority in which an institution could fail to meet its P2G: a. Where the level of own funds falls below the level of P2G (while remaining above OCR) in institution-specific or external circumstances in which risks that P2G was aimed at covering have materialised, the competent authority may allow the institution to temporarily operate below the level of P2G, provided that the revised capital plan is considered credible in accordance with the criteria set out in section 7.7. The competent authority may also consider adjusting the level of P2G where appropriate; b. Where the level of own funds falls below the level of P2G (while remaining above the OCR) in institution-specific or external circumstances as a result of the materialisation of risks that P2G was not aimed at covering, competent authorities should expect the institution to increase the level of own funds to the level of P2G within an appropriate timeline; c. Where the institution disregards P2G, does not incorporate it into its risk management framework or does not establish own funds to meet P2G within the relevant time limits set out by the competent authority, this may lead to competent authorities applying additional supervisory measures as set out in table 16. Where the permission to operate below the level of P2G as referred to in point (a) has not been granted and the institution’s own funds are repeatedly below the level of P2G, the competent authority should impose P2R in accordance with Title 7.
453. Notwithstanding particular supervisory responses in accordance with the previous paragraph, competent authorities may also consider the application of the capital and additional supervisory measures set out in Title 7, where these are deemed more appropriate to address the reasons for the own funds falling below the level determined by P2G.
9.6. Interaction between supervisory, early intervention measures and resolution authorities’ assessment
454. In addition to the supervisory measures, competent authorities may apply early intervention measures as specified in Article 27 of Directive 2014/59/EU, which are intended to supplement the set of supervisory measures specified in Articles 104 and 105 of Directive 2013/36/EU.
455. Competent authorities should apply early intervention measures without prejudice to any other supervisory measures and, when applying early intervention measures, should choose the most appropriate measure(s) to ensure a response that is proportionate to the particular circumstances.
456. When setting supervisory or early intervention measures, competent authorities should, in addition to considering the escalation framework set out in Title 2, also take into account the results of the resolvability assessment conducted by the resolution authority, including the related work programme, with a view to ensuring consistency in supervisory actions.
9.7. Interaction between supervisory and macroprudential measures
457. Where an institution is subject to macroprudential measures and the SREP assessment determines that these macroprudential measures do not adequately address the institutionspecific risk profile or deficiencies present in the institution (i.e. the institution is exposed to or poses a higher level of risk than the level targeted by the macroprudential measure, or the deficiencies identified are more material than those targeted by the measure), competent authorities should consider supplementing the macroprudential measures with additional institution-specific measures.
9.8. Interaction between supervisory and AML/CFT measures
458. When applying supervisory measures to address prudential deficiencies related to ML/TF risk, competent authorities should engage with AML/CFT supervisors so that the underlying deficiencies/vulnerabilities are adequately addressed by the appropriate measures within the respective remit of AML/CFT supervisors and competent authorities from their respective perspectives .
459. Where competent authorities in the course of exercising their supervisory activities have reasonable indications of deficiencies in the institution’s systems and controls framework or the internal governance framework that are related to AML/CFT or reasonable grounds to suspect that the institution has increased exposure to ML/TF risks, they should: a. notify the AML/CFT supervisor of these deficiencies and risks as soon as they are identified and liaise with them in line with the AML/CFT Cooperation Guidelines; b. assess the impact that such deficiencies and risks may have on the prudential situation of the institution; c. liaise with AML/CFT supervisors and in line with the respective authorities’ mandates and functions, consider the most appropriate prudential supervisory measures to address these deficiencies and risks in addition to any measures taken by the AML/CFT supervisors.
460. Where the competent authorities are notified or become aware of supervisory measures or sanctions planned or imposed by the AML/CFT supervisors, they should consider whether and how the potential prudential implications of the weaknesses and failures identified by the AML/CFT supervisors need to be mitigated.
10. Title 10. Application of the SREP to cross-border groups
461. This title addresses the application of the SREP procedures and methodology as specified in these guidelines in relation to cross-border groups and their entities. It also provides links with the joint assessment and decision process to be carried out pursuant to Article 113 of Directive 2013/36/EU and the Commission Implementing Regulation (EU) No 710/2014.
462. In the SREP, competent authorities should also consider the potential ML/TF risks and risks of non-implementation and evasion of targeted financial sanctions, taking into account input received from the AML/CFT competent authority of the Member State where a parent undertaking is established as well as AML/CFT supervisors responsible for the AML/CFT supervision of the group’s establishments in different jurisdictions, in particular the assessments of ML/TF risks, material weaknesses and breaches of AML/CFT legislation that are linked to the cross-border banking group structure.
463. When assessing prudential implications of ML/TF risks and risks of non-implementation and evasion of targeted financial sanctions in the SREP for a cross-border group, competent authorities should leverage the information obtained through bilateral engagements with relevant AML/CFT competent authorities in accordance with the AML/CFT Cooperation Guidelines and through their participation in AML/CFT colleges and prudential colleges.
10.1. Application of the SREP to cross-border groups
464. When applying the SREP and these guidelines to cross-border groups, competent authorities should assess the viability of the group as a whole, as well as its individual entities. Consolidating supervisors should perform the initial assessment of the parent undertaking and the group of institutions on a consolidated level, while the other competent authorities should perform the initial assessment of the entities under their supervision (individual, or subconsolidated, where relevant).
465. When these guidelines are applied to the subsidiaries of a cross-border group, competent authorities for subsidiaries should, when performing their initial assessment, primarily consider institutions on an individual basis, as they would with a standalone institution. The findings from such initial assessments, where relevant, should also include the identification of key vulnerabilities in the cross-border or group context, and reflect strengths and mitigating factors related to the entity being part of the group.
466. The results of any such initial assessment of the SREP elements, including, if identified, views on key dependencies on the parent/group, should serve as an input into the joint assessment and decision process pursuant to the requirements of Article 113 of Directive 2013/36/EU. These results should therefore be discussed by the competent authorities within the framework of the colleges of supervisors established pursuant to Article 116 of Directive 2013/36/EU.
467. In accordance with Article 3 of the Commission Implementing Regulation (EU) No 710/2014, prior to the start of the joint decision process the consolidating supervisor and the relevant competent authorities need to agree on a joint decision timetable setting out steps to be followed in the process and adhere to the agreed timetable throughout the process.
468. Following the discussions within the colleges of supervisors and the outcomes of the joint assessment process, competent authorities should finalise their respective SREP assessments, making the necessary adjustments based on the outcomes of the college discussions.
469. Where a competent authority’s assessment revealed specific deficiencies related to intragroup positions negatively affecting the overall viability of the entity on an individual basis, competent authorities should, within the colleges of supervisors, discuss whether the final assessment of an entity should be changed considering the overall group dimension, including the consolidated group business model, strategy and the existence and specific features of intra-group financial support arrangements.
470. Competent authorities should discuss and coordinate the following within the colleges of supervisors: a. planning, including frequency, and timelines for performing the assessment of various SREP elements for the consolidated group and its entities to facilitate preparation of the group risk and liquidity risk reports required for the joint decisions as specified in Article 113 of Directive 2013/36/EU and in Article 3 of the Commission Implementing Regulation (EU) No 710/2014 taking into account the proportionality and supervisory engagement set out in Title 2; b. details of the application of benchmarks used for the assessment of SREP elements; c. approach to assessing and scoring subcategories of risks individually, where such subcategories have been identified as material; d. inputs required from the institution at consolidated and entity level for conducting the assessment of SREP elements, including those from the ICAAP and ILAAP; e. outcomes of the assessment, including the SREP scores assigned to various elements, and the overall SREP assessment and overall SREP score at consolidated and entity level. When discussing the assessment of individual risks to capital and liquidity, competent authorities should focus on the risks that are identified as material for the respective entities; f. cross-border prudential implications of ML/TF risks, risks of non-implementation and evasion of targeted financial sanctions and concerns; and g. planned supervisory and early intervention measures, if relevant.
471. When preparing the summary of the overall SREP assessment for the cross-border group and its entities, competent authorities should structure it in a way that will facilitate filling in the templates for the SREP report, group risk report, liquidity risk assessment and group liquidity risk assessment report templates required for the joint decision in accordance with Article 113 of Directive 2013/36/EU as specified in the Commission Implementing Regulation (EU) No 710/2014.
10.2. SREP capital assessment and institution-specific prudential requirements
472. The determination of capital adequacy, and related requirements and guidance in accordance with the process described in Title 7 for cross-border groups is part of the competent authorities’ joint decision process pursuant to Article 113 of Directive 2013/36/EU.
473. For parent or subsidiary institutions of a cross-border group, the application of P2R and P2R- LR pursuant to Article 104(1)(a) of Directive 2013/36/EU should be carried out in accordance with the joint decision process provided for in Article 113(1)(a) of that Directive.
474. In the context of discussions on the adequacy of the level of own funds and determining P2R and P2R-LR, competent authorities should consider: a. the assessment of the materiality of risks and deficiencies identified at both consolidated and individual entity level (i.e. which risks are material to the group as a whole and which are material to just one entity) and the level of own funds required to cover such risks; b. where deficiencies identified are common across all entities (e.g. same governance deficiencies present in all entities, or deficiencies in the models used across several entities), coordinating the assessment and supervisory response, and in particular, deciding whether measures should be imposed at a consolidated level or proportionally at entity level for the entities where common deficiencies are present; c. outcomes of ICAAP assessments and views on the reliability of ICAAP calculations and their possible use as an input in determining P2R; d. outcomes of the supervisory benchmark calculations used to determine P2R for all entities within the group and at a consolidated level; e. P2R to be imposed on entities and at a consolidated level to ensure there is consistency of final own funds requirements and whether there is a need for transferring own funds from consolidated to entity level.
475. To determine the TSCR as specified in Title 7, competent authorities should consider the same level of application as the joint decision requirements in accordance with Article 113(1)(a) of Directive 2013/36/EU. In particular, the TSCR and other capital measures, if applicable, should be set at consolidated and solo levels for entities operating in other Member States. For the sub-consolidated level, the TSCR and other capital measures should cover only the parent undertaking of the sub-consolidated group to avoid double counting of P2R considered by competent authorities for subsidiaries in other Member States.
476. If the outcome of the supervisory assessment of the risk of excessive leverage for the parent or subsidiary institutions of a cross-border group is that Pillar 2 requirements to address the risk of excessive leverage P2R-LR should be set, this should be carried out in accordance with the joint decision process provided for in Article 113(1)(a) of the CRD and should reflect the separate stack of own funds requirements based on the leverage ratio.
477. In the context of the discussions on the adequacy of the level of own funds to cover the risk of excessive leverage and determining P2R-LR, competent authorities should consider: a. aspects included in paragraph 3266; b. Pillar 2 requirements to cover the risk of excessive leverage imposed on entities and at a consolidated level to ensure there is consistency of final own funds requirements and whether there is a need for transferring own funds from consolidated to entity level.
478. All the relevant information regarding the determination of P2G and P2G-LR for parent or subsidiary institutions of a cross-border group should be shared among competent authorities, and their setting should be carried out in accordance with the joint decision process pursuant to Article 113(1)(c), of Directive 2013/36/EU. In particular, competent authorities should discuss the approach to establishing P2G and P2G-LR at solo level where no data from the supervisory stress tests are available at that level, or, where relevant, agree on the application of P2G and P2G-LR at consolidated level only. The P2G and P2G-LR should be duly reflected in the joint decision document prepared in accordance with Article 113 of Directive 2013/36/EU.
10.3. SREP liquidity assessment and institution-specific prudential requirements
479. The determination of measures to address any significant matters and material findings relating to liquidity supervision and to the need for institution-specific liquidity requirements should be conducted in accordance with the joint decision process pursuant to Article 113 of Directive 2013/36/EU.
480. For Article 113(1)(b) of Directive 2013/36/EU, competent authorities should consider ‘matters’ to be significant and/or ‘findings’ to be material at least where: a. specific quantitative liquidity requirements are proposed by competent authorities; and/or b. measures other than specific quantitative liquidity requirements are proposed by competent authorities and the score assigned to liquidity risk and/or funding risk adequacy is ‘3’ or ‘4’.
10.4. Application of other supervisory measures
481. Competent authorities responsible for the supervision of cross-border groups and their entities should discuss and coordinate, where possible, application of all supervisory and early intervention measures to the group and/or its material entities to ensure that the most appropriate measures are consistently applied to the identified vulnerabilities, taking into account the group dimension, including inter-dependencies and intra-group arrangements as discussed above.
482. Competent authorities responsible for the prudential supervision of entities of a cross-border group should – when imposing supervisory or administrative measures, including sanctions, on institutions for their failure to address deficiencies related to ML/TF risks adequately – liaise with the relevant AML/CFT supervisors in accordance with section 8 of the AML/CFT Cooperation Guidelines , and – in line with the respective authorities’ mandates and functions – consider the most appropriate prudential supervisory measures to address these deficiencies and risks in addition to any measures taken by the AML/CFT supervisors.
11. Title 11. Supervisory stress testing
11.1. Use of supervisory stress testing by competent authorities
483. Competent authorities should, also on the basis of Article 100 of Directive 2013/36/EU, use supervisory stress testing to facilitate the SREP and, in particular, the supervisory assessment of its key elements, as described in Titles 4 to 8. The integration of ESG factors into supervisory stress testing should be carried out in accordance with the Joint Guidelines on integrating ESG risks in supervisory stress tests, giving priority to environmental risks. In particular, supervisory stress testing should help competent authorities, where appropriate, with the following: a. the assessment of institutions’ individual risks to capital as referred to in Title 6, or risks to liquidity and funding as referred to in Title 8; b. the assessment of the reliability of institutions’ stress testing programmes, as well as the relevance, severity and plausibility of scenarios for institutions’ own stress tests used for ICAAP and ILAAP purposes. This may include challenging institutions’ main assumptions and risk drivers; c. the assessment of institutions’ ability to meet TSCR and OCR in the context of the assessment of capital adequacy, as specified in section 7.7. Depending on the coverage and type of supervisory stress test, this assessment may be limited only to some elements of TSCR covered by the design features of the supervisory stress testing (e.g. P2R for individual risk categories, if the stress test covers only such risk categories); d. the determination of P2G for institutions; e. the identification of possible vulnerabilities or weaknesses in institutions’ risk management and controls on individual risk areas; f. the identification of possible deficiencies in overall governance arrangements or institutionwide controls referred to in Title 5. In particular, if a competent authority identifies by means of supervisory stress testing, deficiencies in the institution’s own stress testing programmes or supporting risk data infrastructure, these should be taken into account in the assessment of the overall governance and risk management framework of that institution; g. the determination of specific quantitative liquidity requirements in the context of the assessment of liquidity adequacy, especially where a competent authority has not developed specific supervisory benchmarks for liquidity requirements. Certain elements of the liquidity supervisory stress tests should, where appropriate, be used as inputs when setting specific liquidity requirements for institutions as specified in section 8.6.
484. Furthermore, supervisory stress testing should help competent authorities to assess supervisory organisational procedures and to plan supervisory resources, considering also other relevant information, in particular for the more frequent and in-depth assessment of certain SREP elements in the case of non-Category 1 institutions, and for the purposes of determining the scope of the supervisory examination programme required by Article 99 of Directive 2013/36/EU.
485. Competent authorities should also, where appropriate, use supervisory stress testing outcomes to: a. support the analysis needed for the purposes of granting various permissions and authorisations required by Regulation (EU) No 575/2013 or Directive 2013/36/EU, for example in relation to qualifying holdings, mergers and acquisitions, and shares buy-backs; b. support a thematic analysis of the potential vulnerabilities of a group of institutions with similar risk profiles; c. support the analysis of the potential impacts of ESG factors on the institutions' business model on the basis of a medium to long-term scenario analysis carried out in accordance with the Joint Guidelines on integrating ESG risks in supervisory stress tests; d. motivate institutions to enhance their internal stress testing and risk management capabilities: in particular, a supervisory stress test with a bottom-up component could motivate institutions to further develop and improve their data aggregation, risk modelling and IT tools for stress testing and risk management purposes.
11.2. Key elements of supervisory stress testing
486. When deciding on the key elements of supervisory stress testing, competent authorities should consider, inter alia, the following: a. coverage, in terms of covering certain risk factors or multiple risk factors, certain individual portfolios or activities or sectors/geographies, all or several portfolios; b. design, in terms of the following: single-factor or simple multi-factor sensitivity analysis, solvency or liquidity stress testing, reverse stress testing or medium to long-term scenario analysis. Competent authorities should choose the design that is most appropriate for the objective pursued by the stress test; c. scope, in terms of covering the perimeter of cross-border groups, ensuring that all relevant group entities are taken into account; d. sample of institutions covered by stress tests: when planning supervisory stress testing, competent authorities should consider the appropriate sample for the purposes of the exercise, in particular when using supervisory stress testing for thematic assessments of certain business lines/models or impact studies/assessments; e. approach, namely top-down stress test, bottom-up stress test, combination of both, prescribing specific anchor scenarios for institutions.
487. When designing and conducting supervisory stress tests for SREP purposes, competent authorities should consider the outcomes of asset quality reviews (AQR), where available, appropriate and not already incorporated into institutions’ financial statements. Combining supervisory stress testing with AQRs can be considered useful in ensuring that the balance- sheet positions of the institutions covered by the supervisory stress tests are reported accurately with improved and comparable starting points across participating institutions.
11.3. Organisational and governance arrangements within competent authorities
488. Competent authorities should establish an effective programme for supervisory stress testing. This programme should be supported by appropriate organisation, governance and IT arrangements ensuring that supervisory stress tests can be conducted with appropriate frequency. The supervisory stress testing programme should support the effective implementation of the supervisory examination programme for individual institutions. The programme should also reflect how the competent authority takes decisions regarding the choice of forms of supervisory stress testing in close connection with the objectives of each exercise.
489. The governance, organisation and IT arrangements supporting the supervisory stress testing programme should include at least the following: a. sufficient human and material resources, data and IT infrastructure to design and conduct supervisory stress tests. In particular, the supervisory stress testing programme should be supported by adequate data and an appropriate methodological approach covering all aspects, including scenarios and assumptions (e.g. templates, guidance, documentation), and ensuring both flexibility and appropriate levels of quality and controls; b. a quality assurance process covering stress testing design, development and execution, and the comparability of results across institutions; c. the integration of supervisory stress testing into other relevant supervisory processes. Hence, when required and subject to any legal constraints, the organisation should support the internal sharing of information and utilisation of all aspects of the stress testing programme.
490. As part of governance arrangements, competent authorities should ensure that the supervisory stress testing programme is reviewed regularly, both qualitatively and quantitatively, to ensure that its continued adequacy.
491. Competent authorities should ensure that they have processes and arrangements in place for an effective dialogue with institutions regarding supervisory stress tests and their outcomes. This dialogue should reflect the intended objectives, be established in particular but not exclusively when supervisory stress tests are run for the purposes of the assessment of institutions’ overall capital adequacy, and be organised within the more general context of the SREP assessments as set out in these guidelines. For the purposes of such a dialogue both at the technical and managerial level, where relevant, the competent authorities should ensure that: a. adequate, sufficiently detailed and accurate explanation and guidance is provided to institutions on the application of the methodologies and assumptions used in a bottom-up stress test; b. adequate, sufficiently detailed and accurate instructions are given to institutions with regard to the supporting information required by them to be submitted to competent authorities along with the results of the stress tests; c. explanation is provided to institutions following discussions, where relevant, of the outcomes of supervisory stress tests that lead to the application of supervisory measures. This should be considered by competent authorities in particular in the context of systemwide stress tests that trigger supervisory measures.
492. When applying supervisory stress testing to cross-border groups, competent authorities should exchange information and, where feasible, appropriately discuss the process within the colleges of supervisors. In particular, competent authorities should ensure that relevant details on the methodologies, scenarios and major assumptions, as well as the results of supervisory stress tests, especially those aimed at assessing capital or liquidity adequacy, are made available and discussed.
493. Competent authorities should also identify what information regarding supervisory stress tests and their outcomes may be publicly disclosed, taking into account the intended purposes of the supervisory stress tests. When deciding on the public disclosure of the results or methodologies of supervisory stress tests, competent authorities should consider their own role in the exercise and the approach chosen and also consider the extent of their own analysis that will accompany published results.
12. Title 12. Assessing third-country branches
494. This title addresses the application of the SREP procedures and methodology as specified in these guidelines in relation to third-country branches (TCBs) as defined in Article 47(3) of Directive 2013/36/EU. It also addresses the application by competent authorities of supervisory measures to address deficiencies identified through the SREP assessment of TCBs.
495. When performing the SREP assessment for TCBs, competent authorities should evaluate inter alia the compliance of the institution with the legal acts published separately on the EBA website as referred to in paragraph 12.
496. The SREP assessment of a TCB should include an assessment of the branch’s business model, internal governance arrangements and controls, capital endowment and liquidity resources and booking arrangements (the SREP elements for TCBs). In line with the supervisory review and evaluation process for credit institutions (the SREP for credit institutions), the assessment of these areas should be conducted on a continuous basis and accompanied by ongoing monitoring of key indicators.
497. The review should be conducted with a level of frequency and intensity that is proportionate to the TCB’s classification as class 1 or class 2 in accordance with Article 48a of Directive 2013/36/EU and the nature, scale, and complexity of the TCBs’ activities. For class 1 TCBs, competent authorities should apply at a minimum the level of supervisory engagement for category 3 institutions as set out in table 1 of section 2.4. For class 2 TCBs, competent authorities should apply at a minimum the level of supervisory engagement for category 4 institutions as set out in table 1 of section 2.4.
498. In addition to assessing the core SREP elements for TCBs, competent authorities should ensure they understand the branch’s other material risks and how these are mitigated. This includes any significant exposures to credit risk, market risk, operational risk and IRRBB. Competent authorities may deem it appropriate to perform a more in-depth assessment of one or more of these areas based on the relevance and materiality of the risk for the TCB. In such cases, competent authorities should use the guidance in the relevant corresponding titles of these Guidelines as the basis for the assessment and seek to apply the principles contained in a manner proportionate to the TCB.
499. Where competent authorities exercise their right in accordance with Article 48a of Directive 2013/36/EU to subject the TCB to requirements for credit institutions in accordance with the Directive, effectively treating the TCB as a subsidiary, competent authorities should apply the SREP for credit institutions to the TCB in question and refer to the relevant titles of these Guidelines (Titles 2, 3, 4, 5, 6, 7, 8, 9, 10, and 11, as well as section 12.1.2 of this section, on business model analysis).
500. Competent authorities should use the findings from the assessment of the individual SREP elements for TCBs to score each area. The competent authority should use this analysis to form an overall assessment and score for the TCB and use the considerations in table 21 as a guide in this regard. The overall assessment and score should also take account of the assessment and scoring of the TCB’s other material risks (where applicable). Based on the overall SREP assessment and the assessment of the individual SREP elements for TCBs, competent authorities should take supervisory measures as specified in section 12.2 of this title to address any deficiencies identified.
12.1. Application of SREP to third-country branches
12.1.1. General considerations
501. The SREP assessment should focus on the TCB’s material risks and how these are dependent on the business, and the risk profile of the rest of the group and how they are managed. Recognising the status of the branch and its reliance on the third-country parent, the assessment should also focus on whether the branch has sufficient independence in its governance and risk management to act in the best interests of the branch, safeguarding its safety, soundness and viability, and its capacity to fulfil its commitment to clients and counterparties within the Member State where they have been authorised to carry out business.
502. To inform the assessment, competent authorities should take into account the results of the independent third-party assessment of the branch and the independent opinion on compliance with booking requirements mandated by Articles 48g(8) and 48h(3) of Directive 2013/36/EU, respectively. They should also cooperate with the authority responsible for supervision of the head undertaking (‘the home authority’) in accordance with administrative or other arrangements in accordance with Article 48c(2) of Directive 2013/36/EU and take into account the results of the home authority’s supervisory assessments of the branch where available.
503. Competent authorities should ensure that the scope of the assessment contains measures to identify TCBs of systemic importance or posing financial stability risks. Further, the assessment should enable identification of TCBs for which authorisation in accordance with Title III, Chapter 1 of Directive 2013/36/EU (as a subsidiary) may be appropriate. Competent authorities should refer to Article 48i for criteria to consider in this regard.
504. Where the review of the TCB’s governance, business model, or activities, gives competent authorities reasonable ground to suspect that, in connection with the TCB, money laundering or terrorist financing is being or has been committed or attempted, or that there is increased risk thereof, the competent authority is required to immediately notify the EBA and the TCB’s AML/CFT supervisor in accordance with Article 48n(4) of Directive 2013/36/EU.
12.1.2. Business model analysis
505. Competent authorities should analyse the TCB’s business model and strategy to understand the key drivers of its risks. They should use the guidance provided in Title 4 as the basis for the assessment and seek to apply the principles contained in a manner proportionate to the TCB. Competent authorities should verify that the strategy for the third-country branch and a separate assessment of the associated risks is adequately documented along with evidence of its review and scrutiny by branch management.
506. Competent authorities should pay specific attention to the outreach of the TCB activities, to assess whether it complies with the territorial scope of the authorisation granted by the competent authority where the TCB is established. Attention should also be paid to any crossborder business activity carried out upon reverse solicitation.
507. Competent authorities should consider how the head undertaking’s strategic priorities for the TCB impact its risk profile. They should pay attention to any earnings or strategic targets set for the TCB branch and whether these are supported by the TCB’s resourcing and risk management capabilities. They should also assess the nature of the services and activities offered by the TCB and how, if at all, these diverge from the offering of the wider group and whether this results in any increased risks or go beyond the scope of services and activities authorised to be carried out by the TCB, which cannot be more extensive than that of the direct head undertaking in the third country.
12.1.3. Assessment of internal governance arrangements and controls
508. Competent authorities should assess the adequacy of the TCB’s governance arrangements using Title 5 and section 7 of the EBA Guidelines on Internal Governance in accordance with Directive 2013/36/EU as a guide as well as the TCB-specific considerations below. The assessment should include the overall framework, risk culture and risk conduct, remuneration policies and practices, and the internal control and risk management framework including the management of ICT risks and third-party risks.
509. In conducting the assessment of internal governance, competent authorities should consider whether the TCB maintains sufficient substance in the Member State in accordance with the requirements in paragraph 90(g) of the EBA Guidelines on internal governance.
Organisational framework
510. Competent authorities should assess whether the persons directing the TCB: a. have sufficient understanding of the activities and risks of the branch and knowledge of the local market, as well as of EU and national regulations of the Member State; b. have sufficient authority, stature, and independence, taking into account the extent they are empowered to contribute to decisions by the head undertaking affecting the branch; c. spend sufficient time within its Member State and in the premises of the branch to effectively fulfil their role.
511. Where the TCB branch has established a management committee, competent authorities should review its role in ensuring adequate governance. In the absence of such body, competent authorities should review whether an appropriate and proportionate alternative framework for senior management oversight of the TCB’s activities and risks has been implemented.
Relation with the head undertaking
512. Competent authorities should assess the TCB’s relation with the head undertaking, including whether the branch is integrated into the group governance and risk management framework effectively. They should take into account whether: a. the branch’s reporting to the head undertaking provides sufficient visibility of the branch’s material risks; d. the risk framework applied to the TCB adequately addresses EU financial services regulations.
513. Where the TCB engages in back-to-back or intragroup operations, competent authorities should verify that the branch has an appropriate framework for managing its counterparty credit risk.
Internal control framework and third-party risk management
514. Competent authorities should assess whether the TCB has robust internal control functions. For class 1 TCBs (and class 2 TCBs where applicable in accordance with Article 48g(3) of Directive 2013/36/EU), competent authorities should assess whether suitable heads of internal control functions have been appointed who are independent and have sufficient capacity to fulfil the function as provided for in Article 76(6) of Directive 2013/36/EU.
515. Competent authorities should assess whether the TCB conducts appropriate due diligence and ongoing oversight of functions provided by third-party service providers. They should verify that third-party arrangements, including intragroup arrangements, are governed by documented agreements and that the TCB has access to all information required to exercise its monitoring obligations, including when subcontractors are used. Competent authorities should review the TCB’s management of its ICT risks, including whether the TCB maintains an appropriate register of its third-party service providers including when subcontractors performing critical or important function are used.
12.1.4. Assessment of capital endowment and liquidity resources
516. Competent authorities should assess: a. whether the TCB branch meets the minimum capital endowment requirement as specified in Article 48e(1) of Directive 2013/36/EU; b. whether the concentration of the capital endowment on a particular form of instrument or on instruments from a particular geographical location, or the currency inconsistency of the capital endowment instruments with the TCB’s liabilities, especially with deposits, would lead to heightened volatility of the value of the instruments and to the potential breach of the minimum requirement; c. whether the capital endowment is held in an eligible escrow account in the Member State where the third-country branch has been authorised and the capital endowment instruments meet the criteria specified in Article 48e(2) of Directive 2013/36/EU and the conditions set in the EBA Guidelines on instruments available for third-country branches for unrestricted and immediate use to cover risks or losses .
517. Competent authorities should assess whether the institution holds sufficient liquid and unencumbered assets to mitigate its liquidity risks and in particular that the branch’s liquid assets are sufficient for cover liquidity outflows over a minimum of 30 days in line with Article 48f(1) of Directive 2013/36/EU. For Class 1 TCBs, the assessment should cover the branch’s compliance with the liquidity coverage requirement as described in the same Article.
518. In conducting the capital endowment and liquidity assessment, competent authorities should consider whether the TCB maintains documentation that is adequate for a prompt and accurate review of its compliance with the minimum capital endowment and liquidity requirement.
519. Competent authorities should assess: a. the quality of the engagement between the TCB and head undertaking on capital and liquidity management decisions – including how the branch is covered in group capital and liquidity planning processes, monitoring and stress testing and the existence of appropriate escalation mechanisms for the branch to promptly notify the head undertaking of potential or actual capital or liquidity issues; b. whether the cross-border intra-group funding arrangements are within the limits of the exception allowed in accordance with Article 48c(4) (d) of Directive 2013/36/EU and do not disguise cross-border business activities in breach of the territorial scope of the authorisation – for instance where the intragroup funding provided to a TCB established in another Member State in exchange for a (total or partial) share of the economic risks and returns of a specific asset.
12.1.5. Assessment of booking arrangements
520. Competent authorities should assess whether the TCB has an adequate framework for managing and recording assets and liabilities booked or originated in the Member State, including off-balance sheet items. Competent authorities shall verify that the TCB’s framework includes a registry book that adequately documents all assets and liabilities booked or originated by the branch in line with Regulatory Technical Standards in accordance with Article 48h(4) of Directive 2013/36/EU and a policy in compliance with Article 48h of Directive 2013/36/EU.
521. Competent authorities should assess whether the activities performed by the TCB, its assets and liabilities booked or originated, or other hedging arrangements identified in the registry book are in line with the TCB’s policy on booking arrangements and its business strategy.
522. Where the TCB engages in back-to-back booking arrangements, competent authorities should assess whether the TCB appropriately manages the risks of back-to-back and remote booking arrangements respectively, including counterparty credit risk, CVA risk, and settlement risk.
523. Competent authorities should assess whether the TCB manages assets and liabilities autonomously. They should consider whether the TCB demonstrates independence in accepting new activities, including through the enforcement of a risk appetite agreed by the branch management. They should consider whether the TCB has sufficient controls and reporting to independently understand and act upon the risks of actual or prospective activities. They should take into account whether the TCB’s framework adequately addresses both the prudential risks of the booked activities in so far as they impact the branch’s capital and liquidity risk profile, and AML/CFT risks.
524. Where the TCB originates assets and liabilities for other branches or subsidiaries of the same group, competent authorities should assess whether any particular risks arise from these arrangements including operational vulnerabilities and legal constraints.
12.2. Summary of findings, scoring and supervisory measures
525. Following the above assessment, competent authorities should form an overall risk on the key risks of the TCB. This view should be reflected in an annual summary of the overall SREP assessment, accompanied by a viability score based on the considerations specified in table 21. The annual summary should also include any supervisory findings made over the course of the previous 12 months.
526. Competent authorities may, on the basis of the vulnerabilities and deficiencies identified in the assessment of the SREP elements for TCBs, impose supervisory measures requiring the TCB to: a. hold an amount of capital endowment in excess of the minimum requirements laid down in Article 48e of Directive 2013/36/EU; b. restrict the form of instruments allowed in accordance with the EBA Guidelines on instruments available for third-country branches for unrestricted and immediate use to cover risks or losses in accordance with Article 48e(2)(c) of Directive 2013/36/EU, the instruments from a particular jurisdiction or the instruments denominated in a particular currency; c. introduce operational conditions additional to those in accordance with the EBA Guidelines on instruments available for third-country branches for unrestricted and immediate use to cover risks or losses in accordance with Article 48e(2)(c) of Directive 2013/36/EU; d. meet other specific liquidity requirements in addition to the requirements laid down in Article 48f of Directive 2013/36/EU; e. reinforce their governance, risk management or booking arrangements; f. restrict or limit the scope of their business or of the activities they conduct, as well as the counterparties to those activities; g. reduce the risk inherent in their activities, products and systems, including outsourced activities, and stop engaging in such activities or offering such products; h. comply with additional reporting requirements in accordance with Article 48k(3) or increase the frequency of the regular reporting; i. make public disclosures; j. On a case-by-case basis and having had regard to the criteria in Article 48i(1) of Directive 2013/36/EU, competent authorities may require the TCB to apply for authorisation as a subsidiary in accordance with Title III, Chapter 1 of the Directive. This includes where the competent authority assesses that the TCB is of systemic importance or poses significant financial stability risks in line with Article 48j of Directive 2013/36/EU.
527. For TCBs of systemic importance, competent authorities may also consider: a) Requiring the TCB to structure its assets or activities in such a manner that it ceases to qualify as of systemic importance or that it ceases to pose an undue risk to the financial stability of the Union or the Member State where it is established; b) imposing additional prudential – including governance – requirements on the TCB.
