Internal governance for credit granting and monitoring
In addition to the provisions set out in the EBA Guidelines on internal governance, institutions should apply further conditions in relation to credit granting and monitoring, as set out in this section.
4.1Credit risk governance and culture
4.1.1Responsibilities of the management body
The management body, as referred to in the EBA Guidelines on internal governance, in relation to credit granting, should:
approve the institution’s credit risk strategy, within the overall risk strategy, and business strategy, to ensure that they are in line with the institution’s risk appetite framework (RAF), capital and liquidity planning, and are in line with the internal capital adequacy assessment process (ICAAP) and internal liquidity adequacy assessment process (ILAAP), when relevant;
set the credit risk appetite within the overall RAF, including credit-granting standards, qualitative statements, quantitative metrics and limits, and escalation thresholds, without business performance biases;
approve the framework for the credit approval process, including, when relevant, the internal structures for credit granting and monitoring, and defining delegated decision-making authorities;
ensure an effective oversight of credit risk quality, in particular at the point of credit granting, and provisioning;
ensure adequate credit approval, monitoring and control processes, for the purposes of effective credit risk management;
ensure that all staff involved in credit risk taking, and the managing, monitoring and controlling of credit risk, are adequately skilled, resourced and experienced;
set, approve and oversee the implementation of the institution’s risk culture, core values and expectations regarding credit risk;
ensure that the remuneration framework, including any relevant performance targets, and the performance assessment framework for credit decision-makers who are identified staff remain aligned with the credit risk and credit risk appetite.
4.1.2Credit risk culture
Institutions should develop a credit risk culture as part of the overall risk culture through policies, communication and staff training, in accordance with the EBA Guidelines on internal governance.
The credit risk culture should include an adequate ‘tone from the top’ and ensure that credit is granted to borrowers who, to the institution’s best knowledge at the time of granting the credit, will be able to fulfil the terms and conditions of the credit agreement, and is secured, when relevant, by sufficient and appropriate collateral, where relevant, and considering the impact on the institution’s capital position and profitability, and sustainability, and related environmental, social and governance (ESG) factors.
Institutions should ensure that a credit risk culture is implemented effectively across all levels of the institution, and that all members of staff involved in the credit risk-taking, credit risk management and monitoring processes are fully aware of it and they will be held accountable for their actions.
Institutions should adopt policies and processes to monitor adherence of all staff members involved in credit-granting, monitoring and control processes to the institution’s credit risk culture (e.g. by means of self-assessments carried out by staff members). In situations in which there are noted deficiencies in the credit culture, evidenced either via an institution’s self-assessment or via supervisory actions, the institution should take well-defined, outcome-driven and timely actions to remediate these deficiencies. The credit risk strategy, credit policies and procedures should be tailored to mitigate any potential negative effects arising from a poor credit culture.
4.2Credit risk appetite, strategy and credit risk limits
The credit risk appetite, credit risk strategy and the overall credit risk policy should be aligned with the institution’s overall RAF. The institution’s credit risk appetite should specify the scope and focus of the credit risk of the institution, the composition of the credit portfolio, including its concentration, and diversification objectives in relation to business lines, geographies, economic sectors and products.
The credit risk appetite should be implemented with the support of appropriate credit risk metrics and limits. These metrics and limits should cover key aspects of the credit risk appetite, as well as client segments, currency, collateral types and credit risk mitigation instruments. When relevant, credit metrics should be a combination of backward-looking and forward-looking indicators and should be tailored to the business model and complexity of the institution.
Institutions should ensure that the credit risk appetite and associated metrics and limits are appropriately cascaded down within the institution, including all relevant group entities and business lines and units bearing credit risk.
For the purposes of managing concentration risk, institutions should set quantitative internal credit risk limits for their aggregate credit risk, as well as portfolios with shared credit risk characteristics, sub-portfolios and individual borrowers. In cases of group entities and connected clients, the limits should also account for the consolidated and sub-consolidated position and the position of the individual entities at the consolidated and sub-consolidated levels.
4.3Credit risk policies and procedures
Institutions should set out, in their credit risk policies and procedures, the criteria for identifying, assessing, approving, monitoring, reporting and mitigating credit risk, and the criteria for measuring allowances for both accounting and capital adequacy purposes. Institutions should document the framework and update it regularly.
