Treatment of risks
On this provision: 2 guidelines · 1 EBA Q&A
Amendment details· last amended 30 Dec 2024
Last amended 30 Dec 2024 by Regulation (EU) 2023/1114 of 31 May 2023.
Member States shall ensure that the management body approves and at least every two years reviews the strategies and policies for taking up, managing, monitoring and mitigating the risks the institution is or might be exposed to, including those posed by the macroeconomic environment in which it operates in relation to the status of the business cycle, and those resulting from the current and short-, medium- and long-term impacts of environmental, social and governance (ESG) factors.
Member States may, taking into consideration the principle of proportionality, allow the management bodies of small and non-complex institutions to review the strategies and policies referred to in the first subparagraph every two years.
Member States shall ensure that the management body devotes sufficient time to consideration of risk issues. The management body shall be actively involved in and ensure that adequate resources are allocated to the management of all material risks addressed in this Directive and in Regulation (EU) No 575/2013 as well as in the valuation of assets, the use of external credit ratings and internal models relating to those risks. The institution shall establish reporting lines to the management body that cover all material risks and risk management policies and changes thereof.
Member States shall ensure that the management body develops specific plans and quantifiable targets in accordance with the requirements laid down in Article 7a (opens EUR-Lex in a new tab) of Regulation (EU) No 648/2012 (opens EUR-Lex in a new tab) to monitor and address the concentration risk arising from exposures towards central counterparties offering services of substantial systemic importance for the Union or one or more of its Member States.
Member States shall ensure that the management body develops and monitors the implementation of specific plans that include quantifiable targets and processes to monitor and address the financial risks arising in the short, medium and long term from ESG factors, including those arising from the process of adjustment and from transition trends in the context of the relevant Union and Member State regulatory objectives and legal acts in relation to ESG factors, in particular the objective to achieve climate neutrality, as well as, where relevant for internationally active institutions, third-country legal and regulatory objectives.
The quantifiable targets and processes to address the ESG risks included in the plans referred to in the second subparagraph of this paragraph shall consider the latest reports and measures prescribed by the European Scientific Advisory Board on Climate Change, in particular in relation to the achievement of the climate targets of the Union. Where the institution discloses information on ESG matters in accordance with Directive 2013/34/EU (opens EUR-Lex in a new tab) of the European Parliament and of the Council ((29)), the plans referred to in the second subparagraph of this paragraph shall be consistent with the plans referred to in Article 19a (opens EUR-Lex in a new tab) or 29a (opens EUR-Lex in a new tab) of that Directive and shall, in particular, include actions with regard to the business model and strategy of the institution that are consistent across both plans.
Member States shall ensure a proportionate application of the second and third subparagraphs for the management bodies of small and non-complex institutions, indicating in what areas a waiver or a simplified procedure may be applied.
Member States shall ensure that institutions that are significant in terms of their size, internal organisation and the nature, scope and complexity of their activities establish a risk committee composed of members of the management body who do not perform any executive function in the institution concerned. Members of the risk committee shall have appropriate knowledge, skills and expertise to fully understand and monitor the risk strategy and the risk appetite of the institution.
The risk committee shall advise the management body on the institution’s overall current and future risk appetite and strategy and assist the management body in overseeing the implementation of that strategy by senior management. The management body shall retain overall responsibility for risks.
The risk committee shall review whether prices of liabilities and assets offered to clients take fully into account the institution’s business model and risk strategy. Where prices do not properly reflect risks in accordance with the business model and risk strategy, the risk committee shall present a remedy plan to the management body.
Competent authorities may allow an institution which is not considered significant as referred to in the first subparagraph to combine the risk committee with the audit committee as referred to in Article 41 (opens EUR-Lex in a new tab) of Directive 2006/43/EC (opens EUR-Lex in a new tab). Members of the combined committee shall have the knowledge, skills and expertise required for the risk committee and for the audit committee.
Member States shall ensure that the management body in its supervisory function and, where a risk committee has been established, the risk committee have adequate access to information on the risk situation of the institution and, if necessary and appropriate, to the risk management function and to external expert advice.
The management body in its supervisory function and, where one has been established, the risk committee shall determine the nature, the amount, the format, and the frequency of the information on risk which it is to receive. In order to assist in the establishment of sound remuneration policies and practices, the risk committee shall, without prejudice to the tasks of the remuneration committee, examine whether incentives provided by the remuneration system take into consideration risks, including those resulting from the impacts of ESG factors, capital, liquidity and the likelihood and timing of earnings.
Member States shall, in accordance with the proportionality requirement laid down in Article 7(2) (opens EUR-Lex in a new tab) of Commission Directive 2006/73/EC (opens EUR-Lex in a new tab) ((30)), ensure that institutions have internal control functions independent of the operational functions and which shall have sufficient authority, stature, resources and access to the management body.
Member States shall ensure that:
the internal control functions ensure that all material risks are properly identified, measured and reported;
the internal control functions provide a comprehensive view of the whole range of risks that the institution is exposed to;
the risk management function is actively involved in elaborating the institution’s risk strategy and in all its material risk management decisions and has control over the effective implementation of the risk strategy;
the internal audit function performs an independent review of the effective implementation of the institution’s risk strategy;
the compliance function assesses and mitigates compliance risk and ensures that the institution’s risk strategy takes into account compliance risk and that compliance risk is adequately taken into account in all material risk management decisions.
Member States shall ensure that the internal control functions have direct access and can report directly to the management body in its supervisory function.
To that end, the internal control functions shall be independent of the members of the management body in its management function and of senior management, and shall in particular be able to raise concerns and warn the management body in its supervisory function, where appropriate, or where specific risk developments affect or can affect the institution, without prejudice to the responsibilities of the management body pursuant to this Directive and Regulation (EU) No 575/2013.
The heads of internal control functions shall be independent senior managers with distinct responsibility for the risk management, compliance and internal audit functions. Where the nature, scale and complexity of the activities of the institution do not justify appointing a specific person for the risk management function or the compliance function, another senior person that performs other tasks within the institution may fulfil the responsibilities for the compliance or risk management functions, provided that there is no conflict of interest and that the person responsible for the risk management function and the compliance function:
fulfils the suitability criteria and requirements of knowledge, skills and experience necessary for the different areas concerned; and
has sufficient time to perform both control functions correctly.
The internal audit function shall not be combined with any other business line or control function of the institution.
The heads of the internal control functions shall not be removed without prior approval of the management body in its supervisory function.