Commission Delegated Regulation (EU) 2022/439 of 20 October 2021 supplementing Regulation (EU) No 575/2013 of the European Parliament and of the Council with regard to regulatory technical standards for the specification of the assessment methodology competent authorities are to follow when assessing the compliance of credit institutions and investment firms with the requirements to use the Internal Ratings Based Approach (Text with EEA relevance)
In order to assess whether an institution calculates the own funds requirements using its risk parameters for different exposure classes in accordance with Article 110(2) and (3), point (g) of Article 144(1) and Articles 151 to 168 of Regulation (EU) No 575/2013 and is able to carry out the reporting required by Article 430 of Regulation (EU) No 575/2013, competent authorities shall verify all of the following:
(a) the reliability of the system used for the calculation of own funds requirements, in accordance with Article 68;
(b) the data quality, in accordance with Article 69;
(c) the correctness of the implementation of the methodology and procedures for different exposure classes, in accordance with Article 70;
(d) the organisation of the process for the calculation of own funds requirements, in accordance with Article 71.
As regards groups, competent authorities shall for the purpose of the assessment under paragraph 1 take into consideration the structure of the banking group and the established roles and responsibilities of the parent institution and its subsidiaries.
For the purposes of the verification under paragraphs 1 and 2, competent authorities shall apply all of the following methods:
(a) review the institution’s internal policies and procedures with regard to the process of calculation of own funds requirements, including the sources of data, calculation methods and controls applied;
(b) review the relevant roles and responsibilities of the different units and internal bodies involved in the process of calculation of own funds requirements;
(c) review the relevant minutes of the institution’s internal bodies, including the management body, or committees;
(d) review the documentation of the tests of the calculation system, including the scenarios covered in the tests, their results and approvals;
(e) review the relevant control reports, including the results of reconciliation of data stemming from different sources;
(f) review the relevant findings of the internal audit or of other control functions of the institution;
(g) review the progress reports on the efforts made by the institution to correct shortcomings and mitigate risks detected during relevant audits;
(h) obtain written statements from or interview the relevant staff and senior management of the institution.
For the purpose of the assessment under paragraphs 1 and 2, competent authorities may also apply any of the following additional methods:
(a) review the functional documentation of the IT systems used for the calculation of own funds requirements;
(b) request the institution to perform a live computation of the own funds requirements for certain types of exposures;
(c) perform own sample testing of the calculation of own funds requirements on institution’s data for certain types of exposures;
(d) perform own tests on the data of the institution or request the institution to perform tests proposed by the competent authorities;
(e) review other relevant documents of the institution.
Article 68
Reliability of the system used for the calculation of own funds requirements
When assessing the reliability of the institution’s system used for the calculation of own funds requirements as referred to in Article 144(1)(g) of Regulation (EU) No 575/2013, in addition to the requirements of Article 72 to 75 regarding the assessment methodology for data maintenance, competent authorities shall verify that:
(a) the control tests performed by the institution to confirm that the calculation of own funds requirements is compliant with Articles 151 to 168 of Regulation (EU) No 575/2013 are complete;
(b) those control tests are reliable, and in particular that the calculations made in the system used for the own funds requirements are coherent with the calculations made in an alternative calculation tool;
(c) the frequency of the control tests performed by the institution is adequate and the tests take place at least at the moment of the implementation of the algorithms for the calculation of own funds requirements and in all other cases where changes to the system are made.
Article 69
Data quality
When assessing the data quality used for the calculation of own funds requirements referred to in Article 144(1)(g) of Regulation (EU) No 575/2013, in addition to the requirements in Article 73, competent authorities shall verify the mechanisms and procedures implemented by the institution for identifying the exposure values with all relevant characteristics, including data relating to risk parameters and credit risk mitigation techniques. Competent authorities shall verify that:
(a) the risk parameters are complete, including in cases where missing parameters are substituted by default values, and that where such a substitution has taken place, it is conservative, justified and documented;
(b) the range of the parameter values complies with the regulatory and minimum values specified in Articles 160 to 164 of Regulation (EU) No 575/2013;
(c) the data used in the calculation of own funds requirements is consistent with the data used in other internal processes;
(d) the application of risk parameters is in accordance with the exposure characteristics, and in particular that the LGD assigned is accurate and consistent with the type of exposure and collateral used to secure the exposure in accordance with Article 164 and Article 230(2) of Regulation (EU) No 575/2013;
(e) the calculation of the exposure value is correct, and in particular the netting agreements and the classification of off-balance sheet items are used in accordance with Article 166 of Regulation (EU) No 575/2013;
(f) where the PD/LGD method is applied for equity exposures, the classification of the exposures and the application of risk parameters is correct in accordance with Article 165 of Regulation (EU) No 575/2013.
