Overview of the SREP framework
Competent authorities should have a comprehensive SREP framework covering the following components, which should be assessed on a regular basis, having regard to the list of legal acts published separately on the EBA website against which compliance of institution should be evaluated. The SREP engagement model in section 2.4 sets out how this framework can be calibrated across diverse institutions in application of the proportionality principle. These components are:
categorisation of the institution as specified in section 2.1.1;
Competent authorities should consider the SREP an ongoing process that integrates the outcome of all the supervisory activities and all available sources of information into a comprehensive supervisory overview of an institution. The SREP should include consideration of the following:
the outcome of previous SREP assessments, business model analysis and ongoing off-site supervision;
institution’s financial reporting, strategic plan(s), regulatory reporting (common reporting – COREP, financial reporting – FINREP, and credit register, where available) and internal reporting (e.g. management information, capital and liquidity reporting, internal risk reports);
institution’s ICAAP/ILAAP and recovery planning arrangements;
on-site inspections;
internal model assessments;
targeted deep-dive analysis;
horizontal thematic reviews;
stress testing analysis;
third-party reports (e.g. audit reports, reports by equity/credit analysts);
other relevant sectoral or macroeconomic studies/surveys.
2.1.1Categorisation of institutions
Competent authorities should categorise all institutions under their supervisory remit into four different categories based on the size, systemic importance, nature, scale and complexity of the activities of the institutions concerned and considering Article 97(4) of Directive 2013/36/EU. The categorisation should reflect the assessment of systemic risk posed by institutions to the financial system.
Within a group of entities, if competent authorities determine that the relevance of different entities within the group, based on the elements listed in paragraph 17, varies, they may apply categorisation at the individual level to reflect these differences (e.g. assigning different categories to various group subsidiaries and/or consolidated entity).
Competent authorities should review the categorisation of their institutions periodically, and following events that may affect the business models’ riskiness, or major corporate operations such as a large divestment, a merger or acquisition, an important strategic action.
To ensure a minimum level of comparability, competent authorities should refer to the categories below as a starting point:
► Category 1 – All institutions defined as ‘large institutions’ in Article 4(1), point 146 of Regulation (EU) 575/2013. Competent authorities may classify ‘large institutions’ as Category 2 or Category 3 institutions for proportionality reasons provided they are not G-SIIs. The reclassification of ‘large institutions’ that are not G-SIIs should be performed in accordance with the qualitative criteria of Category 2 and Category 3 below, considering the institution’s size, systemic importance, nature, scale and complexity of the activities.
► Category 2 – (i) Medium to large institutions other than those included in Category 1 which are not ‘small and non-complex institutions’ as defined in Article 4(1), point 145, of Regulation (EU) 575/2013 and operate in several business lines, including non-banking activities, or have sizeable cross-border activities, and offer credit and financial products to retail and corporate customers; (ii) non-systemically important specialised institutions with significant market shares in their lines of business or payment systems, or trading platforms/markets for financial instruments; (iii) institutions considered important, due to their size, activities, or business model (e.g. central institutions of an IPS, CCPs, CSDs, central cooperative banks or central savings banks), for the economy (e.g. in terms of total assets over gross domestic product – TA/GDP) or for the banking sector in a particular Member State.
► Category 3 – (i) Small to medium institutions other than those included in Categories 1 and 2, which are not ‘small and non-complex institutions’ as defined in Article 4(1), point 145, of Regulation (EU) 575/2013 and operate in a limited number of business lines, or have non-significant cross-border activities, offering predominantly credit products to retail, corporate and institutional customers with a limited offering of financial products; (ii) specialised institutions with less-significant market shares in their lines of business or payment systems, or financial exchanges.
► Category 4 – All institutions defined as ‘small and non-complex institutions’ in Article 4(1), point 145 of Regulation (EU) 575/2013 and all other small non-complex institutions that do not fall into Categories 1 to 3 (e.g. with a limited scope of activities and non-significant market shares in their lines of business).
2.1.2Continuous assessment of risks, escalation framework and supervisory measures
Competent authorities should continuously assess the risks to which the institution is or might be exposed through their supervisory activities in accordance with the SREP engagement model set out in section 2.4.
Competent authorities should ensure that the findings of their assessments are clearly documented, with a focus on the root causes of the identified deficiencies. These findings should be reflected in the SREP scores assigned in accordance with these guidelines and should inform subsequent supervisory measures that competent authorities may apply as specified in Articles 102, 104 and 105 of Directive 2013/36/EU and national law, and, when applicable, early intervention measures as specified in Article 27 of Directive 2014/59/EU, or any combination of the above.
As part of their ongoing supervisory activities, competent authorities should undertake appropriate and timely follow-up activities to ensure that an institution has effectively addressed the identified deficiencies. In this regard, competent authorities should establish a high-level escalation framework for supervisory measures, supporting the selection of the most appropriate measures (both quantitative and qualitative) to address the identified deficiencies. This is without prejudice to the supervisory powers provided under the applicable legal framework and the competent authorities’ discretion to determine the most appropriate measures based on the specific circumstances and deficiencies.
The framework referred to in the previous paragraph should consider the following actions, which are not to be intended to be strictly sequential and may be escalated or de-escalated as appropriate:
engaging in an enhanced supervisory dialogue with the institution, such as holding a meeting with the management body or requiring a self-assessment from the institution;
communicating corrective actions expected from the institution (non-binding measures), such as supervisory expectations or recommendations;
requiring specific corrective action(s) from the institution (binding measures), such as setting qualitative measures the institution needs to comply with and/or setting/increasing Pillar 2 requirement or liquidity requirements;
enforcing supervisory measures to remedy the deficiencies identified, such as administrative penalties, remedial measures or fines.
When selecting supervisory measures, competent authorities should identify the full escalation path, taking into account the information available, the nature, size and complexity of the institution and the need to ensure timely remediation of identified deficiencies. The selection should be guided by the following considerations, as applicable:
the intended outcome that the measures aim to achieve and, where feasible, the expected timelines for the institution to address the deficiencies;
the severity of the deficiencies and the potential prudential impact of not addressing the issue (i.e. whether it is necessary to address the issue with a specific measure) and whether the deficiencies have already been addressed/covered by other measures;
the demonstrated ability or intention of the institution to remediate to the deficiencies;
whether other measures would achieve the same objective with less of an administrative and financial impact on the institution;
the possibility that risks and vulnerabilities identified may be correlated or self-reinforcing, or both, meriting an increase in the rigorousness of supervisory measures;
any other factors deemed relevant by the competent authorities.
Without prejudice to the discretion of the competent authorities in selecting the most appropriate measures, all available quantitative and qualitative measures should be used in a way that allows to best address the risk level and/or deficiencies. This should take into account the nature of the risk (quantitative and/or qualitative), the escalation process, and the fact that quantitative measures should be applied to address deficiencies in internal governance, including internal control arrangements, and other issues, where other supervisory measures have not been effective or are considered insufficient to address the identified deficiencies within an appropriate timeframe(16).
The provisions of this title are without prejudice to the possibility of competent authorities taking supervisory measures directly linked to the outcomes of any supervisory activities (e.g. on-site examinations or assessments of the suitability of members of the management body and key functions) where the outcomes of such activities necessitate immediate application of supervisory measures to address material deficiencies.
2.1.3Dialogue with institutions
Competent authorities should engage in dialogue with institutions as they perform their supervisory activities.