Summary of findings, scoring and supervisory measures
Following the above assessment, competent authorities should form a view on the adequacy of the institution’s internal governance arrangements and institution-wide controls. This view should be reflected in a summary of findings, accompanied by a viability score based on the considerations specified in table 4.
Score | Supervisory view Considerations |
1 | • The institution has a robust and transparent organisational structure with clear responsibilities and separation of risk-taking from risk management and control functions. • The composition and functioning of the management body are appropriate. • The time commitment of the management body members is appropriate and they Deficiencies in internal governance comply with the limitation on the number of and institution-wide control directorships, where relevant. arrangements pose a low level of • There is a sound risk culture and business risk to the viability of the institution. conduct, including management of conflicts of interest and whistleblowing processes. • The institution has adopted a diversity policy that fosters a diverse management body composition and complies with the targets set. • The remuneration policy is in line with the institution’s risk strategy and long-term interests. |
Score | Supervisory view Considerations |
• The risk management framework and risk management processes, including the ICAAP, ILAAP, NPAP, stress testing framework, capital planning and liquidity planning, are appropriate. • The internal control framework and internal controls are appropriate. • The risk management, compliance and internal audit functions are independent, operate effectively, have sufficient resources, and the internal audit function operates in accordance with established international standards and requirements. • ICT systems, risk data aggregation and risk reporting are appropriate. • The integration of ESG risks into the internal governance and risk management framework is appropriate. • The recovery planning governance framework is appropriate. • The institution addresses swiftly identified deficiencies and/or concerns expressed by competent authorities and effectively remediates them within a short timeframe providing satisfactory outcomes. Additionally, the institution proactively reports and informs the competent authorities throughout this process. | |
2 | • The institution has a largely robust and transparent organisational structure with clear responsibilities and separation of risk-taking from risk management and control functions. • The composition and functioning of the management body are largely appropriate. • The time commitment of the management body members is largely appropriate, and, where relevant, they comply with the Deficiencies in internal governance limitation on the number of directorships. and institution-wide control • There is a largely sound risk culture and arrangements pose a medium-low business conduct, including management of level of risk to the viability of the conflicts of interest and whistleblowing institution. processes. • The institution has adopted a diversity policy that fosters a diverse management body composition, and largely complies with the targets set or has implemented appropriate measures to achieve the targets set in the policy. • The remuneration policy is largely in line with the institution’s risk strategy and long-term interests. |
Score | Supervisory view Considerations |
• The risk management framework and risk management processes, including the ICAAP, ILAAP, NPAP, stress testing framework, capital planning and liquidity planning, are largely appropriate. • The internal control framework and internal controls are largely appropriate. • The risk management, compliance and internal audit functions are independent and their operations are largely effective. • ICT systems, risk data aggregation and risk reporting are largely appropriate. • The integration of ESG risks into the internal governance and risk management framework is largely appropriate. • The recovery planning governance framework is largely appropriate. • The institution is able to adequately address most of the deficiencies identified and/or concerns expressed by competent authorities, within an acceptable timeframe and – where applicable – complies with the reporting requirements set by the competent authorities in relation to these deficiencies. | |
3 | • The institution’s organisational structure and responsibilities are not fully transparent and risk-taking is not fully separated from risk management and control functions. • There are doubts about the appropriateness of the composition and functioning of the management body. • There are doubts about the appropriate time commitment of the management body member and where relevant they do not comply with the limitation on the number of Deficiencies in internal governance directorships. and institution-wide control • There are doubts about the appropriateness arrangements pose a medium-high of the risk culture and business conduct, level of risk to the viability of the including management of conflicts of interest institution. and/or whistleblowing processes. • The institution has not adopted a diversity policy and has not implemented measures to achieve an appropriate level of diversity within the management body. • There are concerns that the remuneration policy may not be aligned with the institution’s risk strategy and long-term interests. • There are doubts about the appropriateness of the risk management framework and risk management processes, including the ICAAP, |