528. Competent authorities should communicate the outcomes of the SREP assessment to the management of the third-country branch and inform them of any action the third-country branch has to take to comply with supervisory measures applied based on the findings. Competent authorities should communicate the outcomes of the SREP assessment including any supervisory measures applied to the authority responsible for the supervision of the head undertaking in accordance with the administrative agreements or other arrangements concluded in accordance with Article 48c(2) of Directive 2013/36/EU.
Annex I – Credit risk sub-categories
The table below presents a non-exhaustive list of sub-categories for credit risk that competent authorities should consider when relevant.
Credit risk sub- Legal references related to the Legal references/Definitions Assessment areas categories assessment areas
Credit risk sub- Legal references related to the Legal references/Definitions Assessment areas categories assessment areas
Credit risk sub- Legal references related to the Legal references/Definitions Assessment areas categories assessment areas
Credit risk sub- Legal references related to the Legal references/Definitions Assessment areas categories assessment areas
Annex II – Market risk sub-categories
The table below presents a non-exhaustive list of sub-categories for market risk that competent authorities should consider when relevant.
Market risk sub- 63
Legal references/Definitions categories (level 1)
The risk of losses arising from changes in the market value of debt instruments due to a change in the level of interest rates unrelated to any specific attributes of those individual debt instruments.
Relevant legal references for capital treatment: > Pre-Fundamental Review of the Trading Book (FRTB) – internal models Regulation (EU) 575/2013, Part Three, Title IV, Chapter 5 – Article 362
General interest
> Pre-FRTB – Standardised Approach /Post-FRTB – Simplified Standardised Approach
rate risk
Regulation (EU) 575/2013, Part Three, Title IV, Chapter 2, Section 2, Subsection 2 – Articles 339-340 (general risk of debt instruments)
(trading book)
> Post-FRTB – Alternative Standardised Approach
Regulation (EU) 575/2013, Part Three, Title IV, Chapter 1a, Section 2 – Articles 325d-325k (sensitivity-based method, general interest
rate risk) > Post-FRTB – Alternative internal model approach
Regulation (EU) 575/2013, Part Three, Title IV, Chapter 1b – Articles 325az-325bp (expected shortfall /Stress Scenario Risk Measure
(SSRM) component)
The risk arising from changes in the market value of debt financial instruments due to fluctuations in their credit spread (please refer Credit spread risk to ‘Definitions’, Title 1). (trading book) - Capital treatment differentiated by type of instrument/portfolio:
1) Credit spread risk of non-securitisations
Market risk sub- 63
Legal references/Definitions categories (level 1)
2) Credit spread risk of securitisations (outside the alternative correlation trading portfolio (ACTP)) 3) Credit spread risk of securitisations included in the ACTP - Also covers sovereign risk (i.e. risk of losses due to decreasing market values of sovereign exposures)
Relevant legal references for capital treatment > Pre-FRTB – internal models
Regulation (EU) 575/2013, Part Three, Title IV, Chapter 5 CRR – Article 362 (Value at Risk (VaR) - component; and additional ACTP component (‘comprehensive risk measure’) for positions in the ACTP) > Pre-FRTB – Standardised Approach /Post-FRTB - Simplified Standardised Approach Regulation (EU) 575/2013, Part Three, Title IV, Chapter 2, Section 2, Subsection 1 – Articles 335-338 (specific risk of debt instruments)
> Post-FRTB – Alternative Standardised Approach
Regulation (EU) 575/2013, Part Three, Title IV, Chapter 1a, Section 2 – Articles 325d-325k (sensitivity-based method, credit spread risk (CSR) non-securitisation, CSR securitisation non-ACTP, CSR securitisation-ACTP)
> Post-FRTB – Alternative internal model approach
Regulation (EU) 575/2013, Part Three, Title IV, Chapter 1b – Articles 325az-325bp (expected shortfall/SSRM component) The risk of a change in the market value of an instrument due to a broad equity-market movement or due to factors related to the issuer of the instrument or, in the case of a derivative, the issuer of the underlying instrument.
Relevant legal references for capital treatment
Equity risk
> Pre-FRTB – internal models
(trading book)
Regulation (EU) 575/2013, Part Three, Title IV, Chapter 5 – Article 362 CRR > Pre-FRTB – Standardised Approach /Post-FRTB – Simplified Standardised Approach Regulation (EU) 575/2013, Part Three, Title IV, Chapter 2, Section 3 – Articles 341-344 (general risk of equity instruments + specific risk
of equity instruments)
Market risk sub- 63
Legal references/Definitions categories (level 1)
> Post-FRTB – Alternative Standardised Approach
Regulation (EU) 575/2013, Part Three, Title IV, Chapter 1a, Section 2 – Articles 325d-325k (sensitivity-based method, risk class equity
risk) > Post-FRTB – Alternative internal model approach
Regulation (EU) 575/2013, Part Three, Title IV, Chapter 1b – Articles 325az-325bp (expected shortfall/SSRM component) The risk of loss on financial instruments due to the deterioration of the creditworthiness of the issuer or of the issuer of reference assets or underlying assets. This excludes default risk. Under FRTB this risk is treated as part of credit spread risk.
Relevant legal references for capital treatment
Migration risk > Pre-FRTB – internal models Regulation (EU) 575/2013, Part Three, Title IV, Chapter 5, Section 4 – Articles 372-376
> Post-FRTB – Alternative Standardised Approach
Regulation (EU) 575/2013, Part Three, Title IV, Chapter 1a, Section 2 – Articles 325d-325k
> Post-FRTB – Alternative internal model approach
Regulation (EU) 575/2013, Part Three, Title IV, Chapter 1b – Articles 325az-325bp The risk of loss on financial instruments due to the default of the issuers of those financial instruments or of the issuers of reference or of underlying assets. Also covers sovereign risk, i.e. risk of losses due to the default of sovereign exposures.
Default risk
Relevant legal references for capital treatment
(trading book) > Pre-FRTB – internal models Regulation (EU) 575/2013, Part Three, Title IV, Chapter 5 – Articles 372-376 (‘Incremental default risk charge’-component)
> Post-FRTB – Alternative Standardised Approach
Regulation (EU) 575/2013, Part Three, Title IV, Chapter 1a, Section 5 – Articles 325v-325ad
Market risk sub- 63
Legal references/Definitions categories (level 1)
> Post-FRTB – Alternative internal model approach
Regulation (EU) 575/2013, Part Three, Title IV, Chapter 1b – Articles 325az-325bp (default risk charge) Regulation (EU) 575/2013, Article 4(1), point (142) – includes, among others, translation risk and structural foreign exchange risk
Relevant legal references for capital treatment
I) Exemption for Structural Foreign Exchange positions (S-FX positions)
- Guidelines on S-FX (EBA/2020/09)
Foreign exchange
II) Treatment of positions other than S-FX positions
risk
> Pre-FRTB – internal models
(trading and
Regulation (EU) 575/2013, Part Three, Title IV, Chapter 5 – Articles 362-377
banking books)
> Pre-FRTB – Standardised Approach /Post-FRTB – Simplified Standardised Approach Regulation (EU) 575/2013, Part Three, Title IV, Chapter 3 – Articles 351-354
> Post-FRTB – Alternative Standardised Approach
Regulation (EU) 575/2013, Part Three, Title IV, Chapter 1a, Section 2 – Articles 325d-325k (sensitivity-based method, risk class foreign
exchange risk) > Post-FRTB – Alternative internal model approach
Regulation (EU) 575/2013, Part Three, Title IV, Chapter 1b Articles 325az-325bp (expected shortfall/SSRM component)
Commodities risk (trading and
Relevant legal references for capital treatment
banking books)
> Pre-FRTB – internal models
Market risk sub- 63
Legal references/Definitions categories (level 1)
Regulation (EU) 575/2013, Part Three, Title IV, Chapter 5 – Articles 362-377 > Pre-FRTB – Standardised Approach /Post-FRTB - Simplified Standardised Approach Regulation (EU) 575/2013, Part Three, Title IV, Chapter 4 – Articles 351-354
> Post-FRTB – Alternative Standardised Approach
Regulation (EU) 575/2013, Part Three, Title IV, Chapter 1a, Section 2 – Articles 325d-325k (sensitivity-based method, risk class
commodities risk) > Post-FRTB – Alternative internal model approach
Regulation (EU) 575/2013, Part Three, Title IV, Chapter 1b – Articles 325az-325bp (expected shortfall/SSRM component) Credit valuation Regulation (EU) 575/2013, Article 381
adjustment risk
(trading and banking books)
The risk of losses from revisions of or adjustments to the - Market price uncertainties RTS on Prudent Valuation
Valuation risk
accounting value of fair-valued assets and liabilities - Close-out costs (Regulation (EU) 2016/101)
(trading and non-
(Regulation (EU) 575/2013, Article 105 and Regulation (EU) - Valuation model risks
trading books)
2016/101) - Unearned credit spreads - Investing and funding costs - Concentrated positions - Future administrative cost
Market risk sub- 63
Legal references/Definitions categories (level 1)
- Early termination - Operational (valuation) risks
Regulation (EU) 575/2013, Article 325u and RTS on Residual Risk Add-on (Regulation (EU) 2022/2328) – comprises the broad categories of risks arising from instruments with exotic underlying and residual risk of instruments bearing other residual risks
Residual risk
Relevant legal references for capital treatment > Post-FRTB – Alternative Standardised Approach
Regulation (EU) 575/2013, Part Three, Title IV, Chapter 1a, Section 4 – Article 325u Market risk: Model Regulation (EU) 575/2013, Article 4(1), point (52b)
risk
- Delta risk (risk of changes of the value of a financial instrument due to a change in the value of the risk factor (first order effects)) Market risk: Risks - Vega risk (risk arising from changes of the volatility of the underlying of a non-linear instrument) by linearity - Curvature risk (including gamma risk) (risks not captured under delta and vega risk, including risk arising from second order effects of changes in the underlying and from other parameters of options) Market risk: The risk that the institution will incur market/liquidity losses stemming from a concentration either from exposures to a single risk Market liquidity factor or from exposures to multiple risk factors that are correlated, or from instruments with high liquidity horizons
and concentration risk
Market risk: Basis Risk of losses due to imperfect correlation in the value change of nominally offsetting instruments
risk
Annex III – Operational risk sub-categories
The table below presents a non-exhaustive list of sub-categories for operational risk that competent authorities should consider when relevant.
Operational risk sub- Operational risk sub- Legal references/Definitions Legal references/Definitions categories (level 1) categories (level 2)
Operational risk sub- Operational risk sub- Legal references/Definitions Legal references/Definitions categories (level 1) categories (level 2)
Annex IV – IRRBB sub-categories
The table below presents a non-exhaustive list of sub-categories for IRRBB that competent authorities should consider when relevant.
IRRBB sub- Legal references/Definitions IRRBB sub-categories (level 2) Legal references/Definitions categories (level 1)
Annex V – Transfer pricing risk measurement
P2R for transfer pricing risk should be determined by summing up the P2R corresponding to the risk linked to each transfer pricing arrangement (TPA) that is based on the transaction profitmethod (TPM) as referred to in paragraph 173 of these Guidelines. Other types of TPA, similarly transferring material losses to the EU entity, should be assessed in a similar way. P2R corresponding to a TPA belonging to the set TPM should be determined as follows: a) The institution should identify the portfolio whose profits and losses are used as a basis to determine the amount to be allocated to the institution in accordance with the TPA. b) On the basis of (i) empirical evidence and (ii) key-metrics included in the pricing arrangement as referred to in paragraph 1743, point (b), of these Guidelines, the institution should determine its marginal contribution ‘m’ to the key metrics used to determine the portion of profits and losses to be allocated across the entities taking part to the TPA. c) The institution should obtain the market risk capital requirements (C_MRPortfolio) relating to the portfolio identified in point (a). d) The P2R for the transfer pricing arrangement is m × C_MRPortfolio. This may be capped by the maximum loss that can be allocated to the institution in accordance with the TPA. An institution may be provided with C_MRPortfolio by an entity established outside of the Union with which there is the TPA. That entity may provide the capital requirements on the basis of the rules for market risk applicable in the jurisdiction where it is established. Where those third country provisions are based on a Pillar 1 capital framework that is not in line with the Pillar 1 market risk capital framework implemented in the EU in accordance with Regulation (EU) 575/2013, competent authorities should increase the requirement by a factor of 1.5. Competent authorities can lower or increase that multiplier to reflect the materiality of the differences in the market risk rules between the EU and the third country. Competent authorities may set the P2R of a transfer pricing arrangement to a lower value than the one obtained in accordance with the first paragraph of this Annex when all the below conditions are met: a. In the context of that TPA, the institution is assessed to hold and manage most of the market risk relating to the portfolio on which the transfer pricing arrangement is based; b. The booking model implies that the institution may allocate its trading book losses to other entities taking part to the transfer pricing arrangement; c. The institution provides sufficient evidence that, in light of its role as main contributor to the TPA in the sense of point (a), the capital requirements for market risk relating to the positions that are subject to the TPA already cover for potential losses resulting from the TPA.
FINAL REPORT ON THE REVISED SREP GUIDELINES
5. Accompanying documents
5.1. Cost-benefit analysis/impact assessment
Directive (EU) 2024/1619 amending Directive 2013/36/EU entered into force on 9 July 2024, and will become applicable on 11 January 2026, with certain exceptions, in particular with regard to third-country branches.
In this context, the EBA has undertaken a third revision of the Supervisory Review and Evaluation Process (SREP) Guidelines (GL) to ensure alignment with the changes introduced by the CRRIII/CRDVI. The revision reflects key considerations including: (i) the application of proportionality as a key driver of the revision to support risk-based supervision; (ii) considerations on operational resilience to enable a holistic assessment of institution’s ability to deliver critical or important functions in the event of disruptions; (iii) the inclusion of ESG risks to enable a more comprehensive and forward-looking supervisory approach; (iv) the treatment of market risk transfer pricing models to ensure that institutions are adequately capitalised for the risks they bear and to establish a level playing field; (v) considerations on the interaction between the revised Pillar 1 framework (including the output floor) and Pillar 2 to avoid double counting and ensure consistency in capital requirements; (vi) the inclusion of provisions for third-country branches to support the assessment of material risks to their operations; (vii) the introduction of a high-level supervisory escalation framework to promptly identify and address deficiencies in institutions; and (viii) the repeal of the stand-alone ICT SREP GL, with ICT risk assessments now integrated into the general SREP GL.
The updates aim to incorporate the relevant CRRIII/CRDVI provisions into the existing set of GL, which underpin the day-to-day activities of supervisory authorities and ensure a coherent, riskbased, and proportionate supervisory framework across the EU.
5.1.1. Policy objectives
The focus of the third revision of the SREP GL is on, inter alia, incorporating elements relating to proportionality, operational resilience, ESG risks, market risk transfer pricing models, interaction between Pillar 1 and Pillar 2 frameworks, third-country branches, supervisory effectiveness, and ICT risk assessments.
5.1.2. Baseline scenario
The SREP GL were first published in December 2014 and entered into force in January 2016. The first revision took place in 2017, with the updated GL applying from 2019. A second review was carried out in 2021 to align the GL with the regulatory developments since the last revision. This updated version came into force in January 2023. The revision reflected the changes introduced by
FINAL REPORT ON THE REVISED SREP GUIDELINES
Regulation (EU) 2019/876 amending the CRR and Directive (EU) 2019/878 amending the CRD, as well as the other relevant EBA GL and technical standards.
5.1.3. Options considered
In preparing these revised SREP GL, the EBA considered the following policy options during the drafting process to ensure alignment with the CRRIII/CRDVI provisions.
Proportionality
One of the key drivers for the revision of the SREP GL was to further clarify and improve the application of proportionality, which is already embedded in the existing SREP GL, in order to better support risk-based supervision. The revision of the proportionality provisions also took into account the recommendations of the peer review on the application of proportionality in the SREP and the relevant recommendations of the EBA’s Advisory Committee on Proportionality (ACP).
The revision focused primarily on two areas that are central to the application of proportionality in the SREP: the categorisation of institutions (Section 2.1.1) and the supervisory engagement model (Section 2.4).
The minimum supervisory engagement model has been revised to allow for a lighter assessment of SREP elements or risk areas that are considered immaterial or unchanged since the last assessment. In addition, competent authorities are given more flexibility in categorising institutions for SREP purposes — in particular for ‘large’ institutions in accordance with Regulation (EU) No 575/2013 that are not G-SIIs, given their high degree of heterogeneity. Flexibility has also been increased with regard to the frequency and granularity of SREP assessments. In this context, two policy options were considered.
Option 1: Retaining the minimum frequency for the assessment of all SREP elements for small and non-complex institutions while increasing flexibility with regard to the granularity of the
assessment
Under this option, competent authorities would retain the current minimum frequency for the assessment of all SREP elements for all categories of institutions, while at the same time being granted greater flexibility in adjusting the level of granularity of the assessment.
This approach would allow competent authorities to adjust the scope and depth of the SREP assessment to reflect the institution’s risk profile, the materiality of individual risks and SREP elements, and emerging risks. It allows for a lighter and more targeted assessment of risks that are considered immaterial and supports maintaining previous assessments and scores where no material changes have occurred, based on available supervisory information (e.g. monitoring indicators and reporting).
FINAL REPORT ON THE REVISED SREP GUIDELINES
The additional flexibility offered under Option 1 is considered sufficient to support a risk-based approach without requiring changes to the minimum frequency of assessments under the supervisory engagement model.
Option 2: Extending the minimum frequency for the assessment of all SREP elements for small and non-complex institutions while increasing flexibility with regard to the granularity of the
assessment
In addition to the flexibility regarding the granularity of the assessment described in Option 1, this option provides for an extension of the minimum frequency for the assessment of all SREP elements from three to five years for a subset of Category 4 institutions (i.e. small and non-complex institutions), provided they meet certain criteria: − a stable, low-risk profile; − stable financial metrics and healthy margins; − no concerns based on the quarterly monitoring of key risk indicators. This extension enables competent authorities to use their supervisory resources more efficiently, particularly in jurisdictions with a large number of small and non-complex institutions. The approach includes safeguards to ensure that: 1. the extended frequency applies only to institutions that meet the above criteria; 2. supervisory attention can be intensified if new risks emerge or other indicators change (in addition to the quarterly monitoring of key risk indicators); 3. the minimum level of dialogue with the institution’s management body and senior management is maintained at a risk-based frequency of at least every three years. This approach is consistent with a multi-year SREP strategy, where in-depth assessments of selected risks or risk factors are planned over a longer (multi-year) time horizon.
Option 2 is the preferred option as it supports a risk-based supervisory engagement model and enables a more targeted use of supervisory resources, in particular for competent authorities supervising a large number of small and non-complex institutions.
Operational resilience
Operational resilience has gained international prominence, particularly through the BCBS framework. Although its key components are already reflected in the EU regulatory framework and embedded in the existing SREP GL, it was considered appropriate to specifically introduce the concept of operational resilience. In this context, two policy options were considered.
Option 1: Introduction of a stand-alone module on operational resilience in the SREP GL
One option is to introduce a dedicated module within the SREP GL that focuses exclusively on operational resilience. This would improve the visibility of the supervisory assessment of an
FINAL REPORT ON THE REVISED SREP GUIDELINES
institution’s ability to maintain critical or important functions during disruptions, thereby increasing the attention paid to this area by both the competent authorities and the supervised institutions.
However, given the interdependence of operational risk and operational resilience, this approach would require strong interlinkages with existing SREP elements, in particular with the areas of internal governance and operational risk management. This could lead to overlaps in assessments and duplication of work, which would increase the complexity of the SREP and the burden on both the competent authorities and the supervised institutions.
Furthermore, this option would not be consistent with the simplification objective of the revised SREP GL or with the objective of more effective and efficient supervision. In addition, the current EU regulatory framework does not necessarily justify expanding the scope and complexity of the SREP solely for the purpose of operational resilience, particularly given the potential regulatory burden on institutions.
Option 2: Integrating operational resilience into existing SREP elements
Alternatively, operational resilience could be integrated into the existing SREP elements. This approach would incorporate considerations of operational resilience into the assessment of internal governance, operational risk management, and other relevant elements, making operational resilience a regular ‘business-as-usual’ part of the SREP.
This option is more closely aligned with the BCBS framework, which recognises that while operational resilience and operational risk management have different objectives, they are closely related and share common principles. Effective operational risk management supports operational resilience, and together they provide a complementary framework towards reducing the frequency and impact of operational risk events, while safeguarding critical operations.
Implementing this integration would require supervisors to assess the institution’s ability to deliver critical or important functions even in the event of disruptions, with a focus on the following areas: − internal governance; − operational risk management; − business continuity planning and testing; − mapping of interconnections and interdependencies; − third-party dependency management; − incident management; − ICT, including cyber security.
This approach is also consistent with the BCBS’s Core Principles for Effective Banking Supervision, which group operational risk and operational resilience under a single core principle in relation to prudential regulation and institutional requirements.
Option 2 is the preferred option.
FINAL REPORT ON THE REVISED SREP GUIDELINES
ESG risks
The SREP GL that came into force in January 2023 contained first references to ESG risks. However, in line with the requirements of the CRDVI, a more comprehensive approach to dealing with ESG risks is necessary. In this context, two policy options were considered.
Option 1: Introduction of a stand-alone module on ESG risks in the SREP GL
One option is to create a dedicated module within the SREP GL that deals exclusively with ESG risks. This would improve visibility of the supervisory assessment of ESG risks and allow for the specific characteristics of these risks, such as their forward-looking nature and their potential to materialise over different, including long-term, time horizons, to be adequately captured.
However, this approach would require close interlinkages with existing SREP elements, as ESG risks typically materialise through traditional financial risk categories, as clarified in the CRRIII definition. Moreover, ESG risks should not be managed in isolation by institutions, but rather embedded in the institution’s core business strategy, governance arrangements, and risk management framework.
The introduction of a stand-alone module could lead to overlaps and duplication of work, which would increase the complexity of the SREP and the burden on both the competent authorities and the supervised institutions.
Option 2: Integrating ESG risks into existing SREP elements
Alternatively, ESG risks could be integrated into existing SREP elements. This approach would incorporate ESG considerations into the assessment of the business model, internal governance, risks to capital, and risks to liquidity and funding, thereby making ESG risks a regular ‘business-asusual’ part of the SREP.
This option is more closely aligned with the regulatory definition of ESG risks and their role as drivers of traditional financial risk categories such as credit, market, and operational risks. Implementing this integration would require targeted guidance and capacity building within the competent authorities, which the EBA could support through its supervisory convergence activities.
In addition, while ESG risks would be assessed using existing SREP elements, competent authorities could still leverage insights from specific supervisory activities related to ESG risks (e.g. thematic reviews, on-site inspections) to inform their assessment of the relevant SREP elements.
Option 2 is the preferred option.
Market risk – transfer pricing models
Certain transfer pricing arrangements may expose institutions to market risk that is not adequately captured under the Pillar 1 framework. In particular, entities established in the Union that are part of a third-country group may be subject to re-allocated gains or losses from market risk activities
FINAL REPORT ON THE REVISED SREP GUIDELINES
conducted and recorded elsewhere in the group. To ensure these institutions are adequately capitalised for this risk, two policy options were considered.
Option 1: Introduction of a methodology for the calculation of Pillar 2 requirements
One option is to introduce an approach to address the market risk of transfer pricing arrangements based on a transaction profit method, including a formula for determining P2R .
This option is grounded in the principle of business neutrality: institutions exposed to market risk through the transfer pricing arrangement should be capitalised in the same way as those managing the risks directly. Thereby, the following two scenarios are considered equivalent from a market risk perspective: 1. The institution manages the risk locally within the Union and calculates a Pillar 1 capital requirement. 2. Initially, the institution transfers its market risk through back-to-back positions to a related entity (e.g. sibling or parent) located outside the Union. Subsequently, the institution enters into a transfer pricing arrangement whereby a portion of the economic gains or losses arising from the market risk activities is re-allocated based on pre-agreed metrics (e.g. 10% of the group’s gains/losses will be allocated to the subsidiary established in the Union). In this scenario, the institution does not calculate a Pillar 1 capital requirement for the risk. In the second scenario, there is no Pillar 1 capital requirement because transfer pricing arrangements typically do not qualify as financial instruments under accounting standards. The Pillar 2 approach can mimic the capital charge that would apply under the assumption that the transfer pricing arrangement is considered a financial instrument.
The proposed risk measurement approach is not mandatory and competent authorities can apply equally robust, alternative methodologies that meet certain conditions. This ensures flexibility in addressing institution-specific circumstances and allows for proportionality in supervisory responses.
Option 2: Do not introduce a methodology in the SREP GL
Alternatively, the SREP GL could not provide for a methodology and competent authorities would be able to determine how best to assess and address the risk. This option may result in inconsistent treatment across jurisdictions and could perpetuate regulatory arbitrage, whereby institutions bearing market risk through transfer pricing arrangements are not subject to equivalent capital requirements.
Option 1 is the preferred option. It ensures that institutions are adequately capitalised for market risk arising from transfer pricing arrangements, promotes consistency across supervisory practices,
FINAL REPORT ON THE REVISED SREP GUIDELINES
and establishes a level playing field between institutions directly capitalising their market risk as part of a Pillar 1 capital requirement and those institutions that bear the risk but have no capital against it.
Interaction between the revised Pillar 1 framework (including the output floor) and Pillar 2
The implementation of the revised Basel framework in the EU required careful consideration of the possible interactions between the output floor (OF) and the Pillar 2 requirements (P2R). In particular, there was a risk that applying the OF to an institution’s TREA could lead to double counting of risks that had already been addressed by the P2R set by the competent authorities in accordance with the CRD.
To avoid this, the EBA was mandated in accordance with Article 104a(7) of Directive 2013/36/EU to issue GL to ensure that the interaction between the OF and the P2R does not lead to overlapping capital requirements. These GL also operationalise the requirement set out in Article 104a(6) of Directive 2013/36/EU. Given the relevance of this issue for the SREP assessment, the forthcoming GL in accordance with Article 104a(7) of Directive 2013/36/EU have been incorporated into the revised SREP GL. Pending the adoption of the revised SREP GL and to promote harmonised supervisory approaches, both proactive and reactive, the EBA has issued an Opinion on the initial entry into force of the OF. In this context, two policy options were considered, which are not mutually exclusive but rather additive, with Option 2 encompassing Option 1.
Option 1: Integration of the EBA Opinion on the output floor
This option involves incorporating the provisions already set out in the EBA Opinion into the guidelines, with a specific focus on the interaction between OF and P2R. The following guidance would apply: 1. Once an institution becomes first bound by the OF, the applicable P2R percentage – as communicated to the institution following the last SREP cycle – should be applied to the unfloored TREA (so-called ‘temporary cap’). This operationalises the temporary cap in accordance with Article 104a(6)(a), ensuring that P2R is not increased solely because of OF has become binding. 2. When reviewing double counting, competent authorities should consider offsets for P2R addons related to ‘regulatory model deficiencies’, where these exist. The add-on must relate to a model used to determine the TREA, and the offset amount must not exceed the impact of the OF on the TREA. 3. Competent authorities that use methodologies to determine P2R amounts based on a multiplication of the TREA should pay attention to automatic arithmetic increases (i.e. where the P2R nominal amount increase is not due to an increase in risk but results from the P2R being expressed as a percentage of TREA). These authorities are expected to consider how to prevent undue effects when performing the one-off double counting review of the OF.
FINAL REPORT ON THE REVISED SREP GUIDELINES
Option 2: Integration of the EBA Opinion on the output floor and more general provision on the
interaction between P1R and P2R
In addition to the provisions under Option 1 – limited to the interaction between OF and P2R – this approach would involve a more comprehensive assessment by competent authorities of the interactions between P1R and P2R, where a material impact on an institution’s capital profile is expected due to relevant changes to the regulatory framework for determining P1R. The aim is to ensure that P2R continues to cover risks, or elements of risks, that are not covered or not sufficiently covered by the P1R, in line with Article 104a(1) of Directive 2013/36/EU.
The revised Pillar 1 framework, as set out in the CRRIII/CRDVI, introduces improved and more risksensitive measurement approaches – both standardised and advanced – for determining TREA. Against this background, and taking into account the overarching requirement to avoid double counting between Pillar 1 and Pillar 2 frameworks, the revised guidelines encourage competent authorities, in cases of relevant changes to the regulatory framework for determining P1R, to ensure that P2R prevent overlaps with risks already covered under Pillar 1. In such cases, this may require a redetermination of the quantity or composition of the P2R to ensure that the institution’s overall own funds requirements are in line with Article 104a(1) of Directive 2013/36/EU.
Option 2, which also encompasses Option 1, is the preferred option as it provides a broader operationalisation of the requirement in accordance with Article 104a(1) of Directive 2013/36/EU and aims to ensure that the complementary nature between P1R (including the OF) and P2R is maintained.
Third-country branches
The EBA is mandated with issuing GL to further specify the common procedures and methodologies for the SREP for third-country branches (TCBs) and for the assessment of material risks to their operations in accordance with Article 48n(6)(a) of Directive 2013/36/EU.
As part of this process, competent authorities are expected to evaluate whether the arrangements, strategies, processes, and mechanisms implemented by TCBs – along with their capital endowment and liquidity – ensure sound management and coverage of material risks to their operations and viability. This mandate is part of the new prudential framework for TCBs introduced by CRDVI, which provides competent authorities with the necessary tools to monitor the specific risks posed by TCBs operating within the EU. In this context, two policy options were considered.
Option 1: Develop stand-alone SREP GL for third-country branches
One option is to develop a dedicated set of GL on common procedures and methodologies for the SREP of TCBs. This approach would be consistent with the precedent set for investment firms, for
FINAL REPORT ON THE REVISED SREP GUIDELINES
However, unlike investment firms, TCBs are governed under a dedicated Title (Title VI) within the existing regulatory framework for credit institutions in accordance with Directive 2013/36/EU. Therefore, developing separate SREP GL for TCBs would represent a departure from the Level 1 approach, which integrates TCBs within the broader framework of credit institutions.
This option was also considered in light of the European Commission’s initiative to reduce regulatory burdens and simplifying EU legislation. While separate GL could offer clarity, they could also contribute to fragmentation and complexity in the supervisory framework.
Option 2: Incorporate SREP GL for third-country branches into the revised SREP GL for credit
institutions
Alternatively, the SREP GL for TCBs could be incorporated into the revised SREP GL for credit institutions. This approach would combine both mandates, in accordance with Article 48n(6)(a) and Article 107(3) of Directive 2013/36/EU, into a single, coherent set of GL.
There are no legal constraints preventing the consolidation of GL from different but related mandates. Given that the section on TCBs is relatively short and concise, this approach would support the overall streamlining of the revised SREP GL.
From a timing perspective, the planned publication of the revised SREP GL by the end of June 2026 would allow for timely fulfilment of the mandate by the legal deadline of 10 July 2026. As an alternative option, in the event of delays, the section on TCBs could be carved out and published separately to ensure compliance with the deadline.
From a content perspective, consolidating the SREP GL for credit institutions and TCBs in a single document allows competent authorities to use existing methodologies while addressing the specific risks and context of TCBs in a separate section, which is consistent with the integrated approach at Level 1.
Option 2 is the preferred option.
Supervisory effectiveness
Recent episodes of stress in the banking sector have once again highlighted the importance of effective supervisory measures, in particular the ability of competent authorities to promptly identify and address deficiencies in the institutions under their remit, using the most appropriate supervisory tools available. In this context, two policy options were considered.
Option 1: Introduction of an escalation framework for supervisory measures in the SREP GL
One option is to introduce a dedicated module within the SREP GL that deals explicitly with supervisory measures, with a focus on establishing a high-level escalation framework. This
FINAL REPORT ON THE REVISED SREP GUIDELINES
framework would support the competent authorities in selecting the most appropriate measures – both qualitative and quantitative – to address identified deficiencies.
The proposed escalation framework would include the following steps: − supervisory dialogue; − communication of expected corrective actions, such as supervisory expectations or recommendations (non-binding measures); − adoption of specific corrective actions to be implemented by the institution (binding measures); − enforcement of supervisory measures, including administrative penalties, sanctions, and other applicable remedial measures.
The general objectives of the escalation framework are: 1. to provide practical guidance and support to supervisors, promoting clarity and consistency across competent authorities; 2. to promote the full and effective use of supervisory tools; 3. to improve predictability and transparency for institutions. The framework should be high-level and flexible. Competent authorities may consider additional or alternative measures based on the supervisory powers granted to them under the applicable legal framework. The steps outlined are not intended to be followed in a strict sequential manner and may be escalated or de-escalated as appropriate, while preserving the discretion of the competent authorities.
Option 2: Maintain the current SREP GL unchanged
Alternatively, the SREP GL could remain unchanged with regard to supervisory measures, meaning that this issue is not addressed.
However, given the central importance of supervisory measures for the SREP assessment and the crucial importance of effective supervision for the timely and appropriate resolution of institutional deficiencies, Option 1 is the preferred option.
ICT risk assessment
The current SREP GL refer to the ICT SREP GL (EBA/GL/2017/05) for assessing ICT risk and complement the assessment of operational risk (Title 6.4), the business model (Title 4), and internal governance and institution-wide controls (Title 5). Although the ICT SREP GL did not introduce a distinct methodology – they largely mirror the assessment of operational risk – they did establish a separate process, which was often interpreted as treating ICT risk separately from operational risk. This approach has led to certain unintended overlaps and complications in the consolidation of supervisory assessments. In particular, the results of the related peer review (EBA/REP/2022/25) highlighted the challenges of integrating ICT risk into the broader operational risk framework, which has led to inconsistencies in supervisory practices.
FINAL REPORT ON THE REVISED SREP GUIDELINES
Since their application from 1 January 2018, the ICT SREP GL have supported competent authorities in improving supervisory attention on ICT risks and promoting harmonised supervisory practices. However, with the entry into force of the Digital Operational Resilience Act (DORA) on 17 January 2025, the regulatory landscape has changed significantly as DORA consolidates ICT risk management requirements across the EU financial services framework.