The objective followed in credit risk policies and procedures should be to promote a proactive approach to monitoring credit quality, identifying deteriorating credit early and managing the overall credit quality and associated risk profile of the portfolio, including through new credit-granting activities.
Credit risk policies and procedures should cover all lending activities, asset classes, client segments, products and specific credit facilities, credit risk management practices, and associated responsibilities and controls.
Credit risk policies and procedures should include specific lending policies and procedures, with sufficient granularity to capture the specific business lines of the institution, for different sectors, in line with their varying complexities and sizes, and risks of different market segments related to the credit facility.
Credit risk policies and procedures should specify:
policies and procedures and rules for the approval of credit granting and decision-making, including appropriate authorisation levels set in accordance with the credit risk appetite and limits;
requirements for the handling of information and data needed for the creditworthiness assessment, as set out in Section 5.1;
requirements for the creditworthiness assessment, including a sensitivity analysis, as referred to in Section 5.2;
requirements for exposure aggregation and credit risk limits and the management of credit risk concentrations;
requirements and procedures regarding the acceptance and use of collateral and credit risk mitigation measures, to determine their effectiveness in minimising the inherent risk of a credit facility — such requirements and procedures should be asset class-specific and product type-specific and should duly consider the type, size and complexity of the credit facilities being granted;
conditions for the application of automated decision-making in the credit-granting process, including identifying products, segments and limits for which automated decision-making is allowed;
a risk-based approach, addressing possible deviations from standard credit policies and procedures and credit-granting criteria, including:
conditions defining the approval process for deviations and exceptions and the specific documentation requirements, including the audit trail;
criteria for rejections and criteria for the escalation of deviations/exceptions to higher levels of the decision-making authority (including overrides, overrules, exposures possibly approved as an exception to general lending standards and other non-standard business under a special process with different approval authorities);
requirements for the monitoring of circumstances and conditions for an exceptional credit-granting decision, including requirements for their review by the relevant functions during the regular review of the application and compliance with policies and limits;
requirements relating to what is to be documented and recorded as part of the credit-granting process, including for sampling and audit purposes — this should include, at a minimum, the requirements for the completion of credit applications, the qualitative and quantitative rationale/analysis, and all supportive documentation that served as a basis for approving or declining the credit facility;
requirements for monitoring credit-granting activities — the internal control framework should ensure that it covers all phases after the granting of credit;
criteria as set out in Section 4.3.1 and 4.3.7.
Within their credit risk policies and procedures and building on the credit risk strategy, institutions should also take into account principles of responsible lending. In particular:
For the credit products that are offered to consumers, institutions should ensure that the credit-granting criteria are not inducing undue hardship and over-indebtedness for the borrowers and their households.
In their credit risk policies and procedures dealing with credit decision-making as referred to in paragraph 38(a) and creditworthiness assessments as referred to in paragraph 38(d), institutions should also specify the use of any automated models in the creditworthiness assessment and credit decision-making processes in a way that is appropriate to the size, nature and complexity of the credit facility and the types of borrowers. In particular, institutions should set out appropriate governance arrangements for the design and use of such models and the management of the associated model risk, taking into account the criteria set out in Section 4.3.4, and for model risk-related aspects of the EBA Guidelines on the supervisory review and evaluation process(23).
Institutions should ensure that the credit risk policies and procedures are designed to minimise the risk of internal or external fraud in the credit-granting process. Institutions should have adequate processes in place to monitor any suspicious or fraudulent behaviour.
Institutions should review the credit risk policies and procedures on a regular basis, and for this purpose should clearly identify the functions and staff members tasked with maintaining specific policies and procedures to date and their roles and responsibilities in this regard.