Score | Supervisory view Considerations |
ILAAP, NPAP, stress testing framework, capital planning and/or liquidity planning. • There are doubts about the appropriateness of the internal control framework and internal controls. • There are doubts about the independence and effective operation of the risk management, compliance and internal audit functions. • There are doubts about the appropriateness of ICT systems, risk data aggregation and risk reporting. • There are doubts about the appropriateness of the integration of ESG risks into the internal governance and risk management framework. • The recovery planning governance framework was assessed as potentially having material deficiencies and/or having material impediments to its effective implementation and supervisory concerns have not been fully addressed. • The institution faces significant challenges or demonstrates limited intention to adequately address the deficiencies identified and/or concerns expressed by competent authorities, in terms of the quality of the remediation actions and/or the timeframe for their implementation, which might indicate the need for escalation. The institution also has challenges in reporting on its remediation status to competent authorities. | |
4 | • The institution’s organisational structure and responsibilities are not transparent and risk-taking is not separated from risk management and control functions. • The composition and functioning of the management body are inappropriate. • The time commitment of the management body members is insufficient, and, where Deficiencies in internal governance relevant, they do not comply with the and institution-wide control limitation on the number of directorships. arrangements pose a high level of • The risk culture and business conduct, risk to the viability of the institution. including management of conflicts of interest and/or whistleblowing processes are inappropriate. • The institution has not adopted a diversity policy, the management body is not diverse and the institution has not implemented measures to aim for an appropriate level of diversity. |
Score | Supervisory view Considerations |
• The remuneration policy is not aligned with the institution’s risk strategy and long-term interests. • The risk management framework and the risk management processes, including the ICAAP, ILAAP, NPAP, stress testing framework, capital planning and/or liquidity planning, are inappropriate. • The risk management, compliance and/or internal audit functions are not independent, not operating effectively and/or the internal audit function is not operating in accordance with established international standards and requirements. • The internal control framework and internal controls are inappropriate. • The ICT systems, risk data aggregation and risk reporting are inappropriate. • The integration of ESG risks into the internal governance and risk management framework is inappropriate. • The recovery planning governance framework was assessed as having material deficiencies and/or having material impediments to its effective implementation and supervisory concerns have not been fully addressed. • The institution is unable or does not intend to adequately address deficiencies identified and/or concerns expressed by competent authorities and lacks the capability to remedy them within an acceptable timeframe, following escalation from competent authorities. The institution also has severe challenges in reporting on its remediation status to competent authorities. |
The table below presents a non-exhaustive list of supervisory measures that competent authorities may take in case of identified deficiencies in institution’s internal governance and institution-wide controls. Competent authorities should decide on the type of supervisory measure based on its effectiveness towards the specific identified deficiency. Competent authorities may apply additional supervisory measures or a combination of these with the ones listed in the table below, if these are deemed more appropriate to address the identified deficiencies. For breaches of DORA, competent authorities should consider the applicable corrective and remedial measures provided in Article 50 of DORA.
Table 5. Potential and non-exhaustive list of supervisory measures stemming from the assessment of institution’s internal governance and institution-wide controls Potential supervisory measures for competent authorities in accordance with Article 104(1) points (b), (d), (e), (f), (g), (j), (l, (m), and (n) of Directive 2013/36/EU and Article 50 of Regulation (EU) 2022/2554 – Competent authorities may require the institution to: A. enhance and have a more active involvement of the management body or its committees; B. develop and implement corrective action plans to address deficiencies; C. strengthen internal controls; D. improve the internal governance framework; E. enhance reporting mechanisms and oversight; F. limit variable remuneration; G. implement compliance management systems; H. have additional or more frequent reporting requirements; I. reinforce specific arrangements, processes, mechanisms and strategies; J. reperform stress tests using modified assumptions; K. enhance governance and risk management arrangements applied to ESG risks, in particular environmental risks.