Assessment of the market risk management and control framework
To achieve an adequate understanding of the management of market risk, commensurate to the institution’s risk profile, competent authorities should review the institution’s risk management and control framework and its adequacy with respect to inherent risk exposures. For this assessment, the competent authority should use the paragraphs set out in this section, while also leveraging on:
the outcome of the assessment of other SREP elements (such as the BMA and governance areas);
the outcome of the assessment referred to in Article 325c of Regulation 575/2013/EU for institutions using the alternative standardised approach, and the outcome of the assessment performed in accordance with Delegated Regulation (EU) 2024/1085, especially in relation to the requirements referred to in Articles 104b, 325bi, and 325bj of Regulation 575/2013/EU.
Market risk strategy and risk appetite
Competent authorities should assess whether institutions have sound, clearly formulated and documented risk appetite, strategy and limits approved by their management body. For this assessment, among other factors, competent authorities should take into account the role of the management body in setting, approving and reviewing the risk strategy and appetite, the proper implementation of this strategy by the management body as well as its appropriateness for the institution given its business model, overall risk appetite, current and perspective market environment and financial condition.
Organisational and internal control framework
Competent authorities should assess whether the institution has an appropriate organisation framework for identifying, understanding, measuring, monitoring and controlling market risk, with sufficient (both qualitative and quantitative) human and technical resources to carry out the required tasks. For this assessment, competent authorities should take into account the adequacy of the lines of responsibility for taking, monitoring, reporting and controlling market risk, their coverage of the entire institution, the existence of a clear separation between the front office and back office and between the risk-taking and the control functions, and the skills and expertise of staff involved.
Competent authorities should assess whether the institution has clearly defined policies and procedures for the identification, management, measurement and control of market risk and whether these are sound and consistent with the institution’s risk strategy and cover all the main businesses and processes. This includes the assessment of whether these policies and procedures are clearly formalised, communicated and applied consistently across the institution.
In particular, the assessment should cover the positions to be included/excluded from the trading book for regulatory purposes, the policies on internal hedges and the procedures for new market activities and/or products.
Competent authorities should assess whether the institution has an appropriate framework for identifying, understanding and measuring market risk, in line with the institution’s size and complexity, and that this framework is compliant with relevant minimum requirements in accordance with the applicable legal and regulatory framework.
Competent authorities should assess whether institutions have in place an adequate monitoring and reporting framework for market risks that ensures there will be prompt action at the appropriate level of the institution’s senior management or management body in case of breaches. The monitoring system should include specific indicators and relevant triggers to provide effective early warning alerts and should inform the management body and senior management about current exposures and measures compared to policy limits.
Competent authorities should assess whether the institution has a strong and comprehensive limit systems and control framework with sound safeguards to mitigate its risks in line with its risk strategy and appetite. For this assessment, competent authorities should pay particular attention to the adequate scope covered by the institution’s control functions (including all consolidated entities, geographical locations and market activities), to the existence of operating limits (including individual limits at desk or business-unit level which should be daily monitored) and other practices aimed at keeping market risk exposures within levels acceptable to the institution in accordance with its risk appetite and limits.
Competent authorities should also assess whether the internal validation process is sound and effective in challenging model assumptions and identifying any potential shortcomings with respect to the market risk management system. For institutions adopting an internal approach to determining minimum own funds requirements for market risk, this assessment should be based – where available – on the information stemming from already performed supervisory activities on internal models (such as on-site inspections).
Competent authorities should also assess the functionality of the internal audit function in terms of adequacy, scope and frequency of internal audits on the market risk management framework. This should comprise the review of the main elements of risk management, measurement and controls framework across the institution and the adherence to relevant external regulations of the internal policies and procedures and any deviations from either.