4.3.1Anti-money laundering and counter-terrorist financing policies and procedures
Institutions should also specify in their policies how they identify, assess and manage the money laundering and terrorist financing (ML/TF) risks to which they are exposed as a result of their credit-granting activities(24). In particular, institutions should:
at the level of their business, identify, assess and manage the ML/TF risk associated with the type of customers they serve, the lending products they provide, the geographies to which they are exposed and the distribution channels they use;
at the level of the individual relationship, identify, assess and manage the ML/TF risk associated with this relationship — as part of this, institutions should:
consider the purpose of the credit;
consider the extent to which the association of a natural person or legal person that is neither the borrower nor the institution with the credit facility gives rise to ML/TF risk;
in particular, in situations in which the ML/TF risk associated with the individual relationship is established, institutions should take risk-sensitive measures to understand if the funds used to repay the credit, including cash or equivalents provided as collateral, are from legitimate sources. When considering the legitimacy of the source of funds, institutions should have regard to the activity that generated the funds and whether this information is credible and consistent with the institution’s knowledge of the customer and the customer’s professional activity.
Institutions should have internal processes to ensure that the information obtained for the purposes of creditworthiness assessment, such as the information specified in Section 5.1 and Annex 2 of these guidelines, also informs their anti-money laundering and countering financing of terrorism (AML/CFT) processes.
Institutions should have policies and procedures in place to ensure that the disbursement of loans is made in line with the credit decision and the loan agreement. They should also ensure that there are appropriate checks in place to identify, assess and manage ML/TF risks, and that relevant records are kept, in line with institutions’ wider AML/CFT obligations under Directive (EU) 2015/849 (opens EUR-Lex in a new tab).
4.3.2Leveraged transactions
As part of their policies and procedures, institutions should have in place an overarching definition of leveraged transactions that takes into consideration the level of leverage of the borrower and the purpose of the transaction. This definition should encompass all business lines and units bearing credit risk.
The scope and implementation of the definition of a leveraged transaction by an institution should be regularly reviewed to ensure that no undue exclusion has been made.
Institutions should define their appetite and strategy for leveraged transactions in a way that encompasses all relevant business units involved in such operations. Institutions should define which types of leveraged transactions they are prepared to enter into, as well as acceptable values for parameters, such as rating note, probability of default, level of collateralisation and leverage levels, including at sector level, when relevant.
Institutions should define their risk appetite for syndicating leveraged transactions and derive a comprehensive limit framework, including dedicated underwriting limits and a granular set of sub-limits, detailing both maximum limits and the nature of transactions that the institution is prepared to participate in.
Institutions should establish a sound governance structure for leveraged transactions, enabling a comprehensive and consistent oversight of all leveraged transactions originated, syndicated or purchased by them, including, when relevant, ‘best efforts’ deals and ‘club deals’, as well as standard bilateral loans to micro, small, medium-sized and large enterprises.
Institutions should ensure that all leveraged transactions are adequately reviewed, in line with institutions’ risk appetite, strategies and policies, and approved by relevant credit decision-makers. For transactions including syndication and underwriting risks, there should be specific approval requirements and processes in place.
4.3.3Technology-enabled innovation for credit granting
When using technology-enabled innovation for credit-granting purposes, institutions should do the following:
Adequately capture, in their risk management and control frameworks, the inherent risks associated with the technology-enabled innovation in use. This should be commensurate with the business model, credit risk exposure, complexity of the methods and the extent of the use of technology-enabled innovation.
Ensure that the management body has a sufficient understanding of the use of technology-enabled innovation, its limitation and the impact it has on credit-granting procedures.
Understand the underlying models used, including their capabilities, assumptions and limitations, along with ensuring their traceability, auditability, and robustness and resilience.
Ensure that the models are fit for purpose, taking into account the identified task and other criteria, such as its performance and use. If explanations are required during the models’ use, then consideration should be given to developing an interpretable model.
Understand the quality of data and inputs to the model and detect and prevent bias in the credit decision-making process, ensuring that appropriate safeguards are in place to provide confidentiality, integrity and availability of information and systems.
Ensure the performance of the model, including the validity and quality of its outputs, is continuously monitored and appropriate remediation measures are taken in a timely manner in the case of detected issues (e.g. worsening or deviating from expected behaviour).
4.3.4Models for creditworthiness assessment and credit decision-making
When using automated models for creditworthiness assessment and credit decision-making, institutions should understand the models used, and their methodology, input data, assumptions, limitations and outputs, and should have in place:
internal policies and procedures detecting and preventing bias and ensuring the quality of the input data;
measures to ensure the traceability, auditability, and robustness and resilience of the inputs and outputs;
internal policies and procedures ensuring that the quality of the model output is regularly assessed, using measures appropriate to the model’s use, including backtesting the performance of the model;
control mechanisms, model overrides and escalation procedures within the regular credit decision-making framework, including qualitative approaches, qualitative risk assessment tools (including expert judgement and critical analysis) and quantitative limits.