Thereby, Directive 2013/36/EU was amended by Directive (EU) 2022/2556 to explicitly address ICT risks and clarify their inclusion in the scope of the SREP, thereby ensuring legal certainty and enabling supervisory authorities to effectively identify and monitor ICT risks. In this context, two policy options were considered.
Option 1: Retaining the ICT SREP GL as a separate policy product and adapting it to DORA
Under this option, the ICT SREP GL would be revised to take account of DORA but would remain a separate policy product. However, this approach would require a comprehensive revision that would have only limited added value from both a supervisory and institutional perspective. It could also lead to disproportionate emphasis on ICT risks compared to other SREP elements and would not be consistent with the objective of simplifying the SREP and the EU’s broader efforts to reduce regulatory burden and streamlining of policy frameworks.
Option 2: Integration of the ICT SREP GL into the general SREP GL and adapting them to DORA
Alternatively, the ICT SREP GL could be repealed and integrated into the general SREP GL in a targeted and comprehensive manner. This approach would ensure balanced supervisory attention across all key SREP elements and align ICT risk assessment with the harmonized requirements of DORA.
From a regulatory perspective, the revised Regulation (EU) 575/2013 contains a definition of ICT risk that is consistent with DORA. In addition, the updated definition of operational risk (Article 4(1)(52) of Regulation (EU) 575/2013) explicitly includes ICT risk, and the supplementary technical standards on the taxonomy of operational risk (pursuant to Article 317(9) of Regulation (EU) 575/2013) require that operational loss events be attributed, among other things, to ICT risk.
This option also reflects the recommendation of the relevant peer review, which took place in October 2022, to integrate the ICT SREP GL into the general SREP GL and ensure that ICT risks are appropriately highlighted within the SREP.
Option 2 is the preferred option.
FINAL REPORT ON THE REVISED SREP GUIDELINES
5.2. Views of the Banking Stakeholder Group (BSG)
Overall, the BSG welcomed the revised SREP Guidelines and highlighted the need to strike an appropriate balance between supervisory convergence and the principle of proportionality, stressing that supervisory judgement and flexibility remain essential to address institution‑specific risks and evolving risk profiles. The BSG broadly supported the integration of ESG risks and welcomed the proposed phased approach, advocating for a gradual and proportionate implementation across all ESG dimensions. The BSG welcomed the increased emphasis on proportionality and invited further clarification on how proportionality should apply in practice.
The BSG raised comments on the proposed treatment of transfer pricing arrangements in market risk, highlighting the importance of avoiding double counting, ensuring alignment with the actual risk borne by EU entities and preserving flexibility in methodologies. On the interaction between Pillar 1 and Pillar 2 requirements, the BSG welcomed the additional supervisory guidance while expressing diverging views on the extent to which rebasing of P2R and alignment with macroprudential buffers, such as the countercyclical buffer, should be considered.
The BSG supported enhanced transparency and communication of SREP outcomes, stressing that disclosure should not undermine supervisory discretion or lead to mechanistic application of the framework. Lastly, the BSG welcomed guidance aimed at strengthening coordination within supervisory colleges and the assessment of cross‑border groups and third‑country branches, while emphasising the need to avoid duplication, unnecessary fragmentation and undue burden at group level, and to preserve the ability of local authorities to address entity‑specific risks.
FINAL REPORT ON THE REVISED SREP GUIDELINES
5.3. Feedback on the public consultation and on the opinion of the BSG
The EBA publicly consulted on the draft proposal contained in the consultation paper of the draft revised Guidelines on common procedures and methodologies for the SREP and supervisory stress testing. The consultation period lasted for three months and ended on 06 February 2026. Twentyfive responses were received, of which nineteen were published on the EBA website.
This section presents a summary of the key points and other comments arising from the consultation, the analysis and discussion triggered by these comments and the actions taken to address them if deemed necessary. In many cases, several industry bodies made similar comments, or the same body repeated its comments in the response to different questions. In such cases, the comments, and EBA analysis are included in the section of this paper where the EBA considers them most appropriate.
Changes to the draft Guidelines have been incorporated as a result of the responses received during the public consultation.
Summary of key issues and the EBA’s response
Overall, respondents broadly welcomed the revision of the SREP Guidelines and acknowledged the EBA’s efforts to consolidate, modernise and clarify the framework. The objectives of enhanced risk‑based supervision, improved transparency, and better alignment with recent regulatory developments were generally supported. At the same time, respondents noted the need for effective simplification, proportionality application and reduction of supervisory burden. Respondents highlighted the need to avoid duplication and double counting (e.g. between Pillar 1- Pillar 2 requirements, P2G-macroprudential buffers, SREP-DORA risk frameworks). Respondents suggested greater transparency on scoring, methodologies, thresholds, benchmarking practices, peer selection, and the calibration of P2R/P2G, while still preserving supervisory discretion. Proportionality enhancements were welcomed noting for stronger operationalisation, especially for groups, subsidiaries and small, less complex institutions.
Respondents broadly supported the integration of DORA/ICT risk, raising caution to avoid overlaps and duplicative supervisory requests, and suggested more clarity on the boundaries between ICT risk, operational risk, digital operational resilience and operational resilience. Moreover, some respondents considered the introduction of operational resilience as a new framework not fully grounded in the current EU legal framework. On ESG risks, respondents generally supported integration into SREP and advocated for a gradual, proportionate and materiality‑based approach, prioritising climate and environmental risks, a more consistent use of concepts and caution against premature capital impacts. The high‑level escalation framework was welcomed in principle with proposals for clear criteria, sequencing and more practical examples. Enhanced communication of SREP outcomes was widely supported, with suggestions for clearer explanations of scores, key risk drivers, and supervisory expectations, while avoiding excessive mechanisation of the SREP process.
FINAL REPORT ON THE REVISED SREP GUIDELINES
The EBA has also considered the response received from the Banking Stakeholder Group (BSG), which was analysed and taken into account alongside the other responses to the public consultation.
Summary of responses to the consultation and the EBA’s analysis
Comments Summary of responses received EBA analysis Amendments to the proposals
Q1. What are the respondents’ views on the overall amendments and clarifications made to the revised guidelines (across Titles 2 – 12)?
Clarifications on Respondents proposed to harmonise the It is clarified that the SREP GL, consistent with Explanatory text has information and information/reporting requests between DORA, SREP their principle-based nature, do not require been added in the ‘Background’ reporting requests and other frameworks/regulations, to add guidance on institutions to produce separate or additional section along with between DORA, the articulation/interaction between SREP and DORA information/reporting where existing amendment in SREP and other assessments (e.g. how remediation timelines will be governance arrangements already demonstrate paragraph 121. frameworks coordinated) and to ensure that the revised SREP GL compliance. Furthermore, it is highlighted that will not impose any new or additional information the SREP GL state the view on all the SREP requirements beyond those included in the existing or elements to be based on information gathered upcoming EBA GL. through the full range of supervisory activities in line with Title 2, paragraph44.
Risk sub- A respondent noted the draft taxonomy is partial and, It is clarified that institutions are expected to No change categories (annex) on some elements, it uses a regulatory approach. It maintain their own risk taxonomies for risk was proposed to adjust it to be more economic and, if management purposes as the risk subpossible consistent with that of the ECB. categorisations set out in the Annex are intended to be used as guidance for the competent authorities and to further promote consistent risk identification across authorities, while remaining non-exhaustive and flexible.
FINAL REPORT ON THE REVISED SREP GUIDELINES
Level of detail, Several respondents indicated that further Respective comments were made to the Targeted cross-references simplification and reduction of complexity is needed in individual Titles hence respective clarifications (please and layered the SREP Guidelines, noting that despite consolidation responses/analysis are provided separately in see comments requirements efforts the framework remains detailed and resource the below questions. The use of cross-references further down) intensive. Respondents suggested reducing regulatory should not form an impediment to the layers, eliminating parallel requirements and cross- proportionate approach to be applied references, and focusing more strongly on risk-based throughout the SREP assessment focusing on the supervision rather than process-heavy documentation risks and sub-categories of risk insofar as they requirements. are material for the institution. It is also clarified that SREP is considered an ongoing process that integrates the outcome of all the supervisory activities and all available sources of information into a comprehensive supervisory overview of an institution (please refer to paragraph13).
References to In this context of simplification, a respondent The removal of outdated provisions or Removal of related regulatory proposed to reduce or remove the references to assessments already set out in other relevant tables and products relevant regulatory products at the beginning of each regulatory products was partially facilitated development of a Title as this renders the use of SREP GL a complex through the list of relevant regulatory products separate list of legal issue for practitioners. Moreover, a respondent at the beginning of each Title. To further acts facilitating suggested to remove references to products facilitate transparency, the references to SREP assessments addressed to competent authorities (e.g. EBA GL on applicable EU legal and regulatory requirements to be published on ICAAP and ILAAP information) as institutions are not will be published as a separate list on the EBA the EBA website. obliged to comply with them. website. Moreover, the removal of references to regulatory products addressed to competent authorities could undermine the very purpose of the SREP GL as a supervisory tool.
Interaction with Respondents noted the draft revised SREP GL The EBA acknowledges the interaction of the Legal acts other regulatory interacted with other EBA GL which were going revised SREP GL with other upcoming EBA GL, facilitating SREP through parallel consultation (e.g. EBA Internal which were also going through public assessments to be
FINAL REPORT ON THE REVISED SREP GUIDELINES
products and Governance GL), hence it was challenging to provide consultation. It is clarified that the revised SREP published as a timeline comments on certain aspects. Respondents suggested GL aim to be future-proof and fully aligned with separate list on the to ensure alignment of content and implementation the final adopted text of regulatory products, EBA website. deadlines, allowing for a sufficient implementation including EBA GL. This is ensured via direct period before being considered in the SREP references to applicable EU legislation and assessment. A respondent suggested that any adopted regulatory products. reference to non-final provisions (e.g. mapping of duties, individual statements) should remain limited, high-level and principle based. Respondents suggested clarifying the scope and limits of early implementation before the official application date of January 2027, noting that unclear timing could create legal uncertainty for institutions. A respondent proposed to encourage competent authorities to start the reassessment for the possible redetermination of P2R at an earlier stage, where possible.
Investment firms Respondents requested to ensure consistency on the All institutions and investment firms that are No change under scope distinction between credit institutions and investment subject to the CRD-CRR requirements are in firms, with one respondent pointing out that the scope of the SREP GL under the CRD-CRR, and Guidelines clearly distinguish credit institutions and the investment firms that are subject to IFD-IFR Class 1 investment firms from Class 2 and Class 3 requirements are in scope of the SREP GL for investment firms, inviting the EBA to review the scope investment firms. The same logic is applied in of other related prudential frameworks – for example the Level 2 and Level 3 work under the CRD-CRR the scope of the BRRD – to ensure consistency. and under IFD-IFR. The BRRD framework is outside of the scope of these SREP GL.
AML/CFT aspects Respondents requested to future proof references to It is clarified that references to Directive (EU) Additional clarity in the new EU AML package and AMLA supervision, with 2015/849 will be automatically repealed and the ‘Background’ one respondent suggesting to already align the SREP construed as references to the new AML and the definitions, GL (applicable as of 1 Jan 2027) with the new EU AML framework once Article 77 of Directive (EU) along with the package including AMLD6 (coming into force by and 2024/1640 (AMLD6) enters into force. This will addition of
FINAL REPORT ON THE REVISED SREP GUIDELINES
large as of 10 July 2027), and direct supervision by ensure full alignment with the new AML package transitional AMLA of selected obliged entities as of 2028. Some as well as the definition of ‘AML/CFT provision for respondents suggested to ensure close alignment with supervisors’ (Article 2(45) of Regulation (EU) aspects becoming AMLA on common understanding what to consider as 2024/1624) which also includes AMLA. applicable with the material finding/shortcoming and align definitions of Moreover, to ensure better alignment with the new AMLD6/AMLR. AML/CFT supervisors and ML/TF risk to the new EU new AML package, references to the ‘risks of AML package. non-implementation and evasion of targeted financial sanctions’ has been incorporated in the Few respondents noted the need of close coordination SREP GL, noting the transitional application of between supervisory authorities and AML/CFT the related references from 10 July 2027 authorities for cross-cutting deficiencies to avoid onwards. conflicting or duplicative supervisory measures. Moreover, a respondent suggested to add in Section 9.8 of the draft revised SREP GL already paragraph105 that close coordination between promotes cooperation with AML/CFT supervisory and AML/CFT authorities should also cover supervisors, in particular when applying potential measures to avoid duplicative or conflicting supervisory measures. The EBA takes note of the measures. comment as it informs the ongoing implementation of the recommendations in the EBA TFE report, in particular the setup of supervisory platforms that bring together authorities from different horizons in pilot cases for specific institutions (recommendation 14).
Quality assurance Consistency in the application of supervisory The EBA notes that quality assurance processes Paragraph 40 has judgement across banks (within the same and internal consistency mechanisms fall within been expanded to authority)/quality assurance. At the roundtable the organisational and governance strengthen quality discussion, participants suggested to add quality arrangements of competent authorities. The assurance and assurance aspects to the revised SREP GL to ensure revised SREP Guidelines are considered to supervisory consistency in the application of supervisory judgment provide sufficient clarity on supervisory consistency. within the same authority. A respondent proposed expectations, while allowing competent adding further clarity on expectations for consistency authorities the necessary flexibility to apply supervisory judgement in a proportionate
FINAL REPORT ON THE REVISED SREP GUIDELINES
and transparency across competent authorities and manner. Additional clarification has been added supervisory teams. in section 2.3 to further encourage adequate internal quality assurance arrangements and to enhance supervisory effectiveness.
Comparisons with Suggestion to add peer comparisons with non-EU The SREP GL already requires competent No change non-EU peers and peers and non-EU regulatory developments as input to authorities to consider the broader context in non-EU regulatory SREP – one respondent suggested to requiring CAs to which institutions operate, including their developments as take into account for the SREP and adding to international activities and group structures, and input to SREP paragraph 13: (i) peer comparisons, including third- the principle-based nature of paragraph 13 aims country groups active in the EU/EEA and relevant to preserve supervisory judgment on which peers in countries outside the EU/EEA where the inputs are material for a given institution. supervised institution operates and (ii) regulatory Making peer comparisons with non-EU peers developments, including in countries outside the and non-EU regulatory developments a EU/EEA, to ensure a level playing field with cross- mandatory SREP input would risk imposing a border groups. disproportionate and operationally burdensome obligation on competent authorities, particularly for institutions with limited cross-border exposure where such comparisons would add little supervisory value.
Ad-hoc reporting A respondent raised concerns about the potential use The EBA acknowledges the concern raised by the Paragraph 121 has of ad-hoc reporting agreed bilaterally with institutions, respondent regarding the potential subjectivity been amended to noting that such practices may introduce subjectivity associated with ad-hoc reporting agreed prioritise the use of and suggested that benchmarking-related reporting bilaterally with institutions. In this respect, regular and readily should be standardised across peer groups. It was competent authorities are expected to make use available further suggested to refrain from ad-hoc reporting of existing regulatory and supervisory reporting information agreed bilaterally with institutions from paragraph frameworks to the maximum extent possible. At sources, having 124. the same time, the SREP framework needs to regard to the retain a degree of supervisory flexibility to allow objective of competent authorities to request additional minimising the information where necessary to support risk reporting burden on
FINAL REPORT ON THE REVISED SREP GUIDELINES
assessments or benchmarking analyses that institutions and cannot be adequately performed using existing avoiding data sources. Such requests are expected to unnecessary or remain limited and proportionate and should be duplicative data justified by the specific supervisory need. requests. Wording has been adjusted in this regard.
List of supervisory A respondent suggested the review of the supervisory It is noted that the consideration on any No change measures measures listed in the respective tables across the necessary supervisory measures to address SREP Titles and replace them with more general concerns emerged by the SREP has been moved references to the supervisory powers in accordance from Title 10 of the previous SREP GL to the with Article 104 of the CRD as some interfere with the specific assessment areas (in the form of a table) institutions’ business and risk policy decisions. to directly link them with the relevant assessment areas. This aims to enhance the relevance of supervisory measures and hence supervisory effectiveness.
Q2. What are the respondents’ views on the integration of ESG risks and factors across the existing SREP elements in the revised guidelines?
ESG risks as Broad support for integrating ESG risks as drivers The EBA acknowledges the support for the No change drivers within within existing SREP elements rather than creating a proposed approach. ESG risks are embedded as existing SREP standalone ESG element or module, with respondents drivers of traditional risk types and existing SREP elements agreeing this approach is aligned with CRR/CRD, EBA elements where relevant in the final GL. GL and risk-based supervision, and helps avoid redundancy and over complexity.
FINAL REPORT ON THE REVISED SREP GUIDELINES
The EBA has taken into account that the CRD Terminology Terminology flagged as problematic, with respondents provisions refer to ESG risks, e.g. Article 98(9) on Wording amended noting interchangeable use of ‘ESG’, ‘environmental’, the incorporation of ESG into the SREP. On the and aligned ‘climate and environmental’ ‘risks’ or ‘factors’. A other hand, the EBA recognises that supervisors throughout the GL. have so far mostly focused on climate-related gradual, sequenced approach is supported by banking risks and a sequential approach giving priority to sector respondents, prioritising climate risk first, environmental risks is recognised both by recital followed by other environmental risks, and only later 40 of the CRDVI and various EBA Guidelines (GL social and governance risks, reflecting differences in on the management of ESG risks, GL on data availability and methodological maturity. Several environmental scenario analysis, Joint GL on ESG respondents request to explicitly and consistently stress testing). embed this sequencing in the final Guidelines and not The EBA has reviewed and harmonised only in the background. They also suggest that the terminology across the SREP GL while remaining guidelines should concentrate on C&E ‘risks’ rather aligned with the CRD (i.e. the GL refer to ESG than ‘factors’. On the other hand, other respondents risks but highlight more consistently that priority consider that the GL should include explicit should be given to environmental risks). expectations for supervisors on nature-related risks, To reflect the specific focus of paragraph 69 recognising the potential significant impacts of these (medium- to long-term resilience) and ensure consistency with EBA GL on environmental risks on financial institutions’ portfolios and leveraging scenario analysis, this paragraph only refers to the work already undertaken in international fora (e.g. environmental risks. NGFS, TNFD).
To allow for further developments on environmental risks beyond climate, referring to ‘environmental risks’ is more appropriate than a restricted focus on ‘climate-related risks’ only. The CRR definition of environmental risks captures both climate and other environmental risks. The GL still recognise in the background the greater capacity to quantify climate-related risks at this point.
FINAL REPORT ON THE REVISED SREP GUIDELINES
Finally, while most provisions refer to ‘risks’ rather than ‘factors’, the term ‘ESG factors’ is still used in specific paragraphs when it better fits the context and/or to ensure alignment with the CRD text.
Proportionality, Some respondents stress proportionality, materiality Proportionality and materiality principles are key Clarification in the materiality and and feasibility challenges, highlighting that ESG overarching, cross cutting principles in the SREP ‘Background’ feasibility integration should only affect scores and capital where GL and they apply to the treatment of ESG risks. section. challenges there is clear evidence of material financial risk, and The GL expect CAs to take into account ESG risks should not lead to disproportionate capital add-ons, as well as a range of other considerations when especially given recent regulatory developments, assigning a score e.g. in BMA, internal persistent data gaps and methodological immaturity. governance, and risks to capital elements. In this respect, it should be clarified that only material Where deficiencies relating to the management ESG risks are concerned throughout the guidelines and of ESG risks are identified that could pose particularly when referring to potential supervisory material risks to the institution’s solvability, CAs measures. may take supervisory measures with due consideration to the escalation framework and ensure respective communication.
Strengthening the Some respondents call for a more precautionary and The SREP GL explicitly require CAs to include in No change on treatment of forward-looking supervisory approach, urging stronger the scope of their analysis the institutions’ plans transition plan, climate and recognition of uncertainty, tail risks and tipping points to address ESG risks to be developed in supervisory environmental associated with climate and environmental risks. accordance with the CRD, with specific reference measures and fossil risks in SREP These specific characteristics, if unaccounted, can to these plans included in sections relating to fuels. significantly distort the results of supervisory elements 1 and 2. Regarding supervisory The background of assessments. The SREP GL should also mandate measures, the GL provide that institutions’ the GL further systematic assessment of transition plan robustness exposure to and management of ESG risks
FINAL REPORT ON THE REVISED SREP GUIDELINES
and promote readiness to use Pillar 2 measures where should be taken into account when assigning clarifies the need to ESG risks are mismanaged. In addition, the GL should scores and deciding on potential supervisory take into account explicitly require supervisors to consider fossil fuel measures. With regard to fossil fuel exposures, a the specific exposures as part of assets and activities subject to specific and systematic focus on those exposures characteristics of elevated risk, as these exposures – especially when would not be consistent with the general and environmental risks, financing new fossil fuel developments –- are high-level nature of the SREP GL, which should whilst keeping in inherently misaligned with climate objectives or remain relevant to all types of institutions with mind associated with high and difficult-to-mitigate transition different business models and/or portfolios, methodological risks, while at the same contributing to increased along with supervisory judgement. However, the challenges system-wide physical risks. EBA is updating its Pillar 3 disclosure and especially when supervisory reporting technical standards to considering longfacilitate information gathering on institutions’ term horizons. exposure to fossil fuel sector entities, which would allow CAs to consider this information in their assessment where relevant.
Time horizons for Some respondents raise concerns on time horizons ESG risks can materialise across different time New paragraph 43 assessing climate highlighting the tension between long term ESG horizons. The need for a forward-looking in the ‘Background’ and horizons (10+ years) and shorter prudential planning approach is recognised in the GL and has been section and greater environmental cycles, calling for clearer guidance on how uncertainty further emphasized in the background. While recognition of risks should be treated and avoided in capital challenges related to longer time horizons are uncertainties determinations. On the other hand, other respondents acknowledged, it remains relevant for the associated with consider that expectations on time horizons remain competent authorities to review how long-term insufficient to fully capture climate- and nature- institutions ensure long-term resilience to ESG projections in related risks, especially those that are more likely to risks in particular as part of the BMA, including paragraph 146. materialise over longer timeframes, and they suggest by considering transition planning developments articulating expectations more consistently across the and assessing environmental business model guidelines by extending the long-term perspective to resilience analyses performed by institutions.
FINAL REPORT ON THE REVISED SREP GUIDELINES
20 or 30 years or until 2050, aligning with the Paris For this, the BMA section includes a reference to Agreement. Finally, other respondents suggested a long-term time horizon of at least 10 years, defining time horizons for ESG assessment in the BMA which is aligned with the CRD Article 87a(2) and (paragraph 58) in the following manner: less than two other EBA Guidelines. The consideration given to years for short-term, two to five years for medium- medium- and long-term horizons specifically in term, and more than five years for long-term. the BMA section, along with the stronger recognition of uncertainties associated with long-term projections and the clarification that any supervisory measure should address ESG risks that could pose material risks to the institution’s solvability., overall provides appropriate guidance for the treatment of ESG risks and time horizons.
Concerns about Some respondents consider that given the nascent It is acknowledged that the supervision of supervisory nature of prudential transition plans (PTPs) and the institutions’ plans to address ESG risks will be an Reference to this expectations fact that supervisory practices around their review are iterative process. However on this point, the GL potential regarding still evolving, requiring institutions to adjust their reflect Article 104(1)(m) of the CRD (‘competent supervisory prudential strategies based on an assessment of an institution’s authorities shall have at least the power to (…) measure kept in transition plans PTP appears premature (paragraph 71.h). Such an require institutions to reduce the risks arising in table 3 with approach could have significant negative impacts on the short, medium and long term from ESG wording institutions’ abilities to set their own strategies and factors, including those arising from the process adjustments to could undermine the quality and credibility of both of adjustment and from transition trends in the more closely align strategies and transition planning. They therefore context of the relevant Union, Member States or with the CRD recommend at a minimum amending paragraph 71.h third-country legal and regulatory objectives, provision. to frame the envisaged supervisory measure in a through adjustments to their business broader, principles-based manner. strategies, governance and risk management for which a reinforcement of the targets, measures,
FINAL REPORT ON THE REVISED SREP GUIDELINES
Role of portfolio Respondents express different views on transition The focus of the SREP GL is on the assessment of Wording alignment in planning and the role of portfolio alignment the plan to be prepared by institutions in adjustment in supervisory methodologies and/or criteria. On the one hand, some accordance with Article 76(2) of the CRD. The paragraph 68a to assessment of respondents flag that there is a clear delineation in EBA guidelines do not require the CRD-based clarify that the transition plans both the level one legislation and the underlying EBA plans to set out an objective of fully aligning focus is on assessing GL between the plan required in accordance with CRD with Member States or Union sustainability the institution’s Article 76(2), and broader transition plans. They objectives or one specific transition trajectory. plan to address ESG request clarity in the SREP Guidelines that the plans At the same time, it must be noted that plans risks, including risks mandated by CRD do not require the institution to be developed by institutions to monitor and from misaligned aligned to either Union or Member State transition address ESG risks in accordance with the CRD portfolios with objectives or trajectories, to avoid the supervision also need to consider and ensure consistency specific reference to leading to divergence between Members States/CAs. with institutions’ voluntary commitments, climate objectives On the other hand, other respondents consider that broader business strategy, and other (as in the CRD). the SREP GL should require a systematic assessment of requirements stemming from non-prudential alignment of the institution’s plan with climate regulations. In addition, while institutions objectives, i.e. degree of alignment of the entity's plan remain responsible for setting their business with international climate goals and its own climate strategy, institutions need to assess financial commitments, and they should refer more clearly to risks stemming from misalignments of their the risks of misalignment. portfolios with relevant EU regulatory objectives, in particular climate-related objectives.
Credit risk Respondents highlighted that the proposed expansion The inclusion of ESG risks in the guidelines No change assessment scope of the scope of the assessment of credit risk, which follows a proportionate and gradual approach,
FINAL REPORT ON THE REVISED SREP GUIDELINES
and uncertainty in now also includes ESG factors, leads to a considerable taking into account the ongoing consolidation of estimates level of detail, which should be reviewed critically. This supervisory practices in this area. As a result, only targeted references to ESG risks have been expansion is seen as leading to a focus on included in the credit risk section, without documentation requirements, which would dilute the introducing a significant level of additional detail principle of risk-based supervision. and focusing on the most relevant aspects of environment-related credit risk.
Some respondents highlighted that assessing the New paragraph 43 As mentioned above, the specific characteristics medium- and long-term impacts of ESG factors on the of environmental risks including time horizons in the background
inherent credit risk (§149) is still particularly difficult. and uncertainties have been further emphasized section and One respondent suggested that the current paragraph in the ‘Background’ section and in the credit risk adjustment of section, paragraph 146, while still noting the paragraph 146. 149 should explicitly acknowledge the radical need for CAs to build capacity and improve uncertainty surrounding ESG factors, which makes assessment methods over time. them particularly difficult to model, especially in the
area of credit risk. Competent authorities should
therefore ensure that banks have applied conservative
estimates in order to mitigate the impact of such
uncertainty in their modelling.
One respondent suggested explicitly reflecting ESG risk Table 6 ‘Supervisory considerations for assigning considerations not only in the assessment of inherent No change a credit and counterparty risk score’ includes credit risk, but also in the assessment of the credit risk ESG risks among the considerations in relation to management and control framework, as the current adequate management and controls. wording could otherwise result in a lower degree of
supervisory attention being paid to ESG risk
management, including risk-mitigating actions.
FINAL REPORT ON THE REVISED SREP GUIDELINES
Clarification of Some respondents request further guidance to ensure The SREP GL provide a high-level framework for No change supervisory consistent and actionable supervisory outcomes competent authorities and now include further expectations for relating to ESG risks, noting that the SREP GL remain guidance for the treatment of ESG risks while sometimes vague and high-level. They encourage the ESG risks in SREP still achieving an overall simplification. While it is EBA to further clarify aspects such as proportionality recognised that the GL do not provide detailed and/or materiality thresholds and triggers, minimum operational guidance, the EBA is in parallel expectations for ESG-related governance and internal controls, and the way ESG-related forward-looking actively engaging with supervisors and providing considerations should be used. They also recommend tools to support a consistent implementation of explicit guidance on how supervisors should address the ESG-related aspects of the SREP GL. It is also information gaps and expectations for remediation reminded that some principles in the GL are plans where ESG-related risk identification is applicable across the board i.e. including to the incomplete. One respondent also suggested including treatment of ESG risks, such as proportionality additional details in the guidelines concerning the and categorization of institutions, and that the weight of ESG factors in the overall BMA. expectations for institutions are not set out in the SREP GL but in other GL (EBA GL on ESG risks management, EBA GL on environmental scenario analysis, EBA GL on internal governance, EBA GL on loan origination and monitoring). Finally, the SREP GL do not aim at providing any specific weight for any SREP elements or sub-elements as the overarching objective is not to mechanistically produce SREP scores combining different SREP elements and sub-elements but, instead, to provide a common and holistic assessment framework to be taken into account by competent authorities when performing the SREP.
FINAL REPORT ON THE REVISED SREP GUIDELINES
Consistency Some respondents highlight the need for consistency Title 7 (SREP capital assessment) and Title 9 No change between ESG risk with ICAAP and stress testing, avoiding double (Overall SREP assessment) of the GL explain how assessment, counting. Where ESG drivers are captured via internal competent authorities should determine P2R ICAAP and stress and supervisory stress tests and through the ICAAP and P2G and how the findings from the testing and ILAAP, the Guidelines should clarify how outcomes assessment of each SREP element are combined feed into P2R/P2G in a coherent manner, so that the into the overall SREP assessment, respectively, same underlying ESG-related risk is not counted including with a view to avoid double counting multiple times (e.g. via business model, governance of the same risks. This guidance applies to the findings, risk-specific add-ons and stress testing treatment of ESG risks. simultaneously).
Fragmented Some respondents warn that due to the current The SREP GL are addressed to competent No change international fragmented international landscape, it is important to authorities and do not introduce new landscape allow certain requirements to be applied in a way that requirements for institutions. Competent permits the banking groups to comply with local laws authorities shall apply the review and evaluation and regulations in line with the objectives of such local process in accordance with the level of jurisdictions. application of the requirements of Regulation (EU) No 575/2013 set out in Part One, Title II of that Regulation. The supervision of institutions’ plans to address ESG risks should take into account how the institution manages risks stemming from the transition toward regulatory objectives, in particular climate-related objectives, applicable in the jurisdiction(s) where the institution operates.
FINAL REPORT ON THE REVISED SREP GUIDELINES
Regulatory Some respondents advocate for reviewing banking The SREP GL address the CRD mandate given to No change simplification and regulation to reflect the changes being made via the the EBA and reflect the new regulatory alignment with recently agreed Omnibus I, by changing level 1 texts requirements for the prudential supervision of legislative and reviewing supervisory expectations and EBA ESG risks. They do so in a proportionate and developments guidelines with a view to streamlining and efficient manner, by embedding ESG risks where simplification. Regardless of the legislative processes relevant without changing the SREP structure, that this might entail, the need to simplify and and through concise, targeted amendments. streamline the regulatory burden for European banks Hence the treatment of ESG risks in the SREP GL should be considered in the context of supervisors is consistent with the broader EBA efforts and applying the SREP GL. Also, it is important that the EU objectives for achieving simplification and remains broadly aligned with global prudential efficiency in the regulatory framework. standards and avoids gold-plating. Regarding international prudential standards, the review of the SREP GL takes into account the BCBS Core Principles for effective banking supervision which expect supervisors to consider climate-related financial risks in their supervision, in a flexible manner.
Q3. What are the respondents’ views on the enhanced simplification and proportionality aspects?
FINAL REPORT ON THE REVISED SREP GUIDELINES
Many respondents stated that proportionality is not The provision on the adaptation of focus and No change Proportionality sufficiently operationalised beyond reduced granularity of assessments to reflect the risk clarifications assessment frequency and lacks concrete guidance. profile of the institution, the materiality of the Respondents proposed to clarify how proportionality risks, trends and risks emerging, stress testing or should apply to the scope, level of detail, outcome of previous SREP assessments applies documentation, information requests and continuous throughout the SREP GL providing flexibility in supervision, including how it should work in groups the application of proportionality to take into with different risk profiles across subsidiaries and account differences in business models and risk parent entities. Respondents stated that the profiles. The comments will inform the administrative burden remains high also for small, implementation of the recommendations in the low-risk and non-complex institutions due to extensive EBA Report on the efficiency of the regulatory requirements and new regulatory layers. and supervisory framework (EBA/REP/2025/26), in particular on the consideration for a more systematic application of simpler requirements for the SNCI category, while preserving a single-bank regime and examining the potential expansion of the category, and the reduction of the reporting burden.
