Credit risk policies and procedures
Institutions should set out, in their credit risk policies and procedures, the criteria for identifying, assessing, approving, monitoring, reporting and mitigating credit risk, and the criteria for measuring allowances for both accounting and capital adequacy purposes. Institutions should document the framework and update it regularly.
The objective followed in credit risk policies and procedures should be to promote a proactive approach to monitoring credit quality, identifying deteriorating credit early and managing the overall credit quality and associated risk profile of the portfolio, including through new credit-granting activities.
Credit risk policies and procedures should cover all lending activities, asset classes, client segments, products and specific credit facilities, credit risk management practices, and associated responsibilities and controls.
Credit risk policies and procedures should include specific lending policies and procedures, with sufficient granularity to capture the specific business lines of the institution, for different sectors, in line with their varying complexities and sizes, and risks of different market segments related to the credit facility.
Credit risk policies and procedures should specify:
policies and procedures and rules for the approval of credit granting and decision-making, including appropriate authorisation levels set in accordance with the credit risk appetite and limits;
requirements for the handling of information and data needed for the creditworthiness assessment, as set out in Section 5.1;
requirements for the creditworthiness assessment, including a sensitivity analysis, as referred to in Section 5.2;
requirements for exposure aggregation and credit risk limits and the management of credit risk concentrations;
requirements and procedures regarding the acceptance and use of collateral and credit risk mitigation measures, to determine their effectiveness in minimising the inherent risk of a credit facility — such requirements and procedures should be asset class-specific and product type-specific and should duly consider the type, size and complexity of the credit facilities being granted;
conditions for the application of automated decision-making in the credit-granting process, including identifying products, segments and limits for which automated decision-making is allowed;
a risk-based approach, addressing possible deviations from standard credit policies and procedures and credit-granting criteria, including:
conditions defining the approval process for deviations and exceptions and the specific documentation requirements, including the audit trail;
criteria for rejections and criteria for the escalation of deviations/exceptions to higher levels of the decision-making authority (including overrides, overrules, exposures possibly approved as an exception to general lending standards and other non-standard business under a special process with different approval authorities);
requirements for the monitoring of circumstances and conditions for an exceptional credit-granting decision, including requirements for their review by the relevant functions during the regular review of the application and compliance with policies and limits;
requirements relating to what is to be documented and recorded as part of the credit-granting process, including for sampling and audit purposes — this should include, at a minimum, the requirements for the completion of credit applications, the qualitative and quantitative rationale/analysis, and all supportive documentation that served as a basis for approving or declining the credit facility;
requirements for monitoring credit-granting activities — the internal control framework should ensure that it covers all phases after the granting of credit;
criteria as set out in Section 4.3.1 and 4.3.7.
Within their credit risk policies and procedures and building on the credit risk strategy, institutions should also take into account principles of responsible lending. In particular:
For the credit products that are offered to consumers, institutions should ensure that the credit-granting criteria are not inducing undue hardship and over-indebtedness for the borrowers and their households.
In their credit risk policies and procedures dealing with credit decision-making as referred to in paragraph 38(a) and creditworthiness assessments as referred to in paragraph 38(d), institutions should also specify the use of any automated models in the creditworthiness assessment and credit decision-making processes in a way that is appropriate to the size, nature and complexity of the credit facility and the types of borrowers. In particular, institutions should set out appropriate governance arrangements for the design and use of such models and the management of the associated model risk, taking into account the criteria set out in Section 4.3.4, and for model risk-related aspects of the EBA Guidelines on the supervisory review and evaluation process(23).
Institutions should ensure that the credit risk policies and procedures are designed to minimise the risk of internal or external fraud in the credit-granting process. Institutions should have adequate processes in place to monitor any suspicious or fraudulent behaviour.
Institutions should review the credit risk policies and procedures on a regular basis, and for this purpose should clearly identify the functions and staff members tasked with maintaining specific policies and procedures to date and their roles and responsibilities in this regard.
