Risk management framework
In assessing the institution’s risk management framework, competent authorities should assess institution’s compliance with the EBA Guidelines on Internal Governance, the DORA and other EBA Guidelines issued pursuant to Article 74(3) of Directive 2013/36/EU on internal governance arrangements, processes and mechanisms. In this context, competent authorities should consider inter alia whether:
the institution has established an appropriate risk management framework and risk management processes, encompassing an appropriate and implemented risk strategy, risk appetite, including a third-party risk management policy, ICAAP and ILAAP frameworks and stress testing capabilities and results;
where applicable, the group-wide risk management framework covers all material risks regardless of whether the risk arises from entities not subject to consolidation and establishes a comprehensive view on all risks the institution is or might be exposed to;
the management body has the ultimate responsibility for the risk strategy, risk appetite and risk management framework and provides appropriate direction and oversight;
the institution, and where applicable the consolidating institution, has documented and implemented an appropriate risk strategy and risk appetite, which cover all the institution’s material risks, contain risk limits and tolerances, and reflect the institution’s financial resources;
the risk management framework establishes adequate procedures for risk identification, measurement, mitigation and monitoring and the extent to which it is embedded in, and how it influences, the overall strategy of the institution;
the decision-making processes are clear, transparent and adequately documented, and take into account the appropriate risk considerations, and whether policies and amendments to policies are communicated in a proper and timely manner;
there are appropriate and consistent links between the business strategy, risk strategy, digital operational resilience strategy, risk appetite and risk management framework, and the capital and liquidity management frameworks, as well as the institution’s plan to address ESG risks in accordance with Article 76(2) of Directive 2013/36/EU.
Competent authorities should assess whether the institution has in place a well-documented new product approval policy, approved by the management body, that addresses the development of new markets, products and services, and significant changes to existing ones, including exceptional transactions. Competent authorities should also consider whether the risk management and compliance functions are appropriately involved in the assessment and approval of new products or significant changes to existing ones, with approvals linked to the adequacy of the respective controls.
ICAAP and ILAAP frameworks
In assessing the institution’s ICAAP and ILAAP frameworks, competent authorities should assess institution’s compliance with the EBA Guidelines on ICAAP and ILAAP information(31). The assessment of the institution’s ICAAP and ILAAP frameworks should encompass periodic review of the ICAAP and ILAAP and determine their soundness, effectiveness and comprehensiveness. In this regard, competent authorities should:
assess how ICAAP and ILAAP are integrated into the institution’s overall risk management and strategic management practices, including capital and liquidity planning, as well as the extent of their forward-looking nature;
consider the appropriateness of the ICAAP and ILAAP to assess and maintain an adequate level of internal capital and liquidity to cover the institution’s risks and to take sound business decisions (e.g. in relation to allocating capital under the business plan), including under stressed conditions;
assess whether the ICAAP and ILAAP are embedded into the decision-making and management processes at all levels in the institution (e.g. limit setting, performance measurement);
verify whether the ICAAP and ILAAP frameworks are subject to regular oversight by the management body, including the approval of these frameworks and their outcomes;
assess whether the ICAAP and ILAAP are consistently and proportionately implemented in all the institution’s business lines and legal entities and cover all material risks to which the institution is or might be exposed to;
assess compliance with related legal and regulatory requirements and also consider whether institution’s ICAAP identifies emerging risks and/or low-probability, high-impact risks, including ICT risks, environmental risks and geopolitical uncertainties;
assess whether any deviations from the institution’s standard ICAAP or ILAAP for one or more of its legal entities or business lines are justified.
Assessment of institution’s stress testing
In assessing the institution’s stress testing, competent authorities should assess institution’s compliance with the EBA Guidelines on stress testing(32) and the EBA Guidelines on environmental scenario analysis for the integration of environmental risks. This assessment encompasses the review of the institution’s stress testing programme, taking into account the size and internal organisation, and the nature, scale and complexity of the activities of the institution.
Competent authorities should perform a qualitative assessment of the institution’s stress testing programme, as well as a quantitative assessment of the results of stress tests. Competent authorities should consider the outcomes of qualitative and quantitative assessments together with the results of supervisory stress tests (see Title 11) for the purposes of assessing capital and liquidity adequacy and determining the appropriate supervisory response to the deficiencies identified. If the stress testing review identifies deficiencies in the institution’s governance and institution-wide controls, these should be considered by competent authorities in the assessment of these areas. Furthermore, the results of an institution’s stress tests can be used for the assessment of the institution’s capital planning, and in the quantification of liquidity requirements for the assessment of liquidity adequacy.
Competent authorities should assess the extent to which stress testing is embedded in the institution’s risk management framework, including how stress testing is considered in the processes of setting up the institution’s risk appetite and limits. Furthermore, competent authorities should assess the involvement of institution’s senior management and management body in the stress testing programme, including the related internal reporting, and the degree of integration of stress testing and its outcomes into the decision-making processes.
When assessing the stress testing programme, the results of stress tests and proposed management actions, competent authorities should consider both idiosyncratic and system-wide perspectives. Competent authorities should consider the feasibility of management actions in stress situations, including whether the timelines for the implementation of the actions are realistic and consider the idiosyncrasies of the institution. For the review of stress testing programmes of cross-border groups, competent authorities should take into account potential barriers to the transferability of capital and liquidity within groups and the functioning of any intra-group financial support arrangements, which may arise in stressed conditions.
Competent authorities should assess the results of stress tests(33) and whether the institution is able to maintain the applicable TSCR, at all times, in an adverse scenario and if it has identified a set of management actions to address any potential breaches of the TSCR. Competent authorities should also consider the impact of stress tests on the institution’s leverage ratio, as well as its eligible liabilities held for the purposes of minimum requirements for eligible liabilities (MREL) as referred to in Directive 2014/59/EU.
In the assessment of stress test results, competent authorities should also consider all known future regulatory changes affecting the institution within the scope and the time horizon of the stress test exercise.