Respondents suggested to further clarify how the The aim is to support competent authorities to No change Lighter SREP following will be applied in practice: ‘The minimum adapt their supervisory activities to the specific assessment supervisory engagement model has been revised to level of risk in the institution supporting the riskallow for a lighter assessment of SREP elements or risk based approach and allowing for an efficient use areas that are considered immaterial or unchanged of supervisory resources. The comments will since the last assessment.’ inform the implementation of the recommendations in the EBA Report on the efficiency of the regulatory and supervisory framework (EBA/REP/2025/26), in particular on
FINAL REPORT ON THE REVISED SREP GUIDELINES
the consideration for a more systematic application of simpler requirements for the SNCI category. One responded suggested to clarify what is considered A SREP score is considered to be poor when it Wording Poor SREP score a poor overall SREP score in paragraph 45. reflects severe supervisory concerns. adjustment in paragraph 45. Several respondents suggested a prior impact The comment will inform the ongoing No change Prior impact assessment of the feasibility of the annual Supervisory implementation of the recommendations in the assessment of the Examination Programme for both supervised entities EBA Report on the efficiency of the regulatory Supervisory and competent authorities to allow orderly execution and supervisory framework (EBA/REP/2025/26), Examination of activities, and ease accurate supervisory in particular the set-up of supervisory platforms Programmes conclusions. that bring together authorities from different horizons in pilot cases for specific institutions (recommendation 14). A few respondents asked to reword paragraph 12 of The wording in paragraph 12 of the background Wording Minimum the background section to read that ‘for a subset of section has been aligned to the one used in adjustment in frequency for the smallest Category 4 institutions, the minimum paragraph 46 of Title 2 as follows: ‘The revised paragraph 12 of the assessing all SREP frequency for assessing all SREP elements should be SREP GL provide for an extension of the background section. elements for extended from three to five years, provided they minimum frequency for the assessment of all smallest Category maintain a stable low-risk profile, sound financial SREP elements from three to five years for a 4 institutions metrics and healthy margins, and quarterly monitoring subset of Category 4 institutions, provided they does not raise material concerns.’ maintain a stable low-risk profile, sound financial metrics and healthy margins, and quarterly monitoring does not raise material concerns.’
FINAL REPORT ON THE REVISED SREP GUIDELINES
Several respondents suggested for the SREP GL to The revised SREP GL support a risk-based and No change Issues with address issues related to continuous supervision, such proportionate supervisory approach noting at continuous as reducing the operative burden related to the the same time that decisions on materiality of supervision intense scrutiny on internal models, as well as the risks depend on the supervisory judgement. related portfolios. One respondent asked to clarify how the provision of As laid out in paragraph 14 of Title 2, Article No change Reference to the Article 97(4) of Directive 2013/36/EU would be 97(4) of Directive 2013/36/EU should be taken CRD Article 97(4) implemented in the SREP GL. into account by competent authorities when categorising institutions under their supervisory remit into the four categories driving the application of proportionality in the SREP, also considering the size, systemic importance, nature, scale and complexity of their activities. Several respondents asked for competent authorities The current criteria and methodological No change Increased to inform banks of their SREP categorisation to ensure considerations for determining the SREP transparency on transparency, convergence and predictability on the categorisation are deemed sufficiently clear, and categorisation of (minimum) supervisory engagement, and to further competent authorities have discretion over the institutions clarify the criteria and methodological considerations transparency of the categorisation towards for determining the SREP categorisation. institutions, also retaining the ability to adapt the intensity of the supervisory engagement to evolving/emerging risks. One respondent suggested providing an expected The current provisions on the periodic and ad No change Increased clarity timeline for category reassessment and further hoc re-categorisation of institutions are deemed and transparency clarifying how supervisors’ review of the category sufficiently clear, and competent authorities on (periodic/ad assignments over time may be driven by specific have the discretion over how to inform hoc) refactors, and how institutions will be informed about institutions about potential changes. categorisation of potential changes. institutions
FINAL REPORT ON THE REVISED SREP GUIDELINES
A few respondents asked if competent authorities can Competent authorities can rely on a previous Wording Reliance on prior rely on a previous assessment of a risk area for any assessment of a risk area if nothing has adjustment in assessment category of institution where there is clear evidence materially changed in accordance with the paragraph 46. that the risk profile has not materially changed? available information for any category of institution. The wording in paragraph 46 has been adjusted to clarify the reliance on previous assessments can be done ‘regardless of the SREP categorisation’.
Q4. What are the respondents’ views on the introduction of a high-level escalation framework?
Clear criteria or Respondents proposed to consider clear criteria, or The revised SREP GL introduces this high-level Paragraph 20 has examples for illustrative examples and references to qualitative and flexible escalation framework for been amended to transitioning considerations, for transitioning between escalation supervisory measures drawing on past strengthen between stages to anticipate supervisory expectations. supervisory and relevant experiences, lessons supervisory escalation stages, Furthermore, it was proposed to clarify within the learned, and with a view to strengthening effectiveness. underlying drivers SREP GL the underlying drivers determining the supervisory effectiveness and establishing a and supervisors’ decision (interaction between actions in high-level common framework across the EU. acknowledgement paragraph21 and considerations in paragraph22) and The principle-based escalation framework of institutions’ acknowledge the institutions’ history of remediation intends to guide competent authorities in history of when evaluating the necessity for escalation. Further selecting measures proportionate to the nature, remediation proposals to clarify that the order of the measures severity and persistence of identified should be specifically explained and justified to the deficiencies, while preserving the necessary respective institution. flexibility to address institution-specific circumstances. Moreover, paragraph22 already More structured, Few respondents encouraged a more structured, envisages the identification of the full escalation transparent and transparent and predictable use of supervisory path when selecting supervisory actions, taking predictable use of measures, including a clearer articulation of escalation into account the information available and the mechanisms and their role within the overall SREP
FINAL REPORT ON THE REVISED SREP GUIDELINES
supervisory framework. It was further proposed to add more nature, size and complexity of the institution, as measures clarity on the alignment of this escalation framework well as the severity of the deficiencies. with existing governance and remediation practices.
Respondents mentioned cases where different teams The EBA notes these concerns. It is clarified that Centralisation of Paragraph 49 has within the same authority (e.g. supervisory teams, on- the revised SREP GL position the SREP as the supervisory been expanded to site inspections, horizontal teams) investigate the overarching process integrating all supervisory activities and encompass all same or overlapping topics, hence the need to ensure outcomes (including on-site inspections, escalation supervisory that decisions regarding such topics are centralised to horizontal reviews and internal model information at activities and to avoid multiple supervisory actions for the same issue. assessments) with the aim of ensuring colleges enable a coherence A respondent noted that for cross-border groups, consistent feedback to institutions and avoiding assessment by the supervisory colleges should play an active role in fragmented supervisory actions. Paragraph 49, competent avoiding contradictory signals and ensuring that which requires competent authorities to authorities. escalation decisions and measures are coherent across coordinate SREP activities with all parties levels of consolidation. involved in the assessment, has been expanded to facilitate a coherence assessment.
In relation to cross-border groups, paragraph 6 requires that procedural requirements be applied in a coordinated manner within the framework of supervisory colleges in accordance with Articles 51 and 116 of the CRD, with Title 10 setting out the applicable arrangements in detail. Therefore, on this point, the existing provisions are considered sufficient.
FINAL REPORT ON THE REVISED SREP GUIDELINES
Alignment with Respondents mentioned cases where the escalation It is acknowledged that supervisory priorities Paragraph 22 has supervisory progressed quite rapidly (on ESG), partly due to its can inform focus and timing and preserve been amended to priorities and link alignment with supervisory priorities. However predictability. However, supervisory measure embed with other supervisory priorities are not included as a selection should remain risk-based. For the consideration on activities and consideration in paragraph22 for selecting the purposes of paragraph 22, supervisory priorities timely remediation measures appropriate measure. Respondents also suggested to can be taken into account, while the need to of identified clarify whether the escalation framework also applies timely remediate has been added. It is clarified, efficiencies. outside the SREP context e.g. onsite inspections. A in line with paragraph 21(c), that capital-based respondent proposed to ensure a clear distinction and measures form part of the escalation framework a coherent interaction between escalation measures and may be used where the nature or severity of and capital-based requirements to preserve the deficiencies warrants prudential reinforcement. consistency of the SREP framework and to avoid Paragraph23 also clarifies that all available unintended double counting. quantitative and qualitative measures should be used by the competent authorities in a way that allows to best address the risk level and/or deficiencies. It is also clarified that SREP is considered an ongoing process that integrates the outcome of all the supervisory activities and all available sources of information into a comprehensive supervisory overview of an institution (please refer to paragraph13). However, the high-level escalation framework does not prevent competent authorities from taking immediate supervisory measures arising directly from other supervisory activities whenever those activities reveal material deficiencies that require prompt action (please refer to paragraph24).
FINAL REPORT ON THE REVISED SREP GUIDELINES
Time to remediate A respondent proposed to emphasise that supervised The revised SREP GL already emphasise a No change institutions shall at all times have sufficient time to proportionate and risk‑based supervisory remediate any findings. approach, under which escalation measures should reflect the nature, severity and persistence of deficiencies and the institution’s demonstrated ability to remediate them in a timely manner.
Application of A respondent noted that part of the wording in The EBA clarifies that the escalation framework Paragraph 22 has supervisory paragraph22 and 23 could be understood as is principle‑based and risk-focused and that been amended to measures and supervisory measures should be applied in accordance supervisory measures should be appropriate and embed escalation path with the maximum principle rather than to the extent commensurate with the nature, severity and consideration on necessary and appropriate in each specific case. It was persistence of identified deficiencies. The timely remediation further noted that it is not always necessary to identify measures are selected based on supervisory of identified an escalation path from the outset. Other respondents judgement informed by the considerations listed efficiencies. argued that the selection of measures should not in paragraph22. Proportionality considerations depend on the category (nature, size and complexity) guide the intensity, scope and frequency of of the institution, which is relevant only for the supervisory engagement however, they should frequency and engagement intensity of the not limit the supervisor’s ability to act where assessment, hence the deletion of the related wording material deficiencies are present. from paragraph22. Supervisory measures should be based only on the characteristics and materiality of the deficiencies, maintaining a risk-focused dimension. Another respondent suggested to add further clarity on how proportionality should guide escalation
FINAL REPORT ON THE REVISED SREP GUIDELINES
choices for institutions with different risk profiles or SREP categories.
Role and impact A respondent proposed to provide more information Within the escalation framework, No change of institution self- on the role and impact (if any) of the self-assessment self‑assessments provided by institutions could assessment of the institution in the enhanced supervisory serve as useful inputs to the supervisory dialogue. analysis, supporting the understanding of the institution’s risks evaluation, remediation progress and prioritisation. It could be part of the enhanced dialogue to inform supervisory judgement on the nature and materiality of deficiencies and on the sequencing of measures, without altering the supervisor’s responsibility to form an independent view under the escalation framework.
Q5. Do you consider the coverage and level of detail of Title 3 appropriate for its intended purpose?
Tailoring of Some respondents suggested that the minimum set of Proportionality is covered at high-level in No change indicators indicators and thresholds should be tailored to each paragraph53. The framework strikes a balance category of institution (1 to 4), and further examples between minimum harmonisation and flexibility, should be added for instance, on governance, by identifying the main categories and types of operational resilience, DORA‑related and risk indicators while leaving flexibility to design macroeconomic indicators. and adjust as needed, including to reflect proportionality.
FINAL REPORT ON THE REVISED SREP GUIDELINES
Supervisory Some respondents expressed concerns about The revised SREP GL are clear that material No change response mechanical supervisory reactions and emphasised that changes to the indicators should prompt an indicators should serve as early‑warning tools analysis of the causes rather than automatic supporting supervisory dialogue and holistic responses. assessment, and not as automatic triggers for score downgrades, escalation or capital add‑ons without institution‑specific analysis.
Transparency Some respondents requested more transparency on Title 9 of the revised guidelines already No change key risk indicators, benchmarks and monitoring envisages a dedicated section devoted to the concepts (e.g. on what constitutes a ‘material change’ communication of the SREP assessment, and an ‘anomaly’) to support consistency and help comprising all the relevant information that maintain a level playing field across competent competent authorities are expected to share authorities. Some recommended that competent with institutions as a basis for an enhanced authorities should systematically communicate supervisory dialogue. indicators and benchmark results to institutions to ensure consistency and a level playing field.
Review for Need for regular review, back‑testing and feedback To ensure supervisory effectiveness, it is Paragraph 50 has effectiveness loops for indicators and benchmarks, especially where important to clarify that the monitor indicators been amended to they influence risk scores, with respondents asking are subject to regular review to ensure they include regular supervisors to periodically reassess indicator maintain their relevance. review and update relevance, learn from cases where indicators prove of indicators where misleading, and adjust monitoring methodologies necessary. accordingly.
FINAL REPORT ON THE REVISED SREP GUIDELINES
Q6. Do you consider the coverage and level of detail of Title 4 appropriate for its intended purpose?
Examples of Some respondents suggested removing the illustrative While the reference was intended for illustrative Paragraph 56 has acceptability of reference to return on equity and cost of equity when purposes only, it is acknowledged that it may been amended. returns assessing the acceptability of an institution’s returns. not be fully exhaustive in all cases. Therefore, it They argued that the assessment should focus on the has been removed from paragraph 56. safety and soundness of the institutions rather than on value generation above a hurdle rate, advocating a more principles-based approach instead of prescriptive metrics. They also noted that the calculation of cost of equity can vary across methodologies and institutions, leading to inconsistencies. Additionally, institutions may face one-off events or restructuring in certain periods, which can affect profitability.
Recovery and Some respondents argue that, by their nature, recovery The informative role of recovery and resolution No change resolution plans in and resolution plans are not intended to reflect an plans, as one of the many sources of BMA institution’s normal or forward-looking business model. information, has been retained from the They therefore consider that their current informative previous version of the Guidelines. The intention role within the BMA is not fully appropriate and should is to make use of all available and relevant be reconsidered. With regard specifically to the information to inform the BMA assessment, outcome of the resolvability assessment, respondents without prescribing any mechanical manner in noted that this is expected to affect the calibration of which such information should be used. For MREL or subordinated MREL, rather than the P2R/P2G example, a recovery plan may identify potential capital stack, and should therefore be taken into vulnerabilities in certain institutions’ portfolios that could usefully inform supervisors’ focus on
FINAL REPORT ON THE REVISED SREP GUIDELINES
account in that context. They accordingly advise against the business model assessment. Likewise, where the proposal. the resolvability assessment may lead an institution to adjust certain aspects of its business model, such as its funding structure in order to comply with MREL requirements, competent authorities should be aware of this in the context of the SREP assessment. The current wording does not imply any impact on the setting of capital requirements.
Use of prior Respondents supported the more explicit reference to The EBA considers that the current wording on Paragraphs 62 and assessment as a the possibility of relying on prior or existing the use of prior assessments to define the scope 63 have been baseline in case of assessments in cases of non-material changes to and depth of the BMA is already sufficiently amended. limited changes to institutions’ BMA. However, they suggested further comprehensive. It appropriately balances the the institution’s clarifying the wording to more explicitly steer need for competent authorities to form a view business model competent authorities toward using previous on the overall viability and sustainability of an across different assessments. Additionally, some wording suggestions institution’s business model, while avoiding SREP cycles were proposed for the elements to be considered in the undue burden on institutions where no material materiality assessment under paragraphs 62 and 63. changes have occurred. Therefore, no changes are made in this respect. Wording suggestions relating to the materiality assessment under paragraphs 62 and 63 have been incorporated.
Operational Some respondents suggested that dependencies on It is clarified that competent authorities are Paragraph 65 has resilience in BMA third-party service providers, including ICT providers expected to assess the nature and governance been amended. and other critical service providers, are an integral and of third-party dependencies — distinguishing strategic component of the operating model rather between dependencies that are strategically than an inherent weakness of the business model. They embedded, appropriately managed and subject
FINAL REPORT ON THE REVISED SREP GUIDELINES
therefore considered that the BMA should clearly to appropriate controls, and those that are distinguish between unmanaged or excessive unmanaged, concentrated or insufficiently dependencies, on the one hand, and dependencies that mitigated — rather than treating dependency as are appropriately governed, diversified and mitigated an inherent weakness per se. A short through robust third-party risk management and clarificatory sentence to that effect has been operational resilience frameworks, including those added in paragraph 65. implemented under DORA, on the other hand.
Crypto assets in Some respondents suggested removing references to As engaging in crypto-asset activities may No change BMA crypto-assets from the BMA, as these are already represent a change in an institution’s business covered in other sections of the Guidelines. profile, the current high-level reference has been retained as potentially relevant to the BMA. It is further noted that amended Article 98 of the CRDVI requires competent authorities to assess institutions’ governance and risk management processes for crypto-asset exposures and the provision of crypto-asset services, including by considering institutions’ policies and procedures for identifying risks, as well as the adequacy of the results of the assessments.
Geopolitical Respondents welcomed the inclusion of geopolitical The introduction of geopolitical factors among Paragraph 68 has factors inclusion factors within the scope of the BMA. However, they those that can materially affect institutions’ been amended. called for more specific guidance and examples in business model is meant to be kept at a high order to avoid making the assessment of those factors level at this stage to leave room for a flexible overly subjective. It was also suggested to address it as approach by competent authorities as those geopolitical ‘risk’ rather than ‘factor’. Finally, factors may – by their very nature – materialise
FINAL REPORT ON THE REVISED SREP GUIDELINES
respondents proposed that, when assessing such risks, in different manners and impacting institutions potential mitigating elements should be taken into and jurisdictions in very specific manner. The account, such as an institution’s capacity to withstand term ‘risk’ has been used instead of ‘factor’ in these uncertainties, for instance through the relevant paragraph, and a reference to the diversification of its geographic footprint and business elements that may influence how this risk profile. affects the business model has been added.
Time horizon and Respondents suggested linking the BMA time horizon As the title already refers to those processes as No change proportionality in more explicitly to the time horizons already used in relevant sources of information for the BMA, BMA institutions’ operating environment, with strategic the link is already reflected in the text. This has plans, ICAAP/ILAAP and recovery plans typically been further reinforced through the explicit covering a three- to five-year period. introduction of the possibility for competent authorities to rely on previous assessments In addition, they suggested that competent authorities and to focus only on material changes, where should focus their assessment on the most material these have occurred. areas and, where there is clear evidence that no material change has occurred, be able to rely on Paragraph 62, as well as the background and previous supervisory assessments as a baseline. This rationale, already explicitly allows prior was considered helpful in promoting risk-based supervisory assessments to be used as a supervision and reducing unnecessary burden. baseline for the BMA where no material changes have occurred since the previous SREP cycle, provided that materiality has been duly assessed.
Interplay between The BMA should be appropriately articulated with the A non-exhaustive list of potential supervisory No change BMA and other ICAAP, ILAAP, governance and operational resilience measures is already included in the Guidelines. SREP elements, frameworks so as to avoid duplication or double The purpose of the table is to summarise, in an supervisory indicative manner, the supervisory measures
FINAL REPORT ON THE REVISED SREP GUIDELINES
measures counting of risks, for example in the context of ESG that may arise from the BMA in accordance with potentially assessments or stress testing. the existing supervisory powers provided for in stemming from Article 104 of the CRD. The aim is to ensure a the BMA common baseline for competent authorities, without expanding the powers conferred by the CRD or creating any obligation for competent authorities to apply specific measures where a particular circumstance arises.
Assessment of Some respondents urged either the provision of further The qualitative elements of the BMA have been No change qualitative BMA guidance or the removal of the more qualitative maintained, as they are needed to complement elements elements of the BMA, such as assessments of the the quantitative assessment and to ensure a competitive dynamics of the business environment or sufficiently comprehensive view. Quantitative execution-related considerations, in order to avoid indicators alone may not fully capture certain overly judgement-driven concepts. They also raised aspects of the business environment, execution concerns about areas in which metrics or scenarios capacity or emerging risks. In this context, a remain insufficiently mature in terms of quantification degree of expert supervisory judgement remains and precision, such as environmental scenario analysis, necessary, particularly in relatively new areas AI-related risks and other emerging non-financial risks where methodologies and metrics are still and considered that greater clarity would be needed to evolving. The intention is not to promote an support consistent outcomes. unduly judgement-driven approach, but to allow competent authorities to combine quantitative evidence with qualitative assessment in a proportionate and informed manner.
Q7. What are the respondents’ views on the updated section 5.7 ‘ICT systems, risk data aggregation and risk reporting’?
FINAL REPORT ON THE REVISED SREP GUIDELINES
Clarifications on Some respondents requested further clarity on certain It is clarified that all terms are already used and No change terminology terminologies to reduce subjectivity and to better stem directly from the CRD and/or other EBA frame the assessment: Guidelines. • risk awareness (paragraph85c) • appropriate understanding (paragraph83c) • sufficient knowledge and skills (paragraph83c) • through regular training (paragraph83c) • other emerging risks (paragraph83c)
Assessment A respondent requested further clarity on the exact Section 5.7 already sets out the core elements of No change criteria to ensure requirements to ensure the ‘appropriateness of ICT this assessment. The requirements are ‘appropriateness systems, data aggregation, and risk reporting’. comprehensively addressed in the EU legal and of ICT systems, regulatory framework (e.g. the CRR/CRD, DORA, data aggregation, EBA GL) and the SREP GL do not duplicate those and risk reporting’ provisions but assess, from a prudential perspective, whether institutions effectively implement them. The SREP GL build on the existing legal requirements and do not intend to change or limit these requirements.
Role of A respondent proposed to remove the reference of The revised SREP GL distinguish between the Paragraph 101 has management ‘senior management’ from paragraph104 as only the approval of the risk data aggregation and risk been amended to body in the risk management body can take decisions. Another reporting framework, which rests with the clarify the role of data aggregation respondent proposed to replace the word ‘validated’ management body, and its implementation, the management and risk reporting in paragraph104 with the word ‘reviewed’ as it does maintenance and ensuring its effective body and the framework not refer to validation activities in the strict sense. operation, responsibility of the senior independent management. It is therefore clarified that validation in reference to ‘senior management’ in accordance with the
FINAL REPORT ON THE REVISED SREP GUIDELINES
paragraph101 did not assign decision-making institution’s internal authority but reflected its implementation role, control framework. in line with the CRD provisions. It is further clarified that the validation of the risk data aggregation capabilities and risk reporting practices should be independent to ensure that risk data aggregation and reporting processes are functioning as intended and are appropriate for the institution’s risk profile. These activities should be aligned and integrated with the other independent review activities within the institution’s risk management framework.
Alignment with In relation to paragraph92(g), some respondents noted It is clarified that the revised SREP GL, consistent No change DORA/ICT strategy potential duplication of strategies and governance with their principle‑based nature, do not require complexity as (i) it was understood that no separate institutions to produce separate or additional document on DORA/ICT strategy would be required as information/reporting where existing long as the requirements could be evidenced within governance arrangements already demonstrate existing or other strategies and (ii) DORA only requires compliance. In this regard, Article 6(8), points (a) the institutions to be able to describe how the DOR to (h), of DORA specify the elements that the strategy supports their business strategy. digital operational resilience strategy shall include. Specifically, Article 6(8)(a) requires institutions’ ICT risk management framework to include a digital operational resilience strategy setting out how the framework shall be implemented. The digital operational resilience strategy shall explain how the ICT risk management framework supports the
FINAL REPORT ON THE REVISED SREP GUIDELINES
institution’s business strategy and objectives. Moreover, Article 6(9) of DORA provides additional details in case institutions include (within the strategy) an ICT multi-vendor strategy. It is further noted that the EBA Guidelines on ICT risk assessment under the SREP (EBA/GL/2017/05) already envisaged the assessment of the alignment between the ICT strategy and the business strategy due to the strong links between the two. ICT-specific view A respondent noted that the newly added sub-chapter It is clarified that sub-section 5.8 of the revised No change for sub-section 5.8 5.7 will also require institutions to provide an ICT- SREP GL covers, among other elements, the specific view even for risk types covering ICT and non- assessment of the reliability, resilience and ICT aspects. adequacy of ICT systems insofar as they support the institution’s risk data aggregation and risk reporting.
Addition of Two respondents proposed to add operational The proposals go beyond the level of No change operational clarifications/examples and, where feasible, indicative principle-based guidance envisaged for the SREP clarifications benchmarks in relation to risk data aggregation and GL. Moreover, this revision aims to reduce overrisk reporting, including supervisory expectations (e.g. prescription and to refrain from detailed data governance framework, data architecture, data operational specifications. This would preserve management and data governance, data quality the appropriate flexibility for the CAs, avoid management, timeliness, testing of continuity and unintended compliance burden to the recovery, governance and monitoring of third-party institutions and remain consistent with the arrangements), guidance on escalation protocols, and objectives of the SREP GL. further references to documentation standards and evidence requirements.
FINAL REPORT ON THE REVISED SREP GUIDELINES
References to A respondent proposed to reduce the level of No change Paragraph 81 reflects the requirements of mapping of duties granularity of paragraph84, in particular by removing Article 74 of the CRD, which mandates robust and individual references to the mapping of duties and individual governance arrangements, including clear statements statements, to avoid the creation of additional allocation of responsibilities. The mapping of documentation layers that do not materially enhance duties and individual statements of supervisory outcomes. It was further noted that any responsibilities are tools to operationalise this expectation to maintain these mappings or statements requirement. The SREP GL build on the existing at consolidated level exceeds the scope of the CRDVI legal requirements and do not intend to change and would generate disproportionate burdens for or limit these requirements nor to add further complex groups. documentation layers beyond what the legal
framework requires.
On the concern regarding consolidated
application, the SRER GL apply in accordance
with the scope of consolidation set out in the
CRDVI. Competent authorities retain supervisory
judgment in assessing proportionality, including
for complex groups, in line with the general
proportionality framework set out in Title 2. No
amendment is made.
References to A respondent proposed to closer align paragraph90 The EBA welcomes the proposal to fully align Paragraph 87 has
function assesses and mitigates compliance risk. which supports one of the objectives of this
revision, the alignment with the latest
regulatory developments such as the CRDVI.
FINAL REPORT ON THE REVISED SREP GUIDELINES
Reference to Another respondent proposed explicitly referring to The Guidelines remain principle-based and Paragraph 100 has common key risk data aggregation and risk reporting standards anchored to the applicable EU legislation. It is been amended to standards on risk commonly considered (e.g. BCBS 239) to support a noted that while BCBS 239 principles are refer to the BCBS data aggregation common understanding of supervisory expectations applicable to global systemically important 239 for the and risk reporting and promote consistent supervisory assessment. banks, related expectations have been already institutions that set by competent authorities (where deemed under fall their necessary) as robust internal governance and scope. effective processes to identify, measure, manage and monitor all material risks are expected by all the institutions. According to the ICT SREP GL, for managing material ICT data integrity risks, institutions that fall under the scope of the BCBS 239 principles should assess their risk reporting and data aggregation capabilities against those principles and maintain appropriate supporting documentation. A footnote has been added to clarify this point.
Types of A respondent suggested the review of paragraph100 It is clarified that paragraph 97 refers specifically A footnote has been institutions’ stress as it may be currently implied that all types of stress to conventional adverse scenarios used for added in paragraph testing testing should be considered, which might contradict capital adequacy assessments, in line with Title 97. the expectations of reverse stress tests. 7, and does not extend to reverse stress tests, which aim to identify scenarios that would render the institution unviable rather than to test ongoing compliance with capital requirements. Delegated Respondents noted that paragraph232(c) does not It is clarified the revised SREP GL do not prohibit Paragraph 229(c) responsibilities recognise that the management body may delegate delegation to committees, where these apply, has been amended
FINAL REPORT ON THE REVISED SREP GUIDELINES
some of its responsibilities for follow-up and response and are fully aligned with the EBA Guidelines on to refer to critical to audit findings, nor does it consider the materiality Internal Governance. In particular, paragraph ICT audit findings. of audit findings in question. It was therefore 151 of those Guidelines clarifies that the proposed to amend it as follows: ‘adequate follow-up management body should follow up on the and response by the management body or its findings of the internal control functions in a delegates on material ICT related audit findings and timely and effective manner and require findings reported under Article 13(5) of DORA’. adequate remedial actions. Furthermore, paragraph 45 of same GL clarifies that committees should support the supervisory function in specific areas and facilitate the development and implementation of a sound internal governance framework. At the same time, delegating to committees does not in any way release the management body in its supervisory function from collectively fulfilling its duties and responsibilities. The reference to ‘ICT audit findings’ has been slightly adjusted to fully align with Article 6(7) of DORA.
Contractual A respondent proposed to clarify that contractual Contractual requirements on third-party services No change arrangements matters should be addressed separately under DORA. are comprehensively addressed under DORA Another respondent requested enabling the and the upcoming EBA Guidelines on the sound competent authorities to recognise and consider the management of third-party risk management. use of standardised contractual terms on operational The SREP GL do not duplicate those provisions resilience as reliable evidence of resilience for but assesses, from a prudential perspective, third‑party dependencies supporting critical or whether institutions effectively implement and important functions. It was further proposed to manage them within their overall risk harmonise risk oversight through accredited audit management framework.
FINAL REPORT ON THE REVISED SREP GUIDELINES
regimes based on agreed auditing standards, which could be developed jointly by the ESAs-ENISA.
The SREP is inherently risk-based and relies on Taxonomy for A respondent suggested introducing a shared No change supervisory judgement, taking into account the deficiencies supervisory taxonomy for deficiencies considered in specific risk profile, size, and complexity of each paragraph 80. institution. Introducing a common taxonomy could unduly constrain this judgement and risk oversimplifying supervisory findings. Furthermore, the existing framework already provides sufficient guidance to ensure an appropriate level of consistency and comparability across competent authorities, while preserving the necessary flexibility. A predefined taxonomy could incentivise a more mechanical or ‘box-ticking’ approach and reduce the forward-looking nature of supervisory assessments. Lastly, the introduction of such a taxonomy would increase operational complexity with uncertain evidence of commensurate benefits in terms of supervisory convergence or effectiveness.
Q8. Do you consider the coverage and level of detail of Title 6.2 appropriate for its intended purpose?
Proposed credit Respondents suggested that the proposed taxonomy As noted at the beginning of the feedback table, No change risk taxonomy should be more economic and consistent with others the risk sub-categorisations set out in the Annex used in supervisory practice. The fact that ensuring are intended to serve as guidance for competent
FINAL REPORT ON THE REVISED SREP GUIDELINES
greater alignment and clearer mapping principles authorities and to further promote consistent would help institutions reconcile classifications across risk identification across authorities, while frameworks (e.g. ICAAP, including diversification remaining non-exhaustive and flexible. effects) was hinted at.
Practical guidance Respondents noted that the inclusion of dilution risk While dilution risk has indeed been added to No change on new/expanded and the expanded wording on model risk for approved the list of credit risk sub-categories, this is items regulatory models would benefit from brief practical already qualified in the Level 1 text. The guidance on supervisory expectations in the wording on model risk for approved regulatory assessment. This would support supervisory models has not been expanded in the credit convergence and facilitate implementation by risk section. On the contrary, its relevance is institutions. A question was also raised as to whether expected to diminish in light of the output specialised lending should be treated as a separate floor provisions set out in Title 7. sub-category of credit risk. Specialised lending remains a relevant element of the assessment, particularly where it is considered material. However, it is viewed more as a specific type of transaction giving rise to credit risk than as a distinct category of credit risk in its own right. This is why it is addressed in the relevant credit risk section but not included as such in the list of credit risk sub-categories.
Reference to the Respondents suggested removing the reference to the It is acknowledged that, since the handbook is Paragraph 124 has IRB EBA EBA Supervisory Handbook on IRB validation of addressed to competent authorities, an indirect been amended. Supervisory internal ratings-based systems from the table in reference to compliance checks from an handbook for the paragraph 127, as it is not applicable to institutions. institution’s perspective should not be included. validation of
FINAL REPORT ON THE REVISED SREP GUIDELINES
internal ratingsbased systems
Use of internal A respondent suggested that paragraph 136 should The paragraph already includes a statement (‘As No change credit risk refer primarily to IRB institutions and that the text additional source of information for the parameters for should be amended accordingly. materiality assessment, competent authorities the materiality should – where available and appropriate – assessment of consider the internal credit risk parameters used credit risk by the institution […]’) that allows competent portfolio authorities to use this information where it is more relevant.
Q9. Do you agree with the treatment proposed to account for transfer pricing risk in the context of trading book activities? Please elaborate.
General feedback Some respondents supported the proposal to The costs and benefits of introducing a new No change on the new introduce a new approach to address the market risk approach to support supervisors’ assessment of approach to of transfer pricing arrangements (TPA) based on a TPA risks have been analysed and set out as part transfer pricing transaction profit method, including a formula for of the EBA consultation. It was concluded that arrangements determining a P2 capital requirement. They supported the proposed approach promotes consistency ensuring that material risks are adequately capitalised, across supervisory practices and establishes a and depositor funds and investor capital are protected level-playing field between institutions directly from hidden risks and losses. Others challenged a capitalising their market risk as part of a Pillar 1 prescriptive approach with a fixed formula, noting that capital requirement and those institutions that applying supervisory judgement would ensure bear the risk but have no capital against it. The proportionality and avoid unintended capital fact that the TPA are agreed with governments increases. Concerns about commercial impact on via APA does not change the risk embedded in advance pricing agreements (APAs) negotiated such agreements.
FINAL REPORT ON THE REVISED SREP GUIDELINES
between banks and governments, which are based on As regards the concern on using a prescribed expectations about where capital and risk reside. formula for the measurement, the SREP GL set
out, in paragraph 174, point (c), that ‘competent
authorities may use […] an alternative
methodology that provides accurate
measurement of the risk not covered in P1R and
identifies the consequent P2R, considering as a
reference the methodology in Annex V.’
Limited adjustments made to clarify that other Risk capture and Some respondents observed that the adjustment The first and second types of TPA similarly transferring losses to the measurement should be risk‑based, TP‑method‑agnostic and limited paragraphs in EU entity should be assessed in a similar way; and to residual risk borne by the EU entity; or expressed Annex V have been to confirm that the 1.5 multiplier, which concern about double counting with Pillar 1 market amended. addresses differences in the market risk rules risk and other regulatory requirements (e.g. between the EU and the third country, can be intra‑group exposures); or asked to have flexibility to adjusted to reflect the materiality of these reduce the 1.5 multiplier when the differences in the differences. As regards the risk measurement, market risk rules between the EU and the third the approach described in the GL already aims to country are not significant. One respondent suggested target the loss that may crystallise in the EU having a Pillar 1 requirement. entity. Any double counting is expected to be
assessed as part of the overall SREP.
Further Some respondents suggested clarifying further the The approach should be considered in the No change
clarifications supervisory expectations (e.g. in relation to broader context of other GL or requirements on
governance, documentation), and having examples governance, documentation, etc.
and illustrative scenarios.