4.3.1Anti-money laundering and counter-terrorist financing policies and procedures
Institutions should also specify in their policies how they identify, assess and manage the money laundering and terrorist financing (ML/TF) risks to which they are exposed as a result of their credit-granting activities(24). In particular, institutions should:
at the level of their business, identify, assess and manage the ML/TF risk associated with the type of customers they serve, the lending products they provide, the geographies to which they are exposed and the distribution channels they use;
at the level of the individual relationship, identify, assess and manage the ML/TF risk associated with this relationship — as part of this, institutions should:
consider the purpose of the credit;
consider the extent to which the association of a natural person or legal person that is neither the borrower nor the institution with the credit facility gives rise to ML/TF risk;
in particular, in situations in which the ML/TF risk associated with the individual relationship is established, institutions should take risk-sensitive measures to understand if the funds used to repay the credit, including cash or equivalents provided as collateral, are from legitimate sources. When considering the legitimacy of the source of funds, institutions should have regard to the activity that generated the funds and whether this information is credible and consistent with the institution’s knowledge of the customer and the customer’s professional activity.
Institutions should have internal processes to ensure that the information obtained for the purposes of creditworthiness assessment, such as the information specified in Section 5.1 and Annex 2 of these guidelines, also informs their anti-money laundering and countering financing of terrorism (AML/CFT) processes.
Institutions should have policies and procedures in place to ensure that the disbursement of loans is made in line with the credit decision and the loan agreement. They should also ensure that there are appropriate checks in place to identify, assess and manage ML/TF risks, and that relevant records are kept, in line with institutions’ wider AML/CFT obligations under Directive (EU) 2015/849 (opens EUR-Lex in a new tab).
4.3.2Leveraged transactions
As part of their policies and procedures, institutions should have in place an overarching definition of leveraged transactions that takes into consideration the level of leverage of the borrower and the purpose of the transaction. This definition should encompass all business lines and units bearing credit risk.
The scope and implementation of the definition of a leveraged transaction by an institution should be regularly reviewed to ensure that no undue exclusion has been made.
Institutions should define their appetite and strategy for leveraged transactions in a way that encompasses all relevant business units involved in such operations. Institutions should define which types of leveraged transactions they are prepared to enter into, as well as acceptable values for parameters, such as rating note, probability of default, level of collateralisation and leverage levels, including at sector level, when relevant.
Institutions should define their risk appetite for syndicating leveraged transactions and derive a comprehensive limit framework, including dedicated underwriting limits and a granular set of sub-limits, detailing both maximum limits and the nature of transactions that the institution is prepared to participate in.
Institutions should establish a sound governance structure for leveraged transactions, enabling a comprehensive and consistent oversight of all leveraged transactions originated, syndicated or purchased by them, including, when relevant, ‘best efforts’ deals and ‘club deals’, as well as standard bilateral loans to micro, small, medium-sized and large enterprises.
Institutions should ensure that all leveraged transactions are adequately reviewed, in line with institutions’ risk appetite, strategies and policies, and approved by relevant credit decision-makers. For transactions including syndication and underwriting risks, there should be specific approval requirements and processes in place.
4.3.3Technology-enabled innovation for credit granting
When using technology-enabled innovation for credit-granting purposes, institutions should do the following:
Adequately capture, in their risk management and control frameworks, the inherent risks associated with the technology-enabled innovation in use. This should be commensurate with the business model, credit risk exposure, complexity of the methods and the extent of the use of technology-enabled innovation.
Ensure that the management body has a sufficient understanding of the use of technology-enabled innovation, its limitation and the impact it has on credit-granting procedures.
Understand the underlying models used, including their capabilities, assumptions and limitations, along with ensuring their traceability, auditability, and robustness and resilience.
Ensure that the models are fit for purpose, taking into account the identified task and other criteria, such as its performance and use. If explanations are required during the models’ use, then consideration should be given to developing an interpretable model.
Understand the quality of data and inputs to the model and detect and prevent bias in the credit decision-making process, ensuring that appropriate safeguards are in place to provide confidentiality, integrity and availability of information and systems.
Ensure the performance of the model, including the validity and quality of its outputs, is continuously monitored and appropriate remediation measures are taken in a timely manner in the case of detected issues (e.g. worsening or deviating from expected behaviour).