When assessing the coherence of the data used for the calculation of own funds requirements with the data used for internal purposes in accordance with Articles 18 to 22 on assessment methodology for use test and experience test, competent authorities shall verify that:
(a) there are adequate control and reconciliation mechanisms in place to ensure that the values of risk parameters used in the calculation of own funds requirements are consistent with the value of parameters used for internal purposes;
(b) there are adequate control and reconciliation mechanisms in place to ensure that the value of exposures for which the own funds requirements are calculated is consistent with the accounting data;
(c) the calculation of own funds requirements for all exposures included in the general ledger of the institution is complete, and that the split between the exposures under the IRB Approach and the Standardised Approach complies with Articles 148 and 150 of Regulation (EU) No 575/2013.
Article 70
Correctness of the implementation of the methodology and procedures for different exposure classes
When assessing the correctness of the implementation of the methodology and procedures for the calculation of own funds requirements referred to in Article 144(1)(g) of Regulation (EU) No 575/2013 for different exposure classes, competent authorities shall verify that:
(a) the risk weight formula is implemented correctly in accordance with Articles 153 and 154 of Regulation (EU) No 575/2013, taking into account the assignment of exposures to exposure classes;
(b) the calculation of the correlation coefficient is done based on the characteristics of the exposures, in particular that the total sales parameter is applied on the basis of consolidated financial information;
(e) the floors for the exposure-weighted average LGD for retail exposures secured by residential property and commercial real estate, which are not benefiting from guarantees of central governments laid down in Article 164(4) and (5) of Regulation (EU) No 575/2013, are calculated at the aggregated level of all retail exposures secured by residential property and commercial real estate respectively, and that, where the exposure-weighted average LGD at the aggregated level is below the respective floors, relevant adjustments are applied consistently over time by the institution;
(g) where the simple risk weight approach is used in accordance with Article 155(2) of Regulation (EU) No 575/2013, the application of risk weights is correct, in particular that the risk weight of 190 % is used only for sufficiently diversified portfolios, where the institution has proved that significant reduction of risk has been achieved as a result of the diversification of the portfolio in comparison to the risk of individual exposures in the portfolio;
Article 71
Organisation of the process for the calculation of own funds requirements
When assessing the soundness of the process for the calculation of own funds requirements as referred to in Article 144(1)(g) of Regulation (EU) No 575/2013, competent authorities shall verify that:
(a) the allocation of responsibilities of the unit or units in charge of the control and management of the calculation process, in particular the allocation of responsibilities for the specific controls to be performed at each step of the calculation process, is clearly defined;
(b) relevant procedures, including back-up procedures, ensure that the calculation of own funds requirements is carried out in accordance with Article 430 of Regulation (EU) No 575/2013;
(c) all input data, including the values of risk parameters and the previous versions of the system, are stored to allow replication of the calculation of own funds requirements;
(d) the results of the calculation are approved on an adequate management level and that senior management is informed about possible errors or inadequacies of the calculation and the measures to be taken.
CHAPTER 12
ASSESSMENT METHODOLOGY FOR DATA MAINTENANCE
Article 72
General
When assessing compliance with the requirements on data maintenance laid down in Article 144(1)(d) and Article 176 of Regulation (EU) No 575/2013, competent authorities shall evaluate all of the following:
(a) the quality of the internal, external or pooled data, including the data quality management process, in accordance with Article 73;
(b) the data documentation and reporting, in accordance with Article 74;
(c) the relevant IT infrastructure, in accordance with Article 75.