FINAL REPORT ON THE REVISED SREP GUIDELINES
Q10. What are the respondents’ views on the integration of the EBA GL on ICT risk assessment under the SREP (EBA/GL/2017/05) and DORA aspects?
ICT risk as part of Respondents argued that the revised GL should not The structure of the SREP GL reflects the Explanatory text has OpRisk duplicate efforts of activities within the overall assessment of ICT risk within the operational risk been added in the operational risk management framework, of which ICT framework, along with related linkage to ‘Background’ risk represents a key, but not exclusive component. It internal governance (reflecting DORA) and risk section to further was hence recommended that the ICT risk maintains data aggregation aspects. This cross‑referencing clarify that within its normal weight within operational risk. Other is intended to ensure that ICT considerations are the EU regulatory respondents noted that ICT risk is covered repeatedly integrated consistently across the relevant SREP framework, ICT risk throughout the SREP GL and welcomed a elements, in line with the holistic assessment is part of rationalisation. At the same time, another respondent approach central to the SREP GL. operational risk, strongly argued for the reclassification and recognition The revised SREP GL reflect the applicable EU and DORA of ICT risk (including digital resilience) as a primary and legal framework: Article 4(52) of the CRR strengthens its independent non-financial risk (NFR) and hence the includes ICT risk under operational risk, and prudential development of the new Title dedicated to ICT risk. DORA (recital 12) specifies that ICT risk treatment through This could guarantee the relevance of ICT risk, its requirements are consolidated and upgraded as digital operational alignment with DORA and other EU-level part of the operational risk requirements. resilience regulations/strategies, and its consistency with Moreover, the DORA Directive amends the requirements. specialised supervisory groups. prudential framework by making ICT risk an Together these explicit component of the SREP. It is further contribute to the Interconnection of Respondents requested more clarity on the noted that ‘Title 6.4 – Assessment of operational broader objective of DORA, ICT risk and interconnection of DORA, ICT risk and operational risk’ of the revised SREP GL explicitly embeds operational operational resilience, for example in the form of a consistent DORA into the ICT risk assessment, replacing and resilience resilience taxonomy. Other respondents noted the need for integrating the separate ICT SREP GL and further clarification on how DORA-based assessments aligning expectations with applicable legislation. can be leveraged to inform or partially substitute It is further noted that CAs are expected to take existing ICT and operational risk evaluations under the into account relevant supervisory findings and
FINAL REPORT ON THE REVISED SREP GUIDELINES
SREP to reduce unnecessary duplication and ensure assessments conducted under DORA as part of supervisory focus on material risk drivers their SREP/ICT risk assessments, thereby avoiding unnecessary duplication while maintaining a comprehensive evaluation of material risks. This approach ensures that DORAbased supervisory work informs SREP outcomes where appropriate, consistent with the riskfocused and proportionate supervisory objectives of the revised SREP framework. Operational resilience, which constitutes an integral element of the robust governance arrangements and adequate internal control mechanisms required under Article 74 of the CRD, is considered as an outcome, not risk category, a cross-cutting capability that sits above existing risk frameworks. Operational resilience does not replace operational risk; it extends it beyond loss prevention into service continuity. Therefore, the institution’s frameworks on operational risk, ICT risk and third-party risk management should be used as inputs into a broader resilience evaluation. The operational risk sub-categories (Annex III) already cover ICT risk and third-party risk, which constitute the foundational layers upon which operational resilience is built.
FINAL REPORT ON THE REVISED SREP GUIDELINES
Unimprovable ICT The EBA takes note of these cases, and it is No change A respondent mentioned cases where subsidiaries risk score to clarified that under the revised SREP GL, were provided an unimprovable ICT risk score due to subsidiaries competent authorities may assign different perceived risk associated with being a subsidiary. It categories to the group subsidiaries and/or was noted that subsidiaries retain the autonomy to consolidated entity (section 2.1.1). The implement additional internal controls and assessment at subsidiary level should cover arrangements if necessary to comply with local whether group-wide policies and procedures are regulatory requirements, where relevant in alignment implemented consistently and whether group or consultation with the parent company. entities have taken appropriate measures to Another respondent argued for the SREP GL to ensure that their activities are compliant with all adequately recognise how cybersecurity risk is applicable laws and regulations. In the case of effectively managed in cross‑border groups, where subsidiaries of a cross-border group, competent centralised policies, expertise and incident‑response authorities should consider subsidiaries on an capabilities often strengthen ICT risk management. individual basis and the findings from initial Caution was raised against treating subsidiaries as assessments should also include the inherently higher‑risk or requiring full subsidiarisation identification of key vulnerabilities in the crossof ICT controls, and proposed a more nuanced border or group context and reflect strengths assessment that reflects actual dependencies, and mitigating factors related to the entity being centralised mitigants, and the institution‑specific part of the group. The SREP framework does not effectiveness of cybersecurity arrangements. envisage predetermined or structural scores linked to an institution’s position within a group in line with the requirement to continuously assess risks using institution‑specific supervisory judgment and to avoid mechanistic scoring.
Inputs to the SREP Respondents proposed adding further clarification on SREP scoring remains a holistic, expert-based No change score how each ICT-related input impacts the CAs’ risk supervisory judgement that takes into account a assessment and influences the SREP score. It was broad range of quantitative and qualitative
FINAL REPORT ON THE REVISED SREP GUIDELINES
further noted that ICT-related inputs to the SREP could elements. ICT-related inputs are assessed in benefit from industry input and welcomed further context and do not mechanically translate into a engagement with CAs before the assignment of the specific score. The SREP GL do not introduce an SREP scores to avoid misinterpretation and to ensure automatic link between individual ICT indicators proactive communication (cases reported where and the SREP outcome. It is also noted that CAs banks were unaware of risks perceived by the are expected, in line with the existing SREP supervisors and expressed with supervisory letters). framework, to engage in an ongoing supervisory Other respondents noted that significant importance dialogue with institutions, including the is placed on the quantification of ICT risk and the communication of key risk drivers underpinning utilisation of an institution’s reporting metrics (e.g. supervisory assessments. The SREP decision reported incidents, internal reporting) which directly process, including the opportunity for correlates to a higher risk score to larger institutions institutions to provide factual clarifications prior with strong reporting cultures. It was hence to the final decision, is intended to mitigate the recommended to give greater consideration to the risk of misinterpretation and to promote other SREP instruments available to competent transparency. Regarding the quantification of authorities, along with the supervisory experience, ICT risk and the use of reporting metrics, it is which should be considered for the risk score. reiterated that supervisory assessments should consider the effectiveness of an institution’s risk management framework and control environment, including its reporting culture. CAs are expected to consider all relevant supervisory tools and evidence, including qualitative assessments, on-site findings and supervisory experience, when forming their overall judgement and assigning SREP scores.
Capital as mitigant A respondent noted that institutions have developed The revised SREP GL aim to further specify the No change for ICT risk dedicated ICT/cyber risk frameworks that sometimes assessment of ICT risk as a component of
FINAL REPORT ON THE REVISED SREP GUIDELINES
go beyond the traditional operational risk operational risk under Article 85 of Directive management structure. It was proposed that the SREP 2013/36/EU. This assessment will result in a GL to acknowledge this and limit the imposition of summary of findings which, based on a set of additional capital requirements to situations where considerations, will form the operational risk there is evidence of a material and quantifiable score – which will inform among others the prudential risk. It was further mentioned that the determination of additional own funds treatment of ICT risk should primarily focus on requirements. As noted in paragraph 16, ICT risk qualitative measures. may be assessed and scored individually as a sub-category of operational risk if deemed material by the competent authorities. In such a case, the scoring table (table 1) in these Guidelines should be used to reach a score. It is also noted that DORA sets targeted qualitative requirements for the protection, detection, containment, recovery and repair capabilities against ICT-related incidents, as well as reporting and digital testing capabilities, thereby addressing ICT risk prevention, mitigation and recovery in a manner that capital measures alone may not achieve. Proportionality Few respondents indicated the need for further clarity The revised SREP GL clarify that the assessment Paragraph 121 has application on proportionality and supervisory intensity, especially of ICT risk is subject to the overarching SREP been amended. for SNCIs, and the overall application of principle of proportionality, including where proportionality in the ICT risk assessment, primarily on applicable as regards the frequency, scope and the information and tasks requested by institutions depth of supervisory tools. CAs are expected to within a year (e.g. ICT self-assessment questionnaires, calibrate supervisory engagement to the ICT RM review report, onsite inspection, TLPT, cyber institution’s size, business model, risk profile and stress test participation). Another respondent noted systemic relevance, thereby avoiding undue
FINAL REPORT ON THE REVISED SREP GUIDELINES
that reinforcing proportionality in the application of burden and ensuring a focus on material risk ICT expectations would also help maintain a clear drivers. In addition, DORA itself embeds a distinction between prudential issues and issues falling proportionate application of its requirements, under the broader compliance with DORA. taking into account the institution’s size, overall risk profile and the nature, scale and complexity of its services and activities. The integration of DORA elements within the SREP therefore builds on this existing proportionality framework.
Assessment of Some respondents proposed to amend paragraph197 It is noted that paragraph194 stems directly Paragraph 194 has materiality of as it would be more appropriate for the competent from the previous SREP GL (paragraph273) been adjusted along operational risk authorities to assess the institution’s approach to where ‘competent authorities should assess the with explanatory arising from third- determining the materiality of operational risk arising materiality of operational risk arising from text in the party providers from third-party providers. For the same paragraph, a outsourced services and activities’. It is further ‘Background’ respondent requested to clarify the delimitation of the clarified that materiality assessment depends on section references to DORA and EBA GL on third-party risk the supervisory judgement (paragraph116). management to ensure the SREP does not Regarding the delineation of DORA and the unintentionally expand the scope of the upcoming EBA Guidelines on the sound aforementioned frameworks. management of third-party risk, it is clarified that the revised SREP GL do not intend to expand the scope of either framework. The reference to DORA is limited to ICT services provided by ICT third-party service providers, while the EBA Guidelines apply to all other thirdparty services, consistent with the respective scopes of those frameworks. The clarification wording has been moved to the ‘Background’ section while paragraph 194 has been amended.
FINAL REPORT ON THE REVISED SREP GUIDELINES
Third-party risk Some respondents proposed to clarify expectations for Paragraph 194 already refers to a risk-based Paragraph 194 has assessment third-party ICT concentration risk and subcontracting supervisory assessment of operational risk been amended. chain visibility/complexity, and to reinforce arising from third-party service providers. Article supervisory attention to third-party and concentration 3(29) of DORA provides a definition of risk. Another respondent proposed to clarify that concentration risk focused on critical ICT TPPs subcontracting chain complexity should be considered and Article 29 (1) provides further specifications by competent authorities as a contextual factor, rather on the assessment of including concentration than a standalone proxy for concentration risk. risk, as the competent authorities are expected to assess whether institutions adequately identify, measure, monitor and mitigate thirdparty concentration risk, taking into account the institution’s size, business model, systemic relevance and complexity. As per Title 6.4.2.3 and paragraph 216, supervisory assessments are expected to rely on a holistic evaluation of dependency, criticality, substitutability and risk mitigation capacity. Paragraph 194 has been amended to clarify the concentration level and to reinforce supervisory attention to third-party concentration risk.
Risk-based and A respondent strongly proposed the application of a In line with the principle‑based design of the No change proportionate risk-based and proportionate approach in the SREP (Title 2) and also paragraph 194, approach in the assessment of third-party risk, focusing on supervisors assess risks arising from third‑party assessment of dependencies that could affect critical or important providers to the extent relevant for the third-party risk functions and deprioritize low impact support services. institution’s prudential profile and particularly
FINAL REPORT ON THE REVISED SREP GUIDELINES
It was further noted that the assessment of non-ICT where these affect critical or important third-party risk should in practice not lead to an overly functions. The revised SREP GL enable broad supervisory focus given the non-material impact competent authorities to rely on work of most non-ICT third party services to institutions. It performed under other supervisory activities was proposed to explicitly exclude from the and the broader SREP provisions on leveraging assessment functions that are either legally required other supervisory evidence. It is further noted to be performed by a third-party provider or are that the scope, definitions, assurance/audit typically performed by a supervised entity and are not requirements applicable to ICT and non‑ICT regularly carried out by the institutions themselves or third‑party arrangements, along with their provided by other institutions or licensed financial respective proportionality application, are set entities. Moreover, it was proposed that third-party directly in the relevant legal/regulatory audits should be leveraged in a standardised and frameworks (DORA and upcoming EBA GL on the widely recognised format, preferably aligned with the sound management of third-party risk), and are established frameworks such as ISO certification, as not established by the SREP GL. this would reduce unnecessary costs without jeopardising industry-wide resilience.
Incident reporting A respondent requested further clarity on how major It is clarified that paragraph 205 refers to Article No change and cyber-threats ICT-related incidents and remediation maturity 17(2) of DORA where financial entities are influence scoring and escalation. Some respondents required to record all ICT‑related incidents and noted that paragraph208 refers to competent significant cyber threats as part of their authorities using reports of significant cyber threats as ICT‑related incident management process. a source of information. However the reporting of Therefore, in the context of the SREP, significant cyber threats is performed on a voluntary competent authorities could draw on the basis under DORA and may not be available to all information that institutions are already competent authorities, hence it was proposed to required to maintain internally. This does not imply, nor should it be interpreted as, a requirement for institutions to submit or
FINAL REPORT ON THE REVISED SREP GUIDELINES
clarify this may be a source of information where proactively transmit those records on threats to available. competent authorities. Clarifications and A respondent encouraged greater considerations of It is clarified that paragraph 214 provides a No change wording the factors competent authorities should take into non‑exhaustive set of elements that competent alignment account to assess inherent ICT risk (as listed in authorities should consider where relevant paragraph216) and to provide further detail in when identifying the materiality of inherent ICT explaining why those factors relate to risk. It was risk. These factors should not predetermine argued the factors listed in paragraph216 vary widely outcomes, nor be applied in isolation as in impact and may lead to highly subjective supervisory judgement considers the supervisory interpretations. Moreover, it was noted institution‑specific context, including the design that, when reliance is placed on Lead Overseer and effectiveness of the controls in place, the recommendations regarding CTPPs, institution‑specific institution’s dependency structure, and its actual mitigating controls and actual dependency levels may exposure to ICT‑related vulnerabilities. Having be overlooked. said that, references to external inputs (e.g. Lead Overseers’ recommendations) form one source of information and should be assessed together with the institution’s mitigating controls, contractual arrangements, and dependency profile.
Point (i) of paragraph 214 stems from Paragraph 214(i) Some respondents noted that paragraph216(i) could paragraph39(b) of the ICT SREP GL where, in the has been amended benefit from defining the term ‘digital technologies’. context of reviewing an institution’s ICT risk to refer to Moreover, it was proposed to link this point to a profile, competent authorities should consider ‘innovative ICT specific desired outcome otherwise it risks whether the institution may be subject to ICT solutions’. overstepping the boundary of supervisory risks due to high adoption of innovative ICT solutions. It is noted that the term ‘ICT solutions’
FINAL REPORT ON THE REVISED SREP GUIDELINES
responsibility into taking a direct hand in institutions’ is also used in DORA (Article 2). The SREP GL
ICT strategy. have been adjusted on that basis.
It is clarified that the reference to the external Paragraph 214(o)
threat environment in paragraph 214 concerns has been amended
Some respondents proposed to clarify in to refer to threat independent external threat data (e.g. ENISA paragraph216(o) the type of vulnerabilities that can be and vulnerability threat landscape report) that CAs should use to intelligence. used for the SREP. It was further noted that sharing of inform their supervisory assessment and does vulnerabilities outside the institution can pose a not entail disclose of vulnerabilities that could material security risk hence it is proposed that instead pose a security risk. The SREP GL have been the competent authorities should consider the adjusted on that basis. institution’s approach to identifying the external
threat environment.
Paragraph 215 and It is noted that paragraph 215 stems from title in page 89 have paragraph 40 of the ICT SREP GL where CAs been amended Some respondents proposed paragraph 217 to instead should form an opinion on which ICT systems accordingly. require CAs to review the approach that institutions and services are critical for the adequate have taken to determine which ICT systems and ICT functioning, availability, continuity and security services support their critical or important functions. of the institution’s essential activities. Similarly, Some respondents noted that the title, ‘Identification the title in page 89 has been adjusted and mapping of material ICT risks to critical ICT accordingly. systems and ICT services’ on page 89 uses terminology
which is not present in the existing regulatory
framework. It was therefore proposed to amend this
to ‘ICT systems and ICT services supporting critical or
important functions’.
FINAL REPORT ON THE REVISED SREP GUIDELINES
No change
Some respondents proposed adjusting paragraph218 It is noted that paragraph 216 stems from as it would be more appropriate for the CAs to review paragraph 42 of the ICT SREP GL where CAs the institution’s approach to determining the material should form an opinion on the material ICT risks ICT risks to which they are exposed. that, in their supervisory judgement, can have a significant prudential impact on the institution’s critical ICT systems and services.
No change A respondent proposed the deletion of the The reference to ICT risk appetite (already in the parenthesis in paragraph221 – ‘ICT risk appetite and ICT SREP GL) and digital operational resilience digital operational resiliency strategy’ – as the strategy do not narrow the focus of the emphasis on these two elements risks narrowing the assessment but rather clarify in light of DORA, focus from the institution’s overall material risks, which establishes specific requirements for ICT which should form the foundation of its strategy and risk management. ICT risk remains a component risk appetite. of operational risk, and it is assessed within the broader framework of all material risks under the SREP. The amendment aims to ensure alignment with DORA while maintaining the holistic, risk-based nature of the SREP assessment, which continues to be grounded in the institution’s overall material risk profile. Paragraph 226(e) has been amended It is noted that Article 6(a) of DORA requires to fully align with A respondent proposed to further clarify financial entities to test the ICT business the DORA paragraph227 and paragraph229(e) to ensure full continuity plans and the ICT response and framework alignment with DORA, in particular to clarify that recovery plans in relation to ICT systems
FINAL REPORT ON THE REVISED SREP GUIDELINES
institutions maintain their own BCPs when using TPSPs supporting all functions at least yearly. regarding the ICT and in turn TPSPs maintain their own independent Moreover, Article 11(4) of DORA requires BCPs when using resilience frameworks. financial entities to put in place, maintain and ICT TPPs. periodically test appropriate ICT business continuity plans, notably with regard to critical or important functions outsourced or contracted through arrangements with ICT TPSPs. Moreover, Article 25(2) of the Delegated Regulation (EU) 2024/1774 requires that financial entities’ testing of ICT business continuity plans contain the testing of ICT services provided by ICT TPSPs, where applicable, and contain procedures to verify the ability of the financial entities’ ICT TPSPs to respond adequately to the relevant scenarios. Lastly, Article 25(4) of the same Delegated Regulation requires financial entities to consider and implement continuity measures to mitigate failures of ICT TPSPs of ICT services supporting critical or important functions as part of the ICT response and recovery plans.
Paragraph 229(c) has been adjusted It is clarified the revised SREP GL do not prohibit Respondents noted that paragraph232(c) does not to fully align with delegation to committees, where these apply, recognise that the management body may delegate the DORA and are fully aligned with the EBA Guidelines on some of its responsibilities for follow-up and response framework Internal Governance. In particular (paragraph to audit findings, nor does it consider the materiality 151 of those Guidelines clarifies that), the of audit findings in question. It was therefore
FINAL REPORT ON THE REVISED SREP GUIDELINES
proposed to amend it as follows: ‘adequate follow-up management body should follow up on the regarding critical and response by the management body or its findings of the internal control functions in a ICT audit findings. delegates on material ICT related audit findings and timely and effective manner and require findings reported under Article 13(5) of DORA’. adequate remedial actions. Furthermore, paragraph45 of same GL clarifies that committees should support the supervisory function in specific areas and facilitate the development and implementation of a sound internal governance framework. At the same time, delegating to committees does not in any way release the management body in its supervisory function from collectively fulfilling its duties and responsibilities. The reference to ‘ICT audit findings’ has been slightly adjusted to fully align with Article 6(7) of DORA. Paragraph 230, points (a), (b) and A respondent proposed to remove the term (c), have been ‘adequacy’ from paragraph233, points (a), (b), (c), as The proposal is acknowledged and, in an effort, adjusted to refer to this could add subjectivity and divergence across the to enhance clarity while preserving the risk- appropriateness, competent authorities and potentially going beyond based and proportionate nature of the SREP, the effectiveness and DORA requirements. wording has been refined to better reflect the implementation. supervisory objective under Directive 2013/36/EU.
Technical risk Some respondents proposed the development of a It is clarified that the SREP GL treat ICT risk as Wording taxonomy clear, stable and technically coherent risk taxonomy, in part of operational risk (consistent with te CRR adjustments in ICT which ICT risk is consistently positioned as a Article 4.1(52), EBA/RTS/2025/03, DORA recital risk sub-categories. component of operational risk, to support the 12) and embeds ICT/governance assessments
FINAL REPORT ON THE REVISED SREP GUIDELINES
integration of DORA into the SREP. This should be across Titles 5 and 6, enabling competent closely linked to business processes, critical or authorities to rely on other supervisory work important functions, and the underlying applications and artefacts where appropriate while and ICT assets supporting those functions. maintaining supervisory judgement and proportionality. Accordingly, supervisors can Another respondent noted that the ICT riskconsider DORA‑driven information as evidence subcategories (Annex III) are not defined in DORA and inputs in the SREP. this may lead to classification and delimitation issues. It is further noted that the sub-categorisation reflected in Annex III is based on the taxonomy already established in the ICT SREP GL, also reflecting DORA, hence it does not introduce new concepts or additional regulatory obligations. The sub-categories serve a supervisory methodology purpose, enabling competent authorities to perform a structured, consistent and risk-based assessment of risks under the CRD. Accordingly, the continued use of this supervisory classification does not create classification or delimitation issues but supports convergence and continuity in the assessment of ICT risk. It is therefore clarified that institutions are expected to maintain their own risk taxonomies for risk management purposes as the risk sub-categorisations set out in the Annex is intended to be used as guidance for the competent authorities and to further promote
FINAL REPORT ON THE REVISED SREP GUIDELINES
consistent risk identification across authorities, while remaining non-exhaustive and flexible.
Supervisory In relation to the potential supervisory measures in It is clarified that competent authorities may, on No change measures table 11, a respondent noted that competent a risk-based and proportionate basis, exercise authorities’ powers are covered under Article 50 of their supervisory powers under Directive DORA and the SREP GL should not extend these 2013/36/EU, including Article 104, to address further or include explicit rights not included under material deficiencies in governance and risk DORA. management arising from outsourced arrangements.
Audit findings A respondent proposed to clarify that paragraph235, Paragraph 232 is not considered to extend audit No change related to TPSPs points (c) and (d), apply to the institution’s own or remediation obligations beyond those remediation processes and governance, and that established under DORA. DORA requires competent authorities should assess whether financial entities to maintain an effective institutions have appropriate processes for reviewing internal control framework, including audit findings including with third-party service independent review mechanisms, and to remain providers, when applicable. fully responsible for ICT risk, including risks arising from ICT third-party arrangements. Paragraph 232 does not impose audit obligations directly on third-party service providers nor require alignment of their internal risk management approaches with those of the institution. The provision reflects the institution’s responsibility for effective ICT risk management and oversight and remains aligned
FINAL REPORT ON THE REVISED SREP GUIDELINES
with both the CRD supervisory framework and the requirements of DORA.
Operational risk A respondent suggested to clarify the concept of It is noted that the concept of ‘operational risk No change exposure and ‘operational risk exposure’ and to specify it refers to exposure’ is already used and consistently assessment operational risk losses arising from operational risk applied since the initial SREP GL, in line with the events and to risks not captured under Pillar 1 definitions and scope of operational risk set out requirements. It was further suggested to clarify that in the CRR. The SREP assessment considers risks the assessment of operational risk losses for the to which the institutions are or might be purposes of inherent risk should be based on net exposed in accordance with Articles 97 and 104 losses rather than gross losses, in order to of the CRD. Therefore, further clarification as appropriately reflect existing risk mitigants, such as suggested is not considered necessary. insurance policies, and provide a more accurate view Under the CRR operational risk framework, of the institution’s effective operational risk exposure. capital requirements are based on gross losses from insurance since, in accordance with Article 314(7), point (b) of the CRR, payments received from insurance or reinsurance policies purchased must not be used in the calculation of the Business Indicator. This ensures consistency and comparability across institutions. The SREP distinguishes between inherent risk and the effectiveness of risk management and mitigants. Inherent risk reflects the underlying level of operational risk exposure before the effect of controls or risk transfer mechanisms. Insurance and other mitigants are assessed separately as part of the evaluation of internal governance
FINAL REPORT ON THE REVISED SREP GUIDELINES
and risk management, and may be considered in the overall SREP outcome where appropriate. However, using net from insurance losses for the assessment of inherent risk would not be consistent with this framework and could obscure the institution’s underlying risk profile.
The SREP GL will therefore remain aligned with the CRR framework and continue to rely on gross loss from insurance information for the assessment of inherent operational risk.
Metrics in relative A respondent suggested clarifying in paragraph204 The SREP assessment should be risk-based and No change terms that the metrics used should be expressed in relative forward-looking and not intended to replicate terms as the use of absolute metrics in the SREP the calibration of Pillar 1 requirements. The assessment could result in undue size bias and SREP GL do not prescribe the exclusive use of potential double counting, while a relative assessment absolute metrics and supervisors are expected would better reflect the institution’s risk profile and to exercise judgement and may use both ensure consistency between Pillar 1 and SREP absolute and relative indicators, as appropriate, assessments. to ensure a proportionate and risk-sensitive assessment. In certain cases, absolute metrics may provide relevant information on the scale and potential impact of operational risk exposures. A respondent proposed to clarify in paragraph211 that No change It is noted that the assessment in paragraph 209 existing provisions already constituted by the focuses on the institution’s underlying exposure institution should be considered as a mitigating factor to legal risk on a forward-looking basis. While
FINAL REPORT ON THE REVISED SREP GUIDELINES
to support a more comprehensive and risk-sensitive existing accounting provisions may be view of the institution’s exposure to legal risk. considered as part of the overall supervisory assessment, they do not eliminate the underlying risk or the uncertainty surrounding potential outcomes.
The EBA acknowledges the benefit from Paragraph 222 A respondent recommended to consolidate consolidating paragraph 222 with section 6.4.2.2 moved before paragraph225 with section 6.4.2.2 (Model Risk) to on model risk to improve coherence and paragraph 212. reduce repetition. enhance clarity of the SREP GL.
Supervisory A respondent suggested to further specify qualitative The qualitative descriptors referred to are No change considerations for descriptors or support them with quantitative criteria intended to allow for a proportionate and riskassigning an or clear benchmarks, where possible, when based assessment across institutions with operational risk considering inherent risk to assess frequency and diverse business models and risk profiles. The score severity. This could help reduce subjectivity and SREP GL do not introduce mechanically binding enhance consistency of the SREP assessment across quantitative thresholds, as this could reduce institutions. It was further proposed to add clarity on supervisory flexibility and risk sensitivity. supervisory expectations regarding the use of scenario Since the initial SREP GL, scenario analysis was analysis within the inherent risk assessment, including recognised relevant as a forward-looking tool its role, calibration and interaction with other within the operational risk framework. The use, elements of the operational risk framework. calibration and integration of scenario analysis are assessed as part of the review of the institution’s risk management and internal
FINAL REPORT ON THE REVISED SREP GUIDELINES
governance arrangements, taking into account proportionality and the nature, scale and complexity of activities. Further prescriptive clarification is therefore not considered necessary.
Status of OpRisk A respondent noted that paragraph195 does not The EBA takes note of the comment, and it is Removal of related technical reflect the draft status of the first three RTS related to clarified that the first three RTS related to tables and standards operational risk. operational risk were referring to the final draft development of a RTS published by the EBA. In this regard, separate list of legal amendments have been made to clarify in the acts to be published separate list. on the EBA website.
Use of business A respondent suggested removing the reference to The reference to business lines (paragraph 202) No change lines business lines in the context of operational risk or is used in a descriptive context, without implying clarifying the references are not intended for supervisors should apply the previous business operational risk assessment purposes to avoid line categorisation for the purposes of the misalignment with the current Pillar 1 framework. operational risk assessment or creating misalignment with the Standardised Measurement Approach under the CRR. Accordingly, no amendment is considered necessary.
Operational Risk A respondent proposed that operational risk It is noted that the SREP assessment of No change Metrics, Loss assessments should rely on relative, normalised operational risk under the CRD Articles 97 and Treatment and metrics rather than absolute ones, the framework 104 does not intend to replicate Pillar 1 Comparability should distinguish historical losses from current requirements, nor to rely mechanically on
FINAL REPORT ON THE REVISED SREP GUIDELINES
operational risk, and it should also differentiate individual metrics. Further, the SREP GL do not manageable from non‑manageable losses. It was also prescribe the exclusive use of absolute or proposed that internal risk metrics be recognised as relative indicators. Supervisors may use a not comparable across institutions, and therefore used combination of both, as appropriate, to ensure a cautiously in benchmarking, and that horizontal proportionate and risk-sensitive assessment. comparisons of loss data be avoided, given the lack of Historical losses are one input into the analysis consistent industry‑wide loss‑recording practices. and should not be applied mechanically, in Lastly, it was proposed to not take into account credit particular where root causes have been boundary events when assessing operational risk gross addressed. Supervisors are also expected to losses to avoid overlap between credit and operational consider the nature and drivers of losses, risk assessments. including the institution’s resilience and response capacity. Internal metrics are assessed within a harmonised supervisory framework to promote consistency, while acknowledging institution-specific methodologies. In line with the CRR, gross losses provide a consistent basis for assessing underlying exposure, while insurance and other mitigants are considered separately in the evaluation of risk management and control effectiveness. Accordingly, no amendments to the Guidelines are considered necessary.
Reputational risk Two respondents noted that the way reputational risk It is acknowledged that the assessment of No change implications can be identified, quantified and reputational risk involves a degree of compared between institutions in order to ensure a supervisory judgement. As set out in the existing proportionate approach remains subjective. One of SREP GL, reputational risk is typically a these participants suggested removing reputational consequence or amplification channel of other
FINAL REPORT ON THE REVISED SREP GUIDELINES
risk from the operational risk section. Another risk categories rather than a standalone risk participant suggested clarifying in section 6.4.4 that type. Supervisors are expected to assess it in a strategic and reputational risks should not form part of proportionate manner, taking into account the operational risk assessment but instead be institution-specific circumstances and using a assessed under the relevant underlying risk category, combination of quantitative and qualitative depending on their source, consistently with the indicators to ensure comparability across approach outlined in the introductory section of the institutions. Guidelines. Concerning the suggestion to exclude strategic and reputational risks from the operational risk assessment, the SREP GL already clarify in the introductory section that risks should be assessed under the relevant underlying risk category, depending on their source. Accordingly, strategic and reputational risks are not treated as independent risk categories within the operational risk assessment but are considered in connection with the originating risk drivers. Further clarification in Section 6.4.4 is therefore not deemed necessary.
Q11. What are the respondents’ views on the introduction of operational resilience (section 6.4.5)?
Introduction of Some respondents raised concerns that the Operational resilience constitutes an integral Explanatory text has operational introduction of ‘operational resilience’ as a holistic element of the robust governance arrangements been added in the resilience concept in the SREP lacks a clear legal or regulatory and adequate internal control mechanisms ‘Background’ basis, goes beyond DORA’s mandate, and risks required under Article 74 of Directive section to clarify the creating a new supervisory framework without Level 1 2013/36/EU (CRD). Operational introduction of operational legislation or dedicated consultation. On the other resilience-related elements are already
FINAL REPORT ON THE REVISED SREP GUIDELINES
hand, some respondents clearly support operational evaluated through the existing EU legal and resilience. resilience, which is consistent with the direction of regulatory framework (e.g. the CRD/CRR, DORA, Paragraph 242 has been adjusted to supervisory developments, including BCBS framework, EBA GL). The integration of operational refer to the and with the holistic view expected under DORA, resilience should be seen as a coherent effectiveness of the provided it avoids duplicative or parallel related supervisory consolidation of existing institution’s testing by building on existing elements and work requirements, not as imposing new operational already performed by institutions. requirements. The introduction of operational resilience approach. Proposal for a Some respondents suggested (i) establishing a resilience does not introduce a new framework, new taxonomy consistent taxonomy that explicitly defines the nor it intends to introduce duplicative reporting and clarification concepts of operational resilience, operational risk, ICT or testing beyond the requirements already on operational risk, and digital operational resilience, outlines their established across the EU regulatory framework. resilience maturity interrelationships, and specifies which elements fall The supervisors would be expected to form a under the operational resilience assessment versus view on the institution’s operational resilience other frameworks, and (ii) avoiding vague concepts approach leveraging existing information such as ‘maturity level’ or undefined notions of provided by the institutions. resilience. The comment on paragraph 242 is noted and it is clarified the reference to ‘maturity level’ did not intend to undermine the application of proportionality principle. In this regard, to better reflect a risk‑based supervisory assessment and to support consistent application the wording has been adjusted to place greater emphasis on the effectiveness of the institution’s operational resilience approach, taking into account the nature, scale and complexity of the risks to which it is exposed.