4.3.4Models for creditworthiness assessment and credit decision-making
When using automated models for creditworthiness assessment and credit decision-making, institutions should understand the models used, and their methodology, input data, assumptions, limitations and outputs, and should have in place:
internal policies and procedures detecting and preventing bias and ensuring the quality of the input data;
measures to ensure the traceability, auditability, and robustness and resilience of the inputs and outputs;
internal policies and procedures ensuring that the quality of the model output is regularly assessed, using measures appropriate to the model’s use, including backtesting the performance of the model;
control mechanisms, model overrides and escalation procedures within the regular credit decision-making framework, including qualitative approaches, qualitative risk assessment tools (including expert judgement and critical analysis) and quantitative limits.
Institutions should have adequate model documentation that covers:
methodology, assumptions and data inputs, and an approach to detecting and preventing bias and ensuring the quality of input data;
the use of model outputs in the decision-making process and the monitoring of these automated decisions on the overall quality of the portfolio or products in which these models are used.
4.3.5Environmental, social and governance factors
Institutions should incorporate ESG factors and associated risks in their credit risk appetite and risk management policies, credit risk policies and procedures, adopting a holistic approach.
Institutions should take into account the risks associated with ESG factors on the financial conditions of borrowers, and in particular the potential impact of environmental factors and climate change, in their credit risk appetite, policies and procedures. The risks of climate change for the financial performance of borrowers can primarily materialise as physical risks, such as risks to the borrower that arise from the physical effects of climate change, including liability risks for contributing to climate change, or transition risks, e.g. risks to the borrower that arise from the transition to a low-carbon and climate-resilient economy. In addition, other risks can occur, such as changes in market and consumer preferences and legal risks that may affect the performance of underlying assets.
4.3.6Environmentally sustainable lending
Institutions that originate or plan to originate environmentally sustainable credit facilities should develop, as part of their credit risk policies and procedures, specific details of their environmentally sustainable lending policies and procedures, covering the granting and monitoring of such credit facilities. These policies and procedures should, in particular:
Provide a list of the projects and activities, as well as the criteria, that the institution considers eligible for environmentally sustainable lending or a reference to relevant existing standards on environmentally sustainable lending that define what type of lending is considered to be environmentally sustainable;.
Specify the process by which the institutions evaluating that the proceeds of the environmentally sustainable credit facilities they have originated are used for environmentally sustainable activities. In cases of lending to enterprises, the process should include:
collecting information about the climate-related and environmental or otherwise sustainable business objectives of the borrowers;
assessing the conformity of the borrowers’ funding projects with the qualifying environmentally sustainable projects or activities and related criteria;
ensuring that the borrowers have the willingness and capacity to appropriately monitor and report the allocation of the proceeds towards the environmentally sustainable projects or activities;
monitoring, on a regular basis, that the proceeds are allocated properly (which may consist of requesting that borrowers provide updated information on the use of the proceeds until the relevant credit facility is repaid).
Institutions should position their environmentally sustainable lending policies and procedures within the context of their overarching objectives, strategy and policy related to sustainable finance. In particular, institutions should set up qualitative and, when relevant, quantitative targets to support the development and the integrity of their environmentally sustainable lending activity, and to assess the extent to which this development is in line with or is contributing to their overall climate-related and environmentally sustainable objectives.
4.3.7Data infrastructure
Institutions should have appropriate data infrastructure as well as relevant policies and procedures to support the credit-granting process and for the purposes of credit risk management and monitoring throughout the life cycle of the credit facilities (e.g. loan origination and creditworthiness assessment, risk assessment, credit review and monitoring). The data infrastructure should ensure the continuity, integrity and security of information on the exposure, borrower and collateral, from the point of origination and throughout the life cycle of the credit facility.
The data infrastructure should be detailed and sufficiently granular to capture specific loan-by-loan information, in particular actual credit-granting criteria applied at the point of origination, allowing data regarding the borrower to be linked with data regarding collateral, to support the effective monitoring of credit risk (see Section 8) and enable effective audit trailing, operational and credit performance and efficiency measurement, as well as the tracking of policy deviations, exceptions and overrides (including credit/transaction rating or scoring overrides).