Control framework
The management body should be responsible for establishing and monitoring the adequacy and effectiveness of the internal control framework. In particular, effective and efficient internal control processes should be implemented for the NPE workout framework in order to ensure full alignment between the NPE strategy and operational plan on the one hand and the credit institution’s overall business strategy, including the NPE strategy and operational plan, and risk appetite on the other hand.
Internal control functions should regularly submit to the management body written reports on NPE management highlighting major identified deficiencies. These reports should include, for each new identified major deficiency, the relevant risks involved, an impact assessment, recommendations and corrective measures to be taken. Where necessary, the heads of internal control functions should be able to have access to and report directly to the management body in its supervisory function to raise concerns and warn the supervisory function, where appropriate, when specific developments affect or may affect the institution. This should not prevent the heads of internal control functions from reporting within regular reporting lines as well.
The management body should follow up on the findings of the internal control functions in a timely and effective manner and require adequate remedial actions. A formal follow-up procedure on findings and corrective measures taken should be put in place.
The internal control framework should involve all three lines of defence in line with the EBA Guidelines on internal governance.(30) The roles of the different functions involved should be assigned and documented clearly to avoid gaps or overlaps. Key outcomes of second- and third-line activities as well as defined mitigating actions and progress on those needs should be reported to the management body regularly.
In the implementation of the control framework, larger and more complex credit institutions should apply all three lines of defence; the second line of defence does not have to be NPE specific and may be performed by the credit risk (control) function.
In the implementation of the control framework, smaller and less complex credit institutions (e.g. those that are classified in SREP Category 3 or 4) do not necessarily have to have three fully fledged NPE-specific lines of defence, but they have to ensure that any conflict of interest is sufficiently mitigated.
5.3.1First line of defence controls
Credit institutions should ensure that the first line of defence is embedded into the procedures and processes of the operational units, mainly the NPE WUs, that actually own and manage the credit institution’s risks in the specific context of NPE workout.
In order to ensure that adequate control mechanisms are implemented, credit institutions should have internal policies in place on the NPE workout framework. The managers of the operational units are responsible for ensuring that these internal policies are implemented, including through their incorporation into IT procedures. Annex 4 to these guidelines sets out key elements of NPE framework-related policies that should be implemented in credit institutions.
5.3.2Second line of defence controls
Second line of defence functions should perform controls on a continuous basis to check that NPE management in the first line of defence is operating as intended. To adequately perform their control tasks, second-line functions require a strong degree of independence from functions performing business activities, including the NPE WUs, and should have sufficient resources. They should have an adequate number of qualified staff. The qualifications of staff should be reassessed on an ongoing basis, and staff should receive training as necessary.
The second line of defence controls the implementation of risk management measures by the NPE WUs and should have a special focus on:
a) monitoring and measuring of NPE-related risks on a granular and aggregate basis, including in relation to internal/regulatory capital adequacy;
b) reviewing the performance of the overall NPE operating model, as well as elements of it (e.g. NPE WU management/staff, outsourcing/servicing arrangements, NPE reduction targets and early warning mechanisms);
c) assuring quality across NPE loan processing, monitoring/reporting (internal and external), forbearance, impairments, write-offs, collateral valuation and NPE reporting (in order to fulfil this role, second-line functions should have sufficient power to intervene ex ante on the implementation of individual workout solutions);
d) reviewing the alignment of NPE-related processes with internal policy and public guidance, most notably related to NPE classification, provisioning, write-offs, collateral valuations, forbearance and early warning mechanisms.
Risk control and compliance functions should also provide guidance on the process of designing and reviewing NPE-related policies and procedures and on the controls being established across NPE WUs. These functions should be involved in the design and review of the policies before they are approved by the management body.
5.3.3Third line of defence controls
The third line of defence, the independent internal audit function, should have sufficient NPE workout expertise to perform its periodic control activities on the efficiency and effectiveness of the NPE framework, including the first- and second-line controls.
In determining the frequency, scope and scale of the controls to be carried out, credit institutions should take into account the level of NPEs and whether significant irregularities and weaknesses have been identified by recent audits.
Based on the results of its controls, the internal audit function should make recommendations to the management body, bringing possible improvements to their attention.