FINAL REPORT ON THE REVISED SREP GUIDELINES
Impact on smaller Few respondents mentioned that the introduction of Operational resilience applies to all institutions, Explanatory text has institutions operational resilience could impose additional and in a proportionate manner, as disruptions can been added in the potentially disproportionate requirements on smaller, occur to all institutions and can jeopardise their ‘Background’” less complex institutions. It was proposed that further ability to deliver critical services, undermine section to clarify the proportionality measures be clarified (for example in trust and potentially cause wider market introduction of paragraph244), existing elements be used and disruption. The introduction of operational operational additional reporting/testing burdens beyond DORA be resilience does not intend to introduce resilience should avoided. duplicative reporting or testing beyond the not impose requirements already established across the EU additional regulatory framework. The supervisors would be requirements. expected to form a view on the institution’s Paragraph 241 has operational resilience approach leveraging been adjusted to existing information provided by the institutions. refer explicitly to the application of proportionality principle. Materiality A respondent proposed the CAs to apply materiality It is clarified that the content and reporting Paragraph 213(e) thresholds for thresholds when using DORA register of information requirements of the DORA register of has been amended register of for the SREP (e.g., based on contract value or exclude information are not defined in the SREP GL. As to focus on C&I information low-impact contracts) or simplifying function mentioned in the draft revised GL, the DORA functions. identifiers and to avoid ad-hoc granular information register of information is one of the information requests unless justified by specific supervisory sources the supervisors should utilise to assess concerns. These would reduce reporting burden for the institution’s ICT risk. The materiality the institutions without weakening oversight and threshold is acknowledged and considered to make the SREP use of ROI data more proportionate support one of the objectives of this revision and effective. towards a more risk-based and proportionate supervisory approach. However, it is clarified
FINAL REPORT ON THE REVISED SREP GUIDELINES
that this should not restrict CAs’ supervisory work.
Contractual A respondent proposed to clarify that contractual Contractual requirements on third-party services No change arrangements matters should be addressed separately under DORA. are comprehensively addressed under DORA Another respondent requested enabling the and the EBA Guidelines on the sound competent authorities to recognise and consider the management of third-party risk management. use of standardised contractual terms on operational The SREP GL do not duplicate those provisions resilience as reliable evidence of resilience for but assesses, from a prudential perspective, third‑party dependencies supporting critical or whether institutions effectively implement and important functions. It was further proposed that risk manage them within their overall risk oversight be harmonised through accredited audit management framework. regimes based on agreed auditing standards, which could be developed jointly by the ESAs-ENISA. Introduction of a Few respondents proposed to refrain from referring to The intention of the provision is not to introduce Explanatory text has new framework ‘operational resilience framework’ in paragraph68(c) an additional framework but rather to ensure been added in the as there is currently no explicit regulatory that institutions adopt a coherent and ‘Background’ requirement. proportionate approach embedded within their section to clarify the existing frameworks/arrangements. introduction of operational resilience. Residual risk as an Few respondents suggested further clarifying that the The revised SREP GL further promote a No change assessment basis operational resilience assessment should be based on proportionate and risk-based supervision. It is the residual risk rather than inherent risk to enable a noted that risks were already assessed on a net more proportionate, risk‑sensitive and outcome‑based basis, considering both inherent risks and the supervisory approach. effectiveness of controls. The supervisory view on the institution’s operational resilience should therefore reflect the institution’s mitigation
FINAL REPORT ON THE REVISED SREP GUIDELINES
capacity and continuity capabilities rather than inherent exposure alone. At the same time, given its forward-looking and cross-cutting nature, forming such a view requires supervisory judgement and should not be reduced to a purely residual-risk metric.
Operational A respondent noted that operational resilience and It is acknowledged that both operational No change resilience and operational continuity in resolution (OCIR) should be resilience and operational continuity in operational aligned under the BIS Principles as a single, integrated resolution (OCIR) rely on similar elements such continuity in resilience model, so that DORA and OCIR rely on as governance, identification of critical resolution shared governance, assessments, testing and functions, operational dependencies and testing. information sets, avoiding duplication between However, the two areas serve distinct purposes supervisory and resolution requirements while and fall under separate supervisory and simplifying supervision and reducing reporting and resolution mandates. Authorities could leverage compliance burdens for institutions. the overlapping areas in their respective assessments (e.g. documentation, scenario testing outcomes, registers and critical function mappings) to reduce duplication and supporting efficiencies, without necessitating formal integration into a single framework.
Further clarity on A respondent requested further guidance on the These terms are used consistently across the No change certain terms terms ‘timely reporting’ and ‘major deficiencies’ EBA products, reflecting a common supervisory (paragraph245b) as it would help institutions design understanding. For the purposes of this effective escalation and governance processes. paragraph, ‘timely reporting’ refers to the Another respondent proposed to include specific prompt internal escalation of relevant information to the management body without
FINAL REPORT ON THE REVISED SREP GUIDELINES
expectations on the management body in determining undue delay, once such information is necessary and defining ‘active role’. to support effective oversight and decisionmaking, and ‘major deficiencies’ are considered significant weaknesses or shortcomings that could materially affect the institution’s ability to deliver its critical or important functions, hence warranting escalation to the management body.
Implementation Some respondents indicated lack of coherence across The EBA takes notes of respondents’ concerns No change challenges Member States in digital and ICT matters, along with regarding supervisory coherence across Member the absence of a fully harmonised supervisory field, States, overlapping requests, and the allocation resulting in overlapping supervisory requests and an of responsibilities in relation to digital/ICT unclear allocation of responsibilities among banks, aspects. It is further acknowledged that certain other regulated entities, and TPSPs. In addition, related national initiatives may coexist alongside national initiatives on defence and ICT resilience the Union framework. further increase divergence among banks across Supervisory assessments should aim to remain jurisdictions. It was therefore proposed to carefully risk-based and proportionate, taking into incorporate the following sentence in paragraph 244: account the nature, scale and complexity of ‘However, the supervisory assessment should take institutions’ activities, as well as the broader into consideration the existing variety across Member national context in which they operate. It is States in addressing operational resilience and the noted that paragraph 49 already envisages relevance of practical obstacles for banks in addressing coordination of supervisory activities with other certain deficiencies related to third-party providers parties directly or indirectly involved in the that may not be in the purview of the institutions’. assessment, in particular when input is required from them.
FINAL REPORT ON THE REVISED SREP GUIDELINES
Q12. What are respondents’ views on the additional section on CSRBB and the combined score for IRRBB and CSRBB?
Concerns on Several respondents voiced understanding of why There should be no double counting since in line No change double counting CSRBB is introduced in the SREP GL but raised with the requirements for institutions under the concerns that duplication and double counting should Guidelines on IRRBB and CSRBB be avoided as IRRBB and CSRBB are already holistically (EBA/GL/2022/14), competent authorities addressed in ICAAP. should also have separate assessments of CSRBB and other risks, including IRRBB. Also, competent authorities should leverage the knowledge gained on IRRBB and CSRBB from the ICAAP information collected for SREP purposes. Transparency on Several respondents supported the combined IRRBB The criteria for the IRRB and CSRBB scoring are Paragraph 249 has the contributions and CSRBB score that allows for simplification, in line with the general approach used for been adjusted to of each provided transparency is ensured on the contributions scoring in the SREP GL providing flexibility to provide for the component of of each component, and that sub-scores, weightings competent authorities to adapt the weightings outcome of the IRRBB and CSRBB and individual contributions remain visible and of individual components of the score. For the assessment of the score explainable. A minority of respondents favored IRRBB and CSRBB score this allows competent individual risks to separate scores (at least initially) given the differing authorities to adapt the weightings to the lower be reflected in a nature and mature of IRRBB and CSRBB. degree of maturity of CSRBB compared to IRRBB. summary of findings Paragraph 249 has been reworded to provide for and an explanation the reflection of the outcome of the assessment of the main risk of the individual risks in a summary of findings drivers. and an explanation of the main risk drivers. Proportionality Several respondents asked for a proportionate and A progressive approach has been applied to No change and phased phased implementation of CSRBB, reflecting the lower introduce CSRBB in the SREP assessment taking implementation of methodological maturity, limited comparability across into account the less mature stage of this risk CSRBB banks and EU-specific nature of CSRBB. compared to IRRBB.
FINAL REPORT ON THE REVISED SREP GUIDELINES
The implementation of CSRBB in the EU regulatory framework at the level of Directive 2013/36/EU, in the Guidelines on IRRBB and CSRBB (EBA/GL/2022/14) as regards to the expectations for institutions, and in the SREP GL as regards the assessment by competent authorities in the context of the SREP has been performed in alignment with the BCBS standards. Proportionality in One respondent asked to clarify if idiosyncratic spreads Proportionality can be applied in the exclusion of Paragraph 285 has exclusion of may only be excluded for proportionality reasons, does idiosyncratic spread in the institution’s been updated to idiosyncratic this imply that institutions of higher SREP categories measurement of CSRBB as long as it is ensured clarify the spreads may not exclude idiosyncratic spreads even if the that the measures will yield more conservative proportionality results were conservative, and which SREP categories results regardless of the SREP category of the applies regardless would be affected. institution. Paragraph 285 has been updated to of the SREP clarify that the application of proportionality categorisation. applies across all SREP categories. Proportionality in One respondent asked for paragraph 286 to take into The provision in paragraph 283 is in line with the No change determination of account the principle of proportionality and materiality provision under paragraph 124 of Guidelines on CSRBB perimeter as not every minor CSRBB sensitivity should lead to IRRBB and CSRBB (EBA/GL/2022/14) requiring mandatory inclusion in the perimeter. Another that institutions not exclude any instrument in respondent indicated that paragraph 286 seems to the banking book from the perimeter of CSRBB ex further narrow down the scope of CSRBB. ante and that any potential exclusion of instruments from the relevant perimeter should be done in the case of the absence of sensitivity to credit spread risk, and should be appropriately documented and justified. It is a prerogative of the institutions to define the criteria under which
FINAL REPORT ON THE REVISED SREP GUIDELINES
the instruments are to be considered sensitive to credit spread risk. Application of Several respondents asked to clarify in the SREP GL Similar to the Guidelines on IRRBB and CSRBB No change SOTs at that for supervisory outlier tests (SOTs) where a legal (EBA/GL/2022/14), also the SREP GL apply at the consolidated level entity appears as an ‘outlier’ based on the solo level entity level (i.e. at the level of institutions as indicators, if the SOT thresholds are met at defined in point 3 of Article 4(1) of Regulation consolidated level, the bank should not be considered (EU) No 575/2013). The level of application is in as an ‘outlier’ for the purpose of the IRRBB score line with the level of application of requirements acknowledging that this risk is often managed at group applicable to the institution under Regulation level. (EU) No 575/2013 and Directive 2013/36/EU, including the SOT requirement under the CRD Article 98(5), and an assessment at the individual entity level can allow to identify vulnerabilities specific to certain entities, which can be relevant in a broader context. Furthermore the IRRBB score is determined on the basis of the overall assessment (including the SOT) and evaluation that the institution’s management of IRRBB is adequate and that the institution is not excessively exposed to IRRBB. Role of NII SOT in One respondent voiced strong support for the fact The NII SOT is reflected in the EU regulatory No change SREP assessment that the NII SOT is not used directly in the final SREP framework in accordance with Article 98(5) of assessment but pointed out that its binding legal Directive 2013/36/EU. However, the provision status elevates it far beyond the complementary under Article 98(5) does not provide for an measures. This raises a risk that in practice the legally automatic link between the identification of an binding threshold will play a dominant role compared institution as an outlier under the SOT NII and to the non-binding additional dimensions designed to the use of measures and specifically mentions provide a broader economic perspective (market- that competent authorities shall not be obliged
FINAL REPORT ON THE REVISED SREP GUIDELINES
value effects, administrative and operating expenses, to exercise supervisory powers where they net fees and commissions, embedded gains/losses). consider, based on the review and evaluation that the institution’s management of IRRBB is adequate and that the institution is not excessively exposed to IRRBB. In accordance with the Level 1 text, the SREP GL provide in paragraph 258 for competent authorities to consider analysing additional dimensions to complement the NII outlier test. Reflect the One respondent suggested complementing table 12 Paragraph 258 already provides for an analysis No change broader set of the criteria on the sensitivity of earnings to changes in of the additional dimensions to complement the earnings-related interest rates, with a reference to the consideration of assessment where an institution is identified as aspects the additional dimensions of earnings related aspects an outlier by the supervisory outlier test on net under paragraph 261. interest income. Also, in table 12 an already extensive reference to the profitability dimension is provided. Structural One respondent pointed out that the structural The criteria outlined in table 12 are not No change interaction interaction between EVE and NII sensitivities means cumulative (i.e. not all of the criteria must be between EVE and that some configurations in table 12 are unlikely to met for a given score). NII sensitivities arise under standard balance-sheet positioning across the rate cycle, and asked for clarification on how the scoring criteria should be applied to enhance consistency, reflect the economic realities of IRRBB and prevent unintended penalisation of prudent ALM practices.
Q13. What are the respondents’ views on the proposed assessment of the interaction between Pillar 1 and Pillar 2 requirements and on the proposed approach for operationalising concerning cases where an institution becomes bound by the output floor?
FINAL REPORT ON THE REVISED SREP GUIDELINES
Holistic and risk- Respondents expressed consensus on the need to The current wording already ensures that Change to based avoid double counting between Pillar 1 and Pillar 2, competent authorities conduct a holistic paragraphs 294 and reassessment of with repeated calls for a holistic, risk-based assessment to preserve the ongoing 317 and clarification P2R when Pillar 1 reassessment of P2R when Pillar 1 changes materially complementarity between P1R and P2R in the in the background changes (e.g. CRRIII, output floor), and for clearer scope of event of material regulatory changes to the and rationale. materially application of paragraph 297. Pillar 1 framework. For the sake of clarity, a more explicit reference has been introduced to TREA dynamics, the potential ongoing impact of the output floor implementation, and the possibility of adjusting (either upward or downward) the level of P2R to ensure that its calibration remains appropriate to the institution’s risk profile in light of its P1R.
Neutralisation of Many respondents argued that ‘arithmetic effects’ With regard to arithmetic effects, the term arithmetic effects arising from the output floor should always be ‘undue’ has been removed from paragraph 317 neutralised, in addition to any P2R set to address to avoid potential confusion. regulatory model deficiencies. They further contended Once any double counting between P2R and the that this neutralisation should be applied over time for output floor has been identified and eliminated, as long as the output floor is binding (including the the ongoing impact of the output floor is impact of transitional factors), in order to avoid considered as part of the holistic assessment mechanical and unwarranted increases in P2R. referred to in paragraph 294, without the need to repeat all the steps (including the continued application of the P2R ‘temporary cap’) set out in paragraph 317. Use of P2R/P2G to Respondents requested clarification on how findings The Guidelines already recall, in paragraph 298, No change. address related to BMA and governance aspects may translate the situations listed in Article 104a(1) of governance and into supervisory measures, ensuring that any impact Directive 2013/36/EU, including deficiencies in
FINAL REPORT ON THE REVISED SREP GUIDELINES
business model on P2R or P2G is confined to cases involving clearly internal governance – such as internal control deficiencies identifiable prudential implications and does not arrangements and other shortcomings – as well overlap with risks already captured under P1R. as risks arising from the institution’s business model, where other supervisory measures have not been effective or are considered insufficient to address the identified deficiencies. Interaction Respondents called for a more systematic or clearer In principle, under the current framework, only No change. between P2G and offset between P2G and macroprudential buffers limited overlap between P2G and the CCyB is macroprudential (particularly the CCyB) in stress scenarios. It was expected, and this is already addressed in the buffers argued that the CCyB would be systematically released SREP GL, including considerations about the in stress scenarios such as those used in the EU-wide design of the stress scenarios. However, it is not stress test and should therefore be offset against the evident why the CCyB would be systematically P2G. Other respondents cautioned more broadly released in the scenarios adopted for the EUagainst weakening the distinction between micro- and wide stress test, nor how this would consistently macroprudential objectives. overlap with the P2G. ORC in SREP Respondents expressed some reservations about It is further clarified that the objective is not to Clarification in the scoring including Overall Recovery Capacity (ORC) in SREP create a mechanistic link between ORC and the background and scoring for capital and liquidity adequacy, citing capital and liquidity adequacy scores, but rather rationale. subjectivity, lack of comparability, short time horizons, to consider it as one of the many elements risk of double counting and increased complexity, contributing to the resilience of an institution’s alongside calls for much greater transparency if ORC is capital and liquidity profile, with the aim of retained. fostering a stronger risk management continuum between ongoing supervision and crisis preparedness.
Q14. What are the respondents’ views on the merger with the ‘SREP liquidity assessment’ and the merger of the scores into a combined liquidity and funding adequacy score?
FINAL REPORT ON THE REVISED SREP GUIDELINES
Clarification on Several respondents asked for clarification on Title 10 provides guidance on the SREP No change group-level versus group-level versus entity-level responsibilities, with assessment in the cross-border or group context entity level strong agreement that while all material legal entities taking into account interactions between the responsibilities should be covered, findings and remediation in assessments at individual entity level and consolidated groups should be coordinated and consolidated level, reflecting strengths and steered by the consolidating entity, recognising group- mitigating factors related to the entity being wide liquidity management frameworks and intra- part of the group, taking into account the group group support arrangements. dimension, including inter-dependencies and intra-group arrangements. Transparent A few respondents asked for a clear and transparent The criteria for the combined liquidity and No change methodology methodology, weighting and benchmarking, including funding adequacy scoring are in line with the explicit explanation of how liquidity vs. funding general approach used to scoring in the SREP GL, components are weighted, peer benchmarking is providing flexibility to competent authorities to performed, and results influence the final score. adapt the weightings of individual components of the score. Paragraph 371 provides for the outcome of the assessment of each individual risk to be reflected in a summary of findings and an explanation of the main risk drivers. Transparency on Several respondents supported the combined liquidity The criteria for the combined liquidity and No change the individual and funding adequacy score allowing for funding adequacy scoring are in line with the components of simplification, with respondents asking to ensure general approach used to scoring in the SREP GL the combined transparency of the individual assessments of the two providing flexibility to competent authorities to score components (liquidity and funding) and their impact adapt the weightings of individual components on the overall score. of the score. Also, paragraph 422 allows competent authorities to use intermediate scores for liquidity and funding risk where relevant. Paragraph 371 provides for the outcome of the assessment of each individual
FINAL REPORT ON THE REVISED SREP GUIDELINES
risk to be reflected in a summary of findings and an explanation of the main risk drivers. Integration of ORC One respondent asked to clarify what considerations The integration of the ORC in the capital and No change competent authorities can consider if they should liquidity and funding adequacy scoring allows include the score of the liquidity overall recovery CAs to positively reflect a sounder recovery capacity in recovery planning when setting the planning in those scores. If the overall recovery liquidity and funding adequacy score. capacity in the context of liquidity adequacy is considered to be weak this should also be reflected in the determination of the liquidity and funding adequacy score Significant impact A few respondents suggested to clarify in paragraph The risk scores aim to capture the likelihood that No change in the liquidity and 29 of Title 2 what makes an impact significant in the the risks to capital, liquidity and funding will funding score liquidity and funding score. have a significant impact on the institution. When assigning risk scores, SREP elements’ scores and the overall SREP score, competent authorities should refer to the supervisory considerations outlined in the tables at the end of each relevant section and title of the SREP GL, alongside the application of supervisory judgment. The SREP element scores and the overall SREP score indicate the magnitude of risks to the institution’s viability. Level of detail in One respondent suggested that the level of detail in Following the streamlining, at the end of the No change potential funding potential funding and liquidity measures appears Title 8 a table has been added with a nonand liquidity extensive compared to capital measures and some of exhaustive, illustrative list of supervisory measures these could influence a bank’s strategic decisions. measures that could be employed by competent authorities to address deficiencies identified in the assessment of liquidity and liquidity risk or
FINAL REPORT ON THE REVISED SREP GUIDELINES
funding risk. The measures include the quantitative measures previously included in section 9.5 and the supervisory measures previously included in Title 10. Whereas the consolidation of the measures into one table, in particular following the merger of Titles 8 and 9, might give the impression that the list is extensive, it is solely meant as a reference for competent authorities and measures are not meant to be applied mechanically. Interaction One respondent suggested clarifying the interaction The paragraph is addressed to competent No change between the between the supervisory liquidity stress testing authorities and specifies that – when designing supervisory framework (paragraph 386) and the LCR framework and calibrating supervisory liquidity stress tests liquidity stress and its associated liquidity buffer. – supervisors may consider the LCR stress testing framework scenario (and its calibration) as a starting point, and the LCR but are also encouraged to extend the scope framework and calibration of such stress tests (e.g. by looking beyond the 30 calendar day time horizon of the LCR and also applying a calibration that is more severe than the LCR stress scenario).
Q15. What are the respondents’ views in relation to enhanced communication aspects?
Several respondents indicated that greater The EBA acknowledges the support for Paragraph 448(b) Enhanced transparency and clearer methodology are needed for enhanced transparency. The revised SREP GL has been amended transparency and risk scoring and overall SREP scoring, especially clearer already provides sufficient guidance on the to refer to material communication of justification of scores, material risk drivers, and communication of SREP outcomes (including the supervisory findings SREP outcomes deficiencies, to help institutions prioritise remediation SREP score and justification providing a clear and the appropriate and allocate resources efficiently. Respondents indication of the material risk drivers
FINAL REPORT ON THE REVISED SREP GUIDELINES
suggested clarifying how overall SREP scores are contributing to the P2R) in a manner that timeframe for derived from sub-scores, defining drivers for preserves the necessary supervisory flexibility remediation. supervisory judgement, and specifying how inherent while providing institutions adequate clarity to risk and risk management controls are assessed. prioritise remediation and allocate resources Respondents indicated that communication of SREP efficiently. Slight adjustment to focus on outcomes could be improved. A wording proposal on material findings and remediation. paragraph 39 suggested the following: ‘shall disclose to institutions the SREP scores for relevant elements or sub-elements.’
Repeated demands for transparency on P2R The calibration and composition of P2R and P2G, No change Transparency on composition and calibration, including clearer including the translation of SREP scores into P2R composition explanation of how scores translate into P2R/P2G, capital requirements and guidance, involve and calibration breakdowns by main risk drivers, and communication supervisory judgment that is institution-specific of ‘before/after’ effects where relevant. and inherently sensitive. The current SREP GL provides sufficient guidance on the communication of SREP outcomes while preserving the necessary supervisory discretion in this regard. Moreover, timely communication throughout the findings’ lifecycle is already embedded in the existing guidance on SREP communication. No amendments are therefore considered necessary. Calls for greater granularity in communicated scores, Higher communication granularity is already No change Granularity in including disclosure of element and sub-element envisaged in the revised consultation paper, on communicated scores, qualifiers and severity labels for qualitative a material risk basis. scores requirements, and consistent treatment across group and subsidiary levels.
FINAL REPORT ON THE REVISED SREP GUIDELINES
Support for benchmarking transparency, with requests It is not clear how disclosing peer groups would No change Benchmarking that peer groups, criteria and results be clearly defined be beneficial in fostering higher-quality transparency and systematically communicated to institutions but supervisory dialogue. No amendments are not used mechanically as enforcement tools. therefore considered necessary.
Caution against over-standardisation of No specific communication template is foreseen No change Preservation of communication, with some respondents stressing the in the GL. supervisory need to preserve supervisory discretion and flexibility, discretion and particularly for LSIs and timing of communication. flexibility
Q16. Do you consider the coverage and level of detail of Title 10 appropriate for its intended purpose?
Interaction A few respondents asked for a clearer articulation Title 10 provides guidance on taking into No change between between consolidated and local assessments, account key vulnerabilities in the cross-border or consolidated and including how group-level tools (stress tests, recovery group context and reflecting strengths and local assessments planning, ORC) should inform entity-level SREP mitigating factors related to the entity being decisions to avoid fragmentation. part of the group into the assessment of the individual entities of the group (paragraph 465); using views on key dependencies on the parent/group as an input into the joint assessment and decision for the group (paragraph 466); adjusting assessments of individual entities based on the outcomes of the college discussions (paragraph 468); discussing in the college context deficiencies related to
FINAL REPORT ON THE REVISED SREP GUIDELINES
intra-group positions of an individual entity considering the overall group dimension, including the consolidated group business model, strategy and existence and specific features of intra-group financial support arrangements (paragraph 469); discussing and coordinating within the college details of the application of benchmarks used for the assessment of SREP elements, where common deficiencies are identified across all entities coordinating the assessment and supervisory response and deciding whether measures should be imposed at a consolidated level or proportionally at entity level (paragraph 474(b)); discussing outcomes of the supervisory benchmark calculations used to determine P2R for all entities within the group and at consolidated level (paragraph 474(d)).
Coordination Several respondents suggested stronger coordination The role and tasks of colleges of supervisors are No change within supervisory within supervisory colleges in the following areas: set out in Commission Delegated Regulation colleges (EU) 2025/791 and in Commission Implementing (i) fostering convergence, especially to Regulation (EU) 2025/790 aimed at ensuring a harmonise methodologies for cross-border consistent, efficient and effective functioning of banking groups; colleges of supervisors and to facilitate (ii) guaranteeing flow of information between cooperation and coordination between competent authorities; competent authorities including for the planning of supervisory activities, for the SREP
FINAL REPORT ON THE REVISED SREP GUIDELINES
(iii) supporting coordinated planning of assessment and for the joint decision process. supervisory actions and intervention The colleges of supervisors shall also facilitate measures; the identification of early warning signs, potential risks and vulnerabilities for the group (iv) managing divergent home/host views; and its entities, and increase the effectiveness (v) managing the complexity of cross-border and efficiency of the group supervision. financial groups to ensure the vulnerabilities arising from individual entities are properly In this context we also refer to the review of the assessed in their group-wide context while Implementing Technical Standards on joint recognising that consolidated supervision decisions on institution-specific capital and should not prevent local authorities from liquidity requirements in colleges of supervisors adopting proportionate measures in response under Article 113 of Directive 2013/36/EU, and to risks that are specific to a particular entity to the work on enhanced and integrated or market. coordination between public authorities under recommendation 14 of the EBA Report on the efficiency of the regulatory and supervisory framework (EBA/REP/2025/26).
Moreover, the common SREP GL aim to harmonise the methodologies used for the SREP; and Title 10 provides for the coordinated execution of the SREP assessment and the coordination of planned supervisory and early intervention measures and joint decisions for cross-border groups.
FINAL REPORT ON THE REVISED SREP GUIDELINES
Planning of Several respondents asked for more predictability and The role and tasks of colleges of supervisors are No change supervisory better planning of the supervisory activities with the set out in Commission Delegated Regulation activities Yearly Supervisory Examination Programmes (SEP) to (EU) 2025/791 and in Commission Implementing be submitted for prior feasibility/impact assessment to Regulation (EU) 2025/790 aimed at ensuring a competent authorities and supervised entities to allow consistent, efficient and effective functioning of orderly execution on both sides. colleges of supervisors and facilitating cooperation and coordination between competent authorities, including for the planning of supervisory activities, including offsite activities and onsite inspections, and areas of joint work.
The comment will inform the ongoing implementation of the recommendations in the EBA Report on the efficiency of the regulatory and supervisory framework (EBA/REP/2025/26), in particular the set-up of supervisory platforms that bring together authorities from different horizons in pilot cases for specific institutions (recommendation 14).
Group-wide A few respondents voiced support for group-wide The SREP GL provide for the assessment of No change consolidation of consolidation of risks beyond capital and leverage, contagion risks in the liquidity context as per risks with requests to pay more systematic attention to risk paragraph 376(b) and of key vulnerabilities in concentration, contagion channels and cross-sectoral the cross-border or group context (paragraph risks within groups. 465), specific deficiencies related to intra-group positions (paragraph 469), and cross-border
FINAL REPORT ON THE REVISED SREP GUIDELINES
prudential implications of ML/TF risks and concerns (paragraph 470(f)).
Proportionality A few respondents asked for proportionality and The SREP GL provide for competent authorities No change and avoidance of avoidance of undue burden on groups, particularly to consider the assessment of the materiality of undue burden on where subsidiary-level measures deviate significantly risks and deficiencies at consolidated and groups from group-wide frameworks without clear risk individual entity level, to coordinate the justification. assessment and supervisory response and decide whether measures should be imposed at consolidated or entity level where deficiencies identified are common across all entities, and for competent authorities to coordinate the application of supervisory and early intervention measures to the group and its material entities.
Q17. Do you consider the coverage and level of detail of Title 11 appropriate for its intended purpose?
Use of AQR in Respondents noted that the current wording on the The reference to AQR in the supervisory stress No change supervisory stress use of the outcomes of asset quality reviews (AQR) test has not been amended with respect to the test when designing and conducting supervisory stress previous version. As specified in the remaining tests for SREP purposes in paragraph 490 could part of the paragraph, AQRs may help ensure potentially lead to inconsistencies and suggested it that the balance-sheet positions of the may need further clarification. institutions covered by the supervisory stress tests are reported accurately with improved and comparable starting points across participating institutions.
FINAL REPORT ON THE REVISED SREP GUIDELINES
Target capital Respondents called for more predictable rules on The title focuses on the use of supervisory stress No change ratios in stress target capital ratios, regarding the conditions under testing, its key elements, and the organisational test which they are set, how they relate to P2G and and governance arrangements within buffers, and how they are communicated. competent authorities. In this context, the possible use of target capital ratios – which are not explicitly mentioned in the guidelines – may fall within the broader uses of supervisory stress testing, including the assessment of institutions’ ability to meet the TSCR and OCR. However, it remains in the competent authorities’ remit whether to define and use such ratios.
Prudent timeline Respondents suggested that new resilience-oriented The reference to the integration of ESG factors No change and design for stress tests, including those incorporating ESG factors, into supervisory stress testing has already been new resilience- should build on existing frameworks and should not be made at a high level. The design of future EUoriented and ESG- launched before a sufficiently mature EU-wide wide stress tests is outside the scope of these related scenarios approach has been agreed, ideally not before the 2029 guidelines. EU-wide stress test.
Use of Respondents encouraged competent authorities to One of the potential uses of supervisory stress No change institution’s leverage, to the largest extent possible, institutions’ testing is to support competent authorities in internal data and internal models and data, with supervisory overlays assessing the reliability of institutions’ stressmethodology where necessary. testing programmes. Accordingly, while competent authorities should have a sufficient understanding of the internal models and data underpinning institutions’ stress-testing frameworks, those models and data are not
FINAL REPORT ON THE REVISED SREP GUIDELINES
expected to constitute the main basis for the supervisory stress test
Articulation Respondents noted it would be helpful for the Paragraph 483 already covers the relationship No change between Guidelines to clarify how stress test outcomes will be between supervisory stress test and other supervisory stress articulated with other SREP assessments to ensure relevant SREP elements. test and other consistency and avoid double-counting of risks. SREP elements
Proportionality in Respondents suggested including additional guidance Proportionality elements are addressed on a No change supervisory stress on how to achieve greater proportionality, in particular cross-cutting basis in Title 2, rather than in the testing through simplification options for institutions in SREP specific title. categories 3 and 4.
Q18. Do respondents consider the guidance for the assessment of third-country branches appropriate and sufficiently clear?
Scope of Several respondents asked for clarification on the Paragraph 494 has been updated to clarify that Paragraph 494 has application scope of application, especially whether the guidance Title 12 should be applied for third-country been updated to applies only to the list of third-country branches branches as defined in Article 47(3) of Directive clarify the scope of published by the EBA on 13 October 2025 or more 2013/36/EU. application of Title broadly based on materiality and supervisory 12. judgement.
Application of One respondent asked to apply increased For class 1 TCBs, competent authorities should No change proportionality proportionality for class 1 branches which are part of a apply at a minimum the level of supervisory G-SII and allow for a lower assessment frequency of engagement for category 3 institutions as set the SREP elements than an annual review.
FINAL REPORT ON THE REVISED SREP GUIDELINES
out in table 1 of section 2.4.5, thus evaluating all SREP elements at least every three years.
As for all SREP categories, competent authorities should provide an annual summary of the overall SREP assessment.
Home-host Several respondents focused on structured home–host The modalities for the cooperation between No change cooperation cooperation and information sharing, and requested competent authorities and the functioning of clearer channels for information sharing, and colleges of supervisors for third-country consultation with the home authority where host branches under Article 48p of Directive measures depend on group-level policies, systems or 2013/36/EU are set out in draft Regulatory arrangements. Technical Standards on cooperation and colleges of supervisors for third-country branches (EBA/RTS/2026/02) published on the EBA website in January 2026 and submitted to the European Commission for adoption. In line with the requirement under Article 48p(b) and (c) of Directive 2013/36/EU, the draft Regulatory Technical Standards also provide for competent authorities to exchange information on the results of the SREP and to endeavour to align the application of the supervisory measures and powers referred to in Article 48o of Directive 2013/36/EU.
FINAL REPORT ON THE REVISED SREP GUIDELINES
Branch A few respondents raised concerns about excessive Whereas a branch is, by nature, a legally No change independence expectations of branch ‘independence’, stressing that dependent part of its parent institution and can branches are legally dependent parts of the parent be subject to a range of intragroup and that requirements should remain proportionate dependencies such as for funding/liquidity and avoid costly duplication of resources. support, risk transfer arrangements, shared services/ICT reliance, and outsourcing to group entities, the branch is functioning in a local context and is subject to legal requirements and local supervision to ensure consumer protection and safeguarding of financial stability. Hence it should ensure sufficient independence towards the group in terms of governance and risk management to safeguard its safety, soundness and viability and its capacity to fulfil its commitment to clients and counterparties.
Use of One respondent asked for clarification of access to The current provision limits the access to Paragraph 515 has subcontractors information when using subcontractors and suggested information to the information that is required been updated to the wording should be amended to avoid overly broad for the third-country branch to exercise its clarify the access to interpretations by limiting the scope to information monitoring. The wording in paragraph 515 has information for the head undertaking has access to and that is been amended to clarify the access to exercising the necessary for the third-country branch to exercise its information for exercising the monitoring monitoring monitoring obligations, including when subcontractors obligations of the third-country branch. obligations of the are used. third-country branch
FINAL REPORT ON THE REVISED SREP GUIDELINES
Aggregation of A few respondents asked for clarification on the The criteria for the scoring of the viability of No change SREP score aggregation logic for the SREP outcomes for third- third-country branches are in line with the country branches, and how the overall viability score is general approach used for scoring in the SREP derived from the individual components. GL, providing flexibility to competent authorities to adapt the weightings of individual components and aggregate them into the overall score of the viability of the third-country branch defined as its proximity to a point of nonviability on the basis of the evaluation of whether the arrangements, strategies, processes and mechanisms implemented and the capital endowment and liquidity held by the thirdcountry branch ensure a sound management and coverage of its material risks.