Institutions should have adequate model documentation that covers:
methodology, assumptions and data inputs, and an approach to detecting and preventing bias and ensuring the quality of input data;
the use of model outputs in the decision-making process and the monitoring of these automated decisions on the overall quality of the portfolio or products in which these models are used.
4.3.5Environmental, social and governance factors
Institutions should incorporate ESG factors and associated risks in their credit risk appetite and risk management policies, credit risk policies and procedures, adopting a holistic approach.
Institutions should take into account the risks associated with ESG factors on the financial conditions of borrowers, and in particular the potential impact of environmental factors and climate change, in their credit risk appetite, policies and procedures. The risks of climate change for the financial performance of borrowers can primarily materialise as physical risks, such as risks to the borrower that arise from the physical effects of climate change, including liability risks for contributing to climate change, or transition risks, e.g. risks to the borrower that arise from the transition to a low-carbon and climate-resilient economy. In addition, other risks can occur, such as changes in market and consumer preferences and legal risks that may affect the performance of underlying assets.
4.3.6Environmentally sustainable lending
Institutions that originate or plan to originate environmentally sustainable credit facilities should develop, as part of their credit risk policies and procedures, specific details of their environmentally sustainable lending policies and procedures, covering the granting and monitoring of such credit facilities. These policies and procedures should, in particular:
Provide a list of the projects and activities, as well as the criteria, that the institution considers eligible for environmentally sustainable lending or a reference to relevant existing standards on environmentally sustainable lending that define what type of lending is considered to be environmentally sustainable;.
Specify the process by which the institutions evaluating that the proceeds of the environmentally sustainable credit facilities they have originated are used for environmentally sustainable activities. In cases of lending to enterprises, the process should include:
collecting information about the climate-related and environmental or otherwise sustainable business objectives of the borrowers;
assessing the conformity of the borrowers’ funding projects with the qualifying environmentally sustainable projects or activities and related criteria;
ensuring that the borrowers have the willingness and capacity to appropriately monitor and report the allocation of the proceeds towards the environmentally sustainable projects or activities;
monitoring, on a regular basis, that the proceeds are allocated properly (which may consist of requesting that borrowers provide updated information on the use of the proceeds until the relevant credit facility is repaid).
Institutions should position their environmentally sustainable lending policies and procedures within the context of their overarching objectives, strategy and policy related to sustainable finance. In particular, institutions should set up qualitative and, when relevant, quantitative targets to support the development and the integrity of their environmentally sustainable lending activity, and to assess the extent to which this development is in line with or is contributing to their overall climate-related and environmentally sustainable objectives.
4.3.7Data infrastructure
Institutions should have appropriate data infrastructure as well as relevant policies and procedures to support the credit-granting process and for the purposes of credit risk management and monitoring throughout the life cycle of the credit facilities (e.g. loan origination and creditworthiness assessment, risk assessment, credit review and monitoring). The data infrastructure should ensure the continuity, integrity and security of information on the exposure, borrower and collateral, from the point of origination and throughout the life cycle of the credit facility.
The data infrastructure should be detailed and sufficiently granular to capture specific loan-by-loan information, in particular actual credit-granting criteria applied at the point of origination, allowing data regarding the borrower to be linked with data regarding collateral, to support the effective monitoring of credit risk (see Section 8) and enable effective audit trailing, operational and credit performance and efficiency measurement, as well as the tracking of policy deviations, exceptions and overrides (including credit/transaction rating or scoring overrides).
4.4Credit decision-making
Institutions should establish a clear and well-documented credit decision-making framework that should set out a clear and sound structure for the credit decision-making responsibilities within an institution, including a description of the hierarchy of the credit decision-makers and their allocation within the institution’s organisational and business structure and their reporting lines.
The structure of credit decision-makers should be in line with and integrated into credit risk appetite, policies and limits and reflect the business model of the institutions. The allocation of credit decision-makers to the organisational and business structure should reflect the cascading credit risk appetite and limits within an organisation and be based on objective criteria, including risk indicators.