For the purpose of the assessment under paragraph 1, competent authorities shall apply all of the following methods:
(a) review the data quality management policies, methods and procedures relevant to the data used in the IRB Approach;
(b) review the relevant data quality reports, as well as their conclusions, findings and recommendations;
(c) review the IT infrastructure policies and IT systems management procedures, including the contingency planning policies, relevant for the IT systems used for the purpose of the IRB Approach;
(d) review the relevant minutes of the institution’s internal bodies, including management body, or committees;
(e) review the relevant findings of the internal audit or of other control functions of the institution;
(f) review the progress reports on the efforts made by the institution to correct shortcomings and mitigate risks detected during relevant audits;
(g) obtain written statements from or interview the relevant staff and senior management of the institution.
For the purpose of the assessment under paragraph 1, competent authorities may also apply any of the following additional methods:
(a) perform own tests on the data of the institution or request the institution to perform tests proposed by the competent authorities;
(b) review other relevant documents of the institution.
Article 73
Data quality
When assessing the quality of internal, external or pooled data necessary to effectively support credit risk measurement and management process in accordance with Article 144(1)(d) and Article 176 of Regulation (EU) No 575/2013, competent authorities shall verify:
(a) the completeness of values in the attributes that require them;
(b) the accuracy of data ensuring that the data is substantively error-free;
(c) the consistency of data ensuring that a given set of data can be matched across different data sources of the institution;
(d) the timeliness of data values ensuring that the values are up-to-date;
(e) the uniqueness of data ensuring that the aggregate data is free from any duplication given by filters or other transformations of source data;
(f) the validity of data ensuring that the data is founded on an adequate system of classification, rigorous enough to compel acceptance;
(g) the traceability of data ensuring that the history, processing and location of data under consideration can be easily traced.
When assessing the data quality management process, competent authorities shall verify that:
(b) there is a sufficient degree of independence of the data collection process from the data quality management process, including a separation of the organizational structure and staff, where appropriate.
Article 74
Data documentation and reporting
When assessing the documentation of data necessary to effectively support credit risk measurement and management process in accordance with Articles 144(1)(d) and 176 of Regulation (EU) No 575/2013 competent authorities shall evaluate all of the following:
(b) the data management policy and allocation of responsibilities, including users’ profiles and data owners;
(c) the transparency, accessibility and consistency of the controls implemented in the data management framework.
When assessing data reporting, competent authorities shall verify, in particular, that data reporting:
(a) specifies the scope of reports or reviews, the findings and, where applicable, the recommendations to address weaknesses or shortcomings detected;
(b) is communicated to the senior management and management body of the institution with an adequate frequency and that the level of the recipient of the data reporting is consistent with the institution's organizational structure, and the type and significance of the information;
(c) is performed regularly and where appropriate, also on an ad hoc basis;
(d) provides adequate evidence that the recommendations are sufficiently addressed and properly implemented by the institution.
Article 75
IT infrastructure
When assessing the architecture of the IT systems, of relevance to the institution’s rating systems and to the application of the IRB Approach in accordance with Article 144 of Regulation (EU) No 575/2013, competent authorities shall evaluate all of the following:
(a) the IT systems architecture including all applications, their interfaces and interactions;
(b) a data flow diagram showing a map of the key applications, databases and IT components involved in the application of the IRB Approach and relating to rating systems;
(c) the assignment of IT systems owners;
(d) the capacity, scalability and efficiency of IT systems;
(e) the manuals of the IT systems and databases.
When assessing the soundness, safety and security of the IT infrastructure that is of relevance to the institution’s rating systems and to the application of the IRB Approach, competent authorities shall verify that:
(a) the IT infrastructure can support the ordinary and extraordinary processes of an institution in a timely, automatic and flexible manner;
(b) the risk of suspension of the abilities of the IT infrastructure (‘failures’), the risk of loss of data and the risk of incorrect evaluations (‘faults’) are appropriately addressed;
(c) the IT infrastructure is adequately protected against theft, fraud, manipulation or sabotage of data or systems by malicious insiders or outsiders.
When assessing the robustness of the IT infrastructure that is of relevance to the institution’s rating systems and to the application of the IRB Approach, competent authorities shall verify that:
(a) the procedures to back up the IT systems, data and documentation are implemented and tested on a periodic basis;
(b) continuity action plans are implemented for critical IT systems;
(c) the recovery procedures of IT systems in case of failure are defined and tested on a periodic basis;
(d) the management of IT systems users is compliant with the institution’s relevant policies and procedures;
(e) audit trails are implemented for critical IT systems;
(f) the management of changes of IT systems is adequate and the monitoring of changes covers all IT systems.