Communication of A few respondents asked for clarification on the Paragraph 528 has been added to provide clarity Paragraph 528 SREP outcomes modalities for the communication of the SREP on the modalities for the communication of the added to provide outcomes for third-country branches to branch SREP outcomes and related measures for third- clarity on modalities management, to the head undertaking and to the country branches in terms of communication to for communication authority responsible for the supervision of the head the management of the third-country branch, of SREP outcomes undertaking (the ‘home authority’), and how findings and to the authority responsible for the for third-country interact with group-level remediation. supervision of the head undertaking in branches accordance with the administrative agreements or other arrangements concluded under Article 48c(2) of Directive 2013/36/EU.
Fotnoter
- 1 Competent authorities supervising class 2 and class 3 investment firms that are subject to the requirements under IFD/IFR are covered by the SREP Guidelines for investment firms (EBA/GL/2022/09) and by the Commission Delegated Regulation (EU) 2023/1668 on additional own funds requirements for investment firms. 2 Opinion of the European Banking Authority on interaction between Pillar 2 requirements and the output floor (EBA/Op/2025/01).
- Figure 1: Overview of the SREP framework
- 4 Basel Committee on Banking Supervision – Principles for effective risk data aggregation and risk reporting (January 2013)
- 5 BCBS Basel III: Finalising post-crisis reforms – December 2017. 6 Aimed at limiting the unwarranted variability in the own funds requirements produced by internal models relative to an institution using the standardised approaches.
- Figure 2: High-level and flexible escalation framework for supervisory measures
- 7 Joint Guidelines (JC 2025 78) to ensure that consistency, long-term considerations and common standards for assessment methodologies are integrated into the stress testing of environmental, social and governance risks pursuant to Article 100(4) of Directive 2013/36/EU and Article 304c(3) of Directive 2009/138/EC.
- 8 EBA Guidelines on triggers for use of early intervention measures (EBA/GL/2015/03). 9 EBA Guidelines on the interpretation of the different circumstances when an institution shall be considered as failing or likely to fail under Article 32(6) of Directive 2014/59/EU (EBA/GL/2015/07).
- Figure 3: Link between ongoing supervision, early intervention and failing or likely to fail
- 10 Regulation (EU) No 1093/2010 of the European Parliament and of the Council of 24 November 2010 establishing a European Supervisory Authority (European Banking Authority), amending Decision No 716/2009/EC and repealing Commission Decision 2009/78/EC, (OJL 331, 15.12.2010, p.12, ELI: http://data.europa.eu/eli/reg/2010/1093/oj).
- 11 Directive 2013/36/EU of the European Parliament and of the Council of 26 June 2013 on access to the activity of credit institutions and the prudential supervision of credit institutions and investment firms, amending Directive 2002/87/EC and repealing Directives 2006/48/EC and 2006/49/EC (OJL 176 27.6.2013, p. 338, ELI: http://data.europa.eu/eli/dir/2013/36/oj).
- 12 Regulation (EU) No 575/2013 of the European Parliament and of the Council of 26 June 2013 on prudential requirements for credit institutions and investment firms and amending Regulation (EU) No 648/2012 (OJL 176 27.6.2013, p. 1, ELI: http://data.europa.eu/eli/reg/2013/575/oj). 13 Directive 2014/59/EU of the European Parliament and of the Council of 15 May 2014 establishing a framework for the recovery and resolution of credit institutions and investment firms and amending Council Directive 82/891/EEC, and Directives 2001/24/EC, 2002/47/EC, 2004/25/EC, 2005/56/EC, 2007/36/EC, 2011/35/EU, 2012/30/EU and 2013/36/EU, and Regulations (EU) No 1093/2010 and (EU) No 648/2012 of the European Parliament and of the Council (OJ L 173 12.6.2014, p. 190, ELI: http://data.europa.eu/eli/dir/2014/59/oj). 14 EBA Guidelines on institutions’ stress testing (EBA/GL/2018/04).
- 15 EBA Guidelines on the characteristics of a risk-based approach to anti-money laundering and terrorist financing supervision, and the steps to be taken when conducting supervision on a risk-sensitive basis under Article 48(10) of Directive (EU) 2015/849 (amending the Joint Guidelines ESAs 2016 72) (‘The Risk-Based Supervision Guidelines’) (EBA/GL/2021/16).
- 16 In accordance with Article 104a(1)(b) of Directive 2013/36 of the European Union and of the Council on access to the activity of credit institutions and the prudential supervision of credit institutions, amending Directive 2002/87/EC and repealing Directives 2006/48/EC and 2006/49/EC (OJL 176 27.6.2013, p. 338, ELI: http://data.europa.eu/eli/dir/2013/36/2026-01-11).
- Figure 1. Overview of the scoring framework
- 17 EBA Guidelines on the interpretation of the different circumstances when an institution shall be considered as failing or likely to fail under Article 32(6) of Directive 2014/59/EU (EBA/GL/2015/07). 18 EBA Guidelines on triggers for use of early intervention measures (EBA/GL/2015/03).
- 19 Commission Implementing Regulation (EU) No 710/2014 of 23 June 2014 laying down implementing technical standards with regard to conditions of application of the joint decision process for institution-specific prudential requirements according to Directive 2013/36/EU of the European Parliament and of the Council (OJL 188, 27.6.2014, p. 19, ELI: http://data.europa.eu/eli/reg_impl/2014/710/oj). 20 Regulation (EU) No 596/2014 of the European Parliament and of the Council of 16 April 2014 on market abuse (market-abuse regulation) and repealing Directive 2003/6/EC of the European Parliament and of the Council and Commission Directives 2003/124/EC, 2003/125/EC and 2004/72/EC (OJL 173, 12.6.2014, p. 1). 21 Directive 2014/57/EU of the European Parliament and of the Council of 16 April 2014 on criminal sanctions for market abuse (market-abuse directive) (OJL 173, 12.6.2014, p.179, ELI: http://data.europa.eu/eli/reg/2014/596/oj). 22 Directive 2004/109/EC of the European Parliament and of the Council of 15 December 2004 on the harmonisation of transparency requirements in relation to information about issuers whose securities are admitted to trading on a regulated market and amending Directive 2001/34/EC (OJL 390, 31.12.2004, p.38, ELI: http://data.europa.eu/eli/dir/2004/109/oj).
- Table 1. Application of SREP to different categories of institutions
- Minimum level of engagement/dialogue with Monitoring of key Evaluation of all SREP Summary of the overall Category institution’s management indicators elements (at least)* SREP assessment body and senior management
- 1 Quarterly Annual Annual Continuous/ongoing 2 Quarterly Every 2 years Annual Continuous/ongoing Risk-based at least every 3 3 Quarterly Every 3 years Annual years Every 3 years, extensible Risk-based at least every 3 4 Quarterly Annual to 5 years** years *With the focus and granularity of the review tailored to reflect the risk profile of the institution, materiality of the different risks, and trends and emerging risks identified through supervisory activities. This can be based on previous assessments if nothing has materially changed in accordance with the available information (e.g. monitoring of indicators and reporting), regardless of the categorisation of the institution. **The minimum frequency for assessing all SREP elements can be extended from 3 to 5 years for category 4 institutions provided that: (i) they have a stable low-risk profile, stable financial metrics and healthy margins; and (ii) the quarterly monitoring of KRIs does not give rise to concerns.
- As defined in Article 3(9) of Directive 2013/36 of the European Union and of the Council on access to the activity of credit institutions and the prudential supervision of credit institutions, amending Directive 2002/87/EC and repealing Directives 2006/48/EC and 2006/49/EC (OJL 176 27.6.2013, p. 338, ELI: http://data.europa.eu/eli/dir/2013/36/2026-01- 11).
- 24 If not waived in the context of simplified obligations as determined in article 4 of Directive 2014/59/EU of the European Parliament and of the Council of 15 May 2014 establishing a framework for the recovery and resolution of credit institutions and investment firms and amending Council Directive 82/891/EEC, and Directives 2001/24/EC, 2002/47/EC, 2004/25/EC, 2005/56/EC, 2007/36/EC, 2011/35/EU, 2012/30/EU and 2013/36/EU, and Regulations (EU) No 1093/2010 and (EU) No 648/2012, of the European Parliament and of the Council (OJL L 173, 12.6.2014, p. 190, ELI: http://data.europa.eu/eli/dir/2014/59/oj).
- 25 In accordance with the EBA AML/CFT Cooperation Guidelines (EBA/GL/2021/15).
- Table 2. Supervisory considerations for assigning a business model score
- Score Supervisory view Considerations
- • The institution has a strong competitive position in its chosen markets The business model and a strategy likely to reinforce this. and strategy pose a • The institution generates strong and stable returns which are 1 low level of risk to the commensurate to the risk it takes on, given its risk appetite and viability of the funding structure and that are not driven by excessive risk-taking, or institution. reliance on an unrealistic strategy.
- Score Supervisory view Considerations
- • There are no material asset concentrations or unsustainable concentrated sources of income. • The institution has financial forecasts drawn up based on plausible assumptions about the future business environment. • The institution addresses strategic implications of material ESG risks, in particular environmental transition and physical risks, for its business model in the short, medium and long term through a robust transition planning process. • Strategic plans are appropriate given the current business model and management execution capabilities. • The institution faces competitive pressure on its products/services in one or more key markets. There is some doubt about its strategy to address the situation. • The institution generates average returns compared to peers and/or historic performance which are broadly commensurate to the risk it takes on, given its risk appetite and funding structure. The business model • There are some asset concentrations or concentrated sources of and strategy pose a income. 2 medium-low level of • The institution has financial forecasts drawn up based on optimistic risk to the viability of assumptions about the future business environment. the institution. • The institution broadly addresses strategic implications of material ESG risks, in particular environmental transition and physical risks, for its business model through an overall reasonable yet not fully robust transition planning process. • Strategic plans are reasonable given the current business model and management execution capabilities, but not without risk. • The institution has a weak competitive position for its products/services in its chosen markets and may have few business lines with good prospects. The institution’s market share may be declining significantly. There are doubts about its strategy to address the situation. • The institution generates returns that are often weak or unstable or not commensurate to the risk it takes given its risk appetite or funding The business model structure and that raise supervisory concerns. and strategy pose a • There are material asset concentrations or concentrated sources of 3 medium-high level of income. risk to the viability of • The institution has financial forecasts drawn up based on overly the institution. optimistic assumptions about the future business environment. • The institution addresses strategic implications of material ESG risks, in particular environmental transition and physical risks, for its business model only partially. Its transition planning process shows some weaknesses and/or deficiencies. • Strategic plans may not be plausible given the current business model and management execution capabilities. • The institution has a very poor competitive position for its The business model products/services in its chosen markets and participates in business and strategy pose a lines with very weak prospects. Strategic plans are very unlikely to 4 high level of risk to address the situation. the viability of the • The institution generates very weak and highly unstable returns or institution relies on an unacceptable risk appetite or funding structure to generate appropriate returns.
- Score Supervisory view Considerations
- • The institution has extreme asset concentrations or unsustainable concentrated sources of income. • The institution has financial forecasts drawn up based on very unrealistic assumptions about the future business environment. • The institution is exposed to material ESG risks, in particular environmental transition and physical risks, and does not address strategic implications for its business model. Its transition planning process is inconsistent with the broader business strategy. Its transition planning process shows severe weaknesses and/or deficiencies. • Strategic plans are not plausible given the current business model and management execution capabilities.
- Table 3. Potential and non-exhaustive list of supervisory measures stemming from the BMA
- Potential supervisory measures for competent authorities in accordance with Article 104(1)(b), (d), (e), (f), (m), (n) of Directive 2013/36/EU – Competent authorities may require the institution to:
- A. adjust the financial plan assumed in the strategy, if it is not supported by internal capital planning or credible assumptions; B. make changes to organisational structures, reinforcement of risk management and control functions and arrangements to support the implementation of the business model or strategy; C. make changes to and reinforcement of IT systems to support the implementation of the business model or strategy; D. make changes to the business model or strategy; E. reduce the risk inherent in the products they originate/distribute, including requiring changes to the risks inherent in certain product offerings; and/or requiring improvements to the governance and control arrangements for product development and maintenance; D. reduce the risk inherent in its systems, including requiring improvements to the systems, or increasing the level of investment or speeding-up the implementation of new systems; and/or requiring improvements to the governance and control arrangements for system development and maintenance; G. reduce the risk inherent in their activities, including outsourced activities and requiring changes to or reduction of certain activities with a view to reducing their inherent risk; and/or requiring improvements to governance and control arrangements and oversight of outsourced activities; H. reduce ESG risks, in particular environmental risks, through adjustments to its business strategy, for which a reinforcement of the targets, measures, and actions included in the institution’s plan to be prepared in accordance with Article 76(2) of Directive 2013/36/EU could be requested.
- 27 EBA/GL/2021/05 28 EBA/GL/2021/06
- 30 DORA - Regulation (EU) No 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU)No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 (OJ L 333, 27.12.2022, p.1, ELI: http://data.europa.eu/eli/reg/2022/2554/oj).
- 31 EBA Guidelines on ICAAP and ILAAP information collected for SREP purposes (EBA/GL/2016/10). 32 EBA Guidelines on stress testing (EBA/GL/2018/04).
- 33 For the purposes of this paragraph, stress tests do not extend to reverse stress tests.
- 34 Basel Committee on Banking Supervision Principles for effective risk data aggregation and risk reporting (BCBS 239).
- Table 4. Supervisory considerations for assigning a score for internal governance and institution-wide controls
- Score Supervisory view Considerations
- • The institution has a robust and transparent organisational structure with clear responsibilities and separation of risk-taking from risk management and control functions. • The composition and functioning of the management body are appropriate. • The time commitment of the management body members is appropriate and they Deficiencies in internal governance comply with the limitation on the number of and institution-wide control directorships, where relevant.
- arrangements pose a low level of • There is a sound risk culture and business risk to the viability of the institution. conduct, including management of conflicts of interest and whistleblowing processes. • The institution has adopted a diversity policy that fosters a diverse management body composition and complies with the targets set. • The remuneration policy is in line with the institution’s risk strategy and long-term interests.
- Score Supervisory view Considerations
- • The risk management framework and risk management processes, including the ICAAP, ILAAP, NPAP, stress testing framework, capital planning and liquidity planning, are appropriate. • The internal control framework and internal controls are appropriate. • The risk management, compliance and internal audit functions are independent, operate effectively, have sufficient resources, and the internal audit function operates in accordance with established international standards and requirements. • ICT systems, risk data aggregation and risk reporting are appropriate. • The integration of ESG risks into the internal governance and risk management framework is appropriate. • The recovery planning governance framework is appropriate. • The institution addresses swiftly identified deficiencies and/or concerns expressed by competent authorities and effectively remediates them within a short timeframe providing satisfactory outcomes. Additionally, the institution proactively reports and informs the competent authorities throughout this process. • The institution has a largely robust and transparent organisational structure with clear responsibilities and separation of risktaking from risk management and control functions. • The composition and functioning of the management body are largely appropriate. • The time commitment of the management body members is largely appropriate, and, where relevant, they comply with the Deficiencies in internal governance limitation on the number of directorships. and institution-wide control • There is a largely sound risk culture and 2 arrangements pose a medium-low business conduct, including management of level of risk to the viability of the conflicts of interest and whistleblowing institution. processes. • The institution has adopted a diversity policy that fosters a diverse management body composition, and largely complies with the targets set or has implemented appropriate measures to achieve the targets set in the policy. • The remuneration policy is largely in line with the institution’s risk strategy and long-term interests.
- Score Supervisory view Considerations
- • The risk management framework and risk management processes, including the ICAAP, ILAAP, NPAP, stress testing framework, capital planning and liquidity planning, are largely appropriate. • The internal control framework and internal controls are largely appropriate. • The risk management, compliance and internal audit functions are independent and their operations are largely effective. • ICT systems, risk data aggregation and risk reporting are largely appropriate. • The integration of ESG risks into the internal governance and risk management framework is largely appropriate. • The recovery planning governance framework is largely appropriate. • The institution is able to adequately address most of the deficiencies identified and/or concerns expressed by competent authorities, within an acceptable timeframe and – where applicable – complies with the reporting requirements set by the competent authorities in relation to these deficiencies. • The institution’s organisational structure and responsibilities are not fully transparent and risk-taking is not fully separated from risk management and control functions. • There are doubts about the appropriateness of the composition and functioning of the management body. • There are doubts about the appropriate time commitment of the management body member and where relevant they do not comply with the limitation on the number of Deficiencies in internal governance directorships. and institution-wide control • There are doubts about the appropriateness 3 arrangements pose a medium-high of the risk culture and business conduct, level of risk to the viability of the including management of conflicts of interest institution. and/or whistleblowing processes. • The institution has not adopted a diversity policy and has not implemented measures to achieve an appropriate level of diversity within the management body. • There are concerns that the remuneration policy may not be aligned with the institution’s risk strategy and long-term interests. • There are doubts about the appropriateness of the risk management framework and risk management processes, including the ICAAP,
- Score Supervisory view Considerations
- ILAAP, NPAP, stress testing framework, capital planning and/or liquidity planning. • There are doubts about the appropriateness of the internal control framework and internal controls. • There are doubts about the independence and effective operation of the risk management, compliance and internal audit functions. • There are doubts about the appropriateness of ICT systems, risk data aggregation and risk reporting. • There are doubts about the appropriateness of the integration of ESG risks into the internal governance and risk management framework. • The recovery planning governance framework was assessed as potentially having material deficiencies and/or having material impediments to its effective implementation and supervisory concerns have not been fully addressed. • The institution faces significant challenges or demonstrates limited intention to adequately address the deficiencies identified and/or concerns expressed by competent authorities, in terms of the quality of the remediation actions and/or the timeframe for their implementation, which might indicate the need for escalation. The institution also has challenges in reporting on its remediation status to competent authorities. • The institution’s organisational structure and responsibilities are not transparent and risktaking is not separated from risk management and control functions. • The composition and functioning of the management body are inappropriate. • The time commitment of the management body members is insufficient, and, where Deficiencies in internal governance relevant, they do not comply with the and institution-wide control 4 limitation on the number of directorships. arrangements pose a high level of • The risk culture and business conduct, risk to the viability of the institution. including management of conflicts of interest and/or whistleblowing processes are inappropriate. • The institution has not adopted a diversity policy, the management body is not diverse and the institution has not implemented measures to aim for an appropriate level of diversity.
- Score Supervisory view Considerations
- • The remuneration policy is not aligned with the institution’s risk strategy and long-term interests. • The risk management framework and the risk management processes, including the ICAAP, ILAAP, NPAP, stress testing framework, capital planning and/or liquidity planning, are inappropriate. • The risk management, compliance and/or internal audit functions are not independent, not operating effectively and/or the internal audit function is not operating in accordance with established international standards and requirements. • The internal control framework and internal controls are inappropriate. • The ICT systems, risk data aggregation and risk reporting are inappropriate. • The integration of ESG risks into the internal governance and risk management framework is inappropriate. • The recovery planning governance framework was assessed as having material deficiencies and/or having material impediments to its effective implementation and supervisory concerns have not been fully addressed. • The institution is unable or does not intend to adequately address deficiencies identified and/or concerns expressed by competent authorities and lacks the capability to remedy them within an acceptable timeframe, following escalation from competent authorities. The institution also has severe challenges in reporting on its remediation status to competent authorities.
- Table 5. Potential and non-exhaustive list of supervisory measures stemming from the assessment of institution’s internal
- governance and institution-wide controls
- Potential supervisory measures for competent authorities in accordance with Article 104(1) points (b), (d), (e), (f), (g), (j), (l, (m), and (n) of Directive 2013/36/EU and Article 50 of Regulation (EU) 2022/2554 – Competent authorities may require the institution to:
- A. enhance and have a more active involvement of the management body or its committees; B. develop and implement corrective action plans to address deficiencies; C. strengthen internal controls; D. improve the internal governance framework; E. enhance reporting mechanisms and oversight; F. limit variable remuneration; G. implement compliance management systems; H. have additional or more frequent reporting requirements; I. reinforce specific arrangements, processes, mechanisms and strategies; J. reperform stress tests using modified assumptions; K. enhance governance and risk management arrangements applied to ESG risks, in particular environmental risks.
- 36 Recommendation of the European Systemic Risk Board of 21 September 2011 on lending in foreign currencies (ESRB/2011/1) (OJC 342, 22.11.2011, p.1).
- Figure 2. Assessment workflow for risks to capital
- 37 Please refer to Annex I for a non-exhaustive breakdown of credit risk sub-categories and further details on their assessment.
- Table 6. Supervisory considerations for assigning a credit and counterparty risk score
- Considerations in relation to Risk Considerations in relation to Supervisory view adequate management and score inherent risk controls
- • The nature and composition of
- credit risk exposure imply non- • Risk management and controls material risk/very low risk. are adequate with respect to • Exposure to complex products the requirements set out in the and transactions is not relevant EBA Guidelines. material/very low. • There is consistency between • The level of credit the institution’s credit-risk concentration risk is not policy and strategy and its material/very low. overall strategy and risk • The level of forborne and non- There is a low risk of appetite. performing exposures is not significant • The organisational framework material/very low. prudential impact for credit risk is robust with • The credit risk posed by on the institution clear responsibilities and performing exposures is not 1 considering the separation of tasks between material/very low. level of inherent risk risk takers and management • The impact of ESG risks, in and the and control functions. particular environmental management and • Credit-risk measurement, transition and physical risks, on controls. monitoring and reporting credit risk is not material/very systems are appropriate. low. • Internal limits and the control • The level of coverage of framework for credit risk are provisions and of credit sound. valuation adjustments are • Limits allowing the credit risk to adequate and reliable to a very be mitigated or limited are in high level of certainty. line with the institution’s credit • The level of coverage and risk management strategy and quality of guarantees and risk appetite. collateral are very high. • ESG risks, in particular There is a medium- • The nature and composition of environmental transition and low risk of credit risk exposure imply low physical risks, are properly significant to medium risk. 2 integrated into the credit risk prudential impact • Exposure to complex products management and controls. on the institution and transactions is low to
- considering the medium.
- EBA/REP/2023/29.
- Considerations in relation to Risk Considerations in relation to Supervisory view adequate management and score inherent risk controls
- level of inherent risk • The level of credit and the concentration risk is low to management and medium. controls. • The level of forborne and nonperforming exposures is low to medium. • The credit risk posed by performing exposures is low to medium. • The impact of ESG risks, in particular environmental transition and physical risks, on credit risk is low to medium. • The level of coverage of provisions and of credit valuation adjustments are adequate and reliable to a high level of certainty. • The level of coverage and quality of guarantees and collateral are high. • The nature and composition of • Risk management and controls credit risk exposure imply are not compliant with respect medium to high risk. to the requirements set out in • Exposure to complex products the relevant EBA Guidelines. and transactions is medium to • There is a lack of consistency high. between the institution’s • The level of credit credit-risk policy and strategy concentration risk is medium to and its overall strategy and risk high. appetite. There is a medium- • The level of forborne and non- • The organisational framework high risk of performing exposures is for credit risk is not sufficiently significant medium to high. robust; there is no clear prudential impact • The credit risk posed by separation of tasks between on the institution performing exposures is risk takers or management and 3 considering the medium to high and subject to control functions. level of inherent risk further deterioration under • Credit-risk measurement, and the stressed conditions. monitoring and reporting management and • The impact of ESG risks, in systems are not appropriate. controls. particular environmental • Internal limits and the control transition and physical risks, on framework for credit risk are credit risk is medium to high. not sufficiently sound. • The level of coverage of • Limits allowing the credit risk to provisions and of credit be mitigated or limited are not valuation adjustments is in line with the institution’s medium. credit risk management • The level of coverage and strategy and risk appetite. quality of guarantees and • ESG risks, in particular collateral are medium. environmental transition and
- Considerations in relation to Risk Considerations in relation to Supervisory view adequate management and score inherent risk controls
- • The nature and composition of physical risks, are insufficiently credit risk exposure imply high integrated into the credit risk risk. management and controls. • Exposure to complex products and transactions is high. • The level of credit There is a high risk concentration risk is high. of significant • The level of forborne and nonprudential impact performing exposures is high. on the institution • The credit risk posed by 4 considering the performing exposures is high. level of inherent risk • The impact of ESG risks, in and the particular environmental management and transition and physical risks, on controls. credit risk is high. • The level of coverage of provisions and of credit valuation adjustments is low. • The level of coverage and quality of guarantees and collateral are low.
- Table 7. Potential and non-exhaustive supervisory measures for credit and counterparty risk
- Potential supervisory measures for competent authorities in accordance with Article 104(1)(b), (d), (e), (f), (j), (l), (m), (n) of Directive 2013/36/EU – Competent authorities may require the institution to:
- A. involve the management body or its committees more actively in relevant credit decisions; B. improve credit risk measurement systems; C. improve controls on credit processes, including credit granting, monitoring and recovery; D. enhance collateral management, evaluation and monitoring; E. enhance the quality and frequency of reporting on credit risk to the management body and senior management; F. apply a specific provisioning policy, and – where permitted by accounting rules and regulations – require it to increase provisions; G. adjust internal risk parameters and/or risk weights used to calculate risk exposure amounts for specific products, sectors or types of obligors; H. apply higher haircuts to the value of collateral; I. reduce large exposures or other sources of credit concentration risk; J. tighten credit-granting criteria for all or some product or obligor categories; K. reduce its exposure to, or acquire protection for, specific types of facilities (e.g. mortgages, export finance, commercial real estate, securitisations), obligor categories, sectors, countries, etc.; L. implement an appropriate strategy to reduce the amount or share of nonperforming exposure;
- Potential supervisory measures for competent authorities in accordance with Article 104(1)(b), (d), (e), (f), (j), (l), (m), (n) of Directive 2013/36/EU – Competent authorities may require the institution to:
- M. enhance the credit risk management related to ESG risks, in particular environmental risks, potentially based on one or several actions listed above.
- 39 Please refer to Annex II for a non-exhaustive breakdown of market risk sub-categories. 40 Migration risk is treated as part of credit spread risk under the Fundamental Review of the Trading Book.
- Table 8. Supervisory considerations for assigning a market risk score
- Considerations in relation to Risk Considerations in relation to Supervisory view adequate management and score inherent risk controls
- • The nature and • There is consistency composition of market risk between the institution’s exposures imply not market risk policy and material/very low risk. strategy and its overall There is a low risk of significant • The institution’s exposures strategy and risk appetite. prudential impact on the to market risk are non- • The organisational 1 institution considering the complex. framework for market risk level of inherent risk and the • The level of market risk is robust, with clear management and controls. concentration is not responsibilities and a clear material/very low. separation of tasks • The institution’s market between risk-takers and risk exposures generate management and control non-volatile returns. functions. • Market risk measurement, • The nature and monitoring and reporting There is a medium-low risk of composition of market risk systems are appropriate. significant prudential impact exposures imply low to • Internal limits and the 2 on the institution considering medium risk. control framework for the level of inherent risk and • The complexity of the market risk are sound and the management and controls. institution’s market risk in line with the institution’s risk
- Considerations in relation to Risk Considerations in relation to Supervisory view adequate management and score inherent risk controls
- exposures is low to management strategy and
- medium. risk appetite. • The level of market risk
- concentration is low to
- medium. • The institution’s market
- risk exposures generate
- returns that have a low to
- medium degree of
- volatility.
- • The nature and
- composition of market risk • There is not full exposures imply medium consistency between the to high risk. institution’s market risk • The complexity of the policy and strategy and its institution’s market risk There is a medium-high risk of overall strategy and risk exposures is medium to significant prudential impact profile. high. 3 on the institution considering • The organisational • The level of market risk the level of inherent risk and framework for market risk concentration is medium the management and controls. does not sufficiently to high. separate responsibilities • The institution’s exposures and tasks between to market risk generate risktakers and returns that have a management and control medium to high degree of functions. volatility. • Market risk measurement, • The nature and monitoring and reporting composition of market risk systems are not exposures imply high risk. undertaken with sufficient • The complexity of the There is a high risk of accuracy and frequency. institution’s market risk significant prudential impact • Internal limits and the exposures is high. 4 on the institution considering control framework for • The level of market risk the level of inherent risk and market risk are not in line concentration is high. the management and controls. with the institution’s risk • The institution’s exposures management strategy or to market risk generate risk appetite. returns that have a high
- degree of volatility.
- Table 9. Potential and non-exhaustive supervisory measures for market risk
- Potential supervisory measures for competent authorities in accordance with Article 104(1)(b), (d), (e), (f), (j), (l) (m), (n) of Directive 2013/36/EU – Competent authorities may require the institution to:
- A. enhance the quality and frequency of the market risk reporting to the institution’s management body and senior management; B. enhance the performance of the institution’s internal approaches, or of its back-testing or stress testing capacity; C. perform more frequent and in-depth internal audits of market activity; D. restrict investment in certain products when the institution’s policies and procedures do not ensure that the risk from those products will be adequately covered and controlled; E. divest financial products when the valuation processes of the institution do not produce conservative valuations that comply with the standards of Regulation (EU) No 575/2013; F. reduce the level of inherent market risk (e.g. through hedging or sale of assets or increase of derivatives settled through central counterparties (CCPs)) when significant shortcomings have been found in the institution’s measurement or control systems; G. present a plan to reduce its exposures to distressed assets and/or illiquid positions gradually.
- 41 Please refer to Annex III for a non-exhaustive breakdown of operational risk sub-categories.
- 42 EBA Guidelines on internal policies, procedures and controls to ensure the implementation of Union and national restrictive measures (EBA/GL/2024/14)
- 45 In accordance with DORA, these should include at least the information security policy, backup policies, ICT asset management policy, encryption and cryptographic controls policy, cryptographic key management policy, ICT project management policy, acquisition, development, and maintenance of ICT systems policy, human resources policy, physical and environmental security policy, ICT-related incident management policy, policy on the use of ICT services supporting critical or important functions provided by ICT third-party service providers.
- 46 ESAs’ Joint Guidelines on the oversight cooperation and information exchange between the ESAs and the competent authorities under Regulation (EU) 2022/2554 (JC/2024/36).
- 47 Commission Delegated Regulation (EU) 2024/1772 of 13 March 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the criteria for the classification of ICT-related incidents and cyber threats, setting out materiality thresholds and specifying the details of reports of major incidents, C/2024/1519 (OJL, 2024/1772, 25.6.2024, ELI: http://data.europa.eu/eli/reg_del/2024/1772/oj).
- Table 10. Supervisory considerations for assigning an operational risk score
- Considerations in relation to Risk Supervisory Considerations in relation to adequate management and score view inherent risk controls
- • Operational risk exposures are • There is consistency between limited to a few highthe institution’s operational risk frequency/low-severity impact policy and strategy and its categories. overall strategy and risk • The significance of the appetite. exposure to operational risk is • The organisational framework not material/very low, as for operational risk is robust There is a low shown by scenario analysis and with clear responsibilities and a risk of compared with the losses of clear separation of tasks significant peers. between risk-takers and prudential • The level of gross losses (before management and control impact on the recoveries and including losses functions. institution on credit portfolio caused by 1 • Operational risk framework considering the operational risk) experienced includes all relevant risks. level of by the institution in recent • Operational risk measurement, years has been not inherent risk monitoring and reporting material/very low or has and the systems are appropriate. decreased from a higher level. management • The control framework for • No significant ICT risk and controls. operational risk is sound. exposures, • ICT risk management and simple/resilient/agile ICT controls are adequate with architecture and no respect to the requirements set material/very low ICT risks. out in DORA. • The level of concentration risk • Third-party risk management towards third-party service framework is sound and providers is low, with simple effective, along with subcontracting chains.
- Considerations in relation to Risk Supervisory Considerations in relation to adequate management and score view inherent risk controls
- • The threat intensity that could appropriate contractual
- result into major operational arrangements. disruption (including ICT- • Effective and sound business
- related incidents) of critical or continuity management,
- important functions is low. including tested business • Operational risk exposures are continuity, response and
- mainly in high-frequency/low- recovery plans.
- severity impact categories. • The significance of the
- exposure to operational risk is
- low to medium, as shown by
- scenario analysis and compared
- There is a with the losses of peers. • The level of gross losses medium-low experienced by the institution risk of in recent years has been low to significant medium, or is expected to prudential increase from a lower historic impact on the level or decrease from a higher 2 institution historic level. considering the • Low ICT risk exposures,
- level of moderately complex/partially inherent risk constrained ICT architecture
- and the and low/medium ICT risks.
- management • The level of concentration risk
- and controls. towards third-party service
- providers is medium, with
- moderate subcontracting
- chains. • The threat intensity that could
- result into major operational
- disruption (including ICT-
- related incidents) of critical or
- important functions is medium. • Operational risk exposures • The consistency between the There is a extend to some lowinstitution’s operational risk medium-high frequency/high-severity impact policy and strategy and its risk of categories. overall strategy and risk significant • The significance of the appetite is not sufficiently prudential exposure to operational risk is developed or even inadequate. impact on the medium to high, as shown by • The organisational framework 3 institution scenario analysis and compared for operational risk is not considering the with the losses of peers. sufficiently robust. • The level of gross losses level of • Operational risk framework experienced by the institution inherent risk does not include all relevant in recent years has been and the risks. medium to high, or is expected management • Operational risk measurement, to increase from a lower and controls. monitoring and reporting historic level or decrease from a systems are inappropriate. higher historic level.
