Assessment of CSRBB management and control framework
To achieve a comprehensive understanding of the institution’s credit spread risk profile in the non-trading book, competent authorities should review the governance and framework underlying its interest rate exposures.
The review of the institution’s governance of CSRBB should include the following elements:
For the assessment of these areas, competent authorities should refer to section 6.5.2.2 on the assessment of the IRRBB management and control framework, with the principles contained also applicable to the assessment of CSRBB management.
When analysing the perimeter of assets and liabilities covered by the CSRBB assessment, also as considered within the institution’s methodologies, competent authorities should assess whether any potential exclusion of instruments from the relevant perimeter is only made in the absence of sensitivity to credit spread risk and is appropriately documented and justified, as required in paragraph 124 of the EBA Guidelines on IRRBB and CSRBB(50). Factors to take into account include:
whether the institution includes all assets and liabilities accounted at fair value;
whether the institution includes all assets and liabilities whose credit spread risk can be inferred from a direct/indirect or even modelled market price, whatever their accounting treatment;
the potential relevance of credit spreads in the institution’s pricing practice for different assets/liabilities (for example through explicit references to observed market prices or more indirect relevance);
differences, if any, that the institution applies between the perimeter for EVE and NII in the measurement of CSRBB (e.g. due to the NII time horizon or other reasons).
To analyse the institution’s measurement of CSRBB, competent authorities should consider, where appropriate, to review which shock scenarios the institution is considering, and, how and why the shocks may be different between balance sheet items.
Competent authorities should check the exclusion of idiosyncratic spread in the institution’s measurement of CSRBB or its inclusion only for proportionality reasons and regardless of the SREP categorisation of the institution, as long as it is ensured that the measures will yield more conservative results.
Competent authorities should assess whether the institution has an appropriate framework for identifying, evaluating, managing and mitigating CSRBB, in line with the level, complexity and riskiness of non-trading book positions and the institution’s size and complexity. They should consider whether the information systems and measurement techniques enable management to measure the inherent CSRBB in all its material on- and off-balance- sheet exposures (where relevant at group level) in the non-trading book portfolio. The CSRBB framework should be subject to regular reviews and evaluations of its effectiveness. In this context, competent authorities should assess whether significant measurement assumptions are reviewed at least annually and more frequently during rapidly changing market conditions.
Competent authorities should consider whether the institution’s internal measurement systems (IMS) take into account all sources of CSRBB which are relevant for the institution’s business model. The IMS should be properly calibrated, independently validated, back-tested and reviewed at an appropriate frequency. Competent authorities should take into account whether the IMS is supported by documentation considering the nature, scale and complexity of the CSRBB inherent in the business model and the institution’s activities.
Competent authorities should assess whether the institution has an appropriate monitoring and internal reporting framework for CSRBB that ensures there is prompt action at the appropriate level of the institution’s senior management or management body, where necessary. Competent authorities should take into account whether the management and control area reports the results of the monitoring regularly to the management body and senior management, with an appropriate frequency depending on the scale, complexity and level of CSRBB exposures.
Competent authorities should assess whether the institution has a strong and comprehensive control framework and sound safeguards to mitigate significant exposures to CSRBB in line with its risk management strategy and risk appetite. The internal control function should include all consolidated entities, all geographical locations and all financial activities. Competent authorities should assess the functionality of the internal audit function, including whether its reviews are conducted sufficiently frequently and cover the main elements of the CRSBB framework.