When assessing whether the IT infrastructure that is of relevance to the institution’s rating systems and to the application of the IRB Approach is reviewed both regularly and on an ad hoc basis, competent authorities shall verify that:
(a) regular monitoring and ad hoc reviews result in recommendations to address weaknesses or shortcomings, where detected;
(b) the findings and the recommendations referred to in point (a) are communicated to the senior management and management body of the institution;
(c) there is adequate evidence that the recommendations are properly addressed and implemented by the institution.
CHAPTER 13
ASSESSMENT METHODOLOGY OF INTERNAL MODELS FOR EQUITY EXPOSURES
Article 76
General
When assessing whether an institution is able to develop and validate the internal model for equity exposures and to assign each exposure to the range of application of an internal models approach for equity exposures as required by points (f) and (h) of Article 144(1) and Articles 186, 187 and 188 of Regulation (EU) No 575/2013, competent authorities shall evaluate all of the following:
(a) the adequacy of the data used, in accordance with Article 77;
(b) the adequacy of the models, in accordance with Article 78;
(c) the comprehensiveness of the stress-testing programme, in accordance with Article 79;
(d) the integrity of the model and modelling process, in accordance with Article 80;
(e) the adequacy of the assignment of exposures to the internal models approach, in accordance with Article 81;
(f) the adequacy of the validation function, in accordance with Article 82.
For the purposes of the evaluation under paragraph 1, competent authorities shall apply all of the following methods:
(a) review the institution’s relevant internal policies and procedures;
(b) review the institution’s technical documentation on the methodology and process of the development of the internal model for equity exposures;
(c) review and challenge the relevant development manuals, methodologies and processes;
(d) review the roles and responsibilities of the different units and internal bodies involved in the design, validation and application of the internal model for equity exposures;
(e) review the relevant minutes of the institution’s internal bodies, including the management body, or committees;
(f) review the relevant reports on the performance of the internal models for equity exposures and the recommendations by the credit risk control unit, validation function, internal audit function or any other control function of the institution;
(g) review the relevant progress reports on the efforts made by the institution to correct shortcomings and mitigate risks detected during monitoring, validations and audits;
(h) obtain written statements from or interview the relevant staff and senior management of the institution.
For the purposes of the evaluation under paragraph 1, competent authorities may also apply any of the following additional methods:
(a) request and analyse data used in the process of development of internal models for equity exposures;
(b) conduct their own or replicate the institution’s Value at Risk estimations using relevant data supplied by the institution;
(c) request the provision of additional documentation or analysis substantiating the methodological choices and the results obtained;
(d) review the functional documentation of the IT systems used for the value at risk calculation;
(e) review other relevant documents of the institution.
Article 77
Adequacy of the data
When assessing the adequacy of the data used to represent the actual return distributions on equity exposures in accordance with Article 186 of Regulation (EU) No 575/2013, competent authorities shall verify that:
(a) the data represents the risk profile of the institution’s specific equity exposures;
(b) the data is sufficient to provide statistically reliable loss estimates, or it has been adequately adjusted in order to attain model outputs that achieve appropriate realism and conservatism;
(c) the data used comes from external sources or, where internal data is used, it is independently reviewed by a relevant control function of the institution;
(d) the data reflects the longest available period in order to provide a conservative estimate of potential losses over a relevant long-term or business cycle, and in particular that it includes the period of significant financial stress relevant to the institution’s portfolio;
(e) where converted-quarterly data from a shorter horizon is used, that the conversion procedure is supported by empirical evidence through a well-developed and documented approach and applied conservatively and consistently over time;
(f) the longest time horizon is chosen which allows the estimation of the 99 percentile with non-overlapping observations.