- Considerations in relation to Risk Supervisory Considerations in relation to adequate management and score view inherent risk controls
- • Indications of possible • The control framework for significant ICT risk exposures, operational risk is tenuous. complex/rigid/fragmented ICT • ICT risk management and architecture and medium/high controls are not compliant with ICT risks. respect to the requirements set • The level of concentration risk out in DORA. towards third-party service • Third-party risk management providers is high, with framework is incomplete/weak, moderate to long/complex along with inadequate subcontracting chains. contractual arrangements. • The threat intensity that could • Inadequate business continuity result into major operational management, including disruption (including ICT- unreliable/ineffective/incomple related incidents) of critical or te business continuity, response important functions is high. and recovery plans. • Operational risk exposures extend to all main categories. • The significance of the exposure to operational risk is high and increasing, as shown by scenario analysis and compared with the losses of There is a high peers. risk of • The level of gross losses significant experienced by the institution prudential over the last few years has impact on the been high, or risk has institution significantly increased. considering the • Multiple indications of 4 level of significant ICT risk exposures, inherent risk highly complex/fragile ICT and the architecture and high ICT risks. management • The level of concentration risk and controls. towards third-party service providers is very high/severe, with long/complex subcontracting chains. • The threat intensity that could result into major operational disruption (including ICTrelated incidents) of critical or important functions is very high/severe.
- and operational resilience
- Potential supervisory measures for competent authorities in accordance with Article 104(1), points (b), (d), (e), (f), (j), (l), (m), and (n) of Directive 2013/36/EU and Article 50 of Regulation (EU) 2022/2554 – Competent authorities may require the institution to:
- A. involve the management body or its committees more actively in operational risk management decisions; B. improve operational risk measurement systems; C. strengthen controls on operational processes, including identification, monitoring, response and recovery; D. improve the operational governance framework; E. enhance operational risk reporting to the management body and senior management; F. develop and implement corrective action plans to address deficiencies; G. limit certain third-party arrangements, in particular for critical or important functions; H. enhance stress testing and scenario analysis of operational risk; I. implement stronger operational measures; J. enhance business continuity, response and recovery plans; K. enhance operational risk management related to ESG risks, in particular environmental risks, potentially based on one or several actions listed above.
- 48 Please refer to Annex IV for a non-exhaustive breakdown of IRRBB sub-categories.
- 49 Also considering the guidance in EBA/2022/14.
- 50 Guidelines issued on the basis of Article 84 (6) of Directive 2013/36/EU specifying criteria for the identification, evaluation, management and mitigation of the risks arising from potential changes in interest rates and of the assessment and monitoring of credit spread risk, of institutions’ non-trading book activities (EBA/GL/2022/14).
- Table 12. Supervisory considerations for assigning an IRRBB and CSRBB score
- Risk Supervisory Considerations in relation to Considerations in relation to score view inherent risk adequate management and controls
- For IRRBB: For IRRBB and CSRBB: There is a low • The sensitivity of the economic • There is consistency between the
- risk of value to changes in interest rates institutions risk policy and significant is not material/very low. strategy for interest rate- and prudential • The sensitivity of earnings to credit spread risk and its overall
- impact on the changes in interest rates is not strategy and risk appetite. 1 institution material/very low. • The organisational framework for considering the • The sensitivity of the economic interest rate and credit spread level of inherent value and earnings to changes in risk is robust with clear risk and the the underlying assumptions (e.g. responsibilities and a clear management in the case of products with separation of tasks between riskand controls. embedded customer optionality) takers and management and are not material/very low. control functions. For IRRBB: • Interest rate and credit spread There is a • The sensitivity of the economic risk measurement, monitoring medium-low value to changes in interest rates and reporting systems are risk of is low to medium. appropriate. significant • The sensitivity of earnings to • There are clearly defined internal prudential changes in interest rates is low to policy limits together with their impact on the 2 medium. associated risk mitigation institution • The sensitivity of the economic measures, and the control considering the value and earnings to changes in framework for interest rate and level of inherent the underlying assumptions (e.g. credit spread risk (if material) that risk and the in the case of products with are sound and are in line with the management embedded customer optionality) institution’s risk strategy and risk and controls. is low to medium. . appetite. There is a For IRRBB: medium-high • There is inconsistency between • The sensitivity of the economic 3 risk of the institution’s risk policy and value to changes in interest rates significant strategy for interest rate- and is medium to high. prudential
- Risk Supervisory Considerations in relation to Considerations in relation to score view inherent risk adequate management and controls
- impact on the • The sensitivity of earnings to credit spread risk and its overall institution changes in interest rates is strategy and risk appetite. considering the medium to high. • The organisational framework for level of inherent • The sensitivity of the economic interest rate and credit spread risk and the value and earnings to changes in risk does not sufficiently separate management the underlying assumptions (e.g. responsibilities and tasks and controls. in the case of products with between risk-takers and embedded customer optionality) management and control is medium to high. functions. • Interest rate and credit spread For IRRBB: There is a high risk measurement, monitoring • The sensitivity of the economic risk of and reporting systems are not value to changes in interest rates significant undertaken with sufficient is high. prudential accuracy and frequency. • The sensitivity of earnings to impact on the • Internal policy limits, risk changes in interest rates is high. 4 institution mitigation measures and/or the • The sensitivity of the economic considering the control framework for interest value and earnings to changes in level of inherent rate and credit spread risk (if the underlying assumptions (e.g. risk and the material) are not aligned among in the case of products with management themselves or not in line with the embedded customer optionality and controls. institution’s risk strategy and risk is high.) appetite.
- Table 13. Potential and non-exhaustive supervisory measures for IRRBB and CSRBB
- Potential supervisory measures for competent authorities in accordance with Article 104(1), points (b), (d), (e), (f), (j), and (l) and Article 84(3) of Directive 2013/36/EU – Competent authorities may require the institution to:
- A. enhance their stress testing capacity; B. enhance the reporting of IRRBB management information to the management body and senior management; C. apply variations to internal limits to reduce the risk inherent in activities, products and systems; D. provide additional or more frequent reporting of the institutions’ IRRBB positions; E. use the standardised methodology for IRRBB; F. specify modelling and parametric assumptions, other than those identified by the EBA RTS (in accordance with the last paragraph of Article 98(5) of Directive 2013/36/EU.
- 51 At least 56.25% CET1 and at least 75% Tier 1.
- Table 14. Determination of TSCR in terms of CET1, T1 and total own funds
- TSCR = (a) + (b) Component (a) Component (b)
- Own funds requirement under P2R required to be held in CET1 In terms of CET1 Capital Article 92(1)(a), of Regulation (EU) capital in accordance with Section No 575/2013 7.2 Own funds requirement under P2R required to be to be held in Tier In terms of Tier 1 Capital Article 92(1)(b), of Regulation (EU) 1 capital in accordance with Section No 575/2013 7.2 Own funds requirement under Total P2R set in accordance with In terms of Total Own Funds Article 92(1)(c), of Regulation (EU) Section 7.2 No 575/2013
- 52 EBA Guidelines on overall recovery capacity in recovery planning (EBA/GL/2023/06) - Section II. Assessment of ORC – ‘adjusted ORC’.
- Table 15. Supervisory considerations for assigning a score to capital adequacy
- Score Supervisory view Considerations
- • The institution is able to comfortably meet its P2G and P2G LR. • The institution holds a level of own funds comfortably above its OCR and OLRR, and is expected to do so in the future. • Stress testing does not reveal any discernible risk regarding the impact of a severe but plausible economic downturn on own funds or leverage. • The free flow of capital between entities in the The quantity and composition of own group, where relevant, is not impeded, or all 1 funds held pose a low level of risk to the entities are well capitalised above supervisory viability of the institution. requirements. • The institution has a plausible and credible capital plan that has the potential to be effective if required. • The overall recovery capacity of the institution with regard to capital, resulting from the supervisory assessment, is ‘satisfactory’. • There is no material/a very low risk of excessive leverage. • The institution has difficulty meeting its P2G or P2G LR. Management mitigating actions to address this are assessed as credible. • The institution is near to breaching some of its capital buffers but is still clearly above its TSCR and TSLRR. • Stress testing reveals a low level of risk regarding the impact of a severe but plausible economic downturn on own funds or leverage, but management actions to address this seem The quantity and composition of own credible. 2 funds held pose a medium-low level of • The free flow of capital between entities in the risk to the viability of the institution. group, where relevant, is or could be marginally impeded. • The institution has a plausible and credible capital plan that, although not without risk, has the potential to be effective if required. • The overall recovery capacity of the institution with regard to capital, resulting from the supervisory assessment, is ‘satisfactory’ or ‘adequate with room for improvement’. • There is a low level of risk of excessive leverage. The quantity and composition of own • The institution does not meet its P2G or P2G LR. 3 funds held pose a medium-high level of There are concerns about the credibility of risk to the viability of the institution. management mitigating actions to address this.
- Score Supervisory view Considerations
- • The institution is using some of its capital buffers. There is potential for the institution to breach its TSCR or TSLRR if the situation deteriorates. • Stress testing reveals a medium level of risk regarding the impact of a severe but plausible economic downturn on own funds or leverage. Management actions may not credibly address this. • The free flow of capital between entities in the group, where relevant, is impeded. • The institution has a capital plan that is unlikely to be effective. • The overall recovery capacity of the institution with regard to capital, resulting from the supervisory assessment, is ‘adequate with room for improvement’ or ‘weak’. • There is a medium level of risk of excessive leverage. • The institution does not meet its P2G or P2G LR (or deliberately has not established P2G or P2G LR) and will not be able to do so in the foreseeable future. Management mitigating actions to address this are assessed as not credible. • The institution is near to breaching its TSCR or TSLRR. • Stress testing reveals that TSCR or TSLRR would The quantity and composition of own be breached near the beginning of a severe but 4 funds held pose a high level of risk to plausible economic downturn. Management the viability of the institution. actions will not credibly address this. • The free flow of capital between entities in the group, where relevant, is impeded. • The institution has no capital plan, or one that is manifestly inadequate. • The overall recovery capacity of the institution with regard to capital, resulting from the supervisory assessment, is ‘weak’ • There is a high level of risk of excessive leverage.
- Table 16. Potential and non-exhaustive supervisory measures for capital adequacy
- Potential supervisory measures for competent authorities in accordance with Article 104(1), points (a), (c) (h), (i), and (j), of Directive 2013/36/EU – Competent authorities may require the institution to:
- A. hold additional own funds requirements by setting TSCR and determining P2G, where relevant B. submit a credible capital plan that addresses the risk of not meeting its applicable capital requirements, in case the quantitative outcomes of the stress tests indicate that, under the given stress scenarios, an institution will not be able to meet the requirements, and set a deadline for its implementation; C. make changes to capital plans as appropriate, including to the proposed management actions, or take additional mitigating actions that would become relevant given the scenarios and current macroeconomic conditions; D. limit variable remuneration as a percentage of net revenues where it is inconsistent with the maintenance of a sound capital base; E. restrict or limit its business or operations or divest activities that pose excessive risks to its soundness; E. reduce the risk inherent in certain activities, products and systems of institutions, including activities provided by third-parties; F. use net profits to strengthen own funds; G. restrict or prohibit distributions or interest payments to shareholders, members or holders of Additional Tier 1 instruments where such a prohibition does not constitute an event of default; H. impose additional or more frequent reporting requirements, including reporting on own funds and leverage.
- Figure 3. Elements of the assessment of risks to liquidity and funding
- 54 The best practices are available in the EBA report: Monitoring of liquidity coverage ratio implementation in the EU – Second report (EBA/REP/2021/07).
- 56 In case the LCP is fully integrated into the recovery plan, this will be incorporated into the liquidity ORC score. In case the LCP is not incorporated into the recovery plan and the two documents are separate, the LCP needs to be analysed separately.
- Table 17. Supervisory considerations for assigning a liquidity and funding adequacy score
- Risk Supervisory Considerations in relation to inherent Considerations in relation to score view risk adequate management and controls
- • There is non-material/very low risk arising from mismatches (e.g. between maturities, currencies). • The size and composition of the liquidity buffer is adequate and appropriate. • The level of other drivers of • There is consistency between the liquidity risk (e.g. reputational risk, institution’s liquidity/funding risk inability to transfer intra-group policy and strategy and its overall liquidity) is not material/very low. strategy and risk appetite. • The institution’s counterbalancing • The organisational framework for There is a low capacity and liquidity buffers are liquidity and funding risk is robust risk of comfortably above supervisory with clear responsibilities and a significant quantitative requirements and are clear separation of tasks between prudential expected to remain so in the future. risk-takers and management and impact on the • The free flow of liquidity between control functions. institution entities in the group, where • Liquidity and funding risk 1 considering relevant, is not impeded, or all measurement, monitoring and the level of entities have a counterbalancing reporting systems are appropriate. inherent risk capacity and liquidity buffers above • Internal limits and the control and the supervisory requirements. framework for liquidity risk are management • There is non-material/very low risk sound and are in line with the and controls. from the institution’s funding institution’s risk management profile or its sustainability. strategy and risk appetite. • The risk posed by the stability of • The institution has a plausible and funding is not material. credible liquidity contingency plan • Other drivers of funding risk (e.g. that has the potential to be reputational risk, access to funding effective if required. markets) are not material/very low. • The composition and stability of longer-term funding (>1 year) pose non-material/very low risk in relation to the activities and business model of the institution.
- Risk Supervisory Considerations in relation to inherent Considerations in relation to score view risk adequate management and controls
- • The overall recovery capacity of the institution with regard to liquidity resulting from the supervisory assessment, is ‘satisfactory’. • Mismatches (e.g. between maturities, currencies) entail low to medium risk. • The risk posed by the size and composition of the liquidity buffer is low to medium. • The level of other drivers of liquidity risk (e.g. reputational risk, inability to transfer intra-group liquidity) is low to medium. • The institution’s counterbalancing capacity and liquidity buffers are above supervisory quantitative There is a requirements, but there is a risk medium-low that they will not remain so in the risk of future. significant • The free flow of liquidity between prudential entities in the group, where impact on the relevant, is or could be marginally 2 institution impeded. considering • The risk posed by the institution’s the level of funding profile and its sustainability inherent risk is low to medium. and the • The risk posed by the stability of management funding is low to medium. and controls. • Other drivers of funding risk (e.g. reputational risk, access to funding markets) are low to medium. • The composition and stability of longer-term funding (>1 year) pose a low level of risk in relation to the activities and business model of the institution. • The overall recovery capacity of the institution with regard to liquidity, resulting from the supervisory assessment, is ‘satisfactory’ or ‘adequate with room for improvement’. There is a • Mismatches (e.g. between • There is not full consistency medium-high maturities, currencies) entail between the institution’s liquidity risk of medium to high risk. and funding risk policy and strategy significant • The risk posed by the size and and its overall strategy and risk 3 prudential composition of the liquidity buffer appetite. impact on the is medium to high. • The organisational framework for institution • The level of other drivers of liquidity and funding risk does not considering liquidity risk (e.g. reputational risk, sufficiently separate the level of
- Risk Supervisory Considerations in relation to inherent Considerations in relation to score view risk adequate management and controls
- inherent risk inability to transfer intra-group responsibilities and tasks between and the liquidity) is medium to high. risk-takers and management and management • The institution’s counterbalancing control functions. and controls. capacity and liquidity buffers are • Liquidity and funding risk deteriorating and/or are below measurement, monitoring and supervisory quantitative reporting systems are not requirements, and there are undertaken with sufficient accuracy concerns about the institution’s and frequency. ability to restore compliance with • Internal limits and the control these requirements in a timely framework for liquidity and funding manner. risk are not in line with the • The free flow of liquidity between institution’s risk management entities in the group, where strategy or risk appetite. relevant, is impeded. • The institution has a liquidity • The risk posed by the institution’s contingency plan that is unlikely to funding profile and its sustainability be effective or the institution has is medium to high. no liquidity contingency plan, or • The risk posed by the stability of one that is manifestly inadequate funding is medium to high. • Other drivers of funding risk (e.g. reputational risk, access to funding markets) are medium to high. • The composition and stability of longer-term funding (>1 year) pose a medium level of risk in relation to the activities and business model of the institution. • The overall recovery capacity of the institution with regard to liquidity, resulting from the supervisory assessment, is ‘adequate with room for improvement’ or ‘weak’. • Mismatches (e.g. between maturities, currencies) entail high risk. • The risk posed by the size and There is a high composition of the liquidity buffer risk of is high. significant • The level of other drivers of prudential liquidity risk (e.g. reputational risk, impact on the inability to transfer intra-group institution 4 liquidity) is high. considering • The institution’s counterbalancing the level of capacity and liquidity buffers are inherent risk rapidly deteriorating and/or are and the below the supervisory quantitative management requirements, and there are and controls. serious concerns about the institution’s ability to restore compliance with these requirements in a timely manner.
- Risk Supervisory Considerations in relation to inherent Considerations in relation to score view risk adequate management and controls
- • The free flow of liquidity between entities in the group, where relevant, is severely impeded. • The risk posed by the institution’s funding profile and its sustainability is high. • The risk posed by the stability of funding is high. • Other drivers of funding risk (e.g. reputational risk, access to funding markets) are high. • The composition and stability of longer-term funding (>1 year) pose a high level of risk in relation to the activities and business model of the institution. • The overall recovery capacity of the institution with regard to liquidity, resulting from the supervisory assessment, is ‘weak’.
- Table 18. Potential and non-exhaustive supervisory measures for liquidity and funding risk
- Potential supervisory measures for competent authorities in accordance with Articles 102, 104(1), points (b), (e), (f), (j), (k), (i), and (n) and Article 105 of Directive 2013/36/EU, Article 8 of Commission Delegated Regulation (EU) 2015/61, and Article 428b(5) of Regulation (EU) No 575/2013
- A. require institutions to hold an LCR higher than the regulatory minimum, of such a size that shortcomings identified are sufficiently mitigated; B. require institutions to apply a minimum survival period of such length that identified shortcomings are sufficiently mitigated;
- Potential supervisory measures for competent authorities in accordance with Articles 102, 104(1), points (b), (e), (f), (j), (k), (i), and (n) and Article 105 of Directive 2013/36/EU, Article 8 of Commission Delegated Regulation (EU) 2015/61, and Article 428b(5) of Regulation (EU) No 575/2013
- C. require institutions to hold a minimum total amount of liquid assets or counterbalancing capacity, of such a size that identified shortcomings are sufficiently mitigated; D. require institutions to hold a NSFR higher than the regulatory minimum, of such a size that shortcomings identified are sufficiently mitigated; E. require institutions to hold a minimum total amount of available stable funding, of such a size that identified shortcomings are sufficiently mitigated; F. impose specific liquidity requirements, including restrictions on maturity mismatches between assets and liabilities; G. impose administrative penalties or other administrative measures, including prudential charges; H. impose requirements on the concentration of the liquid assets held, including: - requirements for the composition of the institution’s liquid-assets profile in respect of counterparties, currency; and/or - caps, limits or restrictions on funding concentrations. I. impose restrictions on short-term contractual or behavioural maturity mismatches between assets and liabilities, including: - limits on maturity mismatches (in specific time buckets) between assets and liabilities; - limits on minimum survival periods; and/or - limits on dependency on certain short-term funding sources, such as money market funding.
- J. impose additional or more frequent reporting requirements on liquidity positions, including: - the frequency of regulatory reporting on LCR; and/or - the frequency and granularity of other liquidity reports, such as ‘additional monitoring metrics’. K. require action to be taken to address deficiencies identified with regard to the institution’s ability to identify, measure, monitor and control liquidity risk, by means including: - enhancing its stress testing capacity to improve its ability to identify and quantify material sources of liquidity risk to the institution; - enhancing its ability to monetise its liquid assets; - enhancing its liquidity contingency plan and liquidity early warning indicators framework; and/or - enhancing reporting of liquidity management information to the institution’s management body and senior management. L. require action to be taken to amend the institution’s funding profile, including: - reducing its dependency on certain (potentially volatile) funding markets,, such as wholesale funding markets, such as wholesale funding; - reducing the concentration of its funding profile with respect to counterparties, peaks in the long-term maturity profile, (mismatches in) currencies, etc.; and/or - reducing the amount of its encumbered assets, potentially differentiating between total encumbrance and overcollateralisation (e.g. for covered bonds, margin calls). M. Require additional or more frequent reporting on the institution’s funding positions, including: - increased frequency of regulatory reporting relevant to the monitoring of the funding profile (such as the NSFR report and ‘additional monitoring metrics’); and/or - increased frequency of reporting on the institution’s funding plan to the supervisors. N. Require actions to be taken to address deficiencies identified with regard to the institution’s control of funding risk, including: - requiring actions to be taken to address deficiencies identified with regard to the institution’s control of funding risk, including: - enhancing reporting on funding risk to the institution’s management body and senior management; - restating or enhancing the funding plan; and/or - placing limits on its risk appetite; - enhancing the institution’s stress testing capabilities by means including requiring the institution to cover a longer stress period.
- Table 19. Illustrative example of benchmark for liquidity quantification
- Figure 4. Illustrative example of setting specific quantitative liquidity requirement
- Figure 5. Illustrative example of setting specific quantitative requirements
- Table 20. Supervisory considerations for assigning the overall SREP score
- Score Supervisory view Considerations
- • The institution’s business model and strategy do not raise concerns. • The internal governance and institution-wide control arrangements do not raise concerns. • The institution’s risks to capital and liquidity pose a non- The risks identified pose a material/a very low risk of a significant prudential impact. 1 low level of risk to the • The composition and quantity of own funds held do not raise viability of the institution. concerns. • The institution’s liquidity position and funding profile do not raise concerns. • No material concerns about the credibility and feasibility of the institution’s recovery plan. • There is a low to medium level of concern about the institution’s business model and strategy. • There is a low to medium level of concern about the institution’s governance or institution-wide control arrangements. The risks identified pose a • There is a low to medium level of risk of a significant medium-low level of risk to 2 prudential impact caused by risks to capital and liquidity. the viability of the • There is a low to medium level of concern about the institution. composition and quantity of own funds held. • There is a low to medium level of concern about the institution’s liquidity position and/or funding profile. • There is a low to medium level of concern about the credibility and feasibility of the institution’s recovery plan. • There is a medium to high level of concern about the institution’s business model and strategy. The risks identified pose a • There is a medium to high level of concern about the medium-high level of risk to 3 institution’s governance or institution-wide control the viability of the arrangements. institution. • There is a medium to high level of risk of a significant prudential impact caused by risks to capital and liquidity.
- Score Supervisory view Considerations
- • There is a medium to high level of concern about the composition and quantity of own funds held by the institution. • There is a medium to high level of concern about the institution’s liquidity position and/or funding profile. • There is a medium to high level of concern about the credibility and feasibility of the institution’s recovery plan • There is a high level of concern about the institution’s business model and strategy. • There is a high level of concern about the institution’s governance or institution-wide control arrangements. • There is a high level of risk of a significant prudential impact The risks identified pose a caused by risks to capital and liquidity. 4 high level of risk to the • There is a high level of concern about the composition and viability of the institution. quantity of own funds held by the institution. • There is a high level of concern about the institution’s liquidity position and/or funding profile. • There is a high level of concern about the credibility and feasibility of the institution’s recovery plan.
- 58 In accordance with the EBA AML/CFT Cooperation Guidelines (EBA/GL/2021/15).
- 59 AML/CFT colleges as defined in the Joint guidelines on cooperation and information exchange for the purpose of Directive (EU) 2015/849 between competent authorities supervising credit and financial institutions (‘The AML/CFT Colleges Guidelines’ and in Article 2(8) of Directive (EU) 2024/1640.
- 60 EBA AML/CFT Cooperation Guidelines (EBA/GL/2021/15).
- Table 21. Supervisory considerations for assigning the overall SREP score
- Score Supervisory view Considerations
- • The TCB’s business model and strategy do not raise
- concerns. • The TCB’s internal governance and controls arrangements do not raise concerns. The risks identified pose a low • The TCB’s risks are not material or risk management and 1 level of risk to the viability of controls are adequate to mitigate those risks that are the TCB branch. identified as material. • The TCB’s capital endowment and liquidity position do not raise concerns. • The TCB’s booking arrangements do not raise concerns. • There is a low to medium level of concern about the TCB’s business model and strategy. • There is a low to medium level of concern about the TCB’s governance or control arrangements. The risks identified pose a • There is a low to medium level of concern about the TCB’s 2 medium-low level of risk to material risks and their management and control. the viability of the TCB. • There is a low to medium level of concern about the TCB's capital endowment and/or liquidity position. • There is a low to medium level of concern about the TCB’s booking arrangements.
- • There is a medium to high level of concern about the TCB’s business model and strategy. • There is a medium to high level of concern about the TCB’s governance or control arrangements. The risks identified pose a • There is a medium to high level of concern about the TCB’s 3 medium-high level of risk to material risks and their management and control. the viability of the TCB. • There is a medium to high level of concern about the TCB's capital endowment and/or liquidity position. • There is a medium to high level of concern about the TCB’s booking arrangements.
- • There is a high level of concern about the TCB’s business model and strategy. • There is a high level of concern about the TCB’s governance or control arrangements. The risks identified pose a • There is a high level of concern about the TCB’s material 4 high level of risk to the risks and their management and control. viability of the TCB. • There is a high level of concern about the TCB’s capital endowment and/or liquidity position. • There is a high level of concern about the TCB’s booking
- arrangements.
- The risk that the institution will • Single-name concentrations (including a client or group of connected incur significant credit losses clients as defined for large exposures) stemming from a concentration of • Sectoral concentrations Regulation (EU) 575/2013: Articles Credit exposures to a small group of • Geographical concentrations 129, 170, 171, 184, 207, 209, 395, concentration borrowers, to a set of borrowers • Product concentration 400-401 risk with similar default behaviour or • Collateral and guarantees concentration Directive 2013/36/EU: Articles 81, to highly correlated financial • Hidden sources of concentration that can materialise under stressed 98 assets and concentrated credit conditions, when the level of credit risk correlation can increase compared
- risk mitigation to normal conditions
- • The quality of counterparties and relevant CVAs and the complexity of
- • The wrong-way risk arising when the exposure to a counterparty is
- adversely correlated with its credit quality
- • The exposure to counterparty credit and settlement risks in terms of both current market values and nominal amount, compared to the overall The risk that the counterparty to a credit exposure and to own funds Regulation (EU) 575/2013: Articles Counterparty transaction could default before • The proportion of transactions processed through financial market 181, 246, Part Three, Title II, credit risk the final settlement of the infrastructures that provide payment versus delivery settlement Chapter 6 transaction’s cash flows • The proportion of transactions to central counterparties and the Directive 2013/36/EU: Article 79
- effectiveness of loss protection mechanisms for them
- • The proportion of transactions to central counterparties established in third countries the effectiveness of loss protection mechanisms for them,
- and how any excessive exposure to non-EU CCPs is reduced
- • The proportion of non-centrally cleared OTC transactions and the
- effectiveness of loss protection mechanisms for them
- • The existence, significance, effectiveness and enforceability of netting
- The risk arising in the case of transactions with debt instruments, equities, foreign currencies and commodities
- Settlement and (excluding repurchase Regulation (EU) 575/2013: Articles delivery risk transactions and securities or 1,92, Part Three, Title V
- commodities lending and securities or commodities borrowing) remain unsettled after their due delivery date
- • The risk of a deterioration in the quality of an institution’s exposures in a specific country (including collective debtor risk – i.e. the default by a large group of debtors), stemming from threats, occurrences, and the escalation of adverse events associated with wars, terrorism, and tensions The risk that the institution will among states and political actors affecting international relations incur credit losses associated to • The degree of concentration within all types of exposures to country the business carried out in a risk, including sovereign exposures, in proportion to the whole specific country due to adverse institution’s credit portfolio (per obligor and amount)
- Country risk
- circumstances and/or events, • The economic strength and stability of the borrower’s country and its including the impact of track record in terms of punctual payment and occurrence of serious
- geopolitical events, in the specific default events
- country • The risk of other forms of sovereign intervention that can materially impair the creditworthiness of borrowers (e.g. deposit freezes,
- expropriation or punitive taxation)
- • The transfer risk linked to cross-border foreign currency lending for material cross-border lending and exposures in foreign currencies
- • The appropriateness of allocation of securitisation exposures to the
- banking book and trading book and the consistency with the institution’s
- securitisation strategy
- The risks arising from • The rating and the performance of the securitisation tranches held by
- securitisation transactions in the institution, the nature, composition and quality of the underlying
- relation to which the credit assets Regulation (EU) 575/2013: Article
- Credit risk from institutions are investor, • The consistency of the capital relief with the actual risk transfer for
- 67, Part Three, Title II, Chapter 5
- securitisations originator or sponsor, including originated securitisations
- Directive 2013/36/EU: Article 82
- reputational risks, such as arise in • Whether there is a clear distinction between drawn and undrawn
- relation to complex structures or amounts for liquidity facilities provided to the securitisation vehicle
- products • The existence of contingency plans for Asset-Backed Commercial Paper
- conduits managed by the institution in the event that an issuance of
- commercial paper is not possible because of liquidity conditions, and the
- impact on the total credit risk exposure of the institution
- • Any non-linear relationship between market risk and credit risk where
- The additional credit risk arising exchange rates may have a disproportional impact on the credit risk of an
- from FX lending exposures to institution’s FX loans portfolio such as a material increase in both the
- FX lending risk
- unhedged retail and SME outstanding value of debt and the flow of payments to service such debt
- borrowers and an increase in the outstanding value of debt compared to the value of
- collateral assets denominated in the domestic currency
- • The risk of decline in the value of the institution’s equity investments
- The risk of loss on financial
- and ensure that this risk is appropriately captured by the institution’s risk Equity risk in the instruments from changes in Regulation (EU) 575/2013: Article
- banking book equities posted in the banking 133 • Where relevant, on participation risk in strategic holdings (both
- book insurance and non-insurance)
- The risk of loss due to changes in For immovable properties owned • The risk of decline in the value of the institution’s real estate the market value of real estate by an institution Regulation (EU)
- Real estate risk own assets or of financial 575/2013: • Where relevant, the value of financial instruments linked to real estate
- • Dilution risk for all credit portfolios for which the IRB approach is not adopted, and for those whose dilution risk is deemed immaterial from a
- portfolio perspective
- • How exposures that are immaterial within each portfolio or exposure class are factored in the institution’s aggregate dilution risk assessment • Where relevant, whether the risk assessment of exposures to dilution Dilution risk Article 4 (53) of the CRR risk in the acquiring business for merchant payment systems (for example, in the portfolio of contingent liabilities for chargeback positions) is appropriate and based upon a consistent segmentation of the underlying positions in accordance with their key contractual features – i.e. the nature of underlying sales transactions, the timing of processed payments, and the application of standard risk mitigation mechanisms. • Monitor whether the institution continues to fulfil the minimum Model risk (for requirements and ensure that related own funds requirements are not regulatory underestimated Article 4(1), point (52b) of the CRR Directive 2013/36/EU: Article 3 approved • The assessment may be based on the insights gained in other models) supervisory actions, including those carried out in accordance with Article
- 101 of Directive 2013/36/EU
- 63 In this table, we refer to ‘Pre-Fundamental Review of the Trading Book (FRTB)’ for the definition and treatment applicable before the FRTB comes into effect. Post-FRTB refers to the definitions and approach applicable once the FRTB comes into effect.
- - Regulation (EU) 575/2013, Article 104c
- Market risk sub-categories (level 2) Legal references/Definitions
- Legal risk Article 4(1), point (52a) of the CRR Model risk Article 4(1), point (52b) of the CRR The risk that performance and availability of ICT systems, data or services are adversely impacted, including the inability to timely
- ICT availability and
- recover the institution’s services, due to a failure of ICT hardware
- continuity risk
- or software components; weaknesses in ICT system management; or any other event
- The risk that unauthorised access or malicious or intentional acts ICT security risk compromise ICT systems, data or services irrespective of whether (including cyber) they originate from within or outside the institution (e.g. cyber-
- ICT risk Article 4(1), point (52c) of the CRR The risk arising from the inability of the institution to manage ICT change risk changes to ICT systems or ICT services in a timely and controlled
- The risk that data stored and processed by ICT systems are incomplete, inaccurate or inconsistent across different ICT
- ICT data integrity risk systems impairing the soundness or continuity of the institution’s services and activities and potentially resulting in operational,
- financial, legal, or reputational impact
- the risk that may arise for an institution in relation to its use of ICT services provided by ICT third-party service providers or by
- subcontractors of the latter, including through outsourcing
- ICT third-party risk
- non-critical ICT third-party services providers
- The risk that may arise for a financial entity in relation to the use of function provided by third-party service providers or by
- Third-party risk subcontractors of the latter, including the (non-ICT) provision of a function or the support to a
- function, including through outsourcing arrangements (upcoming EBA Guidelines on sound management of third-party risk)
- Credit risk (operational risk events related to credit risk not accounted Article 317 (5) of the CRR for in the risk-weighted exposure for credit risk) Market risk (operational risk events related to Article 317 (6) of the CRR market risk)
- Gap risk EBA/GL/2022/14 (paragraph7 ‘Definitions’) Basis risk EBA/GL/2022/14 (paragraph7 ‘Definitions’) EBA/GL/2022/14 (paragraph7 ‘Definitions’) Automatic option risk EBA/GL/2022/14 (paragraph7 ‘Definitions’)
- Option risk
- Behavioural option risk EBA/GL/2022/14 (paragraph7 ‘Definitions’)
- 64 Peer review report on the application of proportionality in the SREP (EBA/REP/2025/02).
- 65 According to this method the profits and losses relating to positions owned by several entities are re-distributed across those entities on the basis of the marginal contribution of each entity towards key metrics set out in the pricing arrangement.
- 66 “Competent authorities shall impose the additional own funds requirement […] where […] the institution is exposed to risks or elements of risks that are not covered or not sufficiently covered […] by the own funds requirements set out in Parts Three, Four, and Seven of Regulation (EU) No 575/2013 and in Chapter 2 of Regulation (EU) 2017/2402 of the European Parliament and of the Council.”
- 67 Report on the peer review on ICT risk assessment under the SREP (EBA/REP/2022/25).