Documentation, internal policies and risk management processes
Timeliness of the identification of default
Institutions should have effective processes that allow them to obtain the relevant information in order to identify defaults in a timely manner, and to channel the relevant information in the shortest possible time and, where possible, in an automated manner, to the personnel that is responsible for taking credit decisions, and more in particular:
where they apply automatic processes, such as counting of days past due, the identification of indications of default should be performed on a daily basis;
where they implement manual processes, such as checking external sources and databases, analysis of watch lists, analysis of the lists of forborne exposures, identification of SCRA, the information should be updated with a frequency that guarantees the timely identification of default.
Institutions should verify on a regular basis that all forborne non-performing exposures are classified as default. Institutions should also analyse on a regular basis the forborne performing exposures in order to determine whether any of them fulfils the indication of unlikeliness to pay as specified in Article 178(3)(d) Regulation (EU) No 575/2013 and in paragraphs 51 to 55.
Control mechanisms should ensure that the relevant information is used in the default identification process immediately after being obtained. All exposures to a defaulted obligor or all relevant exposures in case of the application of the definition of default at the facility level for retail exposures should be marked as defaulted in all relevant IT systems without undue delay. If delays occur in the recording of the default, such delays should not lead to errors or inconsistencies in risk management, risk reporting, the own funds requirements calculation or the use of data in risk quantification. In particular it should be ensured that the internal and external reporting figures reflect a situation where all exposures are correctly classified.
Documentation
Institutions should document their policies regarding the definition of default including all triggers for identification of default and the exit criteria as well as clear identification of the scope of application of the definition of default and, more in particular they should:
For the purposes of point (a) of paragraph 109, institutions should document the application of the definition of default in a detailed manner by including the operationalization of all indications of default, including the process, sources of information and responsibilities for the identification of particular indications of default.
For the purposes of point (b) of paragraph 109, institutions should document the operationalization of the criteria for reclassification of a defaulted obligor to a non-defaulted status, including the processes, sources of information and responsibilities assigned to relevant personnel.
For the purposes of paragraphs 110 and 111, the documentation should include description of all automatic mechanisms and manual processes, and where qualitative indications of default or criteria for the return to non-defaulted status are applied manually the description should be sufficiently detailed to facilitate common understanding and consistent application by all responsible personnel.
For the purposes of point (c) of paragraph 109, institutions should keep an updated register of all current and past versions of the default definition at least starting from the date of application of these guidelines. This register should include at least the following information:
the scope of application of the default definition, if there is more than one default definition used within the institution, the parent undertaking or any of its subsidiaries;
the body approving the definition or definitions of default and date of approval for each of those definitions of default;
the date of implementation of each definition of default;
brief description of all changes performed relatively to the last version;
in the case of institutions that have permission to use the IRB Approach, the change category assigned, the date of submission to the competent authorities and, if applicable, the date of approval by the competent authorities.
Internal governance requirements for institutions applying the IRB Approach
Institutions that use the IRB Approach should adopt adequate mechanisms and procedures in order to ensure that the definition of default is implemented and used in a correct manner, and should in particular ensure that:
the definition of default and the scope of its application is what is required to be approved by the management body, or by a committee designated by it, and by senior management in accordance with Article 189(1) of Regulation (EU) 575/2013;
the definition of default is used consistently for the purpose of the own funds requirements calculation and plays a meaningful role in the internal risk management processes by being used at least in the area of monitoring of exposures and in the internal reporting to senior management and management body;
the internal audit unit or another comparable independent auditing unit reviews regularly the robustness and effectiveness of the process used by the institution for the identification of default, taking into account in particular the timeliness of the identification of default referred to in paragraphs 106 to 108; and ensuring that the conclusions of the internal audit’s review and respective recommendations, as well as the measures taken to remedy the identified weaknesses are communicated directly to the management body or the committee designated by it.