Article 78
Adequacy of the models
When assessing the adequacy of the models used to estimate the equity return distributions for the calculation of own funds requirements in accordance with Article 186 of Regulation (EU) No 575/2013, competent authorities shall verify that:
(a) the model is appropriate for the risk profile and complexity of an institution's equity portfolio, and that where the institution has material holdings with values that are highly non-linear in nature, the model accounts for that in an appropriate manner;
(b) the mapping of individual positions to proxies, market indices and risk factors is plausible, intuitive and conceptually sound;
(c) the selected risk factors are appropriate and effectively cover both general and specific risk;
(d) the model adequately explains the historical price variation;
(e) the model captures both the magnitude of potential concentrations and changes in their composition.
Article 79
Comprehensiveness of the stress-testing programme
When assessing the comprehensiveness of the stress-testing programme required under Article 186(g) of Regulation (EU) No 575/2013, competent authorities shall verify that the institution is able to provide loss estimates under alternative adverse scenarios and that those scenarios are different from the ones used by the internal model but still likely to occur.
For the purpose of the assessment under paragraph 1, competent authorities shall verify that:
(a) the alternative adverse scenarios are relevant to the specific holdings of the institution, reflect significant losses to the institution and capture effects which are not reflected in the outcomes of the model;
(b) the outcomes of the model under the alternative adverse scenarios are used in the actual risk management for the equity portfolio and are periodically reported to senior management;
(c) the alternative adverse scenarios are periodically reviewed and updated.
Article 80
Integrity of the model and modelling process
When assessing the integrity of the models and modelling process required under Article 187 of Regulation (EU) No 575/2013, competent authorities shall verify that:
(a) the internal model is fully integrated into the management of the non-trading book equity portfolio, the overall management information systems of the institution and the institution's risk management infrastructure and is used to monitor the investment limits and the risk of equity exposures;
(b) the modelling unit is competent and independent from the unit responsible for managing the individual investments.
For the purpose of the assessment under paragraph 1(a), competent authorities shall verify that:
(a) the institution’s management body and senior management are actively involved in the risk control process in the sense that they have, endorsed a set of investment limits based, among other factors, on the internal model’s results;
(b) the reports produced by the risk control unit are reviewed by persons at a level of management with sufficient authority to enforce reductions of positions as well as reduction in the institution’s overall risk exposure;
(c) action plans are in place for market crisis situations affecting activities within the model’s scope, describing the events that trigger them and the planned actions.
For the purpose of the assessment under paragraph 1(b), competent authorities shall verify that:
(a) the staff and the senior management responsible for the modelling unit do not perform tasks relating to managing the individual investments;
(b) the senior managers of modelling units and of units responsible for managing the individual investments have different reporting lines at the level of the management body of the institution or the committee designated by it;
(c) the remuneration of the staff and of the senior management responsible for the modelling unit is not linked to the performance of the tasks relating to managing the individual investments.
Article 81
Adequacy of assignment of exposures to the internal models approach
When assessing the adequacy of the assignment of each exposure in the range of application of an approach for equity exposures to the internal models approach in accordance with Article 144(1)(h) of Regulation (EU) No 575/2013, competent authorities shall evaluate the definitions, processes and criteria for assigning or reviewing the assignment.
Article 82
Adequacy of the validation function
When assessing the adequacy of the validation function with regard to the requirements laid down in point (f) of Article 144(1) and Article 188 of Regulation (EU) No 575/2013, competent authorities shall apply Articles 10 to 13 and shall verify that:
(a) the institution compares the first percentile of the actual equity returns with the modelled estimates at least on a quarterly basis;
(b) the comparison referred to in point (a) makes use of an observation period equal at least to one year and of a time horizon that allows the computation of the first percentile based on non-overlapping observations;
(c) where the percentage of observations below the estimated first percentile of equity returns is above 1 %, this is adequately justified and relevant remedial actions are taken by the institution.
CHAPTER 14
ASSESSMENT METHODOLOGY FOR MANAGEMENT OF CHANGES TO RATING SYSTEMS
Article 83
General
In order to assess an institution’s compliance with the requirements regarding the management of changes, and documentation of changes, to the range of application of a rating system or to the range of application of an internal models approach to equity exposures, and of changes to the rating systems or internal models approach to equity exposures in accordance with Article 143(3) and (4) and Article 175(2) of Regulation (EU) No 575/2013, competent authorities shall verify that the institution’s policy relating to such changes (‘change policy’) has been properly implemented and meets the requirements of Articles 2 to 5, Article 8 and Annex I to Delegated Regulation (EU) No 529/2014.
