Assessment of credit risk management and control framework
To achieve a comprehensive understanding of the institution’s credit risk profile, competent authorities should review the institution’s credit risk management and control framework and its adequacy with respect to the inherent credit risk exposures. For this assessment, competent authorities should also rely on the outcome coming from the assessment of other SREP elements (such as the BMA and governance areas). For institutions subject to the application of the NPE (reduction) strategies and the associated governance and operational guidance, competent authorities should also assess whether institutions meet specific requirements set out in the relevant EBA guidelines for such strategies and their operationalisation, including with respect to meeting the consumer protection obligations.
Credit risk strategy and appetite
Competent authorities should assess whether the institution has a sound, clearly formulated and documented credit risk appetite, strategy and limits approved by the management body. For this assessment, among other factors, competent authorities should take into account the role of the management body in setting, approving and reviewing the credit risk strategy and appetite, the proper implementation of this strategy by the senior management as well as its appropriateness for the institution given its business model, overall risk appetite, current and prospective market environment and financial condition.
Organisational and internal control framework
Competent authorities should assess whether the institution has an appropriate organisational framework and governance arrangements to enable effective credit risk taking, management, measurement and control, with sufficient (both qualitative and quantitative) human and technical resources to carry out the required tasks. They should in particular assess whether the institution’s management body and senior management understand the assumptions underlying the credit measurement system. For this assessment, competent authorities should take into account the adequacy of the lines of responsibility, as well as staffs’ skills and experience to perform their tasks, for taking on, measuring, monitoring and reporting credit risk, including management of NPEs, and in particular NPE workout, and finally the existence of a clear separation between risk-takers and risk managers.
Competent authorities should assess whether the institution has appropriate policies and procedures for the credit granting, identification, measurement, reporting and control of credit risk and whether these are consistent with the institution’s credit risk strategy and cover all the main businesses and processes. This includes the assessment of whether these policies are clearly formalised, communicated and applied consistently across the institution and the banking group it belongs to. For this assessment, competent authorities should take into account whether the management body approves these policies and discusses and reviews them regularly, in line with risk strategies as well as whether senior management is responsible for drawing up and implementing the policies and procedures, as defined by the management body.
Competent authorities should assess whether the institution has an appropriate framework for identifying, understanding, measuring, monitoring and reporting credit risk, in line with the institution’s size and complexity. In this regard, competent authorities should consider whether the institution has adequate data infrastructure and whether analytical techniques are appropriate to enable the institution to adequately manage their credit risk, and to fulfil supervisory reporting requirements, and to detect, measure and regularly monitor the credit risk inherent in all on- and off-balance-sheet activities (where relevant at group level).
Competent authorities should assess whether the institution’s management body and senior management understand the assumptions underlying the credit measurement system and whether they are aware of the degree of relevant model risk. They should assess whether the institution has undertaken stress testing to understand the impact of adverse events on its credit risk exposures and on the adequacy of its credit risk provisioning, by considering the stress test frequency, relevant risk factors identified, assumptions underlying the stress scenario; and the internal use of stress testing outcomes for capital planning and credit risk strategies.
Competent authorities should assess whether the institution has defined and implemented continuous and effective monitoring of credit risk exposures (including credit concentration) throughout the institution, amongst others, by means of specific indicators and relevant triggers to provide effective early warning alerts. Competent authorities should assess whether the institution has implemented regular reporting of credit risk exposures, including the outcome of stress testing, to the management body, senior management and the relevant credit risk managers.
Competent authorities should assess whether the institution has a strong and comprehensive internal control framework and sound safeguards to mitigate its credit risk in line with its credit risk strategy and appetite. For this assessment, competent authorities should in particular pay attention to the adequate scope covered by the institution’s control functions (including all consolidated entities, geographical locations and credit activities), to the existence of operating limits and other practices aimed at keeping credit risk exposures within levels acceptable to the institution in accordance with its risk appetite and limits. For this purpose, competent authorities should pay particular attention to whether institution has appropriate internal controls and practices to ensure that breaches of (or exceptions to) policies, procedures and limits are reported in a timely manner to the appropriate level of management for action, including checks to identify, assess and manage ML/TF risks to which the institution is exposed as a result of the credit granting activities.
In conducting this assessment, competent authorities should consider whether the limit system is adequate for the institution’s complexity and its capacity to measure and manage credit risk. This includes assessing whether the limits established are absolute or whether breaches thereof may occur. In the latter case, the institution’s policies should clearly describe the period of time during which and the specific circumstances under which such breaches of limits are possible. Furthermore, competent authorities should assess the adequacy of the procedures in place to keep credit managers informed about their limits, as well as whether such limits are subject to regular review and updates (e.g. to remain aligned with changes in strategy).
Competent authorities should also assess the functionality of the internal audit function in terms of adequacy, scope and frequency of internal audits on the credit risk management framework. These audits should capture the review of the main elements of credit risk management, measurement and controls framework across the institution and the adherence to relevant external regulations of the internal policies and procedures and any deviations from either.
For institutions adopting an internal rating-based approach to determining minimum own funds requirements for credit risk, competent authorities should also assess whether the internal validation process is sound and effective in challenging model assumptions and identifying any potential shortcomings with respect to the credit risk management system. This assessment should be based – where available – on the information stemming from already performed supervisory activities on internal models (such as onsite inspections) and taking into account the supervisory practices detailed in the EBA Supervisory handbook for the validation of internal ratings-based systems(38).