The credit decision-making framework should clearly articulate the decision-making powers and limitations of each decision-maker and of any automated models for credit decision-making purposes, in line with the criteria for such models set out in Section 4.3.4. These powers and limitations should account for the characteristics of the credit portfolio, including its concentration and diversification objectives, in relation to business lines, geographies, economic sectors and products, as well as credit limits and maximum exposures. Where relevant, institutions should set time limits for the delegated powers or the size of delegated approvals.
When delegating credit decision-making powers, including limits, to members of staff, institutions should consider the specificities of the credit facilities subject to this individual decision-making, including their size and complexity, and the types and risk profiles of borrowers. Institutions should also ensure that these staff members are adequately trained and hold relevant expertise and seniority in relation to the specific authority delegated to them.
The credit decision-making framework should account for the risk perspective in the decision-making. It should also take into account the specificities of credit products and borrowers, including the type of product, the size of credit facility or limit, and the risk profile of the borrower.
The framework should also specify the working modalities of the credit committees and the roles of their members, including, when applicable, aspects such as voting procedures (unanimity or simple majority of votes).
If the institutions grant specific veto rights in relation to positive credit decisions to the head of the risk management function, institutions should consider granting such veto rights to additional staff members within the risk management function for specific credit decisions, to ensure that such a veto can be exercised, if appropriate, at all levels of the credit decision-making framework below the management body. Institutions should specify the scope of these veto rights, the escalation or appeal procedures, and how the management body will be involved.
4.4.1Objectivity and impartiality in credit decision-making
Institutions should ensure that decisions taken by credit decision-makers are impartial and objective and not adversely affected by any conflict of interest, in line with the EBA Guidelines on internal governance. More specifically, for the purposes of these guidelines, institutions should ensure that any individual involved in credit decision-making, such as members of staff and members of the management body, should not take part in credit decisions if any of the following occurs:
any individual involved in credit decision-making has a personal or professional relationship (outside the professional relationship when representing the institution) with the borrower;
any individual involved in credit decision-making has an economic or any other interest, including direct or indirect, actual or potential, financial or non-financial, associated with the borrower;
any individual involved in credit decision-making has undue political influence on or a political relationship with the borrower.
Notwithstanding the governance structures implemented in institutions to operationalise the credit decision-making framework, institutions should have policies, procedures and organisational controls in place that guarantee and ensure objectivity and impartiality in the credit decision-making process. These policies, procedures and organisational controls, including any mitigating measures, should be clearly defined and understood, and should address any potential conflicts of interest. Institutions should ensure effective oversight of the decisions taken by credit decision-makers, including credit granting, to ensure their objectivity and impartiality.
4.5Credit risk management and internal control frameworks
In accordance with the EBA Guidelines on internal governance, institutions should implement a robust and comprehensive internal control framework, including credit risk management, respecting inter alia the principles of accountability, segregation and independence of functions and responsibilities, challenge and assurance of outcomes.
Risk management and internal controls for credit risk should be integrated into the institution’s overall risk management and internal control frameworks, as well as into the organisational and decision-making structure. Institutions should ensure that the internal control framework, including credit risk management, supports robust and appropriate credit risk taking, analysis, and monitoring throughout the life cycle of a credit facility, including the design and development of the specific product, sales and administration.
Institutions should establish regular and transparent reporting mechanisms so that the management body, its risk committee, if established, and all relevant units or functions are provided with reports in a timely, accurate and concise manner and can take informed and effective actions within their respective mandates, to ensure the identification, measurement or assessment, monitoring and management of credit risk (see also Section 8).
Institutions should define, in a clear and transparent manner, the allocation of responsibilities and authority within the organisation, including within and between business lines, units and functions, including risk management. To this end, institutions should clearly define functions responsible for performing the various tasks related to credit risk taking and the credit decision-making process, specified in a way that does not lead to a conflict of interest and ensures the effective management of credit risk.
The business lines and units originating the credit risk should be primarily responsible for managing the credit risk generated by their activities throughout the lifetime of the credit. These business lines and units should have adequate internal controls in place to ensure adherence with internal policies and relevant external requirements.
The institutions should have a risk management function, in line with the EBA Guidelines on internal governance, that is responsible for ensuring the proper controls of credit risk. The risk management function should be independent of the business-originating units.
