Assessment of reputational risk
Competent authorities should assess the reputational risk to which the institution is exposed by leveraging the understanding gained from Title 4 to Title 6.2. Such an assessment should also focus on the overall reputational risk framework, ensuring the ability of the institution to effectively manage any reputation events. For this assessment, competent authorities should avoid double counting aspects already considered under the assessment of legal risk (section 6.4.2.1).
When assessing the relevance of reputational risk, competent authorities should consider the size of the institution as well as the nature, scale and complexity of their services, activities and operations (for example, listed equities or debts or participation in interbank markets).
Competent authorities should consider both internal and external factors or events that might give rise to reputational concerns, excluding events that result in legal proceedings. For Category 1 and Category 2 institutions, competent authorities should consider all the following indicators in their assessment:
negative media/social media coverage and consumer-association initiatives that could deteriorate the public perception and reputation of the institution;
the number of and changes in customer complaints or sudden loss of customers or investors;
negative events relating to the institution’s peers that the public could associate with the whole financial sector or a group of institutions;
the reputation of individuals involved in the management of the institution or with qualifying shareholdings;
involvement or operation in sectors or jurisdictions highly exposed to ML/TF or with individuals associated with high risk from an ML/TF perspective;
involvement or operation in sectors or jurisdictions and/or with counterparties highly exposed to material issues or public controversies related to ESG factors, including but not necessarily limited to environmental factors;
the reputational impact of ICT-related incidents as recorded by the institution in accordance to the Commission Delegated Regulation (EU) 2024/1772(47);
other ‘market’ indicators, if available (e.g. rating downgrades or changes in the share price throughout the year).
Competent authorities should assess the significance of the institution’s reputational risk exposure and its interconnectedness with the other risks by leveraging the relevant risk assessments (including from other supervisory authorities) to identify any possible secondary effects in either direction.
In the context of the operational risk analysis, competent authorities should take into account the relevance and significance of the institution’s exposures to ML/TF risk from a prudential perspective under the scope of operational risk. In this respect, competent authorities should use the relevant input received from AML/CFT supervisors to supplement their findings from ongoing supervision and evaluate whether they give rise to prudential concerns related to ML/TF risk.
Competent authorities should bear in mind that any institution can be exposed to ML/TF risk regardless of the institution’s size or financial soundness. Therefore, sufficient attention should also be paid to institutions that are perceived to be financially sound and may have a good reputation given that these institutions might be specifically targeted for ML/TF purposes. Attention should also be paid to institutions that are very successful in attracting new customers/expanding market share – especially by using non-traditional distribution channels
since this could be related to weak customer due diligence controls at the onboarding phase.
Competent authorities should share relevant information on operational risk issues identified that can give rise to ML/TF risks, risks of non-implementation and evasion of targeted financial sanctions and concerns such as deficiencies in the institutions’ ICT system or internal control framework with AML/CFT supervisors.
Competent authorities should assess whether the institution has implemented adequate arrangements, strategies, processes and mechanisms to manage reputational risk. In particular, competent authorities should take into account whether:
the institution has formalised policies and processes in place for the identification, management and monitoring of this risk, including a robust code of conduct, and whether these policies and processes are proportionate to its size and its relevance in the system;
the institution addresses this risk in a precautionary manner, including putting in place appropriate metrics and monitoring tools, coverage of potential reputation issues in contingency plans, conducting relevant training and awareness sessions and leveraging lessons learned;
the institution conducts stress testing or scenario analysis to assess any secondary effects of reputational risk (e.g. liquidity and funding costs, securitisation transactions, access to correspondent banking service);
the institution acts to protect its brand through tools to monitor media/social media, protocols to address misinformation and adverse publicity as well as prompt communication campaigns;
the institution considers the potential impact of its strategy and business plans, and more generally of its behaviour, on its reputation.