For the purposes of the assessment under paragraph 1, competent authorities shall apply all of the following methods:
(a) review the institution’s change policy;
(b) review the relevant minutes of the institution’s internal bodies, including the management body, model committee, or other committees;
(c) review the relevant reports on the management of changes to the rating systems and the recommendations by the credit risk control unit, validation function, internal audit function or any other control function of the institution;
(d) review the relevant progress reports on the efforts made by the institution to correct shortcomings and mitigate risks detected during monitoring, validations and audits;
(e) obtain written statements from or interview the relevant staff and the senior management of the institution.
For the purposes of the assessment under paragraph 1, competent authorities may also review other relevant documents of the institution.
Article 84
Change policy content
When assessing an institution’s change policy, competent authorities shall verify that the change policy implements the requirements of Regulation (EU) No 575/2013 as well as the criteria laid down in Articles 1 to 5, Article 8 and Annex I to Delegated Regulation (EU) No 529/2014 and that it provides for the practical application of those requirements and criteria taking into account the following:
(a) responsibilities, reporting lines and procedures for the internal approval of changes, having regard to the institution’s organisational characteristics and approach specificities;
(b) definitions, methods and, where applicable, metrics for the classification of changes;
(c) procedures to identify, monitor, notify and apply for permission on changes to competent authorities;
(d) procedures for the implementation of changes, including their documentation.
CHAPTER 15
FINAL PROVISION
Article 85
Entry into force
This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.
This Regulation shall be binding in its entirety and directly applicable in all Member States.
Done at Brussels, 20 October 2021.
For the Commission The President Ursula VON DER LEYEN
(1) OJ L 176, 27.6.2013, p. 1.
(2) Commission Delegated Regulation (EU) No 529/2014 of 12 March 2014 supplementing Regulation (EU) No 575/2013 of the European Parliament and of the Council with regard to regulatory technical standards for assessing the materiality of extensions and changes of the Internal Ratings Based Approach and the Advanced Measurement Approach (OJ L 148, 20.5.2014, p. 36).
(3) Directive 2013/36/EU of the European Parliament and of the Council of 26 June 2013 on access to the activity of credit institutions and the prudential supervision of credit institutions and investment firms, amending Directive 2002/87/EC and repealing Directives 2006/48/EC and 2006/49/EC (OJ L 176, 27.6.2013, p. 338).
(4) Regulation (EU) No 1093/2010 of the European Parliament and of the Council of 24 November 2010 establishing a European Supervisory Authority (European Banking Authority), amending Decision No 716/2009/EC and repealing Commission Decision 2009/78/EC (OJ L 331, 15.12.2010, p. 12).
(5) Commission Delegated Regulation (EU) 2018/171 of 19 October 2017 on supplementing Regulation (EU) No 575/2013 of the European Parliament and of the Council with regard to regulatory technical standards for the materiality threshold for credit obligations past due (OJ L 32, 6.2.2018, p. 1).
(6) Commission Delegated Regulation (EU) 2017/72 of 23 September 2016 supplementing Regulation (EU) No 575/2013 of the European Parliament and of the Council with regard to regulatory technical standards specifying conditions for data waiver permissions (OJ L 10, 14.1.2017, p. 1).
(7) Commission Implementing Decision 2014/908/EU of 12 December 2014 on the equivalence of the supervisory and regulatory requirements of certain third countries and territories for the purposes of the treatment of exposures according to Regulation (EU) No 575/2013 of the European Parliament and of the Council (OJ L 359, 16.12.2014, p. 155).
Reading this document does not replace reading the official text published in the Official Journal of the European Union. We assume no responsibility for any inaccuracies arising from the conversion of the original to this format.
This text is published under EUR-Lex's own terms of reuse, not a Legalize or public-domain licence.
EUR-Lex
Creative Commons Attribution 4.0 International (CC BY 4.0)
© European Union, https://eur-lex.europa.eu — Source: EUR-Lex (Publications Office of the European Union). Reused under the Creative Commons Attribution 4.0 International (CC BY 4.0) licence. Only EU legislation published in the printed Official Journal of the European Union is deemed authentic; consolidated texts are reproduced here for documentation purposes and have been reformatted to Markdown.