For the purposes of paragraph 75, institutions should consider the following areas/tasks:
developing and maintaining credit-granting and monitoring processes and procedures;
defining and developing processes, mechanisms and methodologies for credit risk appetite, credit risk strategy and credit risk policies, including the overall cascading-down process for policies and procedures, and business strategy;
designing and implementing an appropriate credit decision-making framework in accordance with these guidelines;
designing, defining and performing credit risk monitoring and reporting, including early warning systems, credit portfolio and aggregate risk monitoring, including in relation to ICAAP and any applicable regulatory metrics, e.g. large exposures rules;
performing an assessment of creditworthiness and a credit risk analysis for scoring or rating purposes;
providing an independent/second opinion on the creditworthiness assessment and credit risk analysis for the purposes of credit decision-making, specifying in which circumstances, considering the specificities of the credit facility, its size and the risk profile of the borrower, this independent/second opinion is relevant;
assessing the appropriateness of allowances in accordance with the relevant accounting framework;
developing new credit products, also considering the requirements for the new product approval process, and ongoing monitoring of the appropriateness of credit products;
managing early arrears and non-performing exposures, and granting and monitoring forbearance measures, in line with the provisions of the EBA Guidelines on management of non-performing and forborne exposures(26) and the EBA Guidelines on arrears and foreclosure under Directive 2014/17/EU (opens EUR-Lex in a new tab)(27), and the institution’s internal policies – in relation to lending to consumers, such tasks may also include liaising with independent debt-counselling and debt advice services when relevant;
performing stress tests on the aggregate credit portfolio as well as on relevant sub-portfolios and geographical segments;
ensuring the integrity and reliability of the internal ratings assignment process, as described in Article 173 of Regulation (EU) No 575/2013, where relevant for institutions with permission to use an internal ratings-based approach, and the integrity and reliability of the rating scale and ratings assignment process used by the institution, for the institutions using the standardised approach;
performing quality assurance of credit assessments, taking into account an appropriate sample size, and ensuring that credit risk is properly identified, measured, monitored and managed within the institution’s business origination activities, and that regular reporting is communicated to the institution’s management body.
4.6Resources and skills
Institutions should have sufficient resources and staff allocated to credit risk taking and, in particular, credit decision-making, credit risk management and internal control. The organisational structure should be reviewed periodically to ensure that there are adequate resources, competencies and expertise within the credit risk management functions to effectively manage credit risk.
Institutions should ensure that the staff members involved in credit granting, in particular decision-making, risk management and internal control, have an appropriate level of experience, skills and credit-related competence.
Staff involved in credit granting, including credit decision-making, credit risk management and internal control, should frequently receive appropriate training, which includes considering changes to the applicable legal and regulatory frameworks. Training should be aligned with the institutions’ credit culture and business strategy and should be conducted on a regular basis to ensure that all relevant staff are appropriately skilled and familiar with the institutions’ credit policies, procedures and processes.
4.7Remuneration
As part of the requirements of institutions’ remuneration policies set out in Articles 74, 75 and 92 of Directive 2013/36/EU and the EBA Guidelines on remuneration policies and practices related to the sale and provision of retail banking products and services, the EBA Guidelines on sound remuneration policies under Articles 74(3) and 75(2) of Directive 2013/36/EU and disclosures under Article 450 of Regulation (EU) No 575/2013, and Article 7 (opens EUR-Lex in a new tab) of Directive 2014/17/EU (opens EUR-Lex in a new tab), institutions’ remuneration policies and practices should be in line with the approach to credit risk management, credit risk appetite and strategies, and should not create a conflict of interest. Remuneration policies and practices applicable to staff, and in particular identified staff engaged in credit granting, credit administration and monitoring, should be consistent and not provide incentives for risk taking that exceeds the tolerated risk of the institution, and should be aligned with the business strategy, objectives and long-term interests of the institution. In addition, remuneration policies and practices should incorporate measures to manage conflicts of interest, with a view to protecting consumers from undesirable detriment arising from the remuneration of sales staff.
Institutions’ remuneration policies and practices should, in particular, ensure that the performance and risk measurement process to determine the variable remuneration of the staff involved in credit granting includes appropriate credit quality metrics that are in line with the institution’s credit risk appetite.