Internal culture, capabilities and controls
Institutions should develop on an ongoing basis their capabilities to identify, assess, monitor, manage and mitigate ESG risks as appropriate. Institutions should ensure, as part of their training policy, that their management body and staff are adequately trained to understand the implications of ESG factors and ESG risks with a view to fulfilling their responsibilities ef-fectively. The policies and procedures on training activities should be kept up to date and take into account scientific and regulatory developments; the procedure for managers should take into account that knowledge of ESG factors and ESG risks is relevant for the assessment of the suitability of members of the management body and for key function holders in line with the Joint EBA and ESMA Guidelines on suitability assessments(12).
The sound and consistent risk culture that accounts for ESG risks implemented within the institution in accordance with Title IV of the EBA Guidelines on internal governance(13) should include clear communication from the management body (‘tone from the top’) and appropri-ate measures to promote knowledge of ESG factors and ESG risks across the institution, as well as awareness of the institution’s ESG strategic objectives and commitments.
For the purposes of Title V of the EBA Guidelines on internal governance(14), institutions should incorporate ESG risks into their internal control frameworks across the three lines of defence. The internal control framework should include a clear definition and assignment of ESG risk responsibilities and reporting lines.
The first line of defence should be responsible for undertaking assessments of ESG risks, tak-ing into account materiality and proportionality considerations, during the client onboarding, credit application, credit review and, where relevant, investing processes, and in ongoing monitoring and engagement with existing clients. Staff in the first line of defence should have an adequate understanding and knowledge to be able to identify potential ESG risks.
As part of the activities of the second line of defence:
the risk management function should be responsible for undertaking ESG risk assess-ment and monitoring independently from the first line of defence, including by en-suring adherence to the risk limits, questioning and where necessary challenging the initial assessment conducted by the business relationship officers;
the compliance function should oversee how the first line of defence ensures adher-ence to applicable ESG risk legal requirements and internal policies, and should advise the management body and other relevant staff on measures to be taken to ensure such compliance. In addition, in relation to the sustainability claims and/or commit-ments made by the institution, it should provide advice on the reputational and con-duct risks associated with the implementation or failure to implement such claims and/or commitments;
the compliance function and the risk management function should be consulted for the approval of new products with ESG features or for significant changes to existing products to embed ESG aspects.
As third line of defence, the internal audit function (IAF) should provide an independent re-view and objective assurance of the quality and effectiveness of the overall internal control framework and systems in relation to ESG risks, including the first and second lines of defence and the ESG risk governance framework.